A method and network device for SF failover

By configuring multiple End.AS in the SFF device and using NQA or ICMP to probe the link status, efficient link switching during SF failure is achieved, solving the resource waste and complex processing problems caused by SF failure in SRv6 SFC service chain network and improving the efficiency of network devices.

CN118555191BActive Publication Date: 2025-11-07NEW H3C TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410833510.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-06-25
Publication Date
2025-11-07
Estimated Expiration
2044-06-25

AI Technical Summary

Technical Problem

In an SRv6 SFC service chain network, when the application service node SF fails, packets cannot be forwarded in the normal logical order, and existing technologies require at least two SFF devices to perform master-slave switching, resulting in resource waste and complex processing procedures.

Method used

The SFF device is configured with multiple End.AS, which detect link status via NQA or ICMP and switch to a backup SF when a fault is detected, simplifying the process and saving SFF device resources.

Benefits of technology

It enables link switching during SF failure, simplifies the packet processing flow, saves SFF device resources, avoids repetitive packet decapsulation and encapsulation, and improves the efficiency of network devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118555191B_ABST
    Figure CN118555191B_ABST
Patent Text Reader

Abstract

The specification provides a method and network device for SF failure switching, the method comprising: at least configuring a first End.AS and a second End.AS in the SFF device, wherein the first End.AS and the second End.AS correspond to a first SF and a second SF respectively, and when the SFF device detects that a link to the first SF is faulty, the first End.AS is placed in a first state. Through the method, the SC device can learn the link conditions to the first SF and the second SF, and when it is learned that the link to the first SF (the primary SF) is faulty, the service message can be sent to the second SF through the SFF.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present specification relates to the technical field of communication, and particularly relates to a method for SF fault switching and a network device. BACKGROUND

[0002] In order to meet the needs of user service safety, stability and the like, when data messages are transmitted in a network, the data messages often need to pass through various service nodes in sequence according to service logic, such as a firewall (Firewall), an intrusion prevention system (Intrusion Prevention System), an application accelerator and network address translation (Network Address Translation) and the like. SRv6 SFC (Service Function Chain) is a technology of guiding messages to pass through application layer service devices in sequence according to a specified path by adding SRv6 path information in an original message. The SRv6 SFC technology can conveniently meet the above needs.

[0003] An SRv6 SFC service chain network includes the following roles:

[0004] · SC (Service Classifier, service classification node): located at the edge of the SRv6 SFC service chain network, and is a source node of a service chain path. The SC can adopt different diversion methods to introduce service data into an SRv6 TE Policy tunnel for forwarding.

[0005] · SF (Service Function, application service node): a node providing specific application services for traffic. An application service node that cannot recognize an SRv6 message is referred to as an SRv6-unaware SF, and an application service node that can recognize an SRv6 message is referred to as an SRv6-aware SF.

[0006] · SFF (Service Function Forwarder, service chain forwarding node): the SFF serves as a service chain proxy of the SF, and forwards a received message to a plurality of SFs associated with the SFF according to SRv6 encapsulation information. After the SF processes the message, the message is returned to the SFF, and the SFF decides whether to continue forwarding the message.

[0007] Without any protection, when an SF is unreachable, a message that needs to pass through an application service node SF is discarded after reaching an SFF device, and the message cannot be forwarded in a normal logical order or pass through the processing of the application service node. SUMMARY

[0008] To overcome the problems in the related art, the specification provides a method and network device for SF failover.

[0009] According to a first aspect of an embodiment of the specification, a method for SF failover of an application service node is provided, which is applied to a service chain forwarding node SFF device in an SRv6 SFC service chain network, and the method comprises:

[0010] The SFF device is configured with at least a first End.AS and a second End.AS, wherein the first End.AS and the second End.AS correspond to a first SF and a second SF respectively;

[0011] When the SFF device detects that a link to the first SF is faulty, the first End.AS is placed in a first state, so that the SFF device sends a packet received from a service classification node SC to the second SF through the second End.AS.

[0012] The SFF device is configured with at least a first End.AS and a second End.AS, wherein the first End.AS and the second End.AS correspond to a first SF and a second SF respectively, and the method comprises:

[0013] The SFF device is dual-homed to the first SF and the second SF, the first End.AS is configured for a link to the first SF, and the second End.AS is configured for a link to the second SF.

[0014] The SFF device is configured with at least a first End.AS and a second End.AS, wherein the first End.AS and the second End.AS correspond to a first SF and a second SF respectively, and the method comprises:

[0015] The SFF device detects the link conditions of the first SF and the second SF through NQA or ICMP.

[0016] When it is detected that the link to the first SF is faulty, the first End.AS corresponding to the first SF is placed in a first state, and the first state is used to indicate a DOWN state.

[0017] As can be seen from the above method, the SFF can be dual-homed (multi-homed) to multiple SF devices, and when it is detected that the link to the first SF (primary SF) is faulty, the second SF can be switched on, thereby realizing the switching of the primary and backup links, simplifying the processing flow of the packet, saving one SFF device compared with the SF dual-protection scenario and the Bypass protection scenario, and simplifying the networking.

[0018] According to a second aspect of the embodiments of the present specification, a method for service function node (SF) failover is provided, the method is applied to a service classification node (SC) device in a SRv6 SFC service chain network, and the method comprises the following steps:

[0019] configuring an Srv6 policy corresponding to a first End.AS and a second End.AS in an SFF device, wherein the first End.AS and the second End.AS correspond to a first SF and a second SF respectively;

[0020] detecting, by an SBFD packet, link reachability of a first SF corresponding to the first End.AS and a second SF corresponding to the second End.AS;

[0021] when it is detected that the link to the first SF is unreachable, sending a service packet to the second SF.

[0022] The configuration of the Srv6 policy comprises the following steps:

[0023] configuring a first Srv6 policy and a second Srv6 policy;

[0024] The first Srv6 policy corresponds to the first End.AS, and the second Srv6 policy corresponds to the second End.AS.

[0025] When it is detected that the link to the first SF is unreachable, the SC device sends a service packet to the second SF through the second Srv6 policy.

[0026] When it is detected that the link to the first SF is unreachable, the SC device sends a service packet to the second SF through the second Srv6 policy.

[0027] As can be seen from the above embodiments, the SC device can know the link conditions to the first SF and the second SF, and when it is known that the link to the first SF (primary SF) is faulty, the SC device can send a service packet to the second SF through the SFF.

[0028] According to a third aspect of the embodiments of the present specification, a network device is provided, the network device is configured as a service chain forwarding node (SFF) device in a SRv6 SFC service chain network, and the network device comprises the following steps:

[0029] a configuration module configured to configure a first End.AS and a second End.AS, wherein the first End.AS and the second End.AS correspond to a first SF and a second SF respectively;

[0030] The detection module is configured to detect whether a link to the first SF and the second SF is faulty, and when it is detected that the link to the first SF is faulty, the first End.AS is placed in a first state, so that the SFF device sends a packet to the second SF through the second End.AS after receiving the packet sent by the service classification node SC.

[0031] The configuration module is configured to access the first SF and the second SF in dual-homing mode, configure the first End.AS for a link of the first SF, and configure the second End.AS for a link of the second SF.

[0032] The detection module is configured to detect a link condition of the first SF and the second SF through NQA or ICMP probe.

[0033] When it is detected that the link to the first SF is faulty, the first End.AS corresponding to the first SF is placed in a first state, and the first state is used to represent a DOWN state.

[0034] According to a third aspect of the embodiments of the present specification, a network device is provided, which is configured as a service classification node SC device in an SRv6 SFC service chain network, and the network device comprises:

[0035] The configuration module is configured to configure an Srv6 policy corresponding to a first End.AS and a second End.AS in an SFF device, wherein the first End.AS and the second End.AS correspond to a first SF and a second SF respectively.

[0036] The detection module is configured to detect a link reachability condition of a first SF corresponding to the first End.AS and a second SF corresponding to the second End.AS through an SBFD packet.

[0037] The sending module is configured to send a service packet to the second SF when it is detected that a link to the first SF is unreachable.

[0038] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present specification. BRIEF DESCRIPTION OF DRAWINGS

[0039] The accompanying drawings incorporated in the specification and forming a part of the specification illustrate embodiments consistent with the present specification and serve to explain the principles of the present specification together with the specification.

[0040] Figure 1 is a network architecture diagram of SF dual-homing protection according to an exemplary embodiment of the present specification.

[0041] Figure 2is a schematic diagram of a network architecture with Bypass protection according to an example embodiment.

[0042] Figure 3 is a schematic diagram of a method for service function (SF) failover according to an example embodiment.

[0043] Figure 4 is a schematic diagram of a network architecture according to an example embodiment. DETAILED DESCRIPTION

[0044] The example embodiments will be described in detail in this disclosure with reference to the drawings. Whenever the shapes, relative arrangements, numerical values and other technical features described in this disclosure are clearly described, they are intended to include all technical and structural modifications thereof, in addition to the examples shown in the drawings. The following description is presented for people skilled in the art to make a better understanding of the example embodiments. Accordingly, those skilled in the art can easily implement the example embodiments by properly modifying them while being aware that some embodiments can be carried out in other specific forms, all without departing from the scope of the example embodiments. In the drawings:

[0045] The terminology used in the present disclosure is for the purpose of describing particular embodiments only and is not intended to be limiting of the present disclosure. As used in the present disclosure and the appended claims, the singular forms "a," "an" and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will be further understood that the terms "comprises" and / or "comprising," when used in this specification, specify the presence of stated features, integers, steps, operations, elements, and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof.

[0046] It is to be understood that the terms first, second, third, etc. can be adopted herein only to describe various information and should not be limited to these terms. These terms are only used to distinguish one type of information from another. For example, the first information can also be referred to as the second information, and similarly, the second information can also be referred to as the first information, without departing from the scope of the present disclosure. Depending on the context, the word "if' as used herein can be interpreted as meaning "when" or "upon determination" or "in response to a determination."

[0047] As Figure 1As shown in the SF dual-homing protection scenario, when SFF 1 detects that the SF is unreachable from SFF 1, SFF 1 decapsulates the packet, removes the original IPv6 and SRH packet header, and re-encapsulates the IPv6 and SRH header according to the configuration, wherein the SID list in the SRH header includes the backup End.ASSID X2 and the End SID C of SFF 2. The destination address of the IPv6 header is C, and SFF 1 searches the routing table to forward the encapsulated packet to the dual-homing backup node SFF 2. After the packet arrives at SFF 2, if SFF 2 is reachable to the SF, the packet is processed according to the normal SRv6 SFC service chain static proxy forwarding process; if SFF 2 is unreachable to the SF, the packet is discarded.

[0048] As shown in the SF dual-homing protection scenario, when SFF 1 detects that the SF is unreachable from SFF 1, SFF 1 decapsulates the packet, removes the original IPv6 and SRH packet header, and re-encapsulates the IPv6 and SRH header according to the configuration, wherein the SID list in the SRH header includes the backup End.ASSID X2 and the End SID C of SFF 2. The destination address of the IPv6 header is C, and SFF 1 searches the routing table to forward the encapsulated packet to the dual-homing backup node SFF 2. After the packet arrives at SFF 2, if SFF 2 is reachable to the SF, the packet is processed according to the normal SRv6 SFC service chain static proxy forwarding process; if SFF 2 is unreachable to the SF, the packet is discarded. Figure 2 As shown in the Bypass protection scenario, there is a Bypass protection service node SF 2 of SF 1 in the SFC network, SF 1 is single-homed to SFF 1, and the Bypass protection service node SF 2 is single-homed to SFF 2.

[0049] When SFF 1 detects that the SF is unreachable from SFF 1, SFF 1 decapsulates the packet, removes the original IPv6 and SRH packet header, and re-encapsulates the IPv6 header according to the configuration, wherein the destination address of the IPv6 is C, and SFF 1 searches the routing table to forward the encapsulated packet to SFF 2. SFF 2 receives the packet and processes the packet according to the normal SRv6 SFC service chain static proxy forwarding process.

[0050] From the above SF dual-homing protection scenario and Bypass protection scenario, it can be seen that in both the dual-homing scenario and the Bypass scenario, when the SF fails, SFF 1 forwards the packet to the next SFF 2 device for processing, and the packet is decapsulated on SFF 1, the original IPv6 and SRH header are removed, and the original packet is forwarded to the SF for processing after the packet is decapsulated on SFF 2. The packet is decapsulated twice, which increases the packet processing flow. At the same time, two SFF devices are needed, which wastes SFF device resources.

[0051] To solve the above technical problems, the embodiments of the present disclosure provide a method for switching application service node SF failure, which is applied to a service chain forwarding node SFF device in an SRv6 SFC service chain network, as shown in Figure 3 The method comprises the following steps:

[0052] S301 The SFF device is configured with at least a first End.AS and a second End.AS, wherein the first End.AS and the second End.AS correspond to a first SF and a second SF respectively;

[0053] S302, when the SFF device detects that the link to the first SF is faulty, the first End.AS is placed in the first state, so that the SFF device sends the message sent by the service classification node SC to the second SF through the second End.AS after receiving the message.

[0054] In step S301, multiple End.ASs can be configured in the SFF device, and the number of End.ASs corresponds to the SFs, as shown in the table. Figure 4 As shown in the table, if there are two SFs, two End.ASs corresponding to the SFs are configured, i.e., a first End.AS and a second End.AS, wherein the first End.AS is set to correspond to the first SF, i.e., End.ASSID=X1, and the second End.AS is set to correspond to the second SF, i.e., End.ASSID=X2.

[0055] In this embodiment, the SFF device accesses the first SF and the second SF (here, it is not limited to only two SFs, and in actual applications, there can be a third SF and a fourth SF) in a dual-homing manner. The link accessing the first SF is configured with a first End.AS, and the link accessing the second SF is configured with a second End.AS.

[0056] In step S302, the SFF device can detect the link conditions of the first SF and the second SF by NQA or ICMP, and configure the states of the first End.AS and the second End.AS according to the detection results. For example, in this example, the first state is set as a DOWN state, and the second state is set as an UP state. Under normal circumstances, if the SFF detects that the detection results of the first End.AS and the second End.AS are normal, the SFF configures the second state for the first End.AS and the second End.AS, and if the SFF detects that the detection result of the first End.AS or the second End.AS is abnormal, the SFF configures the first state for the abnormal End.AS.

[0057] In one embodiment, it is assumed that the first SF is a primary SF and the second SF is a backup SF. When the SFF detects that the link to the first SF is abnormal, the SFF places the first End.AS in the first state, and when the SFF detects that the link to the second SF is normal, the SFF places the second End.AS in the first state, thereby completing the action of primary-backup switching.

[0058] The state can be represented by a forward-state attribute. When in the first state, the forward-state attribute is set to DOWN, and when in the second state, the forward-state attribute is set to UP.

[0059] In the embodiment, when the SFF receives the service packet sent from the SC device, if the state of the first End.AS of the first SF (assuming the primary SF) is the first state, the SFF sends the service packet to the first SF for processing, and if the state of the first End.AS of the first SF (assuming the primary SF) is the first state, the SFF sends the service packet to the second SF for processing.

[0060] As can be seen from the above embodiments, the SFF device is connected with multiple SFs, and an End.AS is configured for each SF, so that the link switching capability to the primary and backup SFs is realized by using one SFF, and the technical problem that at least two SFFs are required in the SF dual-homing protection scenario and the Bypass protection scenario in the prior art is solved.

[0061] The embodiments of the present disclosure further provide a method for service node SF fault switching, which is applied to a service classification node SC device in an SRv6 SFC service chain network, and includes the following steps:

[0062] configuring an Srv6 policy corresponding to a first End.AS and a second End.AS in an SFF device, wherein the first End.AS and the second End.AS correspond to a first SF and a second SF respectively;

[0063] detecting, through an SBFD packet, link reachability to a first SF corresponding to the first End.AS and a second SF corresponding to the second End.AS;

[0064] when it is detected that the link to the first SF is unreachable, sending a service packet to the second SF.

[0065] In the embodiment, the SC to the SFF can configure one Srv6 policy, and the SC sends a service packet through the Srv6 policy, and the SFF can send the service packet to the first SF or the second SF according to the link state of the first SF and the second SF.

[0066] In other embodiments, the SC configures a corresponding number of Srv6 policies according to the number of SFs, for example, in the case of the first SF and the second SF, the SC can configure a first Srv6 policy and a second Srv6 policy, wherein the first Srv6 policy corresponds to the first End.AS, and the second Srv6 policy corresponds to the second End.AS.

[0067] Meanwhile, the SC can send SBFD packets through each Srv6 policy to detect the link connectivity, and assume that the SFF detects that the link to the first SF is abnormal, and sets the state of the first End.AS to the first state, at this time, the SFF will discard the packets sent to the first SF.

[0068] When the SBFD packet sent by the SC through the first Srv6 policy is discarded on the SFF, the SC can determine that the link from the SFF to the first SF is abnormal, at this time, if the SC wants to send service packets, the SC sends the service packets to the SFF through the second Srv6 policy.

[0069] After the SFF receives the service packets through the second Srv6 policy, the SFF sends the service packets to the second SF through the second End.AS.

[0070] As can be seen from the above embodiment, the SC can configure multiple Srv6 policies, and different Srv6 policies correspond to the links from the SFF to different SFs, thereby realizing the function of link switching of the SC according to the link conditions of the primary and backup SFs.

[0071] Based on the above method embodiments, the embodiment of the disclosure further provides a network device, which is configured as a service chain forwarding node SFF device in an SRv6 SFC service chain network, and the network device comprises:

[0072] A configuration module is configured to configure a first End.AS and a second End.AS, wherein the first End.AS and the second End.AS correspond to a first SF and a second SF respectively;

[0073] A detection module is configured to detect whether the links to the first SF and the second SF are faulty, and when it is detected that the link to the first SF is faulty, set the first End.AS to a first state, so that the SFF device sends the packets sent by a service classification node SC to the second SF through the second End.AS after receiving the packets.

[0074] The configuration module is configured to dual-homed to the first SF and the second SF, configure the first End.AS for the link of the first SF, and configure the second End.AS for the link of the second SF.

[0075] The detection module is configured to detect the link conditions of the first SF and the second SF through NQA or ICMP.

[0076] When it is detected that the link to the first SF is faulty, set the first End.AS corresponding to the first SF to the first state, and the first state is used to represent a DOWN state.

[0077] The embodiment of the present disclosure further provides a network device configured as a service classification node SC device in an SRv6 SFC service chain network, the network device comprising:

[0078] The configuration module is configured to configure an Srv6 policy corresponding to a first End.AS and a second End.AS in the SFF device, wherein the first End.AS and the second End.AS correspond to a first SF and a second SF respectively;

[0079] The detection module is configured to detect, through an SBFD packet, link reachability of a first SF corresponding to the first End.AS and a second SF corresponding to the second End.AS;

[0080] The sending module is configured to send a service packet to the second SF when it is detected that the link to the first SF is unreachable.

[0081] For the device embodiment, since it basically corresponds to the method embodiment, the related parts can be referred to the part of the method embodiment. The device embodiment described above is only illustrative, wherein the modules described as separate components can or can not be physically separated, and the components displayed as modules can or can not be physical modules, that is, they can be located in one place or distributed on multiple network modules. According to actual needs, part or all of the modules can be selected to achieve the purpose of the scheme of the present specification. Those skilled in the art can understand and implement without creative labor.

[0082] The above describes specific embodiments of the present specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims can be performed in an order different than the order in the embodiments and still achieve the desired result. In addition, the processes depicted in the figures do not necessarily require the particular order shown, or sequential order, to achieve the desired results. In some implementations, multitasking and parallel processing can be advantageous or required.

[0083] Other embodiments of the present specification will be readily apparent to those skilled in the art upon considering the specification in its entirety. The present specification is intended to cover any variations, uses, or adaptations of the present specification following, in general, the principles of the present specification and including such departures from the present specification as come within the known and customary practice in the art to which the present specification pertains or the like. The specification is to be regarded in an illustrative manner and embodiments of the present specification are to be presented for purposes of exemplification and not limitation, as the true scope and spirit of the present specification are indicated in the following claims.

[0084] It is to be understood that the present description is not limited to the precise construction herein described and as shown in the attached drawings, and that various modifications and changes can be made by those skilled in the art without departing from the scope thereof. The scope of the description is indicated only by the appended claims.

[0085] The above description is merely the preferred embodiments of the present description and is not intended to limit the present description. It is understood by those skilled in the art that any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present description shall be included in the scope of the present description.

Claims

1. A method for application service node (SF) failover, characterized in that, The method is applied to a service chain forwarding node SFF device in an SRv6 SFC service chain network, and the method comprises: The SFF device is configured with at least a first End.AS and a second End.AS, wherein the first End.AS and the second End.AS correspond to a first SF and a second SF respectively; When the SFF device detects that a link to the first SF is faulty, the first End.AS is placed in a first state, so that the SFF device sends a packet to the second SF through the second End.AS after receiving the packet sent by a service classification node SC.

2. The method of claim 1, wherein, The SFF device is configured with at least a first End.AS and a second End.AS, wherein the first End.AS and the second End.AS correspond to a first SF and a second SF respectively, comprising: The SFF device is dual-homed to the first SF and the second SF, a first End.AS is configured to a link to the first SF, and a second End.AS is configured to a link to the second SF.

3. The method of claim 1, wherein, The SFF device detects a link condition of the first SF and the second SF through NQA or ICMP; When it is detected that the link to the first SF is faulty, the first End.AS corresponding to the first SF is placed in a first state, and the first state is used to indicate a DOWN state. The method is applied to a service classification node SC device in an SRv6 SFC service chain network, and the method comprises: 4.A method for service function (SF) failover, the method comprising: An Srv6 policy is configured, the Srv6 policy corresponds to a first End.AS and a second End.AS in the SFF device, wherein the first End.AS and the second End.AS correspond to a first SF and a second SF respectively; A link reachability condition of a first SF corresponding to the first End.AS and a second SF corresponding to the second End.AS is detected through an SBFD packet; When it is detected that the link to the first SF is unreachable, a service packet is sent to the second SF. The Srv6 policy is configured, comprising:

5. The method of claim 4, wherein, A first Srv6 policy and a second Srv6 policy are configured; The first Srv6 policy corresponds to the first End.AS, and the second Srv6 policy corresponds to the second End.AS. When it is detected that the link to the first SF is unreachable, the service packet is sent to the second SF through the second Srv6 policy.

6. The method of claim 5, wherein, The network device is configured as a service chain forwarding node SFF device in an SRv6 SFC service chain network, and the network device comprises: A configuration module is configured to configure a first End.AS and a second End.AS, wherein the first End.AS and the second End.AS correspond to a first SF and a second SF respectively; 7. A network device, comprising: ​ ​ The detection module is configured to detect whether a link to the first SF and the second SF is faulty, and when it is detected that the link to the first SF is faulty, the first End.AS is placed in a first state, so that the SFF device sends a packet to the second SF through the second End.AS after receiving the packet sent by the service classification node SC.

8. The network device of claim 7, wherein, The configuration module is configured to access the first SF and the second SF in dual-homing mode, configure a first End.AS for a link of the first SF, and configure a second End.AS for a link of the second SF.

9. The network device of claim 7, wherein, The detection module is configured to detect a link condition of the first SF and the second SF through NQA or ICMP probe. When it is detected that the link to the first SF is faulty, the first End.AS corresponding to the first SF is placed in a first state, and the first state is used to represent a DOWN state.

10. A network device, comprising: The network device is configured as a service classification node SC device in an SRv6 SFC service chain network, and the network device comprises: A configuration module is configured to configure an Srv6 policy corresponding to a first End.AS and a second End.AS in an SFF device, wherein the first End.AS and the second End.AS correspond to a first SF and a second SF respectively; A detection module is configured to detect a link reachability condition of a first SF corresponding to the first End.AS and a second SF corresponding to the second End.AS through an SBFD packet; A sending module is configured to send a service packet to the second SF when it is detected that the link to the first SF is unreachable.