Traffic forwarding method and device and related equipment
By creating a destination address micro-segment group and building an access control list ACL for each Leaf device in the Spine-Leaf architecture network, the problem of insufficient ACL resources of the device is solved, and fine traffic path navigation is realized in high-bandwidth scenarios.
Patent Information
- Application Number
- CN202510238359.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-28
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2045-02-28
AI Technical Summary
In high-bandwidth intelligent computing scenarios, the device's ACL resources are insufficient and it is impossible to achieve fine traffic path navigation.
In the Spine-Leaf architecture networking, M destination address micro-segment groups are created for each Leaf device, and a corresponding access control list ACL is built to forward traffic. The method includes building multiple ACLs for each source address and sending them to the Leaf device to achieve fine forwarding of traffic.
Through this method, the ACL hardware resource usage of Leaf devices is significantly reduced, the utilization rate of ACL hardware resources is improved, and fine traffic path navigation can be achieved in high bandwidth scenarios.
Smart Images

Figure CN119996305A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network communication technology, and in particular to a traffic forwarding method, device and related equipment. Background Art
[0002] The traffic bandwidth in current intelligent computing scenarios is getting higher and higher, requiring precise traffic path navigation to fully utilize the bandwidth of device ports. The current implementation uses the traffic-matrix function to achieve path navigation. The traffic-matrix implementation requires specifying the source and destination IPs as well as the device egress port to achieve precise traffic path navigation. However, one flow will occupy one ACL (Access Control Lists) resource of the device. In large-scale intelligent computing GPU scenarios, the device ACL resources are insufficient and cannot be applied. Summary of the invention
[0003] The present invention provides a method, device and related equipment for forwarding traffic.
[0004] In a first aspect, the present application provides a traffic forwarding method, which is applied to a controller in a Spine-Leaf architecture network, and the method includes:
[0005] For each Leaf device, M destination address micro-segment groups are created with the network card addresses of the first server connected to other Leaf devices except the Leaf device as the destination address;
[0006] Taking the network card addresses of the second server connected to the Leaf device as the source address, for each source address, according to the source address and the M destination address micro-segment groups, construct M access control lists ACL corresponding to the source address, wherein M is the number of uplinks between the Leaf device and each Spine device, and each ACL includes a source address item, a destination address micro-segment group, an outbound interface, and next hop information;
[0007] The M ACLs are sent down to the Leaf device so that after receiving the traffic message sent by the locally accessed server network card, the Leaf device searches for the source address as the source address of the traffic message based on the source address and destination address of the traffic message, and the destination address micro-segment group includes the target ACL of the destination address of the traffic message, and forwards the traffic message based on the target ACL.
[0008] Optionally, the method further comprises:
[0009] Get the size of the traffic carried by each ACL;
[0010] When it is determined that the traffic carried by the first ACL reaches a first preset value and there is traffic carried by the second ACL that does not reach a second preset value, part of the traffic carried by the first ACL is dynamically adjusted to be carried by the second ACL.
[0011] Optionally, a destination address micro-segment group includes multiple destination addresses; and the step of dynamically adjusting part of the traffic carried by the first ACL to be carried by the second ACL includes:
[0012] At least one destination address included in the first destination address micro-segment group corresponding to the first ACL is dynamically adjusted to the second destination address micro-segment corresponding to the second ACL.
[0013] In a second aspect, the present application provides a traffic forwarding method, which is applied to a target Leaf device in a Spine spine-Leaf leaf architecture network, wherein the controller of the network uses the network card addresses of servers accessed by other Leaf devices except the target Leaf device as the destination address, creates M destination address micro-segment groups, and uses the network card addresses of servers accessed by the target Leaf device as the source address. For each source address, according to the source address and the M destination address micro-segment groups, M access control lists ACLs corresponding to the source address are constructed and sent to the target Leaf device, wherein M is the number of uplinks between the Leaf device and each Spine device, and each ACL includes a source address item, a destination address micro-segment group, an outbound interface, and next hop information; the method includes:
[0014] Receive traffic packets sent by the local access server network card;
[0015] Based on the source address and the destination address of the flow message, searching for a source address that is the source address of the flow message, and a destination address micro-segment group that includes a target ACL of the destination address of the flow message;
[0016] The traffic message is forwarded based on the target ACL.
[0017] In a third aspect, the present application provides a traffic forwarding device, which is applied to a controller in a Spine-Leaf architecture network, and the device includes:
[0018] A creating unit, configured to create, for each Leaf device, M destination address micro-segment groups by taking the network card addresses of the first server connected to other Leaf devices except the Leaf device as destination addresses;
[0019] A construction unit is used to use the network card addresses of the second server connected to the Leaf device as source addresses, and for each source address, according to the source address and the M destination address micro-segment groups, to construct M access control lists ACL corresponding to the source address, wherein M is the number of uplinks between the Leaf device and each Spine device, and each ACL includes a source address item, a destination address micro-segment group, an outbound interface, and next hop information;
[0020] The sending unit is used to send the M ACLs to the Leaf device, so that after receiving the traffic message sent by the locally accessed server network card, the Leaf device searches for the source address as the source address of the traffic message based on the source address and destination address of the traffic message, and the destination address micro-segment group includes the target ACL of the destination address of the traffic message, and forwards the traffic message based on the target ACL.
[0021] Optionally, the device further comprises:
[0022] An acquisition unit, used for acquiring the size of the traffic carried by each ACL;
[0023] The adjustment unit is used to dynamically adjust part of the traffic carried by the first ACL to be carried by the second ACL when it is determined that the traffic carried by the first ACL reaches a first preset value and there is traffic carried by the second ACL that does not reach a second preset value.
[0024] Optionally, a destination address micro-segment group includes multiple destination addresses; when part of the traffic carried by the first ACL is dynamically adjusted to be carried by the second ACL, the adjusting unit is specifically used to:
[0025] At least one destination address included in the first destination address micro-segment group corresponding to the first ACL is dynamically adjusted to the second destination address micro-segment corresponding to the second ACL.
[0026] In a fourth aspect, the present application provides a traffic forwarding device, which is applied to a target Leaf device in a Spine spine-Leaf leaf architecture network, wherein the controller of the network uses the network card addresses of servers accessed by other Leaf devices except the target Leaf device as the destination address, creates M destination address micro-segment groups, and uses the network card addresses of servers accessed by the target Leaf device as the source address. For each source address, according to the source address and the M destination address micro-segment groups, M access control lists ACL corresponding to the source address are constructed and sent to the target Leaf device, wherein M is the number of uplinks between the Leaf device and each Spine device, and each ACL includes a source address item, a destination address micro-segment group, an outbound interface, and next hop information; the device includes:
[0027] A receiving unit, used to receive traffic messages sent by a locally connected server network card;
[0028] A search unit, configured to search, based on the source address and the destination address of the flow message, for a source address that is the source address of the flow message, wherein the destination address micro-segment group includes a target ACL of the destination address of the flow message;
[0029] A forwarding unit is used to forward the traffic message based on the target ACL.
[0030] In a fifth aspect, an embodiment of the present application provides a traffic forwarding device, the traffic forwarding device comprising:
[0031] A memory for storing program instructions;
[0032] The processor is used to call the program instructions stored in the memory, and execute the steps of the method as described in any one of the first aspects above according to the obtained program instructions.
[0033] In a sixth aspect, an embodiment of the present application further provides a computer-readable storage medium, wherein the computer-readable storage medium stores computer-executable instructions, and the computer-executable instructions are used to enable the computer to execute the steps of the method described in any one of the above-mentioned first aspects.
[0034] In a seventh aspect, an embodiment of the present application provides a traffic forwarding device, the traffic forwarding device comprising:
[0035] A memory for storing program instructions;
[0036] The processor is used to call the program instructions stored in the memory and execute the steps of the method as described in any one of the second aspects according to the obtained program instructions.
[0037] In an eighth aspect, an embodiment of the present application further provides a computer-readable storage medium, wherein the computer-readable storage medium stores computer-executable instructions, and the computer-executable instructions are used to enable the computer to execute the steps of the method described in any one of the second aspects above.
[0038] In summary, the traffic forwarding method provided in the embodiment of the present application is applied to the controller in the Spine-Leaf architecture network, and the method includes: for each Leaf device, taking the network card addresses of the first server connected to other Leaf devices except the Leaf device as the destination address, creating M destination address micro-segment groups; taking the network card addresses of the second server connected to the Leaf device as the source address, for each source address, according to the source address and the M destination address micro-segment groups, constructing M access control lists ACLs corresponding to the source address, wherein M is the number of uplinks between the Leaf device and each Spine device, and each ACL includes a source address item, a destination address micro-segment group, an outbound interface and next hop information; sending the M ACLs to the Leaf device, so that after receiving the traffic message sent by the locally connected server network card, the Leaf device searches for the target ACL whose source address is the source address of the traffic message based on the source address and destination address of the traffic message, and the destination address micro-segment group includes the destination address of the traffic message, and forwards the traffic message based on the target ACL.
[0039] By adopting the traffic forwarding method provided in the embodiment of the present application, the controller takes the GPU network card of other GPU servers as the destination address for each GPU network card, divides the destination address into several micro-segment groups according to the number of hops of the uplink from the Leaf device to the Spine device, and configures the corresponding ACL for each destination address micro-segment group, which greatly reduces the ACL hardware resource occupancy of the Leaf device and improves the ACL hardware resource utilization rate of the Leaf device. BRIEF DESCRIPTION OF THE DRAWINGS
[0040] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments of the present application or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this application. For ordinary technicians in this field, other drawings can also be obtained based on these drawings of the embodiments of the present application.
[0041] Figure 1 A detailed flow chart of a traffic forwarding method provided in an embodiment of the present application;
[0042] Figure 2 A network diagram provided for an embodiment of the present application;
[0043] Figure 3 A detailed flow chart of another traffic forwarding method provided in an embodiment of the present application;
[0044] Figure 4 A schematic diagram of the structure of a traffic forwarding device provided in an embodiment of the present application;
[0045] Figure 5 A schematic diagram of the structure of another traffic forwarding device provided in an embodiment of the present application;
[0046] Figure 6 A schematic diagram of the hardware architecture of a traffic forwarding device provided in an embodiment of the present application;
[0047] Figure 7 A schematic diagram of the hardware architecture of another traffic forwarding device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0048] The terms used in the embodiments of the present application are only for the purpose of describing specific embodiments, rather than limiting the present application. The singular forms of "a", "said" and "the" used in the present application and claims are also intended to include plural forms, unless the context clearly indicates other meanings. It should also be understood that the term "and / or" used herein refers to any or all possible combinations of one or more associated listed items.
[0049] It should be understood that, although the terms first, second, third, etc. may be used to describe various information in the embodiments of the present application, these information should not be limited to these terms. These terms are only used to distinguish the same type of information from each other. For example, without departing from the scope of the present application, the first information may also be referred to as the second information, and similarly, the second information may also be referred to as the first information. Depending on the context, in addition, the word "if" used may be interpreted as "at..." or "when..." or "in response to determination".
[0050] For example, see Figure 1 As shown, it is a detailed flow chart of a traffic forwarding method provided in an embodiment of the present application, which is applied to a controller in a Spine-Leaf architecture network. The method includes the following steps:
[0051] Step 100: For each Leaf device, M destination address micro-segment groups are created by taking the network card addresses of the first server connected to other Leaf devices except the Leaf device as destination addresses.
[0052] In actual applications, the controller obtains the network connection relationship (such as network topology) between the various network devices (such as Spine devices and Leaf devices) included in the managed network, and obtains the server (such as GPU server) to which each Leaf device is connected, the interface information of the network card of each Leaf device connected to each server, and the IP address information of each server network.
[0053] For example, see Figure 2As shown, a network diagram provided in an embodiment of the present application is taken as an example of a network including two Spine devices (Spine 1 and Spine 2) and two Leaf devices (Leaf 1 and Leaf 2). Leaf 1 is connected to GPU server 1, wherein the downstream port 11 of Leaf 1 is connected to the network card 11 of GPU server 1, and the downstream port 12 of Leaf 1 is connected to the network card 12 of GPU server 1; Leaf 2 is connected to GPU server 2, wherein the downstream port 21 of Leaf 2 is connected to the network card 21 of GPU server 2, and the downstream port 22 of Leaf 2 is connected to the network card 22 of GPU server 2. Leaf 1 and Leaf 2 establish uplinks with Spine 1 and Spine 2 respectively, that is, the number of uplinks from Leaf 1 to the Spine device is 2; the number of uplinks from Leaf 2 to the Spine device is 2.
[0054] In summary, in the embodiment of the present application, the controller can obtain the topology diagram of the network and the network card address of the GPU server network card connected to each downstream port of the Leaf device. Then, for each Leaf device, the network card addresses of the servers connected to other Leaf devices other than the Leaf device can be used as the destination address to create M destination address micro-segment groups (such as destination EPGs). Furthermore, based on preset rules, the above-determined destination addresses can be allocated to the M destination address micro-segment groups.
[0055] In the embodiment of the present application, one destination address micro-segment group includes multiple destination addresses.
[0056] Taking a 64-card environment as an example, the network includes 8 Leaf devices and 8 Spine devices. The GPU server connected to a single Leaf device includes 8 network cards, which are respectively connected to the downlink port of the Leaf device. For each network card address, the number of destination network cards that need to transmit traffic through the network is 56. Therefore, the 56 destination addresses can be allocated to 8 destination address micro-segments based on preset rules.
[0057] For example, taking a 64-card environment as an example, the network includes 8 Leaf devices and 8 Spine devices. The GPU server connected to a single Leaf device includes 8 network cards, which are respectively connected to the downstream port of the Leaf device. The number of source addresses is 8, and each source address corresponds to 56 destination addresses. There are 8 uplinks between Leaf and Spine devices. In actual applications, for a source address, no matter which network card's network card address the destination address is, one of the 8 uplinks between Leaf and Spine devices must be selected for forwarding. In this way, 8 destination address micro-segments are created, and according to the traffic scheduling strategy, the 56 destination addresses are allocated to the specified destination address micro-segments.
[0058] For example, it is assumed that GPU servers 1 to 8 are connected to Leaf 1 to Leaf 8 respectively, where:
[0059] The network card addresses of GPU server 1 are: 1.1.1.1; 1.1.1.2; ...; 1.1.1.8;
[0060] The network card addresses of GPU server 2 are: 2.1.1.1; 2.1.1.2; ...; 2.1.1.8;
[0061] The network card addresses of GPU server 3 are: 3.1.1.1; 3.1.1.2; ...; 3.1.1.8;
[0062] The network card addresses of GPU server 4 are: 4.1.1.1; 4.1.1.2; ...; 4.1.1.8;
[0063] The network card addresses of GPU server 5 are: 5.1.1.1; 5.1.1.2; ...; 5.1.1.8;
[0064] The network card addresses of GPU server 6 are: 6.1.1.1; 6.1.1.2; ...; 6.1.1.8;
[0065] The network card addresses of GPU server 7 are: 7.1.1.1; 7.1.1.2; ...; 7.1.1.8;
[0066] The network card addresses of GPU server 8 are: 8.1.1.1; 8.1.1.2; ...; 8.1.1.8;
[0067] Take the address of network card 11 (1.1.1.1) of GPU server 1 connected to Leaf 1 as the source address, and the network card address of the GPU server connected to Leaf 2 to Leaf 8 as the destination address (56) as an example. The number of uplinks from each Leaf to the Spine device is 8, and 8 destination address micro-segment groups are created. The 56 destination addresses are allocated to the 8 micro-segments as shown in Table 1:
[0068]
[0069]
[0070] Table 1
[0071] Step 110: Using the network card addresses of the second server connected to the Leaf device as source addresses, for each source address, construct M access control lists ACL corresponding to the source address according to the source address and the M destination address micro-segment groups.
[0072] Among them, M is the number of uplinks between the Leaf device and each Spine device, and each ACL includes a source address item, a destination address micro-segment group, an outbound interface, and next hop information.
[0073] The address of network card 11 (1.1.1.1) of GPU server 1 connected to Leaf 1 is used as the source address. According to the source address and the created 8 destination address micro-segment groups, 8 ACLs corresponding to the source address are constructed as shown in Table 2:
[0074]
[0075]
[0076] Table 2
[0077] Among them, 0 / 0 / 1 is the uplink interface 1 on Leaf 1 connected to Spine 1, and 10.1.1.1 is the IP address of Spine 1; 0 / 0 / 2 is the uplink interface 2 on Leaf 1 connected to Spine 2, and 10.1.1.2 is the IP address of Spine 2; ...; 0 / 0 / 8 is the uplink interface 8 on Leaf 1 connected to Spine 8, and 10.1.1.8 is the IP address of Spine 8.
[0078] Similarly, using other network card addresses of GPU server 1 (eg, 1.1.1.2 to 1.1.1.8) as source addresses, 8 corresponding ACLs can also be constructed respectively, which will not be described in detail in the embodiment of the present application.
[0079] Thus, compared with the related art in which an ACL is configured for each source address and each destination address, in the embodiment of the present application, on Leaf 1, for GPU server 1, only 64 ACLs need to be constructed to achieve traffic forwarding to other GPU server network cards. In the related art, each source IP corresponds to 56 destination IPs, and 56 ACLs need to be constructed for each source IP. It can be seen that the traffic forwarding method provided in the embodiment of the present application greatly reduces the ACL hardware resource occupation of the Leaf device and improves the ACL hardware resource utilization rate of the Leaf device.
[0080] Step 120: Send the M ACLs to the Leaf device.
[0081] In an embodiment of the present application, the controller sends the ACL policy to the corresponding Leaf device so that after receiving the traffic message sent by the locally accessed server network card, the Leaf device searches for the source address as the source address of the traffic message based on the source address and destination address of the traffic message, and the destination address micro-segment group includes the target ACL of the destination address of the traffic message, and forwards the traffic message based on the target ACL.
[0082] In an embodiment of the present application, after the controller configures the ACL corresponding to each network card of the GPU server to which a Leaf device is connected, the controller sends the ACL to the Leaf device, so that after receiving a traffic message sent by a network card, the Leaf device parses the traffic message to obtain the source IP address and destination IP address of the traffic message, and then matches the source IP address and destination IP address of the traffic message with the ACL, determines that the source IP address is the source IP address of the traffic message, the destination EPG includes the ACL of the destination IP address of the traffic message, and forwards the traffic message based on the egress port included in the ACL.
[0083] Furthermore, in the embodiment of the present application, the above traffic forwarding method may also include the following steps:
[0084] Obtain the size of the traffic carried by each ACL; when it is determined that the traffic carried by the first ACL reaches a first preset value and there is a traffic carried by the second ACL that does not reach a second preset value, dynamically adjust part of the traffic carried by the first ACL to the second ACL.
[0085] That is to say, the controller monitors the traffic size information carried by each ACL. If it is determined that the traffic carried by an ACL reaches a first preset value, it means that the available bandwidth of the uplink (egress port) corresponding to the ACL is not sufficient. At this time, it can be determined whether there is an ACL in other ACLs that carries a traffic less than a second preset value. If so, part of the traffic carried by the ACL that has reached the first preset value can be adjusted to be carried on the ACL that carries a traffic less than the second preset value.
[0086] For example, the maximum bandwidth of the outbound ports included in each ACL is 10G, the first preset value is 8G, and the second preset value is 6G. If it is detected that the traffic size carried by ACL1 is 9G, and the traffic size carried by ACL2 is 5G, then part of the traffic carried by ACL1 (such as 2G) can be adjusted to ACL2.
[0087] In the embodiment of the present application, when part of the traffic carried by the first ACL is dynamically adjusted to be carried by the second ACL, a preferred implementation method is:
[0088] At least one destination address included in the first destination address micro-segment group corresponding to the first ACL is dynamically adjusted to the second destination address micro-segment corresponding to the second ACL.
[0089] Specifically, the controller sends an adjustment instruction to the Leaf device, so that the Leaf device adjusts one or more destination addresses in the destination EPG included in ACL1 to the destination EPG included in ACL2.
[0090] For example, see Figure 3 As shown, it is a detailed flow chart of a traffic forwarding method provided by an embodiment of the present application, which is applied to a target Leaf device in a Spine-Leaf architecture network, wherein the controller of the network uses the network card addresses of servers accessed by other Leaf devices except the target Leaf device as the destination address, creates M destination address micro-segment groups, uses the network card addresses of servers accessed by the target Leaf device as the source address, and for each source address, constructs M access control lists ACLs corresponding to the source address according to the source address and the M destination address micro-segment groups, and sends them to the target Leaf device, wherein M is the number of uplinks between the Leaf device and each Spine device, and each ACL includes a source address item, a destination address micro-segment group, an outbound interface, and next hop information; the method comprises the following steps:
[0091] Step 300: Receive a traffic message sent by a locally connected server network card.
[0092] Step 310: Based on the source address and the destination address of the flow message, find a target ACL whose source address is the source address of the flow message, and the destination address micro-segment group includes the destination address of the flow message.
[0093] Step 320: Forward the traffic message based on the target ACL.
[0094] Based on the same inventive concept as the above method embodiment applied to the controller, for example, refer to Figure 4 As shown, it is a structural schematic diagram of a traffic forwarding device provided in an embodiment of the present application, and the device is applied to a controller in a Spine-Leaf architecture network, and the device includes:
[0095] A creating unit 40 is used to create, for each Leaf device, M destination address micro-segment groups by taking the network card addresses of the first server connected to other Leaf devices except the Leaf device as destination addresses;
[0096] A construction unit 41 is used to use the network card addresses of the second server connected to the Leaf device as source addresses, and for each source address, construct M access control lists ACL corresponding to the source address according to the source address and the M destination address micro-segment groups, wherein M is the number of uplinks between the Leaf device and each Spine device, and each ACL includes a source address item, a destination address micro-segment group, an outbound interface, and next hop information;
[0097] The sending unit 42 is used to send the M ACLs to the Leaf device, so that after receiving the traffic message sent by the locally accessed server network card, the Leaf device searches for the source address as the source address of the traffic message based on the source address and destination address of the traffic message, and the destination address micro-segment group includes the target ACL of the destination address of the traffic message, and forwards the traffic message based on the target ACL.
[0098] Optionally, the device further comprises:
[0099] An acquisition unit, used for acquiring the size of the traffic carried by each ACL;
[0100] The adjustment unit is used to dynamically adjust part of the traffic carried by the first ACL to be carried by the second ACL when it is determined that the traffic carried by the first ACL reaches a first preset value and there is traffic carried by the second ACL that does not reach a second preset value.
[0101] Optionally, a destination address micro-segment group includes multiple destination addresses; when part of the traffic carried by the first ACL is dynamically adjusted to be carried by the second ACL, the adjusting unit is specifically used to:
[0102] At least one destination address included in the first destination address micro-segment group corresponding to the first ACL is dynamically adjusted to the second destination address micro-segment corresponding to the second ACL.
[0103] Based on the same inventive concept as the above method embodiment applied to the Leaf device, for example, refer to Figure 5 As shown, it is a structural schematic diagram of a traffic forwarding device provided by an embodiment of the present application, and the device is applied to a target Leaf device in a Spine spine-Leaf leaf architecture network, wherein the controller of the network uses the network card addresses of the servers accessed by other Leaf devices except the target Leaf device as the destination address, creates M destination address micro-segment groups, and uses the network card addresses of the servers accessed by the target Leaf device as the source address. For each source address, according to the source address and the M destination address micro-segment groups, M access control lists ACLs corresponding to the source address are constructed and sent to the target Leaf device, wherein M is the number of uplinks between the Leaf device and each Spine device, and each ACL includes a source address item, a destination address micro-segment group, an outbound interface and next hop information; the device includes:
[0104] The receiving unit 50 is used to receive the flow message sent by the local access server network card;
[0105] A search unit 51 is used to search, based on the source address and the destination address of the flow message, for a source address that is the source address of the flow message, and a destination address micro-segment group that includes a target ACL of the destination address of the flow message;
[0106] The forwarding unit 52 is configured to forward the traffic message based on the target ACL.
[0107] The above units may be one or more integrated circuits configured to implement the above methods, such as one or more application specific integrated circuits (ASIC), or one or more digital signal processors (DSP), or one or more field programmable gate arrays (FPGA). For another example, when a certain unit is implemented in the form of a processing element scheduling program code, the processing element may be a general-purpose processor, such as a central processing unit (CPU) or other processor that can call program code. For another example, these units may be integrated together and implemented in the form of a system-on-a-chip (SOC).
[0108] Furthermore, the traffic forwarding device provided in the embodiment of the present application, from the hardware level, the hardware architecture diagram of the traffic forwarding device can be seen in Figure 6 As shown, the traffic forwarding device may include: a memory 60 and a processor 61,
[0109] The memory 60 is used to store program instructions; the processor 61 calls the program instructions stored in the memory 60 and executes the above method embodiment applied to the controller according to the obtained program instructions. The specific implementation method and technical effect are similar and will not be repeated here.
[0110] Optionally, the present application also provides a controller, comprising at least one processing element (or chip) for executing the above method embodiment applied to the controller.
[0111] Optionally, the present application also provides a program product, such as a computer-readable storage medium, which stores computer-executable instructions, and the computer-executable instructions are used to enable the computer to execute the above-mentioned method embodiment applied to the controller.
[0112] Furthermore, the traffic forwarding device provided in the embodiment of the present application, from the hardware level, the hardware architecture diagram of the traffic forwarding device can be seen in Figure 7 As shown, the traffic forwarding device may include: a memory 70 and a processor 71,
[0113] The memory 70 is used to store program instructions; the processor 71 calls the program instructions stored in the memory 70 and executes the above method embodiment applied to the Leaf device according to the obtained program instructions. The specific implementation method and technical effect are similar and will not be repeated here.
[0114] Optionally, the present application also provides a Leaf device, comprising at least one processing element (or chip) for executing the above method embodiment applied to the Leaf device.
[0115] Optionally, the present application also provides a program product, such as a computer-readable storage medium, which stores computer-executable instructions, and the computer-executable instructions are used to enable the computer to execute the above-mentioned method embodiment applied to the Leaf device.
[0116] Here, the machine-readable storage medium may be any electronic, magnetic, optical or other physical storage device that may contain or store information, such as executable instructions, data, etc. For example, the machine-readable storage medium may be: RAM (RadomAccess Memory), volatile memory, non-volatile memory, flash memory, storage drive (such as hard disk drive), solid state drive, any type of storage disk (such as CD, DVD, etc.), or similar storage medium, or a combination thereof.
[0117] The systems, devices, modules or units described in the above embodiments may be implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer, which may be in the form of a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email transceiver, a game console, a tablet computer, a wearable device or a combination of any of these devices.
[0118] For the convenience of description, the above device is described in various units according to their functions. Of course, when implementing the present application, the functions of each unit can be implemented in the same or multiple software and / or hardware.
[0119] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the embodiments of the present application may adopt the form of a computer program product implemented in one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.
[0120] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0121] Moreover, these computer program instructions can also be stored in a computer-readable memory that can guide a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory produce a product including an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.
[0122] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for executing on the computer or other programmable device to implement the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.
[0123] The above description is only a preferred embodiment of the present application and is not intended to limit the present application. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present application shall be included in the scope of protection of the present application.
Claims
1. A traffic forwarding method, characterized in that: Applied to a controller in a Spine-Leaf architecture network, the method includes: For each Leaf device, M destination address micro-segment groups are created with the network card addresses of the first server connected to other Leaf devices except the Leaf device as the destination address; Taking the network card addresses of the second server connected to the Leaf device as the source address, for each source address, according to the source address and the M destination address micro-segment groups, construct M access control lists ACL corresponding to the source address, wherein M is the number of uplinks between the Leaf device and each Spine device, and each ACL includes a source address item, a destination address micro-segment group, an outbound interface, and next hop information; The M ACLs are sent down to the Leaf device so that after receiving the traffic message sent by the locally accessed server network card, the Leaf device searches for the source address as the source address of the traffic message based on the source address and destination address of the traffic message, and the destination address micro-segment group includes the target ACL of the destination address of the traffic message, and forwards the traffic message based on the target ACL.
2. The method according to claim 1, characterized in that The method further comprises: Get the size of the traffic carried by each ACL; When it is determined that the traffic carried by the first ACL reaches a first preset value and there is traffic carried by the second ACL that does not reach a second preset value, part of the traffic carried by the first ACL is dynamically adjusted to be carried by the second ACL, wherein the first preset value is greater than or equal to the second preset value.
3. The method according to claim 2, characterized in that A destination address micro-segment group includes multiple destination addresses; The step of dynamically adjusting part of the traffic carried by the first ACL to be carried by the second ACL includes: At least one destination address included in the first destination address micro-segment group corresponding to the first ACL is dynamically adjusted to the second destination address micro-segment corresponding to the second ACL.
4. A traffic forwarding method, characterized in that: The invention is applied to the target Leaf device in the Spine-Leaf architecture network, wherein the controller of the network takes the network card addresses of the servers connected by other Leaf devices except the target Leaf device as the destination address, creates M destination address micro-segment groups, takes the network card addresses of the servers connected by the target Leaf device as the source address, and for each source address, according to the source address and the M destination address micro-segment groups, constructs M access control lists ACL corresponding to the source address, and sends them to the target Leaf device, wherein M is the number of uplinks between the Leaf device and each Spine device, and each ACL includes a source address item, a destination address micro-segment group, an outbound interface and next hop information; the method includes: Receive traffic packets sent by the local access server network card; Based on the source address and the destination address of the flow message, searching for a source address that is the source address of the flow message, and a destination address micro-segment group that includes a target ACL of the destination address of the flow message; The traffic message is forwarded based on the target ACL.
5. A traffic forwarding device, characterized in that: Applicable to the controller in the Spine-Leaf architecture network, the device includes: A creating unit, configured to create, for each Leaf device, M destination address micro-segment groups by taking the network card addresses of the first server connected to other Leaf devices except the Leaf device as destination addresses; A construction unit is used to use the network card addresses of the second server connected to the Leaf device as source addresses, and for each source address, according to the source address and the M destination address micro-segment groups, to construct M access control lists ACL corresponding to the source address, wherein M is the number of uplinks between the Leaf device and each Spine device, and each ACL includes a source address item, a destination address micro-segment group, an outbound interface, and next hop information; The sending unit is used to send the M ACLs to the Leaf device, so that after receiving the traffic message sent by the locally accessed server network card, the Leaf device searches for the source address as the source address of the traffic message based on the source address and destination address of the traffic message, and the destination address micro-segment group includes the target ACL of the destination address of the traffic message, and forwards the traffic message based on the target ACL.
6. The device according to claim 5, characterized in that The device also includes: An acquisition unit, used for acquiring the size of the traffic carried by each ACL; The adjustment unit is used to dynamically adjust part of the traffic carried by the first ACL to be carried by the second ACL when it is determined that the traffic carried by the first ACL reaches a first preset value and there is traffic carried by the second ACL that does not reach a second preset value.
7. The device according to claim 6, characterized in that A destination address micro-segment group includes multiple destination addresses; when part of the traffic carried by the first ACL is dynamically adjusted to be carried by the second ACL, the adjustment unit is specifically used to: At least one destination address included in the first destination address micro-segment group corresponding to the first ACL is dynamically adjusted to the second destination address micro-segment corresponding to the second ACL.
8. A traffic forwarding device, characterized in that: The invention is applied to the target Leaf device in the Spine-Leaf architecture network, wherein the controller of the network takes the network card addresses of the servers connected by other Leaf devices except the target Leaf device as the destination address, creates M destination address micro-segment groups, takes the network card addresses of the servers connected by the target Leaf device as the source address, and for each source address, according to the source address and the M destination address micro-segment groups, constructs M access control lists ACL corresponding to the source address, and sends them to the target Leaf device, wherein M is the number of uplinks between the Leaf device and each Spine device, and each ACL includes a source address item, a destination address micro-segment group, an outbound interface and next hop information; the device includes: A receiving unit, used to receive traffic messages sent by a locally connected server network card; A search unit, configured to search, based on the source address and the destination address of the flow message, for a source address that is the source address of the flow message, wherein the destination address micro-segment group includes a target ACL of the destination address of the flow message; A forwarding unit is used to forward the traffic message based on the target ACL.
9. A traffic forwarding device, characterized in that: The traffic forwarding device comprises: A memory for storing program instructions; A processor is used to call the program instructions stored in the memory, and execute the steps of the method as described in any one of claims 1-3, or 4 according to the obtained program instructions.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer-executable instructions, and the computer-executable instructions are used to enable the computer to execute the steps of the method according to any one of claims 1 to 3 or 4.
Citation Information
Patent Citations
Method for processing uplink message, device and system thereof
CN101527681A
Traffic control method and device
CN111541616A
Data processing method, network card and server
CN114090495A
Security authentication method and device
CN115277100A
Network access control method and device
CN116155532A