Message processing method and device and service function repeater
By introducing a message mirroring processing method into the service function forwarder, the problem of incomplete coverage of service function in the SRv6 service function chain in deep traffic detection and traffic statistics is solved, and the in-depth analysis and application of messages is realized.
Patent Information
- Application Number
- CN202510195004.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-21
- Publication Date
- 2025-05-30
AI Technical Summary
The SRv6-based service function chain has the problem of incomplete coverage of service functions in applications such as deep traffic detection and traffic statistics for deep packet analysis.
By introducing a message mirroring processing method into the service function forwarder, mirroring processing is performed after receiving the message, adjusting the mirror message parameters to make it suitable for deep analysis, and sending it to the service function node for deep analysis.
It realizes in-depth analysis of packets, supports applications such as deep traffic detection and traffic statistics, and improves the service function coverage of the service function chain.
Smart Images

Figure CN120075328A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of data processing, and particularly relates to a message processing method, apparatus, and service function forwarder. Background Art
[0002] In service function orchestration based on IPv6 Segment Routing (SRv6), a corresponding segment identifier (SID) is assigned to each service function node and connected together in a specific order to form a forwarding path of a service chain. Currently, a Service Function Forwarder (SFF) only supports serial forwarding with service function nodes, that is, forwarding traffic to service function nodes for cleaning and protection, and after receiving the cleaned traffic sent by the service function nodes, completing subsequent forwarding. This method is not applicable to in-depth parsing of messages such as deep traffic detection and traffic statistics, resulting in incomplete coverage of service functions in the service function chain based on SRv6. Summary of the Invention
[0003] This application provides a message processing method and apparatus for mirroring messages, thereby realizing in-depth parsing of messages.
[0004] In a first aspect, an embodiment of this application provides a message processing method, which is applied to any service function forwarding module in a service function forwarder, and includes:
[0005] Receiving a first message from a first device, and obtaining a first identifier from the first message; the first identifier is used to indicate the identifier of any service function forwarding module;
[0006] Querying, from a routing forwarding table, a message operation type corresponding to the first identifier; the routing forwarding table stores the identifiers of all service function forwarding modules in the service function forwarder and the corresponding operation types;
[0007] Determining whether to mirror the first message based on the message operation type, and if so, mirroring the first message to obtain a mirrored message;
[0008] Querying, based on the first identifier, a mirror parameter and a service function node corresponding to the first identifier from a preset mirror parameter configuration table;
[0009] Adjusting the parameters of the mirrored message based on the mirror parameters so that the mirrored message is suitable for in-depth parsing, to obtain a second message; and sending the second message to the service function node; the service function node is used to perform in-depth parsing on the second message.
[0010] In this method, the correspondence between the identifiers of each service function forwarding module and the message operation type is set. The corresponding message operation type is queried from the routing forwarding table according to the first identifier of the first message. Querying based on the routing forwarding table can improve the query speed. And it is determined whether to perform mirror processing on the first message according to the message operation type. If so, the mirror parameters and service function nodes corresponding to the first identifier are queried, and the parameters of the mirror message are adjusted based on the mirror parameters, so that the mirror message is suitable for in-depth parsing to obtain a second message, and the second message is sent to the service function node for in-depth parsing, thereby realizing the in-depth parsing of the first message, facilitating subsequent applications such as in-depth traffic detection and traffic statistics of the first message, and improving the service functions of the service function chain.
[0011] Optionally, determining whether it is necessary to perform mirror processing on the first message based on the message operation type includes: if not, forwarding the first message according to the forwarding rule indicated by the message operation type.
[0012] Optionally, the method further includes: obtaining the Segment Left field and the Segment List field included in the first message; wherein, the Segment List field includes at least one identifier, and the at least one identifier is used to indicate at least one node passed through in the transmission path of the first message, and the Segment Left field is used to indicate the position of the identifier corresponding to any service function forwarding module in the Segment list field; the Segment Left field and the Segment List field are jointly used to determine the first identifier; subtracting one from the value of the Segment Left field in the first message, and obtaining the second identifier of the field value obtained after subtraction in the Segment List field; the second identifier is the identifier corresponding to the next node of the node corresponding to the first identifier in the Segment List field, and the second identifier is used to indicate the next node to which the first message is to be forwarded; updating the first identifier based on the second identifier; forwarding the first message to the node indicated by the updated first identifier.
[0013] Optionally, the preset mirror parameter configuration table includes the mirror parameters and output interfaces corresponding to the first identifier. The mirror parameters include at least one of: whether to perform mirroring and intercepting of the payload of the mirror packet, whether to perform physical address encapsulation on the mirror packet, and whether to perform virtual local area network encapsulation on the mirror packet; the output interface is used to send the second packet to the corresponding service function node; adjusting the parameters of the mirror packet based on the mirror parameters includes: adjusting the parameters of the mirror packet based on at least one of the mirror parameters included; sending the second packet to the service function node includes: sending the second packet to the service function node through the output interface corresponding to the first identifier, so that the service function node performs in-depth parsing on the second packet.
[0014] In a second aspect, an embodiment of the present application provides a packet processing device, which is applied to any service function forwarding module in a service function forwarder, and includes:
[0015] A routing and forwarding module, configured to: receive a first packet from a first device, and obtain a first identifier from the first packet; the first identifier is used to indicate the identifier of any service function forwarding module; query the packet operation type corresponding to the first identifier from the routing forwarding table; the routing forwarding table stores the identifiers of all service function forwarding modules in the service function forwarder and the corresponding operation types; determine whether mirroring processing needs to be performed on the first packet based on the packet operation type;
[0016] A packet forwarding module, configured to: if mirroring processing needs to be performed on the first packet, perform mirroring processing on the first packet to obtain a mirror packet;
[0017] A packet mirroring module, configured to: query the mirror parameters and service function node corresponding to the first identifier from the preset mirror parameter configuration table based on the first identifier; adjust the parameters of the mirror packet based on the mirror parameters so that the mirror packet is suitable for in-depth parsing to obtain a second packet; send the second packet to the service function node; the service function node is used to perform in-depth parsing on the second packet.
[0018] Optionally, the packet forwarding module is further configured to: if mirroring processing does not need to be performed on the first packet, forward the first packet based on the forwarding rule indicated by the packet operation type.
[0019] Optionally, the packet forwarding module is further configured to: obtain the Segment Left field and the Segment List field included in the first packet; wherein, the Segment List field includes at least one identifier, and the at least one identifier is used to indicate at least one node passed through in the transmission path of the first packet, and the Segment Left field is used to indicate the position of the identifier corresponding to any service function forwarding module in the Segment list field; the Segment Left field and the SegmentList field are jointly used to determine the first identifier; subtract one from the value of the Segment Left field in the first packet, and obtain the second identifier in the Segment List field for the field value after subtraction; the second identifier is the identifier corresponding to the next node of the node corresponding to the first identifier in the Segment List field, and the second identifier is used to indicate the next node to which the first packet is to be forwarded; update the first identifier based on the second identifier; and forward the first packet to the node indicated by the updated first identifier.
[0020] Optionally, the preset mirror parameter configuration table includes the mirror parameters and output interfaces corresponding to the first identifier, and the mirror parameters include at least one of: whether to perform mirror truncation on the payload of the mirror packet, whether to perform physical address encapsulation on the mirror packet, and whether to perform virtual local area network encapsulation on the mirror packet; the output interface is used to send the second packet to the corresponding service function node; when the packet mirroring module adjusts the parameters of the mirror packet based on the mirror parameters, it is specifically configured to: adjust the parameters of the mirror packet based on at least one of the included mirror parameters; when the packet mirroring module sends the second packet to the service function node, it is specifically configured to: send the second packet to the service function node through the output interface corresponding to the first identifier, so that the service function node deeply analyzes the second packet.
[0021] In a third aspect, an embodiment of the present application provides a service function forwarder, which includes at least one service function forwarding module, and each service function forwarding module in the at least one service function forwarding module is configured to execute the method in the first aspect or any optional implementation manner of the first aspect.
[0022] In a fourth aspect, an embodiment of the present application provides an electronic device, which includes at least one processor, and when the at least one processor executes a computer program stored in a memory, the method in the first aspect or any optional implementation manner of the first aspect is implemented.
[0023] In a fifth aspect, an embodiment of the present application provides a computer-readable storage medium, which is used to store instructions, and when the instructions are executed, the method in the first aspect or any optional implementation manner of the first aspect is implemented.
[0024] In a sixth aspect, an embodiment of the present application provides a computer program product, including computer program code, which when running on a computer, enables the method in the first aspect or any optional implementation manner of the first aspect to be implemented.
[0025] In the embodiments of the present application, the technical effects or advantages of one or more technical solutions provided in the second, third, fourth, fifth, and sixth aspects can be correspondingly explained by the technical effects or advantages of the corresponding one or more technical solutions provided in the first aspect. Description of the Drawings
[0026] Figure 1 It is a flowchart of a message forwarding method provided by an embodiment of the present application;
[0027] Figure 2 It is a flowchart of a message mirroring method provided by an embodiment of the present application;
[0028] Figure 3 It is a flowchart of a message processing method provided by an embodiment of the present application;
[0029] Figure 4 It is an example diagram of a method for configuring a service function forwarder provided by an embodiment of the present application;
[0030] Figure 5 It is an example diagram of a method for message mirroring and forwarding processing provided by an embodiment of the present application;
[0031] Figure 6 It is an example diagram of a message processing method of a service function forwarder provided by an embodiment of the present application;
[0032] Figure 7 It is a structural diagram of a message processing device provided by an embodiment of the present application;
[0033] Figure 8 It is a structural diagram of an electronic device provided by an embodiment of the present application. Detailed Embodiments
[0034] In the technical solution of the present application, the collection, dissemination, use, etc. of data all comply with the requirements of relevant national laws and regulations.
[0035] It should be noted that in the embodiments of the present application, some existing solutions in the industry such as certain software, components, models, etc. may be mentioned. They should be regarded as exemplary, and their purpose is only to illustrate the feasibility in the implementation of the technical solution of the present application, but it does not mean that the applicant has already or necessarily used this solution.
[0036] The technical solution of the present application will be described in detail below with reference to the accompanying drawings and specific embodiments. It should be understood that the embodiments of the present application and the specific features in the embodiments are detailed descriptions of the technical solution of the present application, rather than limitations on the technical solution of the present application. Without conflict, the technical features in the embodiments of the present application and the embodiments can be combined with each other.
[0037] It should be understood that in the description of the embodiments of the present application, "a plurality of" means two or more. The "first", "second", etc. in the embodiments of the present application are used to distinguish different objects, rather than to describe a specific order. The term "and / or" in the embodiments of the present application is only a description of the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the term "including" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device that includes a series of steps or units is not limited to the listed steps or units, but optionally further includes steps or units not listed, or optionally further includes other steps or units inherent to these processes, methods, products or devices. A module in the embodiments of the present application refers to a part with independent functions in a software system.
[0038] For the convenience of understanding, the following is an introduction to some professional terms involved in the embodiments of the present application:
[0039] 1. Service Function Chain (SFC) is a network service architecture used to define and manage service function links in a network to achieve a specific data packet processing process. Specifically, multiple network service functions are combined in a specific order to form a service link to meet specific network service requirements. In SFC, data packets are processed through a series of service function nodes in the order of a predefined service function link, thereby realizing the flexible deployment and traffic control of network services. Service function chains are usually used for the processing and forwarding of network traffic, guiding the traffic through a series of network service functions, such as firewalls, load balancers, deep packet inspection, etc., to provide specific network services. There are various implementation technologies for the forwarding plane of service function chains, including Network Service Header (NSH), Openflow, and SRv6, etc.
[0040] 2. Packet mirroring (or traffic mirroring) means that during network transmission, a copy of the original packet is forwarded to another place for subsequent analysis and auditing to detect potential security threats or problems. Security administrators can use packet mirroring to monitor network traffic in real time, perform data packet analysis, and take corresponding measures to protect network security when necessary.
[0041] 3. SRv6 (Segment Routing IPv6) is a network addressing and routing technology based on IPv6 that introduces a new packet format and allows the use of "Segments" in the IPv6 packet header to define paths. SRv6 utilizes the Extension Header of IPv6 packets to implement source routing and traffic engineering, providing flexible network programming and traffic control mechanisms.
[0042] 4. SRH (Segment Routing Header) is a key component in the SRv6 protocol and an extension header of IPv6 packets, used to implement source routing and flexible path control. SRH contains a series of Segment Identifiers (SIDs) that define the path of the packet in the network.
[0043] 5. A Service Function Forwarder (SFF) is a network device or a functional module and is also one of the basic components of SFC. It is used to forward packets to service functions for subsequent processing in a service function chain.
[0044] 6. A Service Function (SF) is one of the basic components of SFC and is used to refer to service nodes that provide specific functions in the network. These service nodes can be hardware devices, virtual machines, containers, etc., and are used to perform specific tasks or operations in the network. Each SF provides specific network service functions, such as firewalls, traffic analysis and detection, load balancing, encryption and decryption, etc.
[0045] 7. SRv6 Policy refers to a series of rules defined and implemented in the network to control the path selection, forwarding logic, and processing method of packets from the source node to the target node. SRv6 Policy is an application of SRv6 technology that achieves fine-grained control of the packet path by embedding SIDs in the extension header field of the IPv6 packet header.
[0046] 8. A Service Classifier (SC) is a component in SFC used to identify, classify, and forward traffic. Its main responsibility is to allocate traffic to appropriate service functions according to predefined rules (such as traffic characteristics, user attributes, service types, etc.).
[0047] In the service function orchestration based on SRv6, a corresponding segment identifier (SID) is assigned to each service function node. These SIDs are connected together in a specific order to form a forwarding path of the service chain. When network traffic passes through the service chain, it sequentially matches each SID and is forwarded to the service function node corresponding to the SID for specific processing and analysis, and then the processed traffic is passed to the next SRv6 node until the service functions of the entire service link are completed. Based on the powerful programmable ability of the SRv6 protocol, flexible service link customization and dynamic scheduling can be achieved, improving the flexibility and programmability of the network and meeting the requirements in different business scenarios.
[0048] However, in the implementation solution of the service function chain orchestration based on SRv6, the SFF device (i.e., the service function forwarder) only supports the serial forwarding implementation with the service function node. That is, the SFF device forwards the traffic to the service function node for cleaning and protection, then receives the cleaned traffic sent by the service function node, and then completes the subsequent forwarding. This implementation method is applicable to gateway security service function nodes such as firewalls, intrusion prevention systems, and web application firewalls, but is not applicable to security service functions such as deep traffic detection, traffic statistics, or auditing, which results in the defect that the service functions covered by the SRv6 service function chain are incomplete.
[0049] The following is an example of a service function chain business scenario provided by the embodiments of the present application.
[0050] In the service function chain of the embodiments of the present application, according to the processing method of the service function node for traffic, the service functions can be divided into mirror (Mirror) type service functions or detection (Detection) type service functions, and forward (Forward) type service functions or gateway (Gateway) type service functions.
[0051] The forward type service function refers to that the service function node receives the traffic, and after processing, sends the traffic to the next device or service function node without replication or mirroring. The forward type service function is usually used for processing such as traffic acceleration, filtering, and security inspection to ensure that the traffic is smoothly transmitted according to the specified service function chain. That is, there is a problem that the existing service function chain cannot deeply parse the packets.
[0052] The mirroring service function means that the service function node copies (mirrors) the traffic and sends it to another device or service function node for analysis or storage, while the original traffic continues to be transmitted to the target device. The mirroring service function is usually used in scenarios such as network monitoring, security auditing, and traffic analysis to perform additional processing on the traffic without affecting the original traffic. That is, the solution provided by the embodiments of the present application for realizing in-depth parsing of packets.
[0053] Specifically, refer to Figure 1 , which is an example diagram of the forwarding scenario of the forwarding service function provided by the embodiments of the present application.
[0054] As Figure 1 shown, the service packet needs to be sent from device 1 to device 2. Packet 1 is sent from device 1. When passing through the service function forwarder, the service function forwarder modifies the parameters of Packet 1 according to the SID of the corresponding service function 1 to obtain Packet 2, and sends Packet 2 to service function node 1. Service function node 1 performs basic processing on Packet 2 and generates Packet 3 to send to the service function forwarder. The service function forwarder generates Packet 4 according to the previous cache record (such as the packet header and packet characteristics of the packet), looks up the route according to the destination IP of Packet 4 (i.e., the IP of device 2) and forwards it to device 2.
[0055] Refer to Figure 2 , which is an example diagram of the forwarding scenario of the mirroring service function provided by the embodiments of the present application.
[0056] As Figure 2 shown, the service packet needs to be sent from device 1 to device 2. Packet 1 is sent from device 1. When passing through the service function forwarder, the service function forwarder copies Packet 1 to obtain a mirrored packet, that is, Packet 2, and sends Packet 2 to service function 1. At the same time, the service function forwarder executes the SRv6 transit node function to generate Packet 3 and forward it to device 2; Service function 1 can perform subsequent forwarding without returning the service packet to the service function forwarder.
[0057] It can be understood that in actual deployment, physically only one service function forwarder can be deployed, but there is a service function forwarding module between every two nodes to implement the above-mentioned forwarding service function or mirroring service function, that is, there is at least one service forwarding function module in one service function forwarder.
[0058] Refer to Figure 3 , the embodiments of the present application mainly implement a packet processing method based on the above-mentioned forwarding scenario of the mirroring service function, which is applied to any service function forwarding module in the service function forwarder. The method includes steps S301 to S306:
[0059] S301. Receive a first message from a first device, and obtain a first identifier from the first message.
[0060] Among them, the first identifier is used to indicate the identifier of any service function forwarding module.
[0061] Exemplarily, the first identifier may be the SID in the above example, and the identifier of any service function forwarding module may be the IP address of any service function forwarding module. It can be understood that the first identifier and the identifier of any service function forwarding module may also be represented by other identifiers according to actual needs, and the embodiments of the present application do not limit this.
[0062] S302. Query the message operation type corresponding to the first identifier from the routing forwarding table.
[0063] Among them, the routing forwarding table stores the identifiers of all service function forwarding modules in the service function forwarder and the corresponding operation types. The identifiers of each service function forwarding module are different.
[0064] Exemplarily, the identifiers of all service function forwarding modules and the corresponding message operation types are stored in the local database of the service function forwarder, and are loaded into the routing forwarding table during operation to facilitate accelerating the query speed.
[0065] In the local database, multiple configuration tables are stored. Each configuration table stores the identifier of a service function forwarding module and the corresponding message operation type; or in the local database, one configuration table is stored, and this one configuration table stores the identifiers of all service function forwarding modules and the corresponding message operation types.
[0066] Exemplarily, the first identifier is the same as the identifier of the service function forwarding module. For example, the first identifier is the outer IPv6 destination address of the SRv6 data packet (i.e., the first message), that is, the address of the service function forwarding module. In practical applications, when encapsulating the first message, if there is a need to perform a mirror operation on the first message, the identifier (such as the IP address) of the corresponding service function forwarding module with the mirror operation function can be encapsulated into the Segment List of the first message, so that the first message is guided by this identifier and reaches the corresponding service function forwarding module.
[0067] S303. Determine whether the first message needs to be mirror-processed based on the message operation type. If so, perform mirror processing on the first message to obtain a mirror message.
[0068] Exemplarily, the message operation type may include a mirror operation and a forwarding operation. The mirror operation is used to indicate that the first message needs to be mirror-processed, and the forwarding operation is used to indicate that the first message is forwarded according to a preset forwarding rule.
[0069] If the message operation type corresponding to the first identifier is a mirror operation, mirror the first message to obtain a mirrored message;
[0070] If the message operation type corresponding to the first identifier is a forwarding operation (i.e., not a mirror operation), forward the first message according to the forwarding rule indicated by the message operation type.
[0071] It can be understood that the above message operation types are only a possible example according to the application scenarios mentioned in the above text. In actual applications, other message operation types can also be set according to requirements, such as format conversion, parameter adjustment, data detection, etc.
[0072] S304. Query the mirror parameters and service function nodes corresponding to the first identifier from a preset mirror parameter configuration table based on the first identifier.
[0073] Exemplarily, the preset mirror parameter configuration table can be an independent data table stored in a local database, or the same as the configuration table mentioned in S302 above for storing the identifiers of service function forwarding modules and the corresponding message operation types. That is, this configuration table stores both the identifiers of service function forwarding modules and the corresponding message operation types, and also stores the corresponding mirror parameters when the message operation type is a mirror operation.
[0074] In a possible example, the preset mirror parameter configuration table includes the mirror parameters and output interfaces corresponding to the first identifier. The mirror parameters include at least one of: whether to perform mirror truncation on the payload of the mirrored message, whether to perform physical address encapsulation on the mirrored message, and whether to perform virtual local area network encapsulation on the mirrored message; the output interface is used to send the second message to the corresponding service function node.
[0075] Specifically, an example of a configuration table provided in an embodiment of the present application is shown in Table 1 below.
[0076] Table 1 Configuration Table Example
[0077]
[0078] As shown in Table 1, localsid is the identifier of each service function forwarding module, which can be represented by SID, that is, an IPv6 address. It can be understood that this configuration table can be used only to store the SIDs that need to perform mirror operations. behavior is the message operation type, where End.MI is used to represent the mirror operation (i.e., traffic mirroring). oif is the interface name, which is used to specify the interface for outputting the mirrored message corresponding to this SID, that is, to determine which service function node to send the mirrored message corresponding to this SID to for subsequent processing.
[0079] The above three fields are mandatory fields, and the following fields are mirror parameters that can be selected according to the specific SID. Specifically, as shown in Table 1, the encap field is used to indicate whether the mirrored packet carries an outer SRv6 header. By default, it does not, that is, the default value of this field is no, which means that the outer SRv6 header of the mirrored packet needs to be removed; if the value of this field is yes, the outer SRv6 header of the mirrored packet is retained. The len field is the length of the mirrored packet and is used to indicate whether to intercept the length of the payload of the mirrored packet. If the value of the encap field is yes, the content intercepted by the len field also needs to include the outer SRv6 header; otherwise, the interception length of the inner packet length after removing the outer packet header is directly calculated. The mac field is the Media Access Control (MAC) address of the mirrored packet, that is, the physical address, and is used to indicate that the destination MAC in the mirrored packet is modified to the specified MAC. The vlan field is the Virtual Local Area Network (VLAN) name of the mirrored packet and is used to specify the VLAN of the mirrored packet. If the mirrored packet carries a VLAN header, the VLAN header is modified to the specified VlanID; otherwise, the specified VLAN header is encapsulated for the packet. Extensions are other extension fields, that is, other mirror parameters can be set according to the requirements in actual applications, such as desensitization, encryption, etc.
[0080] It can be understood that Table 1 is only an example of the configuration representation of an operation type of mirror operation given in the embodiments of this application. The operation type can also be other operation types, such as forwarding operation, and the configuration table also needs to include parameters such as forwarding rules, and actually includes but is not limited to this.
[0081] S305. Adjust the parameters of the mirrored packet based on the mirror parameters so that the mirrored packet is suitable for in-depth parsing to obtain a second packet.
[0082] Exemplarily, taking the mirror parameters shown in Table 1 above as an example, adjust the parameters of the mirrored packet based on at least one of the included mirror parameters. That is, adjust the parameters of the mirrored packet based on at least one of encap, len, mac, vlan, and extensions shown in Table 1 to obtain a second packet suitable for the in-depth parsing operation of the corresponding service function node.
[0083] S306. Send the second packet to the service function node.
[0084] Exemplarily, taking the configuration table shown in Table 1 above as an example, the second message is sent to the service function node through the output interface corresponding to the first identifier. That is, the output interface of the second message is determined based on the oif shown in Table 1, and the second message is sent to the service function node through this interface.
[0085] The service function node does not need to feedback the processed second message to the service function forwarding module, and can directly perform in-depth parsing on the second message, as well as perform subsequent traffic statistics, in-depth data detection, etc. according to actual requirements.
[0086] In this embodiment, the correspondence between the identifiers of each service function forwarding module and the message operation type is set, and the corresponding message operation type is queried from the routing forwarding table according to the first identifier of the first message. Querying based on the routing forwarding table can improve the query speed; and it is determined whether to perform mirror processing on the first message according to the message operation type. If so, the mirror parameters and the service function node corresponding to the first identifier are queried, and the parameters of the mirror message are adjusted based on the mirror parameters, so that the mirror message is suitable for in-depth parsing to obtain the second message, and the second message is sent to the service function node for in-depth parsing, thereby realizing in-depth parsing of the first message, facilitating subsequent in-depth traffic detection, traffic statistics, etc. applications of the first message, and improving the service functions of the service function chain.
[0087] In a possible design, in addition to performing mirror processing on the first message, the embodiment of the present application also provides a method for performing forwarding processing on the first message. The specific implementation manner of this method is as follows:
[0088] First, obtain the Segment Left field and the Segment List field included in the first message;
[0089] Among them, the Segment List field includes at least one identifier, and the at least one identifier is used to indicate at least one node passed through in the transmission path of the first message. The Segment Left field is used to indicate the position of the identifier corresponding to any service function forwarding module in the Segment list field; the Segment Left field and the Segment List field are jointly used to determine the first identifier.
[0090] Exemplarily, the at least one identifier in the Segment List field is arranged in the order of the corresponding nodes that need to be passed through in sequence, and the Segment Left field can be understood as a pointer used to indicate the position of each identifier in the Segment List field.
[0091] Second, decrement the value of the Segment Left field in the first message by one, and obtain the second identifier of the field value after the decrement in the Segment List field; update the first identifier based on the second identifier;
[0092] wherein, the second identifier is the identifier corresponding to the next node of the node corresponding to the first identifier in the Segment List field, and the second identifier is used to indicate the next node to which the first message is to be forwarded;
[0093] Finally, forward the first message to the node indicated by the updated first identifier.
[0094] In this way, for the first message whose operation type corresponding to the first identifier is a mirror operation, while implementing the mirror operation and in-depth parsing of the first message, the first message will also be forwarded according to the normal forwarding process synchronously, without affecting the normal transmission of the first message, and the reliability of the embodiments of the present application can be improved.
[0095] In a possible design, before executing the above message processing method, it is also necessary to first configure the correspondence between the identifier and the operation type of each service function module, as well as the mirror parameters. Refer to Figure 4 Taking the configuration of Table 1 above as an example, the embodiments of the present application also provide a method flow for configuring a service function forwarder. The specific implementation manner of this method is as follows:
[0096] First, the administrator or an external system writes the configuration information (i.e., the above Table 1) into the message mirror configuration module through the management port, and the message mirror configuration module writes the mirror parameter configuration table into the End.Ml localsid configuration storage device.
[0097] Exemplarily, the End.Ml localsid configuration storage device can be the local storage space or database of the service function forwarder (i.e., the SFF device).
[0098] The message mirror configuration module can write the configuration information into the End.Ml localsid configuration storage device immediately after receiving the configuration information, or write the configuration information into the End.Ml localsid configuration storage device periodically, or write the configuration information into the End.Ml localsid configuration storage device when receiving a query request from the End.Ml localsid configuration storage device. The embodiments of the present application do not limit this.
[0099] The way to write configuration information can be as follows: When configuring the localsid (i.e., SID) with the operation type of mirror operation, the configuration command of the Command Line Interface (CLI) grid can be used, such as: addlocalsid <sid>behavior End.MI oif <ifname>[encap<yes|no>][len <length>[mac <mac-address>[vlan <vlanid> ][ <extensions>It can be implemented or by means of configuration such as Netconf or RestApi. The embodiments of the present application do not limit this.
[0100] Secondly, during the operation of the service function forwarder, the configuration information in the packet mirroring configuration module is loaded into the routing forwarding table.
[0101] It can be understood that in order to speed up the query speed of the packet operation type corresponding to the identifier of each packet, the corresponding information stored locally can be loaded into the routing forwarding table to facilitate querying the packet operation type of the packet while querying the forwarding path of the packet.
[0102] Then, configure the forwarding logic of the routing forwarding table.
[0103] Specifically, the forwarding logic of the routing forwarding table is as follows: when a packet with the operation type of End.MI corresponding to the identifier localsid is matched, the packet is sent to the mirror forwarding module. If a packet with the operation type of End.MI corresponding to the identifier localsid is not matched, the routing forwarding table can also forward the packet to the corresponding device through each forwarding port.
[0104] Next, configure the processing logic of the packet mirroring forwarding module.
[0105] Specifically, the processing logic of the packet mirroring forwarding module is as follows: for the received packet, query the mirroring parameters corresponding to the packet in the End.Ml localsid configuration storage device, and after performing corresponding processing on the packet according to the mirroring parameters, send the processed mirroring packet to the corresponding service function node through the mirroring port (i.e., the interface configured in the configuration table).
[0106] It can be understood that the mirroring port only supports the traffic sent from the packet mirroring forwarding module to the service function node and does not support the traffic from the service function node to the packet mirroring forwarding module.
[0107] Optionally, the service function forwarder is further used to, when performing service function chain path orchestration, encapsulate the SID of the End.MI type into the Segment List of the SRv6 packet for the SRv6 packet that needs to implement the mirroring packet, so as to divert the traffic to the corresponding service function node for processing.
[0108] The above is only an example of the method flow for configuring a service function forwarder provided by the embodiments of the present application, and the actual situation is not limited thereto.
[0109] Next, in combination with Figure 5 and Figure 6 , taking the configuration table as the example given in Table 1 above, the embodiments of the present application provide an example of a complete packet mirroring and forwarding method, and the specific implementation manner of this method is as follows:
[0110] First, refer to Figure 5 , the localsid of device 1 is A1::1, and the behavior is End; the localsid of the service function forwarder is A2::1, and the behavior is End.ML; the localsid of device 2 is A3::1, and the behavior is End;
[0111] Packet 1 is sent from device 1, and the SID indicated by the Segment List of Packet 1 is currently A2::1, that is, it is sent from device 1 to the service function forwarder.
[0112] The specific process of the service function forwarder for mirroring and forwarding the packet is as follows:
[0113] As Figure 6 shown, the service function forwarder receives Packet 1 (SRv6 packet) from device 1 through forwarding port 1, and looks up the routing forwarding table according to the destination IP (i.e., A2::1) of the outer layer of the packet, that is, queries the configuration table information corresponding to this destination IP in the routing forwarding table.
[0114] Exemplarily, the configuration table information corresponding to A2::1 is shown in Table 2 below.
[0115] Table 2 Example of the configuration table corresponding to A2::1
[0116]
[0117] According to Table 2, the operation type corresponding to A2::1 is End.MI, that is, Packet 1 needs to be mirrored.
[0118] Therefore, through Figure 6 the packet forwarding module in, subtract 1 from the Segment Left of Packet 1, and update the destination address of the SRv6 outer layer IPv6 header to the next SID in the Segment List (the specific method can refer to the detailed steps recorded in the forwarding method part above, and the embodiments of the present application will not elaborate here) to obtain Packet 3. Make a copy of Packet 1 to get the mirror packet, and put it into the mirror packet cache queue. And resubmit Packet 3 to the routing forwarding table for the next-hop look-up processing. Since the destination IP is A3::1, therefore, send Packet 3 to device 2.
[0119] For the mirror packet stored in the packet mirror cache queue, through Figure 6 The packet mirroring module shown retrieves the mirrored packet from the mirrored packet cache queue and adjusts the parameters of the mirrored packet according to the mirroring parameters in Table 2 above. Specifically, the outer SRv6 header of the mirrored packet is removed, the destination MAC of the mirrored packet is modified to 01:2B:3C:4D:5E:6F, and the VLAN of the mirrored packet is specified as 100 to obtain Packet 2. Packet 2 is sent to Service Function Node 1 through the specified mirror port 1.
[0120] It can be understood that the various modules involved in the embodiments of the present application are only a possible functional division, and are not limited thereto in practice.
[0121] The method provided by the embodiments of the present application is introduced above. The device provided by the embodiments of the present application is introduced below.
[0122] Based on the same technical concept, the embodiments of the present application provide a packet processing device, which includes a module / unit / means for executing the method performed by the packet function forwarding module in the above method embodiments. This module / unit / means can be implemented by software, or by hardware, or by hardware executing corresponding software.
[0123] Exemplarily, as Figure 7 shown, device 700 includes:
[0124] A routing and forwarding module 701, configured to: receive a first packet from a first device, and obtain a first identifier from the first packet; the first identifier is used to indicate the identifier of any service function forwarding module; query the packet operation type corresponding to the first identifier from the routing forwarding table; the routing forwarding table stores the identifiers of all service function forwarding modules in the service function forwarder and the corresponding operation types; determine whether mirroring processing needs to be performed on the first packet based on the packet operation type;
[0125] A packet forwarding module 702, configured to: if mirroring processing needs to be performed on the first packet, perform mirroring processing on the first packet to obtain a mirrored packet;
[0126] A packet mirroring module 703, configured to: query the mirroring parameters and service function node corresponding to the first identifier from a preset mirroring parameter configuration table based on the first identifier; adjust the parameters of the mirrored packet according to the mirroring parameters so that the mirrored packet is suitable for in-depth parsing to obtain a second packet; send the second packet to the service function node; the service function node is used to perform in-depth parsing on the second packet.
[0127] Optionally, the packet forwarding module 702 is further configured to: if mirroring processing does not need to be performed on the first packet, forward the first packet according to the forwarding rule indicated by the packet operation type.
[0128] Optionally, the packet forwarding module 702 is further configured to: obtain the Segment Left field and the Segment List field included in the first packet; wherein, the Segment List field includes at least one identifier, and the at least one identifier is used to indicate at least one node passed through in the transmission path of the first packet, and the Segment Left field is used to indicate the position of the identifier corresponding to any service function forwarding module in the Segment list field; the Segment Left field and the SegmentList field are jointly used to determine the first identifier; subtract one from the value of the Segment Left field in the first packet, and obtain the second identifier in the Segment List field for the field value after subtraction; the second identifier is the identifier corresponding to the next node of the node corresponding to the first identifier in the Segment List field, and the second identifier is used to indicate the next node to which the first packet is to be forwarded; update the first identifier based on the second identifier; and forward the first packet to the node indicated by the updated first identifier.
[0129] Optionally, the preset mirror parameter configuration table includes the mirror parameters corresponding to the first identifier and the output interface. The mirror parameters include at least one of: whether to perform mirror truncation on the payload of the mirror packet, whether to perform physical address encapsulation on the mirror packet, and whether to perform virtual local area network encapsulation on the mirror packet; the output interface is used to send the second packet to the corresponding service function node; when the packet mirroring module 703 adjusts the parameters of the mirror packet based on the mirror parameters, it is specifically configured to: adjust the parameters of the mirror packet based on at least one of the mirror parameters included; when the packet mirroring module 703 sends the second packet to the service function node, it is specifically configured to: send the second packet to the service function node through the output interface corresponding to the first identifier, so that the service function node performs in-depth parsing on the second packet.
[0130] It should be understood that all relevant contents of each step involved in the above method embodiment can be cited in the function description of the corresponding functional module, and will not be repeated here.
[0131] Based on the same technical concept, see Figure 8 , the embodiment of the present application further provides an electronic device 800, including:
[0132] At least one processor 801; and a communication interface 803 communicatively connected to the at least one processor 801; the at least one processor 801 makes the electronic device 800 execute the method steps performed by the kanban in the above method embodiment through the communication interface 803 by executing the instructions stored in the memory 802.
[0133] Optionally, the memory 802 is located outside the electronic device 800.
[0134] Optionally, the electronic device 800 includes the memory 802, which is connected to the at least one processor 801, and the memory 802 has instructions executable by the at least one processor 801. The Figure 8 memory 802 is represented by a dashed line as being optional for the electronic device 800.
[0135] Wherein, the at least one processor 801 and the memory 802 may be coupled through an interface circuit or integrated together, and there is no limitation here.
[0136] In the embodiments of the present application, the specific connection medium between the at least one processor 801, the memory 802, and the communication interface 803 is not limited. In the embodiments of the present application Figure 8 it is shown that the at least one processor 801, the memory 802, and the communication interface 803 are connected through a bus 804. The bus is Figure 8 represented by a thick line. The connection manners between other components are only for illustrative purposes and are not to be taken as limiting. This bus portion may be an address bus, a data bus, a control bus, etc. For the sake of convenience of representation, Figure 8 only one thick line is used to represent it, but it does not mean that there is only one bus or one type of bus.
[0137] It should be understood that the processor mentioned in the embodiments of the present application may be implemented by hardware or by software. When implemented by hardware, the processor may be a logic circuit, an integrated circuit, etc. When implemented by software, the processor may be a general-purpose processor that implements by reading software code stored in the memory.
[0138] Exemplarily, the processor may be a Central Processing Unit (CPU), or may also be other general-purpose processors, Digital Signal Processors (DSPs), Application Specific Integrated Circuits (ASICs), Field Programmable Gate Arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.
[0139] It should be understood that the memory mentioned in the embodiments of the present application may be a volatile memory or a non-volatile memory, or may include both a volatile memory and a non-volatile memory. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable ROM (PROM), an erasable programmable ROM (EPROM), an electrically erasable programmable ROM (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), which serves as an external cache. By way of example but not limitation, many forms of RAM are available, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchlink DRAM (SLDRAM), and direct rambus RAM (DR RAM).
[0140] It should be noted that when the processor is a general-purpose processor, DSP, ASIC, FPGA, or other programmable logic device, discrete gate or transistor logic device, discrete hardware component, the memory (storage module) may be integrated in the processor.
[0141] It should be noted that the memory described herein is intended to include, but not be limited to, these and any other suitable types of memory.
[0142] Based on the same technical concept, the embodiments of the present application also provide a computer-readable storage medium for storing instructions, which, when executed, cause a computer to execute the method steps performed by any of the devices in the above method embodiments.
[0143] Based on the same technical concept, the embodiments of the present application also provide a computer program product, including computer program code, which, when running on a computer, causes the method steps performed by any of the devices in the above method embodiments to be implemented.
[0144] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.
[0145] The present application is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the present application. It should be understood that each flow and / or block in the flowchart and / or block diagram, as well as the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices generate means for implementing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.
[0146] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory generate a manufactured article including instruction means that implement the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.
[0147] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, so that the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.
[0148] Obviously, those skilled in the art can make various modifications and variations to the present application without departing from the scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalent technologies, the present application is also intended to include these modifications and variations.< / extensions> < / vlanid> < / length> < / ifname> < / sid>
Claims
1. A message processing method, applied to any service function forwarding module in a service function forwarder, characterized in that: include: Receiving a first message from a first device, and obtaining a first identifier from the first message; The first identifier is used to indicate an identifier of any service function forwarding module; Querying the message operation type corresponding to the first identifier from the routing forwarding table; The routing forwarding table stores identifiers of all service function forwarding modules in the service function forwarder and corresponding message operation types; Determine whether the first message needs to be mirrored based on the message operation type, and if so, perform mirroring on the first message to obtain a mirrored message; Based on the first identifier, query the mirroring parameters and service function node corresponding to the first identifier from a preset mirroring parameter configuration table; Adjusting the parameters of the mirrored message based on the mirrored parameters so that the mirrored message is suitable for deep parsing to obtain a second message; The second message is sent to the service function node; the service function node is used to perform in-depth analysis on the second message.
2. The method according to claim 1, characterized in that The determining whether the first message needs to be mirrored based on the message operation type further includes: If not, forwarding the first message based on the forwarding rule indicated by the message operation type.
3. The method according to claim 1, characterized in that The method further comprises: Obtaining a Segment Left field and a Segment List field included in the first message; wherein the Segment List field includes at least one identifier, the at least one identifier is used to indicate at least one node passed through in the transmission path of the first message, and the Segment Left field is used to indicate the position of the identifier corresponding to any service function forwarding module in the Segment list field; the Segment Left field and the SegmentList field are used together to determine the first identifier; Subtract one from the value of the Segment Left field in the first message, and obtain a second identifier of the field value obtained after subtracting one in the Segment List; the second identifier is an identifier corresponding to the next node of the node corresponding to the first identifier in the Segment List, and the second identifier is used to indicate the next node to which the first message is to be forwarded; The first identifier is updated based on the second identifier; and the first message is forwarded to the node indicated by the updated first identifier.
4. The method according to claim 1, characterized in that The preset mirroring parameter configuration table includes mirroring parameters and output interfaces corresponding to the first identifier, wherein the mirroring parameters include at least one of whether to intercept the payload of the mirroring message, whether to perform physical address encapsulation on the mirroring message, and whether to perform virtual local area network encapsulation on the mirroring message; the output interface is used to send the second message to the corresponding service function node; The adjusting the parameters of the mirrored message based on the mirrored parameters comprises: adjusting the parameters of the mirrored message based on the at least one item included in the mirrored parameters; The sending the second message to the service function node includes: sending the second message to the service function node through an output interface corresponding to the first identifier, so that the service function node performs in-depth analysis on the second message.
5. A message processing device, applied to any service function forwarding module in a service function forwarder, characterized in that: include: A routing forwarding module, configured to: receive a first message from a first device, and obtain a first identifier from the first message; The first identifier is used to indicate an identifier of any service function forwarding module; Querying the message operation type corresponding to the first identifier from the routing forwarding table; The routing forwarding table stores identifiers of all service function forwarding modules in the service function forwarder and corresponding message operation types; Determining whether to perform mirroring processing on the first message based on the message operation type; A message forwarding module, used for: if the first message needs to be mirrored, mirroring the first message to obtain a mirrored message; A message mirroring module, used to: query the mirroring parameters and service function node corresponding to the first identifier from a preset mirroring parameter configuration table based on the first identifier; Adjusting the parameters of the mirrored message based on the mirrored parameters so that the mirrored message is suitable for deep parsing to obtain a second message; The second message is sent to the service function node; the service function node is used to perform in-depth analysis on the second message.
6. The device according to claim 5, characterized in that The message forwarding module is further used for: Obtaining a Segment Left field and a Segment List field included in the first message; wherein the Segment List field includes at least one identifier, the at least one identifier is used to indicate at least one node passed through in the transmission path of the first message, and the Segment Left field is used to indicate the position of the identifier corresponding to any service function forwarding module in the Segment list field; the Segment Left field and the SegmentList field are used together to determine the first identifier; Subtract one from the value of the Segment Left field in the first message, and obtain a second identifier of the field value obtained after subtracting one in the Segment List; the second identifier is an identifier corresponding to the next node of the node corresponding to the first identifier in the Segment List, and the second identifier is used to indicate the next node to which the first message is to be forwarded; The first identifier is updated based on the second identifier; and the first message is forwarded to the node indicated by the updated first identifier.
7. The device according to claim 5, characterized in that The preset mirroring parameter configuration table includes mirroring parameters and output interfaces corresponding to the first identifier, wherein the mirroring parameters include at least one of whether to intercept the payload of the mirroring message, whether to perform physical address encapsulation on the mirroring message, and whether to perform virtual local area network encapsulation on the mirroring message; the output interface is used to send the second message to the corresponding service function node; When the message mirroring module adjusts the parameters of the mirrored message based on the mirroring parameters, it is specifically used to: adjust the parameters of the mirrored message based on the at least one item included in the mirroring parameters; When sending the second message to the service function node, the message mirroring module is specifically used to: send the second message to the service function node through the output interface corresponding to the first identifier, so that the service function node performs in-depth analysis on the second message.
8. A service function forwarder, characterized in that: The service function forwarder comprises at least one service function forwarding module, and each of the at least one service function forwarding module is used to execute the steps included in the method according to any one of claims 1 to 4.
9. An electronic device, characterized in that: include: A memory for storing program instructions; A processor is used to call the program instructions stored in the memory, and execute the steps included in the method according to any one of claims 1 to 4 according to the obtained program instructions.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium is used to have a computer program, wherein the computer program includes program instructions, and when the program instructions are executed by a computer, the method according to any one of claims 1 to 4 is implemented.