Message forwarding method and system, computer device, medium, product

By deploying service gateway devices and SDN controllers that support SRv6 protocol on EVPN devices, dynamically adjusting flow tables and policies, the problem of inconsistent traffic paths in EVPN devices is solved, precise forwarding of traffic and security checks are realized, and network flexibility and security are improved.

CN120090969BActive Publication Date: 2025-07-11BEIJING ELECTRONIC DIGITAL INTELLIGENCE TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510574659.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-05-06
Publication Date
2025-07-11
Estimated Expiration
2045-05-06

AI Technical Summary

Technical Problem

When running on an EVPN device, due to the limitations of the RFC 8986 protocol specification, the actual forwarding path of the traffic is inconsistent with the user's expectations, and the traffic fails to pass the firewall for security checks, and the firewall policy cannot take effect.

Method used

By deploying a service gateway device that supports SRv6 protocol on the service side, combining with the SDN controller, dynamically obtaining service routing information, flexibly adjusting flow tables and policies, making judgments based on the preset flow table mechanism, and calling the target policy for packet encapsulation and forwarding, ensuring that traffic passes through the firewall according to the user's expected path.

Benefits of technology

It realizes precise control of traffic paths, ensures that traffic passes through the firewall for security checks, improves network security and service quality, reduces management costs and error probability, and enhances network flexibility and scalability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120090969B_ABST
    Figure CN120090969B_ABST
Patent Text Reader

Abstract

The present application discloses a method and system for packet forwarding, a computer device, a medium, and a product. Among them, the method includes: in response to a packet forwarding instruction, calling a service gateway device deployed on the service side to receive service packets to be forwarded; the SDN controller obtains service routing information from the edge node of the EVPN through the EBGP protocol and converts it into a target flow table, and then issues the target flow table and at least two preset policies in the SDN controller to the service gateway device, and judges the service packets based on the preset flow table mechanism. When it meets the conditions, obtain the service information of the service packets; when it is determined that the packet needs path control, call the target policy from the preset policies, and encapsulate the service packets according to the target policy to obtain an SRv6 packet and forward it. This method does not need to modify the RFC 8986 rules, does not need to modify the software of equipment manufacturers one by one, has strong compatibility and lower costs, and realizes flexible and controllable forwarding of different packets.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of network communication technologies, and in particular, to a method and system for packet forwarding, a computer device, a medium, and a product. Background Art

[0002] In some complex service scenarios, traffic needs to pass through a specific path to reach the destination; when EVPN runs on a PE (Provider Edge) device, it automatically generates and distributes a list of SIDs through the BGP protocol, and these SID lists define the path of traffic in the network. In some cases, the SID list generated by EVPN will compulsorily include a special SID named end.dt4 SID, and the function of this SID is to convert traffic from the IPv6 SRv6 domain to the IPv4 traditional network (such as the public network egress).

[0003] Specifically, in complex service scenarios, the user's expectation is that traffic starts from the source node, passes through the SRv6 path, and the traffic is directed to the firewall using the end.dx4 SID at a certain node. After the firewall processes it, the traffic then enters the public network egress. However, due to the fact that the SID list automatically distributed by EVPN compulsorily includes the end.dt4 SID, and the end.dt4 SID is usually the last hop of the SID list (that is, according to the specification of RFC 8986, the function of the end.dt4 SID is to divert traffic from the IPv6 domain to the IPv4 domain, so it is usually placed at the end of the SID list), the actual path of the traffic becomes: the traffic passes through the SRv6 path, and since the end.dt4 SID is placed at the end, the traffic is directly directed to the public network egress without passing through the firewall expected by the user; therefore, this will cause the traffic not to pass through the security check of the firewall, and the functions of the firewall (such as intrusion detection, policy filtering, etc.) cannot take effect, and the end.dx4 SID set by the user does not play the expected forwarding role. Summary of the Invention

[0004] In view of this, the embodiments of the present disclosure provide a method and system for packet forwarding, a computer device, a medium, and a product, which can solve the problems in the prior art that due to the limitations of the RFC 8986 protocol specification, the actual forwarding path of traffic is inconsistent with the expected forwarding policy path, etc.

[0005] In a first aspect, an embodiment of the present disclosure provides a method for packet forwarding, including:

[0006] In response to a packet forwarding instruction, call a service gateway device to receive the service packet to be forwarded; the service gateway device is deployed on the service side and supports the SRv6 protocol and the orchestration of the SID list;

[0007] Invoke the SDN controller to dynamically obtain service routing information from the edge nodes of EVPN through the EBGP protocol;

[0008] Convert the service routing information into a target flow table according to the docking protocol, and send the target flow table and at least two preset policies in the SDN controller to the service gateway device through the API interface; Judge the service packet based on the preset flow table mechanism, and when it meets the preset flow table mechanism, trigger a service information acquisition instruction;

[0009] Respond to the service information acquisition instruction to obtain the service information of the service packet;

[0010] When it is determined according to the service information that the service packet is a packet that needs path control, call the target policy from the at least two preset policies; The target policy includes a target SR policy and a target SID list;

[0011] Based on the target SR policy, encapsulate an outer IPv6 header and an SRH SID List for the service packet, and set the SL value at the same time to obtain an SRv6 packet;

[0012] Forward the SRv6 packet according to the target SID list.

[0013] In a second aspect, the present application discloses a packet forwarding system, including:

[0014] A deployment module for deploying a service gateway device on the service side to completely separate the forwarding plane from the control plane, and the service gateway device supports the SRv6 protocol and supports the orchestration of the SID list;

[0015] An SDN controller module for dynamically obtaining service routing information from the edge nodes of EVPN through the EBGP protocol, converting the service routing information into a target flow table according to the docking protocol, and sending the target flow table and at least two configured preset policies to the service gateway device through the API interface;

[0016] An invocation module for invoking the service gateway device to receive the service packet to be forwarded in response to a packet to be forwarded instruction;

[0017] A trigger execution module for judging the service packet based on the preset flow table mechanism, triggering a service information acquisition instruction when it meets the preset flow table mechanism, and responding to the service information acquisition instruction to obtain the service information of the service packet;

[0018] An invocation module for calling the target policy from the at least two preset policies when it is determined according to the service information that the service packet is a packet that needs path control; The target policy includes a target SR policy and a target SID list;

[0019] An encapsulation module, which is used to encapsulate an outer IPv6 header and an SRH SIDList for the service packet based on the target SR policy, and at the same time set the SL value to obtain an SRv6 packet;

[0020] A forwarding module, which is used to forward the SRv6 packet according to the target SID list.

[0021] In a third aspect, the present application discloses a packet forwarding method, including:

[0022] Deploy a service gateway device on the service side; the service gateway device supports the SRv6 protocol and supports the orchestration of the SID list;

[0023] In response to a packet to-be-forwarded instruction, call the service gateway device to receive the service packet to be forwarded;

[0024] Call the SDN controller to dynamically obtain service routing information from the edge node of the EVPN through the EBGP protocol, and convert the service routing information into a target flow table according to the docking protocol;

[0025] According to the service attributes of the packet to be forwarded, obtain the policy associated with the service attributes from the SDN controller, and send the target flow table and the associated policy to the service gateway device through the API interface;

[0026] Based on a preset flow table mechanism, judge the service packet. When it meets the preset flow table mechanism, trigger a service information acquisition instruction;

[0027] In response to the service information acquisition instruction, obtain the service information of the service packet;

[0028] According to the service information, judge whether the service packet is a packet that requires path control. If not, call the first policy from the associated policy, execute the first policy to obtain the encapsulated SRv6 packet, and forward the SRv6 packet;

[0029] If so, call the second policy from the associated policy, execute the second policy to obtain the encapsulated SRv6 packet, and forward the SRv6 packet.

[0030] Fourthly, the present application discloses a collaborative management system for SRv6 policies and EVPN automatic SIDs, including a service system, a service gateway device, an SDN controller, several intermediate node routers, an egress node router, and a side-mounted firewall. The service system is communicatively connected to the service gateway device, and the SDN controller is communicatively connected to one or more of the several intermediate node routers; one or more of the several intermediate node routers are communicatively connected to the egress node router; the egress node router is communicatively connected to the side-mounted firewall;

[0031] The service system is used to initiate a packet forwarding instruction;

[0032] The SDN controller is used to configure at least two SR policies and policies associated with the service attributes of the packets to be forwarded, to dynamically obtain service routing information from the corresponding intermediate node routers of EVPN through the EBGP protocol, to convert the service routing information into a target flow table according to the docking protocol, and to send the target flow table and the associated policies to the service gateway device through the API interface;

[0033] The service gateway device is used to judge the received service packets based on a preset flow table mechanism. When the preset flow table mechanism is met, it obtains the service information of the service packets, judges whether the service packets are packets that need path control according to the service information, and triggers the execution of corresponding policies according to different judgment results.

[0034] Fifthly, an embodiment of the present disclosure also provides a computer device, adopting the following technical solution:

[0035] The computer device includes:

[0036] At least one processor; and,

[0037] A memory communicatively connected to the at least one processor; wherein,

[0038] The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute any one of the above packet forwarding methods.

[0039] Sixthly, an embodiment of the present disclosure also provides a computer-readable storage medium, which stores computer instructions for causing a computer to execute any one of the above packet forwarding methods.

[0040] Seventhly, an embodiment of the present disclosure also provides a computer program product, including a computer program / instructions, and when the computer program / instructions are executed by a processor, the steps of any one of the above methods are implemented.

[0041] The packet forwarding method disclosed in this application, in response to a packet forwarding instruction, calls a service gateway device deployed on the service side to receive service packets to be forwarded, calls an SDN controller, dynamically obtains service routing information from the edge nodes of EVPN through the EBGP protocol, converts the service routing information into a target flow table according to the docking protocol, and issues the target flow table and at least two preset policies in the SDN controller to the service gateway device through the API interface. This method enables the service gateway device to flexibly adjust the flow table and policies according to different docking protocols and service requirements, improving the adaptability and scalability of the system. As the core of centralized control, the SDN controller can uniformly manage and issue the flow table and policies, avoiding the complexity and inconsistency of decentralized configuration of devices in traditional networks, and reducing the management cost and error probability; judging the service packet based on the preset flow table mechanism, and triggering a service information acquisition instruction when it meets the preset flow table mechanism; acquiring the service information of the service packet in response to the service information acquisition instruction; when judging that the service packet is a packet that needs path control according to the service information, calling a target policy from at least two preset policies. Only qualified service packets will acquire service information and select a target policy according to the service information. This intelligent judgment and policy selection mechanism can provide precise path control for packets according to different service requirements and network conditions, improving the utilization rate of network resources and the quality of service. The existence of at least two preset policies enables the system to flexibly select appropriate policies according to different service scenarios and requirements, meeting diverse service needs; encapsulating an outer IPv6 header and an SRH SID List for the service packet based on the target SR policy, and setting the SL value at the same time to obtain an SRv6 packet, and forwarding the SRv6 packet according to the target SID list. Forwarding the SRv6 packet according to the target SID list enables the packet to be forwarded along a pre-set path, achieving precise control of the packet forwarding path and meeting the special path requirements of different services. By introducing a service gateway device between network-side edge devices (i.e., PE devices) and combining with the SDN controller for dynamic SID policy orchestration, the interference of the EVPN default attached SID to SRv6 traffic is effectively avoided. Compared with traditional methods, it is not necessary to modify the RFC 8986 rules, and it is not necessary to modify the software implementations of device manufacturers one by one, with lower compatibility and implementation costs, while improving the flexibility and controllability of traffic forwarding.

[0042] The above description is only an overview of the technical solution of this disclosure. In order to understand the technical means of this disclosure more clearly, it can be implemented according to the content of the specification. And in order to make the above and other purposes, features and advantages of this disclosure more obvious and understandable, the following specific preferred embodiments are given and described in detail in conjunction with the accompanying drawings. Brief Description of the Drawings

[0043] To more clearly illustrate the technical solutions of the embodiments of the present disclosure, the accompanying drawings required for the embodiments will be briefly introduced below. Obviously, the accompanying drawings in the following description are only some embodiments of the present disclosure. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can be obtained based on these drawings.

[0044] Figure 1 It is a schematic flowchart of the packet forwarding method provided in the first aspect of the embodiments of the present disclosure.

[0045] Figure 2 It is a schematic flowchart of the method for judging service packets based on a preset flow table mechanism provided in the embodiments of the present disclosure.

[0046] Figure 3 It is a schematic flowchart of the analysis and forwarding method of service packets provided in the embodiments of the present disclosure when it is determined according to service information that the service packet is not a packet that requires path control.

[0047] Figure 4 It is a schematic flowchart of the method for forwarding SRv6 packets according to a target SID list provided in the embodiments of the present disclosure.

[0048] Figure 5 It is a schematic flowchart of the deployment method of the service gateway device provided in the embodiments of the present disclosure.

[0049] Figure 6 It is a schematic flowchart of the packet forwarding method provided in the second aspect of the embodiments of the present disclosure.

[0050] Figure 7 For Figure 6 It is a schematic flowchart of the method for calling the first policy from associated policies, executing the first policy to obtain the encapsulated SRv6 packet and forwarding the SRv6 packet in

[0051] Figure 8 For Figure 6 It is a schematic flowchart of the method for calling the second policy from associated policies, executing the second policy to obtain the encapsulated SRv6 packet and forwarding the SRv6 packet in

[0052] Figure 9 It is a schematic diagram of the composition of the SRv6 policy and EVPN automatic SID collaborative management system in the SRv6 policy side-hanging networking scenario provided in the embodiments of the present disclosure.

[0053] Figure 10 It is a schematic diagram of the structure of a computer device provided in the embodiments of the present disclosure.

[0054] Explanation of reference numerals: 100, business system; 200, business gateway device; 300, SDN controller; 400, intermediate node router; 500, tail node router; 600, side-mounted firewall. DETAILED DESCRIPTION

[0055] The embodiments of the present disclosure are described in detail below with reference to the accompanying drawings.

[0056] It should be clear that the following embodiments of the present disclosure are described by specific specific examples, and those skilled in the art can easily understand other advantages and effects of the present disclosure from the contents disclosed in this specification. Obviously, the described embodiments are only a part of the embodiments of the present disclosure, rather than all of the embodiments. The present disclosure can also be implemented or applied through other different specific embodiments, and the details in this specification can also be modified or changed in various ways based on different viewpoints and applications without departing from the spirit of the present disclosure. It should be noted that the following embodiments and features in the embodiments can be combined with each other in the absence of conflict. Based on the embodiments in the present disclosure, all other embodiments obtained by ordinary technicians in the field without making creative work are within the scope of protection of the present disclosure.

[0057] It should be noted that various aspects of the embodiments within the scope of the appended claims are described below. It should be apparent that the aspects described herein may be embodied in a wide variety of forms, and any specific structure and / or function described herein is merely illustrative. Based on the present disclosure, it should be understood by those skilled in the art that an aspect described herein may be implemented independently of any other aspect, and two or more of these aspects may be combined in various ways. For example, any number of aspects described herein may be used to implement the device and / or practice the method. In addition, other structures and / or functionalities other than one or more of the aspects described herein may be used to implement this device and / or practice this method.

[0058] It should also be noted that the illustrations provided in the following embodiments are only schematic illustrations of the basic concept of the present disclosure. The drawings only show components related to the present disclosure rather than being drawn according to the number, shape and size of components in actual implementation. In actual implementation, the type, quantity and proportion of each component may be changed arbitrarily, and the component layout may also be more complicated.

[0059] Additionally, in the following description, specific details are provided to facilitate a thorough understanding of the examples. However, it will be understood by those skilled in the art that the aspects described may be practiced without these specific details.

[0060] Reference Figure 1 The first aspect of the present application discloses a message forwarding method, comprising:

[0061] S100. In response to the instruction that a service message is to be forwarded, call a service gateway device to receive the service message to be forwarded.

[0062] Among them, the service gateway device is deployed on the service side and supports the SRv6 protocol and the orchestration of the SID list.

[0063] In this step, the service gateway device is deployed on the service side, which can be closer to the service source, quickly receive the service message to be forwarded, reduce the delay of message transmission, and the support for the SRv6 protocol and SID list orchestration lays a foundation for subsequent flexible path control.

[0064] S200. Call an SDN controller to dynamically obtain service routing information from the edge nodes of the EVPN through the EBGP protocol.

[0065] In this step, by calling the SDN controller and using the EBGP protocol to dynamically obtain service routing information from the edge nodes of the EVPN, it is possible to perceive the changes in the network topology, the changes in the link status, and the update of the routing information in real time; the SDN controller can make more reasonable path decisions based on the latest routing information to avoid forwarding errors caused by using outdated routing information.

[0066] In this embodiment, at least two SR policies are configured in the SDN controller; the at least two SR policies include the mapping relationship between different types of service messages and the SRH SID list (i.e., the SRv6 SRH SID lis); among them, different types of service messages are messages corresponding to different service requirements.

[0067] In this embodiment, the SDN controller supports a multi-tenant scenario and can generate different SID policies according to tenant requirements. For example, in the first type of scenario, it is required that the service message passes through a firewall, and the corresponding SID list is: [SID1, SID2, end.dx4 corresponds to SID1], and the service gateway device ensures that this order is not affected by the EVPN and the PE1 forwards correctly.

[0068] In the second type of scenario, it is required that the service message directly enters the public network without passing through firewall inspection. The SID list is: [SID1, SID2, end.dt4 corresponds to SID2].

[0069] In a multi-tenant scenario, the traffic of different tenants passes through different firewall policies; through the configuration in the SDN controller, the SID list can be dynamically adjusted. For example, for tenant A: [SID1, SID2, end.dx4 corresponds to SID3], and for tenant B: [SID1, SID2, end.dx4 corresponds to SID4].

[0070] A variety of preset policies can be pre-configured in the SDN controller, and these policies can be added, modified or deleted at any time as needed; when new business needs or network policies emerge, only the corresponding configuration needs to be made in the SDN controller, and then the updated policies can be sent to the business gateway device through the API interface, without the need for large-scale transformation of the entire network, which enhances the scalability of the network.

[0071] As for S200, as long as the SDN controller establishes an EBGP protocol neighbor, it can be triggered to execute. This step can be after S100 or before S100.

[0072] S300, converting the service routing information into a target flow table according to the docking protocol, and sending the target flow table and at least two preset policies in the SDN controller to the service gateway device through an API interface.

[0073] Specifically, it includes: 1) converting the service routing information into a target flow table in the SDN controller according to the docking protocol; 2) determining the policy associated with the service attribute of the service message from several policies configured by the SDN controller according to the service needs of the message to be forwarded, as at least two preset policies to be sent to the service gateway device; 3) the SDN controller sends the target flow table and at least two preset policies to the service gateway device through the API interface.

[0074] In this embodiment, the at least two preset policies are policies associated with the service attributes of the service message determined from the at least two SR policies.

[0075] At least two preset policies include a default policy and at least one target policy. The default policy matches the default attributes of the service message through the default route. The last hop of the SID list in the default policy is the SID corresponding to end.dt4 automatically carried by EVPN. The target policy is a detailed policy after modifying the SR policy and SID list according to the preset path requirements of the service message.

[0076] It should be noted that the delivery of the target flow table can be automatically triggered by a set period or increment.

[0077] This step includes determining policies associated with the service attributes of the service message according to the service requirements of the service message, that is, selecting these associated policies as at least two preset policies to be issued in the SDN controller.

[0078] In this embodiment, compared with the forwarding mechanism of SRv6 traffic in the prior art, the first node is changed from an intermediate router to a deployed service gateway device. The service gateway device receives the information sent by the SDN controller, and it is not allowed to autonomously insert any other SIDs into the SID List in the service gateway device.

[0079] In this embodiment, the SDN controller can modify and delete the policies that have been sent to the service gateway through the API, and batch deletion is supported.

[0080] Convert the service routing information into a target flow table, so that the service gateway device can forward packets according to the flow table rules; sending preset policies can enable the service gateway device to select appropriate policies for path control according to different situations, improving the flexibility and manageability of the network.

[0081] S400, judge the service packets based on the preset flow table mechanism. When they meet the preset flow table mechanism, trigger the service information acquisition instruction.

[0082] Perform a preliminary judgment on the service packets through the preset flow table mechanism. Only the packets that meet specific conditions will trigger the service information acquisition instruction, avoiding detailed parsing and processing of all packets, reducing unnecessary calculations and resource consumption, and improving the efficiency of packet processing.

[0083] S500, respond to the service information acquisition instruction to obtain the service information of the service packets.

[0084] Among them, the service information includes one or more of the source IP address, destination IP address, DSCP value, port number, and protocol type.

[0085] Specifically, when the service gateway device receives the service information acquisition instruction, obtain the service information of the service packets through the service gateway device.

[0086] S600, when it is judged according to the service information that the service packet is a packet that needs path control, call the target policy from at least two preset policies.

[0087] Among them, the target policy includes a target SR policy and a target SID list.

[0088] Judge whether the packet needs path control based on the service information, and call the target policy from multiple preset policies, so as to customize appropriate forwarding paths for different services and meet the special needs of diversified services.

[0089] In the target policy, filter and adjust the SIDs corresponding to end.dt4 automatically attached by EVPN to ensure that it does not affect the forwarding logic of SRv6 packets. Specifically, by adjusting the order of the SID list or adding / removing SIDs in the SID list, combined with the SRv6 policy configuration, make the SIDs corresponding to end.dt4 only used for traffic paths that do not need to pass through the firewall.

[0090] In this step, the service gateway device makes a judgment based on the obtained service information. For example, if the service packet is a high-priority real-time video stream and needs to pass through a specific security check node, it is judged that the packet is a packet that requires path control; then select the target policy suitable for the service from the preset policies issued, and the target policy includes the target SR policy and the target SID list. The target SR policy defines the encapsulation rules of the packet, and the target SID list specifies the forwarding path of the packet. Selecting the appropriate target policy according to the service information can achieve fine-grained path control of different service packets, meet the special needs of different services, and improve the quality of network services.

[0091] S700, based on the target SR policy, encapsulates the outer IPv6 header and the SRH SID List for the service packet, and at the same time sets the SL value to obtain the SRv6 packet.

[0092] Specifically, in the networking scenario with a firewall in a side-hung configuration, encapsulating the outer IPv6 header for the service packet generates a SID list with the end.dx4 corresponding IPv6 address as the last hop.

[0093] In this step, the service gateway device adds the outer IPv6 header and the SRH (Segment Routing Header) SID List to the service packet according to the target SR policy. The outer IPv6 header contains information such as the destination address of the packet, and the SRH SIDList specifies the order of nodes that the packet needs to pass through; at the same time, set the SL (Segment Left) value, and the SL value represents the number of SIDs that the packet still needs to pass through. Encapsulating the outer IPv6 header and the SRH SID List enables the packet to be forwarded according to the SRv6 protocol. By setting the SL value, the forwarding path of the packet can be controlled to achieve flexible routing of the packet.

[0094] S800, forward the SRv6 packet according to the target SID list.

[0095] Among them, the target SID list is composed of multiple SIDs arranged in a certain order, which defines the path that the packet passes from the source node to the destination node; for example, [SID1, SID2, SID3] means that the packet first passes through the resource represented by SID1, then passes through SID2, and finally reaches SID3.

[0096] Forwarding packets according to the target SID list can ensure that the packets are forwarded along the predetermined path, avoiding the path problems caused by the end.dt4 SID in the SID list automatically issued by EVPN, enabling the traffic to pass through security devices such as firewalls as expected by users, and improving the network security.

[0097] Dynamically obtaining service routing information through the SDN controller, combined with the preset policy and the target flow table, can flexibly adjust the packet forwarding path according to the service requirements, effectively avoiding the problems brought by the default path, ensuring that the traffic can pass through specific nodes such as firewalls as expected by users, and achieving precise control of the path.

[0098] The packet forwarding method disclosed in the first aspect of this application, in response to a packet forwarding instruction, calls the service gateway device deployed on the service side to receive the service packet to be forwarded, calls the SDN controller, dynamically obtains service routing information from the edge nodes of the EVPN through the EBGP protocol, converts the service routing information into a target flow table according to the docking protocol, and issues the target flow table and at least two preset policies in the SDN controller to the service gateway device through the API interface. This method enables the service gateway device to flexibly adjust the flow table and policies according to different docking protocols and service requirements, improving the adaptability and scalability of the system. As the core of centralized control, the SDN controller can uniformly manage and issue the flow table and policies, avoiding the complexity and inconsistency of decentralized device configuration in traditional networks, reducing management costs and error probabilities; judging the service packet based on the preset flow table mechanism, and triggering a service information acquisition instruction when the preset flow table mechanism is met; acquiring the service information of the service packet in response to the service information acquisition instruction; when it is determined according to the service information that the service packet is a packet that requires path control, calling a target policy from at least two preset policies. Only eligible service packets will acquire service information and select a target policy according to the service information. This intelligent judgment and policy selection mechanism can provide precise path control for packets according to different service requirements and network conditions, improving the utilization rate of network resources and the quality of service. The existence of at least two preset policies enables the system to flexibly select appropriate policies according to different service scenarios and requirements to meet diverse service needs; encapsulating an outer IPv6 header and an SRH SIDList for the service packet based on the target SR policy, and setting the SL value at the same time to obtain an SRv6 packet, and forwarding the SRv6 packet according to the target SID list. Forwarding the SRv6 packet according to the target SID list enables the packet to be forwarded along a pre-set path, achieving precise control of the packet forwarding path and meeting the special path requirements of different services. By introducing a service gateway device between network-side edge devices (i.e., PE devices) and combining with the SDN controller for dynamic SID policy orchestration, the interference of the EVPN default attached SID to SRv6 traffic can be effectively avoided. Compared with traditional methods, there is no need to modify the RFC 8986 rules, and there is no need to modify the software implementation of device manufacturers one by one, with lower compatibility and implementation costs, while improving the flexibility and controllability of traffic forwarding.

[0099] The packet forwarding method disclosed in this application can solve the problem that in complex service scenarios, due to the mandatory inclusion of the end.dt4 SID in the SID list automatically issued by EVPN, the traffic cannot pass through the firewall expected by the user, ensuring that the traffic can be forwarded along the path expected by the user and passing through necessary security checks; dynamically obtain service routing information through the SDN controller and issue preset policies and target flow tables, and the service gateway device can perform flexible path control according to different service requirements and network conditions, improving the network manageability; select appropriate target policies according to service information, perform refined path control on different service packets, can meet the special requirements of different services, improve the network service quality, and ensure the normal operation of high-priority services.

[0100] Referring to Figure 2 , in S400, "judge the service packet based on the preset flow table mechanism, and when it conforms to the preset flow table mechanism, trigger the service information acquisition instruction", that is, the method for judging the service packet based on the preset flow table mechanism includes:

[0101] S410, call the service gateway device to receive the service packet to be forwarded and obtain the destination IP address of the service packet.

[0102] S420, obtain the target entry corresponding to the target flow table based on the destination IP address.

[0103] Among them, the target flow table stores the entry information corresponding to different destination IP addresses.

[0104] By searching for the target entry based on the destination IP address, the forwarding rule related to the packet can be quickly located, improving the efficiency of packet processing. At the same time, this method enables the service gateway device to forward packets according to the pre-configured flow table rules, ensuring the accuracy and consistency of forwarding.

[0105] S430, judge whether the target entry is complete. If it is, trigger the service information acquisition instruction; if not, report the destination IP address to the SDN controller and initiate a query request.

[0106] Specifically, a complete target entry should contain all the key information required for forwarding. In this embodiment, a complete target entry means that it must contain the destination IP address, the next-hop address, and the outgoing interface name. If the entry lacks the next-hop address information, it is considered that the target entry is incomplete. At this time, the service gateway device will report the destination IP address to the SDN controller and send a query request to inquire about the complete forwarding information of the destination IP address. If the target entry contains all the necessary information, the service information acquisition instruction will be triggered and the next step of processing will be entered.

[0107] Judging the integrity of the target entry can ensure that the service gateway device has sufficient information when forwarding packets. When the target entry is incomplete, reporting it to the SDN controller in a timely manner and requesting a query can utilize the global information advantage of the SDN controller to obtain complete forwarding information, avoid forwarding errors caused by information loss, and improve the reliability of the system.

[0108] S440, in response to the received signal of the query request, calls the global routing information base.

[0109] Specifically, after receiving the query request sent by the service gateway device, the SDN controller will process the request and trigger the call to the global routing information base. The global routing information base is a database that stores the entire network topology and routing information. For example, after receiving a query request regarding the destination IP address, the SDN controller will search for the relevant information of this IP address in the global routing information base.

[0110] The global routing information base contains the global information of the entire network. By calling this library, the SDN controller can obtain the most comprehensive and accurate routing information, which helps to solve the problem of insufficient local information of the service gateway device and provides a more reliable basis for packet forwarding.

[0111] S450, query in the global routing information base whether there is legal forwarding information corresponding to the destination IP address. If so, obtain the legal forwarding information corresponding to the destination IP address from the global routing information base and convert it into an incremental flow table; if not, generate an incremental flow table pointing to NULL0 for the destination IP address.

[0112] For example, the SDN controller queries the destination IP address X.Y1.Y2.Y3 in the global routing information base (where X can be any value from 1 to 255, and Y1, Y2, Y3 can be any value from 0 to 255). If the legal forwarding information corresponding to this IP address is queried, for example, the next-hop address is x.y1.y2.y3 (where X can be any value from 1 to 255, and y1, y2, y3 can be any value from 0 to 255) and the forwarding port is eth0, then these information will be sorted into an incremental flow table; if the legal forwarding information of this destination IP address is not queried in the global routing information base, it indicates that this IP address may be illegal or there is no corresponding reachable path in the network. At this time, the SDN controller will generate an incremental flow table pointing to NULL0 (black hole), which means that this packet will be discarded.

[0113] Different incremental flow tables can be generated according to the query results to reasonably process packets. For packets with legitimate forwarding information, generating the corresponding incremental flow tables can supplement the flow table information of the service gateway device to ensure the correct forwarding of packets. For illegal or unreachable packets, generating incremental flow tables pointing to the black hole can prevent the waste of network resources and improve network security.

[0114] S460, the SDN controller issues an incremental flow table to the service gateway device.

[0115] The SDN controller uniformly issues incremental flow tables to the service gateway device, realizing the centralized management and configuration of the network. The service gateway device can update its flow table information in a timely manner, ensuring the consistency and accuracy of network configuration, and at the same time improving the network manageability.

[0116] S470, in response to the received signal of the incremental flow table, triggers a service information acquisition instruction.

[0117] Specifically, after the service gateway device receives the incremental flow table issued by the SDN controller, it will send a received signal to the SDN controller. When the SDN controller receives this signal, the service gateway device triggers a service information acquisition instruction to continue the subsequent processing of service packets. Through this step, it can be ensured that the incremental flow table has been successfully issued to the service gateway device before triggering the service information acquisition instruction, avoiding processing errors caused by unupdated flow tables. This step ensures the coherence and reliability of the entire processing flow.

[0118] Refer to Figure 3 , when it is determined according to the service information that the service packet is not a packet that needs to perform path control, the analysis and forwarding method of the service packet includes:

[0119] A100, call the default policy from at least two preset policies, and the default policy includes the default SR policy and the default SID list;

[0120] A200, based on the default SR policy, trigger the execution of the end.dt4 SID automatically attached according to EVPN to generate an encapsulated SRv6 packet.

[0121] A300, forward the SRv6 packet based on the default SID list.

[0122] In an SRv6 VPN network environment deployed based on EVPN, when the tail node of SRv6 sends service routes (i.e., VPN routes) to the head node, it needs to attach the SID corresponding to end.dt4. This SID can be automatically generated by the tail node router or manually configured through opcode. When the tail node transmits the route to the head node through the EVPN protocol, it will automatically attach this SID. When the head node performs SRv6 packet encapsulation, it will list this SID as the last hop in the SRH SID list.

[0123] Regarding the subsequent forwarding: According to the requirements of the RFC 8986 protocol rules, after the SRv6 packet encapsulated by the head node arrives at the tail node, the tail node only forwards it according to the forwarding policy corresponding to the last hop SID. The forwarding policy of end.dt4 can only be set for VPN and cannot set the next hop and outgoing interface. Therefore, it is impossible to forward the packet to the firewall as needed.

[0124] In this embodiment, invoking the default policy can simplify the processing flow of packet forwarding. For packets that do not require special path control, the default policy is directly used for processing, reducing additional judgment and configuration steps and improving processing efficiency. At the same time, the existence of the default policy provides a unified and standardized forwarding method for the network, ensuring the stability and consistency of the network.

[0125] After the service gateway device invokes the default SR policy, it will operate according to the end.dt4 SID automatically attached by EVPN. The end.dt4 SID is a specific type of SID used to identify the function of Ethernet termination and layer 3 forwarding in an SRv6 (Segment Routing over IPv6) network. The service gateway device will encapsulate this SID and other necessary information into the outer layer of the service packet to generate an SRv6 packet. For example, it will add information such as an outer IPv6 header, SRH (Segment Routing Header), and SID List to the packet to complete the packet encapsulation. Using the end.dt4 SID automatically attached by EVPN for packet encapsulation fully combines the advantages of EVPN and SRv6 technologies. EVPN provides flexible network virtualization and multi-tenant support, while SRv6 realizes efficient path orchestration and forwarding. In this way, while ensuring network flexibility, the efficiency and scalability of packet forwarding can be improved. In addition, the unified encapsulation method also facilitates network devices to process and identify packets.

[0126] Forwarding packets based on the default SID list can achieve fast and accurate packet forwarding; the default SID list pre-defines the packet forwarding path, avoiding hop-by-hop routing lookups in the network and reducing forwarding latency. At the same time, this method also facilitates network administrators to monitor and manage network traffic, because the packet forwarding path can be changed by adjusting the default SID list.

[0127] In this embodiment, the target flow table and at least two preset policies are both stored in the target database of the service gateway device, that is, the information sent by the SDN controller to the service gateway device through the API interface is all sent to the target database of the service gateway device.

[0128] Among them, when it is determined according to the service information that the service packet is a packet that needs path control, the target policy is called from the target database; when it is determined according to the service information that the service packet is not a packet that needs path control, the default policy is called from the target database.

[0129] In the computer field, the default policy refers to a default policy. When the user does not set or specify a specific option or value, the computer system will operate according to the preset default value. For example, in the configuration of the operating system, the settings of software applications, or the parameter configuration of network devices, the application of default values is involved, which can ensure the stable operation of the system in various situations; when encountering situations where no specific value is clearly specified, using the default value can simplify the operation process and improve efficiency and convenience.

[0130] Refer to Figure 4 , for the method of forwarding SRv6 packets according to the target SID list in S800, it includes:

[0131] S810, send the SRv6 packet to the intermediate node through the service gateway device.

[0132] The intermediate node is a router with the role of an intermediate node.

[0133] S820, replace the destination IP of the outer IPv6 header of the SRv6 packet according to the SRH SID List, and at the same time reduce the SL value by n 1s to obtain the processed SRv6 packet, and send it to the tail node.

[0134] Among them, n is the number of intermediate nodes.

[0135] In this embodiment, the intermediate node dynamically changes the destination IP of the outer IPv6 header and adjusts the SL value according to the SRH SID List, realizing the per-hop forwarding of SRv6 packets. This method enables the packets to be accurately transmitted in the network according to the pre-planned path, improving the flexibility and scalability of the network; by reducing the SL value, the node can know the number of hops the packet has passed through, which helps to control the forwarding process of the packet and avoid problems such as loops.

[0136] S830, the tail node forwards the processed SRv6 packet to the side-hung firewall according to the destination SID list.

[0137] Among them, the destination SID list includes specifying a specific vpn-instance, the outgoing interface name, and the next-hop IP address.

[0138] S840, the firewall performs a security check on the processed SRv6 packet and forwards the packet that passes the security check to the public network egress corresponding to the public network egress router.

[0139] When the packet reaches the tail node, SL = 0, and the tail node forwards it according to the forwarding policy configured by its opcode. In this embodiment, the forwarding policy of end.dx4 set by the corresponding opcode includes specifying a specific vpn-instance, the outgoing interface name, and the next-hop IP address, which can accurately direct the traffic to the side-hung firewall.

[0140] Specifically, after receiving the processed SRv6 packet, the firewall can check the packet according to the pre-configured security policy. For example, the firewall checks information such as the source IP address, destination IP address, and port number of the packet to determine whether the packet complies with the security rules; if the packet passes the security check, the firewall forwards the packet to the public network egress corresponding to the public network egress router, enabling the packet to enter the public network for further transmission. The security check of the firewall provides important security protection for the network. It can prevent illegal network traffic from entering the enterprise network and prevent security incidents such as network attacks and data leaks. By forwarding the packet that passes the security check to the public network egress, it ensures that legitimate network communications can proceed normally, improving the security and reliability of the network.

[0141] Refer to Figure 5 , the deployment method of the service gateway device in this application includes:

[0142] B100, determine the service gateway device. The physical form of the service gateway device is a general computing power server or a programmable network device. The service gateway device supports the SRv6 protocol and supports the orchestration of the SID list.

[0143] Selecting a business gateway device with a suitable physical form can meet the diverse needs of different enterprises. General computing power servers have powerful computing capabilities and flexibility, enabling complex business processing and function expansion; programmable network devices provide higher flexibility and customizability at the network level, supporting the SRv6 protocol and SID list orchestration, and laying the foundation for implementing SRv6-based path control and traffic forwarding.

[0144] B200: Deploy the business gateway device on the service side and connect the business gateway device to the SDN controller through the API.

[0145] Deploying the business gateway device on the service side can reduce the transmission delay of service traffic and improve the efficiency of business processing; connecting to the SDN controller through the API enables centralized management and control of the business gateway device. The SDN controller can dynamically send control instructions to the business gateway device according to the real-time status of the network and business requirements, adjust the SID list and forwarding policies, enhancing the flexibility and manageability of the network.

[0146] B300: Configure the connection between the SDN controller and the edge node of the EVPN.

[0147] Configuring the connection between the SDN controller and the EVPN edge node can achieve the integration of SDN technology and EVPN technology; the SDN controller can obtain the topology information and service status of the EVPN network, thereby better performing path planning and traffic scheduling. At the same time, through the centralized management of the SDN controller, the configuration and maintenance process of the EVPN network can be simplified, improving the reliability and scalability of the network.

[0148] B400: Set the business gateway device as the gateway of the business system.

[0149] In an enterprise's business system, such as an ERP system, a CRM system, etc., configure the IP address of the business gateway device as the default gateway of the business system. Taking a Windows server as an example, in the network settings of the server, set the default gateway address to the IP address of the business gateway device. In this way, all external network traffic generated by the business system will be forwarded through the business gateway device.

[0150] Setting the business gateway device as the gateway of the business system enables the traffic of the business system to be uniformly processed through the business gateway device; the business gateway device can monitor, filter, and optimize the business traffic, ensuring the network security and performance of the business system; at the same time, through the unified forwarding of the business gateway device, it is convenient to centrally manage and analyze the business traffic.

[0151] B500: Configure the communication connection between the business gateway device and the intermediate router.

[0152] Configuring the communication connection between the service gateway device and the intermediate router ensures the smooth transmission of service traffic in the enterprise network. The intermediate router can act as a bridge between the service gateway device and other network nodes, expanding the coverage of the service gateway device. At the same time, by reasonably configuring the routing protocol, network load balancing and failover can be achieved, improving the reliability and availability of the network.

[0153] In a second aspect, the present application discloses a packet forwarding system for executing the packet forwarding method disclosed in the first aspect of the present application. The system specifically includes:

[0154] A deployment module for deploying a service gateway device on the service side, completely separating the forwarding plane from the control plane. The service gateway device supports the SRv6 protocol and supports the orchestration of the SID list.

[0155] An SDN controller module for dynamically obtaining service routing information from the edge nodes of the EVPN through the EBGP protocol, converting the service routing information into a target flow table according to the docking protocol, and sending the target flow table and at least two preset policies that have been configured to the service gateway device through the API interface.

[0156] An invocation module for, in response to a packet to-be-forwarded instruction, invoking the service gateway device to receive the service packet to be forwarded.

[0157] A trigger execution module for judging the service packet based on a preset flow table mechanism. When it meets the preset flow table mechanism, it triggers a service information acquisition instruction and acquires the service information of the service packet in response to the service information acquisition instruction.

[0158] An invocation module for, when judging that the service packet is a packet that needs path control according to the service information, invoking a target policy from at least two preset policies; the target policy includes a target SR policy and a target SID list.

[0159] An encapsulation module for encapsulating an outer IPv6 header and an SRH SID List for the service packet based on the target SR policy, and at the same time setting the SL value to obtain an SRv6 packet.

[0160] A forwarding module for forwarding the SRv6 packet according to the target SID list.

[0161] The packet forwarding system disclosed in the present application further includes a first configuration module and a second configuration module;

[0162] The first configuration module is used to configure at least two SR policies in the SDN controller; at least two SR policies include the mapping relationship between different types of service packets and the SRH SID list (i.e., the SRv6 SRH SID lis).

[0163] The second configuration module is used to determine a policy associated with the service attributes of service packets from at least two SR policies; the at least two preset policies include a default policy and at least one target policy. The default policy matches the default attributes of service packets through a default route, and the last hop of the SID list in the default policy is the SID corresponding to end.dt4 automatically carried by EVPN; the target policy is a detailed policy that includes a modified target SR policy and a target SID list.

[0164] Refer to Figure 6 In a third aspect, the present application discloses a packet forwarding method, including:

[0165] S10, deploy a service gateway device on the service side.

[0166] Among them, the service gateway device supports the SRv6 protocol and supports the orchestration of SID lists.

[0167] Deploying the service gateway device on the service side can reduce the transmission distance of service packets in the network, reduce transmission latency, and improve the service response speed. Supporting the SRv6 protocol and SID list orchestration enables the service gateway device to flexibly perform path planning and traffic scheduling for packets, enhancing the flexibility and scalability of the network.

[0168] S20, in response to a packet to-be-forwarded instruction, call the service gateway device to receive the service packet to be forwarded.

[0169] Specifically, when a service server inside an enterprise needs to send data to an external network, a packet to-be-forwarded instruction will be generated; after receiving this instruction, the service gateway device starts to monitor the network port where the service server is located and receives the service packet to be forwarded. Through the service gateway device, the packet to-be-forwarded instruction can be timely responded to, ensuring the timely reception of service packets, avoiding the loss and backlog of packets, and guaranteeing the normal operation of services.

[0170] S30, call the SDN controller, dynamically obtain service routing information from the edge nodes of EVPN through the EBGP protocol, and convert the service routing information into a target flow table according to the docking protocol.

[0171] Specifically, the SDN controller can periodically send a routing information request to the edge nodes of EVPN, and the edge nodes of EVPN will send the service routing information they have mastered to the SDN controller through the EBGP protocol. After receiving these routing information, the SDN controller converts them into a target flow table according to the docking protocol with the service gateway device.

[0172] S40. According to the service attributes of the packet to be forwarded, obtain the policies associated with the service attributes from the SDN controller, and send the target flow table and the associated policies to the service gateway device through the API interface.

[0173] Among them, when the EBGP neighbor between the SDN controller and the edge node of the EVPN is established, the routing information can be dynamically obtained from the edge node of the EVPN through the EBGP protocol, the routing information is converted into the target flow table according to the docking protocol, and then the sending operation can be automatically triggered periodically or incrementally, that is, the target flow table is sent to the service gateway device through the standard API interface.

[0174] Obtaining the associated policies according to the service attributes realizes the differential processing of different service packets; sending the target flow table and policies to the service gateway device enables the service gateway device to forward packets according to specific service requirements and network status, improving the intelligent and refined management level of the network.

[0175] S50. Judge the service packet based on the preset flow table mechanism. When it meets the preset flow table mechanism, trigger the service information acquisition instruction.

[0176] The preset flow table mechanism can preliminarily screen the service packets and only further process the packets that meet specific conditions, reducing unnecessary service information acquisition operations and improving the processing efficiency.

[0177] S60. Respond to the service information acquisition instruction to obtain the service information of the service packet.

[0178] S70. Judge whether the service packet is a packet that needs path control according to the service information. If not, call the first policy from the associated policies, execute the first policy to obtain the encapsulated SRv6 packet and forward the SRv6 packet;

[0179] If so, call the second policy from the associated policies, execute the second policy to obtain the encapsulated SRv6 packet and forward the SRv6 packet.

[0180] In this embodiment, the associated policies are stored in the target database of the service gateway device.

[0181] Judging the path control according to the service information and adopting different policies for packet forwarding realizes the optimized processing of different types of service packets; for the packets that need path control, it can provide better network services to meet the special needs of the service; for the packets that do not need path control, the default policy is adopted for forwarding, ensuring the basic performance and efficiency of the network.

[0182] Refer to Figure 7, a method for invoking a first policy from associated policies, executing the first policy to obtain an encapsulated SRv6 packet, and forwarding the SRv6 packet, includes:

[0183] A10, invoking a first policy from a target database, the first policy including a default SR policy and a default SID list.

[0184] The default policies have undergone prior testing and verification and can provide a stable operating environment for the network. In most cases, these default policies can meet basic business requirements and reduce the risk of network failures caused by incorrect policy configurations.

[0185] A20, triggering the execution of the end.dt4 SID automatically attached according to EVPN based on the default SR policy to generate an encapsulated SRv6 packet.

[0186] EVPN (Ethernet Virtual Private Network) can automatically attach the end.dt4 SID, which means that network devices do not need to perform a large number of manual configurations. This automation feature reduces the possibility of human errors, speeds up the packet encapsulation process, and improves the efficiency of network deployment. The end.dt4 SID is a standardized mechanism and has good compatibility with the SRv6 (Segment Routing over IPv6) network architecture. By leveraging this feature of EVPN, it can be ensured that the generated SRv6 packets can be smoothly transmitted between network devices of different vendors, enhancing network interoperability. The default SR policy combined with the end.dt4 SID can flexibly encapsulate packets according to the actual situation of the network. It can add necessary information to the packets according to the network topology and business requirements, enabling the packets to accurately find the forwarding path in the SRv6 network.

[0187] A30, forwarding the SRv6 packet based on the default SID list.

[0188] The default SID list defines the forwarding path of the packet. Network devices can directly forward the SRv6 packet to the corresponding destination according to the information in the list. This list-based forwarding method avoids complex routing calculations, reduces the delay in the packet forwarding process, and improves the forwarding efficiency. The default SID list is usually planned according to the overall situation of the network and resource allocation. By forwarding packets according to this list, network bandwidth and device resources can be reasonably utilized, avoiding congestion on certain links or devices due to overuse.

[0189] Refer to Figure 8 , a method for invoking a second policy from associated policies, executing the second policy to obtain an encapsulated SRv6 packet, and forwarding the SRv6 packet, includes:

[0190] B10, Call the second policy from the target database. The second policy is the detailed policy obtained by modifying the SR policy and the SID list according to the preset path requirements of the service message.

[0191] B20, Encapsulate the outer IPv6 header and the SRH SID List for the service message according to the SR policy in the second policy, and set the SL value at the same time to obtain the SRv6 message.

[0192] Among them, the SL (Segment Left) value is used to indicate the segments that the SRv6 message needs to pass through, that is, the SL value represents how many more segments the message needs to pass through to reach the destination; the SL value is the total number of segments in the SID List minus 1.

[0193] B30, Send the SRv6 message to the intermediate node through the service gateway device according to the SID list in the second policy.

[0194] B40, The intermediate node replaces the destination IP of the outer IPv6 header of the SRv6 message according to the SRH SID List, and reduces the SL value by n 1s at the same time to obtain the processed SRv6 message, and sends it to the tail node.

[0195] Among them, n is the number of intermediate nodes;

[0196] B50, The tail node forwards the processed SRv6 message to the firewall attached on the side according to the target SID list; the target SID list includes the specified specific vpn-instance, the outgoing interface name, and the next-hop IP address.

[0197] B60, Perform security checks on the processed SRv6 message through the firewall, and forward the message that passes the security check to the public network exit corresponding to the public network exit router.

[0198] The overall solution executes and forwards the SRv6 message by calling the second policy. From policy calling, message encapsulation to finally passing through the firewall check and forwarding to the public network exit, each step closely cooperates. From the business level, the second policy is the detailed policy obtained by modifying the SR policy and the SID list according to the preset path requirements of the service message. This enables the network to tailor exclusive forwarding paths for different business special requirements, such as video conferencing services with high real-time requirements and file transfer services with high bandwidth requirements, greatly improving the operation effect of the business; when network failures or traffic congestion occur, the SR policy and the SID list in the second policy can be adjusted to quickly re-plan the path for the service message, avoid service interruption, and ensure the continuous and stable operation of critical services.

[0199] From the perspective of network performance, based on the SR policy, the outer IPv6 header and SRH SID List are encapsulated for the packet and the SL value is set, which clarifies the exact forwarding path of the packet. Intermediate nodes only need to perform simple operations based on this information without complex routing calculations, greatly improving the packet forwarding efficiency and reducing the transmission delay. By reasonably designing the SID list, network traffic can be evenly distributed to different links and nodes, avoiding congestion on some links or nodes due to overloading, and enhancing the throughput and performance of the entire network.

[0200] From the perspective of network management, all policies are stored in the target database. Network administrators can manage, modify, and update policies in a unified location, with simple operations, reducing management costs and workload. When the network scale expands or business requirements change, only the second policy in the target database needs to be adjusted without large-scale transformation of the entire network architecture, facilitating network expansion and upgrade.

[0201] From the perspective of security, the processed SRv6 packets are forwarded to the side-mounted firewall for security checks, which can effectively filter malicious traffic such as viruses, Trojans, DDoS attacks, etc., protecting the internal network from external threats and providing strong protection for network security. The target SID list specifies a specific vpn-instance, which can isolate packets of different services in different virtual private networks, preventing interference and data leakage between different services, and further enhancing network security and privacy.

[0202] From the perspective of compatibility, as a standardized network technology, SRv6 has good compatibility with existing IPv6 networks. This solution is designed based on SRv6 and can be easily integrated into existing network infrastructure, reducing the cost of network upgrade and transformation.

[0203] Fourthly, this application discloses a packet forwarding system, which is based on the packet forwarding method disclosed in the third aspect of this application and includes:

[0204] A service gateway device invocation module, which is used to respond to a packet to-be-forwarded instruction and invoke the service gateway device to receive the service packet to be forwarded; the service gateway device is deployed on the service side and supports the SRv6 protocol and the orchestration of the SID list;

[0205] An SDN controller invocation module, which is used to invoke the SDN controller to dynamically obtain service routing information from the edge nodes of the EVPN through the EBGP protocol;

[0206] A distribution module, which is used to convert the service routing information into a target flow table according to the docking protocol, and distribute the target flow table and at least two preset policies in the SDN controller to the service gateway device through the API interface;

[0207] A judgment module, configured to judge service packets based on a preset flow table mechanism, and trigger a service information acquisition instruction when the preset flow table mechanism is met;

[0208] An information acquisition module, configured to acquire service information of a service packet in response to a service information acquisition instruction;

[0209] An analysis module, configured to judge whether a service packet is a packet that needs path control according to the service information. If not, call a first policy from at least two preset policies, execute the first policy to obtain an encapsulated SRv6 packet, and forward the SRv6 packet; if so, call a second policy from at least two preset policies, execute the second policy to obtain an encapsulated SRv6 packet, and forward the SRv6 packet.

[0210] In a fifth aspect, the present application discloses a collaborative management system for SRv6 policies and EVPN automatic SIDs, including a service system, a service gateway device, an SDN controller, several intermediate node routers, an egress node router, and a side-hung firewall. The service system is communicatively connected to the service gateway device, and the SDN controller is communicatively connected to one or more of the several intermediate node routers; one or more of the several intermediate node routers are communicatively connected to the egress node router; the egress node router is communicatively connected to the side-hung firewall.

[0211] Among them, the service system is used to initiate a packet forwarding instruction.

[0212] The SDN controller is configured to configure at least two SR policies and policies associated with the service attributes of the packets to be forwarded, dynamically obtain service routing information from the intermediate node routers corresponding to EVPN through the EBGP protocol, convert the service routing information into a target flow table according to the docking protocol, and send the target flow table and the associated policies to the service gateway device through the API interface.

[0213] The service gateway device is configured to judge the received service packets based on a preset flow table mechanism, acquire the service information of the service packets when the preset flow table mechanism is met, judge whether the service packets are packets that need path control according to the service information, and trigger the execution of corresponding policies according to different judgment results.

[0214] Refer to Figure 9, the figure shows a schematic diagram of the collaborative management system of SRv6 policy and EVPN automatic SID in the firewall bypass networking scenario. After all connections of the service gateway device are deployed, when the EBGP neighbor of the SDN controller 300 and the edge node of the EVPN is established, it will automatically execute the dynamic acquisition of routing information from the edge node of the EVPN (in this embodiment, the intermediate node router 400) through the EBGP protocol, and convert the routing information into a flow table according to the docking protocol; then it can automatically trigger the execution of the distribution operation according to the set period or increment, that is, the flow table can be distributed to the target database of the service gateway device through the standard API interface.

[0215] The business system 100 wants to send a message. When receiving a message to be forwarded instruction, it calls the business gateway device 200 to receive the business message to be forwarded, and judges the business message based on the preset flow table mechanism in the business gateway device 200. When it meets the preset flow table mechanism, it triggers the business information acquisition instruction, which specifically includes: obtaining the destination IP address of the business message, obtaining (i.e., querying) the target table entry corresponding to the target flow table based on the destination IP address, and judging whether the target table entry is complete (i.e., whether there is a destination IP address, a next-hop address, and an outbound interface name). If so, triggering the business information acquisition instruction; if not, the destination IP The address is reported to the SDN controller 300, and a query request is initiated; the SDN controller responds to the received signal of the query request, calls the global routing information base, and then queries whether there is legal forwarding information corresponding to the destination IP address in the global routing information base. If so, the legal forwarding information corresponding to the destination IP address is obtained from the global routing information base and converted into an incremental flow table; if not, an incremental flow table pointing to NULL0 (black hole) is generated for the destination IP address, and the incremental flow table is sent to the service gateway device through the SDN controller. The service gateway device responds to the received signal of the incremental flow table and triggers the service information acquisition instruction.

[0216] In the service gateway device, in response to the service information acquisition instruction, the service information of the service message is obtained, and whether the service message is a message that needs path control is determined according to the service information. If so, a target policy is called from at least two preset policies, and the target policy includes a target SR policy and a target SID list. Based on the target SR policy, an outer IPv6 header and an SRH SID List are encapsulated for the service message, and an SL value is set at the same time to obtain an SRv6 message;

[0217] Then, forward the SRv6 packet according to the target SID list, specifically: send the SRv6 packet to the intermediate node router 400 through the service gateway device. The intermediate node router replaces the destination IP of the outer IPv6 header of the SRv6 packet according to the SRH SID List, and at the same time reduces the SL value by n 1s to obtain the processed SRv6 packet, and sends it to the tail node router 500; where n is the number of intermediate nodes; the tail node router forwards the processed SRv6 packet to the side-mounted firewall 600 according to the target SID list; the target SID list includes specifying a specific vpn-instance, the outgoing interface name, and the next-hop IP address; perform a security check on the processed SRv6 packet through the side-mounted firewall 600, and forward the packet that passes the security check to the public network egress router (i.e., the tail node router 500), and forward it to the corresponding public network egress ISP through the public network egress router (i.e., the tail node router 500).

[0218] In the side-mounted networking scenario, the public network egress router and the SRv6 tail node router are the same network device.

[0219] In the prior art, in order to reduce the operation and maintenance difficulty and configuration complexity, the firewall is often connected in series in the network, such as between different routers, or between the egress router and the operator router, or between the router and the switch. However, such a setting is not convenient for the horizontal expansion of the firewall, and will make the firewall become the bandwidth bottleneck of the entire network, resulting in slow network speed; therefore, in order to enable the capacity of the firewall to be smoothly horizontally expanded and to bypass the firewall for traffic in necessary cases, the side-mounted setting of the firewall is proposed. However, in the side-mounted setting, the traffic of the router needs to be diverted to the firewall. The current mainstream solution is to divert traffic through policy routing, which is complex to set up and maintain. Therefore, SRv6 technology is used for diversion.

[0220] However, after adopting the SRv6 technology, in the business scenario, the user's expectation is that the traffic starts from the source node, passes through the SRv6 path, and at a certain node, the traffic is directed to the firewall using the end.dx4 SID. After the firewall processes it, the traffic then enters the public network exit. However, since the SID list automatically issued by EVPN compulsorily includes the end.dt4 SID, and the end.dt4 SID is usually the last hop of the SID list (that is, according to the specification of RFC 8986, the role of the end.dt4 SID is to divert the traffic from the IPv6 domain to the IPv4 domain, so it is usually placed at the end of the SID list), the actual path of the traffic becomes: the traffic passes through the SRv6 path. Since the end.dt4 SID is placed at the end, the traffic is directly directed to the public network exit without passing through the firewall expected by the user. Therefore, this will cause the traffic not to pass through the security check of the firewall, and the functions of the firewall (such as intrusion detection, policy filtering, etc.) cannot take effect, and the end.dx4 SID set by the user does not play the expected forwarding role.

[0221] The packet forwarding method disclosed in this application has good flexibility. By flexibly combining service characteristics and the SID list on the SDN control, SRv6 policies suitable for various scenarios and meeting various requirements can be flexibly combined. Based on the SRv6 policies, flexible control of the traffic forwarding path can be achieved, avoiding the problem that the default and unchangeable rules of control layer protocols such as EVPN lead to uncontrollable traffic forwarding paths.

[0222] The packet forwarding method disclosed in this application has good compatibility. This solution does not need to modify the protocol specification of RFC 8986, nor does it need to modify the implementation methods of the operating systems (OS) of each device manufacturer, and can be compatible with different manufacturers and different models of communication devices that support SRv6.

[0223] The packet forwarding method disclosed in this application has high reliability. The SDN controller and the EVPN edge node synchronize routes in real time through EBGP. At the same time, a double query and confirmation mechanism is set between the service gateway and the SDN controller to ensure the information synchronization between the service gateway and the SDN controller, avoid the occurrence of unreasonable traffic black holes, and improve the overall reliability of the system.

[0224] The computer device according to an embodiment of the present disclosure includes a memory and a processor. The memory is used to store non-temporary computer-readable instructions. Specifically, the memory may include one or more computer program products, and the computer program products may include various forms of computer-readable storage media, such as volatile memory and / or non-volatile memory. The volatile memory may include, for example, random access memory (RAM) and / or cache memory, etc. The non-volatile memory may include, for example, read-only memory (ROM), hard disk, flash memory, etc.

[0225] The processor may be a central processing unit (CPU) or other forms of processing units with data processing capabilities and / or instruction execution capabilities, and may control other components in the computer device to perform desired functions. In one embodiment of the present disclosure, the processor is used to run the computer-readable instructions stored in the memory, so that the computer device executes all or part of the steps of the message forwarding method in the foregoing embodiments of the present disclosure.

[0226] Those skilled in the art should understand that, in order to solve the technical problem of how to obtain good user experience effects, this embodiment may also include well-known structures such as communication buses and interfaces, and these well-known structures should also be included in the protection scope of the present disclosure.

[0227] As Figure 10 FIG. is a schematic structural diagram of a computer device provided by an embodiment of the present disclosure. It shows a schematic structural diagram of a computer device suitable for implementing the computer device in the embodiments of the present disclosure. Figure 10 The shown computer device is only an example and should not impose any limitations on the functions and usage scope of the embodiments of the present disclosure.

[0228] As Figure 10 As shown, the computer device may include a processor (such as a central processing unit, a graphics processing unit, etc.), which may perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) or a program loaded from a storage device into a random access memory (RAM). In the RAM, various programs and data required for the operation of the computer device are also stored. The processor, ROM, and RAM are connected to each other through a bus. An input / output (I / O) interface is also connected to the bus.

[0229] Generally, the following devices may be connected to the I / O interface: an input device including, for example, a sensor or a visual information acquisition device; an output device including, for example, a display screen; a storage device including, for example, a magnetic tape, a hard disk, etc.; and a communication device. The communication device may allow the computer device to communicate with other devices (such as edge computing devices) wirelessly or wiredly to exchange data. Although Figure 10 the shown computer device has various devices, it should be understood that it is not required to implement or include all the shown devices. More or fewer devices may be alternatively implemented or included.

[0230] In particular, according to embodiments of the present disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments of the present disclosure include a computer program product comprising a computer program carried on a non-transitory computer-readable medium, the computer program including program code for performing the methods shown in the flowcharts. In such an embodiment, the computer program can be downloaded and installed from a network via a communication device, or installed from a storage device, or installed from a ROM. When the computer program is executed by a processor, all or part of the steps of the message forwarding method according to embodiments of the present disclosure are performed.

[0231] For a detailed description of this embodiment, reference may be made to the corresponding descriptions in the foregoing embodiments, and details will not be repeated herein.

[0232] A computer-readable storage medium according to an embodiment of the present disclosure stores non-transitory computer-readable instructions. When the non-transitory computer-readable instructions are run by a processor, all or part of the steps of the message forwarding methods according to the foregoing embodiments of the present disclosure are performed.

[0233] The above-mentioned computer-readable storage media include, but are not limited to: optical storage media (e.g., CD-ROMs and DVDs), magneto-optical storage media (e.g., MOs), magnetic storage media (e.g., magnetic tapes or external hard drives), media with built-in rewritable non-volatile memories (e.g., memory cards), and media with built-in ROMs (e.g., ROM cartridges).

[0234] For a detailed description of this embodiment, reference may be made to the corresponding descriptions in the foregoing embodiments, and details will not be repeated herein.

[0235] The basic principles of the present disclosure have been described above in conjunction with specific embodiments. However, it should be noted that the advantages, benefits, effects, etc. mentioned in the present disclosure are only examples and not limitations, and it cannot be considered that these advantages, benefits, effects, etc. are essential for each embodiment of the present disclosure. Additionally, the above-disclosed specific details are for illustrative and easy-to-understand purposes only and not limitations, and the present disclosure is not limited to implementing with the above specific details.

[0236] In this disclosure, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. The block diagrams of devices, apparatuses, equipment, and systems involved in this disclosure are only illustrative examples and do not intend to require or imply that they must be connected, arranged, and configured in the manner shown in the block diagrams. As those skilled in the art will recognize, these devices, apparatuses, equipment, and systems can be connected, arranged, and configured in any way. Words such as "including", "comprising", "having", etc. are open-ended words, meaning "including but not limited to", and can be used interchangeably with each other. The words "or" and "and" used herein refer to the word "and / or", and can be used interchangeably with each other, unless the context clearly indicates otherwise. The word "such as" used herein refers to the phrase "such as but not limited to", and can be used interchangeably with each other.

[0237] In addition, as used herein, the "or" used in the listing of items starting with "at least one" indicates a separate listing, so that for example, the listing of "at least one of A, B, or C" means A or B or C, or AB or AC or BC, or ABC (i.e., A and B and C). Furthermore, the term "exemplary" does not mean that the described examples are preferred or better than other examples.

[0238] It should also be noted that in the systems and methods of this disclosure, each component or each step can be decomposed and / or recombined. These decompositions and / or recombinations should be regarded as equivalent solutions of this disclosure.

[0239] Various changes, substitutions, and alterations to the technologies described herein can be made without departing from the teachings defined by the appended claims. In addition, the scope of the claims of this disclosure is not limited to the specific aspects of the processes, machines, manufactures, compositions of events, means, methods, and acts described above. Current or later-developed processes, machines, manufactures, compositions of events, means, methods, or acts that perform substantially the same function or achieve substantially the same result as the corresponding aspects described herein can be utilized. Accordingly, the appended claims include such processes, machines, manufactures, compositions of events, means, methods, or acts within their scope.

[0240] The above description of the disclosed aspects is provided to enable any person skilled in the art to make or use this disclosure. Various modifications to these aspects will be readily apparent to those skilled in the art, and the general principles defined herein can be applied to other aspects without departing from the scope of this disclosure. Therefore, this disclosure is not intended to be limited to the aspects shown herein, but rather to the broadest scope consistent with the principles and novel features disclosed herein.

[0241] The foregoing description has been presented for purposes of illustration and description. In addition, this description is not intended to limit embodiments of the present disclosure to the form disclosed herein. Although several example aspects and embodiments have been discussed above, those skilled in the art will recognize some variations, modifications, alterations, additions, and sub-combinations thereof.

Claims

1. A message forwarding method, characterized in that, Including: In response to the message to be forwarded instruction, call the service gateway device to receive the service message to be forwarded; the service gateway device is deployed on the service side and supports the SRv6 protocol and the orchestration of the SID list; Call the SDN controller to dynamically obtain service routing information from the edge node of the EVPN through the EBGP protocol; Convert the service routing information into a target flow table according to the docking protocol, and send the target flow table and at least two preset policies in the SDN controller to the service gateway device through the API interface; Judge the service message based on the preset flow table mechanism, and when it meets the preset flow table mechanism, trigger the service information acquisition instruction; In response to the service information acquisition instruction, obtain the service information of the service message; When it is judged according to the service information that the service message is a message that needs path control, call the target policy from the at least two preset policies; the target policy includes a target SR policy and a target SID list; Based on the target SR policy, encapsulate an outer IPv6 header and an SRH SID List for the service message, and set the SL value at the same time to obtain an SRv6 message; Forward the SRv6 message according to the target SID list.

2. The message forwarding method according to claim 1, wherein The judging the service message based on the preset flow table mechanism and triggering the service information acquisition instruction when it meets the preset flow table mechanism includes: Call the service gateway device to receive the service message to be forwarded, and obtain the destination IP address of the service message; Obtain the target entry corresponding to the target flow table based on the destination IP address; Judge whether the target entry is complete. If so, trigger the service information acquisition instruction; if not, report the destination IP address to the SDN controller and initiate a query request; In response to the received signal of the query request, call the global routing information library; Query whether there is legal forwarding information corresponding to the destination IP address in the global routing information library. If so, obtain the legal forwarding information corresponding to the destination IP address from the global routing information library and convert it into an incremental flow table; if not, generate an incremental flow table pointing to NULL0 for the destination IP address; Send the incremental flow table to the service gateway device through the SDN controller; In response to the received signal of the incremental flow table, trigger the service information acquisition instruction.

3. The message forwarding method according to claim 1, wherein The service information includes one or more of the source IP address, destination IP address, DSCP value, port number, and protocol type; When it is judged according to the service information that the service message is not a message that needs path control, call the default policy from the at least two preset policies, and the default policy includes a default SR policy and a default SID list; Based on the default SR policy, trigger the execution of generating an encapsulated SRv6 message according to the end.dt4 SID automatically attached by the EVPN; Forward the SRv6 message based on the default SID list.

4. The message forwarding method according to claim 3, wherein The target flow table and the at least two preset policies are both stored in the target database of the service gateway device; When it is determined according to the service information that the service message is a message that requires path control, a target policy is called from the target database; When it is determined according to the service information that the service message is not a message that requires path control, a default policy is called from the target database.

5. The packet forwarding method according to claim 4, wherein At least two SR policies are configured in the SDN controller; at least two of the SR policies include the mapping relationship between different types of service messages and the SRH SID list; The at least two preset policies are policies determined from the at least two SR policies and associated with the service attributes of the service message; The at least two preset policies include a default policy and at least one target policy. The default policy matches the default attributes of the service message through a default route, and the last hop of the SID list in the default policy is the SID corresponding to end.dt4 automatically carried by EVPN; The target policy is a detailed policy obtained by modifying the SR policy and the SID list according to the preset path requirements of the service message.

6. The message forwarding method according to claim 1, wherein Forwarding the SRv6 message according to the target SID list includes: Sending the SRv6 message to an intermediate node through the service gateway device; Replacing the destination IP of the outer IPv6 header of the SRv6 message according to the SRH SID List, and at the same time reducing the SL value by n 1s to obtain the processed SRv6 message, and sending it to the tail node; where n is the number of intermediate nodes; The tail node forwards the processed SRv6 message to the side-mounted firewall according to the target SID list; the target SID list includes specifying a specific vpn-instance, an outgoing interface name, and a next-hop IP address; Performing a security check on the processed SRv6 message through the firewall, and forwarding the message that passes the security check to the public network exit corresponding to the public network exit router.

7. The packet forwarding method according to claim 1, wherein The service gateway device is deployed on the service side and includes: Determining a service gateway device, the physical form of the service gateway device is a general computing power server or a programmable network device, and the service gateway device supports the SRv6 protocol and supports the orchestration of the SID list; Deploying the service gateway device on the service side, and docking the service gateway device with the SDN controller through an API; Configuring the connection between the SDN controller and the edge node of EVPN; Setting the service gateway device as the gateway of the service system; Configuring the communication connection between the service gateway device and the intermediate router.

8. A message forwarding system, characterized in that, Including: A deployment module for deploying a service gateway device on the service side, completely separating the forwarding plane and the control plane, and the service gateway device supports the SRv6 protocol and supports the orchestration of the SID list; An SDN controller module for dynamically obtaining service routing information from the edge node of EVPN through the EBGP protocol, converting the service routing information into a target flow table according to the docking protocol, and sending the target flow table and at least two preset policies that have been configured to the service gateway device through an API interface; A calling module, configured to call a service gateway device to receive a service message to be forwarded in response to a message forwarding instruction; A triggering execution module, configured to judge the service message based on a preset flow table mechanism, and when the preset flow table mechanism is met, trigger a service information acquisition instruction, and acquire service information of the service message in response to the service information acquisition instruction; A calling module, configured to call a target policy from the at least two preset policies when judging that the service message is a message that requires path control according to the service information; the target policy includes a target SR policy and a target SID list; An encapsulation module, configured to encapsulate an outer IPv6 header and an SRH SIDList for the service message based on the target SR policy, and set an SL value at the same time to obtain an SRv6 message; A forwarding module, configured to forward the SRv6 message according to the target SID list.

9. The message forwarding system according to claim 8, wherein It further includes a first configuration module and a second configuration module; The first configuration module is configured to configure at least two SR policies in the SDN controller; the at least two SR policies include the mapping relationship between different types of service messages and the SRH SID list; The second configuration module is configured to determine a policy associated with the service attribute of the service message from the at least two SR policies; the at least two preset policies include a default policy and at least one target policy, the default policy matches the default attribute of the service message through a default route, and the last hop of the SID list in the default policy is the SID corresponding to end.dt4 automatically carried by EVPN; the target policy is a detailed policy including a modified target SR policy and a target SID list.

10. A message forwarding method, characterized in that, It includes: Deploy a service gateway device on the service side; The service gateway device supports the SRv6 protocol and supports the orchestration of the SID list; In response to a message forwarding instruction, call a service gateway device to receive a service message to be forwarded; Call the SDN controller, dynamically obtain service routing information from the edge node of EVPN through the EBGP protocol, and convert the service routing information into a target flow table according to the docking protocol; According to the service attribute of the message to be forwarded, obtain a policy associated with the service attribute from the SDN controller, and send the target flow table and the associated policy to the service gateway device through the API interface; Judge the service message based on a preset flow table mechanism, and when the preset flow table mechanism is met, trigger a service information acquisition instruction; Acquire service information of the service message in response to the service information acquisition instruction; Judge whether the service message is a message that requires path control according to the service information. If not, call a first policy from the associated policies, execute the first policy to obtain an encapsulated SRv6 message and forward the SRv6 message; If so, call a second policy from the associated policies, execute the second policy to obtain an encapsulated SRv6 message and forward the SRv6 message.

11. The packet forwarding method according to claim 10, wherein The associated policies are stored in the target database of the service gateway device; Invoking the first policy from the associated policies, executing the first policy to obtain the encapsulated SRv6 packet and forwarding the SRv6 packet includes: Invoking the first policy from the target database, where the first policy includes a default SR policy and a default SID list; Triggering the execution of the end.dt4 SID automatically attached according to EVPN based on the default SR policy to generate an encapsulated SRv6 packet; Forwarding the SRv6 packet based on the default SID list.

12. The packet forwarding method according to claim 11, wherein Invoking the second policy from the associated policies, executing the second policy to obtain the encapsulated SRv6 packet and forwarding the SRv6 packet includes: Invoking the second policy from the target database, where the second policy is a detailed policy obtained by modifying the SR policy and the SID list according to the preset path requirement of the service packet; Encapsulating an outer IPv6 header and an SRH SID List for the service packet according to the SR policy in the second policy, and setting the SL value at the same time to obtain an SRv6 packet; Wherein, the SL value is used to indicate the segments that the SRv6 packet needs to pass through; Sending the SRv6 packet to an intermediate node through the service gateway device according to the SID list in the second policy; Replacing the destination IP of the outer IPv6 header of the SRv6 packet according to the SRH SID List, and reducing the SL value by n 1s at the same time to obtain the processed SRv6 packet, and sending it to the tail node; where n is the number of intermediate nodes; The tail node forwards the processed SRv6 packet to the side-mounted firewall according to the SID list; the SID list includes specifying a specific vpn-instance, an outgoing interface name, and a next-hop IP address; Performing a security check on the processed SRv6 packet through the firewall, and forwarding the packet that passes the security check to the public network exit corresponding to the public network exit router.

13. A collaborative management system for SRv6 policies and EVPN automatic SIDs, characterized in that, Including a service system, a service gateway device, an SDN controller, several intermediate node routers, an exit node router, and a side-mounted firewall. The service system is communicatively connected to the service gateway device, and the SDN controller is communicatively connected to one or more of the several intermediate node routers; one or more of the several intermediate node routers are communicatively connected to the exit node router; The exit node router is communicatively connected to the side-mounted firewall; The service system is used to initiate a packet forwarding instruction; The SDN controller is used to configure at least two SR policies and policies associated with the service attributes of the packet to be forwarded, to dynamically obtain service routing information from the intermediate node router corresponding to EVPN through the EBGP protocol, to convert the service routing information into a target flow table according to the docking protocol, and to send the target flow table and the associated policies to the service gateway device through the API interface; The service gateway device is used to judge the received service packets based on a preset flow table mechanism. When the preset flow table mechanism is met, the service information of the service packets is obtained, and it is judged whether the service packets are packets that need path control according to the service information, and corresponding policies are triggered and executed according to different judgment results.

14. A computer device, characterized in that, The computer device includes: at least one processor; and, a memory communicatively connected to the at least one processor; wherein, the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the packet forwarding method according to any one of claims 1-7 or any one of claims 10-12.

15. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions for causing a computer to execute the packet forwarding method according to any one of claims 1-7 or any one of claims 10-12.

16. A computer program product, comprising computer instructions, characterized in that, When the computer instructions are executed by a processor, the steps of the method according to any one of claims 1-7 or any one of claims 10-12 are implemented.

Citation Information

Patent Citations

  • Service flow forwarding method and device based on 5G core network, and equipment

    CN113676959A

  • SFC path change scheme based on SRV6

    CN119155244A