Method and equipment for realizing service chain pseudo proxy
By setting the correspondence between the pseudo-proxy segment identification SID and the virtual firewall IP address on the smart network card, the packet discarding problem during virtual firewall migration is solved, and the pseudo-proxy function of the virtual firewall is realized to ensure the continuity and security of network communication.
Patent Information
- Application Number
- CN202510397869.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-28
- Publication Date
- 2025-07-04
- Estimated Expiration
- 2045-03-28
AI Technical Summary
In the SRv6 SFC network, when the virtual firewall is migrated, the source node cannot be sensed in time, resulting in the SRv6 packets being continuously discarded, affecting network communication.
Set the correspondence between the pseudo-proxy segment identification SID and the virtual firewall IP address on the smart network card, generate flow table entries by identifying the SID list of SRv6 messages, encapsulate cache SRH headers, and stripping the SRH headers to send the message to the virtual firewall to realize the pseudo-proxy function.
It realizes that the virtual firewall does not need to support SRV6 and the service chain during the migration process, ensures secure message exchange, avoids message discarding, and maintains network communication continuity.
Smart Images

Figure CN120263464A_ABST
Abstract
Description
Technical Field
[0001] This application relates to service chain technology, and more specifically, to a method and device for implementing a service chain pseudo-proxy. Background Art
[0002] SRv6 SFC (Service Function Chain, service chain based on SRv6) uses SRv6 TE Policy to orchestrate the forwarding path of service packets. By encapsulating the path information of SRv6 TE Policy in the original packet, the packet is guided to pass through each service node in sequence according to the specified path. The service nodes supported by SRv6 SFC include firewall (FW), intrusion prevention system (IPS), load balancing (LB) device, address translation (NAT) device, etc.
[0003] The SRv6 SFC network consists of SC (Service Classifier, service classification node), SFF (Service Function Forwarder, service chain forwarding node), SF (Service Function, service node), and Tail Endpoint (tail node) nodes, and is used to guide specific user service packets to the specified service node for processing and forward them to the destination.
[0004] SC is the source node located at the edge of the SRv6 SFC network, and the service packet is drained to SRv6 TE Policy for forwarding by creating SRv6 TE Policy. SF provides a certain type of application service, such as services like firewall, load balancing, address translation, etc. SF can be a physical device or a virtual device. As an agent of SF, SFF forwards the received packet to the SF associated with the SRv6 SID of the packet for processing. SF returns the processed packet to SFF, and SFF decides whether to continue forwarding the packet. Tail Endpoint is the tail node of the SRv6 SFC network, that is, the destination node of SRv6 TE Policy.
[0005] In the SRv6 SFC network, the virtual firewall acting as SF performs security authentication on the SRv6 sent from the source node to the tail node. However, when the virtual firewall migrates to other servers, it cannot be detected by SC until the routing protocol notifies SC of the virtual firewall. Before that, the SRv6 packets sent to the virtual firewall are continuously discarded. Summary of the Invention
[0006] The purpose of this application is to provide a method and device for implementing a service chain pseudo-proxy, and implement the service chain pseudo-proxy on the intelligent network card of the server.
[0007] To achieve the above object, the present application provides a method for implementing a service chain pseudo-proxy. The method includes setting the correspondence between the pseudo-proxy segment identifier SID and the virtual firewall IP address on the smart network card, where the virtual network card is located on the server carrying the virtual firewall; receiving an SRv6 packet from the service chain interface; identifying that the SID list of the received SRv6 packet contains the pseudo-proxy SID to generate a flow table entry; where the matching item is the packet feature information of the outer MAC header of the SRv6 packet; the action item is encapsulating the SRH header of the cached SRv6 packet; based on the SID list of the SRv6 packet containing the pseudo-proxy SID, finding the IP address of the virtual firewall; stripping off and caching the SRH header of the SRv6 packet, and sending the SRv6 packet to the virtual firewall.
[0008] To achieve the above object, the present application further provides a device for implementing a service chain pseudo-proxy. The device includes a processor and a memory; the memory is used to store processor-executable instructions; wherein, the processor is configured to perform the following operations by running the processor-executable instructions in the memory: setting the correspondence between the pseudo-proxy segment identifier SID and the virtual firewall IP address, where the virtual network card is located on the server carrying the virtual firewall; receiving a first SRv6 packet from the service chain interface; identifying that the SID list of the received first SRv6 packet contains the pseudo-proxy SID; generating a first flow table entry; where the matching item is the packet feature information of the outer MAC header of the first SRv6 packet; the action item is encapsulating the SRH header of the cached first SRv6 packet; based on the SID list of the first SRv6 packet containing the pseudo-proxy SID, finding the IP address of the virtual firewall; stripping off and caching the first SRH header of the first SRv6 packet, and sending the first SRv6 packet to the virtual firewall.
[0009] In the present application, the smart network card of the virtual firewall server serves as an application service node capable of identifying SRv6 packets. The virtual firewall does not need to support SRV6 or service chain, and can perform secure packet exchange without changing the processing flow of the SFF in the service chain. BRIEF DESCRIPTION OF THE DRAWINGS
[0010] Figure 1 It is a schematic diagram of an embodiment of the method for implementing a service chain pseudo-proxy provided by the present application;
[0011] Figure 2 It is a schematic diagram of the service chain provided by the present application;
[0012] Figure 3 It is a schematic diagram of the security authentication of the virtual firewall of the service chain provided by the present application;
[0013] Figure 4 It is a schematic diagram of the security authentication of the virtual firewall after migration of the service chain provided by the present application;
[0014] Figure 5 Schematic diagram of the device for implementing the service chain pseudo proxy provided by this application. Detailed implementation mode
[0015] Multiple examples shown in multiple attached drawings will be described in detail. In the following detailed description, multiple specific details are used to provide a comprehensive understanding of this application. Known methods, steps, components, and circuits are not described in detail in the examples to avoid making these examples difficult to understand.
[0016] Among the terms used, the term "including" means including but not limited to; the term "containing" means including but not limited to; the terms "above", "within", and "below" include the number itself; the terms "greater than" and "less than" do not include the number itself. The term "based on" means at least based on a part of it.
[0017] Figure 1 Schematic diagram of the method embodiment for implementing the service chain pseudo proxy provided by this application; this embodiment is used to implement the service chain pseudo proxy by the smart network card of the server. This embodiment includes,
[0018] Step 101, set the correspondence between the pseudo proxy segment identifier SID and the virtual firewall IP address on the smart network card. The virtual network card is located on the server carrying the virtual firewall;
[0019] Step 102, the smart network card receives the SRv6 packet from the service chain interface;
[0020] Step 103, the smart network card identifies that the SID list of the received SRv6 packet contains the pseudo proxy SID and generates a flow table entry; the matching item is the packet feature information of the outer MAC header of the SRv6 packet; the action item is to encapsulate the SRH header of the cached SRv6 packet;
[0021] Step 104, step 101, the smart network card finds the IP address of the virtual firewall based on the SID list of the SRv6 packet containing the pseudo proxy SID;
[0022] Step 105, strip off and cache the SRH header of the SRv6 packet, and send the SRv6 packet to the virtual firewall.
[0023] Figure 1 The beneficial effect of the embodiment is that the smart network card of the virtual firewall server, as an application service node capable of identifying SRv6 packets, the virtual firewall does not need to support SRV6, nor does it need to support the service chain, and performs secure packet exchange without changing the processing flow of the SFF in the service chain.
[0024] Figure 2 Service chain schematic diagram provided by this application;
[0025] Figure 2 Among them, the intelligent network card 21a of server 21 and the intelligent network card 22b of server 22 are service nodes that can identify application service nodes.
[0026] The virtualization management platforms of servers 21 and 22 ( Figure 2 not shown in the figure) configure SID a1 as the redirection SID for the intelligent network card 21a and configure SID b1 as the redirection SID for the intelligent network card 22b, respectively, for encapsulating the outer redirection SRH header.
[0027] The virtualization management platform advertises SID a1 and SID b1 to the intelligent network cards 21a and 22b.
[0028] The virtualization management platform advertises the IP address IP27 of the virtual firewall 27 and the corresponding End.AM SID 24 to the intelligent network card 21a. The intelligent network card 21a records the correspondence between End.AM SID 24 and the IP address of the virtual firewall 27.
[0029] The End.AM SID is a pseudo-proxy SID and the corresponding forwarding action is: SFF24 first modifies the destination address of the SRv6 packet to the first SID value in the SRH, i.e., SRH[0], and then forwards it according to the outgoing interface associated with the End.AM SID; when SFF receives the SRv6 of the application service node (the intelligent network cards 21a and 22b in this application), it restores the outer destination IP address according to the SID list of the SRH header of the SRv6 packet and SL (Segment Left), and forwards the packet according to the normal SRv6 packet forwarding process.
[0030] Figure 3 It is a schematic diagram of the security authentication of the virtual firewall in the service chain provided by this application;
[0031] The source node 23 receives the original IP packet of the user network and encapsulates it as an SRv6 packet according to the matched SRv6 TE Policy; among them, the outer destination IP address of the SRv6 packet is the End.AM SID of SFF24. In the SRH header, the SID list includes: Segment list[0]=End.DT4 SID 26, Segment list[1]=End.X SID 25, Segment list[2]=End.AM SID 24; SL = 2.
[0032] The SFF24 receives an SRv6 packet. By looking up the Local SID table, it finds that the destination address is End.AM SID 24. It replaces the outer destination IP address of the SRv6 packet with the last SID in the SRH SID list: End.DT4 SID 26. At the same time, it decrements the SL by 1 to get Segment list[1], and sends the packet from the outgoing interface bound to End.AM SID24 to the smart network card 21a.
[0033] The smart network card 21a receives the SRv6 packet from the service chain interface of the VLAN to which the outer destination IP address belongs, and recognizes that the SID list in the SRH header of the SRv6 packet contains the pseudo proxy SID End.AM SID 24.
[0034] The smart network card 21a receives the SRv6 packet and issues a flow table entry; the matching item is the packet feature information of the outer MAC header of the SRv6 packet; the action item is to encapsulate the cached SRH header.
[0035] Based on Segment list[2] = End.AM SID 24 in the SID list of the SRv6 packet, the smart network card 21a finds the IP address IP27 of the virtual firewall 27.
[0036] The smart network card 21a strips off the SRH header of the SRv6 packet and caches the stripped SRH header, and sends the SRv6 packet with the SRH header stripped to the IP address IP27 of the virtual firewall 27.
[0037] The virtual firewall 27 performs a security check on the received SRv6 packet. If it determines that there is no threat, it returns the SRv6 packet to the smart network card 21a.
[0038] The smart network card 21a receives the SRv6 packet, finds the matching flow table entry, encapsulates the cached SRH header for the SRv6 packet, repackages it as an SRv6 packet, and sends the SRv6 packet through the service chain interface.
[0039] The SFF24 receives the SRv6 packet through the service chain interface of the VLAN to which the outer IP address belongs. According to the SL value = 1 in the SRH, it restores the destination address of the SRv6 packet to End.X SID 25; thus sending the SRv6 along the path of the SRv6 Policy to the SFF25 and the tail node 26.
[0040] Figure 4 This is a schematic diagram of the security authentication of the virtual firewall after the migration of the service chain provided by this application.
[0041] The virtual firewall 27 is hot migrated to the server 22, and the virtualization management platform notifies the smart network card 21a through a remote call channel (such as an RPC channel).
[0042] The intelligent network card 21a modifies the action of restoring the SRH flow table entry in the Figure 3 embodiment to a redirected reserved SID that redirects to the intelligent network card 22b.
[0043] The intelligent network card 22b records the correspondence between the End.AM SID 24 and the IP address of the virtual firewall 27.
[0044] The virtualization management platform advertises the IP address IP27 of the virtual firewall 27 and the corresponding End.AM SID 24 to the intelligent network card 22b.
[0045] The source node 23 receives the original IP packet of the user network and encapsulates it into an SRv6 packet according to the matched SRv6 TE Policy; among them, the outer destination IP address of the SRv6 packet is the End.AM SID of SFF24. In the SRH header, the SID list includes: Segment list[0]=End.DT4 SID 26, Segment list[1]=End.X SID 25, Segment list[2]=End.AM SID 24; SL = 2.
[0046] The intelligent network card 21a receives the SRv6 packet and finds the modified redirected flow table entry.
[0047] The intelligent network card 21a encapsulates an outer SRH header for the SRv6 packet, learns that the virtual firewall has migrated to server B, adds an SRH header to the packet, and the SID list includes: Segment list[0]=SID22b1, SL = 0; modifies the outer destination IP address of the SRv6 packet to the SID22b1 of the intelligent network card 22b, modifies the VLAN of the SRv6 packet to the redirected VLAN, and sends it to SFF24 through the service connection port within the redirected VLAN; to prevent SFF24 from misjudging that the virtual firewall 27 has completed the security processing when receiving the SRv6 packet.
[0048] SFF24 sends the SRv6 packet to SFF25, and then SFF25 forwards it to the intelligent network card 22b according to the outer destination IP address (SID22b1 of the intelligent network card 22b) of the SRv6 packet.
[0049] The SRv6 packet redirected by the intelligent network card 21a is forwarded through ordinary routing and sent to the intelligent network card 22b via SFF24 and SFF25.
[0050] The intelligent network card 22b receives the SRv6 packet through the service connection port of the redirected VLAN. Based on the Segment list[0] = SID 22b1 in the SID list of the outer SRH header, which is a locally reserved redirection SID, a redirected flow entry is generated. The matching item is the packet feature information of the outer MAC header of the outer SRv6 packet, and the action item is to encapsulate the cached inner SRH header and encapsulate the outer redirected SRH header.
[0051] The intelligent network card 22b looks up the IP address IP27 of the virtual firewall 27 according to the Segment list[2] = End.AMSID 24 in the SID list of the inner SRH header of the SRv6 packet.
[0052] The intelligent network card 22b strips the outer SRH of the SRv6 packet, strips the inner SRH header and caches the stripped inner SRH header, and sends the SRv6 packet with the SRH header stripped to the IP address IP27 of the virtual firewall 27.
[0053] The virtual firewall 27 performs a security check on the received SRv6 packet. If no threat is determined, the SRv6 packet is returned to the intelligent network card 22b.
[0054] The intelligent network card 22b receives the SRv6 packet, looks up the matching redirected flow entry, first encapsulates the cached inner SRH header for the SRv6 packet, and then encapsulates the outer SRH header. The SID list includes: Segment list[0] = SID 22a1, SL = 0; modifies the outer destination IP address of the SRv6 packet to the SID22a1 of the intelligent network card 21a, and sends it to the SFF25 within the redirected VLAN.
[0055] The SFF25 sends the SRv6 packet to the SFF25, and then the SFF25 sends it to the intelligent network card 21a according to the outer destination IP address (SID22b1 of the intelligent network card 22b) of the SRv6 packet.
[0056] The intelligent network card 21a receives the SRV6 packet with a double-layer SRH header at the redirected VLAN service interface, determines that the reserved SID in the outer SRH header is the local redirected reserved SID, identifies the redirected SRv6 packet, strips the outer SRH header, and modifies the outer destination IP address of the SRv6 according to the last SID Segment list[0] = End.DT4 SID 26 of the inner SRH; modifies the VLAN of the SRv6 packet to the VLAN where the outer destination IP address is located, and sends it to the SFF24.
[0057] The SFF24 receives an SRv6 packet. According to the SL value = 1 in the SRH, the destination address of the SRv6 packet is restored to End.XSID 25, and then the SRv6 packet is sent along the path of the SRv6 Policy to SFF25 and the tail node 26.
[0058] After the routing is refreshed, in the SID list of the SRv6 packet encapsulated by the source node 23, Segment list[2] = End.AM SID 25. When SFF25 receives the SRv6 packet and finds that the destination address is End.AM SID25 by looking up the Local SID table, it replaces the outer destination IP address of the SRv6 packet with the last SID in the SRH SID list: End.DT4 SID 26, and at the same time subtracts 1 from SL to get Segment list[0]. Then the packet is sent from the outgoing interface bound to End.AM SID25 to the smart network card 22b. The processing of the smart network card 22b and SFF25 is the same as that of Figure 3 the smart network card 21a and SFF24 in
[0059] When the virtual firewall migrates back from the server 22 to the server 21, the processing of the smart network card 22b and SFF25 is the same as that of Figure 4 the smart network card 21a and SFF24 in Figure 4 and the processing of the smart network card 21a and SFF24 is the same as that of the smart network card 22b and SFF25 in
[0060] Figure 5 FIG. is a schematic diagram of a device for implementing a service chain pseudo proxy provided by this application. The device 50 is applied as a smart network card of a server, and the device includes a processor 51 and a memory 52; the memory 52 is used to store processor-executable instructions; wherein, the processor 51 is used to execute the following operations by running the processor-executable instructions in the memory 52: set the correspondence between the pseudo proxy segment identifier SID and the virtual firewall IP address, and the virtual network card is located on the server carrying the virtual firewall; receive a first SRv6 packet from the service chain interface; identify that the SID list of the received first SRv6 packet contains the pseudo proxy SID; generate a first flow table entry; wherein the matching item is the packet feature information of the outer MAC header of the first SRv6 packet; the action item is to encapsulate the SRH header of the cached first SRv6 packet; based on the fact that the SID list of the first SRv6 packet contains the pseudo proxy SID, find the IP address of the virtual firewall; strip off and cache the first SRH header of the first SRv6 packet, and send the first SRv6 packet to the virtual firewall.
[0061] The processor 51 also performs the following operations by running the processor-executable instructions in the memory 52: receiving a first SRv6 packet returned by the virtual firewall, and finding a matching first flow table entry; encapsulating the first SRv6 packet with the cached first SRH header; and sending the first SRv6 packet through the service chain interface.
[0062] The processor 51 also performs the following operations by running the processor-executable instructions in the memory 52: based on the peer intelligent network card redirection reserved SID of the migrated server of the virtual firewall, modifying the action item of the first flow table entry to redirect to the peer redirection reserved SID; receiving a second SRv6 packet from the service chain interface; finding that the second SRv6 packet matches the first flow table entry, and having a second outer SRH header in the encapsulation of the second SRv6 packet; only setting the peer redirection reserved SID in the second outer SRH header; modifying the outer destination IP address of the second SRv6 packet to the peer redirection reserved SID to which it belongs; modifying the initial VLAN of the second SRv6 packet to the redirected VLAN; and sending the second SRv6 packet through the service chain interface of the redirected VLAN.
[0063] The processor 51 also performs the following operations by running the processor-executable instructions in the memory 52: receiving the second SRv6 packet returned by the redirection through the service connection interface of the redirected VLAN; identifying that the second outer SRH header of the second SRv6 packet returned by the redirection carries the local redirection reserved SID; stripping off the second outer SRH header, and modifying the outer destination IP address of the second SRv6 packet according to the last SID of the SRH header of the second SRv6 packet; replacing the redirected VLAN based on the outer destination IP address of the second SRv6 packet; and sending the second SRv6 packet through the service chain interface.
[0064] The processor 51 also performs the following operations by running the processor-executable instructions in the memory 52: setting the correspondence between the pseudo-agent SID and the migrated virtual firewall IP address on the smart network card; receiving a third SRv6 packet through the service connection port of the redirected VLAN; identifying that the SID list in the outer SRH header of the third SRv6 packet carries a locally reserved redirect SID, generating a second redirect flow table entry, with the matching item being the packet feature information in the outer MAC header of the third SRv6 packet, and the action item being encapsulating the third SRH header of the cached third SRv6 packet and encapsulating an outer redirect SRH header; finding the IP address of the migrated virtual firewall according to the pseudo-agent SID in the SID list in the inner SRH header of the third SRv6 packet, stripping the outer SRH header and the third SRH header of the third SRv6 packet, caching the third SRH header, and sending the SRv6 packet to the migrated virtual firewall; receiving the third SRv6 packet returned by the migrated virtual firewall, finding the matching second flow table entry, and encapsulating the cached third SRH header for the third SRv6 packet; encapsulating a new outer SRH header and only setting the peer redirect reserved SID; the smart network card modifies the outer destination IP address of the third SRv6 packet to the peer redirect reserved SID and sends it through the redirected VLAN service chain interface.
[0065] In this application, the machine-readable storage medium can be any electronic, magnetic, optical, or other physical storage device used to store or contain information (such as executable instructions, data, etc.). For example, any machine-readable storage medium described herein can be any type of random access memory (RAM), volatile memory, non-volatile memory, flash memory, storage drive (such as a hard disk drive), solid-state drive, any type of storage optical disc (such as an optical disc, DVD, etc.), and similar devices, or a combination thereof. Additionally, any machine-readable storage medium described herein can be a non-transitory machine-readable storage medium.
[0066] The above are only the preferred embodiments of this application and are not intended to limit this application. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of this application shall be included within the scope of protection of this application.
Claims
1. A method for implementing a service chain pseudo-proxy, characterized in that, The method includes: Setting the correspondence between the pseudo - proxy segment identifier SID and the virtual firewall IP address on the intelligent network card, where the virtual network card is located on the server hosting the virtual firewall; The intelligent network card receives a first SRv6 packet from the service chain interface; The intelligent network card identifies that the SID list of the received first SRv6 packet contains the pseudo - proxy SID; The intelligent network card generates a first flow entry; Where the matching item is the packet feature information of the outer MAC header of the first SRv6 packet; The action item is to encapsulate the SRH header of the cached first SRv6 packet; Based on the fact that the SID list of the first SRv6 packet contains the pseudo - proxy SID, the intelligent network card finds the IP address of the virtual firewall; Strip off and cache the first SRH header of the first SRv6 packet, and send the first SRv6 packet to the virtual firewall.
2. The method according to claim 1, wherein The method further includes: The intelligent network card receives the first SRv6 packet returned by the virtual firewall and finds the matching first flow entry; The intelligent network card encapsulates the cached first SRH header for the first SRv6 packet; The intelligent network card sends the first SRv6 packet through the service chain interface.
3. The method according to claim 1, wherein The method further includes: Based on the peer intelligent network card redirection reserved SID of the migrated - to server of the virtual firewall, the intelligent network card modifies the action item of the first flow entry to redirect to the peer redirection reserved SID; The intelligent network card receives a second SRv6 packet from the service chain interface; The intelligent network card finds that the second SRv6 packet matches the first flow entry, and the encapsulation of the second SRv6 packet has a second outer - layer SRH header; The second outer - layer SRH header only sets the peer redirection reserved SID; The intelligent network card modifies the outer destination IP address of the second SRv6 packet to the peer redirection reserved SID it belongs to; The intelligent network card modifies the initial VLAN of the second SRv6 packet to the redirection VLAN; The intelligent network card sends the second SRv6 packet through the service chain interface of the redirection VLAN.
4. The method according to claim 3, characterized in that The method further includes: The intelligent network card receives the second SRv6 packet returned by the redirection through the service connection interface of the redirection VLAN; The intelligent network card identifies that the second outer - layer SRH header of the second SRv6 packet returned by the redirection carries the local redirection reserved SID; The intelligent network card strips off the second outer - layer SRH header, and modifies the outer destination IP address of the second SRv6 packet according to the last SID of the SRH header of the second SRv6 packet; Based on the outer destination IP address of the second SRv6 packet, the intelligent network card replaces the redirection VLAN; The intelligent network card sends the second SRv6 packet through the service chain interface.
5. The method according to claim 1, wherein The method further includes: The intelligent network card sets the correspondence between the pseudo - proxy SID and the IP address of the migrated - in virtual firewall on the intelligent network card; The intelligent network card receives a third SRv6 packet through the service connection port of the redirected VLAN; The intelligent network card identifies that the SID list in the outer SRH header of the third SRv6 packet carries a locally reserved redirected SID, generates a second redirected flow table entry, the matching item is the packet feature information of the outer MAC header of the third SRv6 packet, and the action item is to encapsulate the third SRH header of the cached third SRv6 packet and encapsulate an outer redirected SRH header; The intelligent network card finds the IP address of the migrated virtual firewall according to the pseudo-agent SID in the SID list of the inner SRH header of the third SRv6 packet, strips the outer SRH header and the third SRH header of the third SRv6 packet, caches the third SRH header, and sends the SRv6 packet to the migrated virtual firewall; The intelligent network card receives the third SRv6 packet returned by the migrated virtual firewall, finds the matching second flow table entry, and encapsulates the cached third SRH header for the third SRv6 packet; encapsulates a new outer SRH header and only sets the peer redirected reserved SID; The intelligent network card modifies the outer destination IP address of the third SRv6 packet to the peer redirected reserved SID and sends it through the redirected VLAN service chain interface.
6. A device for implementing a service chain pseudo proxy, characterized in that, An intelligent network card for a server, the device includes a processor and a memory; the memory is used to store processor-executable instructions; wherein, the processor is used to execute the following operations by running the processor-executable instructions in the memory: Set the correspondence between the pseudo-agent segment identifier SID and the virtual firewall IP address, and the virtual network card is located on the server carrying the virtual firewall; Receive a first SRv6 packet from the service chain interface; Identify that the SID list of the received first SRv6 packet contains the pseudo-agent SID; Generate a first flow table entry; wherein the matching item is the packet feature information of the outer MAC header of the first SRv6 packet; the action item is to encapsulate the SRH header of the cached first SRv6 packet; Based on the fact that the SID list of the first SRv6 packet contains the pseudo-agent SID, find the IP address of the virtual firewall; Strip the first SRH header of the first SRv6 packet and cache it, and send the first SRv6 packet to the virtual firewall.
7. The device according to claim 6, characterized in that, The processor also executes the following operations by running the processor-executable instructions in the memory: Receive the first SRv6 packet returned by the virtual firewall and find the matching first flow table entry; Encapsulate the cached first SRH header for the first SRv6 packet; Send the first SRv6 packet through the service chain interface.
8. The device according to claim 6, characterized in that, The processor also executes the following operations by running the processor-executable instructions in the memory: Based on the peer intelligent network card redirected reserved SID of the migrated virtual firewall's server, modify the action item of the first flow table entry to redirect to the peer redirected reserved SID; Receive a second SRv6 packet from the service chain interface; It is found that the second SRv6 packet matches the first flow entry, and the encapsulation of the second SRv6 packet has a second outer SRH header; only the peer redirection reserved SID is set in the second outer SRH header. Modify the outer destination IP address of the second SRv6 packet to the peer redirection reserved SID to which it belongs. Modify the initial VLAN of the second SRv6 packet to the redirection VLAN. Send the second SRv6 packet through the service chain interface of the redirection VLAN.
9. The device according to claim 8, characterized in that, The processor also performs the following operations by running the processor-executable instructions in the memory: Receive the second SRv6 packet returned by redirection through the service connection port of the redirection VLAN. Identify that the second outer SRH header of the second SRv6 packet returned by redirection carries the local redirection reserved SID. Strip off the second outer SRH header, and modify the outer destination IP address of the second SRv6 packet according to the last SID of the SRH header of the second SRv6 packet. Replace the redirection VLAN based on the outer destination IP address of the second SRv6 packet. Send the second SRv6 packet through the service chain interface.
10. The device according to claim 6, characterized in that, The processor also performs the following operations by running the processor-executable instructions in the memory: Set the correspondence between the pseudo-agent SID and the migrated virtual firewall IP address on the intelligent network card. Receive the third SRv6 packet through the service connection port of the redirection VLAN. Identify that the SID list of the outer SRH header of the third SRv6 packet carries the local reserved redirection SID, generate a second redirection flow entry, the matching item is the packet feature information of the outer MAC header of the third SRv6 packet, and the action item is to encapsulate the third SRH header of the cached third SRv6 packet and encapsulate the outer redirection SRH header. According to the pseudo-agent SID in the SID list of the inner SRH header of the third SRv6 packet, find the IP address of the migrated virtual firewall, strip off the outer SRH header and the third SRH header of the third SRv6 packet, cache the third SRH header, and send the SRv6 packet to the migrated virtual firewall. Receive the third SRv6 packet returned by the migrated virtual firewall, find the matching second flow entry, encapsulate the cached third SRH header for the third SRv6 packet; encapsulate a new outer SRH header and only set the peer redirection reserved SID. The intelligent network card modifies the outer destination IP address of the third SRv6 packet to the peer redirection reserved SID and sends it through the redirection VLAN service chain interface.
Citation Information
Patent Citations
Method for forwarding message in SRv6 service chain, SFF and SF equipment
CN113691448A
Data transmission method and device, electronic equipment and storage medium
CN114285907A
Message forwarding method and device
CN116418729A
Message forwarding method and equipment
CN116781594A
SRv6 traffic scheduling method and control system based on VPP
CN117376231A