Message forwarding method and device for distributed equipment
By introducing the coordinated processing of sharded reorganization CPU and logical service board in distributed devices, the problem that sharded packets cannot match rules due to memory limitations in traditional forwarding architectures is solved, efficient packet forwarding and resource optimization are achieved, and the performance of the device in a high-load network environment is improved.
Patent Information
- Application Number
- CN202510539226.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-27
- Publication Date
- 2025-07-08
AI Technical Summary
When existing distributed devices deal with sharded packets, due to the memory limitations of the CPU business board and the cumbersome restructuring process, they are unable to effectively process sharded packets, which seriously affects the performance and adaptability in high-load network environments.
Combining the logical service board with a multi-CPU architecture, configuring sharded reorganization CPUs to use large-capacity memory buffers, directly processing sharded message reorganization and rule matching. Non-sanded messages are still processed by the logical service board, optimizing resource usage and forwarding paths.
It improves the processing efficiency and adaptability of distributed devices in complex network environments, solves the rule matching problem caused by memory limitations, and improves the overall forwarding performance and system stability.
Smart Images

Figure CN120281725A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer information processing. Specifically, it relates to a method and device for packet forwarding for distributed devices. Background Art
[0002] Currently, distributed devices usually adopt a collaborative working mode of CPU service boards and logical service boards to process network traffic forwarding. The CPU service board is good at performing complex rule matching operations, but has low forwarding performance; while the logical service board can only process simple rule matching, but has higher forwarding performance. To balance performance and function, in the prior art, usually the logical service board receives and preliminarily judges the packet type, and then forwards the packets that require complex processing to the CPU service board for rule matching. More specifically, the logical service board is responsible for receiving and preliminarily processing data packets, and the CPU service board is specifically responsible for rule matching.
[0003] In the implementation of the prior art, packet processing is as Figure 1 shown. The following are the key steps in the prior art: for fragmented packets, the logical service board will directly send them to the CPU service board for reassembly processing, and after the reassembly is completed, it will be sent back to the logical service board; for non-fragmented packets, the logical service board will establish a session and then forward them to the CPU service board for rule matching.
[0004] This solution has two significant defects: First, since the packet buffer of the CPU service board uses pre-allocated memory with a fixed size (usually limited to about 1500 bytes), it cannot effectively process large fragmented packets that may reach thousands or even tens of thousands of bytes after reassembly; Second, fragmented packets need to go through the cumbersome process of "CPU reassembly, return to the logical board, and then go to the CPU for matching", resulting in low processing efficiency. These technical bottlenecks seriously restrict the processing performance and large packet support ability of distributed devices in high-load network environments.
[0005] Therefore, a new method and device for packet forwarding for distributed devices are needed.
[0006] The above information disclosed in the background art section is only used to enhance the understanding of the background of this application. Therefore, it may include information that does not constitute the prior art known to those of ordinary skill in the art. Summary of the Invention
[0007] In view of this, this application provides a method and device for packet forwarding for distributed devices, which can solve the problem that fragmented large packets cannot match rules due to memory limitations in the traditional forwarding architecture on the premise of ensuring high-performance forwarding, and improve the adaptability and processing efficiency of distributed devices in complex network environments.
[0008] Other features and advantages of the present application will become apparent from the following detailed description, or will be learned in part from the practice of the present application.
[0009] According to one aspect of the present application, a method for forwarding packets for distributed devices is provided. The method includes: a logical service board determines whether a packet to be forwarded is a fragmented packet; when the packet is a fragmented packet, the packet is forwarded to a fragmentation reassembly CPU; the packet is fragmented and reassembled in the fragmentation reassembly CPU; when the packet reassembly is successful, rule matching is performed on the packet; the fragmentation reassembly CPU directly forwards the packet according to the matching result.
[0010] In an exemplary embodiment of the present application, it further includes: when the packet is not a fragmented packet, determining whether there is session information corresponding to the packet in the logical service board; if there is no session information, establishing the session information corresponding to the packet; the logical service board sends the packet to a rule matching CPU for rule matching; receiving the matching result from the rule matching CPU to forward the packet.
[0011] In an exemplary embodiment of the present application, it further includes: if there is session information corresponding to the packet, determining whether the session information includes a forwarding path; when the forwarding path is included, the logical service board forwards the packet according to the forwarding path; when the forwarding path is not included, the logical service board sends the packet to a rule matching CPU for rule matching; receiving the matching result from the rule matching CPU to forward the packet.
[0012] In an exemplary embodiment of the present application, when the packet reassembly is successful, performing rule matching on the packet includes: when the packet reassembly is successful and the total length of the packet is less than a threshold, determining whether there is session information corresponding to the packet in the fragmentation reassembly CPU; if there is session information, the fragmentation reassembly CPU performs rule matching on the packet; if there is no session information, the fragmentation reassembly CPU establishes the session information corresponding to the packet and then performs rule matching on the packet.
[0013] In an exemplary embodiment of the present application, the fragmentation reassembly CPU forwards the packet according to the matching result, including: when a rule is matched, the fragmentation reassembly CPU forwards the packet according to the path corresponding to the matched rule.
[0014] In an exemplary embodiment of the present application, the fragmentation reassembly CPU forwarding the packet according to the matching result further includes: when no rule is matched, the fragmentation reassembly CPU forwards the packet according to a preset special path; or when no rule is matched, the fragmentation reassembly CPU discards the packet.
[0015] In an exemplary embodiment of the present application, sending the message to a rule matching CPU for rule matching includes: determining whether session information corresponding to the message exists in the rule matching CPU; if the session information exists, the rule matching CPU performs rule matching on the message; if the session information does not exist, the rule matching CPU establishes the session information corresponding to the message and then performs rule matching on the message.
[0016] In an exemplary embodiment of the present application, sending the message to a rule matching CPU for rule matching further includes: when a rule is matched, the rule matching CPU notifies the matched rule to the logical service board and forwards the message back to the logical service board.
[0017] In an exemplary embodiment of the present application, sending the message to a rule matching CPU for rule matching further includes: when no rule is matched, the rule matching CPU notifies the logical service board of the unmatched message; the logical service board forwards the message according to a preset special path; or the logical service board discards the message.
[0018] According to one aspect of the present application, there is provided a message forwarding device for a distributed device, the device including: a fragmentation module for the logical service board to determine whether a message to be forwarded is a fragmented message; a reservation module for forwarding the message to a fragmentation and recombination CPU when the message is a fragmented message; a recombination module for performing fragmentation and recombination on the message in the fragmentation and recombination CPU; a matching module for performing rule matching on the message when the message recombination is successful; and a forwarding module for the fragmentation and recombination CPU to forward the message according to the matching result.
[0019] According to one aspect of the present application, there is provided an electronic device, the electronic device including: one or more processors; a storage device for storing one or more programs; when the one or more programs are executed by the one or more processors, enabling the one or more processors to implement the method as described above.
[0020] According to one aspect of the present application, there is provided a computer-readable medium having a computer program stored thereon, and when the program is executed by a processor, the method as described above is implemented.
[0021] The method and apparatus for packet forwarding for distributed devices according to the present application determine whether a packet to be forwarded is a fragmented packet through a logical service board; when the packet is a fragmented packet, forward the packet to a fragmentation and reassembly CPU; perform fragmentation and reassembly on the packet in the fragmentation and reassembly CPU; when the packet reassembly is successful, perform rule matching on the packet; the fragmentation and reassembly CPU directly forwards the packet according to the matching result, which can solve the problem that fragmented large packets cannot match rules due to memory limitations in the traditional forwarding architecture on the premise of ensuring high-performance forwarding, and improve the adaptability and processing efficiency of distributed devices in complex network environments.
[0022] It should be understood that the above general description and subsequent detailed description are exemplary only and do not limit the present application. Brief Description of the Drawings
[0023] By referring to the accompanying drawings and describing its exemplary embodiments in detail, the above and other objects, features, and advantages of the present application will become more apparent. The following described drawings are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0024] Figure 1 is a schematic diagram of packet forwarding for distributed devices in the prior art.
[0025] Figure 2 is a schematic diagram of a method for packet forwarding for distributed devices according to an exemplary embodiment.
[0026] Figure 3 is a flowchart of a method for packet forwarding for distributed devices according to another exemplary embodiment.
[0027] Figure 4 is a flowchart of a method for packet forwarding for distributed devices according to another exemplary embodiment.
[0028] Figure 5 is a flowchart of a method for packet forwarding for distributed devices according to an exemplary embodiment.
[0029] Figure 6 is a block diagram of an apparatus for packet forwarding for distributed devices according to an exemplary embodiment.
[0030] Figure 7 is a block diagram of an electronic device according to an exemplary embodiment.
[0031] Figure 8 is a block diagram of a computer-readable medium according to an exemplary embodiment. Detailed Implementation Modes
[0032] Example embodiments will now be described more fully with reference to the accompanying drawings. However, the example embodiments can be implemented in various forms and should not be construed as limited to the embodiments set forth herein; rather, these embodiments are provided so that this application will be thorough and complete, and will fully convey the concept of the example embodiments to those skilled in the art. Like reference numerals in the figures denote like or similar parts, and thus their repetitive description will be omitted.
[0033] In addition, the described features, structures, or characteristics can be combined in any suitable manner in one or more embodiments. In the following description, numerous specific details are provided to give a thorough understanding of the embodiments of this application. However, those skilled in the art will realize that the technical solutions of this application can be practiced without one or more of the specific details, or other methods, components, devices, steps, etc. can be adopted. In other cases, well-known methods, devices, implementations, or operations are not shown or described in detail to avoid obscuring aspects of this application.
[0034] The block diagrams shown in the drawings are only functional entities and do not necessarily correspond to physically independent entities. That is, these functional entities can be implemented in software form, or in one or more hardware modules or integrated circuits, or in different networks and / or processor devices and / or microcontroller devices.
[0035] The flowcharts shown in the drawings are only illustrative and do not necessarily include all the contents and operations / steps, nor do they necessarily need to be executed in the described order. For example, some operations / steps can be decomposed, while some operations / steps can be combined or partially combined, so the actual execution order may change according to the actual situation.
[0036] It should be understood that although terms such as first, second, and third may be used herein to describe various components, these components should not be limited by these terms. These terms are used to distinguish one component from another. Thus, the first component discussed below can be referred to as the second component without departing from the teachings of the concept of this application. As used herein, the term "and / or" includes any one and all combinations of one or more of the associated listed items.
[0037] Those skilled in the art can understand that the drawings are only schematic diagrams of the example embodiments, and the modules or processes in the drawings are not necessarily essential for implementing this application, so they cannot be used to limit the protection scope of this application.
[0038] The technical abbreviations related to this application are explained as follows:
[0039] Distributed device: In order to break through the upper limit of computing power that a single computer device (centralized device) can achieve, multiple computers are combined into one device in a certain way (physically or logically); a problem with a huge amount of computation is decomposed into multiple sub-problems, which are respectively handed over to multiple members of the device for processing, and after all the computations are completed, a total result is aggregated and returned to the problem submitter. Such a device is called a distributed device, and this computing method is called distributed computing. The computing power of a distributed device is equal to the sum of the computing powers of all member devices (except for a small amount of performance consumed by internal interactions of member devices), so its performance is greatly improved compared to centralized devices. Usually, a frame device is a kind of distributed device.
[0040] Main control board: Used for frame devices, it controls the normal operation of the entire device, uniformly manages the configuration distribution and status display of all boards, and uniformly stores all configuration files of this device. The main control board is equipped with a CPU and a CF card for storing configurations, and is used to control the operation of the entire device. The device requires at least one main control board card to operate normally. Some main control board cards are equipped with switching chips.
[0041] Service board: A board specifically used to process services, such as a CPU service board and a logic service board.
[0042] To solve the problem that the CPU service board in existing distributed devices cannot effectively process large fragmented packets and the performance bottleneck problem, this application proposes an improved multi-CPU packet forwarding architecture. Figure 2 It is a schematic diagram of a packet forwarding method for a distributed device shown according to an exemplary embodiment.
[0043] Specifically, for a service board with multiple CPUs, at least one of the CPUs is configured as a fragmentation and recombination CPU, that is, CPU0 in the figure, which is specifically used to process fragmented packets; the remaining CPUs are kept as rule matching CPUs, that is, CPU1 in the figure, which is used to process ordinary packets. Among them, CPU0 can be pre-allocated a larger memory buffer to support the caching and recombination operations of large-sized fragmented packets, avoiding the problem of recombination failure caused by insufficient memory. The specific capacity of the memory buffer can be set according to the actual size of the processed packets, and this application is not limited thereto.
[0044] During system operation, the logic service board first determines whether the received packet is a fragmented packet: for a fragmented packet, it can be directly forwarded to CPU0, which completes the recombination and rule matching and performs corresponding forwarding operations according to the matching result; for a non-fragmented packet, the logic service board continues to select CPU1 for rule matching according to the original process. This method has high processing efficiency for packets and less resource occupation.
[0045] The solution of this application realizes the classification processing of different types of packets. It not only solves the problem of failed processing of large packets, but also optimizes the usage efficiency of system resources through duty division, improves the overall forwarding performance and system stability, and is especially applicable to network scenarios with high load and large data volume. According to the packet forwarding method for distributed devices of this application, it can solve the problem that fragmented large packets cannot match rules due to memory limitations in the traditional forwarding architecture on the premise of ensuring high-performance forwarding, and improve the adaptability and processing efficiency of distributed devices in complex network environments.
[0046] It should be clearly understood that this application describes how to form and use specific examples, but the principles of this application are not limited to any details of these examples. On the contrary, based on the teachings of the content disclosed in this application, these principles can be applied to many other embodiments.
[0047] Figure 3 It is a flowchart of a packet forwarding method for distributed devices shown according to an exemplary embodiment. The packet forwarding method 30 for distributed devices is a detailed description of the working process of the logical service board in this application.
[0048] As Figure 3 shown, in S302, receive a packet. The logical service board receives a data packet from the network and triggers the packet processing process.
[0049] In S304, determine whether the packet is a fragmented packet. The logical service board parses the received packet and determines whether the packet is an IP fragmented packet. It can be identified by detecting the flag bit or specific field in the packet header.
[0050] If the judgment result is "yes", that is, the packet is a fragmented packet, then execute step S306;
[0051] If the judgment result is "no", that is, the packet is a non-fragmented packet, then execute step S308.
[0052] In S306, if it is a fragmented packet, then forward the packet to CPU0 for processing. To address the problem of processing large packets after fragmented packet recombination, the system is pre-configured with a CPU (such as CPU0) dedicated to fragmented packet recombination and rule matching. The logical service board sends the fragmented packet to CPU0, which completes the processing processes such as caching, recombination, and rule matching.
[0053] In S308, if it is not a fragmented packet, determine whether there is session information. For non-fragmented packets, the logical service board first checks whether there is corresponding session information for the five-tuple to which the packet belongs in the local session table.
[0054] If there is session information, then continue to execute step S310;
[0055] If there is no session information, step S316 is executed.
[0056] In S310, if there is session information, it is determined whether there is a forwarding path. If there is corresponding session information in the logical service board, it is further determined whether a valid forwarding path has been recorded for this session.
[0057] If there is a valid forwarding path, step S314 is executed;
[0058] In S312, if the forwarding path has not been recorded yet, the packet needs to be forwarded to CPU1 for rule matching.
[0059] In S314, if there is a forwarding path, it is directly forwarded. It is directly forwarded from the preset port. When there is already a forwarding path in the session information, the logical service board directly sends the packet from the preset port, completing fast forwarding, avoiding unnecessary re - matching processes, and improving processing efficiency.
[0060] In S316, if there is no session information, a session is established according to the five - tuple, and the packet is forwarded to CPU1 for processing. If there is no session information corresponding to the packet in the logical service board yet, a new session record is created according to the five - tuple information of the packet. At the same time, the packet is sent to the rule - matching CPU (such as CPU1), which completes the rule - matching operation and feeds back the matching result to the logical service board to complete subsequent forwarding.
[0061] Figure 4 It is a flowchart of a packet forwarding method for a distributed device shown according to another exemplary embodiment. Figure 4 The shown process 40 is a detailed description of the working process of the fragmentation and reassembly CPU in this application.
[0062] As Figure 4 shown, in S402, the logical service board obtains the packet.
[0063] In S404, is it a fragmented packet?
[0064] In S406, the packet is reassembled. CPU0 can cache the received fragmented packets and perform the reassembly operation based on the identification field and offset information. After reassembly, a complete original data packet is formed.
[0065] In S408, the reassembly is successful and the total length of the packet is lower than the threshold. After the packet reassembly is completed, it is judged whether its total length exceeds the system - preset processing threshold:
[0066] If it exceeds the threshold, the system considers that this packet does not meet the forwarding requirements or may cause system anomalies, and step S410 is executed;
[0067] If it is lower than or equal to the threshold, continue to step S412.
[0068] In S410, discard. If the total length of the reorganized message is higher than the threshold, the system can actively discard the message to protect the memory and processing resources and avoid the spread of abnormal situations.
[0069] In S412, check if there is session information. Check if there is already a session. If there is no session information, create a new session. Determine whether there is session information corresponding to the message in the system (based on five-tuple matching):
[0070] If there is already session information, skip session establishment and directly enter the rule matching process;
[0071] If not, enter step S414 to establish a new session.
[0072] In S414, establish a session. CPU0 can establish a new session information locally according to the message five-tuple information (source / destination IP, source / destination port, protocol), which can be reused in subsequent processing.
[0073] In S416, perform rule matching. After successful rule matching, store the forwarding path on the session and forward the message out according to the forwarding path.
[0074] In S418, directly forward according to the matched forwarding path. If there is session information, check whether the status of this flow is the known forwarding status. If so, directly send it out according to the forwarding path.
[0075] In S420, forward according to a special path or discard the packet. After failed matching, continue with the subsequent messages of the same flow. If the subsequent N messages cannot be successfully matched, record the status on the session and forward it out according to a specific forwarding path.
[0076] Figure 5 It is a flowchart of a message forwarding method for a distributed device shown according to another exemplary embodiment. Figure 5 The shown process 50 is a detailed description of the working process of the rule matching CPU in this application.
[0077] As Figure 5 shown, in S502, the logical service board obtains the message.
[0078] In S504, check if there is session information. After the rule matching CPU (CPU1) receives the message, it first queries the local session table to determine whether there is already session information corresponding to the message (such as comparison based on five-tuples). It is worth mentioning that there can be multiple CPU1s in the system.
[0079] If there is session information, directly enter the rule matching step S508;
[0080] If there is no session information, step S506 is executed.
[0081] In S506, a session is established. A new session record can be established based on the five-tuple information (source IP, destination IP, source port, destination port, protocol type) of the message to support subsequent rule matching and result caching.
[0082] In S508, rule matching is performed.
[0083] In S510, the forwarding path is notified to the logical service board, and the message is sent back to the logical service board. The forwarding path in the matching result is notified to the logical service board, and the message is also returned to the logical service board, which completes the final forwarding operation according to the path. The matching status and path information are synchronously recorded in the session information to accelerate subsequent message processing.
[0084] In S512, it is notified to the logical service board that this message does not match the rule, and the message is forwarded back to the logical service board. If the rule matching fails, the "not matched" status is notified to the logical service board, and the message is returned. The logical service board can decide whether to discard the message, forward it to the default path, or perform further processing according to the configuration.
[0085] Those skilled in the art can understand that all or part of the steps of implementing the above embodiments are implemented as a computer program executed by a CPU. When the computer program is executed by the CPU, the above functions defined by the above method provided by the present application are executed. The program can be stored in a computer-readable storage medium, and the storage medium can be a read-only memory, a magnetic disk, an optical disk, etc.
[0086] In addition, it should be noted that the above drawings are only schematic illustrations of the processes included in the method according to the exemplary embodiments of the present application, rather than for limiting purposes. It is easy to understand that the processes shown in the above drawings do not indicate or limit the time sequence of these processes. Additionally, it is also easy to understand that these processes can be executed, for example, synchronously or asynchronously in multiple modules.
[0087] The following is an embodiment of the apparatus of the present application, which can be used to execute the method embodiment of the present application. For details not disclosed in the embodiment of the apparatus of the present application, please refer to the method embodiment of the present application.
[0088] Figure 6 is a block diagram of a message forwarding apparatus for a distributed device shown according to another exemplary embodiment. As Figure 6As shown, the packet forwarding device 60 for a distributed device includes: a fragmentation module 602, a reservation module 604, a reassembly module 606, a matching module 608, a forwarding module 610. The packet forwarding device 60 for a distributed device further includes: a rule module 612, a path module 614.
[0089] The fragmentation module 602 is used for the logical service board to determine whether the packet to be forwarded is a fragmented packet;
[0090] The reservation module 604 is used for, when the packet is a fragmented packet, forwarding the packet to the fragmentation and reassembly CPU;
[0091] The reassembly module 606 is used for reassembling the packet in the fragmentation and reassembly CPU;
[0092] The matching module 608 is used for, when the packet reassembly is successful, performing rule matching on the packet; the matching module 608 is further used for, when the packet reassembly is successful and the total length of the packet is less than the threshold, determining whether there is session information corresponding to the packet in the fragmentation and reassembly CPU; if there is session information, the fragmentation and reassembly CPU performs rule matching on the packet; if there is no session information, the fragmentation and reassembly CPU establishes the session information corresponding to the packet and then performs rule matching on the packet.
[0093] The forwarding module 610 is used for the fragmentation and reassembly CPU to forward the packet according to the matching result. The forwarding module 610 is further used for, when a rule is matched, the fragmentation and reassembly CPU to forward the packet according to the path corresponding to the matched rule. The forwarding module 610 is further used for, when no rule is matched, the fragmentation and reassembly CPU to forward the packet according to a preset special path; the forwarding module 610 is further used for, when no rule is matched, the fragmentation and reassembly CPU to discard the packet.
[0094] The rule module 612 is used to determine whether there is session information corresponding to the packet in the logical service board when the packet is not a fragmented packet; if there is no session information, session information corresponding to the packet is established; the logical service board sends the packet to the rule matching CPU for rule matching; and receives the matching result from the rule matching CPU for forwarding the packet. The rule module 612 is also used to determine whether there is session information corresponding to the packet in the rule matching CPU; the rule module 612 is also used that if there is session information, the rule matching CPU performs rule matching on the packet; if there is no session information, the rule matching CPU establishes session information corresponding to the packet and then performs rule matching on the packet. The rule module 612 is also used that when a rule is matched, the rule matching CPU notifies the logical service board of the matched rule and forwards the packet back to the logical service board. The rule module 612 is also used that when no rule is matched, the rule matching CPU notifies the logical service board of the unmatched message; the logical service board forwards the packet according to a preset special path; or the logical service board discards the packet.
[0095] The path module 614 is used that if there is session information corresponding to the packet, it determines whether the session information contains a forwarding path; when the forwarding path is included, the logical service board forwards the packet according to the forwarding path; when the forwarding path is not included, the logical service board sends the packet to the rule matching CPU for rule matching; and receives the matching result from the rule matching CPU for forwarding the packet.
[0096] According to the packet forwarding device for a distributed device of the present application, the logical service board determines whether the packet to be forwarded is a fragmented packet; when the packet is a fragmented packet, the packet is forwarded to the fragmentation and reassembly CPU; the packet is fragmented and reassembled in the fragmentation and reassembly CPU; when the packet reassembly is successful, rule matching is performed on the packet; the fragmentation and reassembly CPU directly forwards the packet according to the matching result, which can solve the problem that fragmented large packets cannot match rules due to memory limitations in the traditional forwarding architecture on the premise of ensuring high-performance forwarding, and improve the adaptability and processing efficiency of the distributed device in a complex network environment.
[0097] Figure 7 It is a block diagram of an electronic device shown according to an exemplary embodiment.
[0098] Next, refer to Figure 7 to describe the electronic device 700 according to this embodiment of the present application. Figure 7 The shown electronic device 700 is only an example and should not bring any limitation to the functions and usage scope of the embodiments of the present application.
[0099] As Figure 7 shown, the electronic device 700 is presented in the form of a general-purpose computing device. The components of the electronic device 700 may include, but are not limited to: at least one processing unit 710, at least one storage unit 720, a bus 730 connecting different system components (including the storage unit 720 and the processing unit 710), a display unit 740, etc.
[0100] Among them, the storage unit stores program code, and the program code can be executed by the processing unit 710, so that the processing unit 710 executes the steps according to various exemplary embodiments of the present application described in this specification. For example, the processing unit 710 can execute as Figure 3 , Figure 4 , Figure 5 shown in.
[0101] The storage unit 720 may include a readable medium in the form of a volatile storage unit, such as a random access storage unit (RAM) 7201 and / or a cache storage unit 7202, and may further include a read-only storage unit (ROM) 7203.
[0102] The storage unit 720 may further include a program / utilities 7204 having a set (at least one) of program modules 7205. Such program modules 7205 include, but are not limited to: an operating system, one or more application programs, other program modules, and program data. Each or some combination of these examples may include the implementation of a network environment.
[0103] The bus 730 may represent one or more of several types of bus structures, including a storage unit bus or a storage unit controller, a peripheral bus, a graphics acceleration port, a processing unit, or a local bus using any bus structure in a variety of bus structures.
[0104] The electronic device 700 can also communicate with one or more external devices 700' (such as a keyboard, a pointing device, a Bluetooth device, etc.), devices that enable a user to interact with the electronic device 700, and / or any device with which the electronic device 700 can communicate with one or more other computing devices (such as a router, a modem, etc.). Such communication can be carried out through the input / output (I / O) interface 750. Also, the electronic device 700 can further communicate with one or more networks (such as a local area network (LAN), a wide area network (WAN), and / or a public network, such as the Internet) through the network adapter 760. The network adapter 760 can communicate with other modules of the electronic device 700 through the bus 730. It should be understood that, although not shown in the figure, other hardware and / or software modules can be used in conjunction with the electronic device 700, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems, etc.
[0105] Through the description of the above embodiments, those skilled in the art can easily understand that the example embodiments described herein can be implemented by software, or by a combination of software and necessary hardware. Therefore, as Figure 8 shown, the technical solutions according to the embodiments of the present application can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, including several instructions to enable a computing device (which can be a personal computer, a server, or a network device, etc.) to execute the above method according to the embodiments of the present application.
[0106] The software product can adopt any combination of one or more readable media. The readable medium can be a readable signal medium or a readable storage medium. The readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples (non-exhaustive list) of the readable storage medium include: an electrical connection with one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.
[0107] The computer-readable storage medium may include a data signal propagated in a baseband or as part of a carrier wave, in which the readable program code is carried. Such a propagated data signal may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the foregoing. The readable storage medium may also be any readable medium other than the readable storage medium, which can send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on the readable storage medium may be transmitted using any appropriate medium, including but not limited to wireless, wired, optical fiber cable, RF, etc., or any suitable combination of the foregoing.
[0108] The program code for performing the operations of this application may be written in any combination of one or more programming languages. The programming languages include object-oriented programming languages such as Java, C++, etc., and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code may be executed entirely on the user computing device, partially on the user device, executed as a stand-alone software package, partially on the user computing device and partially on a remote computing device, or entirely on a remote computing device or server. In the case of a remote computing device, the remote computing device may be connected to the user computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computing device (e.g., by connecting through the Internet using an Internet service provider).
[0109] The above computer-readable medium carries one or more programs. When the above one or more programs are executed by a device, the computer-readable medium realizes the following functions: the logical service board determines whether the packet to be forwarded is a fragmented packet; when the packet is a fragmented packet, the packet is forwarded to the fragmentation and reassembly CPU; the packet is fragmented and reassembled in the fragmentation and reassembly CPU; when the packet reassembly is successful, rule matching is performed on the packet; the fragmentation and reassembly CPU directly forwards the packet according to the matching result.
[0110] Those skilled in the art can understand that the above-mentioned modules can be distributed in the device according to the description of the embodiments, or can be correspondingly changed and uniquely located in one or more devices different from this embodiment. The modules of the above embodiments can be combined into one module, or further split into multiple sub-modules.
[0111] Through the description of the above embodiments, those skilled in the art can easily understand that the exemplary embodiments described herein can be implemented by software or by a combination of software and necessary hardware. Therefore, the technical solutions according to the embodiments of the present application can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on the network, including several instructions to enable a computing device (which can be a personal computer, a server, a mobile terminal, or a network device, etc.) to execute the method according to the embodiments of the present application.
[0112] The exemplary embodiments of the present application have been specifically illustrated and described above. It should be understood that the present application is not limited to the detailed structures, settings, or implementation methods described herein; on the contrary, the present application is intended to cover various modifications and equivalent settings included within the spirit and scope of the appended claims.
Claims
1. A packet forwarding method for distributed devices, characterized in that, including: The logical service board determines whether the packet to be forwarded is a fragmented packet; When the packet is a fragmented packet, forward the packet to the fragmentation reassembly CPU; Perform fragmentation reassembly on the packet in the fragmentation reassembly CPU; When the packet reassembly is successful, perform rule matching on the packet; The fragmentation reassembly CPU directly forwards the packet according to the matching result.
2. The method according to claim 1, characterized in that also including: When the packet is not a fragmented packet, determine whether there is session information corresponding to the packet in the logical service board; If there is no session information, establish the session information corresponding to the packet; The logical service board sends the packet to the rule matching CPU for rule matching; Receive the matching result from the rule matching CPU to forward the packet.
3. The method according to claim 2, wherein also including: If there is session information corresponding to the packet, determine whether the session information contains a forwarding path; When the forwarding path is included, the logical service board forwards the packet according to the forwarding path; When the forwarding path is not included, the logical service board sends the packet to the rule matching CPU for rule matching; Receive the matching result from the rule matching CPU to forward the packet.
4. The method according to claim 1, characterized in that, When the packet reassembly is successful, performing rule matching on the packet includes: When the packet reassembly is successful and the total length of the packet is less than the threshold, determine whether there is session information corresponding to the packet in the fragmentation reassembly CPU; If there is session information, the fragmentation reassembly CPU performs rule matching on the packet; If there is no session information, the fragmentation reassembly CPU establishes the session information corresponding to the packet and then performs rule matching on the packet.
5. The method according to claim 1, wherein The fragmentation reassembly CPU forwards the packet according to the matching result, including: When a rule is matched, the fragmentation reassembly CPU forwards the packet according to the path corresponding to the matched rule.
6. The method according to claim 5, characterized in that, The fragmentation reassembly CPU forwarding the packet according to the matching result further includes: When no rule is matched, the fragmentation reassembly CPU forwards the packet according to a preset special path; or When no rule is matched, the fragmentation reassembly CPU discards the packet.
7. The method according to claim 2, wherein Sending the packet to the rule matching CPU for rule matching includes: Determine whether there is session information corresponding to the packet in the rule matching CPU; If there is session information, the rule matching CPU performs rule matching on the packet; If there is no session information, the rule matching CPU establishes the session information corresponding to the packet and then performs rule matching on the packet.
8. The method according to claim 7, wherein Sending the packet to the rule matching CPU for rule matching further includes: When a rule is matched, the rule matching CPU notifies the logical service board of the matched rule and forwards the packet back to the logical service board.
9. The method according to claim 8, wherein Sending the packet to the rule matching CPU for rule matching further includes: When no rule is matched, the rule matching CPU notifies the logical service board of the unmatched message; The logical service board forwards the packet according to a preset special path; or The logical service board discards the packet.
10. A packet forwarding device for a distributed device, characterized in that including: The sharding module is used for the logical service board to determine whether the packet to be forwarded is a sharded packet; The reservation module is used to forward the packet to the shard recombination CPU when the packet is a sharded packet; The recombination module is used to perform shard recombination on the packet in the shard recombination CPU; The matching module is used to perform rule matching on the packet when the packet recombination is successful; The forwarding module is used for the shard recombination CPU to forward the packet according to the matching result.