ACL-based flexible customized port isolation method, apparatus and device, and medium

Through the ACL-based port isolation method, user-defined fields are set through ACL entries in the incoming and outgoing directions, precise isolation or non-isolation of specific service flows is achieved, which solves the problems of insufficient flexibility and complex configuration in the existing technology, and improves network management efficiency and resource utilization.

CN120301716APending Publication Date: 2025-07-11YUNHE ZHIWANG (SHANGHAI) TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510786241.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-12
Publication Date
2025-07-11

AI Technical Summary

Technical Problem

Existing port isolation technologies have shortcomings in flexibility, configuration complexity and resource limitations, especially in large-scale, high-density network environments, which are difficult to meet demand.

Method used

Using a flexible and customized port isolation method based on ACL, we can realize accurate or non-isolation of specific service flows by receiving messages and setting user-defined fields in ACL entries in the incoming and outgoing directions, and simplifying configuration and management.

Benefits of technology

It realizes a flexible port isolation strategy, supports layer 2 and layer 3 network environments, reduces management complexity and cost, improves network management efficiency, and is suitable for diverse scenario needs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120301716A_ABST
    Figure CN120301716A_ABST
Patent Text Reader

Abstract

The invention discloses a flexible customized port isolation method, device and equipment based on an ACL (Access Control List) and a medium. The method comprises the following steps of: receiving a message input from a specified ingress port; judging whether an ACL entry in the incoming direction matched with the flow classification field of the current message exists or not; when the ACL entry matched with the incoming direction exists, setting a specific user-defined field for the service flow of the current message; the specific user-defined field is used for identifying whether the message needs to be isolated or not; and matching the user-defined field with the ACL entry in the out direction, and executing a corresponding isolation operation on the current message according to a matching result. The method has the advantages of various isolation modes, wide applicability, high isolation efficiency, high management efficiency, low implementation cost, simple configuration and the like.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network technologies, and in particular, to a flexible customized port isolation method, device, equipment and medium based on ACL. Background Art

[0002] VLAN isolation is a network technology used to divide a physical network into multiple logically independent network segments (VLANs). By assigning the ports of a switch to different VLANs, devices within the same VLAN can communicate with each other, while devices in different VLANs cannot directly communicate by default and must communicate through a router or a layer 3 switch. VLAN isolation can be achieved in various ways, including port-based partitioning, MAC address-based partitioning, protocol-based partitioning, and subnet-based partitioning.

[0003] The main functions of VLAN isolation are to enhance network security, reduce the size of the broadcast domain, simplify network management, and improve network performance. By isolating different network traffic, VLANs can prevent unauthorized access, reduce the impact of broadcast storms on the network, and optimize the utilization of network resources. For example, in an enterprise network, the network traffic of the finance department and the human resources department can be isolated to ensure the security of sensitive data; in a data center, the traffic of different tenants can be isolated to avoid interference with each other. In short, VLAN isolation is a flexible and efficient network management technology applicable to various network environments.

[0004] To achieve layer 2 isolation between packets, users can add different ports to different VLANs, but this will waste limited VLAN resources. If a user wants to isolate packets within the same VLAN, the port isolation technology is needed. By using the port isolation function, isolation between ports within the same VLAN can be achieved. Users only need to add the ports to the isolation group to achieve layer 2 data isolation between the ports in the isolation group. The port isolation function provides users with a more secure and flexible networking solution.

[0005] The method and application scenario of port isolation are as Figure 1 shown. PC1, PC2, and PC3 belong to VLAN10. After adding the ports GE1 / 0 / 1 and GE1 / 0 / 2 corresponding to PC1 and PC2 to the port isolation group, PC1 and PC2 cannot access each other within VLAN10, but PC3 can access PC1, and PC3 can also access PC2.

[0006] There are various network port isolation technologies, but most of them have problems such as insufficient flexibility and complex configuration. Traditional port isolation may increase the complexity of network management. If there are many different ports to be isolated, managing these ports may become very difficult. Incorrect port isolation configuration may lead to network latency and packet loss. While hardware-based isolation solutions have high performance, they are costly and not easy to manage and maintain. The port isolation solution based on business flows (such as applications in some smart grid communication technologies) realizes the port mode conversion and VLAN conversion functions of data packets by obtaining the key business flow function set, formulating a rule library, and constructing the dynamic mapping relationship between the rule library and the data packet VLAN. This solution overcomes the limitations of static VLAN isolation through dynamic VLAN allocation and port mode conversion, reduces the singularity of the physical isolation card rules, and improves the flexibility of network resource scheduling. However, this method also has the following defects:

[0007] VLAN resource limitation: Although dynamic VLAN allocation can alleviate the resource limitation problem of static VLAN isolation, the number of VLANs is still limited (such as 4094), and it may be difficult to meet the requirements in large-scale and high-density network environments;

[0008] Configuration and management complexity: It is necessary to maintain the dynamic mapping relationship between VLANs and business flows, which increases the complexity of configuration and management. Especially in scenarios where network traffic changes frequently, dynamically adjusting the strategies of VLAN allocation and port mode conversion may be cumbersome;

[0009] Applicability limitation: This type of solution may be mainly applicable to specific fields (such as power system communication), and its applicability and flexibility in a wider network environment (such as enterprise networks, data centers, etc.) may be limited. Summary of the Invention

[0010] In view of the above problems, the purpose of the embodiments of the present invention is to provide a flexible customization port isolation method, device, equipment and medium based on ACL to improve the above problems.

[0011] The embodiments of the present invention provide a flexible customization port isolation method based on ACL, which includes the following steps:

[0012] Receive a packet input from a specified input port;

[0013] Determine whether there is an inbound ACL entry that matches the flow classification field of the current packet;

[0014] When there is a matching inbound ACL entry, set a specific user-defined field for the business flow of the current packet; the specific user-defined field is used to identify whether the packet needs to be isolated;

[0015] Match the user-defined field with the outbound ACL entry, and perform corresponding isolation operations on the current packet according to the matching result.

[0016] Preferably, before receiving a packet input from a specified inbound port, it further includes:

[0017] Create an ACL table: used to define the attributes and scope of the isolation group, including the member ports of the isolation group and the priority of the isolation rules;

[0018] Create an inbound ACL entry, used to match the service flow characteristics to match the service flow characteristics that need to be isolated;

[0019] Set a user-defined field, used to identify whether the packet needs to be isolated;

[0020] Create an outbound ACL entry, including:

[0021] Match the user-defined field: In the outbound ACL entry, match the user-defined field set by the inbound ACL entry;

[0022] Match the ports that need to be isolated: In the outbound ACL entry, add the ports that need to be isolated to the matching rule;

[0023] Perform a discard action: If the outbound ACL entry matches both the user-defined field and the isolation port, discard the packet; otherwise, allow the packet to be forwarded.

[0024] Preferably, when there is no matching inbound ACL entry, hand over the packet to other forwarding processes for processing.

[0025] Preferably, the matching of the user-defined tag with the outbound ACL entry and the performance of corresponding isolation operations on the current packet according to the matching result are specifically as follows:

[0026] Judge whether the outbound ACL entry matches the user-defined tag and the isolation port;

[0027] If not, hand over the packet to other forwarding processes for processing;

[0028] If it matches, judge whether the action defined by the ACL entry is to discard;

[0029] If so, discard the packet to achieve isolation;

[0030] Otherwise, forward the packet.

[0031] Preferably, before receiving a packet input from a specified inbound port, it further includes:

[0032] Create an ACL table to define the attributes and scope of the isolation group, including the member ports of the isolation group and the priority of the isolation rules;

[0033] Create an inbound ACL entry to match the traffic flow characteristics that need not be isolated;

[0034] Set user-defined fields: After a specific traffic flow is matched, set the user-defined field of the ACL entry to a specific value to indicate that the packet does not need to be isolated.

[0035] Create a first outbound ACL entry with high priority to match the user-defined field set by the inbound ACL entry.

[0036] Match the ports that need to be isolated: Add the ports that need to be isolated to the first ACL entry;

[0037] Perform a forwarding action: Allow the packet to be forwarded;

[0038] Create a second outbound ACL entry with low priority:

[0039] Match the ports that need to be isolated: Add the ports that need to be isolated to the second ACL entry;

[0040] Perform a discard action: Discard the packet.

[0041] Preferably, when there is no matching inbound ACL entry, directly forward the packet.

[0042] Preferably, the matching of the user-defined tag with the outbound ACL entry and the execution of the corresponding isolation operation on the current packet according to the matching result are specifically as follows:

[0043] Determine whether the packet egress matches the first outbound ACL entry;

[0044] If it matches, forward the packet;

[0045] If it does not match, determine whether it matches the second ACL entry;

[0046] If it matches, discard the packet, otherwise forward the packet.

[0047] An embodiment of the present invention further provides a flexible customized port isolation device based on ACL, which includes:

[0048] A packet receiving unit for receiving a packet input from a specified inbound port;

[0049] A matching unit for determining whether there is an inbound ACL entry that matches the flow classification field of the current packet;

[0050] A field setting unit is configured to set a specific user-defined field for the service flow of the current packet when there is a matching ACL entry in the incoming direction; the specific user-defined field is used to identify whether the packet needs to be isolated.

[0051] An operation execution unit is configured to match the user-defined field with the ACL entry in the outgoing direction, and perform corresponding operations on the current packet according to the matching result.

[0052] An embodiment of the present invention further provides a flexible customized port isolation device based on ACL, which includes a memory and a processor. A computer program is stored in the memory, and the computer program can be executed by the processor to implement the flexible customized port isolation method based on ACL as described above.

[0053] An embodiment of the present invention further provides a computer-readable storage medium, which stores a computer program. The computer program can be executed by the processor of the device where the computer-readable storage medium is located to implement the flexible customized port isolation method based on ACL as described above.

[0054] In summary, the present invention realizes customized port isolation through ACL entries. The incoming ACL entries can be used to mark the service flow with user-defined fields, and the outgoing ACL entries can match these user-defined fields to achieve accurate ACL matching, so as to ensure that the specified service flow is strictly isolated or the specific service flow is not isolated. Compared with the prior art, the present solution has the following advantages:

[0055] First, it supports layer-2 and layer-3 network environments, and can flexibly customize isolation policies according to service flow characteristics, and set service flow attributes that need to be isolated, such as the DSCP, PCP, TTL, MAC address, etc. of the packet. As long as it is a matching field supported by the ACL function, accurate isolation can be achieved.

[0056] Second, users can dynamically adjust the ACL configuration as needed without reconfiguring the network, significantly improving management efficiency.

[0057] Finally, it provides two modes of isolating and not isolating specific service flows to meet the diverse scenario requirements. This port isolation solution only requires one ACL table and one ACL entry to complete the configuration, simplifying maintenance and saving resources. BRIEF DESCRIPTION OF THE DRAWINGS

[0058] In order to more clearly illustrate the technical solutions of the present invention, the drawings required for implementation will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0059] Figure 1 It is a diagram of the existing port isolation method and application scenario.

[0060] Figure 2 It is a schematic flowchart of the flexible customized port isolation method based on ACL provided by the first embodiment of the present invention.

[0061] Figure 3 It is a schematic flowchart of isolating a specific service flow.

[0062] Figure 4 It is a schematic flowchart of not isolating a specific service flow.

[0063] Figure 5 It is a schematic structural diagram of the flexible customized port isolation device based on ACL provided by the second embodiment of the present invention. Detailed implementation manners

[0064] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0065] To increase the understanding of the present invention, some technical terms related to the present invention will be described first below.

[0066] IP address (Internet Protocol Address): The address used to identify a device in a network, which is divided into two versions, IPv4 and IPv6, and is an important identifier in network communication.

[0067] MAC address (Media Access Control Address): The physical address of a network device, used to uniquely identify a device in a local area network, usually consisting of 6 bytes.

[0068] DSCP (Differentiated Services Code Point): The differentiated service code point, used to classify and mark the priority of traffic in a network, and is an important field in the QoS (Quality of Service) policy.

[0069] ACL (Access Control List): The access control list, which is a mechanism used to define network traffic filtering rules.

[0070] ACL table (acl_table): The set used to store ACL entries, which defines the attributes and scope of the isolation group.

[0071] ACL entry (acl_entry): The specific rule in the ACL table, which defines the matching conditions and corresponding actions.

[0072] In-port (in_port): The port through which the packet enters the network device.

[0073] Out-port (out_port): The port through which the packet leaves the network device.

[0074] Flow classification field: The field used to distinguish different service flows, such as field_pcp (Priority Code Point), field_dscp (Differentiated Services Code Point), etc.

[0075] Isolation group: A group of isolated ports or service flows.

[0076] Please refer to Figure 2 , the first embodiment of the present invention provides a flexible customized port isolation method based on ACL, which can be executed by a flexible customized port isolation device based on ACL (hereinafter referred to as the isolation device), specifically, executed by one or more processors in the isolation device, to implement the following steps:

[0077] S101, Receive the packet input from the specified in-port;

[0078] S102, Determine whether there is an in-direction ACL entry that matches the flow classification field of the current packet;

[0079] S103, When there is a matching in-direction ACL entry, set a specific user-defined field for the service flow of the current packet; the specific user-defined field is used to identify whether the packet needs to be isolated;

[0080] S104, Match the user-defined field with the out-direction ACL entry, and perform corresponding isolation operations on the current packet according to the matching result.

[0081] In this embodiment, based on the above flexible customized port isolation method, it is possible to isolate or not isolate a specific service flow, and the following will be described in detail respectively.

[0082] I. Isolation of specific service flows

[0083] To achieve the isolation of specific service flows, before step S101, it is necessary to create an ACL table and corresponding ACL entries, specifically including:

[0084] Create an ACL table: Define the attributes and scope of the isolation group, including the member ports of the isolation group and the priority of the isolation rules.

[0085] Create an inbound ACL entry to precisely match the service flow characteristics, including: matching the service flow characteristics that need to be isolated, such as source IP address, destination IP address, MAC address, DSCP value, etc. For example, it is possible to set to match packets with a source IP of 192.168.1.1.

[0086] Set user-defined fields: Set the user-defined field of the ACL to a specific value. This value is used to identify that the packet needs to be isolated.

[0087] Create an outbound ACL entry to match the user-defined field; among them, in the rule of the outbound ACL entry, match the user-defined field set by the inbound ACL entry.

[0088] Match the ports that need to be isolated: In the outbound ACL entry, add the ports that need to be isolated to the matching rule.

[0089] Perform a discard action: If the outbound ACL entry matches both the user-defined field and the isolation port at the same time, discard the packet; otherwise, allow the packet to be forwarded.

[0090] In this embodiment, after the ACL entry is configured, the process of the packet entering the port is as Figure 3 shown. After the packet enters the isolation device (usually a network device) from the specified inbound port, first determine whether there is an inbound ACL entry that matches the flow classification field of the current packet. If the match is successful, set a specific user-defined field for the service flow to identify that the service flow needs to be isolated; then determine whether the outbound ACL entry matches the user-defined field and the isolation port set in the inbound direction. If the match is successful, further determine whether the action defined by the outbound ACL entry is to discard. If so, discard the packet to achieve isolation; otherwise, forward the packet.

[0091] Among them, if the inbound ACL entry fails to match the flow classification field, or the outbound ACL entry fails to match the user-defined field, the packet will be transferred to other forwarding processes for processing.

[0092] II. Specific service flows are not isolated

[0093] To implement the isolation of specific service flows, before step S101, it is necessary to create an ACL table and the corresponding ACL entries, specifically including:

[0094] Create an ACL table: Define the attributes and scope of the isolation group, including the member ports of the isolation group and the priority of the isolation rules.

[0095] Create an inbound ACL entry to precisely match the service flow characteristics, including: matching the service flow characteristics that do not require isolation, such as source IP address, destination IP address, MAC address, DSCP value, etc. For example, it is possible to set to match packets with a source IP of 192.168.1.1.

[0096] Set user-defined fields: After a specific service flow is matched, set the user-defined field of the ACL to a specific value (e.g., 10). This value is used to indicate that the packet does not need to be isolated.

[0097] Create the first outbound ACL entry (high priority):

[0098] Match user-defined fields: Match the user-defined fields set by the inbound ACL entry.

[0099] Match the ports that need to be isolated: Add the ports that need to be isolated to the rules of the first ACL entry.

[0100] Perform a forwarding action: Allow the packet to be forwarded.

[0101] Create the second outbound ACL entry (low priority):

[0102] Match the ports that need to be isolated: Add the ports that need to be isolated to the rules of the second ACL entry.

[0103] Perform a discard action: Discard the packet.

[0104] After the ACL rules are configured, the forwarding process of the packet after entering the port is as Figure 4 shown. After the packet enters the network device from the inbound port, first determine whether the inbound ACL entry matches the flow classification field. If it matches, set the user-defined field for the service flow, and then determine whether the packet exit matches the first outbound ACL entry. If it matches, forward the packet; if it does not match, determine whether it matches the second outbound ACL entry. If it matches, discard the packet; otherwise, forward the packet.

[0105] Among them, if the inbound ACL entry does not match the flow classification field, directly forward the packet.

[0106] In summary, in this embodiment, customized port isolation is achieved through ACL entries. The inbound ACL entry can set user-defined fields for the service flow, and the outbound ACL entry can match this user-defined field to achieve precise ACL matching, thereby ensuring that specified service flows are strictly isolated or specific service flows are not isolated. Compared with the prior art, this solution has the following advantages:

[0107] 1. Diversified Modes: Provide two configuration modes. One is the specific service flow isolation mode, and the other is the non-isolation mode for specific service flows. Support flexible isolation based on different service flow characteristics (such as IP, MAC, DSCP, etc.) to meet diverse network management requirements.

[0108] 2. Wide Applicability: Applicable to both layer 2 and layer 3 network environments to meet network isolation requirements in different scenarios.

[0109] 3. High-efficiency Isolation: Achieve high-efficiency isolation of specific service flows through flexible configuration of ACLs to ensure network security and stability.

[0110] 4. High Management Efficiency: Users do not need to reconfigure the entire network. They can dynamically adjust the port isolation policy by simply adjusting the ACL configuration, greatly improving the efficiency of network management.

[0111] 5. Low Implementation Cost: Do not rely on expensive hardware solutions. The port isolation function can be achieved through software configuration, reducing the cost of network isolation.

[0112] 6. Simple Configuration: The isolation solution in this embodiment only requires one ACL table, and each isolation group only needs one ACL entry, which is simple to maintain and convenient to operate. By reducing the configuration entries, the management complexity is reduced, and the operation convenience is improved.

[0113] Please refer to Figure 5 , in the second embodiment of the present invention, a flexible customizable port isolation device based on ACL, which includes:

[0114] A packet receiving unit 210 for receiving packets input from a specified input port;

[0115] A matching unit 220 for determining whether there is an inbound ACL entry that matches the flow classification field of the current packet;

[0116] A field setting unit 230 for setting a specific user-defined field for the service flow of the current packet when there is a matching inbound ACL entry; the specific user-defined field is used to identify whether the packet needs to be isolated;

[0117] An operation execution unit 240 for matching the user-defined field with the outbound ACL entry and performing corresponding isolation operations on the current packet according to the matching result.

[0118] In the third embodiment of the present invention, a flexible customizable port isolation device based on ACL includes a memory and a processor. The memory stores a computer program that can be executed by the processor to implement the flexible customizable port isolation method based on ACL as described above.

[0119] The fourth embodiment of the present invention further provides a computer-readable storage medium storing a computer program, which can be executed by a processor of a device where the computer-readable storage medium is located to implement the ACL-based flexible customization port isolation method as described above.

[0120] In several embodiments provided by the embodiments of the present invention, it should be understood that the disclosed devices and methods can also be implemented in other ways. The device and method embodiments described above are merely illustrative. For example, the flowcharts and block diagrams in the accompanying drawings show the possible architectures, functions, and operations of devices, methods, and computer program products according to multiple embodiments of the present invention. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code, and the module, program segment, or part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order from that marked in the accompanying drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, as well as the combination of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or actions, or can be implemented by a combination of dedicated hardware and computer instructions.

[0121] In addition, the functional modules in each embodiment of the present invention may be integrated together to form an independent part, or each module may exist separately, or two or more modules may be integrated to form an independent part.

[0122] When the above functions are implemented in the form of software function modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on such understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, an electronic device, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The aforementioned storage medium includes: various media that can store program codes, such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs. It should be noted that in this article, the terms "including", "comprising", or any other variant thereof are intended to cover non-exclusive inclusion, so that a process, method, article, or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed, or elements inherent to such process, method, article, or device. Without further limitation, an element defined by the statement "including one..." does not exclude the existence of another identical element in the process, method, article, or device including the said element.

[0123] The terms used in the embodiments of the present invention are only for the purpose of describing specific embodiments and are not intended to limit the present invention. The singular forms "a", "the", and "said" used in the embodiments of the present invention and the appended claims are also intended to include the plural forms unless the context clearly indicates otherwise.

[0124] It should be understood that the term "and / or" used herein is only a description of the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B may represent: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the character " / " in this article generally represents an "or" relationship between the associated objects before and after.

[0125] Depending on the context, the word "if" as used herein can be interpreted as "when" or "while" or "in response to determining" or "in response to detecting". Similarly, depending on the context, the phrase "if determined" or "if detected (stated condition or event)" can be interpreted as "when determined" or "in response to determining" or "when detecting (stated condition or event)" or "in response to detecting (stated condition or event)".

[0126] The "first / second" mentioned in the embodiments is only used to distinguish similar objects and does not represent a specific order for the objects. It can be understood that the "first / second" can be interchanged with a specific order or sequence when permitted. It should be understood that the objects distinguished by the "first / second" can be interchanged under appropriate circumstances so that the embodiments described herein can be implemented in an order other than those illustrated or described herein.

[0127] The foregoing is only a preferred embodiment of the present invention and is not intended to limit the present invention. For those skilled in the art, the present invention may have various modifications and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.

Claims

1. A flexible customized port isolation method based on ACL, characterized in that Including the following steps: Receiving a packet input from a specified input port; Determining whether there is an inbound ACL entry that matches the flow classification field of the current packet; When there is a matching inbound ACL entry, setting a specific user-defined field for the service flow of the current packet; the specific user-defined field is used to identify whether the packet needs to be isolated; Matching the user-defined field with the outbound ACL entry and performing corresponding isolation operations on the current packet according to the matching result.

2. The ACL-based flexible customization port isolation method according to claim 1, wherein Before receiving a packet input from a specified input port, it further includes: Creating an ACL table: used to define the attributes and scope of the isolation group, including the member ports of the isolation group and the priority of the isolation rules; Creating an inbound ACL entry for matching service flow characteristics to match the service flow characteristics that need to be isolated; Setting a user-defined field to identify that the packet needs to be isolated; Creating an outbound ACL entry, including: Matching the user-defined field: In the outbound ACL entry, matching the user-defined field set by the inbound ACL entry; Matching the ports that need to be isolated: In the outbound ACL entry, adding the ports that need to be isolated to the matching rule; Performing a discard action: If the outbound ACL entry matches both the user-defined field and the isolation port, discarding the packet; otherwise, allowing the packet to be forwarded.

3. The method for flexible customized port isolation based on ACL according to claim 2, characterized in that When there is no matching inbound ACL entry, handing the packet over to other forwarding processes for processing.

4. The ACL-based flexible customization port isolation method according to claim 2, characterized in that Matching the user-defined tag with the outbound ACL entry and performing corresponding isolation operations on the current packet according to the matching result specifically means: Determining whether the outbound ACL entry matches the user-defined tag and the isolation port; If not, handing the packet over to other forwarding processes for processing; If it matches, determining whether the action defined by the ACL entry is to discard; If so, discarding the packet to achieve isolation; Otherwise, forwarding the packet.

5. The method for flexible customized port isolation based on ACL according to claim 1, characterized in that Before receiving a packet input from a specified input port, it further includes: Creating an ACL table for defining the attributes and scope of the isolation group, including the member ports of the isolation group and the priority of the isolation rules; Creating an inbound ACL entry for matching service flow characteristics that do not need to be isolated; Setting a user-defined field: After matching a specific service flow, setting the user-defined field of the ACL entry to a specific value to identify that the packet does not need to be isolated. Creating a first outbound ACL entry with a high priority for matching the user-defined field set by the inbound ACL entry. Matching the ports that need to be isolated: Adding the ports that need to be isolated to the first ACL entry; Performing a forwarding action: Allowing the packet to be forwarded; Creating a second outbound ACL entry with a low priority: Matching the ports that need to be isolated: Adding the ports that need to be isolated to the second ACL entry; Performing a discard action: Discarding the packet.

6. The buffer resource allocation method based on dynamic adjustment according to claim 5, wherein When there is no matching inbound ACL entry, directly forwarding the packet.

7. The buffer resource allocation method based on dynamic adjustment according to claim 5, characterized in that Matching the user-defined tag with the outbound ACL entry and performing corresponding isolation operations on the current packet according to the matching result specifically means: Determine whether the packet egress matches the first ACL entry in the egress direction; If it matches, forward the packet; If it does not match, determine whether it matches the second ACL entry; If it matches, discard the packet, otherwise forward the packet.

8. A flexible customized port isolation device based on ACL, characterized in that, It includes: A packet receiving unit for receiving a packet input from a specified ingress port; A matching unit for determining whether there is an ACL entry in the ingress direction that matches the flow classification field of the current packet; A field setting unit for setting a specific user-defined field for the service flow of the current packet when there is a matching ingress direction ACL entry; the specific user-defined field is used to identify whether the packet needs to be isolated; An operation execution unit for matching the user-defined field with the ACL entry in the egress direction and performing corresponding isolation operations on the current packet according to the matching result.

9. A flexible and customizable port isolation device based on ACL, characterized in that, It includes a memory and a processor, and a computer program is stored in the memory. The computer program can be executed by the processor to implement the ACL-based flexible customized port isolation method according to any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that, A computer program is stored, and the computer program can be executed by the processor of the device where the computer-readable storage medium is located to implement the ACL-based flexible customized port isolation method according to any one of claims 1 to 7.