Data message forwarding method, device and equipment
By adopting network tuple groups in the service chain, selecting the security network element that has not failed to occur to determine the forwarding path, solving the problem of high service availability in the security network element failure, and achieving efficient resource utilization and load balancing.
Patent Information
- Application Number
- CN202510560234.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-29
- Publication Date
- 2025-07-18
AI Technical Summary
In the prior art, the security network element fails to ensure high service availability, and the main and standby deployment model leads to excessive resource overhead.
By using network tuple groups in the service chain, multiple target network tuple groups are selected, multiple forwarding paths are determined based on the security network elements that have not failed, and target forwarding paths are determined through the parameter information of the data packets, and the secure network elements in the target forwarding path are controlled to forward data packets.
It realizes high service availability in the event of a secure network element failure, avoids resource waste, and ensures effective resource utilization and load sharing through load balancing algorithms.
Smart Images

Figure CN120342573A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network security technologies, and particularly to a method, apparatus, and device for forwarding data packets. Background Art
[0002] In the field of network security, service chaining has become one of the security orchestration means in complex business scenarios, and users can flexibly orchestrate security capabilities according to security protection requirements. However, during the gradual application of service chaining, security network element failures (such as illegal shutdown, abnormal restart, system failure, etc.) often occur, resulting in the inability to process network traffic normally and thus affecting user services. In existing applications, security vendors mainly adopt two technical solutions to address the network element failure problem: One is to deploy two security network elements in a primary-backup mode. When the primary security network element fails, the traffic can be automatically switched to the backup security network element for processing to ensure service continuity. However, this technical solution requires a one-to-one primary-backup deployment of security network elements, doubling the resource overhead. The other is to adopt the virtual switch fault migration technology of cloud computing, but this method can only handle the security network element failure problem caused by the failure of the host machine, and high service availability cannot be achieved when the security network element itself fails. Summary of the Invention
[0003] Embodiments of this application provide a method, apparatus, and device for forwarding data packets to solve the problems of large resource overhead in the primary-backup deployment mode of security network elements and the inability to guarantee high service availability when security network elements fail in the prior art.
[0004] In a first aspect, embodiments of this application provide a method for forwarding data packets, and the method includes:
[0005] Determine a data packet to be forwarded, where the data packet contains first parameter information;
[0006] According to the service chain type indicated by the first parameter information, select multiple target network element groups from multiple pre-configured network element groups; each target network element group in the multiple target network element groups includes at least one security network element of the same network element type;
[0007] Based on the security network elements that have not failed in the multiple target network element groups, determine multiple forwarding paths;
[0008] Based on a preset scheduling rule, determine a target forwarding path that needs to perform forwarding from the multiple forwarding paths;
[0009] Control the security network elements in the target forwarding path to forward the data packet.
[0010] In a possible implementation, determining a target forwarding path to be executed from the multiple forwarding paths based on the second parameter information of the data packet includes:
[0011] Performing a hash operation on the second parameter information of the data packet to determine the hash value of the second parameter information;
[0012] Taking the remainder of the hash value with respect to the quantity value of the multiple forwarding paths, and determining the target forwarding path from the multiple forwarding paths according to the remainder result.
[0013] In a possible implementation, determining the target forwarding path from the multiple forwarding paths according to the remainder result includes:
[0014] Determining a target path identifier that matches the remainder result from the path identifiers respectively corresponding to the multiple forwarding paths;
[0015] Taking the forwarding path corresponding to the target path identifier as the target forwarding path.
[0016] In a possible implementation, taking the forwarding path corresponding to the target path identifier as the target forwarding path includes:
[0017] Determining the number of packet forwards of the forwarding path corresponding to the target path identifier within a set historical time period;
[0018] When the number of packet forwards is not greater than a set packet threshold, taking the forwarding path corresponding to the target path identifier as the target forwarding path;
[0019] The method further includes:
[0020] When the number of packet forwards is greater than the set packet threshold, selecting a service chain with the number of packet forwards not greater than the set packet threshold within the set historical time period from the multiple forwarding paths as the target forwarding path.
[0021] In a possible implementation, the service chain type indicated by the first parameter information is determined by the following method:
[0022] Based on the pre-configured correspondence between the first parameter information and the service chain type, determining the service chain type indicated by the first parameter information;
[0023] Wherein, the correspondence between the first parameter information and the service chain type is configured by the following method:
[0024] For data packets of each service requirement, the following operations are respectively performed:
[0025] The network element type of at least one security network element that needs to be passed through when determining the target data packet for the forwarded target service requirement;
[0026] Determine the connection order among the security network elements of at least one network element type to obtain a service chain type;
[0027] Establish a correspondence relationship between the service chain type and the first parameter information of the target data packet.
[0028] In a possible implementation manner, determining multiple forwarding paths based on the non-failed security network elements in the multiple target network element groups includes:
[0029] Perform fault detection on each security network element in each target network element group to determine the non-failed security network elements;
[0030] Repeat the following operations to obtain multiple forwarding paths:
[0031] For each network element group in the multiple target network element groups, select a target security network element from the non-failed security network elements to obtain multiple target security network elements;
[0032] Arrange the multiple target security network elements in order to obtain a forwarding path.
[0033] In a possible implementation manner, the security network element is subjected to fault detection in the following manner:
[0034] Control the virtual switch corresponding to the security network element to send a forward detection packet to the first interface of the security network element, and control the virtual switch to send a reverse detection packet to the second interface of the security network element;
[0035] When it is determined that the virtual switch receives the forward detection packet sent by the second interface and the reverse detection packet sent by the first interface, it is determined that the security network element has not failed.
[0036] In a second aspect, an embodiment of the present application provides a data packet forwarding device, and the device includes:
[0037] A first determination module, configured to determine a data packet to be forwarded, and the data packet includes first parameter information;
[0038] A second determination module, configured to select multiple target network element groups from a plurality of pre-configured network element groups according to the service chain type indicated by the first parameter information; each target network element group in the multiple target network element groups includes at least one security network element of the same network element type;
[0039] Determine multiple forwarding paths based on the non-failed security network elements in the multiple target network element groups;
[0040] Determine a target forwarding path that needs to perform forwarding from the multiple forwarding paths based on a preset scheduling rule;
[0041] Control the security network element in the target forwarding path to forward the data packet.
[0042] In a possible implementation manner, when the second determination module determines a target forwarding path that needs to perform forwarding from the multiple forwarding paths based on a preset scheduling rule, it specifically is used for:
[0043] Perform a hash operation on the second parameter information of the data packet to determine the hash value of the second parameter information;
[0044] Take the remainder of the hash value with respect to the quantity value of the multiple forwarding paths, and determine the target forwarding path from the multiple forwarding paths according to the remainder result.
[0045] In a possible implementation manner, when the second determination module determines the target forwarding path from the multiple forwarding paths according to the remainder result, it specifically is used for:
[0046] Determine a target path identifier that matches the remainder result from the path identifiers respectively corresponding to the multiple forwarding paths;
[0047] Use the forwarding path corresponding to the target path identifier as the target forwarding path.
[0048] In a possible implementation manner, when the second determination module determines the target forwarding path that needs to perform forwarding from the multiple forwarding paths based on a preset scheduling rule, it specifically is used for:
[0049] Send probe packets to the multiple forwarding paths respectively;
[0050] According to the response times of the probe packets respectively corresponding to the multiple forwarding paths, use the forwarding path with the shortest response time as the target forwarding path.
[0051] In a possible implementation manner, the second determination module is further used to determine the service chain type indicated by the first parameter information in the following manner:
[0052] Determine the service chain type indicated by the first parameter information based on a preconfigured correspondence between the first parameter information and the service chain type;
[0053] Wherein, the correspondence between the first parameter information and the service chain type is configured in the following manner:
[0054] For data packets of each service requirement, respectively perform the following operations:
[0055] The network element type of at least one security network element that needs to be passed through when determining the target data packet for the forwarded target service requirement;
[0056] Determine the connection order among the security network elements of at least one network element type to obtain a service chain type;
[0057] Establish a correspondence relationship between the service chain type and the first parameter information of the target data packet.
[0058] In a possible implementation manner, when the second determination module determines multiple forwarding paths based on the non-failed security network elements in the multiple target network element groups, it is specifically used for:
[0059] Perform a fault detection on each security network element in each target network element group to determine the non-failed security network elements;
[0060] Repeat the following operations to obtain multiple forwarding paths:
[0061] For each network element group in the multiple target network element groups, select a target security network element from the non-failed security network elements to obtain multiple target security network elements;
[0062] Arrange the multiple target security network elements in sequence to obtain a forwarding path.
[0063] In a possible implementation manner, the second determination module is further used to perform a fault detection on the security network element in the following manner:
[0064] Control the virtual switch corresponding to the security network element to send a forward detection packet to the first interface of the security network element, and control the virtual switch to send a reverse detection packet to the second interface of the security network element;
[0065] When it is determined that the virtual switch receives the forward detection packet sent by the second interface and the reverse detection packet sent by the first interface, it is determined that the security network element has not failed.
[0066] In a third aspect, an embodiment of the present application provides an execution device, including:
[0067] A memory for storing program instructions;
[0068] A processor for obtaining the program instructions stored in the memory and executing the methods described in the first aspect and different implementation manners of the first aspect according to the obtained program instructions.
[0069] Fourthly, an embodiment of the present application provides a computer-readable storage medium, which includes computer instructions. When the computer instructions are executed by a computer, the methods described in the first aspect and different implementation manners of the first aspect are implemented.
[0070] Fifthly, the present application provides a computer program product, which includes: computer program code. When the computer program code runs on a computer, the computer is caused to execute the methods described in the above-mentioned first aspect and different implementation manners of the first aspect.
[0071] The beneficial effects of the present application are as follows:
[0072] In the present application, a network element group includes multiple security network elements. Various security network elements in the service chain are added to the service chain in the form of a network element group. When a certain security network element fails, the forwarding of data packets can be realized through other network elements in the network element group, ensuring high availability of services. In addition, the present application does not require deploying two security network elements on the device in a primary / standby deployment mode, avoiding waste of resources.
[0073] In addition, the present application can detect the availability of security network elements by sending packets through a virtual switch, ensuring the timeliness of fault discovery and also avoiding interference of non-network element faults caused by excessive forwarding hops of detection packets. BRIEF DESCRIPTION OF THE DRAWINGS
[0074] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required to be used in the description of the embodiments or the prior art. Obviously, the following drawings are some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0075] Figure 1 FIG. is a schematic diagram of an application scenario provided by an embodiment of the present application;
[0076] Figure 2 FIG. is a flowchart of a method for forwarding data packets provided by an embodiment of the present application;
[0077] Figure 3 FIG. is a schematic diagram of fault detection of a security network element provided by an embodiment of the present application;
[0078] Figure 4 FIG. is a schematic diagram of a link composed of a network element group provided by an embodiment of the present application;
[0079] Figure 5 FIG. is a schematic diagram of forwarding data packets provided by an embodiment of the present application;
[0080] Figure 6Schematic diagram of a data packet forwarding device provided by an embodiment of the present application;
[0081] Figure 7 Structural diagram of an execution device provided by an embodiment of the present application. Specific implementation manners
[0082] To make the objectives, technical solutions and advantages of the present application clearer and more understandable, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. Apparently, the described embodiments are only a part rather than all of the embodiments of the present application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present application without making creative efforts shall fall within the scope of protection of the present application. Without conflict, the embodiments in the present application and the features in the embodiments may be combined with each other arbitrarily. And although the logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a sequence different from that here.
[0083] The terms "first" and "second" in the specification, claims and above-mentioned drawings of the present application are used to distinguish different objects rather than to describe a specific order. In addition, the term "comprising" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device that includes a series of steps or units is not limited to the listed steps or units, but optionally further includes steps or units not listed, or optionally further includes other steps or units inherent to these processes, methods, products or devices. The "plurality" in the present application may represent at least two, for example, it may be two, three or more, and the embodiments of the present application do not make limitations.
[0084] To better understand the data packet forwarding method, device and equipment proposed in the present application, the technical terms involved in the present application will be explained below.
[0085] Security network element: A security network element refers to a device, software or virtualized component in the network that is specifically responsible for executing security functions. It is a key component in the network security architecture and is usually embedded in various levels of the network (such as the boundary, core, and terminal).
[0086] Network element group: A network element group is a logical set of a group of network functions (physical or virtual), which realizes specific network services or business objectives through collaborative work. In the cloud-native and SDN (Software-Defined Network) environment, network element groups are often used for dynamic orchestration and management of distributed network resources.
[0087] Service chain: In a network environment, it refers to a logically linear path formed by connecting multiple network services in a predefined order to process specific data streams. These services may include devices such as firewalls, web application firewalls (WAFs), and intrusion prevention systems. The main purpose of the service chain is to ensure that data packets can undergo a series of security checks, attack protection, and compliance processing during transmission.
[0088] In the field of network security, service chains have become one of the security orchestration means in complex business scenarios, and users can flexibly orchestrate security capabilities according to security protection requirements. However, during the gradual application of service chains, security network element failures (such as illegal shutdowns, abnormal restarts, system failures, etc.) often occur, resulting in the inability to process network traffic normally and thus affecting user services. In existing applications, security vendors mainly adopt two technical solutions to address network element failure problems: One is to deploy two security network elements in a primary-backup mode. When the primary security network element fails, the traffic can be automatically switched to the backup security network element for processing to ensure business continuity. However, this technical solution requires a one-to-one primary-backup deployment of security network elements, doubling the resource overhead. The other is to use the virtual switch fault migration technology of cloud computing, but this method can only handle security network element failures caused by host failures and cannot achieve high availability of services when the security network elements themselves fail.
[0089] To address the above problems, the embodiments of this application provide a method, device, and equipment for forwarding data packets. Based on the service chain type indicated by the first parameter information in the data packet to be forwarded, multiple target network element groups are selected from multiple pre-configured network element groups. Further, multiple forwarding paths can be determined based on the non-failed security network elements in the multiple target network element groups. Then, based on the second parameter information of the data packet, the target forwarding path to be executed is determined from the multiple forwarding paths, and the security network elements in the target forwarding path are controlled to forward the data packet. Through the above method, each network element group includes multiple security network elements, and various security network elements in the service chain are added to the service chain in the form of network element groups. When a certain security network element fails, the data packet can be forwarded through other network elements in the network element group, ensuring high availability of services. In addition, this application does not require two security network elements to be deployed in a primary-backup mode on the device, avoiding waste of resources.
[0090] As Figure 1 shown, Figure 1A schematic diagram of the forwarding scenario of the data packet involved in the present application is exemplarily shown, where it includes a source device 100, a control device 200, and a destination device 300. Among them, the source device 100 is a device that generates data packets, and the destination device 300 is a device that receives data packets. In addition, it also includes multiple network element groups. Each network element group includes multiple security network elements of the same type, and the types of security network elements included in different network element groups are different. In addition, the number of security network elements included in different network element groups may be the same or different. It should be noted that one security network element is deployed in one security device, and different security network elements are deployed in different security devices. The security device can be a terminal device or a server. Among them, the server can be implemented by a physical server or a virtual server. Exemplarily, taking the example of including a total of 4 network element groups, namely network element group 1, network element group 2, network element group 3, and network element group 4. Among them, network element group 1 includes 3 security network elements, network element group 2 includes 4 security network elements, network element group 3 includes 2 security network elements, and network element group 4 includes 3 security network elements. Of course, more or fewer security network elements may be included in different network element groups, and the present application does not make specific limitations on this.
[0091] In some scenarios, after the source device 100 generates a data packet, it can send the data packet to the control device 200. Further, the control device 200 can determine the service chain type indicated by the data packet based on the data packet, and determine a target network element group that matches the service chain type from multiple network element groups.
[0092] Suppose the target network element groups that match the service chain type indicated by the data packet are network element group 1, network element group 2, and network element group 4 respectively. Further, multiple forwarding paths can be determined respectively based on the non-failed security network elements in network element group 1, network element group 2, and network element group 4 which are the target network element groups respectively, and a target forwarding path for forwarding can be determined from the multiple forwarding paths based on a preset scheduling rule, and then control the security network elements in the target forwarding path to forward the data packet.
[0093] It should be noted that the above Figure 1 shown scenario is only an example, and the number of network element groups and the number of security network elements in each network element group can be more or less, and the embodiments of the present application do not make limitations on this.
[0094] See Figure 2 shown, which is a flowchart of a method for forwarding a data packet provided by an embodiment of the present application. The specific process of the method for forwarding the data packet provided by the present application can be implemented by the control device 200 in Figure 1 as follows:
[0095] Step S201, determine the data packet to be forwarded.
[0096] Among them, the data packet to be forwarded contains first parameter information. Specifically, the first parameter information may be the triple information or quintuple information of the data packet.
[0097] Step S202: Select a plurality of target network element groups from a plurality of pre-configured network element groups according to the service chain type indicated by the first parameter information.
[0098] Among them, each target network element group among the plurality of target network element groups includes at least one security network element of the same network element type.
[0099] In some embodiments, among the plurality of pre-configured network element groups, the network element types of the security network elements included in different network element groups are different, and the number of security network elements included may be the same or different. As an example, assume that in the network, the network element type of 4 security network elements is network element type 1, the network element type of 3 security network elements is network element type 2, the network element type of 3 security network elements is network element type 3, and the network element type of 2 security network elements is network element type 4. Further, the 4 security network elements of network element type 1 can be formed into network element group 1, the 3 security network elements of network element type 2 can be formed into network element group 2, the 3 security network elements of network element type 3 can be formed into network element group 3, and the 2 security network elements of network element type 4 can be formed into network element group 4. Network element group 1, network element group 2, network element group 3, and network element group 4 can form multiple service chain types according to the service requirements of the data packet.
[0100] In some embodiments, different service chain types include different network element types, and the number and connection order of network element types may also be different. For example, service chain type 1 can be represented as network element type 1 → network element type 2 → network element type 3. When the data packet needs to be forwarded through the service chain of service chain type 1, it needs to pass through the security network elements of network element type 1, the security network elements of network element type 2, and the security network elements of network element type 3 in sequence. Service chain type 2 can be represented as network element type 1 → network element type 3. When the data packet needs to be forwarded through the service chain of service chain type 2, it needs to pass through the security network elements of network element type 1 and the security network elements of network element type 3 in sequence.
[0101] In some scenarios, the service chain type indicated by the first parameter information can be determined based on the corresponding relationship between the pre-configured first parameter information and the service chain type.
[0102] Among them, the corresponding relationship between the first parameter information and the service chain type is configured in the following manner:
[0103] For each data packet with service requirements, the following operations are respectively performed:
[0104] The network element types of at least one security network element that need to be passed through when determining the target data packet for the target service requirement for forwarding. As an example, when forwarding the data packet of a certain service requirement, it needs to pass through 2 security network elements, and their corresponding network element types are network element type 1 and network element type 2 respectively. Then, the connection order between the security network elements of at least one network element type can be determined to obtain the service chain type. For example, if the connection order of 2 security network elements is the security network element of network element type 1 → the security network element of network element type 2, then the service chain type can be expressed as network element type 1 → network element type 2. Further, a correspondence relationship can be established between the service chain type and the first parameter information of the target data packet. Continuing with the above example, a correspondence relationship can be established between the first parameter information of the above data packet and the service chain type.
[0105] Through the above method, a correspondence relationship can be established between the first parameter information of the data packets of different service requirements and the service chain type. Furthermore, when determining the data packet to be forwarded, based on the correspondence relationship between the first parameter information and the service chain type, the service chain type indicated by the first parameter information of the data packet to be forwarded can be determined.
[0106] In some embodiments, if the service chain type indicated by the first parameter information of the data packet to be forwarded is network element type 1 → network element type 2 → network element type 3, then from multiple network element groups, the network element group 1 of network element type 1, the network element group 2 of network element type 2, and the network element group 3 of network element type 3 can be determined as the target network element groups.
[0107] Step S203, determine multiple forwarding paths based on the security network elements that have not failed among the multiple target network element groups.
[0108] In some embodiments, fault detection can be performed on each security network element in each target network element group to determine the security network elements that have not failed. In some scenarios, when forwarding data packets, the security network element needs to forward the data packet through the virtual switch corresponding to the security network element. Therefore, the following method can be used to perform fault detection on the security network element: control the virtual switch corresponding to the security network element to send a forward detection packet to the first interface of the security network element, and control the virtual switch to send a reverse detection packet to the second interface of the security network element. When it is determined that the virtual switch receives the forward detection packet sent by the second interface and the reverse detection packet sent by the first interface, it is determined that the security network element has not failed.
[0109] Such as Figure 3As shown in the figure, taking security network element 1 as an example, security network element 1 includes two interfaces, interface 1 and interface 2. A forward detection message can be sent to interface 1 through virtual switch 1 corresponding to security network element 1, and a reverse detection message can be sent to interface 2. If path 1 from interface 1 to interface 2 is normal, the forward data message will be sent to virtual switch 1 through interface 2. Similarly, if path 2 from interface 2 to interface 1 is normal, the reverse data message will be sent to virtual switch 1 through interface 1. Therefore, if virtual switch 1 can receive the forward detection message sent by interface 2 and virtual switch 1 can receive the reverse detection message sent by interface 1, it indicates that security network element 1 has not failed. Figure 3 In the figure, the solid line represents the flow direction of the forward detection message, and the dashed line represents the flow direction of the reverse detection message.
[0110] Further, the following operations can be repeatedly executed to obtain multiple forwarding paths: for each network element group in multiple target network element groups, select a target security network element from the non-failed security network elements to obtain multiple target security network elements. Then, the multiple target security network elements can be arranged in sequence to obtain a forwarding path.
[0111] Continuing with the above example, if the target network element groups include network element group 1 of network element type 1, network element group 2 of network element type 2, and network element group 3 of network element type 3, and the non-failed security network elements in network element group 1 include security network element 11, security network element 12, and security network element 13, the non-failed security network elements in network element group 2 include security network element 21, security network element 22, and security network element 23, and the non-failed security network elements in network element group 3 include security network element 31 and security network element 32. Further, a network element can be selected from network element group 1, network element group 2, and network element group 3 respectively as the target security network element, and they can be arranged according to the arrangement order of the network element types in the service chain type to obtain a forwarding path. For example, security network element 11 can be selected from network element group 1, security network element 21 can be selected from network element group 2, and security network element 31 can be selected from network element group 3 as the target security network elements, and they are arranged in sequence according to the corresponding connection relationship of the service chain type. The obtained forwarding path can be expressed as security network element 11 → security network element 21 → security network element 31. Similarly, security network element 12 can be selected from network element group 1, security network element 21 can be selected from network element group 2, and security network element 32 can be selected from network element group 3 as the target security network elements, and they are arranged in sequence according to the corresponding connection relationship of the service chain type. The obtained forwarding path can be expressed as security network element 12 → security network element 21 → security network element 32. Through the above method, 18 forwarding paths can be obtained.
[0112] Step S204, based on a preset scheduling rule, determine a target forwarding path that needs to perform forwarding from multiple forwarding paths.
[0113] In some embodiments, a hash operation may be performed on the second parameter information of the data packet to determine the hash value of the second parameter information. Further, the number value of multiple forwarding paths may be taken modulo based on the hash value, and the target forwarding path may be determined from the multiple forwarding paths according to the modulo result.
[0114] Specifically, the target path identifier matching the modulo result may be determined from the path identifiers respectively corresponding to the multiple forwarding paths, and the forwarding path corresponding to the target path identifier may be used as the target forwarding path.
[0115] As an example, the second parameter information may be the five-tuple information of the data packet. Further, a hash operation may be performed on the five-tuple information to determine the hash value of the five-tuple information. If the determined number of forwarding paths is 18, the hash value of the five-tuple information is taken modulo 18, and then the remainder less than 18 is obtained. Then, when determining the multiple forwarding paths, a path identifier may be determined for each forwarding path, and the path identifiers of the 18 forwarding paths may be represented as 0-17. Further, the forwarding path corresponding to the target path identifier matching the modulo result may be used as the target forwarding path.
[0116] In some scenarios, when determining the target forwarding path, the delay of the forwarding path corresponding to the target path identifier may also be determined first. When the delay is not greater than the set delay threshold, the forwarding path corresponding to the target path identifier may be used as the target forwarding path. Specifically, a probe packet may be sent to the forwarding path corresponding to the target path identifier, and the delay of the forwarding path may be determined according to the response time of the probe packet, that is, the total time from the sending of the probe packet to the receiving of the response.
[0117] In some scenarios, when the delay is greater than the set delay threshold, a forwarding path may be selected from the remaining forwarding paths as the target forwarding path.
[0118] Specifically, assuming there are 18 forwarding paths in total and the modulo result of the second parameter information is 3, when the delay of the forwarding path with the target path identifier of 3 (denoted as forwarding path 3) is greater than the set delay threshold, it may be considered that the load of forwarding path 3 is relatively high, and a forwarding path may be selected from the remaining 17 forwarding paths as the target forwarding path.
[0119] In one implementation, the target path identifier may be incremented by one first, and the forwarding path corresponding to the incremented target path identifier may be used as the target forwarding path. As an example, the modulo result is 3 and the determined target path identifier is 3. Then the target path identifier is incremented by one to obtain a target path identifier of 4, and the forwarding path corresponding to the target path identifier 4 (i.e., forwarding path 4) may be used as the target forwarding path. Preferably, the above operation of incrementing the target path identifier by one may be repeated until the delay of the determined target path identifier is not greater than the set delay threshold.
[0120] In another implementation, to ensure load balancing between forwarding paths, data packets can be forwarded in a round-robin manner. For example, the 18 forwarding paths under the current service chain type can be represented as forwarding paths 0 - 17. If the forwarding path used for data packet forwarding last time was forwarding path 10, then this data packet can be forwarded through forwarding path 11 this time.
[0121] Through the above method, each service chain uses a load balancing algorithm for scheduling processing, ensuring the effective utilization of resources, load sharing, and high service availability of all security network elements.
[0122] In some embodiments, the bandwidths of multiple forwarding paths can be determined, and scheduling can be performed according to the bandwidth weights of each forwarding path. For example, the bandwidth weight ratio among three forwarding paths is 5:4:1. If a data packet is received, traffic forwarding is performed according to the bandwidth weight ratio.
[0123] In other embodiments, traffic forwarding can be performed in a weighted round-robin manner. Specifically, the bandwidths and latencies respectively corresponding to multiple forwarding paths can be determined, and then for each forwarding path, the bandwidth and latency are weighted to determine the load weight of each forwarding path. As an example, the bandwidth of forwarding path A is 5 Gbps and the latency is 50 ms, and the bandwidth of forwarding path B is 3 GB and the latency is 20 ms. If the bandwidth weight coefficient is 0.7 and the latency coefficient is 0.3, then the score of forwarding path A is 5×0.7 + 1 / 50×0.3 = 3.506, and the score of forwarding path B is 3×0.7 + 1 / 20×0.3 = 2.115. The load weight of forwarding path A can be expressed as 3.506 / (3.506 + 2.115) = 62.3%, and the load weight of forwarding path B can be expressed as 2.115 / (3.506 + 2.115) = 37.7%. Then, forwarding path A is used to forward 62.3% of the traffic, and forwarding path B is used to forward 37.7% of the traffic. Preferably, the bandwidth and latency can be normalized first, and then the above operations can be performed to determine the load weights of each forwarding path.
[0124] Step S205: Control the security network element in the target forwarding path to forward the data packet.
[0125] As an example, assume that the target forwarding path can be expressed as Security Network Element 11 → Security Network Element 21 → Security Network Element 31. Then, the data packet and the forwarding path can be sent to Security Network Element 11, so that Security Network Element 11 forwards the data packet and the forwarding path to Security Network Element 21 according to the forwarding path. Similarly, after receiving the data packet, Security Network Element 21 can forward the data packet and the forwarding path to Security Network Element 31 according to the forwarding path. Further, Security Network Element 31 can send the data packet to the destination device according to the destination address in the data packet. In some scenarios, the forwarding path may also include the destination address of the destination device. Thus, after receiving the data packet, the last-hop security network element can forward the data packet to the target device based on the destination address.
[0126] In some embodiments, when it is determined that all security devices in a certain network element group have failed, the network element group can be set to bypass, and then the data packet can be directly forwarded to the security network element in the next network element group to ensure high service availability.
[0127] In some embodiments, after determining multiple target network element groups, multiple forwarding paths can be determined based on the security network elements in the multiple target network element groups. Further, the security network elements that have failed in each network element group are determined, and the forwarding paths where the failed security network elements are located in the multiple forwarding paths are removed to obtain multiple forwarding paths that can achieve normal forwarding.
[0128] In this application, the configuration of the network element group can be implemented through the policy configuration module. The security network elements join the service chain in the form of network element groups, and 1-N security network elements can be referenced within each network element group. Among them, the network element group can include a firewall network element group, an IPS network element group, a WAF network element group, and so on. Further, the service chain can be configured. Specifically, the connection order of each network element group in the service chain can be determined according to the service requirements. For example, assume that under a certain service requirement, the connection order between the firewall network element group, the IPS network element group, and the WAF network element group is: firewall network element group → IPS network element group → WAF network element group. Among them, the firewall network element group includes one security network element FW1, the IPS network element group includes 3 security network elements IPS1, IPS2, and IPS3, and the WAF network element group includes 3 security network elements WAF1, WAF2, and WAF3. Then, the obtained multiple links (represented as link groups in the figure) are as Figure 4 shown. Further, the policy configuration module can also configure security policies, that is, associate different service chain types based on different service requirements, and configure the load balancing algorithm. The security policy mainly configures the rules for flow matching and references the service chain to achieve the purpose of specific traffic passing through the service chain.
[0129] In some embodiments, the traffic orchestration module schedules, assembles, and issues flow table forwarding rules in the service chain forwarding path according to the security policy configuration. The traffic orchestration module can orchestrate the traffic path. Specifically, all forwarding paths can be calculated based on the service chain order and the status of each security network element and network element group. Further, a service chain forwarding path table can be generated based on the forwarding paths.
[0130] In some embodiments, the fault detection module can control the virtual switch to encapsulate the forward / backward probe messages and send them to two service interfaces of the security network element respectively to determine whether the security network element forwards the messages normally. If so, it is determined that the security network element is normal; otherwise, the security network element fails, and the forwarding path status (normal / fault) in the service chain is determined, and then notified to the traffic orchestration module, so that the traffic orchestration module generates a service chain forwarding path table according to the forwarding path status in the service chain. When a security network element or network element group fails, the traffic orchestration module updates the flow table rules, removes the forwarding paths where the faulty security network element or network element group is located from the scheduling queue, and automatically adds the forwarding paths where the security network element or network element group is located back to the scheduling queue after the fault recovery of the security network element or network element group.
[0131] In some embodiments, after receiving the service traffic (data packet), the traffic forwarding module can match it with the flow table generated by the traffic orchestration module (i.e., the association relationship between data packets with different service requirements and service chain types, including the forward flow table and the reverse flow table). If there is a match, the packet is forwarded according to the flow table rules. Otherwise, it is sent to the traffic orchestration module for route selection (i.e., selecting a forwarding path). Further, the traffic orchestration module matches the policy and configures route selection according to the load balancing algorithm. That is, it is determined whether there is a security policy associated with the service requirements of the service traffic. If the security policy matches, the flow table rules (including forward and reverse flow table rules) are assembled and the flow table is configured / updated. Since all data packets are forwarded and processed by the virtual switch, the virtual switch information of the host where the network element is located can be included in the flow table. If the security policy does not match, the packet is discarded, as Figure 5 shown.
[0132] In this application, various network elements in the service chain are added to the service chain in the form of a network element group. The number of network elements in the network element group can be multiple, and the flexibility and scalability of the network elements are higher, adapting to business scenarios with different user scales and high availability. When a single network element fails, high availability of services is achieved by switching the forwarding path within the service chain. When all network elements in the network element group are in a failed state, the entire network element group is bypassed to ensure high availability of services. Secondly, after the service chain configuration is completed in this application, the combined paths of all security network elements can be automatically calculated, and each forwarding path is scheduled using a load balancing algorithm, ensuring the effective utilization of resources, load sharing, and high availability of services for all security network elements. Additionally, by using a virtual switch to send packets to detect the availability of security network elements, not only the timeliness of fault discovery is guaranteed, but also the interference of non-security network element failures caused by excessive forwarding hops of detection packets is avoided.
[0133] Based on the same technical concept, refer to Figure 6 As shown, this application embodiment provides a data packet forwarding device 600. This device 600 can implement any step in the above data packet forwarding method. To avoid repetition, it will not be elaborated here. This device 600 includes a first determination module 601 and a second determination module 602.
[0134] The first determination module 601 is used to determine the data packet to be forwarded, and the data packet contains first parameter information;
[0135] The second determination module 602 is used to select multiple target network element groups from multiple pre-configured network element groups according to the service chain type indicated by the first parameter information; each target network element group in the multiple target network element groups includes at least one security network element of the same network element type;
[0136] Determine multiple forwarding paths based on the security network elements that have not failed in the multiple target network element groups;
[0137] Determine the target forwarding path to be executed from the multiple forwarding paths based on a preset scheduling rule;
[0138] Control the security network elements in the target forwarding path to forward the data packet.
[0139] In a possible implementation manner, when the second determination module 602 determines the target forwarding path to be executed from the multiple forwarding paths based on the second parameter information of the data packet, it is specifically used for:
[0140] Perform a hash operation on the second parameter information of the data packet to determine the hash value of the second parameter information;
[0141] Taking the remainder of the number value of the multiple forwarding paths based on the hash value, and determining a target forwarding path from the multiple forwarding paths according to the remainder result.
[0142] In a possible implementation manner, when the second determination module 602 determines a target forwarding path from the multiple forwarding paths according to the remainder result, it is specifically configured to:
[0143] Determine a target path identifier that matches the remainder result from the path identifiers respectively corresponding to the multiple forwarding paths;
[0144] Taking the forwarding path corresponding to the target path identifier as the target forwarding path.
[0145] In a possible implementation manner, when the second determination module 602 takes the forwarding path corresponding to the target path identifier as the target forwarding path, it is specifically configured to:
[0146] Determine the number of message forwards of the forwarding path corresponding to the target path identifier within a set historical time period;
[0147] When the number of message forwards is not greater than a set message threshold, taking the forwarding path corresponding to the target path identifier as the target forwarding path;
[0148] The second determination module 602 is further configured to:
[0149] When the number of message forwards is greater than the set message threshold, select a service chain whose number of message forwards within the set historical time period is not greater than the set message threshold from the multiple forwarding paths as the target forwarding path.
[0150] In a possible implementation manner, the second determination module 602 is further configured to determine the service chain type indicated by the first parameter information in the following manner:
[0151] Based on the correspondence between pre-configured first parameter information and service chain types, determining the service chain type indicated by the first parameter information;
[0152] Among them, the correspondence between the first parameter information and the service chain type is configured in the following manner:
[0153] For data packets of each service requirement, the following operations are respectively performed:
[0154] Determine the network element types of at least one security network element that needs to be passed through when forwarding target data packets of the target service requirement;
[0155] Determine the connection order between security network elements of at least one network element type to obtain a service chain type;
[0156] Establish a correspondence relationship between the service chain type and the first parameter information of the target data packet.
[0157] In a possible implementation manner, when the second determination module 602 determines multiple forwarding paths based on the secure network elements that do not fail among the multiple target network element groups, it is specifically configured to:
[0158] Perform a fault detection on each secure network element in each target network element group to determine the secure network elements that do not fail;
[0159] Repeat the following operations to obtain multiple forwarding paths:
[0160] For each network element group among the multiple target network element groups, select a target secure network element from the secure network elements that do not fail to obtain multiple target secure network elements;
[0161] Arrange the multiple target secure network elements in order to obtain a forwarding path.
[0162] In a possible implementation manner, the second determination module 602 is further configured to:
[0163] Perform a fault detection on the secure network elements in the following manner:
[0164] Control the virtual switch corresponding to the secure network element to send a forward detection packet to the first interface of the secure network element, and control the virtual switch to send a reverse detection packet to the second interface of the secure network element;
[0165] When it is determined that the virtual switch receives the forward detection packet sent by the second interface and the reverse detection packet sent by the first interface, determine that the secure network element does not fail.
[0166] Based on the same technical concept, refer to Figure 7 As shown, an execution device 700 provided by an embodiment of the present application can implement any step of the data packet forwarding method discussed above. To avoid repetition, it will not be elaborated here. The device 700 includes a memory 701 and a processor 702.
[0167] The memory 701 is used to store program instructions;
[0168] The processor 702 is used to call the program instructions stored in the memory and execute any step of the above data packet forwarding method according to the obtained program.
[0169] In the embodiments of the present application, the processor 702 may be a general-purpose processor, a digital signal processor, an application specific integrated circuit, a field programmable gate array or other programmable logic device, discrete gate or transistor logic device, discrete hardware component, and can implement or execute the various methods, steps and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor may be a microprocessor or any conventional processor, etc. The steps of the method disclosed in combination with the embodiments of the present application can be directly embodied as being executed by a hardware processor, or executed by a combination of hardware and software modules in the processor.
[0170] As a non-volatile computer-readable storage medium, the memory 701 can be used to store non-volatile software programs, non-volatile computer-executable programs and modules. The memory 701 may include at least one type of storage medium, for example, it may include flash memory, hard disk, multimedia card, card-type memory, random access memory (RAM), static random access memory (SRAM), programmable read-only memory (PROM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), magnetic memory, magnetic disk, optical disc, and so on. The memory 701 is any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory 701 in the embodiments of the present application may also be a circuit or any other device capable of implementing a storage function, for storing program instructions and / or data.
[0171] Based on the same technical concept, the embodiments of the present application provide a computer-readable storage medium, the computer-readable storage medium stores a computer program, the computer program includes program instructions, when the program instructions are executed by a computer, the computer is made to execute any step in the above data packet forwarding method, and for the sake of avoiding repetition, it will not be elaborated here.
[0172] Based on the same technical concept, the present application provides a computer program product, the computer program product includes: computer program code, when the computer program code runs on a computer, the computer is made to execute any step in the above data packet forwarding method, and for the sake of avoiding repetition, it will not be elaborated here.
[0173] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.
[0174] The present application is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to the present application. It should be understood that each flow and / or block in the flowchart and / or block diagram, as well as the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices produce means for implementing the functions specified in Figure 1 one or more of the flows Figure 1 or a combination of flows and / or blocks
[0175] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory produce a manufactured article including instruction means that implement the functions specified in Figure 1 one or more of the flows Figure 1 or a combination of flows and / or blocks
[0176] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in Figure 1 one or more of the flows Figure 1 or a combination of flows and / or blocks
[0177] Obviously, those skilled in the art can make various modifications and variations to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalent technologies, the present application also intends to include these modifications and variations.
Claims
1. A method for forwarding data packets, characterized in that, The method includes: Determine a data packet to be forwarded, where the data packet contains first parameter information; According to the service chain type indicated by the first parameter information, select multiple target network element groups from multiple pre-configured network element groups; each target network element group in the multiple target network element groups includes at least one security network element of the same network element type; Based on the non-faulty security network elements in the multiple target network element groups, determine multiple forwarding paths; Based on a preset scheduling rule, determine a target forwarding path that needs to perform forwarding from the multiple forwarding paths; Control the security network elements in the target forwarding path to forward the data packet.
2. The method according to claim 1, wherein The determining, based on a preset scheduling rule, a target forwarding path that needs to perform forwarding from the multiple forwarding paths includes: Perform a hash operation on second parameter information of the data packet to determine a hash value of the second parameter information; Take the remainder of the number value of the multiple forwarding paths based on the hash value, and determine a target forwarding path from the multiple forwarding paths according to the remainder result.
3. The method according to claim 2, characterized in that The determining a target forwarding path from the multiple forwarding paths according to the remainder result includes: Determine a target path identifier that matches the remainder result from the path identifiers corresponding to the multiple forwarding paths respectively; Use the forwarding path corresponding to the target path identifier as the target forwarding path.
4. The method according to claim 1, wherein The determining, based on a preset scheduling rule, a target forwarding path that needs to perform forwarding from the multiple forwarding paths includes: Send probe packets to the multiple forwarding paths respectively; Based on the response times of the probe packets corresponding to the multiple forwarding paths respectively, use the forwarding path with the shortest response time as the target forwarding path.
5. The method according to any one of claims 1 to 4, characterized in that, Determine the service chain type indicated by the first parameter information in the following manner: Based on the pre-configured correspondence between the first parameter information and the service chain type, determine the service chain type indicated by the first parameter information; Among them, the correspondence between the first parameter information and the service chain type is configured in the following manner: For each data packet of each service requirement, perform the following operations respectively: Determine the network element types of at least one security network element that needs to be passed through when forwarding a target data packet for a target service requirement; Determine the connection order among the security network elements of at least one network element type to obtain a service chain type; Establish a correspondence between the service chain type and the first parameter information of the target data packet.
6. The method according to any one of claims 1-4, characterized in that The determining, based on the non-faulty security network elements in the multiple target network element groups, multiple forwarding paths includes: Perform a fault detection on each security network element in each target network element group to determine the non-faulty security network elements; Repeat the following operations to obtain multiple forwarding paths: For each network element group in the multiple target network element groups, select a target security network element from the non-faulty security network elements to obtain multiple target security network elements; Arrange the multiple target security network elements in order to obtain a forwarding path.
7. The method according to claim 6, characterized in that, Perform a fault detection on the security network elements in the following manner: Control the virtual switch corresponding to the security network element to send a forward detection message to the first interface of the security network element, and control the virtual switch to send a reverse detection message to the second interface of the security network element; When it is determined that the virtual switch receives the forward detection message sent by the second interface and the reverse detection message sent by the first interface, it is determined that the security network element has not failed.
8. A forwarding device for data packets, characterized in that, The device includes: A first determination module, configured to determine a data packet to be forwarded, where the data packet contains first parameter information; A second determination module, configured to select a plurality of target network element groups from a plurality of pre-configured network element groups according to the service chain type indicated by the first parameter information; each target network element group in the plurality of target network element groups includes at least one security network element of the same network element type; Determine multiple forwarding paths based on the security network elements that have not failed in the multiple target network element groups; Determine a target forwarding path that needs to perform forwarding from the multiple forwarding paths based on a preset scheduling rule; Control the security network element in the target forwarding path to forward the data packet.
9. An execution device, characterized in that, Includes: A memory, configured to store program instructions; A processor, configured to obtain the program instructions stored in the memory and execute the method according to any one of claims 1-7 according to the program instructions.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, the computer program includes program instructions, and when the program instructions are executed by a computer, the computer is caused to execute the method according to any one of claims 1-7.