Method, device and equipment for realizing packet play by using port group and medium
By configuring the port group and ecmp group and combining ACL rules, fine control of traffic flows on different outgoing ports is achieved, the problem of insufficient granularity in the existing technology is solved, and the flexibility and accuracy of ACL rules are improved.
Patent Information
- Application Number
- CN202510782275.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-12
- Publication Date
- 2025-07-22
AI Technical Summary
In the prior art, the granularity of traffic control based on the incoming port is not fine enough, the user management is not flexible enough, and the traffic flow of different outlets of the same incoming port cannot be finely controlled, and the ACL rules cannot be finely specified to the outgoing port.
By configuring the port group, adding members and enabling the packet spray function, using ACL rules to specify hash selection paths, adding an ecmp group and setting it in the port group collection, deleting the ACL rules to achieve packet-by-packet forwarding, and finally deleting the port group to restore the initial forwarding behavior.
It realizes more refined control of traffic on different outgoing ports, improving the flexibility and accuracy of ACL rules.
Smart Images

Figure CN120358077A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network technologies, and in particular, to a method, device, equipment, and medium for implementing packet spray using port groups. Background Art
[0002] Currently, the design architectures of manufacturers' switching devices are all based on a global perspective. Based on the traffic ingress port, after the traffic enters the corresponding ingress port, per-packet load sharing of the traffic is achieved, and at the same time, ACL rules can be set to ensure that other protocol packets can normally perform flow-based load sharing.
[0003] In order to detect network vulnerabilities, it is usually necessary to use the packet spray technology to send a large number of data packets to the target network or device. However, packet spray is meaningful only on the basis that the next hop of the traffic is ecmp and finally takes effect on the egress port. Currently, for traffic control based on the ingress port, the granularity is not fine enough, and user management is not flexible enough. For the same ingress port, the traffic of different egress ports cannot be finely controlled; similarly, the ACL rules cannot be finely specified for the behavior of the egress port. Summary of the Invention
[0004] In view of the above problems, the purpose of the embodiments of the present invention is to provide a method, device, equipment, and medium for implementing packet spray using port groups to improve the above problems.
[0005] The embodiments of the present invention provide a method for implementing packet spray using port groups, which includes:
[0006] S1, configure a port group, add group members, and enable the packet spray function for the group members;
[0007] S2, match the port group through ACL, enable the ACL rule to specify a flow-based hash selection path;
[0008] S3, add a new ecmp group, and set its ports in the set of the port group to generate corresponding ACL rules according to the configurations of S1 and S2 to affect the traffic forwarded to the ecmp group;
[0009] S4, delete the ACL rule to enable per-packet forwarding of the traffic based on the packet;
[0010] S5, delete the port group to delete the ACL rules generated for the ecmp group, so that the packets return to the initial forwarding behavior.
[0011] Preferably, step S1 is specifically as follows:
[0012] Configure a port group, add members within the group, and set the ECMP mode of the port group to be packet-based, so that the configuration of the port group will notify the ACL module to check whether there is an ACL rule matching the port group currently.
[0013] Preferably, in step S2, configure an ACL rule, bind it to the created port group, and at the same time set the reserved field of the matching reported packet, and specify that the action of packet spray of this ACL rule is disabled.
[0014] Preferably, in step S3, match the newly created ECMP group with the configured port group, so as to issue a packet-based ACL rule to the ECMP group, so that the traffic of the ECMP group can perform per-packet load sharing according to the packet. At the same time, since the issued ACL rule also matches the ECMP group, the traffic that meets the reserved field in the ACL rule will take flow-based hash, and other traffic will take packet-based load sharing.
[0015] Preferably, in step S4, after deleting the ACL rule configured by the user, the traffic of the originally matched ECMP group is forwarded packet by packet according to the packet.
[0016] Preferably, in step S5, find all the currently matched ECMP groups of this port group, and delete the previously issued packet spray ACL rule, then the traffic returns to the behavior of selecting a route according to the hash per flow for forwarding.
[0017] The embodiment of the present invention also provides a device for implementing packet spray by using a port group, which includes:
[0018] A configuration unit, configured to configure a port group, add members within the group, and enable the packet spray function for the members within the group;
[0019] A matching unit, configured to match the port group through the ACL and enable the ACL rule to specify a flow-based hash selection path;
[0020] A setting unit is used to add an ECMP group and set its ports in a set of port groups, so as to generate corresponding ACL rules according to the configurations of a configuration unit and a matching unit to affect the traffic forwarded to the ECMP group;
[0021] A first deletion unit is used to delete ACL rules so that traffic is forwarded packet by packet based on packets;
[0022] A second deletion unit is used to delete port groups to delete the ACL rules generated for the ECMP group, so that the packets return to the initial forwarding behavior.
[0023] An embodiment of the present invention further provides a device for implementing packet spray using port groups, which includes a memory and a processor. A computer program is stored in the memory and can be executed by the processor to implement the method for implementing packet spray using port groups as described above.
[0024] An embodiment of the present invention further provides a computer-readable storage medium that stores a computer program, and the computer program can be executed by the processor of the device where the computer-readable storage medium is located to implement the method for implementing packet spray using port groups as described above.
[0025] In summary, this embodiment proposes the concept of port groups. A series of sets of outgoing ports can be configured in the port group. Users can directly configure packet spray or match to the port group based on ACL rules and set packet spray based on ACL. For the outgoing ports in the routed ECMP group that are subsets of the current port group, according to the configuration of the port group, the function of packet spray for the traffic of these routes is realized. In this way, more refined control of the traffic of different outgoing ports is achieved. BRIEF DESCRIPTION OF THE DRAWINGS
[0026] In order to more clearly illustrate the technical solutions of the present invention, the drawings required for implementation will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0027] Figure 1 It shows a schematic flowchart of a method for implementing packet spray using port groups provided by the first embodiment of the present invention;
[0028] Figure 2 The business process diagram for implementing packet spray based on port group is shown;
[0029] Figure 3 The processing flowcharts of the routing module and ACL module after creating a port group and setting the mode to packet are shown;
[0030] Figure 4 The flowchart showing that the port group is matched by the acl configuration rule and the acl action of packet spray is set to disable is shown;
[0031] Figure 5 The flowchart showing that when the ecmp group is updated, the corresponding ACL rules are issued according to the configuration of the current port group in the routing module and ACL module is shown;
[0032] Figure 6 The flowchart showing that after deleting the previously created ACL rules, the flow-based ACL rules will be deleted, so that the traffic will be forwarded packet by packet based on packet is shown;
[0033] Figure 7 The flowchart showing that after deleting the previously created port group, the previously created ACL rules based on packet spray will be deleted, and the traffic returns to the default flow-based hash routing is shown;
[0034] Figure 8 The structural schematic diagram of the device for implementing packet spray using a port group provided in the second embodiment of the present invention is shown. Detailed implementation manners
[0035] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0036] Please refer to Figure 1 and Figure 2 , the first embodiment of the present invention provides a method for implementing packet spray using a port group, which can be executed by a device for implementing packet spray using a port group (hereinafter referred to as the device), particularly, by one or more processors in the device, to implement the following steps:
[0037] S1, configure the port group, add group members, and enable the packet spray function for the group members.
[0038] In this embodiment, specifically, Figure 3 As shown in the figure, first configure the port group, add members, and set the ecmp mode of the port group to packet-based. At this time, the port group configuration will notify the ACL module to check whether there are currently ACL rules matching the port group. If so, the ACL rules issued by the packet spray action specified by the ACL rules will be used. If not, the cached ACL rule configuration will be updated.
[0039] S2, through ACL matching port group, enable ACL rules to specify the flow-based hash path selection.
[0040] Specifically, if Figure 4 As shown, in step S2, the ACL rule is configured and bound to the created port group, and the reserved field of the matching message is set, and the action of the packet spray of the ACL rule is specified to be disable.
[0041] S3, adds a new ecmp group and sets its port in the set of port groups to generate corresponding ACL rules based on the configuration of S1 and S2 to affect the corresponding traffic forwarded to the ecmp group.
[0042] Specifically, in step S3, Figure 5 As shown in the figure, the newly created ecmp group matches the configured portgroup, so that the packet-based ACL rules are issued to the ecmp group, so that the traffic of the ecmp group can be load-balanced packet by packet. At the same time, because the issued ACL rules also match the ecmp group, the traffic that meets the reserved field in the ACL rules is hashed based on the flow, while other traffic is load-balanced based on the packet.
[0043] S4, delete the ACL rules to forward traffic on a packet-by-packet basis.
[0044] Specifically, in step S4, Figure 6 As shown in the figure, after deleting the user-configured ACL rules, the ecmp groups that were originally matched will be forwarded packet by packet, that is, packet spray.
[0045] In S5, delete the port group to delete the ACL rules generated for the ECMP group, so that the packets return to the initial forwarding behavior.
[0046] Specifically, in step S5, as Figure 7 shown, all current ECMP groups matching this port group will be found, and the previously issued ACL rules for packet spray will be deleted, and the traffic will return to the behavior of selecting routes according to hash for each flow.
[0047] In summary, this embodiment proposes the concept of a port group. A series of outbound port sets can be configured in the port group. Users can directly configure packet spray, or can match the port group based on ACL rules and set packet spray based on ACL. For the outbound ports in the routing ECMP group that are subsets of the current port group, according to the configuration of the port group, the function of packet spray for the traffic of these routes is implemented. In this way, more refined control of the traffic for different outbound ports is achieved.
[0048] Please refer to Figure 8 , the second embodiment of the present invention also provides a device for implementing packet spray using a port group, which includes:
[0049] A configuration unit 210, configured to configure a port group, add group members, and enable the packet spray function for the group members;
[0050] A matching unit 220, configured to match the port group through ACL, enable the ACL rules to specify the hash selection path based on the flow;
[0051] A setting unit 230, configured to add a new ECMP group and set its ports in the set of the port group to generate corresponding ACL rules according to the configurations of the configuration unit and the matching unit to affect the traffic forwarded to the ECMP group;
[0052] A first deletion unit 240, configured to delete the ACL rules so that the traffic is forwarded packet by packet based on the packet;
[0053] A second deletion unit 250, configured to delete the port group to delete the ACL rules generated for the ECMP group, so that the packets return to the initial forwarding behavior.
[0054] The third embodiment of the present invention further provides a device for implementing packet spray using a port group, which includes a memory and a processor. A computer program is stored in the memory and can be executed by the processor to implement the method for implementing packet spray using a port group as described above.
[0055] The fourth embodiment of the present invention further provides a computer-readable storage medium that stores a computer program. The computer program can be executed by the processor of the device where the computer-readable storage medium is located to implement the method for implementing packet spray using a port group as described above.
[0056] In several embodiments provided by the embodiments of the present invention, it should be understood that the disclosed devices and methods can also be implemented in other ways. The device and method embodiments described above are merely illustrative. For example, the flowcharts and block diagrams in the drawings show the possible architectures, functions, and operations of devices, methods, and computer program products according to multiple embodiments of the present invention. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code, and the module, program segment, or part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than marked in the drawings. For example, two consecutive blocks can actually be executed substantially in parallel, and they can sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, as well as the combination of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or actions, or can be implemented by a combination of dedicated hardware and computer instructions.
[0057] In addition, each functional module in various embodiments of the present invention can be integrated together to form an independent part, or each module can exist separately, or two or more modules can be integrated to form an independent part.
[0058] When the above-mentioned functions are implemented in the form of software function modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, an electronic device, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The aforementioned storage medium includes: various media that can store program codes, such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs. It should be noted that in this article, the terms "include", "comprise", or any other variant thereof are intended to cover non-exclusive inclusion, so that a process, method, article, or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed, or also includes elements inherent to such a process, method, article, or device. Without further limitations, an element defined by the statement "including one..." does not exclude the existence of another identical element in the process, method, article, or device including the said element.
[0059] The terms used in the embodiments of the present invention are only for the purpose of describing specific embodiments and are not intended to limit the present invention. The singular forms "a", "the", and "said" used in the embodiments of the present invention and the appended claims are also intended to include the plural forms unless the context clearly indicates otherwise.
[0060] It should be understood that the term "and / or" used herein is only a description of the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B may represent: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the character " / " in this article generally represents an "or" relationship between the associated objects before and after.
[0061] Depending on the context, the word "if" as used herein can be interpreted as "when", "while", "in response to determining", or "in response to detecting". Similarly, depending on the context, the phrase "if determined" or "if detecting (stated condition or event)" can be interpreted as "when determined", "in response to determining", "when detecting (stated condition or event)", or "in response to detecting (stated condition or event)".
[0062] The "first / second" mentioned in the embodiments is merely to distinguish similar objects and does not represent a specific order for the objects. It can be understood that the "first / second" can be interchanged with a specific order or sequence when permitted. It should be understood that the objects distinguished by the "first / second" can be interchanged under appropriate circumstances so that the embodiments described herein can be implemented in an order other than those illustrated or described herein.
[0063] The foregoing is only a preferred embodiment of the present invention and is not intended to limit the present invention. For those skilled in the art, the present invention may have various modifications and variations. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. A method for implementing packet spray using a port group, characterized in that, Including: S1, configure a port group, add members to the group, and enable the packet spray function for the members in the group; S2, match the port group through ACL, enable the ACL rule to specify the path selection based on flow hash; S3, add a new ecmp group, and set its ports in the set of port groups, so as to generate corresponding ACL rules according to the configurations of S1 and S2 to affect the traffic forwarded to the ecmp group; S4, delete the ACL rule to enable packet-by-packet forwarding of traffic; S5, delete the port group to delete the ACL rules generated for the ecmp group, so that the packets return to the initial forwarding behavior.
2. The method for implementing packet spray using a port group according to claim 1, wherein The specific steps of S1 are as follows: Configure a port group, add members to the group, and set the ecmp mode of the port group to be packet-based, so that the configuration of the port group will notify the ACL module to check whether there is an ACL rule matching the port group currently.
3. The method for implementing packet spray using a port group according to claim 1, wherein In step S2, configure the ACL rule, bind it to the created port group, and at the same time set the reserved field of the packet in the match report, and specify that the action of packet spray of this ACL rule is disable.
4. The method for implementing packet spray using a port group according to claim 3, characterized in that, In step S3, match the newly created ecmp group with the configured port group, so as to issue a packet-based ACL rule to the ecmp group, so that the traffic of the ecmp group can perform packet-by-packet load sharing according to packets. At the same time, since the issued ACL rule also matches the ecmp group, the traffic that meets the reserved field in the ACL rule will take the flow-based hash, while other traffic takes the packet-based load sharing.
5. The method for implementing packet spray using a port group according to claim 3, wherein In step S4, after deleting the ACL rule configured by the user, the traffic of the ecmp group that was originally matched is forwarded packet by packet according to packets.
6. The method for implementing packet spray using a port group according to claim 1, wherein In step S5, find all the ecmp groups that currently match this port group, and delete the previously issued packet spray ACL rules, so that the traffic returns to the behavior of selecting the path according to the hash for each flow for forwarding.
7. An apparatus for implementing packet spray using a port group, characterized in that, Including: A configuration unit for configuring a port group, adding members to the group, and enabling the packet spray function for the members in the group; A matching unit for matching the port group through ACL and enabling the ACL rule to specify the path selection based on flow hash; A setting unit for adding a new ecmp group and setting its ports in the set of port groups, so as to generate corresponding ACL rules according to the configurations of the configuration unit and the matching unit to affect the traffic forwarded to the ecmp group; The first deletion unit is used to delete the ACL rule so that the traffic is forwarded packet by packet based on the packet. The second deletion unit is used to delete the port group to delete the ACL rule generated for the ecmp group, so that the packet returns to the initial forwarding behavior.
8. A device for implementing packet spray using a port group, characterized in that, It includes a memory and a processor. A computer program is stored in the memory and can be executed by the processor to implement the method for implementing packet spray using a port group as described in any one of claims 1 to 6.
9. A computer-readable storage medium, characterized in that, A computer program is stored, and the computer program can be executed by the processor of the device where the computer-readable storage medium is located to implement the method for implementing packet spray using a port group as described in any one of claims 1 to 6.