Flow monitoring method, system, device and application
By copying and editing messages within the switch chip, the problem of heavy CPU load in IFA2.0 is resolved, efficient IFA detection and forwarding are achieved, and network stability and performance are improved.
Patent Information
- Application Number
- CN202511026499.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-24
- Publication Date
- 2025-09-12
AI Technical Summary
The IFA 2.0 protocol relies on the CPU to process IFA encapsulation and metadata, which increases the length of service messages and may cause them to be discarded and cause excessive CPU resource usage, affecting network stability and performance.
By copying messages within the switching chip and performing IFA editing processing, the CPU burden is reduced, and the IFA Clone mode is implemented by using hardware instead of software to ensure message forwarding consistency.
It effectively saves CPU resources, improves IFA Clone mode processing performance, ensures network stability and forwarding performance, reduces CPU usage, and improves sampling stability.
Smart Images

Figure CN120639702A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of flow analysis, and in particular relates to a flow monitoring method, system, equipment and application. Background Art
[0002] With the development of cloud computing, the demand for high-performance, low-latency networks is increasing due to the massive amount of data and low-latency applications in the network. To meet these needs, IFA is a technical solution that can effectively control network congestion and monitor latency.
[0003] The IFA2.0 technology solution primarily encapsulates information such as the congestion status of network nodes, queue depth, and latency into packets for on-link detection. During on-link detection, IFA encapsulates the detected information into packets. This approach has the advantage of collecting as much information and information types as possible. However, it increases the length of service packets, potentially preventing them from being forwarded due to MTU detection or chip parser limitations, leading to discarded packets and fluctuations in service stability.
[0004] To address the issue of increased service message length leading to message discard, the IFA 2.0 protocol draft proposes a Clone mode. However, this mode's performance bottleneck stems from CPU processing power. Because both IFA encapsulation and metadata encapsulation are performed by the CPU, a high acquisition frequency can cause congestion detection delays. Furthermore, the high CPU utilization of IFA processing can impact the performance of other services on the CPU.
[0005] Therefore, in response to the above technical problems, it is necessary to provide a flow monitoring method, system, device and application.
[0006] The information disclosed in this background technology section is only intended to enhance understanding of the overall background of the invention and should not be regarded as an admission or any form of suggestion that the information constitutes the prior art already known to a person skilled in the art. Summary of the Invention
[0007] The object of the present invention is to provide a flow monitoring method, system, device and application, which can effectively save CPU resources and improve the processing performance of IFA Clone mode.
[0008] In order to achieve the above object, a specific embodiment of the present invention provides the following technical solutions:
[0009] In a first aspect, the present invention provides a flow monitoring method, comprising:
[0010] Receive and copy the original message from the inbound processing engine;
[0011] Sending the original message along the outbound processing engine, and returning the copied message copy along the outbound processing engine to the inbound processing engine;
[0012] The inbound processing engine performs IFA editing on the returned message copy, and sends the message copy after the IFA editing along the forwarding path of the original message.
[0013] In one or more embodiments of the present invention, the method further comprises:
[0014] In the inbound processing engine, based on the physical port information of the message entering the inbound processing engine and the characteristic information of the message, the ACL table entry is matched to obtain the outbound interface and editing index corresponding to the message;
[0015] The outbound processing engine edits the message based on the outbound interface and the editing index and sends the edited message along the outbound interface.
[0016] In one or more embodiments of the present invention, the step of transmitting the copied message copy back to the inbound processing engine along the outbound processing engine includes:
[0017] Sending the message copy to the outbound processing engine by the replication module;
[0018] The packet copy is transmitted back to the inbound processing engine based on the loop port of the outbound processing engine.
[0019] In one or more embodiments of the present invention, the loop port and the physical port through which the original message enters the inbound processing engine have the same local port number.
[0020] In one or more embodiments of the present invention, the method further comprises:
[0021] Based on a preset sampling frequency, sampling the packets that match and hit the ACL entry;
[0022] The sampled message is marked as an original message that needs to be detected by IFA, and the original message is sent to the replication module.
[0023] In one or more embodiments of the present invention, the method further comprises:
[0024] In the programmable data segment inside the switch chip, the corresponding IFA session identifier is injected into the original message that needs to be IFA detected. The IFA session identifier is associated with an independent IFA encapsulation configuration;
[0025] In response to a return instruction of a message copy corresponding to the original message, the programmable data segment is returned to the inbound processing engine along with the message copy;
[0026] Based on the IFA session identifier in the programmable data segment matching the preset IFA encapsulation configuration, the corresponding IFA message editing process is triggered.
[0027] In one or more embodiments of the present invention, the method further comprises:
[0028] In the inbound processing engine, the IFA session identifier is detected on the returned message.
[0029] If the returned message has a valid IFA session identifier, matching a preset IFA encapsulation configuration based on the IFA session identifier;
[0030] If the returned message does not contain a valid IFA session identifier, the IFA editing process is skipped.
[0031] In a second aspect, the present invention provides a flow monitoring system, comprising:
[0032] A copy module is used to receive and copy the original message from the inbound processing engine;
[0033] A forwarding module, configured to send the original message along the outgoing direction processing engine and return the copied message copy along the outgoing direction processing engine to the incoming direction processing engine;
[0034] The processing module is configured to perform IFA editing on the returned message copy in the inbound processing engine, and send the message copy after the IFA editing along the forwarding path of the original message.
[0035] In a third aspect, the present invention provides a computer device comprising: a memory and a processor, wherein the memory and the processor are communicatively connected to each other, computer instructions are stored in the memory, and the processor executes the flow monitoring method by executing the computer instructions.
[0036] In a fourth aspect, the present invention provides a computer-readable storage medium, wherein the computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a computer to execute the flow monitoring method.
[0037] Compared to existing technologies, the traffic monitoring method provided by this invention addresses the drawback of the original Clone mode's over-reliance on CPU processing. This reduces the CPU burden, thereby ensuring the stability of other CPU services. It also improves the forwarding performance of the IFA Clone mode, ensuring sampling stability even at high sampling frequencies. Furthermore, it reduces the difficulty of user function development and maintenance; implementing Clone mode is achieved simply by configuring the chip according to this solution. BRIEF DESCRIPTION OF THE DRAWINGS
[0038] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments recorded in the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0039] Figure 1 Schematic diagram of an implementation scenario of a flow monitoring method in one embodiment of the present invention;
[0040] Figure 2 Flowchart of a flow monitoring method according to an embodiment of the present invention;
[0041] Figure 3 is a structural block diagram of a flow monitoring system in another embodiment of the present invention;
[0042] Figure 4 It is a structural block diagram of an electronic device in one embodiment of the present invention. DETAILED DESCRIPTION
[0043] In order to enable those skilled in the art to better understand the technical solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of the present invention.
[0044] Unless expressly stated otherwise, throughout the specification and claims, the term "comprise" or variations such as "include" or "comprising", etc., will be understood to include the stated elements or components but not to exclude other elements or other components.
[0045] In one technical implementation, to implement the Clone mode of IFA2.0, the specific operations include: the device collects specified business traffic and performs a cloning operation on the captured business message. After the cloning is completed, the original message will continue to be forwarded along the established path, and no IFA-related encapsulation processing will be performed. At the same time, the cloned business message will be encapsulated with the IFA base header and the required network detection metadata. The cloning and encapsulation process is completed by the host CPU on the device or the embedded CPU integrated in the switching chip and optimized for lightweight processing. Specifically, the CPU is responsible for executing the message copy operation and adding the IFA base header and detection metadata to the generated cloned message.
[0046] However, the encapsulation of the IFA Base Header and Metadata relies entirely on the CPU for software processing. When business traffic is large or high-frequency sampling is required, the CPU may not be able to complete the encapsulation of all cloned messages in a timely manner. This will directly lead to delays in congestion detection results and may even cause packet loss due to backlogs in the processing queue, thus affecting the real-time and accuracy of monitoring. In addition, IFA processing itself consumes a large amount of CPU computing resources. This not only limits the supported IFA sampling rate and traffic scale, but more seriously, it may squeeze the processing power required for other key businesses running on the same CPU, thereby damaging the overall performance and stability of the device. In addition, when software processing occupies resources, it cannot guarantee that the forwarding behavior of cloned messages throughout the network is consistent with the original message, which can easily cause forwarding confusion.
[0047] The inventors of the present invention have discovered the main shortcomings of the existing technology and proposed a new technical implementation idea based on the shortcomings of the existing technology: to implement the IFA2.0 Clone mode based on hardware architecture instead of software. Specifically, the message copying capability of the chip is used to copy the original message. The original message continues to be forwarded according to the forwarding configuration of the business, and the copied message returns to the IPE node through the Loop Channel in the chip, and then continues to be forwarded according to the forwarding configuration of the business, while encapsulating the IFAbase header and metadata information. This solves the shortcoming of over-reliance on CPU processing in the original clone mode. The burden on the CPU is reduced, thereby ensuring the stability of other CPU services. By associating the programmable fields in the chip, errors in the message circulation process can be further reduced and the system stability can be improved. The selection of the loop channel and the original message inlet port ensures that the forwarding behavior of the cloned message in the entire network remains consistent with the original message.
[0048] Please refer to Figure 1, which is a schematic diagram of an application scenario of the traffic monitoring method provided by the present invention under one embodiment, the scenario specifically includes: an inbound processing engine (IPE) 101, a duplication module (Duplicate module) 102 and an outbound processing engine (EPE) 103.
[0049] It should be noted that communication connections are established between the inbound processing engine (IPE) 101, the replication module (Duplicate module) 102, and the outbound processing engine (EPE) 103. The communication network extended by the communication connection can include various connection types, including but not limited to: wired connection, wireless connection, or fiber optic cable connection. In addition, the communication network can be a local area network, a metropolitan area network, a wide area network, or any combination of the three.
[0050] like Figure 1 As shown, a packet enters from the IPE and is matched against the service packet's features in the IPE's ACL module. If a match is found, log sampling is enabled on the IPE module and the sampling frequency is configured. The original packet also matches the service forwarding configuration, such as L2 / L3, at the IPE node. The outbound interface and edit index are obtained after a match. The packet is then replicated in the replication module, with the destination port set to the loop channel. No processing is performed in the EPE phase, and the packet loops back to the IPE. The original packet is then edited in the EPE phase based on the outbound interface and edit index obtained in the IPE phase, and forwarded to the designated outbound interface. After the replicated packet loops back to the IPE, the local port in the IPE matches the original packet, ensuring consistent forwarding behavior. The replicated packet is then matched against the ACL again, and if a match is found, the IFA edit process is performed.
[0051] It should be noted that in the implementation scenario of the present invention, at least one user terminal should also be provided. The user terminal is installed with a computer software program that matches the traffic monitoring method provided by this method, and is used to provide a platform for users to configure custom items. In an embodiment of the present invention, the custom items may include but are not limited to: sampling frequency, IFA encapsulation configuration, the correspondence between the IFA session identifier and the IFA encapsulation configuration, etc. The present invention does not limit the custom items.
[0052] Furthermore, the user terminal 103 may include but is not limited to a desktop computer (PC), a desktop computer, a smart phone, a handheld computer, a tablet computer, a personal digital assistant (PDA), and other portable electronic devices or wearable electronic devices. The embodiments of the present invention do not limit the above content.
[0053] It should also be noted that the flow monitoring method of the embodiments of the present invention can be applied to the flow monitoring system of the embodiments of the present invention. The flow monitoring system can be deployed on a terminal. The terminal may include, but is not limited to, a PC (Personal Computer), a PDA (Tablet Computer), a smartphone, a smart wearable device, and the like.
[0054] Please refer to Figure 2 FIG. 1 is a flow chart of a flow monitoring method according to an embodiment of the present invention. The flow monitoring method specifically comprises the following steps:
[0055] S201: Receive and copy the original message from the inbound processing engine;
[0056] In this embodiment of the present invention, the ingress pipeline engine processes inbound traffic, specifically packets entering the system from the outside. "External ingress" generally refers to data arriving from a specific port on the ingress pipeline engine. These ports include at least physical ports connected to other packet output ports and loopback ports on the outbound pipeline engine.
[0057] It should be noted that the original message in the present invention refers to the message that enters the inbound processing engine for the first time from the external physical port and requires IFA detection. The message that requires IFA detection in the present invention can refer to all service messages that meet the above conditions, or select some service messages that meet the conditions for IFA detection.
[0058] It is understandable that if all business messages that meet the conditions are configured as original messages that need to be detected by IFA, and operations such as copying, marking and deep detection are performed in the subsequent processing unit, the network flow status information can be obtained to the greatest extent. Since a complete sample of traffic is captured, this mode helps to significantly improve the accuracy and coverage of IFA detection; on the other hand, if only a portion of eligible messages are selected for IFA detection, it is a resource optimization strategy. This mode can effectively reduce the burden on the system in terms of memory resources and computing resources, and is more suitable for scenarios that are sensitive to resources or have extremely high traffic loads. The two modes have different applicable scenarios, and can be dynamically selected according to actual needs. The embodiment of the present invention does not limit this. In order to facilitate users to flexibly adjust the above two modes, the following is a preferred embodiment of the present invention.
[0059] In this preferred embodiment, the traffic monitoring method provided by the present invention further includes: sampling the messages that match and hit the ACL table entry based on a preset sampling frequency; marking the sampled messages as original messages that need to be detected by IFA, and sending the original messages to the replication module.
[0060] It is understood that the sampling frequency ranges from [0 to 1]. As the sampling frequency increases, the proportion of original messages marked as requiring IFA detection increases. When the sampling frequency is 1, this proportion reaches its peak, indicating that all service messages require IFA detection. Users can control the number of original messages by adjusting the sampling frequency based on the actual processing capacity of the system.
[0061] It should also be noted that, unlike conventional message processing, where ACL entries are matched based on quintuple information, the inbound processing engine can distinguish between the original message and the looped-back message copy by matching ACL entries based on the physical port information of the original message or message copy entering the inbound processing engine and the feature information of the original message or message copy, thereby obtaining the outbound interface, editing index, and subsequent operations of the original message or message copy.
[0062] S202: The original message is sent out along the outbound processing engine, and the copied message copy is returned to the inbound processing engine along the outbound processing engine;
[0063] In an exemplary embodiment, transmitting the copied message copy back to the inbound processing engine along the outbound processing engine includes: sending the message copy from the replication module to the outbound processing engine; and transmitting the message copy back to the inbound processing engine based on a loopback port of the outbound processing engine. Alternatively, for the original message, the outbound processing engine may edit the message based on the outbound interface and the edit index, and transmit the edited message along the outbound interface.
[0064] The replication module is set in the message transmission link, and the input port of the replication module is connected to the output port of the input processing engine; the output port of the replication module is connected to the input port of the output processing engine. It can be understood that the replication module is located between the input processing engine and the output processing engine in the data transmission link and has the message replication capability. The replication module can be an independent functional module, or it can reuse the replication function of other modules in appropriate positions. For example, Figure 1 In the usage scenario shown, the copy function of the copy module reuses the message copy function of the memory management unit in the switch.
[0065] The destination port corresponding to the message copy generated by the replication is a loop channel of the egress processing engine. The loop channel is set with the egress processing engine and is used to loop the message from the egress processing engine back to the corresponding ingress processing engine.
[0066] It should be noted that the loopback port through which the message copy is transmitted back to the inbound processing engine must have the same local port number as the physical port through which the corresponding original message entered the inbound physical engine. The local port number is an externalized representation of the inherent logical relationship between ports. By looping back through a loopback port with the same local port number as the physical port through which the original message was transmitted, the message copy in the inbound processing engine has the same local port information as the corresponding original message. This further ensures that the forwarding lookup (L2 / L3) behavior of the message copy in the inbound processing engine is completely consistent with that of the original message, and that the correct outbound interface and edit index are obtained.
[0067] S203: In the inbound processing engine, perform IFA editing on the returned message copy, and send the message copy after the IFA editing along the forwarding path of the original message.
[0068] In an exemplary embodiment, the returned message copy can traverse the ACL table entries based on the port information (loop port) of the message entering the inbound processing engine and its message characteristics to obtain the IFA editing behavior, the outbound interface, and the editing index in the outbound processing engine.
[0069] However, in scenarios with mixed multi-service flows or different congestion signaling detection requirements, messages identical to the duplicated message may be looped back to the inbound processing engine via the loopback port. In this case, matching the ACL can cause messages that do not require IFA detection to be mistakenly edited using IFA. To address this situation, the present invention provides another exemplary embodiment as follows.
[0070] In this exemplary embodiment, IFA editing and ACL rules are independent of each other and do not affect each other. Specifically, it includes: injecting the corresponding IFA session identifier into the programmable data segment inside the switching chip for the original message that needs to be detected by IFA, and the IFA session identifier is associated with an independent IFA encapsulation configuration; in response to the return instruction of the message copy corresponding to the original message, the programmable data segment is returned to the inbound processing engine along with the message copy; in the inbound processing engine, the IFA session identifier is detected on the returned message; if the returned message has a valid IFA session identifier, the preset IFA encapsulation configuration is matched based on the IFA session identifier; if the returned message does not have a valid IFA session identifier, the IFA editing process is skipped.
[0071] The programmable data segment is located inside the switching chip and is transmitted along with the original message before passing through the replication module. After passing through the replication module, it is transmitted along with the message copy corresponding to the original message, and is used to identify the message as requiring IFA editing after the copy is returned to the inbound processing engine. Furthermore, different IFA session identifiers can directly correspond to different IFA editing and processing rules, including but not limited to: encapsulation format, metadata type, etc., and are used to indicate to the inbound processing engine what kind of editing and processing should be performed on the message copy.
[0072] Please refer to Figure 3 As shown, based on the same inventive concept as the aforementioned traffic monitoring method, an embodiment of the present invention provides a traffic monitoring system 300 , which includes: a replication module 301 , a forwarding module 302 and a processing module 303 .
[0073] Specifically, the copy module 301 is used to receive and copy the original message from the input direction processing engine; the forwarding module 302 is used to send the original message along the output direction processing engine, and return the copied message copy along the output direction processing engine to the input direction processing engine; the processing module 303 is used to perform IFA editing on the returned message copy in the input direction processing engine, and send the message copy after the IFA editing along the forwarding path of the original message.
[0074] Please refer to Figure 4 As shown, an embodiment of the present invention further provides an electronic device 400, which includes at least one processor 401, a memory 402 (e.g., a non-volatile memory), a storage 403, and a communication interface 404, wherein the at least one processor 401, the memory 402, the storage 403, and the communication interface 404 are connected together via an internal bus 405. The at least one processor 401 is configured to call at least one program instruction stored or encoded in the storage 402, so that the at least one processor 401 performs various operations and functions of the flow monitoring method described in various embodiments of this specification.
[0075] In the embodiments of the present specification, the electronic device 400 may include but is not limited to: a personal computer, a server computer, a workstation, a desktop computer, a laptop computer, a notebook computer, a mobile electronic device, a smart phone, a tablet computer, a cellular phone, a personal digital assistant (PDA), a handheld device, a messaging device, a wearable electronic device, a consumer electronic device, and the like.
[0076] An embodiment of the present invention further provides a computer-readable medium carrying computer-executable instructions. When the computer-executable instructions are executed by a processor, they can be used to implement the various operations and functions of the flow monitoring method described in the various embodiments of this specification.
[0077] The computer-readable medium in the present invention may be a computer-readable signal medium or a computer-readable storage medium, or any combination thereof. A computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of computer-readable storage media may include, but are not limited to, an electrical connection having one or more conductors, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In the present invention, a computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device.
[0078] In the present invention, a computer-readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, which carries computer-readable program code. This propagated data signal may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A computer-readable signal medium may also be any computer-readable medium other than a computer-readable storage medium, which may transmit, propagate, or transfer a program for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium may be transmitted using any suitable medium, including but not limited to wireless, wired, optical cable, RF, etc., or any suitable combination thereof.
[0079] Those skilled in the art will appreciate that embodiments of the present invention may be provided as methods, systems, or computer program products. Thus, the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0080] The present invention is described with reference to flowcharts and / or block diagrams of methods, apparatuses, systems, and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowcharts and / or block diagrams, as well as combinations of processes and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowcharts and / or block diagrams. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0081] The foregoing descriptions of specific exemplary embodiments of the present invention are for purposes of illustration and description. These descriptions are not intended to limit the invention to the precise forms disclosed, and it is apparent that many variations and modifications are possible in light of the foregoing teachings. The exemplary embodiments have been selected and described for the purpose of explaining the specific principles of the invention and their practical application, thereby enabling those skilled in the art to realize and utilize a variety of exemplary embodiments of the invention and various options and modifications. The scope of the invention is intended to be defined by the claims and their equivalents.
[0082] It will be apparent to those skilled in the art that the present invention is not limited to the details of the exemplary embodiments described above and that the invention can be embodied in other specific forms without departing from the spirit or essential characteristics of the invention. Therefore, the embodiments should be considered in all respects as illustrative and non-restrictive, and the scope of the invention is defined by the appended claims, not the foregoing description, and all variations within the meaning and range of equivalents of the claims are intended to be included therein. Any reference sign in a claim should not be construed as limiting the claim to which it relates.
[0083] In addition, it should be understood that although this specification is described in terms of implementation methods, not every implementation method contains only one independent technical solution. This narrative method of the specification is only for the sake of clarity. Those skilled in the art should regard the specification as a whole. The technical solutions in each embodiment can also be appropriately combined to form other implementation methods that can be understood by those skilled in the art.
Claims
1. A flow monitoring method, characterized in that: include: Receive and copy the original message from the inbound processing engine; Sending the original message along the outbound processing engine, and returning the copied message copy along the outbound processing engine to the inbound processing engine; The inbound processing engine performs IFA editing on the returned message copy, and sends the message copy after the IFA editing along the forwarding path of the original message.
2. The flow monitoring method according to claim 1, characterized in that: The method further comprises: In the programmable data segment inside the switch chip, the corresponding IFA session identifier is injected into the original message that needs to be IFA detected. The IFA session identifier is associated with an independent IFA encapsulation configuration; In response to a return instruction of a message copy corresponding to the original message, the programmable data segment is returned to the inbound processing engine along with the message copy; Based on the IFA session identifier in the programmable data segment matching the preset IFA encapsulation configuration, the corresponding IFA message editing process is triggered.
3. The flow monitoring method according to claim 2, characterized in that: The method further comprises: In the inbound processing engine, the IFA session identifier is detected on the returned message. If the returned message has a valid IFA session identifier, matching a preset IFA encapsulation configuration based on the IFA session identifier; If the returned message does not contain a valid IFA session identifier, the IFA editing process is skipped.
4. The flow monitoring method according to claim 1, characterized in that: The method further comprises: Based on the preset sampling frequency, samples the packets that match and hit the ACL entries. The sampled message is marked as an original message that needs to be detected by IFA, and the original message is sent to the replication module.
5. The flow monitoring method according to claim 1, characterized in that: The step of transmitting the copied message copy back to the inbound processing engine along the outbound processing engine includes: Sending the message copy to the outbound processing engine by the replication module; The packet copy is transmitted back to the inbound processing engine based on the loop port of the outbound processing engine.
6. The flow monitoring method according to claim 5, characterized in that: The loop port has the same local port number as the physical port through which the original message enters the inbound processing engine.
7. The flow monitoring method according to claim 1, characterized in that: The method further comprises: In the inbound processing engine, based on the port information of the message entering the inbound processing engine and the characteristic information of the message, the ACL table entry is matched to obtain the outbound interface and editing index corresponding to the message; The outbound processing engine edits the message based on the outbound interface and the editing index and sends the edited message along the outbound interface.
8. A flow monitoring system, characterized in that: include: A copy module is used to receive and copy the original message from the inbound processing engine; A forwarding module, configured to send the original message along the outgoing direction processing engine and return the copied message copy along the outgoing direction processing engine to the incoming direction processing engine; The processing module is configured to perform IFA editing on the returned message copy in the inbound processing engine, and send the message copy after the IFA editing along the forwarding path of the original message.
9. A computer device, characterized in that: include: A memory and a processor, wherein the memory and the processor are communicatively connected to each other, the memory stores computer instructions, and the processor executes the flow monitoring method according to any one of claims 1 to 7 by executing the computer instructions.
10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a computer to execute the flow monitoring method according to any one of claims 1 to 7.