Network device, network forwarding function configuration method, storage medium and program

CN122824697APending Publication Date: 2026-09-25CLOUD INTELLIGENCE ASSETS HOLDING (SINGAPORE) PTE LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510353623.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-24
Publication Date
2026-09-25

AI Technical Summary

Technical Problem

[0004]在实际应用中,当应用层的某应用程序需求变化,从而需要修改报文转发规则时,只能把报文转发规则的修改操作在软件侧的处理器上触发,而网络芯片则无法感知该报文转发规则的修改

Benefits of technology

[0021]第五方面,本申请实施例提供了一种非暂时性机器可读存储介质,所述非暂时性机器可读存储介质上存储有可执行代码,当所述可执行代码被电子设备的处理器执行时,使所述处理器至少可以实现如第二方面或第三方面所述的网络转发功能配置方法。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122824697A_ABST
    Figure CN122824697A_ABST
Patent Text Reader

Abstract

Embodiments of the present application provide a network device, a network forwarding function configuration method, a storage medium and a program. The network device comprises a network card and a virtual machine. The network card comprises a processor and a network chip, and the processor runs a virtual switch. The virtual switch is configured to, in response to a first packet forwarding configuration being changed to a second packet forwarding configuration corresponding to a target port of the virtual machine, generate a correspondence between a port identifier of the target port and a first version number, and synchronize the correspondence to the network chip. The network chip is configured to receive a first packet corresponding to the target port, and if it is determined that a first flow table entry matching a packet identifier of the first packet exists in a locally stored flow table, and a second version number corresponding to the port identifier in the first flow table entry is different from the first version number in the correspondence, it is determined that the first flow table entry needs to be updated. The present scheme can quickly and efficiently enable the network chip on the hardware side to perceive the change in the packet forwarding configuration corresponding to the target port.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network communication technology, and in particular to a network device, a network forwarding function configuration method, a storage medium, and a program. Background Technology

[0002] With the development of cloud computing, users' performance demands on network devices are increasing. These network devices include multiple virtual machines and network interface cards (NICs) for forwarding packets between these virtual machines. The NICs contain processors that provide packet forwarding configuration. It's important to note that in addition to packet forwarding, these processors also need to perform other processing functions, such as controlling bandwidth allocation, data format conversion, and normalization. Performing so many processing functions inevitably increases their workload.

[0003] Therefore, many current network interface cards (NICs) incorporate network chips with hardware offloading capabilities. This offloads the aforementioned packet forwarding configuration to the network chip for execution. In this way, packets sent and received by multiple virtual machines are forwarded and processed through this network chip, thereby reducing the processor's load. To implement the network chip's offloading function, flow table entries corresponding to the packet forwarding configurations supported by the processor need to be set in the network chip. Multiple flow table entries are used to generate a flow table, which is then used to implement the forwarding of packets sent and received by multiple virtual machines within the network chip.

[0004] In practical applications, when the requirements of an application at the application layer change, thus requiring modification of the packet forwarding rules, the modification operation can only be triggered on the processor on the software side, while the network chip cannot detect the modification of the packet forwarding rules. Summary of the Invention

[0005] This application provides a network device, a network forwarding function configuration method, a storage medium, and a program that enable the network chip on the hardware side to quickly and efficiently detect changes in the packet forwarding configuration corresponding to the target port.

[0006] In a first aspect, embodiments of this application provide a network device, the network device comprising: a network interface card (NIC) and a virtual machine;

[0007] The network interface card includes a processor and a network chip. The processor runs a virtual switch, and the virtual switch provides packet forwarding configuration corresponding to the target port of the virtual machine.

[0008] The virtual switch is configured to, in response to a change in the first packet forwarding configuration corresponding to the target port of the virtual machine to the second packet forwarding configuration, generate a correspondence between the port identifier of the target port and the first version number, and synchronize the correspondence to the network chip. The first version number is used to reflect the number of times the packet forwarding configuration corresponding to the target port has been changed.

[0009] The network chip is used to receive a first packet corresponding to the target port. If it is determined that there is a first flow table entry in the locally stored flow table that matches the packet identifier of the first packet, and based on the second version number in the first flow table entry corresponding to the port identifier and the first version number in the correspondence, it determines whether the packet forwarding configuration has changed.

[0010] The first flow table entry contains first forwarding operation information determined according to the first packet forwarding configuration, and the second version number is the version number corresponding to the target port when the virtual switch generates the first flow table entry.

[0011] Secondly, embodiments of this application provide a network forwarding function configuration method. The method is applied to a virtual switch running in the network interface card (NIC) of a network device. The virtual switch runs in the processor of the NIC, and the virtual switch provides packet forwarding configuration corresponding to the target port of the virtual machine. The NIC further includes a network chip, and the network device further includes a virtual machine. The method includes:

[0012] In response to a change in the first packet forwarding configuration corresponding to the target port of the virtual machine to the second packet forwarding configuration, a correspondence between the port identifier of the target port and the first version number is generated, wherein the first version number is used to reflect the number of times the packet forwarding configuration corresponding to the target port has been changed;

[0013] The correspondence is synchronized to the network chip so that when the network chip receives a first packet corresponding to the target port, it determines that there is a first flow table entry in its locally stored flow table that matches the packet identifier of the first packet. Based on the second version number corresponding to the port identifier in the first flow table entry and the first version number in the correspondence, it determines whether the packet forwarding configuration has changed.

[0014] The first flow table entry contains first forwarding operation information determined according to the first packet forwarding configuration, and the second version number is the version number corresponding to the target port when the virtual switch generates the first flow table entry.

[0015] Thirdly, embodiments of this application provide a network forwarding function configuration method. The method is applied to a network chip in a network interface card (NIC) of a network device. The NIC further includes a processor running a virtual switch. The virtual switch provides packet forwarding configuration corresponding to the target port of the virtual machine. The network device also includes a virtual machine. The method includes:

[0016] The virtual switch receives the correspondence between the port identifier of the target port and the first version number, wherein the correspondence is generated by the virtual switch in response to the change of the first packet forwarding configuration corresponding to the target port to the second packet forwarding configuration;

[0017] Receive the first message corresponding to the target port;

[0018] If it is determined that there is a first flow table entry in the locally stored flow table that matches the packet identifier of the first packet, then based on the second version number corresponding to the port identifier in the first flow table entry and the first version number in the correspondence, it is determined whether the packet forwarding configuration has changed;

[0019] The first flow table entry contains first forwarding operation information determined according to the first packet forwarding configuration, and the second version number is the version number corresponding to the target port when the virtual switch generates the first flow table entry.

[0020] Fourthly, embodiments of this application provide an electronic device, the electronic device including: a memory, a processor, and a communication interface; wherein, the memory stores executable code, and when the executable code is executed by the processor, the processor performs the network forwarding function configuration method as described in the second or third aspect.

[0021] Fifthly, embodiments of this application provide a non-transitory machine-readable storage medium storing executable code, which, when executed by a processor of an electronic device, enables the processor to at least implement the network forwarding function configuration method as described in the second or third aspect.

[0022] Sixthly, embodiments of this application provide a computer program product, the computer program product including a computer program, which, when executed by a processor, can implement the network forwarding function configuration method as described in the second or third aspect.

[0023] The network device provided in this application embodiment generates a correspondence between the port identifier and the first version number of the target port when the packet forwarding configuration corresponding to the target port is changed in the virtual switch in the software side processor. This correspondence is then synchronized to the network chip on the hardware side to ensure that the network chip on the hardware side can promptly detect any changes in the packet forwarding configuration corresponding to the target port, thus laying the foundation for subsequent packets to be accurately forwarded by the network chip.

[0024] In practical applications, when a network chip receives the first packet corresponding to a target port, it first checks if a first flow table entry matching the packet identifier of the first packet exists in its locally stored flow table. If it does, it determines whether the packet forwarding configuration has changed based on the second version number corresponding to the port identifier in the first flow table entry and the first version number in the corresponding relationship. That is, the network chip successfully detects whether the packet forwarding configuration corresponding to the target port has changed. Next, it only needs to update the first flow table entry in a timely manner and continue packet forwarding based on the updated first flow table entry. In summary, this solution mainly involves two parts: "synchronization of the corresponding relationship" and "comparison of version numbers." The operation steps are simple, and the amount of data to be operated is small, enabling the network chip on the hardware side to quickly and efficiently detect changes in the packet forwarding configuration corresponding to the target port. Attached Figure Description

[0025] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0026] Figure 1 This application provides a schematic diagram of the structure of a network device according to an embodiment of the present application.

[0027] Figure 2 This application provides an schematic diagram of a network device.

[0028] Figure 3 This is another application diagram of a network device provided in an embodiment of this application;

[0029] Figure 4 This is a schematic diagram illustrating another application of a network device provided in an embodiment of this application;

[0030] Figure 5 This is an application diagram illustrating a network forwarding function configuration method provided in an embodiment of this application;

[0031] Figure 6A flowchart illustrating a network forwarding function configuration method provided in this application embodiment;

[0032] Figure 7 Another flowchart of a network forwarding function configuration method provided in an embodiment of this application;

[0033] Figure 8 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation

[0034] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application. In addition, the timing of the steps in the following method embodiments is only an example and not a strict limitation.

[0035] It should be noted that, in the cases involving user information in the embodiments of this application, the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in the embodiments of this application are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, use, and processing of related data must comply with the relevant laws, regulations, and standards of the relevant countries and regions, and corresponding operation entry points are provided for users to choose to authorize or refuse. In addition, the various models involved in this application (including but not limited to large language models or other models) comply with relevant laws and standards.

[0036] First, the terms or concepts involved in the embodiments of this application will be explained:

[0037] Virtual Switch (vSwitch): A software-simulated switch responsible for forwarding virtual machine traffic. It is used to forward packets received by network devices to virtual machines, or to forward packets sent by virtual machines to external networks.

[0038] Hardware offloading based on network interface card (NIC): The process of offloading the functionality of the software in the NIC to the hardware chip in the NIC.

[0039] Flow table: A table used to record packet forwarding rules in a virtual switch.

[0040] Flow entry: A flow table contains an entry that specifies the packet forwarding rules.

[0041] A network flow is a set of data packets that share common characteristics that allow network devices to treat them as a logical whole. A network flow is typically identified based on at least one of the following fields: source IP address, destination IP address, source port number, destination port number, and protocol type.

[0042] Currently, many network interface cards (NICs) incorporate a network chip, offloading packet forwarding configuration to be executed within the network chip. In practical applications, when packet forwarding rules need to be modified, the modification operation can only be triggered on the software-side processor, while the network chip remains unaware of the change.

[0043] In view of this, this application provides a network device that solves the above problems through the following approach: Using a software-side virtual switch, when the packet forwarding configuration corresponding to the target port of the virtual machine changes, a correspondence between the port identifier of the target port and the first version number is generated, and this correspondence is synchronized to the network chip. When the hardware-side network chip receives the first packet corresponding to the target port in actual application, if it determines that the first packet can match the first flow table entry in the locally stored flow table, it determines whether the packet forwarding configuration has changed based on the second version number corresponding to the port identifier in the first flow table entry and the first version number in the correspondence. At this point, it indicates that the network chip has successfully detected whether the packet forwarding configuration corresponding to the target port has changed. The entire detection process is simple and fast, enabling the hardware-side network chip to efficiently detect changes in the packet forwarding configuration corresponding to the target port, thus allowing for timely processing when the packet forwarding configuration corresponding to the target port changes, ensuring the accuracy of subsequent packet forwarding.

[0044] Figure 1 This is a schematic diagram of the structure of a network device provided in an embodiment of this application, such as... Figure 1 As shown, the network device 10 includes a network interface card (NIC) 11 and a virtual machine 12. The NIC 11 includes a processor 111 and a network chip 112. The processor 111 runs a virtual switch, which provides packet forwarding configuration corresponding to the target port of the virtual machine 12.

[0045] The virtual switch, in response to a change in the first packet forwarding configuration corresponding to the target port of virtual machine 12 to a second packet forwarding configuration, generates a mapping between the port identifier of the target port and the first version number, and synchronizes this mapping to network chip 112. The first version number reflects the number of times the packet forwarding configuration corresponding to the target port has been changed. Network chip 112 receives the first packet corresponding to the target port. If it determines that a first flow table entry matching the packet identifier of the first packet exists in its locally stored flow table, it determines whether the packet forwarding configuration has changed based on the second version number corresponding to the port identifier in the first flow table entry and the first version number in the mapping. If the second version number corresponding to the port identifier in the first flow table entry is different from the first version number in the mapping, it determines that the first flow table entry needs to be updated. The first flow table entry contains first forwarding operation information determined according to the first packet forwarding configuration. The second version number is the version number corresponding to the target port when the virtual switch generates the first flow table entry. Simply put, the second version number is the initial version number corresponding to the target port in the first flow table entry, which is less than or equal to the first version number.

[0046] It should be noted that the network interface card 11 can be a standard network interface card (NIC) or a smart NIC; no specific limitation is made here. There can be one or more virtual machines 12, and each virtual machine 12 can be configured with multiple virtual NICs. Each virtual NIC has a corresponding port, which can be logically bound to the NIC 11 through a virtual switch in the processor 111, thereby enabling communication between the virtual machine 12 and the external network. The same port can correspond to different network flows, and different network flows can be distinguished by the five-tuple information of the packets. The network chip 112 can be an application-specific integrated circuit (AISC), a field-programmable gate array (FPGA), or similar.

[0047] Furthermore, each port can be associated with at least one packet forwarding rule, and at least one packet forwarding rule constitutes a packet forwarding configuration. Packet forwarding rules can be, for example, Access Control Lists (ACLs), Route rules, Quality of Service (QoS) rules, etc., which will not be listed here. ACL rules are used to allow or deny the transmission of certain packets by matching packet characteristics (such as matching source IP address, destination IP address, source port number, destination port number, etc.). Route rules are used to select the path for packet transmission based on the routing table, ensuring that data arrives at its destination from the source. QoS rules are used to optimize network resource allocation, avoid congestion, and ensure low latency and high reliability for high-priority traffic through priority marking, bandwidth guarantees, traffic shaping, and other means.

[0048] To facilitate understanding, the following explanation will use the example of virtual machine 12 sending a message to the external network. (It should be understood that the processing logic of virtual machine 12 receiving and sending messages at network card 11 is the same. The only difference is that sending a message is a process of encapsulating the message, while receiving a message is a process of decapsulating it. Therefore, the processing of receiving messages will not be described in detail below.)

[0049] In practical applications, a packet forwarding configuration is considered changed if at least one parameter in the packet forwarding rules corresponding to the packet forwarding configuration changes. For example, suppose that initially, the first packet forwarding configuration is based on ACL rules and routing rules, specifically "only allow internal network access, next hop address is A". Now, according to the needs of the application in the application layer, the first packet forwarding configuration corresponding to the target port is changed to the second packet forwarding configuration (such as "only allow internal network access, next hop address is B"). It is clear that the next hop address has changed, which indicates that the packet forwarding configuration corresponding to the port has changed. Subsequently, the virtual switch in processor 111 receives the change information of the packet forwarding configuration and generates a mapping between the port identifier of the target port and the first version number based on this change information, synchronizing this mapping to network chip 112.

[0050] In specific implementation, when network chip 112 receives the first packet corresponding to the target port, it parses the first packet to obtain the packet identifier corresponding to the first packet. Network chip 112 then determines whether there is a first flow table entry in the locally stored flow table that matches the packet identifier of the first packet. The specific representation of the flow table can be found in [reference needed]. Figures 2-4The "flow table" in the context of flow tables consists of a single entry, where each row represents a flow table entry. A flow table entry can contain information such as flow ID, virtual network interface ID (port ID), traffic direction (dir), source IP address (sip), destination IP address (dip), source port number (sport), destination port number (dport), protocol type (proto), port version (port version), and forwarding action information. For more details, please refer to [link to relevant documentation / reference]. Figures 2-4 .

[0051] Specifically, the packet identifier of the first packet (such as source IP address, destination IP address, source port number, protocol type, etc.) can be matched with each flow table entry in the flow table. If a flow table entry matching the packet identifier exists, it is determined that a first flow table entry matching the packet identifier of the first packet exists in the locally stored flow table. It should be noted that the flow identifier (flow id) is not used as a matching condition in the flow table entry; all other items can be used as matching conditions between the packet identifier and the flow table entry. For example, assuming the packet identifier of the first packet contains source IP address, destination IP address, source port number, destination port number, and protocol type, then if the flow table locally stored by the network chip 112 contains a flow table entry with the same values ​​as the first packet's "source IP address, destination IP address, source port number, destination port number, and protocol type," then it can be determined that a first flow table entry matching the packet identifier of the first packet exists in the flow table.

[0052] After determining the first flow entry, it is also necessary to further determine whether the second version number corresponding to the port identifier in the first flow entry is the same as the first version number.

[0053] One approach is to directly compare the second version number corresponding to the port identifier in the first flow entry with the first version number. If the comparison results are different, it can be determined that the second version number corresponding to the port identifier in the first flow entry is different from the first version number in the correspondence. In this case, it indicates that the first packet forwarding configuration corresponding to the port identifier has changed, and the first flow entry needs to be updated.

[0054] As another implementation, processor 111 maintains a table mapping port numbers to version numbers, which can be found in [reference needed]. Figures 2-4 The "Correspondence Table 1" in the document illustrates the correspondence between four port numbers and version numbers. Assuming the target port number is "1", its corresponding first version number is 5, indicating that the packet forwarding configuration for the target port has changed five times. Similarly, network chip 112 also maintains a correspondence table between port numbers and version numbers; see [link to relevant documentation] for details. Figures 2-4The contents of "Correspondence Table 2" are the same as those in "Correspondence Table 1" if the packet forwarding configuration corresponding to the port remains unchanged. See [link to relevant documentation] for details. Figure 2 The data in "Correspondence Table 1" and "Correspondence Table 2".

[0055] In practice, after the virtual switch in processor 111 generates the mapping between the port identifier and the first version number of the target port based on the change information of the packet forwarding configuration, it will update the mapping to the "Mapping Table 1" maintained in processor 111 (the updated "Mapping Table 1" can be found in [reference]). Figure 3 ,exist Figure 3 In the process, the first version number corresponding to port 1 in "Correspondence Table 1" is updated to 6), and the updated content in "Correspondence Table 1" is synchronized to "Correspondence Table 2" in network chip 112 (the synchronized "Correspondence Table 2" can be found in [reference]). Figure 3 ,exist Figure 3 In the process, the first version number corresponding to port 1 in "Correspondence Table 2" is also updated to 6. Then, the version number corresponding to the port identifier in the first flow table entry (i.e., "port version" in the flow table) is compared with the version number corresponding to that port identifier in "Correspondence Table 2". If the comparison result shows different version numbers, it can be determined that the second version number corresponding to the port identifier in the first flow table entry is different from the first version number in the correspondence table. Figure 3 The example shown here illustrates the case where the version number is different. In this case, it indicates that the first packet forwarding configuration corresponding to the port identifier has changed, and the first flow entry needs to be updated.

[0056] Conversely, if the network chip 112 determines that there is a first flow table entry in the locally stored flow table that matches the packet identifier of the first packet, and the second version number corresponding to the port identifier in the first flow table entry is the same as the first version number in the correspondence, then the first packet is forwarded according to the first forwarding operation information in the first flow table entry.

[0057] Understandably, if the second version number corresponding to the port identifier in the first flow table entry is the same as the first version number in the correspondence, it means that the packet forwarding configuration of the target port has not changed since the last packet was sent. In this case, the first packet can be forwarded directly according to the first forwarding operation information in the first flow table entry. By comparing the version number corresponding to the target port on the hardware side and then forwarding the first packet based on the network chip 112 on the hardware side, the operation is not only simple, but the whole process does not require software side involvement, thus reducing the load on the processor 111.

[0058] Following the above, after the network chip 112 matches the packet identifier of the first packet with each flow table entry in the flow table, if it determines that there is no first flow table entry in the flow table that matches the packet identifier of the first packet, it sends the first packet to the virtual switch. The virtual switch determines the first packet forwarding configuration corresponding to the port identifier based on the port identifier of the destination port contained in the packet identifier of the first packet. It then processes the first packet according to the first packet forwarding configuration and forwards the processed first packet. It also determines the first forwarding operation information based on the first packet forwarding configuration, generates a first flow table entry containing the packet identifier of the first packet, the first forwarding operation information, and the second version number, and sends the first flow table entry to the network chip 112. In response to receiving the first flow table entry from the virtual switch, the network chip 112 adds the first flow table entry to the flow table.

[0059] In practical applications, after receiving the first packet sent by the virtual machine 12, the network chip 112 parses the first packet to obtain the packet identifier corresponding to the first packet, such as the five-tuple information of the first packet (source IP address, destination IP address, source port number, destination port number, and protocol type). Then, the network chip 112 searches for a matching first flow table entry in its locally stored flow table based on this packet identifier. If no matching entry is found, it indicates that the first packet may have been sent through a newly accessed network flow. At this time, a "miss flow table entry" operation is triggered, and the first packet is sent to the virtual switch.

[0060] After receiving the first packet, the virtual switch determines the first packet forwarding configuration corresponding to the port identifier of the target port contained in the packet identifier of the first packet, processes the first packet according to the first packet forwarding configuration, forwards the processed first packet, determines the first forwarding operation information according to the first packet forwarding configuration, generates a first flow table entry containing the packet identifier of the first packet, the first forwarding operation information and the second version number, and sends the first flow table entry to the network chip 112.

[0061] For details regarding the first forwarding operation, please refer to [link / reference]. Figures 2-4The "Forwarding Action" section exemplifies encapsulating VXLAN and QoS (corresponding to the aforementioned Quality of Service rules). Encapsulating VXLAN refers to the operation of encapsulating raw data in VXLAN during packet forwarding. VXLAN, short for Virtual Extensible LAN, is a network virtualization technology used to extend Layer 2 networks on top of existing Layer 3 networks. QoS can specifically include the following operations: classifying traffic into different categories based on packet identification information, assigning priority tags to the classified packets, allocating packets to different queues based on priority tags, and sending them according to a scheduling algorithm. During transmission, the transmission rate is controlled. Furthermore, the first forwarding operation information can also include packet encapsulation and decapsulation, etc., which will not be listed here.

[0062] After receiving the first flow entry from the virtual switch, the network chip 112 adds it to the flow table. When other packets from the network flow to which the first packet belongs are subsequently received, the other packets are directly matched with the first flow entry and forwarded. Therefore, in this embodiment, only the first packet of a network flow needs to be processed by the virtual switch program of the software-side processor 111. Subsequent packets of this network flow can be quickly forwarded based on the flow table in the hardware-side network chip 112 (which contains the first flow entry generated by the virtual switch after processing the first packet), reducing processing latency. It should be understood that in this process, the hardware-side network chip 112 undertakes most of the packet forwarding work, greatly alleviating the load pressure on the software-side processor 111.

[0063] Based on the above, the network device provided in this application embodiment, when the packet forwarding configuration corresponding to the target port changes, synchronizes the correspondence between the port identifier of the target port generated by the software-side virtual switch and the first version number to the hardware-side network chip 112, and performs flow table entry matching and version number comparison in the network chip 112. This allows the hardware-side network chip to quickly and efficiently perceive the change in the packet forwarding configuration corresponding to the target port and process it in a timely manner, ensuring the accuracy of subsequent packet forwarding.

[0064] The above describes the process of achieving efficient perception of the hardware-side network chip 112. The sign of efficient perception is that the first flow entry needs to be updated. In traditional solutions, when the first flow entry needs to be updated, the entire first flow entry is usually deleted and all packets of the network flow corresponding to that entry are sent to the processor 111 for processing. However, this approach can easily cause the processor 111 to receive a large number of packets in a short period of time, resulting in the processor 111 being overwhelmed and packet loss.

[0065] In view of this, in this embodiment, the network chip 112 forwards the first packet according to the first forwarding operation information in the first flow entry, and sends a copy of the first packet with a set tag to the virtual switch. Based on the set tag, the virtual switch processes the copy of the first packet according to the second packet forwarding configuration to generate a second flow entry, and sends the second flow entry to the network chip 112. In response to receiving the second flow entry from the virtual switch, the network chip 112 updates the first flow entry with the second flow entry. The set tag is used to prompt the virtual switch to update the packet forwarding configuration of the target port. The version number corresponding to the port identifier in the second flow entry is updated to the first version number. The second flow entry contains the second forwarding operation information determined according to the second packet forwarding configuration.

[0066] In practical applications, when it is determined that a first-flow entry needs to be updated, the first packet can be forwarded according to the first forwarding operation information in the first-flow entry. Simultaneously, a copy with a defined flag is generated and sent to the virtual switch. This defined flag can be a binary flag added to the header of the first packet copy, a unique session ID embedded in the first packet copy, or the version number of the first-flow entry, etc., and will not be listed here.

[0067] After receiving a copy of the first packet, the virtual switch parses the copy of the first packet to obtain a set tag, and determines that the copy of the first packet belongs to the "mirror packet" of the first packet based on the set tag. At this time, the copy of the first packet is processed according to the modified second packet forwarding configuration, generating a second flow table entry that contains at least the second forwarding operation information that can be determined according to the second packet forwarding configuration, and sending the second flow table entry to the network chip 112. At the same time, the copy of the first packet is deleted.

[0068] After receiving the second flow table entry from the virtual switch, network chip 112 can directly overwrite the original first flow table entry with the second flow table entry and update the version number corresponding to the port identifier in the second flow table entry to the first version number. See details in [link to documentation]. Figure 3 and Figure 4 The version number corresponding to the port identifier of the target port in the original first-flow entry is "5" (see...). Figure 3 The version number corresponding to the port identifier of the target port in the second flow table is "6". Therefore, after overwriting the original first flow table entry with the second flow table entry, the version number changes from "5" to "6". The version number of the first flow table entry after the change can be found in [reference needed]. Figure 4 .

[0069] Subsequently, if network chip 112 receives a second packet corresponding to the target port and determines that a second flow table entry exists that matches the packet identifier of the second packet, and the first version number corresponding to the port identifier in the second flow table entry is the same as the first version number in the correspondence, it indicates that the packet forwarding configuration corresponding to the target port has not changed during the period between the last packet transmission and the current transmission of the second packet in the network flow containing the second packet. At this time, the second packet can be forwarded according to the second forwarding operation information in the second flow table entry. By comparing the version number corresponding to the target port on the hardware side and then forwarding the second packet based on the network chip 112 on the hardware side, the operation is not only simple, but the entire process does not require software side involvement, reducing the load on the software side processor 111.

[0070] Based on the above, firstly, the network chip 112 can update the packet forwarding rules in real time according to the second flow table entry generated by the virtual switch, ensuring that the network policy can be dynamically adjusted as needed. For example, when the security policy (such as ACL rules) or routing path changes, the flow table update can be completed without interrupting the service. Secondly, in this embodiment, when the first flow table entry needs to be updated, it is not necessary to send all the packets of the corresponding network flow to the processor 111 for processing, avoiding the processor 111 being overwhelmed by receiving a large amount of data in a short period of time, resulting in packet loss. In addition, in this embodiment, for the same network flow, only the first packet and packets with changed packet forwarding configurations are processed through the virtual switch, while other packets can be forwarded through the hardware-side network chip 112, reducing the load on the processor 111.

[0071] Furthermore, after sending a copy of the first packet to the virtual switch, another possible scenario is that the processor 111 becomes overloaded, and the virtual switch does not process the copy of the first packet in a timely manner. This can easily lead to packet loss at the processor 111, causing the first flow table entry to fail to be updated successfully. To solve this problem, in this embodiment, after sending a copy of the first packet to the virtual switch, the network chip 112 will, when a set delay condition is met, determine whether the second version number in the first flow table entry is the same as the first version number in the corresponding relationship. If they are still different, the copy of the packet with the set mark will continue to be sent to the virtual switch. The set delay condition judgment operation is iteratively executed. Specifically, after each copy of the packet is sent to the virtual switch, the set delay condition is judged until a copy of the third packet with the set mark is sent to the virtual switch, at which point the second version number in the first flow table entry is the same as the first version number in the corresponding relationship. The virtual switch processes a copy of the third packet based on a set tag and according to the second packet forwarding configuration to generate a second flow entry, and sends the second flow entry to the network chip. The set delay conditions include at least one of the following: set time, set packet forwarding quantity, the third packet being the same as or different from the first packet, and the third packet corresponding to the target port.

[0072] In specific implementation, such as Figure 5 As shown, after receiving the target packet, the network chip 112 parses the target packet to obtain the packet identifier corresponding to the target packet, and determines whether there is a first flow table entry in the locally stored flow table that matches the packet identifier of the target packet.

[0073] If it exists, determine whether the second version number in the first flow entry is the same as the first version number in the corresponding relationship. If they are different, send a copy of the first packet to the virtual switch. When the set delay condition is met (e.g., 10 seconds after sending the copy of the first packet to the virtual switch, or when the network chip has forwarded 500 packets through the first flow entry), determine whether the second version number in the first flow entry is the same as the first version number in the corresponding relationship. If they are the same, forward the target packet directly based on the first flow entry. If they are still different, continue sending copies of packets with the set tag to the virtual switch; iterate the set delay condition judgment operation until a copy of the third packet with the set tag is sent to the virtual switch. After this, the second version number in the first flow entry is the same as the first version number in the corresponding relationship, so that the virtual switch processes the copy of the third packet based on the set tag and the second packet forwarding configuration to generate a second flow entry, and sends the second flow entry to the network chip.

[0074] If the target packet does not exist, the target packet is sent to the virtual switch, so that the virtual switch determines the target packet forwarding configuration corresponding to the port identifier based on the port identifier of the target port contained in the packet identifier of the target packet, processes the target packet according to the target packet forwarding configuration, forwards the processed target packet, and determines the target forwarding operation information according to the target packet forwarding configuration. It generates a target flow table entry containing the packet identifier of the target packet, the target forwarding operation information, and the target version number, and sends the target flow table entry to the network chip 112, which adds the target flow table entry to the flow table.

[0075] By sending a copy of the first packet to the virtual switch via network chip 112 and reaching a set delay condition, it can be determined whether the second version number in the first flow entry is the same as the first version number in the corresponding relationship. This determines whether the first flow entry has been successfully updated. If the result is "still not the same," it means that the first flow entry has not been updated. In this case, by sending a copy of the third packet with the set flag to the virtual switch again, the virtual switch can be requested to process the packet copy again, and then update the first flow entry based on the second flow entry generated by the virtual switch after processing.

[0076] In summary, the embodiments of this application can provide a fallback for situations where "the virtual switch does not process the copy of the first packet in a timely manner." By setting a delay condition, the packet copy can continue to be uploaded even when the virtual switch does not process the copy of the first packet in a timely manner, until the first flow table entry is successfully updated. This solves the packet loss problem that occurs at processor 111 and the problem of not being able to update the first flow table entry successfully. It should be noted that the packet copy sent to the virtual switch again (i.e., the copy of the third packet) can be the same as or different from the first packet. It should be understood that if no new packet is forwarded based on the first flow table entry when the set delay condition is met, the third packet can be the same as the first packet. However, if a new packet is forwarded based on the first flow table entry when the set delay condition is met, the third packet can be the same as the latest packet. There is no limitation on the third packet.

[0077] Figure 6 The flowchart illustrates a network forwarding function configuration method provided in this application embodiment. This method is applied to a virtual switch running in the network interface card (NIC) of a network device. The virtual switch runs in the processor of the NIC and provides packet forwarding configuration corresponding to the target port of the virtual machine. The NIC also includes a network chip, and the network device also includes a virtual machine.

[0078] like Figure 6 As shown, the method includes the following steps:

[0079] 601. In response to the change of the first packet forwarding configuration corresponding to the target port of the virtual machine to the second packet forwarding configuration, the virtual switch generates a correspondence between the port identifier of the target port and the first version number. The first version number is used to reflect the number of times the packet forwarding configuration corresponding to the target port has been changed.

[0080] 602. The virtual switch synchronizes the correspondence to the network chip so that when the network chip receives the first packet corresponding to the target port, it determines that there is a first flow table entry in its locally stored flow table that matches the packet identifier of the first packet. Based on the second version number corresponding to the port identifier in the first flow table entry and the first version number in the correspondence, it determines whether the packet forwarding configuration has changed.

[0081] The first flow entry contains the first forwarding operation information determined according to the first packet forwarding configuration, and the second version number is the version number corresponding to the target port when the virtual switch generates the first flow entry.

[0082] Optionally, determining whether the packet forwarding configuration has changed based on the second version number corresponding to the port identifier in the first flow entry and the first version number in the correspondence includes: if the second version number corresponding to the port identifier in the first flow entry is different from the first version number in the correspondence, then it is determined that the first flow entry needs to be updated; the method further includes: receiving a copy of a first packet with a set tag sent by the network chip; processing the copy of the first packet according to the set tag and the second packet forwarding configuration to generate a second flow entry, the second flow entry containing second forwarding operation information determined according to the second packet forwarding configuration; sending the second flow entry to the network chip so that the network chip updates the first flow entry with the second flow entry, wherein the version number corresponding to the port identifier in the second flow entry is updated to the first version number.

[0083] Optionally, a network forwarding function configuration method provided in this application embodiment may include the following steps:

[0084] In response to the change of the first packet forwarding configuration corresponding to the target port of the virtual machine to the second packet forwarding configuration, the virtual switch generates a correspondence between the port identifier of the target port and the first version number. The first version number is used to reflect the number of times the packet forwarding configuration corresponding to the target port has been changed.

[0085] The virtual switch synchronizes the mapping relationship to the network chip so that when the network chip receives the first packet corresponding to the target port, it determines that there is a first flow table entry in its locally stored flow table that matches the packet identifier of the first packet. Based on the second version number corresponding to the port identifier in the first flow table entry and the first version number in the mapping relationship, it determines whether the packet forwarding configuration has changed. The first flow table entry contains the first forwarding operation information determined according to the first packet forwarding configuration, and the second version number is the version number corresponding to the target port when the virtual switch generates the first flow table entry.

[0086] If the second version number corresponding to the port identifier in the first flow table entry is different from the first version number in the correspondence, the network chip determines that the first flow table entry needs to be updated.

[0087] The virtual switch receives a copy of the first message sent by the network chip, which is marked with a specific tag.

[0088] Based on the set tag, the copy of the first message is processed according to the second message forwarding configuration to generate a second flow table entry, which contains the second forwarding operation information determined according to the second message forwarding configuration;

[0089] The second flow entry is sent to the network chip so that the network chip updates the first flow entry with the second flow entry, wherein the version number corresponding to the port identifier in the second flow entry is updated to the first version number.

[0090] Optionally, the network forwarding function configuration method provided in this application embodiment further includes:

[0091] The virtual switch receives the first message sent by the network chip. The first message is sent by the network chip when it determines that there is no first flow table entry in the flow table that matches the message identifier of the first message.

[0092] The virtual switch determines the first packet forwarding configuration corresponding to the port identifier based on the port identifier of the target port contained in the packet identifier of the first packet;

[0093] The virtual switch processes the first packet according to the first packet forwarding configuration and forwards the processed first packet.

[0094] The virtual switch determines the first forwarding operation information based on the first packet forwarding configuration, and generates a first flow table entry containing the packet identifier of the first packet, the first forwarding operation information, and the second version number;

[0095] The virtual switch sends the first-flow entry to the network chip.

[0096] The above method can perform the steps in the foregoing embodiments. For detailed execution process and technical effects, please refer to the description in the foregoing embodiments, which will not be repeated here.

[0097] Figure 7 This is a flowchart illustrating a network forwarding function configuration method provided in an embodiment of this application. The method is applied to a network chip in the network interface card (NIC) of a network device. The NIC also includes a processor, which runs a virtual switch. The virtual switch provides packet forwarding configuration corresponding to the target port of the virtual machine. The network device also includes a virtual machine. Figure 7 As shown, the method includes the following steps:

[0098] 701. The network chip receives the port identifier of the target port sent by the virtual switch and the correspondence between it and the first version number. The correspondence is generated by the virtual switch in response to the change of the first packet forwarding configuration corresponding to the target port to the second packet forwarding configuration.

[0099] 702. The network chip receives the first message corresponding to the target port.

[0100] 703. If the network chip determines that there is a first flow table entry in the locally stored flow table that matches the packet identifier of the first packet, it determines whether the packet forwarding configuration has changed based on the second version number corresponding to the port identifier in the first flow table entry and the first version number in the corresponding relationship.

[0101] The first flow entry contains the first forwarding operation information determined according to the first packet forwarding configuration, and the second version number is the version number corresponding to the target port when the virtual switch generates the first flow entry.

[0102] Optionally, the network forwarding function configuration method provided in this application embodiment may include the following steps:

[0103] The network chip receives the port identifier of the target port sent by the virtual switch and the correspondence between it and the first version number. This correspondence is generated by the virtual switch in response to the change of the first packet forwarding configuration corresponding to the target port to the second packet forwarding configuration.

[0104] The network chip receives the first message corresponding to the target port;

[0105] If the network chip determines that there is a first flow table entry in the locally stored flow table that matches the packet identifier of the first packet, it determines whether the packet forwarding configuration has changed based on the second version number corresponding to the port identifier in the first flow table entry and the first version number in the corresponding relationship.

[0106] If the second version number corresponding to the port identifier in the first flow table entry is different from the first version number in the correspondence, then it is determined that the first flow table entry needs to be updated. The first flow table entry contains the first forwarding operation information determined according to the first packet forwarding configuration, and the second version number is the version number corresponding to the target port when the virtual switch generates the first flow table entry.

[0107] The network chip forwards the first packet according to the first forwarding operation information in the first flow table entry;

[0108] The network chip sends a copy of the first packet with a set tag to the virtual switch, so that the virtual switch processes the copy of the first packet based on the set tag and the second packet forwarding configuration to generate a second flow table entry.

[0109] The network chip receives the second flow table entry sent by the virtual switch. The version number corresponding to the port identifier in the second flow table entry is updated to the first version number. The second flow table entry contains the second forwarding operation information determined according to the second packet forwarding configuration.

[0110] The network chip updates the first-flow entry with the second-flow entry.

[0111] Optionally, the network forwarding function configuration method provided in this application embodiment may include the following steps:

[0112] The network chip receives the port identifier of the target port sent by the virtual switch and the correspondence between it and the first version number. This correspondence is generated by the virtual switch in response to the change of the first packet forwarding configuration corresponding to the target port to the second packet forwarding configuration.

[0113] The network chip receives the first message corresponding to the target port;

[0114] If the network chip determines that there is a first flow table entry in the locally stored flow table that matches the packet identifier of the first packet, and the second version number corresponding to the port identifier in the first flow table entry is different from the first version number in the correspondence, then it determines that the first flow table entry needs to be updated. The first flow table entry contains the first forwarding operation information determined according to the forwarding configuration of the first packet, and the second version number is the version number corresponding to the target port when the virtual switch generates the first flow table entry.

[0115] The network chip forwards the first packet according to the first forwarding operation information in the first flow table entry;

[0116] The network chip sends a copy of the first message, marked with a specific tag, to the virtual switch;

[0117] If the network chip sends a copy of the first packet to the virtual switch and the set delay condition is met, and the second version number in the first flow table entry is still different from the first version number in the corresponding relationship, then it continues to send a copy of the packet with the set tag to the virtual switch. After each copy of the packet is sent to the virtual switch, the set delay condition is checked until a copy of the third packet with the set tag is sent to the virtual switch, and the second version number in the first flow table entry is the same as the first version number in the corresponding relationship. The set delay condition includes at least one of the following: set time, set packet forwarding quantity, the third packet is the same as or different from the first packet, and the third packet corresponds to the target port.

[0118] The above method can perform the steps in the foregoing embodiments. For detailed execution process and technical effects, please refer to the description in the foregoing embodiments, which will not be repeated here.

[0119] Figure 8 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application, such as... Figure 8 As shown, in practice, this electronic device includes a memory 21 and a processor 22.

[0120] Memory 21 is used to store computer programs and can be configured to store various other data to support operation on the electronic device. Examples of this data include instructions for any application or method used to operate on the electronic device, data structures, contact data, phone book data, messages, pictures, videos, etc.

[0121] The processor 22, coupled to the memory 21, is used to execute the computer program in the memory 21 to implement the network forwarding function configuration method provided in the foregoing embodiments.

[0122] Furthermore, such as Figure 8 As shown, the electronic device also includes other components such as a communication component 23, a display 24, a power supply component 25, and an audio component 26. Figure 8 The diagram only shows some components and does not mean that the electronic device includes only these components. Figure 8 The components shown are as follows. The electronic device in this embodiment can be a terminal device such as a desktop computer, laptop computer, smartphone, or IoT device, or a server device such as a conventional server, cloud server, or server array.

[0123] The aforementioned memory can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as Static Random-Access Memory (SRAM), Electrically Erasable Programmable Read-Only Memory (EEPROM), Erasable Programmable Read-Only Memory (EPROM), Programmable Read-Only Memory (PROM), Read-Only Memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk.

[0124] The aforementioned communication component is configured to facilitate wired or wireless communication between the device containing the communication component and other devices. The device containing the communication component can access wireless networks based on communication standards, such as 2G, 3G, 4G / LTE, 5G, or combinations thereof. In one exemplary embodiment, the communication component receives broadcast signals or broadcast-related information from an external broadcast management system via a broadcast channel.

[0125] The aforementioned display includes a screen, which may include a liquid crystal display (LCD) and a touch panel (TP). If the screen includes a touch panel, the screen can be implemented as a touchscreen to receive input signals from the user. The touch panel includes one or more touch sensors to sense touches, swipes, and gestures on the touch panel. The touch sensors can sense not only the boundaries of touch or swipe actions but also the duration and pressure associated with the touch or swipe operation.

[0126] The aforementioned power supply components provide power to various components within the device in which they reside. These power supply components may include a power management system, one or more power sources, and other components associated with generating, managing, and distributing power to the device in which they reside.

[0127] The aforementioned audio component can be configured to output and / or input audio signals. For example, the audio component includes a microphone (MIC) configured to receive external audio signals when the device containing the audio component is in an operating mode, such as call mode, recording mode, or voice recognition mode. The received audio signals can be further stored in memory or transmitted via a communication component. In some embodiments, the audio component also includes a speaker for outputting audio signals.

[0128] Accordingly, embodiments of this application also provide a computer-readable storage medium storing a computer program, which, when executed by a processor, enables the processor to implement the steps in the above-described method embodiments. The computer-readable storage medium includes volatile or non-volatile or a combination thereof, and can be removable or non-removable. Examples of computer-readable storage media include, but are not limited to, phase-change random access memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random-access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), flash memory or other memory technologies, CD-ROM, digital video disc (DVD) or other optical storage, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other non-transmission medium.

[0129] Accordingly, this application also provides a computer program product, which includes a computer program or instructions that, when executed by a processor, cause the processor to implement the steps in the above method embodiments. It should be understood that each step or combination of steps in the above method flow can be implemented by the computer program or instructions. Furthermore, these computer programs or instructions can be applied to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device, enabling the processor of the general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing device to function as an apparatus for implementing the corresponding functions in the above method embodiments.

[0130] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application.

Claims

1. A network device, characterized in that, include: Network interface card and virtual machine; The network interface card includes a processor and a network chip. The processor runs a virtual switch, and the virtual switch provides packet forwarding configuration corresponding to the target port of the virtual machine. The virtual switch is configured to, in response to a change in the first packet forwarding configuration corresponding to the target port of the virtual machine to the second packet forwarding configuration, generate a correspondence between the port identifier of the target port and the first version number, and synchronize the correspondence to the network chip. The first version number is used to reflect the number of times the packet forwarding configuration corresponding to the target port has been changed. The network chip is used to receive a first packet corresponding to the target port. If it is determined that there is a first flow table entry in the locally stored flow table that matches the packet identifier of the first packet, then based on the second version number in the first flow table entry corresponding to the port identifier and the first version number in the correspondence, it determines whether the packet forwarding configuration has changed. The first flow table entry contains first forwarding operation information determined according to the first packet forwarding configuration, and the second version number is the version number corresponding to the target port when the virtual switch generates the first flow table entry.

2. The network device according to claim 1, characterized in that, The network chip is further configured to: determine that the first flow table entry needs to be updated if the second version number corresponding to the port identifier in the first flow table entry is different from the first version number in the correspondence.

3. The network device according to claim 1, characterized in that, The network chip is further configured to: if the second version number corresponding to the port identifier in the first flow table entry is the same as the first version number in the correspondence, then forward the first packet according to the first forwarding operation information in the first flow table entry.

4. The network device according to claim 2, characterized in that, The network chip is further configured to: forward the first packet according to the first forwarding operation information in the first flow table entry, send a copy of the first packet with a set flag to the virtual switch, and update the first flow table entry with the second flow table entry in response to receiving the second flow table entry from the virtual switch, wherein the set flag is used to prompt the virtual switch to update the packet forwarding configuration of the target port. The virtual switch is further configured to: process a copy of the first packet based on the set tag and according to the second packet forwarding configuration to generate the second flow table entry, send the second flow table entry to the network chip, and clear the copy of the first packet, wherein the version number corresponding to the port identifier in the second flow table entry is updated to the first version number, and the second flow table entry contains second forwarding operation information determined according to the second packet forwarding configuration.

5. The network device according to claim 4, characterized in that, The network chip is also used to iteratively execute the following steps: After sending a copy of the first packet to the virtual switch, if the set delay condition is met and the second version number in the first flow table entry is still different from the first version number in the correspondence, then the copy of the packet with the set tag is sent to the virtual switch. Each time a copy of the packet is sent to the virtual switch, the set delay condition is checked until a copy of the third packet with the set tag is sent to the virtual switch, and the second version number in the first flow table entry is the same as the first version number in the correspondence. The set delay condition includes at least one of the following: set time, set packet forwarding quantity, the third packet is the same as or different from the first packet, and the third packet corresponds to the target port. The virtual switch is further configured to: process a copy of the third packet based on the set tag and according to the second packet forwarding configuration to generate the second flow table entry, and send the second flow table entry to the network chip.

6. The network device according to any one of claims 1-5, characterized in that, The network chip is further configured to: if it is determined that there is no first flow table entry in the flow table that matches the packet identifier of the first packet, send the first packet to the virtual switch, and add the first flow table entry to the flow table in response to receiving the first flow table entry from the virtual switch; The virtual switch is further configured to: determine the first packet forwarding configuration corresponding to the port identifier based on the port identifier of the target port contained in the packet identifier of the first packet; process the first packet according to the first packet forwarding configuration and forward the processed first packet; determine the first forwarding operation information according to the first packet forwarding configuration; generate the first flow table entry containing the packet identifier of the first packet, the first forwarding operation information and the second version number; and send the first flow table entry to the network chip.

7. A method for configuring network forwarding function, characterized in that, A virtual switch is applied to a network interface card (NIC) running in a network device. The virtual switch runs in a processor within the NIC and provides packet forwarding configuration corresponding to the target port of the virtual machine. The NIC also includes a network chip, and the network device further includes a virtual machine. The method includes: In response to a change in the first packet forwarding configuration corresponding to the target port of the virtual machine to the second packet forwarding configuration, a correspondence between the port identifier of the target port and the first version number is generated, wherein the first version number is used to reflect the number of times the packet forwarding configuration corresponding to the target port has been changed; The correspondence is synchronized to the network chip so that when the network chip receives a first packet corresponding to the target port, it determines that there is a first flow table entry in its locally stored flow table that matches the packet identifier of the first packet. Based on the second version number corresponding to the port identifier in the first flow table entry and the first version number in the correspondence, it determines whether the packet forwarding configuration has changed. The first flow table entry contains first forwarding operation information determined according to the first packet forwarding configuration, and the second version number is the version number corresponding to the target port when the virtual switch generates the first flow table entry.

8. The method according to claim 7, characterized in that, The step of determining whether the packet forwarding configuration has changed based on the second version number corresponding to the port identifier in the first flow table entry and the first version number in the correspondence includes: if the second version number corresponding to the port identifier in the first flow table entry is different from the first version number in the correspondence, then it is determined that the first flow table entry needs to be updated; the method further includes: Receive a copy of the first message with a set tag sent by the network chip; Based on the set flag, the copy of the first packet is processed according to the second packet forwarding configuration to generate a second flow table entry, the second flow table entry containing second forwarding operation information determined according to the second packet forwarding configuration; The second flow table entry is sent to the network chip so that the network chip updates the first flow table entry with the second flow table entry, wherein the version number corresponding to the port identifier in the second flow table entry is updated to the first version number.

9. The method according to claim 7, characterized in that, The method further includes: The network chip receives the first message sent by the network chip, which is sent when the network chip determines that there is no first flow table entry in the flow table that matches the message identifier of the first message; Based on the port identifier of the target port contained in the message identifier of the first message, determine the first message forwarding configuration corresponding to the port identifier; The first message is processed according to the first message forwarding configuration, and the processed first message is forwarded. The first forwarding operation information is determined based on the first message forwarding configuration, so as to generate the first flow table entry containing the message identifier of the first message, the first forwarding operation information, and the second version number; The first flow table entry is sent to the network chip.

10. A method for configuring network forwarding function, characterized in that, A network chip is installed in a network interface card (NIC) of a network device. The NIC also includes a processor, which runs a virtual switch. The virtual switch provides packet forwarding configuration corresponding to the target port of the virtual machine. The network device also includes a virtual machine. The method includes: The virtual switch receives the correspondence between the port identifier of the target port and the first version number, wherein the correspondence is generated by the virtual switch in response to the change of the first packet forwarding configuration corresponding to the target port to the second packet forwarding configuration; Receive the first message corresponding to the target port; If it is determined that there is a first flow table entry in the locally stored flow table that matches the packet identifier of the first packet, then based on the second version number corresponding to the port identifier in the first flow table entry and the first version number in the correspondence, it is determined whether the packet forwarding configuration has changed; The first flow table entry contains first forwarding operation information determined according to the first packet forwarding configuration, and the second version number is the version number corresponding to the target port when the virtual switch generates the first flow table entry.

11. The method according to claim 10, characterized in that, The step of determining whether the packet forwarding configuration has changed based on the second version number corresponding to the port identifier in the first flow table entry and the first version number in the correspondence includes: if the second version number corresponding to the port identifier in the first flow table entry is different from the first version number in the correspondence, then it is determined that the first flow table entry needs to be updated; the method further includes: The first packet is forwarded according to the first forwarding operation information in the first flow table entry; A copy of the first packet with a set tag is sent to the virtual switch, so that the virtual switch processes the copy of the first packet based on the set tag and the second packet forwarding configuration to generate the second flow table entry. The system receives the second flow table entry sent by the virtual switch, wherein the version number corresponding to the port identifier in the second flow table entry is updated to the first version number, and the second flow table entry contains second forwarding operation information determined according to the second packet forwarding configuration. Update the first flow table entry with the second flow table entry.

12. The method according to claim 11, characterized in that, The method further includes: If, after sending a copy of the first packet to the virtual switch, the set delay condition is met, and the second version number in the first flow table entry is still different from the first version number in the correspondence, then the copy of the packet with the set tag continues to be sent to the virtual switch. Each time a copy of the packet is sent to the virtual switch, the set delay condition is checked until a copy of the third packet with the set tag is sent to the virtual switch, and the second version number in the first flow table entry is the same as the first version number in the correspondence. The set delay condition includes at least one of the following: set time, set packet forwarding quantity, the third packet being the same as or different from the first packet, and the third packet corresponding to the target port.

13. A non-transitory machine-readable storage medium, characterized in that, The non-transitory machine-readable storage medium stores executable code that, when executed by a processor of an electronic device, causes the processor to perform the method as claimed in any one of claims 7 to 9, or claims 10 to 12.

14. A computer program product, characterized in that, include: A computer program, when executed by a processor of an electronic device, causes the processor to perform the method as claimed in any one of claims 7 to 9, or claims 10 to 12.