Method and apparatus for implementing application service in service function chain pseudo-proxy networking
By deploying switches in the service chain pseudo-agent network and virtualizing multiple Vsys on SF, the high networking cost problem in the existing technology is solved, and multiple application services can be provided on a single device, thereby improving resource utilization.
Patent Information
- Application Number
- PCT/CN2024/102116
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-06-27
- Publication Date
- 2026-01-02
AI Technical Summary
In service chain pseudo-proxy networking, existing technologies require multiple firewall devices to provide different firewall security services, which increases networking costs.
By deploying switches in the service chain pseudo-agent network and virtualizing multiple virtual systems (Vsys) on the application service node (SF), each Vsys is associated with a different VLAN and configured with different application service policies. By using the switches to carry VLAN identifiers in the packets, multiple application services can be provided on the SF.
Providing multiple application services on the same SF reduces networking costs and improves resource utilization.
Smart Images

Figure CN2024102116_02012026_PF_FP_ABST
Abstract
Description
Application service implementation method and device in service chain pseudo-proxy networking TECHNICAL FIELD
[0001] The present application relates to network communication technology, in particular to an application service implementation method and device in service chain pseudo-proxy networking. BACKGROUND
[0002] In service chain pseudo-proxy networking, an application service node (SF: Service Function) is accessed to a service chain forwarding node (SFF: Service Function Forwarder) in a side hanging manner. In service chain pseudo-proxy networking, the SF can identify a message, such as identifying whether to continue forwarding the message in an SRv6 service chain (SFC: Service Function Chain) and the like. FIG. 1 exemplarily shows service chain pseudo-proxy networking. The SF here is, for example, a firewall device. As shown in FIG. 1, in service chain pseudo-proxy networking, SF1 is accessed to SFF1 in a side hanging manner.
[0003] In service chain pseudo-proxy networking, the SF is only responsible for implementing an application service such as a firewall security service, and the SFF is responsible for forwarding a message along a service chain. Specifically, the SFF forwards the message to the SF according to SRv6 encapsulation information such as an SRv6 source routing extension header (SRH). After the SF receives and processes the message, the SF performs corresponding service processing on the message based on the configured application service, and then forwards the message to the SFF for continuing to forward the message along the SRv6 SFC if it is identified to continue forwarding the message.
[0004] In service chain pseudo-proxy networking, the application service provided by the SF is relatively single. When a message passing through an SRv6 SFC needs to perform two different application services, two SFFs in the SRv6 SFC need to be side hung with one SF in a side hanging manner to provide corresponding application services. Such adjustment will increase the networking cost. Taking the SF as a firewall device as an example, one firewall device can only run one firewall security service. When a message passing through an SRv6 SFC needs to apply two services (i.e., service 1 and service 2) at the same time, two SFFs in the SRv6 SFC need to be side hung with two firewall devices respectively to provide service 1 and service 2 respectively, which increases the networking cost.
[0005] SUMMARY
[0006] Embodiments of the present application provide an application service implementation method and device in service chain pseudo-proxy networking, to provide different application services on the same SF by combining multiple VLANs and a virtual system Vsys on the SF.
[0007] The embodiment of the application provides a service chain pseudo-proxy networking application service implementation method, at least one group of node pairs in the service chain pseudo-proxy networking are deployed with switches, the node pairs comprise a service chain forwarding node SFF and an application service node SF; the switches and the SF support the same N VLANs, N is greater than 1; the SF is virtually provided with a plurality of virtual systems Vsys, any Vsys is associated with at least two VLANs supported by the SF; different Vsys are configured with different application service policies; the method comprises:
[0008] The SF receives a first message forwarded by the switch through a local first interface; the first message carries a first VLAN identifier, the first VLAN identifier is determined by the switch when receiving the first message forwarded by the SFF to the SF through a second interface, and the first VLAN identifier is the identifier of a first VLAN supported by the second interface;
[0009] The SF determines a first Vsys associated with the first VLAN identifier, and performs corresponding service processing on the first message according to the application service policy corresponding to the first Vsys.
[0010] The embodiment of the application provides a service chain pseudo-proxy networking application service implementation method, at least one group of node pairs in the service chain pseudo-proxy networking are deployed with switches, the node pairs comprise a service chain forwarding node SFF and an application service node SF; the switches and the SF support the same N VLANs, N is greater than 1; the SF is virtually provided with a plurality of virtual systems Vsys, any Vsys is associated with at least two VLANs supported by the SF; different Vsys are configured with different application service policies; the method comprises:
[0011] The switch receives the first message forwarded by the SFF to the SF through a second interface;
[0012] The switch carries the identifier of the first VLAN supported by the second interface in the first message to the SF for forwarding, so that the SF receives the first message carrying the first VLAN identifier through a local first interface and determines a first Vsys associated with the first VLAN identifier, and performs corresponding service processing on the first message according to the application service policy corresponding to the first Vsys.
[0013] The embodiment of the present application provides a device for implementing application service in a service chain pseudo-proxy networking, at least one group of node pairs in the service chain pseudo-proxy networking are deployed with a switch, the node pairs comprise a service chain forwarding node SFF and an application service node SF; the switch and the SF support the same N VLANs, and N is greater than 1; the SF is virtually provided with a plurality of virtual systems Vsys, any Vsys is associated with at least two VLANs supported by the SF; different Vsys are configured with different application service policies; the device is applied to the SF and comprises:
[0014] a first receiving unit configured to receive a first packet forwarded by the switch through a local first interface; the first packet carries a first VLAN identifier, the first VLAN identifier is determined by the switch when receiving the first packet forwarded by the SFF to the SF through a second interface, and the first VLAN identifier is an identifier of a first VLAN supported by the second interface;
[0015] a service unit configured to determine a first Vsys associated with the first VLAN identifier, and perform corresponding service processing on the first packet according to an application service policy corresponding to the first Vsys.
[0016] The embodiment of the present application provides a device for implementing application service in a service chain pseudo-proxy networking, at least one group of node pairs in the service chain pseudo-proxy networking are deployed with a switch, the node pairs comprise a service chain forwarding node SFF and an application service node SF; the switch and the SF support the same N VLAN identifiers, and N is greater than 1; the SF is virtually provided with a plurality of virtual systems Vsys, any Vsys is associated with at least two VLAN identifiers supported by the SF; different Vsys are configured with different application service policies; the device comprises:
[0017] a second receiving unit configured to receive a first packet forwarded by the SFF to the SF through a second interface;
[0018] a processing unit configured to carry an identifier of a first VLAN supported by the second interface in the first packet to the SF for forwarding, so that the SF receives the first packet carrying the first VLAN identifier through a local first interface and determines a first Vsys associated with the first VLAN identifier, and performs corresponding service processing on the first packet according to an application service policy corresponding to the first Vsys.
[0019] The embodiment of the present application further provides an electronic device, which comprises a processor and a machine readable storage medium;
[0020] The machine readable storage medium stores machine executable instructions capable of being executed by the processor;
[0021] The processor is configured to execute machine executable instructions to implement any of the above methods.
[0022] The machine readable storage medium stores machine executable instructions capable of being executed by the processor.
[0023] The machine executable instructions are executed by the processor to implement any of the above methods.
[0024] From the above technical solutions, in the embodiments of the present application, by deploying a switch between the SFF and the SF, configuring the switch and the SF to support the same multiple VLANs, and associating different VLANs supported by the SF to corresponding virtual systems Vsys on the SF, and configuring the virtual systems Vsys with corresponding application service policies, the switch carries the identification of the VLAN on the packet sent from the SFF to the SF, the SF determines the virtual system Vsys associated with the VLAN corresponding to the VLAN identification based on the VLAN identification carried by the packet, and performs corresponding service processing on the packet according to the application service policy corresponding to the virtual system Vsys, which realizes the provision of different application services on the same SF through the combination of multiple VLANs and virtual systems Vsys on the SF, reduces the networking cost, and improves the resource utilization of the SF. BRIEF DESCRIPTION OF DRAWINGS
[0025] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present disclosure and serve to explain the principles of the present disclosure together with the specification.
[0026] FIG. 1 is a service chain pseudo-proxy networking structure diagram;
[0027] FIG. 2 is a service chain pseudo-proxy networking structure diagram provided by an embodiment of the present application;
[0028] FIG. 3 is another service chain pseudo-proxy networking structure diagram provided by an embodiment of the present application;
[0029] FIG. 4 is a flowchart of an application service implementation method in a service chain pseudo-proxy networking provided by an embodiment of the present application;
[0030] FIG. 5 is a flowchart of another application service implementation method in a service chain pseudo-proxy networking provided by an embodiment of the present application;
[0031] FIG. 6 is a structural diagram of an application service implementation device in a service chain pseudo-proxy networking provided by an embodiment of the present application;
[0032] FIG. 7 is a structural diagram of another application service implementation device in a service chain pseudo-proxy networking provided by an embodiment of the present application;
[0033] Figure 8 is an electronic device structure diagram of the application service implementation method in the pseudo-proxy networking of the implementation service chain provided in the embodiments of this application. Detailed Implementation
[0034] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application.
[0035] To enable those skilled in the art to better understand the technical solutions provided in the embodiments of this application, and to make the above-mentioned objectives, features and advantages of the embodiments of this application more apparent and understandable, the technical solutions in the embodiments of this application will be further described in detail below with reference to the accompanying drawings.
[0036] First, in this embodiment, a switch is deployed between at least one pair of nodes in the service chain pseudo-proxy network. These node pairs include SFF and SF. As shown in Figure 2, in this embodiment, a switch is deployed between the node pair SFF2 and SF1.
[0037] In this embodiment, the SF and the switch it accesses support the same N VLANs, where N is greater than 1. Each VLAN is a VLAN instance created on the SF for cross-VLAN forwarding, and different VLAN instances correspond to different VLAN identifiers.
[0038] In practical implementation, this embodiment can configure N interfaces of the switch as Layer 2 Access ports, and configure each of these N interfaces with a supported VLAN. Different interfaces support different VLANs, and the set of VLANs supported by these N interfaces constitutes the N VLANs supported by the switch. It should be noted that, to ensure that packets within the same VLAN are successfully forwarded from the switch, it is also necessary to further configure M interfaces of the switch as Layer 2 Trunk ports and configure each of these M interfaces with at least one supported VLAN, indicating that packets carrying the identifier of their supported VLAN are allowed to pass through. Ultimately, this achieves the goal of the same switch supporting N VLANs. Here, M is less than or equal to N. When M is less than N, it means that at least one of the M interfaces supports at least two of the aforementioned N VLANs.
[0039] Taking N as 2 as an example, the identifiers of the two VLANs are assumed to be VLAN100 and VLAN200, respectively. In this embodiment, the interface SG1 of the switch accessing the SFF can be configured as a Layer 2 Access port, and the interface SG1 supports VLAN100. The interface SG2 of the switch accessing the SFF can be configured as a Layer 2 Access port, and the interface SG2 supports VLAN200. Correspondingly, the interface SG3 of the switch accessing the SF can be configured as a Layer 2 Trunk port, indicating that a message carrying VLAN100 is allowed to pass through. The interface SG4 of the switch accessing the SF can be configured as a Layer 2 Trunk port, indicating that a message carrying VLAN200 is allowed to pass through. Finally, the switch supports the following VLANs with identifiers corresponding to the VLANs, respectively: VLAN100 and VLAN200. FIG. 3 exemplarily shows a configuration diagram of a switch in a service chain pseudo-proxy network.
[0040] Similarly, in this embodiment, the M interfaces of the switch accessing the SF can also be configured as Layer 2 Trunk ports, and the VLANs supported by the M interfaces can be configured, respectively. Any interface of the M interfaces allows a message carrying an identifier of a VLAN supported by the interface to pass through. Different interfaces of the M interfaces support different VLANs, and the set of the VLANs supported by the M interfaces is the N VLANs supported by the SF. Finally, the same SF supports the N VLANs. As described above, M is less than or equal to N, and when M is less than N, at least one interface of the M interfaces supports at least two VLANs of the N VLANs.
[0041] Still taking N as 2 as an example, the identifiers of the two VLANs are assumed to be VLAN100 and VLAN200, respectively. In this embodiment, the interface FG1 of the switch accessing the SF can be configured as a Layer 2 Trunk port, indicating that a message carrying VLAN100 is allowed to pass through. The interface FG2 of the switch accessing the SF can be configured as a Layer 2 Trunk port, indicating that a message carrying VLAN200 is allowed to pass through. Finally, the SF supports the following VLANs with identifiers corresponding to the VLANs, respectively: VLAN100 and VLAN200. FIG. 3 exemplarily shows a configuration diagram of a SF in a service chain pseudo-proxy network.
[0042] In this embodiment, there are multiple virtual systems Vsys virtually existing on the SF, and any Vsys is associated with at least two VLANs supported by the SF. For example, the SF supports 10 VLANs, and the corresponding identifiers are VLAN1 to VLAN10 respectively. Five Vsys (denoted as Vsys1 to Vsys5 respectively) are virtually existing on the SF, wherein each Vsys is associated with two VLANs, and different Vsys is associated with different VLANs. For example, Vsys1 is associated with the following VLANs corresponding to the identifiers: VLAN1 to VLAN2, Vsys2 is associated with the following VLANs corresponding to the identifiers: VLAN3 to VLAN4, Vsys3 is associated with the following VLANs corresponding to the identifiers: VLAN5 to VLAN6, Vsys4 is associated with the following VLANs corresponding to the identifiers: VLAN7 to VLAN8, and Vsys5 is associated with the following VLANs corresponding to the identifiers: VLAN9 to VLAN10.
[0043] In this embodiment, different Vsys is configured to correspond to different application service policies. For example, the five Vsys (i.e., Vsys1 to Vsys5) described above correspond to different application service policies respectively, which are five specific types of firewall security services respectively. This embodiment is not specifically limited.
[0044] Based on the above description, the method provided by the embodiments of the present application is described as follows:
[0045] Referring to FIG. 4, FIG. 4 is a flowchart of an application service implementation method in a service chain pseudo-proxy networking provided by an embodiment of the present application. As shown in FIG. 4, the flowchart can be applied to the SF, which includes
[0046] In step 401, the SF receives the first packet forwarded by the switch through the local first interface.
[0047] In this embodiment, when the switch receives the first packet forwarded by the SFF to the SF through the second interface, it finds that the second interface is a layer 2 access port as described above and is configured to support the first VLAN, and then forwards the first packet carrying the identifier of the first VLAN to the SF through the local sixth interface. The sixth interface is a layer 2 Trunk port as described above, which allows the first packet carrying the identifier of the first VLAN (i.e., the first packet described above) to pass through. Finally, the SF receives the first packet forwarded by the switch.
[0048] Here, the SFF forwards the first packet to the SF, which is determined by the SFF based on the SRv6 policy corresponding to the received packet such as the first packet. The SRv6 policy can be carried in the packet or configured on the SFF. In addition to instructing the SFF to forward the packet to the SF, it further instructs which local interface of the SFF to forward through.
[0049] It should be noted that in the embodiment, if the SF receives the first packet through the local first interface, the first interface is a two-layer Trunk port as described above, which allows the first packet carrying the first VLAN identifier to pass through.
[0050] In the embodiment, the first interface, the second interface, the sixth interface, the first VLAN identifier, etc. are only named for ease of description and are not intended to be limiting.
[0051] In step 402, the SF determines the first Vsys associated with the first VLAN identifier, and performs corresponding service processing on the first packet according to the application service policy corresponding to the first Vsys.
[0052] As an embodiment, the first packet is composed of an SRv6 inner packet and an SRv6 header. Based on this, in step 402, performing corresponding service processing on the first packet according to the application service policy corresponding to the first Vsys includes:
[0053] When the SF is configured to perform service processing on the SRv6 inner packet, performing corresponding service processing on the SRv6 inner packet in the first packet according to the application service policy corresponding to the first Vsys;
[0054] When the SF is configured to perform service processing on the SRv6 header, or if the SF is not configured to perform service processing on the SRv6 header, and also when the SF is not configured to perform service processing on the SRv6 inner packet, performing corresponding service processing on the SRv6 header in the first packet according to the application service policy corresponding to the first Vsys.
[0055] By distinguishing the SRv6 header or the SRv6 inner packet and performing corresponding service processing, the service processing efficiency can be improved.
[0056] At this point, the process shown in FIG. 4 is completed.
[0057] As can be seen from the process shown in FIG. 4, the embodiment deploys a switch between the SFF and the SF, configures the switch and the SF to support multiple VLANs, associates different VLANs supported by the SF to corresponding virtual systems Vsys on the SF, and configures corresponding application service policies for the virtual systems Vsys. The switch carries the identifier of the VLAN on the packet sent from the SFF to the SF, the SF determines the virtual system Vsys associated with the VLAN corresponding to the VLAN identifier based on the VLAN identifier carried by the packet, and performs corresponding service processing on the packet according to the application service policy corresponding to the virtual system Vsys. This realizes the provision of different application services on the same SF through the combination of multiple VLANs and virtual systems Vsys on the SF, reduces the networking cost, and improves the resource utilization of the SF.
[0058] Still taking the firewall service described in the background as an example, according to the flow shown in FIG. 4, only one firewall device is required, and by associating different VLANs supported by the firewall device to corresponding Vsys on the firewall device and configuring corresponding application service policies for the Vsys, multiple different firewall security services can be run on one firewall device according to user needs, the resource utilization of the firewall device is improved, and the networking cost is also reduced.
[0059] It should be noted that in the embodiment, after the SF performs the corresponding service processing on the first packet, if it is determined that the first packet still needs to be continuously sent to the SFF (that is, the first packet is released), the first VLAN identifier carried by the first packet is replaced with a second VLAN identifier, and the first packet at this time can be recorded as a second packet. Here, the second VLAN identifier is the identifier of the second VLAN associated with the first Vsys and different from the first VLAN. Then, the SF sends the second packet through a third interface locally supporting the second VLAN. In the embodiment, the third interface is a two-layer Trunk port as described above, which is configured to allow packets carrying the second VLAN identifier to pass through. Finally, the SF successfully sends the second packet through the third interface locally supporting the second VLAN. The switch receives the second packet, and here, the switch receives the second packet through a fourth interface locally supporting the second VLAN. The fourth interface is a two-layer Trunk port as described above, which is configured to allow packets carrying the second VLAN identifier to pass through. When the switch receives the second packet, the second VLAN identifier carried by the second packet is removed and forwarded to the SFF. Finally, the first packet is forwarded to the SFF. Then, the SFF can continue to forward the first packet according to the SRv6 SFC.
[0060] The above is a method provided by the embodiment of the application from the perspective of the SF. The following describes a method provided by the embodiment of the application from the perspective of the switch:
[0061] Referring to FIG. 5, FIG. 5 is a flowchart of an application service implementation method in another service chain pseudo-proxy networking provided by the embodiment of the application. The flow is applied to a switch. The flow corresponds to the flow shown in FIG. 4.
[0062] As shown in FIG. 5, the flow can include the following steps:
[0063] Step 501, the switch receives a first packet forwarded by the SFF to the SF through a second interface.
[0064] Here, the second interface is configured as a two-layer access access port as described above.
[0065] At step 502, the switch carries the first VLAN identifier in the first packet to the SF based on the first VLAN supported by the second interface, so that the SF receives the first packet carrying the first VLAN identifier and determines the first Vsys associated with the first VLAN identifier, and performs corresponding service processing on the first packet according to the application service policy corresponding to the first Vsys.
[0066] Optionally, in the embodiment, carrying the first VLAN identifier in the first packet to the SF includes carrying the first VLAN identifier in the first packet and forwarding the first packet carrying the first VLAN identifier to the SF through the sixth interface supporting the first VLAN locally. Here, the sixth interface is configured as a Layer 2 Trunk port as described above, which allows the first packet carrying the first VLAN identifier to pass through, so that the switch successfully forwards the first packet carrying the first VLAN identifier out of the local switch to the SF.
[0067] In the embodiment, the switch can also receive the second packet through the fourth interface. Here, the second packet is obtained by replacing the first VLAN identifier carried in the first packet with a second VLAN identifier associated with the first Vsys other than the first VLAN identifier when the SF determines to continue sending the first packet to the SFF after performing corresponding service processing on the first packet; and the fourth interface supports the second VLAN corresponding to the second VLAN identifier. Here, the fourth interface is configured as a Layer 2 Trunk port as described above, which allows the second packet carrying the second VLAN identifier to pass through. When the switch receives the second packet through the fourth interface, it is found that the fifth interface other than the fourth interface locally supports the second VLAN and is configured as a Layer 2 access port as described above, the second VLAN identifier carried in the second packet is removed to obtain the first packet and is forwarded to the SFF through the fifth interface. Then, the SFF can continue to forward the first packet according to the SRv6 SFC.
[0068] At this point, the process shown in FIG. 5 is completed.
[0069] The embodiments of the present application will be described below in combination with a process:
[0070] Still taking the network shown in FIG. 3 as an example, as shown in FIG. 3, the SFF1 sends an SRv6 packet to the SFF2.
[0071] SFF2 receives the SRv6 packet, determines that the SRv6 packet needs to be sent to SF1 based on the SRv6 policy matched by the SRv6 packet, and then sends the first packet out through the local interface RG2. Here, the first packet can be the SRv6 packet or a packet obtained by removing the SRv6 encapsulation from the SRv6 packet. In addition, the SRv6 policy here can be a policy locally configured by SFF2 and matched by the SRv6 packet (such as the source address and destination address of the SRv6 packet, or the service type carried by the SRv6 packet), or a policy carried by the SRv6 packet. The SRv6 policy indicates the egress interface, such as the above RG2.
[0072] The switch receives the first packet through the local SG1 port and finds that the SG1 port supports VLAN100, so the first packet carries VLAN100.
[0073] The switch locally allows the packet carrying VLAN100 to pass through the SG3 port, and then sends the first packet carrying VLAN100 through the local SG3 port.
[0074] SF1 (which can be a firewall device) receives the first packet carrying VLAN100 through the local FG1 port, first finds the Vsys associated with VLAN100 such as Vsys1 through VLAN100, and performs service processing (such as security services) on the first packet based on the application services configured by Vsys1 (here, the content of the packet is not changed, and SF1 only performs service processing without changing the content of the packet).
[0075] After SF1 performs service processing (such as security services) on the first packet based on the application services configured by Vsys1, if it is determined based on the result of the service processing that the first packet is to be released, the VLAN100 carried by the first packet is replaced with another VLAN identifier associated with Vsys1, that is, VLAN200, and the first packet at this time is referred to as the second packet. SF1 finds that the local FG2 port allows the packet carrying VLAN200 to pass through, and then sends the second packet through the local FG2 port. Of course, if SF1 determines based on the result of the service processing that the first packet is to be prohibited from being released, the first packet is discarded directly.
[0076] The switch receives the second packet through the local SG4 port, finds based on the VLAN200 carried by the second packet that only the local SG2 port allows VLAN200 to pass through, and that the SG2 port is a layer-2 access port, and then removes VLAN200 from the second packet to restore the first packet. Then, the first packet is sent through the SG2 port.
[0077] SFF2 receives the first packet through the local RG3 port, and normally forwards the first packet according to the SRv6 service chain path.
[0078] Through the above embodiment, even if the application service is newly added, the embodiment virtually outputs the Vsys corresponding to the newly added application service on the SF (the Vsys is configured with the application service policy corresponding to the newly added application service), and configures the identification of the VLAN associated with the Vsys on the SF. The VLAN identification associated with the Vsys is carried on the message sent to the SF by the switch on the SFF, the SF determines the Vsys associated with the VLAN identification based on the VLAN identification carried by the message, and performs corresponding service processing on the message according to the application service policy corresponding to the Vsys, so as to realize that even if the application service is newly added, the original SF is multiplexed to provide the newly added application service through the combination of VLAN and Vsys on the SF, the networking cost is reduced, and the resource utilization of the SF is improved.
[0079] The method provided by the embodiments of the present application is described above, and the device provided by the embodiments of the present application is described below.
[0080] Referring to FIG. 6, FIG. 6 is a structural diagram of an application service implementation device in a service chain pseudo-proxy networking provided by an embodiment of the present application. The device is applied to a service chain pseudo-proxy networking. At least one pair of nodes in the service chain pseudo-proxy networking is deployed with a switch, and the pair of nodes is composed of a service chain forwarding node SFF and an application service node SF. The switch and the SF support the same N VLANs, and N is greater than 1. The SF is virtually outputted with multiple virtual systems Vsys, any Vsys is associated with at least two VLANs supported by the SF, and different Vsys are configured with different application service policies.
[0081] Optionally, in the embodiment, different Vsys are associated with different VLANs.
[0082] As shown in FIG. 6, the device is applied to the SF and includes:
[0083] A first receiving unit is configured to receive a first message forwarded by a switch through a local first interface. The first message carries a first VLAN identification, the first VLAN identification is determined by the switch when receiving the first message forwarded by the SFF to the SF through a second interface, and the first VLAN identification is the identification of a first VLAN supported by the second interface.
[0084] A service unit is configured to determine a first Vsys associated with the first VLAN identification, and perform corresponding service processing on the first message according to the application service policy corresponding to the first Vsys.
[0085] Optionally, the service unit further performs the following steps after performing the corresponding service processing on the first message:
[0086] If it is determined to release the first packet, a first VLAN identifier carried by the first packet is replaced by a second VLAN identifier associated with the first Vsys and different from the first VLAN identifier, to obtain a second packet;
[0087] The second packet is sent through a third interface locally supporting the second VLAN, so that when the switch receives the second packet through a fourth interface supporting the second VLAN, the second VLAN identifier carried by the second packet is stripped and forwarded to the SFF.
[0088] Optionally, the first packet is composed of an SRv6 inner packet and an SRv6 header.
[0089] The service unit performing corresponding service processing on the first packet according to the application service policy corresponding to the first Vsys includes: if the SF is configured to perform service processing on the SRv6 inner packet, performing corresponding service processing on the SRv6 inner packet in the first packet according to the application service policy corresponding to the first Vsys; if the SF is configured to perform service processing on the SRv6 header, performing corresponding service processing on the SRv6 header in the first packet according to the application service policy corresponding to the first Vsys.
[0090] Optionally, the interface of the SF accessing the switch is a Layer 2 Trunk port, and any Layer 2 Trunk port is configured to support at least one VLAN supported by the SF, and any Layer 2 Trunk port allows a packet carrying an identifier of a VLAN supported by the Layer 2 Trunk port to pass through.
[0091] So far, the structure of the device shown in FIG. 6 has been described.
[0092] Referring to FIG. 7, FIG. 7 is a structural diagram of an application service implementation device in another service chain pseudo-proxy networking provided by an embodiment of the present application. The device is applied in a service chain pseudo-proxy networking. At least one pair of nodes in the service chain pseudo-proxy networking is deployed with a switch, the pair of nodes is composed of a service chain forwarding node SFF and an application service node SF; the switch and the SF support the same N VLANs, and N is greater than 1; the SF is virtually provided with multiple virtual systems Vsys, and any Vsys is associated with at least two VLANs supported by the SF; different Vsys are configured to correspond to different application service policies;
[0093] Optionally, in the embodiment, different Vsys are associated with different VLANs.
[0094] As shown in FIG. 7, the device includes:
[0095] The second receiving unit is configured to receive, through a second interface, a first packet forwarded by the SFF to the SF;
[0096] The processing unit is configured to carry the identification of the first VLAN in the first packet to the SF based on the first VLAN supported by the second interface, so that the SF receives the first packet carrying the first VLAN identification through the local first interface and determines the first Vsys associated with the first VLAN identification, and performs corresponding service processing on the first packet according to the application service policy corresponding to the first Vsys.
[0097] Optionally,
[0098] The second receiving unit is further configured to receive a second packet through a fourth interface; the second packet is obtained by replacing the first VLAN identification carried in the first packet with a second VLAN identification when the SF determines to release the first packet after performing corresponding service processing on the first packet; the second VLAN identification is the identification of a second VLAN associated with the first Vsys except the first VLAN; and the fourth interface supports the second VLAN;
[0099] The processing unit is further configured to strip the second VLAN identification carried in the second packet and forward to the SFF;
[0100] The processing unit is further configured to strip the second VLAN identification carried in the second packet and forward to the SFF;
[0101] Optionally, carrying the identification of the first VLAN in the first packet to the SF includes carrying the first VLAN identification in the first packet and forwarding the first packet carrying the first VLAN identification to the SF through a sixth interface locally supporting the first VLAN.
[0102] The sixth interface is configured as a two-layer Trunk port and allows the first packet carrying the first VLAN identification to pass through; and the second interface is configured as a two-layer access port.
[0103] So far, the structural description of the device shown in FIG. 7 is completed.
[0104] The embodiment of the present application further provides a hardware structure of the above device. FIG. 8 is a structural diagram of an electronic device provided by the embodiment of the present application. As shown in FIG. 8, the hardware structure can include a processor and a machine readable storage medium, the machine readable storage medium stores machine executable instructions capable of being executed by the processor; and the processor is configured to execute the machine executable instructions to implement the method disclosed in the above examples of the present application.
[0105] Based on the same application concept as the above method, the embodiments of the present application also provide a machine readable storage medium, wherein a plurality of computer instructions are stored on the machine readable storage medium, and the computer instructions can realize the method disclosed in the above examples of the present application when executed by a processor.
[0106] For example, the machine readable storage medium can be a RAM (Random Access Memory), a volatile memory, a non-volatile memory, a flash memory, a storage drive (such as a hard drive), a solid state drive, any type of storage disk (such as an optical disk, a DVD, etc.), or similar storage medium, or a combination thereof.
[0107] The system, device, module or unit illustrated in the above embodiments can be specifically implemented by a computer chip or entity, or by a product with certain functions. A typical implementation device is a computer, and the specific form of the computer can be a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or a combination of any of these devices.
[0108] For the convenience of description, the above device is described as various units by functions respectively. Of course, the functions of each unit can be implemented in one or more software and / or hardware in the implementation of the present application.
[0109] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the embodiments of the present application can take the form of a computer program product implemented on one or more computer usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer usable program code.
[0110] The computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart and / or block diagram block or blocks.
[0111] Also, these computer program instructions can be stored in a computer readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer readable memory produce an article of manufacture including instructions which implement the function specified in the flowchart and / or block diagram block or blocks.
[0112] The computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart and / or block diagram block or blocks.
[0113] The above only describes the embodiments of the present application and is not intended to limit the present application. The present application can have various modifications and changes for those skilled in the art. Any modification, equivalent replacement, improvement, etc. within the spirit and principle of the present application shall be included in the scope of claims of the present application.
Claims
1. A method for implementing application services in a service chain pseudo-proxy network, characterized in that, In the service chain pseudo-proxy network, at least one pair of nodes is connected by a switch. The node pair includes a service chain forwarding node (SFF) and an application service node (SF). The switch and the SF support the same N VLANs, where N is greater than 1. The SF is virtualized into multiple virtual systems (Vsys), and any Vsys is associated with at least two VLANs supported by the SF. Different Vsys systems are configured with different application service policies; The method includes: The SF receives the first message forwarded by the switch through its local first interface; The first message carries a first VLAN identifier, which is determined by the switch when it receives the first message forwarded by the SFF to the SF through the second interface. The first VLAN identifier is the identifier of the first VLAN supported by the second interface. The SF determines the first Vsys associated with the first VLAN identifier and performs corresponding service processing on the first packet according to the application service policy corresponding to the first Vsys.
2. The method according to claim 1, characterized in that, The method also includes: After performing the corresponding service processing on the first packet, if the SF determines to allow the first packet, it replaces the first VLAN identifier carried in the first packet with the second VLAN identifier to obtain the second packet; the second VLAN identifier is the identifier of the second VLAN other than the first VLAN associated with the first Vsys. The SF sends the second packet through a third interface that supports the second VLAN locally, so that when the switch receives the second packet through a fourth interface that supports the second VLAN, it removes the second VLAN identifier carried in the second packet and forwards it to the SFF.
3. The method according to claim 1, characterized in that, The first message consists of an SRv6 inner message and an SRv6 header; The step of performing corresponding service processing on the first packet according to the application service policy corresponding to the first Vsys includes: When the SF is configured to perform service processing on the SRv6 inner packet, the corresponding service processing is performed on the SRv6 inner packet in the first packet according to the application service policy corresponding to the first Vsys. When the SF is configured to perform service processing on the SRv6 header, or if the SF is not configured to perform service processing on the SRv6 header, then when the SF is also not configured to perform service processing on the SRv6 inner packet, the corresponding service processing is performed on the SRv6 header in the first packet according to the application service policy corresponding to the first Vsys.
4. The method according to claim 2, characterized in that, The first interface through which the SF receives the first message is a Layer 2 Trunk port; The first interface is configured to allow packets carrying the first VLAN identifier to pass through; The third interface is a Layer 2 Trunk port; the third interface is configured to carry the second VLAN identifier. The message passed.
5. A method for implementing application services in a service chain pseudo-proxy network, characterized in that, In the service chain pseudo-proxy network, at least one pair of nodes is connected by a switch. The node pair includes a service chain forwarding node (SFF) and an application service node (SF). The switch and the SF support the same N VLANs, where N is greater than 1. The SF is virtualized into multiple virtual systems (Vsys), and any Vsys is associated with at least two VLANs supported by the SF. Different Vsys systems are configured with different application service policies; The method includes: The switch receives the first message forwarded by the SFF to the SF through the second interface; The switch forwards the first packet to the SF based on the first VLAN supported by the second interface, carrying the identifier of the first VLAN. This enables the SF to receive the first packet carrying the first VLAN identifier through its local first interface, determine the first Vsys associated with the first VLAN identifier, and perform corresponding service processing on the first packet according to the application service policy corresponding to the first Vsys.
6. The method according to claim 5, characterized in that, The method further includes: The switch receives the second packet through the fourth interface; the second packet is obtained by the SF after performing the corresponding service processing on the first packet and determining to allow the first packet, by replacing the first VLAN identifier carried in the first packet with the second VLAN identifier; the second VLAN identifier is the identifier of the second VLAN other than the first VLAN associated with the first Vsys; the fourth interface supports the second VLAN; The switch removes the second VLAN identifier carried in the second packet and forwards it to the SFF.
7. The method according to claim 6, characterized in that, The process of the switch removing the second VLAN identifier carried in the second packet and forwarding it to the SFF includes: If the switch determines that its local fifth interface (excluding the fourth interface) supports the second VLAN and that the fifth interface is configured as a Layer 2 access port, then it removes the second VLAN identifier carried in the second packet and forwards it to the SFF through the fifth interface.
8. The method according to any one of claims 5 to 7, characterized in that, The step of forwarding the first VLAN identifier to the SF in the first packet includes: forwarding the first packet carrying the first VLAN identifier to the SF through the sixth interface that supports the first VLAN locally; The sixth interface is configured as a Layer 2 Trunk port, allowing the first packet carrying the first VLAN identifier to pass through; the second interface is configured as a Layer 2 access port.
9. An application service implementation device in a service chain pseudo-proxy network, characterized in that, In the service chain pseudo-proxy network, at least one pair of nodes is connected by a switch. The node pair includes a service chain forwarding node (SFF) and an application service node (SF). The switch and the SF support the same N VLANs, where N is greater than 1. The SF is virtualized into multiple virtual systems (Vsys), and any Vsys is associated with at least two VLANs supported by the SF. Different Vsys systems are configured with different application service policies; This device is used in SF and includes: The first receiving unit is used to receive a first packet forwarded by the switch through a local first interface; the first packet carries a first VLAN identifier, which is determined by the switch when it receives the first packet forwarded by the SFF to the SF through the second interface, and the first VLAN identifier is the identifier of the first VLAN supported by the second interface; The service unit is used to determine the first Vsys associated with the first VLAN identifier and perform corresponding service processing on the first packet according to the application service policy corresponding to the first Vsys.
10. The apparatus according to claim 9, characterized in that, After performing the corresponding service processing on the first message, the service unit further performs the following steps: If it is determined that the first packet can be allowed, the first VLAN identifier carried in the first packet is replaced with the second VLAN identifier associated with the first Vsys, excluding the first VLAN identifier, to obtain the second packet; The second packet is sent through a third interface that supports the second VLAN locally, so that when the switch receives the second packet through a fourth interface that supports the second VLAN, it removes the second VLAN identifier carried in the second packet and forwards it to the SFF.
11. The apparatus according to claim 9, characterized in that, The first message consists of an SRv6 inner message and an SRv6 header; The service unit performs corresponding service processing on the first packet according to the application service policy corresponding to the first Vsys, including: if the SF is configured to perform service processing on the SRv6 inner packet, then the SF performs corresponding service processing on the SRv6 inner packet in the first packet according to the application service policy corresponding to the first Vsys; if the SF is configured to perform service processing on the SRv6 header, then the SF performs corresponding service processing on the SRv6 header in the first packet according to the application service policy corresponding to the first Vsys; and / or, The interfaces on the SF that connect to the switch are Layer 2 Trunk ports. Each Layer 2 Trunk port is configured to support at least one VLAN supported by the SF, and each Layer 2 Trunk port allows packets carrying the identifier of the VLAN supported by that Layer 2 Trunk port to pass through.
12. An application service implementation device in a service chain pseudo-proxy network, characterized in that, In the service chain pseudo-proxy network, at least one pair of nodes is connected by a switch. The node pair includes a service chain forwarding node (SFF) and an application service node (SF). The switch and the SF support the same N VLAN identifiers, where N is greater than 1. The SF is virtualized into multiple virtual systems (Vsys), and any Vsys is associated with at least two VLAN identifiers supported by the SF. Different Vsys systems are configured with different application service policies; The device includes: The second receiving unit is used to receive the first message forwarded by the SFF to the SF through the second interface; The processing unit is configured to, based on the first VLAN supported by the second interface, assign the identifier of the first VLAN... The first packet is forwarded to the SF so that the SF can receive the first packet carrying the first VLAN identifier through the local first interface and determine the first Vsys associated with the first VLAN identifier, and perform corresponding service processing on the first packet according to the application service policy corresponding to the first Vsys.
13. The apparatus according to claim 12, characterized in that, The second receiving unit is also configured to receive a second message through the fourth interface; the second message is obtained by the SF after performing corresponding service processing on the first message and determining to allow the first message to pass, by replacing the first VLAN identifier carried in the first message with the second VLAN identifier; The second VLAN identifier is the identifier of the second VLAN other than the first VLAN associated with the first Vsys; The fourth interface supports the second VLAN; The processing unit further removes the second VLAN identifier carried in the second message and forwards it to the SFF; The process of the processing unit removing the second VLAN identifier carried in the second message and forwarding it to the SFF includes: determining that the local fifth interface (excluding the fourth interface) supports the second VLAN and that the fifth interface is configured as a Layer 2 access port, then removing the second VLAN identifier carried in the second message and forwarding it to the SFF through the fifth interface.
14. The apparatus according to claim 12 or 13, characterized in that, The step of forwarding the first VLAN identifier to the SF in the first packet includes: forwarding the first packet carrying the first VLAN identifier to the SF through the sixth interface that supports the first VLAN locally; The sixth interface is configured as a Layer 2 Trunk port, allowing the first packet carrying the first VLAN identifier to pass through; the second interface is configured as a Layer 2 access port.
15. An electronic device, characterized in that, The electronic device includes: a processor and a machine-readable storage medium; The machine-readable storage medium stores machine-executable instructions that can be executed by the processor; The processor is configured to execute machine-executable instructions to implement the method of any one of claims 1 to 8.
16. A machine-readable storage medium, characterized in that, Machine-readable storage media store machine-executable instructions that can be executed by a processor; The machine-executable instructions are executed by a processor to implement the method of any one of claims 1 to 8.
Citation Information
Patent Citations
Service function chaining across multiple subnetworks
CN108463989A
Message forwarding method and network equipment
CN114374634A
System and method for realizing service chain function based on VLAN (Virtual Local Area Network)
CN115695086A
Method, architecture, apparatus and system relating to network programming
CN117441328A