CN106878194A - A kind of message processing method and device - Google Patents

A kind of message processing method and device Download PDF

Info

Publication number
CN106878194A
CN106878194A CN201611260096.0A CN201611260096A CN106878194A CN 106878194 A CN106878194 A CN 106878194A CN 201611260096 A CN201611260096 A CN 201611260096A CN 106878194 A CN106878194 A CN 106878194A
Authority
CN
China
Prior art keywords
message
address
flow table
service chaining
processed
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Granted
Application number
CN201611260096.0A
Other languages
Chinese (zh)
Other versions
CN106878194B (en
Inventor
樊超
王海
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
New H3C Technologies Co Ltd
Original Assignee
New H3C Technologies Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by New H3C Technologies Co Ltd filed Critical New H3C Technologies Co Ltd
Priority to CN201611260096.0A priority Critical patent/CN106878194B/en
Publication of CN106878194A publication Critical patent/CN106878194A/en
Application granted granted Critical
Publication of CN106878194B publication Critical patent/CN106878194B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L47/00Traffic control in data switching networks
    • H04L47/10Flow control; Congestion control
    • H04L47/12Avoiding congestion; Recovering from congestion
    • H04L47/125Avoiding congestion; Recovering from congestion by balancing the load, e.g. traffic engineering
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L12/00Data switching networks
    • H04L12/28Data switching networks characterised by path configuration, e.g. LAN [Local Area Networks] or WAN [Wide Area Networks]
    • H04L12/46Interconnection of networks
    • H04L12/4633Interconnection of networks using encapsulation techniques, e.g. tunneling
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L45/00Routing or path finding of packets in data switching networks
    • H04L45/74Address processing for routing
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L47/00Traffic control in data switching networks
    • H04L47/10Flow control; Congestion control
    • H04L47/24Traffic characterised by specific attributes, e.g. priority or QoS
    • H04L47/2425Traffic characterised by specific attributes, e.g. priority or QoS for supporting services specification, e.g. SLA
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L47/00Traffic control in data switching networks
    • H04L47/70Admission control; Resource allocation
    • H04L47/82Miscellaneous aspects
    • H04L47/825Involving tunnels, e.g. MPLS
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L61/00Network arrangements, protocols or services for addressing or naming
    • H04L61/09Mapping addresses
    • H04L61/25Mapping addresses of the same type
    • H04L61/2503Translation of Internet protocol [IP] addresses

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer And Data Communications (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

The application provides a kind of message processing method and device, and the method includes:Control strategy is issued to load-balancing device;Receive the first kind message sent on access device;Determine that the first kind message is message or the message without service chaining treatment by service chaining treatment according to the control strategy;If the message for having been processed by service chaining, then generate the first flow table and the second flow table, and the first flow table and the second flow table are handed down into the access device;First flow table is used to make access device that first kind message is sent into the server, second flow table is used to make access device carry out tunnel encapsulation and be sent to load-balancing device for corresponding first response message of first kind message, and the tunnel head of first response message is identified including service chaining.By the technical scheme of the application, address translation feature and service chaining function can be simultaneously supported in load balancing network, improve the use scope of load balancing network, improve user's use feeling.

Description

A kind of message processing method and device
Technical field
The application is related to communication technical field, more particularly to a kind of message processing method and device.
Background technology
As shown in figure 1, being the networking schematic diagram of load balancing, load balancing network includes load-balancing device and multiple clothes There is business device, these servers identical to configure, and for realizing identical business function, and these servers externally provide one VSIP (Virtual Service IP, void service IP), and, void service IP can be as the IP of load-balancing device ground Location.Load-balancing device, can be from these servers after the data message that purpose IP address are void service IP is received One server (such as server 1) of selection, and the purpose IP address of data message are revised as the real IP address of server 1, And the server 1 is given by amended data message forwarding, Business Processing is carried out by the server 1, to realize load balancing.
In order to find failed server and faulty link in time, load-balancing device can be periodically to each server (by taking server 1 as an example) sends health monitoring message, and the source IP address of the health monitoring message is void service IP, purpose IP ground Location is the real IP address of server 1.And server 1 can return to response message after the health monitoring message is received, load Balancing equipment analyses whether to break down according to response message.
Service chaining (Service Chain) is as guiding data message sequenced through service node (ServiceNode) Retransmission technique, is widely used.In conventional manner, in order to realize service chaining function, can on the controller configuration message it is special Levy (usually source IP address+purpose IP address, such as IP address of the IP address+server of main frame) corresponding with what service chaining was identified Relation.Based on this, for the response message of data message, after the response message that controller send on access device is received, Because the source IP address of the response message is the IP address of server 1, purpose IP address are the IP address of main frame, therefore can be looked into Service chaining mark is ask, and the flow table identified including the service chaining is issued to access device, so that access device utilizes the service Chain mark is packaged treatment.Additionally, for the response message of health monitoring message, controller send on access device is received The response message after, due to the response message source IP address for server 1 IP address, purpose IP address are load balancing The IP address of equipment, therefore service chaining mark will not be inquired, and the flow table not identified including service chaining is issued to access device, So that access device carries out common encapsulation process.
But, under a kind of application scenarios, load-balancing device is the number that the void services IP purpose IP address are received After according to message, the purpose IP address of data message are not only revised as the real IP address of server 1, can also be by data message Source IP address is revised as void service IP.Based on this application scenarios, if the configuration IP address of main frame, server on the controller The corresponding relation that IP address is identified with service chaining, because the purpose IP of the response message of data message is empty service IP, rather than The IP address of main frame, so as to lead to not inquire service chaining mark corresponding with the response message, then cannot be to the response Message carries out service chaining treatment.
The content of the invention
The application provides a kind of message processing method, is applied to controller, and methods described includes:
Control strategy is issued to load-balancing device, the control strategy is used to make the load-balancing device to having passed through Message and/or carry out designated treatment without the message that service chaining is processed that service chaining is processed, the load-balancing device has Address translation feature;
The first kind message sent on access device is received, the first kind message is load-balancing device according to control strategy Message after being processed, the source address of the first kind message is the address of the load-balancing device, and destination address is company Connect the address of the server of the access device;
According to the control strategy determine the first kind message be by service chaining process message or without The message of service chaining treatment;
If the first kind message is the message for being processed by service chaining, the first flow table and the second flow table are generated, and First flow table and the second flow table are handed down to the access device;
Wherein, first flow table is used to make the access device that first kind message is sent into the server, described Second flow table is used to make the access device carry out tunnel encapsulation and be sent to for corresponding first response message of first kind message Load-balancing device, the tunnel head of first response message is identified including service chaining.
The application provides a kind of message process device, is applied to controller, and described device includes:
Sending module, for issuing control strategy to load-balancing device, the control strategy is used to make the load equal Weighing apparatus equipment carries out designated treatment to the message by service chaining treatment and/or the message without service chaining treatment, wherein, institute Stating load-balancing device has address translation feature;
Receiver module, for receiving the first kind message sent on access device, the first kind message is that load balancing sets For the message after being processed according to control strategy, the source address of the first kind message is the ground of the load-balancing device Location, destination address is the address of the server for connecting the access device;
Determining module, for determining that the first kind message is report by service chaining treatment according to the control strategy Text or the message processed without service chaining;
Generation module, for when the first kind message be by service chaining process message when, generate the first flow table With the second flow table;First flow table is used to make access device that first kind message is sent into the server, the second Table is used to make access device for corresponding first response message of first kind message carries out tunnel encapsulation and be sent to load balancing setting Standby, the tunnel head of first response message is identified including service chaining;
The sending module, is additionally operable to for the first flow table and the second flow table to be handed down to the access device.
Based on above-mentioned technical proposal, in the embodiment of the present application, if load-balancing device receives purpose IP address and is taken for empty During the data message of business IP, the purpose IP address of data message are not only revised as the IP address of server, also by data message Source IP address be revised as empty service IP, under such application scenarios, although the address information of the response message of data message, Address information with the response message of health monitoring message is identical, but, control strategy is issued by load-balancing device, with Make load-balancing device to the message (such as data message) for having been processed by service chaining and/or the message without service chaining treatment (such as health monitoring message) carries out designated treatment, so, after the first kind message that controller send on access device is received, can It is data message by service chaining treatment to distinguish the first kind message, or the health prison processed without service chaining Observe and predict text.Can be that the response message generation of data message includes service chaining for the data message for having been processed by service chaining The flow table (i.e. the second flow table) of mark, and access device is handed down to, so that access device carries out tunnel encapsulation for the response message, And the tunnel head after encapsulation is identified including service chaining, the service chaining treatment to this response message is realized.In sum, Ke Yi Support that address translation feature (purpose IP address is such as revised as the IP address of server, and by source in load balancing network simultaneously IP address is revised as empty service IP) and service chaining function, the use scope of load balancing network is improved, improve user's use feeling Receive.
Brief description of the drawings
In order to clearly illustrate the embodiment of the present application or technical scheme of the prior art, below will be to the application The accompanying drawing to be used needed for embodiment or description of the prior art is briefly described, it should be apparent that, in describing below Accompanying drawing is only some embodiments described in the application, for those of ordinary skill in the art, can also be according to this Shen Please these accompanying drawings of embodiment obtain other accompanying drawings.
Fig. 1 is the networking schematic diagram of load balancing;
Fig. 2 is the flow chart of the message processing method in a kind of implementation method of the application;
Fig. 3 is the application scenarios schematic diagram in a kind of implementation method of the application;
Fig. 4 is the hardware structure diagram of the controller in a kind of implementation method of the application;
Fig. 5 is the structure chart of the message process device in a kind of implementation method of the application.
Specific embodiment
In term used in this application merely for the sake of the purpose for describing specific embodiment, and unrestricted the application.This Shen Please it is also intended to include most forms with " one kind ", " described " and " being somebody's turn to do " of the singulative used in claims, unless Context clearly shows that other implications.It is also understood that term "and/or" used herein refers to comprising one or more Associated any or all of project listed may be combined.
It will be appreciated that though various information, but this may be described using term first, second, third, etc. in the application A little information should not necessarily be limited by these terms.These terms are only used for being distinguished from each other open same type of information.For example, not departing from In the case of the application scope, the first information can also be referred to as the second information, and similarly, the second information can also be referred to as One information.Depending on linguistic context, additionally, used word " if " can be construed to " and ... when " or " when ... when " Or " in response to determining ".
A kind of message processing method is proposed in the embodiment of the present application, the method can apply to include controller (such as SDN (Software Defined Network, software defined network) controller), load-balancing device, access device, at least two In the network (such as load balancing network) of server.
In one example, access device (such as interchanger) is connected with each server respectively.In a kind of application scenarios Under, multiple servers, access device can be deployed on a physical equipment, and such as server is virtual on the physical equipment Machine, access device is the OVS (open vswitch, virtual switch of increasing income) on the physical equipment.In another application scenarios Under, multiple servers, access device can be deployed on different physical equipments, and such as each server is a physical equipment, Access device is another physical equipment.
It is shown in Figure 2 under above-mentioned application scenarios, it is the flow of the message processing method of proposition in the embodiment of the present application Figure, the method can apply to controller, and the method may comprise steps of:
Step 201, control strategy is issued to load-balancing device, and the control strategy is used to make load-balancing device to Cross the message of service chaining treatment and/or carry out designated treatment without the message that service chaining is processed.
Wherein, load-balancing device has address translation feature, for example, for the data message for receiving, by the data The source IP address of message is converted to empty service IP, and the purpose IP address of the data message are converted to the IP address of server, right This transfer process, will be described in detail in subsequent process.
Wherein, refer to by the message of service chaining treatment:The message of service node treatment is passed through, for example, for Main frame is sent to the data message of server, and the data message can first pass through service node before load-balancing device is reached Treatment, reach load-balancing device when, the data message be exactly pass through service node treatment message, can will this Data message is referred to as the message for having been processed by service chaining.
Without service chaining process message refer to:The message not processed by service node, for example, equal for loading The health monitoring message of weighing apparatus equipment generation, the health monitoring message therefore, it can be good for this without going past the treatment of service node Health monitoring message is referred to as the message processed without service chaining.
In one example, the message addition first that the control strategy is specially to having been processed by service chaining is identified, and The control strategy includes specifying address information.Or, the control strategy is specially the message addition to being processed without service chaining Second mark, and the control strategy does not include specified address information.Or, the control strategy is specially at without service chaining The message addition second of reason is identified, and the control strategy includes specifying address information.Or, the control strategy is specially to Cross the mark of message addition the 3rd of service chaining treatment, the message to being processed without service chaining and add the 4th mark, and the control Strategy does not include specifying address information.Or, the control strategy is specially the message addition the 3rd to having been processed by service chaining Mark, the message to being processed without service chaining add the 4th mark, and the control strategy includes specifying address information.
Wherein, the specified address information can include source IP address and purpose IP address, and the source IP address can take for empty Business IP (i.e. above-mentioned VSIP), the purpose IP address can be the IP address of server.
Step 202, receives the first kind message sent on access device, and the first kind message is load-balancing device according to control Strategy processed processed after message, and, the source address of the first kind message is the address of load-balancing device, and destination address is Connect the address of the server of access device.
In one example, load-balancing device can carry out designated treatment (tool to first kind message using control strategy Body processing procedure is repeated in subsequent step), and the first kind message after treatment is sent to access device.Access device is being received To after first kind message, if not inquiring the flow table matched with the first kind message, the first kind message will be sent to control Device processed, the first kind message is received by controller.
Step 203, determines that the first kind message is the message or not that is processed by service chaining according to the control strategy By the message that service chaining is processed.If the message for having been processed by service chaining, then step 204 is performed.
For " according to the control strategy determine the first kind message be by service chaining process message or without Cross service chaining treatment message " process, following manner can be included but is not limited to:
The message addition first that mode one, control strategy is specially to having been processed by service chaining is identified, and the control plan Slightly include specifying address information.In this fashion, it is empty service IP for source IP address, purpose IP address are the IP ground of server The first kind message of location, if first kind message is the message (such as health monitoring message) of load-balancing device itself generation, bears Carry balancing equipment and the first mark is added not in the first kind message, and first kind message is sent to access device.If first Class message is not the message (data that such as main frame is sent by load-balancing device to server of load-balancing device itself generation Message), then load-balancing device adds the first mark in the first kind message, and first kind message is sent into access sets It is standby.
In this fashion, controller first parses address letter after first kind message is received from the first kind message Breath, if the address information for parsing is identical with the specified address information that control strategy includes, can be true based on control strategy The fixed first kind message is the message for being processed by service chaining or the message processed without service chaining.Otherwise, can adopt The flow table matched with the first kind message is generated with traditional approach.
For " based on control strategy determine the first kind message be by service chaining process message or without The process of the message of service chaining treatment ", when the first kind message carries first to be identified, then can determine that the first kind message is The message for having been processed by service chaining;When the first kind message does not carry the first mark, then the first kind message can be determined It is the message processed without service chaining.
The message addition second that mode two, control strategy is specially to being processed without service chaining is identified, and the control plan Do not include slightly specifying address information.In this fashion, the first kind message for being generated for load-balancing device itself, load balancing Equipment adds the second mark in the first kind message, and first kind message is sent into access device;For not being equal load The first kind message of weighing apparatus equipment itself generation, then load-balancing device adds the second mark not in the first kind message, and incites somebody to action First kind message is sent to access device.
In this fashion, controller is after first kind message is received, when the first kind message carries second to be identified, then Can determine that the first kind message is the message processed without service chaining;When the first kind message does not carry the second mark, Can then determine that the first kind message is the message for being processed by service chaining.
The message addition second that mode three, control strategy is specially to being processed without service chaining is identified, and the control plan Slightly include specifying address information.In this fashion, it is empty service IP for source IP address, purpose IP address are the IP ground of server The first kind message of location, if first kind message is the message of load-balancing device itself generation, load-balancing device this Addition second is identified in one class message, and first kind message is sent into access device.If first kind message is not load balancing The message of equipment itself generation, then load-balancing device add second not in the first kind message and identifies, and by first kind report Text is sent to access device.
In this fashion, controller first parses address letter after first kind message is received from the first kind message Breath, if the address information for parsing is identical with the specified address information that control strategy includes, can be true based on control strategy The fixed first kind message is the message for being processed by service chaining or the message processed without service chaining.Otherwise, can adopt The flow table matched with the first kind message is generated with traditional approach.
For " based on control strategy determine the first kind message be by service chaining process message or without The process of the message of service chaining treatment ", when the first kind message carries second to be identified, then can determine that the first kind message is Without the message that service chaining is processed;When the first kind message does not carry the second mark, then the first kind message can be determined It is the message for having been processed by service chaining.
Mode four, control strategy is specially to by the mark of message addition the 3rd of service chaining treatment, to without clothes The message addition the 4th of business chain treatment is identified, and the control strategy does not include specifying address information.
In this fashion, the first kind message for being generated for load-balancing device itself, then load-balancing device can be Addition the 4th is identified in the first kind message, and the first kind message is sent into access device;For not being that load balancing sets The first kind message of standby itself generation, then load-balancing device can add the 3rd in the first kind message and identify, and should First kind message is sent to access device.
In this fashion, controller is after first kind message is received, when the first kind message carries the 4th to be identified, then Can determine that the first kind message is the message processed without service chaining;When the first kind message carries the 3rd to be identified, then Can determine that the first kind message is the message for being processed by service chaining.
Mode five, control strategy is specially to by the mark of message addition the 3rd of service chaining treatment, to without clothes The message addition the 4th of business chain treatment is identified, and the control strategy includes specifying address information.
In this fashion, it is empty service IP for source IP address, purpose IP address are the first kind of the IP address of server Message, if first kind message is the message of load-balancing device itself generation, load-balancing device can be in the first kind report Addition the 4th is identified in text, and the first kind message is sent into access device.If first kind message is not load-balancing device The message of itself generation, then load-balancing device can add the 3rd in the first kind message and identify, and by the first kind report Text is sent to access device.
In this fashion, controller first parses address letter after first kind message is received from the first kind message Breath, if the address information for parsing is identical with the specified address information that control strategy includes, can be true based on control strategy The fixed first kind message is the message for being processed by service chaining or the message processed without service chaining.Otherwise, can adopt The flow table matched with the first kind message is generated with traditional approach.
For " based on control strategy determine the first kind message be by service chaining process message or without The process of the message of service chaining treatment ", when the first kind message carries the 4th to be identified, then can determine that the first kind message is Without the message that service chaining is processed;When the first kind message carries the 3rd to be identified, then can determine that the first kind message is The message for having been processed by service chaining.
For aforesaid way, control strategy is specially TOS (the Type of to the message for having been processed by service chaining Service, COS) field addition first identifies, based on this, controller by parsing the TOS fields of the first kind message, Determine whether first kind message carries the first mark.Or, control strategy is specially to the message that is processed without service chaining TOS fields addition second is identified, and based on this, controller determines first kind message by parsing the TOS fields of the first kind message Whether second mark is carried.Or, control strategy is specially the TOS fields addition the 3rd to the message for having been processed by service chaining Mark, the TOS fields of message to being processed without service chaining add the 4th mark, based on this, controller by parse this The TOS fields of one class message, determine that the first kind message carries is the 3rd mark, or the 4th mark.
Step 204, generates the first flow table and the second flow table, and the first flow table and the second flow table are handed down into access device. Wherein, the first flow table is used to make access device that first kind message is sent into server, and the second flow table is for making access device Corresponding first response message of first kind message carries out tunnel encapsulation and is sent to load-balancing device, the tunnel of the first response message Trace header is identified including service chaining.
In one example, after step 203, if first kind message is the message processed without service chaining, give birth to Into the 3rd flow table and the 4th flow table, and by the 3rd flow table and the 4th flow table issuance to access device;Wherein, the 3rd flow table is used to make First kind message is sent to server by access device, and the 4th flow table is used to make access device by first kind message corresponding second Response message carries out tunnel encapsulation and is sent to load-balancing device, and the tunnel head of the second response message does not include service chaining mark Know.
In one example, for " generation the first flow table and the second flow table, and the first flow table and the second flow table are handed down to The process of access device ", controller can be generated as the first flow table and the second flow table when first kind message is received, and will First flow table and the second flow table are handed down to access device.Or, controller can only generate when first kind message is received One flow table, and the first flow table is handed down to access device;Afterwards, when access device receives the response message of first kind message When, if the flow table not matched, the response message is sent to controller, the corresponding stream of the response message is generated by controller Table, the flow table i.e. the second above-mentioned flow table, and second flow table is handed down to access device.
Controller can also generate the 5th flow table according to control strategy, and by the 5th flow table issuance to access device;Should 5th flow table is used to make access device be the address and destination of load-balancing device by processed without service chaining, source address Location is the message up sending of the address of the server for connecting the access device to controller.
Wherein, access device, for aforesaid way one, connects after the first kind message from load-balancing device is received Enter equipment and can not will carry the first kind message of the first mark to be defined as the message processed without service chaining, and by this report Controller is given on text.For aforesaid way two and mode three, access device can will carry the first kind message of the second mark It is defined as the message processed without service chaining, and by this message up sending to controller.For aforesaid way four and mode five, The first kind message that access device can carry the 4th mark is defined as the message processed without service chaining, and by this report Controller is given on text.
In one example, the priority of the 5th flow table can be higher than the priority of the first flow table;And the 5th flow table it is excellent First level can be less than the priority of the 3rd flow table.Based on this, access device can first judge whether message matches the 3rd flow table, such as Fruit is then to be processed based on the 3rd flow table, if it is not, then may determine that whether the message matches the 5th flow table, if it is, Then processed based on the 5th flow table, if it is not, then may determine that whether the message matches the first flow table, if it is, base Processed in first flow table.
In one example, the match options of the first flow table can include:Source IP address is the source IP ground of first kind message Location, purpose IP address are the purpose IP address of first kind message;Action option can include:By the interface associated with server The message that transmission is matched with the match options of the first flow table.The match options of the second flow table can include:Source IP address is first The purpose IP address of class message, purpose IP address are the source IP address of first kind message;Action option can include:With second Packing service chain mark in the message of the match options matching of flow table, and envelope is sent by the interface associated with load-balancing device Message equipped with service chaining mark.Wherein, priority of the priority of the 4th flow table higher than the second flow table.The matching of the 3rd flow table Option can include:Source IP address is the source IP address of first kind message, and purpose IP address are the purpose IP ground of first kind message Location;Action option can include:The message matched with the match options of the 3rd flow table is sent by the interface associated with server. The match options of the 4th flow table can include:Source IP address is the purpose IP address of first kind message, and purpose IP address are first The source IP address of class message, source port is the destination interface of first kind message, and destination interface is the source port of first kind message;It is dynamic Making option can include:The report matched with the match options of the 4th flow table is sent by the interface associated with load-balancing device Text.
In another example, the match options of the 3rd flow table can also include:Source port and destination interface, and source port It is the source port of first kind message, destination interface is the destination interface of first kind message.
Based on above-mentioned technical proposal, in the embodiment of the present application, if load-balancing device receives purpose IP address and is taken for empty During the data message of business IP, the purpose IP address of data message are not only revised as the IP address of server, also by data message Source IP address be revised as empty service IP, then under such application scenarios, can by configure on the controller empty service IP, The corresponding relation that the IP address of server is identified with service chaining, so, due to the purpose IP address of the response message of data message It is void service IP, source IP address is the IP address of server, therefore can inquire service chaining mark corresponding with the response message Know, service chaining treatment then is carried out to the response message.And, although the address information of the response message of data message, it is and strong The address information of the response message of health monitoring message is identical, but, control strategy is issued by load-balancing device, so that negative Carry balancing equipment to by service chaining process message (such as data message) and/or without service chaining process message (such as Health monitoring message) designated treatment is carried out, so, and after the first kind message that controller send on access device is received, can be with It is the data message for being processed by service chaining to distinguish the first kind message, or the health monitoring processed without service chaining Message.Can be that the response message generation of data message includes service chaining mark for the data message for having been processed by service chaining The flow table of knowledge, and access device is handed down to, so that access device is identified for the response message packing service chain of data message, realize Service chaining treatment to this response message.Can be health monitoring for the health monitoring message processed without service chaining The response message generation of message does not include the flow table of service chaining mark, and is handed down to access device, so that access device is not strong The response message packing service chain mark of health monitoring message, it is to avoid service chaining treatment is carried out to this response message.In sum, Can in load balancing network simultaneously support address translation feature (purpose IP address are such as revised as the IP address of server, And source IP address is revised as empty service IP) and service chaining function, the use scope of load balancing network is improved, improving user makes With impression.
In one example, it is health monitoring message with the message processed without service chaining, is processed by service chaining Message as a example by data message, to illustrate the Message processing process in the embodiment of the present application.
In the present embodiment, illustrate as a example by two in the above described manner, i.e., control strategy is specially to health monitoring message Addition second is identified.And, the source IP address of health monitoring message is identical with the source IP address of data message, health monitoring message Purpose IP address it is identical with the purpose IP address of data message.
Situation one, load-balancing device first sends health monitoring message, after send datagram.
Load-balancing device generate health monitoring message after, for itself generate health monitoring message, in the health Addition second is identified in monitoring message, and the health monitoring message is sent into access device.Access device receive this be good for After health monitoring message, because the health monitoring message can match the 5th flow table, therefore the health monitoring message is sent to Controller.Controller is identified after the health monitoring message is received because the health monitoring message carries second, therefore, really The fixed health monitoring message is the message processed without service chaining, generates the 3rd flow table and the 4th flow table, and by the 3rd flow table With the 4th flow table issuance to access device.Access device can be based on the health monitoring that the 3rd flow table sends load-balancing device Message, is transmitted to server, and this repeating process is no longer repeated in detail;Access device can be sent out server based on the 4th flow table The response message of the health monitoring message for sending, is transmitted to load-balancing device, and this repeating process is no longer repeated in detail.
Load-balancing device is modified after data message is received to data message, such as by the source IP of data message Empty service IP (source IP address with health monitoring message is identical) is revised as in address, and the purpose IP address of data message are revised as The IP address (purpose IP address with health monitoring message are identical) of server, the modification process is said in subsequent embodiment It is bright.For not being data message that itself is generated, load-balancing device add second not in data message and identifies, and by data Message is sent to access device.
Access device is after the data message is received, if the match options of the 3rd flow table only include source IP address and purpose IP address, due to there is the 3rd flow table matched with the data message, therefore, access device can be based on the 3rd flow table by number Server is sent to according to message.Access device is receiving the response message of server return (for the response of the data message Message) after, due in the absence of the flow table matched with the response message, therefore the response message is sent to controller.Controller After the response message is received, the second flow table is generated, and the second flow table is handed down to access device.In this case, connect Entering equipment can be based on the data message that the 3rd flow table sends load-balancing device, be transmitted to server;Access device can be with The response message of the data message for being sent server based on the second flow table, is transmitted to load-balancing device.
Access device is after the data message is received, if the match options of the 3rd flow table include source IP address, purpose IP Address, source port and destination interface, due to the flow table not matched with the data message, are then sent to control by the data message Device.Controller after the data message is received, because the data message does not carry the second mark, accordingly, it is determined that the datagram The message that Wen Weiyi is processed by service chaining, generates the first flow table and the second flow table, and by the first flow table and the second flow table issuance To access device.Or, the first flow table is only generated, and the first flow table is handed down to access device.Access device can be based on the The data message that one flow table sends load-balancing device, is transmitted to server, and this repeating process is no longer repeated in detail.If control Device processed issues the second flow table to access device, then access device can be based on the data message that the second flow table sends server Response message, be transmitted to load-balancing device.If controller does not issue the second flow table to access device, access device exists After the response message of the data message for receiving server transmission, the response message is sent to controller.Controller is connecing After receiving the response message, the second flow table is generated, and the second flow table is handed down to access device.Access device can be based on second Response message is transmitted to load-balancing device by flow table.
Situation two, load-balancing device is first sent datagram, and health monitoring message is sent afterwards.
Load-balancing device is modified after data message is received to data message, such as by the source IP of data message Empty service IP is revised as in address, and the purpose IP address of data message are revised as the IP address of server, and the modification process is rear Illustrated in continuous embodiment.For the data message for not being itself generation, load-balancing device is added not in data message Second mark, and data message is sent to access device.
Access device is after the data message is received, if the flow table not matched with the data message, by the data Message is sent to controller.Controller after the data message is received, because the data message does not carry the second mark, because This, determines that the data message is the message for being processed by service chaining, generates the first flow table and the second flow table, and by the first flow table Access device is handed down to the second flow table.Or, the first flow table is only generated, and the first flow table is handed down to access device.Access Equipment can be based on the data message that the first flow table sends load-balancing device, be transmitted to server, to this repeating process not Repeat in detail again.If controller issues the second flow table to access device, access device can be based on the second flow table by server The response message of the data message for sending, is transmitted to load-balancing device.If controller does not issue second to access device Flow table, then access device receive server transmission the data message response message after, the response message is sent to Controller.Controller generates the second flow table, and the second flow table is handed down into access device after the response message is received.Connect Entering equipment can be transmitted to load-balancing device based on the second flow table by response message.
(its source IP address is identical with the source IP address of data message, mesh in generation health monitoring message for load-balancing device IP address it is identical with the purpose IP address of data message) after, for itself generate health monitoring message, in the health monitoring Addition second is identified in message, and the health monitoring message is sent into access device.Access device is receiving health prison After observing and predicting text, due to the priority of the priority higher than the first flow table of the 5th flow table, therefore, access device will not be based on first-class The health monitoring message is sent to server by table, but the health monitoring message is sent into controller based on the 5th flow table.Control Device processed is identified, accordingly, it is determined that health monitoring message after health monitoring message is received because health monitoring message carries second It is the message processed without service chaining, generates the 3rd flow table and the 4th flow table, and the 3rd flow table and the 4th flow table issuance are given Access device.Access device can be based on the health monitoring message that the 3rd flow table sends load-balancing device, be transmitted to service (due to the priority of the priority higher than the 5th flow table of the 3rd flow table, therefore access device receives health monitoring report to device again Wen Hou, can be sent to server based on the 3rd flow table by the health monitoring message, rather than based on the 5th flow table by the health Monitoring message sends controller);Access device can be based on the sound of the health monitoring message that the 4th flow table sends server Message is answered, load-balancing device is transmitted to.
Below in conjunction with specific application scenarios, the technical scheme to the embodiment of the present application is described in detail.
As shown in figure 3, being the application scenarios schematic diagram of the embodiment of the present application, server 1, server 2 and server 3 have Identical is configured, and for realizing identical business function, the empty service IP that load-balancing device is used is 100.100.100.100.Data message (being subsequently referred to as data message 1), the server of server are sent to for main frame 1 The response message (being subsequently referred to as data message 2) of the data message 1 of main frame 1 is returned to, is required to carry out service chaining treatment. Wherein, service chaining (Service Chain) is a kind of retransmission technique for guiding data message in order through service node, to this Service chaining processing procedure is not limited.
In order to find failed server and faulty link in time, load-balancing device periodically can be sent out to each server Health monitoring message is sent, server can be returned strong for this after health monitoring message message is received to load-balancing device Health monitors the response message of message, is subsequently referred to as health monitoring response message.
Because data message 1, data message 2 need to carry out service chaining treatment, therefore, it can data message 1, datagram Text 2 is referred to as the message for having been processed by service chaining.Because health monitoring message, health monitoring response message need not be serviced Chain treatment, therefore, it can for health monitoring message, health monitoring response message to be referred to as the message processed without service chaining. Under above-mentioned application scenarios, health monitoring message is first sent with load-balancing device, after send datagram as a example by, then at the message Reason method may comprise steps of:
Step 11, controller issue control strategy to load-balancing device, and it is used to make load-balancing device supervise health Text addition mark is observed and predicted, is such as set to the TOS fields of health monitoring message to identify A.
In one example, controller issues the 5th flow table (abbreviation flow table 5) to access device, and the 5th flow table is used to make Access device will carry the health monitoring message up sending of mark A to controller.
Step 12, load-balancing device are needing to send health monitoring to server (being illustrated by taking server 1 as an example) During message, then the TOS fields of the health monitoring message are set to identify A.
The health monitoring message is sent to access device by step 13, load-balancing device.
Wherein, the source IP address of the health monitoring message is empty service IP (100.100.100.100), and purpose IP address can Think the real IP address (200.200.200.200) of server 1, source port is the port A of load-balancing device, destination interface It is the port B of server 1, and TOS fields are mark A.
After health monitoring message is received, inquiry is local to be whether there is and health monitoring message for step 14, access device 3rd flow table of matching.If it does not, performing step 15;If it does, using the 3rd matched with the health monitoring message Health monitoring message is sent to server 1 by flow table, subsequently introduces transmission process.
In one example, when having also set up tunnel (such as VXLAN (Virtual between load-balancing device and access device EXtensible Local Area Network, expansible Virtual Local Area Network) tunnel) when, load-balancing device can also be Health monitoring message encapsulation tunnel head (such as VXLAN tunnels head), access device first removes tunnel after health monitoring message is received Trace header, obtains health monitoring message therein, and this application scenarios is not limited.
Step 15, access device are based on flow table 5, and health monitoring message is sent into controller.
Step 16, controller after health monitoring message is received, due to parsing TOS fields from health monitoring message It is mark A, accordingly, it is determined that health monitoring message is the message processed without service chaining.
Wherein, can also be encapsulated in health monitoring message in packet-in message by access device, then should Packet-in message is sent to controller, and health monitoring message is parsed from packet-in message by controller.
Step 17, the corresponding flow table 1 (the 3rd flow table) of controller generation health monitoring message and flow table 2 (the 4th flow table). Flow table 1 is used to make access device that health monitoring message is sent into server 1, and flow table 2 is used to make access device by unencapsulated clothes The health monitoring response message of business chain mark is sent to load-balancing device.
In one example, the match options of the flow table 1 can include:Source IP address is the source IP of the health monitoring message Address (100.100.100.100), purpose IP address are the purpose IP address of the health monitoring message (200.200.200.200), source port is the source port (port A) of the health monitoring message, and destination interface is the health monitoring The destination interface (port B) of message.The Action option of flow table 1 can include:By the interface that is associated with server 1 (i.e. interface X the message matched with the flow table 1) is sent.
In one example, the match options of the flow table 2 can include:Source IP address is the purpose of the health monitoring message IP address (200.200.200.200), purpose IP address are the source IP address of the health monitoring message (100.100.100.100), source port is the destination interface (port B) of the health monitoring message, and destination interface is supervised for the health Observe and predict the source port (port A) of text.The Action option of flow table 2 can include:By the interface that is associated with load-balancing device (i.e. Interface Y) send the message matched with the flow table 2.
The flow table 1 and the flow table 2 are handed down to access device by step 18, controller.
Additionally, controller is after health monitoring message is received, health monitoring message can also be sent to server 1, it is right This transmission process is repeated no more.Access device after flow table 1 and flow table 2 is received, in local maintenance flow table 1 and flow table 2, when again It is secondary receive health monitoring message (i.e. step 14) after, due to locally there is the flow table 1 that match with health monitoring message, therefore utilization Health monitoring message is sent to server 1 by flow table 1.
Step 19, server 1 return to health monitoring response message after health monitoring message is received.
In one example, the source IP address of the health monitoring response message can be the real IP address of server 1 (200.200.200.200), purpose IP address can be empty service IP (100.100.100.100), and source port can be service The port B of device 1, destination interface can be the port A of load-balancing device.
Step 20, access device after health monitoring response message is received, because the health monitoring response message can be with Above-mentioned flow table 2 is matched, therefore, it can send the health monitoring response message by interface Y.
In this step, because health monitoring response message can match flow table 2, therefore access device will not be by health Giving controller, the i.e. response message of non-serving chain type on monitoring response message will not arrive controller.
Step 21, load-balancing device determine failure detection result after health monitoring response message is received.
Based on said process, it is possible to complete health monitoring message, the transmission of health monitoring response message, and load balancing Equipment can determine failure detection result based on health monitoring response message, and this process fault detection is not limited.Additionally, pin To data message 1 and the transmitting procedure of data message 2, can also include:
Step 22, main frame 1 send datagram 1, and the data message 1 is processing it by the service chaining of each service node Afterwards, load-balancing device is eventually arrived at, this service chaining processing procedure is not limited.
Step 23, load-balancing device carry out DNAT after data message 1 is received to data message 1 (Destination Network Address Translation, purpose network address translation) and SNAT (Source Network Address Translation, source network address conversion) conversion, the data message 1 after being changed.
In one example, the source IP address of data message 1 is the IP address (10.10.10.10) of main frame 1, purpose IP ground Location is empty service IP (100.100.100.100).Load-balancing device is to the conversion that data message 1 carries out DNAT and SNAT Refer to:Assuming that it is the destination server of data message 1 that server 1 is selected, then the source IP address of data message 1 is revised as empty clothes Business IP (100.100.100.100), the purpose IP address of data message 1 are revised as the real IP address of server 1 (200.200.200.200)。
Step 24, load-balancing device safeguard the session entry of data message 1, before the session entry can include conversion Five-tuple information, the five-tuple information after conversion, service chaining mark.Wherein, five-tuple information can include source IP address, purpose IP address, source port, destination interface and protocol type.
In one example, load-balancing device can be the final jump equipment of service chaining, therefore, load-balancing device The data message 1 for receiving be process of passing through tunnel encapsulation message, in tunnel head can carry service chaining mark (such as service chaining mark 1), load-balancing device can parse service chaining mark from tunnel head.Then, load-balancing device removal tunnel head, obtains To above-mentioned data message 1, and above-mentioned steps 23 and step 24 are performed based on data message 1.Based on above-mentioned treatment, load balancing sets For the five-tuple information before being changed, the five-tuple information after conversion, service chaining identifies the content such as 1, and the institute of Maintenance Table 1 The session entry for showing.
Table 1
Data message 1 after conversion is sent to access device by step 25, load-balancing device.
After data message 1 is received, local whether there is matches with the data message 1 for inquiry for step 26, access device Flow table.If it does not exist, then performing step 27;If it is present using the flow table matched with the data message 1 by the data Message 1 is sent to server 1, and the transmission process is introduced in subsequent process.
In one example, when tunnel is set up between load-balancing device and access device, load-balancing device may be used also Think the encapsulation tunnel head of data message 1, access device removes tunnel head after data message 1 is received, and obtains data message 1, This application scenarios is not limited.
In one example, although the match options of flow table 1 include:Source IP address is 100.100.100.100, purpose IP Address is 200.200.200.200, and source port is port A, and destination interface is port B, and, the source IP address of data message 1 It is void service IP (100.100.100.100), purpose IP address are the real IP address (200.200.200.200) of server 1. But, due to data message and health monitoring message using different port number as destination interface, therefore, data message 1 Destination interface can't be port B, therefore, the data message 1 would not also match above-mentioned flow table 1, will not be based on flow table 1 Forwarded.
Data message 1 is sent to controller by step 27, access device.
Step 28, controller after data message 1 is received, because the TOS fields parsed from data message 1 are not Mark A, accordingly, it is determined that data message 1 is the message for having been processed by service chaining.
Wherein, can also be encapsulated in data message 1 in packet-in message by access device, then by the packet-in Message is sent to controller, and data message 1 is parsed from packet-in message by controller.
Step 29, the controller flow table 3 (i.e. the first flow table) that is matched with the data message 1 of generation and flow table 4 (i.e. second Table).The flow table 3 is used to make access device that data message 1 is sent into server 1, and the flow table 4 is used to make access device be data Message 1 corresponding response message (i.e. data message 2) packing service chain is identified, and will be packaged with the data message of service chaining mark 2 are sent to load-balancing device.
In one example, the match options of the flow table 3 can include:Source IP address is the source IP ground of the data message 1 Location (100.100.100.100), purpose IP address are the purpose IP address (200.200.200.200) of the data message 1.Flow table 3 Action option can include:The message matched with the flow table 3 is sent by the interface (i.e. interface X) associated with server 1. The match options of the flow table 4 can include:Source IP address is the purpose IP address (200.200.200.200) of the data message 1, Purpose IP address are the source IP address (100.100.100.100) of the data message 1.The Action option of flow table 4 can include: Packing service chain mark in the message matched with flow table 4, and sent by the interface (i.e. interface Y) associated with load-balancing device The amended message (being packaged with the message of service chaining mark) matched with the flow table 4.
In one example, when needing to carry out data message service chaining and processing, can configuration data on the controller The corresponding relation that message characteristic is identified with service chaining, and data message feature is usually the source IP address and purpose IP of data message Address, can such as configure 100.100.100.100+200.200.200.200+ service chainings mark A, and service chaining mark A is used Need to carry out service chaining treatment to message in instruction.
Controller can inquire about this correspondence when flow table 4 is generated by 100.100.100.100+200.200.200.200 Relation, obtains service chaining and is designated service chaining mark A, and recorded in the Action option of flow table 4:In the report matched with flow table 4 Packing service chain mark A in text, and amended message is sent by interface Y.
The flow table 3 and the flow table 4 are handed down to access device by step 30, controller.
Additionally, controller is after data message 1 is received, data message 1 can also be sent to server 1, to this hair Journey is passed through to repeat no more.Access device after flow table 3 and flow table 4 is received, in local maintenance flow table 3 and flow table 4, when connecing again After receiving data message 1 (i.e. step 26), due to locally there is the flow table 3 matched with data message 1, therefore, will using flow table 3 The data message 1 is sent to server 1.
Step 31, server 1 after data message 1 is received, returned data message 2.
In one example, the source IP address of the data message 2 can be the real IP address of server 1 (200.200.200.200), purpose IP address can be empty service IP (100.100.100.100).
Step 32, access device after data message 2 is received, because the data message 2 can match above-mentioned flow table 4, therefore, access device packing service chain mark A in data message 2, and by the interface that is associated with load-balancing device (i.e. Interface Y) send the data message 2 for being packaged with service chaining mark A.
In this step, because data message 2 can match flow table 4, therefore access device will not send out data message 2 Give controller.And, when foundation has tunnel between load-balancing device and access device, access device can be datagram Literary 2 encapsulation tunnel heads, it is possible to which service chaining mark A is encapsulated into tunnel head, and the data after interface Y sends encapsulation Message 2.
Step 33, load-balancing device parse service chaining mark after data message 2 is received from data message 2 A, and determine to need to carry out service chaining treatment to data message 2 based on service chaining mark A.
For the process of " carrying out service chaining treatment to data message 2 ", by the five-tuple information of data message 2 (such as source IP address 200.200.200.200, purpose IP address 100.100.100.100, source port 12, destination interface 22, protocol type TCP) the session entry shown in inquiry table 1, obtains five-tuple information (such as source IP address 10.10.10.10, purpose IP address 100.100.100.100, source port 11, destination interface 21, protocol type TCP) and service chaining mark 1, by data message 2 Five-tuple information be converted to currently available five-tuple information, and tunnel encapsulation is carried out to the data message 2 after conversion.And And, service chaining mark 1 is carried in tunnel head after packaging, identify A rather than service chaining.So, for the number of different main frames According to the response message of message, its corresponding service chaining mark may be different, so as to carry out different service chaining treatment.
Data message 2 after encapsulation is sent to the corresponding service section of service chaining mark 1 by step 34, load-balancing device Point, the data message 2 after encapsulation eventually arrives at main frame 1, at this service chaining after being processed by the service chaining of service node Reason is not limited.
Based on said process, it is possible to complete data message 1, the transmitting procedure of data message 2.
In the embodiment of the present application, because the source IP address in flow table 2 is identical with the source IP address in flow table 4, in flow table 2 Purpose IP address are identical with the purpose IP address in flow table 4, therefore, in order that health monitoring response message can match flow table 2, data message 2 can match flow table 4, then set the priority of the priority higher than flow table 4 of flow table 2.Access device is connecing After receiving health monitoring response message, first inquire about whether health monitoring response message matches flow table 2, due to health monitoring response Message can match flow table 2, therefore send health monitoring response message based on flow table 2, without sending health based on flow table 4 Monitoring response message.Access device inquires about whether data message 2 matches flow table 2 after data message 2 is received, first, although The source IP address and purpose IP address of data message 2 can match the source IP address and purpose IP address of flow table 2, but, number The source port and destination interface of flow table 2 cannot be matched according to the source port and destination interface of message 2, therefore, data message 2 is not Flow table 2 is fitted on, and inquires about whether data message 2 matches flow table 4, because data message 2 can match flow table 4, therefore base 2 are sent datagram in flow table 4.
Conceived based on the application same with the above method, a kind of message process device additionally provided in the embodiment of the present application, The message process device can be applied in controller.Wherein, the message process device can be realized by software, it is also possible to be passed through The mode of hardware or software and hardware combining is realized.It is by it as the device on a logical meaning as a example by implemented in software The processor of the controller at place, corresponding computer program instructions are formed in reading non-volatile storage.From hardware layer For face, as shown in figure 4, a kind of hardware structure diagram of the controller where the message process device proposed for the application, except Outside processor, nonvolatile memory shown in Fig. 4, controller can also include other hardware, such as be responsible for turning for treatment message Hair chip, network interface, internal memory etc.;For from hardware configuration, the controller is also possible to be distributed apparatus, potentially includes many Individual interface card, to carry out the extension of Message processing in hardware view.
As shown in figure 5, the structure chart of the message process device proposed for the application, described device specifically includes:
Sending module 11, for issuing control strategy to load-balancing device, the control strategy is used to make load balancing Equipment carries out designated treatment to the message by service chaining treatment and/or the message without service chaining treatment, wherein, it is described Load-balancing device has address translation feature;
Receiver module 12, for receiving the first kind message sent on access device, the first kind message is load balancing Equipment processed according to control strategy after message, the source address of the first kind message is the ground of the load-balancing device Location, destination address is the address of the server for connecting the access device;
Determining module 13, for determining that the first kind message is to be processed by service chaining according to the control strategy Message or the message processed without service chaining;
Generation module 14, for when the first kind message be by service chaining process message when, generate it is first-class Table and the second flow table;First flow table is used to make access device that first kind message is sent into the server, described second Flow table is used to make access device carry out tunnel encapsulation and be sent to load balancing for corresponding first response message of first kind message Equipment, the tunnel head of first response message is identified including service chaining;
The sending module 11, is additionally operable to for the first flow table and the second flow table to be handed down to the access device.
The generation module 14, is additionally operable to when the first kind message is the message without service chaining treatment, then give birth to Into the 3rd flow table and the 4th flow table;3rd flow table is used to make the access device that first kind message is sent into the service Device, the 4th flow table is used to make the access device that corresponding second response message of first kind message is carried out into tunnel encapsulation simultaneously Load-balancing device is sent to, the tunnel head of second response message is not identified including service chaining;
The sending module 11, is additionally operable to the 3rd flow table and the 4th flow table issuance to the access device.
The determining module 13, specifically for determining the first kind message to have passed through clothes according to the control strategy During the message or the message without service chaining treatment of business chain treatment:
If the message addition first that the control strategy is specially to having been processed by service chaining is identified, and the control plan Slightly include specifying address information, then address information is parsed from the first kind message, if the address information for parsing and institute State the specified address information that control strategy includes identical, then when the first kind message carries first to be identified, it is determined that described First kind message is the message for being processed by service chaining;Otherwise, it determines the first kind message is to be processed without service chaining Message;Or,
If the message addition second that the control strategy is specially to being processed without service chaining is identified, when described first When class message carries the second mark, determine that the first kind message is the message processed without service chaining;Otherwise, it determines described First kind message is the message for being processed by service chaining;Or,
If the message addition second that the control strategy is specially to being processed without service chaining is identified, and the control plan Slightly include specifying address information, then address information is parsed from the first kind message, if the address information for parsing and institute State the specified address information that control strategy includes identical, then when the first kind message carries second to be identified, it is determined that described First kind message is the message processed without service chaining;Otherwise, it determines the first kind message is for by service chaining treatment Message;Or,
If the control strategy is specially to by the mark of message addition the 3rd of service chaining treatment, to without service The message addition the 4th of chain treatment is identified, then when the first kind message carries the 3rd to be identified, determine the first kind message It is the message processed by service chaining;When the first kind message carries the 4th to be identified, determine the first kind message for not By the message that service chaining is processed;Or,
If the control strategy is specially to by the mark of message addition the 3rd of service chaining treatment, to without service The message addition the 4th of chain treatment is identified, and the control strategy includes specifying address information, then from the first kind message Address information is parsed, if the address information for parsing is identical with the specified address information that the control strategy includes, when When the first kind message carries the 3rd mark, determine that the first kind message is the message processed by service chaining;When described When first kind message carries the 4th mark, determine that the first kind message is the message processed without service chaining.
The generation module 14, is additionally operable to generate the 5th flow table according to the control strategy;5th flow table is used to make The access device is by address that processed without service chaining, source address is the load-balancing device and destination address to connect The message up sending of address of the server of the access device is connect to the controller;
The sending module 11, is additionally operable to the 5th flow table issuance to the access device;
Wherein, priority of the priority of the 5th flow table higher than first flow table;
Priority of the priority of the 5th flow table less than the 3rd flow table.
The match options of first flow table include:Source IP address is the source IP address of first kind message, purpose IP address It is the purpose IP address of first kind message;Action option includes:Sent and described the by the interface that is associated with the server The message of the match options matching of one flow table;
The match options of second flow table include:Source IP address is the purpose IP address of first kind message, purpose IP ground Location is the source IP address of first kind message;Action option includes:In the message that the match options with second flow table are matched Packing service chain is identified, and the report for being packaged with the service chaining mark is sent by the interface associated with the load-balancing device Text;
The match options of the 3rd flow table include:Source IP address is the source IP address of first kind message, purpose IP address It is the purpose IP address of first kind message;Action option includes:Sent and described the by the interface that is associated with the server The message of the match options matching of three flow tables;
The match options of the 4th flow table include:Source IP address is the purpose IP address of first kind message, purpose IP ground Location is the source IP address of first kind message, and source port is the destination interface of first kind message, and destination interface is first kind message Source port;Action option includes:Sent by the interface that is associated with the load-balancing device and matched with the 4th flow table The message of option matching;
Wherein, priority of the priority of the 4th flow table higher than second flow table.
System, device, module or unit that above-described embodiment is illustrated, can specifically be realized by computer chip or entity, Or realized by the product with certain function.A kind of typically to realize equipment for computer, the concrete form of computer can Being personal computer, laptop computer, cell phone, camera phone, smart phone, personal digital assistant, media play In device, navigation equipment, E-mail receiver/send equipment, game console, tablet PC, wearable device or these equipment The combination of any several equipment.
For convenience of description, it is divided into various units with function during description apparatus above to describe respectively.Certainly, this is being implemented The function of each unit can be realized in same or multiple softwares and/or hardware during application.
It should be understood by those skilled in the art that, embodiments herein can be provided as method, system or computer program Product.Therefore, the application can be using the reality in terms of complete hardware embodiment, complete software embodiment or combination software and hardware Apply the form of example.And, the embodiment of the present application can be used and wherein include computer usable program code at one or more The computer implemented in computer-usable storage medium (including but not limited to magnetic disk storage, CD-ROM, optical memory etc.) The form of program product.
The application is the flow with reference to method, equipment (system) and computer program product according to the embodiment of the present application Figure and/or block diagram are described.It is generally understood that each in realizing flow chart and/or block diagram by computer program instructions The combination of flow and/or square frame in flow and/or square frame and flow chart and/or block diagram.These computer journeys can be provided Sequence instruction to all-purpose computer, special-purpose computer, Embedded Processor or other programmable data processing devices processor with Produce a machine so that being produced by the instruction of computer or the computing device of other programmable data processing devices is used for The dress of the function that realization is specified in one flow of flow chart or multiple one square frame of flow and/or block diagram or multiple square frames Put.
And, these computer program instructions can also be stored can guide computer or the treatment of other programmable datas to set In the standby computer-readable memory for working in a specific way so that instruction of the storage in the computer-readable memory is produced Manufacture including command device, the command device is realized in one flow of flow chart or multiple flows and/or block diagram one The function of being specified in individual square frame or multiple square frames.
These computer program instructions can be also loaded into computer or other programmable data processing devices so that in meter Series of operation steps is performed on calculation machine or other programmable devices to produce computer implemented treatment, so as in computer Or the instruction performed on other programmable devices is provided for realizing in one flow of flow chart or multiple flows and/or block diagram The step of function of being specified in one square frame or multiple square frames.
It will be understood by those skilled in the art that embodiments herein can be provided as method, system or computer program product. Therefore, the application can be using the implementation in terms of complete hardware embodiment, complete software embodiment or combination software and hardware The form of example.And, the application can be used and wherein include the calculating of computer usable program code at one or more The computer implemented in machine usable storage medium (magnetic disk storage, CD-ROM, optical memory etc. can be included but is not limited to) The form of program product.
Embodiments herein is the foregoing is only, the application is not limited to.For those skilled in the art For, the application can have various modifications and variations.It is all any modifications made within spirit herein and principle, equivalent Replace, improve etc., within the scope of should be included in claims hereof.

Claims (11)

1. a kind of message processing method, is applied to controller, it is characterised in that methods described includes:
Control strategy is issued to load-balancing device, the control strategy is used to make the load-balancing device to having passed through service Message and/or carry out designated treatment without the message that service chaining is processed that chain is processed, the load-balancing device has address Translation function;
The first kind message sent on access device is received, the first kind message is that load-balancing device is carried out according to control strategy Message after treatment, the source address of the first kind message is the address of the load-balancing device, and destination address is connection institute State the address of the server of access device;
According to the control strategy determine the first kind message be by service chaining process message or without service The message of chain treatment;
If the first kind message is the message for being processed by service chaining, the first flow table and the second flow table are generated, and by the One flow table and the second flow table are handed down to the access device;
Wherein, first flow table is used to make the access device that first kind message is sent into the server, described second Flow table is used to make the access device carry out tunnel encapsulation and be sent to load for corresponding first response message of first kind message Balancing equipment, the tunnel head of first response message is identified including service chaining.
2. method according to claim 1, it is characterised in that
It is described according to the control strategy determine the first kind message be by service chaining process message or without After the message of service chaining treatment, methods described also includes:
If the first kind message is the message processed without service chaining, the 3rd flow table and the 4th flow table are generated, and by the Three flow tables and the 4th flow table issuance give the access device;
Wherein, the 3rd flow table is used to make the access device that first kind message is sent into the server, the described 4th Flow table is used to make the access device that corresponding second response message of first kind message be carried out into tunnel encapsulation and load is sent to Balancing equipment, the tunnel head of second response message is not identified including service chaining.
3. method according to claim 1 and 2, it is characterised in that
It is described according to the control strategy determine the first kind message be by service chaining process message or without The process of the message of service chaining treatment, specifically includes:
If the message addition first that the control strategy is specially to having been processed by service chaining is identified, and the control strategy bag Specified address information is included, then parses address information from the first kind message, if the address information for parsing and the control The specified address information that system strategy includes is identical, then when the first kind message carries first to be identified, determine described first Class message is the message for being processed by service chaining;Otherwise, it determines the first kind message is the report processed without service chaining Text;Or,
If the message addition second that the control strategy is specially to being processed without service chaining is identified, when the first kind report When text carries the second mark, determine that the first kind message is the message processed without service chaining;Otherwise, it determines described first Class message is the message for being processed by service chaining;Or,
If the message addition second that the control strategy is specially to being processed without service chaining is identified, and the control strategy bag Specified address information is included, then parses address information from the first kind message, if the address information for parsing and the control The specified address information that system strategy includes is identical, then when the first kind message carries second to be identified, determine described first Class message is the message processed without service chaining;Otherwise, it determines the first kind message is the report for being processed by service chaining Text;Or,
If the control strategy be specially to processed by service chaining the mark of message addition the 3rd, at without service chaining Reason message addition the 4th identify, then when the first kind message carry the 3rd identify when, determine the first kind message be through Cross the message of service chaining treatment;When the first kind message carry the 4th identify when, determine the first kind message be without The message of service chaining treatment;Or,
If the control strategy be specially to processed by service chaining the mark of message addition the 3rd, at without service chaining The message addition the 4th of reason is identified, and the control strategy includes specifying address information, then parsed from the first kind message Go out address information, if the address information for parsing is identical with the specified address information that the control strategy includes, when described When first kind message carries the 3rd mark, determine that the first kind message is the message processed by service chaining;When described first When class message carries the 4th mark, determine that the first kind message is the message processed without service chaining.
4. method according to claim 3, it is characterised in that
The Type Of Service TOS field addition first that the control strategy is specially the message to having been processed by service chaining is identified; Or, the TOS fields addition second that the control strategy is specially the message to being processed without service chaining is identified;Or, institute Control strategy is stated to be specially to being identified by the TOS fields addition the 3rd of the message of service chaining treatment, to without service chaining The TOS fields addition the 4th of the message for the treatment of is identified.
5. method according to claim 2, it is characterised in that methods described also includes:
5th flow table is generated according to the control strategy, and the access device is given by the 5th flow table issuance;
5th flow table is used to make the access device by processed without service chaining, source address for the load balancing sets Standby address and destination address is the message up sending of the address of the server for connecting the access device to the controller;
Wherein, priority of the priority of the 5th flow table higher than first flow table;
Priority of the priority of the 5th flow table less than the 3rd flow table.
6. the method according to claim 2 or 5, it is characterised in that
The match options of first flow table include:Source IP address is the source IP address of first kind message, and purpose IP address are the The purpose IP address of one class message;Action option includes:Send first-class with described by the interface associated with the server The message of the match options matching of table;
The match options of second flow table include:Source IP address is the purpose IP address of first kind message, and purpose IP address are The source IP address of first kind message;Action option includes:Encapsulated in the message that the match options with second flow table are matched Service chaining is identified, and the message for being packaged with the service chaining mark is sent by the interface associated with the load-balancing device;
The match options of the 3rd flow table include:Source IP address is the source IP address of first kind message, and purpose IP address are the The purpose IP address of one class message;Action option includes:Sent and the described 3rd stream by the interface associated with the server The message of the match options matching of table;
The match options of the 4th flow table include:Source IP address is the purpose IP address of first kind message, and purpose IP address are The source IP address of first kind message, source port is the destination interface of first kind message, and destination interface is the source of first kind message Mouthful;Action option includes:The match options with the 4th flow table are sent by the interface associated with the load-balancing device The message of matching;
Wherein, priority of the priority of the 4th flow table higher than second flow table.
7. a kind of message process device, is applied to controller, it is characterised in that described device includes:
Sending module, for issuing control strategy to load-balancing device, the control strategy is used to set the load balancing It is standby that designated treatment is carried out to the message by service chaining treatment and/or the message without service chaining treatment, wherein, it is described negative Carrying balancing equipment has address translation feature;
Receiver module, for receiving the first kind message sent on access device, the first kind message is load-balancing device root Message after being processed according to control strategy, the source address of the first kind message is the address of the load-balancing device, mesh Address be the server for connecting the access device address;
Determining module, for according to the control strategy determine the first kind message be by service chaining process message, Or the message processed without service chaining;
Generation module, for when the first kind message is the message for processing by service chaining, the first flow table of generation and the Two flow tables;First flow table is used to make access device that first kind message is sent into the server, and second flow table is used In making access device carry out tunnel encapsulation and be sent to load-balancing device for corresponding first response message of first kind message, institute The tunnel head for stating the first response message is identified including service chaining;
The sending module, is additionally operable to for the first flow table and the second flow table to be handed down to the access device.
8. device according to claim 7, it is characterised in that
The generation module, is additionally operable to when the first kind message is the message without service chaining treatment, then generate the 3rd Flow table and the 4th flow table;3rd flow table is used to make the access device that first kind message is sent into the server, institute The 4th flow table is stated for making the access device that corresponding second response message of first kind message is carried out tunnel encapsulation and be sent To load-balancing device, the tunnel head of second response message is not identified including service chaining;
The sending module, is additionally operable to the 3rd flow table and the 4th flow table issuance to the access device.
9. the device according to claim 7 or 8, it is characterised in that
The determining module, specifically for determined according to the control strategy first kind message for by service chaining at During the message of reason or the message without service chaining treatment:
If the message addition first that the control strategy is specially to having been processed by service chaining is identified, and the control strategy bag Specified address information is included, then parses address information from the first kind message, if the address information for parsing and the control The specified address information that system strategy includes is identical, then when the first kind message carries first to be identified, determine described first Class message is the message for being processed by service chaining;Otherwise, it determines the first kind message is the report processed without service chaining Text;Or,
If the message addition second that the control strategy is specially to being processed without service chaining is identified, when the first kind report When text carries the second mark, determine that the first kind message is the message processed without service chaining;Otherwise, it determines described first Class message is the message for being processed by service chaining;Or,
If the message addition second that the control strategy is specially to being processed without service chaining is identified, and the control strategy bag Specified address information is included, then parses address information from the first kind message, if the address information for parsing and the control The specified address information that system strategy includes is identical, then when the first kind message carries second to be identified, determine described first Class message is the message processed without service chaining;Otherwise, it determines the first kind message is the report for being processed by service chaining Text;Or,
If the control strategy be specially to processed by service chaining the mark of message addition the 3rd, at without service chaining Reason message addition the 4th identify, then when the first kind message carry the 3rd identify when, determine the first kind message be through Cross the message of service chaining treatment;When the first kind message carry the 4th identify when, determine the first kind message be without The message of service chaining treatment;Or,
If the control strategy be specially to processed by service chaining the mark of message addition the 3rd, at without service chaining The message addition the 4th of reason is identified, and the control strategy includes specifying address information, then parsed from the first kind message Go out address information, if the address information for parsing is identical with the specified address information that the control strategy includes, when described When first kind message carries the 3rd mark, determine that the first kind message is the message processed by service chaining;When described first When class message carries the 4th mark, determine that the first kind message is the message processed without service chaining.
10. device according to claim 8, it is characterised in that
The generation module, is additionally operable to generate the 5th flow table according to the control strategy;5th flow table is used to make described connecing Enter equipment by address that processed without service chaining, source address is the load-balancing device and destination address for connection is described The message up sending of the address of the server of access device gives the controller;
The sending module, is additionally operable to the 5th flow table issuance to the access device;
Wherein, priority of the priority of the 5th flow table higher than first flow table;
Priority of the priority of the 5th flow table less than the 3rd flow table.
11. device according to claim 8 or 10, it is characterised in that
The match options of first flow table include:Source IP address is the source IP address of first kind message, and purpose IP address are the The purpose IP address of one class message;Action option includes:Send first-class with described by the interface associated with the server The message of the match options matching of table;
The match options of second flow table include:Source IP address is the purpose IP address of first kind message, and purpose IP address are The source IP address of first kind message;Action option includes:Encapsulated in the message that the match options with second flow table are matched Service chaining is identified, and the message for being packaged with the service chaining mark is sent by the interface associated with the load-balancing device;
The match options of the 3rd flow table include:Source IP address is the source IP address of first kind message, and purpose IP address are the The purpose IP address of one class message;Action option includes:Sent and the described 3rd stream by the interface associated with the server The message of the match options matching of table;
The match options of the 4th flow table include:Source IP address is the purpose IP address of first kind message, and purpose IP address are The source IP address of first kind message, source port is the destination interface of first kind message, and destination interface is the source of first kind message Mouthful;Action option includes:The match options with the 4th flow table are sent by the interface associated with the load-balancing device The message of matching;
Wherein, priority of the priority of the 4th flow table higher than second flow table.
CN201611260096.0A 2016-12-30 2016-12-30 Message processing method and device Active CN106878194B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201611260096.0A CN106878194B (en) 2016-12-30 2016-12-30 Message processing method and device

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201611260096.0A CN106878194B (en) 2016-12-30 2016-12-30 Message processing method and device

Publications (2)

Publication Number Publication Date
CN106878194A true CN106878194A (en) 2017-06-20
CN106878194B CN106878194B (en) 2020-01-03

Family

ID=59165451

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201611260096.0A Active CN106878194B (en) 2016-12-30 2016-12-30 Message processing method and device

Country Status (1)

Country Link
CN (1) CN106878194B (en)

Cited By (10)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN109714259A (en) * 2018-12-27 2019-05-03 新华三技术有限公司 A kind of flow processing method and device
CN110545230A (en) * 2019-09-06 2019-12-06 北京百度网讯科技有限公司 method and device for forwarding VXLAN message
CN111107178A (en) * 2019-12-29 2020-05-05 苏州浪潮智能科技有限公司 Method and equipment for assigning message to use local address
CN111158864A (en) * 2019-12-31 2020-05-15 奇安信科技集团股份有限公司 Data processing method, device, system, medium, and program
CN111343030A (en) * 2020-03-31 2020-06-26 新华三信息安全技术有限公司 Message processing method, device, network equipment and storage medium
CN111614539A (en) * 2020-05-12 2020-09-01 京信通信系统(中国)有限公司 Service data processing method and device and communication transmission equipment
CN111835576A (en) * 2019-04-19 2020-10-27 厦门网宿有限公司 DPVS-based back-end server health detection method and server
CN111865963A (en) * 2020-07-16 2020-10-30 郑州信大捷安信息技术股份有限公司 IP data packet processing method and system based on IP option
CN112311895A (en) * 2020-11-12 2021-02-02 中国电子科技集团公司第五十四研究所 Transparent mode TCP flow load balancing method and device based on SDN
CN113472677A (en) * 2021-07-01 2021-10-01 华云数据控股集团有限公司 Load balancing flow processing method, system and computer medium for virtualized environment

Citations (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20150063102A1 (en) * 2013-08-30 2015-03-05 Cisco Technology, Inc. Flow Based Network Service Insertion
CN104579998A (en) * 2013-10-29 2015-04-29 国家计算机网络与信息安全管理中心 Load balance processing device
CN104780088A (en) * 2015-03-19 2015-07-15 杭州华三通信技术有限公司 Service message transmission method and equipment
CN105681218A (en) * 2016-04-11 2016-06-15 北京邮电大学 Flow processing method and device in Openflow network
CN105830404A (en) * 2013-12-17 2016-08-03 思科技术公司 Method for implicit session routing
CN106105165A (en) * 2014-03-25 2016-11-09 思科技术公司 There is the dynamic service chain of network address translation detection
US20160366046A1 (en) * 2015-06-09 2016-12-15 International Business Machines Corporation Support for high availability of service appliances in a software-defined network (sdn) service chaining infrastructure

Patent Citations (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20150063102A1 (en) * 2013-08-30 2015-03-05 Cisco Technology, Inc. Flow Based Network Service Insertion
CN104579998A (en) * 2013-10-29 2015-04-29 国家计算机网络与信息安全管理中心 Load balance processing device
CN105830404A (en) * 2013-12-17 2016-08-03 思科技术公司 Method for implicit session routing
CN106105165A (en) * 2014-03-25 2016-11-09 思科技术公司 There is the dynamic service chain of network address translation detection
CN104780088A (en) * 2015-03-19 2015-07-15 杭州华三通信技术有限公司 Service message transmission method and equipment
US20160366046A1 (en) * 2015-06-09 2016-12-15 International Business Machines Corporation Support for high availability of service appliances in a software-defined network (sdn) service chaining infrastructure
CN105681218A (en) * 2016-04-11 2016-06-15 北京邮电大学 Flow processing method and device in Openflow network

Cited By (19)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN109714259B (en) * 2018-12-27 2021-04-27 新华三技术有限公司 Traffic processing method and device
CN109714259A (en) * 2018-12-27 2019-05-03 新华三技术有限公司 A kind of flow processing method and device
CN111835576A (en) * 2019-04-19 2020-10-27 厦门网宿有限公司 DPVS-based back-end server health detection method and server
CN111835576B (en) * 2019-04-19 2022-03-04 厦门网宿有限公司 DPVS-based back-end server health detection method and server
CN110545230B (en) * 2019-09-06 2023-09-26 北京百度网讯科技有限公司 Method and device for forwarding VXLAN message
CN110545230A (en) * 2019-09-06 2019-12-06 北京百度网讯科技有限公司 method and device for forwarding VXLAN message
CN111107178A (en) * 2019-12-29 2020-05-05 苏州浪潮智能科技有限公司 Method and equipment for assigning message to use local address
CN111158864A (en) * 2019-12-31 2020-05-15 奇安信科技集团股份有限公司 Data processing method, device, system, medium, and program
CN111158864B (en) * 2019-12-31 2023-05-30 奇安信科技集团股份有限公司 Data processing method, device, system, medium, and program
CN111343030A (en) * 2020-03-31 2020-06-26 新华三信息安全技术有限公司 Message processing method, device, network equipment and storage medium
CN111343030B (en) * 2020-03-31 2022-07-12 新华三信息安全技术有限公司 Message processing method, device, network equipment and storage medium
CN111614539A (en) * 2020-05-12 2020-09-01 京信通信系统(中国)有限公司 Service data processing method and device and communication transmission equipment
CN111614539B (en) * 2020-05-12 2022-02-08 京信网络系统股份有限公司 Service data processing method and device and communication transmission equipment
CN111865963B (en) * 2020-07-16 2022-02-25 郑州信大捷安信息技术股份有限公司 IP data packet processing method and system based on IP option
CN111865963A (en) * 2020-07-16 2020-10-30 郑州信大捷安信息技术股份有限公司 IP data packet processing method and system based on IP option
CN112311895B (en) * 2020-11-12 2022-10-11 中国电子科技集团公司第五十四研究所 Transparent mode TCP flow load balancing method and device based on SDN
CN112311895A (en) * 2020-11-12 2021-02-02 中国电子科技集团公司第五十四研究所 Transparent mode TCP flow load balancing method and device based on SDN
CN113472677A (en) * 2021-07-01 2021-10-01 华云数据控股集团有限公司 Load balancing flow processing method, system and computer medium for virtualized environment
CN113472677B (en) * 2021-07-01 2024-02-09 华云数据控股集团有限公司 Virtualized environment load balancing flow processing method, system and computer medium

Also Published As

Publication number Publication date
CN106878194B (en) 2020-01-03

Similar Documents

Publication Publication Date Title
CN106878194A (en) A kind of message processing method and device
CN104348740B (en) Data package processing method and system
CN106664261B (en) A kind of methods, devices and systems configuring flow entry
US8537839B2 (en) Traffic generator with dynamic MPLS label assignment
US9900090B1 (en) Inter-packet interval prediction learning algorithm
CN105306368B (en) A kind of transmission method and device of data message
CN106878164A (en) A kind of message transmitting method and device
CN104283780B (en) The method and apparatus for establishing data transfer path
CN106341338B (en) A kind of retransmission method and device of message
CN106789652A (en) Service shunting method and device
CN109656767A (en) A kind of acquisition methods, system and the associated component of CPLD status information
CN109088820A (en) A kind of striding equipment link aggregation method, device, computing device and storage medium
CN109495320A (en) A kind of transmission method and device of data message
CN106453625A (en) Information synchronization method and high-availability cluster system
CN112787913B (en) Intelligent network card assembly, physical machine, cloud service system and message sending method
CN106506515A (en) A kind of authentication method and device
CN105656708A (en) Single-board testing method and device
CN107547346A (en) A kind of message transmitting method and device
CN115065637B (en) Method and device for transmitting computing power resource information and electronic equipment
CN108718258A (en) The quality determining method and equipment of link between a kind of plate
CN109039959A (en) A kind of the consistency judgment method and relevant apparatus of SDN network rule
CN106559339A (en) A kind of message processing method and device
CN108259348A (en) A kind of message transmitting method and device
CN104219160B (en) Generate the method and apparatus of input parameter
CN107086960A (en) A kind of message transmitting method and device

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination
GR01 Patent grant
GR01 Patent grant