WO2016150296A1 - Method and device for sending and receiving flow specification rule - Google Patents

Method and device for sending and receiving flow specification rule Download PDF

Info

Publication number
WO2016150296A1
WO2016150296A1 PCT/CN2016/075632 CN2016075632W WO2016150296A1 WO 2016150296 A1 WO2016150296 A1 WO 2016150296A1 CN 2016075632 W CN2016075632 W CN 2016075632W WO 2016150296 A1 WO2016150296 A1 WO 2016150296A1
Authority
WO
WIPO (PCT)
Prior art keywords
orf
flow specification
specification rule
network device
record
Prior art date
Application number
PCT/CN2016/075632
Other languages
French (fr)
Chinese (zh)
Inventor
梁乾灯
尤建洁
郝卫国
Original Assignee
华为技术有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 华为技术有限公司 filed Critical 华为技术有限公司
Publication of WO2016150296A1 publication Critical patent/WO2016150296A1/en

Links

Images

Definitions

  • the embodiments of the present invention relate to communication technologies, and in particular, to a method and an apparatus for transmitting and receiving a flow specification rule.
  • the Border Gateway Protocol (BGP) protocol is widely used on the Internet to transfer routing information between Autonomous Systems (ASs) and ASs.
  • the routing information that is transmitted includes: Network Protocol Reachability Information (NLRI) information such as Internet Protocol (IP) routing, Media Access Control (MAC) routing, and flow specification rules.
  • NLRI Network Protocol Reachability Information
  • IP Internet Protocol
  • MAC Media Access Control
  • the flow specification rule is mainly used for network security defense, and the attack information or the suspected attack traffic information and the coping strategy (speed limit, dyeing, redirection, etc.) detected in the AS are distributed to the AS network edge router, and even spread across the domain, so that Attack traffic as early as possible.
  • the receiving end filters the flow specification rule sent by the sending end locally, and filters out the invalid flow specification rule.
  • the transmitting end still needs to send a large number of invalid flow specification rules, and the network bandwidth occupied by a large number of invalid flow specification rules and the central processing unit (CPU) computing resources are generated. Waste of network resources and computing resources.
  • Embodiments of the present invention provide a method and apparatus for transmitting and receiving a flow specification rule, which can support outbound route filtering for a flow specification rule, and reduce transmission of an invalid flow specification rule.
  • a first aspect of the present invention provides a method for transmitting a flow specification rule, including:
  • the first network device records, according to the flow specification rule ORF, a flow specification rule to be sent to the second network device;
  • the first network device sends the filtered flow specification rule to the second network device.
  • the flow specification rule ORF record includes: a sequence number field of a flow specification rule ORF record, an action matching field, a filter type field, a filter specific operation and a value field, the sequence number field of the flow specification rule ORF record is used to carry a priority of the flow specification rule ORF record, and the action matching field is used to carry an action type that matches the flow specification rule.
  • the filter type field is used to carry a filter type, and the filter specific operation and value field are used to carry a filter condition corresponding to the filter type.
  • the flow specification rule ORF record further includes: a route identifier number field and a route identifier field
  • the route identifier number field is used to carry the number of route identifiers, and the route identifier field is used to carry the route identifier.
  • the flow specification rule ORF record further includes: a filter number field The filter number field is used to carry the number of filters.
  • the first network device records, according to the flow specification rule ORF, the The flow specification rules of the second network device are filtered, including:
  • the first network device includes, by the flow specification rule ORF record, an action matching field, a filter number field, a filter type field, a filter specific operation, and a value field, respectively, and the to-be-sent to the
  • the flow specification rule of the second network device includes: an action type field, a filter Type field, filter specific operation, and value field for comparison;
  • the flow specification rule ORF record includes a filter set that is empty or a filter-specific operation of each filter type and a value space of the value field contain the to-be-sent to the second network
  • the flow specification rule of the device includes a filter-specific operation of the filter type and a numerical space of the value field, and the first network device determines that the flow specification rule to be sent to the second network device matches the flow Specification rule ORF record.
  • the first network device records, according to the flow specification rule ORF, the The flow specification rules of the second network device are filtered, including:
  • the first network device includes, by the flow specification rule ORF record, an action matching field, a filter type field, a filter specific operation and a value field, and a route identifier field, respectively, to be sent to the second
  • the flow specification rule of the network device includes: an action type field, a filter type field, a filter specific operation and a value field, and a route identifier field for comparison;
  • the flow specification rule ORF record includes a filter set that is empty or a filter-specific operation of each filter type and a value space of the value field contain the to-be-sent to the second network
  • the flow specification rule of the device includes a filter-specific operation of the corresponding filter type and a numerical space of the value field
  • the flow specification rule ORF record includes a route identifier set consisting of a route identifier that is empty or included in the route identifier set.
  • the first network device determines that the flow specification rule to be sent matches the flow specification rule ORF record, where the flow specification rule is to be sent to the second network device.
  • the first The network device determines that the second network device is capable of transmitting the flow specification rule ORF record to the first network device, including:
  • the first network device obtains a first flow specification rule ORF capability parameter, where the first flow specification rule ORF capability parameter indicates a flow specification rule ORF capability supported by the second network device, where the first flow specification rule ORF capability parameter includes: At least one group is identified by an address family identifier, a sub-address family, a parameter set consisting of a flow specification rule ORF type and a transceiver capability identifier, and the transceiver capability identifier included in the first flow specification rule ORF capability parameter is used to indicate whether the second network device supports sending and/or receiving a flow specification rule ORF record. ;
  • the first network device compares the first flow specification rule ORF capability parameter with a second flow specification rule ORF capability parameter, and the second flow specification rule ORF capability parameter indicates a flow specification rule ORF capability supported by the first network device
  • the second flow specification rule ORF capability parameter includes: at least one set of parameters consisting of an address family identifier, a sub-address family identifier, a flow specification rule ORF type, and a transceiving capability identifier, and the second flow specification rule ORF capability parameter
  • the transceiver capability identifier included in the method is used to indicate whether the first network device supports sending and/or receiving a flow specification rule ORF record;
  • the first parameter set included in the first flow specification rule ORF capability parameter and the second parameter set included in the second flow specification rule ORF capability parameter include a flow specification rule ORF type
  • the first parameter set and the The second parameter set includes the same address family identifier and the sub-address family identifier, and the transceiver capability identifier of the first parameter set indicates the indication
  • the second network device supports transmission, the flow specification rule ORF record
  • the second The transceiver capability identifier of the parameter set indicates that the first network device supports receiving the flow specification rule ORF record
  • the first network device determines that the second network device can send the flow specification rule ORF record to the first network device.
  • the first network device obtains the first flow specification rule ORF capability parameter, including:
  • the first Receiving, by the network device, a flow specification rule ORF record sent by the second network device including:
  • the first network device receives a BGP route refresh message sent by the second network device, where the BGP route refresh message includes the flow specification rule ORF record.
  • the method further includes:
  • the stream specification rule ORF records are stored in an ordered manner into the stream specification rule ORF list of the corresponding type.
  • a second aspect of the present invention provides a method for receiving a flow specification rule, including:
  • the second network device determines that the first network device is capable of receiving the flow specification rule outbound route filtering ORF record
  • the second network device generates a flow specification rule ORF record according to the flow specification rule policy saved by itself;
  • the second network device receives the flow specification rule sent by the first network device, where the flow specification rule is that the first network device records the filtered flow specification rule according to the flow specification rule ORF.
  • the flow specification rule ORF record includes: a sequence number field of a flow specification rule ORF record, an action matching field, and a filter type field. a filter specific operation and a value field, wherein the sequence number field of the flow specification rule ORF record is used to carry a priority of the flow specification rule ORF record, and the action matching field is used to carry an action type that matches the flow specification rule.
  • the filter type field is used to carry a filter type, and the filter specific operation and value field are used to carry a filter condition corresponding to the filter type.
  • the flow specification rule ORF record further includes: a route identifier number field and a route identifier field
  • the route identifier number field is used to carry the number of route identifiers, and the route identifier field is used to carry the route identifier.
  • the flow specification rule ORF record further includes: a filter number field The filter number field is used to carry the number of filters.
  • the second The network device determines that the flow specification rule outbound route filtering ORF record can be sent to the first network device, including:
  • the second network device obtains a second flow specification rule ORF capability parameter, where the second flow specification rule ORF capability parameter indicates a flow specification rule ORF capability supported by the first network device, and the second flow specification rule ORF capability
  • the parameter includes: at least one set of parameters consisting of an address family identifier and a sub-address family identifier, a flow specification rule ORF type, and a transceiver capability identifier, where the transceiver capability identifier included in the second flow specification rule ORF capability parameter is used to indicate the Whether the first network device supports sending and/or receiving a flow specification rule ORF record;
  • the second network device compares the second flow specification rule ORF capability parameter with a first flow specification rule ORF capability parameter, where the first flow specification rule ORF capability parameter indicates a flow specification rule ORF capability supported by the second network device,
  • the first flow specification rule ORF capability parameter includes: at least one set of parameters consisting of an address family identifier and a sub-address family identifier, a flow specification rule ORF type, and a transceiving capability identifier, and the first stream specification rule ORF capability parameter includes The capability identifier is used to indicate whether the second network device supports sending and/or receiving a flow specification rule ORF record;
  • the first parameter set included in the first flow specification rule ORF capability parameter and the second parameter set included in the second flow specification rule ORF capability parameter include a flow specification rule ORF type
  • the first parameter set and the The second parameter set includes the same address family identifier and the sub-address family identifier, and the transceiver capability identifier of the first parameter set indicates that the second network device supports the sending flow specification rule ORF record, and the second parameter set is capable of transmitting and receiving.
  • the identifier indicates that the first network device supports receiving the flow specification rule ORF record, and the second network device determines that the flow specification rule ORF record can be sent to the first network device.
  • the second network device obtains the second flow specification rule ORF capability parameter, including:
  • the BGP open message sent by the first network device in the process of establishing a BGP connection with the first network device, where the BGP open message sent by the first network device includes the The second-flow specification rules ORF capability parameters.
  • the second The network device sends the flow specification rule ORF record to the first network device, including:
  • the second network device sends a BGP route refresh message to the first network device, where the route BGP refresh message includes the flow specification rule ORF record.
  • a third aspect of the present invention provides a first network device, including:
  • a determining module configured to determine, by the second network device, a flow specification rule outbound route filtering ORF record to the first network device
  • a receiving module configured to receive the flow specification rule ORF record sent by the second network device, where the flow specification rule ORF records a flow specification rule to be sent by the first network device to the second network device Filtering;
  • a filtering module configured to filter, according to the flow specification rule ORF, a flow specification rule to be sent to the second network device;
  • a sending module configured to send the filtered flow specification rule to the second network device.
  • the flow specification rule ORF record includes: a sequence number field, an action matching field, and a filter type field of a flow specification rule ORF record a filter specific operation and a value field, wherein the sequence number field of the flow specification rule ORF record is used to carry a priority of the flow specification rule ORF record, and the action matching field is used to carry an action type that matches the flow specification rule.
  • the filter type field is used to carry a filter type, and the filter specific operation and value field are used to carry a filter condition corresponding to the filter type.
  • the flow specification rule ORF record further includes: a route identifier number field and a route identifier field
  • the route identifier number field is used to carry the number of route identifiers, and the route identifier field is used to carry the route identifier.
  • the flow specification rule ORF record further includes: a filter number field The filter number field is used to carry the number of filters.
  • the filtering module is specifically configured to:
  • the flow specification rule ORF record includes: an action matching field, a filter number field, a filter type field, a filter specific operation, and a value field, respectively, and the flow to be sent to the second network device
  • the specification rules include: action type fields, filter type fields, filter specific operations, and value fields for comparison;
  • the flow specification rule ORF records include filtering The filter set is empty or the value space of the filter specific operation and value field of each filter type contains the filter specific operation of the filter type included in the flow specification rule to be sent to the second network device and And determining a value space of the value field, determining that the flow specification rule to be sent to the second network device matches the flow specification rule ORF record.
  • the filtering module is specifically configured to:
  • the flow specification rule ORF record includes: an action matching field, a filter type field, a filter specific operation and a value field, and a route identification field, respectively, and the flow specification rule to be sent to the second network device Included: action type field, filter type field, filter specific operation and value field and route identification field are compared;
  • the flow specification rule ORF record includes a filter set that is empty or a filter-specific operation of each filter type and a value space of the value field that includes the flow specification rule to be sent to the second network device a filter-specific operation and a value space of a value field, the flow specification rule ORF record includes a route identifier set consisting of a route identifier that is empty or the route identifier set includes the to-be-sent to the first And determining, by the flow specification rule of the network device, the flow identifier rule to be sent to the second network device, and matching the flow specification rule ORF record.
  • the determining module Specifically used for:
  • first flow specification rule ORF capability parameter indicating a flow specification rule ORF capability supported by the second network device
  • the first flow specification rule ORF capability parameter comprising: at least one group of address families
  • the parameter set consisting of the identifier, the sub-address family identifier, the flow specification rule ORF type, and the transceiver capability identifier, and the transceiver capability identifier included in the first-flow specification rule ORF capability parameter is used to indicate whether the second network device supports sending and/or Or receive a flow specification rule ORF record;
  • the specification rule ORF capability parameters include: at least one group is identified by an address family, a parameter set consisting of a sub-address family identifier, a flow specification rule ORF type, and a transceiving capability identifier, where the transceiving capability identifier included in the second-flow specification rule ORF capability parameter is used to indicate whether the first network device supports sending and/or Receive stream specification rule ORF record;
  • the first parameter set included in the first flow specification rule ORF capability parameter and the second parameter set included in the second flow specification rule ORF capability parameter include a flow specification rule ORF type
  • the first parameter set and the The second parameter set includes the same address family identifier and the sub-address family identifier, and the transceiver capability identifier of the first parameter set indicates that the second network device supports the sending flow specification rule ORF record, and the second parameter set is capable of transmitting and receiving.
  • the identifier indicates that the first network device supports receiving the flow specification rule ORF record, and determining that the second network device is capable of sending a flow specification rule ORF record to the first network device.
  • the acquiring the first flow specification rule ORF capability parameter includes:
  • the BGP open message sent by the second network device is received in the process of establishing a BGP connection with the second network device, and the BGP open message sent by the second network device includes the first flow specification rule ORF capability parameter.
  • the receiving module Specifically used for:
  • the device is further Including a storage processing module
  • the storage processing module configured to determine, after the receiving module receives the flow specification rule ORF record sent by the second network device, according to the address family identifier and the sub-address family identifier included in the flow specification rule ORF record
  • the flow specification rules the type of ORF record, and stores the flow specification rule ORF record in an orderly manner according to the sequence number of the flow specification rule ORF record into the flow specification rule ORF list of the corresponding type.
  • a fourth aspect of the present invention provides a second network device, including:
  • a determining module configured to determine that the first network device is capable of receiving a flow specification rule outbound route filtering ORF record
  • a generating module configured to generate a flow specification rule ORF record according to a flow specification rule policy saved by the second network device
  • a sending module configured to send, to the first network device, a flow specification rule ORF record generated by the generating module
  • a receiving module configured to receive a flow specification rule sent by the first network device, where the flow specification rule is that the first network device records the filtered flow specification rule according to the flow specification rule ORF.
  • the flow specification rule ORF record includes: a sequence number field of a flow specification rule ORF record, an action matching field, and a filter type field. a filter specific operation and a value field, wherein the sequence number field of the flow specification rule ORF record is used to carry a priority of the flow specification rule ORF record, and the action matching field is used to carry an action type that matches the flow specification rule.
  • the filter type field is used to carry a filter type, and the filter specific operation and value field are used to carry a filter condition corresponding to the filter type.
  • the flow specification rule ORF record further includes: a route identifier number field and a route identifier field
  • the route identifier number field is used to carry the number of route identifiers, and the route identifier field is used to carry the route identifier.
  • the flow specification rule ORF record further includes: a filter number field The filter number field is used to carry the number of filters.
  • the determining module Specifically used for:
  • the second flow specification rule ORF capability parameter indicates a flow specification rule ORF capability supported by the first network device
  • the second flow specification rule ORF capability parameter includes: at least one group a parameter set consisting of an address family identifier, a sub-address family identifier, a flow specification rule ORF type, and a transceiver capability identifier, where the transceiver capability identifier included in the second-flow specification rule ORF capability parameter is used to indicate whether the first network device is Support for sending and/or receiving flow specification rules ORF records;
  • the first flow specification rule ORF capability parameter indicating a flow specification rule supported by the second network device ORF capability
  • the first flow specification rule ORF capability parameter includes: at least one set of parameters consisting of an address family identifier, a sub-address family identifier, a flow specification rule ORF type, and a transceiving capability identifier
  • the first flow specification rule ORF capability parameter The transceiver capability identifier included in the indication is used to indicate whether the second network device supports sending and/or receiving a flow specification rule ORF record;
  • the first parameter set included in the first flow specification rule ORF capability parameter and the second parameter set included in the second flow specification rule ORF capability parameter include a flow specification rule ORF type
  • the first parameter set and the The second parameter set includes the same address family identifier and the sub-address family identifier
  • the transceiver capability identifier of the first parameter set indicates that the second network device supports sending, the flow specification rule ORF records, and the second parameter set of the transceiver capability identifier Instructing the first network device to support receiving a flow specification rule ORF record, determining that the second network device is capable of transmitting a flow specification rule ORF record to the first network device.
  • the acquiring the second flow specification rule ORF capability parameter includes:
  • the sending module Specifically used for:
  • a fifth aspect of the present invention provides a network system, where the network system includes: a first network device and a second network device;
  • the first network device is configured to perform the method according to any one of the first to ninth possible implementations of the first aspect of the present invention and the first aspect of the present invention;
  • the second network device is configured to perform the method of any one of the second aspect of the present invention and the first to sixth possible implementations of the second aspect of the present invention.
  • the method and device for transmitting and receiving a flow specification rule provided by the embodiment of the present invention after determining that the second network device can send the flow specification rule ORF record to the first network device, the first network device receives the flow specification sent by the second network device.
  • the rule ORF record, the flow specification rule ORF record is used by the first network device to filter the flow specification rule sent to the second network device, when the first network device has
  • the first network device filters the flow specification rule to be sent according to the flow specification rule ORF, and only sends the flow specification rule that satisfies the flow specification rule ORF record filter condition to the second network device,
  • the problem that the network device sends a large number of invalid flow specification rules and wastes resources is solved.
  • FIG. 1 is a flowchart of a method for sending a flow specification rule according to Embodiment 1 of the present invention
  • FIG. 3 is a format of a filter corresponding to four types of Filter Types provided by the embodiment
  • 5 is an example of message content of an IPv4 flow specification rule ORF record B carrying a filter that rejects any matching ICMP Code value
  • FIG. 6 is a flowchart of a method for receiving a flow specification rule according to Embodiment 2 of the present invention.
  • FIG. 7 is a schematic structural diagram of a first network device according to Embodiment 3 of the present invention.
  • FIG. 8 is a schematic structural diagram of a second network device according to Embodiment 4 of the present invention.
  • FIG. 9 is a schematic structural diagram of a first network device according to Embodiment 5 of the present invention.
  • FIG. 10 is a schematic structural diagram of a second network device according to Embodiment 6 of the present invention.
  • FIG. 11 is a schematic structural diagram of a network system according to Embodiment 7 of the present invention.
  • FIG. 1 is a flowchart of a method for sending a flow specification rule according to Embodiment 1 of the present invention. As shown in FIG. 1 , the method in this embodiment may include the following steps:
  • Step 101 The first network device determines that the second network device is capable of sending a flow specification rule ORF record to the first network device.
  • an outbound route filtering (English translation is: Outbound Route Filtering, ORF for short) type: flow specification rule (English translation: Flow Specification rule) ORF type, flow specification rule ORF capability for border gateway
  • BGP Border Gateway Protocol
  • a new ORF type is added to the original BGP protocol, that is, the flow specification ORF type is supported, so that the flow specification ORF capability is supported.
  • the first network device may determine, by using the flow specification rule ORF capability negotiation, that the second network device can send the flow specification rule outbound route filtering ORF record to the first network device.
  • the negotiation process is specifically as follows:
  • the first network device obtains a first flow specification rule ORF capability parameter, where the first flow specification rule ORF capability parameter indicates a flow specification rule ORF capability supported by the second network device, and the first flow specification rule ORF capability parameter includes: at least one group of addresses A set of parameters consisting of an address family identifier (AFI), a sub-address family identifier sub-address family identifier (SAFI), a flow specification rule ORF type, and a transceiver capability identifier.
  • AFI address family identifier
  • SAFI sub-address family identifier sub-address family identifier
  • SAFI sub-address family identifier
  • a flow specification rule ORF type a flow specification rule ORF type
  • transceiver capability identifier The first-flow specification rule ORF capability.
  • the transceiving capability identifier included in the parameter is used to indicate whether the second network device supports sending and/or receiving a stream specification rule ORF record (Entry).
  • the first network device obtains the first flow specification rule ORF capability parameter, where the first network device receives the BGP open (OPEN) message sent by the second network device in the process of establishing a BGP connection with the second network device, and the second network
  • the BGP OPEN message sent by the device includes the first flow specification rule ORF capability parameter.
  • the flow specification rule ORF record, Flow Spec-ORF-Type indicates the flow specification rule ORF type, and the specific value of the flow specification rule ORF type can be set as needed, for example, by the Internet Assigned Numbers Authority (IANA).
  • the distribution is not limited by the present invention.
  • the first network device supports sending and receiving an IPv4 flow specification rule ORF record
  • the first network device may also support sending and/or receiving multiple types of flow specification rule ORF records, as shown in Table 1:
  • the first network device compares the first flow specification rule ORF capability parameter with the second flow specification rule ORF capability parameter, where the second flow specification rule ORF capability parameter indicates the flow supported by the first network device Regulating the rule ORF capability, the second flow specification rule ORF capability parameter includes: at least one set of parameters consisting of AFI, SAFI, flow specification rule ORF type, and transceiving capability identifier, the second flow specification rule included in the ORF capability parameter
  • the transceiving capability identifier is used to indicate whether the first network device supports sending and/or receiving a flow specification rule ORF record.
  • the first parameter set included in the first flow specification rule ORF capability parameter and the second parameter set included in the second flow specification rule ORF capability parameter both contain a flow specification rule ORF type
  • the first parameter set and the second parameter set include the same AFI and SAFI
  • the transceiver capability identifier of the first parameter set indicates that the second network device supports the transmission flow specification rule ORF record
  • the transceiver capability identifier of the second parameter set indicates that the first network device supports the receive flow specification rule ORF record
  • the first parameter set is the first stream specification rule.
  • the ORF capability parameter includes at least one set of parameters in the plurality of sets of parameters.
  • the second parameter set is the second stream specification rule.
  • the ORF capability parameter includes at least one set of parameter sets in the plurality of sets of parameter sets. If the first norm rule ORF capability parameter includes a set of parameters, the first parameter set is the set of parameters included in the first stream specification rule ORF capability parameter, and if the second stream specification rule ORF capability parameter includes a set of parameters The second parameter set is the set of parameters included in the second flow specification rule ORF capability parameter.
  • the first network device is used as the sending end of the flow specification rule, and the receiving end of the flow specification rule ORF record, and the second network device is used as the receiving end of the flow specification rule and the sending end of the flow specification rule ORF record.
  • the first network device may be used as the receiving end of the flow specification rule, the sending end of the flow specification rule ORF record, and the second network device is used as the transmitting end of the flow specification rule and the receiving end of the flow specification rule ORF record. It is also possible that the first network device and the second network device simultaneously serve as a transmitting end and a receiving end of the flow specification rule and the flow specification rule ORF record.
  • the flow specification rule ORF capability negotiation result of the first network device and the second network device may have the following four results: (1) the first network device only sends the flow specification rule ORF record corresponding to at least one type of flow specification rule, The second network device only receives the flow specification rule ORF record corresponding to the at least one type of flow specification rule sent by the first network device. (2) The first network device only receives the flow specification rule ORF record corresponding to the at least one type of flow specification rule, and the second network device sends only the flow specification corresponding to the at least one type of flow specification rule that the first network device can receive. Regular ORF record. (3) Both the first network device and the second network device support sending and receiving a flow specification rule ORF record corresponding to at least one type of flow specification rule. (4) If the negotiation is unsuccessful, the first network device and the second network device cannot spread the ORF of the flow specification rule to each other.
  • the flow specification rule ORF capability supported or enabled by the first network device and the second network device should be based on the capability of the flow specification rule supported or enabled, for example, the first network device and the second network device are only in the
  • the IPv4 flow specification rule ORF function can be supported or enabled when the IPv4 flow specification rule function is enabled or enabled.
  • Step 102 The first network device receives a flow specification rule ORF record sent by the second network device, where the flow specification rule ORF records a flow specification rule used by the first network device to be sent to the second network device.
  • the second network device generates a flow specification rule ORF record according to its own flow specification rule policy, and the flow specification rule policy may be a network operation and maintenance personnel through a configuration command/network management or application.
  • the program is configured into a second network device through a device open interface (eg, RESTful API Over Http), which is a filtering policy for a particular type of flow specification rule for the first network device.
  • a device open interface eg, RESTful API Over Http
  • the flow specification rule ORF type needs to match the filter set expressing the message characteristics in the flow specification rule, so the filter type supported by the flow specification rule ORF type and the filter type supported by the flow specification rule are completely consistent.
  • the packet feature tuple corresponding to the filter type supported by the flow specification rule ORF type includes: the packet length, the destination IP address of the Internet Protocol (IP) header, the source IP address, the protocol type, and the difference. Source port and destination of the Service Code Point (DSCP), the Fragment Flag, and the User Datagram Protocol (UDP)/Transmission Control Protocol (TCP) Port, TCP Flag field and Internet Control Message Protocol (ICMP) Type field and Code field.
  • IP Internet Protocol
  • DSCP Service Code Point
  • UDP User Datagram Protocol
  • TCP Transmission Control Protocol
  • ICMP Internet Control Message Protocol
  • ORF entity message format For the newly added flow specification rule ORF type of the present invention, a new ORF entity message format needs to be defined, which is used to carry the filter condition of the flow specification rule, and the basic format of the flow specification rule ORF record newly defined in this embodiment is existing.
  • the ORF [RFC5291] definition is consistent and extends the Type specific part field of the ORF record.
  • the format of the flow specification rule ORF record includes the following fields: an Action field, a Match field, and a Reserved (Reserved). ) field and Type specific part field.
  • the Action field usually takes 2 bits and has three values. For example, you can use 00 for the Add operation, 01 for the Remove operation, and 10 for the Remove-all operation.
  • the Match field usually takes 1 bit and can represent two different meanings by two values. For example, 0 means Permit, 1 means Deny, and when the stream specification rule ORF records the value of the Match field. 0 indicates that the flow specification rule that satisfies the filter condition is allowed to pass.
  • the value of the Match field of the flow specification rule ORF record is 1, it indicates that the flow specification rule that satisfies the filter condition is not allowed to pass.
  • the sender of the Reserved field shall pad it to 0, and the receiver shall ignore this field.
  • the Type specific part field is a variable length field.
  • the Type specific part field includes: a sequence number (Sequence) field, an action matching (Action Matching) field, and a filter number (Filter Number) of the flow specification rule ORF record. Field, Filter Type field, filter specific action, and value field. Where the Sequence field can occupy 4
  • the byte is generally used to carry the priority of the flow specification rule ORF record, and can also be used to carry the ID or key value of the flow specification rule ORF record. When the first network device stores the flow specification rule ORF entry, it can follow the sequence of the sequence.
  • the flow specification rule to be matched is preferentially matched with the flow specification rule ORF entry with higher priority.
  • the Filter Number field can occupy 8 bits and is used to carry the number of filters included in the flow specification ORF record.
  • a flow specification rule ORF record can include multiple filters, which can also be called a filter set.
  • Action Matching is used to carry the action type that matches the flow specification rule.
  • the action type of each flow specification rule corresponds to a tag bit, and the action position corresponding to the action type of the flow specification rule indicates that the action type matches the flow specification rule.
  • the mark position 0 corresponding to the action type of the rule indicates the action type that does not match the flow specification rule.
  • the action type of the flow specification rule corresponding to the set flag bit is included in the currently compared flow specification rule, if If the part of the action type of the flow specification rule corresponding to the set flag bit is not in the currently compared flow specification rule, the currently compared flow specification rule does not match.
  • the value of the Action Matching field is 0, that is, no flag bit is set, indicating that the action type set of the flow specification rule to be matched is empty, and the matching result of the action type is matched by default.
  • the action type definition of the flow specification rule represented by the bit of the Action Matching is as shown in Table 2. The definition is changed according to the standard change of the type of the flow specification rule action. Table 2 is the action type of the commonly used flow specification rule:
  • Table 2 shows that when the action matching bit 0 is set, the action type of the flow specification rule to be matched is traffic-rate.
  • the action type of the canonical rule is traffic-action.
  • the action type of the flow specification rule to be matched is redirect.
  • the bit 3 of the Action Matching is set. , indicating that the action type of the flow specification rule to be matched is traffic-marking.
  • the flow specification rule ORF record may further include more or less fields.
  • the flow specification rule ORF record may have no Filter Number field, and the SAFI value is 134 (representing the VPN flow)
  • the ORF record also includes: the number of the route identifier (RD number: Route Distinguisher, RD for short) field and the route identifier field, the RD number field is used to carry the number of RDs, and the RD field is used for the rule ORF record. Carrying a route identifier, the RD field can carry multiple RDs.
  • the value of SAFI is other, the RD number field and the RD field are not included in the flow specification rule ORF record.
  • the order of the fields of the flow specification rule ORF record can be adjusted, and only one possible format is shown in FIG. 2, and the length of each field is not limited in this embodiment.
  • the filter type field is used to carry the filter type.
  • the Filter Type of the flow specification rule ORF record is consistent with the definition of the Filter Type of the existing flow specification rule, and most of the flow specification rules ORF record and flow specification
  • the filter-specific actions and the format definition of the values are also consistent. Only a few flow specification rules ORF record Filter Type filter specific operation and value format definition (specifically the filter corresponding to the four Filter Types in Table 3) and filter specification rules filter specific operations and take The format definition of the value is different.
  • the four Filter Types in Table 3 are all Filter Types of the prefix type.
  • Type 1 is used to match the destination IP address prefix of the flow specification rule.
  • the destination IP address can be of IPv4 or IPv6 type (for example, the flow specification rule ORF record corresponds to AFI).
  • the filter type is the IPv4 destination address prefix filter.
  • Type 2 is used to match the source IP address prefix of the flow specification rule.
  • the source IP address can be IPv4 or IPv6, and Type 14 is used for the flow specification rule.
  • the destination MAC prefix is matched, and Type 15 is used to match the source MAC prefix of the flow specification rule.
  • FIG. 3 is a format of a Filter corresponding to the four Filter Types provided by the embodiment.
  • the format of the Filter includes the following fields: a Filter Type field and a matching prefix.
  • Maximum length (MaxLen) minimum length of matching prefix (MinLen), actual length of matching prefix, and matching prefix (Prefix)
  • the definitions of the MaxLen, MinLen, Length, and Prefix fields are consistent with the definitions of the same fields in RFC5292, and are not described in detail here.
  • MaxLen is not greater than 32.
  • MaxLen is not greater than 128.
  • the filter-specific rules and value fields of the flow specification rule ORF record are the collection of MaxLen, MinLen, Length, and Prefix fields.
  • the filter-specific operation and value field of the flow specification rule are Length. , a collection of Prefix fields.
  • the Filter Type can also include:
  • Type3 IP protocol, used to match the protocol type of the flow specification rule message.
  • Type 4 Port used to match the source port and destination port of the flow specification packet.
  • Type 5 Destination port, used to match the destination port of the flow specification rule packet.
  • Type6 Source port, used to match the source port of the flow specification rule packet.
  • Type7 ICMP type, used to match the ICMP type field of the flow specification rule packet.
  • Type 8 ICMP code, used to match the ICMP code field of the flow specification rule message.
  • Type 9 TCP Flags, used to match the TCP Flags field of the flow specification rule message.
  • Type 10 Packet length, used to match the total length of the flow specification rule message.
  • Type11 DSCP is used to match the DSCP field of the flow specification rule packet.
  • Type12 Fragment, used to match the mask bit format of the flow specification rule message.
  • the corresponding filter-specific operations and value fields of the flow specification rule ORF record and the flow specification rule are at least one of the option field and the value corresponding to the option field.
  • the flow specification rule ORF record can be used to indicate the specific capability or some security policy of the second network device to support the flow specification rule.
  • a conventional router and a three-layer (L3) switch implement a forwarding information table FIB in a hardware manner, for example, a Ternary Content Addressable Memory (TCAM) or an application specific integrated circuit (Application Specific Integrated). Circuits (referred to as ASICs) implement FIB. Generally, they can support IPv4/IPv6 Access Control List (ACL) and Layer 2 (L2) ACLs.
  • ACL IPv4/IPv6 Access Control List
  • L2 Layer 2
  • the forwarding planes of such network devices generally do not support ICMP Types and Codes. Match of fields.
  • the matching tuples of the virtual router (vRouter) or some new forwarding devices that support the flow specification rules are more comprehensive. Therefore, even if different network devices have the flow specification rule function enabled, their support
  • the flow specification rules Filter and Action Type may also differ.
  • the network device can generate a flow specification rule ORF record to express the specific capability difference of the network device supporting the flow specification rule, and advertise it to its own BGP peer to avoid receiving the BGP peer from the BGP peer. Flow specification rules that are not fully supported.
  • the two stream specification rule ORF entries generated by the second network device will be rejected (Deny) containing any matching ICMP Code or Type field values.
  • the flow specification rules for the filter After generating the flow specification rule ORF record, the second network device sends the flow specification rule ORF record to the first network device, where the flow specification rule ORF record is used by the first network device to perform flow specification rules sent to the second network device. filter.
  • the second network device sends the flow specification rule ORF record in a BGP Route Refresh (ROUTE-REFRESH) message to the first network device.
  • ROUTE-REFRESH BGP Route Refresh
  • FIG. 4 is an example of a packet content carrying an IPv4 flow specification rule ORF record A that rejects any filter matching the ICMP Type value
  • FIG. 5 is an IPv4 flow specification rule ORF carrying a filter that rejects any matching ICMP Code value.
  • the fields of the packet of the flow specification rule ORF record A are: 2-bit Action field, 1-bit Match field, 32-bit Sequence field, 8-bit Filter Number field, 32-bit Action Matching Field, 8-bit Filter Type field, 8-bit first option field (op1), 8-bit first value field (value1), 8-bit second option field (op2) and 8-bit second ratio Value field (value2).
  • the Action field of the Action field has the value of Add, the corresponding enumeration value is 0; the value of the Match field is Deny, the enumeration value of Deny is 1, and the value of the Sequence field is 1; the Filter Number field The value of 1 indicates that there is only one Filter in the ORF record of the flow specification rule; the value of the Action Matching field is 0, indicating that the action type of any flow specification rule does not match.
  • the value of the Filter Type field is ICMP Type, ICMP Type.
  • the corresponding enumeration value can be 7, the value of op1 is 0x03, the value of value1 is 0x00, indicating that the value of ICMP Type is greater than or equal to 0, the value of op2 is 0xc5, and the value of value2 is 0xff, indicating ICMP Type.
  • the value of the filter-specific operation and value field of the "ICMP Type" type filter included in the flow specification rule ORF record is 0 to 255.
  • the format of the "ICMP Code" type filter included in the ORF record B of the Pv4 stream specification rule in FIG. 5 is the same as the format definition of the "ICMP Type" type filter included in the ORF record A of FIG. 4, and will not be described here. -
  • the first network device receives the flow specification rule ORF record sent by the second network device.
  • the first network device may further determine the type of the flow specification rule ORF record according to the AFI and SAFI included in the flow specification rule ORF record, and store the flow specification rule ORF record in an orderly manner according to the sequence number of the flow specification rule ORF record.
  • Step 103 The first network device records, according to the flow specification rule ORF, a flow specification rule to be sent to the second network device.
  • the first network device When the first network device sends the flow specification rule to the second network device, the first network device queries the flow specification rule ORF record sent by the second network device, and performs matching filtering processing on the flow specification rule to be sent to the second network device. .
  • Different types of flow specification rules ORF records are stored in different flow specification rule ORF lists.
  • the first network device Before matching, the first network device first determines to be sent to the second according to the AFI and SAFI of the flow specification rules to be sent to the second network device.
  • the type of the flow specification rule of the network device query the corresponding type flow specification rule ORF list, and then use the flow specification rule ORF record in the flow specification rule ORF list to match the flow specification rule to be sent to the second network device, and match first.
  • the flow specification rules ORF records take effect.
  • the action indicated by the matching field recorded by the matched ORF specification rule ORF (allow or deny) determines whether to send the flow specification rule to be sent to the second network device to the second network device. If the action indicated by the matching field is allowed, the first network device sends the flow specification rule to be sent to the second network device to the second network device, and if the action indicated by the matching field is rejected, the first network device is to be sent.
  • the flow specification rules for the second network device are filtered out and are not sent to the second network device.
  • the to-be-sent flow specification rule that the first network device sends to the second network device may be sent by the other network device to the first network device, or may be generated by the first network device according to the configuration.
  • the first network device When matching each flow specification rule ORF record, the first network device records the flow specification rule ORF record: an Action Matching field, a Filter Type field, a filter specific operation, and a value field, respectively, to be sent to the second
  • the flow specification rules of the network device include: an Action Type field, a Filter Type field, a filter specific operation, and a value field for comparison.
  • the flow specification rule ORF record includes an Action Matching field indicating that the set of action types to match is empty (ie, the value of the Action Matching field is 0) or the flow specification rule ORF record includes The action type indicated by the Action Matching field to be matched is included in the action type included in the flow specification rule to be sent to the second network device, and the flow specification rule ORF record includes the filter set as empty or the flow specification rule ORF record includes The value space of the filter-specific operation and value field for each filter type contains the value space of the filter-specific operation and value field of the filter type to be sent to the flow specification rule of the second network device. The first network device determines that the flow specification rule to be sent to the second network device matches the flow specification rule ORF record.
  • the first network device filters the flow specification rule to be sent according to the flow specification rule ORF, specifically: the first network device includes the flow specification rule ORF record.
  • the Action Matching field, the Filter Type field, the filter specific operation and the value field, and the RD field are respectively included in the flow specification rule to be sent to the second network device: an Action Type field, a Filter Type field, a filter specific operation, and The value field and the RD field are compared.
  • the action type specified by the Action Matching field included in the flow specification rule ORF record is set to be empty or the flow specification rule ORF record includes the action type indicated by the Action Matching field to be matched, the action type to be matched is included in the second network to be sent.
  • the flow specification rule ORF record includes a filter set that is empty or the flow specification rule ORF records contain filter-specific operations and the value space of each value field contains
  • the flow specification rule of the filter type to be sent to the second network device includes a filter-specific operation and a value space of the value field
  • the flow specification rule ORF record includes a set of route identifiers consisting of RDs or is in the route identifier set. And including the RD included in the flow specification rule to be sent to the second network device, the first network device determines that the flow specification rule to be sent to the second network device matches the flow specification rule ORF record.
  • Step 104 The first network device sends the filtered flow specification rule to the second network device.
  • the first network device may send the filtered flow specification rule to the second network device in the BGP update (UPDATE) message.
  • the first network device may also carry the filtered flow specification rule in other messages.
  • the method is sent to the second network device, which is not limited in this embodiment.
  • the first network device receives the flow specification rule ORF record sent by the second network device, and the flow specification rule ORF Recording a flow specification rule for the first network device to send to the second network device, when the first network device has a flow specification rule sent to the second network device, the first network device records the ORF according to the flow specification rule Flow specification rules Filtering, only the flow specification rule that satisfies the flow specification rule ORF record filtering condition is sent to the second network device, which solves the problem that the network device sends a large number of invalid flow specification rules, resulting in waste of resources.
  • FIG. 6 is a flowchart of a method for receiving a flow specification rule according to Embodiment 2 of the present invention. This embodiment is described from the perspective of a second network device. As shown in FIG. 6, the method provided in this embodiment may include the following steps:
  • Step 201 The second network device determines that the first network device is capable of receiving the flow specification rule ORF record.
  • the second network device obtains a second flow specification rule ORF capability parameter, where the second flow specification rule ORF capability parameter indicates a flow specification rule ORF capability supported by the first network device, and the second flow specification
  • the rule ORF capability parameter includes: at least one set of parameters consisting of AFI, SAFI, flow specification rule ORF type, and transceiver capability identifier, and the transceiver capability identifier included in the second flow specification rule ORF capability parameter is used to indicate the first network device. Whether to support sending and/or receiving flow specification rules ORF records.
  • the second network device obtains the second flow specification rule ORF capability parameter, where the second network device receives the BGP OPEN message sent by the first network device in the process of establishing a BGP connection with the first network device, where the first network
  • the BGP OPEN message sent by the device includes the second flow specification rule ORF capability parameter.
  • the second network device compares the second flow specification rule ORF capability parameter with the first flow specification rule ORF capability parameter, the first flow specification rule ORF capability parameter indicates a flow specification rule ORF capability supported by the second network device, and the first flow specification rule ORF
  • the capability parameter includes: a set of parameters consisting of the AFI, the SAFI, the flow specification rule ORF type, and the transceiver capability identifier, where the transceiver capability identifier included in the first flow specification rule ORF capability parameter is used to indicate whether the second network device supports sending And/or receive flow specification rules ORF records.
  • the first parameter set included in the first flow specification rule ORF capability parameter and the second parameter set included in the second flow specification rule ORF capability parameter both contain a flow specification rule ORF type
  • the first parameter set and the second parameter set include the same AFI and SAFI
  • the transceiver capability identifier of the first parameter set indicates that the second network device supports the transmission flow specification rule ORF record
  • the transceiver capability identifier of the second parameter set indicates that the first network device supports the receive flow specification rule ORF record
  • Step 202 The second network device generates a flow specification rule ORF record according to its own flow specification rule policy.
  • the flow specification rule ORF record includes: Action field, Match field, Reserved a field and a Type specific part field, where the Type specific part field includes: a Sequence field of the flow specification rule ORF record, an Action Matching field, a Filter Type field, a filter specific operation and a value field, and a Sequence field is used to carry the flow specification rule ORF The priority of the record.
  • the Action Matching field is used to carry the Action Type that matches the flow specification rule.
  • the Filter Type field is used to carry the Filter Type.
  • the filter specific operation and the value field are used to carry the filter condition corresponding to the Filter Type.
  • the Type specific part field may further include a Filter Number field, where the Filter Number field is used to carry the number of filters.
  • the Type specific part field further includes: an RD Number field and an RD field.
  • Step 203 The second network device sends the flow specification rule ORF record to the first network device.
  • the second network device transmits the flow specification rule ORF record to the first network device, so that the first network device records the flow specification rule to be sent to the second network device according to the flow specification rule ORF.
  • Step 204 The second network device receives a flow specification rule sent by the first network device, where the flow specification rule is that the first network device records the filtered flow specification rule according to the flow specification rule ORF.
  • the flow specification rule ORF record is generated according to the flow specification rule policy, and the flow specification rule ORF record is sent to the first a network device
  • the first network device records, according to the flow specification rule ORF sent by the second network device, the flow specification rule to be sent to the second network device, and only sends the flow specification that meets the flow specification rule filtering condition to the second network device.
  • the rule solves the problem of waste of resources caused by the network device sending a large number of invalid flow specification rules.
  • FIG. 7 is a schematic structural diagram of a first network device according to Embodiment 3 of the present invention.
  • the network device provided in this embodiment includes: a determining module 11, a receiving module 12, a filtering module 13, and a sending module 14.
  • the determining module 11 is configured to determine that the second network device can send the flow specification rule ORF record to the first network device.
  • the receiving module 12 is configured to receive the flow specification rule ORF record sent by the second network device, where the flow specification rule ORF records a flow specification used by the first network device to be sent to the second network device Rules are filtered;
  • a filtering module 13 configured to send, according to the flow specification rule, an ORF record to the second network Filtering the flow specification rules of the network device;
  • the sending module 14 is configured to send the filtered flow specification rule to the second network device.
  • the flow specification rule ORF record includes: a sequence number field of the flow specification rule ORF record, an action matching field, a filter type field, and a filter specific operation and value field, and the sequence number field of the flow specification rule ORF record is used for Carrying a priority of the flow specification rule ORF record, the action matching field is used to carry an action type that matches whether the flow specification rule is used, and the filter type field is used to carry a filter type, the filter specific operation and the value field It is used to carry the filter condition corresponding to the filter type.
  • the flow specification rule ORF record further includes: a filter number field, where the filter number field is used to carry the number of filters.
  • the filtering module 13 is specifically configured to: include, by the flow specification rule ORF record, an action matching field, a filter type field, a filter specific operation, and a value field, respectively, and the flow specification rule to be sent : an action type field, a filter type field, a filter specific operation, and a value field are compared; if the action specification field included in the flow specification rule ORF record indicates that the set of action types to be matched is empty or the match is to be matched The action types are all included in the action type included in the flow specification rule to be sent to the second network device, the flow specification rule ORF record includes a filter set that is empty or a filter of each filter type The value space of the specific operation and the value field includes the value space of the filter-specific operation and the value field of the filter type to be sent to the flow specification rule of the second network device, and then the to-be-sent is determined.
  • a flow specification rule for the second network device matches the flow specification rule ORF record.
  • the flow specification rule ORF record further includes: a route identifier number field and a route identifier field, where the route identifier number field is used to carry the number of route identifiers, and the route identifier field is used to carry the route identifier .
  • the filtering module 13 is specifically configured to: include the flow specification rule ORF record: an action matching field, a filter type field, and filtering
  • the specific operation and value field and the route identification field are respectively included in the flow specification rule to be sent to the second network device: an action type field, a filter type field, a filter specific operation, and a value field.
  • the route identifier field is compared; if the action type set to be matched by the action matching field included in the flow specification rule ORF record is empty or the action type to be matched is included in the second to be sent to the second
  • the filter specification included in the flow specification rule ORF record is empty or the value space of the filter specific operation and the value field of each filter type includes the to-be-sent
  • the flow specification rule sent to the second network device includes a filter-specific filter operation-specific value and a value space of the value field
  • the flow specification rule ORF record includes a route identifier set consisting of a route identifier set to be empty or
  • the routing identifier set includes the routing identifier included in the flow specification rule to be sent to the second network device, and determining that the flow specification rule to be sent to the second network device matches the flow specification rule ORF record.
  • the determining module 11 is specifically configured to:
  • the first flow specification rule ORF capability parameter is obtained, where the first flow specification rule ORF capability parameter indicates a flow specification rule ORF capability supported by the second network device, and the first flow specification rule ORF capability parameter includes: at least one group consisting of The parameter set consisting of the address family identifier, the sub-address family identifier, the flow specification rule ORF type, and the transceiver capability identifier, and the transceiver capability identifier included in the first-flow specification rule ORF capability parameter is used to indicate whether the second network device supports sending And/or receive flow specification rules ORF records.
  • the first flow specification rule ORF capability parameter and the second flow specification rule ORF capability parameter indicating a flow specification rule ORF capability supported by the first network device
  • the second-flow specification rule ORF capability parameter includes: at least one set of parameters consisting of an address family identifier, a sub-address family identifier, a flow specification rule ORF type, and a transceiving capability identifier
  • the second stream specification rule ORF capability parameter includes The capability identifier is used to indicate whether the first network device supports sending and/or receiving a flow specification rule ORF record.
  • the first parameter set included in the first flow specification rule ORF capability parameter and the second parameter set included in the second flow specification rule ORF capability parameter include a flow specification rule ORF type
  • the first parameter set and the The second parameter set includes the same address family identifier and the sub-address family identifier, and the transceiver capability identifier of the first parameter set indicates that the second network device supports the sending flow specification rule ORF record, and the second parameter set is capable of transmitting and receiving.
  • the identifier indicates that the first network device supports receiving the flow specification rule ORF record, and determining that the second network device is capable of sending a flow specification rule ORF record to the first network device.
  • the determining module 11 obtains the first flow specification rule ORF capability parameter, specifically: receiving the BGP open message sent by the second network device during the process of establishing a BGP connection between the first network device and the second network device,
  • the BGP open message sent by the second network device includes the first flow specification rule ORF capability parameter.
  • the receiving module 12 is specifically configured to: receive a BGP route refresh message sent by the second network device, where the BGP route refresh message includes the flow specification rule ORF record.
  • the first network device further includes a storage processing module.
  • the storage processing module is configured to determine, after the receiving module 12 receives the flow specification rule ORF record sent by the second network device, according to the address family identifier and the sub-address family identifier included in the flow specification rule ORF record.
  • the flow specification rules the type of the ORF record, and stores the flow specification rule ORF record in an orderly manner according to the sequence number of the flow specification rule ORF record into the flow specification rule ORF list of the corresponding type.
  • the first network device provided in this embodiment may be used to perform the method in the first embodiment.
  • the specific implementation manners and technical effects are similar, and details are not described herein again.
  • FIG. 8 is a schematic structural diagram of a second network device according to Embodiment 4 of the present invention.
  • the second network device provided in this embodiment includes: a determining module 21, a generating module 22, a sending module 23, and a receiving module 24. .
  • the determining module 21 is configured to determine that the first network device is capable of receiving the flow specification rule ORF record;
  • the generating module 22 is configured to generate a flow specification rule ORF record according to the flow specification rule policy saved by the second network device;
  • the sending module 23 is configured to send the flow specification rule ORF record generated by the generating module 22 to the first network device;
  • the receiving module 24 is configured to receive a flow specification rule sent by the first network device, where the flow specification rule is that the first network device records the filtered flow specification rule according to the flow specification rule ORF.
  • the flow specification rule ORF record includes: a sequence number field of the flow specification rule ORF record, an action matching field, a filter type field, a filter specific operation, and a value field, and the flow specification rule ORF records
  • the sequence number field is used to carry the priority of the flow specification rule ORF record
  • the action matching field is used to carry an action type that matches whether the flow specification rule is used
  • the filter type field is used to carry a filter type, the filter specific
  • the operation and value fields are used to carry the filter conditions corresponding to the filter type.
  • the flow specification rule ORF record further includes: a filter number field, where the filter number field is used to carry the number of filters.
  • the flow specification rule ORF record further includes: a route identifier number field and a route identifier field, where the route identifier number field is used to carry the number of route identifiers, and the route identifier field is used to carry the route identifier .
  • the determining module 21 is specifically configured to:
  • the second stream specification rule ORF capability parameter is obtained, and the second stream specification rule ORF can
  • the force parameter indicates a flow specification rule ORF capability supported by the first network device
  • the second flow specification rule ORF capability parameter includes: at least one group consists of an address family identifier, a sub-address family identifier, a flow specification rule ORF type, and a transceiving capability. And identifying, by the set of parameters, the transceiver capability identifier included in the second stream specification rule ORF capability parameter is used to indicate whether the first network device supports sending and/or receiving a flow specification rule ORF record.
  • the first flow specification rule ORF capability parameter indicating a flow specification rule ORF capability supported by the second network device
  • the first flow The specification rule ORF capability parameter includes: at least one set of parameters consisting of an address family identifier, a sub-address family identifier, a flow specification rule ORF type, and a transceiving capability identifier
  • the first-flow specification rule ORF capability parameter includes a transceiving capability identifier. And indicating whether the second network device supports sending and/or receiving a flow specification rule ORF record.
  • the first parameter set included in the first flow specification rule ORF capability parameter and the second parameter set included in the second flow specification rule ORF capability parameter include a flow specification rule ORF type
  • the first parameter set and the The second parameter set includes the same address family identifier and the sub-address family identifier
  • the transceiver capability identifier of the first parameter set indicates that the second network device supports sending, the flow specification rule ORF records, and the second parameter set of the transceiver capability identifier Instructing the first network device to support receiving a flow specification rule ORF record, determining that the second network device is capable of transmitting a flow specification rule ORF record to the first network device.
  • the determining module 21 obtains the second flow specification rule ORF capability parameter, specifically: receiving the BGP openness sent by the first network device in the process of establishing a BGP connection between the second network device and the first network device
  • the BGP open message sent by the first network device includes the second flow specification rule ORF capability parameter.
  • the sending module 23 is specifically configured to: send a BGP route refresh message to the first network device, where the BGP route refresh message includes the flow specification rule ORF record.
  • the second network device provided in this embodiment may be used to perform the method in the second embodiment.
  • the specific implementation manners and technical effects are similar, and details are not described herein again.
  • FIG. 9 is a schematic structural diagram of a first network device according to Embodiment 5 of the present invention.
  • the first network device 300 of this embodiment includes: a processor 31, a memory 32, a communication interface 33, and a communication bus 34.
  • Memory 32 and communication interface 33 are coupled and in communication with processor 31 via communication bus 34 for storing computer instructions, communication interface 33 for communicating with other network devices, and processor 31 for executing computer instructions stored by memory 32.
  • the flow specification rule ORF record includes: a sequence number field of the flow specification rule ORF record, an action matching field, a filter type field, and a filter specific operation and value field, and the sequence number field of the flow specification rule ORF record a priority for carrying a flow specification rule ORF record, the action matching field is configured to carry an action type that matches a flow specification rule, the filter type field is used to carry a filter type, and the filter specific operation and fetch The value field is used to carry the filter condition corresponding to the filter type.
  • the flow specification rule ORF record further includes: a filter number field, where the filter number field is used to carry the number of filters.
  • the flow specification rule ORF record further includes: a route identifier number field and a route identifier field, where the route identifier number field is used to carry the number of route identifiers, and the route identifier field is used to carry the route identifier .
  • a flow specification rule to be sent specifically:
  • the flow specification rule ORF record includes: an action matching field, a filter type field, a filter specific operation, and a value field, respectively, and the flow specification rule to be sent includes: an action type field, a filter type field , filter specific operations and value fields are compared. If the action type set to be matched by the action matching field included in the flow specification rule ORF record is empty or the action type to be matched is included in the flow specification rule to be sent to the second network device In the action type included, the filter specification ORF record includes a filter set of each filter type that is empty or the value space of the filter specific operation and the value field includes the to-be-sent to the second network.
  • the flow specification rule of the device includes a filter-specific operation and a value space of the value field, and then determining that the flow specification rule to be sent to the second network device matches the flow specification rule ORF record.
  • the flow specification rule ORF record includes: action matching field, filter type The field, the filter specific operation and the value field, and the route identifier field are respectively performed with the flow specification rule to be sent: an action type field, a filter type field, a filter specific operation, a value field, and a route identifier field. Comparison.
  • the flow specification rule ORF record includes a filter set that is empty or a filter-specific operation of each filter type and a value space of the value field contain the to-be-sent to the second network
  • the flow specification rule of the device includes a filter-specific operation of the filter type and a numerical space of the value field
  • the flow specification rule ORF record includes a route identifier set consisting of a route identifier or the route identifier set includes the And determining, by the flow specification rule included in the flow specification rule of the second network device, the flow specification rule to be sent to the second network device to match the flow specification rule ORF record.
  • the determining, by the second network device, the flow specification rule ORF record to the first network device includes: acquiring a first flow specification rule ORF capability parameter, where the first flow specification rule ORF capability parameter indicates that the second network device supports The flow specification standard ORF capability, the first flow specification rule ORF capability parameter includes: at least one set of parameters consisting of an address family identifier, a sub-address family identifier, a flow specification rule ORF type, and a transceiving capability identifier, the first flow specification The transceiving capability identifier included in the regular ORF capability parameter is used to indicate whether the second network device supports sending and/or receiving a flow specification rule ORF record.
  • the specification rule ORF capability parameter includes: at least one set of parameters consisting of an address family identifier, a sub-address family identifier, a flow specification rule ORF type, and a transceiving capability identifier, and the transceiving capability identifier included in the second stream specification rule ORF capability parameter And used to indicate whether the first network device supports sending and/or receiving a flow specification rule ORF record.
  • the first parameter set included in the first flow specification rule ORF capability parameter and the second parameter set included in the second flow specification rule ORF capability parameter include a flow specification rule ORF type
  • the first parameter set and the The second parameter set includes the same address family identifier and the sub-address family identifier, and the transceiver capability identifier of the first parameter set indicates that the second network device supports the sending flow specification rule ORF record, and the second parameter set is capable of transmitting and receiving.
  • the identifier indicates that the first network device supports receiving the flow specification rule ORF record, and determining that the second network device is capable of sending a flow specification rule ORF record to the first network device.
  • Obtaining the first flow specification rule ORF capability parameter including: at the first network device And receiving, by the second network device, a BGP open message sent by the second network device, where the BGP open message sent by the second network device includes the first flow norm rule ORF capability parameter.
  • receiving the flow specification rule ORF record sent by the second network device including: receiving a BGP route refresh message sent by the second network device, where the BGP route refresh message includes the flow specification rule ORF record.
  • the processor 31 After receiving the flow specification rule ORF record sent by the second network device, the processor 31 is further configured to: determine, according to the address family identifier and the sub-address family identifier included in the flow specification rule ORF record, the flow specification rule ORF The type of the record, and the stream specification rule ORF record is stored in an orderly manner in the stream specification rule ORF list of the corresponding type according to the sequence number of the flow specification rule ORF record.
  • the first network device provided in this embodiment may be used to perform the method in the first embodiment.
  • the specific implementation manners and technical effects are similar, and details are not described herein again.
  • the second network device 400 of this embodiment includes: a processor 41, a memory 42, a communication interface 43, and a communication bus 44.
  • Memory 42 and communication interface 43 are coupled and in communication with processor 41 via communication bus 44 for storing computer instructions, communication interface 43 for communicating with other network devices, and processor 41 for executing computer instructions stored by memory 42.
  • the flow specification rule ORF record includes: a sequence number field of the flow specification rule ORF record, an action matching field, a filter number field, a filter type field, a filter specific operation, and a value field, and the flow specification rule
  • the sequence number field of the ORF record is used to carry the priority of the flow specification rule ORF record
  • the action matching field is used to carry an action type that matches the flow specification rule
  • the filter type field is used to carry a filter type
  • a filter specific operation and value field is used to carry the filter condition corresponding to the filter type.
  • the flow specification rule ORF record further includes: a filter number field, where the filter number field is used to carry the number of filters.
  • the flow specification rule ORF record further includes: a route identifier number field and a route identifier field, where the route identifier number field is used to carry the number of route identifiers, and the route identifier field is used to carry the route identifier .
  • Determining that the first network device is capable of receiving the flow specification rule ORF record including:
  • the second flow specification rule ORF capability parameter is obtained, where the second flow specification rule ORF capability parameter indicates a flow specification rule ORF capability supported by the first network device, and the second flow specification rule ORF capability parameter includes: at least A set of parameters consisting of an address family identifier and a sub-address family identifier, a flow specification rule ORF type, and a transceiving capability identifier, where the transceiving capability identifier included in the second-flow specification rule ORF capability parameter is used to indicate the first network device Whether to support sending and/or receiving flow specification rules ORF records.
  • the first flow specification rule ORF capability parameter includes: at least one set of parameters consisting of an address family identifier and a sub-address family identifier, a flow specification rule ORF type, and a transceiving capability identifier, where the transceiving capability identifier included in the first-flow specification rule ORF capability parameter is used for Indicates whether the second network device supports transmitting and/or receiving a flow specification rule ORF record.
  • the first parameter set included in the first flow specification rule ORF capability parameter and the second parameter set included in the second flow specification rule ORF capability parameter include a flow specification rule ORF type
  • the first parameter set and the The second parameter set includes the same address family identifier and the sub-address family identifier, and the transceiver capability identifier of the first parameter set indicates that the second network device supports the sending flow specification rule ORF record, and the second parameter set is capable of transmitting and receiving.
  • the identifier indicates that the first network device supports receiving the flow specification rule ORF record, and determining that the second network device is capable of sending a flow specification rule ORF record to the first network device.
  • the obtaining the second flow specification rule ORF capability parameter includes: receiving, in the process of establishing a BGP connection between the second network device and the first network device, receiving a BGP open message sent by the first network device, The BGP open message sent by the first network device includes the second flow specification rule ORF capability parameter.
  • the sending the flow specification rule ORF record to the first network device includes: sending a BGP route refresh message to the first network device, where the BGP route refresh message includes the flow specification rule ORF record.
  • the second network device provided in this embodiment may be used to implement the method in Embodiment 2, and the specific implementation is implemented. The method and technical effect are similar and will not be described here.
  • FIG. 11 is a schematic structural diagram of a network system according to Embodiment 7 of the present invention.
  • the network system of this embodiment includes: a first network device 51 and a second network device 52, where the first network device The method can be used to perform the method of the first embodiment, and the second network device 52 can be used to perform the method of the second embodiment.
  • the specific implementation and the technical effects are similar. Please refer to the descriptions of the first embodiment and the second embodiment, and details are not described herein again.
  • the aforementioned program can be stored in a computer readable storage medium.
  • the program when executed, performs the steps including the foregoing method embodiments; and the foregoing storage medium includes various media that can store program codes, such as a ROM, a RAM, a magnetic disk, or an optical disk.

Abstract

Provided in embodiments of the present invention are a method and device for sending and receiving the flow specification rule. A first network device receives a flow specification rule ORF record sent from a second network device after determining that the second network device has the ability of sending the flow specification rule ORF record to the first network device, the flow specification rule ORF record being used for the first network device to filter the flow specification rule to be sent to the second network device. When the flow specification rule is available to be sent to the second network device by the first network device, the first network device filters the flow specification rule to be sent to the second network device according to the flow specification rule ORF record in order to send only the flow specification rule satisfied the flow specification rule ORF record filtering condition to the second network device, thereby solving the problem of resources waste caused by the network device of sending numerous invalid flow specification rules.

Description

发送、接收流规范规则的方法和装置Method and device for transmitting and receiving flow specification rules
本申请要求于2015年3月23日提交中国专利局、申请号为CN 201510127833.9、发明名称为“发送、接收流规范规则的方法和装置”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。This application claims the priority of the Chinese Patent Application filed on March 23, 2015, the Chinese Patent Application No. CN 201510127833.9, entitled "Method and Apparatus for Sending and Receiving Flow Specification Rules", the entire contents of which are incorporated by reference. In this application.
技术领域Technical field
本发明实施例涉及通信技术,尤其涉及一种发送、接收流规范规则(Flow Specification rule)的方法和装置。The embodiments of the present invention relate to communication technologies, and in particular, to a method and an apparatus for transmitting and receiving a flow specification rule.
背景技术Background technique
基于边界网关协议(Border Gateway Protocol,简称BGP)协议广泛应用在Internet中,用于在自治域(Autonomous System,简称AS)之间和AS内边缘路由器间传递路由信息。传递的路由信息包括:网络协议(Internet Protocol,简称IP)路由、媒体接入控制(Media Access Control,简称MAC)路由和流规范规则等网络侧可达信息(Network Layer Reachability Information,简称NLRI)信息。其中,流规范规则主要用于网络安全防御,将AS内检测到的攻击或疑似攻击流量信息和应对策略(限速、染色、重定向等)散播到AS网络边缘路由器,甚至跨域散播,以便尽早对攻击流量进行处理。The Border Gateway Protocol (BGP) protocol is widely used on the Internet to transfer routing information between Autonomous Systems (ASs) and ASs. The routing information that is transmitted includes: Network Protocol Reachability Information (NLRI) information such as Internet Protocol (IP) routing, Media Access Control (MAC) routing, and flow specification rules. . The flow specification rule is mainly used for network security defense, and the attack information or the suspected attack traffic information and the coping strategy (speed limit, dyeing, redirection, etc.) detected in the AS are distributed to the AS network edge router, and even spread across the domain, so that Attack traffic as early as possible.
对于某个路由器而言,收到的流规范规则中可能存在大量无效流规范规则。现有技术中,为了避免无效流规范规则对正常通信的影响,接收端通过在本地对发送端发送来的流规范规则进行过滤,过滤掉无效流规范规则。但是,现有技术的方法中,发送端还是要发送大量的无效流规范规则,发送大量的无效流规范规则会占用的网络带宽和中央处理单元(Central Processing Unit,简称CPU)的计算资源,造成网络资源和计算资源的浪费。For a router, there may be a large number of invalid flow specification rules in the received flow specification rules. In the prior art, in order to avoid the impact of the invalid flow specification rule on normal communication, the receiving end filters the flow specification rule sent by the sending end locally, and filters out the invalid flow specification rule. However, in the prior art method, the transmitting end still needs to send a large number of invalid flow specification rules, and the network bandwidth occupied by a large number of invalid flow specification rules and the central processing unit (CPU) computing resources are generated. Waste of network resources and computing resources.
发明内容Summary of the invention
本发明实施例提供一种发送、接收流规范规则的方法和装置,能够支持对流规范规则进行出站路由过滤,减少了无效流规范规则的传输。Embodiments of the present invention provide a method and apparatus for transmitting and receiving a flow specification rule, which can support outbound route filtering for a flow specification rule, and reduce transmission of an invalid flow specification rule.
本发明第一方面提供一种发送流规范规则的方法,包括:A first aspect of the present invention provides a method for transmitting a flow specification rule, including:
第一网络设备确定第二网络设备能够向所述第一网络设备发送流规范规则出站路由过滤ORF记录;Determining, by the first network device, the second network device to send a flow specification rule outbound route filtering ORF record to the first network device;
所述第一网络设备接收所述第二网络设备发送的所述流规范规则ORF记录,所述流规范规则ORF记录用于所述第一网络设备对待发送给所述第二网络设备的流规范规则进行过滤;Receiving, by the first network device, the flow specification rule ORF record sent by the second network device, where the flow specification rule ORF records a flow specification used by the first network device to be sent to the second network device Rules are filtered;
所述第一网络设备根据所述流规范规则ORF记录对待发送给所述第二网络设备的流规范规则进行过滤;The first network device records, according to the flow specification rule ORF, a flow specification rule to be sent to the second network device;
所述第一网络设备向所述第二网络设备发送过滤后的流规范规则。The first network device sends the filtered flow specification rule to the second network device.
结合本发明第一方面,在本发明第一方面的第一种可能的实现方式中,所述流规范规则ORF记录包括:流规范规则ORF记录的序列号字段、行动匹配字段、滤器类型字段、过滤器特定操作和取值字段,所述流规范规则ORF记录的序列号字段用于携带流规范规则ORF记录的优先级,所述行动匹配字段用于携带是否匹配流规范规则的动作类型,所述过滤器类型字段用于携带过滤器类型,所述过滤器特定操作和取值字段用于携带所述过滤器类型对应的过滤条件。With reference to the first aspect of the present invention, in a first possible implementation manner of the first aspect of the present invention, the flow specification rule ORF record includes: a sequence number field of a flow specification rule ORF record, an action matching field, a filter type field, a filter specific operation and a value field, the sequence number field of the flow specification rule ORF record is used to carry a priority of the flow specification rule ORF record, and the action matching field is used to carry an action type that matches the flow specification rule. The filter type field is used to carry a filter type, and the filter specific operation and value field are used to carry a filter condition corresponding to the filter type.
结合本发明第一方面的第一种可能的实现方式,在本发明第一方面的第二种可能的实现方式中,所述流规范规则ORF记录还包括:路由标识个数字段和路由标识字段,所述路由标识个数字段用于携带路由标识的个数,所述路由标识字段用于携带路由标识。With reference to the first possible implementation manner of the first aspect of the present invention, in a second possible implementation manner of the first aspect of the present disclosure, the flow specification rule ORF record further includes: a route identifier number field and a route identifier field The route identifier number field is used to carry the number of route identifiers, and the route identifier field is used to carry the route identifier.
结合本发明第一方面的第一种或第二种可能的实现方式,在本发明第一方面的第三种可能的实现方式中,所述流规范规则ORF记录还包括:过滤器个数字段,所述过滤器个数字段用于携带过滤器的个数。With reference to the first or second possible implementation manner of the first aspect of the present invention, in a third possible implementation manner of the first aspect of the present disclosure, the flow specification rule ORF record further includes: a filter number field The filter number field is used to carry the number of filters.
结合本发明第一方面的第一种可能的实现方式,在本发明第一方面的第四种可能的实现方式中,所述第一网络设备根据所述流规范规则ORF记录对待发送给所述第二网络设备的流规范规则进行过滤,包括:With reference to the first possible implementation manner of the first aspect of the present invention, in a fourth possible implementation manner of the first aspect, the first network device records, according to the flow specification rule ORF, the The flow specification rules of the second network device are filtered, including:
所述第一网络设备将所述流规范规则ORF记录包括的:行动匹配字段、过滤器个数字段、过滤器类型字段、过滤器特定操作和取值字段,分别与所述待发送给所述第二网络设备的流规范规则包括的:动作类型字段、过滤器 类型字段、过滤器特定操作和取值字段进行比较;The first network device includes, by the flow specification rule ORF record, an action matching field, a filter number field, a filter type field, a filter specific operation, and a value field, respectively, and the to-be-sent to the The flow specification rule of the second network device includes: an action type field, a filter Type field, filter specific operation, and value field for comparison;
若所述流规范规则ORF记录包括的行动匹配字段所指示的要匹配的动作类型集合为空或所述要匹配的动作类型都包含在所述待发送给所述第二网络设备的流规范规则包括的动作类型中,所述流规范规则ORF记录包括的过滤器集合为空或每种过滤器类型的过滤器特定操作和取值字段的数值空间都包含所述待发送给所述第二网络设备的流规范规则包括的过滤器类型的过滤器特定操作和取值字段的数值空间,则所述第一网络设备确定所述待发送给所述第二网络设备的流规范规则匹配所述流规范规则ORF记录。If the action type set to be matched by the action matching field included in the flow specification rule ORF record is empty or the action type to be matched is included in the flow specification rule to be sent to the second network device In the action type included, the flow specification rule ORF record includes a filter set that is empty or a filter-specific operation of each filter type and a value space of the value field contain the to-be-sent to the second network The flow specification rule of the device includes a filter-specific operation of the filter type and a numerical space of the value field, and the first network device determines that the flow specification rule to be sent to the second network device matches the flow Specification rule ORF record.
结合本发明第一方面的第二种可能的实现方式,在本发明第一方面的第五种可能的实现方式中,所述第一网络设备根据所述流规范规则ORF记录对待发送给所述第二网络设备的流规范规则进行过滤,包括:With reference to the second possible implementation manner of the first aspect of the present invention, in a fifth possible implementation manner of the first aspect, the first network device records, according to the flow specification rule ORF, the The flow specification rules of the second network device are filtered, including:
所述第一网络设备将所述流规范规则ORF记录包括的:行动匹配字段、过滤器类型字段、过滤器特定操作和取值字段、路由标识字段,分别与所述待发送给所述第二网络设备的流规范规则包括的:动作类型字段、过滤器类型字段、过滤器特定操作和取值字段和路由标识字段进行比较;The first network device includes, by the flow specification rule ORF record, an action matching field, a filter type field, a filter specific operation and a value field, and a route identifier field, respectively, to be sent to the second The flow specification rule of the network device includes: an action type field, a filter type field, a filter specific operation and a value field, and a route identifier field for comparison;
若所述流规范规则ORF记录包括的行动匹配字段所指示的要匹配的动作类型集合为空或所述要匹配的动作类型都包含在所述待发送给所述第二网络设备的流规范规则包括的动作类型中,所述流规范规则ORF记录包括的过滤器集合为空或每种过滤器类型的过滤器特定操作和取值字段的数值空间都包含所述待发送给所述第二网络设备的流规范规则包括的对应过滤器类型的过滤器特定操作和取值字段的数值空间,所述流规范规则ORF记录包括的路由标识组成的路由标识集合为空或所述路由标识集合中包含所述待发送给所述第二网络设备的流规范规则包括的路由标识,则所述第一网络设备确定所述待发送的流规范规则匹配上所述流规范规则ORF记录。If the action type set to be matched by the action matching field included in the flow specification rule ORF record is empty or the action type to be matched is included in the flow specification rule to be sent to the second network device In the action type included, the flow specification rule ORF record includes a filter set that is empty or a filter-specific operation of each filter type and a value space of the value field contain the to-be-sent to the second network The flow specification rule of the device includes a filter-specific operation of the corresponding filter type and a numerical space of the value field, and the flow specification rule ORF record includes a route identifier set consisting of a route identifier that is empty or included in the route identifier set. And the first network device determines that the flow specification rule to be sent matches the flow specification rule ORF record, where the flow specification rule is to be sent to the second network device.
结合本发明第一方面以及本发明第一方面的第一种至第五种可能的实现方式中的任意一种,在本发明第一方面的第六种可能的实现方式中,所述第一网络设备确定第二网络设备能够向所述第一网络设备发送流规范规则ORF记录,包括:In conjunction with the first aspect of the present invention and any one of the first to fifth possible implementations of the first aspect of the present invention, in a sixth possible implementation of the first aspect of the present invention, the first The network device determines that the second network device is capable of transmitting the flow specification rule ORF record to the first network device, including:
所述第一网络设备获取第一流规范规则ORF能力参数,所述第一流规范规则ORF能力参数指示所述第二网络设备支持的流规范规则ORF能力,所述第一流规范规则ORF能力参数包括:至少一组由地址族标识、子地址族标识、 流规范规则ORF类型和收发能力标识组成的参数集合,所述第一流规范规则ORF能力参数中包括的收发能力标识用于指示所述第二网络设备是否支持发送和/或接收流规范规则ORF记录;The first network device obtains a first flow specification rule ORF capability parameter, where the first flow specification rule ORF capability parameter indicates a flow specification rule ORF capability supported by the second network device, where the first flow specification rule ORF capability parameter includes: At least one group is identified by an address family identifier, a sub-address family, a parameter set consisting of a flow specification rule ORF type and a transceiver capability identifier, and the transceiver capability identifier included in the first flow specification rule ORF capability parameter is used to indicate whether the second network device supports sending and/or receiving a flow specification rule ORF record. ;
所述第一网络设备比较所述第一流规范规则ORF能力参数与第二流规范规则ORF能力参数,所述第二流规范规则ORF能力参数指示所述第一网络设备支持的流规范规则ORF能力,所述第二流规范规则ORF能力参数包括:至少一组由地址族标识、子地址族标识、流规范规则ORF类型和收发能力标识组成的参数集合,所述第二流规范规则ORF能力参数中包括的收发能力标识用于指示所述第一网络设备是否支持发送和/或接收流规范规则ORF记录;The first network device compares the first flow specification rule ORF capability parameter with a second flow specification rule ORF capability parameter, and the second flow specification rule ORF capability parameter indicates a flow specification rule ORF capability supported by the first network device The second flow specification rule ORF capability parameter includes: at least one set of parameters consisting of an address family identifier, a sub-address family identifier, a flow specification rule ORF type, and a transceiving capability identifier, and the second flow specification rule ORF capability parameter The transceiver capability identifier included in the method is used to indicate whether the first network device supports sending and/or receiving a flow specification rule ORF record;
若所述第一流规范规则ORF能力参数包含的第一参数集合和所述第二流规范规则ORF能力参数包含的第二参数集合都包含流规范规则ORF类型,所述第一参数集合和所述第二参数集合包含相同的地址族标识和子地址族标识,并且所述第一参数集合的收发能力标识指示所述,并且所述第二网络设备支持发送,流规范规则ORF记录,所述第二参数集合的收发能力标识指示所述第一网络设备支持接收流规范规则ORF记录,则所述第一网络设备确定所述第二网络设备能够向所述第一网络设备发送流规范规则ORF记录。And if the first parameter set included in the first flow specification rule ORF capability parameter and the second parameter set included in the second flow specification rule ORF capability parameter include a flow specification rule ORF type, the first parameter set and the The second parameter set includes the same address family identifier and the sub-address family identifier, and the transceiver capability identifier of the first parameter set indicates the indication, and the second network device supports transmission, the flow specification rule ORF record, the second The transceiver capability identifier of the parameter set indicates that the first network device supports receiving the flow specification rule ORF record, and the first network device determines that the second network device can send the flow specification rule ORF record to the first network device.
结合本发明第一方面的第六种可能的实现方式,在本发明第一方面的第七种可能的实现方式中,所述第一网络设备获取第一流规范规则ORF能力参数,包括:With reference to the sixth possible implementation manner of the first aspect of the present invention, in a seventh possible implementation manner of the first aspect of the present disclosure, the first network device obtains the first flow specification rule ORF capability parameter, including:
所述第一网络设备在与所述第二网络设备建立BGP连接过程中,接收所述第二网络设备发送的BGP开放消息,所述第二网络设备发送的BGP开放消息中包括所述第一流规范规则ORF能力参数。Receiving, by the first network device, the BGP open message sent by the second network device in the process of establishing a BGP connection with the second network device, where the BGP open message sent by the second network device includes the first flow Standardize the ORF capability parameters.
结合本发明第一方面以及本发明第一方面的第一种至第四种可能的实现方式中的任意一种,在本发明第一方面的第七种可能的实现方式中,所述第一网络设备接收所述第二网络设备发送的流规范规则ORF记录,包括:In conjunction with the first aspect of the present invention and any one of the first to fourth possible implementations of the first aspect of the present invention, in a seventh possible implementation of the first aspect of the present invention, the first Receiving, by the network device, a flow specification rule ORF record sent by the second network device, including:
所述第一网络设备接收所述第二网络设备发送的BGP路由刷新消息,所述BGP路由刷新消息中包括所述流规范规则ORF记录。The first network device receives a BGP route refresh message sent by the second network device, where the BGP route refresh message includes the flow specification rule ORF record.
结合本发明第一方面以及本发明第一方面的第一种至第五种可能的实现方式中的任意一种,在本发明第一方面的第九种可能的实现方式中,所述第一网络设备接收所述第二网络设备发送的流规范规则ORF记录之后,所述方法还包括: In conjunction with the first aspect of the present invention and any one of the first to fifth possible implementations of the first aspect of the present invention, in a ninth possible implementation of the first aspect of the present invention, the first After the network device receives the flow specification rule ORF record sent by the second network device, the method further includes:
所述第一网络设备根据所述流规范规则ORF记录中包括的地址族标识和子地址族标识确定所述流规范规则ORF记录的类型,并根据所述流规范规则ORF记录的序列号将所述流规范规则ORF记录有序地存储到对应类型的流规范规则ORF列表中。Determining, by the first network device, the type of the flow specification rule ORF record according to the address family identifier and the sub-address family identifier included in the flow specification rule ORF record, and according to the sequence number recorded by the flow specification rule ORF The stream specification rule ORF records are stored in an ordered manner into the stream specification rule ORF list of the corresponding type.
本发明第二方面提供一种接收流规范规则的方法,包括:A second aspect of the present invention provides a method for receiving a flow specification rule, including:
第二网络设备确定第一网络设备能够接收流规范规则出站路由过滤ORF记录;The second network device determines that the first network device is capable of receiving the flow specification rule outbound route filtering ORF record;
所述第二网络设备根据自身保存的流规范规则策略生成流规范规则ORF记录;The second network device generates a flow specification rule ORF record according to the flow specification rule policy saved by itself;
所述第二网络设备将所述流规范规则ORF记录发送给所述第一网络设备;Transmitting, by the second network device, the flow specification rule ORF record to the first network device;
所述第二网络设备接收所述第一网络设备发送的流规范规则,所述流规范规则为所述第一网络设备根据所述流规范规则ORF记录过滤后的流规范规则。The second network device receives the flow specification rule sent by the first network device, where the flow specification rule is that the first network device records the filtered flow specification rule according to the flow specification rule ORF.
结合本发明第二方面,在本发明第二方面的第一种可能的实现方式中,所述流规范规则ORF记录包括:流规范规则ORF记录的序列号字段、行动匹配字段、过滤器类型字段、过滤器特定操作和取值字段,所述流规范规则ORF记录的序列号字段用于携带流规范规则ORF记录的优先级,所述行动匹配字段用于携带是否匹配流规范规则的动作类型,所述过滤器类型字段用于携带过滤器类型,所述过滤器特定操作和取值字段用于携带所述过滤器类型对应的过滤条件。With reference to the second aspect of the present invention, in a first possible implementation manner of the second aspect of the present invention, the flow specification rule ORF record includes: a sequence number field of a flow specification rule ORF record, an action matching field, and a filter type field. a filter specific operation and a value field, wherein the sequence number field of the flow specification rule ORF record is used to carry a priority of the flow specification rule ORF record, and the action matching field is used to carry an action type that matches the flow specification rule. The filter type field is used to carry a filter type, and the filter specific operation and value field are used to carry a filter condition corresponding to the filter type.
结合本发明第二方面的第一种可能的实现方式,在本发明第二方面的第二种可能的实现方式中,所述流规范规则ORF记录还包括:路由标识个数字段和路由标识字段,所述路由标识个数字段用于携带路由标识的个数,所述路由标识字段用于携带路由标识。With reference to the first possible implementation manner of the second aspect of the present invention, in a second possible implementation manner of the second aspect of the present invention, the flow specification rule ORF record further includes: a route identifier number field and a route identifier field The route identifier number field is used to carry the number of route identifiers, and the route identifier field is used to carry the route identifier.
结合本发明第二方面的第一种或第二种可能的实现方式,在本发明第二方面的第三种可能的实现方式中,所述流规范规则ORF记录还包括:过滤器个数字段,所述过滤器个数字段用于携带过滤器的个数。With reference to the first or second possible implementation manner of the second aspect of the present invention, in a third possible implementation manner of the second aspect of the present invention, the flow specification rule ORF record further includes: a filter number field The filter number field is used to carry the number of filters.
结合本发明第二方面以及本发明第二方面的第一种至第三种可能的实现方式中的任意一种,在本发明第二方面的第四种可能的实现方式中,所述第二网络设备确定能够向第一网络设备发送流规范规则出站路由过滤ORF记录,包括: In conjunction with the second aspect of the present invention and any one of the first to third possible implementations of the second aspect of the present invention, in a fourth possible implementation of the second aspect of the present invention, the second The network device determines that the flow specification rule outbound route filtering ORF record can be sent to the first network device, including:
所述第二网络设备获取第二流规范规则ORF能力参数,所述第二流规范规则ORF能力参数指示所述第一网络设备支持的流规范规则ORF能力,所述第二流规范规则ORF能力参数包括:至少一组由地址族标识和子地址族标识、流规范规则ORF类型和收发能力标识组成的参数集合,所述第二流规范规则ORF能力参数中包括的收发能力标识用于指示所述第一网络设备是否支持发送和/或接收流规范规则ORF记录;The second network device obtains a second flow specification rule ORF capability parameter, where the second flow specification rule ORF capability parameter indicates a flow specification rule ORF capability supported by the first network device, and the second flow specification rule ORF capability The parameter includes: at least one set of parameters consisting of an address family identifier and a sub-address family identifier, a flow specification rule ORF type, and a transceiver capability identifier, where the transceiver capability identifier included in the second flow specification rule ORF capability parameter is used to indicate the Whether the first network device supports sending and/or receiving a flow specification rule ORF record;
所述第二网络设备比较所述第二流规范规则ORF能力参数与第一流规范规则ORF能力参数,所述第一流规范规则ORF能力参数指示所述第二网络设备支持的流规范规则ORF能力,所述第一流规范规则ORF能力参数包括:至少一组由地址族标识和子地址族标识、流规范规则ORF类型和收发能力标识组成的参数集合,所述第一流规范规则ORF能力参数中包括的收发能力标识用于指示所述第二网络设备是否支持发送和/或接收流规范规则ORF记录;The second network device compares the second flow specification rule ORF capability parameter with a first flow specification rule ORF capability parameter, where the first flow specification rule ORF capability parameter indicates a flow specification rule ORF capability supported by the second network device, The first flow specification rule ORF capability parameter includes: at least one set of parameters consisting of an address family identifier and a sub-address family identifier, a flow specification rule ORF type, and a transceiving capability identifier, and the first stream specification rule ORF capability parameter includes The capability identifier is used to indicate whether the second network device supports sending and/or receiving a flow specification rule ORF record;
若所述第一流规范规则ORF能力参数包含的第一参数集合和所述第二流规范规则ORF能力参数包含的第二参数集合都包含流规范规则ORF类型,所述第一参数集合和所述第二参数集合包含相同的地址族标识和子地址族标识,并且所述第一参数集合的收发能力标识指示所述第二网络设备支持发送流规范规则ORF记录,所述第二参数集合的收发能力标识指示所述第一网络设备支持接收流规范规则ORF记录,则所述第二网络设备确定能够向所述第一网络设备发送流规范规则ORF记录。And if the first parameter set included in the first flow specification rule ORF capability parameter and the second parameter set included in the second flow specification rule ORF capability parameter include a flow specification rule ORF type, the first parameter set and the The second parameter set includes the same address family identifier and the sub-address family identifier, and the transceiver capability identifier of the first parameter set indicates that the second network device supports the sending flow specification rule ORF record, and the second parameter set is capable of transmitting and receiving. The identifier indicates that the first network device supports receiving the flow specification rule ORF record, and the second network device determines that the flow specification rule ORF record can be sent to the first network device.
结合本发明第二方面的第四种可能的实现方式,在本发明第二方面的第五种可能的实现方式中,所述第二网络设备获取第二流规范规则ORF能力参数,包括:With reference to the fourth possible implementation manner of the second aspect of the present invention, in a fifth possible implementation manner of the second aspect of the present disclosure, the second network device obtains the second flow specification rule ORF capability parameter, including:
所述第二网络设备在与所述第一网络设备建立BGP连接的过程中,接收所述第一网络设备发送的BGP开放消息,所述第一网络设备发送的BGP开放消息中包括所述第二流规范规则ORF能力参数。Receiving, by the second network device, the BGP open message sent by the first network device in the process of establishing a BGP connection with the first network device, where the BGP open message sent by the first network device includes the The second-flow specification rules ORF capability parameters.
结合本发明第二方面以及本发明第二方面的第一种至第五种可能的实现方式中的任意一种,在本发明第二方面的第六种可能的实现方式中,所述第二网络设备将所述流规范规则ORF记录发送给所述第一网络设备,包括:In conjunction with the second aspect of the present invention and any one of the first to fifth possible implementations of the second aspect of the present invention, in a sixth possible implementation of the second aspect of the present invention, the second The network device sends the flow specification rule ORF record to the first network device, including:
所述第二网络设备向所述第一网络设备发送BGP路由刷新消息,所述路由BGP刷新消息中包括所述流规范规则ORF记录。The second network device sends a BGP route refresh message to the first network device, where the route BGP refresh message includes the flow specification rule ORF record.
本发明第三方面提供一种第一网络设备,包括: A third aspect of the present invention provides a first network device, including:
确定模块,用于确定第二网络设备能够向所述第一网络设备发送流规范规则出站路由过滤ORF记录;a determining module, configured to determine, by the second network device, a flow specification rule outbound route filtering ORF record to the first network device;
接收模块,用于接收所述第二网络设备发送的所述流规范规则ORF记录,所述流规范规则ORF记录用于所述第一网络设备对待发送给所述第二网络设备的流规范规则进行过滤;a receiving module, configured to receive the flow specification rule ORF record sent by the second network device, where the flow specification rule ORF records a flow specification rule to be sent by the first network device to the second network device Filtering;
过滤模块,用于根据所述流规范规则ORF记录对待发送给所述第二网络设备的流规范规则进行过滤;a filtering module, configured to filter, according to the flow specification rule ORF, a flow specification rule to be sent to the second network device;
发送模块,用于向所述第二网络设备发送过滤后的流规范规则。And a sending module, configured to send the filtered flow specification rule to the second network device.
结合本发明第三方面,在本发明第三方面的第一种可能的实现方式中,所述流规范规则ORF记录包括:流规范规则ORF记录的序列号字段、行动匹配字段、过滤器类型字段、过滤器特定操作和取值字段,所述流规范规则ORF记录的序列号字段用于携带流规范规则ORF记录的优先级,所述行动匹配字段用于携带是否匹配流规范规则的动作类型,所述过滤器类型字段用于携带过滤器类型,所述过滤器特定操作和取值字段用于携带所述过滤器类型对应的过滤条件。With reference to the third aspect of the present invention, in a first possible implementation manner of the third aspect of the present invention, the flow specification rule ORF record includes: a sequence number field, an action matching field, and a filter type field of a flow specification rule ORF record a filter specific operation and a value field, wherein the sequence number field of the flow specification rule ORF record is used to carry a priority of the flow specification rule ORF record, and the action matching field is used to carry an action type that matches the flow specification rule. The filter type field is used to carry a filter type, and the filter specific operation and value field are used to carry a filter condition corresponding to the filter type.
结合本发明第三方面的第一种可能的实现方式,在本发明第三方面的第二种可能的实现方式中,所述流规范规则ORF记录还包括:路由标识个数字段和路由标识字段,所述路由标识个数字段用于携带路由标识的个数,所述路由标识字段用于携带路由标识。With reference to the first possible implementation manner of the third aspect of the present invention, in a second possible implementation manner of the third aspect of the present invention, the flow specification rule ORF record further includes: a route identifier number field and a route identifier field The route identifier number field is used to carry the number of route identifiers, and the route identifier field is used to carry the route identifier.
结合本发明第三方面的第一种或第二种可能的实现方式,在本发明第三方面的第三种可能的实现方式中,所述流规范规则ORF记录还包括:过滤器个数字段,所述过滤器个数字段用于携带过滤器的个数。With reference to the first or second possible implementation manner of the third aspect of the present invention, in a third possible implementation manner of the third aspect of the present invention, the flow specification rule ORF record further includes: a filter number field The filter number field is used to carry the number of filters.
结合本发明第三方面的第一种可能的实现方式,在本发明第三方面的第四种可能的实现方式中,所述过滤模块具体用于:With reference to the first possible implementation manner of the third aspect of the present invention, in a fourth possible implementation manner of the third aspect, the filtering module is specifically configured to:
将所述流规范规则ORF记录包括的:行动匹配字段、过滤器个数字段、过滤器类型字段、过滤器特定操作和取值字段,分别与所述待发送给所述第二网络设备的流规范规则包括的:动作类型字段、过滤器类型字段、过滤器特定操作和取值字段进行比较;And the flow specification rule ORF record includes: an action matching field, a filter number field, a filter type field, a filter specific operation, and a value field, respectively, and the flow to be sent to the second network device The specification rules include: action type fields, filter type fields, filter specific operations, and value fields for comparison;
若所述流规范规则ORF记录包括的行动匹配字段所指示的要匹配的动作类型集合为空或所述要匹配的动作类型都包含在所述待发送给所述第二网络设备的流规范规则包括的动作类型中,所述流规范规则ORF记录包括的过滤 器集合为空或每种过滤器类型的过滤器特定操作和取值字段的数值空间都包含所述待发送给所述第二网络设备的流规范规则包括的过滤器类型的过滤器特定操作和取值字段的数值空间,则确定所述待发送给所述第二网络设备的流规范规则匹配所述流规范规则ORF记录。If the action type set to be matched by the action matching field included in the flow specification rule ORF record is empty or the action type to be matched is included in the flow specification rule to be sent to the second network device Among the types of actions included, the flow specification rule ORF records include filtering The filter set is empty or the value space of the filter specific operation and value field of each filter type contains the filter specific operation of the filter type included in the flow specification rule to be sent to the second network device and And determining a value space of the value field, determining that the flow specification rule to be sent to the second network device matches the flow specification rule ORF record.
结合本发明第三方面的第二种可能的实现方式,在本发明第三方面的第五种可能的实现方式中,所述过滤模块具体用于:With reference to the second possible implementation manner of the third aspect of the present invention, in a fifth possible implementation manner of the third aspect, the filtering module is specifically configured to:
将所述流规范规则ORF记录包括的:行动匹配字段、过滤器类型字段、过滤器特定操作和取值字段、路由标识字段,分别与所述待发送给所述第二网络设备的流规范规则包括的:动作类型字段、过滤器类型字段、过滤器特定操作和取值字段和路由标识字段进行比较;And the flow specification rule ORF record includes: an action matching field, a filter type field, a filter specific operation and a value field, and a route identification field, respectively, and the flow specification rule to be sent to the second network device Included: action type field, filter type field, filter specific operation and value field and route identification field are compared;
若所述流规范规则ORF记录包括的行动匹配字段所指示的要匹配的动作类型集合为空或所述要匹配的动作类型都包含在所述待发送的流规范规则包括的动作类型中,所述流规范规则ORF记录包括的过滤器集合为空或每种过滤器类型的过滤器特定操作和取值字段的数值空间都包含所述待发送给所述第二网络设备的流规范规则包括的过滤器类型的过滤器特定操作和取值字段的数值空间,所述流规范规则ORF记录包括的路由标识组成的路由标识集合为空或所述路由标识集合中包含所述待发送给所述第二网络设备的流规范规则包括的路由标识,则确定所述待发送给所述第二网络设备的流规范规则匹配上所述流规范规则ORF记录。If the action type set to be matched by the action matching field included in the flow specification rule ORF record is empty or the action type to be matched is included in the action type included in the flow specification rule to be sent, The flow specification rule ORF record includes a filter set that is empty or a filter-specific operation of each filter type and a value space of the value field that includes the flow specification rule to be sent to the second network device a filter-specific operation and a value space of a value field, the flow specification rule ORF record includes a route identifier set consisting of a route identifier that is empty or the route identifier set includes the to-be-sent to the first And determining, by the flow specification rule of the network device, the flow identifier rule to be sent to the second network device, and matching the flow specification rule ORF record.
结合本发明第三方面以及本发明第三方面的第一种至第五种可能的实现方式中的任意一种,在本发明第三方面的第六种可能的实现方式中,所述确定模块具体用于:With reference to the third aspect of the present invention and any one of the first to fifth possible implementation manners of the third aspect of the present invention, in a sixth possible implementation manner of the third aspect of the present invention, the determining module Specifically used for:
获取第一流规范规则ORF能力参数,所述第一流规范规则ORF能力参数指示所述第二网络设备支持的流规范规则ORF能力,所述第一流规范规则ORF能力参数包括:至少一组由地址族标识、子地址族标识、流规范规则ORF类型和收发能力标识组成的参数集合,所述第一流规范规则ORF能力参数中包括的收发能力标识用于指示所述第二网络设备是否支持发送和/或接收流规范规则ORF记录;Obtaining a first flow specification rule ORF capability parameter, the first flow specification rule ORF capability parameter indicating a flow specification rule ORF capability supported by the second network device, the first flow specification rule ORF capability parameter comprising: at least one group of address families The parameter set consisting of the identifier, the sub-address family identifier, the flow specification rule ORF type, and the transceiver capability identifier, and the transceiver capability identifier included in the first-flow specification rule ORF capability parameter is used to indicate whether the second network device supports sending and/or Or receive a flow specification rule ORF record;
比较所述第一流规范规则ORF能力参数与第二流规范规则ORF能力参数,所述第二流规范规则ORF能力参数指示所述第一网络设备支持的流规范规则ORF能力,所述第二流规范规则ORF能力参数包括:至少一组由地址族标识、 子地址族标识、流规范规则ORF类型和收发能力标识组成的参数集合,所述第二流规范规则ORF能力参数中包括的收发能力标识用于指示所述第一网络设备是否支持发送和/或接收流规范规则ORF记录;Comparing the first flow specification rule ORF capability parameter with a second flow specification rule ORF capability parameter, the second flow specification rule ORF capability parameter indicating a flow specification rule ORF capability supported by the first network device, the second flow The specification rule ORF capability parameters include: at least one group is identified by an address family, a parameter set consisting of a sub-address family identifier, a flow specification rule ORF type, and a transceiving capability identifier, where the transceiving capability identifier included in the second-flow specification rule ORF capability parameter is used to indicate whether the first network device supports sending and/or Receive stream specification rule ORF record;
若所述第一流规范规则ORF能力参数包含的第一参数集合和所述第二流规范规则ORF能力参数包含的第二参数集合都包含流规范规则ORF类型,所述第一参数集合和所述第二参数集合包含相同的地址族标识和子地址族标识,并且所述第一参数集合的收发能力标识指示所述第二网络设备支持发送流规范规则ORF记录,所述第二参数集合的收发能力标识指示所述第一网络设备支持接收流规范规则ORF记录,则确定所述第二网络设备能够向所述第一网络设备发送流规范规则ORF记录。And if the first parameter set included in the first flow specification rule ORF capability parameter and the second parameter set included in the second flow specification rule ORF capability parameter include a flow specification rule ORF type, the first parameter set and the The second parameter set includes the same address family identifier and the sub-address family identifier, and the transceiver capability identifier of the first parameter set indicates that the second network device supports the sending flow specification rule ORF record, and the second parameter set is capable of transmitting and receiving. The identifier indicates that the first network device supports receiving the flow specification rule ORF record, and determining that the second network device is capable of sending a flow specification rule ORF record to the first network device.
结合本发明第三方面的第六种可能的实现方式,在本发明第三方面的第七种可能的实现方式中,所述获取第一流规范规则ORF能力参数,包括:With reference to the sixth possible implementation manner of the third aspect of the present invention, in the seventh possible implementation manner of the third aspect of the present invention, the acquiring the first flow specification rule ORF capability parameter includes:
在与所述第二网络设备建立BGP连接过程中,接收所述第二网络设备发送的BGP开放消息,所述第二网络设备发送的BGP开放消息中包括所述第一流规范规则ORF能力参数。The BGP open message sent by the second network device is received in the process of establishing a BGP connection with the second network device, and the BGP open message sent by the second network device includes the first flow specification rule ORF capability parameter.
结合本发明第三方面以及本发明第三方面的第一种至第五种可能的实现方式中的任意一种,在本发明第三方面的第八种可能的实现方式中,所述接收模块具体用于:With reference to the third aspect of the present invention and any one of the first to fifth possible implementation manners of the third aspect of the present invention, in the eighth possible implementation manner of the third aspect of the present invention, the receiving module Specifically used for:
接收所述第二网络设备发送的BGP路由刷新消息,所述BGP路由刷新消息中包括所述流规范规则ORF记录。Receiving a BGP route refresh message sent by the second network device, where the BGP route refresh message includes the flow specification rule ORF record.
结合本发明第三方面以及本发明第三方面的第一种至第五种可能的实现方式中的任意一种,在本发明第三方面的第九种可能的实现方式中,所述设备还包括存储处理模块;With reference to the third aspect of the present invention and any one of the first to fifth possible implementation manners of the third aspect of the present invention, in a ninth possible implementation manner of the third aspect of the present invention, the device is further Including a storage processing module;
所述存储处理模块,用于在所述接收模块接收所述第二网络设备发送的流规范规则ORF记录之后,根据所述流规范规则ORF记录中包括的地址族标识和子地址族标识确定所述流规范规则ORF记录的类型,并根据所述流规范规则ORF记录的序列号将所述流规范规则ORF记录有序地存储到对应类型的流规范规则ORF列表中。The storage processing module, configured to determine, after the receiving module receives the flow specification rule ORF record sent by the second network device, according to the address family identifier and the sub-address family identifier included in the flow specification rule ORF record The flow specification rules the type of ORF record, and stores the flow specification rule ORF record in an orderly manner according to the sequence number of the flow specification rule ORF record into the flow specification rule ORF list of the corresponding type.
本发明第四方面提供一种第二网络设备,包括:A fourth aspect of the present invention provides a second network device, including:
确定模块,用于确定第一网络设备能够接收流规范规则出站路由过滤ORF记录; a determining module, configured to determine that the first network device is capable of receiving a flow specification rule outbound route filtering ORF record;
生成模块,用于根据所述第二网络设备保存的流规范规则策略生成流规范规则ORF记录;a generating module, configured to generate a flow specification rule ORF record according to a flow specification rule policy saved by the second network device;
发送模块,用于将所述生成模块生成的流规范规则ORF记录发送给所述第一网络设备;a sending module, configured to send, to the first network device, a flow specification rule ORF record generated by the generating module;
接收模块,用于接收所述第一网络设备发送的流规范规则,所述流规范规则为所述第一网络设备根据所述流规范规则ORF记录过滤后的流规范规则。And a receiving module, configured to receive a flow specification rule sent by the first network device, where the flow specification rule is that the first network device records the filtered flow specification rule according to the flow specification rule ORF.
结合本发明第四方面,在本发明第四方面的第一种可能的实现方式中,所述流规范规则ORF记录包括:流规范规则ORF记录的序列号字段、行动匹配字段、过滤器类型字段、过滤器特定操作和取值字段,所述流规范规则ORF记录的序列号字段用于携带流规范规则ORF记录的优先级,所述行动匹配字段用于携带是否匹配流规范规则的动作类型,所述过滤器类型字段用于携带过滤器类型,所述过滤器特定操作和取值字段用于携带所述过滤器类型对应的过滤条件。With reference to the fourth aspect of the present invention, in a first possible implementation manner of the fourth aspect of the present invention, the flow specification rule ORF record includes: a sequence number field of a flow specification rule ORF record, an action matching field, and a filter type field. a filter specific operation and a value field, wherein the sequence number field of the flow specification rule ORF record is used to carry a priority of the flow specification rule ORF record, and the action matching field is used to carry an action type that matches the flow specification rule. The filter type field is used to carry a filter type, and the filter specific operation and value field are used to carry a filter condition corresponding to the filter type.
结合本发明第四方面的第一种可能的实现方式,在本发明第四方面的第二种可能的实现方式中,所述流规范规则ORF记录还包括:路由标识个数字段和路由标识字段,所述路由标识个数字段用于携带路由标识的个数,所述路由标识字段用于携带路由标识。With reference to the first possible implementation manner of the fourth aspect of the present invention, in a second possible implementation manner of the fourth aspect of the present invention, the flow specification rule ORF record further includes: a route identifier number field and a route identifier field The route identifier number field is used to carry the number of route identifiers, and the route identifier field is used to carry the route identifier.
结合本发明第四方面的第一种或第二种可能的实现方式,在本发明第四方面的第三种可能的实现方式中,所述流规范规则ORF记录还包括:过滤器个数字段,所述过滤器个数字段用于携带过滤器的个数。With reference to the first or second possible implementation manner of the fourth aspect of the present invention, in a third possible implementation manner of the fourth aspect of the present invention, the flow specification rule ORF record further includes: a filter number field The filter number field is used to carry the number of filters.
结合本发明第四方面以及本发明第四方面的第一种至第三种可能的实现方式中的任意一种,在本发明第四方面的第四种可能的实现方式中,所述确定模块具体用于:With reference to the fourth aspect of the present invention and any one of the first to third possible implementation manners of the fourth aspect of the present invention, in a fourth possible implementation manner of the fourth aspect of the present invention, the determining module Specifically used for:
获取第二流规范规则ORF能力参数,所述第二流规范规则ORF能力参数指示所述第一网络设备支持的流规范规则ORF能力,所述第二流规范规则ORF能力参数包括:至少一组由地址族标识、子地址族标识、流规范规则ORF类型和收发能力标识组成的参数集合,所述第二流规范规则ORF能力参数中包括的收发能力标识用于指示所述第一网络设备是否支持发送和/或接收流规范规则ORF记录;Obtaining a second flow specification rule ORF capability parameter, where the second flow specification rule ORF capability parameter indicates a flow specification rule ORF capability supported by the first network device, and the second flow specification rule ORF capability parameter includes: at least one group a parameter set consisting of an address family identifier, a sub-address family identifier, a flow specification rule ORF type, and a transceiver capability identifier, where the transceiver capability identifier included in the second-flow specification rule ORF capability parameter is used to indicate whether the first network device is Support for sending and/or receiving flow specification rules ORF records;
比较所述第二流规范规则ORF能力参数与第一流规范规则ORF能力参数,所述第一流规范规则ORF能力参数指示所述第二网络设备支持的流规范规则 ORF能力,所述第一流规范规则ORF能力参数包括:至少一组由地址族标识、子地址族标识、流规范规则ORF类型和收发能力标识组成的参数集合,所述第一流规范规则ORF能力参数中包括的收发能力标识用于指示所述第二网络设备是否支持发送和/或接收流规范规则ORF记录;Comparing the second flow specification rule ORF capability parameter with a first flow specification rule ORF capability parameter, the first flow specification rule ORF capability parameter indicating a flow specification rule supported by the second network device ORF capability, the first flow specification rule ORF capability parameter includes: at least one set of parameters consisting of an address family identifier, a sub-address family identifier, a flow specification rule ORF type, and a transceiving capability identifier, and the first flow specification rule ORF capability parameter The transceiver capability identifier included in the indication is used to indicate whether the second network device supports sending and/or receiving a flow specification rule ORF record;
若所述第一流规范规则ORF能力参数包含的第一参数集合和所述第二流规范规则ORF能力参数包含的第二参数集合都包含流规范规则ORF类型,所述第一参数集合和所述第二参数集合包含相同的地址族标识和子地址族标识,并且第一参数集合的收发能力标识指示所述第二网络设备支持发送,流规范规则ORF记录,所述第二参数集合的收发能力标识指示所述第一网络设备支持接收流规范规则ORF记录,则确定所述第二网络设备能够向所述第一网络设备发送流规范规则ORF记录。And if the first parameter set included in the first flow specification rule ORF capability parameter and the second parameter set included in the second flow specification rule ORF capability parameter include a flow specification rule ORF type, the first parameter set and the The second parameter set includes the same address family identifier and the sub-address family identifier, and the transceiver capability identifier of the first parameter set indicates that the second network device supports sending, the flow specification rule ORF records, and the second parameter set of the transceiver capability identifier Instructing the first network device to support receiving a flow specification rule ORF record, determining that the second network device is capable of transmitting a flow specification rule ORF record to the first network device.
结合本发明第四方面的第四种可能的实现方式,在本发明第四方面的第五种可能的实现方式中,所述获取第二流规范规则ORF能力参数,包括:With reference to the fourth possible implementation manner of the fourth aspect of the present invention, in the fifth possible implementation manner of the fourth aspect of the present invention, the acquiring the second flow specification rule ORF capability parameter includes:
在所述第二网络设备与所述第一网络设备建立BGP连接的过程中,接收所述第一网络设备发送的BGP开放消息,所述第一网络设备发送的BGP开放消息中包括所述第二流规范规则ORF能力参数。Receiving, in the process of establishing a BGP connection between the second network device and the first network device, receiving a BGP open message sent by the first network device, where the BGP open message sent by the first network device includes the The second-flow specification rules ORF capability parameters.
结合本发明第四方面以及本发明第四方面的第一种至第五种可能的实现方式中的任意一种,在本发明第四方面的第六种可能的实现方式中,所述发送模块具体用于:With reference to the fourth aspect of the present invention and any one of the first to fifth possible implementation manners of the fourth aspect of the present invention, in a sixth possible implementation manner of the fourth aspect of the present invention, the sending module Specifically used for:
向所述第一网络设备发送BGP路由刷新消息,所述BGP路由刷新消息中包括所述流规范规则ORF记录。Sending a BGP route refresh message to the first network device, where the BGP route refresh message includes the flow specification rule ORF record.
本发明第五方面提供一种网络系统,所述网络系统包括:第一网络设备和第二网络设备;A fifth aspect of the present invention provides a network system, where the network system includes: a first network device and a second network device;
所述第一网络设备,用于执行如本发明第一方面以及本发明第一方面的第一种至第九种可能的实现方式提供的任一所述的方法;The first network device is configured to perform the method according to any one of the first to ninth possible implementations of the first aspect of the present invention and the first aspect of the present invention;
所述第二网络设备,用于执行本发明第二方面以及本发明第二方面的第一种至第六种可能的实现方式提供的任一所述的方法。The second network device is configured to perform the method of any one of the second aspect of the present invention and the first to sixth possible implementations of the second aspect of the present invention.
本发明实施例提供的发送、接收流规范规则的方法和装置,第一网络设备在确定第二网络设备能够向第一网络设备发送流规范规则ORF记录后,接收第二网络设备发送的流规范规则ORF记录,流规范规则ORF记录用于第一网络设备对发送给第二网络设备的流规范规则进行过滤,当第一网络设备有 流规范规则发送给第二网络设备时,第一网络设备根据流规范规则ORF记录对待发送的流规范规则进行过滤,只向第二网络设备发送满足流规范规则ORF记录过滤条件的流规范规则,解决了网络设备发送大量无效的流规范规则,造成的资源浪费的问题。The method and device for transmitting and receiving a flow specification rule provided by the embodiment of the present invention, after determining that the second network device can send the flow specification rule ORF record to the first network device, the first network device receives the flow specification sent by the second network device. The rule ORF record, the flow specification rule ORF record is used by the first network device to filter the flow specification rule sent to the second network device, when the first network device has When the flow specification rule is sent to the second network device, the first network device filters the flow specification rule to be sent according to the flow specification rule ORF, and only sends the flow specification rule that satisfies the flow specification rule ORF record filter condition to the second network device, The problem that the network device sends a large number of invalid flow specification rules and wastes resources is solved.
附图说明DRAWINGS
为了更清楚地说明本发明实施例或现有技术中的技术方案,下面将对实施例或现有技术描述中所需要使用的附图逐一简单地介绍,显而易见地,下面描述中的附图是本发明的一些实施例,对于本领域普通技术人员来讲,在不付出创造性劳动性的前提下,还可以根据这些附图获得其他的附图。In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings used in the embodiments or the description of the prior art will be briefly introduced one by one. It is obvious that the drawings in the following description are Some embodiments of the present invention may also be used to obtain other drawings based on these drawings without departing from the prior art.
图1为本发明实施例一提供的发送流规范规则的方法的流程图;FIG. 1 is a flowchart of a method for sending a flow specification rule according to Embodiment 1 of the present invention;
图2为本发明实施例新定义的流规范规则ORF记录的格式;2 is a format of a flow specification ORF record newly defined in an embodiment of the present invention;
图3为本实施例提供的四种Filter Type对应的Filter的格式;FIG. 3 is a format of a filter corresponding to four types of Filter Types provided by the embodiment;
图4为携带拒绝任何匹配ICMP Type取值的过滤器的IPv4流规范规则ORF记录A的一种消息内容示例;4 is an example of a message content carrying an IPv4 flow specification rule ORF record A that rejects any filter that matches the value of ICMP Type;
图5为携带拒绝任何匹配ICMP Code取值的过滤器的IPv4流规范规则ORF记录B的一种消息内容示例;5 is an example of message content of an IPv4 flow specification rule ORF record B carrying a filter that rejects any matching ICMP Code value;
图6为本发明实施例二提供的接收流规范规则的方法的流程图;FIG. 6 is a flowchart of a method for receiving a flow specification rule according to Embodiment 2 of the present invention;
图7为本发明实施例三提供的第一网络设备的结构示意图;FIG. 7 is a schematic structural diagram of a first network device according to Embodiment 3 of the present invention;
图8为本发明实施例四提供的第二网络设备的结构示意图;FIG. 8 is a schematic structural diagram of a second network device according to Embodiment 4 of the present invention;
图9为本发明实施例五提供的第一网络设备的结构示意图;FIG. 9 is a schematic structural diagram of a first network device according to Embodiment 5 of the present invention;
图10为本发明实施例六提供的第二网络设备的结构示意图;FIG. 10 is a schematic structural diagram of a second network device according to Embodiment 6 of the present invention;
图11为本发明实施例七提供的网络系统的结构示意图。FIG. 11 is a schematic structural diagram of a network system according to Embodiment 7 of the present invention.
具体实施方式detailed description
为使本发明实施例的目的、技术方案和优点更加清楚,下面将结合本发明实施例中的附图,对本发明实施例中的技术方案进行清楚、完整地描述,显然,所描述的实施例是本发明一部分实施例,而不是全部的实施例。基于本发明中的实施例,本领域普通技术人员在没有作出创造性劳动前提下所获 得的所有其他实施例,都属于本发明保护的范围。The technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the drawings in the embodiments of the present invention. It is a partial embodiment of the invention, and not all of the embodiments. Based on the embodiments of the present invention, those of ordinary skill in the art obtain the following without creative efforts. All other embodiments obtained are within the scope of the invention.
图1为本发明实施例一提供的发送流规范规则的方法的流程图,如图1所示,本实施例的方法可以包括以下步骤:FIG. 1 is a flowchart of a method for sending a flow specification rule according to Embodiment 1 of the present invention. As shown in FIG. 1 , the method in this embodiment may include the following steps:
步骤101、第一网络设备确定第二网络设备能够向第一网络设备发送流规范规则ORF记录。Step 101: The first network device determines that the second network device is capable of sending a flow specification rule ORF record to the first network device.
本实施例中新定义了一种出站路由过滤(英文翻译为:Outbound Route Filtering,简称ORF)类型:流规范规则(英文翻译为:Flow Specification rule)ORF类型,流规范规则ORF能力对于边界网关协议(Border Gateway Protocol,简称BGP)是一种新能力。要实现本实施例的功能,本实施例需要对BGP协议进行相应的扩展,在原有BGP协议的基础上增加一种新的ORF类型,即流规范规则ORF类型,使其支持流规范规则ORF能力的协商。In this embodiment, an outbound route filtering (English translation is: Outbound Route Filtering, ORF for short) type: flow specification rule (English translation: Flow Specification rule) ORF type, flow specification rule ORF capability for border gateway The Border Gateway Protocol (BGP) is a new capability. To implement the functions of this embodiment, the BGP protocol needs to be extended accordingly. A new ORF type is added to the original BGP protocol, that is, the flow specification ORF type is supported, so that the flow specification ORF capability is supported. Negotiation.
本实施例中,第一网络设备可以通过流规范规则ORF能力协商确定第二网络设备能够向第一网络设备发送流规范规则出站路由过滤ORF记录。协商过程具体为:In this embodiment, the first network device may determine, by using the flow specification rule ORF capability negotiation, that the second network device can send the flow specification rule outbound route filtering ORF record to the first network device. The negotiation process is specifically as follows:
首先,第一网络设备获取第一流规范规则ORF能力参数,该第一流规范规则ORF能力参数指示第二网络设备支持的流规范规则ORF能力,第一流规范规则ORF能力参数包括:至少一组由地址族标识(Address Family Identifier,简称AFI)、子地址族标识子地址族标识(Subsequent Address Family Identifier,简称SAFI)、流规范规则ORF类型和收发能力标识组成的参数集合,该第一流规范规则ORF能力参数中包括的收发能力标识用于指示第二网络设备是否支持发送和/或接收流规范规则ORF记录(Entry)。First, the first network device obtains a first flow specification rule ORF capability parameter, where the first flow specification rule ORF capability parameter indicates a flow specification rule ORF capability supported by the second network device, and the first flow specification rule ORF capability parameter includes: at least one group of addresses A set of parameters consisting of an address family identifier (AFI), a sub-address family identifier sub-address family identifier (SAFI), a flow specification rule ORF type, and a transceiver capability identifier. The first-flow specification rule ORF capability. The transceiving capability identifier included in the parameter is used to indicate whether the second network device supports sending and/or receiving a stream specification rule ORF record (Entry).
第一网络设备获取第一流规范规则ORF能力参数,具体可以为:第一网络设备在与第二网络设备建立BGP连接过程中,接收第二网络设备发送的BGP开放(OPEN)消息,第二网络设备发送的BGP OPEN消息中包括该第一流规范规则ORF能力参数。第一流规范规则ORF能力参数可以通过以下方式表示:<AFI=1/SAFI=133,FlowSpec-ORF-Type,Send/Receive=both>,该表达式表示第一网络设备能够接收和发送IPv4类型的流规范规则ORF记录,Flow Spec-ORF-Type表示流规范规则ORF类型,流规范规则ORF类型的具体取值可以根据需要进行设置,例如由互联网数字分配机构(The Internet Assigned Numbers Authority,简称IANA)分配,本发明并不对此进行限制。The first network device obtains the first flow specification rule ORF capability parameter, where the first network device receives the BGP open (OPEN) message sent by the second network device in the process of establishing a BGP connection with the second network device, and the second network The BGP OPEN message sent by the device includes the first flow specification rule ORF capability parameter. The first-flow specification rule ORF capability parameter can be expressed in the following manner: <AFI=1/SAFI=133, FlowSpec-ORF-Type, Send/Receive=both>, the expression indicates that the first network device can receive and transmit the IPv4 type. The flow specification rule ORF record, Flow Spec-ORF-Type indicates the flow specification rule ORF type, and the specific value of the flow specification rule ORF type can be set as needed, for example, by the Internet Assigned Numbers Authority (IANA). The distribution is not limited by the present invention.
上述例子中,第一网络设备支持发送和接收IPv4的流规范规则ORF记录, 当然,第一网络设备还可能同时支持发送和/或接收多种类型的流规范规则ORF记录,如表1所示:In the above example, the first network device supports sending and receiving an IPv4 flow specification rule ORF record, Of course, the first network device may also support sending and/or receiving multiple types of flow specification rule ORF records, as shown in Table 1:
表1Table 1
Figure PCTCN2016075632-appb-000001
Figure PCTCN2016075632-appb-000001
通过表1可知,当AFI=1/SAFI=134时,第一网络设备支持发送和/或接收基于IPV4的虚拟私有网络(Virtual Private Network,简称VPN)流规范规则ORF记录,当AFI=2/SAFI=133时,第一网络设备支持发送和/或接收基于IPV6的流规范规则ORF记录,当AFI=2,SAFI=134时,第一网络设备支持发送和/或接收基于IPV6的VPN流规范规则ORF记录,当AFI=25,SAFI=134时,第一网络设备支持发送和/或接收二层VPN流规范规则ORF记录。It can be seen from Table 1 that when AFI=1/SAFI=134, the first network device supports sending and/or receiving an IPV4-based Virtual Private Network (VPN) flow specification rule ORF record when AFI=2/ When SAFI=133, the first network device supports sending and/or receiving IPV6-based flow specification rule ORF records. When AFI=2, SAFI=134, the first network device supports sending and/or receiving IPV6-based VPN flow specifications. The rule ORF records that when AFI=25, SAFI=134, the first network device supports sending and/or receiving a Layer 2 VPN flow specification rule ORF record.
第一网络设备在获取第一流规范规则ORF能力参数后,比较第一流规范规则ORF能力参数与第二流规范规则ORF能力参数,该第二流规范规则ORF能力参数指示第一网络设备支持的流规范规则ORF能力,该第二流规范规则ORF能力参数包括:至少一组由AFI、SAFI、流规范规则ORF类型和收发能力标识组成的参数集合,该第二流规范规则ORF能力参数中包括的收发能力标识用于指示第一网络设备是否支持发送和/或接收流规范规则ORF记录。若第一流规范规则ORF能力参数包含的第一参数集合和第二流规范规则ORF能力参数包含的第二参数集合都包含流规范规则ORF类型,第一参数集合和所述第二参数集合包含相同的AFI和SAFI,并且第一参数集合的收发能力标识指示第二网络设备支持发送流规范规则ORF记录,第二参数集合的收发能力标识指示第一网络设备支持接收流规范规则ORF记录,则第一网络设备确定第二网络设备能够向第一网络设备发送流规范规则ORF记录,流规范规则ORF能力协商通过。本发明实施例中,若第一流规范规则ORF能力参数包含多组 参数集合时,第一参数集合为第一流规范规则ORF能力参数包含多组参数集合中的至少一组参数集合。同理,若第二流规范规则ORF能力参数中包含多组参数集合时,第二参数集合为第二流规范规则ORF能力参数中包含多组参数集合中的至少一组参数集合。若第一规范规则ORF能力参数包含一组参数集合时,第一参数集合为第一流规范规则ORF能力参数包含的该一组参数集合,若第二流规范规则ORF能力参数中包含一组参数集合时,第二参数集合为第二流规范规则ORF能力参数中包含的该一组参数集合。After obtaining the first flow specification rule ORF capability parameter, the first network device compares the first flow specification rule ORF capability parameter with the second flow specification rule ORF capability parameter, where the second flow specification rule ORF capability parameter indicates the flow supported by the first network device Regulating the rule ORF capability, the second flow specification rule ORF capability parameter includes: at least one set of parameters consisting of AFI, SAFI, flow specification rule ORF type, and transceiving capability identifier, the second flow specification rule included in the ORF capability parameter The transceiving capability identifier is used to indicate whether the first network device supports sending and/or receiving a flow specification rule ORF record. If the first parameter set included in the first flow specification rule ORF capability parameter and the second parameter set included in the second flow specification rule ORF capability parameter both contain a flow specification rule ORF type, the first parameter set and the second parameter set include the same AFI and SAFI, and the transceiver capability identifier of the first parameter set indicates that the second network device supports the transmission flow specification rule ORF record, and the transceiver capability identifier of the second parameter set indicates that the first network device supports the receive flow specification rule ORF record, then A network device determines that the second network device can send a flow specification rule ORF record to the first network device, and the flow specification rule ORF capability is negotiated. In the embodiment of the present invention, if the first flow specification rule ORF capability parameter includes multiple groups In the parameter set, the first parameter set is the first stream specification rule. The ORF capability parameter includes at least one set of parameters in the plurality of sets of parameters. Similarly, if the second stream specification rule ORF capability parameter includes multiple sets of parameter sets, the second parameter set is the second stream specification rule. The ORF capability parameter includes at least one set of parameter sets in the plurality of sets of parameter sets. If the first norm rule ORF capability parameter includes a set of parameters, the first parameter set is the set of parameters included in the first stream specification rule ORF capability parameter, and if the second stream specification rule ORF capability parameter includes a set of parameters The second parameter set is the set of parameters included in the second flow specification rule ORF capability parameter.
本实施例中,第一网络设备作为流规范规则的发送端、流规范规则ORF记录的接收端,第二网络设备作为流规范规则的接收端、流规范规则ORF记录的发送端。当然,也可以第一网络设备作为流规范规则的接收端、流规范规则ORF记录的发送端,第二网络设备作为流规范规则的发送端、流规范规则ORF记录的接收端。也可以第一网络设备和第二网络设备同时作为流规范规则和流规范规则ORF记录的发送端和接收端。第一网络设备和第二网络设备的流规范规则ORF能力协商结果可能会有如下四种结果:(1)第一网络设备只发送至少一种类型的流规范规则对应的流规范规则ORF记录,第二网络设备只接收第一网络设备只发送的该至少一种类型的流规范规则对应的流规范规则ORF记录。(2)第一网络设备只接收至少一种类型流规范规则对应的流规范规则ORF记录,第二网络设备只发送第一网络设备能够接收的该至少一种类型的流规范规则对应的流规范规则ORF记录。(3)第一网络设备和第二网络设备都支持发送和接收至少一种类型流规范规则对应的流规范规则ORF记录。(4)协商不成功,第一网络设备和第二网络设备不能彼此散播流规范规则的ORF。In this embodiment, the first network device is used as the sending end of the flow specification rule, and the receiving end of the flow specification rule ORF record, and the second network device is used as the receiving end of the flow specification rule and the sending end of the flow specification rule ORF record. Of course, the first network device may be used as the receiving end of the flow specification rule, the sending end of the flow specification rule ORF record, and the second network device is used as the transmitting end of the flow specification rule and the receiving end of the flow specification rule ORF record. It is also possible that the first network device and the second network device simultaneously serve as a transmitting end and a receiving end of the flow specification rule and the flow specification rule ORF record. The flow specification rule ORF capability negotiation result of the first network device and the second network device may have the following four results: (1) the first network device only sends the flow specification rule ORF record corresponding to at least one type of flow specification rule, The second network device only receives the flow specification rule ORF record corresponding to the at least one type of flow specification rule sent by the first network device. (2) The first network device only receives the flow specification rule ORF record corresponding to the at least one type of flow specification rule, and the second network device sends only the flow specification corresponding to the at least one type of flow specification rule that the first network device can receive. Regular ORF record. (3) Both the first network device and the second network device support sending and receiving a flow specification rule ORF record corresponding to at least one type of flow specification rule. (4) If the negotiation is unsuccessful, the first network device and the second network device cannot spread the ORF of the flow specification rule to each other.
本实施例中,第一网络设备和第二网络设备支持或开启的流规范规则ORF能力应以其支持或开启的流规范规则的能力为基础,例如第一网络设备和第二网络设备仅在支持或开启IPv4流规范规则功能时,才能支持或开启IPv4流规范规则ORF功能。In this embodiment, the flow specification rule ORF capability supported or enabled by the first network device and the second network device should be based on the capability of the flow specification rule supported or enabled, for example, the first network device and the second network device are only in the The IPv4 flow specification rule ORF function can be supported or enabled when the IPv4 flow specification rule function is enabled or enabled.
步骤102、第一网络设备接收第二网络设备发送的流规范规则ORF记录,该流规范规则ORF记录用于第一网络设备对待发送给第二网络设备的流规范规则进行过滤。Step 102: The first network device receives a flow specification rule ORF record sent by the second network device, where the flow specification rule ORF records a flow specification rule used by the first network device to be sent to the second network device.
本实施例中,第二网络设备根据自身的流规范规则策略生成流规范规则ORF记录,该流规范规则策略可以是网络运维人员通过配置命令/网管或应用 程序通过设备开放接口(例如RESTful API Over Http)配置到第二网络设备中,该流规范规则策略是针对第一网络设备的特定类型流规范规则的过滤策略。In this embodiment, the second network device generates a flow specification rule ORF record according to its own flow specification rule policy, and the flow specification rule policy may be a network operation and maintenance personnel through a configuration command/network management or application. The program is configured into a second network device through a device open interface (eg, RESTful API Over Http), which is a filtering policy for a particular type of flow specification rule for the first network device.
本实施例中,流规范规则ORF类型需要对流规范规则中表达报文特征的过滤器集合做匹配,所以流规范规则ORF类型支持的过滤器类型和流规范规则支持的过滤器类型完全保持一致。例如流规范规则ORF类型支持的过滤器类型对应的报文特征元组包括:报文长度、报文的互联网协议(Internet Protocol,简称IP)头的目的IP地址、源IP地址、协议类型、差分服务代码点(Differentiated Services Code Point,简称DSCP)、分片标记(Fragment flag)、用户数据报协议(User Datagram Protocol,简称UDP)/传输控制协议(Transmission Control Protocol,简称TCP)的源端口、目的端口、TCP的Flag字段和互联网控制消息协议(Internet Control Message Protocol,简称ICMP)的Type字段和Code字段等。In this embodiment, the flow specification rule ORF type needs to match the filter set expressing the message characteristics in the flow specification rule, so the filter type supported by the flow specification rule ORF type and the filter type supported by the flow specification rule are completely consistent. For example, the packet feature tuple corresponding to the filter type supported by the flow specification rule ORF type includes: the packet length, the destination IP address of the Internet Protocol (IP) header, the source IP address, the protocol type, and the difference. Source port and destination of the Service Code Point (DSCP), the Fragment Flag, and the User Datagram Protocol (UDP)/Transmission Control Protocol (TCP) Port, TCP Flag field and Internet Control Message Protocol (ICMP) Type field and Code field.
针对本发明新添加的流规范规则ORF类型,需要定义一种新的ORF实体消息格式,用来携带流规范规则的过滤条件,本实施例新定义的流规范规则ORF记录的基础格式与现有的ORF[RFC5291]定义一致,并扩展了ORF记录的特定类型部分(Type specific part)字段。For the newly added flow specification rule ORF type of the present invention, a new ORF entity message format needs to be defined, which is used to carry the filter condition of the flow specification rule, and the basic format of the flow specification rule ORF record newly defined in this embodiment is existing. The ORF [RFC5291] definition is consistent and extends the Type specific part field of the ORF record.
图2为本发明实施例新定义的流规范规则ORF记录的格式,如图2所示,流规范规则ORF记录的格式包括如下字段:动作(Action)字段、匹配(Match)字段、保留(Reserved)字段和Type specific part字段。Action字段通常占用2比特,有三种取值,例如,可以用00表示添加(Add)操作,用01表示删除(Remove)操作,用10表示删除所有(Remove-all)操作。Match字段通常占用1比特,可以通过两个数值表示两种不同的含义,例如,用0表示允许(Permit),用1表示拒绝(Deny),当流规范规则ORF记录的Match字段的取值为0时,表示对满足过滤条件的流规范规则允许通过,当流规范规则ORF记录的Match字段的取值为1时,表示满足过滤条件的流规范规则不允许通过。Reserved字段发送端应将其填充为0,接收端应忽略该字段。2 is a format of a flow specification ORF record newly defined in the embodiment of the present invention. As shown in FIG. 2, the format of the flow specification rule ORF record includes the following fields: an Action field, a Match field, and a Reserved (Reserved). ) field and Type specific part field. The Action field usually takes 2 bits and has three values. For example, you can use 00 for the Add operation, 01 for the Remove operation, and 10 for the Remove-all operation. The Match field usually takes 1 bit and can represent two different meanings by two values. For example, 0 means Permit, 1 means Deny, and when the stream specification rule ORF records the value of the Match field. 0 indicates that the flow specification rule that satisfies the filter condition is allowed to pass. When the value of the Match field of the flow specification rule ORF record is 1, it indicates that the flow specification rule that satisfies the filter condition is not allowed to pass. The sender of the Reserved field shall pad it to 0, and the receiver shall ignore this field.
Type specific part字段为可变长字段,本实施例中,Type specific part字段包括:流规范规则ORF记录的序列号(Sequence)字段、行动匹配(Action Matching)字段、过滤器个数(Filter Number)字段、过滤器类型(Filter Type)字段、过滤器特定操作和取值字段。其中,Sequence字段可以占用4 字节,一般用于携带流规范规则ORF记录的优先级,也可以用于携带流规范规则ORF记录的ID或键值,第一网络设备在存储流规范规则ORF条目时,可以按照Sequence的顺序有序存储,后续在进行流规范规则匹配时,也优先将待匹配的流规范规则与优先级高的流规范规则ORF条目进行匹配。Filter Number字段可以占用8比特,用来携带流规范规则ORF记录中包括的过滤器的个数,一条流规范规则ORF记录中可以包括多个过滤器,也可以称为过滤器集合。Action Matching用于携带是否匹配流规范规则的动作类型,每种流规范规则的动作类型对应一个标记位,流规范规则的动作类型对应的标记位置1表示匹配该流规范规则的动作类型,流规范规则的动作类型对应的标记位置0表示不匹配该流规范规则的动作类型。一旦Action Matching字段某些标记位被置位,则在匹配过程中,需要检查被置位的标记位对应的流规范规则的动作类型是否都包含在在当前比较的流规范规则中都存在,如果被置位的标记位对应的流规范规则的动作类型中部分动作类型不在当前比较的流规范规则中,则当前比较的流规范规则没有匹配。Action Matching字段的值为0,即没有任何标记位被置位,表示待匹配流规范规则的动作类型集合为空,则默认所述动作类型的匹配结果为匹配。Action Matching的比特位表示的流规范规则的动作类型定义如表2所示,该定义随着流规范规则动作的类型的标准变更而变更,表2为常用的流规范规则的动作类型:The Type specific part field is a variable length field. In this embodiment, the Type specific part field includes: a sequence number (Sequence) field, an action matching (Action Matching) field, and a filter number (Filter Number) of the flow specification rule ORF record. Field, Filter Type field, filter specific action, and value field. Where the Sequence field can occupy 4 The byte is generally used to carry the priority of the flow specification rule ORF record, and can also be used to carry the ID or key value of the flow specification rule ORF record. When the first network device stores the flow specification rule ORF entry, it can follow the sequence of the sequence. In-order storage, when the flow specification rule is matched, the flow specification rule to be matched is preferentially matched with the flow specification rule ORF entry with higher priority. The Filter Number field can occupy 8 bits and is used to carry the number of filters included in the flow specification ORF record. A flow specification rule ORF record can include multiple filters, which can also be called a filter set. Action Matching is used to carry the action type that matches the flow specification rule. The action type of each flow specification rule corresponds to a tag bit, and the action position corresponding to the action type of the flow specification rule indicates that the action type matches the flow specification rule. The mark position 0 corresponding to the action type of the rule indicates the action type that does not match the flow specification rule. Once some of the flag bits of the Action Matching field are set, in the matching process, it is necessary to check whether the action type of the flow specification rule corresponding to the set flag bit is included in the currently compared flow specification rule, if If the part of the action type of the flow specification rule corresponding to the set flag bit is not in the currently compared flow specification rule, the currently compared flow specification rule does not match. The value of the Action Matching field is 0, that is, no flag bit is set, indicating that the action type set of the flow specification rule to be matched is empty, and the matching result of the action type is matched by default. The action type definition of the flow specification rule represented by the bit of the Action Matching is as shown in Table 2. The definition is changed according to the standard change of the type of the flow specification rule action. Table 2 is the action type of the commonly used flow specification rule:
表2Table 2
Figure PCTCN2016075632-appb-000002
Figure PCTCN2016075632-appb-000002
通过表2可知,当Action Matching的bit 0置位时,表示要匹配的流规范规则的动作类型为traffic-rate(流限速),当Action Matching的bit 1置位时,表示要匹配的流规范规则的动作类型为traffic-action(流动作),当Action Matching的bit 2置位时,表示要匹配的流规范规则的动作类型为redirect(重定向),当Action Matching的bit 3置位时,表示要匹配的流规范规则的动作类型为traffic-marking(流标记)。上述四种流规范规则的动作类型的具体定义可以参照RFC5575,这里不做详细说明。 Table 2 shows that when the action matching bit 0 is set, the action type of the flow specification rule to be matched is traffic-rate. When the bit 1 of the Action Matching is set, the flow to be matched is indicated. The action type of the canonical rule is traffic-action. When the bit 2 of the Action Matching is set, the action type of the flow specification rule to be matched is redirect. When the bit 3 of the Action Matching is set. , indicating that the action type of the flow specification rule to be matched is traffic-marking. The specific definition of the action types of the above four flow specification rules can be referred to RFC5575, and will not be described in detail herein.
需要说明的时,本实施例中,流规范规则ORF记录中还可以包括更多或者更少的字段,例如,流规范规则ORF记录可以没有Filter Number字段,当SAFI取值为134(表示VPN流规范规则ORF记录)时,流规范规则ORF记录还包括:路由标识个数(RD number:Route Distinguisher,简称RD)字段和路由标识字段,RD number字段用于携带RD的个数,RD字段用于携带路由标识,RD字段可以携带多个RD。当SAFI的取值为其他时,流规范规则ORF记录中不包括RD number字段和RD字段。并且流规范规则ORF记录的各个字段的顺序可以调整,图2所示的只是一种可能的格式,并且每个字段的长度本实施例也不做限制。In the embodiment, the flow specification rule ORF record may further include more or less fields. For example, the flow specification rule ORF record may have no Filter Number field, and the SAFI value is 134 (representing the VPN flow) The ORF record also includes: the number of the route identifier (RD number: Route Distinguisher, RD for short) field and the route identifier field, the RD number field is used to carry the number of RDs, and the RD field is used for the rule ORF record. Carrying a route identifier, the RD field can carry multiple RDs. When the value of SAFI is other, the RD number field and the RD field are not included in the flow specification rule ORF record. And the order of the fields of the flow specification rule ORF record can be adjusted, and only one possible format is shown in FIG. 2, and the length of each field is not limited in this embodiment.
过滤器类型字段用于携带过滤器类型,本实施例中,流规范规则ORF记录的Filter Type与现有的流规范规则的Filter Type的定义保持一致,并且大部分流规范规则ORF记录和流规范规则的过滤器特定操作和取值的格式定义也保持一致。仅几种流规范规则ORF记录的Filter Type的过滤器特定操作和取值的格式定义(具体表现在表3中的4种Filter Type对应的过滤器)与流规范规则的过滤器特定操作和取值的格式定义不一样。The filter type field is used to carry the filter type. In this embodiment, the Filter Type of the flow specification rule ORF record is consistent with the definition of the Filter Type of the existing flow specification rule, and most of the flow specification rules ORF record and flow specification The filter-specific actions and the format definition of the values are also consistent. Only a few flow specification rules ORF record Filter Type filter specific operation and value format definition (specifically the filter corresponding to the four Filter Types in Table 3) and filter specification rules filter specific operations and take The format definition of the value is different.
表3table 3
Figure PCTCN2016075632-appb-000003
Figure PCTCN2016075632-appb-000003
表3中的4种Filter Type都是前缀类型的Filter Type,Type 1用于对流规范规则的目的IP地址前缀进行匹配,该目的IP地址可以为IPv4或IPv6类型(例如流规范规则ORF记录对应AFI为1时,该过滤器类型为IPv4目的地址前缀过滤器),Type 2用于对流规范规则的源IP地址前缀进行匹配,该源IP地址可以为IPv4或IPv6类型,Type 14用于对流规范规则的目的MAC前缀进行匹配,Type 15用于对流规范规则的源MAC前缀进行匹配。The four Filter Types in Table 3 are all Filter Types of the prefix type. Type 1 is used to match the destination IP address prefix of the flow specification rule. The destination IP address can be of IPv4 or IPv6 type (for example, the flow specification rule ORF record corresponds to AFI). When the value is 1, the filter type is the IPv4 destination address prefix filter. Type 2 is used to match the source IP address prefix of the flow specification rule. The source IP address can be IPv4 or IPv6, and Type 14 is used for the flow specification rule. The destination MAC prefix is matched, and Type 15 is used to match the source MAC prefix of the flow specification rule.
表3中的4种Filter Type对应的Filter格式定义如图3所示,图3为本实施例提供的四种Filter Type对应的Filter的格式,Filter的格式包括如下字段:Filter Type字段、匹配前缀的最大长度(MaxLen)、匹配前缀的最小长度(MinLen)、匹配前缀的实际长度Length和匹配前缀(Prefix),其 中,MaxLen、MinLen、Length、Prefix字段的定义和RFC5292中相同字段的定义一致,这里不做详细描述。当Filter为IPv4的源地址前缀或目的地址前缀过滤器时,MaxLen不大于32,当Filter为IPv6的源地址前缀或目的地址前缀过滤器时,MaxLen不大于128。The definition of the Filter format corresponding to the four Filter Types in Table 3 is as shown in FIG. 3. FIG. 3 is a format of a Filter corresponding to the four Filter Types provided by the embodiment. The format of the Filter includes the following fields: a Filter Type field and a matching prefix. Maximum length (MaxLen), minimum length of matching prefix (MinLen), actual length of matching prefix, and matching prefix (Prefix), The definitions of the MaxLen, MinLen, Length, and Prefix fields are consistent with the definitions of the same fields in RFC5292, and are not described in detail here. When Filter is the source address prefix or destination address prefix filter of IPv4, MaxLen is not greater than 32. When Filter is the source address prefix or destination address prefix filter of IPv6, MaxLen is not greater than 128.
对于表3中的4种Filter Type,流规范规则ORF记录的过滤器特定操作和取值字段为MaxLen、MinLen、Length、Prefix字段的集合,流规范规则的过滤器特定操作和取值字段为Length、Prefix字段的集合。For the four Filter Types in Table 3, the filter-specific rules and value fields of the flow specification rule ORF record are the collection of MaxLen, MinLen, Length, and Prefix fields. The filter-specific operation and value field of the flow specification rule are Length. , a collection of Prefix fields.
除了上述4中Filter Type,Filter Type还可以包括:In addition to the above 4 Filter Type, the Filter Type can also include:
Type3:IP协议,用于用流规范规则报文的协议类型进行匹配。Type3: IP protocol, used to match the protocol type of the flow specification rule message.
Type4:端口,用于对流规范规则报文的源端口和目的端口进行匹配。Type 4: Port used to match the source port and destination port of the flow specification packet.
Type5:目的端口,用于对流规范规则报文的目的端口进行匹配。Type 5: Destination port, used to match the destination port of the flow specification rule packet.
Type6:源端口,用于对流规范规则报文的源端口进行匹配。Type6: Source port, used to match the source port of the flow specification rule packet.
Type7:ICMP type,用于对流规范规则报文的ICMP type字段进行匹配。Type7: ICMP type, used to match the ICMP type field of the flow specification rule packet.
Type 8:ICMP code,用于对流规范规则报文的ICMP code字段进行匹配。Type 8: ICMP code, used to match the ICMP code field of the flow specification rule message.
Type 9:TCP Flags,用于对流规范规则报文的TCP Flags字段进行匹配。Type 9: TCP Flags, used to match the TCP Flags field of the flow specification rule message.
Type 10:包长(Packet length),用于对流规范规则报文的总长度进行匹配。Type 10: Packet length, used to match the total length of the flow specification rule message.
Type11:DSCP,用于对流规范规则报文的DSCP字段进行匹配。Type11: DSCP is used to match the DSCP field of the flow specification rule packet.
Type12:Fragment,用于对流规范规则报文的掩码比特格式进行匹配。Type12: Fragment, used to match the mask bit format of the flow specification rule message.
对于表3所示的4种Filter Type,流规范规则ORF记录和流规范规则的对应过滤器特定操作和取值字段为至少一个包含选项(option)字段和该选项字段对应的取值(value)字段的二元组的集合。For the four Filter Types shown in Table 3, the corresponding filter-specific operations and value fields of the flow specification rule ORF record and the flow specification rule are at least one of the option field and the value corresponding to the option field. A collection of two-tuple fields.
具体应用时,流规范规则ORF记录可以用来表示第二网络设备支持流规范规则的具体能力或某种安全策略。例如,传统的路由器和三层(L3)交换机会采用硬件的方式实现转发信息表FIB时,例如用三元内容可寻址存储器(Ternary Content Addressable Memory,简称TCAM)或专用集成电路(Application Specific Integrated Circuit,简称ASIC)实现FIB,一般可以支持IPv4/IPv6访问控制列表(Access Control List,简称ACL)和二层(L2)ACL,但这类网络设备的转发面一般不支持对ICMP的Type、Code字段的匹配。而虚拟路由器(vRouter)或一些新的转发设备支持流规范规则的匹配元组会全面些。所以不同网络设备即使都开启了流规范规则功能,其支 持的流规范规则Filter和Action Type也可能存在差异。针对这种情况,网络设备可以生成流规范规则ORF记录来表达该网络设备支持流规范规则的具体能力差异,并将其通告给自己的BGP对等体,避免从这些BGP对等体收到自己不完全支持的流规范规则。For specific applications, the flow specification rule ORF record can be used to indicate the specific capability or some security policy of the second network device to support the flow specification rule. For example, a conventional router and a three-layer (L3) switch implement a forwarding information table FIB in a hardware manner, for example, a Ternary Content Addressable Memory (TCAM) or an application specific integrated circuit (Application Specific Integrated). Circuits (referred to as ASICs) implement FIB. Generally, they can support IPv4/IPv6 Access Control List (ACL) and Layer 2 (L2) ACLs. However, the forwarding planes of such network devices generally do not support ICMP Types and Codes. Match of fields. The matching tuples of the virtual router (vRouter) or some new forwarding devices that support the flow specification rules are more comprehensive. Therefore, even if different network devices have the flow specification rule function enabled, their support The flow specification rules Filter and Action Type may also differ. In this case, the network device can generate a flow specification rule ORF record to express the specific capability difference of the network device supporting the flow specification rule, and advertise it to its own BGP peer to avoid receiving the BGP peer from the BGP peer. Flow specification rules that are not fully supported.
假设第二网络设备不支持对流规范规则ICMP报文的Code和Type字段匹配时,第二网络设备生成的两条流规范规则ORF条目将会拒绝(Deny)掉包含匹配任何ICMP Code或Type字段值的过滤器的流规范规则。第二网络设备生成该流规范规则ORF记录后,向第一网络设备发送该流规范规则ORF记录,该流规范规则ORF记录用于第一网络设备对发送给第二网络设备的流规范规则进行过滤。第二网络设备将该流规范规则ORF记录包含在BGP路由刷新(ROUTE-REFRESH)消息中发送给第一网络设备。Assuming that the second network device does not support the matching of the Code and Type fields of the ICMP packet of the traffic specification rule, the two stream specification rule ORF entries generated by the second network device will be rejected (Deny) containing any matching ICMP Code or Type field values. The flow specification rules for the filter. After generating the flow specification rule ORF record, the second network device sends the flow specification rule ORF record to the first network device, where the flow specification rule ORF record is used by the first network device to perform flow specification rules sent to the second network device. filter. The second network device sends the flow specification rule ORF record in a BGP Route Refresh (ROUTE-REFRESH) message to the first network device.
图4为携带拒绝任何匹配ICMP Type取值的过滤器的IPv4流规范规则ORF记录A的一种报文内容示例,图5为携带拒绝任何匹配ICMP Code取值的过滤器的IPv4流规范规则ORF记录B的一种报文内容示例。如图4所示,流规范规则ORF记录A的报文的字段依次为:2比特的Action字段、1比特的Match字段、32比特的Sequence字段、8比特的Filter Number字段、32比特的Action Matching字段、8比特的Filter Type字段、8比特的第一选项字段(op1)、8比特的第一取值字段(value1),8比特的第二选项字段(op2)和8特比的第二取值字段(value2)。其中,Action字段的Action字段的取值为Add,Add对应的枚举值为0;Match字段的取值为Deny,Deny对应的枚举值为1,Sequence字段的取值为1;Filter Number字段的取值为1,表示该流规范规则ORF记录中只有一个Filter;Action Matching字段的取值为0,表示不匹配任何流规范规则的动作类型,Filter Type字段的取值为ICMP Type,ICMP Type对应的枚举值可以为7,op1的取值为0x03,value1的取值为0x00,表示ICMP Type的值大于或等于0,op2的取值为0xc5,value2的取值为0xff,表示ICMP Type的值小于或等于255(即该流规范规则ORF记录包括的“ICMP Type”类型过滤器的过滤器特定操作和取值字段的数值空间为0到255)。图5中Pv4流规范规则ORF记录B包含的“ICMP Code”类型过滤器和图4中Pv4流规范规则ORF记录A包含的“ICMP Type”类型过滤器的格式定义相同,此处不再描述。-4 is an example of a packet content carrying an IPv4 flow specification rule ORF record A that rejects any filter matching the ICMP Type value, and FIG. 5 is an IPv4 flow specification rule ORF carrying a filter that rejects any matching ICMP Code value. An example of a message content of record B. As shown in FIG. 4, the fields of the packet of the flow specification rule ORF record A are: 2-bit Action field, 1-bit Match field, 32-bit Sequence field, 8-bit Filter Number field, 32-bit Action Matching Field, 8-bit Filter Type field, 8-bit first option field (op1), 8-bit first value field (value1), 8-bit second option field (op2) and 8-bit second ratio Value field (value2). The Action field of the Action field has the value of Add, the corresponding enumeration value is 0; the value of the Match field is Deny, the enumeration value of Deny is 1, and the value of the Sequence field is 1; the Filter Number field The value of 1 indicates that there is only one Filter in the ORF record of the flow specification rule; the value of the Action Matching field is 0, indicating that the action type of any flow specification rule does not match. The value of the Filter Type field is ICMP Type, ICMP Type. The corresponding enumeration value can be 7, the value of op1 is 0x03, the value of value1 is 0x00, indicating that the value of ICMP Type is greater than or equal to 0, the value of op2 is 0xc5, and the value of value2 is 0xff, indicating ICMP Type. The value of the filter-specific operation and value field of the "ICMP Type" type filter included in the flow specification rule ORF record is 0 to 255. The format of the "ICMP Code" type filter included in the ORF record B of the Pv4 stream specification rule in FIG. 5 is the same as the format definition of the "ICMP Type" type filter included in the ORF record A of FIG. 4, and will not be described here. -
可选的,第一网络设备接收第二网络设备发送的流规范规则ORF记录之 后,第一网络设备还可以根据流规范规则ORF记录中包括的AFI和SAFI确定流规范规则ORF记录的类型,并根据流规范规则ORF记录的序列号将流规范规则ORF记录有序地存储到对应类型的流规范规则ORF列表中。例如,假设共有两种类型的流规范规则ORF列表,分别用于存储AFI=1,SAFI=133的IPv4流规范规则ORF记录、AFI=1,SAFI=134的VPNv4流规范规则ORF记录。每种类型的流规范规则ORF列表中按照流规范规则ORF记录的序列号有序存储流规范规则ORF记录。Optionally, the first network device receives the flow specification rule ORF record sent by the second network device. After that, the first network device may further determine the type of the flow specification rule ORF record according to the AFI and SAFI included in the flow specification rule ORF record, and store the flow specification rule ORF record in an orderly manner according to the sequence number of the flow specification rule ORF record. The corresponding type of flow specification is in the ORF list. For example, suppose there are two types of flow specification rule ORF lists, which are used to store AFI=1, SAFI=133 IPv4 flow specification rule ORF record, AFI=1, SAFI=134 VPNv4 flow specification rule ORF record. Each type of flow specification rule ORF list stores the sequence specification ORF record according to the sequence number of the stream specification rule ORF.
步骤103、第一网络设备根据流规范规则ORF记录对待发送给第二网络设备的流规范规则进行过滤。Step 103: The first network device records, according to the flow specification rule ORF, a flow specification rule to be sent to the second network device.
当第一网络设备有流规范规则向第二网络设备发送时,第一网络设备查询第二网络设备发送过来的流规范规则ORF记录,对待发送给第二网络设备的流规范规则进行匹配过滤处理。不同类型的流规范规则ORF记录存储在不同的流规范规则ORF列表中,在匹配前,第一网络设备首先根据待发送给第二网络设备的流规范规则的AFI和SAFI确定待发送给第二网络设备的流规范规则的类型,查询对应类型流规范规则ORF列表,依次用流规范规则ORF列表中的流规范规则ORF记录和待发送给第二网络设备的流规范规则进行匹配,最先匹配的流规范规则ORF记录生效。在匹配成功后,根据匹配到的流规范规则ORF记录的匹配字段指示的动作(允许或决绝)决定是否向第二网络设备发送待发送给第二网络设备的流规范规则。如果匹配字段指示的动作为允许,则第一网络设备将待发送给第二网络设备的流规范规则发送给第二网络设备,如果匹配字段指示的动作为拒绝,则第一网络设备将待发送给第二网络设备的流规范规则过滤掉,不会发送给第二网络设备。When the first network device sends the flow specification rule to the second network device, the first network device queries the flow specification rule ORF record sent by the second network device, and performs matching filtering processing on the flow specification rule to be sent to the second network device. . Different types of flow specification rules ORF records are stored in different flow specification rule ORF lists. Before matching, the first network device first determines to be sent to the second according to the AFI and SAFI of the flow specification rules to be sent to the second network device. The type of the flow specification rule of the network device, query the corresponding type flow specification rule ORF list, and then use the flow specification rule ORF record in the flow specification rule ORF list to match the flow specification rule to be sent to the second network device, and match first. The flow specification rules ORF records take effect. After the matching is successful, the action indicated by the matching field recorded by the matched ORF specification rule ORF (allow or deny) determines whether to send the flow specification rule to be sent to the second network device to the second network device. If the action indicated by the matching field is allowed, the first network device sends the flow specification rule to be sent to the second network device to the second network device, and if the action indicated by the matching field is rejected, the first network device is to be sent. The flow specification rules for the second network device are filtered out and are not sent to the second network device.
本实施例中,第一网络设备要发送给第二网络设备的待发送流规范规则可能是其他网络设备发送给第一网络设备的,也可能是第一网络设备根据配置自己生成的。In this embodiment, the to-be-sent flow specification rule that the first network device sends to the second network device may be sent by the other network device to the first network device, or may be generated by the first network device according to the configuration.
在对每一条流规范规则ORF记录进行匹配时,第一网络设备将流规范规则ORF记录包括的:Action Matching字段、Filter Type字段、过滤器特定操作和取值字段,分别与待发送给第二网络设备的流规范规则包括的:Action Type字段、Filter Type字段、过滤器特定操作和取值字段进行比较。若流规范规则ORF记录包括的Action Matching字段所指示的要匹配的动作类型集合为空(即Action Matching字段的值为0)或流规范规则ORF记录包括的 Action Matching字段所指示的要匹配的动作类型都包含在待发送给第二网络设备的流规范规则包括的动作类型中,流规范规则ORF记录包括的过滤器集合为空或流规范规则ORF记录包括的每种过滤器类型的过滤器特定操作和取值字段的数值空间都包含待发送给第二网络设备的流规范规则包括的过滤器类型的过滤器特定操作和取值字段的数值空间,则第一网络设备确定待发送给第二网络设备的流规范规则匹配该流规范规则ORF记录。When matching each flow specification rule ORF record, the first network device records the flow specification rule ORF record: an Action Matching field, a Filter Type field, a filter specific operation, and a value field, respectively, to be sent to the second The flow specification rules of the network device include: an Action Type field, a Filter Type field, a filter specific operation, and a value field for comparison. If the flow specification rule ORF record includes an Action Matching field indicating that the set of action types to match is empty (ie, the value of the Action Matching field is 0) or the flow specification rule ORF record includes The action type indicated by the Action Matching field to be matched is included in the action type included in the flow specification rule to be sent to the second network device, and the flow specification rule ORF record includes the filter set as empty or the flow specification rule ORF record includes The value space of the filter-specific operation and value field for each filter type contains the value space of the filter-specific operation and value field of the filter type to be sent to the flow specification rule of the second network device. The first network device determines that the flow specification rule to be sent to the second network device matches the flow specification rule ORF record.
当流规范规则ORF记录的Type specific part字段包括RD字段时,第一网络设备根据流规范规则ORF记录对待发送的流规范规则进行过滤,具体为:第一网络设备将流规范规则ORF记录包括的:Action Matching字段、Filter Type字段、过滤器特定操作和取值字段、RD字段,分别与待发送给第二网络设备的流规范规则包括的:Action Type字段、Filter Type字段、过滤器特定操作和取值字段、RD字段进行比较。若流规范规则ORF记录包括的Action Matching字段所指示的要匹配的动作类型集合为空或流规范规则ORF记录包括的Action Matching字段所指示的要匹配的动作类型都包含在待发送给第二网络设备的流规范规则包括的动作类型中,流规范规则ORF记录包括的过滤器集合为空或流规范规则ORF记录包含的每种过滤器类型的过滤器特定操作和取值字段的数值空间都包含待发送给第二网络设备的流规范规则包括的过滤器类型的过滤器特定操作和取值字段的数值空间,流规范规则ORF记录包括的RD组成的路由标识集合为空或该路由标识集合中包含待发送给第二网络设备的流规范规则包括的RD,则第一网络设备确定待发送给第二网络设备的流规范规则匹配该流规范规则ORF记录。When the Type specific part field of the flow specification rule ORF record includes the RD field, the first network device filters the flow specification rule to be sent according to the flow specification rule ORF, specifically: the first network device includes the flow specification rule ORF record. The Action Matching field, the Filter Type field, the filter specific operation and the value field, and the RD field are respectively included in the flow specification rule to be sent to the second network device: an Action Type field, a Filter Type field, a filter specific operation, and The value field and the RD field are compared. If the action type specified by the Action Matching field included in the flow specification rule ORF record is set to be empty or the flow specification rule ORF record includes the action type indicated by the Action Matching field to be matched, the action type to be matched is included in the second network to be sent. Among the action types included in the flow specification rule of the device, the flow specification rule ORF record includes a filter set that is empty or the flow specification rule ORF records contain filter-specific operations and the value space of each value field contains The flow specification rule of the filter type to be sent to the second network device includes a filter-specific operation and a value space of the value field, and the flow specification rule ORF record includes a set of route identifiers consisting of RDs or is in the route identifier set. And including the RD included in the flow specification rule to be sent to the second network device, the first network device determines that the flow specification rule to be sent to the second network device matches the flow specification rule ORF record.
步骤104、第一网络设备向第二网络设备发送过滤后的流规范规则。Step 104: The first network device sends the filtered flow specification rule to the second network device.
具体地,第一网络设备可以将过滤后的流规范规则携带在BGP更新(UPDATE)消息中发送给第二网络设备,当然,第一网络设备也可以将过滤后的流规范规则携带在其他消息中发送给第二网络设备,本实施例并不对此进行限制。Specifically, the first network device may send the filtered flow specification rule to the second network device in the BGP update (UPDATE) message. Of course, the first network device may also carry the filtered flow specification rule in other messages. The method is sent to the second network device, which is not limited in this embodiment.
本实施例中,第一网络设备在确定第二网络设备能够向第一网络设备发送流规范规则出站路由过滤ORF记录之后,接收第二网络设备发送的流规范规则ORF记录,流规范规则ORF记录用于第一网络设备对待发送给第二网络设备的流规范规则进行过滤,当第一网络设备有流规范规则发送给第二网络设备时,第一网络设备根据流规范规则ORF记录对待发送的流规范规则进行 过滤,只向第二网络设备发送满足流规范规则ORF记录过滤条件的流规范规则,解决了网络设备发送大量无效的流规范规则,造成的资源浪费的问题。In this embodiment, after determining that the second network device can send the flow specification rule outbound route filtering ORF record to the first network device, the first network device receives the flow specification rule ORF record sent by the second network device, and the flow specification rule ORF Recording a flow specification rule for the first network device to send to the second network device, when the first network device has a flow specification rule sent to the second network device, the first network device records the ORF according to the flow specification rule Flow specification rules Filtering, only the flow specification rule that satisfies the flow specification rule ORF record filtering condition is sent to the second network device, which solves the problem that the network device sends a large number of invalid flow specification rules, resulting in waste of resources.
图6为本发明实施例二提供的接收流规范规则的方法的流程图,本实施例从第二网络设备的角度描述,如图6所示,本实施例提供的方法可以包括以下步骤:FIG. 6 is a flowchart of a method for receiving a flow specification rule according to Embodiment 2 of the present invention. This embodiment is described from the perspective of a second network device. As shown in FIG. 6, the method provided in this embodiment may include the following steps:
步骤201、第二网络设备确定第一网络设备能够接收流规范规则ORF记录。Step 201: The second network device determines that the first network device is capable of receiving the flow specification rule ORF record.
具体可通过如下方式确定:首先,第二网络设备获取第二流规范规则ORF能力参数,该第二流规范规则ORF能力参数指示第一网络设备支持的流规范规则ORF能力,该第二流规范规则ORF能力参数包括:至少一组由AFI、SAFI、流规范规则ORF类型和收发能力标识组成的参数集合,该第二流规范规则ORF能力参数中包括的收发能力标识用于指示第一网络设备是否支持发送和/或接收流规范规则ORF记录。其中,第二网络设备获取该第二流规范规则ORF能力参数,具体为:第二网络设备在与第一网络设备建立BGP连接过程中,接收第一网络设备发送的BGP OPEN消息,第一网络设备发送的BGP OPEN消息中包括该第二流规范规则ORF能力参数。Specifically, the second network device obtains a second flow specification rule ORF capability parameter, where the second flow specification rule ORF capability parameter indicates a flow specification rule ORF capability supported by the first network device, and the second flow specification The rule ORF capability parameter includes: at least one set of parameters consisting of AFI, SAFI, flow specification rule ORF type, and transceiver capability identifier, and the transceiver capability identifier included in the second flow specification rule ORF capability parameter is used to indicate the first network device. Whether to support sending and/or receiving flow specification rules ORF records. The second network device obtains the second flow specification rule ORF capability parameter, where the second network device receives the BGP OPEN message sent by the first network device in the process of establishing a BGP connection with the first network device, where the first network The BGP OPEN message sent by the device includes the second flow specification rule ORF capability parameter.
然后,第二网络设备比较第二流规范规则ORF能力参数与第一流规范规则ORF能力参数,该第一流规范规则ORF能力参数指示第二网络设备支持的流规范规则ORF能力,第一流规范规则ORF能力参数包括:至少一组由AFI、SAFI、流规范规则ORF类型和收发能力标识组成的参数集合,该第一流规范规则ORF能力参数中包括的收发能力标识用于指示第二网络设备是否支持发送和/或接收流规范规则ORF记录。Then, the second network device compares the second flow specification rule ORF capability parameter with the first flow specification rule ORF capability parameter, the first flow specification rule ORF capability parameter indicates a flow specification rule ORF capability supported by the second network device, and the first flow specification rule ORF The capability parameter includes: a set of parameters consisting of the AFI, the SAFI, the flow specification rule ORF type, and the transceiver capability identifier, where the transceiver capability identifier included in the first flow specification rule ORF capability parameter is used to indicate whether the second network device supports sending And/or receive flow specification rules ORF records.
若第一流规范规则ORF能力参数包含的第一参数集合和第二流规范规则ORF能力参数包含的第二参数集合都包含流规范规则ORF类型,第一参数集合和所述第二参数集合包含相同的AFI和SAFI,并且第一参数集合的收发能力标识指示第二网络设备支持发送流规范规则ORF记录,第二参数集合的收发能力标识指示第一网络设备支持接收流规范规则ORF记录,则第二网络设备确定能够向第一网络设备发送流规范规则ORF记录。If the first parameter set included in the first flow specification rule ORF capability parameter and the second parameter set included in the second flow specification rule ORF capability parameter both contain a flow specification rule ORF type, the first parameter set and the second parameter set include the same AFI and SAFI, and the transceiver capability identifier of the first parameter set indicates that the second network device supports the transmission flow specification rule ORF record, and the transceiver capability identifier of the second parameter set indicates that the first network device supports the receive flow specification rule ORF record, then The second network device determines that the flow specification rule ORF record can be sent to the first network device.
本步骤的具体实现方式可参照实施例一的相关描述,这里不再赘述。For a specific implementation of this step, reference may be made to the related description of Embodiment 1, and details are not described herein again.
步骤202、第二网络设备根据自身的流规范规则策略生成流规范规则ORF记录。Step 202: The second network device generates a flow specification rule ORF record according to its own flow specification rule policy.
其中,流规范规则ORF记录包括:Action字段、Match字段、Reserved 字段和Type specific part字段,其中,Type specific part字段包括:流规范规则ORF记录的Sequence字段、Action Matching字段、Filter Type字段、过滤器特定操作和取值字段,Sequence字段用于携带流规范规则ORF记录的优先级,Action Matching字段用于携带是否匹配流规范规则的Action Type,Filter Type字段用于携带Filter Type,过滤器特定操作和取值字段用于携带Filter Type对应的过滤条件。可选的,Type specific part字段还可以包括Filter Number字段,Filter Number字段用于携带过滤器的个数。The flow specification rule ORF record includes: Action field, Match field, Reserved a field and a Type specific part field, where the Type specific part field includes: a Sequence field of the flow specification rule ORF record, an Action Matching field, a Filter Type field, a filter specific operation and a value field, and a Sequence field is used to carry the flow specification rule ORF The priority of the record. The Action Matching field is used to carry the Action Type that matches the flow specification rule. The Filter Type field is used to carry the Filter Type. The filter specific operation and the value field are used to carry the filter condition corresponding to the Filter Type. Optionally, the Type specific part field may further include a Filter Number field, where the Filter Number field is used to carry the number of filters.
当SAFI为134时,Type specific part字段还包括:RD Number字段和:RD字段。When the SAFI is 134, the Type specific part field further includes: an RD Number field and an RD field.
本步骤的具体实现方式可参照实施例一的相关描述,这里不再赘述。For a specific implementation of this step, reference may be made to the related description of Embodiment 1, and details are not described herein again.
步骤203、第二网络设备将流规范规则ORF记录发送给第一网络设备。Step 203: The second network device sends the flow specification rule ORF record to the first network device.
第二网络设备通过将流规范规则ORF记录发送给第一网络设备,以使第一网络设备根据流规范规则ORF记录对待发送给第二网络设备的流规范规则进行过滤。The second network device transmits the flow specification rule ORF record to the first network device, so that the first network device records the flow specification rule to be sent to the second network device according to the flow specification rule ORF.
步骤204、第二网络设备接收第一网络设备发送的流规范规则,该流规范规则为第一网络设备根据流规范规则ORF记录过滤后的流规范规则。Step 204: The second network device receives a flow specification rule sent by the first network device, where the flow specification rule is that the first network device records the filtered flow specification rule according to the flow specification rule ORF.
本实施例中,第二网络设备确定能够向第一网络设备发送流规范规则出站ORF记录后,根据自身的流规范规则策略生成流规范规则ORF记录,并将流规范规则ORF记录发送给第一网络设备,第一网络设备根据第二网络设备发送的流规范规则ORF记录对待发送给第二网络设备的流规范规则进行过滤,只向第二网络设备发送满足流规范规则过滤条件的流规范规则,解决了网络设备发送大量无效的流规范规则,造成的资源浪费的问题。In this embodiment, after the second network device determines that the flow specification rule outbound ORF record can be sent to the first network device, the flow specification rule ORF record is generated according to the flow specification rule policy, and the flow specification rule ORF record is sent to the first a network device, the first network device records, according to the flow specification rule ORF sent by the second network device, the flow specification rule to be sent to the second network device, and only sends the flow specification that meets the flow specification rule filtering condition to the second network device. The rule solves the problem of waste of resources caused by the network device sending a large number of invalid flow specification rules.
图7为本发明实施例三提供的第一网络设备的结构示意图,如图7所示,本实施例提供的网络设备包括:确定模块11、接收模块12、过滤模块13和发送模块14。FIG. 7 is a schematic structural diagram of a first network device according to Embodiment 3 of the present invention. As shown in FIG. 7, the network device provided in this embodiment includes: a determining module 11, a receiving module 12, a filtering module 13, and a sending module 14.
其中,确定模块11,用于确定第二网络设备能够向所述第一网络设备发送流规范规则ORF记录;The determining module 11 is configured to determine that the second network device can send the flow specification rule ORF record to the first network device.
接收模块12,用于接收所述第二网络设备发送的所述流规范规则ORF记录,所述流规范规则ORF记录用于所述第一网络设备对待发送给所述第二网络设备的流规范规则进行过滤;The receiving module 12 is configured to receive the flow specification rule ORF record sent by the second network device, where the flow specification rule ORF records a flow specification used by the first network device to be sent to the second network device Rules are filtered;
过滤模块13,用于根据所述流规范规则ORF记录对待发送给所述第二网 络设备的流规范规则进行过滤;a filtering module 13 configured to send, according to the flow specification rule, an ORF record to the second network Filtering the flow specification rules of the network device;
发送模块14,用于向所述第二网络设备发送过滤后的流规范规则。The sending module 14 is configured to send the filtered flow specification rule to the second network device.
所述流规范规则ORF记录包括:流规范规则ORF记录的序列号字段、行动匹配字段、过滤器类型字段和过滤器特定操作和取值字段,所述流规范规则ORF记录的序列号字段用于携带流规范规则ORF记录的优先级,所述行动匹配字段用于携带是否匹配流规范规则的动作类型,所述过滤器类型字段用于携带过滤器类型,所述过滤器特定操作和取值字段用于携带所述过滤器类型对应的过滤条件。可选的,所述流规范规则ORF记录还包括:过滤器个数字段,所述过滤器个数字段用于携带过滤器的个数。The flow specification rule ORF record includes: a sequence number field of the flow specification rule ORF record, an action matching field, a filter type field, and a filter specific operation and value field, and the sequence number field of the flow specification rule ORF record is used for Carrying a priority of the flow specification rule ORF record, the action matching field is used to carry an action type that matches whether the flow specification rule is used, and the filter type field is used to carry a filter type, the filter specific operation and the value field It is used to carry the filter condition corresponding to the filter type. Optionally, the flow specification rule ORF record further includes: a filter number field, where the filter number field is used to carry the number of filters.
所述过滤模块13具体用于:将所述流规范规则ORF记录包括的:行动匹配字段、过滤器类型字段、过滤器特定操作和取值字段,分别与所述待发送的流规范规则包括的:动作类型字段、过滤器类型字段、过滤器特定操作和取值字段进行比较;若所述流规范规则ORF记录包括的行动匹配字段所指示的要匹配的动作类型集合为空或所述要匹配的动作类型都包含在所述待发送给所述第二网络设备的流规范规则包括的动作类型中,所述流规范规则ORF记录包括的过滤器集合为空或每种过滤器类型的过滤器特定操作和取值字段的数值空间都包含所述待发送给所述第二网络设备的流规范规则包括的过滤器类型的过滤器特定操作和取值字段的数值空间,则确定所述待发送给所述第二网络设备的流规范规则匹配所述流规范规则ORF记录。The filtering module 13 is specifically configured to: include, by the flow specification rule ORF record, an action matching field, a filter type field, a filter specific operation, and a value field, respectively, and the flow specification rule to be sent : an action type field, a filter type field, a filter specific operation, and a value field are compared; if the action specification field included in the flow specification rule ORF record indicates that the set of action types to be matched is empty or the match is to be matched The action types are all included in the action type included in the flow specification rule to be sent to the second network device, the flow specification rule ORF record includes a filter set that is empty or a filter of each filter type The value space of the specific operation and the value field includes the value space of the filter-specific operation and the value field of the filter type to be sent to the flow specification rule of the second network device, and then the to-be-sent is determined. A flow specification rule for the second network device matches the flow specification rule ORF record.
可选的,所述流规范规则ORF记录还包括:路由标识个数字段和路由标识字段,所述路由标识个数字段用于携带路由标识的个数,所述路由标识字段用于携带路由标识。Optionally, the flow specification rule ORF record further includes: a route identifier number field and a route identifier field, where the route identifier number field is used to carry the number of route identifiers, and the route identifier field is used to carry the route identifier .
当所述流规范规则ORF记录包括路由标识个数字段和路由标识字段时,所述过滤模块13具体用于:将所述流规范规则ORF记录包括的:行动匹配字段、过滤器类型字段、过滤器特定操作和取值字段、路由标识字段,分别与所述待发送给所述第二网络设备的流规范规则包括的:动作类型字段、过滤器类型字段、过滤器特定操作和取值字段和路由标识字段进行比较;若所述流规范规则ORF记录包括的行动匹配字段所指示的要匹配的动作类型集合为空或所述要匹配的动作类型都包含在所述待发送给所述第二网络设备的流规范规则包括的动作类型中,所述流规范规则ORF记录包括的过滤器集合为空或每种过滤器类型的过滤器特定操作和取值字段的数值空间都包含所述待发 送给所述第二网络设备的流规范规则包括的过滤器类型的过滤器特定操作和取值字段的数值空间,所述流规范规则ORF记录包括的路由标识组成的路由标识集合为空或所述路由标识集合中包含所述待发送给所述第二网络设备的流规范规则包括的路由标识,则确定所述待发送给所述第二网络设备的流规范规则匹配上所述流规范规则ORF记录。When the flow specification rule ORF record includes a route identifier number field and a route identifier field, the filtering module 13 is specifically configured to: include the flow specification rule ORF record: an action matching field, a filter type field, and filtering The specific operation and value field and the route identification field are respectively included in the flow specification rule to be sent to the second network device: an action type field, a filter type field, a filter specific operation, and a value field. The route identifier field is compared; if the action type set to be matched by the action matching field included in the flow specification rule ORF record is empty or the action type to be matched is included in the second to be sent to the second In the action type included in the flow specification rule of the network device, the filter specification included in the flow specification rule ORF record is empty or the value space of the filter specific operation and the value field of each filter type includes the to-be-sent The flow specification rule sent to the second network device includes a filter-specific filter operation-specific value and a value space of the value field, and the flow specification rule ORF record includes a route identifier set consisting of a route identifier set to be empty or The routing identifier set includes the routing identifier included in the flow specification rule to be sent to the second network device, and determining that the flow specification rule to be sent to the second network device matches the flow specification rule ORF record.
本实施例中,所述确定模块11具体用于:In this embodiment, the determining module 11 is specifically configured to:
首先,获取第一流规范规则ORF能力参数,所述第一流规范规则ORF能力参数指示所述第二网络设备支持的流规范规则ORF能力,所述第一流规范规则ORF能力参数包括:至少一组由地址族标识、子地址族标识、流规范规则ORF类型和收发能力标识组成的参数集合,所述第一流规范规则ORF能力参数中包括的收发能力标识用于指示所述第二网络设备是否支持发送和/或接收流规范规则ORF记录。First, the first flow specification rule ORF capability parameter is obtained, where the first flow specification rule ORF capability parameter indicates a flow specification rule ORF capability supported by the second network device, and the first flow specification rule ORF capability parameter includes: at least one group consisting of The parameter set consisting of the address family identifier, the sub-address family identifier, the flow specification rule ORF type, and the transceiver capability identifier, and the transceiver capability identifier included in the first-flow specification rule ORF capability parameter is used to indicate whether the second network device supports sending And/or receive flow specification rules ORF records.
然后,比较所述第一流规范规则ORF能力参数与第二流规范规则ORF能力参数,所述第二流规范规则ORF能力参数指示所述第一网络设备支持的流规范规则ORF能力,所述第二流规范规则ORF能力参数包括:至少一组由地址族标识、子地址族标识、流规范规则ORF类型和收发能力标识组成的参数集合,所述第二流规范规则ORF能力参数中包括的收发能力标识用于指示所述第一网络设备是否支持发送和/或接收流规范规则ORF记录。And comparing, the first flow specification rule ORF capability parameter and the second flow specification rule ORF capability parameter, the second flow specification rule ORF capability parameter indicating a flow specification rule ORF capability supported by the first network device, where the The second-flow specification rule ORF capability parameter includes: at least one set of parameters consisting of an address family identifier, a sub-address family identifier, a flow specification rule ORF type, and a transceiving capability identifier, and the second stream specification rule ORF capability parameter includes The capability identifier is used to indicate whether the first network device supports sending and/or receiving a flow specification rule ORF record.
若所述第一流规范规则ORF能力参数包含的第一参数集合和所述第二流规范规则ORF能力参数包含的第二参数集合都包含流规范规则ORF类型,所述第一参数集合和所述第二参数集合包含相同的地址族标识和子地址族标识,并且所述第一参数集合的收发能力标识指示所述第二网络设备支持发送流规范规则ORF记录,所述第二参数集合的收发能力标识指示所述第一网络设备支持接收流规范规则ORF记录,则确定所述第二网络设备能够向所述第一网络设备发送流规范规则ORF记录。And if the first parameter set included in the first flow specification rule ORF capability parameter and the second parameter set included in the second flow specification rule ORF capability parameter include a flow specification rule ORF type, the first parameter set and the The second parameter set includes the same address family identifier and the sub-address family identifier, and the transceiver capability identifier of the first parameter set indicates that the second network device supports the sending flow specification rule ORF record, and the second parameter set is capable of transmitting and receiving. The identifier indicates that the first network device supports receiving the flow specification rule ORF record, and determining that the second network device is capable of sending a flow specification rule ORF record to the first network device.
所述确定模块11获取第一流规范规则ORF能力参数,具体为:在所述第一网络设备与所述第二网络设备建立BGP连接过程中,接收所述第二网络设备发送的BGP开放消息,所述第二网络设备发送的BGP开放消息中包括所述第一流规范规则ORF能力参数。The determining module 11 obtains the first flow specification rule ORF capability parameter, specifically: receiving the BGP open message sent by the second network device during the process of establishing a BGP connection between the first network device and the second network device, The BGP open message sent by the second network device includes the first flow specification rule ORF capability parameter.
本实施例中,所述接收模块12具体用于:接收所述第二网络设备发送的BGP路由刷新消息,所述BGP路由刷新消息中包括所述流规范规则ORF记录。 In this embodiment, the receiving module 12 is specifically configured to: receive a BGP route refresh message sent by the second network device, where the BGP route refresh message includes the flow specification rule ORF record.
可选的,第一网络设备还包括存储处理模块。所述存储处理模块,用于在所述接收模块12接收所述第二网络设备发送的流规范规则ORF记录之后,根据所述流规范规则ORF记录中包括的地址族标识和子地址族标识确定所述流规范规则ORF记录的类型,并根据所述流规范规则ORF记录的序列号将所述流规范规则ORF记录有序地存储到对应类型的流规范规则ORF列表中。Optionally, the first network device further includes a storage processing module. The storage processing module is configured to determine, after the receiving module 12 receives the flow specification rule ORF record sent by the second network device, according to the address family identifier and the sub-address family identifier included in the flow specification rule ORF record. The flow specification rules the type of the ORF record, and stores the flow specification rule ORF record in an orderly manner according to the sequence number of the flow specification rule ORF record into the flow specification rule ORF list of the corresponding type.
本实施例提供的第一网络设备,可用于执行实施例一的方法,具体实现方式和技术效果类似,这里不再赘述。The first network device provided in this embodiment may be used to perform the method in the first embodiment. The specific implementation manners and technical effects are similar, and details are not described herein again.
图8为本发明实施例四提供的第二网络设备的结构示意图,如图8所示,本实施例提供的第二网络设备包括:确定模块21、生成模块22、发送模块23和接收模块24。FIG. 8 is a schematic structural diagram of a second network device according to Embodiment 4 of the present invention. As shown in FIG. 8, the second network device provided in this embodiment includes: a determining module 21, a generating module 22, a sending module 23, and a receiving module 24. .
其中,确定模块21,用于确定第一网络设备能够接收流规范规则ORF记录;The determining module 21 is configured to determine that the first network device is capable of receiving the flow specification rule ORF record;
生成模块22,用于根据所述第二网络设备保存的流规范规则策略生成流规范规则ORF记录;The generating module 22 is configured to generate a flow specification rule ORF record according to the flow specification rule policy saved by the second network device;
发送模块23,用于将所述生成模块22生成的流规范规则ORF记录发送给所述第一网络设备;The sending module 23 is configured to send the flow specification rule ORF record generated by the generating module 22 to the first network device;
接收模块24,用于接收所述第一网络设备发送的流规范规则,所述流规范规则为所述第一网络设备根据所述流规范规则ORF记录过滤后的流规范规则。The receiving module 24 is configured to receive a flow specification rule sent by the first network device, where the flow specification rule is that the first network device records the filtered flow specification rule according to the flow specification rule ORF.
本实施例中,所述流规范规则ORF记录包括:流规范规则ORF记录的序列号字段、行动匹配字段、过滤器类型字段、过滤器特定操作和取值字段,所述流规范规则ORF记录的序列号字段用于携带流规范规则ORF记录的优先级,所述行动匹配字段用于携带是否匹配流规范规则的动作类型,所述过滤器类型字段用于携带过滤器类型,所述过滤器特定操作和取值字段用于携带所述过滤器类型对应的过滤条件。可选的,所述流规范规则ORF记录还包括:过滤器个数字段,所述过滤器个数字段用于携带过滤器的个数。In this embodiment, the flow specification rule ORF record includes: a sequence number field of the flow specification rule ORF record, an action matching field, a filter type field, a filter specific operation, and a value field, and the flow specification rule ORF records The sequence number field is used to carry the priority of the flow specification rule ORF record, the action matching field is used to carry an action type that matches whether the flow specification rule is used, and the filter type field is used to carry a filter type, the filter specific The operation and value fields are used to carry the filter conditions corresponding to the filter type. Optionally, the flow specification rule ORF record further includes: a filter number field, where the filter number field is used to carry the number of filters.
可选的,所述流规范规则ORF记录还包括:路由标识个数字段和路由标识字段,所述路由标识个数字段用于携带路由标识的个数,所述路由标识字段用于携带路由标识。Optionally, the flow specification rule ORF record further includes: a route identifier number field and a route identifier field, where the route identifier number field is used to carry the number of route identifiers, and the route identifier field is used to carry the route identifier .
本实施例中,所述确定模块21具体用于:In this embodiment, the determining module 21 is specifically configured to:
首先,获取第二流规范规则ORF能力参数,所述第二流规范规则ORF能 力参数指示所述第一网络设备支持的流规范规则ORF能力,所述第二流规范规则ORF能力参数包括:至少一组由地址族标识、子地址族标识、流规范规则ORF类型和收发能力标识组成的参数集合,所述第二流规范规则ORF能力参数中包括的收发能力标识用于指示所述第一网络设备是否支持发送和/或接收流规范规则ORF记录。First, the second stream specification rule ORF capability parameter is obtained, and the second stream specification rule ORF can The force parameter indicates a flow specification rule ORF capability supported by the first network device, and the second flow specification rule ORF capability parameter includes: at least one group consists of an address family identifier, a sub-address family identifier, a flow specification rule ORF type, and a transceiving capability. And identifying, by the set of parameters, the transceiver capability identifier included in the second stream specification rule ORF capability parameter is used to indicate whether the first network device supports sending and/or receiving a flow specification rule ORF record.
然后,比较所述第二流规范规则ORF能力参数与第一流规范规则ORF能力参数,所述第一流规范规则ORF能力参数指示所述第二网络设备支持的流规范规则ORF能力,所述第一流规范规则ORF能力参数包括:至少一组由地址族标识、子地址族标识、流规范规则ORF类型和收发能力标识组成的参数集合,所述第一流规范规则ORF能力参数中包括的收发能力标识用于指示所述第二网络设备是否支持发送和/或接收流规范规则ORF记录。若所述第一流规范规则ORF能力参数包含的第一参数集合和所述第二流规范规则ORF能力参数包含的第二参数集合都包含流规范规则ORF类型,所述第一参数集合和所述第二参数集合包含相同的地址族标识和子地址族标识,并且第一参数集合的收发能力标识指示所述第二网络设备支持发送,流规范规则ORF记录,所述第二参数集合的收发能力标识指示所述第一网络设备支持接收流规范规则ORF记录,则确定所述第二网络设备能够向所述第一网络设备发送流规范规则ORF记录。Then, comparing the second flow specification rule ORF capability parameter with the first flow specification rule ORF capability parameter, the first flow specification rule ORF capability parameter indicating a flow specification rule ORF capability supported by the second network device, the first flow The specification rule ORF capability parameter includes: at least one set of parameters consisting of an address family identifier, a sub-address family identifier, a flow specification rule ORF type, and a transceiving capability identifier, and the first-flow specification rule ORF capability parameter includes a transceiving capability identifier. And indicating whether the second network device supports sending and/or receiving a flow specification rule ORF record. And if the first parameter set included in the first flow specification rule ORF capability parameter and the second parameter set included in the second flow specification rule ORF capability parameter include a flow specification rule ORF type, the first parameter set and the The second parameter set includes the same address family identifier and the sub-address family identifier, and the transceiver capability identifier of the first parameter set indicates that the second network device supports sending, the flow specification rule ORF records, and the second parameter set of the transceiver capability identifier Instructing the first network device to support receiving a flow specification rule ORF record, determining that the second network device is capable of transmitting a flow specification rule ORF record to the first network device.
所述确定模块21获取第二流规范规则ORF能力参数,具体为:在所述第二网络设备与所述第一网络设备建立BGP连接的过程中,接收所述第一网络设备发送的BGP开放消息,所述第一网络设备发送的BGP开放消息中包括所述第二流规范规则ORF能力参数。The determining module 21 obtains the second flow specification rule ORF capability parameter, specifically: receiving the BGP openness sent by the first network device in the process of establishing a BGP connection between the second network device and the first network device The BGP open message sent by the first network device includes the second flow specification rule ORF capability parameter.
本实施例中,所述发送模块23具体用于:向所述第一网络设备发送BGP路由刷新消息,所述BGP路由刷新消息中包括所述流规范规则ORF记录。In this embodiment, the sending module 23 is specifically configured to: send a BGP route refresh message to the first network device, where the BGP route refresh message includes the flow specification rule ORF record.
本实施例提供的第二网络设备可用于执行实施例二的方法,具体实现方式和技术效果类似,这里不再赘述。The second network device provided in this embodiment may be used to perform the method in the second embodiment. The specific implementation manners and technical effects are similar, and details are not described herein again.
图9为本发明实施例五提供的第一网络设备的结构示意图,如图9所示,本实施例的第一网络设备300包括:处理器31、存储器32、通信接口33和通信总线34,存储器32和通信接口33通过通信总线34与处理器31连接和通信,存储器32用于存储计算机指令,通信接口33用于与其他网络设备进行通信,处理器31用于执行存储器32存储的计算机指令,以执行如下所述 的方法:FIG. 9 is a schematic structural diagram of a first network device according to Embodiment 5 of the present invention. As shown in FIG. 9, the first network device 300 of this embodiment includes: a processor 31, a memory 32, a communication interface 33, and a communication bus 34. Memory 32 and communication interface 33 are coupled and in communication with processor 31 via communication bus 34 for storing computer instructions, communication interface 33 for communicating with other network devices, and processor 31 for executing computer instructions stored by memory 32. To perform as described below Methods:
确定第二网络设备能够向所述第一网络设备发送流规范规则ORF记录;Determining that the second network device is capable of transmitting a flow specification rule ORF record to the first network device;
接收所述第二网络设备发送的流规范规则ORF记录,所述流规范规则ORF记录用于所述第一网络设备对待发送给所述第二网络设备的流规范规则进行过滤;Receiving, by the second network device, a flow specification rule ORF record, where the flow specification rule ORF records a flow specification rule to be sent by the first network device to the second network device;
根据所述流规范规则ORF记录对待发送给所述第二网络设备的流规范规则进行过滤;And filtering, according to the flow specification rule ORF, a flow specification rule to be sent to the second network device;
向所述第二网络设备发送过滤后的流规范规则。Sending the filtered flow specification rule to the second network device.
其中,所述流规范规则ORF记录包括:流规范规则ORF记录的序列号字段、行动匹配字段、过滤器类型字段和过滤器特定操作和取值字段,所述流规范规则ORF记录的序列号字段用于携带流规范规则ORF记录的优先级,所述行动匹配字段用于携带是否匹配流规范规则的动作类型,所述过滤器类型字段用于携带过滤器类型,所述过滤器特定操作和取值字段用于携带所述过滤器类型对应的过滤条件。可选的,所述流规范规则ORF记录还包括:过滤器个数字段,所述过滤器个数字段用于携带过滤器的个数。The flow specification rule ORF record includes: a sequence number field of the flow specification rule ORF record, an action matching field, a filter type field, and a filter specific operation and value field, and the sequence number field of the flow specification rule ORF record a priority for carrying a flow specification rule ORF record, the action matching field is configured to carry an action type that matches a flow specification rule, the filter type field is used to carry a filter type, and the filter specific operation and fetch The value field is used to carry the filter condition corresponding to the filter type. Optionally, the flow specification rule ORF record further includes: a filter number field, where the filter number field is used to carry the number of filters.
可选的,所述流规范规则ORF记录还包括:路由标识个数字段和路由标识字段,所述路由标识个数字段用于携带路由标识的个数,所述路由标识字段用于携带路由标识。Optionally, the flow specification rule ORF record further includes: a route identifier number field and a route identifier field, where the route identifier number field is used to carry the number of route identifiers, and the route identifier field is used to carry the route identifier .
所述根据所述流规范规则ORF记录对待发送的流规范规则进行过滤,具体为:And filtering, according to the flow specification rule ORF, a flow specification rule to be sent, specifically:
将所述流规范规则ORF记录包括的:行动匹配字段、过滤器类型字段、过滤器特定操作和取值字段,分别与所述待发送的流规范规则包括的:动作类型字段、过滤器类型字段、过滤器特定操作和取值字段进行比较。若所述流规范规则ORF记录包括的行动匹配字段所指示的要匹配的动作类型集合为空或所述要匹配的动作类型都包含在所述待发送给所述第二网络设备的流规范规则包括的动作类型中,所述流规范规则ORF记录包括的每种过滤器类型过滤器集合为空或的过滤器特定操作和取值字段的数值空间都包含所述待发送给所述第二网络设备的流规范规则包括的过滤器类型的过滤器特定操作和取值字段的数值空间,则确定所述待发送给所述第二网络设备的流规范规则匹配所述流规范规则ORF记录。The flow specification rule ORF record includes: an action matching field, a filter type field, a filter specific operation, and a value field, respectively, and the flow specification rule to be sent includes: an action type field, a filter type field , filter specific operations and value fields are compared. If the action type set to be matched by the action matching field included in the flow specification rule ORF record is empty or the action type to be matched is included in the flow specification rule to be sent to the second network device In the action type included, the filter specification ORF record includes a filter set of each filter type that is empty or the value space of the filter specific operation and the value field includes the to-be-sent to the second network. The flow specification rule of the device includes a filter-specific operation and a value space of the value field, and then determining that the flow specification rule to be sent to the second network device matches the flow specification rule ORF record.
或者,将所述流规范规则ORF记录包括的:行动匹配字段、过滤器类型 字段、过滤器特定操作和取值字段、路由标识字段,分别与所述待发送的流规范规则包括的:动作类型字段、过滤器类型字段、过滤器特定操作和取值字段和路由标识字段进行比较。若所述流规范规则ORF记录包括的行动匹配字段所指示的要匹配的动作类型集合为空或所述要匹配的动作类型都包含在所述待发送给所述第二网络设备的流规范规则包括的动作类型中,所述流规范规则ORF记录包括的过滤器集合为空或每种过滤器类型的过滤器特定操作和取值字段的数值空间都包含所述待发送给所述第二网络设备的流规范规则包括的过滤器类型的过滤器特定操作和取值字段的数值空间,所述流规范规则ORF记录包括的路由标识组成的路由标识集合为空或所述路由标识集合包含所述待发送给所述第二网络设备的流规范规则包括的路由标识,则确定所述待发送给所述第二网络设备的流规范规则匹配上所述流规范规则ORF记录。Alternatively, the flow specification rule ORF record includes: action matching field, filter type The field, the filter specific operation and the value field, and the route identifier field are respectively performed with the flow specification rule to be sent: an action type field, a filter type field, a filter specific operation, a value field, and a route identifier field. Comparison. If the action type set to be matched by the action matching field included in the flow specification rule ORF record is empty or the action type to be matched is included in the flow specification rule to be sent to the second network device In the action type included, the flow specification rule ORF record includes a filter set that is empty or a filter-specific operation of each filter type and a value space of the value field contain the to-be-sent to the second network The flow specification rule of the device includes a filter-specific operation of the filter type and a numerical space of the value field, the flow specification rule ORF record includes a route identifier set consisting of a route identifier or the route identifier set includes the And determining, by the flow specification rule included in the flow specification rule of the second network device, the flow specification rule to be sent to the second network device to match the flow specification rule ORF record.
所述确定第二网络设备能够向所述第一网络设备发送流规范规则ORF记录,包括:获取第一流规范规则ORF能力参数,所述第一流规范规则ORF能力参数指示所述第二网络设备支持的流规范规则ORF能力,所述第一流规范规则ORF能力参数包括:至少一组由地址族标识、子地址族标识、流规范规则ORF类型和收发能力标识组成的参数集合,所述第一流规范规则ORF能力参数中包括的收发能力标识用于指示所述第二网络设备是否支持发送和/或接收流规范规则ORF记录。比较所述第一流规范规则ORF能力参数与第二流规范规则ORF能力参数,所述第二流规范规则ORF能力参数指示所述第一网络设备支持的流规范规则ORF能力,所述第二流规范规则ORF能力参数包括:至少一组由地址族标识、子地址族标识、流规范规则ORF类型和收发能力标识组成的参数集合,所述第二流规范规则ORF能力参数中包括的收发能力标识用于指示所述第一网络设备是否支持发送和/或接收流规范规则ORF记录。The determining, by the second network device, the flow specification rule ORF record to the first network device, includes: acquiring a first flow specification rule ORF capability parameter, where the first flow specification rule ORF capability parameter indicates that the second network device supports The flow specification standard ORF capability, the first flow specification rule ORF capability parameter includes: at least one set of parameters consisting of an address family identifier, a sub-address family identifier, a flow specification rule ORF type, and a transceiving capability identifier, the first flow specification The transceiving capability identifier included in the regular ORF capability parameter is used to indicate whether the second network device supports sending and/or receiving a flow specification rule ORF record. Comparing the first flow specification rule ORF capability parameter with a second flow specification rule ORF capability parameter, the second flow specification rule ORF capability parameter indicating a flow specification rule ORF capability supported by the first network device, the second flow The specification rule ORF capability parameter includes: at least one set of parameters consisting of an address family identifier, a sub-address family identifier, a flow specification rule ORF type, and a transceiving capability identifier, and the transceiving capability identifier included in the second stream specification rule ORF capability parameter And used to indicate whether the first network device supports sending and/or receiving a flow specification rule ORF record.
若所述第一流规范规则ORF能力参数包含的第一参数集合和所述第二流规范规则ORF能力参数包含的第二参数集合都包含流规范规则ORF类型,所述第一参数集合和所述第二参数集合包含相同的地址族标识和子地址族标识,并且所述第一参数集合的收发能力标识指示所述第二网络设备支持发送流规范规则ORF记录,所述第二参数集合的收发能力标识指示所述第一网络设备支持接收流规范规则ORF记录,则确定所述第二网络设备能够向所述第一网络设备发送流规范规则ORF记录。And if the first parameter set included in the first flow specification rule ORF capability parameter and the second parameter set included in the second flow specification rule ORF capability parameter include a flow specification rule ORF type, the first parameter set and the The second parameter set includes the same address family identifier and the sub-address family identifier, and the transceiver capability identifier of the first parameter set indicates that the second network device supports the sending flow specification rule ORF record, and the second parameter set is capable of transmitting and receiving. The identifier indicates that the first network device supports receiving the flow specification rule ORF record, and determining that the second network device is capable of sending a flow specification rule ORF record to the first network device.
所述获取第一流规范规则ORF能力参数,包括:在所述第一网络设备与 所述第二网络设备建立BGP连接过程中,接收所述第二网络设备发送的BGP开放消息,所述第二网络设备发送的BGP开放消息中包括所述第一流规范规则ORF能力参数。Obtaining the first flow specification rule ORF capability parameter, including: at the first network device And receiving, by the second network device, a BGP open message sent by the second network device, where the BGP open message sent by the second network device includes the first flow norm rule ORF capability parameter.
所述接收所述第二网络设备发送的流规范规则ORF记录,包括:接收所述第二网络设备发送的BGP路由刷新消息,所述BGP路由刷新消息中包括所述流规范规则ORF记录。And receiving the flow specification rule ORF record sent by the second network device, including: receiving a BGP route refresh message sent by the second network device, where the BGP route refresh message includes the flow specification rule ORF record.
所述处理器31接收所述第二网络设备发送的流规范规则ORF记录之后,还用于:根据所述流规范规则ORF记录中包括的地址族标识和子地址族标识确定所述流规范规则ORF记录的类型,并根据所述流规范规则ORF记录的序列号将所述流规范规则ORF记录有序地存储到对应类型的流规范规则ORF列表中。After receiving the flow specification rule ORF record sent by the second network device, the processor 31 is further configured to: determine, according to the address family identifier and the sub-address family identifier included in the flow specification rule ORF record, the flow specification rule ORF The type of the record, and the stream specification rule ORF record is stored in an orderly manner in the stream specification rule ORF list of the corresponding type according to the sequence number of the flow specification rule ORF record.
本实施例提供的第一网络设备,可用于执行实施例一的方法,具体实现方式和技术效果类似,这里不再赘述。The first network device provided in this embodiment may be used to perform the method in the first embodiment. The specific implementation manners and technical effects are similar, and details are not described herein again.
图10为本发明实施例六提供的第二网络设备的结构示意图,如图10所示,本实施例的第二网络设备400包括:处理器41、存储器42、通信接口43和通信总线44,存储器42和通信接口43通过通信总线44与处理器41连接和通信,存储器42用于存储计算机指令,通信接口43用于与其他网络设备进行通信,处理器41用于执行存储器42存储的计算机指令,以执行如下所述的方法:10 is a schematic structural diagram of a second network device according to Embodiment 6 of the present invention. As shown in FIG. 10, the second network device 400 of this embodiment includes: a processor 41, a memory 42, a communication interface 43, and a communication bus 44. Memory 42 and communication interface 43 are coupled and in communication with processor 41 via communication bus 44 for storing computer instructions, communication interface 43 for communicating with other network devices, and processor 41 for executing computer instructions stored by memory 42. To perform the method described below:
确定第二网络设备第一网络设备能够接收流规范规则ORF记录;Determining that the second network device first network device is capable of receiving the flow specification rule ORF record;
根据所述第二网络设备保存的流规范规则策略生成流规范规则ORF记录;Generating a flow specification rule ORF record according to the flow specification rule policy saved by the second network device;
将所述流规范规则ORF记录发送给所述第一网络设备;Transmitting the flow specification rule ORF record to the first network device;
接收所述第一网络设备发送的流规范规则,所述流规范规则为所述第一网络设备根据所述流规范规则ORF记录过滤后的流规范规则。And receiving, by the first network device, a flow specification rule, where the flow specification rule is that the first network device records the filtered flow specification rule according to the flow specification rule ORF.
其中,所述流规范规则ORF记录包括:流规范规则ORF记录的序列号字段、行动匹配字段、过滤器个数字段、过滤器类型字段、过滤器特定操作和取值字段,所述流规范规则ORF记录的序列号字段用于携带流规范规则ORF记录的优先级,所述行动匹配字段用于携带是否匹配流规范规则的动作类型,所述过滤器类型字段用于携带过滤器类型,所述过滤器特定操作和取值字段用于携带所述过滤器类型对应的过滤条件。可选的,所述流规范规则ORF记录还包括:过滤器个数字段,所述过滤器个数字段用于携带过滤器的个数。 The flow specification rule ORF record includes: a sequence number field of the flow specification rule ORF record, an action matching field, a filter number field, a filter type field, a filter specific operation, and a value field, and the flow specification rule The sequence number field of the ORF record is used to carry the priority of the flow specification rule ORF record, the action matching field is used to carry an action type that matches the flow specification rule, and the filter type field is used to carry a filter type, A filter specific operation and value field is used to carry the filter condition corresponding to the filter type. Optionally, the flow specification rule ORF record further includes: a filter number field, where the filter number field is used to carry the number of filters.
可选的,所述流规范规则ORF记录还包括:路由标识个数字段和路由标识字段,所述路由标识个数字段用于携带路由标识的个数,所述路由标识字段用于携带路由标识。Optionally, the flow specification rule ORF record further includes: a route identifier number field and a route identifier field, where the route identifier number field is used to carry the number of route identifiers, and the route identifier field is used to carry the route identifier .
所述确定第一网络设备能够接收流规范规则ORF记录,包括:Determining that the first network device is capable of receiving the flow specification rule ORF record, including:
首先,获取第二流规范规则ORF能力参数,所述第二流规范规则ORF能力参数指示所述第一网络设备支持的流规范规则ORF能力,所述第二流规范规则ORF能力参数包括:至少一组由地址族标识和子地址族标识、流规范规则ORF类型和收发能力标识组成的参数集合,所述第二流规范规则ORF能力参数中包括的收发能力标识用于指示所述第一网络设备是否支持发送和/或接收流规范规则ORF记录。First, the second flow specification rule ORF capability parameter is obtained, where the second flow specification rule ORF capability parameter indicates a flow specification rule ORF capability supported by the first network device, and the second flow specification rule ORF capability parameter includes: at least A set of parameters consisting of an address family identifier and a sub-address family identifier, a flow specification rule ORF type, and a transceiving capability identifier, where the transceiving capability identifier included in the second-flow specification rule ORF capability parameter is used to indicate the first network device Whether to support sending and/or receiving flow specification rules ORF records.
然后,比较所述第二流规范规则ORF能力参数与第一流规范规则ORF能力参数,所述第一流规范规则ORF能力参数指示所述第二网络设备支持的流规范规则ORF能力,所述第一流规范规则ORF能力参数包括:至少一组由地址族标识和子地址族标识、流规范规则ORF类型和收发能力标识组成的参数集合,所述第一流规范规则ORF能力参数中包括的收发能力标识用于指示所述第二网络设备是否支持发送和/或接收流规范规则ORF记录。Then, comparing the second flow specification rule ORF capability parameter with the first flow specification rule ORF capability parameter, the first flow specification rule ORF capability parameter indicating a flow specification rule ORF capability supported by the second network device, the first flow The specification rule ORF capability parameter includes: at least one set of parameters consisting of an address family identifier and a sub-address family identifier, a flow specification rule ORF type, and a transceiving capability identifier, where the transceiving capability identifier included in the first-flow specification rule ORF capability parameter is used for Indicates whether the second network device supports transmitting and/or receiving a flow specification rule ORF record.
若所述第一流规范规则ORF能力参数包含的第一参数集合和所述第二流规范规则ORF能力参数包含的第二参数集合都包含流规范规则ORF类型,所述第一参数集合和所述第二参数集合包含相同的地址族标识和子地址族标识,并且所述第一参数集合的收发能力标识指示所述第二网络设备支持发送流规范规则ORF记录,所述第二参数集合的收发能力标识指示所述第一网络设备支持接收流规范规则ORF记录,则确定所述第二网络设备能够向所述第一网络设备发送流规范规则ORF记录。And if the first parameter set included in the first flow specification rule ORF capability parameter and the second parameter set included in the second flow specification rule ORF capability parameter include a flow specification rule ORF type, the first parameter set and the The second parameter set includes the same address family identifier and the sub-address family identifier, and the transceiver capability identifier of the first parameter set indicates that the second network device supports the sending flow specification rule ORF record, and the second parameter set is capable of transmitting and receiving. The identifier indicates that the first network device supports receiving the flow specification rule ORF record, and determining that the second network device is capable of sending a flow specification rule ORF record to the first network device.
所述获取第二流规范规则ORF能力参数,包括:在所述第二网络设备与所述第一网络设备建立BGP连接的过程中,接收所述第一网络设备发送的BGP开放消息,所述第一网络设备发送的BGP开放消息中包括所述第二流规范规则ORF能力参数。The obtaining the second flow specification rule ORF capability parameter includes: receiving, in the process of establishing a BGP connection between the second network device and the first network device, receiving a BGP open message sent by the first network device, The BGP open message sent by the first network device includes the second flow specification rule ORF capability parameter.
所述将所述流规范规则ORF记录发送给所述第一网络设备,包括:向所述第一网络设备发送BGP路由刷新消息,所述BGP路由刷新消息中包括所述流规范规则ORF记录。The sending the flow specification rule ORF record to the first network device includes: sending a BGP route refresh message to the first network device, where the BGP route refresh message includes the flow specification rule ORF record.
本实施例提供的第二网络设备,可用于执行实施例二的方法,具体实现 方式和技术效果类似,这里不再赘述。The second network device provided in this embodiment may be used to implement the method in Embodiment 2, and the specific implementation is implemented. The method and technical effect are similar and will not be described here.
图11为本发明实施例七提供的一种网络系统的结构示意图,如图11所示,本实施例的网络系统包括:第一网络设备51和第二网络设备52,其中,第一网络设备51可用于执行实施例一的方法,第二网络设备52可用于执行实施例二的方法,具体实现方式和技术效果类似,请参照实施例一和实施例二的描述,这里不再赘述。FIG. 11 is a schematic structural diagram of a network system according to Embodiment 7 of the present invention. As shown in FIG. 11, the network system of this embodiment includes: a first network device 51 and a second network device 52, where the first network device The method can be used to perform the method of the first embodiment, and the second network device 52 can be used to perform the method of the second embodiment. The specific implementation and the technical effects are similar. Please refer to the descriptions of the first embodiment and the second embodiment, and details are not described herein again.
本领域普通技术人员可以理解:实现上述各方法实施例的全部或部分步骤可以通过程序指令相关的硬件来完成。前述的程序可以存储于一计算机可读取存储介质中。该程序在执行时,执行包括上述各方法实施例的步骤;而前述的存储介质包括:ROM、RAM、磁碟或者光盘等各种可以存储程序代码的介质。One of ordinary skill in the art will appreciate that all or part of the steps to implement the various method embodiments described above may be accomplished by hardware associated with the program instructions. The aforementioned program can be stored in a computer readable storage medium. The program, when executed, performs the steps including the foregoing method embodiments; and the foregoing storage medium includes various media that can store program codes, such as a ROM, a RAM, a magnetic disk, or an optical disk.
最后应说明的是:以上各实施例仅用以说明本发明的技术方案,而非对其限制;尽管参照前述各实施例对本发明进行了详细的说明,本领域的普通技术人员应当理解:其依然可以对前述各实施例所记载的技术方案进行修改,或者对其中部分或者全部技术特征进行等同替换;而这些修改或者替换,并不使相应技术方案的本质脱离本发明各实施例技术方案的范围。 Finally, it should be noted that the above embodiments are merely illustrative of the technical solutions of the present invention, and are not intended to be limiting; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art will understand that The technical solutions described in the foregoing embodiments may be modified, or some or all of the technical features may be equivalently replaced; and the modifications or substitutions do not deviate from the technical solutions of the embodiments of the present invention. range.

Claims (35)

  1. 一种发送流规范规则的方法,其特征在于,包括:A method for transmitting a flow specification rule, comprising:
    第一网络设备确定第二网络设备能够向所述第一网络设备发送流规范规则出站路由过滤ORF记录;Determining, by the first network device, the second network device to send a flow specification rule outbound route filtering ORF record to the first network device;
    所述第一网络设备接收所述第二网络设备发送的所述流规范规则ORF记录,所述流规范规则ORF记录用于所述第一网络设备对待发送给所述第二网络设备的流规范规则进行过滤;Receiving, by the first network device, the flow specification rule ORF record sent by the second network device, where the flow specification rule ORF records a flow specification used by the first network device to be sent to the second network device Rules are filtered;
    所述第一网络设备根据所述流规范规则ORF记录对待发送给所述第二网络设备的流规范规则进行过滤;The first network device records, according to the flow specification rule ORF, a flow specification rule to be sent to the second network device;
    所述第一网络设备向所述第二网络设备发送过滤后的流规范规则。The first network device sends the filtered flow specification rule to the second network device.
  2. 根据权利要求1所述的方法,其特征在于,所述流规范规则ORF记录包括:流规范规则ORF记录的序列号字段、行动匹配字段、过滤器类型字段、过滤器特定操作和取值字段,所述流规范规则ORF记录的序列号字段用于携带流规范规则ORF记录的优先级,所述行动匹配字段用于携带是否匹配流规范规则的动作类型,所述过滤器类型字段用于携带过滤器类型,所述过滤器特定操作和取值字段用于携带所述过滤器类型对应的过滤条件。The method according to claim 1, wherein the flow specification rule ORF record comprises: a sequence number field of a flow specification rule ORF record, an action matching field, a filter type field, a filter specific operation, and a value field, The sequence number field of the flow specification rule ORF record is used to carry the priority of the flow specification rule ORF record, and the action matching field is used to carry an action type that matches the flow specification rule, and the filter type field is used to carry the filter. The filter type, the filter specific operation and the value field are used to carry the filter condition corresponding to the filter type.
  3. 根据权利要求2所述的方法,其特征在于,所述流规范规则ORF记录还包括:路由标识个数字段和路由标识字段,所述路由标识个数字段用于携带路由标识的个数,所述路由标识字段用于携带路由标识。The method according to claim 2, wherein the flow specification rule ORF record further comprises: a route identifier number field and a route identifier field, wherein the route identifier number field is used to carry the number of route identifiers, The route identifier field is used to carry a route identifier.
  4. 根据权利要求2或3的方法,其特征在于,所述流规范规则ORF记录还包括:过滤器个数字段,所述过滤器个数字段用于携带过滤器的个数。The method according to claim 2 or 3, wherein the flow specification rule ORF record further comprises: a filter number field, and the filter number field is used to carry the number of filters.
  5. 根据权利要求2所述的方法,其特征在于,所述第一网络设备根据所述流规范规则ORF记录对待发送给所述第二网络设备的流规范规则进行过滤,包括:The method according to claim 2, wherein the first network device records, according to the flow specification rule ORF, a flow specification rule to be sent to the second network device, including:
    所述第一网络设备将所述流规范规则ORF记录包括的:行动匹配字段、过滤器类型字段、过滤器特定操作和取值字段,分别与所述待发送给所述第二网络设备的流规范规则包括的:动作类型字段、过滤器类型字段、过滤器特定操作和取值字段进行比较;The first network device records, by the flow specification rule ORF, an action matching field, a filter type field, a filter specific operation, and a value field, respectively, and the flow to be sent to the second network device The specification rules include: action type fields, filter type fields, filter specific operations, and value fields for comparison;
    若所述流规范规则ORF记录包括的行动匹配字段所指示的要匹配的动作类型集合为空或所述要匹配的动作类型都包含在所述待发送给所述第二网络 设备的流规范规则包括的动作类型中,所述流规范规则ORF记录包括的过滤器集合为空或每种过滤器类型的过滤器特定操作和取值字段的数值空间都包含所述待发送给所述第二网络设备的流规范规则包括的过滤器类型的过滤器特定操作和取值字段的数值空间,则所述第一网络设备确定所述待发送给所述第二网络设备的流规范规则匹配所述流规范规则ORF记录。And if the action type set to be matched indicated by the action matching field included in the flow specification rule ORF record is empty or the action type to be matched is included in the second network to be sent to the second network In the action type included in the flow specification rule of the device, the filter specification included in the flow specification rule ORF record is empty or the value space of the filter specific operation and the value field of each filter type includes the to-be-sent to be sent to The flow specification rule of the second network device includes a filter-specific operation of the filter type and a numerical space of the value field, and the first network device determines the flow specification to be sent to the second network device The rules match the flow specification rule ORF record.
  6. 根据权利要求3所述的方法,其特征在于,所述第一网络设备根据所述流规范规则ORF记录对待发送给所述第二网络设备的流规范规则进行过滤,包括:The method according to claim 3, wherein the first network device records, according to the flow specification rule ORF, a flow specification rule to be sent to the second network device, including:
    所述第一网络设备将所述流规范规则ORF记录包括的:行动匹配字段、过滤器类型字段、过滤器特定操作和取值字段、路由标识字段,分别与所述待发送给所述第二网络设备的流规范规则包括的:动作类型字段、过滤器类型字段、过滤器特定操作和取值字段和路由标识字段进行比较;The first network device includes, by the flow specification rule ORF record, an action matching field, a filter type field, a filter specific operation and a value field, and a route identifier field, respectively, to be sent to the second The flow specification rule of the network device includes: an action type field, a filter type field, a filter specific operation and a value field, and a route identifier field for comparison;
    若所述流规范规则ORF记录包括的行动匹配字段所指示的要匹配的动作类型集合为空或所述要匹配的动作类型都包含在所述待发送给所述第二网络设备的流规范规则包括的动作类型中,所述流规范规则ORF记录包括的过滤器集合为空或每种过滤器类型的过滤器特定操作和取值字段的数值空间都包含所述待发送给所述第二网络设备的流规范规则包括的对应过滤器类型的过滤器特定操作和取值字段的数值空间,所述流规范规则ORF记录包括的路由标识组成的路由标识集合为空或所述路由标识集合中包含所述待发送给所述第二网络设备的流规范规则包括的路由标识,则所述第一网络设备确定所述待发送的流规范规则匹配上所述流规范规则ORF记录。If the action type set to be matched by the action matching field included in the flow specification rule ORF record is empty or the action type to be matched is included in the flow specification rule to be sent to the second network device In the action type included, the flow specification rule ORF record includes a filter set that is empty or a filter-specific operation of each filter type and a value space of the value field contain the to-be-sent to the second network The flow specification rule of the device includes a filter-specific operation of the corresponding filter type and a numerical space of the value field, and the flow specification rule ORF record includes a route identifier set consisting of a route identifier that is empty or included in the route identifier set. And the first network device determines that the flow specification rule to be sent matches the flow specification rule ORF record, where the flow specification rule is to be sent to the second network device.
  7. 根据权利要求1-6中任一项所述的方法,其特征在于,所述第一网络设备确定第二网络设备能够向所述第一网络设备发送流规范规则ORF记录,包括:The method according to any one of claims 1-6, wherein the first network device determines that the second network device can send a flow specification rule ORF record to the first network device, including:
    所述第一网络设备获取第一流规范规则ORF能力参数,所述第一流规范规则ORF能力参数指示所述第二网络设备支持的流规范规则ORF能力,所述第一流规范规则ORF能力参数包括:至少一组由地址族标识、子地址族标识、流规范规则ORF类型和收发能力标识组成的参数集合,所述第一流规范规则ORF能力参数中包括的收发能力标识用于指示所述第二网络设备是否支持发送和/或接收流规范规则ORF记录;The first network device obtains a first flow specification rule ORF capability parameter, where the first flow specification rule ORF capability parameter indicates a flow specification rule ORF capability supported by the second network device, where the first flow specification rule ORF capability parameter includes: At least one set of parameters consisting of an address family identifier, a sub-address family identifier, a flow specification rule ORF type, and a transceiving capability identifier, where the transceiving capability identifier included in the first-flow specification rule ORF capability parameter is used to indicate the second network Whether the device supports sending and/or receiving flow specification rule ORF records;
    所述第一网络设备比较所述第一流规范规则ORF能力参数与第二流规范 规则ORF能力参数,所述第二流规范规则ORF能力参数指示所述第一网络设备支持的流规范规则ORF能力,所述第二流规范规则ORF能力参数包括:至少一组由地址族标识、子地址族标识、流规范规则ORF类型和收发能力标识组成的参数集合,所述第二流规范规则ORF能力参数中包括的收发能力标识用于指示所述第一网络设备是否支持发送和/或接收流规范规则ORF记录;The first network device compares the first flow specification rule ORF capability parameter with a second flow specification a regular ORF capability parameter, the second flow specification rule ORF capability parameter indicates a flow specification rule ORF capability supported by the first network device, and the second flow specification rule ORF capability parameter includes: at least one group is identified by an address family, a parameter set consisting of a sub-address family identifier, a flow specification rule ORF type, and a transceiving capability identifier, where the transceiving capability identifier included in the second-flow specification rule ORF capability parameter is used to indicate whether the first network device supports sending and/or Receive stream specification rule ORF record;
    若所述第一流规范规则ORF能力参数包含的第一参数集合和所述第二流规范规则ORF能力参数包含的第二参数集合都包含流规范规则ORF类型,所述第一参数集合和所述第二参数集合包含相同的地址族标识和子地址族标识,并且所述第一参数集合的收发能力标识指示所述第二网络设备支持发送流规范规则ORF记录,所述第二参数集合的收发能力标识指示所述第一网络设备支持接收流规范规则ORF记录,则所述第一网络设备确定所述第二网络设备能够向所述第一网络设备发送流规范规则ORF记录。And if the first parameter set included in the first flow specification rule ORF capability parameter and the second parameter set included in the second flow specification rule ORF capability parameter include a flow specification rule ORF type, the first parameter set and the The second parameter set includes the same address family identifier and the sub-address family identifier, and the transceiver capability identifier of the first parameter set indicates that the second network device supports the sending flow specification rule ORF record, and the second parameter set is capable of transmitting and receiving. The identifier indicates that the first network device supports receiving a flow specification rule ORF record, and the first network device determines that the second network device can send a flow specification rule ORF record to the first network device.
  8. 根据权利要求7所述的方法,其特征在于,所述第一网络设备获取第一流规范规则ORF能力参数,包括:The method according to claim 7, wherein the first network device acquires the first flow specification rule ORF capability parameter, including:
    所述第一网络设备在与所述第二网络设备建立边界网关协议BGP连接过程中,接收所述第二网络设备发送的BGP开放消息,所述第二网络设备发送的BGP开放消息中包括所述第一流规范规则ORF能力参数。Receiving, by the first network device, a BGP open message sent by the second network device in a process of establishing a border gateway protocol BGP connection with the second network device, where the BGP open message sent by the second network device includes The first-flow specification rule ORF capability parameter.
  9. 根据权利要求1-6中任一项所述的方法,其特征在于,所述第一网络设备接收所述第二网络设备发送的流规范规则ORF记录,包括:The method according to any one of claims 1-6, wherein the first network device receives a flow specification rule ORF record sent by the second network device, including:
    所述第一网络设备接收所述第二网络设备发送的BGP路由刷新消息,所述BGP路由刷新消息中包括所述流规范规则ORF记录。The first network device receives a BGP route refresh message sent by the second network device, where the BGP route refresh message includes the flow specification rule ORF record.
  10. 根据权利要求1-6中任一项所述的方法,其特征在于,所述第一网络设备接收所述第二网络设备发送的流规范规则ORF记录之后,所述方法还包括:The method according to any one of claims 1-6, wherein after the first network device receives the flow specification rule ORF record sent by the second network device, the method further includes:
    所述第一网络设备根据所述流规范规则ORF记录中包括的地址族标识和子地址族标识确定所述流规范规则ORF记录的类型,并根据所述流规范规则ORF记录的序列号将所述流规范规则ORF记录有序地存储到对应类型的流规范规则ORF列表中。Determining, by the first network device, the type of the flow specification rule ORF record according to the address family identifier and the sub-address family identifier included in the flow specification rule ORF record, and according to the sequence number recorded by the flow specification rule ORF The stream specification rule ORF records are stored in an ordered manner into the stream specification rule ORF list of the corresponding type.
  11. 一种接收流规范规则的方法,其特征在于,包括:A method for receiving a flow specification rule, comprising:
    第二网络设备确定第一网络设备能够接收流规范规则出站路由过滤ORF记录; The second network device determines that the first network device is capable of receiving the flow specification rule outbound route filtering ORF record;
    所述第二网络设备根据自身保存的流规范规则策略生成流规范规则ORF记录;The second network device generates a flow specification rule ORF record according to the flow specification rule policy saved by itself;
    所述第二网络设备将所述流规范规则ORF记录发送给所述第一网络设备;Transmitting, by the second network device, the flow specification rule ORF record to the first network device;
    所述第二网络设备接收所述第一网络设备发送的流规范规则,所述流规范规则为所述第一网络设备根据所述流规范规则ORF记录过滤后的流规范规则。The second network device receives the flow specification rule sent by the first network device, where the flow specification rule is that the first network device records the filtered flow specification rule according to the flow specification rule ORF.
  12. 根据权利要求11所述的方法,其特征在于,所述流规范规则ORF记录包括:流规范规则ORF记录的序列号字段、行动匹配字段、过滤器类型字段、过滤器特定操作和取值字段,所述流规范规则ORF记录的序列号字段用于携带流规范规则ORF记录的优先级,所述行动匹配字段用于携带是否匹配流规范规则的动作类型,所述过滤器类型字段用于携带过滤器类型,所述过滤器特定操作和取值字段用于携带所述过滤器类型对应的过滤条件。The method according to claim 11, wherein the flow specification rule ORF record comprises: a sequence number field of a flow specification rule ORF record, an action matching field, a filter type field, a filter specific operation, and a value field, The sequence number field of the flow specification rule ORF record is used to carry the priority of the flow specification rule ORF record, and the action matching field is used to carry an action type that matches the flow specification rule, and the filter type field is used to carry the filter. The filter type, the filter specific operation and the value field are used to carry the filter condition corresponding to the filter type.
  13. 根据权利要求12所述的方法,其特征在于,所述流规范规则ORF记录还包括:路由标识个数字段和路由标识字段,所述路由标识个数字段用于携带路由标识的个数,所述路由标识字段用于携带路由标识。The method according to claim 12, wherein the flow specification rule ORF record further comprises: a route identifier number field and a route identifier field, wherein the route identifier number field is used to carry the number of route identifiers, The route identifier field is used to carry a route identifier.
  14. 根据权利要求12或13所述的方法,其特征在于,所述流规范规则ORF记录还包括:过滤器个数字段,所述过滤器个数字段用于携带过滤器的个数。The method according to claim 12 or 13, wherein the flow specification rule ORF record further comprises: a filter number field, wherein the filter number field is used to carry the number of filters.
  15. 根据权利要求11-14中任一项所述的方法,其特征在于,所述第二网络设备确定第一网络设备能够接收流规范规则出站路由过滤ORF记录,包括:The method according to any one of claims 11 to 14, wherein the second network device determines that the first network device is capable of receiving the flow specification rule outbound route filtering ORF record, including:
    所述第二网络设备获取第二流规范规则ORF能力参数,所述第二流规范规则ORF能力参数指示所述第一网络设备支持的流规范规则ORF能力,所述第二流规范规则ORF能力参数包括:至少一组由地址族标识和子地址族标识、流规范规则ORF类型和收发能力标识组成的参数集合,所述第二流规范规则ORF能力参数中包括的收发能力标识用于指示所述第一网络设备是否支持发送和/或接收流规范规则ORF记录;The second network device obtains a second flow specification rule ORF capability parameter, where the second flow specification rule ORF capability parameter indicates a flow specification rule ORF capability supported by the first network device, and the second flow specification rule ORF capability The parameter includes: at least one set of parameters consisting of an address family identifier and a sub-address family identifier, a flow specification rule ORF type, and a transceiver capability identifier, where the transceiver capability identifier included in the second flow specification rule ORF capability parameter is used to indicate the Whether the first network device supports sending and/or receiving a flow specification rule ORF record;
    所述第二网络设备比较所述第二流规范规则ORF能力参数与第一流规范规则ORF能力参数,所述第一流规范规则ORF能力参数指示所述第二网络设备支持的流规范规则ORF能力,所述第一流规范规则ORF能力参数包括:至少一组由地址族标识和子地址族标识、流规范规则ORF类型和收发能力标识 组成的参数集合,所述第一流规范规则ORF能力参数中包括的收发能力标识用于指示所述第二网络设备是否支持发送和/或接收流规范规则ORF记录;The second network device compares the second flow specification rule ORF capability parameter with a first flow specification rule ORF capability parameter, where the first flow specification rule ORF capability parameter indicates a flow specification rule ORF capability supported by the second network device, The first flow specification rule ORF capability parameter includes: at least one group is identified by an address family identifier and a sub-address family, a flow specification rule ORF type, and a transceiving capability identifier. a set of parameters, the transceiver capability identifier included in the first stream specification rule ORF capability parameter is used to indicate whether the second network device supports sending and/or receiving a flow specification rule ORF record;
    若所述第一流规范规则ORF能力参数包含的第一参数集合和所述第二流规范规则ORF能力参数包含的第二参数集合都包含流规范规则ORF类型,所述第一参数集合和所述第二参数集合包含相同的地址族标识和子地址族标识,并且所述第一参数集合的收发能力标识指示所述第二网络设备支持发送流规范规则ORF记录,所述第二参数集合的收发能力标识指示所述第一网络设备支持接收流规范规则ORF记录,则所述第二网络设备确定能够向所述第一网络设备发送流规范规则ORF记录。And if the first parameter set included in the first flow specification rule ORF capability parameter and the second parameter set included in the second flow specification rule ORF capability parameter include a flow specification rule ORF type, the first parameter set and the The second parameter set includes the same address family identifier and the sub-address family identifier, and the transceiver capability identifier of the first parameter set indicates that the second network device supports the sending flow specification rule ORF record, and the second parameter set is capable of transmitting and receiving. The identifier indicates that the first network device supports receiving the flow specification rule ORF record, and the second network device determines that the flow specification rule ORF record can be sent to the first network device.
  16. 根据权利要求15所述的方法,其特征在于,所述第二网络设备获取第二流规范规则ORF能力参数,包括:The method according to claim 15, wherein the second network device acquires the second flow specification rule ORF capability parameter, including:
    所述第二网络设备在与所述第一网络设备建立边界网关协议BGP连接的过程中,接收所述第一网络设备发送的BGP开放消息,所述第一网络设备发送的BGP开放消息中包括所述第二流规范规则ORF能力参数。Receiving, by the second network device, the BGP open message sent by the first network device in the process of establishing a border gateway protocol BGP connection with the first network device, where the BGP open message sent by the first network device includes The second stream normalizes the regular ORF capability parameter.
  17. 根据权利要求11-16中任一项所述的方法,其特征在于,所述第二网络设备将所述流规范规则ORF记录发送给所述第一网络设备,包括:The method according to any one of claims 11 to 16, wherein the second network device sends the flow specification rule ORF record to the first network device, including:
    所述第二网络设备向所述第一网络设备发送BGP路由刷新消息,所述BGP路由刷新消息中包括所述流规范规则ORF记录。The second network device sends a BGP route refresh message to the first network device, where the BGP route refresh message includes the flow specification rule ORF record.
  18. 一种第一网络设备,其特征在于,包括:A first network device, comprising:
    确定模块,用于确定第二网络设备能够向所述第一网络设备发送流规范规则出站路由过滤ORF记录;a determining module, configured to determine, by the second network device, a flow specification rule outbound route filtering ORF record to the first network device;
    接收模块,用于接收所述第二网络设备发送的所述流规范规则ORF记录,所述流规范规则ORF记录用于所述第一网络设备对待发送给所述第二网络设备的流规范规则进行过滤;a receiving module, configured to receive the flow specification rule ORF record sent by the second network device, where the flow specification rule ORF records a flow specification rule to be sent by the first network device to the second network device Filtering;
    过滤模块,用于根据所述流规范规则ORF记录对待发送的流规范规则进行过滤;a filtering module, configured to filter, according to the flow specification rule ORF, a flow specification rule to be sent;
    发送模块,用于向所述第二网络设备发送过滤后的流规范规则。And a sending module, configured to send the filtered flow specification rule to the second network device.
  19. 根据权利要求18所述的设备,其特征在于,所述流规范规则ORF记录包括:流规范规则ORF记录的序列号字段、行动匹配字段、过滤器类型字段、过滤器特定操作和取值字段,所述流规范规则ORF记录的序列号字段用于携带流规范规则ORF记录的优先级,所述行动匹配字段用于携带是否匹配 流规范规则的动作类型,所述过滤器类型字段用于携带过滤器类型,所述过滤器特定操作和取值字段用于携带所述过滤器类型对应的过滤条件。The apparatus according to claim 18, wherein said flow specification rule ORF record comprises: a sequence number field of a flow specification rule ORF record, an action matching field, a filter type field, a filter specific operation, and a value field, The sequence number field of the flow specification rule ORF record is used to carry the priority of the flow specification rule ORF record, and the action matching field is used to carry whether to match The action type of the flow specification rule, the filter type field is used to carry a filter type, and the filter specific operation and the value field are used to carry a filter condition corresponding to the filter type.
  20. 根据权利要求19所述的设备,其特征在于,所述流规范规则ORF记录还包括:路由标识个数字段和路由标识字段,所述路由标识个数字段用于携带路由标识的个数,所述路由标识字段用于携带路由标识。The device according to claim 19, wherein the flow specification rule ORF record further comprises: a route identifier number field and a route identifier field, wherein the route identifier number field is used to carry the number of route identifiers, The route identifier field is used to carry a route identifier.
  21. 根据权利要求19或20所述的设备,其特征在于,所述流规范规则ORF记录还包括:过滤器个数字段,所述过滤器个数字段用于携带过滤器的个数。The device according to claim 19 or 20, wherein the flow specification rule ORF record further comprises: a filter number field, wherein the filter number field is used to carry the number of filters.
  22. 根据权利要求19所述的设备,其特征在于,所述过滤模块具体用于:The device according to claim 19, wherein the filtering module is specifically configured to:
    将所述流规范规则ORF记录包括的:行动匹配字段、过滤器类型字段、过滤器特定操作和取值字段,分别与所述待发送给所述第二网络设备的流规范规则包括的:动作类型字段、过滤器类型字段、过滤器特定操作和取值字段进行比较;And the flow specification rule ORF record includes: an action matching field, a filter type field, a filter specific operation, and a value field, respectively, and the flow specification rule to be sent to the second network device: Type field, filter type field, filter specific operation, and value field for comparison;
    若所述流规范规则ORF记录包括的行动匹配字段所指示的要匹配的动作类型集合为空或所述要匹配的动作类型都包含在所述待发送给所述第二网络设备的流规范规则包括的动作类型中,所述流规范规则ORF记录包括的过滤器集合为空或每种过滤器类型的过滤器特定操作和取值字段的数值空间都包含所述待发送给所述第二网络设备的流规范规则包括的过滤器类型的过滤器特定操作和取值字段的数值空间,则确定所述待发送给所述第二网络设备的流规范规则匹配所述流规范规则ORF记录。If the action type set to be matched by the action matching field included in the flow specification rule ORF record is empty or the action type to be matched is included in the flow specification rule to be sent to the second network device In the action type included, the flow specification rule ORF record includes a filter set that is empty or a filter-specific operation of each filter type and a value space of the value field contain the to-be-sent to the second network The flow specification rule of the device includes a filter-specific operation and a value space of the value field, and then determining that the flow specification rule to be sent to the second network device matches the flow specification rule ORF record.
  23. 根据权利要求20所述的设备,其特征在于,所述过滤模块具体用于:The device according to claim 20, wherein the filtering module is specifically configured to:
    将所述流规范规则ORF记录包括的:行动匹配字段、过滤器类型字段、过滤器特定操作和取值字段、路由标识字段,分别与所述待发送给所述第二网络设备的流规范规则包括的:动作类型字段、过滤器类型字段、过滤器特定操作和取值字段和路由标识字段进行比较;And the flow specification rule ORF record includes: an action matching field, a filter type field, a filter specific operation and a value field, and a route identification field, respectively, and the flow specification rule to be sent to the second network device Included: action type field, filter type field, filter specific operation and value field and route identification field are compared;
    若所述流规范规则ORF记录包括的行动匹配字段所指示的要匹配的动作类型集合为空或所述要匹配的动作类型都包含在所述待发送给所述第二网络设备的流规范规则包括的动作类型中,所述流规范规则ORF记录包括的过滤器集合为空或每种过滤器类型的过滤器特定操作和取值字段的数值空间都包含所述待发送给所述第二网络设备的流规范规则包括的过滤器类型的过滤器特定操作和取值字段的数值空间,所述流规范规则ORF记录包括的路由标识 组成的路由标识集合为空或所述路由标识集合中包含所述待发送给所述第二网络设备的流规范规则包括的路由标识,则确定所述待发送给所述第二网络设备的流规范规则匹配上所述流规范规则ORF记录。If the action type set to be matched by the action matching field included in the flow specification rule ORF record is empty or the action type to be matched is included in the flow specification rule to be sent to the second network device In the action type included, the flow specification rule ORF record includes a filter set that is empty or a filter-specific operation of each filter type and a value space of the value field contain the to-be-sent to the second network The flow specification rule of the device includes a filter-specific operation of the filter type and a numerical space of the value field, and the flow specification rule ORF record includes the route identifier Determining the flow to be sent to the second network device, if the set of route identifiers is empty or the route identifier set includes the route identifier included in the flow specification rule to be sent to the second network device, The specification rules match the flow specification rules ORF record.
  24. 根据权利要求18-23中任一项所述的设备,其特征在于,所述确定模块具体用于:The device according to any one of claims 18 to 23, wherein the determining module is specifically configured to:
    获取第一流规范规则ORF能力参数,所述第一流规范规则ORF能力参数指示所述第二网络设备支持的流规范规则ORF能力,所述第一流规范规则ORF能力参数包括:至少一组由地址族标识、子地址族标识、流规范规则ORF类型和收发能力标识组成的参数集合,所述第一流规范规则ORF能力参数中包括的收发能力标识用于指示所述第二网络设备是否支持发送和/或接收流规范规则ORF记录;Obtaining a first flow specification rule ORF capability parameter, the first flow specification rule ORF capability parameter indicating a flow specification rule ORF capability supported by the second network device, the first flow specification rule ORF capability parameter comprising: at least one group of address families The parameter set consisting of the identifier, the sub-address family identifier, the flow specification rule ORF type, and the transceiver capability identifier, and the transceiver capability identifier included in the first-flow specification rule ORF capability parameter is used to indicate whether the second network device supports sending and/or Or receive a flow specification rule ORF record;
    比较所述第一流规范规则ORF能力参数与第二流规范规则ORF能力参数,所述第二流规范规则ORF能力参数指示所述第一网络设备支持的流规范规则ORF能力,所述第二流规范规则ORF能力参数包括:至少一组由地址族标识、子地址族标识、流规范规则ORF类型和收发能力标识组成的参数集合,所述第二流规范规则ORF能力参数中包括的收发能力标识用于指示所述第一网络设备是否支持发送和/或接收流规范规则ORF记录;Comparing the first flow specification rule ORF capability parameter with a second flow specification rule ORF capability parameter, the second flow specification rule ORF capability parameter indicating a flow specification rule ORF capability supported by the first network device, the second flow The specification rule ORF capability parameter includes: at least one set of parameters consisting of an address family identifier, a sub-address family identifier, a flow specification rule ORF type, and a transceiving capability identifier, and the transceiving capability identifier included in the second stream specification rule ORF capability parameter Means to indicate whether the first network device supports sending and/or receiving a flow specification rule ORF record;
    若所述第一流规范规则ORF能力参数包含的第一参数集合和所述第二流规范规则ORF能力参数包含的第二参数集合都包含流规范规则ORF类型,所述第一参数集合和所述第二参数集合包含相同的地址族标识和子地址族标识,并且所述第一参数集合的收发能力标识指示所述第二网络设备支持发送流规范规则ORF记录,所述第二参数集合的收发能力标识指示所述第一网络设备支持接收流规范规则ORF记录,则确定所述第二网络设备能够向所述第一网络设备发送流规范规则ORF记录。And if the first parameter set included in the first flow specification rule ORF capability parameter and the second parameter set included in the second flow specification rule ORF capability parameter include a flow specification rule ORF type, the first parameter set and the The second parameter set includes the same address family identifier and the sub-address family identifier, and the transceiver capability identifier of the first parameter set indicates that the second network device supports the sending flow specification rule ORF record, and the second parameter set is capable of transmitting and receiving. The identifier indicates that the first network device supports receiving the flow specification rule ORF record, and determining that the second network device is capable of sending a flow specification rule ORF record to the first network device.
  25. 根据权利要求24所述的设备,其特征在于,所述获取第一流规范规则ORF能力参数,包括:The device according to claim 24, wherein the obtaining the first flow specification rule ORF capability parameter comprises:
    在所述第一网络设备与所述第二网络设备建立边界网关协议BGP连接过程中,接收所述第二网络设备发送的BGP开放消息,所述第二网络设备发送的BGP开放消息中包括所述第一流规范规则ORF能力参数。Receiving a BGP open message sent by the second network device, where the first network device and the second network device establish a border gateway protocol BGP connection, where the BGP open message sent by the second network device includes The first-flow specification rule ORF capability parameter.
  26. 根据权利要求18-23中任一项所述的设备,其特征在于,所述接收模块具体用于: The device according to any one of claims 18 to 23, wherein the receiving module is specifically configured to:
    接收所述第二网络设备发送的BGP路由刷新消息,所述BGP路由刷新消息中包括所述流规范规则ORF记录。Receiving a BGP route refresh message sent by the second network device, where the BGP route refresh message includes the flow specification rule ORF record.
  27. 根据权利要求18-23中任一项所述的设备,其特征在于,所述设备还包括存储处理模块;The device according to any one of claims 18 to 23, wherein the device further comprises a storage processing module;
    所述存储处理模块,用于在所述接收模块接收所述第二网络设备发送的流规范规则ORF记录之后,根据所述流规范规则ORF记录中包括的地址族标识和子地址族标识确定所述流规范规则ORF记录的类型,并根据所述流规范规则ORF记录的序列号将所述流规范规则ORF记录有序地存储到对应类型的流规范规则ORF列表中。The storage processing module, configured to determine, after the receiving module receives the flow specification rule ORF record sent by the second network device, according to the address family identifier and the sub-address family identifier included in the flow specification rule ORF record The flow specification rules the type of ORF record, and stores the flow specification rule ORF record in an orderly manner according to the sequence number of the flow specification rule ORF record into the flow specification rule ORF list of the corresponding type.
  28. 一种第二网络设备,其特征在于,包括:A second network device, comprising:
    确定模块,用于确定第一网络设备能够接收流规范规则出站路由过滤ORF记录;a determining module, configured to determine that the first network device is capable of receiving a flow specification rule outbound route filtering ORF record;
    生成模块,用于根据所述第二网络设备保存的流规范规则策略生成流规范规则ORF记录;a generating module, configured to generate a flow specification rule ORF record according to a flow specification rule policy saved by the second network device;
    发送模块,用于将所述生成模块生成的流规范规则ORF记录发送给所述第一网络设备;a sending module, configured to send, to the first network device, a flow specification rule ORF record generated by the generating module;
    接收模块,用于接收所述第一网络设备发送的流规范规则,所述流规范规则为所述第一网络设备根据所述流规范规则ORF记录过滤后的流规范规则。And a receiving module, configured to receive a flow specification rule sent by the first network device, where the flow specification rule is that the first network device records the filtered flow specification rule according to the flow specification rule ORF.
  29. 根据权利要求28所述的设备,其特征在于,所述流规范规则ORF记录包括:流规范规则ORF记录的序列号字段、行动匹配字段、过滤器类型字段、过滤器特定操作和取值字段,所述流规范规则ORF记录的序列号字段用于携带流规范规则ORF记录的优先级,所述行动匹配字段用于携带是否匹配流规范规则的动作类型,所述过滤器类型字段用于携带过滤器类型,所述过滤器特定操作和取值字段用于携带所述过滤器类型对应的过滤条件。The apparatus according to claim 28, wherein said flow specification rule ORF record comprises: a sequence number field of a flow specification rule ORF record, an action matching field, a filter type field, a filter specific operation, and a value field, The sequence number field of the flow specification rule ORF record is used to carry the priority of the flow specification rule ORF record, and the action matching field is used to carry an action type that matches the flow specification rule, and the filter type field is used to carry the filter. The filter type, the filter specific operation and the value field are used to carry the filter condition corresponding to the filter type.
  30. 根据权利要求29所述的设备,其特征在于,所述流规范规则ORF记录还包括:路由标识个数字段和路由标识字段,所述路由标识个数字段用于携带路由标识的个数,所述路由标识字段用于携带路由标识。The device according to claim 29, wherein the flow specification rule ORF record further comprises: a route identifier number field and a route identifier field, wherein the route identifier number field is used to carry the number of route identifiers, The route identifier field is used to carry a route identifier.
  31. 根据权利要求29或30所述的设备,其特征在于,所述流规范规则ORF记录还包括:过滤器个数字段,所述过滤器个数字段用于携带过滤器的个数。The device according to claim 29 or 30, wherein the flow specification rule ORF record further comprises: a filter number field, wherein the filter number field is used to carry the number of filters.
  32. 根据权利要求28-31中任一项所述的设备,其特征在于,所述确定 模块具体用于:Apparatus according to any of claims 28-31, wherein said determining The module is specifically used to:
    获取第二流规范规则ORF能力参数,所述第二流规范规则ORF能力参数指示所述第一网络设备支持的流规范规则ORF能力,所述第二流规范规则ORF能力参数包括:至少一组由地址族标识、子地址族标识、流规范规则ORF类型和收发能力标识组成的参数集合,所述第二流规范规则ORF能力参数中包括的收发能力标识用于指示所述第一网络设备是否支持发送和/或接收流规范规则ORF记录;Obtaining a second flow specification rule ORF capability parameter, where the second flow specification rule ORF capability parameter indicates a flow specification rule ORF capability supported by the first network device, and the second flow specification rule ORF capability parameter includes: at least one group a parameter set consisting of an address family identifier, a sub-address family identifier, a flow specification rule ORF type, and a transceiver capability identifier, where the transceiver capability identifier included in the second-flow specification rule ORF capability parameter is used to indicate whether the first network device is Support for sending and/or receiving flow specification rules ORF records;
    比较所述第二流规范规则ORF能力参数与第一流规范规则ORF能力参数,所述第一流规范规则ORF能力参数指示所述第二网络设备支持的流规范规则ORF能力,所述第一流规范规则ORF能力参数包括:至少一组由地址族标识、子地址族标识、流规范规则ORF类型和收发能力标识组成的参数集合,所述第一流规范规则ORF能力参数中包括的收发能力标识用于指示所述第二网络设备是否支持发送和/或接收流规范规则ORF记录;Comparing the second flow specification rule ORF capability parameter with a first flow specification rule ORF capability parameter, the first flow specification rule ORF capability parameter indicating a flow specification rule ORF capability supported by the second network device, the first flow specification rule The ORF capability parameter includes: at least one set of parameters consisting of an address family identifier, a sub-address family identifier, a flow specification rule ORF type, and a transceiving capability identifier, where the transceiving capability identifier included in the first-flow specification rule ORF capability parameter is used to indicate Whether the second network device supports sending and/or receiving a flow specification rule ORF record;
    若所述第一流规范规则ORF能力参数包含的第一参数集合和所述第二流规范规则ORF能力参数包含的第二参数集合都包含流规范规则ORF类型,所述第一参数集合和所述第二参数集合包含相同的地址族标识和子地址族标识,并且第一参数集合的收发能力标识指示所述第二网络设备支持发送,流规范规则ORF记录,所述第二参数集合的收发能力标识指示所述第一网络设备支持接收流规范规则ORF记录,则确定所述第二网络设备能够向所述第一网络设备发送流规范规则ORF记录。And if the first parameter set included in the first flow specification rule ORF capability parameter and the second parameter set included in the second flow specification rule ORF capability parameter include a flow specification rule ORF type, the first parameter set and the The second parameter set includes the same address family identifier and the sub-address family identifier, and the transceiver capability identifier of the first parameter set indicates that the second network device supports sending, the flow specification rule ORF records, and the second parameter set of the transceiver capability identifier Instructing the first network device to support receiving a flow specification rule ORF record, determining that the second network device is capable of transmitting a flow specification rule ORF record to the first network device.
  33. 根据权利要求32所述的设备,其特征在于,所述获取第二流规范规则ORF能力参数,包括:The device according to claim 32, wherein the obtaining the second flow specification rule ORF capability parameter comprises:
    在所述第二网络设备与所述第一网络设备建立边界网关协议BGP连接的过程中,接收所述第一网络设备发送的BGP开放消息,所述第一网络设备发送的BGP开放消息中包括所述第二流规范规则ORF能力参数。Receiving a BGP open message sent by the first network device, where the second network device establishes a border gateway protocol BGP connection with the first network device, where the BGP open message sent by the first network device includes The second stream normalizes the regular ORF capability parameter.
  34. 根据权利要求28-32中任一项所述的设备,其特征在于,所述发送模块具体用于:The device according to any one of claims 28 to 32, wherein the sending module is specifically configured to:
    向所述第一网络设备发送BGP路由刷新消息,所述BGP路由刷新消息中包括所述流规范规则ORF记录。Sending a BGP route refresh message to the first network device, where the BGP route refresh message includes the flow specification rule ORF record.
  35. 一种网络系统,其特征在于,所述网络系统包括:第一网络设备和第二网络设备;A network system, the network system comprising: a first network device and a second network device;
    所述第一网络设备,用于执行如权利要求1-10任一所述的方法;The first network device is configured to perform the method according to any one of claims 1-10;
    所述第二网络设备,用于执行如权利要求11-17任一所述的方法。 The second network device is configured to perform the method of any one of claims 11-17.
PCT/CN2016/075632 2015-03-23 2016-03-04 Method and device for sending and receiving flow specification rule WO2016150296A1 (en)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201510127833.9 2015-03-23
CN201510127833.9A CN106161226B (en) 2015-03-23 2015-03-23 It sends, the method and apparatus of receiving stream specification rule

Publications (1)

Publication Number Publication Date
WO2016150296A1 true WO2016150296A1 (en) 2016-09-29

Family

ID=56977839

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2016/075632 WO2016150296A1 (en) 2015-03-23 2016-03-04 Method and device for sending and receiving flow specification rule

Country Status (2)

Country Link
CN (1) CN106161226B (en)
WO (1) WO2016150296A1 (en)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN113645154A (en) * 2021-10-12 2021-11-12 阿里云计算有限公司 Method and device for controlling network flow speed

Families Citing this family (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN108924049B (en) * 2018-06-27 2020-12-25 新华三技术有限公司合肥分公司 Flow specification routing scheduling method and device
CN110661714B (en) * 2018-06-30 2022-06-28 华为技术有限公司 Method for sending BGP message, method for receiving BGP message and equipment
CN110505152B (en) * 2019-09-11 2022-02-22 迈普通信技术股份有限公司 Route filtering method and device and electronic equipment
CN116389345A (en) * 2020-03-23 2023-07-04 华为技术有限公司 Method and device for transmitting segmented routing strategy and network transmission system
CN111935100B (en) * 2020-07-16 2022-05-20 锐捷网络股份有限公司 Flowspec rule issuing method, device, equipment and medium
CN115834491A (en) * 2021-09-16 2023-03-21 华为技术有限公司 Message processing method, stream specification transmission method, device, system and storage medium
CN115801676B (en) * 2023-02-13 2023-05-19 北京锐服信科技有限公司 Route filtering method and device and electronic equipment

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20060245374A1 (en) * 2005-04-28 2006-11-02 Keyur Patel Method to scale hierarchical route reflectors using automated outbound route filtering-list mechanism
CN101155175A (en) * 2006-09-27 2008-04-02 华为技术有限公司 Method and device for routing filter based on BGP protocol
CN102611632A (en) * 2012-04-12 2012-07-25 福建星网锐捷网络有限公司 VPLS (Virtual Private LAN Service) output route filtering method and device based on BGP (Border Gateway Protocol)

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20060245374A1 (en) * 2005-04-28 2006-11-02 Keyur Patel Method to scale hierarchical route reflectors using automated outbound route filtering-list mechanism
CN101155175A (en) * 2006-09-27 2008-04-02 华为技术有限公司 Method and device for routing filter based on BGP protocol
CN102611632A (en) * 2012-04-12 2012-07-25 福建星网锐捷网络有限公司 VPLS (Virtual Private LAN Service) output route filtering method and device based on BGP (Border Gateway Protocol)

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN113645154A (en) * 2021-10-12 2021-11-12 阿里云计算有限公司 Method and device for controlling network flow speed
CN113645154B (en) * 2021-10-12 2022-04-15 阿里云计算有限公司 Method and device for controlling network flow speed

Also Published As

Publication number Publication date
CN106161226A (en) 2016-11-23
CN106161226B (en) 2019-06-11

Similar Documents

Publication Publication Date Title
WO2016150296A1 (en) Method and device for sending and receiving flow specification rule
CN112235123B (en) Service function registration mechanism and capability indexing
US10587492B2 (en) Method and apparatus for tracing paths in service function chains
US7996894B1 (en) MAC address modification of otherwise locally bridged client devices to provide security
US10057164B2 (en) Apparatus and methods to aggregate FCoE (fibre channel over ethernet) filter rules of a single interface in a single or few rules on a first-hop FCoE networking element
US7562213B1 (en) Approaches for applying service policies to encrypted packets
US10397066B2 (en) Content filtering for information centric networks
EP3017569B1 (en) Virtual network
US8369333B2 (en) Method and apparatus for transparent cloud computing with a virtualized network infrastructure
US8291114B2 (en) Routing a packet by a device
US10237130B2 (en) Method for processing VxLAN data units
WO2016192396A1 (en) Exchanging application metadata for application context aware service insertion in service function chain
CN111095901A (en) Service operation linking method and computer program
US7990857B2 (en) Priority aware MAC flow control
US7181612B1 (en) Facilitating IPsec communications through devices that employ address translation in a telecommunications network
US7000120B1 (en) Scheme for determining transport level information in the presence of IP security encryption
WO2017107814A1 (en) Method, apparatus and system for propagating qos policies
US8798046B2 (en) Methods and apparatus for providing unique MAC address to individual node for fibre channel over Ethernet (FCoE) traffic
US9917794B2 (en) Redirection IP packet through switch fabric
WO2017133647A1 (en) Packet processing method, traffic classifier, and service function instance
US10165092B2 (en) Using a network service header to manage a network-as-a-system
US9509600B1 (en) Methods for providing per-connection routing in a virtual environment and devices thereof
US7577737B2 (en) Method and apparatus for controlling data to be routed in a data communications network
WO2011082584A1 (en) Implementing method, network and terminal for processing data packet classification
US7522601B1 (en) Filtered router alert hop-by-hop option

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 16767673

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 16767673

Country of ref document: EP

Kind code of ref document: A1