Packet processing method, apparatus, and system, and storage medium
A packet processing method is disclosed. According to the method, a first network device receives a first packet sent by a second network device, where the first packet includes a first group identifier corresponding to a VPN on the second network device, a first source device corresponding to the first packet belongs to the VPN, and the first source device is connected to the second network device. The first network device obtains a second group identifier based on a destination address of the first packet, where the second group identifier corresponds to the VPN on a third network device, a first destination device corresponding to the destination address of the first packet belongs to the VPN, and the first destination device is connected to the third network device. The first network device processes the first packet based on the first group identifier and the second group identifier.
1 . A network device, comprising:
at least one processor;
one or more memories coupled to the at least one processor and storing programming instructions that, when executed by the at least one processor, cause the network device to:
receive a first packet sent by a second network device, wherein the network device comprises a provider edge device (PE), the second network device comprises a first customer premises equipment (CPE) connected to a first source device, and the first packet comprises a first group identifier corresponding to a virtual private network (VPN) on the second network device, the first source device corresponds to the first packet and belongs to the VPN;
obtain a second group identifier based on a destination address of the first packet, wherein obtaining the second group identifier comprises performing a lookup in stored correspondence that maps a destination address to the second group identifier, and wherein the second group identifier corresponds to the VPN on a third network device, the third network device comprises a second CPE connected to a first destination device, the first destination device corresponds to the destination address of the first packet and belongs to the VPN, and the first destination device is connected to the third network device; and
process the first packet based on the first group identifier and the second group identifier by determining, from stored correspondence information, a first processing policy for interconnection between the first and second CPEs,
wherein the stored correspondence information correlates the first group identifier and the second group identifier with a processing policy.
2 . The network device according to claim 1 , wherein the programming instructions, when executed by the at least one processor, further cause the network device to:
obtain the first processing policy based on the first group identifier and the second group identifier; and
process the first packet based on the first processing policy.
3 . The network device according to claim 2 , wherein the programming instructions, when executed by the at least one processor, further cause the network device to:
obtain the first processing policy based on the first group identifier, the second group identifier, and a first correspondence, wherein the first correspondence comprises the first group identifier, the second group identifier, and the first processing policy.
4 . The network device according to claim 2 , wherein the programming instructions, when executed by the at least one processor, further cause the network device to:
send the first packet to the third network device when the first processing policy indicates that a transmission direction from the second network device to the third network device is connected; or
discard the first packet when the first processing policy indicates that the transmission direction from the second network device to the third network device is isolated.
5 . The network device according to claim 4 , wherein the first processing policy further indicates that a transmission direction from the third network device to the second network device is connected, or the first processing policy further indicates that the transmission direction from the third network device to the second network device is isolated.
6 . The network device according to claim 1 , wherein the programming instructions, when executed by the at least one processor, further cause the network device to:
obtain routing information used to send the first packet, wherein the routing information comprises an address of the third network device based on the destination address of the first packet; and
obtain the second group identifier based on the address of the third network device, a network identifier of the VPN, and a second correspondence, wherein the second correspondence comprises the address of the third network device, the network identifier of the VPN, and the second group identifier.
7 . The network device according to claim 1 , wherein the first group identifier is comprised in an internet protocol version 6 (IPv6) extension header of the first packet.
8 . The network device according to claim 7 , wherein the first group identifier is comprised in an application-aware networking (APN) identifier of the IPv6 extension header.
9 . The network device according to claim 1 , wherein the programming instructions, when executed by the at least one processor, further cause the network device to:
receive a second packet sent by the second network device, wherein the second packet comprises a third group identifier corresponding to the VPN on the second network device, a second source device corresponding to the second packet belongs to the VPN, and the second source device is connected to the second network device;
obtain a fourth group identifier based on a destination address of the second packet, wherein the fourth group identifier corresponds to the VPN on a fourth network device, a second destination device corresponding to the destination address of the second packet belongs to the VPN, and the second destination device is connected to the fourth network device; and
process the second packet based on the third group identifier and the fourth group identifier, wherein
the processing of the first packet comprises sending the first packet to the third network device, and the processing of the second packet comprises discarding the second packet.
10 . The network device according to claim 1 , wherein the second network device comprises the first CPE connected to the first source device, and the third network device comprises the second CPE connected to the first destination device.
11 . A network device, comprising:
at least one processor;
one or more memories coupled to the at least one processor and storing programming instructions that, when executed by the at least one processor, cause the network device to:
obtain a first packet from a first source device connected to a first customer premises equipment (CPE), wherein the network device is connected to the CPE, the first source device and the CPE belong to a virtual private network (VPN), and the first packet comprises a first group identifier corresponding to the VPN on the network device;
obtain a second group identifier based on a destination address of the first packet, wherein obtaining the second group identifier comprises performing a lookup in stored correspondence that maps the destination address to the second group identifier, the second group identifier corresponding to the VPN on another network device that is connected to a second CPE providing access to a destination device belonging to the VPN,
determine, from stored correspondence information, a first processing policy for interconnection between the first CPE and the second CPE, wherein the stored correspondence information correlates the first group identifier and the second group identifier with a processing policy; and
send the first packet to another network device based on the first processing policy, wherein the another network device corresponds to the VPN and is connected to a second CPE that provides access to a destination device belonging to the VPN.
12 . The network device according to claim 11 , wherein the programming instructions, when executed by the at least one processor, further cause the network device to:
obtain the first group identifier based on a network identifier of the VPN and a first correspondence, wherein the first correspondence comprises the network identifier of the VPN and the first group identifier.
13 . The network device according to claim 12 , wherein the first correspondence further comprises a first address, and the first address comprises one or more of:
a source address of the first packet or a destination address of the first packet; and
the programming instructions, when executed by the at least one processor, further cause the network device to:
obtain the first group identifier based on the network identifier of the VPN, the first address, and the first correspondence.
14 . The network device according to claim 12 , wherein the network device comprises a first interface bound to the VPN, the first interface is connected to the first source device, and the programming instructions, when executed by the at least one processor, further cause the network device to:
receive a third packet sent by the first source device through the first interface; and
obtain the first packet based on the third packet, wherein the first packet comprises the network identifier of the VPN.
15 . The network device according to claim 11 , further comprising a customer premises equipment (CPE).
16 . The network device according to claim 11 , wherein the other network device comprises a network-side edge device.
17 . A packet processing system, comprising a first network device and a second network device,
wherein the second network device is configured to:
obtain a first packet from a first source device connected to a first customer premises equipment (CPE), the first CPE being connected to the second network device, wherein the first source device and the first CPE belong to a virtual private network (VPN), and the first packet comprises a first group identifier corresponding to the VPN on the second network device; and
send the first packet to the first network device;
wherein the first network device is configured to:
receive the first packet sent by the second network device;
obtain a second group identifier based on a destination address of the first packet, wherein obtaining the second group identifier comprises performing a lookup in stored correspondence that maps a destination address to the second group identifier, and wherein the second group identifier corresponds to the VPN on a third network device connected to a second CPE, the second CPE being connected to a first destination device corresponding to the destination address of the first packet, and the first destination device belongs to the VPN; and
process the first packet based on the first group identifier and the second group identifier by determining, from stored correspondence information, a first processing policy for interconnection between the first and second CPEs,
wherein the stored correspondence information correlates the first group identifier and the second group identifier with a processing policy.
18 . The system according to claim 17 , wherein the first network device is further configured to:
obtain the first processing policy based on the first group identifier and the second group identifier; and
process the first packet based on the first processing policy.
19 . The system according to claim 17 , wherein the first group identifier is comprised in an internet protocol version 6 (IPv6) extension header of the first packet.