Abstract:
This application provides a BIER multicast traffic statistics collection method, a device, and a system. The method includes: A first network device obtains a first BIER packet. The first network device performs traffic statistics collection on the first BIER packet based on multicast flow information, to obtain a traffic statistics collection result of the first BIER packet, where the multicast flow information is used to identify a multicast flow to which the first BIER packet belongs. The first network device sends the multicast flow information and the traffic statistics collection result of the first BIER packet to a controller.
Abstract:
This application provides a BIER multicast traffic statistics collection method, a device, and a system. The method includes: A first network device obtains a first BIER packet. The first network device performs traffic statistics collection on the first BIER packet based on multicast flow information, to obtain a traffic statistics collection result of the first BIER packet, where the multicast flow information is used to identify a multicast flow to which the first BIER packet belongs. The first network device sends the multicast flow information and the traffic statistics collection result of the first BIER packet to a controller.
Abstract:
A method for preventing a replay attack on a Segment Routing over Internet Protocol version 6 (SRv6) keyed hashed message authentication code (HMAC) verification. The method includes a network device receiving an SRv6 packet comprising anti-replay attack verification information. The network device performs anti-replay attack verification based on the anti-replay attack verification information. The network device performs HMAC hash computation on the SRv6 packet in response to the first SRv6 packet passing passes the anti-replay attack verification.
Abstract:
Embodiments of the present invention provide a network label allocation method, a device, and a system, which enable a local PE to distinguish packets from different remote PEs. The method includes: generating, by a local provider edge PE, a VPN label route for each remote PE, where VPN labels in VPN label routes of different remote PEs are different, and the remote PE and the local PE at least belong to a same VPN; and sending the VPN label route to the remote PE, so that the remote PE separately matches an IP address of the remote PE with a target device IP address in the VPN label route, and matches an import route target RT of each VRF of the remote PE with a route target RT in the VPN label route, a packet related to a successfully matched VRF.
Abstract:
Embodiments of this application disclose a method for verifying an SRv6 packet. An egress node of an IPsec tunnel may receive an SRv6 packet, where the SRv6 packet is a packet encapsulated in an IPsec transport mode. The SRv6 packet includes an AH and at least one SRH. The SRv6 packet carries first indication information, where the first indication information indicates the egress node to perform AH verification on the SRv6 packet. A verification range of the AH verification includes the at least one SRH.
Abstract:
A method and network device for distributing Multi-Protocol Label Switching (MPLS) labels are provided by the present invention. The method for distributing the MPLS labels includes: a first device receives a Border Gateway Protocol (BGP) protocol message transmitted from a second device, wherein the BGP protocol message carries a service identifier of the second device; the first device establishes, according to the service identifier of the first device and the service identifier of the second device, a corresponding relationship between the first device and the second device; the first device distributes a MPLS label for the corresponding relationship. The present invention realizes that the MPLS labels are distributed for some type of the specific logical relationship between the two nodes in the BGP protocol, so that the network devices running the BGP protocol can efficiently obtain the MPLS label corresponding to the specific logical relationship.
Abstract:
A method for sending a multicast packet provided in embodiments of this application includes: a first network device obtains a first multicast packet, where the first multicast packet includes a bit string bit string and an identifier of a network slice, the bit string corresponds to a second network device, and the network slice corresponds to a multicast service of the second network device. The first network device obtains, based on the bit string and the identifier of the network slice, a first interface corresponding to the network slice. The first network device sends the first multicast packet to the second network device by using the first interface.
Abstract:
A method and network device for distributing Multi-Protocol Label Switching (MPLS) labels are provided by the present invention. The method for distributing the MPLS labels includes: a first device receives a Border Gateway Protocol (BGP) protocol message transmitted from a second device, wherein the BGP protocol message carries a service identifier of the second device; the first device establishes, according to the service identifier of the first device and the service identifier of the second device, a corresponding relationship between the first device and the second device; the first device distributes a MPLS label for the corresponding relationship. The present invention realizes that the MPLS labels are distributed for some type of the specific logical relationship between the two nodes in the BGP protocol, so that the network devices running the BGP protocol can efficiently obtain the MPLS label corresponding to the specific logical relationship.