Penalty-box policers for network device control plane protection

    公开(公告)号:US10193807B1

    公开(公告)日:2019-01-29

    申请号:US15339473

    申请日:2016-10-31

    IPC分类号: H04L12/801 H04L12/825

    摘要: In general, techniques are described for dynamically controlling host-bound traffic by dynamically adding and updating, within the forwarding plane of a network device, network packet policers that each constrains, for one or more packet flows, an amount of host-bound traffic of the packet flows permitted to reach the control plane in accordance with available resources. In one example, a control plane of the network device detects internal congestion in the communication path from the forwarding plane to control plane (the “host-bound path”), identifies packet flows utilizing an excessive amount of host-bound path resources, computes limits for the identified packet flows, and adds “penalty-box policers” configured with the computed limits for the identified packet flows to the forwarding plane. The forwarding plane subsequently applies the policers to the identified packet flows to constrain the amount of traffic of the packet flows allowed to reach the control plane to the computed limits.

    Penalty-box policers for network device control plane protection
    2.
    发明授权
    Penalty-box policers for network device control plane protection 有权
    用于网络设备控制平面保护的处罚机

    公开(公告)号:US09485118B1

    公开(公告)日:2016-11-01

    申请号:US13631652

    申请日:2012-09-28

    IPC分类号: H04L12/54 H04L12/801

    CPC分类号: H04L12/5695 H04L47/10

    摘要: In general, techniques are described for dynamically controlling host-bound traffic by dynamically adding and updating, within the forwarding plane of a network device, network packet policers that each constrains, for one or more packet flows, an amount of host-bound traffic of the packet flows permitted to reach the control plane in accordance with available resources. In one example, a control plane of the network device detects internal congestion in the communication path from the forwarding plane to control plane (the “host-bound path”), identifies packet flows utilizing an excessive amount of host-bound path resources, computes limits for the identified packet flows, and adds “penalty-box policers” configured with the computed limits for the identified packet flows to the forwarding plane. The forwarding plane subsequently applies the policers to the identified packet flows to constrain the amount of traffic of the packet flows allowed to reach the control plane to the computed limits.

    摘要翻译: 通常,描述了通过在网络设备的转发平面内动态地添加和更新网络分组策略器来动态地控制主机绑定业务的技术,所述网络分组策略对于一个或多个分组流限制了一个或多个分组流量的主机绑定业务量 允许根据可用资源到达控制平面的分组流。 在一个示例中,网络设备的控制平面检测从转发平面到控制平面(“主机绑定路径”)的通信路径中的内部拥塞,利用过多的主机绑定路径资源来识别分组流,计算 对所标识的分组流的限制,并且将配置有所识别的分组流的计算的限制的“惩罚方框策略器”添加到转发平面。 转发平面随后将策略器应用于所识别的分组流,以将允许到达控制平面的分组流的流量约束到计算的极限。