Fast path complex flow processing
Abstract
Methods and systems for processing complex flows are provided. According to one embodiment, a packet associated with a complex flow is received. A first flow-based packet classification is performed based on a first set of attributes of the packet. A first flow processing operation is identified by performing a first flow cache lookup based on the first flow-based packet classification and the first flow processing operation is performed on the packet. After performing the first flow processing operation on the packet, a second flow-based packet classification of the packet is performed based on a second set of attributes of the packet. A second flow processing operation is identified by performing a second flow cache lookup based on the second flow-based packet classification and the second flow processing operation is performed on the packet. Finally, the packet is sent to an egress interface.
Claims
exact text as granted — not AI-modified1 . A method comprising:
receiving, by a virtual router (VR) of a VR-based switch, a packet associated with a complex flow; causing, by the VR an Internet Protocol (IP) flow cache architecture of the VR-based switch to perform a first flow-based packet classification based on a first set of attributes of the packet; identifying a first flow processing operation by performing a first flow cache lookup based on the first flow-based packet classification; performing the first flow processing operation on the packet; after performing the first flow processing operation on the packet, causing the IP flow cache architecture to perform a second flow-based packet classification of the packet based on a second set of attributes of the packet; identifying a second flow processing operation by performing a second flow cache lookup based on the second flow-based packet classification; performing the second flow processing operation on the packet; sending the packet to an egress interface of the VR-based switch.
2 . The method of claim 1 , further comprising:
after performing the second flow processing operation on the packet and before sending the packet to the egress interface, causing the IP flow cache architecture to perform a third flow-based packet classification of the packet based on a third set of attributes of the packet; identifying a third flow processing operation by performing a third flow cache lookup based on the second flow-based packet classification; and performing the third flow processing operation on the packet.
3 . The method of claim 1 , wherein the complex flow is a strict layer 3 flow.
4 . The method of claim 1 , wherein the complex flow is a tunneled flow.
5 . The method of claim 1 , wherein the complex flow is an encrypted flow.
6 . The method of claim 2 , wherein the first flow processing operation comprises reassembling a plurality of IP fragments, the second flow processing operation comprises decrypting the packet and the third flow processing operation comprises looking up forwarding information for the packet.
7 . The method of claim 2 , wherein the first set of attributes comprise layer 3 attributes.
8 . The method of claim 2 , wherein the second set of attributes comprise layer 4 attributes.
9 . A method comprising:
receiving, by an ingress interface of a switching device, a plurality of packets associated with a complex ingress flow; performing fast path processing of the plurality of packets by the switching device by causing each of the plurality of packets to be classified multiple times, performing multiple flow cache lookups for each of the plurality of packets and applying packet transformations identified by the multiple flow cache lookups to the plurality of packets; and transmitting, by an egress interface of the switching device, the plurality of packets.
10 . The method of claim 9 , wherein the complex ingress flow is a strict layer 3 flow.
11 . The method of claim 9 , wherein the complex ingress flow is a tunneled flow.
12 . The method of claim 9 , wherein the complex ingress flow is an encrypted flow.
13 . The method of claim 10 , wherein said applying packet transformations identified by the multiple flow cache lookups comprises one or more of reassembling a plurality of Internet Protocol fragments, decrypting the plurality of packets and the forwarding the plurality of packets.
14 . The method of claim 10 , wherein said performing multiple flow cache lookups for each of the plurality of packets comprises extracting a first set of attributes from the packet for a first lookup of the multiple flow cache lookups and extracting a second set of attributes from the packet for a second lookup of the multiple flow cache lookups.
15 . The method of claim 14 , wherein the first set of attributes comprise layer 4 attributes and the second set of attributes comprise layer 3 attributes.
16 . A computer-readable storage medium readable by one or more processing elements of a plurality of processing elements of a virtual router (VR)-based switch, the computer-readable storage medium tangibly embodying a set of instructions executable by one or more processors of the plurality of processing elements to perform method for performing fast path processing of complex flows, the method comprising:
receiving a packet associated with a complex flow; performing a first flow-based packet classification based on a first set of attributes of the packet; identifying a first flow processing operation by performing a first flow cache lookup based on the first flow-based packet classification; performing the first flow processing operation on the packet; after performing the first flow processing operation on the packet, performing a second flow-based packet classification of the packet based on a second set of attributes of the packet; identifying a second flow processing operation by performing a second flow cache lookup based on the second flow-based packet classification; performing the second flow processing operation on the packet; sending the packet to an egress interface of the VR-based switch.
17 . The computer-readable storage medium of claim 16 , wherein the method further comprises:
after performing the second flow processing operation on the packet and before sending the packet to the egress interface, performing a third flow-based packet classification of the packet based on a third set of attributes of the packet; identifying a third flow processing operation by performing a third flow cache lookup based on the second flow-based packet classification; and performing the third flow processing operation on the packet.
18 . The computer-readable storage medium of claim 16 , wherein the complex flow is a strict layer 3 flow, a tunneled flow or an encrypted flow.
19 . The computer-readable storage medium of claim 16 , wherein the first set of attributes comprise layer 3 attributes and the second set of attributes comprises layer 4 attributes.
20 . The computer-readable storage medium of claim 17 , wherein the first flow processing operation comprises reassembling a plurality of Internet Protocol (IP) fragments, the second flow processing operation comprises decrypting the packet and the third flow processing operation comprises looking up forwarding information for the packet.Join the waitlist — get patent alerts
Track US2011032942A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.