摘要:
A system is provided comprising one or more application layer audit proxies arranged to obtain application layer network traffic sent in a network. Each of the application layer audit proxies configured to: receive application layer network traffic sent as part of a communication session between a producer entity and a consumer entity; record information about the application layer network traffic to an audit log in a distributed permissioned database comprising a blockchain of immutable data blocks; and forward the application layer network traffic to the producer entity or to the consumer entity.
摘要:
A system and method for advertising out-of-resources (OOR) conditions for entities, such as nodes, line cards and data links, in a manner that does not involve using a maximum cost to indicate the entity is “out-of-resources.” According to the technique, an OOR condition for an entity is advertised in one or more type-length-value (TLV) objects contained in an advertisement message. The advertisement message is flooded to nodes on a data network to inform them of the entity's OOR condition. Head-end nodes that process the advertisement message may use information contained in the TLV object to determine a path for a new label switched path (LSP) that does not include the entity associated with the OOR condition.
摘要:
A network includes a route reflector peered with client routers. From a perspective of the route reflector, a best path to the destination address is selected by applying to candidate paths ordered comparison tests that progress from policy tests through one or more additional tests until the best path is selected. A determination is made as to whether the best path was selected based on the policy tests exclusively. If the best path was selected based on the policy tests exclusively, the best path is assigned to each of the client routers. If the best path was not selected based on the policy tests exclusively, from a perspective of each client router, a respective best path is selected by applying to the candidate paths the one or more additional tests, and the respective best paths are assigned to the respective client routers.
摘要:
A method, apparatus, and computer readable medium are disclosed. In one embodiment of the method, a packet and a segment ID stack is received at a first segment routing enabled node. The segment ID stack includes a plurality of segment IDs, one or which is a first area-segment ID that identifies a first area of a subdivided segment routing network. An egress interface of the first segment routing enabled node is selected based on the first area-segment ID. Thereafter, the packet is forwarded via the selected egress interface.
摘要:
In one embodiment, a packet and a segment ID stack is received at a node. The segment ID stack includes a plurality of segment IDs, one or which is a first area-segment ID that identifies a first area of a subdivided network. One of a plurality of forwarding tables at the node is selected based on the first area-segment ID. Thereafter, the packet is forwarded based on information contained in the selected forwarding table.
摘要:
A method for load balancing based on metadata in a network service header. The method includes receiving a packet or frame of a traffic flow, wherein the packet or frame has a payload and the network service header including metadata and service path information for the traffic flow identifying the service path, and the metadata comprises classification information of the packet or frame, extracting, by a service header processor of the load balancer, the classification information of the metadata from the packet or frame, and applying, by a load balancing function of the load balancer, a load balancing policy on the packet or frame based on the classification information of the metadata.
摘要:
A method and apparatus for forwarding packets through a network domain that contains nodes that are label distribution protocol (LDP) enabled and nodes that are segment routing (SR) enabled. In one embodiment, the method may include a network node receiving a packet with a label attached thereto. The node swaps the label with a segment identifier (ID). The node then forwards the packet to an SR node. In another embodiment, the method may include a network node receiving a packet with a segment ID attached thereto. The node swaps the segment ID with a label. The node then forwards the packet to an LDP enabled node.
摘要:
A system and method for advertising out-of-resources (OOR) conditions for entities, such as nodes, line cards and data links, in a manner that does not involve using a maximum cost to indicate the entity is “out-of-resources.” According to the technique, an OOR condition for an entity is advertised in one or more type-length-value (TLV) objects contained in an advertisement message. The advertisement message is flooded to nodes on a data network to inform them of the entity's OOR condition. Head-end nodes that process the advertisement message may use information contained in the TLV object to determine a path for a new label switched path (LSP) that does not include the entity associated with the OOR condition.
摘要:
An apparatus and method is disclosed for segment routing (SR) over label distribution protocol (LDP). In one embodiment, the method includes a node receiving a packet with an attached segment ID. In response, the node may attach a label to the packet. Thereafter, the node may forward the packet with the attached label and segment ID to another node via a label switched path (LSP).
摘要:
A system is provided comprising one or more application layer audit proxies arranged to obtain application layer network traffic sent in a network. Each of the application layer audit proxies configured to: receive application layer network traffic sent as part of a communication session between a producer entity and a consumer entity; record information about the application layer network traffic to an audit log in a distributed permissioned database comprising a blockchain of immutable data blocks; and forward the application layer network traffic to the producer entity or to the consumer entity.