METHOD AND DEVICE FOR VERIFYING SRV6 PACKET
Embodiments of this application disclose a method for verifying an SRv6 packet. An egress node of an IPsec tunnel may receive an SRv6 packet, where the SRv6 packet is a packet encapsulated in an IPsec transport mode. The SRv6 packet includes an AH and at least one SRH. The SRv6 packet carries first...
Gespeichert in:
Hauptverfasser: | , , , |
---|---|
Format: | Patent |
Sprache: | eng ; fre ; ger |
Schlagworte: | |
Online-Zugang: | Volltext bestellen |
Tags: |
Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
|
Zusammenfassung: | Embodiments of this application disclose a method for verifying an SRv6 packet. An egress node of an IPsec tunnel may receive an SRv6 packet, where the SRv6 packet is a packet encapsulated in an IPsec transport mode. The SRv6 packet includes an AH and at least one SRH. The SRv6 packet carries first indication information, where the first indication information indicates the egress node to perform AH verification on the SRv6 packet. A verification range of the AH verification includes the at least one SRH. The method may prevent a network hacker from performing a network attack by using an SRH. For example, the method may prevent a network hacker from performing a network attack by tampering with an SRH or inserting a new SRH. In addition, this solution has the following advantages: consuming less resources, preventing replay attacks, supporting key agreement, verifying an SRH of an SRv6 packet when the SRH is used to forward the SRv6 packet, and the like. |
---|