Generalized forwarding and SDN

Earlier, we described destination-based forwarding as two steps:

  1. match: find the destination IP address
  2. action: send the packet through the switching fabric to the correct output port

The match-plus-action pattern

This "match-plus-action" pattern is widely used in networking devices:

In this generalized model: a match-plus-action table extends the traditional forwarding table used in destination-based routing.

Devices that use this approach are called programmable or flow-based packet switches, because they can make decisions using both network-layer and link-layer addresses. This term is increasingly used instead of just layer 3 "routers" or layer 2 "switches".

These match-and-action capabilities are controlled by a remote SDN controller that computes, installs, and updates match-plus-action tables in each packet switch.

OpenFlow

OpenFlow helped introduce the match-plus-action model and played a major role in the development of SDN.

Each rule in the match-plus-action forwarding table (known as a flow table entry in OpenFlow) includes:

Match

In OpenFlow 1.0, a match-and-action rule can match:

OpenFlow's match abstraction:

As a result, an an OpenFlow-enabled device can act as:

Originally, OpenFlow 1.0 supported 12 match fields. Later versions introduced a much more flexible and extensible match structure rather than a fixed count of fields.

Action

Each flow table entry contains a list of zero or more actions that are applied to matching packets.

Possible actions are:

OpenFlow examples of match-plus-action

To show how flexible generalized forwarding is, consider a network with:

Simple forwarding

Goal:

Flow table entry in s3:

Match                                                       Action
IP Src = 10.3.*.* ; IP Dst = 10.2.*.*                       Forward(3)

Flow table entry in s1:

Match                                                       Action
Ingress Port = 1 ; IP Src = 10.3.*.* ; IP Dst = 10.2.*.*    Forward(4)

Flow table entry in s2:

Match                                                       Action
Ingress port = 2 ; IP Dst = 10.2.0.3                        Forward(3)
Ingress port = 2 ; IP Dst = 10.2.0.4                        Forward(4)

Load balancing

Goal:

Flow table entry in s2:

Match                                                       Action
Ingress port = 3; IP Dst = 10.1.*.*                         Forward(2)
Ingress port = 4; IP Dst = 10.1.*.*                         Forward(1)

Additional rules are needed:

Firewalling

Goal:

Flow table entry in s2:

Match                                                       Action
IP Src = 10.3.*.* IP Dst = 10.2.0.3                         Forward(3)
IP Src = 10.3.*.* IP Dst = 10.2.0.4                         Forward(4)

If no other rules exist: all other traffic is effectively blocked.

Previous IP address space management All ⏎ Next Middleboxes

A Kemar Joint