You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何从POX控制器异步下发流表项至OpenFlow交换机(无需交换机主动发起会话)

Can POX Controller Push Flow Entries Asynchronously to OpenFlow Switches Without the Switch Initiating a Session?

Absolutely possible—this is exactly how dynamic firewall use cases (like your IP blocking requirement) are implemented with POX! Once the OpenFlow switch completes its initial handshake and establishes a connection to the POX controller, the controller maintains an active communication channel to the switch. You can send flow modification messages whenever you need to, no trigger or session initiation from the switch is required.

How to Implement This for Dynamic IP Blocking

Here's a breakdown of the key steps and a practical code example tailored to your firewall scenario:

  1. Track Active Switch Connections
    POX's core openflow component keeps a registry of all connected switches. You can access this via core.openflow.connections, which maps switch DPIDs to their active connection objects.

  2. Construct a Flow Modification Message
    When you need to block an IP (e.g., in response to a security alert, API call, or scheduled trigger), build an ofp_flow_mod message that targets the IP and sets a drop action.

  3. Send the Message Directly to the Switch
    Use the connection object's send_msg() method to push the flow rule to the switch immediately.

Example Code Snippet

from pox.core import core
import pox.openflow.libopenflow_01 as of

# Initialize logger
log = core.getLogger()

def block_target_ip(dpid, src_ip=None, dst_ip=None):
    # Fetch the active switch connection
    if dpid not in core.openflow.connections:
        log.error(f"Switch {dpid} is not connected to the controller!")
        return
    
    switch_conn = core.openflow.connections[dpid]
    
    # Create a flow modification message to add a block rule
    flow_mod = of.ofp_flow_mod()
    flow_mod.command = of.OFPFC_ADD
    
    # Match criteria: target source/destination IP (adjust as needed)
    if src_ip:
        flow_mod.match.nw_src = src_ip
    if dst_ip:
        flow_mod.match.nw_dst = dst_ip
    
    # Set high priority to ensure this rule overrides default allow flows
    flow_mod.priority = 1000
    
    # No actions = drop packets (OpenFlow 1.0 behavior)
    flow_mod.actions = []
    
    # Optional: Add timeout if you want the block to auto-expire
    # flow_mod.hard_timeout = 300  # Blocks for 5 minutes
    
    # Send the rule to the switch
    switch_conn.send_msg(flow_mod)
    log.info(f"Successfully blocked IP on switch {dpid}: src={src_ip}, dst={dst_ip}")

# Example: Trigger block when a switch connects (hook to your own event instead)
def _handle_switch_connect(event):
    # Block a malicious IP as soon as switch 1 connects
    block_target_ip(1, src_ip="192.168.1.100")

def launch():
    core.openflow.addListenerByName("ConnectionUp", _handle_switch_connect)
    log.info("Dynamic IP Block Controller is running")

Key Notes for Your Firewall Use Case

  • Priority Matters: Ensure your block rules have a higher priority than any default allow-all rules you might have, so they take precedence.
  • Auto-Expiry: Use hard_timeout or idle_timeout in the flow mod if you want temporary blocks (useful for mitigating short-lived threats).
  • Reconnection Handling: Re-push critical block rules when a switch reconnects (use the ConnectionUp event like in the example) to maintain protection after switch restarts.

内容的提问来源于stack exchange,提问作者newbie stackoverflow

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.27 06:52:53