摘要 |
A cascade system of network units includes forwarding units which have external ports, a communication fabric connecting the units and at least one processing unit which has no external port by which a packet can egress from the system. The processing unit may perform a security operation such as intrusion prevention or encryption. Each forwarding unit is operable on receipt of a packet to perform a look-up to determine an egress port, to determine whether the packet must be diverted to a processing unit, to provide the packet with a first forwarding instruction 57 identifying the egress port and a second forwarding instruction 58 identifying a diversion port by which the packet can reach the processing unit and to set an order field 59 which determines which of the forwarding instructions shall be performed first. The processing unit need not have any forwarding database and is operative on receipt of the packet by way of the diversion port to change the order field to specify that the packet should now be sent to the egress port. |