Looking for breakthrough ideas for innovation challenges? Try Patsnap Eureka!

Method for realizing network security platform of IP software router by utilizing VLAN technology

A technology of network security and software, applied in the direction of network interconnection, data exchange network, electrical components, etc., can solve the problems of limited number of interfaces, high cost, loss of competitiveness, etc., and achieve the effect of solving multi-port problems and reducing costs

Active Publication Date: 2012-04-18
SHANGHAI JISHENG NETWORK TECH
View PDF2 Cites 0 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

If the traditional X86 technology design is used, it is difficult to achieve more than 10 network interfaces by using PCI expansion technology
Because the number of PCI expandable interfaces is limited (usually 3 to 4 network ports can be expanded), and the cost is quite high (several times switching technology), especially for low-end products, the high cost will lose the market. Competitiveness

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Method for realizing network security platform of IP software router by utilizing VLAN technology
  • Method for realizing network security platform of IP software router by utilizing VLAN technology
  • Method for realizing network security platform of IP software router by utilizing VLAN technology

Examples

Experimental program
Comparison scheme
Effect test

Embodiment

[0015] like figure 2 Shown, the concrete steps of a kind of method utilizing VLAN technology to realize the network security platform of IP software routing provided by the invention are:

[0016] Step 1. Select a Layer 2 Ethernet switching chip with network management function, connect one end of it to the physical layer chip, and connect the other end to the CPU through a bus. The bus can be MII 100M, GMII Gigabit or PCI interface, so as to provide The CPU expands at least 10 Ethernet interfaces, and each Ethernet interface is a switching port. After completing step 1, the following is built. figure 1 The frame shown in this figure illustrates the interface between the switch chip and the CPU and its requirements. In this figure, as long as it is a Layer 2 Ethernet switch chip with VLAN with network management functions, it can be used. For example, VIA company, Also can be the chip of BroadCom company, can also be the chip of Marvell company, choose the model of Joyoung E...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

PUM

No PUM Login to View More

Abstract

The invention provides a method for realizing an embedded and switched network security platform of an IP software router by utilizing a VLAN technology. The method is characterized by comprising the following steps of: selecting a two-layer Ethernet switch chip with a network management function; accessing the chip to a CPU (Central Processing Unit) system; configuring each switch port and a busport between the CPU and the two-layer Ethernet switch chip separately into a same VLAN group; after the two-layer Ethernet switch chip receives data messages from a physical layer chip, stopping datatransmission in the interior of the switch chip by VLA, thus completely transmitting the data to the CPU and being received by the CPU; and carrying out post-processing after the CPU receives and submits the data to an IP layer. The method has the advantages of leading users to obtain network interfaces of a plurality of separate network segments by extremely low hardware cost, solving the problem of network security equipment with multi-ports, greatly reducing the cost of network security equipment and having the characteristic of high stability.

Description

technical field [0001] The invention relates to a method for implementing an embedded switching network safety platform using VLAN technology to realize IP software routing, which is used for realizing network safety functions such as three-layer IP routing and packet filtering firewall on a two-layer Ethernet switch. Background technique [0002] Traditional network devices, such as routers, firewalls / VPN / IDS / UTM and other network security devices, in practical applications, due to the existence of multiple security domains and multiple access paths, usually need to design multiple (more than 10 or even more than 16 , 24, 48, etc.) network interfaces. If the traditional X86 technology is used to design and utilize the PCI expansion technology, it is difficult to achieve more than 10 network interfaces. Because the number of PCI expandable interfaces is limited (usually 3 to 4 network ports can be expanded), and the cost is quite high (several times switching technology), e...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

Application Information

Patent Timeline
no application Login to View More
Patent Type & Authority Patents(China)
IPC IPC(8): H04L29/06H04L12/56H04L12/46H04L12/773
Inventor 周耀华
Owner SHANGHAI JISHENG NETWORK TECH
Who we serve
  • R&D Engineer
  • R&D Manager
  • IP Professional
Why Patsnap Eureka
  • Industry Leading Data Capabilities
  • Powerful AI technology
  • Patent DNA Extraction
Social media
Patsnap Eureka Blog
Learn More
PatSnap group products