DPU switch port mode data transmission method and device based on FreeBSD open source protocol stack
By adding switch port mode attributes and modifying ifconfig command line code in the FreeBSD protocol stack, automatic virtual LAN tag management of data packets is solved, and the problem that VLAN technology cannot effectively isolate and forward broadcast messages is improved, and the security and stability of the network are improved.
Patent Information
- Application Number
- CN202411138523.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-08-19
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2044-08-19
AI Technical Summary
The VLAN technology of the FreeBSD protocol stack cannot limit broadcast packets to one VLAN for forwarding, and cannot securely isolate different VLANs, resulting in degradation of network performance and low security.
Add switch-like port mode attributes in the FreeBSD protocol stack architecture, and modify ifconfig command line code to automatically add or remove virtual LAN tags during transmission, and forward and isolate data packets according to port mode.
It realizes forwarding of broadcast messages within the same virtual LAN and isolation between different virtual LANs, reduces broadcast storms and enhances network security and stability.
Smart Images

Figure CN118890327B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network data forwarding, and in particular to a DPU switch port mode data transmission method and device based on a FreeBSD open source protocol stack. Background Art
[0002] With the continuous development of computer network technology, network traffic is increasing, network topology is becoming more and more complex, and traditional network forwarding technology can no longer meet the needs of modern network management. As an emerging network technology, network virtual local area network (VLAN) technology achieves effective management and secure isolation of network resources by establishing logical network isolation on the physical network. However, VLAN implementation usually relies on physical switches, which not only increases the cost of network equipment, but also limits the flexibility and scalability of VLAN. In particular, the processing of different types of switch ports not only improves the flexibility of management and the ability of logical grouping, but also brings many conveniences to network design and management.
[0003] As an open source Unix-like operating system, FreeBSD has been widely used in the field of computer networks with its stable kernel, efficient protocol stack and good customizability. As an emerging network technology, network virtual local area network (VLAN) technology realizes effective management and secure isolation of network resources by establishing logical network isolation on the physical network. The FreeBSD open source protocol stack provides some virtual local area network (VLAN) solutions, but they are not as widely supported as switches. In particular, the processing of different types of data packets on switch ports is missing in the VLAN function of the FreeBSD protocol stack. When data communication between VLANs is carried out with switches in the network in a network environment with a complex topology, there is a risk of invalid VLAN isolation, packet errors, and packet loss, which greatly affects network performance. At the same time, the existing VLAN technology of the FreeBSD protocol stack is not perfect for forwarding and isolating data in the Layer 2 VLAN. It is impossible to forward packets in the same VLAN according to the configuration and isolate them in different VLANs, which cannot guarantee the security of the network and affects the stability and reliability of the network. Summary of the invention
[0004] In view of this, an embodiment of the present invention provides a DPU-type switch port mode data transmission method and device based on the FreeBSD open source protocol stack to eliminate or improve one or more defects in the prior art, and solve the problem that the current VLAN technology of the FreeBSD protocol stack cannot limit broadcast messages to be forwarded within one VLAN and cannot securely isolate different VLANs.
[0005] One aspect of the present invention provides a DPU switch port mode data transmission method based on the FreeBSD open source protocol stack, the method is used to be executed on a data processor, and the method comprises the following steps:
[0006] For the FreeBSD protocol stack architecture, a switch-like port mode is added to the network interface attributes, and the port default VLAN is marked; the port modes include: Access port mode, Trunk port mode, and Hybrid port mode;
[0007] After receiving the data packet, the network interface performs inbound processing and outbound processing on the data packet based on the ifconfig command line code preconfigured in the FreeBSD protocol stack;
[0008] After receiving the data packet, the network interface performs inbound processing on the data packet, including:
[0009] When the data packet does not have a virtual LAN tag for marking the virtual LAN to which it belongs, the virtual LAN tag is added according to the port default VLAN of the network interface, and the network interface properties of the network interface are queried. If it is in Access port mode, the port default VLAN of the network interface is added to the data packet as a virtual LAN tag; if it is in Trunk or Hybrid port mode, it is determined whether the port default VLAN of the network interface is in the list of virtual LANs allowed to pass, and if not, the data packet is discarded; if so, the port default VLAN of the network interface is added to the data packet as a virtual LAN tag; when the data packet has the virtual LAN tag, the virtual LAN recorded in the virtual LAN tag is compared with the configuration of the network interface to determine whether it is allowed to pass;
[0010] If the data packet is allowed to pass, searching for a corresponding virtual local area network interface according to the virtual local area network label of the data packet;
[0011] Determine whether the data packet is a broadcast message, if so, forward it within the same virtual local area network, otherwise, forward it directly;
[0012] The outgoing direction processing is performed on the data packet, including: stripping the virtual local area network label from the data packet containing the virtual local area network label according to a preset process, and then performing subsequent processing and forwarding.
[0013] In some embodiments, after comparing the virtual local area network recorded in the virtual local area network tag with the configuration of the network interface to determine whether the packet is allowed to pass, the method further includes: discarding the packet if the packet is not allowed to pass;
[0014] After searching for the corresponding virtual LAN interface according to the virtual LAN label added to or carried by the data packet, the method further includes: discarding the data packet if the corresponding virtual LAN interface is not found;
[0015] Furthermore, a log file is created to record the processing and forwarding process of the data packet, and an index is created for backtracking and verification.
[0016] In some embodiments, comparing the virtual local area network recorded in the virtual local area network tag with the configuration of the network interface to determine whether the packet is allowed to pass includes:
[0017] Query the network interface properties of the network interface. If it is in Access port mode, allow the data packet to pass when the virtual LAN tag is the same as the default VLAN of the port, otherwise discard the data packet; if it is in Trunk or Hybrid port mode, determine whether the virtual LAN tag is in the list of virtual LANs allowed to pass, if so, allow the data packet to pass, otherwise discard the data packet.
[0018] In some embodiments, entering the same virtual local area network internal forwarding includes:
[0019] Traversing and searching for other network interfaces other than the current network interface in the virtual local area network; the current network interface is the network interface that receives the data packet;
[0020] According to the target physical address recorded in the data packet, and according to the target physical address, a corresponding outgoing network interface is selected from the other network interfaces;
[0021] The data packet is copied to the outgoing network interface for outgoing processing.
[0022] In some embodiments, subsequent processing and forwarding are performed after the virtual local area network label is stripped according to a preset process, including:
[0023] If the network interface is in Access port mode, determine whether the virtual LAN tag of the data packet is consistent with the default VLAN of the port, and if they are consistent, strip the virtual LAN tag of the data packet; otherwise, discard the data packet;
[0024] If the network interface is in Trunk port mode or Hybrid port mode, first determine whether the virtual LAN tag of the data packet is in the list of virtual LANs allowed to pass. If not, discard the data packet. If so, further determine whether the virtual LAN tag of the data packet is consistent with the default VLAN of the port. If they are consistent, strip the virtual LAN tag of the data packet. If not, continue to execute subsequent forwarding processing of the data packet.
[0025] On the other hand, the present invention also provides a DPU type switch port mode data transmission device based on the FreeBSD open source protocol stack, including a processor, a memory and a computer program or instruction stored in the memory, the processor is used to execute the computer program or instruction, and when the computer program or instruction is executed, the device implements the steps of the above method.
[0026] On the other hand, the present invention also provides a computer-readable storage medium having a computer program or instruction stored thereon, which implements the steps of the above method when the computer program or instruction is executed by a processor.
[0027] On the other hand, the present invention also provides a computer program product, comprising a computer program or instructions, which implement the steps of the above method when executed by a processor.
[0028] The beneficial effects of the present invention are at least:
[0029] The DPU switch port mode data transmission method and device based on the FreeBSD open source protocol stack of the present invention adds switch port mode attributes to the network interface attributes, and modifies the ifconfig command line code in the FreeBSD protocol stack to implement the command configuration function, so that the data packet can detect the current port mode during the transmission process, and automatically add or remove virtual LAN tags according to the different port modes to adapt to the communication between various different data packets. And improve the forwarding and isolation functions of the virtual LAN, realize the forwarding of broadcast messages within the same virtual LAN, and the isolation between different virtual LANs, reduce broadcast storms, prevent network attacks and virus spread, and enhance network security.
[0030] Additional advantages, purposes, and features of the present invention will be described in part in the following description, and will become apparent to those skilled in the art after studying the following, or may be learned from the practice of the present invention. The purposes and other advantages of the present invention may be achieved and obtained by the structures specifically indicated in the specification and the accompanying drawings.
[0031] Those skilled in the art will appreciate that the objectives and advantages that can be achieved with the present invention are not limited to the above specific description, and the above and other objectives that can be achieved by the present invention will be more clearly understood from the following detailed description. BRIEF DESCRIPTION OF THE DRAWINGS
[0032] The drawings described herein are used to provide a further understanding of the present invention, constitute a part of the present application, and do not constitute a limitation of the present invention. In the drawings:
[0033] Figure 1The present invention is a flowchart of a method for transmitting data in a DPU switch port mode based on the FreeBSD open source protocol stack according to an embodiment of the present invention.
[0034] Figure 2 The present invention is a schematic diagram of configuring network interface properties through the ifconfig command line in a DPU switch port mode data transmission method based on the FreeBSD open source protocol stack according to an embodiment of the present invention.
[0035] Figure 3 The present invention is a logical schematic diagram of the inbound direction processing steps in the DPU switch port mode data transmission method based on the FreeBSD open source protocol stack according to an embodiment of the present invention.
[0036] Figure 4 for Figure 3 Diagram showing adding VLAN labels in the inbound direction.
[0037] Figure 5 for Figure 3 Schematic diagram of the process of determining whether a data packet is allowed to pass.
[0038] Figure 6 The present invention is a logical schematic diagram of the outbound processing steps in the DPU switch port mode data transmission method based on the FreeBSD open source protocol stack.
[0039] Figure 7 for Figure 6 Schematic diagram of the process of stripping virtual LAN labels. DETAILED DESCRIPTION
[0040] In order to make the purpose, technical solution and advantages of the present invention more clearly understood, the present invention is further described in detail below in conjunction with the embodiments and the accompanying drawings. Here, the illustrative embodiments of the present invention and their descriptions are used to explain the present invention, but are not intended to limit the present invention.
[0041] It should also be noted that, in order to avoid obscuring the present invention due to unnecessary details, only structures and / or processing steps closely related to the solutions according to the present invention are shown in the accompanying drawings, while other details that are not closely related to the present invention are omitted.
[0042] It should be emphasized that the term “include / comprises” when used herein refers to the presence of features, elements, steps or components, but does not exclude the presence or addition of one or more other features, elements, steps or components.
[0043] The reasons for the above defects in the prior art are as follows: Currently, when configuring the VLAN function in the FreeBSD protocol stack, some commands or tools can be used to manage and configure the virtual LAN interface to add the network port to one or more VLANs, but it is not possible to control which VLAN messages can enter or leave a specific port by configuring interfaces of different port types, which poses a risk of data leakage and does not guarantee the security of the network. It is not possible to perform different configurations according to different port types, and it is not possible to customize the communication behavior of VLAN according to business needs, which reduces the flexibility of the network. In a complex network environment, when communicating with data between VLANs of the switch, interoperability barriers may be encountered, resulting in problems such as low data transmission efficiency, increased delay, and increased packet loss rate. In addition, when multiple network ports are configured to join the same VLAN, the current VLAN technology of the FreeBSD protocol stack cannot limit broadcast messages to one VLAN for forwarding, and cannot securely isolate different VLANs, which reduces the security and stability of the network.
[0044] In the present invention, VLAN (Virtual Local Area Network) is a technology that logically divides a physical network into multiple independent virtual networks, so that devices on the same physical network can be assigned to different virtual networks. Each VLAN is an independent broadcast domain, and the communication between devices is limited to the same VLAN, thereby improving the performance, security and management flexibility of the network.
[0045] There are three types of switch port modes, namely Access port mode, Trunk port mode, and Hybrid port mode.
[0046] The access port can only belong to one VLAN and is generally used to connect to a computer port.
[0047] The Trunk port can allow multiple VLANs to pass through, can receive and send messages from multiple VLANs, and is generally used as a port connecting switches.
[0048] The Hybrid port can allow multiple VLANs to pass through, can receive and send messages from multiple VLANs, can be used to connect between switches, and can also be used to connect user computers.
[0049] When receiving data, the processing method of the Hybrid port and the Trunk port is the same. The only difference is when sending data: the Hybrid port can allow multiple VLAN messages to be sent without tags, while the Trunk port only allows the default VLAN messages to be sent without tags.
[0050] The port default VLAN is also called PVID, and is called native VLAN in Cisco. In Trunk and Hybrid modes, there is a concept of port default VLAN (pvid / native VLAN id). The port default VLAN in access mode is the VLAN that the port allows, that is, port vid == pvid. The port default VLAN refers to the default virtual LAN (VLAN) associated with each port in the network switch. When a port receives frames without a virtual LAN tag, these frames will be assigned to the default VLAN of the port.
[0051] DPU, or Data Processing Unit, is a processor designed specifically to handle data-intensive tasks. DPU is the third most critical processing unit in modern computing systems after CPU (central processing unit) and GPU (graphics processing unit). It is widely used in data centers, network equipment, and high-performance computing (HPC) to accelerate network, storage, and security processing tasks. DPU usually integrates advanced network processors to accelerate data packet processing, forwarding, and traffic management. It can offload network functions traditionally performed by the CPU, such as network address translation (NAT), firewalls, load balancing, and encryption. DPU can handle storage-related operations such as data compression, decompression, encryption, decryption, and RAID calculations, reducing the burden on the CPU and improving the efficiency of the storage system. DPU can perform virtualization tasks such as hypervisor functions and container management to speed up the startup and migration of virtual machines. In addition, it can provide hardware-level security features such as data encryption and isolation to protect the security of data centers.
[0052] Specifically, one aspect of the present invention provides a DPU switch port mode data transmission method based on the FreeBSD open source protocol stack, such as Figure 1 As shown, the method includes the following steps S101-S103:
[0053] Step S101: For the FreeBSD protocol stack architecture, a switch-like port mode is added to the network interface attributes, and the port default VLAN is marked; the port modes include: Access port mode, Trunk port mode, and Hybrid port mode.
[0054] Step S102: After the network interface receives the data packet, it performs inbound processing on the data packet based on the ifconfig command line code pre-configured in the FreeBSD protocol stack, including steps S1021 to S1023:
[0055] Step S1021: When the data packet does not have a virtual LAN tag for marking the virtual LAN to which it belongs, a virtual LAN tag is added according to the port default VLAN of the network interface; when the data packet has a virtual LAN tag, the virtual LAN recorded in the virtual LAN tag is compared with the configuration of the network interface to determine whether it is allowed to pass.
[0056] Step S1022: If the packet is allowed to pass, search for the corresponding virtual LAN interface according to the virtual LAN tag of the data packet.
[0057] Step S1023: Determine whether the data packet is a broadcast message, if so, forward it within the same virtual local area network, otherwise, forward it directly.
[0058] Step S103, performing outbound processing on the data packet based on the ifconfig command line code preconfigured in the FreeBSD protocol stack, including step S1031: stripping the virtual LAN label from the data packet containing the virtual LAN label according to a preset process, and then performing subsequent processing and forwarding.
[0059] In step S101, the network protocol stack of FreeBSD is a highly modular, scalable and high-performance system, which is widely used in servers, routers, firewalls and embedded systems. In this architecture, the port mode and port default VLAN are added to the network interface properties of the network interface.
[0060] In step S102 and step S103, ifconfig is a command for configuring a network interface. In FreeBSD, the ifconfig command can be used to view and modify the status and configuration of a network interface.
[0061] In some embodiments, in step S1021, after comparing the virtual LAN recorded in the virtual LAN tag with the configuration of the network interface to determine whether it is allowed to pass, it also includes: if it is not allowed to pass, discarding the data packet.
[0062] In step S1022, after searching for the corresponding virtual LAN interface according to the virtual LAN label added to or carried by the data packet, the method further includes: discarding the data packet if the corresponding virtual LAN interface is not found.
[0063] In some embodiments, in step S1021, a virtual LAN tag is added according to the port default VLAN of the network interface, including: querying the network interface properties of the network interface, if it is in Access port mode, adding the port default VLAN of the network interface as a virtual LAN tag to the data packet; if it is in Trunk or Hybrid port mode, determining whether the port default VLAN of the network interface is in the list of virtual LANs allowed to pass, if not, discarding the data packet; if so, adding the port default VLAN of the network interface as a virtual LAN tag to the data packet.
[0064] In some embodiments, in step S1021, the virtual LAN recorded in the virtual LAN tag is compared with the configuration of the network interface to determine whether it is allowed to pass, including: querying the network interface properties of the network interface, if it is an Access port mode, then if the virtual LAN tag is the same as the port default VLAN, it is allowed to pass, otherwise the data packet is discarded; if it is a Trunk or Hybrid port mode, then it is determined whether the virtual LAN tag is in the list of virtual LANs allowed to pass, if so, it is allowed to pass, otherwise the data packet is discarded.
[0065] In some embodiments, entering the same virtual local area network internal forwarding includes steps S201 to S203:
[0066] Step S201: traverse and search for other network interfaces except the current network interface in the virtual local area network; the current network interface is the network interface that receives the data packet.
[0067] Step S202: According to the target physical address recorded in the data packet, a corresponding outgoing network interface is selected from other network interfaces according to the target physical address.
[0068] Step S203: copy the data packet to the outgoing network interface to perform outgoing processing.
[0069] In some embodiments, in step S103, subsequent processing and forwarding are performed after the virtual local area network tag is stripped according to a preset process, including steps S1031-S1032:
[0070] Step S1031: If the network interface is in Access port mode, determine whether the virtual LAN tag of the data packet is consistent with the port default VLAN, if consistent, strip the virtual LAN tag of the data packet; otherwise, discard the data packet.
[0071] Step S1032: If the network interface is in Trunk port mode or Hybrid port mode, first determine whether the virtual LAN tag of the data packet is in the list of virtual LANs allowed to pass. If not, discard the data packet; if so, further determine whether the virtual LAN tag of the data packet is consistent with the port default VLAN. If they are consistent, strip the virtual LAN tag of the data packet; if not, continue to execute subsequent forwarding processing of the data packet.
[0072] In some embodiments, the method further includes: establishing a log file to record the processing and forwarding process of the data packet, and establishing an index for backtracking verification.
[0073] On the other hand, the present invention also provides a DPU-type switch port mode data transmission device based on the FreeBSD open source protocol stack, including a processor, a memory and a computer program / instruction stored in the memory, wherein the processor is used to execute the computer program / instruction, and when the computer program / instruction is executed, the device implements the steps of the above method.
[0074] On the other hand, the present invention further provides a computer-readable storage medium having a computer program / instruction stored thereon, which implements the steps of the above method when the computer program / instruction is executed by a processor.
[0075] On the other hand, the present invention also provides a computer program product, comprising a computer program / instruction, which implements the steps of the above method when executed by a processor.
[0076] The present invention is described below in conjunction with a specific embodiment:
[0077] This embodiment proposes a DPU-like switch port mode data transmission method based on the FreeBSD open source protocol stack. By modifying the relevant code of the FreeBSD system kernel and the open source protocol stack, the switch-like port mode configuration is added, and the virtual LAN tag is flexibly and automatically added or removed according to the port mode during the data packet transmission process, and the forwarding and isolation mechanism of the Layer 2 VLAN function is realized. This technology has the advantages of high efficiency, security, flexibility and cost-effectiveness, and can meet the needs of large-scale network applications. The specific technical solution is as follows:
[0078] Step S1, based on the FreeBSD open source protocol stack architecture, add port mode and port default VLAN attributes in the network interface attributes, wherein the port mode is Access, Trunk, and Hybrid, and the port default VLAN is 0.
[0079] Step S2, modify the relevant code of the ifconfig command line in the FreeBSD protocol stack to implement the function of configuring the port mode and the default vlan through the command line, such as Figure 2 shown.
[0080] Step S3: modify the relevant codes in the FreeBSD protocol stack so that the data packet can automatically add or remove the virtual local area network tag (Vlan tag) in the different port modes during the transmission process. The specific steps of the inbound direction processing are:
[0081] Step S3.1: In the inbound direction of the virtual LAN, when the network interface receives a data packet, it is sent to the Vlan_input process for processing via the FreeBSD protocol stack.
[0082] Step S3.2: First, determine whether the data packet carries a virtual LAN tag. If not, enter the processing flow of adding a virtual LAN tag in the inbound direction. After the processing is completed, enter step S3.4.
[0083] Step S3.3: If the data packet carries a virtual LAN tag, determine whether the tag is passed (the specific determination process is described in step S3.5). If the data packet is not allowed to pass, discard the data packet. If the data packet is allowed to pass, proceed to step S3.4.
[0084] Step S3.4, searching for the corresponding virtual LAN interface according to the virtual LAN label in the data packet; if the corresponding virtual LAN interface is not found, discarding the data packet, if the corresponding virtual LAN interface is found, proceeding to step S3.5.
[0085] Step S3.5, determine whether the data packet is a broadcast message. If not, proceed to step S3.6. If it is a broadcast message, proceed to the same virtual LAN forwarding process (specific processing steps are described in step 3.6). After processing, proceed to step S3.6.
[0086] Step S3.6, the FreeBSD protocol stack's subsequent processing flow for the data packet (such as decapsulating the message, verifying the message, responding to the message, discarding the message, etc.).
[0087] In some embodiments, Figure 4 The specific processing flow of adding a virtual local area network tag in the inbound direction is shown in step S4, including:
[0088] Step S4.1, determining the port mode of the network interface;
[0089] Step S4.2: If it is in Access mode, add the virtual local area network tag of pvid to the data, and continue the subsequent received data packet processing;
[0090] Step S4.3: If it is Trunk or Hybrid mode, first determine whether pvid is in the VLAN list allowed to pass. If not, discard the data packet; if so, add pvid's virtual LAN tag to the data and continue to process the subsequent received data packets.
[0091] In some embodiments, Figure 5 As shown, the specific processing flow of determining whether the label of the data band is allowed to pass is as shown in step S5, which includes:
[0092] Step S5.1: Determine the port mode of the network interface.
[0093] Step S5.2: If it is Access mode, when the label is the same as the default Vlan (pvid), the data packet is allowed to pass, otherwise, the data packet is discarded.
[0094] Step S5.3: If it is Trunk or Hybrid mode, first determine whether the tag is in the list of virtual LANs allowed to pass through. If not, discard the data packet; if so, allow it to pass through.
[0095] In the above step S3.5, the specific processing flow of forwarding within the virtual local area network includes:
[0096] Step S6.1, traverse and search for other network interfaces under the virtual local area network.
[0097] Step S6.2: Copy the message and send it to the outbound processing flow of the network interface.
[0098] In some embodiments, the above step S2 modifies the relevant code in the FreeBSD protocol stack so that the data packet can automatically add or remove the virtual local area network tag according to the different port modes during the transmission process, such as Figure 6 As shown, the specific process of outgoing direction processing is shown in step S7, which includes:
[0099] Step S7.1: The data packet to be sent out is finally sent to the out_put process (outgoing process) of the interface for processing.
[0100] Step S7.2: First determine whether the data packet carries a virtual LAN tag. If so, enter the process of stripping the virtual LAN tag in the outbound direction (the specific process is described in step S8), and execute the normal process of the protocol stack for the data packet.
[0101] Step S7.3: If there is no virtual LAN tag, execute the normal processing flow of the protocol stack for the data packet.
[0102] Step S7.4, the subsequent processing flow of the sending packet of the FreeBSD protocol stack, such as checking the message, adding the message header, etc.
[0103] In some embodiments, Figure 6 As shown, the specific processing flow of stripping the virtual LAN label in the outbound direction is shown in step S8, which includes:
[0104] Step S8.1, determining the port mode of the network interface of the data packet;
[0105] Step S8.2: If it is Access mode, determine whether the virtual LAN label of the data packet is the same as pvid. If they are the same, remove the virtual LAN label and continue to send the data packet. Otherwise, discard the data packet.
[0106] Step S8.3, if it is Trunk or Hybrid mode, first determine whether the label is in the VLAN list allowed to pass, if not, discard the data packet, if it is, determine whether the virtual LAN label is the same as pvid, if the same, strip off the virtual LAN label, if not the same, do not strip off the virtual LAN label, and continue to send subsequent data packet processing.
[0107] Based on the current FreeBSD open source protocol stack architecture, this embodiment adds a switch-like port mode attribute to the network interface attributes, and modifies the relevant code in the FreeBSD protocol stack to implement the relevant command line configuration function. By modifying the relevant code in the FreeBSD protocol stack, the data packet can detect the current port mode during transmission, and automatically add or remove the virtual LAN tag according to the different port modes to adapt to the communication between various different data packets. By combining the bridge technology and modifying the relevant code in the FreeBSD protocol stack, the forwarding and isolation functions of the virtual LAN are improved, and the forwarding of broadcast messages within the same virtual LAN and the isolation of different virtual LANs are realized, broadcast storms are reduced, network attacks and virus spread are prevented, and the security of the network is enhanced.
[0108] Corresponding to the above method, the present invention also provides an apparatus / system, which includes a computer device, the computer device includes a processor and a memory, the memory stores computer instructions, the processor is used to execute the computer instructions stored in the memory, and when the computer instructions are executed by the processor, the apparatus / system implements the steps of the method described above.
[0109] The embodiment of the present invention also provides a computer-readable storage medium on which a computer program is stored, and when the computer program is executed by a processor, the steps of the aforementioned edge computing server deployment method are implemented. The computer-readable storage medium can be a tangible storage medium, such as a random access memory (RAM), a memory, a read-only memory (ROM), an electrically programmable ROM, an electrically erasable programmable ROM, a register, a floppy disk, a hard disk, a removable storage disk, a CD-ROM, or any other form of storage medium known in the technical field.
[0110] In summary, the DPU switch port mode data transmission method and device based on the FreeBSD open source protocol stack of the present invention adds switch port mode attributes to the network interface attributes, and modifies the ifconfig command line code in the FreeBSD protocol stack to implement the command configuration function, so that the data packet can detect the current port mode during the transmission process, and automatically add or remove virtual LAN tags according to the different port modes to adapt to the communication between various different data packets. And improve the forwarding and isolation functions of the virtual LAN, realize the forwarding of broadcast messages within the same virtual LAN, and the isolation between different virtual LANs, reduce broadcast storms, prevent network attacks and virus spread, and enhance network security.
[0111] It should be understood by those skilled in the art that the exemplary components, systems and methods described in conjunction with the embodiments disclosed herein can be implemented in hardware, software or a combination of the two. Whether it is performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of the present invention. When implemented in hardware, it can be, for example, an electronic circuit, an application-specific integrated circuit (ASIC), appropriate firmware, a plug-in, a function card, etc. When implemented in software, the elements of the present invention are programs or code segments used to perform the required tasks. The program or code segment can be stored in a machine-readable medium, or transmitted on a transmission medium or a communication link via a data signal carried in a carrier.
[0112] It should be clear that the present invention is not limited to the specific configuration and processing described above and shown in the figures. For the sake of simplicity, a detailed description of the known method is omitted here. In the above embodiments, several specific steps are described and shown as examples. However, the method process of the present invention is not limited to the specific steps described and shown, and those skilled in the art can make various changes, modifications and additions, or change the order between the steps after understanding the spirit of the present invention.
[0113] In the present invention, features described and / or illustrated for one embodiment may be used in the same or similar manner in one or more other embodiments, and / or combined with features of other embodiments or replace features of other embodiments.
[0114] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. For those skilled in the art, the embodiments of the present invention may have various modifications and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.
Claims
1. A DPU switch port mode data transmission method based on FreeBSD open source protocol stack, characterized in that: The method is used in a data processor DPU, and the method comprises the following steps: For the FreeBSD protocol stack architecture, a switch-like port mode is added to the network interface attributes, and the port default VLAN is marked; the port modes include: Access port mode, Trunk port mode, and Hybrid port mode; After receiving the data packet, the network interface performs inbound processing and outbound processing on the data packet based on the ifconfig command line code preconfigured in the FreeBSD protocol stack; After receiving the data packet, the network interface performs inbound processing on the data packet, including: When the data packet does not have a virtual LAN tag for marking the virtual LAN to which it belongs, the virtual LAN tag is added according to the port default VLAN of the network interface, and the network interface properties of the network interface are queried. If it is in Access port mode, the port default VLAN of the network interface is added to the data packet as a virtual LAN tag; if it is in Trunk or Hybrid port mode, it is determined whether the port default VLAN of the network interface is in the list of virtual LANs allowed to pass, and if not, the data packet is discarded; if so, the port default VLAN of the network interface is added to the data packet as a virtual LAN tag; when the data packet has the virtual LAN tag, the virtual LAN recorded in the virtual LAN tag is compared with the configuration of the network interface to determine whether it is allowed to pass; If the data packet is allowed to pass, searching for a corresponding virtual local area network interface according to the virtual local area network label of the data packet; Determine whether the data packet is a broadcast message, if so, forward it within the same virtual local area network, otherwise, forward it directly; The outgoing direction processing is performed on the data packet, including: stripping the virtual local area network label from the data packet containing the virtual local area network label according to a preset process, and then performing subsequent processing and forwarding.
2. The DPU switch port mode data transmission method based on the FreeBSD open source protocol stack according to claim 1, characterized in that: After comparing the virtual local area network recorded in the virtual local area network tag with the configuration of the network interface to determine whether the data packet is allowed to pass, the method further includes: if the data packet is not allowed to pass, discarding the data packet; After searching for the corresponding virtual LAN interface according to the virtual LAN label added to or carried by the data packet, the method further includes: discarding the data packet if the corresponding virtual LAN interface is not found; Furthermore, a log file is created to record the processing and forwarding process of the data packet, and an index is created for backtracking and verification.
3. The DPU switch port mode data transmission method based on FreeBSD open source protocol stack according to claim 1, characterized in that: Comparing the virtual local area network recorded in the virtual local area network tag with the configuration of the network interface to determine whether the packet is allowed to pass, including: Query the network interface properties of the network interface. If it is in Access port mode, allow the data packet to pass when the virtual LAN tag is the same as the default VLAN of the port, otherwise discard the data packet; if it is in Trunk or Hybrid port mode, determine whether the virtual LAN tag is in the list of virtual LANs allowed to pass, if so, allow the data packet to pass, otherwise discard the data packet.
4. The DPU switch port mode data transmission method based on the FreeBSD open source protocol stack according to claim 1, characterized in that: Enter the same virtual LAN internal forwarding, including: Traversing and searching for other network interfaces other than the current network interface in the virtual local area network; the current network interface is the network interface that receives the data packet; According to the target physical address recorded in the data packet, and according to the target physical address, a corresponding outgoing network interface is selected from the other network interfaces; The data packet is copied to the outgoing network interface for outgoing processing.
5. The DPU switch port mode data transmission method based on FreeBSD open source protocol stack according to claim 1, characterized in that: After the VLAN tag is stripped according to the preset process, subsequent processing and forwarding are performed, including: If the network interface is in Access port mode, determine whether the virtual LAN tag of the data packet is consistent with the default VLAN of the port, and if they are consistent, strip the virtual LAN tag of the data packet; otherwise, discard the data packet; If the network interface is in Trunk port mode or Hybrid port mode, first determine whether the virtual LAN tag of the data packet is in the list of virtual LANs allowed to pass. If not, discard the data packet. If so, further determine whether the virtual LAN tag of the data packet is consistent with the default VLAN of the port. If they are consistent, strip the virtual LAN tag of the data packet. If not, continue to execute subsequent forwarding processing of the data packet.
6. A DPU switch port mode data transmission device based on the freebsd open source protocol stack, comprising a processor, a memory and a computer program or instruction stored in the memory, characterized in that: The processor is used to execute the computer program or instructions. When the computer program or instructions are executed, the device implements the steps of the method according to any one of claims 1 to 5.
7. A computer-readable storage medium having a computer program or instruction stored thereon, characterized in that: When the computer program or instruction is executed by a processor, the steps of the method according to any one of claims 1 to 5 are implemented.
8. A computer program product comprising a computer program or instructions, characterized in that When the computer program or instruction is executed by a processor, the steps of the method according to any one of claims 1 to 5 are implemented.
Citation Information
Patent Citations
Distributed virtual local area network implementation system and method applied to mobile wireless nodes
CN107613033A
Flow isolation method and device, switch and storage medium
CN112714052A