A safety protection method and device

By receiving packets to determine the IP pass-through capability of the WLAN Layer 2 network and adjusting the IP protection function in real time, the problem of the isolation technology not being able to be automatically updated in the existing technology is solved, thereby improving the forwarding efficiency and security of network devices.

CN119299966BActive Publication Date: 2025-10-28NEW H3C TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411696724.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-25
Publication Date
2025-10-28
Estimated Expiration
2044-11-25

AI Technical Summary

Technical Problem

Existing WLAN isolation technologies require manual configuration and cannot be updated in real time. This results in a failure to automatically adjust when the network environment changes, which may lead to invalid copying and forwarding of broadcast and multicast packets, affecting the forwarding efficiency and security of network devices.

Method used

By receiving packets, it is determined whether the WLAN Layer 2 network has IP pass-through capability. If it does, the IP protection function is turned off; if not, it remains on. The detection technology is used to adjust the IP protection function in real time to ensure that the network device automatically adjusts its configuration when the environment changes.

Benefits of technology

It enables automatic adjustment of IP protection functions without manual intervention when the network environment changes, reducing the forwarding of invalid IP multicast and broadcast packets, and improving the forwarding efficiency and security of network devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119299966B_ABST
    Figure CN119299966B_ABST
Patent Text Reader

Abstract

This application provides a security protection method and apparatus, relating to the field of communication technology. The method includes: receiving a first message; if the first message indicates that the WLAN Layer 2 network to which the network device belongs has IP pass-through capability, then disabling the IP protection function, where IP pass-through capability refers to the ability for devices to communicate directly via IP addresses, and the IP protection function refers to not copying and forwarding received IP multicast messages and IP broadcast messages to the wireless interface; if the first message indicates that the WLAN Layer 2 network does not have IP pass-through capability, then keeping the IP protection function enabled. This can improve message forwarding efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technology, and in particular to a security protection method and device. Background Technology

[0002] WiFi technology is one of the most widely used wireless local area network (WLAN) technologies, and the more advanced WiFi 7 standard has now been officially released. This standard is an upgrade from its predecessor, WiFi 6, offering faster, more stable, and more energy-efficient wireless connections. Social development and technological advancements present both significant opportunities and challenges for wireless equipment providers. One long-standing and crucial issue in the WLAN field is minimizing the invalid copying and forwarding of broadcast and multicast packets while improving network device packet processing speed, reducing latency, and enhancing security. To address this, WLAN isolation technology has emerged.

[0003] Currently, most isolation technologies are hard isolation technologies, such as isolation based on domains, groups, or ports. This means isolating and restricting mutual access between users belonging to the same domain or group, or isolating ports belonging to the same port group using Layer 2 or Layer 3 forwarding. However, these isolation technologies require experienced network administrators to plan and configure them in advance. After the configuration information takes effect, if environmental factors such as the number of network devices, the number of wireless terminals, network topology, or network configuration change, the configuration information cannot be automatically updated and still relies on the network administrator's operation and maintenance, resulting in poor flexibility. Furthermore, if mutual access between users in different domains or groups is not isolated and restricted, there may still be problems with invalid copying and forwarding of broadcast and multicast packets, thus affecting the forwarding efficiency of network devices. Summary of the Invention

[0004] The purpose of this application is to provide a security protection method and apparatus to improve the forwarding efficiency and network security of network devices. The specific technical solution is as follows:

[0005] In a first aspect, embodiments of this application provide a security protection method applied to a network device, the method comprising:

[0006] Receive the first message;

[0007] If the first message indicates that the WLAN Layer 2 network to which the network device belongs has Internet Protocol (IP) pass-through capability, then the IP protection function is turned off. The IP pass-through capability is the ability for devices to communicate directly through IP addresses. The IP protection function refers to not copying and forwarding received IP multicast messages and IP broadcast messages to the wireless interface.

[0008] If the first message indicates that the WLAN Layer 2 network does not have IP pass-through capability, then the IP protection function remains enabled.

[0009] In one possible implementation, the method further includes:

[0010] Every first preset time interval, detect whether there is an IP gateway device and a DHCP server in the WLAN Layer 2 network;

[0011] If an IP gateway or DHCP server exists in the WLAN Layer 2 network, then the WLAN Layer 2 network is determined to have IP pass-through capability, and the IP protection function is disabled.

[0012] If there is no IP gateway and DHCP server in the WLAN Layer 2 network, it is determined that the WLAN Layer 2 network does not have IP pass-through capability, and the IP protection function is enabled.

[0013] In one possible implementation, the method further includes:

[0014] When the IP protection function is enabled, if an IP multicast message or IP broadcast message is received, and the duration of the received IP multicast message or broadcast message exceeds the second preset duration, then the presence of an IP gateway device and a DHCP server in the WLAN Layer 2 network is detected.

[0015] If an IP gateway or DHCP server exists in the WLAN Layer 2 network, then the WLAN Layer 2 network is determined to have IP pass-through capability, and the IP protection function is disabled.

[0016] If there is no IP gateway and DHCP server in the WLAN Layer 2 network, it is determined that the WLAN Layer 2 network does not have IP pass-through capability, and the IP protection function remains enabled.

[0017] In one possible implementation, the method further includes:

[0018] With the IP protection function enabled, periodically probe whether devices within the WLAN Layer 2 network can communicate with the external IP server;

[0019] If the devices within the WLAN Layer 2 network can communicate with the external IP server, then the WLAN Layer 2 network is determined to have IP pass-through capability, and the IP protection function is disabled.

[0020] In one possible implementation, detecting the presence of an IP gateway device and a DHCP server in the WLAN Layer 2 network includes:

[0021] Send a routing request (RS) message;

[0022] If a Routing Advertisement (RA) message is received within the third preset time period, it is determined that an IP gateway device exists in the WLAN Layer 2 network.

[0023] Send a DHCP discovery message;

[0024] If a DHCP announcement message is received from the DHCP server within the fourth preset time period, a DHCP request message is sent to the DHCP server.

[0025] If a DHCP reply message is received from the DHCP server within the fifth preset time period, it is determined that a DHCP server exists in the WLAN Layer 2 network.

[0026] In one possible implementation, sending the routing request (RS) message includes:

[0027] If an RA message has been received through the first interface, an RS message is sent through the first interface; if no RA message is received within the sixth preset time period, but an RA message has been received in the first VLAN, an RS message is broadcast in the first VLAN.

[0028] If no RA message is received through any interface, an RS message is broadcast in all VLANs to which the network device belongs.

[0029] In one possible implementation, after sending the DHCP request message to the DHCP server, the method further includes:

[0030] If a DHCP reply message is received from the DHCP server within the fifth preset time period, and the DHCP reply message carries the IP address assigned to the network device, then a DHCP release message is sent to the DHCP server.

[0031] In one possible implementation, the RS message includes a destination address and a source address, wherein the destination address is a general multicast address, and the source address is an all-zero address or a link-local address, wherein the link-local address includes the bridge MAC address and the link-local address prefix of the network device;

[0032] The source address included in the DHCP discovery message and the source address included in the DHCP request message are both the link-local address.

[0033] In one possible implementation, detecting whether a device within the WLAN Layer 2 network can communicate with an external IP server includes:

[0034] A DNS request message is sent to a domain name server; if a DNS response message is received from the domain name server within a seventh preset time period, an ICMP Echo Request message is sent to the external IP server; if an ICMP Echo Reply message is received from the external IP server within an eighth preset time period, it is determined that the device in the WLAN Layer 2 network can communicate with the external IP server; wherein, the DNS request message carries the domain name of the external IP server, the DNS response message carries the first IP address of the external IP server, and the ICMP Echo Request message carries the first IP address; or,

[0035] Send an ICMP Echo Request message to the external IP server; if an ICMP Echo Reply message is received from the external IP server within a ninth preset time period, it is determined that the device in the WLAN Layer 2 network can communicate with the external IP server. The ICMP Echo Request message carries a second IP address, which is the IP address of the external IP server stored by the network device.

[0036] In one possible implementation, the payload portion of the ICMP Echo Request message includes a specified identifier;

[0037] After sending the ICMP Echo Request message to the external IP server, the method further includes:

[0038] If an ICMP Echo Reply message is received from the external IP server within the ninth preset time period, and the payload of the ICMP Echo Reply message includes the specified identifier, then the ICMP Echo Reply message is discarded.

[0039] In one possible implementation, the source address of the DNS request message includes the RA prefix of the IP gateway device and the bridge MAC address of the network device; or, the source address of the DNS request message is an IP address requested from the DHCP server.

[0040] The source address of the ICMP Echo Request message includes the address constructed from the RA prefix of the IP gateway device and the bridge MAC address of the network device; or, the source address of the ICMP Echo Request message is the IP address requested from the DHCP server; or, the source address of the ICMP Echo Request message is the source IP address of the wireless terminal, which is either the source address obtained from the IP packet sent by the wireless terminal or the IP address of the wireless terminal stored in the user management module of the network device.

[0041] In one possible implementation, after receiving the first message, the method further includes:

[0042] If the first message is any of the following, then the first message indicates that the WLAN Layer 2 network has IP pass-through capability:

[0043] Messages during the DHCP dynamic address allocation process;

[0044] Routing announcement messages sent by the gateway device to the terminal;

[0045] Neighbor Notification (NA) message;

[0046] Global unicast IP data packets.

[0047] In one possible implementation, after disabling the IP protection function, the method further includes:

[0048] If no packet indicating that the WLAN Layer 2 network has IP pass-through capability is received for ten consecutive preset time periods, then the IP protection function is activated.

[0049] Secondly, embodiments of this application provide a security protection device applied to network equipment, the device comprising:

[0050] The receiving module is used to receive the first message;

[0051] The shutdown module is used to disable the IP protection function if the first message indicates that the WLAN Layer 2 network to which the network device belongs has IP pass-through capability. The IP pass-through capability is the ability for devices to communicate directly through IP addresses. The IP protection function refers to not copying and forwarding received IP multicast messages and IP broadcast messages to the wireless interface.

[0052] The enabling module is used to keep the IP protection function enabled if the first message indicates that the WLAN Layer 2 network does not have IP pass-through capability.

[0053] In one possible implementation, the device further includes:

[0054] The detection module is used to detect whether there are IP gateway devices and DHCP servers in the WLAN Layer 2 network at first preset intervals.

[0055] The shutdown module is also used to determine that the WLAN Layer 2 network has IP pass-through capability and disable the IP protection function if an IP gateway or DHCP server exists in the WLAN Layer 2 network.

[0056] The enabling module is further configured to determine that the WLAN Layer 2 network does not have IP pass-through capability if there is no IP gateway and DHCP server in the WLAN Layer 2 network, and then enable the IP protection function.

[0057] In one possible implementation, the device further includes:

[0058] The detection module is used to detect whether there is an IP gateway device and a DHCP server in the WLAN Layer 2 network if an IP multicast message or an IP broadcast message is received and the duration of the received IP multicast message or broadcast message exceeds a second preset duration when the IP protection function is enabled.

[0059] The shutdown module is also used to determine that the WLAN Layer 2 network has IP pass-through capability and disable the IP protection function if an IP gateway or DHCP server exists in the WLAN Layer 2 network.

[0060] The enabling module is further configured to determine that the WLAN Layer 2 network does not have IP pass-through capability if there is no IP gateway and DHCP server in the WLAN Layer 2 network, and to keep the IP protection function in the enabled state.

[0061] In one possible implementation, the device further includes:

[0062] The detection module is used to periodically detect whether devices in the WLAN Layer 2 network can communicate with the external IP server when the IP protection function is enabled.

[0063] The shutdown module is further configured to determine that the WLAN Layer 2 network has IP pass-through capability and disable the IP protection function if the devices in the WLAN Layer 2 network can communicate with the external IP server.

[0064] In one possible implementation, the detection module is specifically configured to: send a Routing Request (RS) message; if a Routing Advertisement (RA) message is received within a third preset time period, then determine that an IP gateway device exists in the WLAN Layer 2 network; send a DHCP Discover message; if a DHCP Advertisement message is received from a DHCP server within a fourth preset time period, then send a DHCP Request message to the DHCP server; if a DHCP Reply message is received from the DHCP server within a fifth preset time period, then determine that a DHCP server exists in the WLAN Layer 2 network.

[0065] In one possible implementation, the detection module is specifically configured to: if an RA message has been received through the first interface, then send an RS message through the first interface; if no RA message is received within a sixth preset time period, but an RA message has been received in the first VLAN, then broadcast an RS message in the first VLAN; if no RA message is received through any interface, then broadcast an RS message in all VLANs to which the network device belongs.

[0066] In one possible implementation, the detection module is further configured to send a DHCP release message to the DHCP server if it receives a DHCP reply message from the DHCP server within the fifth preset time period, and the DHCP reply message carries an IP address assigned to the network device.

[0067] In one possible implementation, the RS message includes a destination address and a source address, wherein the destination address is a general multicast address, and the source address is an all-zero address or a link-local address, wherein the link-local address includes the bridge MAC address and the link-local address prefix of the network device;

[0068] The source address included in the DHCP discovery message and the source address included in the DHCP request message are both the link-local address.

[0069] In one possible implementation, the detection module is specifically used for:

[0070] A DNS request message is sent to a domain name server; if a DNS response message is received from the domain name server within a seventh preset time period, an ICMP Echo Request message is sent to the external IP server; if an ICMP Echo Reply message is received from the external IP server within an eighth preset time period, it is determined that the device in the WLAN Layer 2 network can communicate with the external IP server; wherein, the DNS request message carries the domain name of the external IP server, the DNS response message carries the first IP address of the external IP server, and the ICMP Echo Request message carries the first IP address; or,

[0071] Send an ICMP Echo Request message to the external IP server; if an ICMP Echo Reply message is received from the external IP server within a ninth preset time period, it is determined that the device in the WLAN Layer 2 network can communicate with the external IP server. The ICMP Echo Request message carries a second IP address, which is the IP address of the external IP server stored by the network device.

[0072] In one possible implementation, the payload portion of the ICMP Echo Request message includes a specified identifier;

[0073] The detection module is further configured to discard the ICMP Echo Reply message if it receives an ICMP Echo Reply message from the external IP server within the ninth preset time period, and the payload of the ICMP Echo Reply message includes the specified identifier.

[0074] In one possible implementation, the source address of the DNS request message includes the RA prefix of the IP gateway device and the bridge MAC address of the network device; or, the source address of the DNS request message is an IP address requested from the DHCP server.

[0075] The source address of the ICMP Echo Request message includes the RA prefix of the IP gateway device and the bridge MAC address of the network device; or, the source address of the ICMP Echo Request message is an IP address requested from the DHCP server; or, the source address of the ICMP Echo Request message is the source IP address of the wireless terminal, which is either the source address obtained from the IP packet sent by the wireless terminal or the IP address of the wireless terminal stored in the user management module of the network device.

[0076] In one possible implementation, the device further includes:

[0077] The determining module is configured to determine that the first message indicates that the WLAN Layer 2 network has IP pass-through capability if the first message is any of the following:

[0078] Messages during the DHCP dynamic address allocation process;

[0079] Routing announcement messages sent by the gateway device to the terminal;

[0080] Neighbor Notification (NA) message;

[0081] Global unicast IP data packets.

[0082] In one possible implementation, the enabling module is further configured to enable the IP protection function if no packet indicating that the WLAN Layer 2 network has IP pass-through capability is received for a tenth preset time period.

[0083] Thirdly, embodiments of this application provide a network device, including a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory communicate with each other through the communication bus;

[0084] Memory, used to store computer programs;

[0085] When a processor executes a program stored in memory, it implements the method described in the first aspect above.

[0086] Fourthly, embodiments of this application provide a computer-readable storage medium storing a computer program that, when executed by a processor, implements the method described in the first aspect above.

[0087] Fifthly, embodiments of this application also provide a computer program product containing instructions that, when run on a computer, cause the computer to perform the method described in the first aspect above.

[0088] By adopting the above technical solution, after receiving the first packet, if the network device determines that the first packet indicates that the WLAN Layer 2 network to which the network device belongs has IP pass-through capability, then the IP protection function is disabled; if it determines that the first packet indicates that the WLAN Layer 2 network to which the network device belongs does not have IP pass-through capability, then the IP function remains enabled. This means that the IP protection function can be flexibly adjusted based on the packets received by the network device. When the network environment changes, it does not rely on maintenance personnel to adjust configuration information. Furthermore, when it is determined that the WLAN Layer 2 network has IP pass-through capability, the IP protection function can be disabled in a timely manner, thereby reducing the invalid copying and forwarding of IP multicast and IP broadcast packets. This allows the forwarding resources of the network device to be better utilized for forwarding other packets, improving forwarding efficiency. Attached Figure Description

[0089] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other embodiments can be obtained based on these drawings.

[0090] Figure 1 A flowchart illustrating a security protection method provided in an embodiment of this application;

[0091] Figure 2 An exemplary schematic diagram illustrating the detection timing in a security protection method provided in this application embodiment;

[0092] Figure 3 A system architecture diagram provided for an embodiment of this application;

[0093] Figure 4 for Figure 3 The first interaction diagram of the units in the system architecture;

[0094] Figure 5 for Figure 3 The second type of interaction diagram of the units in the system architecture;

[0095] Figure 6 Another system architecture diagram provided for embodiments of this application;

[0096] Figure 7 for Figure 6 A schematic diagram illustrating the interactions between the various units in the system architecture;

[0097] Figure 8 This is a schematic diagram of the structure of a safety protection device provided in an embodiment of this application;

[0098] Figure 9This is a schematic diagram of the structure of a network device provided in an embodiment of this application. Detailed Implementation

[0099] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art based on this application are within the scope of protection of this application.

[0100] In today's rapidly developing digital, intelligent, and modern society, wireless communication technology plays an increasingly important role in homes, offices, and public places due to its unique convenience. With the widespread adoption of wireless terminals such as smartphones, smartwatches, smart tablets, and smart home devices, and the rise of applications such as ultra-high-definition video, virtual reality, and mobile live streaming, higher demands are being placed on current wireless networks, namely faster data transmission speeds, lower network latency, and better network stability and security.

[0101] In wireless networks, WLAN isolation technology has emerged to minimize the invalid copying and forwarding of broadcast and multicast messages. Currently, the mainstream WLAN isolation technologies include the following five:

[0102] Port isolation: Isolating ports belonging to the same port group by performing Layer 2 or Layer 3 forwarding;

[0103] VLAN-based user isolation: Isolating and restricting mutual access between wired users, between wired and wireless users, and between wireless users (regardless of whether wireless users use the same Service Set Identifier (SSID) to access the WLAN network) within a VLAN domain.

[0104] SSID-based user isolation: Isolating and restricting mutual access between wireless users who access the wireless network through the same SSID and are in the same Virtual Local Area Network (VLAN);

[0105] User isolation based on user groups: Isolating and restricting access between wireless users within a user group and between wireless users in different user groups;

[0106] Roaming Group Tunnel Isolation: When there is a loop between multiple devices in the same roaming group, enable the roaming group tunnel isolation function to ensure that the devices will not forward messages between tunnels in the roaming group, thereby avoiding problems such as broadcast storms.

[0107] All five WLAN isolation technologies mentioned above can reduce the invalid copying and forwarding of broadcast and multicast messages by network devices in the WLAN network, allowing more resources to be used for effective basic message forwarding. This improves the overall message forwarding speed of network devices, reduces forwarding latency, and reduces the impact on other devices in the WLAN network.

[0108] However, these isolation technologies are all hard isolation technologies, which require experienced network administrators to plan and configure them in advance. After the configuration information takes effect, the configuration information cannot be updated in real time, making operation and maintenance complex and less flexible. In addition, there are problems with invalid copying and forwarding of broadcast and multicast messages due to incomplete configuration, resulting in low forwarding efficiency of network devices for other messages.

[0109] To address the aforementioned problems, this application provides a security protection method applied to a network device, which can be a wireless access controller (AC) or a wireless access point (AP), such as... Figure 1 As shown, the method includes:

[0110] S101, Receive the first message.

[0111] The first message is any message received by the network device, which can be understood as the network device needing to parse the received messages packet by packet.

[0112] S102. If the first message indicates that the WLAN Layer 2 network to which the network device belongs has IP pass-through capability, then disable the IP protection function.

[0113] Among these, IP passthrough capability refers to the ability of devices to communicate directly via IP addresses, while IP protection function refers to preventing the copying and forwarding of received IP multicast and IP broadcast messages to the wireless interface. For example, received IP multicast and IP broadcast messages can be discarded, or they can be copied and forwarded only to the wired interface.

[0114] If a WLAN Layer 2 network has IP pass-through capability, it means that devices in the WLAN Layer 2 network can communicate directly through IP addresses. Therefore, network devices can correctly forward IP multicast and IP broadcast messages based on IP addresses, and devices that receive IP multicast and IP broadcast messages can also identify and process them. In this case, it is effective copying and forwarding, and no forwarding isolation is required. Therefore, the IP protection function can be turned off, allowing network devices to copy and forward IP multicast and IP broadcast messages normally.

[0115] It should be noted that the WLAN Layer 2 network in this application embodiment includes traditional Layer 2 networks, as well as large Layer 2 networks such as Virtual Extensible Local Area Network (VXLAN).

[0116] S103. If the first message indicates that the WLAN Layer 2 network does not have IP pass-through capability, then keep the IP protection function enabled.

[0117] If a WLAN Layer 2 network does not have IP pass-through capability, it means that devices in the WLAN Layer 2 network cannot communicate directly through IP addresses. Therefore, even if network devices copy the received IP multicast and IP broadcast packets, they cannot successfully forward the IP multicast and IP broadcast packets through the wireless interface based on the IP address. In this case, it is an invalid copying and forwarding. Therefore, forwarding isolation is required, and the IP protection function must be kept in the enabled state so that network devices do not copy and forward the received IP multicast and IP broadcast packets through the wireless interface.

[0118] In this embodiment of the application, the network device can be an AC or an AP. If the network device is an AC, when performing IP protection for the multicast and broadcast messages received by the AC, the AC will not copy the downlink multicast and broadcast messages to the AP. If the network device is an AP, the AP will discard the multicast and broadcast messages received from the wireless terminal on the wireless RF port, and if the AP receives multicast and broadcast messages sent by the wired terminal, it will not copy the downlink multicast and broadcast messages to the wireless terminal.

[0119] Using this method, after receiving the first packet, if the network device determines that the first packet indicates that the WLAN Layer 2 network to which the network device belongs has IP pass-through capability, then the IP protection function is disabled; if it determines that the first packet indicates that the WLAN Layer 2 network to which the network device belongs does not have IP pass-through capability, then the IP function remains enabled. This allows for flexible adjustment of the IP protection function based on the packets received by the network device. When the network environment changes, it does not rely on maintenance personnel to adjust configuration information. Furthermore, when it is determined that the WLAN Layer 2 network has IP pass-through capability, the IP protection function can be disabled promptly, thereby reducing the invalid copying and forwarding of IP multicast and IP broadcast packets. This allows the network device's forwarding resources to be better utilized for forwarding other packets, improving forwarding efficiency.

[0120] Furthermore, once the IP protection function is enabled, it can suppress the copying and forwarding of IP multicast and IP broadcast packets by network devices. This effectively reduces the impact of IP multicast and IP broadcast packets on the wireless interface and forwarding chip of this network device. In addition, this network device does not forward invalid IP multicast and IP broadcast packets to other network devices and wireless terminals, which can also improve the overall packet transmission and reception performance and network security of the WLAN network.

[0121] It should be noted that the granularity of IP protection function in this application embodiment can be one of the following three types:

[0122] The first method is protection based on VLAN granularity, because multicast packets are multicast within the same VLAN.

[0123] The second type is device-level protection. If one board in the device is determined to have IP passthrough capability, the entire device is considered to have IP passthrough capability. If all boards are determined not to have IP passthrough capability, the entire device is considered not to have IP passthrough capability.

[0124] The third type is protection based on multi-device combination systems (such as Intelligent Resilient Framework (IRF) stacking, cloud clusters, various dual-machine / multi-machine systems, etc.). That is, as long as one device determines that it has IP passthrough capability, the system is considered to have IP passthrough capability; if all devices determine that it does not have IP passthrough capability, the system is considered not to have IP passthrough capability.

[0125] It should be noted that the IP pass-through capability in this application embodiment is divided into IPv4 pass-through capability and IPv6 pass-through capability. The IP address involved in this application embodiment can be an IPv4 address or an IPv6 address, the IP multicast message can be an IPv4 or IPv6 multicast message, and the IP broadcast message can be an IPv4 or IPv6 broadcast message.

[0126] Understandably, if it is determined that the WLAN Layer 2 network does not have IPv4 passthrough capability, then protection is needed for IPv4 multicast packets and IPv4 broadcast packets; if it is determined that the WLAN Layer 2 network does not have IPv6 passthrough capability, then protection is needed for IPv6 multicast packets and IPv6 broadcast packets.

[0127] Currently, the internet as a whole is in a transition phase from IPv4 to IPv6. Most network devices support both IPv4 and IPv6 communication, or only IPv4 communication. This can be understood as most network devices having IPv4 pass-through capability. Only after the complete transition from IPv4 to IPv6, or when WLAN networks only support IPv6 network communication, will network devices possibly support only IPv6 communication and not IPv4 communication. This means that only under these circumstances will protecting against the copying and forwarding of IPv4 multicast and broadcast messages have practical value.

[0128] Furthermore, while most mainstream wireless terminals (such as smartphones and tablets) now support IPv4 and IPv6 dual-stack network cards, some gateway devices still lack IPv6 passthrough capabilities, or network administrators have not yet enabled IPv6 communication between the internal and external networks due to cost or other factors. Therefore, at this stage, protecting against the copying and forwarding of IPv6 multicast and broadcast messages is of greater practical value. The method provided in this application is applicable to both IPv4 and IPv6 scenarios; subsequent examples will use IPv6 scenarios for explanation.

[0129] Based on the above embodiments, after receiving the first message, the network device needs to parse the first message. If the first message is any of the following, then it is determined that the first message indicates that the WLAN Layer 2 network has IP pass-through capability:

[0130] Messages used in the Dynamic Host Configuration Protocol (DHCP) dynamic address allocation process;

[0131] Routing announcement messages sent by the gateway device to the terminal;

[0132] Neighbor Advertisement (NA) messages;

[0133] Global unicast IP packets.

[0134] If network devices need to pass through each other on IP, they need to obtain an IPv4 address or an IPv6 address.

[0135] Currently, network devices obtain IPv4 addresses mainly in two ways. The first is to directly obtain a manually configured static IPv4 address. The second is to obtain an IPv4 address dynamically assigned by DHCP or by Point-to-Point Protocol over Ethernet (PPPOE).

[0136] There are currently only three ways for network devices to obtain IPv6 addresses. The first is to directly obtain a manually configured static IPv6 address. The second is to obtain an IPv6 address dynamically assigned by the Dynamic Host Configuration Protocol for IPv6 (DHCPv6). The third is to obtain an automatically configured stateless address.

[0137] After obtaining their own IPv4 or IPv6 address, each network device forwards IPv4 or IPv6 packets based on the IPv4 or IPv6 forwarding table obtained through routing or dynamic learning.

[0138] Taking IPv6 as an example, the messages in the DHCP dynamic address allocation process mainly include:

[0139] (1) Advertise message: This is a message sent by the DHCPv6 server to the DHCPv6 client in the second step of the DHCPv6 client's address request process. The network device can identify that there is a DHCPv6 server in the network through this message, and therefore determines that the network has at least the internal IPv6 pass-through capability.

[0140] (2) Reply message: This is the message sent by the DHCPv6 server to the DHCPv6 client in the fourth step of the DHCPv6 client's address application process. The network device can identify that the network has a DHCPv6 server through this message, and therefore determines that the network has at least the internal IPv6 pass-through capability.

[0141] (3) Renew message: When the address lease is 1 / 2 remaining, the DHCPv6 client sends the message to the DHCPv6 server to renew the lease. The network device can identify that a wireless terminal in this network has obtained an IPv6 address through the DHCPv6 server through this message, and therefore determines that this network has at least the internal network IPv6 pass-through capability.

[0142] (4) Rebind message: When the address lease has 7 / 8 remaining, the DHCPv6 client sends the message to the DHCPv6 server to renew the lease. The network device can identify that there is a terminal in this network that has obtained an IPv6 address through the DHCPv6 server through this message, and therefore determines that this network has at least the internal network IPv6 pass-through capability.

[0143] (5) Release message: The DHCPv6 client sends an active release address to the DHCPv6 server. The network device recognizes that a wireless terminal in this network has obtained an IPv6 address through the DHCPv6 server based on this message, and therefore determines that this network has at least the ability to pass through the internal network IPv6.

[0144] (6) Relay Forward message: This is a relay message that the DHCPv6 relay forwards to the DHCPv6 server after receiving the request message from the DHCPv6 client. It is used in the scenario where the AC acts as a DHCPv6 relay. The network device recognizes that the network has a DHCPv6 server based on this message, and therefore determines that the network has at least the internal IPv6 pass-through capability.

[0145] (7) Relay Reply message: This is the RelayForward response message received by the DHCPv6 relay from the DHCPv6 server. It is used in the scenario where the AC acts as a relay. The network device recognizes that the network has a DHCPv6 server based on this message and determines that the network has at least the internal IPv6 pass-through capability.

[0146] (8) Reconfiguration message: When the configuration of the DHCPv6 server changes, it actively notifies the DHCPv6 client to re-request an address. The network device recognizes that the network has a DHCPv6 server through this message, and therefore determines that the network has at least the internal IPv6 pass-through capability.

[0147] The Router Advertisement (RA) message sent by the gateway device to the wireless terminal is a message involved in the automatic configuration of stateless addresses. The RA message can be a unicast message responding to a Router Solicitation (RS) sent by the gateway device to the wireless terminal, or a multicast message actively and periodically sent by the gateway device. The RA message carries gateway information returned by the gateway device to the wireless terminal, which may specifically include the gateway address and the RA prefix. Network devices can identify that their network has a gateway through the RA message, thus determining that the network at least has internal IPv6 passthrough capability.

[0148] In addition, gateway devices can also identify that the WLAN Layer 2 network has IP pass-through capability through the packets in the IPv6 packet forwarding process. The packets involved in the IPv6 packet forwarding process mainly include Neighbor Advertisement (NA) packets and global unicast IPv6 data packets.

[0149] Among them, the NA message is the response message that performs address resolution in response to the Neighbor Solicitation (NS) message.

[0150] If a network device receives a global unicast IPv6 data packet, it indicates that the network has at least internal IPv6 passthrough capability, but it does not indicate whether it has external IPv6 passthrough capability.

[0151] By parsing the received packets packet by packet, it is possible to determine in real time whether the WLAN Layer 2 network has IPv6 pass-through capability. If IPv6 pass-through capability is determined, the IPv6 protection function is disabled, and IPv6 multicast packets and IPv6 broadcast packets sent to or received from wireless terminals are forwarded normally, thus avoiding impact on normal IPv6 services. If IPv6 pass-through capability is determined not to be available, the IPv6 protection function is kept enabled, thereby preventing invalid forwarding and copying of IPv6 multicast packets and IPv6 broadcast packets. This allows the forwarding resources of network devices to be used for forwarding other packets, improving network device bandwidth, reducing processing latency, and increasing packet forwarding efficiency, thereby minimizing the impact on wireless terminal users and improving their wireless internet access experience.

[0152] When using the above method, the network device needs to parse each received packet. This parsing process consumes network device resources, adding an extra burden and potentially affecting the device's original processing performance. To minimize these problems, the network device can be tested beforehand to evaluate the benefits of copying multicast and broadcast packets versus the additional overhead of this method, thus determining the appropriate time to enable the security protection method. Since the benefit of copying multicast and broadcast packets is determined by the number of wireless terminals, a specified number can be obtained through testing. When a specified number or more wireless terminals simultaneously access a network device, the security protection method provided in this application embodiment is enabled on that network device.

[0153] If no packets indicating that the WLAN Layer 2 network has IP pass-through capability are transmitted in the WLAN Layer 2 network during certain time periods, it is impossible to accurately determine whether the WLAN Layer 2 network has IP pass-through capability. In order to solve this problem, the network device in this application embodiment can also actively detect whether the WLAN Layer 2 network has IP pass-through capability through packet detection technology.

[0154] Currently, in the process of IP network communication, there are no features at the network layer and transport layer to identify whether a message is an internal network message or an external network message. However, the message detection technology provided in this application can detect whether a WLAN Layer 2 network has internal network IP pass-through capability and whether it has external network IP pass-through capability.

[0155] Among them, detecting whether the WLAN Layer 2 network has the ability to pass through to internal network IPs includes the following two situations:

[0156] Scenario 1: Every first preset time interval, detect whether there is an IP gateway device and a DHCP server in the WLAN Layer 2 network; if there is an IP gateway or a DHCP server in the WLAN Layer 2 network, it is determined that the WLAN Layer 2 network has IP pass-through capability, and the IP protection function is turned off; if there is no IP gateway or DHCP server in the WLAN Layer 2 network, it is determined that the WLAN Layer 2 network does not have IP pass-through capability, and the IP protection function is turned on.

[0157] In other words, network devices can periodically detect whether there are IP gateway devices and DHCP servers in the WLAN Layer 2 network, thereby determining whether the WLAN Layer 2 network has IP pass-through capability. Furthermore, even if no packets indicating that the WLAN Layer 2 network has IP pass-through capability are transmitted in the WLAN Layer 2 network, it can still promptly identify whether the WLAN Layer 2 network has IP pass-through capability.

[0158] Scenario 2: When IP protection is enabled, if an IP multicast or IP broadcast message is received, and the time elapsed since the last received IP multicast or broadcast message exceeds the second preset time, the system will detect whether an IP gateway device and a DHCP server exist in the WLAN Layer 2 network. If an IP gateway or DHCP server exists in the WLAN Layer 2 network, it is determined that the WLAN Layer 2 network has IP pass-through capability, and the IP protection function is disabled. If no IP gateway or DHCP server exists in the WLAN Layer 2 network, it is determined that the WLAN Layer 2 network does not have IP pass-through capability, and the IP protection function remains enabled.

[0159] Before conducting a probe, the received IP multicast or IP broadcast packets can be cached. If the probe determines that the IP protection function can be disabled, the cached IP multicast or IP broadcast packets can be copied and forwarded normally. If the probe determines that the IP protection function needs to be kept on, the cached IP multicast or IP broadcast packets will not be copied and forwarded to the wireless interface.

[0160] It should be noted that the aforementioned second preset duration is the suppression duration for the detection method in Case 2. When the IP protection function is enabled, if an IP multicast or IP broadcast message is received, the IP gateway device and / or DHCP server will be actively probed. For the following second preset duration, the current determination result will be maintained. That is, even if another IP multicast or IP broadcast message is received within the following second preset duration, there is no need to actively probe according to the detection method in Case 2, thereby avoiding frequent active probing. Furthermore, if the IP protection function's on / off state needs to be adjusted according to the determination result in Case 1 within the second preset duration, it can be adjusted. Similarly, if it is determined based on the received first message that the IP protection function's on / off state needs to be adjusted, it can also be adjusted.

[0161] If we apply scenarios 1 and 2 above to an IPv4 scenario, the prerequisite is that the only server in the WLAN Layer 2 network used for allocating IPv4 addresses is the DHCP server. If there are other servers in the WLAN Layer 2 network used for allocating IPv4 addresses, such as a Bootstrap Protocol (BOOTP) server or an Authentication, Authorization, Accounting (AAA) server, then each server needs to be probed separately. If it is determined that there is an IPv4 gateway device or any server used for allocating IPv4 addresses in the WLAN Layer 2 network, then the WLAN Layer 2 network is determined to have IPv4 passthrough capability, and the IPv4 protection function is disabled. If it is determined that there is no IPv4 gateway device or any server used for allocating IPv4 addresses in the WLAN Layer 2 network, then the WLAN network is determined to lack IPv4 passthrough capability, and the IPv4 protection function is enabled.

[0162] In cases 1 and 2 above, the method for detecting the presence of an IP gateway device in the WLAN Layer 2 network is as follows:

[0163] Send an RS message. If an RA message is received within a third preset time period, it is determined that an IP gateway device exists in the WLAN Layer 2 network.

[0164] Taking an IPv6 scenario as an example, in normal IPv6 communication, RA messages are sent by the IP gateway device to announce its location, IPv6 address, RA prefix, and Maximum Transmission Unit (MTU) to other devices in the local network to which the IP gateway device belongs. In this embodiment, the network device can proactively send RS messages via multicast to query the local network (i.e., its own WLAN Layer 2 network) for the aforementioned information from the IP gateway device.

[0165] If the network device receives the RA message within the third preset time period, it proves that there is an IP gateway device in the local network, that is, the local network has the ability to pass through the internal network IPv6, and thus the IPv6 protection function can be turned off.

[0166] If the network device does not receive the RA message within the third preset time period, it can further determine whether the local network has the ability to pass through the internal IPv6 network based on the detection results of the DHCP server.

[0167] It should be noted that after receiving an RA message each time, the network device can record the incoming interface and the VLAN to which the RA message belongs. Then, it can send an RS message, specifically as follows:

[0168] If an RA message has been received through the first interface, an RS message is sent through the first interface. If no RA message is received within the sixth preset time period, but an RA message has been received in the first VLAN, an RS message is broadcast in the first VLAN.

[0169] If no RA message is received through any interface, an RS message is broadcast in all VLANs to which the network device belongs.

[0170] In this way, network devices can first send RS messages to the interfaces that have previously received RA messages. If no response is received, they will then attempt to broadcast RS messages in the recorded VLANs. If the network device does not have records of the incoming interface that received the RA message and the VLAN to which the RA message belongs, then the RS message will be broadcast in all VLANs to which the network device belongs.

[0171] Since the location of an IP gateway device generally does not change once it is deployed, the interface that previously received RA messages is likely still connected to the IP gateway device. Therefore, it is highly likely that the IP gateway device can be detected by sending RS messages through this interface. Thus, probing through this interface first can improve detection efficiency. Only if the detection fails through this interface will the RS message be broadcast throughout the entire VLAN. If the detection still fails, the RS message will be broadcast in all VLANs to which the network device belongs. Using this method can maximize detection efficiency.

[0172] Since the network devices in this embodiment are typically used as Layer 2 devices, the destination address included in the RS message can be a general multicast address. For example, the destination address included in the RS message can be a general multicast address starting with "ff02::". The source address included in the RS message is either an all-zero address "::" or a link-local address. The link-local address includes the bridge MAC address of the network device and the link-local address prefix. The link-local address prefix is ​​FE80:: / 10, meaning the source address is a link-local address constructed using the bridge MAC address of the network device and the FE80:: / 10 prefix.

[0173] Since the bridge MAC address of a network device is unique, the link-local address constructed based on the bridge MAC address is also unique. After using the link-local address as the source address of the RS message, the destination address of the RA message corresponding to the RS message is also the link-local address. That is, the RA message is a unicast message, not a multicast message, which can reduce the burden of forwarding RA messages in the WLAN Layer 2 network.

[0174] In addition, since the destination address of the RA message is also the local address of the link, the network device can determine that the RA message is a reply packet to the RS message sent to itself based on the destination address. Therefore, after processing the RA message, the network device can directly discard the RA message and not forward it to the wireless terminals connected to it, thereby avoiding any impact on the wireless terminals.

[0175] In scenarios 1 and 2 above, the method for detecting the presence of a DHCP server in the WLAN Layer 2 network is as follows:

[0176] Send a DHCP discovery message; if a DHCP announcement message is received from the DHCP server within the fourth preset time period, send a DHCP request message to the DHCP server; if a DHCP reply message is received from the DHCP server within the fifth preset time period, it is determined that a DHCP server exists in the WLAN Layer 2 network.

[0177] In IPv6 scenarios, assigning IPv6 addresses to wireless terminals via DHCPv6 servers is a common method for IPv6 address allocation. Furthermore, if there is no need for external network communication, there may not be an IP gateway device in the WLAN Layer 2 network. Therefore, in this embodiment, it is also possible to detect whether a DHCPv6 server exists in the WLAN Layer 2 network.

[0178] During the detection process, network devices can simulate a DHCPv6 client to request an IPv6 address from a DHCPv6 server in order to determine whether a DHCPv6 server exists in the WLAN Layer 2 network.

[0179] The network device first sends a DHCPv6 Solicit message to the DHCPv6 server. If it receives a DHCPv6 Advertise message from the DHCPv6 server within a fourth preset time period, it sends a DHCPv6 Request message to the DHCPv6 server. If it receives a DHCPv6 Reply message from the DHCPv6 server within a fifth preset time period, the IPv6 address request process is completed, and it is determined that there is an available DHCPv6 server in the WLAN Layer 2 network.

[0180] The fourth and fifth preset durations are the durations specified by the DHCP protocol.

[0181] It should be noted that if a network device receives a DHCPv6 Advertise message and a DHCPv6 Reply message from a DHCPv6 server, regardless of whether the network device successfully obtains an IPv6 address, it can be determined that a usable DHCPv6 server exists in the WLAN Layer 2 network, and the WLAN Layer 2 network has IPv6 pass-through capability. Furthermore, during this process, the IPv6 address request interaction process must be completed according to the DHCPv6 protocol to prevent the DHCPv6 server from mistakenly identifying the IPv6 address request as an attack or other unpredictable anomalies.

[0182] If a DHCPv6 Advertise message is not received within the fourth preset time period or a DHCPv6 Reply message is not received within the fifth preset time period, and no IP gateway device is detected, it can be determined that the WLAN Layer 2 network does not have IPv6 pass-through capability.

[0183] Additionally, if a DHCP reply message is received from the DHCP server within the fifth preset time period, and the DHCP reply message carries the IP address assigned to the network device, then a DHCP release message is sent to the DHCP server.

[0184] In an IPv6 scenario, this DHCP release message is a DHCPv6 Release message. If the DHCPv6 Reply message carries the IPv6 address assigned to the network device, it means that the network device has indeed obtained an IPv6 address. If the network device still needs to probe external IP servers, it can temporarily cache the IPv6 address; if the network device does not need to probe external IP servers, it should immediately send a DHCPv6 Release message to the DHCPv6 server to release the IPv6 address, so as not to affect normal wireless terminals from requesting IPv6 addresses.

[0185] In the embodiments of this application, the source address included in the DHCP discovery message and the source address included in the DHCP request message are both link-local addresses, which are addresses constructed by the bridge MAC address of the network device and the link-local address prefix (FE80:: / 10).

[0186] It should be noted that the embodiments of this application do not limit the order of detecting IP gateway devices and DHCP servers. They can be detected simultaneously or in a specific order. If both IP gateway devices and DHCP servers are detected, it can be determined that the WLAN Layer 2 network has IPv6 pass-through capability if either IP gateway device or DHCP server is detected. If neither IP gateway device nor DHCP server is detected, it can be determined that the WLAN Layer 2 network does not have IPv6 pass-through capability.

[0187] Alternatively, you can probe only the IP gateway device or only the DHCP server; you can configure it flexibly according to your actual needs.

[0188] The detection process of the above embodiments will be described below with specific examples, such as Figure 2 As shown, Figure 2 The arrows represent the timeline. Unfilled portions below the timeline indicate that IP protection is enabled, while shaded portions indicate that it is disabled. For ease of description, in this example, the first packet that characterizes the WLAN Layer 2 network's IP pass-through capability is referred to as the signature packet.

[0189] like Figure 2 As shown, assuming the IP protection function is enabled by default, the network device actively probes the WLAN Layer 2 network for the presence of an IP gateway device and / or a DHCP server every first preset time interval. Figure 2 The image shows the two active detection processes, namely "Detection 1" and "Detection 2".

[0190] During the initial active detection, if it is determined that the WLAN Layer 2 network does not have IP pass-through capability, the IP protection function remains enabled. Then, if characteristic packet 1 (Special 1) is received, confirming that the WLAN Layer 2 network now has IP pass-through capability, the IP protection function is disabled. Subsequently, if characteristic packets 2 (Special 2), 3 (Special 3), and n (Special n) are received sequentially, the IP protection function remains disabled during this period. If no characteristic packet is received after receiving characteristic packet n for a preset ten-hour period, the IP protection function is enabled.

[0191] After the network device performs a second active probe and determines that the WLAN Layer 2 network has IP pass-through capability, the IP protection function is turned off. Then, if the network device does not receive any characteristic packets for another ten preset time period, the IP protection function is turned on again.

[0192] Then the network device receives an IP multicast message and triggers a probe (probe 2.1). If the probe determines that the WLAN Layer 2 network does not have IP pass-through capability, the IP protection function will remain enabled, and a second preset duration of probe suppression will be performed. That is, even if an IP multicast message or an IP broadcast message is received within the second preset duration, the network device will not be triggered to perform a probe.

[0193] If the network device receives an IP multicast message again after the second preset time period, it can trigger another probe (probe 2.2). If the probe confirms that the WLAN Layer 2 network has IP pass-through capability, the IP protection function will be turned off.

[0194] If no characteristic packet is received for the tenth preset time period, the IP protection function will be activated again, and a third active detection will be performed after the active detection cycle is reached.

[0195] As can be seen, in the above process, the method of this application embodiment can flexibly adjust the on / off state of IP protection function based on changes in the network environment. During the adjustment process, no operation and maintenance personnel are required, which is more flexible and elastic. It can avoid network devices in WLAN Layer 2 networks with IP pass-through capability from invalid copying and forwarding of broadcast and multicast packets as much as possible, and can improve the forwarding efficiency of basic packets.

[0196] In the above embodiments, by detecting the IP gateway device and / or DHCP server, it can be determined whether the WLAN Layer 2 network has internal IPv6 pass-through capability, but it cannot guarantee whether the WLAN Layer 2 network has external IPv6 pass-through capability. Therefore, as an optional implementation, the network device can also detect whether the WLAN Layer 2 network has external IPv6 pass-through capability. The detection method is as follows:

[0197] With IP protection enabled, the system periodically probes whether devices within the WLAN Layer 2 network can communicate with the external IP server. If devices within the WLAN Layer 2 network can communicate with the external IP server, the system determines that the WLAN Layer 2 network has IP pass-through capability and disables the IP protection function.

[0198] Specifically, detecting whether devices within a WLAN Layer 2 network can communicate with an external IP server includes the following two scenarios:

[0199] Scenario 1: If the network device stores the domain name of the external IP server but not its IP address, it sends a Domain Name System (DNS) request message to the DNS server. If a DNS response message is received from the DNS server within a seventh preset time period, an Internet Control Message Protocol (ICMP) Echo Request message is sent to the external IP server. If an ICMP Echo Reply message is received from the external IP server within an eighth preset time period, it is determined that the device in the WLAN Layer 2 network can communicate with the external IP server. The DNS request message carries the domain name of the external IP server, the DNS response message carries the first IP address of the external IP server, and the ICMP Echo Request message carries the first IP address.

[0200] Among them, ICMP Echo Request and ICMP Echo Reply messages are messages in the ping probe process. If the network device stores the domain name of the external IP server, it can query the IP address of the external IP server through DNS, and then perform a ping probe on the external IP server based on the IP address, thereby determining whether the network device can communicate with the external IP server. If it is determined that communication is possible, it can be determined that the device in the WLAN Layer 2 network can communicate with the external IP server.

[0201] Because domain names are more stable than IP addresses, even if the IP address of the external IP server changes, network devices can still find the latest IP address of the external server through DNS, which can reduce maintenance costs and improve detection accuracy.

[0202] Scenario 2: If the network device stores the IP address of the external IP server, it sends an ICMP Echo Request message to the external IP server. If an ICMP EchoReply message is received from the external IP server within the ninth preset time period, it is determined that the device in the WLAN Layer 2 network can communicate with the external IP server. The ICMP Echo Request message carries a second IP address, which is the IP address of the external IP server stored by the network device.

[0203] If the network device has the IP address of the external IP server pre-configured, you can directly use ping to test whether the network device can communicate with the external IP server. If it is confirmed that communication is possible, it can be determined that the device in the WLAN Layer 2 network can communicate with the external IP server.

[0204] In both Case 1 and Case 2, the payload portion of the ICMP Echo Request message includes a designated identifier indicating that the ICMP Echo Request message is sent by a network device simulating a wireless terminal. As an example, this designated identifier can be a devil number, such as 1F2E3D4C5B6A7089.

[0205] Accordingly, after sending an ICMP Echo Request message to an external IP server, if an ICMP Echo Reply message is received from the external IP server within a ninth preset time period, and the payload of the ICMP Echo Reply message includes a specified identifier, then the ICMP Echo Reply message is discarded.

[0206] When the external IP server receives an ICMP Echo Request message, it will include the same payload as the ICMP Echo Request message in its ICMP Echo Reply message. Therefore, if the ICMP Echo Reply message received by the network device contains a specified identifier, it can be determined that the ICMP Echo Reply message is a reply from the external IP server to the ICMP Echo Request message sent by the network device. After processing the ICMP Echo Reply message, it can be discarded, thus avoiding any impact on the wireless terminal during the probing process.

[0207] It should be noted that the source address of the aforementioned DNS request message includes the RA prefix of the IP gateway device and the bridge MAC address of the network device; or, the source address of the DNS request message is the IP unicast address requested from the DHCP server.

[0208] In the above embodiments, if an RA prefix is ​​obtained during the detection of the IP gateway device, the network device constructs the source address using the RA prefix and the network device's bridge MAC address in the form of a 64-bit Extended Unique Identifier (EUI-64). If an IPv6 address (IPv6 global unicast address) is obtained during the detection of the DHCP server in the above embodiments, the IPv6 address can be directly used as the source address.

[0209] In addition, the source address of the aforementioned ICMP Echo Request message includes the RA prefix of the IP gateway device and the bridge MAC address of the network device; or, the source address of the aforementioned ICMP Echo Request message is the IP address requested from the DHCP server; or, the source address of the ICMP Echo Request message is the source IP address of the wireless terminal, which is either the source address obtained from the IP packet sent by the wireless terminal or the IP address of the wireless terminal stored in the user management module of the network device.

[0210] Among these features, network devices can capture the source IP address of wireless terminals. The source IP address of a wireless terminal refers to the source IP address obtained by the network device from a message received from the wireless terminal.

[0211] During the process of a wireless terminal accessing a network device, the network device can obtain the IP address of the wireless terminal and store the IP address in its own user management module.

[0212] It should be noted that if network devices cannot obtain the source address of DNS request messages or ICMP Echo Request messages from IP gateway devices, DHCP servers, or wireless terminals, they cannot probe external IP servers, thus confirming that the WLAN Layer 2 network does not have the ability to pass through external IP addresses.

[0213] If the network device determines through the above detection methods that the WLAN Layer 2 network does not have the ability to pass through internal network IPs or external network IPs, then the IP protection function can be kept on to avoid the network device from invalidly copying and forwarding broadcast and multicast messages, thereby improving the forwarding efficiency of service messages and enhancing network security.

[0214] The network devices in this application embodiment may involve two system architectures, which will be described separately below.

[0215] In one possible implementation, the network device's packet processing system is a CPU-based software packet processing system; for example, the network device could be a desktop computer. If a CPU-based software packet processing system is used, all packet forwarding processing is performed by the CPU. If IP protection is enabled, protection can be implemented after identifying IP multicast or IP broadcast packets at the packet forwarding entry point, eliminating the need for CPU processing of these packets and reducing the CPU load from invalid packet processing flows. CPU-based software packet processing technology offers strong programmability, low cost, and enables rapid system updates and iterations.

[0216] In this case, the system architecture of the network device is as follows: Figure 3 As shown, the network device is divided into a control plane and a data plane. The control plane includes a monitoring unit and a detection unit, while the data plane includes a parsing unit, a decision-making unit, a protection unit, and a forwarding unit.

[0217] If adopted Figure 3 The system architecture shown is as follows: Figure 4 As shown, the process of implementing the security protection method of this application embodiment in this system architecture includes the following steps.

[0218] Step 1: The network card sends all received packets to the parsing unit.

[0219] Step 2: The parsing unit parses the received message and sends the parsing result to the decision unit.

[0220] If the parsing unit can parse the message into a characteristic message, it can send a specified flag to the decision unit to indicate that the decision unit has received a characteristic message.

[0221] If the parsing unit determines that the message is a response message received after the network device actively probes, and the network device still needs to conduct further probes, then it sends the information in the message required for further probes by the network device to the decision unit.

[0222] For example, if the message is a DHCP advertisement message, the parsing unit needs to notify the decision unit that it has received the DHCP advertisement message and send the information carried in the DHCP advertisement message to the decision unit so that the subsequent forwarding unit can send a DHCP request message to the DHCP server.

[0223] Step 3: If the decision-making unit determines that the network does not have IP pass-through capability, it will send the received broadcast and multicast messages to the protection unit for buffering, packet loss, or copying only to the wired port.

[0224] Step 4: If the decision-making unit determines that the network has IP pass-through capability, it will send all received broadcast, multicast and unicast messages to the forwarding unit for forwarding.

[0225] Step 5: The detection unit detects whether the network has the ability to directly connect to internal and external IP addresses.

[0226] The detection timing and detection method of the detection unit have been described in the above embodiments and will not be repeated here.

[0227] Step 6: The detection unit sends the detection results to the decision-making unit for decision-making.

[0228] Step 7: With IP protection disabled, the monitoring unit periodically checks for any distinctive packets.

[0229] The monitoring unit can periodically check the reception time of each characteristic message stored in the decision unit to determine whether no characteristic message has been received for a preset ten-hour period.

[0230] Step 8: The monitoring unit sends the inspection results to the decision-making unit for decision-making.

[0231] If the inspection result shows no characteristic packets for ten consecutive preset durations, the decision unit can enable the IP protection function.

[0232] Step 9: If the protection unit has cached broadcast or multicast packets when the IP protection function is enabled, it will notify the detection unit to initiate a detection.

[0233] It should be noted that the embodiments of this application can also be configured with a whitelist. When the IP protection function is enabled, the forwarding unit can forward non-broadcast and multicast packets as well as broadcast and multicast packets that meet the packet characteristics set in the whitelist.

[0234] In this application embodiment, at least the following message characteristics can be configured in the whitelist:

[0235] (1) Use the local link address of IPv6 to implement the message of the bonjour protocol. These messages are used for service discovery, etc.

[0236] (2) Messages used by various devices within the cluster system to synchronize control information and keep-alive using the configured IPv6 address.

[0237] (3) Probing service messages such as Bidirectional Forwarding Detection (BFD), using IPv6 broadcast messages or IPv6 multicast messages for keep-alive and measurement, etc.

[0238] As Figure 4 An alternative, such as Figure 5 As shown, the parsing unit can also be set in the network card, that is, the received packets can be parsed using the network card's built-in parsing unit, thereby improving the overall system processing performance. Figure 5 The implementation methods of other units and Figure 4 Same, that is Figure 5 Steps 2-8 in the middle Figure 4 Steps 3 through 9 are the same and will not be described again here.

[0239] use Figure 4 or Figure 5This approach leverages the data plane's parallel packet parsing capabilities to parse packet information before sending it to the control plane. This reduces CPU resource consumption and alleviates the burden of forwarding normal packets. Furthermore, if... Figure 5 The alternative approach utilizes the network card's built-in parsing unit to parse the received packets one by one, thereby improving the overall system's processing performance.

[0240] In another possible implementation, the packet processing system of the network device is a hardware packet processing system based on chips such as Field Programmable Gate Arrays (FPGAs) and Network Processors (NPs). For example, the network device could be a switch or router. If a hardware packet processing system is used, there are two implementation methods. Method one involves a combination of hardware and software. The control plane sends the characteristics of the characteristic packets to the data plane of the hardware chip using coarse-grained rules (such as ACLs). The data plane then copies the characteristic packets that meet the rules to the CPU-based control plane, where it performs further deep analysis and decision-making to determine whether the WLAN Layer 2 network has IP pass-through capability. If it determines that IP pass-through capability is not present, it sends another rule to the data plane, thereby enabling the data plane to protect against multicast and broadcast packets. Method two involves completely offloading packet parsing to the data plane. The parsing method is hard-coded into the hardware chip. Upon receiving a packet, the data plane can directly parse it to determine if it is a characteristic packet and report the result to the control plane, eliminating the need for further parsing by the control plane. Both methods have minimal impact on the normal packet forwarding process of the data plane.

[0241] In this case, if method one is adopted, the system architecture of the network device is as follows: Figure 6 As shown, the network device is divided into a control plane and a data plane. The control plane includes a monitoring unit, a parsing unit, a decision-making unit, and a detection unit, while the data plane includes a matching unit, an action unit, a protection unit, and a forwarding unit.

[0242] If adopted Figure 6 The system architecture shown is as follows: Figure 7 As shown, the process of implementing the security protection method of this application embodiment in this system architecture includes the following steps.

[0243] Step 1: The matching unit of the hardware chip performs message matching through specific hardware. If a message that meets Rule 1 is matched, the message is sent to the action unit to perform the message action.

[0244] The specific hardware can be a ternary content addressable memory (TCAM). The TCAM stores rule 1, which can be an ACL rule issued by the control plane. The matching field of rule 1 can include all or part of the features of the feature packet. If the received packet completely matches the matching field of rule 1, then the packet is determined to satisfy rule 1.

[0245] Step 2: The action unit copies the message or information in the message and sends it to the parsing unit for parsing.

[0246] If Rule 1 includes all the features of the feature message, the action unit only needs to notify the parsing unit whether the feature message has been received. If Rule 1 includes only some of the features of the feature message, the action unit needs to send the message to the parsing unit for further parsing.

[0247] For example, if rule 1 includes the protocol number and port number of the DHCP protocol, and the currently received message matches rule 1, but the matching unit can only determine that the message is a DHCP message, but cannot determine whether the message is a DHCP advertisement message or a DHCP reply message, then the parsing unit of the control plane needs to further parse the message.

[0248] Step 3: After saving the useful information in the message, the parsing unit notifies the decision-making unit of the parsing results.

[0249] Among them, the useful information is information that is useful for subsequent message processing and probing, such as the RA prefix, the ingress interface that receives the RA message, and the VLAN to which the RA message belongs.

[0250] The parsing result indicates whether the currently received message is a characteristic message.

[0251] Step 4: The decision-making unit analyzes the results from the analysis unit, the detection unit, and the monitoring unit, makes a decision, and sends the decided multicast message processing action to the hardware chip.

[0252] The processing action can be in the form of an ACL, for example, the ACL can perform buffering, packet loss or copy only to the wired port if a multicast or broadcast message is matched.

[0253] Step 5: The action unit instructs the protection unit to perform actions such as buffering, packet loss, or copying only to the wired port for multicast or broadcast messages.

[0254] Step 6: The action unit sends all messages except multicast and broadcast messages to the forwarding unit for forwarding.

[0255] Step 7: The detection unit detects whether the network has the ability to directly connect to internal and external IP addresses.

[0256] The detection timing and detection method of the detection unit have been described in the above embodiments and will not be repeated here.

[0257] Step 8: The detection unit sends the detection results to the decision-making unit for decision-making.

[0258] Step 9: With IP protection disabled, the monitoring unit periodically checks for any distinctive packets.

[0259] The monitoring unit can periodically check the reception time of each characteristic message stored in the decision unit to determine whether no characteristic message has been received for a preset ten-hour period.

[0260] Step 10: The monitoring unit sends the monitoring results to the decision-making unit for decision-making.

[0261] Step 11: If the protection unit has cached broadcast or multicast packets when the IP protection function is enabled, it notifies the detection unit to initiate a detection.

[0262] This application utilizes a common basic protocol for active detection and monitoring of characteristic packets, making it applicable to most wireless Layer 2 and large Layer 2 network scenarios. When identifying characteristic packets, it is based on the most basic characteristics of dynamic address allocation protocols, exhibiting good scalability. If new dynamic protocols emerge in the future, only the new protocols need to be adapted. Furthermore, monitoring, detection, and protection are performed based on the lower link and network layers of the seven-layer network model, automatically adapting to changes in most environmental factors, such as changes in the number of connected wireless devices and terminals, network topology changes, and the enabling and disabling of IPv6 forwarding functions, thereby reducing operational costs and improving operational efficiency. Moreover, the identification-then-protection mechanism of this application—that is, first identifying whether IP pass-through capability is available, and then deciding whether to enable or disable IP protection functions—can solve the problem of inter-domain or inter-group isolation failure in related technologies.

[0263] It should be noted that the security protection method provided in this application embodiment has the following three times for opening and closing.

[0264] The first method involves configuring network devices to enable or disable security protection via commands.

[0265] The second method involves enabling or disabling security protection methods via commands. Subsequently, if the network device's traffic load exceeds a preset load threshold, the security protection methods will be automatically enabled; if the network device's traffic load falls below the preset load threshold, the security protection methods will be automatically disabled.

[0266] The third method involves enabling or disabling security protection via commands. Subsequently, if the network device's traffic load exceeds a preset threshold, the security protection method is automatically enabled; if the network device's traffic load falls below the preset threshold, the security protection method is automatically disabled. Furthermore, if the number of wireless terminals connected to the network device exceeds a specified number, the security protection method is automatically enabled; if the number of wireless terminals connected to the network device falls below the specified number, the security protection method is automatically disabled.

[0267] It should also be noted that the security protection method provided in this application embodiment can coexist with other isolation technologies in related technologies. If other isolation technologies also have a whitelist function, the priority between the security protection method of this application embodiment and other isolation technologies can be set in advance. Then, if the results of the decision made by the security protection method provided in this application embodiment and other isolation technologies are different, the decision result of the method with higher priority shall prevail.

[0268] Alternatively, the decision result of the embodiments of this application can be used as the preferred decision result. When the decision results of other isolation technologies are different, the decision result of the embodiments of this application shall be adopted first.

[0269] Corresponding to the above method embodiments, this application provides a security protection device applied to network devices, such as... Figure 8 As shown, the device includes:

[0270] Receiver module 801 is used to receive the first message;

[0271] The shutdown module 802 is used to disable the IP protection function if the first message indicates that the WLAN Layer 2 network to which the network device belongs has IP pass-through capability. IP pass-through capability is the ability for devices to communicate directly through IP addresses. IP protection function means not copying and forwarding received IP multicast messages and IP broadcast messages to the wireless interface.

[0272] The enabling module 803 is used to keep the IP protection function enabled if the first message indicates that the WLAN Layer 2 network does not have IP pass-through capability.

[0273] Optionally, the device further includes:

[0274] The detection module is used to detect whether there are IP gateway devices and DHCP servers in the WLAN Layer 2 network every first preset time interval;

[0275] The shutdown module 802 is also used to determine that the WLAN Layer 2 network has IP pass-through capability and disable IP protection function if an IP gateway or DHCP server exists in the WLAN Layer 2 network.

[0276] The 803 module is also used to determine that the WLAN Layer 2 network does not have IP pass-through capability if there is no IP gateway and DHCP server in the WLAN Layer 2 network, and to enable IP protection function.

[0277] Optionally, the device further includes:

[0278] The detection module is used to detect whether there is an IP gateway device and a DHCP server in the WLAN Layer 2 network if an IP multicast message or IP broadcast message is received when the IP protection function is enabled, and the time between receiving the IP multicast message or broadcast message and the previous time exceeds a second preset time.

[0279] The shutdown module 802 is also used to determine that the WLAN Layer 2 network has IP pass-through capability and disable IP protection function if an IP gateway or DHCP server exists in the WLAN Layer 2 network.

[0280] The enabling module 803 is also used to determine that the WLAN Layer 2 network does not have IP pass-through capability if there is no IP gateway and DHCP server in the WLAN Layer 2 network, and to keep the IP protection function in the enabled state.

[0281] Optionally, the device further includes:

[0282] The detection module is used to periodically detect whether devices in the WLAN Layer 2 network can communicate with the external IP server when the IP protection function is enabled.

[0283] The shutdown module 802 is also used to determine that the WLAN Layer 2 network has IP pass-through capability and disable IP protection function if the devices in the WLAN Layer 2 network can communicate with the external IP server.

[0284] Optionally, the detection module is specifically used for: sending a Routing Request (RS) message; if a Routing Advertisement (RA) message is received within a third preset time period, then determining that an IP gateway device exists in the WLAN Layer 2 network; sending a DHCP Discover message; if a DHCP Advertisement message is received from the DHCP server within a fourth preset time period, then sending a DHCP Request message to the DHCP server; if a DHCP Reply message is received from the DHCP server within a fifth preset time period, then determining that a DHCP server exists in the WLAN Layer 2 network.

[0285] Optionally, the detection module is specifically used to: if an RA message has been received through the first interface, then send an RS message through the first interface; if no RA message has been received within a sixth preset time period, but an RA message has been received in the first VLAN, then broadcast an RS message in the first VLAN; if no RA message has been received through any interface, then broadcast an RS message in all VLANs to which the network device belongs.

[0286] Optionally, the detection module is further configured to send a DHCP release message to the DHCP server if it receives a DHCP reply message from the DHCP server within a fifth preset time period, and the DHCP reply message carries an IP address assigned to the network device.

[0287] Optionally, the RS message includes a destination address and a source address. The destination address is a general multicast address, and the source address is an all-zero address or a link-local address. The link-local address includes the bridge MAC address of the network device and the link-local address prefix.

[0288] Both the source address included in the DHCP Discover message and the source address included in the DHCP Request message are link-local addresses.

[0289] Optionally, the detection module is specifically used for:

[0290] A DNS request message is sent to the domain name server; if a DNS response message is received from the domain name server within a seventh preset time period, an ICMP Echo Request message is sent to the external IP server; if an ICMP Echo Reply message is received from the external IP server within an eighth preset time period, it is determined that the device in the WLAN Layer 2 network can communicate with the external IP server; wherein, the DNS response message carries the IP address of the external IP server; wherein, the DNS request message carries the domain name of the external IP server, the DNS response message carries the first IP address of the external IP server, and the ICMP Echo Request message carries the first IP address; or,

[0291] Send an ICMP Echo Request message to the external IP server; if an ICMP Echo Reply message is received from the external IP server within the ninth preset time period, it is determined that the device in the WLAN Layer 2 network can communicate with the external IP server. The ICMP Echo Request message carries a second IP address, which is the IP address of the external IP server stored in the network device.

[0292] Optionally, the payload portion of the ICMP Echo Request message includes a specified identifier, which indicates that the ICMP Echo Request message is a message sent by a network device simulating a wireless terminal;

[0293] The detection module is also used to discard the ICMP Echo Reply message if it receives an ICMP Echo Reply message from an external IP server within a ninth preset time period, and the payload of the ICMP Echo Reply message includes a specified identifier.

[0294] Optionally, the source address of the DNS request message includes the RA prefix of the IP gateway device and the bridge MAC address of the network device; or, the source address of the DNS request message is the IP address requested from the DHCP server.

[0295] The source address of an ICMP Echo Request message includes the RA prefix of the IP gateway device and the bridge MAC address of the network device; or, the source address of an ICMP Echo Request message is an IP address requested from a DHCP server; or, the source address of an ICMP Echo Request message is a source address obtained from an IP packet sent by a wireless terminal, or the IP address of the wireless terminal stored in the user management module of the network device.

[0296] Optionally, the device further includes:

[0297] The determination module is used to determine that if the first message is any of the following, then the first message indicates that the WLAN Layer 2 network has IP pass-through capability:

[0298] Messages during the DHCP dynamic address allocation process;

[0299] Routing announcement messages sent by the gateway device to the terminal;

[0300] Neighbor Notification (NA) message;

[0301] Global unicast IP data packets.

[0302] Optionally, the enabling module 803 is also used to enable the IP protection function if no packet indicating that the WLAN Layer 2 network has IP pass-through capability is received for a continuous tenth preset time.

[0303] This application also provides a network device, such as... Figure 9 As shown, it includes a processor 901, a communication interface 902, a memory 903, and a communication bus 904, wherein the processor 901, the communication interface 902, and the memory 903 communicate with each other through the communication bus 904.

[0304] Memory 903 is used to store computer programs;

[0305] When the processor 901 executes the program stored in the memory 903, it implements the method steps in the above method embodiments.

[0306] The communication bus mentioned in the above network devices can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. This communication bus can be divided into address bus, data bus, control bus, etc. For ease of illustration, only one thick line is used to represent it in the diagram, but this does not indicate that there is only one bus or one type of bus.

[0307] The communication interface is used for communication between the aforementioned network devices and other devices.

[0308] The memory may include random access memory (RAM) or non-volatile memory (NVM), such as at least one disk storage device. Optionally, the memory may also be at least one storage device located remotely from the aforementioned processor.

[0309] The processors mentioned above can be general-purpose processors, including central processing units (CPUs), network processors (NPs), etc.; they can also be digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components.

[0310] In another embodiment provided in this application, a computer-readable storage medium is also provided, which stores a computer program that, when executed by a processor, implements any of the above-described security protection methods.

[0311] In another embodiment provided in this application, a computer program product containing instructions is also provided, which, when run on a computer, causes the computer to execute any of the security protection methods described above.

[0312] In the above embodiments, implementation can be achieved entirely or partially through software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented entirely or partially as a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid state disk (SSD)).

[0313] It should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply the existence of any such actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, method, article, or device comprising the element.

[0314] The various embodiments in this specification are described in a related manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, the embodiments for apparatus, network devices, storage media, and program products are basically similar to the method embodiments, so the descriptions are relatively simple; relevant parts can be referred to the descriptions of the method embodiments.

[0315] The above description is merely a preferred embodiment of this application and is not intended to limit the scope of protection of this application. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application are included within the scope of protection of this application.

Claims

1. A security protection method, characterized in that, Applied to network devices, the method includes: Receive the first message; If the first message indicates that the WLAN Layer 2 network to which the network device belongs has IP pass-through capability, then the IP protection function is turned off. The IP pass-through capability is the ability for devices to communicate directly through IP addresses. The IP protection function refers to not copying and forwarding received IP multicast messages and IP broadcast messages to the wireless interface. If the first message indicates that the WLAN Layer 2 network does not have IP pass-through capability, then the IP protection function remains enabled.

2. The method according to claim 1, characterized in that, The method further includes: Every first preset time interval, detect whether there is an IP gateway device and a DHCP server in the WLAN Layer 2 network; If an IP gateway or DHCP server exists in the WLAN Layer 2 network, then the WLAN Layer 2 network is determined to have IP pass-through capability, and the IP protection function is disabled. If there is no IP gateway and DHCP server in the WLAN Layer 2 network, it is determined that the WLAN Layer 2 network does not have IP pass-through capability, and the IP protection function is enabled.

3. The method according to claim 1 or 2, characterized in that, The method further includes: When the IP protection function is enabled, if an IP multicast message or IP broadcast message is received, and the duration of the received IP multicast message or broadcast message exceeds the second preset duration, then the presence of an IP gateway device and a DHCP server in the WLAN Layer 2 network is detected. If an IP gateway or DHCP server exists in the WLAN Layer 2 network, then the WLAN Layer 2 network is determined to have IP pass-through capability, and the IP protection function is disabled. If there is no IP gateway and DHCP server in the WLAN Layer 2 network, it is determined that the WLAN Layer 2 network does not have IP pass-through capability, and the IP protection function remains enabled.

4. The method according to claim 3, characterized in that, The method further includes: With the IP protection function enabled, periodically probe whether devices within the WLAN Layer 2 network can communicate with the external IP server; If the devices within the WLAN Layer 2 network can communicate with the external IP server, then the WLAN Layer 2 network is determined to have IP pass-through capability, and the IP protection function is disabled.

5. The method according to claim 2, characterized in that, The detection of the presence of an IP gateway device and a DHCP server in the WLAN Layer 2 network includes: Send a routing request (RS) message; If a Routing Advertisement (RA) message is received within the third preset time period, it is determined that an IP gateway device exists in the WLAN Layer 2 network. Send a DHCP discovery message; If a DHCP announcement message is received from the DHCP server within the fourth preset time period, a DHCP request message is sent to the DHCP server. If a DHCP reply message is received from the DHCP server within the fifth preset time period, it is determined that a DHCP server exists in the WLAN Layer 2 network.

6. The method according to claim 5, characterized in that, The sending of the routing request (RS) message includes: If an RA message has been received through the first interface, an RS message is sent through the first interface; if no RA message is received within the sixth preset time period, but an RA message has been received in the first VLAN, an RS message is broadcast in the first VLAN. If no RA message is received through any interface, an RS message is broadcast in all VLANs to which the network device belongs.

7. The method according to claim 5, characterized in that, After sending the DHCP request message to the DHCP server, the method further includes: If a DHCP reply message is received from the DHCP server within the fifth preset time period, and the DHCP reply message carries the IP address assigned to the network device, then a DHCP release message is sent to the DHCP server.

8. The method according to claim 5, characterized in that, The RS message includes a destination address and a source address. The destination address is a general multicast address, and the source address is either an all-zero address or a link-local address. The link-local address includes the bridge MAC address and the link-local address prefix of the network device. The source address included in the DHCP discovery message and the source address included in the DHCP request message are both the link-local address.

9. The method according to claim 4, characterized in that, The step of detecting whether devices within the WLAN Layer 2 network can communicate with an external IP server includes: A DNS request message is sent to a domain name server; if a DNS response message is received from the domain name server within a seventh preset time period, an ICMP Echo Request message is sent to the external IP server; if an ICMP Echo Reply message is received from the external IP server within an eighth preset time period, it is determined that the device in the WLAN Layer 2 network can communicate with the external IP server; wherein, the DNS request message carries the domain name of the external IP server, the DNS response message carries the first IP address of the external IP server, and the ICMP Echo Request message carries the first IP address; or, Send an ICMP Echo Request message to the external IP server; if an ICMP Echo Reply message is received from the external IP server within a ninth preset time period, it is determined that the device in the WLAN Layer 2 network can communicate with the external IP server. The ICMP Echo Request message carries a second IP address, which is the IP address of the external IP server stored by the network device.

10. The method according to claim 9, characterized in that, The payload portion of the ICMP Echo Request message includes a specified identifier; After sending the ICMP Echo Request message to the external IP server, the method further includes: If an ICMP Echo Reply message is received from the external IP server within the ninth preset time period, and the payload of the ICMP Echo Reply message includes the specified identifier, then the ICMP Echo Reply message is discarded.

11. The method according to claim 9 or 10, characterized in that, The source address of the DNS request message includes the RA prefix of the IP gateway device and the bridge MAC address of the network device; or, the source address of the DNS request message is the IP address requested from the DHCP server. The source address of the ICMP Echo Request message includes the RA prefix of the IP gateway device and the bridge MAC address of the network device; or, the source address of the ICMP Echo Request message is an IP address requested from the DHCP server; or, the source address of the ICMP Echo Request message is the source IP address of the wireless terminal, which is either the source address obtained from the IP packet sent by the wireless terminal or the IP address of the wireless terminal stored in the user management module of the network device.

12. The method according to claim 1, characterized in that, After receiving the first message, the method further includes: If the first message is any of the following, then the first message indicates that the WLAN Layer 2 network has IP pass-through capability: Messages during the DHCP dynamic address allocation process; Routing announcement messages sent by the gateway device to the terminal; Neighbor Notification (NA) message; Global unicast IP data packets.

13. The method according to claim 1, characterized in that, After disabling the IP protection function, the method further includes: If no packet indicating that the WLAN Layer 2 network has IP pass-through capability is received for ten consecutive preset time periods, then the IP protection function is activated.

14. A safety protection device, characterized in that, Applied to network devices, the device includes: The receiving module is used to receive the first message; The shutdown module is used to disable the IP protection function if the first message indicates that the WLAN Layer 2 network to which the network device belongs has IP pass-through capability. The IP pass-through capability is the ability for devices to communicate directly through IP addresses. The IP protection function refers to not copying and forwarding received IP multicast messages and IP broadcast messages to the wireless interface. The enabling module is used to keep the IP protection function enabled if the first message indicates that the WLAN Layer 2 network does not have IP pass-through capability.

Citation Information

Patent Citations

  • Business response method and device, equipment, storage medium and program product

    CN118713987A

  • Secure DHCP processing for layer two access networks

    US20110029645A1