Message forwarding processing method, device, equipment, system and storage medium

By encapsulating the packets on the main ONU of the FTTR network, adding port tags and tunnel headers, the problem of missing information from the ONU port in message forwarding processing after hanging next to the firewall device is solved, and the security and accuracy of message processing are achieved.

CN119966644AActive Publication Date: 2025-05-09HUAWEI TECH CO LTD

Patent Information

Application Number
CN202311490786.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-11-08
Publication Date
2025-05-09
Estimated Expiration
2043-11-08

AI Technical Summary

Technical Problem

In FTTR networking, how to ensure that the forwarding process of packets can accurately identify the port information from the ONU while hanging next to the firewall device, thereby maintaining the security and accuracy of packet processing.

Method used

By encapsulating the received packets on the main ONU and adding port tags and tunnel headers, the firewall device can route forward based on the tunnel header. When the main ONU receives the packets processed by the firewall device, it obtains the processing policy configured by the port from the port tag based on the port tag to ensure the correct forwarding of the packets.

Benefits of technology

It realizes that when hanging next to the firewall device, the main ONU can accurately identify the port information of the slave ONU, ensure the security and accuracy of message processing, and be not affected by the firewall device.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119966644A_ABST
    Figure CN119966644A_ABST
Patent Text Reader

Abstract

The invention discloses a message forwarding processing method, device, equipment and system and a storage medium, and relates to the technical field of communication. The master ONU receives a first message sent by the slave ONU; under the condition of traffic direct connection between the slave ONU and the firewall equipment, a second message is sent to the firewall equipment, the second message is obtained by adding a port label and a first tunnel head to the first message, the port label indicates a port of the slave ONU, and the first tunnel head indicates the firewall equipment to send the second message to the master ONU; receiving a second message which is audited or filtered by the firewall equipment, acquiring the first message and the port label based on the second message, and acquiring a first processing strategy configured from the port of the ONU based on the port label; and processing and forwarding the first message according to the first processing strategy. According to the method, the first message which is transmitted by the slave ONU and forwarded by the firewall equipment can be processed according to the first processing strategy configured by the port of the slave ONU.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of communication technology, and in particular to a message forwarding processing method, device, equipment, system and storage medium. Background Art

[0002] With the development of communication technology, fiber to the room (FTTR) technology has been widely used in home or enterprise access networks. FTTR networking includes a master optical network unit (ONU), a slave ONU and an optical network. The master ONU is located between the optical line terminal (OLT) and the slave ONU. It is connected to the OLT through a passive optical network (PON) interface to support Gigabit access to homes, and provides a PON interface to connect the slave ONU. The slave ONUs are distributed to each room, connected to the master ONU through optical cables or optoelectronic composite cables, and connected to various home Internet terminals to achieve on-demand access to Internet terminals in each room. Therefore, FTTR can also be called fiber-optic on-demand connection.

[0003] In order to improve the security of FTTR networking, firewall devices need to be deployed independently. Firewall devices can create a protective barrier between FTTR networking and external networks, thereby blocking unsafe network factors. Therefore, in the scenario of deploying firewall devices in FTTR networking, how to forward and process received messages is an urgent problem to be solved. Summary of the invention

[0004] The present application provides a message forwarding processing method, apparatus, device, system and storage medium for forwarding received messages in a scenario where a firewall device is deployed in an FTTR network.

[0005] In a first aspect, a message forwarding processing method is provided. Taking a master ONU executing the method as an example, the master ONU receives a first message sent by a slave ONU; in the case of direct traffic between the slave ONU and a firewall device, a second message is sent to the firewall device, the second message is obtained by adding a port tag and a first tunnel header to the first message, the port tag indicates the port of the slave ONU, and the first tunnel header indicates that the firewall device sends the second message to the master ONU; the second message audited or filtered by the firewall device is received, the first message and the port tag are obtained based on the second message, and a first processing strategy configured for the port of the slave ONU is obtained based on the port tag, the first processing strategy including at least one of a service binding strategy, a wide area network (LAN) binding strategy, a local area network (LAN) binding strategy, a port filtering strategy, a priority strategy, or a sending interface strategy; and the first message is forwarded according to the first processing strategy.

[0006] In the method, the first message received from the slave ONU can be forwarded after being processed by the firewall device, that is, the firewall device is cascaded and hung by the main ONU, which improves the security of the first message forwarded by the main ONU. And by encapsulating the port label and the first tunnel header of the first message to obtain the second message, the firewall device can perform routing forwarding of the second message based on the first tunnel header. After the firewall device forwards the second message to the main ONU, the main ONU can obtain the inner encapsulated port label and the first message based on the second message, and determine that the port of the slave ONU originally sent the first message according to the port label, that is, the information of the original port of the first message will not be lost, so that the main ONU can still process the first message received from the firewall device based on the first processing strategy configured by the port of the slave ONU. In other words, the processing method of the main ONU for the first message sent from the slave ONU after the cascaded and hung firewall device is the same as the processing method of the first message sent from the slave ONU before the cascaded and hung firewall device, and the performance of the message processing will not be affected by the cascaded and hung firewall device, thereby improving the accuracy of the message forwarding processing.

[0007] In a possible implementation, the first message carries information indicating a port of a slave ONU; after the master ONU receives the first message sent by the slave ONU, when traffic between the slave ONU and the firewall device is not directly connected, the master ONU obtains a first processing strategy configured for the port of the slave ONU based on information about the port of the slave ONU, processes the first message based on the first processing strategy, and obtains a processed third message; when the next hop of the third message indicates an OLT and traffic between the OLT and the firewall device is directly connected, the master ONU sends the third message to the firewall device; receives the third message that has been audited or filtered by the firewall device, and sends the third message to the OLT.

[0008] The third message sent by the master ONU to the OLT is processed by the firewall device before being forwarded before being sent to the OLT, thereby improving the security of the third message sent to the OLT.

[0009] In a possible implementation, the master ONU also receives a fourth message sent by the OLT; when traffic is directly connected between the OLT and the firewall device, the master ONU sends a fourth message to the firewall device; receives the fourth message that has been audited or filtered by the firewall device, and forwards the fourth message in the same manner as the fourth message sent by the OLT is received.

[0010] Thus, the fourth message sent by the received OLT can be forwarded after being processed by the firewall device, thereby improving the security of the fourth message forwarded by the main ONU. Moreover, after the fourth message enters the main ONU again through the firewall device, the main ONU can simulate the fourth message sent by the received firewall device as the fourth message sent by the received OLT, and then still process it according to the fourth message sent by the received OLT. In other words, the way the main ONU processes the fourth message sent by the OLT after the cascaded bypass firewall device is connected is the same as the way the main ONU processes the fourth message sent by the OLT before the cascaded bypass firewall device is connected, and the accuracy of the message forwarding processing will not be affected by the cascaded bypass firewall device, thereby improving the accuracy of the message forwarding processing.

[0011] In a possible implementation, after the master ONU receives the fourth message sent by the OLT, when the traffic between the OLT and the firewall device is not directly connected, the destination port of the fourth message is determined to be the port of the slave ONU based on the destination address of the fourth message; when the next hop of the fourth message indicates the slave ONU and the traffic between the slave ONU and the firewall device is directly connected, a fifth message is sent to the firewall device, the fifth message is obtained by adding a port label and a second tunnel header to the fourth message, and the second tunnel header indicates the firewall device to send the fifth message to the master ONU; the fifth message that has been audited or filtered by the firewall device is received, the fourth message and the port label are obtained based on the fifth message, and the fourth message is sent to the slave ONU based on the port of the slave ONU indicated by the port label.

[0012] For the fourth message sent by the master ONU to the slave ONU, it is processed by the firewall device before being sent to the slave ONU and then forwarded, thereby improving the security of the fourth message sent to the slave ONU. In addition, by encapsulating the port label and the second tunnel header of the fourth message to obtain the fifth message, the firewall device can perform routing forwarding of the fifth message based on the second tunnel header. After the firewall device forwards the fifth message to the master ONU, the master ONU can obtain the inner encapsulated port label and the fourth message based on the fifth message, and determine that the fourth message is sent to the port of the slave ONU according to the port label, thereby improving the accuracy of message forwarding processing after the cascaded bypass firewall device is connected.

[0013] In a possible implementation, after obtaining the first message and the port label based on the second message, the corresponding relationship between the source address information of the first message and the port of the slave ONU indicated by the port label can also be saved, and the source address information can include media access control (media access control, MAC) information and address resolution protocol (address resolution protocol, ARP) information. In this case, the method of determining that the destination port of the fourth message is the port of the slave ONU based on the destination address of the fourth message can be, based on the MAC information and ARP information indicated by the destination address of the fourth message, determining that the destination port of the fourth message is the port of the slave ONU in the corresponding relationship.

[0014] Among them, after receiving the first message sent by the slave ONU, the master ONU does not learn the source address information of the first message first because the traffic between the slave ONU and the firewall device is directly connected. Instead, after receiving the second message sent by the firewall device based on the first tunnel header, the master ONU obtains the first message and the port label based on the second message, and then learns the source address information of the first message to the port of the slave ONU indicated by the port label, that is, saves the corresponding relationship between the source address information of the first message and the port of the slave ONU indicated by the port label. Although the master ONU receives the first message twice, the source address information of the first message is only learned to the port of the slave ONU indicated by the port label, which does not lead to learning the source address information of the first message twice, nor does it mistakenly learn the source address information of the first message to the port corresponding to the second LAN interface, which improves the accuracy of obtaining the corresponding relationship based on the first message, and further improves the accuracy of determining the port based on the corresponding relationship.

[0015] In a second aspect, a message forwarding processing device is provided, which is applied to a master ONU, and includes:

[0016] A transceiver module, used to perform operations related to receiving and / or sending in the first aspect or any possible implementation manner of the first aspect;

[0017] A processing module is used to perform other operations besides the receiving and / or sending related operations in the first aspect or any possible implementation manner of the first aspect.

[0018] In a possible implementation, the transceiver module includes a receiving module and / or a sending module. The receiving module is used to perform reception-related operations, and the sending module is used to perform sending-related operations.

[0019] In a possible implementation, a transceiver module is used to receive a first message sent from an ONU; in the case where traffic is directly connected between the slave ONU and the firewall device, a second message is sent to the firewall device, the second message is obtained by adding a port tag and a first tunnel header to the first message, the port tag indicates the port of the slave ONU, and the first tunnel header indicates that the firewall device sends the second message to the master ONU; the second message that has been audited or filtered by the firewall device is received; a processing module is used to obtain the first message and the port tag based on the second message, and obtain a first processing strategy configured for the port of the slave ONU based on the port tag, the first processing strategy including at least one of a service binding strategy, a WAN binding strategy, a VLAN binding strategy, a port filtering strategy, a priority strategy, or a sending interface strategy; and forward the first message according to the first processing strategy.

[0020] In a possible implementation, the first message carries information indicating a port of the slave ONU; the processing module is further used to obtain a first processing strategy configured for the port of the slave ONU based on the information of the port of the slave ONU when traffic between the slave ONU and the firewall device is not directly connected, and to process the first message based on the first processing strategy to obtain a processed third message; the transceiver module is further used to send a third message to the firewall device when the next hop of the third message indicates the OLT and traffic between the OLT and the firewall device is directly connected; receive the third message that has been audited or filtered by the firewall device, and send the third message to the OLT.

[0021] In a possible implementation, the transceiver module is further used to receive a fourth message sent by the OLT; send a fourth message to the firewall device when traffic is directly connected between the OLT and the firewall device; receive the fourth message that has been audited or filtered by the firewall device, and forward the fourth message in the same manner as the fourth message sent by the OLT is received.

[0022] In a possible implementation, the processing module is further used to determine that the destination port of the fourth message is the port of the slave ONU based on the destination address of the fourth message when the traffic between the OLT and the firewall device is not directly connected; the transceiver module is further used to send a fifth message to the firewall device when the next hop of the fourth message indicates the slave ONU and the traffic between the slave ONU and the firewall device is directly connected, the fifth message is obtained by adding a port label and a second tunnel header to the fourth message, and the second tunnel header indicates the firewall device to send the fifth message to the master ONU; receive the fifth message that has been audited or filtered by the firewall device, obtain the fourth message and the port label based on the fifth message, and send the fourth message to the slave ONU based on the port of the slave ONU indicated by the port label.

[0023] In a possible implementation, the processing module is also used to save the correspondence between the source address information of the first message and the port of the slave ONU indicated by the port label, the source address information including MAC information and ARP information; based on the MAC information and ARP information indicated by the destination address of the fourth message, the destination port of the fourth message is determined to be the port of the slave ONU in the correspondence.

[0024] In a third aspect, a network device is provided, comprising: a processor, the processor being coupled to a memory, the memory storing at least one program instruction or code, the at least one program instruction or code being loaded and executed by the processor, so that the network device implements the message forwarding processing method as described in the first aspect or any one of the first aspects.

[0025] Optionally, the number of the processors is one or more, and the number of the memories is one or more.

[0026] Optionally, the memory may be integrated with the processor, or the memory may be provided separately from the processor.

[0027] In the specific implementation process, the memory can be a non-transitory memory, such as a read-only memory (ROM), which can be integrated with the processor on the same chip or can be set on different chips. This application does not limit the type of memory and the setting method of the memory and the processor.

[0028] In a fourth aspect, a message forwarding processing system is provided, the message forwarding processing system comprising a master ONU, a slave ONU and a firewall device; the slave ONU is used to send a first message to the master ONU; the master ONU is used to execute the method described in the first aspect or any possible implementation of the first aspect; the firewall device is used to receive a second message sent by the master ONU, the second message is obtained by encapsulating a port label and a first tunnel header in the first message, and the firewall device is also used to send the second message to the master ONU after being audited or filtered by the firewall device.

[0029] In a fifth aspect, a computer-readable storage medium is provided, wherein the storage medium stores at least one instruction, and the instruction is loaded and executed by a processor to enable a computer to implement the method in the above-mentioned first aspect or any possible implementation of the first aspect.

[0030] In a sixth aspect, a computer program (product) is provided, the computer program (product) comprising: a computer program code, when the computer program code is executed by a computer, the computer executes the methods in the above aspects.

[0031] In a seventh aspect, a chip is provided, comprising a processor for calling and executing instructions stored in a memory from the memory, so that a communication device equipped with the chip executes the methods in the above aspects.

[0032] In an eighth aspect, another chip is provided, comprising: an input interface, an output interface, a processor and a memory, wherein the input interface, the output interface, the processor and the memory are connected via an internal connection path, and the processor is used to execute the code in the memory. When the code is executed, the processor is used to execute the methods in the above aspects.

[0033] It should be understood that the beneficial effects achieved by the technical solutions of the second to eighth aspects of the present application and the corresponding possible implementation methods can be referred to the technical effects of the first aspect and its corresponding possible implementation methods mentioned above, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS

[0034] Figure 1 A connection diagram of an FTTR network provided in an embodiment of the present application;

[0035] Figure 2 A schematic diagram of a FTTR networking cascade firewall device provided in an embodiment of the present application;

[0036] Figure 3 A schematic diagram of a FTTR networking cascaded bypass firewall device provided in an embodiment of the present application;

[0037] Figure 4 A schematic diagram of an implementation environment of a message forwarding processing method provided in an embodiment of the present application;

[0038] Figure 5 A flowchart of a message forwarding processing method provided in an embodiment of the present application;

[0039] Figure 6 A schematic diagram of a FTTR networking cascaded bypass firewall device provided in an embodiment of the present application;

[0040] Figure 7 A flowchart of a message forwarding processing method provided in an embodiment of the present application;

[0041] Figure 8 A schematic diagram of another FTTR networking cascaded bypass firewall device provided in an embodiment of the present application;

[0042] Fig. 9 A flowchart of another message forwarding processing method provided in an embodiment of the present application;

[0043] Fig.10 A schematic diagram of the network architecture of an FTTR network provided in an embodiment of the present application;

[0044] Fig.11 A schematic diagram of the structure of a message forwarding processing device provided in an embodiment of the present application;

[0045] Fig.12 A schematic diagram of the structure of a network device provided in an embodiment of the present application;

[0046] Fig.13 A schematic diagram of the structure of another network device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0047] In order to make the objectives, technical solutions and advantages of the present application clearer, the implementation methods of the present application will be further described in detail below with reference to the accompanying drawings.

[0048] With the development of communication technology, most users have accessed the network through optical fiber. The continuous improvement of optical fiber access and network infrastructure has provided a solid information foundation for the prosperity of Internet services. The application types of Internet services are endless, such as ultra-high-definition video, cloud virtual reality (VR), cloud games, online education, remote office, etc., which have put forward higher and higher requirements on network bandwidth, latency, jitter, etc. Therefore, it is possible to provide users with a better Internet experience by increasing bandwidth.

[0049] In the scenario of continuously improving bandwidth, the access rate of the access device used by the user to access the network is insufficient, or the wireless signal in the room is weak due to reasons such as wall penetration, so that the Internet speed that the user can finally perceive is limited; or the carrying capacity of the network cable is low due to reasons such as cable splitting or unqualified network cables. Cable splitting refers to dividing the network cable into two groups for data transmission; or because the network port of the access device connected to the optical transmission network (OTN) is a 100M Ethernet port, the negotiated rate of the user's access to the network is constrained. Then FTTR networking was proposed to ensure stable large bandwidth coverage of the entire room and realize on-demand connection.

[0050] In FTTR networking, the master ONU is the core, the master ONU is connected to the OLT upward, and is connected to multiple slave ONUs downward through a splitter or optical socket, and each slave ONU is connected to at least one user terminal downward. Among them, the slave ONU supports Gigabit Ethernet port and dual-band wireless signal, and each slave ONU enters each room with optical fiber, providing wired or wireless Gigabit network coverage for each room. Optionally, ONU can also be called optical network terminal (ONT). User terminals can include terminals such as computers, cameras, and voice phones.

[0051] For example, see Figure 1 , Figure 1 A connection diagram of an FTTR network provided for an embodiment of the present application. The master ONU is located between the OLT and the slave ONU, connected to the OLT through a PON interface upward, supports gigabit access to homes, and provides a PON interface downward to connect to the slave ONU. The PON interface can be a 10-Gigabit passive optical network (10-Gigabit-capable passive optical network, XGPON) interface or a 10G Ethernet passive optical network (10Gbit / s ethernet passive optical network, 10G-EPON) interface. Multiple slave ONUs are distributed in different rooms, connected to the master ONU upward through optical cables or optoelectronic composite cables, and provide wireless interfaces and gigabit Ethernet interfaces (GE) downward to access various home Internet terminals, thereby realizing on-demand access to Internet terminals. Among them, the slave ONU works in the bridging mode, and the master ONU uniformly allocates and manages the Internet Protocol (IP) address of the slave ONU and the IP address of the user terminal connected to the slave ONU, so that the FTTR network constitutes a unified and interoperable LAN. The user terminals connected to the slave ONU can realize LAN mutual access operations such as screen projection and file sharing under ultra-gigabit bandwidth.

[0052] In order to improve the security of FTTR networking, it is necessary to deploy firewall devices independently. For example, in the scenario where an enterprise deploys FTTR networking, since the enterprise has higher requirements for security, the firewall capabilities of the main ONU cannot support the enterprise's security requirements. Therefore, it is necessary to deploy independent firewall devices. Since the main ONU is connected to the OLT through the PON interface, the network cable interface of the firewall device is usually not a PON interface. For example, the network cable interface of the firewall device is a LAN interface or a WAN interface. If an independent firewall device is cascaded between the OLT and the main ONU, refer to Figure 2 The schematic diagram of the cascaded firewall device shown in the figure requires modifying the PON interface of the main ONU to a LAN interface or a WAN interface, which causes the main ONU to be unable to exert the capabilities of the PON interface, and requires an additional cascaded gateway device to connect the PON interface upstream to the OLT, resulting in additional overhead.

[0053] Therefore, in the FTTR networking scenario, the firewall device can be cascaded and hung on the main ONU through two LAN interfaces, and all traffic accessing the external network through the PON interface in the FTTR network is introduced to the firewall device through the LAN interface, and the firewall device audits the user's Internet behavior. For example, see Figure 3 The schematic diagram of the cascaded bypass firewall device is shown, the master ONU is connected to the OLT through the PON2 interface, and is connected to the slave ONU through the PON1 interface, and the bypass firewall device is cascaded through the LAN2 interface and the LAN1 interface.

[0054] Exemplarily, the master ONU receives a message sent from the slave ONU through the PON1 interface. In a gigabit-capable PON (GPON), the message is encapsulated in a GPON encapsulation mode (GEM) frame. The frame header of the GEM frame carries GEM port information. The GEM port is a virtual port used to carry services in the GPON. One GEM port corresponds to one port identification (ID). The GEM port information can indicate the port of the slave ONU. After the master ONU is cascaded to the firewall device, the master ONU needs to encapsulate the received message into an Ethernet frame and forward it to the LAN1 interface connected to the firewall device based on the bridge forwarding method of the virtual local area network (VLAN) information and MAC information, and send the message to the firewall device through the LAN1 interface, and then forward the message to the master ONU again via the firewall device. Among them, bridging forwarding is used to connect two different LANs, reassemble the messages received from one LAN according to the format of another LAN, and send them to the physical layer of another LAN.

[0055] In this case, the master ONU receives the message sent by the firewall device again through the LAN2 interface connected to the firewall device, sends it to the PON2 interface through bridge forwarding or three-layer network address translation (NAT) forwarding, and sends the message to the OLT through the PON2 interface. Since the message received through the LAN2 interface is encapsulated in an Ethernet frame, the frame header of the Ethernet frame does not include GEM port information, so that the message loses the original GEM port information after being forwarded by the firewall device, resulting in the master ONU being unable to determine whether the message is sent from the port of the ONU, and further resulting in related services based on the port configuration of the slave ONU being affected, for example, the message cannot be processed according to the processing strategy based on the port configuration of the slave ONU.

[0056] The embodiment of the present application provides a message forwarding processing method, which encapsulates a port label and a tunnel header for a message forwarded via a firewall device. Since the port label is used to indicate the port of a slave ONU, the effect of recording the port of the slave ONU is achieved through the port label. Since the tunnel header is used to instruct the firewall device to send a second message to a master ONU, the port information of the slave ONU does not need to be parsed during the forwarding process based on the tunnel header, and the port information of the slave ONU can be protected from being lost during the forwarding process. When the message sent by the slave ONU and received by the master ONU returns to the master ONU after being forwarded via the firewall device, the port information of the slave ONU will not be lost, and the message can be processed based on the processing strategy configured for the port of the slave ONU.

[0057] For example, see Figure 4 , Figure 4 A schematic diagram of an implementation environment for a message forwarding processing method provided in an embodiment of the present application. The implementation environment includes OLT, FTTR networking and firewall equipment. The FTTR networking includes a master ONU and multiple slave ONUs, and the master ONU and the multiple slave ONUs are connected through optical sockets. Among them, the master ONU can be a master gateway or a master optical modem, the slave ONU can be a slave gateway or a slave optical modem, and the slave ONU can also be an access point (AP) device. The number of slave ONUs is not limited in the embodiments of the present application, Figure 4 Two slave ONUs are used as an example, and the number of slave ONUs can be less or more. Each slave ONU serves as a wireless access point and can connect to terminals used by multiple users. The OLT and FTTR network are connected through the PON interface, and the firewall device is cascaded and hung on the master ONU through the LAN interface. The FTTR network and the firewall device belong to two different local area networks and need to be bridged and forwarded.

[0058] See also Figure 5 , Figure 5 A flowchart of a message forwarding processing method provided in an embodiment of the present application. The method can be applied to Figure 4 In the implementation environment shown, for example, Figure 4 The main ONU of the cascaded bypass firewall device is executed as shown. Figure 5 As shown, the message forwarding processing method includes the following steps 501 to 504.

[0059] Step 501: Receive a first message sent from an ONU.

[0060] In the embodiment of the present application, the master ONU includes a first PON interface, and the master ONU is downwardly connected to the slave ONU through the first PON interface, so the first message sent by the slave ONU can be received through the first PON interface. Optionally, the type of the first message is not limited in the embodiment of the present application, for example, the first message can be a dial-up request message, an external network access message, or a service data message of a user terminal connected to the slave ONU by wire or wirelessly.

[0061] Step 502, when traffic is directly passed between the slave ONU and the firewall device, a second message is sent to the firewall device. The second message is obtained by adding a port tag and a first tunnel header to the first message. The port tag indicates the port of the slave ONU, and the first tunnel header indicates that the firewall device sends the second message to the master ONU.

[0062] Direct traffic between the slave ONU and the firewall device means that the next hop of the traffic from the slave ONU is directly determined to be the firewall device. In the embodiment of the present application, the received message sent by the slave ONU is sent to the firewall device after adding the port tag and the first tunnel header. Exemplarily, the master ONU also includes a first LAN interface and a second LAN interface, and the first LAN interface and the second LAN interface are connected to the firewall device, so that the master ONU is cascaded and the firewall device is hung sideways. Among them, the first PON interface of the master ONU is directly connected to the second LAN interface, so that the traffic between the slave ONU and the firewall device is directly connected. The traffic between the slave ONU and the firewall device is not directly connected, which means that for the traffic from the slave ONU, the next hop of the message needs to be determined according to the forwarding strategy, for example, the next hop is determined by the routing table. Among them, the next hop of the message determined according to the forwarding strategy does not include the firewall device.

[0063] See also Figure 6 In the schematic diagram of the cascaded bypass firewall device shown, the downstream PON interface on the main ONU is directly connected to the LAN2 interface, so that the traffic between the slave ONU and the firewall device is directly connected. Among them, the downstream PON interface corresponds to the first PON interface in the embodiment of the present application, the LAN1 interface corresponds to the second LAN interface in the embodiment of the present application, and the LAN2 interface corresponds to the second LAN interface in the embodiment of the present application. In this scenario, all messages received through the first PON interface will be sent to the firewall device through the first LAN interface, and will be forwarded after being processed by the firewall device, which can improve the security of the messages received through the first PON interface forwarded by the main ONU. The main ONU needs to encapsulate the port label and the first tunnel header of the first message to obtain the second message, and then send the second message to the firewall device through the first LAN interface.

[0064] In an embodiment of the present application, the first message sent by the slave ONU and received by the master ONU carries information indicating the port of the slave ONU. For example, the first message carries the GEM port information of the slave ONU, and the GEM port information can indicate the port of the slave ONU. The embodiment of the present application does not limit the setting method of the port label, and the port label can be used to distinguish the ports of different slave ONUs. For example, the port label of the slave ONU can be a private label (Tag) or a VLANTag corresponding to the port of the slave ONU.

[0065] Optionally, the encapsulation type of the first tunnel header is not limited in the embodiment of the present application, and the first tunnel header under different tunnel protocols can be flexibly adopted for encapsulation according to the application scenario. Exemplarily, the first tunnel header includes routing information, so that the message encapsulating the outermost first tunnel header can be transmitted in the network equipped with the tunnel. Tunnel protocols include but are not limited to QinQ protocol, virtual private network (VPN) protocol, point-to-point tunneling protocol (PPTP) or layer 2 tunneling protocol (L2TP), etc. QinQ is the abbreviation of 802.1Q-in-802.1Q, QinQ is also called virtual local area network stacking (VLAN Stacking) or double VLAN, which achieves the purpose of expanding VLAN space by adding another layer of 802.1Q tag on the basis of 802.1Q tag message. Among them, the way of encapsulating the first tunnel header can flexibly adopt different tunnel protocol encapsulation methods for different tunnel protocols.

[0066] Taking the case where the port tag is a VLAN Tag and the first tunnel header is a QinQ VLAN as an example, the method of encapsulating the port tag and the first tunnel header of the first message can be to encapsulate a layer of VLAN Tag in the outer layer of the first message, and then encapsulate another layer of QinQ VLAN in the outer layer of the VLAN Tag, so as to realize the forwarding of the message through the firewall device through the QinQ VLAN encapsulated in the outermost layer. Therefore, by encapsulating the port tag, the information of the port from the ONU can be carried in the forwarded message, and by encapsulating the tunnel header, the message is routed and forwarded based on the outermost tunnel header, and the port tag in the inner layer of the tunnel header will not be parsed, so as to ensure that the port tag will not be lost during the forwarding process.

[0067] Step 503, receiving a second message that has been audited or filtered by a firewall device, obtaining a first message and a port tag based on the second message, and obtaining a first processing policy configured from the port of the ONU based on the port tag, the first processing policy including at least one of a service binding policy, a WAN binding policy, a VLAN binding policy, a port filtering policy, a priority policy, or a sending interface policy.

[0068] In an embodiment of the present application, the firewall device performs audit processing or filtering processing on the received second message. Audit processing may refer to statistical analysis of the received second message; filtering processing may refer to filtering out messages that do not meet security conditions and no longer forwarding them, and forwarding messages that meet security conditions to the main ONU according to the first tunnel header encapsulated in the outermost layer. Among them, the security conditions can be flexibly set according to the application scenario. For example, the firewall device can perform anti-virus monitoring of user traffic and user security review behavior management through security conditions. In an embodiment of the present application, the first LAN interface of the main ONU, the second LAN interface, and the interface of the firewall device connected to the first LAN interface and the interface connected to the second LAN interface are all configured with the routing information indicated by the first tunnel header, so that the second message can be forwarded through the firewall based on the first tunnel header, and the message forwarding can be achieved through the tunnel header without relying on the routing capability of the bypassed firewall device.

[0069] Since the second message is obtained by encapsulating the port label and the first tunnel header of the first message, the first message and the port label can be obtained based on the second message. For example, the second message is decapsulated, the outermost first tunnel header is stripped off, and then the port label and the first message are obtained by parsing. Since the port label indicates the port of the slave ONU, before receiving the first message, the master ONU configures the corresponding first processing strategy based on the port of the slave ONU, and then the first processing strategy configured for the port of the slave ONU can be obtained based on the port label. The embodiment of the present application does not limit the content of the first processing strategy, and different processing strategies can be flexibly configured according to the business requirements of the application scenario.

[0070] Among them, the service binding strategy can be to bind the port of the slave ONU with the target service, so that the message forwarding method configured by the target service is applicable to the message sent from the port of the ONU; the WAN binding strategy can be to bind the port of the slave ONU with the target WAN, so that the message forwarding method configured by the target WAN is applicable to the message sent from the port of the ONU; the VLAN binding strategy can be to bind the port of the slave ONU with the target VAN, so that the message forwarding method configured by the target VAN is applicable to the message sent from the port of the ONU; the port filtering strategy can be a filtering condition, so that the message sent from the port of the ONU that meets the filtering condition can be forwarded, and the message that does not meet the filtering condition is not forwarded; the priority strategy can configure different forwarding priorities for different ports, so that the message sent by the high-priority port can be forwarded first; the sending interface strategy can specify different forwarding interfaces for different ports, so that the messages sent by different ports can be forwarded according to the specified interface.

[0071] Step 504: forward the first message according to the first processing strategy.

[0072] In the embodiment of the present application, since the first processing strategy configured for the port of the slave ONU can be obtained based on the port label, the first message sent through the port corresponding to the second LAN interface can still be processed according to the message sent through the port of the slave ONU, without affecting the use of the relevant configuration of the port of the slave ONU. Wherein, the master ONU receives the first message twice through the first PON interface and the second LAN interface. When the first message is received through the first PON interface, since the first message is sent from the port of the ONU, the information indicating the port of the slave ONU is received at the same time when the first message is received, that is, the port of the slave ONU is the original port for sending the first message; when the second message is received through the second LAN interface, although the first message is sent through the port corresponding to the second LAN interface, the port label encapsulated in the outer layer of the first message can determine that the original port of the first message is the port of the slave ONU, and then after the cascaded bypass firewall device, the processing strategy configured based on the port will not be affected.

[0073] Thus, the forwarding process of the first message from the ONU to the main ONU on the user side through the firewall device bypass processing is realized through the above process, and the first message can still be processed according to the first processing strategy through the port label. After the processed third message is obtained, normal routing forwarding can be performed based on the destination address of the third message. For different first processing strategies, the third message and the first message can be the same or different. In an embodiment of the present application, the main ONU also includes a second PON interface, and the second PON interface is connected to the slave ONU downward. Optionally, the method of forwarding the third message can be, based on the destination address of the third message, sending the third message to the OLT through the second PON interface.

[0074] See also Figure 7 , Figure 7 Based on Figure 6 The schematic diagram of the message forwarding process in the scenario of the cascaded bypass firewall device is shown. Among them, the process of bypass processing for the message received through the first PON interface on the user side is as follows: ① Based on the direct connection between the first PON interface and the first LAN interface, the master ONU directly encapsulates a layer of port label on the outer layer of the message, and then encapsulates a layer of tunnel header on the outer layer of the port label, and then sends it to the LAN interface of the firewall device through the first LAN interface. The firewall device processes and filters the received message, filters out the message that does not meet the security conditions and does not forward it, and forwards the message that meets the security conditions to the WAN interface according to the outermost encapsulated tunnel header, and forwards it to the second LAN interface of the master ONU through the WAN interface. After forwarding by the firewall device, ② After the master ONU receives the message through the second LAN interface, it strips off the outermost tunnel header through the forwarding module, obtains the information of the port of the slave ONU that originally sent the message according to the port label in the inner layer of the tunnel header, and then processes and forwards the message according to the processing strategy configured for the port of the slave ONU, without affecting the management function of the master ONU for the original port of the slave ONU. The master ONU further includes a processor, which is used to implement operations performed by the forwarding module. The forwarding module is a software virtual module used to perform related operations of forwarding messages from the master ONU.

[0075] In addition, for the first message received, the master ONU can also learn the source address information such as MAC carried by the first message to the corresponding port, which is used for routing and forwarding other messages received subsequently. However, after the master ONU is cascaded and the firewall device is hung in the side, because the same first message enters the master ONU once at the first PON interface, and enters the master ONU again at the second LAN interface after being forwarded by the firewall device, the MAC table entry of the same user may learn the port of the slave ONU connected to the first PON interface and the port of the firewall device connected to the second LAN interface at the same time, which leads to inaccurate routing query results based on the user's MAC table entry, making it impossible for the master ONU to perform normal user management. For example, the user topology of the slave ONU hung down displayed by the master ONU is inaccurate, and the user under the first PON interface may be displayed under the second LAN interface.

[0076] Therefore, in an embodiment of the present application, after obtaining the first message and the port label based on the second message, the correspondence between the source address information of the first message and the port of the slave ONU indicated by the port label can also be saved, and the source address information can include MAC information and ARP information. In this case, the method of determining that the destination port of the fourth message is the port of the slave ONU based on the destination address of the fourth message can be, based on the MAC information and ARP information indicated by the destination address of the fourth message, determining the destination port of the fourth message as the port of the slave ONU in the correspondence. In this case, the method of determining that the destination port of the fourth message is the port of the slave ONU based on the destination address of the fourth message is, that is, based on the destination address of the fourth message, the MAC information and ARP information and the correspondence, determining that the destination port of the fourth message is the port of the slave ONU.

[0077] That is to say, after the master ONU receives the first message sent by the slave ONU through the first PON interface, since the first PON interface is directly connected to the first LAN interface, the master ONU does not learn the source address information of the first message first, but after receiving the second message sent by the firewall device based on the first tunnel header through the second LAN interface, since the first message and the port label are obtained based on the second message, the master ONU learns the source address information of the first message to the port of the slave ONU indicated by the port label, that is, the corresponding relationship between the source address information of the first message and the port of the slave ONU indicated by the port label is saved. Although the master ONU receives the first message twice through the first PON interface and the second LAN interface, the source address information of the first message is only learned to the port of the slave ONU indicated by the port label, which does not lead to learning the source address information of the first message twice, nor does it mistakenly learn the source address information of the first message to the port corresponding to the second LAN interface, thereby improving the accuracy of obtaining the corresponding relationship based on the first message, and further improving the accuracy of determining the port based on the corresponding relationship.

[0078] In a possible implementation, when traffic between the slave ONU and the firewall device is not directly connected, the process of the master ONU forwarding and processing the first message is: based on the information of the port of the slave ONU, obtaining the first processing strategy configured for the port of the slave ONU, processing the first message based on the first processing strategy, and obtaining a processed third message; when the next hop of the third message indicates the OLT and traffic between the OLT and the firewall device is directly connected, sending the third message to the firewall device; receiving the third message that has been audited or filtered by the firewall device, and sending the third message to the OLT.

[0079] Exemplarily, after the main ONU receives the first message sent by the slave ONU through the first PON interface, when the first PON interface and the first LAN interface are not directly connected, the main ONU obtains the first processing strategy configured for the port of the slave ONU based on the information of the port of the slave ONU, processes the first message based on the first processing strategy, and obtains a third message; when the destination address of the third message indicates the second PON interface, and the second PON interface and the second LAN interface are directly connected, the second PON interface indicated by the destination address of the third message is converted to the first LAN interface, and the third message is sent to the firewall device through the first LAN interface; the third message sent by the firewall device is received through the second LAN interface, and the third message is sent to the OLT through the second PON interface.

[0080] Therefore, for the third message sent by the main ONU to the OLT, before being sent to the OLT through the second PON interface, it is processed by the firewall device and then forwarded to the second PON interface, thereby improving the security of the third message sent through the second PON interface, and the main ONU can be connected to the OLT through the PON interface, so that the main ONU can not only give play to the capabilities of the PON interface, but also filter the third message sent to the OLT through the LAN interface through the firewall device.

[0081] See also Figure 8 In the schematic diagram of the cascaded bypass firewall device shown, the downstream PON interface on the main ONU is not directly connected to the LAN2 interface, and is forwarded through the forwarding module in the middle, while the upstream PON interface on the main ONU is directly connected to the LAN1 interface, that is, the traffic between the OLT and the firewall device is directly connected. Among them, the upstream PON interface corresponds to the second PON interface in the embodiment of the present application, the downstream PON interface corresponds to the first PON interface in the embodiment of the present application, the LAN1 interface corresponds to the second LAN interface in the embodiment of the present application, and the LAN2 interface corresponds to the second LAN interface in the embodiment of the present application. In this scenario, the first message received through the first PON interface is first processed by the main ONU according to the originally configured processing strategy, and then forwarded through the outbound interface via the firewall device.

[0082] For example, in Fig. 9 In the message forwarding process shown, the process of bypassing the message received through the first PON interface on the user side is as follows: ① The main ONU determines through the forwarding module that the message needs to be sent through the second PON interface; ② The main ONU converts the message that needs to be sent through the second PON interface into a message that is sent through the first LAN interface, and then sends it to the LAN interface of the firewall, and after forwarding it to the second LAN interface via the firewall device, ③ The main ONU directly sends the message received through the second LAN interface to the OLT through the second PON interface. That is to say, the user-side message upstream to the OLT needs to be filtered by the firewall device before being forwarded by the main ONU to the upstream PON interface, and then sent to the OLT through the upstream PON interface.

[0083] In a possible implementation, in addition to the message from the user side to the OLT, the master ONU also receives a fourth message sent from the OLT to the user side, for example, the fourth message sent from the OLT to the user side is received through the second PON interface. Optionally, after the master ONU receives the fourth message sent from the OLT, in the case of direct traffic between the OLT and the firewall device, the master ONU sends the fourth message to the firewall device; receives the fourth message audited or filtered by the firewall device, and forwards the fourth message in the same manner as the fourth message sent from the OLT.

[0084] Direct traffic between the OLT and the firewall device means that the next hop of the traffic from the OLT is directly determined to be the firewall device. In the embodiment of the present application, the received message sent by the OLT is sent to the firewall device. Exemplarily, the second PON interface of the main ONU is directly connected to the first LAN interface, so that the traffic between the OLT and the firewall device is directly connected. The traffic between the OLT and the firewall device is not directly connected, which means that for the traffic from the OLT, the next hop of the message needs to be determined according to the forwarding strategy, for example, the next hop is determined by the routing table. Among them, the next hop of the message determined according to the forwarding strategy does not include the firewall device.

[0085] Exemplarily, the fourth message sent by the OLT is received through the second PON interface; when the second PON interface is directly connected to the second LAN interface, the fourth message is sent to the firewall device through the second LAN interface; the fourth message sent by the firewall device is received through the first LAN interface, and the first LAN interface receiving the fourth message is converted to the second PON interface; the fourth message is forwarded in the same manner as the fourth message is received from the second PON interface. In other words, the fourth message received through the second PON interface is first filtered and processed by the main ONU through the firewall device, and then processed according to the originally configured processing strategy and then forwarded through the output interface. The type of the fourth message is not limited in the embodiment of the present application. For example, the fourth message can be a service data message or a user configuration message sent by the OLT.

[0086] Thus, the fourth message sent by the OLT and received through the second PON interface can be forwarded after being processed by the firewall device, so as to improve the security of the fourth message forwarded by the main ONU. Moreover, after the fourth message enters the main ONU again through the firewall device, the main ONU can simulate the fourth message received through the first LAN interface as the fourth message received through the second PON interface, and then still process it according to the fourth message received through the second PON interface. In other words, the processing method of the fourth message sent by the OLT by the main ONU after the cascaded bypass firewall device is the same as the processing method of the fourth message sent by the OLT before the cascaded bypass firewall device is connected. The accuracy of the message forwarding processing will not be affected by the cascaded bypass firewall device, thereby improving the accuracy of the message forwarding processing.

[0087] See also Figure 8 In the schematic diagram of the cascaded bypass firewall device shown in the figure, after the upstream PON interface on the master ONU receives the message, since the upstream PON interface is directly connected to the LAN1 interface, it will be directly sent to the firewall device through the LAN1 interface. In this scenario, the message received through the upstream PON port is first filtered and processed by the bypass firewall device before entering the forwarding module, and then forwarded to the slave ONU on the user side through the forwarding module. As a result, the master ONU bypasses the traffic of the upstream PON interface by direct flow and disguised upstream PON interface, which does not affect the management function of the master ONU to the slave ONU hanging below, and can facilitate the firewall interception of the traffic of the upstream PON interface.

[0088] For example, in Fig. 9In the message forwarding process shown, the process of bypassing the message received through the second PON interface on the network side is as follows: ④ the main ONU sends the message received through the second PON interface directly to the firewall device through the second LAN interface through the direct flow, and then sends it to the WAN interface of the firewall, and then forwards it to the first LAN interface through the firewall device; ⑤ the main ONU converts the message received through the first LAN interface into the second PON interface to simulate the message entering from the upstream second PON interface; ⑥ the main ONU forwards the message received through the first LAN interface based on the message entering from the second PON interface through the forwarding module.

[0089] In a possible implementation, after the master ONU receives the fourth message sent by the OLT, when the traffic between the OLT and the firewall device is not directly connected, the destination port of the fourth message is determined to be the port of the slave ONU based on the destination address of the fourth message; when the next hop of the fourth message indicates the slave ONU and the traffic between the slave ONU and the firewall device is directly connected, a fifth message is sent to the firewall device, the fifth message is obtained by adding a port label and a second tunnel header to the fourth message, and the second tunnel header indicates the firewall device to send the fifth message to the master ONU; the fifth message that has been audited or filtered by the firewall device is received, the fourth message and the port label are obtained based on the fifth message, and the fourth message is sent to the slave ONU based on the port of the slave ONU indicated by the port label.

[0090] Exemplarily, when the second PON interface and the second LAN interface are not directly connected, the process of the master ONU forwarding and processing the fourth message is: based on the destination address of the fourth message, determine that the destination port of the fourth message is the port of the slave ONU; when the destination address of the fourth message indicates the first PON interface, and the first PON interface and the first LAN interface are directly connected, convert the first PON interface indicated by the destination address of the fourth message to the second LAN interface, and send a fifth message to the firewall device through the second LAN interface. The fifth message is obtained by encapsulating the fourth message with a port label and a second tunnel header, and the second tunnel header indicates the forwarding path of the fifth message through the firewall device; receive the fifth message sent by the firewall device based on the second tunnel header through the first LAN interface, and send the fifth message to the port of the slave ONU indicated by the port label through the first PON interface. The encapsulation method of the second tunnel header can refer to the encapsulation method of the first tunnel header, which will not be repeated here.

[0091] Therefore, the fourth message sent by the master ONU to the slave ONU is processed by the firewall device before being sent to the slave ONU through the first PON interface, and then forwarded to the first PON interface, thereby improving the security of the fourth message sent through the first PON interface. In addition, by encapsulating the port label and the second tunnel header of the fourth message to obtain the fifth message, the firewall device can perform routing forwarding of the fifth message based on the second tunnel header. After the firewall device forwards the fifth message to the first LAN interface of the master ONU, the master ONU can obtain the inner-layer encapsulated port label and the fourth message based on the fifth message, and determine that the fourth message is sent to the port of the slave ONU according to the port label, thereby improving the accuracy of message forwarding processing after the cascaded bypass firewall device is connected.

[0092] See also Figure 6 In the schematic diagram of the cascaded bypass firewall device shown, the upstream PON interface on the main ONU is not directly connected to the LAN1 interface, and is forwarded through the forwarding module in the middle, while the downstream PON interface on the main ONU is directly connected to the LAN2 interface. Among them, the upstream PON interface corresponds to the second PON interface in the embodiment of the present application. In this scenario, the message received through the upstream PON interface is first forwarded by the forwarding module, and then filtered and processed by the bypass firewall device, and forwarded to the slave ONU on the user side through the downstream PON interface. The main ONU gateway supports bypass device configuration, and bypasses the traffic of the upstream PON port by bidirectional direct flow and disguised upstream port. It does not affect the management function of the main FTTR for the original downstream AP. It is convenient to perform firewall interception on the external network export traffic of the upstream PON port. The solution has high forwarding performance, does not occupy CPU resources, and occupies less forwarding resources.

[0093] For example, in Figure 7 In the message forwarding process shown, the process of bypassing the message received through the second PON interface on the network side is as follows: ③ The master ONU determines the port of the slave ONU through the forwarding module, processes the message according to the processing strategy configured for the port of the slave ONU, encapsulates a layer of port label on the outer layer of the processed message, and then encapsulates a layer of tunnel header on the outer layer of the port label, and then sends it to the WAN interface of the firewall device through the second LAN interface. The firewall device processes and filters the received message, filters out the message that does not meet the security conditions and does not forward it, and forwards the message that meets the security conditions to the LAN interface according to the outermost encapsulated tunnel header, and bypasses the LAN interface to the first LAN interface of the master ONU. After forwarding by the firewall device, ④ After receiving the message through the first LAN interface, the master ONU strips off the outermost tunnel header, determines the port of the slave ONU according to the port label in the inner layer of the tunnel header, and since the first LAN interface is directly connected to the first PON interface, it is directly sent to the port of the slave ONU through the first PON interface.

[0094] In the method provided by the embodiment of the present application, the firewall device is cascaded and hung on the first LAN interface and the second LAN interface of the main ONU, so that the first message sent by the slave ONU received through the first PON interface can be forwarded after being processed by the firewall device, so as to improve the security of the first message forwarded by the main ONU. And by encapsulating the port label and the first tunnel header of the first message to obtain the second message, the firewall device can perform routing forwarding of the second message based on the first tunnel header. After the firewall device forwards the second message to the second LAN interface of the main ONU, the main ONU can obtain the inner encapsulated port label and the first message based on the second message, and determine that the port that originally sent the first message is the port of the slave ONU according to the port label, that is, the information of the original port of the first message will not be lost, so that the main ONU can still process the first message received by the second LAN interface based on the first processing strategy configured by the port of the slave ONU. That is to say, the way in which the master ONU processes the first message sent from the slave ONU after the cascaded bypass firewall device is connected is the same as the way in which the master ONU processes the first message sent from the slave ONU before the cascaded bypass firewall device is connected. The performance of message processing will not be affected by the cascaded bypass firewall device, thereby improving the accuracy of message forwarding processing.

[0095] Below, based on Fig.10 The network architecture shown in the figure is used to illustrate the message forwarding processing method provided in the embodiment of the present application. Fig.10 In the embodiment, the OLT is connected to the external network upwards and is connected to the master ONU downwards through an optical splitter, and the connection line between the OLT and the master ONU is an optical fiber. The master ONU is connected to multiple slave ONUs downwards through an optical socket, and the connection line between the master ONU and multiple slave ONUs is an optoelectronic composite cable. Optionally, the master ONU is also connected to the switch downwards through a network cable. The master ONU turns on the bypass mode, that is, the master ONU reserves the network side LAN2 interface and the user side LAN1 interface for bypassing the firewall device, for example, the network side LAN2 interface is connected to the network side LAN7 of the firewall device, and the user side LAN1 interface of the slave ONU is connected to the user side LAN6 of the firewall device. Fig.10 The method of cascading the main ONU and hanging the firewall device in the middle Figure 6Similarly, the main ONU is physically connected to the PON interface of the OLT, and logically all external network traffic, including the traffic sent by the OLT, needs to be processed by the firewall device before transmission. Taking the tunnel header as QinQ VLAN as an example, the LAN2 interface and LAN1 interface of the main ONU and the LAN6 interface and LAN7 interface of the firewall device are configured with the same QinQ VLAN, and the outermost tunnel header is encapsulated as the message by QinQ VLAN to achieve bridge transparent forwarding of the message, so that the message is forwarded through the firewall device without losing the port tag encapsulated in the inner layer of QinQ VLAN.

[0096] The processing and forwarding of messages during the user's Internet access process is taken as an example for detailed description, wherein the user terminal is an intranet terminal device, the intranet terminal device is hung under any slave ONU, and the user accesses the external network through the dynamic host configuration protocol (dynamic host configuration protocol, DHCP). Exemplarily, the intranet terminal device sends a DHCP dial-up request message to the slave ONU, and the slave ONU sends the DHCP dial-up request message to the master ONU through the upstream PON interface, and carries the GEM port information of the slave ONU. For example, the slave ONU encapsulates the DHCP dial-up request message into a GEM frame, the payload of the GEM frame includes the DHCP dial-up request message, the frame header of the GEM frame includes the GEM port information of the slave ONU, and the slave ONU sends the GEM frame to the master ONU through the upstream PON interface.

[0097] After the master ONU receives the DHCP dial-up request message and GEM port information sent by the slave ONU from the downstream PON interface, the GEM port information of the slave ONU can be converted into the port information of the slave ONU. In the case where the slave ONU is an AP device, the GEM port information of the slave ONU can be converted into the AP port information. The master ONU locally stores and manages the correspondence between the port information and the port label of the slave ONU. The port label can be a private VLAN Tag. The master ONU adds a layer of private VLAN Tag to the DHCP dial-up request message, and then adds a layer of Qinq VLAN. The addition corresponds to the above encapsulation. After receiving the DHCP dial-up request message encapsulated with the VLAN Tag and Qinq VLAN, the master ONU directly forwards it to the user-side LAN1 interface of the master ONU. The master ONU does not learn the MAC information and ARP information of the DHCP dial-up request message.

[0098] Since the user-side LAN1 port of the main ONU is directly connected to the user-side LAN6 interface of the firewall device, the DHCP dial-up request message sent to the user-side LAN1 interface of the main ONU is directly transmitted to the user-side LAN6 interface of the firewall device. After the firewall device receives the DHCP dial-up request message with Qinq VLAN encapsulated in the outer layer and VLAN Tag carried in the inner layer through the user-side LAN6 interface, since the user-side LAN6 interface and the network-side LAN7 interface are configured with the same Qinq VLAN, the firewall device performs Layer 2 bridging forwarding in the QinqVLAN layer and forwards the DHCP dial-up request message encapsulated with VLAN Tag and Qinq VLAN to the network-side LAN7 interface of the firewall device.

[0099] Since the network-side LAN7 interface of the firewall device is directly connected to the network-side LAN2 interface of the master ONU, the network-side LAN2 interface of the master ONU receives the DHCP dial-up request message encapsulated with the VLAN Tag and Qinq VLAN, and the master ONU first performs decapsulation processing, that is, strips off the Qinq VLAN layer tunnel header, recovers the port information of the slave ONU from the VLAN Tag, and forwards the DHCP dial-up request message according to the DHCP dial-up request message received from the recovered slave ONU port. For example, the MAC information and ARP information in the source address of the DHCP dial-up request message are learned to the corresponding slave ONU port, that is, the MAC information and ARP information of the user under the slave ONU port are obtained, and it will not be mistaken for the message sent by the network-side LAN2 interface and learned to the network-side LAN2 interface. Therefore, for the DHCP dial-up request message sent from the port of the slave ONU but forwarded by the firewall device, although it enters the main ONU twice, the main ONU only learns the MAC information and ARP information once, and learns it under the port of the slave ONU, ensuring that after the main ONU is hung on the firewall device, it will not affect the main ONU's topology management of users under the original port of the slave ONU.

[0100] After receiving the DHCP dial-up request message of the intranet terminal device sent by the slave ONU, the DHCP service (Server) module on the master ONU will respond to the DHCP dial-up request message, for example, assigning an Internet Protocol (IP) address to the intranet terminal device corresponding to the DHCP dial-up request message. The master ONU returns a DHCP dial-up reply message corresponding to the DHCP dial-up request message to the intranet terminal device. The DHCP dial-up reply message includes the assigned IP address, and adds a layer of VLAN Tag corresponding to the port of the slave ONU to the outer layer of the DHCP dial-up reply message, and then adds a layer of Qinq VLAN. The master ONU sends the DHCP dial-up reply message encapsulated with the VLAN Tag and QinqVLAN to the network side LAN7 interface of the firewall device through the network side LAN2 interface.

[0101] After the firewall device receives the DHCP dial-up reply message with Qinq VLAN encapsulated in the outer layer and VLANTag in the inner layer through the network-side LAN7 interface, it performs Layer 2 bridging forwarding based on Qinq VLAN, and sends the DHCP dial-up reply message encapsulated with VLAN Tag and Qinq VLAN to the user-side LAN6 interface. Since the user-side LAN6 interface of the firewall device is directly connected to the user-side LAN1 interface of the master ONU, the user-side LAN1 interface of the master ONU receives the DHCP dial-up reply message encapsulated with VLAN Tag and Qinq VLAN. The master ONU first performs decapsulation processing, that is, strips off the Qinq VLAN layer tunnel header, recovers the port information of the slave ONU from the VLAN Tag, and sends the DHCP dial-up reply message to the slave ONU through the downstream PON interface based on the port information of the slave ONU.

[0102] After receiving the DHCP dial-up reply message returned to the intranet terminal device from the ONU, the DHCP dial-up reply message is bridge-forwarded to the intranet terminal device based on the destination MAC address of the DHCP dial-up reply message. The intranet terminal device obtains the IP address assigned by the main ONU through DHCP, and then the intranet terminal device can access the external network based on the IP address.

[0103] In the process of intranet terminal devices accessing the external network, the forwarding process of the upstream traffic sent by the intranet terminal devices to the external network is similar to the forwarding process of the DHCP dial-up request message. The upstream traffic message is sent to the user-side LAN1 interface of the main ONU, forwarded by the user-side LAN6 interface and the network-side LAN7 interface of the firewall device, and then sent to the network-side LAN2 interface of the main ONU again. The main ONU forwards the upstream traffic message through the upstream PON interface of the main ONU to the OLT through the three-layer routing forwarding, and then accesses the external network through the OLT upstream.

[0104] After the downstream traffic from the external network to the intranet terminal device is forwarded by the OLT to the upstream PON interface of the main ONU, it is first forwarded at Layer 3 on the main ONU. Based on the correspondence between the port, MAC information, and ARP information of the slave ONU learned during the dial-up request, it can be found that the destination port corresponding to the downstream traffic message is the port of the slave ONU. Then, the forwarding process of the downstream traffic message by the main ONU is similar to the forwarding process of the DHCP dial-up reply message. The downstream traffic message will be forwarded to the firewall device through the network side LAN2 interface, forwarded by the network side LAN7 interface and the user side LAN6 interface of the firewall device, and then sent to the user side LAN1 interface of the main ONU again. Based on the port information of the ONU, the main ONU sends the downstream traffic message to the slave ONU through the downstream PON interface, and the slave ONU bridges and forwards it to the intranet terminal device.

[0105] The above describes the message forwarding processing method of the embodiment of the present application. Corresponding to the above method, the embodiment of the present application also provides a message forwarding processing device. Fig.11 1 is a schematic diagram of the structure of a message forwarding processing device provided in an embodiment of the present application, and the device is applied to a master ONU. Fig.11 As shown in the following multiple modules, the Fig.11 The message forwarding processing device shown can execute Figure 5 All or part of the operations performed by the master ONU shown. It should be understood that the device may include more additional modules than the modules shown or omit some of the modules shown, and the embodiments of the present application are not limited to this. Fig.11 As shown, the device comprises:

[0106] The transceiver module 1101 is used to execute Figure 5 Receiving and / or sending related operations performed by the master ONU in the method shown;

[0107] Processing module 1102, for executing Figure 5 Other operations besides the reception and / or transmission related operations performed by the master ONU in the method shown.

[0108] In a possible implementation, the transceiver module 1101 includes a receiving module and / or a sending module. The receiving module is used to perform reception-related operations, and the sending module is used to perform sending-related operations.

[0109] In one possible implementation, the transceiver module 1101 is used to receive a first message sent from the ONU; in the case where traffic is directly passed between the slave ONU and the firewall device, send a second message to the firewall device, the second message being obtained by adding a port tag and a first tunnel header to the first message, the port tag indicating the port of the slave ONU, and the first tunnel header indicating the firewall device to send the second message to the master ONU; receive the second message that has been audited or filtered by the firewall device; the processing module 1102 is used to obtain the first message and the port tag based on the second message, and obtain a first processing strategy configured for the port of the slave ONU based on the port tag, the first processing strategy including at least one of a service binding strategy, a WAN binding strategy, a VLAN binding strategy, a port filtering strategy, a priority strategy, or a sending interface strategy; and forward the first message according to the first processing strategy.

[0110] In a possible implementation, the first message carries information indicating a port of the slave ONU; the processing module 1102 is further used to obtain a first processing strategy configured for the port of the slave ONU based on the information of the port of the slave ONU when traffic between the slave ONU and the firewall device is not directly connected, and to process the first message based on the first processing strategy to obtain a processed third message; the transceiver module 1101 is further used to send a third message to the firewall device when the next hop of the third message indicates the OLT and traffic between the OLT and the firewall device is directly connected; receive the third message that has been audited or filtered by the firewall device, and send the third message to the OLT.

[0111] In a possible implementation, the transceiver module 1101 is further used to receive a fourth message sent by the OLT; send a fourth message to the firewall device when traffic is directly connected between the OLT and the firewall device; receive the fourth message that has been audited or filtered by the firewall device, and forward the fourth message in the same manner as the fourth message sent by the OLT is received.

[0112] In a possible implementation, the processing module 1102 is further used to determine, based on the destination address of the fourth message, that the destination port of the fourth message is the port of the slave ONU when the traffic between the OLT and the firewall device is not directly connected; the transceiver module 1101 is further used to send a fifth message to the firewall device when the next hop of the fourth message indicates the slave ONU and the traffic between the slave ONU and the firewall device is directly connected, the fifth message is obtained by adding a port tag and a second tunnel header to the fourth message, and the second tunnel header indicates that the firewall device sends the fifth message to the master ONU; receive the fifth message that has been audited or filtered by the firewall device, obtain the fourth message and the port tag based on the fifth message, and send the fourth message to the slave ONU based on the port of the slave ONU indicated by the port tag.

[0113] In a possible implementation, the processing module 1102 is also used to save the correspondence between the source address information of the first message and the port of the slave ONU indicated by the port label, the source address information including MAC information and ARP information; based on the MAC information and ARP information indicated by the destination address of the fourth message, the destination port of the fourth message is determined to be the port of the slave ONU in the correspondence.

[0114] It should be understood that the above Fig.11 When the device provided realizes its functions, only the division of the above-mentioned functional modules is used as an example. In actual applications, the above-mentioned functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. In addition, the device and method embodiments provided in the above embodiments belong to the same concept. The specific implementation process is detailed in the method embodiment and will not be repeated here. Fig.11 The beneficial effects of the provided device can be found in Figure 5 The beneficial effects of the method shown will not be described in detail here.

[0115] See also Fig.12 , Fig.12 A schematic diagram of the structure of a network device 2000 provided by an exemplary embodiment of the present application is shown. Fig.12 The network device 2000 shown is used to perform the above Figure 5 The network device 2000 is, for example, a switch, a router, etc. The network device 2000 can be implemented by a general bus architecture.

[0116] like Fig.12 As shown, the network device 2000 includes at least one processor 2001 , a memory 2003 , and at least one communication interface 2004 .

[0117] The processor 2001 is, for example, a general-purpose central processing unit (CPU), a digital signal processor (DSP), a network processor (NP), a graphics processing unit (GPU), a neural-network processing units (NPU), a data processing unit (DPU), a microprocessor, or one or more integrated circuits for implementing the solution of the present application. For example, the processor 2001 includes an application-specific integrated circuit (ASIC), a programmable logic device (PLD) or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. The PLD is, for example, a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof. It can implement or execute various logic blocks, modules, and circuits described in conjunction with the disclosure of the embodiments of the present invention. The processor can also be a combination that implements a computing function, such as a combination of one or more microprocessors, a combination of a DSP and a microprocessor, and the like.

[0118] Optionally, the network device 2000 further includes a bus. The bus is used to transmit information between the components of the network device 2000. The bus may be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus. The bus may be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Fig.12 The fact that only one line is used in the diagram does not mean that there is only one bus or only one type of bus.

[0119] The memory 2003 is, for example, a read-only memory (ROM) or other types of static storage devices that can store static information and instructions, or a random access memory (RAM) or other types of dynamic storage devices that can store information and instructions, or an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compressed optical disc, laser disc, optical disc, digital versatile disc, Blu-ray disc, etc.), a magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory 2003 is, for example, independent and connected to the processor 2001 via a bus. The memory 2003 can also be integrated with the processor 2001.

[0120] The communication interface 2004 uses any transceiver type device for communicating with other devices or communication networks, and the communication network can be Ethernet, radio access network (radio access network, RAN) or wireless local area network (wireless local area networks, WLAN) and the like. The communication interface 2004 can include a wired communication interface and can also include a wireless communication interface. Specifically, the communication interface 2004 can be an Ethernet interface, a Fast Ethernet (Fast Ethernet, FE) interface, a Gigabit Ethernet (Gigabit Ethernet, GE) interface, an Asynchronous Transfer Mode (Asynchronous Transfer Mode, ATM) interface, a wireless local area network (wireless local area networks, WLAN) interface, a cellular network communication interface or a combination thereof. The Ethernet interface can be an optical interface, an electrical interface or a combination thereof. In an embodiment of the present application, the communication interface 2004 can be used for the network device 2000 to communicate with other devices.

[0121] In a specific implementation, as an embodiment, the processor 2001 may include one or more CPUs, such as Fig.120 and CPU1 shown in FIG. Each of these processors may be a single-core CPU processor or a multi-core CPU processor. A processor herein may refer to one or more devices, circuits, and / or processing cores for processing data (e.g., computer program instructions).

[0122] In a specific implementation, as an embodiment, the network device 2000 may include multiple processors, such as Fig.12 2001 and 2005 are shown in FIG. Each of these processors may be a single-core CPU or a multi-core CPU. A processor herein may refer to one or more devices, circuits, and / or processing cores for processing data (such as computer program instructions).

[0123] In a specific implementation, as an embodiment, the network device 2000 may further include an output device and an input device. The output device communicates with the processor 2001 and may display information in a variety of ways. For example, the output device may be a liquid crystal display (LCD), a light emitting diode (LED) display device, a cathode ray tube (CRT) display device, or a projector. The input device communicates with the processor 2001 and may receive user input in a variety of ways. For example, the input device may be a mouse, a keyboard, a touch screen device, or a sensor device.

[0124] In some embodiments, the memory 2003 is used to store the program code 2010 for executing the solution of the present application, and the processor 2001 can execute the program code 2010 stored in the memory 2003. That is, the network device 2000 can implement the message forwarding processing method provided by the method embodiment through the processor 2001 and the program code 2010 in the memory 2003. The program code 2010 may include one or more software modules. Optionally, the processor 2001 itself can also store the program code or instruction for executing the solution of the present application.

[0125] In a specific embodiment, the network device 2000 of the embodiment of the present application may correspond to the master ONU in each of the above-mentioned method embodiments, and the processor 2001 in the network device 2000 reads the instruction in the memory 2003, so that Fig.12 The illustrated network device 2000 is capable of performing all or part of the operations performed by the master ONU.

[0126] Specifically, the processor 2001 is used to receive a first message sent from the ONU; in the case where traffic is directly passed between the slave ONU and the firewall device, send a second message to the firewall device, the second message is obtained by adding a port tag and a first tunnel header to the first message, the port tag indicates the port of the slave ONU, and the first tunnel header indicates the firewall device to send the second message to the master ONU; receive the second message that has been audited or filtered by the firewall device; obtain the first message and the port tag based on the second message, and obtain the first processing strategy configured for the port of the slave ONU based on the port tag, the first processing strategy including at least one of a service binding strategy, a WAN binding strategy, a VLAN binding strategy, a port filtering strategy, a priority strategy, or a sending interface strategy; and forward the first message according to the first processing strategy.

[0127] For the sake of brevity, other optional implementations are not described here in detail.

[0128] The network device 2000 may also correspond to the above Fig.11 In the packet forwarding processing device shown, each functional module in the packet forwarding processing device is implemented by software of the network device 2000. In other words, the functional modules included in the packet forwarding processing device are generated after the processor 2001 of the network device 2000 reads the program code 2010 stored in the memory 2003.

[0129] in, Figure 5 Each step of the forwarding processing method of the message shown is completed by the hardware integrated logic circuit or software instruction in the processor of the network device 2000. The steps of the method disclosed in conjunction with the embodiment of the present application can be directly embodied as a hardware processor, or a combination of hardware and software modules in the processor. The software module can be located in a mature storage medium in the field such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory or an electrically erasable programmable memory, a register, etc. The storage medium is located in the memory, and the processor reads the information in the memory, and completes the steps of the above method in conjunction with its hardware. To avoid repetition, it is not described in detail here.

[0130] See also Fig.13 , Fig.13 FIG. 2 shows a schematic diagram of the structure of a network device 2100 provided by another exemplary embodiment of the present application. Fig.13 The network device 2100 shown is used to perform the above Figure 5 All or part of the operations involved in the message forwarding processing method shown. The network device 2100 is, for example, a switch, a router, etc. The network device 2100 can be implemented by a general bus architecture.

[0131] like Fig.13As shown, the network device 2100 includes: a main control board 2110 and an interface board 2130 .

[0132] The main control board is also called a main processing unit (MPU) or a route processor card. The main control board 2110 is used to control and manage various components in the network device 2100, including routing calculation, device management, device maintenance, and protocol processing functions. The main control board 2110 includes: a central processing unit 2111 and a memory 2112.

[0133] The interface board 2130 is also called a line processing unit (LPU), a line card (linecard) or a service board. The interface board 2130 is used to provide various service interfaces and realize the forwarding of data packets. The service interface includes but is not limited to an Ethernet interface, a POS (Packet over SONET / SDH) interface, etc., and the Ethernet interface is, for example, a Flexible Ethernet Service Interface (Flexible Ethernet Clients, FlexE Clients). The interface board 2130 includes: a central processing unit 2131, a network processor 2132, a forwarding table entry memory 2134 and a physical interface card (physical interface card, PIC) 2133.

[0134] The central processor 2131 on the interface board 2130 is used to control and manage the interface board 2130 and communicate with the central processor 2111 on the main control board 2110 .

[0135] The network processor 2132 is used to implement the forwarding processing of the message. The network processor 2132 can be in the form of a forwarding chip. The forwarding chip can be a network processor (NP). In some embodiments, the forwarding chip can be implemented by an application-specific integrated circuit (ASIC) or a field programmable gate array (FPGA). Specifically, the network processor 2132 is used to forward the received message based on the forwarding table stored in the forwarding table entry memory 2134. If the destination address of the message is the address of the network device 2100, the message is sent to the CPU (such as the central processor 2131) for processing; if the destination address of the message is not the address of the network device 2100, the next hop and the output interface corresponding to the destination address are found from the forwarding table according to the destination address, and the message is forwarded to the output interface corresponding to the destination address. Among them, the processing of the uplink message may include: processing of the message input interface, forwarding table search; the processing of the downlink message may include: forwarding table search, etc. In some embodiments, the central processor can also perform the function of the forwarding chip, such as implementing software forwarding based on a general-purpose CPU, so that the forwarding chip is not required in the interface board.

[0136] The physical interface card 2133 is used to implement the physical layer docking function, whereby the original traffic enters the interface board 2130, and the processed message is sent out from the physical interface card 2133. The physical interface card 2133, also called a daughter card, can be installed on the interface board 2130, and is responsible for converting the photoelectric signal into a message and forwarding the message to the network processor 2132 for processing after checking the legitimacy of the message. In some embodiments, the central processor 2131 can also perform the functions of the network processor 2132, such as implementing software forwarding based on a general-purpose CPU, so that the network processor 2132 is not required in the physical interface card 2133.

[0137] Optionally, the network device 2100 includes multiple interface boards, for example, the network device 2100 further includes an interface board 2140, and the interface board 2140 includes: a central processor 2141, a network processor 2142, a forwarding table entry memory 2144, and a physical interface card 2143. The functions and implementation methods of the components in the interface board 2140 are the same or similar to those of the interface board 2130, and are not described in detail here.

[0138] Optionally, the network device 2100 further includes a switching fabric board 2120. The switching fabric board 2120 may also be referred to as a switch fabric unit (SFU). When the network device 2100 has multiple interface boards, the switching fabric board 2120 is used to complete data exchange between the interface boards. For example, the interface board 2130 and the interface board 2140 may communicate via the switching fabric board 2120.

[0139] The main control board 2110 is coupled to the interface board. For example, the main control board 2110, the interface board 2130, the interface board 2140, and the switching network board 2120 are connected to the system backplane through the system bus to achieve intercommunication. In a possible implementation, an inter-process communication (IPC) channel is established between the main control board 2110 and the interface board 2130 and the interface board 2140, and the main control board 2110 and the interface board 2130 and the interface board 2140 communicate through the IPC channel.

[0140] Logically, the network device 2100 includes a control plane and a forwarding plane. The control plane includes a main control board 2110 and a central processing unit 2111. The forwarding plane includes various components for performing forwarding, such as a forwarding table entry memory 2134, a physical interface card 2133, and a network processor 2132. The control plane performs functions such as a router, generating a forwarding table, processing signaling and protocol messages, and configuring and maintaining the status of the network device. The control plane sends the generated forwarding table to the forwarding plane. On the forwarding plane, the network processor 2132 forwards the message received by the physical interface card 2133 based on the forwarding table sent by the control plane. The forwarding table sent by the control plane can be stored in the forwarding table entry memory 2134. In some embodiments, the control plane and the forwarding plane can be completely separated and not on the same network device.

[0141] It is worth noting that there may be one or more main control boards, and when there are multiple boards, they may include a primary main control board and a backup main control board. There may be one or more interface boards. The stronger the data processing capability of the network device, the more interface boards are provided. There may also be one or more physical interface cards on the interface board. There may be no switching network board, or there may be one or more switching network boards. When there are multiple switching network boards, they can jointly realize load sharing and redundant backup. In a centralized forwarding architecture, network devices may not need switching network boards, and the interface board is responsible for processing the service data of the entire system. In a distributed forwarding architecture, network devices may have at least one switching network board, and data exchange between multiple interface boards is realized through the switching network board, providing large-capacity data exchange and processing capabilities. Therefore, the data access and processing capabilities of network devices with distributed architectures are greater than those of network devices with centralized architectures. Optionally, the network device may have only one board, that is, no switching board, and the functions of the interface board and the main control board are integrated on the board. In this case, the central processor on the interface board and the central processor on the main control board can be combined into one central processor on the board to perform the functions of the two. This type of network device has low data exchange and processing capabilities (for example, low-end switches or routers and other network devices). The specific architecture to be adopted depends on the specific networking deployment scenario, and no limitation is made here.

[0142] In a specific embodiment, the network device 2100 corresponds to the above Fig.11 The forwarding processing device for the message applied to the main ONU is shown. In some embodiments, Fig.11 The transceiver module 1101 in the message forwarding processing device shown is equivalent to the physical interface card 2133 in the network device 2100 , and the processing module 1102 is equivalent to the central processor 2111 or the network processor 2132 in the network device 2100 .

[0143] The embodiment of the present application also provides a message forwarding processing system, the message forwarding processing system includes a master ONU, a slave ONU and a firewall device, the master ONU is Fig.12 The network device 2000 or Fig.13 The network device 2100 shown in FIG. Fig.12 The network device 2000 or Fig.13 The network device 2100 shown is a firewall device. Fig.12 The network device 2000 or Fig.13 The network device 2100 shown in FIG. 2100. The message forwarding processing method executed by the master ONU, the slave ONU and the firewall device can be referred to in the above Figure 5 The relevant description of the illustrated embodiment will not be repeated here.

[0144] It should be understood that the processor may be a CPU, or other general-purpose processors, digital signal processors (DSP), application specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor, etc. It is worth noting that the processor may be a processor supporting the advanced reduced instruction set machine (ARM) architecture.

[0145] Further, in an optional embodiment, the memory may include a read-only memory and a random access memory, and provide instructions and data to the processor. The memory may also include a non-volatile random access memory. For example, the memory may also store information about the device type.

[0146] The memory may be a volatile memory or a nonvolatile memory, or may include both volatile and nonvolatile memory. Among them, the nonvolatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of RAM are available. For example, static RAM (SRAM), dynamic random access memory (DRAM), synchronous DRAM (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link DRAM (SLDRAM) and direct memory bus random access memory (DR RAM).

[0147] An embodiment of the present application also provides a computer-readable storage medium, in which at least one instruction is stored. The instruction is loaded and executed by a processor so that a computer implements any of the above message forwarding processing methods.

[0148] The embodiments of the present application also provide a computer program (product), which, when executed by a computer, can enable a processor or a computer to execute the corresponding steps and / or processes in the above method embodiments.

[0149] An embodiment of the present application also provides a chip, including a processor, for calling and executing instructions stored in the memory from the memory, so that a communication device equipped with the chip executes any of the above message forwarding processing methods.

[0150] An embodiment of the present application also provides another chip, including: an input interface, an output interface, a processor and a memory, wherein the input interface, the output interface, the processor and the memory are connected via an internal connection path, and the processor is used to execute the code in the memory. When the code is executed, the processor is used to execute any of the above message forwarding processing methods.

[0151] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on the computer, the process or function according to the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from a website site, a computer, a server or a data center by wired (e.g., coaxial cable, optical fiber, digital subscriber line) or wireless (e.g., infrared, wireless, microwave, etc.) mode to another website site, computer, server or data center. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or a data center that includes one or more available media integration. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid state drive (solid state disk)), etc.

[0152] Those of ordinary skill in the art will appreciate that, in conjunction with the various method steps and modules described in the embodiments disclosed herein, they can be implemented in software, hardware, firmware, or any combination thereof. In order to clearly illustrate the interchangeability of hardware and software, the steps and components of each embodiment have been generally described in terms of function in the above description. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Those of ordinary skill in the art may use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.

[0153] A person skilled in the art will understand that all or part of the steps to implement the above embodiments may be accomplished by hardware or by instructing related hardware through a program, and the program may be stored in a computer-readable storage medium, and the above-mentioned storage medium may be a read-only memory, a disk or an optical disk, etc.

[0154] When software is used for implementation, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer program instructions. As an example, the method of the embodiment of the present application can be described in the context of a machine executable instruction, and the machine executable instruction is such as included in the program module executed in the device on the real or virtual processor of the target. Generally speaking, a program module includes a routine, a program, a library, an object, a class, a component, a data structure, etc., which performs a specific task or realizes a specific abstract data structure. In various embodiments, the function of the program module can be merged or divided between the described program modules. The machine executable instruction for the program module can be executed in a local or distributed device. In a distributed device, the program module can be located in both a local and a remote storage medium.

[0155] The computer program code for realizing the method for the embodiment of the present application can be written in one or more programming languages. These computer program codes can be provided to the processor of a general-purpose computer, a special-purpose computer or other programmable data processing device, so that the program code, when executed by a computer or other programmable data processing device, causes the function / operation specified in the flow chart and / or block diagram to be implemented. The program code can be executed completely on a computer, partially on a computer, as an independent software package, partially on a computer and partially on a remote computer or completely on a remote computer or server.

[0156] In the context of the embodiments of the present application, computer program codes or related data may be carried by any appropriate carrier to enable a device, apparatus or processor to perform the various processes and operations described above. Examples of carriers include signals, computer readable media, and the like.

[0157] Examples of signals may include electrical, optical, radio, acoustic or other forms of propagated signals, such as carrier waves, infrared signals, etc.

[0158] A machine-readable medium may be any tangible medium that contains or stores a program for or related to an instruction execution system, apparatus, or device. A machine-readable medium may be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium may include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination thereof. More detailed examples of machine-readable storage media include an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical storage device, a magnetic storage device, or any suitable combination thereof.

[0159] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and modules described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0160] In the several embodiments provided in the present application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are only schematic. For example, the division of the module is only a logical function division. There may be other division methods in actual implementation, such as multiple modules or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interfaces, devices or modules, or it can be an electrical, mechanical or other form of connection.

[0161] The modules described as separate components may or may not be physically separated, and the components displayed as modules may or may not be physical modules, that is, they may be located in one place or distributed on multiple network modules. Some or all of the modules may be selected according to actual needs to achieve the purpose of the embodiments of the present application.

[0162] In addition, each functional module in each embodiment of the present application can be integrated into one processing module, or each module can exist physically separately, or two or more modules can be integrated into one module. The above integrated modules can be implemented in the form of hardware or software functional modules.

[0163] If the integrated module is implemented in the form of a software function module and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method in each embodiment of the present application. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM), random access memory (RAM), disk or optical disk and other media that can store program code.

[0164] In the present application, the terms "first", "second", etc. are used to distinguish between identical or similar items having substantially the same effects and functions. It should be understood that there is no logical or temporal dependency between "first", "second", and "nth", nor is there a limitation on quantity and execution order. It should also be understood that although the following description uses the terms first, second, etc. to describe various elements, these elements should not be limited by the terms. These terms are only used to distinguish one element from another. For example, without departing from the scope of various examples, a first image may be referred to as a second image, and similarly, a second image may be referred to as a first image. Both the first image and the second image may be images, and in some cases, may be separate and different images.

[0165] It should also be understood that in the various embodiments of the present application, the size of the serial number of each process does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.

[0166] The term "at least one" in this application means one or more, and the term "multiple" in this application means two or more, for example, multiple second messages means two or more second messages. The terms "system" and "network" are often used interchangeably herein.

[0167] It should be understood that the terms used in the description of the various examples herein are only for describing specific examples and are not intended to be limiting. As used in the description of the various examples and the appended claims, the singular forms "a", "an", and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise.

[0168] It should also be understood that the term "and / or" used herein refers to and encompasses any and all possible combinations of one or more of the associated listed items. The term "and / or" is a description of the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone. In addition, the character " / " in this application generally indicates that the associated objects before and after are in an "or" relationship.

[0169] It should also be understood that the term “comprise” (also known as “includes,” “including,” “comprises” and / or “comprising”) when used in this specification specifies the presence of stated features, integers, steps, operations, elements, and / or components, but does not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof.

[0170] It should also be understood that the terms "if" and "if" may be interpreted to mean "when" or "upon" or "in response to determining" or "in response to detecting." Similarly, the phrases "if it is determined that ..." or "if [a stated condition or event] is detected" may be interpreted to mean "upon determining that ..." or "in response to determining that ..." or "upon detecting [a stated condition or event]" or "in response to detecting [a stated condition or event]," depending on the context.

[0171] It should be understood that determining B based on A does not mean determining B only based on A. B can also be determined based on A and / or other information.

[0172] It should also be understood that the references to "one embodiment", "an embodiment", or "a possible implementation" throughout the specification mean that specific features, structures, or characteristics related to the embodiment or implementation are included in at least one embodiment of the present application. Therefore, the references to "in one embodiment" or "in an embodiment", or "a possible implementation" throughout the specification do not necessarily refer to the same embodiment. In addition, these specific features, structures, or characteristics may be combined in any suitable manner in one or more embodiments.

[0173] The above description is only an optional embodiment of the present application and is not intended to limit the present application. Any modifications, equivalent substitutions, improvements, etc. made within the principles of the present application should be included in the protection scope of the present application.

Claims

1. A message forwarding processing method, characterized in that: The method is applied to a main optical network unit (ONU), and the method comprises: Receiving a first message sent from the ONU; In the case where traffic is directly connected between the slave ONU and the firewall device, a second message is sent to the firewall device, where the second message is obtained by adding a port tag and a first tunnel header to the first message, the port tag indicates a port of the slave ONU, and the first tunnel header indicates that the firewall device sends the second message to the master ONU; Receiving the second message that has been audited or filtered by the firewall device, acquiring the first message and the port tag based on the second message, and acquiring the first processing strategy configured for the port of the slave ONU based on the port tag, wherein the first processing strategy includes at least one of a service binding strategy, a wide area network WAN binding strategy, a local area network VLAN binding strategy, a port filtering strategy, a priority strategy, or a sending interface strategy; The first message is processed and forwarded according to the first processing strategy.

2. The method according to claim 1, characterized in that The first message carries information indicating the port of the slave ONU; after receiving the first message sent by the slave ONU, the method further includes: In the case where traffic between the slave ONU and the firewall device is not directly connected, obtaining the first processing strategy configured for the port of the slave ONU based on information of the port of the slave ONU, and processing the first message based on the first processing strategy to obtain a processed third message; When the next hop of the third message indicates an optical line terminal OLT and traffic between the OLT and the firewall device is directly connected, sending the third message to the firewall device; The third message that has been audited or filtered by the firewall device is received, and the third message is sent to the OLT.

3. The method according to claim 1 or 2, characterized in that: The method further comprises: receiving a fourth message sent by the optical line terminal OLT; In the case where traffic is directly connected between the OLT and the firewall device, sending the fourth message to the firewall device; The fourth message that has been audited or filtered by the firewall device is received, and the fourth message is forwarded in the same manner as the fourth message sent by the OLT is received.

4. The method according to claim 3, characterized in that After receiving the fourth message sent by the optical line terminal OLT, the method further includes: In the case that traffic between the OLT and the firewall device is not directly connected, determining the destination port of the fourth message as the port of the slave ONU based on the destination address of the fourth message; When the next hop of the fourth message indicates the slave ONU and traffic between the slave ONU and the firewall device is directly connected, send a fifth message to the firewall device, wherein the fifth message is obtained by adding the port tag and the second tunnel header to the fourth message, and the second tunnel header instructs the firewall device to send the fifth message to the master ONU; Receive the fifth message that has been audited or filtered by the firewall device, obtain the fourth message and the port tag based on the fifth message, and send the fourth message to the slave ONU based on the port of the slave ONU indicated by the port tag.

5. The method according to claim 4, characterized in that After acquiring the first message and the port tag based on the second message, the method further includes: Saving the correspondence between the source address information of the first message and the port of the slave ONU indicated by the port label, wherein the source address information includes media access control MAC information and address resolution protocol ARP information; The determining, based on the destination address of the fourth message, that the destination port of the fourth message is the port of the slave ONU includes: Based on the destination address of the fourth message indicating the MAC information and the ARP information, the destination port of the fourth message is determined to be the port of the slave ONU in the corresponding relationship.

6. A message forwarding processing device, characterized in that: The method is applied to a main optical network unit (ONU), and the device comprises: A transceiver module, used to perform operations related to receiving and / or sending in the method according to any one of claims 1 to 5; A processing module, used to perform other operations besides the operations related to receiving and / or sending in the method described in any one of claims 1 to 5.

7. A network device, characterized in that: The network device includes: a processor, the processor is coupled to a memory, the memory stores at least one program instruction or code, and the at least one program instruction or code is loaded and executed by the processor so that the network device implements the message forwarding processing method described in any one of claims 1-5.

8. A message forwarding processing system, characterized in that: The message forwarding processing system includes a master optical network unit (ONU), a slave ONU and a firewall device; the slave ONU is used to send a first message to the master ONU; the master ONU is used to execute the method described in any one of claims 1 to 5; the firewall device is used to receive a second message sent by the master ONU, the second message is obtained by adding a port label and a first tunnel header to the first message, and the firewall device is also used to send the second message to the master ONU after being audited or filtered by the firewall device.

9. A computer-readable storage medium, characterized in that: The computer storage medium stores at least one instruction, and the at least one instruction is loaded and executed by the processor so that the computer implements the message forwarding processing method as described in any one of claims 1 to 5.

10. A computer program product, characterized in that The computer program product includes: a computer program code, and the computer program code is loaded and executed by a computer to enable the computer to implement the message forwarding processing method described in any one of claims 1-5.

Citation Information

Patent Citations

  • Controllable multicast system under environment of passive optical network, and implementing method

    CN101094087A

  • Cascade ONT processing method, device and system

    CN115701138A

  • Firewall service insertion across secure fabric preserving security group tags end to end with dual homed firewall

    US20210075767A1

  • Power Saving For Multi-Wavelength Passive Optical Network (PON)

    US20230040541A1

Cited By

  • Message forwarding method and device, OLT equipment and storage medium

    CN121310002A

  • Message forwarding method and device, OLT device and storage medium

    CN121310002B

  • Adaptive firewall implementation method, device and equipment based on FTTR

    CN121603311A

  • A micro-segmentation control method, device and system based on an FTTR access layer

    CN122661632A

  • Packet forwarding and processing method, apparatus, device, system, and storage medium

    EP4787773A1