Message forwarding processing method, device, equipment, system and storage medium
By adding port labels and tunnel headers between the master ONU and the firewall device in FTTR networking, the problem that the master ONU could not recognize the port information of the slave ONU was solved, thus achieving security and accuracy in packet forwarding.
Patent Information
- Application Number
- CN202311490786.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-08
- Publication Date
- 2025-11-07
- Estimated Expiration
- 2043-11-08
AI Technical Summary
After deploying firewall devices in an FTTR network, the master ONU cannot accurately identify the port information of the slave ONU, causing the packet processing policy to fail and affecting network security and accuracy.
Add port labels and tunnel headers between the main ONU and the firewall device to ensure that the port information of the slave ONU is preserved during packet forwarding, and execute corresponding processing policies based on this information.
This improves the security and accuracy of packet forwarding, ensuring that the main ONU can still correctly process packets sent from the ONU even after a cascaded firewall device is connected, thus avoiding policy failure due to information loss.
Smart Images

Figure CN119966644B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of communication technology, and in particular to a message forwarding processing method and device, equipment, system and storage medium. BACKGROUND
[0002] With the development of communication technology, fiber to the room (FTTR) technology has been widely applied to the access network of a home or an enterprise. FTTR networking includes a master optical network unit (ONU), a slave ONU and an optical network. The master ONU is located between an optical line terminal (OLT) and the slave ONU, connects the OLT through a passive optical network (PON) interface upward, supports gigabit home access, and provides a PON interface to connect the slave ONU downward. The slave ONU is distributed to each room, connects the master ONU through an optical cable or an optical fiber cable upward, and accesses various home network terminals downward, so as to realize on-demand access of the network terminals in each room. Therefore, FTTR can also be referred to as fiber on-demand connection.
[0003] In order to improve the security of FTTR networking, a firewall device needs to be independently deployed. The firewall device can generate a protective barrier between the FTTR networking and an external network, so as to block unsafe network factors. Therefore, in the scenario of deploying the firewall device in FTTR networking, how to perform forwarding processing on a received message is a problem to be solved urgently. SUMMARY
[0004] The present application provides a message forwarding processing method, device, equipment, system and storage medium, which are used for performing forwarding processing on a received message in the scenario of deploying a firewall device in FTTR networking.
[0005] In a first aspect, a packet forwarding processing method is provided. Taking a master ONU as an example, the master ONU receives a first packet sent by a slave ONU; in a case where traffic is straight-through between the slave ONU and a firewall device, the master ONU sends a second packet to the firewall device, the second packet being obtained by adding a port tag and a first tunnel header to the first packet, the port tag indicating a port of the slave ONU, and the first tunnel header indicating that the firewall device sends the second packet to the master ONU; the master ONU receives the second packet that has been subjected to auditing processing or filtering processing by the firewall device, obtains the first packet and the port tag based on the second packet, obtains a first processing policy configured for the port of the slave ONU based on the port tag, and processes and forwards the first packet according to the first processing policy, the first processing policy including at least one of a service binding policy, a wide area network (LAN) binding policy, a local area network (LAN) binding policy, a port filtering policy, a priority policy, or a sending interface policy.
[0006] In the method, the first packet sent by the slave ONU can be processed via the firewall device before being forwarded, that is, the master ONU is cascaded with the firewall device, thereby improving the security of the first packet forwarded by the master ONU. Moreover, the second packet is obtained by encapsulating the port tag and the first tunnel header on the first packet, so that the firewall device can route and forward the second packet based on the first tunnel header. After the firewall device forwards the second packet to the master ONU, the master ONU can obtain the inner encapsulated port tag and the first packet based on the second packet, and determine the port of the slave ONU that originally sent the first packet according to the port tag, that is, the information of the original port of the first packet is not lost, so that the master ONU can still process the first packet received from the firewall device based on the first processing policy configured for the port of the slave ONU. That is, the master ONU processes the first packet sent by the slave ONU in the same way before and after the firewall device is cascaded, and the performance of packet processing is not affected by the cascaded firewall device, thereby improving the accuracy of packet forwarding processing.
[0007] In a possible implementation, the first packet carries information indicating the port of the slave ONU; after the master ONU receives the first packet sent by the slave ONU, in a case where traffic is not straight-through between the slave ONU and the firewall device, the master ONU obtains the first processing policy configured for the port of the slave ONU based on the information of the port of the slave ONU, processes the first packet based on the first processing policy, and obtains a third packet after processing; in a case where the next hop of the third packet indicates an OLT and traffic is straight-through between the OLT and the firewall device, the master ONU sends the third packet to the firewall device; the master ONU receives the third packet that has been subjected to auditing processing or filtering processing by the firewall device, and sends the third packet to the OLT.
[0008] For the third message sent by the master ONU to the OLT, the third message is processed by the firewall device before being sent to the OLT, thereby improving the security of the third message sent to the OLT.
[0009] In a possible implementation, the master ONU further receives a fourth message sent by the OLT; in the case that the traffic is straight-through between the OLT and the firewall device, the fourth message is sent to the firewall device; the fourth message processed by the firewall device through auditing or filtering is received, and the fourth message is forwarded in the manner of receiving the fourth message sent by the OLT.
[0010] In this way, the received fourth message sent by the OLT can be processed by the firewall device before being forwarded, thereby improving the security of the fourth message forwarded by the master ONU. Moreover, after the fourth message enters the master ONU again through the firewall device, the master ONU can simulate the received fourth message sent by the firewall device as the received fourth message sent by the OLT, and further process the fourth message in the manner of receiving the fourth message sent by the OLT. That is, the master ONU processes the fourth message sent by the OLT in the same manner before and after cascading the firewall device, and the accuracy of the message forwarding processing is not affected by the cascading of the firewall device, thereby improving the accuracy of the message forwarding processing.
[0011] In a possible implementation, after the master ONU receives the fourth message sent by the OLT, in the case that the traffic is not straight-through between the OLT and the firewall device, the destination port of the fourth message is determined to be the port of the slave ONU based on the destination address of the fourth message; in the case that the next hop of the fourth message indicates the slave ONU and the traffic is straight-through between the slave ONU and the firewall device, a fifth message is sent to the firewall device, the fifth message is obtained by adding a port tag and a second tunnel header to the fourth message, the second tunnel header indicates that the firewall device sends the fifth message to the master ONU; the fifth message processed by the firewall device through auditing or filtering is received, the fourth message and the port tag are obtained based on the fifth message, and the fourth message is sent to the slave ONU based on the port of the slave ONU indicated by the port tag.
[0012] The fourth message sent by the master ONU to the slave ONU is processed by the firewall device before being forwarded, thereby improving the security of the fourth message sent to the slave ONU. In addition, the fourth message is encapsulated with a port tag and a second tunnel header to obtain a fifth message, so that the firewall device can route and forward the fifth message based on the second tunnel header. After the firewall device forwards the fifth message to the master ONU, the master ONU can obtain the inner-encapsulated port tag and fourth message based on the fifth message, and determine that the fourth message is sent to the port of the slave ONU according to the port tag, thereby improving the accuracy of the message forwarding processing after the cascading of the firewall device.
[0013] In a possible implementation, after obtaining the first message and the port tag based on the second message, the correspondence between the source address information of the first message and the port of the slave ONU indicated by the port tag can be saved. The source address information can include media access control (MAC) information and address resolution protocol (ARP) information. In this case, the way of determining that the destination port of the fourth message is the port of the slave ONU based on the destination address of the fourth message can be as follows: determining that the destination port of the fourth message is the port of the slave ONU in the correspondence based on the MAC information and ARP information indicated by the destination address of the fourth message.
[0014] In this case, after receiving the first message sent by the slave ONU, the master ONU does not learn the source address information of the first message because of the traffic pass-through between the slave ONU and the firewall device. Instead, after receiving the second message sent by the firewall device based on the first tunnel header, the master ONU learns the source address information of the first message to the port of the slave ONU indicated by the port tag because the first message and the port tag are obtained based on the second message, and saves the correspondence between the source address information of the first message and the port of the slave ONU indicated by the port tag. As a result, although the master ONU receives the first message twice, the source address information of the first message is only learned to the port of the slave ONU indicated by the port tag, and the source address information of the first message is not learned twice or incorrectly learned to the port corresponding to the second LAN interface, thereby improving the accuracy of obtaining the correspondence based on the first message and the accuracy of determining the port based on the correspondence.
[0015] In a second aspect, a message forwarding processing apparatus is provided. The apparatus is applied to a master ONU and includes:
[0016] The transceiver module is configured to perform the receiving and / or sending operations in the first aspect or any possible implementation of the first aspect.
[0017] The processing module is configured to perform other operations in addition to the receiving and / or sending related operations in the first aspect or any possible implementation manner of the first aspect.
[0018] In a possible implementation manner, the transceiving module comprises a receiving module and / or a sending module. The receiving module is configured to perform receiving related operations, and the sending module is configured to perform sending related operations.
[0019] In a possible implementation manner, the transceiving module is configured to receive a first packet sent by the ONU, send a second packet to the firewall device in a case where traffic is straight-through between the ONU and the firewall device, the second packet being obtained by adding a port tag and a first tunnel header to the first packet, the port tag indicating a port of the ONU, and the first tunnel header indicating that the firewall device sends the second packet to the main ONU, receive the second packet that has been subjected to auditing processing or filtering processing by the firewall device, and the processing module is configured to obtain the first packet and the port tag based on the second packet, obtain a first processing policy configured for the port of the ONU based on the port tag, and process and forward the first packet according to the first processing policy, the first processing policy comprising at least one of a service binding policy, a WAN binding policy, a VLAN binding policy, a port filtering policy, a priority policy, or a sending interface policy.
[0020] In a possible implementation manner, the first packet carries information indicating the port of the ONU, the processing module is further configured to, in a case where traffic is not straight-through between the ONU and the firewall device, obtain the first processing policy configured for the port of the ONU based on the information indicating the port of the ONU, process the first packet based on the first processing policy to obtain a third packet processed, and the transceiving module is further configured to, in a case where a next hop of the third packet indicates the OLT and traffic is straight-through between the OLT and the firewall device, send the third packet to the firewall device, receive the third packet that has been subjected to auditing processing or filtering processing by the firewall device, and send the third packet to the OLT.
[0021] In a possible implementation manner, the transceiving module is further configured to receive a fourth packet sent by the OLT, send the fourth packet to the firewall device in a case where traffic is straight-through between the OLT and the firewall device, receive the fourth packet that has been subjected to auditing processing or filtering processing by the firewall device, and forward the fourth packet in a manner of receiving the fourth packet sent by the OLT.
[0022] In a possible implementation, the processing module is further configured to determine, in a case where traffic is not straight-through between the OLT and the firewall device, the destination port of the fourth message as the port of the slave ONU based on the destination address of the fourth message; and the transceiver module is further configured to, in a case where the next hop of the fourth message indicates the slave ONU and traffic is straight-through between the slave ONU and the firewall device, send a fifth message to the firewall device, the fifth message being obtained by adding a port tag and a second tunnel header to the fourth message, the second tunnel header indicating that the firewall device sends the fifth message to the master ONU; receive the fifth message that has been subjected to auditing processing or filtering processing by the firewall device, obtain the fourth message and the port tag based on the fifth message, and send the fourth message to the slave ONU based on the port of the slave ONU indicated by the port tag.
[0023] In a possible implementation, the processing module is further configured to save a correspondence between source address information of the first message and the port of the slave ONU indicated by the port tag, the source address information including MAC information and ARP information; and determine, in the correspondence, the destination port of the fourth message as the port of the slave ONU based on the destination address of the fourth message indicating the MAC information and the ARP information.
[0024] In a third aspect, a network device is provided, which includes a processor coupled with a memory, and the memory stores at least one program instruction or code, which is loaded and executed by the processor to enable the network device to implement the message forwarding processing method according to the first aspect or any of the first aspect.
[0025] Optionally, the processor is one or more, and the memory is one or more.
[0026] Optionally, the memory can be integrated with the processor, or the memory and the processor are separately arranged.
[0027] In the implementation process, the memory can be a non-transitory memory, for example, a read only memory (ROM), which can be integrated on the same chip with the processor, or arranged on different chips respectively, and the type of the memory and the arrangement manner of the memory and the processor are not limited in the present application.
[0028] In a fourth aspect, a packet forwarding processing system is provided, which includes a master ONU, a slave ONU, and a firewall device. The slave ONU is configured to send a first packet to the master ONU. The master ONU is configured to perform the method of the first aspect or any possible implementation of the first aspect. The firewall device is configured to receive a second packet sent by the master ONU, the second packet being obtained by encapsulating a port label and a first tunnel header on the first packet, and the firewall device is further configured to send the second packet, which is audited or filtered by the firewall device, to the master ONU.
[0029] In a fifth aspect, a computer readable storage medium is provided, which stores at least one instruction. The instruction is loaded and executed by a processor, so as to enable a computer to implement the method in the first aspect or any possible implementation of the first aspect.
[0030] In a sixth aspect, a computer program (product) is provided, which includes computer program code. When the computer program code is run on a computer, the computer program code enables the computer to perform the method in the aspects.
[0031] In a seventh aspect, a chip is provided, which includes a processor configured to call and run instructions stored in a memory, so as to enable a communication device in which the chip is installed to perform the method in the aspects.
[0032] In an eighth aspect, another chip is provided, which includes an input interface, an output interface, a processor, and a memory. The input interface, the output interface, the processor, and the memory are connected through internal connection paths. The processor is configured to execute code in the memory. When the code is executed, the processor is configured to perform the method in the aspects.
[0033] It should be understood that the beneficial effects achieved by the second aspect to the eighth aspect and the corresponding possible implementations of the present application can be referred to the technical effects of the first aspect and the corresponding possible implementations, which will not be described herein. BRIEF DESCRIPTION OF DRAWINGS
[0034] Figure 1 A connection diagram of FTTR networking provided by an embodiment of the present application;
[0035] Figure 2 A diagram of cascaded firewall devices in FTTR networking provided by an embodiment of the present application;
[0036] Figure 3 A diagram of cascaded firewall devices in FTTR networking provided by an embodiment of the present application;
[0037] Figure 4 An implementation environment schematic diagram of a packet forwarding processing method provided by an embodiment of the present application;
[0038] Figure 5 A flowchart of a packet forwarding processing method provided by an embodiment of the present application;
[0039] Figure 6 A schematic diagram of an FTTR networking cascading bypass firewall device provided by an embodiment of the present application;
[0040] Figure 7 A flowchart of a packet forwarding processing method provided by an embodiment of the present application;
[0041] Figure 8 A schematic diagram of another FTTR networking cascading bypass firewall device provided by an embodiment of the present application;
[0042] Figure 9 A flowchart of another packet forwarding processing method provided by an embodiment of the present application;
[0043] Figure 10 A networking architecture schematic diagram of an FTTR networking provided by an embodiment of the present application;
[0044] Figure 11 A structure schematic diagram of a packet forwarding processing apparatus provided by an embodiment of the present application;
[0045] Figure 12 A structure schematic diagram of a network device provided by an embodiment of the present application;
[0046] Figure 13 A structure schematic diagram of another network device provided by an embodiment of the present application. DETAILED DESCRIPTION
[0047] In order to make the purpose, technical scheme and advantages of the present application clearer, the embodiments of the present application will be further described in detail below with reference to the drawings.
[0048] With the development of communication technology, user access to the network has mostly realized fiber access. Fiber access and the continuous improvement of network infrastructure provide a solid information base for the prosperity of Internet services. The application types of Internet services are emerging in an endless stream, for example, ultra-high-definition video, cloud virtual reality (VR), cloud gaming, online education, remote office, etc., which put forward higher and higher requirements on the bandwidth, delay, jitter, etc. of the network. Therefore, better Internet experience can be provided for users by improving the bandwidth.
[0049] In the scenario of continuously increasing bandwidth, the user's final perceived Internet speed is limited due to insufficient access rate of the access equipment used by the user to access the network, or due to weak wireless signal in the room caused by wall penetration, or due to low carrying capacity of the network cable caused by network cable branching or unqualified network cable, or due to the constraint of the negotiation rate of the user's access to the network caused by the fact that the network port of the access equipment connected to the optical transmission network (OTN) is a 100 Mbps Ethernet port. Further, FTTR networking is proposed to ensure stable large bandwidth covering the entire room and realize on-demand connection.
[0050] In FTTR networking, the main ONU is the core, the main ONU is connected to the OLT upwards and connected to multiple slave ONUs downwards through a splitter or an optical socket, and each slave ONU is connected to at least one user terminal downwards. The slave ONU supports a gigabit Ethernet port and a dual-frequency wireless signal, and each slave ONU enters each room with an optical fiber to provide wired or wireless gigabit network coverage for each room. Optionally, the ONU can also be referred to as an optical network terminal (ONT). The user terminal can include a computer, a camera, and a voice telephone terminal.
[0051] Exemplarily, refer to Figure 1 , Figure 1 A connection diagram of FTTR networking provided by an embodiment of the present application is shown. The main ONU is located between the OLT and the slave ONU, connected to the OLT upwards through a PON interface, supports gigabit access to the home, and provides a PON interface to connect the slave ONU downwards. The PON interface can be a 10-gigabit-capable passive optical network (XGPON) interface or a 10Gbit / s Ethernet passive optical network (10G-EPON) interface. Multiple slave ONUs are distributed to different rooms, connected to the main ONU upwards through an optical cable or an optical and electrical composite cable, and provide a wireless interface and a gigabit Ethernet (GE) interface to access various home Internet terminals, realizing on-demand access of the Internet terminal. The slave ONU works in a bridge mode, and the IP address of the slave ONU and the IP address of the user terminal hung under the slave ONU are uniformly allocated and managed by the main ONU, so that the FTTR networking forms a unified and intercommunicable local area network, and the user terminals accessed by each slave ONU can realize local area network intercommunication operations such as screen projection and file sharing under an ultra-gigabit bandwidth.
[0052] In order to improve the security of the FTTR networking, it is necessary to independently deploy a firewall device. For example, in the scenario of deploying FTTR networking in an enterprise, since the enterprise has higher requirements for security, the firewall capability of the master ONU is difficult to support the security requirements of the enterprise, and therefore, it is necessary to additionally deploy an independent firewall device. Since the master ONU is connected to the OLT through a PON interface upward, and the network interface of the firewall device is usually not a PON interface, for example, the network interface of the firewall device is a LAN interface or a WAN interface. If an independent firewall device is cascaded between the OLT and the master ONU, referring to the schematic diagram of the cascaded firewall device shown in Figure 2 , it is necessary to modify the PON interface of the master ONU to a LAN interface or a WAN interface, which causes the master ONU to fail to exert the capability of the PON interface, and an additional level gateway device is needed to connect the OLT upward through the PON interface, resulting in additional overhead.
[0053] Therefore, in the FTTR networking scenario, the firewall device can be cascaded and side-mounted on the master ONU through two LAN interfaces, all the traffic in the FTTR networking that accesses the external network through the PON interface is introduced to the firewall device through the LAN interface, and the firewall device audits the online behavior of the user. For example, referring to the schematic diagram of the cascaded and side-mounted firewall device shown in Figure 3 , the master ONU is connected to the OLT upward through the PON2 interface and connected to the slave ONU downward through the PON1 interface, and the firewall device is cascaded and side-mounted through the LAN2 interface and the LAN1 interface.
[0054] Exemplarily, the main ONU receives the message sent from the ONU through the PON1 interface. In a gigabit-capable PON (GPON), the message is encapsulated in a GPON encapsulation mode (GEM) frame, and the GEM port information is carried in the frame header of the GEM frame. The GEM port is a virtual port used to carry services in the GPON, and one GEM port corresponds to one port identification (ID). The GEM port information can indicate the port of the ONU. After the main ONU cascades the firewall device, the main ONU needs to encapsulate the received message into an Ethernet frame based on the bridge forwarding mode of the virtual local area network (VLAN) information and the MAC information, and then forwards the Ethernet frame to the LAN1 interface connected to the firewall device. The message is sent to the firewall device through the LAN1 interface, and then the message is forwarded to the main ONU again through the firewall device. The bridge forwarding is used to connect two different local area networks, reassemble the message received from one local area network according to the format of another local area network, and send the message to the physical layer of another local area network.
[0055] In this case, the main ONU receives the message sent by the firewall device again through the LAN2 interface connected to the firewall device, and sends the message to the PON2 interface through the bridge forwarding or the network address translation (NAT) forwarding of the three-layer network. The message is sent to the OLT through the PON2 interface. Since the message received through the LAN2 interface is encapsulated in an Ethernet frame, the GEM port information is not included in the frame header of the Ethernet frame, so that the original GEM port information is lost after the message is forwarded through the firewall device. The main ONU cannot determine that the message is sent from the port of the ONU, and the related services configured based on the port of the ONU are affected, for example, the message cannot be processed according to the processing strategy configured based on the port of the ONU.
[0056] The embodiment of the present application provides a packet forwarding processing method, port labels and tunnel headers are encapsulated for packets forwarded via a firewall device. Since the port label is used for indicating the port of the slave ONU, the port label is used for realizing the effect of recording the port of the slave ONU. Since the tunnel header is used for indicating that the firewall device sends a second packet to the master ONU, in the forwarding process based on the tunnel header, the information of the port of the slave ONU does not need to be parsed, and the information of the port of the slave ONU can be protected from being lost in the forwarding process. When the packet sent by the slave ONU and received by the master ONU is returned to the master ONU after being forwarded via the firewall device, the information of the port of the slave ONU is not lost, and then the packet can be processed based on the processing strategy configured for the port of the slave ONU.
[0057] Exemplarily, referring to Figure 4 , Figure 4 An implementation environment schematic diagram of a packet forwarding processing method provided by the embodiment of the present application is provided. The implementation environment includes an OLT, an FTTR network and a firewall device. The FTTR network includes a master ONU and a plurality of slave ONUs, and the master ONU and the plurality of slave ONUs are connected through optical sockets. The master ONU can be a master gateway or a master optical modem, the slave ONU can be a slave gateway or a slave optical modem, and the slave ONU can also be an access point (AP) device. The number of slave ONUs is not limited in the embodiment of the present application. Figure 4 The number of slave ONUs can be less or more. Each slave ONU can be connected to a plurality of terminals used by users as a wireless access point. The OLT is connected to the FTTR network through a PON interface, the firewall device is cascaded and hung on the master ONU through a LAN interface, and the FTTR network and the firewall device belong to two different local area networks and need to be bridged and forwarded.
[0058] Referring to Figure 5 , Figure 5 A flowchart of a packet forwarding processing method provided by the embodiment of the present application is provided. The method can be applied to Figure 4 The implementation environment, for example, the master ONU cascaded and hung with the firewall device shown in Figure 4 As shown in Figure 5 The packet forwarding processing method includes the following steps 501-504.
[0059] Step 501, receiving a first packet sent by a slave ONU.
[0060] In the embodiment of the present application, the master ONU comprises a first PON interface, and the master ONU is connected to the slave ONU through the first PON interface, so that the master ONU can receive the first message sent by the slave ONU through the first PON interface. Optionally, the type of the first message is not limited in the embodiment of the present application, for example, the first message can be a dial request message of a user terminal connected to the slave ONU through a wired or wireless manner, an external network access message, or a service data message, etc.
[0061] In step 502, the second message is sent to the firewall device in the case that the traffic between the slave ONU and the firewall device is straight-through, and the second message is obtained by adding a port tag and a first tunnel header to the first message, wherein the port tag indicates the port of the slave ONU, and the first tunnel header indicates that the firewall device sends the second message to the master ONU.
[0062] The traffic straight-through between the slave ONU and the firewall device means that the next hop of the traffic from the slave ONU is directly determined as the firewall device, and in the embodiment of the present application, the received message sent by the slave ONU is sent to the firewall device after adding the port tag and the first tunnel header. Exemplarily, the master ONU further comprises a first LAN interface and a second LAN interface, and the first LAN interface and the second LAN interface are connected to the firewall device, so that the master ONU is cascaded with the firewall device. The first PON interface of the master ONU is directly connected to the second LAN interface, so that the traffic between the slave ONU and the firewall device is straight-through. If the traffic between the slave ONU and the firewall device is not straight-through, it means that the next hop of the message from the slave ONU needs to be determined according to a forwarding strategy, for example, the next hop is determined by a routing table. The next hop of the message determined according to the forwarding strategy does not include the firewall device.
[0063] Referring to Figure 6 the schematic diagram of the cascaded firewall device, the downlink PON interface on the master ONU is directly connected to the LAN2 interface, so that the traffic between the slave ONU and the firewall device is straight-through. The downlink PON interface corresponds to the first PON interface in the embodiment of the present application, the LAN1 interface corresponds to the second LAN interface in the embodiment of the present application, and the LAN2 interface corresponds to the second LAN interface in the embodiment of the present application. In this scenario, the message received through the first PON interface is all sent to the firewall device through the first LAN interface, and then forwarded after being processed by the firewall device, which can improve the security of the message received through the first PON interface and forwarded by the master ONU. The master ONU needs to encapsulate the port tag and the first tunnel header to the first message to obtain the second message, and then send the second message to the firewall device through the first LAN interface.
[0064] In the embodiments of the present application, the first message sent by the slave ONU and received by the master ONU carries information indicating the port of the slave ONU. For example, the first message carries GEM port information of the slave ONU, and the GEM port information can indicate the port of the slave ONU. The embodiments of the present application do not limit the setting mode of the port tag, and the port tag can be used to distinguish the ports of different slave ONUs. For example, the port tag of the slave ONU can be a private tag (Tag) or a VLAN Tag corresponding to the port of the slave ONU.
[0065] Optionally, the embodiments of the present application do not limit the encapsulation type of the first tunnel header, and different first tunnel headers under different tunnel protocols can be flexibly used for encapsulation according to application scenarios. For example, the first tunnel header includes routing information, so that the message encapsulated with the outermost first tunnel header can be transmitted in a network equipped with the tunnel. The tunnel protocol includes but is not limited to a QinQ protocol, a virtual private network (VPN) protocol, a point-to-point tunneling protocol (PPTP), or a layer two tunneling protocol (L2TP), etc. QinQ is the abbreviation of 802.1Q-in-802.1Q, and QinQ is also called virtual local area network stacking (VLAN Stacking) or double (Double) VLAN, which achieves the purpose of expanding the VLAN space by adding an 802.1Q tag on the basis of an 802.1Q tag message. The encapsulation mode of the first tunnel header can flexibly use different encapsulation modes of different tunnel protocols for different tunnel protocols.
[0066] Taking the port tag as a VLAN Tag and the first tunnel header as a QinQ VLAN as an example, the encapsulation mode of the port tag and the first tunnel header for the first message can be that a layer of VLAN Tag is encapsulated on the outer layer of the first message, and then a layer of QinQ VLAN is encapsulated on the outer layer of the VLAN Tag, so as to realize the forwarding of the message through the firewall device by the outermost QinQ VLAN. Therefore, the information of the port of the slave ONU can be carried in the forwarded message by encapsulating the port tag, and the message is routed and forwarded based on the outermost tunnel header by encapsulating the tunnel header, so that the port tag in the inner layer of the tunnel header is not analyzed, and it is ensured that the port tag will not be lost in the forwarding process.
[0067] In step 503, the second packet subjected to the auditing processing or the filtering processing by the firewall device is received, the first packet and the port label are acquired based on the second packet, the first processing strategy configured from the port of the ONU is acquired based on the port label, and the first processing strategy includes at least one of the service binding strategy, the WAN binding strategy, the VLAN binding strategy, the port filtering strategy, the priority strategy or the sending interface strategy.
[0068] In the embodiment of the present application, the firewall device performs the auditing processing or the filtering processing on the received second packet. The auditing processing can be statistical analysis on the received second packet, and the filtering processing can be filtering out the packet not meeting the security condition and no longer forwarding, and forwarding the packet meeting the security condition to the main ONU according to the first tunnel header of the outermost encapsulation. The security condition can be flexibly set according to the application scenario, for example, the security condition can be used to realize the antivirus monitoring and the user security behavior management of the firewall device on the user traffic. In the embodiment of the present application, the first LAN interface, the second LAN interface of the main ONU and the interface connected with the first LAN interface and the interface connected with the second LAN interface of the firewall device are all configured with the routing information indicated by the first tunnel header, so that the bypass forwarding of the second packet through the firewall can be realized based on the first tunnel header, and then the routing capability of the firewall device is not relied on to realize the packet forwarding through the tunnel header.
[0069] Since the second packet is obtained by encapsulating the port label and the first tunnel header on the first packet, the first packet and the port label can be acquired based on the second packet. For example, the outermost first tunnel header is stripped and then the port label and the first packet are parsed by decapsulating the second packet. Since the port label indicates the port of the ONU, the first processing strategy configured from the port of the ONU is acquired based on the port label before the first packet is received. The content of the first processing strategy is not limited in the embodiment of the present application, and different processing strategies can be flexibly configured according to the service requirement of the application scenario.
[0070] The service binding policy can bind the port from the ONU to a target service, so that the message forwarding mode configured by the target service is applicable to the message sent from the port of the ONU; the WAN binding policy can bind the port from the ONU to a target WAN, so that the message forwarding mode configured by the target WAN is applicable to the message sent from the port of the ONU; the VLAN binding policy can bind the port from the ONU to a target VAN, so that the message forwarding mode configured by the target VAN is applicable to the message sent from the port of the ONU; the port filtering policy can be a filtering condition, so that the message sent from the port of the ONU that meets the filtering condition can be forwarded, and the message that does not meet the filtering condition is not forwarded; the priority policy can be that different ports are configured with different forwarding priorities, so that the message sent by the port with high priority can be forwarded preferentially; and the sending interface policy can specify different forwarding interfaces for different ports, so that the message sent by different ports can be forwarded according to the specified interface.
[0071] In step 504, the first message is processed according to the first processing policy.
[0072] In the embodiment of the present application, since the first processing policy configured by the port from the ONU can be obtained based on the port label, the first message sent through the port corresponding to the second LAN interface can still be processed by the port from the ONU, without affecting the use of the related configuration of the port from the ONU. Among them, the master ONU receives the first message twice through the first PON interface and the second LAN interface. The first time the first message is received through the first PON interface, since the first message is sent from the port of the ONU, the information indicating the port from the ONU is received at the same time as the first message, that is, the port from the ONU is the original port of the first message. The second time the first message is received through the second LAN interface, although the first message is sent through the port corresponding to the second LAN interface, the port label encapsulated outside the first message can determine that the original port of the first message is the port from the ONU, and then after cascading the firewall device, the processing policy configured based on the port will not be affected.
[0073] Therefore, the above process enables the forwarding of the first packet from the ONU to the main ONU on the user side, bypassed by the firewall device. Port tags ensure that the first packet is still processed according to the first processing policy. After obtaining the processed third packet, normal routing forwarding can be performed based on the destination address of the third packet. Depending on the first processing policy, the third packet can be the same as or different from the first packet. In this embodiment, the main ONU also includes a second PON interface, which is connected to the slave ONU. Optionally, the third packet can be forwarded by sending it to the OLT via the second PON interface based on the destination address of the third packet.
[0074] See Figure 7 , Figure 7 Based on Figure 6 The diagram illustrates the packet forwarding process in a scenario with cascaded bypass firewall devices. The bypass processing of packets received through the user-side first PON interface is as follows: ① The primary ONU, based on the direct connection between the first PON interface and the first LAN interface, directly encapsulates a port label on the outer layer of the packet, and then encapsulates a tunnel header on top of the port label. It then sends the packet through the first LAN interface to the firewall device's LAN interface. The firewall device processes and filters the received packets, discarding those that do not meet security requirements and forwarding those that do meet security requirements to the WAN interface based on the outermost tunnel header. From there, the packets are bypassed and forwarded to the primary ONU's second LAN interface. After being forwarded by the firewall device, ② the primary ONU receives the packet through the second LAN interface. The forwarding module removes the outermost tunnel header and obtains the port information of the original sending slave ONU based on the port label inside the tunnel header. The primary ONU then processes and forwards the packet according to the processing policy configured on the slave ONU's port, without affecting the primary ONU's management functions over the original slave ONU's ports. The main ONU also includes a processor, which is used to implement the operations performed by the forwarding module. The forwarding module, as a software virtual module, is used to perform related operations to forward packets from the main ONU.
[0075] In addition, the master ONU can also learn the source address information such as MAC carried by the first packet to the corresponding port for subsequent routing and forwarding of other received packets. However, after the master ONU cascades the firewall device, the same first packet enters the master ONU once through the first PON interface and enters the master ONU again through the second LAN interface after being forwarded by the firewall device, which may cause the MAC table item of the same user to be learned to the port of the slave ONU connected by the first PON interface and the port of the firewall device connected by the second LAN interface, thereby causing the routing query result based on the MAC table item of the user to be inaccurate, so that the master ONU cannot perform normal user management. For example, the user topology of the slave ONU displayed by the master ONU is inaccurate, and the user under the first PON interface may be displayed under the second LAN interface.
[0076] Therefore, in the embodiment of the present application, after obtaining the first packet and the port tag based on the second packet, the correspondence between the source address information of the first packet and the port of the slave ONU indicated by the port tag can also be saved, and the source address information can include MAC information and ARP information. In this case, the way of determining that the destination port of the fourth packet is the port of the slave ONU based on the destination address of the fourth packet can be that the MAC information and the ARP information are indicated based on the destination address of the fourth packet, and the destination port of the fourth packet is determined to be the port of the slave ONU in the correspondence. In this case, the way of determining that the destination port of the fourth packet is the port of the slave ONU based on the destination address of the fourth packet is to determine the destination port of the fourth packet to be the port of the slave ONU based on the destination address of the fourth packet being the MAC information and the ARP information and the correspondence.
[0077] That is, after the master ONU receives the first packet sent by the slave ONU through the first PON interface, the master ONU does not learn the source address information of the first packet because the first PON interface is directly connected to the first LAN interface, but after receiving the second packet sent by the firewall device based on the first tunnel header through the second LAN interface, the master ONU learns the source address information of the first packet to the port of the slave ONU indicated by the port tag based on the first packet and the port tag obtained from the second packet, that is, saves the correspondence between the source address information of the first packet and the port of the slave ONU indicated by the port tag. Therefore, although the master ONU receives the first packet twice through the first PON interface and the second LAN interface, the source address information of the first packet is only learned to the port of the slave ONU indicated by the port tag, and the source address information of the first packet is not learned twice or incorrectly learned to the port corresponding to the second LAN interface, which improves the accuracy of obtaining the correspondence based on the first packet, and further improves the accuracy of determining the port based on the correspondence.
[0078] In a possible implementation, in the case that the traffic is not straight-through between the ONU and the firewall device, the process of the master ONU forwarding the first packet is: obtaining a first processing strategy configured for the port of the slave ONU based on the information of the port of the slave ONU, processing the first packet based on the first processing strategy to obtain a processed third packet; in the case that the next hop of the third packet indicates the OLT and the traffic is straight-through between the OLT and the firewall device, sending the third packet to the firewall device; receiving the third packet that has been processed by the firewall device, and sending the third packet to the OLT.
[0079] Exemplarily, after the master ONU receives the first packet sent by the slave ONU through the first PON interface, in the case that the first PON interface and the first LAN interface are not straight-through, the master ONU obtains a first processing strategy configured for the port of the slave ONU based on the information of the port of the slave ONU, processes the first packet based on the first processing strategy to obtain a third packet; in the case that the destination address of the third packet indicates the second PON interface and the second PON interface and the second LAN interface are straight-through, the master ONU converts the second PON interface indicated by the destination address of the third packet to the first LAN interface, and sends the third packet to the firewall device through the first LAN interface; receives the third packet sent by the firewall device through the second LAN interface, and sends the third packet to the OLT through the second PON interface.
[0080] Thus, for the third packet sent by the master ONU to the OLT, the third packet is processed by the firewall device before being sent to the OLT through the second PON interface, which improves the security of the third packet sent through the second PON interface, and the master ONU can be connected to the OLT through the PON interface, so that the master ONU can not only exert the capability of the PON interface, but also filter the third packet sent to the OLT through the firewall device through the LAN interface.
[0081] Referring to Figure 8 The downlink PON interface on the master ONU and the LAN2 interface are not straight-through, and are forwarded through the forwarding module, while the uplink PON interface on the master ONU and the LAN1 interface are straight-through, i.e., the traffic is straight-through between the OLT and the firewall device. The uplink PON interface corresponds to the second PON interface in the embodiments of the present application, the downlink PON interface corresponds to the first PON interface in the embodiments of the present application, the LAN1 interface corresponds to the second LAN interface in the embodiments of the present application, and the LAN2 interface corresponds to the second LAN interface in the embodiments of the present application. In this scenario, the first packet received through the first PON interface is first processed according to the originally configured processing strategy, and then is sent out through the egress interface via the firewall device.
[0082] Exemplarily, in the message forwarding process shown in Figure 9 In the message forwarding process shown, the process of bypassing the message received through the first PON interface on the user side is as follows: ① The master ONU determines, through the forwarding module, that the message needs to be sent through the second PON interface; ② The master ONU converts the message that needs to be sent through the second PON interface into a message sent through the first LAN interface, and then sends it to the LAN interface of the firewall; after being forwarded to the second LAN interface via the firewall device, ③ the master ONU sends the message received through the second LAN interface directly to the OLT through the second PON interface. That is, the user-side message going up to the OLT needs to be filtered by the firewall device before being forwarded to the uplink PON interface by the master ONU, and then sent to the OLT through the uplink PON interface.
[0083] In a possible implementation, in addition to the user-side message going up to the OLT, the master ONU also receives the fourth message sent by the OLT to the user side, for example, receives the fourth message sent by the OLT to the user side through the second PON interface. Optionally, after the master ONU receives the fourth message sent by the OLT, in the case of traffic straight-through between the OLT and the firewall device, the fourth message is sent to the firewall device; the fourth message that has been audited or filtered by the firewall device is received, and the fourth message is forwarded in the manner of receiving the fourth message sent by the OLT.
[0084] Traffic straight-through between the OLT and the firewall device means that the next hop of the traffic from the OLT is directly determined to be the firewall device, that is, the received message sent by the OLT is sent to the firewall device in the embodiment of the present application. Exemplarily, the second PON interface of the master ONU is directly connected to the first LAN interface, so that the traffic is straight-through between the OLT and the firewall device. If the traffic is not straight-through between the OLT and the firewall device, it means that the next hop of the message from the OLT needs to be determined according to the forwarding strategy, for example, the next hop is determined to be which device through a routing table. Wherein, the next hop of the message determined according to the forwarding strategy does not include the firewall device.
[0085] Exemplarily, the fourth message sent by the OLT is received through the second PON interface; in the case that the second PON interface is directly connected with the second LAN interface, the fourth message is sent to the firewall device through the second LAN interface; the fourth message sent by the firewall device is received through the first LAN interface, the first LAN interface receiving the fourth message is converted into the second PON interface; and the fourth message is forwarded according to the manner of receiving the fourth message through the second PON interface. That is, the fourth message received through the second PON interface is first filtered by the firewall device, and then is processed according to the originally configured processing strategy and is sent out through the out interface. The type of the fourth message is not limited in the embodiments of the application, for example, the fourth message can be a service data message or a user configuration message sent by the OLT.
[0086] Thus, the fourth message sent by the OLT and received through the second PON interface can be processed by the firewall device and then be forwarded, so as to improve the security of the fourth message forwarded by the master ONU. Moreover, after the fourth message enters the master ONU again by the firewall device, the master ONU can simulate the fourth message received through the first LAN interface as the fourth message received through the second PON interface, and then still processes the fourth message according to the fourth message received through the second PON interface. That is, the processing manner of the fourth message sent by the OLT by the master ONU after cascading the firewall device is the same as the processing manner of the fourth message sent by the OLT by the master ONU before cascading the firewall device, and the accuracy of the message forwarding processing is not affected by the cascading of the firewall device, so as to improve the accuracy of the message forwarding processing.
[0087] Referring to Figure 8 the schematic diagram of the cascaded firewall device shown in the figure, the uplink PON interface of the master ONU receives the message, and since the uplink PON interface is directly connected with the LAN1 interface, the message is directly sent to the firewall device through the LAN1 interface. In this case, the message received through the uplink PON interface is first filtered by the cascaded firewall device before entering the forwarding module, and then is forwarded to the slave ONU on the user side by the forwarding module. Thus, the master ONU bypasses the traffic of the uplink PON interface through the direct connection flow and the manner of simulating the uplink PON interface, does not affect the management function of the master ONU to the slave ONU, and can conveniently perform the firewall interception processing on the traffic of the uplink PON interface.
[0088] Exemplarily, in the case that the second PON interface is directly connected with the second LAN interface, Figure 9The bypass processing process of the message passing through the second PON interface of the network side in the message forwarding process is as follows: ④ the master ONU sends the message received through the second PON interface to the firewall device through the second LAN interface directly via the pass-through flow, and then sends the message to the WAN interface of the firewall, and then forwards the message to the first LAN interface via the firewall device; ⑤ the master ONU converts the message received through the first LAN interface into the second PON interface to simulate the message entering from the uplink second PON interface; and ⑥ the master ONU forwards the message received through the first LAN interface based on the message entering through the second PON interface by the forwarding module.
[0089] In a possible implementation, after the master ONU receives the fourth message sent by the OLT, in the case that the traffic is not directly passed through between the OLT and the firewall device, the destination port of the fourth message is determined to be the port of the slave ONU based on the destination address of the fourth message; in the case that the next hop of the fourth message indicates the slave ONU and the traffic is directly passed through between the slave ONU and the firewall device, the fifth message is sent to the firewall device, the fifth message is obtained by adding a port label and a second tunnel header to the fourth message, the second tunnel header indicates that the firewall device sends the fifth message to the master ONU; the fifth message subjected to the auditing processing or the filtering processing of the firewall device is received, the fourth message and the port label are obtained based on the fifth message, and the fourth message is sent to the slave ONU based on the port of the slave ONU indicated by the port label.
[0090] Exemplarily, in the case that the second PON interface and the second LAN interface are not directly passed through, the process that the master ONU forwards the fourth message is as follows: the destination port of the fourth message is determined to be the port of the slave ONU based on the destination address of the fourth message; in the case that the destination address of the fourth message indicates the first PON interface and the first PON interface and the first LAN interface are directly passed through, the first PON interface indicated by the destination address of the fourth message is converted into the second LAN interface, the fifth message is sent to the firewall device through the second LAN interface, the fifth message is obtained by encapsulating a port label and a second tunnel header to the fourth message, and the second tunnel header indicates the forwarding path of the fifth message through the firewall device; the fifth message sent by the firewall device based on the second tunnel header is received through the first LAN interface, and the fifth message is sent to the port of the slave ONU indicated by the port label through the first PON interface. The encapsulation mode of the second tunnel header can refer to the encapsulation mode of the first tunnel header, which is not described herein again.
[0091] Thus, for the fourth message sent by the master ONU to the slave ONU, the fourth message is processed by the firewall device via the first PON interface before being sent to the slave ONU, thereby improving the security of the fourth message sent through the first PON interface. Moreover, the fourth message is encapsulated with a port tag and a second tunnel header to obtain a fifth message, so that the firewall device can route and forward the fifth message based on the second tunnel header. After the firewall device forwards the fifth message to the first LAN interface of the master ONU, the master ONU can obtain the inner-encapsulated port tag and the fourth message based on the fifth message, and determine that the fourth message is sent to the port of the slave ONU according to the port tag, thereby improving the accuracy of message routing and forwarding processing after the cascaded firewall device is bypassed.
[0092] Referring to Figure 6 The uplink PON interface on the master ONU is not directly connected to the LAN1 interface, but is connected through the forwarding module, while the downlink PON interface on the master ONU is directly connected to the LAN2 interface. The uplink PON interface corresponds to the second PON interface in the embodiments of the present application. In this scenario, the message received through the uplink PON interface is first forwarded through the forwarding module, and then filtered and processed by the bypassed firewall device, and is forwarded to the slave ONU on the user side through the downlink PON interface. The master ONU gateway supports the configuration of the bypassed device, and bypasses the traffic of the uplink PON interface in a bidirectional direct connection flow and a pseudo uplink port manner. The management function of the original down-hung AP by the master FTTR is not affected. The firewall interception processing can be conveniently performed on the out-of-network export traffic of the uplink PON interface. The scheme has high forwarding performance, does not occupy CPU resources, and also has less occupation of forwarding resources.
[0093] Exemplarily, in Figure 7 In the message forwarding process shown in The bypass processing of the message received through the second PON interface on the network side is as follows: ③ The master ONU determines the port of the slave ONU through the forwarding module, processes the message according to the processing strategy configured for the port of the slave ONU, encapsulates a layer of port tag on the outer layer of the processed message, encapsulates a layer of tunnel header on the outer layer of the port tag, and then sends the message to the WAN interface of the firewall device through the second LAN interface. The firewall device processes and filters the received message, filters out the message that does not meet the security condition and does not forward it, and forwards the message that meets the security condition to the LAN interface according to the outermost encapsulated tunnel header, and then bypasses and sends it to the first LAN interface of the master ONU through the LAN interface. After being forwarded by the firewall device, ④ the master ONU receives the message through the first LAN interface, removes the outermost tunnel header, determines the port of the slave ONU according to the port tag in the inner layer of the tunnel header, and directly sends the message to the port of the slave ONU through the first PON interface since the first LAN interface is directly connected to the first PON interface.
[0094] The method provided in this application embodiment involves a firewall device cascaded and connected to the first and second LAN interfaces of the main ONU. This allows the first packet sent by the slave ONU and received through the first PON interface to be processed by the firewall device before being forwarded, thereby improving the security of the first packet forwarded by the main ONU. Furthermore, by encapsulating the first packet with a port label and a first tunnel header to obtain the second packet, the firewall device can route and forward the second packet based on the first tunnel header. After the firewall device forwards the second packet to the second LAN interface of the main ONU, the main ONU can obtain the inner encapsulated port label and the first packet based on the second packet. It can then determine, based on the port label, that the original port that sent the first packet was the slave ONU's port, meaning that the information of the original port of the first packet is not lost. This allows the main ONU to still process the first packet received on the second LAN interface based on the first processing policy configured on the slave ONU's port. In other words, the way the main ONU processes the first packet sent by the slave ONU after cascading the firewall device is the same as the way it processes the first packet sent by the slave ONU before cascading the firewall device. The packet processing performance is not affected by the cascading firewall device, thus improving the accuracy of packet forwarding.
[0095] Below, based on Figure 10 The network architecture shown illustrates the packet forwarding method provided in this application embodiment. Figure 10 In this configuration, the OLT connects upwards to the external network and downwards to the main ONU via an optical splitter. The connection between the OLT and the main ONU is an optical fiber. The main ONU connects downwards to multiple slave ONUs via optical sockets, with the connection between the main ONU and the multiple slave ONUs being a fiber-optic composite cable. Optionally, the main ONU also connects downwards to a switch via a network cable. The main ONU is configured in bypass mode, meaning it has reserved a network-side LAN2 interface and a user-side LAN1 interface for bypassing firewall devices. For example, the network-side LAN2 interface connects to the firewall device's network-side LAN7, and the slave ONU's user-side LAN1 interface connects to the firewall device's user-side LAN6. Figure 10 The method of cascading and side-mounting firewall devices from the main ONU and Figure 6Similarly, the PON interface of the main ONU is physically connected to the OON of the OLT, and logically includes all external network traffic transmitted downward by the OLT. All external network traffic transmitted downward needs to be processed by the firewall device first. For example, the tunnel header is QinQ VLAN, the LAN2 interface and the LAN1 interface of the main ONU are configured with the same QinQ VLAN as the LAN6 interface and the LAN7 interface of the firewall device, the outermost tunnel header is encapsulated by the QinQ VLAN, the bridge transmission forwarding of the message is realized, and the message is forwarded by the firewall device without losing the port label encapsulated in the inner layer of the QinQ VLAN.
[0096] The processing and forwarding of the message in the user's online process are taken as examples for detailed description. The user terminal is an internal network terminal device, the internal network terminal device is hung under any slave ONU, and the user accesses the external network through the dynamic host configuration protocol (DHCP). The internal network terminal device sends a DHCP dial request message to the slave ONU, the slave ONU sends the DHCP dial request message to the main ONU through the uplink PON interface, and carries the GEM port information of the slave ONU. For example, the slave ONU encapsulates the DHCP dial request message into a GEM frame, the load of the GEM frame includes the DHCP dial request message, and the frame header of the GEM frame includes the GEM port information of the slave ONU. The slave ONU sends the GEM frame to the main ONU through the uplink PON interface.
[0097] After the main ONU receives the DHCP dial request message and the GEM port information sent by the slave ONU from the downlink PON interface, the GEM port information of the slave ONU can be converted into the port information of the slave ONU, and in the case that the slave ONU is an AP device, the GEM port information of the slave ONU can be converted into the AP port information. The main ONU locally saves and manages the correspondence between the port information of the slave ONU and the port label, and the port label can be a private VLAN Tag. The main ONU adds a layer of private VLAN Tag to the DHCP dial request message, and then adds a layer of Qinq VLAN, that is, encapsulates the message. After the main ONU obtains the DHCP dial request message encapsulated with the VLAN Tag and the Qinq VLAN, the main ONU directly forwards the message to the user side LAN1 interface of the main ONU, and the main ONU does not learn the MAC information and the ARP information of the DHCP dial request message.
[0098] The user side LAN 6 interface of the firewall device is directly connected to the user side LAN 1 interface of the master ONU, so that the DHCP dial request message sent to the user side LAN 1 interface of the master ONU is directly transmitted to the user side LAN 6 interface of the firewall device. After the firewall device receives the DHCP dial request message which is encapsulated by the outer Qinq VLAN and carries the inner VLAN Tag through the user side LAN 6 interface, because the user side LAN 6 interface and the network side LAN 7 interface are configured with the same Qinq VLAN, the firewall device performs two-layer bridging forwarding in the Qinq VLAN layer, and forwards the DHCP dial request message which is encapsulated by the VLAN Tag and the Qinq VLAN to the network side LAN 7 interface of the firewall device.
[0099] Because the network side LAN 7 interface of the firewall device is directly connected to the network side LAN 2 interface of the master ONU, the network side LAN 2 interface of the master ONU receives the DHCP dial request message which is encapsulated by the VLAN Tag and the Qinq VLAN, and the master ONU first performs decapsulation processing, i.e. stripping the Qinq VLAN layer tunnel header, restores the port information of the slave ONU from the VLAN Tag, and forwards the DHCP dial request message according to the port of the slave ONU from which the DHCP dial request message is received. For example, the MAC information and ARP information in the source address of the DHCP dial request message are learned to the port of the slave ONU, i.e. the MAC information and ARP information of the user of the port of the slave ONU are obtained without being mistakenly learned to the network side LAN 2 interface. Thus, for the DHCP dial request message sent by the port of the slave ONU but forwarded through the firewall device, the master ONU only learns the MAC information and ARP information once and learns to the port of the slave ONU, so that the master ONU does not affect the topology management of the original user of the port of the slave ONU after the firewall device is connected in parallel.
[0100] The DHCP service (Server) module on the master ONU receives the DHCP dial-up request message of the intranet terminal device sent from the ONU, and replies to the DHCP dial-up request message, for example, allocates an internet protocol (IP) address for the intranet terminal device corresponding to the DHCP dial-up request message. The master ONU returns the DHCP dial-up response message corresponding to the DHCP dial-up request message to the intranet terminal device, the DHCP dial-up response message includes the allocated IP address, and adds a layer of VLAN Tag corresponding to the port of the slave ONU to the outer layer of the DHCP dial-up response message, and then adds a layer of Qinq VLAN, and the master ONU sends the DHCP dial-up response message encapsulated with the VLAN Tag and the Qinq VLAN to the network side LAN7 interface of the firewall device through the network side LAN2 interface.
[0101] After the firewall device receives the DHCP dial-up response message encapsulated with the Qinq VLAN in the outer layer and carrying the VLAN Tag in the inner layer through the network side LAN7 interface, the firewall device performs two-layer bridging forwarding based on the Qinq VLAN, and sends the DHCP dial-up response message encapsulated with the VLAN Tag and the Qinq VLAN to the user side LAN6 interface. Since the user side LAN6 interface of the firewall device is directly connected to the user side LAN1 interface of the master ONU, the user side LAN1 interface of the master ONU receives the DHCP dial-up response message encapsulated with the VLAN Tag and the Qinq VLAN, and the master ONU performs decapsulation processing first, that is, stripping the Qinq VLAN layer tunnel header, and restoring the port information of the slave ONU from the VLAN Tag, and sending the DHCP dial-up response message to the slave ONU through the downlink PON interface based on the port information of the slave ONU.
[0102] After the slave ONU receives the DHCP dial-up response message returned to the intranet terminal device, the slave ONU performs bridging forwarding of the DHCP dial-up response message to the intranet terminal device based on the destination MAC address of the DHCP dial-up response message, and the intranet terminal device obtains the IP address allocated by the master ONU through DHCP, and then the intranet terminal device can access the external network based on the IP address.
[0103] In the process of the intranet terminal device accessing the external network, the forwarding processing of the uplink traffic sent by the intranet terminal device to the external network is similar to the forwarding processing of the DHCP dial-up request message. The uplink traffic message is sent to the user side LAN1 interface of the master ONU, and is forwarded through the user side LAN6 interface and the network side LAN7 interface of the firewall device, and is then sent to the network side LAN2 interface of the master ONU again. The master ONU forwards the uplink traffic message to the OLT through the uplink PON interface of the master ONU through three-layer routing forwarding, and then accesses the external network through the OLT uplink.
[0104] The downlink traffic of the external network to the internal network terminal device is first forwarded to the uplink PON interface of the master ONU by the OLT, and then is forwarded on the master ONU. Based on the correspondence between the port and MAC information and the ARP information of the slave ONU learned in the dialing request process, the corresponding destination port of the downlink traffic message can be found as the port of the slave ONU. Further, the forwarding processing of the downlink traffic message of the master ONU is similar to the forwarding processing of the DHCP dialing response message. The downlink traffic message is forwarded to the firewall device through the network side LAN2 interface, and is forwarded through the network side LAN7 interface and the user side LAN6 interface of the firewall device, and is then sent to the user side LAN1 interface of the master ONU again. The master ONU sends the downlink traffic to the slave ONU through the downlink PON interface based on the port information of the slave ONU, and the slave ONU bridges and forwards the downlink traffic to the internal network terminal device.
[0105] The above introduces the packet forwarding processing method of the embodiment of the application. Corresponding to the above method, the embodiment of the application further provides a packet forwarding processing device. Figure 11 is a structural schematic diagram of a packet forwarding processing device provided by the embodiment of the application. The device is applied to a master ONU. Based on the Figure 11 device shown in the figure, the packet forwarding processing device can perform all or part of the operations performed by the master ONU shown in the figure. It should be understood that the device can include more additional modules than the modules shown or omit part of the modules shown, and the embodiment of the application does not limit this. As shown in the figure, the device includes: Figure 11 Figure 5 the packet forwarding processing device shown in the figure. It should be understood that the device can include more additional modules than the modules shown or omit part of the modules shown, and the embodiment of the application does not limit this. As shown in the figure, the device includes: Figure 11
[0106] The transceiving module 1101 is configured to perform the receiving and / or sending related operations performed by the master ONU in the method shown in the figure; Figure 5 The processing module 1102 is configured to perform other operations in addition to the receiving and / or sending related operations performed by the master ONU in the method shown in the figure.
[0107] The processing module 1102 is configured to perform other operations in addition to the receiving and / or sending related operations performed by the master ONU in the method shown in the figure. Figure 5 In a possible implementation, the transceiving module 1101 includes a receiving module and / or a sending module. The receiving module is configured to perform receiving related operations, and the sending module is configured to perform sending related operations.
[0108]
[0109] In a possible implementation, the transceiving module 1101 is configured to receive the first message sent from the ONU; in a case where traffic is straight-through between the ONU and the firewall device, send the second message to the firewall device, the second message being obtained by adding a port tag and a first tunnel header to the first message, the port tag indicating a port of the ONU, and the first tunnel header indicating that the firewall device sends the second message to the master ONU; receive the second message that has been subjected to auditing processing or filtering processing by the firewall device; and the processing module 1102 is configured to obtain the first message and the port tag based on the second message, obtain a first processing policy configured for the port of the ONU based on the port tag, and process and forward the first message according to the first processing policy, the first processing policy including at least one of a service binding policy, a WAN binding policy, a VLAN binding policy, a port filtering policy, a priority policy, or a sending interface policy.
[0110] In a possible implementation, the first message carries information indicating the port of the ONU; the processing module 1102 is further configured to, in a case where traffic is not straight-through between the ONU and the firewall device, obtain the first processing policy configured for the port of the ONU based on the information of the port of the ONU, process the first message based on the first processing policy to obtain a third message that has been processed, and the transceiving module 1101 is further configured to, in a case where a next hop of the third message indicates the OLT and traffic is straight-through between the OLT and the firewall device, send the third message to the firewall device, receive the third message that has been subjected to auditing processing or filtering processing by the firewall device, and send the third message to the OLT.
[0111] In a possible implementation, the transceiving module 1101 is further configured to receive a fourth message sent by the OLT; in a case where traffic is straight-through between the OLT and the firewall device, send the fourth message to the firewall device; receive the fourth message that has been subjected to auditing processing or filtering processing by the firewall device, and forward the fourth message in a manner of receiving the fourth message sent by the OLT.
[0112] In a possible implementation, the processing module 1102 is further configured to, in a case where traffic is not straight-through between the OLT and the firewall device, determine, based on a destination address of the fourth message, that a destination port of the fourth message is the port of the ONU; and the transceiving module 1101 is further configured to, in a case where a next hop of the fourth message indicates the ONU and traffic is straight-through between the ONU and the firewall device, send a fifth message to the firewall device, the fifth message being obtained by adding a port tag and a second tunnel header to the fourth message, the second tunnel header indicating that the firewall device sends the fifth message to the master ONU; receive the fifth message that has been subjected to auditing processing or filtering processing by the firewall device, obtain the fourth message and the port tag based on the fifth message, and send the fourth message to the ONU based on the port of the ONU indicated by the port tag.
[0113] In a possible implementation, the processing module 1102 is further configured to save a correspondence between source address information of the first packet and a port label indicating a port of the ONU, the source address information including MAC information and ARP information; and determine, based on the destination address of the fourth packet indicating the MAC information and the ARP information, the destination port of the fourth packet as the port of the ONU in the correspondence.
[0114] It should be understood that the above Figure 11 The apparatus provided in the present application is only exemplified by the above division of functional modules in realizing its functions, and in actual applications, the above functions can be completed by different functional modules according to needs, that is, the internal structure of the device is divided into different functional modules to complete all or part of the above described functions. In addition, the apparatus and method embodiments provided in the above embodiments belong to the same concept, and the specific implementation process is detailed in the method embodiments, which will not be described here. The above Figure 11 The beneficial effects produced by the apparatus provided in the present application can be referred to the beneficial effects of the method shown in Figure 5 , which will not be described here.
[0115] For details, refer to Figure 12 , Figure 12 The structure schematic diagram of the network device 2000 provided in an example embodiment of the present application is shown. Figure 12 The network device 2000 shown is configured to perform the operations involved in the packet forwarding processing method shown in the above Figure 5 . The network device 2000 is, for example, a switch, a router, etc., and the network device 2000 can be implemented by a general bus architecture.
[0116] As shown in Figure 12 , the network device 2000 includes at least one processor 2001, a memory 2003, and at least one communication interface 2004.
[0117] The processor 2001 is, for example, a general-purpose central processing unit (CPU), a digital signal processor (DSP), a network processer (NP), a graphics processing unit (GPU), a neural-network processing units (NPU), a data processing unit (DPU), a microprocessor, or one or more integrated circuits used to implement a design described in the present application. For example, the processor 2001 includes an application-specific integrated circuit (ASIC), a programmable logic device (PLD) or other programmable logic device, transistor logic, a hardware component, or any combination thereof. The PLD is, for example, a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof. It can implement or execute various logical blocks, modules, and circuits described in combination with the disclosure of the embodiments of the present application. The processor can also be a combination of computing functions, such as a combination of one or more microprocessors, a combination of a DSP and a microprocessor, and the like.
[0118] Optionally, the network device 2000 also includes a bus. The bus is used to transmit information between the components of the network device 2000. The bus can be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 12 In the figure, only one line is used to represent the bus, but it does not mean that there is only one bus or only one type of bus.
[0119] The memory 2003 is, for example, a read-only memory (ROM) or other type of static storage device that can store static information and instructions that are not expected to change, a random access memory (RAM), or other type of dynamic storage device that can store information and instructions that are expected to change, a electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM), or other optical disk storage, a magnetic disk storage or other magnetic storage devices, or any other medium capable of storing instructions or data that is accessible to the computer, but is not limited thereto. The memory 2003 may, for example, exist independently of the processor 2001 and be connected to the processor 2001 via a bus. The memory 2003 may, for example, also be integrated with the processor 2001.
[0120] The communication interface 2004 uses any transceiver-like mechanism for communicating with other devices or a communication network, which can be an Ethernet, a radio access network (RAN), a wireless local area networks (WLAN), or the like. The communication interface 2004 can include a wired communication interface and / or a wireless communication interface. Specifically, the communication interface 2004 can be an Ethernet interface, a Fast Ethernet (FE) interface, a Gigabit Ethernet (GE) interface, an Asynchronous Transfer Mode (ATM) interface, a wireless local area networks (WLAN) interface, a cellular network communication interface, or a combination thereof. The Ethernet interface can be an optical interface, an electrical interface, or a combination thereof. In embodiments of the present application, the communication interface 2004 can be used for the network device 2000 to communicate with other devices.
[0121] In specific implementations, as an example, the processor 2001 can include one or more CPUs, such as Figure 12CPU0 and CPU1 shown in FIG. 1. Each of these processors can be a single-core CPU processor or a multi-core CPU processor. A processor herein can refer to one or more devices, circuits, and / or processing cores for processing data (e.g., computer program instructions).
[0122] In a specific implementation, as an example, the network device 2000 can include multiple processors, such as the processor 2001 and the processor 2005 shown in FIG. 2. Each of these processors can be a single-core CPU processor or a multi-core CPU processor. A processor herein can refer to one or more devices, circuits, and / or processing cores for processing data (e.g., computer program instructions). Figure 12 In a specific implementation, as an example, the network device 2000 can include multiple processors, such as the processor 2001 and the processor 2005 shown in FIG. 2. Each of these processors can be a single-core CPU processor or a multi-core CPU processor. A processor herein can refer to one or more devices, circuits, and / or processing cores for processing data (e.g., computer program instructions).
[0123] In a specific implementation, as an example, the network device 2000 can further include an output device and an input device. The output device is in communication with the processor 2001 and can display information in various ways. For example, the output device can be a liquid crystal display (LCD), a light emitting diode (LED) display device, a cathode ray tube (CRT) display device, or a projector, etc. The input device is in communication with the processor 2001 and can receive user input in various ways. For example, the input device can be a mouse, a keyboard, a touch screen device, a sensor device, etc.
[0124] In some embodiments, the memory 2003 is configured to store program code 2010 for implementing the solutions of the present application, and the processor 2001 can execute the program code 2010 stored in the memory 2003. That is, the network device 2000 can implement the packet forwarding processing method provided by the method embodiments through the processor 2001 and the program code 2010 in the memory 2003. The program code 2010 can include one or more software modules. Alternatively, the processor 2001 itself can also store program codes or instructions for implementing the solutions of the present application.
[0125] In a specific implementation, the network device 2000 of the embodiments of the present application can correspond to the master ONU in the above-mentioned various method embodiments, and the processor 2001 in the network device 2000 reads the instructions in the memory 2003, so that the network device 2000 can perform all or part of the operations performed by the master ONU. Figure 12 The network device 2000 shown in FIG. 2 can perform all or part of the operations performed by the master ONU.
[0126] Specifically, the processor 2001 is configured to receive a first packet sent from an ONU; in a case that traffic is straight-through between the ONU and a firewall device, send a second packet to the firewall device, the second packet being obtained by adding a port tag and a first tunnel header to the first packet, the port tag indicating a port of the ONU, and the first tunnel header indicating that the firewall device sends the second packet to a master ONU; receive the second packet which has been subjected to an auditing process or a filtering process by the firewall device; obtain the first packet and the port tag based on the second packet, and obtain a first processing policy configured for the port of the ONU based on the port tag, the first processing policy including at least one of a service binding policy, a WAN binding policy, a VLAN binding policy, a port filtering policy, a priority policy, or a sending interface policy; and process and forward the first packet according to the first processing policy.
[0127] Other optional embodiments are not described here for brevity.
[0128] The network device 2000 can also correspond to the network device 1000 described above. Figure 11 The packet forwarding processing apparatus shown in FIG. 10 includes the functional modules shown in FIG. 10. Each functional module in the packet forwarding processing apparatus is implemented by software of the network device 2000. In other words, the functional modules included in the packet forwarding processing apparatus are generated after the processor 2001 of the network device 2000 reads the program code 2010 stored in the storage 2003.
[0129] The network device 2000 can also correspond to the network device 1000 described above. Figure 5 The steps of the packet forwarding processing method shown in FIG. 10 are completed by the integrated logic circuits of hardware or instructions in the form of software in the processor of the network device 2000. The steps of the method disclosed in the embodiments of the present application can be directly embodied as being completed by a hardware processor, or being completed by a combination of hardware and software modules in the processor. The software module can be located in a storage medium in the art such as random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, register, or the like. The storage medium is located in the storage, and the processor reads information in the storage, and combines hardware to complete the steps of the above method. To avoid repetition, the details are not described here.
[0130] The network device 2100 shown in FIG. 11 is configured to perform all or part of the operations involved in the packet forwarding processing method shown in FIG. 10. The network device 2100 is, for example, a switch, a router, or the like, and can be implemented by a general bus architecture. Figure 13 Figure 13 The network device 2100 shown in FIG. 11 is configured to perform all or part of the operations involved in the packet forwarding processing method shown in FIG. 10. The network device 2100 is, for example, a switch, a router, or the like, and can be implemented by a general bus architecture. Figure 13 Figure 5 As shown in FIG. 11, the network device 2100 includes a processor 2101, a memory 2103, and a bus 2102.
[0131] As shown in FIG. 11, the network device 2100 includes a processor 2101, a memory 2103, and a bus 2102. Figure 13 As shown, the network device 2100 includes a main board 2110 and an interface board 2130.
[0132] The main board 2110, also referred to as a main processing unit (MPU) or a route processor card, is configured to control and manage various components in the network device 2100, including route computation, device management, device maintenance, and protocol processing functions. The main board 2110 includes a central processing unit 2111 and a memory 2112.
[0133] The interface board 2130, also referred to as a line processing unit (LPU), a line card, or a service board, is configured to provide various service interfaces and implement data packet forwarding. The service interfaces include, but are not limited to, Ethernet interfaces, POS (Packet over SONET / SDH) interfaces, and the like. The Ethernet interface is, for example, a Flexible Ethernet Client (FlexE Client). The interface board 2130 includes a central processing unit 2131, a network processor 2132, a forwarding table entry memory 2134, and a physical interface card (PIC) 2133.
[0134] The central processing unit 2131 on the interface board 2130 is configured to control and manage the interface board 2130 and communicate with the central processing unit 2111 on the main board 2110.
[0135] The network processor 2132 is configured to implement the forwarding processing of the packet. The network processor 2132 can be a forwarding chip. The forwarding chip can be a network processor (NP). In some embodiments, the forwarding chip can be implemented by an application-specific integrated circuit (ASIC) or a field programmable gate array (FPGA). Specifically, the network processor 2132 is configured to forward the received packet based on a forwarding table stored in the forwarding table entry memory 2134, and if the destination address of the packet is the address of the network device 2100, the packet is sent to the CPU (such as the central processor 2131) for processing; if the destination address of the packet is not the address of the network device 2100, the next hop and the out interface corresponding to the destination address are found from the forwarding table according to the destination address, and the packet is forwarded to the out interface corresponding to the destination address. The processing of the uplink packet can include the processing of the packet entry interface and the forwarding table lookup; the processing of the downlink packet can include the forwarding table lookup, and the like. In some embodiments, the central processor can also perform the function of the forwarding chip, such as implementing software forwarding based on a general-purpose CPU, so that the interface board does not need a forwarding chip.
[0136] The physical interface card 2133 is configured to implement the interfacing function of the physical layer, and the original traffic enters the interface board 2130 through the physical interface card 2133, and the processed packet is sent out from the physical interface card 2133. The physical interface card 2133 is also called a daughter card, which can be installed on the interface board 2130 and is responsible for converting the optical and electrical signals into packets and forwarding the packets to the network processor 2132 for processing after performing the legality check. In some embodiments, the central processor 2131 can also perform the function of the network processor 2132, such as implementing software forwarding based on a general-purpose CPU, so that the physical interface card 2133 does not need a network processor 2132.
[0137] Optionally, the network device 2100 includes a plurality of interface boards, for example, the network device 2100 further includes an interface board 2140, the interface board 2140 includes a central processor 2141, a network processor 2142, a forwarding table entry memory 2144 and a physical interface card 2143. The functions and implementation manners of the components in the interface board 2140 are the same as or similar to those of the interface board 2130, and are not described herein again.
[0138] Optionally, the network device 2100 further includes a switch fabric 2120. The switch fabric 2120 can also be referred to as a switch fabric unit (SFU). In the case that the network device 2100 has multiple interface boards, the switch fabric 2120 is used to complete data exchange between the interface boards. For example, the interface board 2130 and the interface board 2140 can communicate through the switch fabric 2120.
[0139] The main control board 2110 is coupled with the interface boards. For example, the main control board 2110, the interface board 2130 and the interface board 2140, and the switch fabric 2120 are connected through a system bus and a system backboard to realize intercommunication. In a possible implementation, an inter-process communication (IPC) channel is established between the main control board 2110 and the interface board 2130 and the interface board 2140, and the main control board 2110 and the interface board 2130 and the interface board 2140 communicate through the IPC channel.
[0140] In logic, the network device 2100 includes a control plane and a forwarding plane. The control plane includes the main control board 2110 and the central processor 2111, and the forwarding plane includes various components that perform forwarding, such as the forwarding table item memory 2134, the physical interface card 2133 and the network processor 2132. The control plane performs functions such as generating a forwarding table, processing signaling and protocol packets, configuring and maintaining the state of the network device, and the like. The control plane generates a forwarding table and delivers the forwarding table to the forwarding plane. In the forwarding plane, the network processor 2132 performs table lookup and forwarding on a packet received by the physical interface card 2133 based on the forwarding table delivered by the control plane. The forwarding table delivered by the control plane can be stored in the forwarding table item memory 2134. In some embodiments, the control plane and the forwarding plane can be completely separated and not on the same network device.
[0141] It's worth noting that a network device may have one or more main control boards, including a primary and a backup main control board. It may also have one or more interface boards; the more powerful the network device's data processing capabilities, the more interface boards it provides. Each interface board may also have one or more physical interface cards. A switching board may or may not exist; multiple boards can share the load and provide redundancy. In a centralized forwarding architecture, the network device may not need a switching board, as the interface boards handle the entire system's business data processing. In a distributed forwarding architecture, the network device can have at least one switching board, which enables data exchange between multiple interface boards, providing high-capacity data exchange and processing capabilities. Therefore, the data access and processing capabilities of a distributed architecture network device are greater than those of a centralized architecture network device. Alternatively, the network device can also be a single board, without a switching board. The functions of the interface board and the main control board are integrated on this one board. In this case, the central processing unit (CPU) on the interface board and the CPU on the main control board can be combined into a single CPU to perform the combined functions. This type of network device has lower data exchange and processing capabilities (e.g., low-end switches or routers). The specific architecture adopted depends on the specific network deployment scenario, and no restrictions are imposed here.
[0142] In a specific embodiment, network device 2100 corresponds to the above. Figure 11 The diagram shows a message forwarding and processing apparatus applied to the master ONU. In some embodiments, Figure 11 The transceiver module 1101 in the message forwarding processing device shown is equivalent to the physical interface card 2133 in the network device 2100, and the processing module 1102 is equivalent to the central processing unit 2111 or network processor 2132 in the network device 2100.
[0143] This application embodiment also provides a packet forwarding processing system, which includes a master ONU, a slave ONU, and a firewall device, wherein the master ONU is... Figure 12 The network device shown is 2000 or Figure 13 The network device 2100 shown is connected to the ONU. Figure 12 The network device shown is 2000 or Figure 13 The network device 2100 shown is a firewall device. Figure 12 The network device shown is 2000 or Figure 13 The network device 2100 shown above. The packet forwarding methods performed by the master ONU, slave ONUs, and firewall devices can be found above. Figure 5 The relevant descriptions of the embodiments shown will not be repeated here.
[0144] It is to be understood that the above-described processor can be a CPU, and can also be other general-purpose processors, digital signal processors (DSP), application specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gates or transistor logic components, discrete hardware components, and the like. The general-purpose processor can be a microprocessor or any conventional processor, and the like. It is to be noted that the processor can be an advanced RISC machines (ARM) architecture processor.
[0145] Further, in an optional embodiment, the above-described memory can include a read-only memory and a random access memory, and provide instructions and data to the processor. The memory can also include a non-volatile random access memory. For example, the memory can also store device type information.
[0146] The memory can be a volatile memory or a non-volatile memory, or can include both volatile and non-volatile memories. Among them, the non-volatile memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically EPROM (EEPROM) or a flash memory. The volatile memory can be a random access memory (RAM) used as an external cache. By way of example but not limitation, many forms of RAM are available. For example, static random access memory (SRAM), dynamic random access memory (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchlink DRAM (SLDRAM) and direct rambus RAM (DRAM) can be used.
[0147] The embodiment of the present application further provides a computer readable storage medium, at least one instruction is stored in the storage medium, the instruction is loaded and executed by a processor, so that the computer implements the packet forwarding processing method of any one of the above.
[0148] The embodiment of the present application further provides a computer program (product), when the computer program is executed by a computer, the processor or the computer can execute the corresponding steps and / or processes in the above method embodiments.
[0149] The embodiment of the present application further provides a chip, comprising a processor, for calling and running instructions stored in a memory, so that a communication device installed with the chip executes the packet forwarding processing method of any one of the above.
[0150] The embodiment of the present application further provides another chip, comprising: an input interface, an output interface, a processor and a memory, the input interface, the output interface, the processor and the memory are connected through internal connection paths, the processor is used for executing codes in the memory, when the codes are executed, the processor is used for executing the packet forwarding processing method of any one of the above.
[0151] In the above embodiments, all or part of them can be realized by software, hardware, firmware or any combination thereof. When realized by software, all or part of them can be realized in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions according to the present application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network or other programmable device. The computer instructions can be stored in a computer readable storage medium or transferred from one computer readable storage medium to another, for example, the computer instructions can be transferred from one website, computer, server or data center to another through wired (such as coaxial cable, optical fiber, digital subscriber line) or wireless (such as infrared, wireless, microwave, etc.) mode. The computer readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server, data center, etc. containing one or more available media sets. The available media can be magnetic media (such as floppy disk, hard disk, magnetic tape), optical media (such as DVD) or semiconductor media (such as solid state disk) and the like.
[0152] Those skilled in the art can appreciate that, in combination with the method steps and modules described in the embodiments disclosed herein, all or part of the steps can be implemented by software, hardware, firmware or any combination thereof. In order to clearly illustrate the interchangeability of hardware and software, the steps and components of the embodiments have been described in the above description in general terms. Whether the functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.
[0153] Those skilled in the art can understand that all or part of the steps of the above-mentioned embodiments can be completed by hardware, or by programs instructing related hardware, which can be stored in a computer-readable storage medium. The storage medium mentioned above can be a read-only memory, a magnetic disk or an optical disk, etc.
[0154] When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer program instructions. As an example, the method of the embodiments of the present application can be described in the context of machine-executable instructions, such as program modules that are executed by devices included in the target real or virtual processor. Generally, program modules include routines, programs, libraries, objects, classes, components, data structures, etc., which perform specific tasks or implement specific abstract data structures. In various embodiments, the functions of the program modules can be combined or divided among the described program modules. Machine-executable instructions for program modules can be executed within a local or distributed device. In a distributed device, program modules can be located in both local and remote storage media.
[0155] The computer program code for implementing the method of the embodiments of the present application can be written in one or more programming languages. These computer program codes can be provided to the processor of a general-purpose computer, a special-purpose computer or other programmable data processing apparatus, so that when the computer program codes are executed by the computer or other programmable data processing apparatus, the functions / operations specified in the flowcharts and / or block diagrams are implemented. The program codes can be executed entirely on the computer, partially on the computer, as a separate software package, partially on the computer and partially on a remote computer, or entirely on a remote computer or server.
[0156] In the context of the embodiments of the present application, computer program codes or related data can be carried by any appropriate carrier to enable the device, apparatus or processor to perform the various processes and operations described above. Examples of the carrier include a signal, a computer readable medium, etc.
[0157] Examples of a signal can include electrical, optical, radio frequency, sound, or other forms of propagated signals, such as carrier waves, infrared signals, etc.
[0158] A machine-readable medium can be any tangible medium that contains or stores the program for use by or in connection with an instruction execution system, apparatus, or device. The machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include but not limited to an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples of the machine-readable storage medium include an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), and a digital versatile disc (DVD), or any suitable combination of the foregoing.
[0159] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working process of the above-described system, device and module can refer to the corresponding process in the foregoing method embodiments, which will not be repeated here.
[0160] In several embodiments provided in the present application, it should be understood that the disclosed system, device and method can be implemented in other ways. For example, the device embodiments described above are merely illustrative, for example, the division of the module is only a logical function division, and actual implementation can have another division manner, for example, a plurality of modules or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the displayed or discussed each other can be indirect coupling or communication connection through some interfaces, devices or modules, and can also be electrical, mechanical or other form of connection.
[0161] The module described as a separate component can or can not be physically separated, and the component displayed as a module can or can not be a physical module, that is, it can be located in one place, or can be distributed to a plurality of network modules. Part or all of the modules can be selected according to actual needs to achieve the purpose of the embodiments of the present application.
[0162] In addition, each functional module in each embodiment of the present application can be integrated into a processing module, or each module can exist physically, or two or more modules can be integrated into one module. The above integrated module can be realized in the form of hardware or in the form of software functional module.
[0163] The integrated module, if implemented in the form of a software function module and sold or used as an independent product, can be stored in a computer readable storage medium. Based on such understanding, the technical solutions of the present application essentially or the part that contributes to the prior art, or the whole or part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium, and includes a plurality of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods in the various embodiments of the present application. The aforementioned storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, and various media that can store program codes.
[0164] The terms "first", "second", and the like in the present application are used to distinguish between items or similar items having substantially the same function and action. It should be understood that there is no logical or chronological dependency between "first", "second", and "nth", and the number and execution order are not limited. It should also be understood that although the following description uses the terms first, second, and the like to describe various elements, these elements should not be limited by the terms. These terms are only used to distinguish one element from another. For example, without departing from the scope of various examples, a first image can be referred to as a second image, and similarly, a second image can be referred to as a first image. The first image and the second image can both be images, and in some cases, can be separate and distinct images.
[0165] It should also be understood that in various embodiments of the present application, the size of the serial number of each process does not mean the order of execution, and the execution order of each process should be determined by its function and inherent logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
[0166] The term "at least one" in the present application means one or more, and the term "a plurality of" in the present application means two or more, for example, a plurality of second messages means two or more second messages. The terms "system" and "network" are often used interchangeably in this document.
[0167] It should be understood that the terms used in the description of various described examples herein are only for the purpose of describing specific examples and are not intended to be limiting. As used in the description of various described examples and the appended claims, the singular forms "a", "an", and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise.
[0168] It should also be understood that, as used in this specification, the terms "comprises", "comprising", "includes", "including", "with" or "comprising", specifies the presence of stated features, integers, steps, operations, elements, and / or components but does not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof.
[0169] It should also be understood that the terms "comprises", "comprising", "includes", "including", "with" or "comprising", specifies the presence of stated features, integers, steps, operations, elements, and / or components but does not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof.
[0170] It should also be understood that the terms "comprises", "comprising", "includes", "including", "with" or "comprising", specifies the presence of stated features, integers, steps, operations, elements, and / or components but does not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof.
[0171] It should be understood that a determination of B based on A does not mean that B is determined only based on A, but B can also be determined based on A and / or other information.
[0172] It should also be understood that the terms "one embodiment", "an embodiment", "one possible implementation", as used in this specification, mean that a particular feature, structure, or characteristic described in connection with an embodiment or implementation is included in at least one implementation of the application. Therefore, the appearance of the phrases "in one embodiment" or "in an embodiment", "one possible implementation", in various places in the specification are not necessarily referring to the same embodiment or implementation. Furthermore, the particular features, structures, or characteristics can be combined in any suitable manner in one or more embodiments.
[0173] The above description is only optional embodiments of the application, and is not used to limit the application, any modification, equivalent replacement, improvement, etc. made within the principles of the application should be included in the protection scope of the application.
Claims
1. A method for processing forwarding of a packet, characterized by, The method is applied to an optical network unit (ONU), and the method comprises: receiving a first packet sent by a slave ONU; in a case where traffic is straight-through between the slave ONU and a firewall device, sending a second packet to the firewall device, the second packet being obtained by adding a port tag and a first tunnel header to the first packet, the port tag indicating a port of the slave ONU, and the first tunnel header indicating that the firewall device sends the second packet to a master ONU; receiving the second packet that has been subjected to auditing processing or filtering processing by the firewall device, obtaining the first packet and the port tag based on the second packet, and obtaining a first processing policy configured for the port of the slave ONU based on the port tag, the first processing policy comprising at least one of a service binding policy, a wide area network (WAN) binding policy, a local area network (LAN) binding policy, a port filtering policy, a priority policy, or a sending interface policy; processing and forwarding the first packet according to the first processing policy.
2. The method of claim 1, wherein, The first packet carries information indicating the port of the slave ONU; and after receiving the first packet sent by the slave ONU, the method further comprises: in a case where traffic is not straight-through between the slave ONU and the firewall device, obtaining the first processing policy configured for the port of the slave ONU based on the information of the port of the slave ONU, and processing the first packet based on the first processing policy to obtain a third packet processed; in a case where a next hop of the third packet indicates an optical line terminal (OLT) and traffic is straight-through between the OLT and the firewall device, sending the third packet to the firewall device; receiving the third packet that has been subjected to auditing processing or filtering processing by the firewall device, and sending the third packet to the OLT.
3. The method according to claim 1 or 2, characterized in that, The method further comprises: receiving a fourth packet sent by an optical line terminal (OLT); in a case where traffic is straight-through between the OLT and the firewall device, sending the fourth packet to the firewall device; receiving the fourth packet that has been subjected to auditing processing or filtering processing by the firewall device, and forwarding the fourth packet in the same manner as receiving the fourth packet sent by the OLT.
4. The method of claim 3, wherein, After receiving the fourth packet sent by the optical line terminal (OLT), the method further comprises: in a case where traffic is not straight-through between the OLT and the firewall device, determining, based on a destination address of the fourth packet, that a destination port of the fourth packet is the port of the slave ONU; in a case where a next hop of the fourth packet indicates the slave ONU and traffic is straight-through between the slave ONU and the firewall device, sending a fifth packet to the firewall device, the fifth packet being obtained by adding the port tag and a second tunnel header to the fourth packet, the second tunnel header indicating that the firewall device sends the fifth packet to the master ONU; The fifth packet received by the firewall device for auditing or filtering is received, the fourth packet and the port label are obtained based on the fifth packet, and the fourth packet is sent to the slave ONU based on the port of the slave ONU indicated by the port label.
5. The method of claim 4, wherein, After the first packet and the port label are obtained based on the second packet, the method further includes: Correspondence between source address information of the first packet and the port of the slave ONU indicated by the port label is saved, and the source address information includes media access control (MAC) information and address resolution protocol (ARP) information. The destination port of the fourth packet is determined as the port of the slave ONU based on the destination address of the fourth packet, and includes: The destination port of the fourth packet is determined as the port of the slave ONU in the correspondence based on the MAC information and the ARP information indicated by the destination address of the fourth packet.
6. A packet forwarding processing apparatus characterized by comprising: The method is applied to a master optical network unit (ONU), and the device includes: A transceiver module is configured to perform receiving and / or sending operations in the method of any one of claims 1-5; A processing module is configured to perform operations other than the receiving and / or sending operations in the method of any one of claims 1-5.
7. A network device, comprising: The network device includes a processor coupled with a memory, and the memory stores at least one program instruction or code, which is loaded and executed by the processor to enable the network device to implement the packet forwarding processing method of any one of claims 1-5.
8. A packet forwarding processing system characterized by comprising: The packet forwarding processing system includes a master optical network unit (ONU), a slave ONU, and a firewall device; the slave ONU is configured to send a first packet to the master ONU; the master ONU is configured to implement the method of any one of claims 1-5; and the firewall device is configured to receive a second packet sent by the master ONU, the second packet being obtained by adding a port label and a first tunnel header to the first packet, and the firewall device is further configured to send the second packet subjected to auditing or filtering by the firewall device to the master ONU.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores at least one instruction, which is loaded and executed by the processor to enable the computer to implement the packet forwarding processing method of any one of claims 1-5.
10. A computer program product, characterised in that, The computer program product includes computer program code, which is loaded and executed by the computer to enable the computer to implement the packet forwarding processing method of any one of claims 1-5.
Citation Information
Patent Citations
Controllable multicast system under environment of passive optical network, and implementing method
CN101094087A
Cascade ONT processing method, device and system
CN115701138A