Message transmission method and SSL VPN device
By receiving the source packet sharding in the SSL VPN device and judging its size, if it exceeds the MTU, it returns the reshaping indication to make the source side reshape, which solves the problem of the impact of the SSL VPN device on the performance characteristics of the source packet sharding, and achieves more accurate packet forwarding.
Patent Information
- Application Number
- CN202510357769.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-24
- Publication Date
- 2025-06-27
- Estimated Expiration
- 2045-03-24
AI Technical Summary
After receiving the data packet sharding sent by the source, the SSL VPN device will shard according to the MTU, resulting in an impact on the performance characteristics of the data packet sharding at the source, analysis errors and other problems.
In an SSL VPN device, after receiving the original data packet sent by the source end, it is determined whether its size exceeds the destination end MTU. If it exceeds, return the reshaping indication to the source end, causing the source end to reshape. The reshaping size of the data packet after reshaping is smaller than the original shard size.
Through this method, SSL VPN devices are avoided from affecting the performance characteristics of source-side packet sharding, reduce the impact on source-side packets, and improve the accuracy of packet forwarding.
Smart Images

Figure CN120223646A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technologies, and in particular, to a message transmission method and a Secure Sockets Layer Virtual Private Network (SSL VPN) device. Background Art
[0002] SSL VPN is a VPN technology based on the SSL / TLS protocol that can provide remote secure connection services. Network devices based on SSL VPN technology are usually referred to as SSL VPN devices, which are typically used to forward messages between a remote source and a destination to provide secure connection services. Among them, TLS is the abbreviation of Transport Layer Security.
[0003] In practical applications, after an SSL VPN device receives each packet fragment of the same data packet sent by the source, it will reconstruct the packet fragments and fragment the reconstructed data packet according to the Maximum Transmission Unit (MTU) between the SSL VPN device and the destination, and then sequentially send each packet fragment obtained by fragmentation to the destination to implement the forwarding of the data packet sent by the source.
[0004] However, the above method of fragmenting again according to the MTU between the SSL VPN device and the destination will affect the performance characteristics of the packet fragments sent by the source. For example, when it is necessary to analyze the source behavior based on the packet fragments sent by the source, analysis errors will occur. Summary of the Invention
[0005] In view of this, this application provides a message transmission method and an SSL VPN device to reduce the impact of the SSL VPN device on the data packets sent by the source.
[0006] An embodiment of this application provides a message transmission method, which is applied to an SSL VPN device between a source and a destination. The method includes:
[0007] Receiving each original packet fragment of the same original data packet sent by the source;
[0008] If it is determined through the received original packet fragments that the size of the original data packet is greater than the first MTU of the data transmission channel between the SSL VPN device and the destination, then determine whether the size of each original packet fragment is less than or equal to the first MTU;
[0009] When the size of each fragment of the original data packet is less than or equal to the first MTU, forward each fragment of the original data packet to the destination end;
[0010] When the size of at least one fragment of the original data packet is greater than the first MTU, return a re-fragmentation indication to the source end, so that the source end re-fragments the original data packet based on the re-fragmentation indication and sends it to the SSL VPN device; the size of the data packet fragments obtained after re-fragmentation is smaller than the size of the data packet fragments obtained before re-fragmentation.
[0011] An embodiment of the present application further provides an SSL VPN device, which is applied between a source end and a destination end; the SSL VPN device includes at least one board;
[0012] Any board is used to receive each fragment of the original data packet belonging to the same original data packet sent by the source end, and determine whether the size of the original data packet is greater than the first MTU of the data transmission channel between the SSL VPN device and the destination end according to the received fragments of the original data packet;
[0013] Among them, the board on the SSL VPN device used to send the original data packet to the destination end is used to judge whether the size of each fragment of the original data packet is less than or equal to the first MTU if the size of the original data packet is greater than the first MTU; when the size of each fragment of the original data packet is less than or equal to the first MTU, forward each fragment of the original data packet to the destination end; when the size of at least one fragment of the original data packet is greater than the first MTU, return a re-fragmentation indication to the source end, so that the source end re-fragments the original data packet based on the re-fragmentation indication and sends it to the SSL VPN device; the size of the data packet fragments obtained after re-fragmentation is smaller than the size of the data packet fragments obtained before re-fragmentation.
[0014] As can be seen from the above technical solutions, in the embodiments of the present application, when the size of the original data packet sent by the source end is greater than the first MTU of the data transmission channel between the SSL VPN device and the destination end, first determine whether the sizes of the original data packet fragments belonging to the original data packet are all less than or equal to the first MTU. If so, the original data packet fragments can be directly forwarded to the destination end. If not, that is, the size of at least one original data packet fragment is greater than the first MTU, a re-fragmentation instruction can be returned to the source end so that the source end re-fragments the original data packet and sends it to the SSL VPN device, where the size of the data packet fragments obtained after re-fragmentation is smaller than the size of the data packet fragments obtained before re-fragmentation, rather than directly re-fragmenting the data packet sent by the source end according to the first MTU as in the prior art. This can avoid the impact on the performance characteristics of the data packet fragments sent by the source end due to re-fragmentation, thereby effectively reducing the impact of the SSL VPN device on the data packet sent by the source end. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] The accompanying drawings herein are incorporated into the specification and form a part of this application, showing embodiments consistent with this application and, together with the specification, are used to explain the principles of this application.
[0016] Figure 1 It is a schematic diagram of the method process provided by the embodiments of this application.
[0017] Figure 2 It is another schematic diagram of the method process provided by the embodiments of this application.
[0018] Figure 3 It is yet another schematic diagram of the method process provided by the embodiments of this application.
[0019] Figure 4 It is yet another schematic diagram of the method process provided by the embodiments of this application.
[0020] Figure 5 It is a schematic diagram of the implementation of the application scenario provided by the embodiments of this application.
[0021] Figure 6 It is a schematic diagram of the structure of the SSL VPN device provided by the embodiments of this application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0022] In order to enable those skilled in the art to better understand the technical solutions provided by the embodiments of this application and make the above-mentioned objects, features, and advantages of the embodiments of this application more obvious and understandable, the technical solutions in the embodiments of this application will be further described in detail below with reference to the accompanying drawings.
[0023] See Figure 1 , Figure 1This is the flowchart of the method provided by the embodiment of the present application. This method is applied to the SSL VPN device between the source end and the destination end. As an embodiment, the source end can be a client, and the destination end can be a server corresponding to the client; it should be noted that this is only an exemplary illustration, and the form of the above source end and destination end is not specifically limited in this embodiment.
[0024] As Figure 1 shown, this process may include the following steps:
[0025] Step 101, receive each original packet fragment of the same original packet sent by the source end.
[0026] In this embodiment, as an example, when the source end sends the above original packet to the SSL VPN device, it will first fragment the original packet according to the source MTU of the data transmission channel between the source end and the SSL VPN device to obtain each original packet fragment, and then send each original packet fragment to the SSL VPN device in sequence. Based on this, the SSL VPN device receives each original packet fragment of the original packet sent by the source end.
[0027] Optionally, in this embodiment, the above original packet may refer to a packet based on the Internet Protocol Version 6 (IPv6) protocol. This embodiment is not specifically limited thereto.
[0028] Step 102, if it is determined from the received original packet fragments that the size of the original packet is greater than the first MTU of the data transmission channel between the SSL VPN device and the destination end, then determine whether the size of each original packet fragment is less than or equal to the first MTU; if so, execute step 103, if not, execute step 104.
[0029] Step 103, forward each original packet fragment to the destination end.
[0030] In this embodiment, when the size of each packet fragment is less than or equal to the first MTU, each packet fragment can be directly forwarded to the destination end through the second board card in sequence, thus realizing the forwarding of the original packet.
[0031] Step 104, return a re-fragmentation indication to the source end, so that the source end re-fragments the original packet based on the re-fragmentation indication and sends it to the SSL VPN device; the size of the packet fragments obtained after re-fragmentation is smaller than the size of the packet fragments obtained before re-fragmentation.
[0032] In this embodiment, if the SSL VPN device determines, based on the received original data packet fragments, that the size of the original data packet is greater than the first MTU, it cannot directly forward the original data packet to the destination. In this case, it can first determine whether the sizes of all the original data packet fragments belonging to the original data packet are less than or equal to the first MTU.
[0033] If the sizes of all the original data packet fragments are less than or equal to the first MTU, the original data packet fragments can be directly forwarded to the destination in sequence.
[0034] If the size of at least one of the original data packet fragments is greater than the first MTU, a re-fragmentation instruction can be returned to the source end so that the source end re-fragments the original data packet based on the re-fragmentation instruction and sends it to the SSL VPN device. Among them, the size of the data packet fragments obtained after re-fragmentation is smaller than the size of the data packet fragments obtained before re-fragmentation.
[0035] In this embodiment, as an example, if the SSL VPN device determines, based on the received original data packet fragments, that the size of the original data packet is less than or equal to the first MTU, the original data packet can be directly forwarded to the destination.
[0036] In this embodiment, as an example, the re-fragmentation instruction at least includes a third MTU, so that the source end re-fragments the original data packet according to the third MTU and sends it to the SSL VPN device; the third MTU is less than or equal to the first MTU. This can ensure that the sizes of all the data packet fragments obtained after re-fragmentation are less than or equal to the first MTU. Based on this, after the SSL VPN device receives the data packet fragments obtained after re-fragmentation sent by the source end, it can directly forward the data packet fragments obtained after re-fragmentation to the destination to achieve the forwarding of the original data packet.
[0037] Thus far, the Figure 1 shown process is completed.
[0038] Through Figure 1As can be seen from the process shown, in the embodiment of the present application, when the size of the original data packet sent by the source end is greater than the first MTU of the data transmission channel between the SSL VPN device and the destination end, first determine whether the sizes of the original data packet fragments belonging to the original data packet are all less than or equal to the first MTU. If so, the original data packet fragments can be directly forwarded to the destination end. If not, that is, the size of at least one original data packet fragment is greater than the first MTU, a re-fragmentation instruction can be returned to the source end so that the source end re-fragments the original data packet and sends it to the SSL VPN device. The size of the data packet fragments obtained after re-fragmentation is smaller than the size of the data packet fragments obtained before re-fragmentation, rather than directly re-fragmenting the data packet sent by the source end according to the first MTU as in the prior art. This can avoid the impact on the performance characteristics of the data packet fragments sent by the source end due to re-fragmentation, thereby effectively reducing the impact of the SSL VPN device on the data packet sent by the source end.
[0039] The above message transmission method will be further described below:
[0040] In this embodiment, as an example, refer to Figure 2 As shown, after determining that the size of the original data packet is greater than the first MTU and before determining whether the sizes of the original data packet fragments are all less than or equal to the first MTU, the method further includes the following steps:
[0041] Step 201, if the SSL VPN device includes multiple boards, determine whether the received original data packet fragments meet the preset inter-board data transmission requirements; if so, execute step 202, if not, execute step 203.
[0042] In this embodiment, as an example, when the SSL VPN device includes multiple boards, if the board on which the original data packet fragments are received on the SSL VPN device is different from the board used to send the original data packet to the destination end, the received original data packet fragments need to be forwarded to the board on the SSL VPN device used to send the original data packet to the destination end for subsequent processing. Based on this, after receiving the original data packet fragments, determine whether the received original data packet fragments meet the preset inter-board data transmission requirements. As for how to specifically determine the board on the SSL VPN device used to send the original data packet to the destination end, it will be described by way of example below and will not be elaborated here for the time being.
[0043] In this embodiment, as an example, in this step, it is determined whether each received original data packet fragment meets the preset inter-board data transmission requirements. In specific implementation, for example, it may include: if the size of at least one original data packet fragment among the original data packet fragments is greater than the second MTU of the data transmission channel between boards, it is determined that the original data packet fragments do not meet the inter-board data transmission requirements; if each original data packet fragment is less than or equal to the second MTU, it is determined that the original data packet fragments meet the inter-board data transmission requirements.
[0044] Step 202: Transmit each original data packet fragment within multiple boards; when each original data packet fragment arrives at the board of the SSL VPN device for sending the original data packet to the destination end, continue to execute the step of determining whether the sizes of all the original data packet fragments are less than or equal to the first MTU.
[0045] In this embodiment, as an example, in this step, when transmitting each original data packet fragment within multiple boards, in specific implementation, for example, it may be: sequentially send each original data packet fragment to the board of the above-mentioned SSL VPN device for sending the original data packet to the destination end.
[0046] Step 203: Restore the original data packet from each original data packet fragment, fragment the restored original data packet to obtain at least two intermediate data packet fragments, so that each intermediate data packet fragment meets the inter-board data transmission requirements, and transmit each intermediate data packet fragment and the fragmentation information of the original data packet fragment sent by the source end within multiple boards. Then continue to execute Step 204.
[0047] In this embodiment, as an example, in this step, when restoring the original data packet from each original data packet fragment, in specific implementation, for example, it may be: according to a preset recombination method, recombine each original data packet fragment to obtain the original data packet. Here, the recombination method is not specifically limited and can be flexibly set according to actual application requirements.
[0048] In this embodiment, as an example, in this step, when fragmenting the restored original data packet, in specific implementation, for example, it may be: fragment the restored original data packet according to the second MTU of the data transmission channel between the boards as mentioned above. In this way, the fragmentation sizes of the obtained intermediate data packet fragments are all less than or equal to the second MTU, that is, each intermediate data packet fragment meets the inter-board data transmission requirements.
[0049] As for how to specifically transmit each intermediate data packet fragment and the fragmentation information of the original data packet fragment sent by the source end within multiple boards in this step, examples will be described below and will not be elaborated here for the time being.
[0050] Step 204, when each intermediate data packet fragment arrives at the board of the SSL VPN device for sending the original data packet to the destination end, restore the original data packet according to each intermediate data packet fragment again, and fragment the original data packet restored again according to the fragmentation information to obtain each original data packet fragment, and continue to execute the step of determining whether the sizes of each original data packet fragment are all less than or equal to the first MTU.
[0051] In this embodiment, the specific implementation manner of restoring the original data packet according to each intermediate data packet fragment in this step is similar to the specific implementation manner of restoring the original data packet according to each original data packet fragment above; for example, as an embodiment, according to a preset recombination method, each intermediate data packet fragment is recombined to obtain the original data packet.
[0052] In this embodiment, as an embodiment, the above fragmentation information may include: the fragmentation size of the original data packet fragment. Optionally, the fragmentation information in this embodiment may be, for example, the fragmentation size of the largest original data packet fragment among the original data packet fragments sent by the source end. As can be seen from the previous description, since each original data packet fragment sent by the source end is obtained by fragmenting the original data packet according to the source MTU of the data transmission channel between the source end and the SSL VPN device, the fragmentation size of the largest original data packet fragment among the original data packet fragments sent by the source end is the same as the above source MTU.
[0053] Based on this, fragmenting the original data packet restored again according to the fragmentation information in this embodiment is equivalent to fragmenting the original data packet according to the source MTU. Therefore, in this way, each original data packet fragment can be obtained, that is, it can be ensured that the data packet fragments obtained by re-fragmentation are as consistent as possible with the original data packet fragments sent by the source end, thereby avoiding the impact of re-fragmentation on the performance characteristics of the data packet fragments sent by the source end, and effectively reducing the impact of the SSL VPN device on the data packets sent by the source end.
[0054] The following describes how to transmit each intermediate data packet fragment and the fragmentation information of the original data packet fragment sent by the source end within multiple boards:
[0055] In this embodiment, there are many ways to implement the transmission of each intermediate data packet fragment and the fragmentation information of the original data packet fragment sent by the source end within multiple boards. For example, as an embodiment, refer to Figure 3 As shown, the following steps may be included in the specific implementation:
[0056] Step 301, obtain the fragmentation information of the original data packet fragment sent by the source end.
[0057] Step 302: Carry the obtained sharding information in each intermediate data packet shard and transmit it within multiple boards.
[0058] In this embodiment, as an example, after obtaining the sharding information, the sharding information can also be carried in one of the intermediate data packet shards and transmitted within multiple boards. Specifically, for example, the sharding information can be carried in the first intermediate data packet shard obtained by sharding and transmitted within multiple boards.
[0059] Optionally, this embodiment can add a custom extension field to the intermediate data packet shard, and the above sharding information can be carried in the custom extension field to implement carrying the sharding information in the intermediate data packet shard.
[0060] The following describes the message transmission method in the case where the SSL VPN device includes one board:
[0061] In this embodiment, as an example, if the SSL VPN device includes one board, there will be no inter-board data transmission. In this case, as Figure 4 shown, the above message transmission method can include the following steps:
[0062] Step 401: The SSL VPN device receives, through the board, each original data packet shard of the same original data packet sent by the source end.
[0063] Step 402: If it is determined, based on the received original data packet shards, that the size of the original data packet is greater than the first MTU of the data transmission channel between the SSL VPN device and the destination end, then determine whether the size of each original data packet shard is less than or equal to the first MTU; if so, execute Step 403, and if not, that is, the size of at least one original data packet shard is greater than the first MTU, then execute Step 404.
[0064] Step 403: Forward each original data packet shard to the destination end through the board.
[0065] Step 404: Return a re-sharding indication to the source end through the board, so that the source end re-shards the original data packet based on the re-sharding indication and sends it to the SSL VPN device; the size of the data packet shards obtained after re-sharding is smaller than the size of the data packet shards obtained before re-sharding.
[0066] The following describes how to specifically determine the board on the SSL VPN device used to send the original data packet to the destination end:
[0067] In this embodiment, as an example, the above-mentioned board on the SSL VPN device for sending the original data packet to the destination end can be specifically implemented as follows: Determine the board on the SSL VPN device for sending the original data packet to the destination end according to the destination IP address and destination port information in the header of the original data packet. Here, IP is the abbreviation of Internet Protocol.
[0068] In this embodiment, since in each original data packet fragment belonging to the same original data packet, the header of the first original data packet fragment includes the above-mentioned destination IP address and destination port information, while the header of the non-first data packet fragment does not include the above-mentioned destination IP address and destination port information. Therefore, as an example, in order to determine the board on the above-mentioned SSL VPN device for sending the original data packet to the destination end, after the SSL VPN device receives each original data packet fragment sent by the source end, it will first recombine each original data packet fragment to obtain the original data packet, and then obtain the above-mentioned destination IP address and destination port information, etc. from the original data packet, so as to determine the board on the SSL VPN device for sending the original data packet to the destination end.
[0069] Optionally, when this embodiment executes the above-mentioned determination of the board on the SSL VPN device for sending the original data packet to the destination end according to the destination IP address and destination port information in the header of the original data packet, the destination IP address and destination port information, etc. can be used as input parameters and input into a preset hash function to obtain a hash value. Then, based on this hash value, a second board is determined. For example, the hash value can be modulo-calculated with the number N of boards on the SSL VPN device, and the board whose board number matches the modulo result is determined as the board on the SSL VPN device for sending the original data packet to the destination end.
[0070] To facilitate understanding of the specific implementation process of the above-mentioned message transmission method, the following Figure 5 shown application scenario will be described by way of specific examples. As Figure 5 shown in the application scenario, it includes a source end 501, an SSL VPN device 502, and a destination end 503. Among them, the source end 501 and the destination end 503 are connected through the SSL VPN device 502. This embodiment will be described by taking the SSL VPN device 502 as an example that includes multiple boards.
[0071] In this embodiment, when the source end sends an original data packet to the SSL VPN device, it will fragment the original data packet according to the MTU of the data transmission channel between the source end and the SSL VPN device to obtain at least two original data packet fragments, and send each original data packet fragment to the SSL VPN device in sequence.
[0072] The SSL VPN device receives each original data fragment of the same original data packet sent by the source end through a board (which can be denoted as the first board). After that, the SSL VPN device reorganizes the received original data packet fragments to obtain the original data packet, and determines the board on the SSL VPN device for sending the original data packet to the destination end (which can be denoted as the second board) based on the destination IP address and destination port information in the original data packet.
[0073] As an embodiment, after determining the second board, if the first board and the second board are the same board, when the SSL VPN device determines through the first board that the size of the original data packet is greater than the first MTU of the data transmission channel between the SSL VPN device and the destination end based on the received original data packet fragments, it determines through the first board whether the size of each original data packet fragment is less than or equal to the first MTU; if so, it forwards each original data packet fragment to the destination end through the first board; if not, it returns a re-fragmentation instruction to the source end through the first board, so that the source end re-fragments the original data packet sent from the source end to the destination end based on the re-fragmentation instruction and sends it to the destination end; where the size of the data packet fragments obtained after re-fragmentation is less than the size of the data packet fragments obtained before re-fragmentation.
[0074] As another embodiment, after determining the second board, if the first board and the second board are different boards, when the SSL VPN device determines through the first board that the size of the original data packet is greater than the first MTU based on the received original data packet fragments, and when the size of at least one original data packet fragment among the received original data packet fragments is greater than the second MTU of the data transmission channel between the first board and the second board, it fragments the original data packet obtained by the above reorganization according to the second MTU through the first board, and sends the fragmented intermediate data packet fragments and the fragmentation information of the original data packet fragments sent by the source end to the second board. The SSL VPN device receives the intermediate data packet fragments and the fragmentation information sent by the first board through the second board. After that, the SSL VPN device reorganizes the intermediate data packet fragments to obtain the original data packet, and fragments the original data packet according to the fragmentation information to obtain each original data packet fragment.
[0075] When the size of each original data packet fragment received by the SSL VPN device through the first board is less than or equal to the second MTU, it sends each original data packet fragment to the second board. The SSL VPN device receives each original data packet fragment sent by the first board through the second board.
[0076] Based on the above description, the SSL VPN device will determine whether the sizes of all the original data packet fragments are less than or equal to the first MTU through the second board.
[0077] When the sizes of all the original data packet fragments are less than or equal to the first MTU, forward all the original data packet fragments to the destination end through the second board.
[0078] When the size of at least one of the original data packet fragments is greater than the first MTU, return a re-fragmentation indication to the source end through the second board.
[0079] Based on this, after receiving the re-fragmentation indication, the source end will re-fragment the original data packet sent from the source end to the destination end according to the third MTU included in the re-fragmentation indication, and send each data packet fragment obtained by re-fragmentation to the destination end; and the source end will also update the MTU between the source end and the SSL VPN device to the third MTU for subsequent data packet fragmentation. Among them, the third MTU is less than or equal to the first MTU.
[0080] So far, the description of the method provided by the embodiments of the present application is completed. Next, the SSL VPN device provided by the embodiments of the present application will be described:
[0081] As an embodiment, the embodiments of the present application also provide an SSL VPN device. Refer to Figure 6 , Figure 6 which is the structural schematic diagram of the SSL VPN device provided by the embodiments of the present application. As shown in Figure 6 , the SSL VPN device 600 is applied between the source end and the destination end. The SSL VPN device 600 includes at least one board 601. It should be noted that Figure 6 the board in
[0082] is only an exemplary board and is not used to limit the number of boards in the SSL VPN device. The SSL VPN device may include one or more boards.
[0083] Among them, the board on the SSL VPN device for sending the original data packet to the destination end is used to determine whether the size of each fragment of the original data packet is less than or equal to the first MTU if the size of the original data packet is greater than the first MTU; when the size of each fragment of the original data packet is less than or equal to the first MTU, forward each fragment of the original data packet to the destination end; when the size of at least one fragment of the original data packet is greater than the first MTU, return a re-fragmentation indication to the source end so that the source end re-fragments the original data packet based on the re-fragmentation indication and sends it to the SSL VPN device; the size of the data packet fragments obtained after re-fragmentation is smaller than the size of the data packet fragments obtained before re-fragmentation.
[0084] As an embodiment, if the SSL VPN device includes multiple boards, after determining that the size of the original data packet is greater than the first MTU and before determining whether the size of each fragment of the original data packet is less than or equal to the first MTU:
[0085] Any one of the boards 601 is further used to determine whether each received fragment of the original data packet meets the preset inter-board data transmission requirements;
[0086] If each fragment of the original data packet does not meet the inter-board data transmission requirements, restore the original data packet from each fragment of the original data packet, fragment the restored original data packet to obtain at least two intermediate data packet fragments so that each intermediate data packet fragment meets the inter-board data transmission requirements, and transmit each intermediate data packet fragment and the fragment information of the fragment of the original data packet sent by the source end within the multiple boards; among them, the board for sending the original data packet to the destination end is further used to, when receiving each intermediate data packet fragment, restore the original data packet from each intermediate data packet fragment again and fragment the original data packet restored again according to the fragment information to obtain each fragment of the original data packet;
[0087] If each fragment of the original data packet meets the inter-board data transmission requirements, transmit each fragment of the original data packet within the multiple boards; among them, the board for sending the original data packet to the destination end is further used to, when receiving each intermediate data packet fragment, continue to execute the step of determining whether the size of each fragment of the original data packet is less than or equal to the first MTU.
[0088] As an embodiment, determining whether each received fragment of the original data packet meets the preset inter-board data transmission requirements includes:
[0089] If the size of at least one of the original data packet fragments is greater than the second MTU of the data transmission channel between the boards, it is determined that the original data packet fragments do not meet the inter-board data transmission requirements;
[0090] If each of the original data packet fragments is less than or equal to the second MTU, it is determined that the original data packet fragments meet the inter-board data transmission requirements.
[0091] As an embodiment, fragmenting the restored original data packet includes: fragmenting the restored original data packet according to the second MTU.
[0092] As an embodiment, the fragmentation information includes: the size of the original data packet fragment.
[0093] As an embodiment, the re-fragmentation indication includes at least a third MTU, so that the source end re-fragments the original data packet according to the third MTU and sends it to the SSL VPN device; the third MTU is less than or equal to the first MTU.
[0094] So far, the Figure 6 structural description of the SSL VPN device shown is completed.
[0095] For the implementation process of the functions and roles of each component in the above SSL VPN device, please refer to the implementation process of the corresponding steps in the above method for details, and will not be repeated here.
[0096] For the SSL VPN device embodiment, since it basically corresponds to the method embodiment, the relevant parts can be referred to the partial description of the method embodiment. Those of ordinary skill in the art can understand and implement it without creative work.
[0097] The above are only the preferred embodiments of the present application, and are not intended to limit the present application. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application.
Claims
1. A message transmission method, characterized in that: The method is applied to a secure socket layer virtual private network (SSL VPN) device between a source end and a destination end; the method comprises: Receiving original data packet fragments belonging to the same original data packet sent by the source end; If it is determined through the received fragments of the original data packet that the size of the original data packet is greater than the first maximum transmission unit MTU of the data transmission channel between the SSL VPN device and the destination end, then it is determined whether the size of each fragment of the original data packet is less than or equal to the first MTU; When the size of each original data packet fragment is less than or equal to the first MTU, forwarding each original data packet fragment to the destination end; When the size of at least one fragment of the original data packet is larger than the first MTU, a re-fragmentation indication is returned to the source end, so that the source end re-fragments the original data packet based on the re-fragmentation indication and sends it to the SSL VPN device; the size of the data packet fragment obtained after re-fragmentation is smaller than the size of the data packet fragment obtained before re-fragmentation.
2. The method according to claim 1, characterized in that After determining that the size of the original data packet is greater than the first MTU and before determining whether the size of each fragment of the original data packet is less than or equal to the first MTU, the method further includes: If the SSL VPN device includes multiple boards, determining whether each received original data packet fragment meets the preset inter-board data transmission requirements; If each original data packet fragment does not meet the inter-board data transmission requirement, restore the original data packet according to each original data packet fragment, fragment the restored original data packet to obtain at least two intermediate data packet fragments, so that each intermediate data packet fragment meets the inter-board data transmission requirement, and transmit each intermediate data packet fragment and the fragment information of the original data packet fragment sent by the source end in the multiple boards; When each intermediate data packet fragment reaches the board on the SSL VPN device used to send the original data packet to the destination, the original data packet is restored again according to each intermediate data packet fragment, and the restored original data packet is fragmented according to the fragmentation information to obtain the original data packet fragments.
3. The method according to claim 2, characterized in that After determining whether each received original data packet fragment meets the preset inter-board data transmission requirement, the method further includes: If each fragment of the original data packet meets the inter-board data transmission requirement, transmitting each fragment of the original data packet within the plurality of boards; When each fragment of the original data packet arrives at the board card on the SSL VPN device used to send the original data packet to the destination, the step of determining whether the size of each fragment of the original data packet is less than or equal to the first MTU is continued.
4. The method according to claim 2, characterized in that: The step of judging whether each received original data packet fragment meets the preset inter-board data transmission requirement includes: If the size of at least one original data packet fragment among the original data packet fragments is larger than the second MTU of the inter-board data transmission channel, it is determined that the original data packet fragments do not meet the inter-board data transmission requirement; If each original data packet fragment is less than or equal to the second MTU, it is determined that each original data packet fragment meets the inter-board data transmission requirement; The fragmenting the restored original data packet includes: fragmenting the restored original data packet according to the second MTU.
5. The method according to claim 2, characterized in that: The fragmentation information includes: the fragmentation size of the original data packet fragment.
6. The method according to claim 1, characterized in that The re-fragmentation indication includes at least a third MTU, so that the source end re-fragments the original data packet according to the third MTU and sends it to the SSL VPN device; the third MTU is less than or equal to the first MTU.
7. A secure socket layer virtual private network (SSL VPN) device, characterized in that: The SSL VPN device is applied between the source end and the destination end; the SSL VPN device includes at least one board card; Any board, used for receiving each original data packet fragment belonging to the same original data packet sent by the source end, and determining whether the size of the original data packet is greater than the first maximum transmission unit MTU of the data transmission channel between the SSL VPN device and the destination end according to each received original data packet fragment; Among them, the board card on the SSL VPN device for sending the original data packet to the destination end is used to determine whether the size of each original data packet fragment is less than or equal to the first MTU if the size of the original data packet is greater than the first MTU; when the size of each original data packet fragment is less than or equal to the first MTU, forward each original data packet fragment to the destination end; when the size of at least one original data packet fragment is greater than the first MTU, return a re-fragmentation indication to the source end, so that the source end re-fragmentates the original data packet based on the re-fragmentation indication and sends it to the SSL VPN device; the size of the data packet fragment obtained after re-fragmentation is smaller than the size of the data packet fragment obtained before re-fragmentation.
8. The device according to claim 7, characterized in that If the SSL VPN device includes multiple boards, after determining that the size of the original data packet is greater than the first MTU and before determining whether the size of each fragment of the original data packet is less than or equal to the first MTU: Any of the boards is further used to determine whether each received original data packet fragment meets the preset inter-board data transmission requirements; If each original data packet fragment does not meet the inter-board data transmission requirement, the original data packet is restored according to each original data packet fragment, and the restored original data packet is fragmented to obtain at least two intermediate data packet fragments, so that each intermediate data packet fragment meets the inter-board data transmission requirement, and each intermediate data packet fragment and the fragmentation information of the original data packet fragment sent by the source end are transmitted within the multiple boards; wherein the board used to send the original data packet to the destination end is also used to restore the original data packet again according to each intermediate data packet fragment when receiving each intermediate data packet fragment, and fragment the restored original data packet again according to the fragmentation information to obtain each original data packet fragment; If each original data packet fragment meets the inter-board data transmission requirements, then each original data packet fragment is transmitted within the multiple boards; wherein, the board used to send the original data packet to the destination end is also used to continue to execute the step of determining whether the size of each original data packet fragment is less than or equal to the first MTU when each intermediate data packet fragment is received.
9. The device according to claim 8, characterized in that The determining whether each received original data packet fragment meets the preset inter-board data transmission requirement includes: if the size of at least one original data packet fragment among the original data packet fragments is larger than the second MTU of the inter-board data transmission channel, then determining that each original data packet fragment does not meet the inter-board data transmission requirement; if each original data packet fragment is smaller than or equal to the second MTU, then determining that each original data packet fragment meets the inter-board data transmission requirement; and / or, The fragmenting of the restored original data packet comprises: fragmenting the restored original data packet according to the second MTU; and / or, The fragmentation information includes: the fragmentation size of the original data packet fragment.
10. The device according to claim 7, characterized in that The re-fragmentation indication includes at least a third MTU, so that the source end re-fragments the original data packet according to the third MTU and sends it to the SSL VPN device; the third MTU is less than or equal to the first MTU.
Citation Information
Patent Citations
Message transmission method and system
CN101640645A
Method for discovering PMTU (Path Maximum Transfer Unit) and node
CN102325076A
Method and equipment for generating and distributing link state protocol data unit fragment messages
CN103152261A
Data transmission processing method and device, network equipment and readable storage medium
CN112333094A
Lightweight fragmentation and reliability for fixed mobile convergence access stratum and non-access stratum signaling
US20220408310A1