Message transmission methods and SSL VPN devices

CN120223646BActive Publication Date: 2026-08-21NEW H3C TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510357769.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-24
Publication Date
2026-08-21
Estimated Expiration
2045-03-24

AI Technical Summary

Technical Problem

[0004]但是,上述这种按照SSLVPN设备与目的端之间的MTU再分片的方式,会对源端所发送数据包分片的性能特征造成影响,例如在需要基于源端发送的数据包分片以分析源端行为的时候,就会产生分析误差等

Benefits of technology

[0014]由以上技术方案可以看出,本申请实施例中,在源端发送的原始数据包的大小大于SSL VPN设备与目的端之间数据传输通道的第一MTU的情况下,先判断属于原始数据包的各原始数据包分片的大小是否均小于或等于第一MTU,若是则可直接向目的端转发各原始数据包分片,若否也即至少一个原始数据包分片的大小大于第一MTU,则可向源端返回重分片指示以使源端对原始数据包重新进行分片并发送至SSL VPN设备,其中重新分片后得到的数据包分片的大小小于重新分片前得到的数据包分片的大小,而非现有直接按照第一MTU对源端所发送数据包进行再分片,这样能够避免由于再分片对源端所发送数据包分片的性能特征造成的影响,从而有效降低了SSL VPN设备对源端所发送数据包的影响。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120223646B_ABST
    Figure CN120223646B_ABST
Patent Text Reader

Abstract

The embodiment of the present application provides a message transmission method and an SSL VPN device. In the embodiment of the present application, in the case that the size of an original data packet sent by a source end is greater than a first MTU of a data transmission channel between the SSL VPN device and a destination end, it is first judged whether the size of each original data packet fragment belonging to the original data packet is less than or equal to the first MTU, if yes, each original data packet fragment is directly forwarded to the destination end, if not, a re-fragmentation indication is returned to the source end to make the source end re-fragment the original data packet and send it, wherein the size of a data packet fragment obtained after re-fragmentation is less than the size of a data packet fragment obtained before re-fragmentation, instead of re-fragmenting the data packet sent by the source end according to the first MTU, so that the influence of the re-fragmentation on the performance characteristics of the data packet fragment sent by the source end can be avoided, thereby effectively reducing the influence of the SSL VPN device on the data packet sent by the source end.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technology, and in particular to message transmission methods and Secure Sockets Layer Virtual Private Network (SSL VPN) devices. Background Technology

[0002] SSL VPN is a VPN technology built on the SSL / TLS protocol, providing secure remote connection services. Network devices based on SSL VPN technology are generally called SSL VPN devices. SSL VPN devices are typically used to forward packets between remote source and destination ends to provide secure connection services. TLS stands for Transport Layer Security.

[0003] In practical applications, after receiving fragments of data packets belonging to the same data packet from the source, the SSLVPN device reassembles the fragments and then fragments the reassembled data packet according to the Maximum Transmission Unit (MTU) between the SSLVPN device and the destination. The fragmented data packet is then sent to the destination in sequence to forward the data packet sent by the source.

[0004] However, this method of re-fragmenting data packets based on the MTU between the SSL VPN device and the destination will affect the performance characteristics of the data packet fragmentation sent by the source. For example, it will cause analysis errors when it is necessary to analyze the behavior of the source based on the data packet fragmentation sent by the source. Summary of the Invention

[0005] In view of this, this application provides a message transmission method and an SSL VPN device to reduce the impact of the SSL VPN device on the data packets sent by the source end.

[0006] This application provides a message transmission method, which is applied to an SSL VPN device between a source and a destination. The method includes:

[0007] Receive fragments of the original data packets belonging to the same original data packet sent by the source end;

[0008] If, based on the received fragments of the original data packets, it is determined that the size of the original data packet is greater than the first MTU of the data transmission channel between the SSLVPN device and the destination, then it is determined whether the size of each fragment of the original data packet is less than or equal to the first MTU.

[0009] If the size of each original data packet fragment is less than or equal to the first MTU, then each original data packet fragment is forwarded to the destination.

[0010] If the size of at least one original data packet fragment is greater than the first MTU, a refraction instruction is returned to the source end, so that the source end can refraction the original data packet based on the refraction instruction and send it to the SSLVPN device; the size of the data packet fragment obtained after refraction is smaller than the size of the data packet fragment obtained before refraction.

[0011] This application embodiment also provides an SSL VPN device, which is used between a source end and a destination end; the SSL VPN device includes at least one board.

[0012] Any board is used to receive fragments of the original data packets belonging to the same original data packet sent by the source end, and determine whether the size of the original data packet is greater than the first MTU of the data transmission channel between the SSL VPN device and the destination end based on the received fragments of the original data packets.

[0013] The SSL VPN device includes a card used to send the original data packet to the destination. If the size of the original data packet is greater than the first MTU, the card determines whether the size of each original data packet fragment is less than or equal to the first MTU. If the size of each original data packet fragment is less than or equal to the first MTU, the card forwards each original data packet fragment to the destination. If the size of at least one original data packet fragment is greater than the first MTU, the card returns a re-fragmentation instruction to the source, so that the source re-fragments the original data packet based on the re-fragmentation instruction and sends it to the SSL VPN device. The size of the re-fragmented data packet fragment is smaller than the size of the original data packet fragment.

[0014] As can be seen from the above technical solutions, in this embodiment, when the size of the original data packet sent by the source end is greater than the first MTU of the data transmission channel between the SSL VPN device and the destination end, it is first determined whether the size of each original data packet fragment belonging to the original data packet is less than or equal to the first MTU. If so, each original data packet fragment can be directly forwarded to the destination end. If not, that is, at least one original data packet fragment is larger than the first MTU, a re-fragmentation instruction can be returned to the source end so that the source end can re-fragment the original data packet and send it to the SSL VPN device. The size of the data packet fragment obtained after re-fragmentation is smaller than the size of the data packet fragment obtained before re-fragmentation, instead of directly re-fragmenting the data packet sent by the source end according to the first MTU as in the existing method. This can avoid the impact of re-fragmentation on the performance characteristics of the data packet fragments sent by the source end, thereby effectively reducing the impact of the SSL VPN device on the data packet sent by the source end. Attached Figure Description

[0015] The accompanying drawings, which are incorporated in and form part of this application, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.

[0016] Figure 1 This is a schematic diagram of the method procedure provided in the embodiments of this application.

[0017] Figure 2 This is a schematic diagram of another method flow provided for an embodiment of this application.

[0018] Figure 3 This is a schematic diagram of another method flow provided in an embodiment of this application.

[0019] Figure 4 This is a schematic diagram of another method flow provided in an embodiment of this application.

[0020] Figure 5 This is a schematic diagram illustrating the implementation of the application scenario provided in the embodiments of this application.

[0021] Figure 6 This is a schematic diagram of the structure of an SSL VPN device provided in an embodiment of this application. Detailed Implementation

[0022] To enable those skilled in the art to better understand the technical solutions provided in the embodiments of this application, and to make the above-mentioned objectives, features and advantages of the embodiments of this application more apparent and understandable, the technical solutions in the embodiments of this application will be further described in detail below with reference to the accompanying drawings.

[0023] See Figure 1 , Figure 1This is a flowchart illustrating a method provided in an embodiment of this application. The method is applied to an SSL VPN device between a source and a destination. As one embodiment, the source can be a client, and the destination can be a server corresponding to the client; it should be noted that this is merely an illustrative example, and this embodiment does not specifically limit the forms of the source and destination.

[0024] like Figure 1 As shown, the process may include the following steps:

[0025] Step 101: Receive fragments of the original data packets belonging to the same original data packet sent by the source.

[0026] In this embodiment, as one example, when the source sends the original data packet to the SSL VPN device, it first fragments the original data packet according to the source MTU of the data transmission channel between the source and the SSL VPN device to obtain individual original data packet fragments, and then sends each original data packet fragment to the SSL VPN device in sequence. Based on this, the SSL VPN device receives each original data packet fragment belonging to the original data packet sent by the source.

[0027] Optionally, in this embodiment, the aforementioned original data packet may refer to a data packet based on the Internet Protocol Version 6 (IPv6) protocol. This embodiment does not specifically limit this.

[0028] Step 102: If the size of the original data packet is determined to be greater than the first MTU of the data transmission channel between the SSLVPN device and the destination based on the received original data packet fragments, then determine whether the size of each original data packet fragment is less than or equal to the first MTU; if yes, proceed to step 103; otherwise, proceed to step 104.

[0029] Step 103: Forward each original data packet fragment to the destination.

[0030] In this embodiment, when the size of each data packet fragment is less than or equal to the first MTU, the data packet fragments can be forwarded to the destination directly through the second board in sequence, thus realizing the forwarding of the original data packet.

[0031] Step 104: Return a refraction instruction to the source end, so that the source end can refraction the original data packet based on the refraction instruction and send it to the SSL VPN device; the size of the data packet fragments obtained after refraction is smaller than the size of the data packet fragments obtained before refraction.

[0032] In this embodiment, if the SSL VPN device determines that the size of the original data packet is greater than the first MTU based on the received original data packet fragments, it cannot directly forward the original data packet to the destination. In this case, it can first determine whether the size of each original data packet fragment belonging to the original data packet is less than or equal to the first MTU.

[0033] If the size of each original data packet fragment is less than or equal to the first MTU, then each original data packet fragment can be forwarded directly to the destination in sequence.

[0034] If at least one original data packet fragment is larger than the first MTU, a refraction instruction can be returned to the source, allowing the source to refraction the original data packet based on the refraction instruction and send it to the SSL VPN device. The size of the refractionated data packet fragment is smaller than the size of the original fragment.

[0035] In this embodiment, as an example, if the SSL VPN device determines, through the received original data packet fragments, that the size of the original data packet is less than or equal to the first MTU, then the original data packet can be directly forwarded to the destination.

[0036] In this embodiment, as one example, the aforementioned refraction instruction includes at least a third MTU, causing the source end to refraction the original data packet according to the third MTU and send it to the SSL VPN device; the third MTU is less than or equal to the first MTU. This ensures that the size of each data packet fragment obtained after refraction is less than or equal to the first MTU. Based on this, after the SSL VPN device receives the data packet fragments obtained after refraction sent by the source end, it can directly forward the data packet fragments obtained after refraction to the destination end to achieve the forwarding of the original data packet.

[0037] This concludes the process. Figure 1 The process is shown below.

[0038] pass Figure 1As can be seen from the process shown, in this embodiment of the application, when the size of the original data packet sent by the source end is greater than the first MTU of the data transmission channel between the SSL VPN device and the destination end, it is first determined whether the size of each original data packet fragment belonging to the original data packet is less than or equal to the first MTU. If so, each original data packet fragment can be directly forwarded to the destination end. If not, that is, at least one original data packet fragment is larger than the first MTU, a re-fragmentation instruction can be returned to the source end so that the source end can re-fragment the original data packet and send it to the SSL VPN device. The size of the data packet fragment obtained after re-fragmentation is smaller than the size of the data packet fragment obtained before re-fragmentation, instead of directly re-fragmenting the data packet sent by the source end according to the first MTU as in the existing method. This can avoid the impact of re-fragmentation on the performance characteristics of the data packet fragments sent by the source end, thereby effectively reducing the impact of the SSL VPN device on the data packet sent by the source end.

[0039] The above message transmission method is described in further detail below:

[0040] In this embodiment, as an example, see [example]. Figure 2 As shown, after determining that the size of the original data packet is greater than the first MTU, and before determining whether the size of each original data packet fragment is less than or equal to the first MTU, the method further includes the following steps:

[0041] Step 201: If the SSL VPN device includes multiple boards, determine whether the received original data packet fragments meet the preset inter-board data transmission requirements; if yes, proceed to step 202; if no, proceed to step 203.

[0042] In this embodiment, as an example, when the SSL VPN device includes multiple cards, if the card on the SSL VPN device that receives each original data packet fragment is different from the card used to send the original data packet to the destination, then the received original data packet fragments need to be forwarded to the card on the SSL VPN device used to send the original data packet to the destination for subsequent processing. Based on this, after receiving each original data packet fragment, it is determined whether the received original data packet fragments meet the preset inter-board data transmission requirements. The specific method for determining the card on the SSL VPN device used to send the original data packet to the destination will be described with examples below and will not be elaborated here.

[0043] In this embodiment, as one example, determining whether the received original data packet fragments meet the preset inter-board data transmission requirements in this step can, for example, include: if the size of at least one original data packet fragment is greater than the second MTU of the inter-board data transmission channel, then it is determined that the original data packet fragments do not meet the inter-board data transmission requirements; if the size of each original data packet fragment is less than or equal to the second MTU, then it is determined that the original data packet fragments meet the inter-board data transmission requirements.

[0044] Step 202: Transmit each original data packet fragment within multiple boards; when each original data packet fragment arrives at the board on the SSLVPN device used to send the original data packet to the destination, continue to execute the step of determining whether the size of each original data packet fragment is less than or equal to the first MTU.

[0045] In this embodiment, as an example, the transmission of each original data packet fragment within multiple boards in this step can be implemented in a specific way, for example, by sequentially sending each original data packet fragment to the board on the aforementioned SSL VPN device used to send the original data packet to the destination.

[0046] Step 203: Reconstruct the original data packets based on the fragments of each original data packet. Fragment the reconstructed original data packets to obtain at least two intermediate data packet fragments. Ensure that each intermediate data packet fragment meets the inter-board data transmission requirements. Transmit the fragmentation information of each intermediate data packet fragment and the original data packet fragments sent from the source end across multiple boards. Then continue to step 204.

[0047] In this embodiment, as one example, the original data packet is reconstructed from each original data packet fragment in this step. In specific implementation, for example, the original data packet fragments can be reassembled according to a preset reassembly method to obtain the original data packet. The reassembly method is not specifically limited here and can be flexibly set according to actual application requirements.

[0048] In this embodiment, as one example, the restored original data packets are fragmented in this step. Specifically, this can be implemented by fragmenting the restored original data packets according to the second MTU of the inter-board data transmission channel. This ensures that the size of each intermediate data packet fragment is less than or equal to the second MTU, meaning that each intermediate data packet fragment meets the inter-board data transmission requirements.

[0049] As for how to transmit the fragmentation information of each intermediate data packet fragment and the original data packet fragment sent by the source end within multiple boards in this step, examples will be provided below, and will not be elaborated here.

[0050] Step 204: When each intermediate data packet fragment arrives at the board on the SSL VPN device used to send the original data packet to the destination, the original data packet is restored again according to each intermediate data packet fragment, and the restored original data packet is fragmented according to the fragmentation information to obtain each original data packet fragment. Then, the step of determining whether the size of each original data packet fragment is less than or equal to the first MTU is continued.

[0051] In this embodiment, the specific implementation method of restoring the original data packet based on each intermediate data packet fragment in this step is similar to the specific implementation method of restoring the original data packet based on each original data packet fragment described above; for example, as an embodiment, each intermediate data packet fragment is reassembled according to a preset reassembly method to obtain the original data packet.

[0052] In this embodiment, as one example, the fragmentation information may include the fragmentation size of the original data packet fragments. Optionally, the fragmentation information in this embodiment may be, for example, the fragmentation size of the largest original data packet fragment among all the original data packet fragments sent by the source. As described above, since each original data packet fragment sent by the source is obtained by the source fragmenting the original data packet according to the source MTU of the data transmission channel between the source and the SSL VPN device, the fragmentation size of the largest original data packet fragment among all the original data packet fragments sent by the source is the same as the aforementioned source MTU.

[0053] Based on this, in this embodiment, the reconstructed original data packet is fragmented according to the fragmentation information, which is equivalent to fragmenting the original data packet according to the source MTU. Therefore, this can obtain fragments of each original data packet, which can ensure that the fragments of the data packet obtained by re-fragmentation are as consistent as possible with the fragments of the original data packet sent by the source. This avoids the impact of re-fragmentation on the performance characteristics of the data packet fragments sent by the source and effectively reduces the impact of the SSL VPN device on the data packets sent by the source.

[0054] The following describes how to transmit intermediate data packet fragments and fragmentation information of the original data packet fragments sent from the source end across multiple boards:

[0055] In this embodiment, the fragmentation information of the intermediate data packet fragments and the original data packet fragments sent from the source end, which are transmitted across multiple boards, can be implemented in many ways. For example, as an embodiment, see... Figure 3 As shown, the specific implementation may include the following steps:

[0056] Step 301: Obtain the fragmentation information of the original data packet sent by the source.

[0057] Step 302: Carry the obtained fragmentation information in each intermediate data packet fragment and transmit it across multiple boards.

[0058] In this embodiment, as one example, after obtaining the fragmentation information, the fragmentation information can also be carried in one of the intermediate data packet fragments and transmitted across multiple boards. Specifically, for example, the fragmentation information can be carried in the first intermediate data packet fragment obtained from the fragmentation and transmitted across multiple boards.

[0059] Optionally, this embodiment may add a custom extended field to the intermediate data packet fragments. The custom extended field may carry the above-mentioned fragmentation information to realize the fragmentation information being carried in the intermediate data packet fragments.

[0060] The following describes the packet transmission method when the SSL VPN device includes a single card:

[0061] In this embodiment, as an example, if the SSL VPN device includes a single board, then inter-board data transmission is not involved. In this case, such as Figure 4 As shown, the above message transmission method may include the following steps:

[0062] Step 401: The SSL VPN device receives fragments of the original data packets belonging to the same original data packet from the source end via the board.

[0063] Step 402: If the size of the original data packet is determined to be greater than the first MTU of the data transmission channel between the SSLVPN device and the destination based on the received original data packet fragments, then determine whether the size of each original data packet fragment is less than or equal to the first MTU; if yes, then proceed to step 403; if no, that is, at least one original data packet fragment is greater than the first MTU, then proceed to step 404.

[0064] Step 403: Forward each original data packet fragment to the destination through the board.

[0065] Step 404: The board returns a re-fragmentation instruction to the source end, so that the source end can re-fragment the original data packet based on the re-fragmentation instruction and send it to the SSL VPN device; the size of the data packet fragments obtained after re-fragmentation is smaller than the size of the data packet fragments obtained before re-fragmentation.

[0066] The following describes how to determine the specific cards on an SSL VPN device used to send raw data packets to the destination:

[0067] In this embodiment, as one example, the aforementioned determination of the board on the SSL VPN device used to send the original data packet to the destination can, in a specific implementation, be as follows: the board on the SSL VPN device used to send the original data packet to the destination is determined based on the destination IP address and destination port information in the header of the original data packet. Here, IP is an abbreviation for Internet Protocol.

[0068] In this embodiment, since the header of the first original data packet fragment belonging to the same original data packet includes the aforementioned destination IP address and destination port information, while the header of subsequent data packet fragments does not include the aforementioned destination IP address and destination port information, as an example, in order to determine the card on the SSL VPN device used to send the original data packet to the destination, after receiving each original data packet fragment sent by the source, the SSL VPN device will first reassemble each original data packet fragment to obtain the original data packet, and then obtain the aforementioned destination IP address and destination port information from the original data packet to determine the card on the SSL VPN device used to send the original data packet to the destination.

[0069] Optionally, in this embodiment, when determining the card on the SSL VPN device used to send the original data packet to the destination based on the destination IP address and destination port information in the header of the original data packet, the destination IP address and destination port information can be used as input parameters and input into a preset hash function to obtain a hash value. Then, the second card can be determined based on the hash value. For example, the hash value can be moduloed with the number of cards N on the SSL VPN device to determine the card whose card number matches the modulo result as the card on the SSL VPN device used to send the original data packet to the destination.

[0070] To facilitate understanding of the specific implementation process of the above message transmission method, the following will combine... Figure 5 The application scenarios shown are illustrated with specific examples. For instance... Figure 5 The application scenario shown includes a source device 501, an SSL VPN device 502, and a destination device 503, wherein the source device 501 and the destination device 503 are connected through the SSL VPN device 502. This embodiment uses an SSL VPN device 502 comprising multiple cards as an example for illustration.

[0071] In this embodiment, when the source sends the original data packet to the SSL VPN device, it will fragment the original data packet according to the MTU of the data transmission channel between the source and the SSL VPN device to obtain at least two original data packet fragments, and send each original data packet fragment to the SSL VPN device in sequence.

[0072] An SSL VPN device receives raw data fragments belonging to the same raw data packet from the source through a single card (referred to as the first card). The SSL VPN device then reassembles the received raw data packet fragments to obtain the original data packet. Based on the destination IP address and destination port information in this original data packet, it determines the card on the SSL VPN device used to send the original data packet to the destination (referred to as the second card).

[0073] As an example, after the second board is determined, if the first board and the second board are the same board, when the SSL VPN device determines, through the first board, that the size of the original data packet is greater than the first MTU of the data transmission channel between the SSL VPN device and the destination based on the received original data packet fragments, the first board determines whether the size of each original data packet fragment is less than or equal to the first MTU; if so, the first board forwards each original data packet fragment to the destination; if not, the first board returns a re-fragmentation instruction to the source, so that the source re-fragments the original data packet sent from the source to the destination based on the re-fragmentation instruction and sends it to the destination; wherein, the size of the data packet fragment obtained after re-fragmentation is smaller than the size of the data packet fragment obtained before re-fragmentation.

[0074] In another embodiment, after the second board is determined, if the first board and the second board are different boards, when the SSL VPN device determines, based on the received original data packet fragments from the first board, that the size of the original data packet is greater than the first MTU, at least one of the original data packet fragments received from the first board will have a size greater than the second MTU of the data transmission channel between the first and second boards. In this case, the first board will fragment the reassembled original data packet according to the second MTU, and send the fragmentation information of the intermediate data packet fragments and the original data packet fragments sent from the source end to the second board. The SSL VPN device receives the intermediate data packet fragments and fragmentation information sent by the first board through the second board. Then, the SSL VPN device will reassemble the intermediate data packet fragments to obtain the original data packet, and fragment the original data packet according to the fragmentation information to obtain the original data packet fragments.

[0075] When the size of each raw data packet fragment received by the SSL VPN device through the first board is less than or equal to the second MTU, the SSL VPN device sends each raw data packet fragment to the second board. The SSL VPN device then receives the raw data packet fragments sent by the first board through the second board.

[0076] Based on the above description, the SSL VPN device will use the second board to determine whether the size of each original data packet fragment is less than or equal to the first MTU.

[0077] When the size of each original data packet fragment is less than or equal to the first MTU, the original data packet fragments are forwarded to the destination via the second board.

[0078] If the size of at least one original data packet fragment is greater than the first MTU, a re-fragmentation instruction is returned to the source end via the second board.

[0079] Based on this, upon receiving the refraction instruction, the source end will refraction the original data packets sent from the source end to the destination end according to the third MTU included in the refraction instruction, and then send the refractionated data packet fragments to the destination end. Furthermore, the source end will update the MTU between itself and the SSL VPN device to the third MTU for subsequent data packet fragmentation. The third MTU is less than or equal to the first MTU.

[0080] This concludes the description of the method provided in the embodiments of this application. The SSL VPN device provided in the embodiments of this application will now be described:

[0081] As one embodiment, this application also provides an SSL VPN device. See [link to documentation]. Figure 6 , Figure 6 This is a schematic diagram of the SSL VPN device provided in an embodiment of this application. Figure 6 As shown, the SSL VPN device 600 is used between the source and destination ends, and the SSL VPN device 600 includes at least one board 601. It should be noted that... Figure 6 The cards listed are merely exemplary and are not intended to limit the number of cards in an SSL VPN device. An SSL VPN device may include one or more cards.

[0082] Any board 601 is used to receive fragments of the original data packets belonging to the same original data packet sent by the source end, and determine whether the size of the original data packet is greater than the first maximum transmission unit (MTU) of the data transmission channel between the SSL VPN device and the destination end based on the received fragments of the original data packets.

[0083] The SSL VPN device includes a card used to send the original data packet to the destination. If the size of the original data packet is greater than the first MTU, the card determines whether the size of each original data packet fragment is less than or equal to the first MTU. If the size of each original data packet fragment is less than or equal to the first MTU, the card forwards each original data packet fragment to the destination. If the size of at least one original data packet fragment is greater than the first MTU, the card returns a re-fragmentation instruction to the source, so that the source re-fragments the original data packet based on the re-fragmentation instruction and sends it to the SSL VPN device. The size of the re-fragmented data packet fragment is smaller than the size of the original data packet fragment.

[0084] As an example, if the SSL VPN device includes multiple cards, then after determining that the size of the original data packet is greater than the first MTU, and before determining whether the size of each original data packet fragment is less than or equal to the first MTU:

[0085] The board 601 is also used to determine whether the received original data packet fragments meet the preset inter-board data transmission requirements.

[0086] If the original data packet fragments do not meet the inter-board data transmission requirements, the original data packet is reconstructed based on the original data packet fragments, and the reconstructed original data packet is fragmented to obtain at least two intermediate data packet fragments, so that each intermediate data packet fragment meets the inter-board data transmission requirements. The fragmentation information of each intermediate data packet fragment and the original data packet fragment sent by the source end is transmitted within the multiple boards. The board used to send the original data packet to the destination end is also used to reconstruct the original data packet again based on each intermediate data packet fragment when each intermediate data packet fragment is received, and to fragment the reconstructed original data packet according to the fragmentation information to obtain the original data packet fragments.

[0087] If each original data packet fragment meets the inter-board data transmission requirements, then each original data packet fragment is transmitted within the plurality of boards; wherein, the board used to send the original data packet to the destination is also used to, when receiving each intermediate data packet fragment, continue to execute the step of determining whether the size of each original data packet fragment is less than or equal to the first MTU.

[0088] As one embodiment, determining whether the received original data packet fragments meet the preset inter-board data transmission requirements includes:

[0089] If the size of at least one original data packet fragment is greater than the second MTU of the inter-board data transmission channel, then it is determined that the original data packet fragments do not meet the inter-board data transmission requirements.

[0090] If each original data packet fragment is less than or equal to the second MTU, then each original data packet fragment is determined to meet the inter-board data transmission requirements.

[0091] As an example, the fragmentation of the restored original data packet includes: fragmenting the restored original data packet according to the second MTU.

[0092] As one example, the fragmentation information includes: the fragmentation size of the original data packet fragments.

[0093] As an example, the refraction instruction includes at least a third MTU, such that the source end refractions the original data packet according to the third MTU and sends it to the SSL VPN device; the third MTU is less than or equal to the first MTU.

[0094] This concludes the process. Figure 6 The diagram shows a structural description of the SSL VPN device.

[0095] The specific implementation process of the functions and roles of each component in the above SSL VPN device can be found in the implementation process of the corresponding steps in the above method, and will not be repeated here.

[0096] For the SSL VPN device implementation, since it basically corresponds to the method implementation, the relevant parts can be referred to in the description of the method implementation. Those skilled in the art can understand and implement this without any inventive effort.

[0097] The above are merely preferred embodiments of this application and are not intended to limit this application. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of protection of this application.

Claims

1. A message transmission method, characterized in that, The method is applied to a Secure Sockets Layer (SSL) VPN device between the source and destination ends; the method includes: Receive fragments of the original data packets belonging to the same original data packet sent by the source end; If, based on the received fragments of the original data packets, it is determined that the size of the original data packet is greater than the first maximum transmission unit (MTU) of the data transmission channel between the SSL VPN device and the destination, then, in the case where the SSL VPN device includes multiple boards, it is determined whether the received fragments of the original data packets meet the preset inter-board data transmission requirements. If the fragments of the original data packets do not meet the inter-board data transmission requirements, the original data packet is reconstructed based on the fragments of the original data packets, and the reconstructed original data packet is fragmented to obtain at least two intermediate data packet fragments, so that each intermediate data packet fragment meets the inter-board data transmission requirements. The fragmentation information of each intermediate data packet fragment and the original data packet fragment sent by the source end is transmitted within the multiple boards. When each intermediate data packet fragment arrives at the board on the SSL VPN device used to send the original data packet to the destination, the original data packet is reconstructed again based on each intermediate data packet fragment, and the reconstructed original data packet is fragmented according to the fragmentation information to obtain each original data packet fragment. Determine whether the size of each original data packet fragment is less than or equal to the first MTU; If the size of each original data packet fragment is less than or equal to the first MTU, then each original data packet fragment is forwarded to the destination. If the size of at least one original data packet fragment is greater than the first MTU, a re-fragmentation instruction is returned to the source end, so that the source end can re-fragment the original data packet based on the re-fragmentation instruction and send it to the SSL VPN device; the size of the data packet fragment obtained after re-fragmentation is smaller than the size of the data packet fragment obtained before re-fragmentation.

2. The method according to claim 1, characterized in that, After determining whether the received original data packet fragments meet the preset inter-board data transmission requirements, the method further includes: If each original data packet fragment meets the inter-board data transmission requirements, then each original data packet fragment is transmitted within the multiple boards. When each original data packet fragment arrives at the board on the SSL VPN device used to send the original data packet to the destination, the step of determining whether the size of each original data packet fragment is less than or equal to the first MTU continues.

3. The method according to claim 1, characterized in that, The determination of whether the received original data packet fragments meet the preset inter-board data transmission requirements includes: If the size of at least one original data packet fragment is greater than the second MTU of the inter-board data transmission channel, then it is determined that the original data packet fragments do not meet the inter-board data transmission requirements. If each original data packet fragment is less than or equal to the second MTU, then it is determined that each original data packet fragment meets the inter-board data transmission requirements. The fragmentation of the restored original data packet includes: fragmenting the restored original data packet according to the second MTU.

4. The method according to claim 1, characterized in that, The fragmentation information includes: the fragment size of the original data packet fragments.

5. The method according to claim 1, characterized in that, The refraction instruction includes at least a third MTU, such that the source end refractions the original data packet according to the third MTU and sends it to the SSL VPN device; the third MTU is less than or equal to the first MTU.

6. A Secure Sockets Layer (SSL) VPN device, characterized in that, The SSL VPN device is used between the source and destination ends; the SSL VPN device includes at least one board. Any board is used to receive fragments of the original data packets belonging to the same original data packet sent by the source end, and determine whether the size of the original data packet is greater than the first maximum transmission unit (MTU) of the data transmission channel between the SSL VPN device and the destination end based on the received fragments of the original data packets. The SSL VPN device includes a card used to send the original data packet to the destination. If the size of the original data packet is greater than the first MTU, the card determines whether the size of each original data packet fragment is less than or equal to the first MTU. If the size of each original data packet fragment is less than or equal to the first MTU, the card forwards each original data packet fragment to the destination. If the size of at least one original data packet fragment is greater than the first MTU, the card returns a re-fragmentation instruction to the source, so that the source re-fragments the original data packet based on the re-fragmentation instruction and sends it to the SSL VPN device. The size of the re-fragmented data packet fragment is smaller than the size of the original data packet fragment. If the SSL VPN device includes multiple cards, then after determining that the size of the original data packet is greater than the first MTU, and before determining whether the size of each original data packet fragment is less than or equal to the first MTU: Any of the boards is further configured to determine whether the received original data packet fragments meet the preset inter-board data transmission requirements; if the original data packet fragments do not meet the inter-board data transmission requirements, the original data packet is reconstructed based on the original data packet fragments, and the reconstructed original data packet is fragmented to obtain at least two intermediate data packet fragments, so that the intermediate data packet fragments meet the inter-board data transmission requirements, and the fragmentation information of the intermediate data packet fragments and the original data packet fragments sent by the source end is transmitted in the plurality of boards; wherein, the board configured to send the original data packet to the destination end is further configured to, when receiving the intermediate data packet fragments, reconstruct the original data packet again based on the intermediate data packet fragments, and fragment the reconstructed original data packet according to the fragmentation information to obtain the original data packet fragments.

7. The device according to claim 6, characterized in that, If the SSL VPN device includes multiple cards, then after determining that the size of the original data packet is greater than the first MTU, and before determining whether the size of each original data packet fragment is less than or equal to the first MTU: The aforementioned board is also used to determine whether the received original data packet fragments meet the preset inter-board data transmission requirements; If each original data packet fragment meets the inter-board data transmission requirements, then each original data packet fragment is transmitted within the plurality of boards; wherein, the board used to send the original data packet to the destination is also used to, when receiving each intermediate data packet fragment, continue to execute the step of determining whether the size of each original data packet fragment is less than or equal to the first MTU.

8. The device according to claim 7, characterized in that, The determination of whether the received original data packet fragments meet the preset inter-board data transmission requirements includes: if the size of at least one original data packet fragment is greater than the second MTU of the inter-board data transmission channel, then it is determined that the original data packet fragments do not meet the inter-board data transmission requirements; if the size of each original data packet fragment is less than or equal to the second MTU, then it is determined that the original data packet fragments meet the inter-board data transmission requirements; and / or, The fragmentation of the restored original data packet includes: fragmenting the restored original data packet according to the second MTU; and / or, The fragmentation information includes: the fragment size of the original data packet fragments.

9. The device according to claim 6, characterized in that, The refraction instruction includes at least a third MTU, such that the source end refractions the original data packet according to the third MTU and sends it to the SSL VPN device; the third MTU is less than or equal to the first MTU.