Method and device for realizing cross-three-layer network communication of two-layer Ethernet, and user side equipment

By configuring LAN, EoGRE network cards and WAN cards on CPE products, and setting network sharing mode and VLAN filtering rules, the cost of layer 2 Ethernet cross-layer network communication on CPE products is solved, and low-cost cross-layer network communication is achieved.

CN120342977APending Publication Date: 2025-07-18SPREADTRUM COMMUNICATION (SHANGHAI) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510538759.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-25
Publication Date
2025-07-18

AI Technical Summary

Technical Problem

The prior art is difficult to realize layer 2 Ethernet across layer 3 network communication on CPE products, resulting in high cost and inability to meet the communication needs of long-distance multi-distance devices.

Method used

By configuring LAN network cards, EoGRE network cards, bridges and WAN cards on CPE products, setting network sharing mode and VLAN filtering rules, and using EoGRE tunnel and layer three routing methods to achieve forwarding of Ethernet data frames.

Benefits of technology

It realizes low-cost layer 2 Ethernet cross-layer network communication on CPE products, and supports communication functions between upper computers, core networks and remote servers.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120342977A_ABST
    Figure CN120342977A_ABST
Patent Text Reader

Abstract

The invention discloses a method and device for realizing cross-three-layer network communication of a two-layer Ethernet and user side equipment, and the method comprises the steps: configuring an LAN network card, an EoGRE network card, a network bridge and a WAN card in advance, and mounting the LAN network card and the EoGRE network card on the network bridge; setting a network sharing mode, setting a VLAN (Virtual Local Area Network) filtering rule, and adding a strategy routing rule in a routing table; an upper computer is connected through an LAN network card interface, and an IP address is allocated to the upper computer according to the network sharing mode; receiving an Ethernet data frame sent by an upper computer; and processing the Ethernet data frame according to the VLAN filtering rule, and then sending the Ethernet data frame through the WAN network card interface. According to the scheme of the invention, two-layer Ethernet cross-three-layer network communication can be simply and conveniently realized on a CPE (Customer Premise Equipment) product.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of communication technologies, and in particular, to a method and apparatus for implementing Layer 2 Ethernet cross-Layer 3 network communication, and a user equipment. Background Art

[0002] The EoGRE (Ethernet over GRE) technology encapsulates Ethernet protocol packets through the GRE (General Routing Encapsulation) technology, enabling these encapsulated data packets to be transmitted in an IP network. The path through which the encapsulated data packets are transmitted in the network is called an EoGRE tunnel. An EoGRE tunnel is a virtual point-to-point connection, and the devices at both ends of the tunnel respectively encapsulate and de-encapsulate the data packets.

[0003] Currently, the demand for communication between devices based on Layer 2 Ethernet local area networks is increasing day by day, and it is limited by hardware environments such as the length of network cables and the number of devices. With the popularization of EoGRE and VLAN (Virtual Local Area Network) technologies, it is possible to achieve Layer 2 Ethernet packet cross-Layer 3 network communication, effectively solving problems such as long distance and multiple devices. Currently, most of the market uses switch devices to implement this technology, with a relatively high implementation cost, and it is impossible to perform device communication between Layer 2 Ethernets on CPE (Customer Premise Equipment) products. Summary of the Invention

[0004] Embodiments of the present application provide a method and apparatus for implementing Layer 2 Ethernet cross-Layer 3 network communication, and a user equipment, to simply and conveniently implement Layer 2 Ethernet cross-Layer 3 network communication on CPE products.

[0005] On the one hand, embodiments of the present application provide a method for implementing Layer 2 Ethernet cross-Layer 3 network communication, the method including:

[0006] Pre-configure a LAN network card, an EoGRE network card, a network bridge, and a WAN network card, and mount the LAN network card and the EoGRE network card on the network bridge;

[0007] Set a network sharing mode, set VLAN filtering rules, and add a policy routing rule to the routing table;

[0008] Connect to a host computer through a LAN network card interface, and assign an IP address to the host computer according to the network sharing mode;

[0009] Receive an Ethernet data frame sent by the host computer;

[0010] Process the Ethernet data frame according to the VLAN filtering rule, and then send it through the WAN network card interface.

[0011] Optionally, the network sharing mode includes any one or more of the following: routing mode, bridge mode, and passthrough mode.

[0012] Optionally, allocating an IP address for the host computer according to the network sharing mode includes:

[0013] When the network sharing mode is the routing mode, the LAN network card allocates a private network IP address for the host computer;

[0014] When the network sharing mode is the bridge mode, the bridge allocates a private network IP address for the host computer;

[0015] When the network sharing mode is the passthrough mode, the LAN network card allocates a public network IP address for the host computer.

[0016] Optionally, processing the Ethernet data frame according to the VLAN filtering rule and then sending it through the WAN network card interface includes:

[0017] When the network sharing mode is the routing mode, determine whether the Ethernet data frame needs to be forwarded through the EoGRE tunnel mode according to the VLAN filtering rule;

[0018] If so, enable the bridge, perform EoGRE encapsulation on the Ethernet data frame, and send the encapsulated EoGRE packet through the WAN network card interface;

[0019] If not, send it through the WAN network card interface in a layer 3 routing manner according to the policy routing rule added in the routing table.

[0020] Optionally, the method further includes: when the network sharing mode is the bridge mode, enable the bridge;

[0021] Processing the Ethernet data frame according to the VLAN filtering rule and then sending it through the WAN network card interface includes:

[0022] Determine whether the Ethernet data frame needs to be forwarded through the EoGRE tunnel mode according to the VLAN filtering rule;

[0023] If so, perform EoGRE encapsulation on the Ethernet data frame, and send the encapsulated EoGRE packet through the WAN network card interface;

[0024] If not, send it through the WAN network card interface in a layer 3 routing manner according to the policy routing rule added in the routing table.

[0025] Optionally, processing the Ethernet data frame according to the VLAN filtering rule and then sending it through the WAN network card interface includes:

[0026] When the network sharing mode is the passthrough mode, determining whether the Ethernet data frame needs to be forwarded through the EoGRE tunnel according to the VLAN filtering rule;

[0027] If so, enabling the bridge, performing EoGRE encapsulation on the Ethernet data frame, and sending the encapsulated EoGRE packet through the WAN network card interface;

[0028] If not, sending it through the WAN network card interface by using the layer 3 routing method according to the policy routing rule added in the routing table.

[0029] Optionally, the VLAN filtering rule includes: if the Ethernet data frame is a VLAN data packet, the Ethernet data frame needs to be forwarded through the EoGRE tunnel; or if the Ethernet data frame is a VLAN data packet and the VLAN ID is the set ID, the Ethernet data frame needs to be forwarded through the EoGRE tunnel.

[0030] Optionally, the method further includes: if the protocol standard carried in the Ethernet data frame is 802_1Q, determining that the Ethernet data frame is a VLAN data packet.

[0031] On the other hand, an embodiment of the present application further provides a device for implementing two-layer Ethernet cross-three-layer network communication. The device includes: a LAN network card, an EoGRE network card, a bridge, and a WAN card, and a setting module; the LAN network card and the EoGRE network card are mounted on the bridge; the LAN network card is used to connect to the upper computer;

[0032] The setting module is used to set the network sharing mode, set the VLAN filtering rule, and add a policy routing rule to the routing table;

[0033] The LAN network card or the bridge receives the Ethernet data frame sent by the upper computer; processes the Ethernet data frame according to the VLAN filtering rule, and then sends it through the WAN network card interface.

[0034] Optionally, the network sharing mode includes any one or more of the following: routing mode, bridge mode, passthrough mode.

[0035] On the other hand, an embodiment of the present application further provides a user terminal device, and the user terminal device includes the device for implementing two-layer Ethernet cross-three-layer network communication.

[0036] On the other hand, an embodiment of the present application further provides a computer-readable storage medium, which is a non-volatile storage medium or a non-transient storage medium, on which a computer program is stored. When the computer program is run by a processor, the steps of the method for implementing two-layer Ethernet cross three-layer network communication are executed.

[0037] On the other hand, an embodiment of the present application further provides a computer program product, including computer programs / instructions, which implement the steps of the method for implementing two-layer Ethernet cross three-layer network communication when executed by a processor.

[0038] The method, device, and user equipment for implementing two-layer Ethernet cross three-layer network communication provided by the embodiments of the present application provide a network sharing technology through a CPE product, share the network to a host computer, so as to implement the communication function among the host computer, the core network, and the remote server; and integrate EoGRE and VLAN technologies to implement two-layer Ethernet cross three-layer network communication at a lower cost. Description of the Drawings

[0039] Figure 1 It is a schematic diagram of the connection mode between the above components in the CPE device using the method of the present application and the host computer and the transmission process of the Ethernet data frame;

[0040] Figure 2 It is a flowchart of a method for implementing remote communication between devices in two-layer Ethernet provided by an embodiment of the present application;

[0041] Figure 3 It is a schematic diagram of the structure of the Ethernet data frame in an embodiment of the present application;

[0042] Figure 4 It is a schematic diagram of the transmission process of the Ethernet data frame sent by the host computer in the routing mode in an embodiment of the present application;

[0043] Figure 5 It is a schematic diagram of the transmission process of the Ethernet data frame sent by the host computer in the bridge mode in an embodiment of the present application;

[0044] Figure 6 It is a schematic diagram of the transmission process of the Ethernet data frame sent by the host computer in the pass-through mode in an embodiment of the present application;

[0045] Figure 7 It is a schematic diagram of the structure of a device for implementing remote communication between devices in two-layer Ethernet provided by an embodiment of the present application. Detailed Embodiments

[0046] To make the above objects, features, and beneficial effects of the present application more obvious and understandable, the following detailed description of the specific embodiments of the present application is provided in conjunction with the accompanying drawings.

[0047] It should be noted that the terms used in the embodiments of the present application are only for the purpose of describing specific embodiments and are not intended to limit this specification. The singular forms "a", "the", and "said" used in the embodiments of the present application and the appended claims are also intended to include the plural forms unless the context clearly indicates otherwise. In addition, "a plurality of" as used in the embodiments of the present application means two or more.

[0048] With the popularization of EoGRE and VLAN technologies, the demand for communication between devices in a two-layer Ethernet on CPE products is increasing day by day. In response to this demand, the embodiments of the present application provide a method, device, and client device for realizing two-layer Ethernet cross-three-layer network communication. By providing network sharing technology through CPE products, the network is shared to the host computer, realizing the communication function between the host computer, the core network, and the remote server, laying the foundation for the network environment. Moreover, EoGRE and VLAN technologies are incorporated into it to achieve two-layer Ethernet cross-three-layer network communication at a relatively low cost.

[0049] In the embodiments of the present application, the following components need to be pre-configured on the CPE product:

[0050] (1) LAN (Local Area Network) network card, which is responsible for duplex data reception of Ethernet packets with the host computer; there are usually multiple LAN ports, and the devices connected to the same local area network usually use the network protocol DHCP (Dynamic Host Configuration Protocol).

[0051] (2) EoGRE (Ethernet over GRE) network card, also known as the EoGRE tunnel, which is responsible for encapsulating and decapsulating EoGRE packets;

[0052] (3) Bridge, both the LAN network card and the EoGRE network card are regarded as port devices and are mounted on the bridge to ensure that when the two network cards conduct business communication, the header information of the Ethernet frame can be retained to realize the forwarding of layer-two data.

[0053] (4) WAN (Wide Area Network) network card, which is responsible for communicating with the EoGRE server. The WAN port is used to connect to external networks such as the Internet and usually there is only one, such as the Internet connection provided by a telecommunications operator.

[0054] Using the above components, a network sharing service can be provided for the host computer. Moreover, by setting the network sharing mode and the corresponding VLAN filtering rules, and adding policy routing rules to the routing table, VLAN filtering can be performed on the Ethernet data frames sent by the host computer, and the Ethernet data frames can be sent through the EoGRE tunnel or the layer 3 routing method according to the filtering conditions.

[0055] The method for realizing remote communication between devices in two-layer Ethernet provided by the embodiments of the present application can be applied to a CPE device. That is to say, the CPE device provides a network sharing function for the host computer, such as Figure 1 shown, which shows the connection method between the above components in the CPE device using the solution of the present application and the host computer, as well as the transmission process of the Ethernet data frames.

[0056] As Figure 2 shown, it is a flowchart of a method for realizing remote communication between devices in two-layer Ethernet provided by the embodiments of the present application, including the following steps:

[0057] Step 201, pre-configure the LAN network card, EoGRE network card, bridge, and WAN network card, and mount the LAN network card and the EoGRE network card on the bridge.

[0058] Step 202, set the network sharing mode, set the VLAN filtering rules, and add policy routing rules to the routing table.

[0059] In the embodiments of the present application, the network sharing mode may include any one or more of the following: routing mode, bridge mode, and pass-through mode. Generally, the structure of an Ethernet data frame is as Figure 3 shown, including the following fields: destination MAC address, source MAC address, VLAN Tag, length or type, data, and FCS (frame check sequence). Among them: the VLAN Tag includes the following fields:

[0060] Tag / Protocol ID: indicates the protocol used for the transmission of this Ethernet data frame;

[0061] Priority: indicates the priority of this Ethernet data frame;

[0062] CFI (Canonical Format Indicator): used to identify the discard priority of the message;

[0063] VLAN ID: used to identify different VLANs.

[0064] The VLAN filtering rules are used to determine how the received Ethernet data frames from the host computer should be sent. For different network sharing modes, the VLAN filtering rules are the same. For example:

[0065] In some embodiments, the following VLAN filtering rules may be set: If the Ethernet data frame is a VLAN data packet, the Ethernet data frame needs to be forwarded through an EoGRE tunnel.

[0066] In other embodiments, the following VLAN filtering rules may also be set: If the Ethernet data frame is a VLAN data packet and the VLAN ID is the set ID, the Ethernet data frame needs to be forwarded through an EoGRE tunnel.

[0067] Step 203: Connect to the host computer through the LAN network card interface and assign an IP address to the host computer according to the network sharing mode.

[0068] When the network sharing mode is the routing mode, the LAN network card can assign a private IP address to the host computer;

[0069] When the network sharing mode is the bridge mode, the bridge can assign a private IP address to the host computer;

[0070] When the network sharing mode is the passthrough mode, the LAN network card can assign a public IP address to the host computer.

[0071] Step 204: Receive the Ethernet data frames sent by the host computer.

[0072] Specifically, receive the Ethernet data frames sent by the host computer through the LAN network card interface.

[0073] Step 205: Process the Ethernet data frames according to the VLAN filtering rules and then send them through the WAN network card interface.

[0074] When the sharing mode is the routing mode, determine whether the received Ethernet data frames need to be forwarded through an EoGRE tunnel according to the VLAN filtering rules; if so, enable the bridge, perform EoGRE encapsulation on the Ethernet data frames, and send the encapsulated EoGRE packets through the WAN network card interface; if not, send them through the WAN network card interface using the layer-three routing method according to the policy routing rules added in the routing table.

[0075] When the network sharing mode is the bridge mode, the bridge needs to be enabled first. After receiving the Ethernet data frame sent by the host computer, it is determined whether the Ethernet data frame needs to be forwarded through the EoGRE tunnel according to the VLAN filtering rule; if so, the Ethernet data frame is encapsulated by EoGRE, and the encapsulated EoGRE packet is sent through the WAN network card interface; if not, it is sent through the WAN network card interface by using the layer 3 routing method according to the policy routing rule added in the routing table.

[0076] When the network sharing mode is the passthrough mode, it is determined whether the Ethernet data frame needs to be forwarded through the EoGRE tunnel according to the VLAN filtering rule; if so, the bridge is enabled, the Ethernet data frame is encapsulated by EoGRE, and the encapsulated EoGRE packet is sent through the WAN network card interface; if not, it is sent through the WAN network card interface by using the layer 3 routing method according to the policy routing rule added in the routing table.

[0077] Refer to Figure 3 the data frame structure shown below, for example, the filtering rules are as follows:

[0078] (1) If the "tag / protocol ID" field in the Ethernet data frame is 802_1Q, whether the Ethernet data frame needs to be forwarded through the EoGRE tunnel; or

[0079] (2) If the "tag / protocol ID" field in the Ethernet data frame is 802_1Q and the "VLAN ID" is 100, whether the Ethernet data frame needs to be forwarded through the EoGRE tunnel. The following combines Figure 4 、 Figure 5 and Figure 6 to detail the sending process of the Ethernet data frame sent by the host computer in the above three network sharing modes respectively.

[0080] Refer to Figure 4 , Figure 4 which is a schematic diagram of the transmission process of the Ethernet data frame sent by the host computer in the routing mode in the embodiment of the present application.

[0081] In the routing mode, the LAN network card interface of the CPE 20 has the IP address 192.168.42.1, and assigns the private network IP address 192.168.42.2 to the host computer 10 through the DHCP server. The IP address of the WAN network card interface is 10.10.1.10, and the IP address of the EoGRE server 30 is 10.10.1.20.

[0082] In the embodiments of the present application, VLAN filtering rules can be set using ebtables (Ethenet bridge frame table administration). Ebtables is an application used to set and maintain rule tables, and the rules in these tables are used to check Ethernet frames.

[0083] Ebtables has three tables, namely the filter (filtering) table, the nat (network address translation) table, and the broute (routing) table. Among them, the filter is the table for the default operation of commands. Use "-t table" to specify the table to be operated on, and the -t parameter must also be the first parameter in the ebtables command line. Among them:

[0084] The filter table contains three chains: FORWARD, INPUT, and OUTPUT, which are used to filter data packets and determine whether to allow the data packets to pass through.

[0085] The nat table is used to implement network address translation and modify the source / destination address of data packets, usually used to route data packets to networks that cannot be directly accessed.

[0086] The broute table has a BROUTING chain, which is used to handle broadcast routing in bridged networks. When a data packet enters or leaves a bridging device, the rules in the broute table will be applied to determine how the data packet is processed.

[0087] When the data matches a rule in the ebtables chain, the data frame will be processed according to that rule; if it does not match, the next rule in the chain will be matched.

[0088] Ebtables has multiple targets, namely ACCEPT, DROP, CONTINUE, and RETURN. Among them, ACCEPT means to let the data frame pass through; DROP means to discard the data frame; in the CONTINUE chain, ACCEPT and DROP have different meanings. CONTINUE means to check the next rule; RETURN means to stop traversing this chain and return to the next rule of the chain that called this chain.

[0089] In this embodiment, the following VLAN filtering rules can be set:

[0090] 1. If the VLAN filtering parameter configured by the user is 0, the command configuration is as follows:

[0091] 1.1 ebtables –A OUTPUT –p! 802_1Q –logical-out tether –j DROP;

[0092] This rule means: Add on the OUTPUT chain, the egress device is a bridge, and packets that are not of the 802_1Q protocol are DROPPED;

[0093] 1.2 ebtables –t broute –A BROUTING –p! 802_1Q –logical-in tether –j DROP;

[0094] This rule means: Add the broute table, on the BROUTING chain, the ingress device is a bridge, and packets that are not of the 802_1Q protocol are DROPPED.

[0095] 2. If the VLAN filtering parameters configured by the user are 100 and 200, then the following three rules need to be added to the above two original rules:

[0096] 2.1 ebtables –t broute –A BROUTING –p 802_1Q --vlan-id 100 --logical-in tether –j ACCEPT;

[0097] This rule means: Add on the broute table, on the BROUTING chain, the protocol is 802_1Q, the vlan_id is 100, the ingress device is a bridge, that is, perform the ACCEPT action;

[0098] 2.2 ebtables –t broute –A BROUTING –p 802_1Q --vlan-id 200 –logical-in tether –j ACCEPT;

[0099] This rule means: Add on the broute table, on the BROUTING chain, the protocol is 802_1Q, the vlan_id is 200, the ingress device is a bridge, that is, perform the ACCEPT action;

[0100] 2.3 ebtables –t broute –A BROUTING –p 802_1Q –logical-in tether –j DROP;

[0101] This rule means: Add on the broute table, on the BROUTING chain, the protocol is 802_1Q, for other vlan_ids (not 100 or 200), perform the DROP action.

[0102] For example, when a non-VLAN data frame sent by the upper computer passes through the bridge device, it will match rule 1.2, and this data frame will be DROPPED and handed over to layer three for processing.

[0103] For another example, when the VLAN ID = 100 in the data frame sent by the upper computer, when passing through the bridge device, Rule 2.1 is matched at this time, and the data frame will be ACCEPTED and forwarded to the EoGRE network card, and the EoGRE network card will encapsulate it, and the encapsulated EoGRE message will be sent through the WAN network card interface.

[0104] Such as Figure 5 shown, is a schematic diagram of the transmission process of the Ethernet data frame sent by the upper computer in the bridge mode of the embodiment of the present application.

[0105] In the bridge mode, the bridge of CPE 20 has an IP address of 192.168.42.1, and assigns a private network IP address of 192.168.42.2 to the upper computer 10 through the DHCP server. The IP address of the WAN network card interface is 10.10.1.10, and the IP address of the EoGRE server 30 is 10.10.1.20.

[0106] In the embodiment of the present application, the VLAN filtering rules can be set by using ebtables (Ethenet bridge frame table administration), specifically as follows:

[0107] 1. If the user configures the vlan parameter to be 0, the following rules are adopted:

[0108] 1.1 ebtables –A FORWARD –p! 802_1Q –i gretap1 –j DROP;

[0109] This rule means that on the FORWARD chain, the protocol is not 802_1Q, the incoming device is the EoGRE network card, and the DROP action is executed;

[0110] 2. If the user configures the vlan parameters to be 100 and 200, the following several rules need to be added on the basis of the above-mentioned rule:

[0111] 2.1 ebtables –A FORWARD –p 802_1Q --vlan-id 100 –i gretap1 –j ACCEPT;

[0112] 2.2 ebtables –A FORWARD –p 802_1Q --vlan-id 100 –o gretap1 –j ACCEPT;

[0113] 2.3 ebtables –A FORWARD –p 802_1Q --vlan-id 200 –i gretap1 –j ACCEPT;

[0114] 2.4 ebtables –A FORWARD –p 802_1Q --vlan-id 200 –o gretap1 –j ACCEPT;

[0115] The above 2.1 - 2.4 means that on the FORWARD chain, the protocol is 802_1Q, the vlan_id is 100 or 200, the in / out device is the EoGRE network card, and the ACCEPT action is executed;

[0116] 2.5 ebtables –A FORWARD –p 802_1Q –i gretap1 –j DROP;

[0117] 2.6 ebtables –A FORWARD –p 802_1Q –o gretap1 –j DROP;

[0118] The above 2.5 - 2.6 means that on the FORWARD chain, the protocol is 802_1Q, the in / out device is the EoGRE network card, and the DROP action is executed.

[0119] For example, when the upper computer sends a non-VLAN data frame, when it passes through the EoGRE network card, it will match rule 1.1, and this data frame will be DROPped and handed over to layer three for processing;

[0120] For another example, when the VLAN ID = 100 in the data frame sent by the upper computer and it passes through the EoGRE network card, at this time rules 2.1 and 2.2 are matched, and this data frame will be ACCEPTed and the encapsulated EoGRE packet will be sent through the WAN network card interface.

[0121] As Figure 6 shown, it is a schematic diagram of the transmission process of the Ethernet data frame sent by the upper computer in the transparent transmission mode in the embodiment of the present application.

[0122] In the transparent transmission mode, the LAN network card interface of the CPE 20 has the IP address 10.10.1.11, and the public network IP address is assigned to the upper computer 10 through the DHCP server, that is, the IP address 10.10.1.10 of the WAN network card interface is directly assigned to the upper computer. The IP address of the WAN network card interface is a randomly assigned private network address 192.168.1.33, and the IP address of the EoGRE server 30 is 10.10.1.20.

[0123] In the embodiments of this application, the VLAN filtering rules can be set using ebtables (Ethenet bridge frame table administration), as follows:

[0124] 1. If the VLAN filtering parameter configured by the user is 0, the command configuration is as follows:

[0125] 1.1 ebtables –A OUTPUT –p! 802_1Q –logical-out tether –j DROP;

[0126] This rule means: Add to the OUTPUT chain, the egress device is the bridge, and packets that are not of the 802_1Q protocol are DROPPED;

[0127] 1.2 ebtables –t broute –A BROUTING –p! 802_1Q –logical-in tether –j DROP;

[0128] This rule means: Add to the broute table, the BROUTING chain, the ingress device is the bridge, and packets that are not of the 802_1Q protocol are DROPPED;

[0129] 2. If the VLAN filtering parameters configured by the user are 100 and 200, then the following three rules need to be added on top of the above two rules:

[0130] 2.1 ebtables –t broute –A BROUTING –p 802_1Q --vlan-id 100 --logical-in tether –j ACCEPT;

[0131] This rule means: Add to the broute table, the BROUTING chain, the protocol is 802_1Q, the vlan_id is 100, the ingress device is the bridge, that is, perform the ACCEPT action;

[0132] 2.2 ebtables –t broute –A BROUTING –p 802_1Q --vlan-id 200 –logical-in tether –j ACCEPT;

[0133] This rule means: Add to the broute table, the BROUTING chain, the protocol is 802_1Q, the vlan_id is 200, the ingress device is the bridge, that is, perform the ACCEPT action;

[0134] 2.3 ebtables –t broute –A BROUTING –p 802_1Q –logical-in tether –j DROP;

[0135] This rule means: Add to the broute table, on the BROUTING chain, with the protocol being 802_1Q, the ingress device being the bridge, and perform the DROP action. For example, when the data frame sent by the host computer is a non-VLAN data frame, when it passes through the bridge device, at this time Rule 1.2 is matched, and this data frame will be DROPped and handed over to Layer 3 for processing;

[0136] For another example, when the VLAN ID = 100 in the data frame sent by the host computer, when it passes through the bridge device, at this time Rule 2.1 is matched, and this data frame will be ACCEPTed and forwarded to the EoGRE network card, and the EoGRE network card will encapsulate it, and the encapsulated EoGRE packet will be sent through the WAN network card interface.

[0137] The method for implementing Layer 2 Ethernet cross-Layer 3 network communication provided by the embodiments of the present application provides a network sharing technology through a CPE product to share the network to the host computer, thereby realizing the communication function between the host computer, the core network, and the remote server; and integrating EoGRE and VLAN technologies to realize Layer 2 Ethernet cross-Layer 3 network communication at a relatively low cost.

[0138] Correspondingly, the embodiments of the present application also provide a device for implementing Layer 2 Ethernet cross-Layer 3 network communication, as Figure 7 shown, which is a schematic structural diagram of the device.

[0139] The device 70 for implementing Layer 2 Ethernet cross-Layer 3 network communication in this embodiment includes:

[0140] A LAN network card 71, an EoGRE network card 72, a bridge 73, a WAN card 74, and a setting module 75. Among them, the LAN network card 71 and the EoGRE network card 72 are mounted on the bridge 73, and the LAN network card 71 is connected to the host computer through a LAN network card interface;

[0141] The setting module 75 is used to set the network sharing mode, set the VLAN filtering rules, and add policy routing rules to the routing table;

[0142] The LAN network card 71 and / or the bridge 73 are used to allocate an IP address to the host computer according to the network sharing mode, receive the Ethernet data frame sent by the host computer; process the received Ethernet data frame according to the VLAN filtering rules, and then send it through the WAN network card interface.

[0143] The network sharing mode may include any one or more of the following: routing mode, bridging mode, and pass-through mode.

[0144] In different network sharing modes, the LAN network card 71 or the bridge 73 receives the Ethernet data frame sent by the host computer; processes the Ethernet data frame according to the VLAN filtering rule, and then sends it through the WAN network card interface. Specifically, when the Ethernet data frame is a VLAN data packet, perform EoGRE on the Ethernet data frame, and send the encapsulated EoGRE data packet to the EoGRE server through the WAN network card interface; or when the Ethernet data frame is a VLAN data packet and the VLAN ID is the set ID, perform EoGRE on the Ethernet data frame, and send the encapsulated EoGRE data packet to the EoGRE server through the WAN network card interface. When the Ethernet data frame is not a VLAN data packet, send the Ethernet data frame through the WAN network card interface using the layer three routing method.

[0145] The network sharing mode includes any one or more of the following: routing mode, bridging mode, and pass-through mode. For the filtering and sending process of the Ethernet data frame in different network sharing modes, refer to the description in the method embodiment of realizing two-layer Ethernet cross-three-layer network communication in the present application before, and details are not described herein again.

[0146] Correspondingly, an embodiment of the present application further provides a client device, including the above device for realizing two-layer Ethernet cross-three-layer network communication. Using this client device, network sharing services can be provided for the host computer, and remote communication across three-layer networks can be provided for the host computer.

[0147] The client device in the embodiment of the present application may also be referred to as a terminal device, and may refer to various forms of terminal devices, such as user equipment, access terminal, user unit, user station, mobile station, mobile station (Mobile Station, MS), remote station, remote terminal, mobile device, user terminal, wireless communication device, user agent or user device. The terminal device may also be a cellular phone, cordless phone, Session Initiation Protocol (SIP) phone, Wireless Local Loop (WLL) station, Personal Digital Assistant (PDA), handheld device with wireless communication function, computing device or other processing devices connected to a wireless modem, vehicle-mounted device, wearable device, terminal device in the future 5G network or terminal device in the future evolved Public Land Mobile Network (PLMN), etc., and the embodiment of the present application does not limit this.

[0148] In a specific implementation, the above-described apparatus for realizing remote communication between devices in a two-layer Ethernet can correspond to a chip with corresponding functions in a network device and / or a terminal device, such as a SOC (System-On-a-Chip), a chip module, etc.

[0149] In a specific implementation, for each module / unit included in each of the above-described apparatuses and products, it can be a software module / unit, a hardware module / unit, or it can also be partially a software module / unit and partially a hardware module / unit.

[0150] For example, for each apparatus and product applied to or integrated into a chip, each module / unit included therein can be implemented in a hardware manner such as a circuit, or at least some of the module / units can be implemented in a software program manner, and the software program runs on a processor integrated inside the chip, and the remaining (if any) part of the module / units can be implemented in a hardware manner such as a circuit; for each apparatus and product applied to or integrated into a chip module, each module / unit included therein can be implemented in a hardware manner such as a circuit, and different module / units can be located in the same component (such as a chip, a circuit module, etc.) or different components of the chip module, or at least some of the module / units can be implemented in a software program manner, and the software program runs on a processor integrated inside the chip module, and the remaining (if any) part of the module / units can be implemented in a hardware manner such as a circuit; for each apparatus and product applied to or integrated into a terminal, each module / unit included therein can be implemented in a hardware manner such as a circuit, and different module / units can be located in the same component (such as a chip, a circuit module, etc.) or different components inside the terminal, or at least some of the module / units can be implemented in a software program manner, and the software program runs on a processor integrated inside the terminal, and the remaining (if any) part of the module / units can be implemented in a hardware manner such as a circuit.

[0151] An embodiment of the present application further provides a computer-readable storage medium, where the computer-readable storage medium is a non-volatile storage medium or a non-transitory storage medium, and a computer program is stored thereon, and when the computer program is run by a processor, it executes the steps in the above-described method embodiments.

[0152] An embodiment of the present application further provides an apparatus for realizing remote communication between devices in a two-layer Ethernet, including a memory and a processor, where a computer program that can run on the processor is stored on the memory, and when the processor runs the computer program, it executes the steps in the above-described method embodiments.

[0153] It should be understood that the term "and / or" in this text is merely a description of the association relationship between associated objects, indicating that there can be three relationships. For example, A and / or B can represent three situations: A exists alone, A and B exist simultaneously, and B exists alone. Additionally, the character " / " in this text indicates that the associated objects before and after are in an "or" relationship.

[0154] In the embodiments of the present application, "a plurality of" means two or more.

[0155] The first, second, etc. descriptions that appear in the embodiments of the present application are only for schematic and distinguishing the described objects, without an order, nor do they represent a special limitation on the number of devices in the embodiments of the present application, and cannot constitute any limitation to the embodiments of the present application.

[0156] Each embodiment provided by the present application can be implemented in whole or in part by software, hardware, firmware, or any other combination. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, the processes or functions described in the embodiments of the present application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center in a wired or wireless manner. It should be understood that in various embodiments of the present application, the magnitudes of the sequence numbers of the above processes do not mean the order of execution, and the execution order of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present application.

[0157] In several embodiments provided by the present application, it should be understood that the disclosed methods, devices, and systems can be implemented in other ways. For example, the device embodiments described above are merely illustrative; for example, the division of the units is only a logical function division, and there can be other division methods in actual implementation; for example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces, and the indirect couplings or communication connections of the devices or units can be in electrical, mechanical, or other forms.

[0158] The unit described as a separation component may or may not be physically separated, and the component displayed as a unit may or may not be a physical unit, that is, it may be located in one place or may be distributed across multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0159] In addition, each functional unit in various embodiments of the present application may be integrated in a processing unit, may be individually physically arranged for each unit, or two or more units may be integrated in one unit. The above integrated unit may be implemented in the form of hardware or in the form of a hardware plus software functional unit.

[0160] Although the present application is disclosed as above, the present application is not limited thereto. Any person skilled in the art can make various changes and modifications without departing from the spirit and scope of the present application. Therefore, the protection scope of the present application should be subject to the scope defined by the claims.

Claims

1. A method for realizing layer - two Ethernet cross - layer - three network communication, characterized in that, The method includes: Pre-configuring a LAN network card, an EoGRE network card, a network bridge, and a WAN card, and mounting the LAN network card and the EoGRE network card on the network bridge; Setting a network sharing mode, setting VLAN filtering rules, and adding policy routing rules to the routing table; Connecting to a host computer through the LAN network card interface, and allocating an IP address to the host computer according to the network sharing mode; Receiving an Ethernet data frame sent by the host computer; Processing the Ethernet data frame according to the VLAN filtering rules, and then sending it through the WAN network card interface.

2. The method according to claim 1, characterized in that, The network sharing mode includes any one or more of the following: routing mode, bridge mode, and pass-through mode.

3. The method according to claim 2, wherein The allocating an IP address to the host computer according to the network sharing mode includes: When the network sharing mode is the routing mode, the LAN network card allocates a private network IP address to the host computer; When the network sharing mode is the bridge mode, the network bridge allocates a private network IP address to the host computer; When the network sharing mode is the pass-through mode, the LAN network card allocates a public network IP address to the host computer.

4. The method according to claim 2, wherein The processing the Ethernet data frame according to the VLAN filtering rules, and then sending it through the WAN network card interface includes: When the network sharing mode is the routing mode, determining whether the Ethernet data frame needs to be forwarded through the EoGRE tunnel mode according to the VLAN filtering rules; If so, enabling the network bridge, performing EoGRE encapsulation on the Ethernet data frame, and sending the encapsulated EoGRE packet through the WAN network card interface; If not, sending it through the WAN network card interface using the layer three routing method according to the policy routing rules added to the routing table.

5. The method according to claim 2, wherein The method further includes: when the network sharing mode is the bridge mode, enabling the network bridge; The processing the Ethernet data frame according to the VLAN filtering rules, and then sending it through the WAN network card interface includes: Determining whether the Ethernet data frame needs to be forwarded through the EoGRE tunnel mode according to the VLAN filtering rules; If so, performing EoGRE encapsulation on the Ethernet data frame, and sending the encapsulated EoGRE packet through the WAN network card interface; If not, sending it through the WAN network card interface using the layer three routing method according to the policy routing rules added to the routing table.

6. The method according to claim 2, wherein The processing the Ethernet data frame according to the VLAN filtering rules, and then sending it through the WAN network card interface includes: When the network sharing mode is the pass-through mode, determining whether the Ethernet data frame needs to be forwarded through the EoGRE tunnel mode according to the VLAN filtering rules; If so, enabling the network bridge, performing EoGRE encapsulation on the Ethernet data frame, and sending the encapsulated EoGRE packet through the WAN network card interface; If not, sending it through the WAN network card interface using the layer three routing method according to the policy routing rules added to the routing table.

7. The method according to claim 4 or 5 or 6, characterized in that, The VLAN filtering rules include: If the Ethernet data frame is a VLAN data packet, the Ethernet data frame needs to be forwarded through an EoGRE tunnel; or If the Ethernet data frame is a VLAN data packet and the VLAN ID is the set ID, the Ethernet data frame needs to be forwarded through an EoGRE tunnel.

8. The method according to claim 7, wherein The method further includes: If the protocol standard carried in the Ethernet data frame is 802_1Q, it is determined that the Ethernet data frame is a VLAN data packet.

9. A device for implementing Layer 2 Ethernet cross-Layer 3 network communication, characterized in that, The device includes: a LAN network card, an EoGRE network card, a bridge, and a WAN card, and a setting module; the LAN network card and the EoGRE network card are mounted on the bridge; the LAN network card is used to connect to the host computer; The setting module is used to set the network sharing mode, set the VLAN filtering rules, and add policy routing rules to the routing table; The LAN network card or the bridge receives the Ethernet data frame sent by the host computer; processes the Ethernet data frame according to the VLAN filtering rules, and then sends it through the WAN network card interface.

10. The device according to claim 9, characterized in that, The network sharing mode includes any one or more of the following: routing mode, bridge mode, pass-through mode.

11. A client device, characterized in that, The client device includes the device for implementing two-layer Ethernet cross-three-layer network communication according to claim 9 or 10.

12. A computer-readable storage medium, the computer-readable storage medium being a non-volatile storage medium or a non-transitory storage medium, having a computer program stored thereon, characterized in that, When the computer program is run by a processor, it executes the steps of the method for implementing two-layer Ethernet cross-three-layer network communication according to any one of claims 1 to 8.

13. A computer program product, comprising a computer program / instructions, characterized in that, When the computer program / instructions are executed by a processor, the steps of the method for implementing two-layer Ethernet cross-three-layer network communication according to any one of claims 1 to 8 are implemented.