A communication method and apparatus
Patent Information
- Application Number
- CN202510378095.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-26
- Publication Date
- 2026-09-29
AI Technical Summary
然而在接入设备上部署安全特性会消耗接入设备的资源,而接入设备的资源通常是有限的,这就导致无法在接入设备上部署较多的安全特性,从而带来安全隐患
Smart Images

Figure CN122845149A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communications, and in particular to a communication method and apparatus. Background Technology
[0002] The campus network adopts a three-layer network architecture of "access + aggregation + core". The access layer provides access methods for terminal devices and is the first layer for terminal devices to access the network. The aggregation layer is the network boundary between the access layer and the campus core backbone network. The aggregation layer is mainly used to forward east-west traffic between terminal devices and north-south traffic between the access layer and the core layer. The core layer is the core of data exchange in the campus and is responsible for high-speed interconnection of the entire campus network. The core layer can connect various components of the campus network, such as data centers and the aggregation layer.
[0003] To improve campus network security, the network needs to support certain security features, such as the common network access control (NAC) function. Currently, common interface-level security features in campus networks require deployment on access layer devices. However, deploying security features on access devices consumes their resources, which are typically limited. This limits the number of security features that can be deployed on access devices, thus creating security vulnerabilities.
[0004] Therefore, a solution is urgently needed to address the above problems. Summary of the Invention
[0005] This application provides a communication method and apparatus that can deploy security features on a central device with more resources than access devices. Furthermore, the security features are related to the access location of the terminal device on the access device, thereby enabling the deployment of access location-level security features on the central device.
[0006] Firstly, this application provides a communication method applied to an access device. The access device receives a first message sent by a terminal device through a first interface, where the first interface is an interface on the access device. The terminal device accesses the access device through the first interface. After receiving the first message, the access device obtains a second message based on the first message; for example, the access device re-encapsulates the first message to obtain the second message. The second message includes access location information, which indicates the first interface on the access device. After obtaining the second message, the access device sends the second message to a central device. This second message is used by the central device to generate table entry information including the access location information, which is used to implement security features related to the terminal device. In this application, the central device has more resources than the access device; therefore, the central device has sufficient resources to generate the table entry information. Moreover, although the table entry information is generated by the central device, it includes the access location information, thereby enabling the table entry information to implement access location-level security features.
[0007] In one possible implementation, the entry information is Dynamic Host Configuration Protocol Snooping (DHCP SNP) entry information, which further includes the media access control (MAC) address and the Internet Protocol (IP) address of the terminal device. In this scenario, the central device can generate DHCP SNP entry information that includes the access location information of the terminal device, thus achieving access location-level security features.
[0008] In one possible implementation, the second message includes the MAC address and IP address of the terminal device. In this case, after receiving the second message, the central device extracts the source IP address (i.e., the IP address of the terminal device), the source MAC address (i.e., the MAC address of the terminal device), and the access location information included in the second message, thereby generating DHCPSNP entry information including the IP address of the terminal device, the MAC address of the terminal device, and the access location information.
[0009] In one possible implementation, the second message includes the MAC address of the terminal device but does not include its IP address. In this scenario, after receiving the second message, the central device extracts the source MAC address and the access location information included in the second message. Furthermore, when the DHCP server sends a DHCP response message to the terminal device through the central device, the central device obtains the IP address of the terminal device from the DHCP message. Further, the central device generates DHCP SNP entry information including the IP address, MAC address, and access location information of the terminal device based on the MAC address, IP address, and access location information of the terminal device.
[0010] In one possible implementation, after generating the aforementioned DHCP SNP entry information, the central device can also intercept illegal ARP packets based on this DHCP SNP entry information. Specifically, the access device receives a first Address Resolution Protocol (ARP) packet sent by the terminal device through the first interface. The source IP address of the first ARP packet is the IP address of the terminal device, and the source MAC address of the first ARP packet is the MAC address of the terminal device. Further, the access device obtains a second ARP packet based on the first ARP packet. The second ARP packet includes the access location information, and the source IP address of the second ARP packet is the IP address of the terminal device, and the source MAC address of the second ARP packet is the MAC address of the terminal device. After obtaining the second ARP packet, the access device sends the second ARP packet to the central device. The source MAC address, source IP address, and access location information in the second ARP packet are used by the central device to verify the legality of the second ARP packet. In one example, after receiving the second ARP packet sent by the access device, the central device extracts the source IP address, the source MAC address, and the access location information from the second ARP packet. Based on the extracted source IP address, source MAC address, and access location information, it matches them with the aforementioned DHCP SNP table entries. If the match is successful, the second ARP packet is determined to be valid; if the match fails, the second ARP packet is determined to be invalid.
[0011] In one possible implementation, after generating the table entry information for the terminal device, the central device sends the table entry information to the access device. Correspondingly, the access device receives the table entry information sent by the central device. As a specific example, the central device sends a control protocol message to the control plane processing unit, the control protocol message including the table entry information. Correspondingly, the control plane processing unit receives the control protocol message sent by the central device and parses the control protocol message to obtain the table entry information, so that the access device can subsequently use the table entry information for traffic filtering.
[0012] In one possible implementation, the control plane processing unit generates an access control list (ACL) corresponding to the received table entry information, and sends the generated ACL to the data plane processing unit, which then filters packets from the terminal device based on the ACL.
[0013] In one possible implementation, after the central device generates the table entry information for the terminal device, it generates a corresponding ACL based on the table entry information and sends the ACL to the access device. Correspondingly, the access device receives the ACL sent by the central device. As a specific example, the central device sends a control protocol message to the control plane processing unit, the control protocol message including the ACL. Correspondingly, the control plane processing unit receives the control protocol message sent by the central device and parses the control protocol message to obtain the ACL, so that the access device can subsequently use the ACL for traffic filtering.
[0014] In one possible implementation, after receiving the ACL sent by the central device, the control plane processing unit sends the ACL to the data plane processing unit, which then filters the packets from the terminal device based on the ACL.
[0015] In one possible implementation, the first packet includes a virtual local area network (VLAN) encapsulation. The access device adds an outer VLAN encapsulation to the first packet to obtain the second packet, and the access location information is located in the outer VLAN encapsulation. In this scenario, the second packet includes two layers of VLAN encapsulation: the outer VLAN encapsulation carries the aforementioned access location information, and the inner VLAN encapsulation is the same as the VLAN encapsulation included in the first packet.
[0016] In one possible implementation, considering that in practice, a VLAN identifier can be assigned to the first interface, for example, a first VLAN identifier can be assigned to the first interface, which can uniquely identify the first interface on the access device, therefore, in one example, the access location information is: the first VLAN identifier assigned to the first interface.
[0017] In one possible implementation, the inner VLAN encapsulation of the second packet includes a second VLAN identifier, which is the VLAN identifier corresponding to the service of the terminal device. The inner VLAN encapsulation of the second packet is the VLAN encapsulation of the first packet. In this scenario, the aforementioned table entry information generated by the central device also includes the second VLAN identifier.
[0018] In one possible implementation, the access device can also receive a fourth message sent by the central device, the destination device of which is the terminal device, and the fourth message includes the access location information. After receiving the fourth message, the central device obtains a third message based on the fourth message. The third message does not include the access location information, and further forwards the third message through the first interface indicated by the access location information. Since the first interface is the interface through which the terminal device accesses the access device, the access device can forward the third message to the terminal device by forwarding it through the first interface, thereby realizing the sending of messages to the terminal device.
[0019] In one possible implementation, the fourth packet includes two layers of VLAN encapsulation. Specifically, the fourth packet is, for example, a packet obtained by the access device by adding an outer VLAN encapsulation to the third packet. The outer VLAN encapsulation of the fourth packet includes the access location information. In this scenario, the access device strips the outer VLAN encapsulation of the fourth packet to obtain the third packet, and determines the interface for forwarding the third packet as the first interface through the access location information in the outer VLAN encapsulation.
[0020] In one possible implementation, the central device includes either a core layer network device or an aggregation layer network device. Using this solution, access location-level security features can be implemented on resource-rich core layer or aggregation layer network devices.
[0021] Secondly, this application provides a communication method applied to a central device. The central device receives a second message sent by an access device, wherein the second message is obtained by the access device based on a first message sent by a terminal device to the access device. The second message includes access location information, which indicates a first interface on the access device. The first interface is an interface on the access device used to receive the first message. The central device has more resources than the access device. After receiving the second message, the central device generates entry information including the access location information based on the access location information. This entry information is used to implement security features related to the terminal device. In this application, because the central device has more resources than the access device, the central device has sufficient resources to generate the entry information. Moreover, although the entry information is generated by the central device, it includes the access location information, thereby enabling the entry information to implement access location-level security features.
[0022] In one possible implementation, the entry information is Dynamic Host Configuration Protocol (DHCP) SNP entry information, which further includes the Media Access Control (MAC) address of the terminal device and the Internet Protocol (IP) address of the terminal device.
[0023] In one possible implementation, the second message further includes the MAC address and the IP address. Before generating the entry information, the method further includes: extracting the access location information, the MAC address, and the IP address from the second message; generating entry information including the access location information based on the access location information includes: generating the DHCP SNP entry information based on the access location information, the MAC address, and the IP address.
[0024] In one possible implementation, the second message includes the MAC address. Before generating the entry information, the method further includes: extracting the access location information and the MAC address from the second message; obtaining the IP address from a DHCP response message sent by the DHCP server to the terminal device; and generating entry information including the access location information based on the access location information, which includes: generating the DHCP SNP entry information based on the access location information, the MAC address, and the IP address.
[0025] In one possible implementation, the central device can also generate ARP entry information for the terminal device based on the DHCP response message and the aforementioned DHCP SNP entry information. Furthermore, the ARP entry information generated by the central device includes the access location information of the terminal device. Specifically, the central device extracts the IP address and MAC address of the terminal device from the DHCP response message sent by the DHCP server to the terminal device, and queries the DHCP SNP entry information based on the IP address and MAC address to obtain the access location information. Further, based on the IP address, MAC address, and access location information of the terminal device, it obtains Address Resolution Protocol (ARP) entry information, which includes the IP address, MAC address, and access location information of the terminal device.
[0026] In one possible implementation, the method further includes: receiving a second ARP packet sent by the access device, the second ARP packet being obtained by the access device based on a first ARP packet sent by a terminal device to the access device, the second ARP packet including the access location information, the first ARP packet being received by the access device through the first interface, the source IP address of the second ARP packet being the IP address of the terminal device, and the source MAC address of the second ARP packet being the MAC address of the terminal device; and performing a validity check on the second ARP packet based on the source MAC address, the source IP address, the access location information, and the DHCPSNP entry information in the second ARP packet.
[0027] In one possible implementation, the method further includes: sending the table entry information or access control list (ACL) to the access device, wherein the ACL is generated by the central device based on the table entry information, and the ACL is used by the access device to filter packets from the terminal device.
[0028] In one possible implementation, the access device includes a control plane processing unit, and sending the table entry information or access control list (ACL) to the access device includes: sending a control protocol message to the control plane processing unit, wherein the control protocol message includes the table entry information or the ACL.
[0029] In one possible implementation, the first message includes a VLAN encapsulation layer, and the second message adds an outer VLAN encapsulation layer to the first message, with the access location information located in the outer VLAN encapsulation layer.
[0030] In one possible implementation, the access location information is: a first VLAN identifier assigned to the first interface.
[0031] In one possible implementation, the inner VLAN encapsulation of the second message includes a second VLAN identifier, which is the VLAN identifier corresponding to the service of the terminal device. The table entry information also includes the second VLAN identifier, and the inner VLAN encapsulation of the second message is the VLAN encapsulation of the first message.
[0032] In one possible implementation, the central device further receives a third message, the destination of which is the terminal device, and obtains a fourth message based on the third message, wherein the fourth message includes the access location information. Further, the fourth message is sent to the access device so that the access device forwards the fourth message to the terminal device based on the access location information.
[0033] In one possible implementation, before obtaining the fourth message based on the third message, the method further includes: querying the table entry information based on the destination IP address and destination MAC address included in the third message to obtain the access location information.
[0034] In one possible implementation, the third message includes a VLAN encapsulation layer, and the fourth message adds an outer VLAN encapsulation layer on top of the first message, with the access location information located in the outer VLAN encapsulation layer of the fourth message.
[0035] In one possible implementation, the central device includes either a core layer network device or a convergence layer network device.
[0036] Thirdly, this application provides a communication device applied to an access device, the device comprising: a receiving unit, configured to receive a first message sent by a terminal device through a first interface, the first interface being an interface on the access device; a processing unit, configured to obtain a second message based on the first message, the second message including access location information, the access location information being used to indicate the first interface on the access device; and a sending unit, configured to send the second message to a central device, the second message being used by the central device to generate table entry information including the access location information, the central device having more resources than the access device.
[0037] In one possible implementation, the entry information is Dynamic Host Configuration Protocol (DHCP) SNP entry information, which further includes the Media Access Control (MAC) address of the terminal device and the Internet Protocol (IP) address of the terminal device.
[0038] In one possible implementation, the second message also includes the MAC address and the IP address.
[0039] In one possible implementation, the second message also includes the MAC address, and the IP address in the DHCP SNP entry information is obtained by the central device from the DHCP response message sent from the DHCP server to the terminal device.
[0040] In one possible implementation, the receiving unit is further configured to receive a first Address Resolution Protocol (ARP) packet sent by the terminal device through the first interface, wherein the source IP address of the first ARP packet is the IP address of the terminal device, and the source MAC address of the first ARP packet is the MAC address of the terminal device; the processing unit is further configured to obtain a second ARP packet based on the first ARP packet, wherein the second ARP packet includes the access location information, wherein the source IP address of the second ARP packet is the IP address of the terminal device, and the source MAC address of the second ARP packet is the MAC address of the terminal device; the sending unit is further configured to send the second ARP packet to the central device, wherein the source MAC address, the source IP address, and the access location information in the second ARP packet are used by the central device to verify the validity of the second ARP packet.
[0041] In one possible implementation, the receiving unit is further configured to receive the table entry information or access control list (ACL) sent by the central device, wherein the ACL is generated by the central device based on the table entry information, and the ACL is used by the access device to filter packets from the terminal device.
[0042] In one possible implementation, the receiving unit is specifically a control plane processing unit, which is used to receive control protocol messages sent by the central device, the control protocol messages including the table entry information or the ACL.
[0043] In one possible implementation, the access device further includes a data plane processing unit; the control plane processing unit is further configured to: if the control protocol message includes the table entry information, generate an access control list (ACL) corresponding to the table entry information based on the table entry information, and send the generated ACL to the data plane processing unit of the access device; or, if the control protocol message includes the ACL, send the ACL received from the central device to the data plane processing unit; wherein: the data plane processing unit is configured to filter packets from the terminal device according to the ACL.
[0044] In one possible implementation, the first message includes a VLAN encapsulation layer, and the second message adds an outer VLAN encapsulation layer to the first message, with the access location information located in the outer VLAN encapsulation layer.
[0045] In one possible implementation, the access location information is: a first VLAN identifier assigned to the first interface.
[0046] In one possible implementation, the inner VLAN encapsulation of the second message includes a second VLAN identifier, which is the VLAN identifier corresponding to the service of the terminal device. The table entry information also includes the second VLAN identifier, and the inner VLAN encapsulation of the second message is the VLAN encapsulation of the first message.
[0047] In one possible implementation, the receiving unit is further configured to receive a fourth message sent by the central device, the destination device of the fourth message being the terminal device, and the fourth message including the access location information; the processing unit is further configured to obtain a third message based on the fourth message, the third message not including the access location information; and the sending unit is further configured to forward the third message through the first interface.
[0048] In one possible implementation, the fourth message includes two layers of VLAN encapsulation, and the third message is a message obtained by stripping the outer VLAN encapsulation of the fourth message, wherein the outer VLAN encapsulation of the fourth message includes the access location information.
[0049] In one possible implementation, the central device includes either a core layer network device or a convergence layer network device.
[0050] Fourthly, this application provides a communication device applied to a central device. The device includes: a receiving unit for receiving a second message sent by an access device, the second message being obtained by the access device based on a first message sent by a terminal device to the access device, the second message including access location information, the access location information being used to indicate a first interface on the access device, the first interface being an interface on the access device used to receive the first message, wherein the resources of the central device are more abundant than those of the access device; and a processing unit for generating table entry information including the access location information based on the access location information.
[0051] In one possible implementation, the entry information is Dynamic Host Configuration Protocol (DHCP) SNP entry information, which further includes the Media Access Control (MAC) address of the terminal device and the Internet Protocol (IP) address of the terminal device.
[0052] In one possible implementation, the second message further includes the MAC address and the IP address. The processing unit is specifically configured to: extract the access location information, the MAC address, and the IP address from the second message; and generate the DHCP SNP entry information based on the access location information, the MAC address, and the IP address.
[0053] In one possible implementation, the second message includes the MAC address, and the processing unit is specifically configured to: extract the access location information and the MAC address from the second message; obtain the IP address from the DHCP response message sent by the DHCP server to the terminal device; and generate the DHCP SNP entry information based on the access location information, the MAC address, and the IP address.
[0054] In one possible implementation, the processing unit is further configured to extract the IP address and MAC address of the terminal device from the DHCP response message sent by the DHCP server to the terminal device; query the DHCP SNP table entry information based on the IP address and the MAC address to obtain the access location information; and obtain Address Resolution Protocol (ARP) table entry information based on the IP address, MAC address, and access location information of the terminal device, wherein the ARP table entry information includes the IP address, MAC address, and access location information of the terminal device.
[0055] In one possible implementation, the receiving unit is further configured to receive a second ARP packet sent by the access device, the second ARP packet being obtained by the access device based on a first ARP packet sent by the terminal device to the access device, the second ARP packet including the access location information, the first ARP packet being received by the access device through the first interface, the source IP address of the second ARP packet being the IP address of the terminal device, and the source MAC address of the second ARP packet being the MAC address of the terminal device; the processing unit is further configured to perform a validity check on the second ARP packet based on the source MAC address, the source IP address, the access location information, and the DHCP SNP entry information in the second ARP packet.
[0056] In one possible implementation, the apparatus further includes: a sending unit, configured to send the entry information or access control list (ACL) to the access device, wherein the ACL is generated by the central device based on the entry information, and the ACL is used by the access device to filter packets from the terminal device.
[0057] In one possible implementation, the access device includes a control plane processing unit, and the sending unit is specifically configured to: send a control protocol message to the control plane processing unit, wherein the control protocol message includes the table entry information or the ACL.
[0058] In one possible implementation, the first message includes a VLAN encapsulation layer, and the second message adds an outer VLAN encapsulation layer to the first message, with the access location information located in the outer VLAN encapsulation layer.
[0059] In one possible implementation, the access location information is: a first VLAN identifier assigned to the first interface.
[0060] In one possible implementation, the inner VLAN encapsulation of the second message includes a second VLAN identifier, which is the VLAN identifier corresponding to the service of the terminal device. The table entry information also includes the second VLAN identifier, and the inner VLAN encapsulation of the second message is the VLAN encapsulation of the first message.
[0061] In one possible implementation, the receiving unit is further configured to receive a third message, the destination device of which is the terminal device; the processing unit is further configured to obtain a fourth message based on the third message, wherein the fourth message includes the access location information; and the sending unit is further configured to send the fourth message to the access device.
[0062] In one possible implementation, the processing unit is further configured to query the table entry information based on the destination IP address and destination MAC address included in the third message before obtaining the fourth message based on the third message, so as to obtain the access location information.
[0063] In one possible implementation, the third message includes a VLAN encapsulation layer, and the fourth message adds an outer VLAN encapsulation layer on top of the first message, with the access location information located in the outer VLAN encapsulation layer of the fourth message.
[0064] In one possible implementation, the central device includes either a core layer network device or a convergence layer network device.
[0065] Fifthly, this application provides an apparatus. The apparatus includes a processor and a memory. The memory is used to store instructions or computer programs. The processor is used to execute the instructions or computer programs in the memory to perform the methods described in the first aspect and any one thereof. Alternatively, the processor is used to execute the instructions or computer programs in the memory to perform the methods described in the second aspect and any one thereof.
[0066] Sixthly, this application provides a computer-readable storage medium including instructions or a computer program that, when run on a computer, causes the computer to perform the methods described in the first aspect and any one of the first aspects above, or causes the computer to perform the methods described in the second aspect and any one of the second aspects above.
[0067] In a seventh aspect, this application provides a computer program product comprising instructions or a computer program, which, when run on a computer, causes the computer to perform the method described in any one of the first aspects above, or causes the computer to perform the method described in the second aspect above and any one of the second aspects above.
[0068] Eighthly, this application provides a communication system comprising: an access device and a central device, wherein the access device is configured to perform the method described in the first aspect above and any one of the first aspects above, and the central device is configured to perform the method described in the second aspect above and any one of the second aspects above. Attached Figure Description
[0069] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0070] Figure 1a A schematic diagram illustrating a method for generating DHCP Snooping entry information is shown.
[0071] Figure 1b This is a schematic diagram illustrating an exemplary application scenario provided in an embodiment of this application;
[0072] Figure 2 This application provides a schematic diagram of the structure of a communication system according to an embodiment of the present application.
[0073] Figure 3 A signaling interaction diagram of a communication method provided in an embodiment of this application;
[0074] Figure 4 A schematic diagram of a message structure provided in an embodiment of this application;
[0075] Figure 5a A flowchart illustrating a method for ARP entry learning provided in an embodiment of this application;
[0076] Figure 5b A flowchart illustrating yet another communication method provided in an embodiment of this application;
[0077] Figure 5c A flowchart illustrating yet another communication method provided in an embodiment of this application;
[0078] Figure 6a This is a schematic diagram illustrating an exemplary application scenario provided in an embodiment of this application;
[0079] Figure 6b This is a schematic diagram illustrating another exemplary application scenario provided in the embodiments of this application;
[0080] Figure 7 This is a schematic diagram of the structure of a communication device provided in an embodiment of this application;
[0081] Figure 8 This is a schematic diagram of the structure of a device provided in an embodiment of this application. Detailed Implementation
[0082] Limited resources on access devices limit the deployment of numerous security features. This application provides a communication method and apparatus that enables the deployment of access location-level security features on resource-rich central devices.
[0083] Resources mentioned in this application include, but are not limited to, memory resources.
[0084] Currently, common interface-level security features in the park need to be deployed on access devices at the access layer. Next, combined with... Figure 1a This will be explained using the security feature DHCP Snooping as an example. Figure 1a This diagram illustrates a method for generating DHCP Snooping entry information. (For example...) Figure 1a As shown: The access device includes interfaces 1, 3, and 4. Interface 1 is used to communicate with the DHCP server. Interface 3 connects to terminal device 1, and interface 4 connects to terminal device 2. Both interfaces 3 and 4 have DHCP Snooping enabled. The access device obtains network information from the terminal devices connected to it. This network information includes, for example, the terminal device's MAC address, IP address, and information about the interfaces on the access device connected to the terminal devices that have DHCP Snooping enabled. Based on this information, the access device generates DHCP Snooping entries. Interface information may include, for example, the interface number, or, the interface number and the VLAN to which that interface belongs.
[0085] The following explanation uses the example of the access device generating DHCP Snooping entries corresponding to terminal device 1:
[0086] The access device determines that the interface connecting it to terminal device 1 is interface 3. Terminal device 1 sends a DHCP request message to the DHCP server through the access device, requesting the DHCP server to assign it an IP address. The DHCP server returns a DHCP response message to the terminal device, which includes the MAC address of terminal device 1 and the IP address assigned to terminal device 1. Assuming that the MAC address of terminal device 1 is MAC1 and the IP address assigned to terminal device 1 is IP address 1, the DHCP Snooping entry information generated by the access device for terminal device 1 is as follows: Figure 1a As shown, it includes: IP address 1, MAC address 1, and interface 3.
[0087] Similarly, the DHCP Snooping entry information generated by the access device for terminal device 2 is as follows: Figure 1aAs shown, it includes: IP address 2, MAC address 2, and interface 4. Among them, IP address 2 is the IP address of terminal device 2, and MAC address 2 is the MAC address of terminal device 2.
[0088] In one example, after the DHCP Snooping entry is generated, the access device filters traffic from terminal devices based on this DHCP Snooping entry, thereby ensuring network security. DHCP Snooping is also commonly referred to as "DHCP SNP". In this application, the two can be used interchangeably.
[0089] The process of creating the aforementioned table entries requires certain memory resources, while access devices are generally ordinary Layer 2 switches with limited resources. Therefore, the limited resources of access switches cannot support the deployment of many security features, but if no security features are deployed, network security cannot be guaranteed.
[0090] In one implementation, replacing all access devices with high-specification devices that have abundant resources can solve the above problems. However, with a large number of access devices, this approach would result in high costs.
[0091] In another implementation, security features are deployed on devices in non-access locations. For example, security features can be deployed on aggregation devices or core devices. Aggregation devices refer to network devices at the aggregation layer, and core devices refer to network devices at the core layer. Network devices include, but are not limited to, switches, routers, and firewalls. Using this approach, the way devices in non-access locations generate table entries related to terminal devices is similar to the way access devices generate such entries. Now, let's combine... Figure 1b The scenario shown is used as an example for illustration. Figure 1b This is a schematic diagram illustrating an exemplary application scenario provided in an embodiment of this application.
[0092] like Figure 1b As shown, interface 1 of the aggregation device is connected to access device 1, and interface 2 of the aggregation device is connected to access device 2. Interface 3 of access device 1 is connected to terminal device 1, and interface 4 of access device 1 is connected to terminal device 2. Similarly, although... Figure 1b Although not shown in the diagram, different interfaces of access device 2 can also connect to different terminal devices.
[0093] The following example illustrates the deployment of the DHCP Snooping feature on a convergence device.
[0094] Terminal device 1 sends a DHCP request message to the DHCP server through access device 1 and aggregation device, requesting the DHCP server to assign it an IP address. The DHCP server returns a DHCP response message to terminal device 1, which is forwarded through the aggregation device and access device 1. This DHCP response message includes the MAC address of terminal device 1 and the IP address assigned to terminal device 1. Additionally, the aggregation device identifies its connection interface with access device 1 as interface 1. Assuming terminal device 1's MAC address is MAC1 and the assigned IP address is IP address 1, the DHCP Snooping entry information generated by the aggregation device for terminal device 1 is as follows: Figure 1b As shown, it includes: IP address 1, MAC address 1, and interface 1 of the aggregation device.
[0095] Similarly, the DHCP Snooping entry information generated by the aggregation device for terminal device 2 is as follows: Figure 1b As shown, it includes: IP address 2, MAC address 2, and interface 1 of the aggregation device, where IP address 2 is the IP address of terminal device 2, and MAC address 2 is the MAC address of terminal device 2.
[0096] With this approach, the aggregation device cannot perceive the access location information of the terminal device on the access device. For example, the aggregation device cannot know which specific interface of access device 1 is connected to, thus preventing the implementation of access location-level security features. For instance, the aggregation device cannot detect terminal spoofing risks at different access locations included in the access device it is connected to. These different access locations might be, for example, different access interfaces of access device 1, such as interface 1 and interface 2 of access device 1.
[0097] Therefore, the communication method and apparatus provided in this application embodiment can realize the deployment of access location-level security features on the central device.
[0098] Before introducing the solutions provided in the embodiments of this application, it should be noted that entry information is stored in a table, and a table may include multiple entries. For example, one row in the table corresponds to one entry. The entry information mentioned in the embodiments of this application (e.g., DHCP SNP entry information or ARP entry information) refers to the information contained in the content of one entry in the table. For example, DHCP SNP entry information refers to the information contained in the content of one entry in the DHCP SNP table, and ARP entry information refers to the information contained in the content of one entry in the ARP table.
[0099] Next, the solutions provided in the embodiments of this application will be described in conjunction with the accompanying drawings.
[0100] See Figure 2 The figure is a schematic diagram of the structure of a communication system provided in an embodiment of this application. Figure 2 The communication system shown includes access devices and central devices. The access devices can connect one or more terminal devices. For ease of understanding, [the following is a simplified explanation]. Figure 2 Only one terminal device is shown in the diagram. The access device includes a first interface, which is the interface through which the access device and the terminal device are connected. In other words, the terminal device can access the network through the first interface, which is also referred to as the access position of the terminal device on the access device.
[0101] In this scenario, the central device has more resources than the access devices. In one example, the central device and the access devices belong to the same network; for instance, both are devices within a campus network. In this scenario, the central device could be a core device or an aggregation device.
[0102] The method provided in the embodiments of this application is applied to... Figure 2 The communication system shown. Next, in conjunction with... Figure 3 ,right Figure 2 The operations performed by the access devices and central devices in the system shown are explained. Figure 3 This is a schematic diagram of signaling interaction for a communication method provided in an embodiment of this application. Figure 3 The method shown includes the following steps S101-S105.
[0103] S101: The access device receives a first message sent by the terminal device through a first interface, where the first interface is an interface on the access device.
[0104] The terminal device sends a first message to the access device, and the first message sent by the terminal device is received by the first interface of the access device. The type of the first message is not specifically limited in this embodiment. In one example, the first message is a control message; in another example, the first message is a service message.
[0105] This application does not specifically limit the content included in the first message.
[0106] In one example, the first message includes the MAC address of the terminal device, which serves as the source MAC address of the first message.
[0107] If the terminal device has already been assigned an IP address, then in one example, the first message also includes the terminal device's IP address, which serves as the source IP address of the first message. In this scenario, the first message might be a service message.
[0108] If the terminal device has not yet been assigned an IP address, the first message will not include the terminal device's IP address. In this scenario, the first message may be, for example, a DHCP request message, used to request a DHCP server to assign an IP address to the device.
[0109] S102: The access device obtains a second message based on the first message. The second message includes access location information, which is used to indicate the first interface on the access device.
[0110] After receiving the first message through the first interface, the access device processes the first message to obtain a second message. Specifically, the access device processes the first message according to access location information to obtain a second message including the access location information. The access location information indicates the access location of the terminal device on the access device. Since the access device uses the first interface to receive the first message sent by the terminal device, the access location of the terminal device on the access device is the first interface; therefore, the aforementioned access location information is used to indicate the first interface on the access device.
[0111] This application does not specifically limit the access location information, as long as the access location information can uniquely identify the first interface on the access device.
[0112] Considering that in practice, a VLAN identifier can be assigned to the first interface, for example, a first VLAN identifier can be assigned to the first interface. This first VLAN identifier can uniquely identify the first interface on the access device. Therefore, in one example, the access location information is: the first VLAN identifier assigned to the first interface. In this scenario, the access device stores, for example, the correspondence between the first VLAN identifier and the first interface, as shown in Table 1. The value of the first VLAN identifier is 5, corresponding to interface 1 on the access device.
[0113] Table 1
[0114] First VLAN ID First Interface 5 Access device interface 1
[0115] Furthermore, considering that in practical applications, the combination of the access device name and the interface identifier of the first interface can uniquely identify the first interface on the access device, in another example, the access location information is: the access device name and the interface identifier of the first interface. The interface identifier of the first interface includes, but is not limited to, the interface name and interface number of the first interface.
[0116] The embodiments of this application do not specifically limit the specific implementation of how the access device processes the first message to obtain the second message.
[0117] In one example, the access device adds the access location information to the available fields in the first message to obtain the second message.
[0118] In another example, the access device re-encapsulates the first packet using access location information to obtain the second packet. As a specific example, the first packet includes one layer of VLAN encapsulation. The access device adds an outer layer of VLAN encapsulation to the first packet to obtain the second packet, and the access location information is located within this outer VLAN encapsulation. In this scenario, the second packet includes two layers of VLAN encapsulation; the outer VLAN encapsulation carries the aforementioned access location information, and the inner VLAN encapsulation is the same as the VLAN encapsulation included in the first packet.
[0119] The outer and inner VLAN encapsulation have the same structure, both including: Tag Protocol Identifier (TPID), Priority (PRI), Canonical Format Indicator (CFI) field, and VLAN Identifier (VID) field. The specific functions of the TPID, PRI, CFI, and VID fields are not detailed here.
[0120] When the access location information is the first VLAN identifier, the first VLAN identifier is, for example, located in the VID field of the outer VLAN encapsulation of the second packet.
[0121] In one example, if the first packet includes a VLAN encapsulation layer, then in that example, the VLAN encapsulation of the first packet includes a second VLAN identifier. This second VLAN identifier is the VLAN identifier corresponding to the service of the terminal device. By carrying the second VLAN identifier in the VLAN encapsulation of the first packet, the network device can perform operations related to the second VLAN identifier. Since the VLAN encapsulation of the first packet is the inner VLAN encapsulation of the second packet, the inner VLAN encapsulation of the second packet includes the second VLAN identifier.
[0122] Regarding the first and second messages, now combined with Figure 4 Please provide an explanation. Figure 4 This is a schematic diagram of a message structure provided in an embodiment of this application. For example... Figure 4 As shown:
[0123] The first packet includes: Destination MAC Address (DMAC), Source MAC Address (SMAC), 802.1Q Tag field 401, Ethernet Type (ETH-Type), Data field, and Frame Check Sequence (FCS) field. The 802.1Q Tag field 401 is the VLAN encapsulation for the first packet. The ETH-Type field in the first packet can be replaced with the length field.
[0124] The second message adds an outer VLAN encapsulation to the first message; this outer VLAN encapsulation is... Figure 4 The 802.1Q tag field 402 shown, and the 802.1Q tag field 401 in the second packet, are also referred to as the inner VLAN encapsulation of the second packet. Figure 4 The encapsulation method of the second packet shown is also known as QinQ (802.1Q-in-802.1Q) encapsulation. QinQ is also called VLAN Stacking or Double VLAN.
[0125] Although Figure 4 The first and second messages shown do not include three-layer encapsulation, however, Figure 4 The images shown are for ease of understanding of outer and inner VLAN encapsulation and do not imply that the first and second packets do not include Layer 3 encapsulation. In some scenarios, both the first and second packets include Layer 3 encapsulation. This Layer 3 encapsulation includes at least the source IP address and the destination IP address.
[0126] S103: The access device sends the second message to the central device, the second message being used by the central device to generate table entry information including the access location information.
[0127] S104: The central device receives the second message sent by the access device.
[0128] S105: The central device generates table entry information including the access location information based on the access location information.
[0129] After receiving the second message, the access device sends it to the central device. The access location information in the second message enables the central device to generate table entries that include the access location information. Specifically, the access location information in the second message enables the central device to generate table entries related to the terminal device, and these table entries related to the terminal device must include the access location information.
[0130] After receiving the second message sent by the access device, the central device extracts the access location information from the second message and generates table entry information including the access location information based on the access location information.
[0131] As described above, the table entry information is related to the terminal device. Therefore, in addition to the access location information, the table entry information also includes the terminal device information. The terminal device information includes, but is not limited to, the terminal device name, terminal device type, or terminal device address, or the VLAN identifier corresponding to the service of the terminal device (i.e., the aforementioned second VLAN identifier). The terminal device address includes, but is not limited to, the terminal device's IP address and / or terminal device's MAC address.
[0132] In a specific example, the aforementioned entry information is DHCP SNP entry information. In this case, the entry information also includes the MAC address and IP address of the terminal device. In this scenario, using this solution, DHCP SNP entry information related to the terminal device can be generated on the central device, and this DHCP SNP entry information includes the access location information of the terminal device. Optionally, in scenarios where the inner VLAN encapsulation of the second packet includes a second VLAN identifier, the DHCP SNP entry information also includes the second VLAN identifier.
[0133] As described above, in one example, the first message includes the MAC address and IP address of the terminal device. In this case, since the second message is obtained by adding access location information to the available fields of the first message, or by encapsulating access location information on top of the first message, the second message also includes the MAC address and IP address of the terminal device. In this case, after receiving the second message, the central device extracts the source IP address (i.e., the IP address of the terminal device), the source MAC address (i.e., the MAC address of the terminal device), and the access location information included in the second message, thereby generating DHCP SNP entry information including the IP address, MAC address, and access location information of the terminal device.
[0134] As described above, in another example, the first message includes the MAC address of the terminal device but not its IP address. In this case, the second message also includes the MAC address of the terminal device but not its IP address. In this scenario, after receiving the second message, the central device extracts the source MAC address and the access location information included in the second message. Furthermore, when the DHCP server sends a DHCP response message to the terminal device through the central device, the central device obtains the IP address of the terminal device from the DHCP message. Further, the central device generates DHCP SNP entry information including the IP address, MAC address, and access location information of the terminal device based on the MAC address, IP address, and access location information of the terminal device.
[0135] In one example, when the access location information is the first VLAN identifier, the central device also stores the correspondence shown in Table 1 above.
[0136] As described above, in this application, the central device generates the table entry information for the terminal device. Since the central device has more resources than the access device, it has sufficient resources to generate the table entry information. Furthermore, although the table entry information is generated by the central device, it includes access location information that characterizes the access location of the first device on the access device, thereby enabling the table entry information to achieve access location-level security features. The table entry information for the terminal device mentioned here refers to the table entry information related to the terminal device mentioned earlier.
[0137] In one example, if the central device enables the DHCP-triggered ARP learning function, after generating the DHCP SNP entry information, the central device can also perform... Figure 5aThe method shown is used to learn ARP entry information based on DHCP response messages.
[0138] Figure 5a This is a flowchart illustrating a method for ARP entry learning provided in an embodiment of this application. Figure 5a The method shown includes the following steps S201-S203.
[0139] S201: The central device extracts the IP address and MAC address of the terminal device from the DHCP response message sent by the DHCP server to the terminal device.
[0140] The DHCP response message is a message sent by the DHCP server to the terminal device after the terminal device sends a DHCP request. This DHCP response message needs to be forwarded by the central device. Therefore, the central device can receive the DHCP response message sent by the DHCP server to the terminal device. After receiving the DHCP response message, the central device extracts the MAC address and IP address of the terminal device from it.
[0141] S202: The central device queries the DHCP SNP table entry information based on the IP address and the MAC address to obtain the access location information.
[0142] S203: The central device obtains ARP entry information based on the IP address of the terminal device, the MAC address of the terminal device, and the access location information. The ARP entry information includes the IP address of the terminal device, the MAC address of the terminal device, and the access location information.
[0143] After obtaining the MAC address and IP address of the terminal device, the central device uses these addresses to query the aforementioned DHCP SNP table entries to obtain the access location information. After obtaining the access location information, the central device further generates ARP table entries for the terminal device. These ARP table entries include not only the terminal device's IP address and MAC address but also the access location information. In this scenario, although the ARP table entries are generated by the central device, they can include the terminal device's access location information on the access device.
[0144] In one example, after generating the aforementioned DHCP SNP entry information, the central device can also intercept illegal ARP packets based on this DHCP SNP entry information. As a specific example, when the central device has enabled dynamic ARP inspection (DAI), after generating the aforementioned DHCP SNP entry information, the central device can intercept illegal ARP packets based on this DHCP SNP entry information. For details, please refer to... Figure 5b , Figure 5b This is a flowchart illustrating another communication method provided in an embodiment of this application. Figure 5b The method shown includes the following steps S301-S305.
[0145] S301: The access device receives a first ARP packet sent by the terminal device through the first interface, wherein the source IP address of the first ARP packet is the IP address of the terminal device, and the source MAC address of the first ARP packet is the MAC address of the terminal device.
[0146] In one example, the first ARP packet is a first ARP request packet, used to request the MAC address of another terminal device.
[0147] In another example, the first ARP packet is a first ARP response packet, used to announce its own MAC address to other terminal devices.
[0148] The first ARP packet sent by the terminal device is received by the first interface of the access device.
[0149] S302: The access device obtains a second ARP packet based on the first ARP packet. The second ARP packet includes the access location information, the source IP address of the second ARP packet is the IP address of the terminal device, and the source MAC address of the second ARP packet is the MAC address of the terminal device.
[0150] After receiving the first ARP packet, the access device processes it to obtain a second ARP packet including the access location information. The principle behind the access device obtaining the second ARP packet from the first ARP packet is the same as that for obtaining the second packet from the first packet. Therefore, for the specific implementation of "obtaining the second ARP packet from the first ARP packet," please refer to the previous description of "obtaining the second packet from the first packet" in S102; it will not be repeated here.
[0151] S303: The access device sends a second ARP packet to the central device. The source MAC address, source IP address, and access location information in the second ARP packet are used by the central device to verify the legality of the second ARP packet.
[0152] S304: The central device receives the second ARP message sent by the access device.
[0153] S305: The central device performs a validity check on the second ARP packet based on the source MAC address, the source IP address, the access location information, and the DHCP SNP entry information in the second ARP packet.
[0154] After receiving the second ARP packet, the access device forwards it to the central device. The central device then receives the second ARP packet from the access device. Upon receiving the second ARP packet, the central device extracts the source IP address, source MAC address, and access location information from the second ARP packet. Based on these extracted information, it matches them with the aforementioned DHCP SNP entry. If a match is found, the second ARP packet is deemed valid; otherwise, it is deemed invalid. A successful match means that the DHCP SNP entry includes the extracted source IP address, source MAC address, and access location information. Conversely, if the DHCP SNP entry does not include any of these three information, the match fails. In one example, if a match fails, the central device discards the second ARP packet, thus preventing illegal packets from continuing to transmit in the network. This ensures network security while preventing illegal packets from unreasonably consuming network resources.
[0155] In one example, after the central device generates the table entry information for the terminal device, it sends the table entry information to the access device. Correspondingly, the access device receives the table entry information sent by the central device.
[0156] In one example, the access device includes a control plane processing unit and a data plane processing unit. The control plane processing unit is, for example, a central processing unit (CPU), a field-programmable gate array (FPGA), a network processor (NP), or an artificial intelligence chip. The data plane processing unit is a forwarding chip, which may be, for example, an NP-architecture chip or a pipeline architecture chip. In some scenarios, the data plane processing unit may also be referred to as a forwarding plane processing unit.
[0157] As a specific example, the central device sends the table entry information to the control plane processing unit of the access device. Specifically, the central device sends the table entry information to the control plane processing unit via a control protocol. For example, the central device sends a control protocol message to the control plane processing unit, the control protocol message including the aforementioned table entry information. Correspondingly, the control plane processing unit receives the control protocol message sent by the central device and parses the control protocol message to obtain the table entry information.
[0158] This application does not specifically limit the control protocol. The control protocol can be any control protocol supported by both the central device and the access device. For example, the control protocol is the Extremely Lean Discovery Protocol (XLDP), and the corresponding control protocol message is an XLDP message.
[0159] In one example, after receiving a control protocol message including the table entry information, the control plane processing unit extracts the table entry information from the control protocol message and further generates an ACL corresponding to the table entry information. The ACL includes matching conditions and execution actions. For example, the matching conditions of the ACL are the IP address, MAC address, and access location information included in the table entry information, and the execution action is "pass," which means determining that the packet is legitimate and continuing to forward the packet. After generating the ACL, the control plane processing unit sends the ACL to the data plane processing unit of the access device. The data plane processing unit filters packets from the terminal device according to the ACL. For example, if the matching conditions included in the ACL are successfully matched, the data plane processing unit executes the execution actions included in the ACL. In this scenario, although the access device needs to consume certain resources to generate the ACL, the resources consumed in generating the ACL are far less than the resources required by the access device to generate the table entry information. Therefore, in this scenario, although the access device still performs traffic filtering based on the ACL corresponding to the table entry information, it still saves the access device's resources compared to the access device first generating the table entry information and then performing traffic filtering based on the ACL corresponding to the table entry information.
[0160] In one example, after the central device generates the table entry information for the terminal device, it generates a corresponding ACL based on the table entry information. For details on the ACL, please refer to the relevant description above; it will not be repeated here. After generating the ACL, the central device sends the ACL to the access device. Correspondingly, the access device receives the ACL sent by the central device. In this scenario, the access device does not need to generate the ACL itself, thus effectively saving the access device's resources.
[0161] As a specific example, the central device sends the ACL to the control plane processing unit of the access device. Specifically, the central device sends the ACL to the control plane processing unit via a control protocol. For example, the central device sends a control protocol message to the control plane processing unit, the control protocol message including the aforementioned ACL. Correspondingly, the control plane processing unit receives the control protocol message sent by the central device and parses the control protocol message to obtain the ACL.
[0162] Regarding the control protocol, please refer to the relevant description above; it will not be repeated here.
[0163] In one example, after receiving a control protocol message that includes the ACL, the control plane processing unit extracts the ACL from the control protocol message and further sends the ACL to the data plane processing unit of the access device, so that the data plane processing unit can filter the messages from the terminal device according to the ACL.
[0164] In addition to sending the aforementioned table entry information or ACL to the control plane processing unit, the central device can also send other configuration information related to the terminal device to the control plane processing unit. Among these, the other configuration information of the terminal device is, for example, the authorization information of the terminal device. The authorization information of the terminal device includes, but is not limited to, the terminal device's rate limit information, the terminal device's priority information, etc., which will not be described in detail here.
[0165] In this application, the central device and access device are not only able to receive and forward messages from terminal devices, but also to forward messages sent to terminal devices by other devices. The following describes how the central device and access device forward messages sent to terminal devices by other devices.
[0166] See Figure 5c , Figure 5c This is a flowchart illustrating another communication method provided in an embodiment of this application. Figure 5c The method shown includes the following steps S401-S406.
[0167] S401: The central device receives a third message, the destination device of which is the terminal device.
[0168] In one example, the third message is a service message. In another example, the third message is a control message.
[0169] The destination device of the third message is the terminal device. In one example, the destination MAC address of the third message is the MAC address of the terminal device, and the destination IP address of the third message is the IP address of the terminal device.
[0170] S402: The central device obtains a fourth message based on the third message, wherein the fourth message includes the access location information.
[0171] After receiving the third message, the central device queries the aforementioned table entries based on the destination IP address and destination MAC address in the third message, for example, by querying the aforementioned DHCP SNP table entries, to obtain the aforementioned access location information. Further, the central device obtains a fourth message including the access location information based on the third message and the access location information.
[0172] In one example, the central device adds the access location information to the available fields of the third message to obtain the fourth message.
[0173] In another example, the central device re-encapsulates the third packet using access location information to obtain the fourth packet. As a specific example, the third packet includes one layer of VLAN encapsulation. In a concrete implementation, the central device re-encapsulates the third packet to obtain the fourth packet by adding an outer VLAN encapsulation to the third packet, thus obtaining the fourth packet. Furthermore, the access location information is located within the outer VLAN encapsulation of the fourth packet. In this scenario, the fourth packet includes two layers of VLAN encapsulation; its outer VLAN encapsulation carries the aforementioned access location information, and its inner VLAN encapsulation is the same as the VLAN encapsulation included in the third packet.
[0174] S403: The central device sends the fourth message to the access device.
[0175] After receiving the fourth packet, the central device sends it to the access device. Specifically, the central device, for example, queries its local forwarding table based on the access location information (e.g., the first VLAN identifier) to determine the outgoing interface for forwarding the fourth packet, and then sends the fourth packet to the access device through that outgoing interface. Alternatively, the central device, for example, queries its local forwarding table based on the access location information (e.g., the first VLAN identifier) and the destination MAC address of the fourth packet to determine the outgoing interface for forwarding the fourth packet, and then sends the fourth packet to the access device through that outgoing interface. The destination MAC address of the fourth packet is the same as the destination MAC address of the third packet.
[0176] S404: The access device receives the fourth message sent by the central device.
[0177] S405: The access device obtains the third message based on the fourth message, and the third message does not include the access location information.
[0178] S406: The access device forwards the third message through the first interface.
[0179] After receiving the fourth packet from the central device, the access device extracts the access location information from the fourth packet. Based on this access location information, the access device determines whether to forward the fourth packet through the first interface. Specifically, if the access location information is the first VLAN identifier, the access device looks up the correspondence shown in Table 1 according to the first VLAN identifier to determine that the interface used to forward the fourth packet is the first interface.
[0180] In addition, before forwarding the fourth packet, the access device obtains the third packet based on the fourth packet. Obtaining the third packet based on the fourth packet is the reverse operation of the aforementioned S402. For example, if the fourth packet is obtained by adding an outer VLAN encapsulation to the third packet, the access device strips the outer encapsulation of the fourth packet to obtain the third packet.
[0181] After receiving the third message, the access device forwards the third message through the first interface. Since the first interface is the interface through which the terminal device accesses the access device, the third message forwarded by the access device through the first interface can be forwarded to the terminal device, and correspondingly, the terminal device can receive the third message.
[0182] The above has introduced the solution provided in this application. Next, in conjunction with... Figures 6a to 6b This paper describes one possible embodiment of the present application.
[0183] Figure 6a This is a schematic diagram illustrating an exemplary application scenario provided by an embodiment of this application. For example... Figure 6a As shown, the access device receives a first message sent by the terminal device through a first interface. After receiving the first message, the access device obtains a second message based on the first message and access location information that indicates the first interface, and sends the second message to the central device through the second interface. The central device generates entry information for the terminal device based on the received information, and this entry information includes the access location information. The second interface is an interface on the access device.
[0184] In one example, after generating the table entry information, the central device uses this information for traffic filtering. For details on the specific implementation of traffic filtering based on this table entry information by the central device, please refer to the preceding descriptions; they will not be repeated here.
[0185] In another example, refer to Figure 6b , Figure 6b This is a schematic diagram illustrating another exemplary application scenario provided in the embodiments of this application.
[0186] like Figure 6b As shown in the upper part of the attached diagram: The central device sends the table entry information to the control plane processing unit of the access device through control protocol messages. The control plane processing unit of the access device generates an ACL based on the received table entry information and sends the ACL to its own data plane processing unit, which then performs traffic filtering based on the ACL.
[0187] like Figure 6bAs shown in the lower half of the attached diagram: The central device generates an ACL based on the table entry information and sends the ACL to the control plane processing unit of the access device through control protocol messages. The control plane processing unit of the access device then distributes the received ACL to its own data plane processing unit, which performs traffic filtering based on the ACL.
[0188] Based on the communication methods provided in the above embodiments, this application also provides a corresponding communication device. Next, the communication device provided in the embodiments of this application will be described in conjunction with the accompanying drawings.
[0189] See Figure 7 The figure is a schematic diagram of the structure of a communication device provided in an embodiment of this application. Figure 7 The communication device 700 shown includes a receiving unit 701, a processing unit 702, and a transmitting unit 703. The transmitting unit 703 is optional.
[0190] In one example Figure 7 The communication device 700 shown is applied to the access device mentioned in the above embodiments and is used to perform the operations performed by the access device provided in the above embodiments. In this case:
[0191] The receiving unit 701 is used to receive a first message sent by the terminal device through a first interface, wherein the first interface is an interface on the access device.
[0192] The processing unit 702 is configured to obtain a second message based on the first message, the second message including access location information, the access location information being used to indicate the first interface on the access device.
[0193] The sending unit 703 is used to send the second message to the central device. The second message is used by the central device to generate table entry information including the access location information. The central device has more resources than the access device.
[0194] In one possible implementation, the entry information is Dynamic Host Configuration Protocol (DHCP) SNP entry information, which further includes the Media Access Control (MAC) address of the terminal device and the Internet Protocol (IP) address of the terminal device.
[0195] In one possible implementation, the second message also includes the MAC address and the IP address.
[0196] In one possible implementation, the second message also includes the MAC address, and the IP address in the DHCP SNP entry information is obtained by the central device from the DHCP response message sent from the DHCP server to the terminal device.
[0197] In one possible implementation, the receiving unit 701 is further configured to receive a first Address Resolution Protocol (ARP) packet sent by the terminal device through the first interface, wherein the source IP address of the first ARP packet is the IP address of the terminal device, and the source MAC address of the first ARP packet is the MAC address of the terminal device; the processing unit 702 is further configured to obtain a second ARP packet based on the first ARP packet, wherein the second ARP packet includes the access location information, wherein the source IP address of the second ARP packet is the IP address of the terminal device, and the source MAC address of the second ARP packet is the MAC address of the terminal device; the sending unit 703 is further configured to send the second ARP packet to the central device, wherein the source MAC address, the source IP address, and the access location information in the second ARP packet are used by the central device to verify the legality of the second ARP packet.
[0198] In one possible implementation, the receiving unit 701 is further configured to receive the table entry information or access control list (ACL) sent by the central device, wherein the ACL is generated by the central device based on the table entry information, and the ACL is used by the access device to filter packets from the terminal device.
[0199] In one possible implementation, the receiving unit 701 is specifically a control plane processing unit, which is used to receive control protocol messages sent by the central device, the control protocol messages including the table entry information or the ACL.
[0200] In one possible implementation, the access device further includes a data plane processing unit; the control plane processing unit is further configured to: if the control protocol message includes the table entry information, generate an access control list (ACL) corresponding to the table entry information based on the table entry information, and send the generated ACL to the data plane processing unit of the access device; or, if the control protocol message includes the ACL, send the ACL received from the central device to the data plane processing unit; wherein: the data plane processing unit is configured to filter packets from the terminal device according to the ACL.
[0201] In one possible implementation, the first message includes a VLAN encapsulation layer, and the second message adds an outer VLAN encapsulation layer to the first message, with the access location information located in the outer VLAN encapsulation layer.
[0202] In one possible implementation, the access location information is: a first VLAN identifier assigned to the first interface.
[0203] In one possible implementation, the inner VLAN encapsulation of the second message includes a second VLAN identifier, which is the VLAN identifier corresponding to the service of the terminal device. The table entry information also includes the second VLAN identifier, and the inner VLAN encapsulation of the second message is the VLAN encapsulation of the first message.
[0204] In one possible implementation, the receiving unit 701 is further configured to receive a fourth message sent by the central device, the destination device of the fourth message being the terminal device, and the fourth message including the access location information; the processing unit 702 is further configured to obtain a third message based on the fourth message, the third message not including the access location information; and the sending unit 703 is further configured to forward the third message through the first interface.
[0205] In one possible implementation, the fourth message includes two layers of VLAN encapsulation, and the third message is a message obtained by stripping the outer VLAN encapsulation of the fourth message, wherein the outer VLAN encapsulation of the fourth message includes the access location information.
[0206] In one possible implementation, the central device includes either a core layer network device or a convergence layer network device.
[0207] In another example, Figure 7 The communication device 700 shown is applied to the central device provided in the above embodiments and is used to perform the operations performed by the central device in the above embodiments. In this scenario, the sending unit 703 is optional. For this situation:
[0208] The receiving unit 701 is used to receive a second message sent by the access device. The second message is obtained by the access device based on a first message sent by the terminal device to the access device. The second message includes access location information, which is used to indicate a first interface on the access device. The first interface is an interface on the access device used to receive the first message. The resources of the central device are more abundant than those of the access device.
[0209] The processing unit 702 is used to generate table entry information including the access location information based on the access location information.
[0210] In one possible implementation, the entry information is Dynamic Host Configuration Protocol (DHCP) SNP entry information, which further includes the Media Access Control (MAC) address of the terminal device and the Internet Protocol (IP) address of the terminal device.
[0211] In one possible implementation, the second message further includes the MAC address and the IP address. The processing unit 702 is specifically configured to: extract the access location information, the MAC address, and the IP address from the second message; and generate the DHCP SNP entry information based on the access location information, the MAC address, and the IP address.
[0212] In one possible implementation, the second message includes the MAC address, and the processing unit 702 is specifically configured to: extract the access location information and the MAC address from the second message; obtain the IP address from the DHCP response message sent by the DHCP server to the terminal device; and generate the DHCP SNP entry information based on the access location information, the MAC address, and the IP address.
[0213] In one possible implementation, the processing unit 702 is further configured to extract the IP address and MAC address of the terminal device from the DHCP response message sent by the DHCP server to the terminal device; query the DHCP SNP table entry information based on the IP address and the MAC address to obtain the access location information; and obtain Address Resolution Protocol (ARP) table entry information based on the IP address, MAC address, and access location information of the terminal device, wherein the ARP table entry information includes the IP address, MAC address, and access location information of the terminal device.
[0214] In one possible implementation, the receiving unit 701 is further configured to receive a second ARP packet sent by the access device. The second ARP packet is obtained by the access device based on a first ARP packet sent by the terminal device to the access device. The second ARP packet includes the access location information. The first ARP packet is received by the access device through the first interface. The source IP address of the second ARP packet is the IP address of the terminal device, and the source MAC address of the second ARP packet is the MAC address of the terminal device. The processing unit 702 is further configured to perform a validity check on the second ARP packet based on the source MAC address, the source IP address, the access location information, and the DHCP SNP entry information in the second ARP packet.
[0215] In one possible implementation, the apparatus further includes: a sending unit 703, configured to send the entry information or access control list (ACL) to the access device, wherein the ACL is generated by the central device based on the entry information, and the ACL is used by the access device to filter packets from the terminal device.
[0216] In one possible implementation, the access device includes a control plane processing unit, and the sending unit 703 is specifically used to: send a control protocol message to the control plane processing unit, wherein the control protocol message includes the table entry information or the ACL.
[0217] In one possible implementation, the first message includes a VLAN encapsulation layer, and the second message adds an outer VLAN encapsulation layer to the first message, with the access location information located in the outer VLAN encapsulation layer.
[0218] In one possible implementation, the access location information is: a first VLAN identifier assigned to the first interface.
[0219] In one possible implementation, the inner VLAN encapsulation of the second message includes a second VLAN identifier, which is the VLAN identifier corresponding to the service of the terminal device. The table entry information also includes the second VLAN identifier, and the inner VLAN encapsulation of the second message is the VLAN encapsulation of the first message.
[0220] In one possible implementation, the receiving unit 701 is further configured to receive a third message, the destination device of which is the terminal device; the processing unit 702 is further configured to obtain a fourth message based on the third message, wherein the fourth message includes the access location information; and the sending unit 703 is further configured to send the fourth message to the access device.
[0221] In one possible implementation, the processing unit 702 is further configured to query the table entry information based on the destination IP address and destination MAC address included in the third message before obtaining the fourth message based on the third message, so as to obtain the access location information.
[0222] In one possible implementation, the third message includes a VLAN encapsulation layer, and the fourth message adds an outer VLAN encapsulation layer on top of the first message, with the access location information located in the outer VLAN encapsulation layer of the fourth message.
[0223] In one possible implementation, the central device includes:
[0224] Network devices in the core layer, or network devices in the aggregation layer.
[0225] For details on the implementation of each unit of the communication device 700, please refer to the description of the communication method provided in the embodiments of this application above; the description will not be repeated here.
[0226] In this application, the aforementioned communication device 700 may have the following hardware structure: Figure 8 The structure shown, Figure 8 This is a schematic diagram of the structure of a device provided in an embodiment of this application.
[0227] Please see Figure 8 As shown, device 800 includes: a processor 810, a communication interface 820, and a memory 830. The number of processors 810 in device 800 can be one or more. Figure 8 Taking a processor as an example. In this embodiment, the processor 810, communication interface 820, and memory 830 can be connected via a bus system or other means, wherein, Figure 8 Taking the connection between China and Israel via the 840 bus system as an example.
[0228] Processor 810 may be a central processing unit (CPU), a network processor (NP), or a combination of a CPU and an NP. Processor 810 may further include hardware chips. These hardware chips may be application-specific integrated circuits (ASICs), programmable logic devices (PLDs), or combinations thereof. The PLD may be a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof.
[0229] Memory 830 may include volatile memory, such as random-access memory (RAM); memory 830 may also include non-volatile memory, such as flash memory, hard disk drive (HDD), or solid-state drive (SSD); memory 830 may also include combinations of the above types of memory. Figure 8 When the device 800 shown is an access device, the memory 830 stores, for example, table entries or ACLs issued by the storage center device; when Figure 8 When the device 800 shown is the central device, the memory 830 stores, for example, table entry information generated by itself.
[0230] Optionally, the memory 830 stores an operating system and programs, executable modules, or data structures, or subsets thereof, or extended sets thereof. The programs may include various operation instructions for implementing various operations. The operating system may include various system programs for implementing various basic services and handling hardware-based tasks. The processor 810 can read the programs in the memory 830 to implement the communication methods provided in the embodiments of this application.
[0231] The bus system 840 can be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus, etc. The bus system 840 can be divided into address bus, data bus, control bus, etc. For ease of representation, Figure 8 The bus is represented by a single thick line, but this does not mean that there is only one bus or one type of bus.
[0232] This application also provides a computer-readable storage medium, including instructions or a computer program, which, when run on a computer, causes the computer to perform the communication method provided in the above embodiments.
[0233] This application also provides a computer program product containing instructions or computer programs, which, when run on a computer, causes the computer to execute the communication method provided in the above embodiments.
[0234] This application also provides a communication system, which includes the access device and central device mentioned in the above embodiments. The central device is used to perform the operations performed by the central device provided in the above embodiments, and the access device is used to perform the operations performed by the access device provided in the above embodiments.
[0235] The terms “first,” “second,” “third,” “fourth,” etc. (if present) in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a particular order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments described herein can be implemented in a sequence other than that illustrated or described herein. Furthermore, the terms “comprising” and “having,” and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0236] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0237] In the embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical business division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces, indirect coupling or communication connection between apparatuses or units, and may be electrical, mechanical, or other forms.
[0238] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0239] Furthermore, the various business units in the embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software business unit.
[0240] If the integrated unit is implemented as a software business unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0241] Those skilled in the art will recognize that, in one or more of the examples above, the services described in this invention can be implemented using hardware, software, firmware, or any combination thereof. When implemented in software, these services can be stored in a computer-readable medium or transmitted as one or more instructions or code on a computer-readable medium. Computer-readable media include computer storage media and communication media, wherein communication media include any medium that facilitates the transmission of computer programs from one place to another. Storage media can be any available medium accessible to general-purpose or special-purpose computers.
[0242] The above specific embodiments further illustrate the purpose, technical solution, and beneficial effects of the present invention. It should be understood that the above are merely specific embodiments of the present invention.
[0243] The above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit it. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of this application.
Claims
1. A communication method, characterized in that, Applied to access devices, the method includes: The system receives a first message sent by a terminal device through a first interface, wherein the first interface is an interface on the access device. A second message is obtained based on the first message, and the second message includes access location information, which is used to indicate the first interface on the access device. The second message is sent to the central device, which is used by the central device to generate table entry information including the access location information, and the central device has more resources than the access device.
2. The method according to claim 1, characterized in that, The entry information is Dynamic Host Configuration Protocol (DHCP) SNP entry information, which also includes: The terminal device's Media Access Control (MAC) address and Internet Protocol (IP) address.
3. The method according to claim 2, characterized in that, The second message also includes the MAC address and the IP address.
4. The method according to claim 2, characterized in that, The second message also includes the MAC address, and the IP address in the DHCP SNP entry information is obtained by the central device from the DHCP response message sent from the DHCP server to the terminal device.
5. The method according to any one of claims 2-4, characterized in that, The method further includes: The first interface receives a first Address Resolution Protocol (ARP) packet sent by the terminal device, wherein the source IP address of the first ARP packet is the IP address of the terminal device, and the source MAC address of the first ARP packet is the MAC address of the terminal device. A second ARP packet is obtained based on the first ARP packet. The second ARP packet includes the access location information, the source IP address of the second ARP packet is the IP address of the terminal device, and the source MAC address of the second ARP packet is the MAC address of the terminal device. The second ARP packet is sent to the central device. The source MAC address, source IP address, and access location information in the second ARP packet are used by the central device to verify the legitimacy of the second ARP packet.
6. The method according to any one of claims 1-5, characterized in that, The method further includes: The access device receives the table entry information or access control list (ACL) sent by the central device. The ACL is generated by the central device based on the table entry information and is used by the access device to filter packets from the terminal device.
7. The method according to claim 6, characterized in that, The access device includes a control plane processing unit, and the step of receiving the entry information or access control list (ACL) sent by the central device includes: The control plane processing unit receives control protocol messages sent by the central device, the control protocol messages including the table entry information or the ACL.
8. The method according to claim 7, characterized in that, The access device further includes a data plane processing unit, and when the control protocol message includes the table entry information, the method further includes: The control plane processing unit generates an Access Control List (ACL) corresponding to the table entry information based on the table entry information, and sends the generated ACL to the data plane processing unit; or... When the control protocol message includes the ACL, the method further includes: The control plane processing unit will send the ACL received from the central device to the data plane processing unit; wherein: The data plane processing unit is used to filter packets from the terminal device according to the ACL.
9. The method according to any one of claims 1-8, characterized in that, The first message includes a VLAN encapsulation layer, and the second message adds an outer VLAN encapsulation layer on top of the first message, with the access location information located in the outer VLAN encapsulation layer.
10. The method according to claim 9, characterized in that, The access location information is: the first VLAN identifier assigned to the first interface.
11. The method according to claim 9 or 10, characterized in that, The inner VLAN encapsulation of the second message includes a second VLAN identifier, which is the VLAN identifier corresponding to the service of the terminal device. The table entry information also includes the second VLAN identifier. The inner VLAN encapsulation of the second message is the VLAN encapsulation of the first message.
12. The method according to any one of claims 1-11, characterized in that, The method further includes: The central device receives a fourth message, the destination device of which is the terminal device, and the fourth message includes the access location information. The third message is obtained based on the fourth message, and the third message does not include the access location information; The third message is forwarded through the first interface.
13. The method according to claim 12, characterized in that, The fourth message includes two layers of VLAN encapsulation, and the third message is a message obtained by stripping the outer VLAN encapsulation of the fourth message. The outer VLAN encapsulation of the fourth message includes the access location information.
14. The method according to any one of claims 1-13, characterized in that, The central equipment includes: Network devices in the core layer, or network devices in the aggregation layer.
15. A communication method, characterized in that, Applied to central equipment, the method includes: The central device receives a second message sent by the access device. The second message is obtained by the access device based on a first message sent by the terminal device to the access device. The second message includes access location information, which is used to indicate a first interface on the access device. The first interface is an interface on the access device used to receive the first message. The central device has more resources than the access device. Based on the access location information, generate table entry information including the access location information.
16. The method according to claim 15, characterized in that, The entry information is Dynamic Host Configuration Protocol (DHCP) SNP entry information, which also includes: The terminal device's Media Access Control (MAC) address and Internet Protocol (IP) address.
17. The method according to claim 16, characterized in that, The second message also includes the MAC address and the IP address. Before generating the table entry information, the method further includes: Extract the access location information, the MAC address, and the IP address from the second message; The step of generating table entry information including the access location information based on the access location information includes: The DHCP SNP entry information is generated based on the access location information, the MAC address, and the IP address.
18. The method according to claim 16, characterized in that, The second message includes the MAC address. Before generating the table entry information, the method further includes: Extract the access location information and the MAC address from the second message; The IP address is obtained from the DHCP response message sent by the DHCP server to the terminal device; The step of generating table entry information including the access location information based on the access location information includes: The DHCP SNP entry information is generated based on the access location information, the MAC address, and the IP address.
19. The method according to any one of claims 16-18, characterized in that, The method further includes: Extract the IP address and MAC address of the terminal device from the DHCP response message sent by the DHCP server to the terminal device; The access location information is obtained by querying the DHCP SNP table entry based on the IP address and the MAC address; Based on the IP address of the terminal device, the MAC address of the terminal device, and the access location information, Address Resolution Protocol (ARP) entry information is obtained, wherein the ARP entry information includes the IP address of the terminal device, the MAC address of the terminal device, and the access location information.
20. The method according to any one of claims 16-19, characterized in that, The method further includes: The access device receives a second ARP packet sent by the access device. The second ARP packet is obtained by the access device based on a first ARP packet sent by the terminal device to the access device. The second ARP packet includes the access location information. The first ARP packet is received by the access device through the first interface. The source IP address of the second ARP packet is the IP address of the terminal device, and the source MAC address of the second ARP packet is the MAC address of the terminal device. The validity of the second ARP packet is verified based on the source MAC address, source IP address, access location information, and DHCP SNP entry information in the second ARP packet.
21. The method according to any one of claims 15-20, characterized in that, The method further includes: The table entry information or access control list (ACL) is sent to the access device. The ACL is generated by the central device based on the table entry information and is used by the access device to filter packets from the terminal device.
22. The method according to claim 21, characterized in that, The access device includes a control plane processing unit, and sending the entry information or access control list (ACL) to the access device includes: A control protocol message is sent to the control plane processing unit, the control protocol message including the table entry information or the ACL.
23. The method according to any one of claims 15-22, characterized in that, The first message includes a VLAN encapsulation layer, and the second message adds an outer VLAN encapsulation layer on top of the first message, with the access location information located in the outer VLAN encapsulation layer.
24. The method according to claim 23, characterized in that, The access location information is: the first VLAN identifier assigned to the first interface.
25. The method according to claim 23 or 24, characterized in that, The inner VLAN encapsulation of the second message includes a second VLAN identifier, which is the VLAN identifier corresponding to the service of the terminal device. The table entry information also includes the second VLAN identifier. The inner VLAN encapsulation of the second message is the VLAN encapsulation of the first message.
26. The method according to any one of claims 15-25, characterized in that, The method further includes: Receive a third message, the destination device of which is the terminal device; A fourth message is obtained based on the third message, wherein the fourth message includes the access location information; The fourth message is sent to the access device.
27. The method according to claim 26, characterized in that, Before obtaining the fourth message based on the third message, the method further includes: Based on the destination IP address and destination MAC address included in the third message, the table entry information is queried to obtain the access location information.
28. The method according to claim 26 or 27, characterized in that, The third message includes a VLAN encapsulation layer, and the fourth message adds an outer VLAN encapsulation layer on top of the first message. The access location information is located in the outer VLAN encapsulation layer of the fourth message.
29. The method according to any one of claims 15-28, characterized in that, The central equipment includes: Network devices in the core layer, or network devices in the aggregation layer.
30. A communication device, characterized in that, The device includes multiple functional modules that interact with each other to implement the method as described in any one of claims 1-29.
31. A communication device, comprising a processor and a memory, the memory for storing program code, the processor for calling the program code in the memory to cause the communication device to perform the method as described in any one of claims 1-29.
32. A computer-readable storage medium storing instructions that, when executed on a computer, cause the computer to perform the method as described in any one of claims 1-29.
33. A computer program product, characterized in that, Includes program code that, when a computer runs the computer program product, causes the computer to perform the method as described in any one of claims 1-29.
34. A communication system, characterized in that, The system includes at least one of the following: An access device that performs the method according to any one of claims 1-14, and a central device that performs the method according to any one of claims 15-29.