In-house communication device

The in-house communication device addresses the challenge of filtering LAN-side terminals by using MAC filtering on the destination MAC address, independent of the IPv6 prefix, ensuring effective and adaptive packet filtering.

JP7693104B2Active Publication Date: 2025-06-16MITSUBISHI ELECTRIC CORP
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2024517707
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-04-27
Publication Date
2025-06-16
Estimated Expiration
2042-04-27

AI Technical Summary

Technical Problem

Existing in-house communication devices face challenges in implementing effective packet filtering for LAN-side terminals using IPv6 addresses, particularly when terminals connect to new IPv6 networks, as the packet filters do not adapt to new addresses.

Method used

The in-house communication device includes a reception interface for receiving packets from a WAN, performing address resolution, and routing them to a LAN, with an extension function unit that performs MAC filtering on the destination MAC address of packets after routing, without relying on the IP address of the terminal connected to the LAN.

Benefits of technology

This solution enables filtering of LAN-side terminal communications without depending on the IPv6 prefix distributed by the communication network, effectively adapting to changes in terminal addresses and ensuring reliable packet filtering.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007693104000001
    Figure 0007693104000001
  • Figure 0007693104000002
    Figure 0007693104000002
  • Figure 0007693104000003
    Figure 0007693104000003
Patent Text Reader

Abstract

A HGW (110) is provided with a WAN interface unit (112) that receives a packet, and an IPv6 packet filter function unit (125) that performs address resolution on the packet to perform routing of the packet, and in accordance with the rule of an IP packet filter, executes MAC filtering that is filtering of a destination MAC address of the packet after routing.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to an in-house communication device and a filtering method.

Background Art

[0002] Due to the problem of exhaustion of IP addresses in IPv4 (Internet Protocol version 4), IPv6 has been used in recent years.

[0003] In IPv6, it is difficult to perform filtering determination by specifying the IP (Internet Protocol) address of a terminal accommodated in an in-house communication device, which was generally performed as packet filtering processing in the in-house communication device in conventional IPv4.

[0004] The main reasons are the following reasons (a) and (b). (a) The IPv6 address assigned to a terminal on the LAN (Local Area Network) side is an address that redistributes a part of the global IPv6 (Internet Protocol version 6) address prefix distributed by a communication network provider by means of an IPv6 Prefix Delegation operation. For this reason, the Prefix part of the IPv6 address of the terminal on the LAN side depends on the address distributed by the communication network provider, and the Prefix part of the IPv6 address cannot be freely determined in advance. Also, since the subnet length of the Prefix part is specified by the communication provider, the subnet length of the Suffix part of the terminal on the LAN side also depends on the subnet length of the Prefix part. (b) In IPv6, an address setting operation such as MultiHoming in which a terminal on the LAN side belongs to a plurality of networks and generates a terminal address with a plurality of Prefixes distributed from each network is also commonly performed.

[0005] Considering the above situation, packet filtering based on IPv6 address specification cannot be achieved unless the addresses distributed by the communication network operator and redistributed to the LAN-side terminals through the IPv6 Prefix Delegation operation are confirmed. Also, in the case of IPv6 MultiHoming operation or the like, if the terminal connects to a new IPv6 network and a new prefix is distributed after the packet filter is configured, the packet filter does not follow the new address.

[0006] Regarding this point, in filtering, it is not always necessary to specify an IP address, and a method of specifying the target terminal by the MAC (Media Access Control) address of the LAN-side terminal that the in-house communication device can know is also conceivable. When specifying a terminal by the MAC address, the problems caused by the difficulty of specifying an IPv6 address as described above are solved.

[0007] Here, for example, when the in-house communication device uses linux as the OS (Operating System), the filter mechanism called iptables provided by linux is used as the packet filter. The iptables of linux is provided with the specification of filtering by the source MAC address.

[0008] Therefore, when sending packets in the direction from the LAN to the WAN (Wide Area Network), by using this function to specify the source MAC address, it is possible to achieve the filtering of the packets received from the LAN-side terminals.

[0009] Regarding this point, Patent Document 1 discloses a method of configuring a load balancer as a configuration example using filtering by the MAC address and iptables.

Prior Art Documents

Patent Documents

[0010]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0011] However, it is not easy to filter the LAN-side terminal as the destination when receiving packets in the direction from the WAN side to the LAN side by the MAC address. The reason is that in order to perform filtering using the MAC address, the in-house communication device needs to go through the following steps 1 to 3.

[0012] Step 1: The in-house communication device routes the packets in the direction from the WAN side to the LAN side and determines the destination I / F (InterFace) for the destination IP address. Step 2: The in-house communication device determines the destination MAC address corresponding to the destination IP address at the determined destination I / F. Here, if necessary, the in-house communication device needs to perform IPv4 ARP (Address Resolution Protocol) resolution or IPv6 Neighbor resolution and hold the packets during that time. Step 3: The in-house communication device performs filtering using the destination MAC address.

[0013] However, the current iptables does not have the above filtering mechanism. The main reasons are considered to be the following (c) to (e). (c) The destination MAC address is only required for an I / F that communicates with a Layer 2 address such as an Ethernet I / F for the destination I / F, and is not required when the destination is an I / F that does not require a Layer 2 address such as a PPP I / F (Point-to-Point Protocol I / F). (d) It is not appropriate to perform the processing when the destination I / F requires a Layer 2 address by a Layer 3 processing such as an IP packet filter. (e) Therefore, in the Layer 3 processing, only common processing that does not depend on the Layer 2 type of the destination I / F is executed, and at the stage of finally transmitting from the destination I / F, destination MAC address resolution necessary for Layer 2 transmission is performed. With this configuration, the hierarchical structure of the communication layer is maintained, and a flexible IP stack structure with scalability is required.

[0014] On the other hand, because of the processing order of the above steps 1 to 3, at the stage of the IP packet filter of Layer 3 that is executed first, the destination MAC address that will be executed later is in an unresolved state. Therefore, it is impossible to specify the destination MAC address of the LAN side terminal.

[0015] As described above, although the in-house communication device has the advantage that it is possible to specify a LAN side terminal without depending on the IPv6 Prefix distributed from the communication network by specifying the LAN side IPv6 terminal with the MAC address, there is a problem in realizing filtering that specifies the LAN side terminal with the destination MAC address when receiving a packet in the direction from the WAN side to the LAN side. Therefore, filtering of LAN side terminals that does not depend on the IPv6 Prefix distributed from the communication network has not been realized.

[0016] Therefore, one or more aspects of the present disclosure aim to enable filtering to be realized for communication of LAN side terminals without depending on the IPv6 prefix distributed from the communication network.

Means for Solving the Problem

[0017] The in-house communication device according to one aspect of the present disclosure includes From a WAN (Wide Area Network) a reception interface that receives a packet, performs address resolution of the packet, and to a LAN (Local Area Network) a transfer unit that performs routing, and an extension function unit that executes MAC filtering, which is filtering of the destination MAC (Media Access Control) address of the packet after the routing, according to the rules of an IP (Internet Protocol) packet filter. The extension function unit performs the MAC filtering on the destination MAC address that designates the MAC address of the terminal without using the IP address of the terminal connected to the LANis characterized by.

Effect of the Invention

[0019] According to one or more aspects of the present disclosure, filtering can be realized for the communication of terminals on the LAN side without depending on the IPv6 prefix distributed from the communication network.

Brief Description of the Drawings

[0020]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Figure 12

Figure 13

Figure 14

Figure 15

Figure 16

Figure 17

Figure 18

Figure 19

Mode for Carrying Out the Invention

[0021] Embodiment 1. FIG. 1 is a block diagram schematically showing the configuration of a communication system 100 including an HGW (Home GateWay) 110 which is an in-house communication device according to Embodiment 1. The communication system 100 includes a plurality of terminals 101A, 101B, 101C, ···, a subscriber access server 102, a first ISP (Internet Service Provider) system 103A, a second ISP system 103B, and an HGW 110. Here, when it is not necessary to particularly distinguish each of the plurality of terminals 101A, 101B, 101C, ···, each of the plurality of terminals 101A, 101B, 101C, ··· is referred to as a terminal 101.

[0022] The terminal 101 and the HGW 110 are connected to the LAN 104, and the HGW 110 and the subscriber access server 102 are connected to the subscriber communication network 105 such as the Internet.

[0023] The terminal 101 accesses the subscriber communication network 105 via the HGW 110. The subscriber access server 102 is a server accessed by the terminal 101 in order to access the subscriber communication network 105. The first ISP system 103A is a system of an operator providing the first Internet service, and the second ISP system 103B is a system of an operator providing the second Internet service. Here, it is assumed that the first Internet service and the second Internet service are different.

[0024] The HGW 110 includes a LANI / F unit 111, a WANI / F unit 112, and a network processing unit 120. The LANI / F unit 111 is a LAN-side communication interface for communicating via the LAN 104. The WANI / F unit 112 is a WAN-side communication interface for communicating via the subscriber communication network 105 as a WAN. Here, the LANI / F unit 111 or the WANI / F unit 112 functions as a receiving I / F for receiving packets, and the LANI / F unit 111 or the WANI / F unit 112 also functions as a transmitting I / F for transmitting packets.

[0025] The network processing unit 120 controls the processing in the HGW 110. For example, the network processing unit 120 controls the relay processing of outputting packets from the subscriber communication network 105 to the LAN 104 and outputting packets from the LAN 104 to the subscriber communication network 105. Here, it is assumed that the network processing unit 120 is compatible with IPv6.

[0026] The network processing unit 120 includes a PPPoE v6 client function unit 121, a DHCP v6 client function unit 122, a DHCP v6 server function unit 123, an IPv6 router advertisement server function unit 124, and an IPv6 packet filter function unit 125.

[0027] The PPPoE v6 client function unit 121 uses PPPoE (Point-to-Point Protocol over Ethernet), which is an IPv6 Internet connection service, to perform communication via the subscriber communication network 105 through the WANI / F unit 112.

[0028] The DHCP v6 client function unit 122 obtains an IPv6 IP address from a DHCP (Dynamic Host Configuration Protocol) server (not shown) included in the first ISP system 103A or the second ISP system 103B via the WANI / F unit 112.

[0029] The DHCP v6 server function unit 123 functions as an IP address distribution unit that distributes IP addresses to the terminal 101. For example, the DHCP v6 server function unit 123 distributes IPv6 IP address information to the terminal 101 via the LANI / F unit 111. Specifically, the DHCP v6 server function unit 123 distributes an IP address included in an IPv6 address range corresponding to an IPv6 prefix obtained from the first ISP system 103A or the second ISP system 103B connected to the subscriber communication network 105 to the terminal 101.

[0030] The IPv6 router advertisement server function unit 124 automatically configures an IPv6 IP address via the LANI / F unit 111. For example, the IPv6 router advertisement server function unit 124 functions as an IP address advertisement unit that causes the terminal 101 to generate an IP address by advertising an IPv6 address range corresponding to the IPv6 prefix obtained from the first ISP system 103A or the second ISP system 103B connected to the subscriber communication network 105 to the terminal 101.

[0031] The IPv6 packet filter function unit 125 controls and executes the filtering of the packets from the LAN 104 side received by the LANI / F unit 111 and the packets from the subscriber communication network 105 side received by the WANI / F unit 112.

[0032] FIG. 2 is a block diagram schematically showing the configuration of the IPv6 packet filter function unit 125. As shown in the figure, the IPv6 packet filter function unit 125 includes an S / W (Software) transfer setting control unit 130 and an S / W transfer processing unit 140.

[0033] The S / W transfer setting control unit 130 accepts the input of the LAN side filtering setting, which is the filtering setting of the packets from the LAN 104 side, or the WAN side filtering setting, which is the filtering setting of the packets from the subscriber communication network 105 side that is the WAN, from another information processing device such as another computer, etc. by methods such as performing GUI settings from any terminal 101 via the LANI / F unit 111 or reading the config settings from another information processing device such as another computer (not shown), or via a connection unit (not shown) such as a USB (Universal Serial Bus), and causes the S / W transfer processing unit 140 to execute the filtering according to the LAN side filtering setting or the WAN side filtering setting.

[0034] The S / W transfer setting control unit 130 includes an ipv6 packet filter GUI (Graphical User Interface) processing unit 131 and an ipv6tables rule expansion AP (Application) execution unit 132.

[0035] The IPv6 packet filter GUI processing unit 131 causes the terminal 101 or an information processing apparatus (not shown) described above to display a screen image of a GUI for LAN-side filtering setting or WAN-side filtering setting, and receives an input of LAN-side filtering setting or WAN-side filtering setting from an operator via the screen image.

[0036] FIG. 3 is a schematic diagram showing an example of a screen image for LAN-side filtering setting. As shown in FIG. 3, the screen image 113 for LAN-side filtering setting includes a packet filter target I / F selection area 113a, a packet filter direction selection area 113b, and a packet filter entry list display area 113c.

[0037] As shown in the packet filter target I / F selection area 113a and the packet filter direction selection area 113b, the screen image 113 for LAN-side filtering setting shown in FIG. 2 is a setting screen image for a connection starting in the direction from the LAN 104 communicating with the “PPPoE1” to the subscriber communication network 105 which is the WAN.

[0038] The entry list display area 113c is an area for setting a filter for packets transferred in the direction from the LAN 104 to the subscriber communication network 105. As will be described later, the entry list display area 113c is an area for displaying the filter settings input by the operator. One entry corresponding to one row in the entry list display area 113c indicates one filter.

[0039] For example, the entry list display area 113c includes an entry number column 113c#1, a source address display column 113c#2, a destination address display column 113c#3, a protocol type display column 113c#4, a source port number display column 113c#5, a destination port number display column 113c#6, and an entry operation display column 113c#7.

[0040] The entry number column 113c#1 displays the entry number as identification information for identifying an entry. The source address display column 113c#2 displays the specified address when the source address is specified as a filter on the LAN104 side. The destination address display column 113c#3 displays the specified address when the destination address is specified as a filter on the LAN104 side. The protocol type display column 113c#4 displays the specified protocol when the protocol is specified as a filter on the LAN104 side. The source port number display column 113c#5 displays the specified port when the source port is specified as a filter on the LAN104 side. The destination port number display column 113c#6 displays the specified port when the destination port is specified as a filter on the LAN104 side. The entry operation display column 113c#7 displays the operation as a filter on the LAN104 side.

[0041] FIG. 4 is a schematic diagram showing an example of an entry input screen image for inputting one entry of the LAN side filter. The entry input screen image 114 shown in FIG. 4 is a screen image when inputting the entry of the entry number "3" in FIG. 3. The entry input screen image 114 includes a title bar 114a, a source address specification column 114b, a destination address specification column 114c, a protocol specification column 114d, a source port number specification column 114e, a destination port number specification column 114f, and an operation specification column 114g. Note that the start value input column 114h and the end value input column 114i are columns for input when performing range specification in the source address specification column 114b, the destination address specification column 114c, the source port number specification column 114e, or the destination port number specification column 114f.

[0042] Here, the source address specification field 114b is enabled to specify the target for filtering by the source address from among "IP address range", "IP subnet", and "MAC address". Here, the source MAC address is specified.

[0043] Also, the destination address specification field 114c is enabled to specify the target for filtering by the destination address from among "IP address range", "IP subnet", and "MAC address". Here, the IP subnet is specified.

[0044] In the packet filter, it is also possible to specify the protocol, source port number, destination port number, etc., but since these are generally specified items rather than items according to this embodiment, the description thereof is omitted. Finally, in the operation specification field 114g, either "pass" or "block" can be selectively selected. Here, "pass" is selected. By performing the input as shown in FIG. 4, the filter with the entry number "3" in FIG. 3 is set.

[0045] FIG. 5 is a schematic diagram showing an example of a screen image for WAN-side filtering setting. As shown in FIG. 5, the WAN-side filtering setting screen image 115 includes a packet filter target I / F selection area 115a, a packet filter direction selection area 115b, and a packet filter entry list display area 115c.

[0046] As shown in the packet filter target I / F selection area 115a and the packet filter direction selection area 115b, the WAN-side filtering setting screen image 115 shown in FIG. 5 is a setting screen image for a connection starting from the subscriber communication network 105 which is the WAN and communicating with the LAN 104 in the direction of "PPPoE1".

[0047] The entry list display area 115c is an area for setting a filter for packets transferred in the direction from the subscriber communication network 105 to the LAN 104. As will be described later, the entry list display area 115c is an area for displaying the filter settings input by the operator. One entry corresponding to one line in the entry list display area 115c indicates one filter.

[0048] For example, the entry list display area 115c includes an entry number column 115c#1, a source address display column 115c#2, a destination address display column 115c#3, a protocol type display column 115c#4, a source port number display column 115c#5, a destination port number display column 115c#6, and an entry operation display column 115c#7.

[0049] The entry number column 115c#1 displays an entry number as identification information for identifying an entry. The source address display column 115c#2 displays the specified address when the source address is specified as a filter on the subscriber communication network 105 side. The destination address display column 115c#3 displays the specified address when the destination address is specified as a filter on the subscriber communication network 105 side. The protocol type display column 115c#4 displays the specified protocol when the protocol is specified as a filter on the subscriber communication network 105 side. The source port number display column 115c#5 displays the specified port when the source port is specified as a filter on the subscriber communication network 105 side. The destination port number display column 115c#6 displays the specified port when the destination port is specified as a filter on the subscriber communication network 105 side. The entry operation display column 115c#7 displays the operation as a filter on the subscriber communication network 105 side.

[0050] FIG. 6 is a schematic diagram showing an example of an entry input screen image for inputting one entry of the WAN side filter. The entry input screen image 116 shown in FIG. 6 is the screen image when the entry of the entry number "1" in FIG. 5 is input. The entry input screen image 116 includes a title column 116a, a source address specification column 116b, a destination address specification column 116c, a protocol specification column 116d, a source port number specification column 116e, a destination port number specification column 116f, and an operation specification column 116g. Note that the start value input column 116h and the end value input column 116i are columns for input when performing range specification in the source address specification column 116b, the destination address specification column 116c, the source port number specification column 116e, or the destination port number specification column 116f.

[0051] Here, the source address specification column 116b can be used to specify the target for filtering by the source address from among "IP address range", "IP subnet", and "MAC address". Here, the IP subnet is specified.

[0052] Also, the destination address specification column 116c can be used to specify the target for filtering by the destination address from among "IP address range", "IP subnet", and "MAC address". Here, the MAC address is specified.

[0053] Although a protocol, a source port number, a destination port number, etc. can also be specified in the packet filter, these are items that are generally specified and not items according to this embodiment, so the description is omitted. Finally, either "pass" or "block" can be selectively selected in the operation specification column 116g. Here, "pass" is selected. By performing the input as shown in FIG. 6, the filter for the entry number "1" in FIG. 5 is set.

[0054] Returning to FIG. 2, the rule deployment AP execution unit 132 for ipv6tables sets the LAN-side filtering setting or the WAN-side filtering setting received by the ipv6 packet filter GUI processing unit 131 in the ip6tables main body unit 141, which will be described later, of the S / W transfer processing unit 140, and causes filtering to be executed according to the filtering setting.

[0055] The S / W transfer processing unit 140 filters the LAN-side packets received by the LAN I / F unit 111 or the WAN-side packets received by the WAN I / F unit 112 and transfers those packets. The S / W transfer processing unit 140 includes an ip6tables main body unit 141, an S / W packet transfer processing unit 142, and an ip6tables extension unit 143.

[0056] The ip6tables main body unit 141 sets, manages, and inspects the table of IPv6 packet filter rules of the linux kernel and executes filtering using that table. The ip6tables main body unit 141 includes a PRE ROUTING execution unit 141a, a FORWARDING execution unit 141b, and a POST ROUTING execution unit 141c. The processing of these functional units is the processing of packet filtering normally performed inside linux and is described in detail in the following documents and the like, so the description here is omitted. Document: Iptables Tutorial 1.2.2, "Searched on December 16, 2021", URL: <https: / / www.frozentux.net / iptables-tutorial / iptables-tutorial.html>

[0057] In the LAN - side filtering setting screen image 113 shown in FIG. 3, when an IP address is specified in the source address display column 113c#2 or the destination address display column 113c#3, or in the WAN - side filtering setting screen image 115 shown in FIG. 5, when an IP address is specified in the source address display column 115c#2 or the destination address display column 115c#3, the ip6tables main body part 141 functions as a filtering execution part that executes IP filtering, which is filtering using an IP address.

[0058] The S / W packet transfer processing part 142 executes the transfer of LAN - side packets received by the LAN I / F part 111 or WAN - side packets received by the WAN I / F part 112. The S / W packet transfer processing part 142 includes a route resolution part 142a and a destination MAC resolution part 142b. Since the processing in these functional parts is also the packet transfer processing normally performed inside linux, a detailed description is omitted.

[0059] The above ip6tables main body part 141 and S / W packet transfer processing part 142 constitute a transfer part that performs address resolution of packets and routes those packets.

[0060] The ip6tables extension part 143 functions as an extension function part that executes MAC filtering, which is filtering of the destination MAC address of the packet after routing by the ip6tables main body part 141 and the S / W packet transfer processing part 142, according to the rules of the IP packet filter. The rules here are those that execute address resolution of the packet after routing and perform MAC filtering based on the destination MAC address resolved by that address resolution. Therefore, the ip6tables extension part 143 causes the destination MAC resolution part 142b to execute address resolution according to the rules and performs MAC filtering based on the resolved MAC address. In particular, in Embodiment 1, the WANI / F unit 112 as the reception I / F receives packets from the subscriber communication network 105. The ip6tables main body unit 141 and the S / W packet transfer processing unit 142 perform routing of the packets to the LAN 104. The ip6tables extension unit 143 can execute MAC filtering on the destination MAC address that designates the MAC address of the terminal 101 without using the IP address of the terminal 101 connected to the LAN 104.

[0061] For example, the ip6tables extension unit 143 executes filtering by the destination MAC address in the destination MAC resolution determination chain PPOE1_WAN_TO_LAN_rule1 that extends the processing in the ip6tables main body unit 141 in response to an instruction from the ip6tables main body unit 141. The ip6tables extension unit 143 includes a DSTMAC processing unit 143a and a routed-dst-mac processing unit 143b.

[0062] The DSTMAC processing unit 143a is activated to perform processing for resolving the destination MAC address from the destination IP address, and gives the packet received according to the evaluation rule configured so that the packet for which destination MAC filtering is to be executed passes through the DSTMAC target, to the routed-dst-mac processing unit 143b.

[0063] The routed-dst-mac processing unit 143b performs a coincidence determination between the destination MAC address of the packet from the DSTMAC processing unit 143a and the destination MAC address resolved from the destination IP address.

[0064] Note that there are also other existing extension operations in iptables as shown in the documents described below. Document: Netfilter Extensions HOWTO, "Searched on December 16, 2021", URL: <https: / / www.netfilter.org / documentation / HOWTO / netfilter-extensions-HOWTO.html>

[0065] Part or all of the network processing unit 120 described above can be constituted by, for example, a memory 10 and a processor 11 such as a CPU (Central Processing Unit) that executes a program stored in the memory 10, as shown in FIG. 7(A). Such a program may be provided through a network or may be provided by being recorded on a recording medium. That is, such a program may be provided, for example, as a program product.

[0066] Also, part or all of the network processing unit 120 can be constituted by a processing circuit 12 such as a single circuit, a composite circuit, a programmed processor, a parallel programmed processor, an ASIC (Application Specific Integrated Circuit), or an FPGA (Field Programmable Gate Array), as shown in FIG. 7(B). As described above, the network processing unit 120 can be constituted by a processing circuit network.

[0067] Note that the LANI / F unit 111 can be realized by a communication interface such as a NIC (Network Interface Card) that can be connected to the LAN 104. Also, the WANI / F unit 112 can be realized by a communication interface such as a NIC that can be connected to the subscriber communication network 105.

[0068] Next, a method for realizing the GUI setting shown in FIGS. 3 and 5 by the processing of a packet filter inside linux, which is often adopted as the OS of the in-house communication control device, is shown. FIG. 8 is a flowchart schematically showing the operation of the packet filter inside linux.

[0069] First, the LANI / F unit 111 or the WANI / F unit 112 receives a packet (S10). The received packet is sent to the S / W transfer processing unit 140.

[0070] The PRE ROUTING execution unit 141a of the S / W transfer processing unit 140 executes three predetermined filtering processes based on ip6tables and provides the packet to the route resolution unit 142a (S11).

[0071] Next, the route resolution unit 142a executes a routing table search based on the destination of the packet (S12). Then, the route resolution unit 142a determines whether the result of the routing table search in step S12 is addressed to the own device HGW110 (S13). If the destination of the packet is an external device other than HGW110 (No in S13), the process proceeds to step S14. If the destination of the packet is HGW110 (Yes in S13), the process proceeds to step S19.

[0072] In step S14, the packet is provided to the FORWARDING execution unit 141b, and two predetermined filtering processes are performed. Then, the packet is provided to the POST ROUTING execution unit 141c.

[0073] The POST ROUTING execution unit 141c performs output I / F transmission processing after executing two predetermined filtering processes (S15). The POST ROUTING execution unit 141c determines whether the destination of the packet is an Ether type I / F in the output I / F transmission processing (S16). If the destination of the packet is an Ether type I / F (Yes in S16), the process proceeds to step S17. If the destination of the packet is not an Ether type I / F (No in S16), the process proceeds to step S18.

[0074] In step S17, the destination MAC resolver 142b performs destination MAC resolution for the destination IP address. Then, the process proceeds to step S18. In step S18, the packet is provided to the LANI / F unit 111 or the WANI / F unit 112 according to the destination, and is transmitted from the LANI / F unit 111 or the WANI / F unit 112.

[0075] On the other hand, in step S13, for the packet determined that the destination is HGW110, in step S19, two filtering processes are executed in the INPUT unit 126 (see FIG. 11). Thereafter, it is provided to the application of HGW110 (S20).

[0076] Also, when the application of HGW110 transmits a packet (S21), the route resolver 142a performs a routing table search for the packet (S22). Then, the packet is processed by the OUTPUT unit 127 (see FIG. 11) to perform two predetermined filtering processes (S23). Thereafter, the packet is sent to the POST ROUTING execution unit 141c, and the processes of steps S15 to S18 are performed in the same manner as described above.

[0077] Next, the expansion of the LAN - side filtering setting shown in FIG. 3 will be described. As shown in FIG. 3, the LAN - side filtering setting is expanded to the packet filtering operation inside the linux as shown in FIG. 9.

[0078] First, since the LAN - side filtering setting is a filter corresponding to the packet from the LAN to the PPPoE of ISP1, the PPPoE1_LAN_TO_WAN, which is the chain 30 corresponding to this, is created. Here, a chain is a block that groups each evaluation rule.

[0079] Next, in this chain PPPoE1_LAN_TO_WAN, the interface corresponding to LAN as the input I / F (here, eth0) is specified, and the interface corresponding to PPPoE as the output I / F (here, ppp1000) is specified, and rule 31 is configured so that transfer packets having the corresponding input / output I / Fs pass through.

[0080] Next, in this chain PPPoE1_LAN_TO_WAN, evaluation rules corresponding to entry numbers 1 to 3 of the LAN-side filtering settings shown in FIG. 3 are described as rules 32 to 33.

[0081] Here, since the filtering setting using the source MAC address shown in entry number 3 of FIG. 3 already has the " -m mac -src-mac" for specifying the source MAC address among the existing iptables determination conditions, it is configured as rule 34 by specifying it as it is.

[0082] Next, as shown in FIG. 10, the WAN-side filtering setting shown in FIG. 5 is expanded to the packet filtering operation inside the linux.

[0083] First, since the WAN-side filtering setting is a filter corresponding to packets from the PPPoE of ISP1 to the LAN, chain 40, PPPoE1_WAN_TO_LAN, corresponding to this is created.

[0084] Also, in Embodiment 1, when there is a setting for specifying a destination MAC filter in the GUI filtering, chain 41, PPPoE1_WAN_TO_LAN_rule1, corresponding to this is created.

[0085] Next, in this chain PPPoE1_WAN_TO_LAN, the interface corresponding to LAN as the output I / F (here, eth0) is specified, and the interface corresponding to PPPoE as the input I / F (here, ppp1000) is specified, and rule 42 is configured so that transfer packets having the corresponding input / output I / Fs pass through.

[0086] Next, in this chain PPPoE1_WAN_TO_LAN, evaluation rules 43 and 44 corresponding to entry numbers 1 and 2 of the WAN-side filtering settings shown in FIG. 5 are described. Here, entry number 1 that specifies the destination MAC address in the filtering condition is like rule 43.

[0087] In rule 43, the filtering settings other than the destination MAC address are directly expanded into the filtering condition settings of rule 43. On the other hand, the filtering setting of the destination MAC address is configured to shift to chains 45 and 46 that evaluate the destination MAC resolution determination chain PPPoE1_WAN_TO_LAN_rule1.

[0088] Chains 45 and 46 show two extended operations configured in iptables to implement filtering by the destination MAC address in the destination MAC resolution determination chain PPPoE1_WAN_TO_LAN_rule1.

[0089] Chain 45 is an evaluation rule that creates a new target DSTMAC that starts the process of resolving the destination MAC address from the destination IP address, and allows the packet attempting to perform destination MAC filtering to pass through the DSTMAC target.

[0090] Chain 46 is an evaluation rule that creates a new option -routed-dst-mac for the extended match module mac for MAC address determination in iptables to perform a match determination with the destination MAC address resolved from the destination IP address, and enables the specification of the destination MAC address filtering condition there. Here, the existing extended match module mac and the option -mac-source that matches the source MAC address are described in the following literature. Document: iptables-extensions, "Searched on December 16, 2021", URL: <https:linuxjm.osdn.jp / html / iptables / man8 / iptables-extensions.8.html>

[0091] Next, the operation of the DSTMAC processing unit 143a, which is the extended operation in Embodiment 1, and the operation of the routed-dst-mac processing unit 143b, which is a new option of the extended matching module for MAC address matching that determines the match with the destination MAC address, will be described with reference to FIG. 11.

[0092] FIG. 11 shows a simplified representation of the IP packet filter processing and the destination MAC resolution processing shown in FIG. 8. In FIG. 11, the operations of the DSTMAC processing unit 143a and the routed-dst-mac processing unit 143b are assumed to be specified by the rules under the FORWARD chain.

[0093] Here, when the DSTMAC target operation by the DSTMAC processing unit 143a is specified as the target operation of the rule, the DSTMAC processing unit 143a issues a destination MAC address resolution request 50 from the destination IP address of the packet to the destination MAC resolution unit 142b, targeting the destination I / F of the packet obtained by the route resolution 60 performed by the route resolution unit 142a.

[0094] When the destination MAC resolution unit 142b already holds the destination MAC address for the destination IP address and synchronously returns a destination MAC address resolved response from the destination MAC resolution unit 142b, the DSTMAC processing unit 143a immediately returns from the DSTMAC target operation and evaluates the next rule.

[0095] On the other hand, when the destination MAC address resolving unit 142b does not hold the destination MAC address for the destination IP address and returns a destination MAC address resolving in-progress response from the destination MAC address resolving unit 142b, the DSTMAC processing unit 143a queues the corresponding packet, interrupts the rule evaluation, and waits until it receives an asynchronous destination MAC address resolution response 51 from the destination MAC address resolving unit 142b.

[0096] After that, when receiving the asynchronous destination MAC address resolution response 51 from the destination MAC address resolving unit 142b, the DSTMAC processing unit 143a returns from the DSTMAC target operation and performs the evaluation of the next rule.

[0097] Next, when the routed-dst-mac processing unit 143b is specified to perform the extended filtering operation based on the destination MAC address, the routed-dst-mac processing unit 143b requests the destination MAC address resolving unit 142b to perform a destination MAC address search 52 from the destination IP address of the packet, targeting the destination I / F of the packet obtained in the route resolution 61 performed by the route resolving unit 142a.

[0098] When the routed-dst-mac processing unit 143b holds the destination MAC address and the destination MAC address resolving unit 142b responds with the destination MAC address, the routed-dst-mac processing unit 143b further compares it with the destination MAC address filter condition passed as a parameter of the extended filtering operation. If the two match as a result of the comparison, the routed-dst-mac processing unit 143b determines that the extended filtering condition is satisfied.

[0099] On the other hand, when the destination MAC address resolving unit 142b does not hold the destination MAC address and responds with an unknown destination MAC address, or when the responded destination MAC address does not match the destination MAC address filter condition passed as a parameter of the extended filtering operation, the routed-dst-mac processing unit 143b determines that the extended filtering condition is not satisfied.

[0100] When the DSTMAC processing unit 143a and the routed-dst-mac processing unit 143b that perform such an expansion operation are provided, the filter with entry number 1 shown in FIG. 5 can be realized by expanding it like the iptables rules 43, 45, and 46 in FIG. 10.

[0101] Next, the content of the DSTMAC target processing in Embodiment 1 will be described. FIG. 12 is a flowchart showing the DSTMAC target processing performed by the DSTMAC processing unit 143a. In FIG. 12, at the timing of evaluating the rule describing the DSTMAC target for the received packet, the internal processing of the DSTMAC target is requested from the iptables side.

[0102] When the DSTMAC target processing is requested (S70), the DSTMAC processing unit 143a first checks the type of the destination I / F of the packet and determines whether the type is Ether type (S71). If the type is not Ether type (No in S71), since the destination MAC address resolution is not required, the process immediately proceeds to step S79, this DSTMAC target processing ends, and the evaluation of the next rule is performed. On the other hand, if the type is Ether type (Yes in S71), the process proceeds to step S72.

[0103] In step S72, the DSTMAC processing unit 143a requests the destination MAC address resolution from the destination MAC resolution unit 142b. Here, the destination I / F for the packet is executed at the timing of the path resolution 60 in FIG. 11 and operates only on the packet to be transferred to another I / F. Therefore, the DSTMAC operation here can be used only in the chain after the path resolution 60, for example, FORWARD or POSTROUTING.

[0104] Next, the DSTMAC processing unit 143a determines whether a destination MAC resolution response has been returned from the destination MAC resolution unit 142b (S73). If a destination MAC resolution response has been returned (Yes in S73), since the destination MAC has been resolved, the process immediately proceeds to step S79, this DSTMAC target process ends, and the evaluation of the next rule is performed. On the other hand, if a destination MAC resolution in-progress response has been returned (No in S73), the process proceeds to step S74.

[0105] In step S74, the DSTMAC processing unit 143a checks the number of packets being queued within the DSTMAC processing unit 143a and determines whether the number of packets is equal to or greater than a threshold. If the number of packets is equal to or greater than the threshold (Yes in S74), the process proceeds to step S75. As the destination MAC cannot be resolved, the DSTMAC processing unit 143a discards the packet. On the other hand, if the number of packets is less than the threshold (No in S74), the process proceeds to step S76.

[0106] In step S76, the DSTMAC processing unit 143a queues the packet.

[0107] Thereafter, the DSTMAC processing unit 143a determines whether a destination MAC resolution result response has been received from the destination MAC resolution unit 142b (S77). If a destination MAC resolution result response has been received (Yes in S77), the process proceeds to step S78.

[0108] In step S78, the DSTMAC processing unit 143a removes the packet from the queue. Then, the process proceeds to step S79.

[0109] In step S79, the DSTMAC processing unit 143a ends the DSTMAC target process and proceeds to the evaluation of the next rule.

[0110] Next, an implementation example of the DSTMAC target queuing process described with reference to FIG. 12 will be described with reference to FIG. 13. First, when the ip6tables main body 141 sends a DSTMAC processing request 80 to the DSTMAC processing unit 143a, the DSTMAC processing unit 143a checks whether the destination IP address of the packet exists in the destination MAC resolving IP list 85. If the destination IP address of the packet exists in the destination MAC resolving IP list 85, the DSTMAC processing unit 143a pairs the packet for which the DSTMAC processing request 80 was made with the target DSTMAC rule, and queues them in the order of packet arrival for each destination IP.

[0111] If the destination IP address of the packet does not exist in the destination MAC resolving IP list 85, the DSTMAC processing unit 143a calls the destination MAC resolving unit 142b by means of a destination MAC address resolving request 82.

[0112] The destination MAC resolving unit 142b responds with a destination MAC address resolving response 83, which is a synchronous response, indicating that the resolution has been completed or is in progress. If the destination MAC address resolving response has been completed, the DSTMAC processing unit 143a responds to the ip6tables main body 141 as DSTMAC end 84 and proceeds to the next rule evaluation.

[0113] If the destination MAC address resolving response 83 is in progress, the DSTMAC processing unit 143a creates a destination MAC resolving IP list 85 for each destination IP to prevent duplicate requests for destination MAC resolution.

[0114] Then, the DSTMAC processing unit 143a pairs the packet for which the DSTMAC processing request 80 was made with the target DSTMAC rule, creates a destination MAC resolving packet list 81 for each destination IP address, and queues them in the order of packet arrival for each destination IP.

[0115] In this case, when the DSTMAC processing unit 143a receives the asynchronous destination MAC resolution result response 86 from the destination MAC resolution unit 142b, the DSTMAC processing unit 143a responds with DSTMAC processing completion 84 to all the packets in the pending packet list corresponding to the destination IP of the destination MAC resolution result response 86 received from the destination MAC resolution in-progress packet list 81, and proceeds to the next rule evaluation.

[0116] Note that the process of simply queuing the packets being processed during packet filtering and then resuming is already implemented in the QUEUE target. Referring to this, the above process can be realized.

[0117] Next, the processing content performed by the routed-dst-mac processing unit 143b, which is an extended matching module for MAC address determination in Embodiment 1, will be described. FIG. 14 is a flowchart showing the processing performed by the routed-dst-mac processing unit 143b. Here, according to the rule that simply uses the extended matching module for MAC address determination in FIG. 11, the routed-dst-mac processing unit 143b queries the destination MAC resolution unit 142b to check whether there is a destination MAC address for the destination IP address of the packet.

[0118] First, when the destination MAC determination process of the extended MAC module is requested from the routed-dst-mac processing unit 143b (S90), the routed-dst-mac processing unit 143b checks the type of the destination I / F of the packet and determines whether the type is Ether type (S91). If the type is not Ether type (No in S91), since the destination MAC cannot be resolved, the process immediately proceeds to step S95, ends the destination MAC determination process as a mismatch, and proceeds to the evaluation of the next rule.

[0119] On the other hand, if the type is Ether type (Yes in S91), the routed-dst-mac processing unit 143b requests the destination MAC resolution unit 142b to perform a destination MAC check (S92). This corresponds to the process indicated by reference numeral 52 in FIG. 11.

[0120] Then, based on the response from the destination MAC resolution unit 142b, the routed-dst-mac processing unit 143b determines whether a destination MAC address exists (S93). If the destination MAC address does not exist (No in S93), the process immediately proceeds to step S95, ends this destination MAC determination process as a mismatch, and proceeds to the evaluation of the next rule.

[0121] On the other hand, if the destination MAC address exists (Yes in S93), the process proceeds to step S94. In step S94, the routed-dst-mac processing unit 143b determines whether the destination MAC address matches the MAC address in the determination condition. If they do not match (No in S94), the process proceeds to step S95. If they match (Yes in S94), the process proceeds to step S96.

[0122] In step S95, the routed-dst-mac processing unit 143b ends this destination MAC determination process as a mismatch and proceeds to the evaluation of the next rule. On the other hand, in step S96, the routed-dst-mac processing unit 143b ends this destination MAC determination process as a match and proceeds to the evaluation of the next rule.

[0123] As described above, the filtering that includes the destination MAC address as a filtering condition indicated by entry number 1 in FIG. 3 can be realized to achieve a desired operation by combining, as in rules 43, 45, and 46 shown in FIG. 10, the DSTMAC target operation described above and the destination MAC determination process of the extended MAC module.

[0124] As described above, in the HGW110 according to the first embodiment, the destination MAC address for the destination IP address is resolved at an arbitrary timing during the packet filter evaluation after the routing table search, and the subsequent packet filter can be evaluated based on the resolved destination MAC address. Therefore, the connection from the terminal 101 on the LAN side to the subscriber communication network 105, which is the WAN, in the direction from the LAN 104 can be specified by the source MAC address, or the connection in the direction from the subscriber communication network 105, which is the WAN, to the LAN 104 can also be specified by the destination MAC address. As a result, it is possible to specify packet filter filtering regardless of the change in the IP address assigned to the terminal 101 on the LAN 104 side.

[0125] In addition, since the resolution of the destination MAC address is specified as the target of the packet filter, packet filter conditions other than the destination MAC address are set like Rule 43, and in Rule 45, destination MAC resolution is required only for packets that require destination MAC filtering, and in Rule 46, the condition evaluation is performed only for the destination MAC address. By configuring in this way, the destination MAC resolution process is not performed for packets that do not require destination MAC filtering, thereby reducing the processing load.

[0126] In the above description, mainly an IPv6 address in which the address of the terminal 101 on the LAN 104 side changes according to the prefix allocated from the ISP network is taken as an example for explanation. However, the first embodiment is also applicable when the terminal 101 on the LAN 104 side has an IPv4 address.

[0127] Second Embodiment. In the first embodiment, a new DSTARP target is created to perform the request for destination MAC address resolution and the holding of packets during destination MAC resolution. However, the configuration method for performing such an operation is not limited to this.

[0128] In Embodiment 2, packet retention during destination MAC resolution is performed using an existing QUEUE target, and a request for destination MAC address resolution is made by the DSTARP application that has received a notification from the NFQUEUE target. The operation of the NFQUEUE target is described in the following document. Document: iptables-extensions, "Searched on December 16, 2021", URL: <https: / / linuxjm.osdn.jp / html / iptables / man8 / iptables-extensions.8.html>

[0129] As shown in FIG. 1, a communication system 200 including an HGW210 which is an in-house communication device according to Embodiment 2 includes a plurality of terminals 101, a subscriber access server 102, a first ISP system 103A, a second ISP system 103B, and the HGW210.

[0130] The terminal 101, the subscriber access server 102, the first ISP system 103A, and the second ISP system 103B in the communication system 200 according to Embodiment 2 are the same as the terminal 101, the subscriber access server 102, the first ISP system 103A, and the second ISP system 103B in the communication system 100 according to Embodiment 1.

[0131] The HGW210 includes a LANI / F unit 111, a WANI / F unit 112, and a network processing unit 220. The LANI / F unit 111 and the WANI / F unit 112 of the HGW210 according to Embodiment 2 are the same as the LANI / F unit 111 and the WANI / F unit 112 of the HGW110 according to Embodiment 1.

[0132] The network processing unit 220 controls the processing in the HGW210. For example, the network processing unit 220 controls relay processing for outputting packets from the subscriber communication network 105 to the LAN 104 and outputting packets from the LAN 104 to the subscriber communication network 105. Here, it is assumed that the network processing unit 220 supports IPv6.

[0133] The network processing unit 220 includes a PPPoE v6 client function unit 121, a DHCP v6 client function unit 122, a DHCP v6 server function unit 123, an IPv6 router advertisement server function unit 124, and an IPv6 packet filter function unit 225. The PPPoE v6 client function unit 121, the DHCP v6 client function unit 122, the DHCP v6 server function unit 123, and the IPv6 router advertisement server function unit 124 of the network processing unit 220 in the second embodiment are the same as those of the PPPoE v6 client function unit 121, the DHCP v6 client function unit 122, the DHCP v6 server function unit 123, and the IPv6 router advertisement server function unit 124 of the network processing unit 120 in the first embodiment.

[0134] The IPv6 packet filter function unit 225 performs filtering on the packets from the LAN 104 side received by the LAN I / F unit 111 and the packets from the subscriber communication network 105 side received by the WAN I / F unit 112.

[0135] FIG. 15 is a block diagram schematically showing the configuration of the IPv6 packet filter function unit 225 in the second embodiment. The IPv6 packet filter function unit 225 includes an S / W transfer setting control unit 130 and an S / W transfer processing unit 240. The S / W transfer setting control unit 130 of the IPv6 packet filter function unit 225 in the second embodiment is the same as the S / W transfer setting control unit 130 of the IPv6 packet filter function unit 125 in the first embodiment.

[0136] The S / W transfer processing unit 240 filters the packets on the LAN side received by the LAN I / F unit 111 or the packets on the WAN side received by the WAN I / F unit 112, and transfers those packets. The S / W transfer processing unit 240 includes an ip6tables main body unit 141, an S / W packet transfer processing unit 142, an ip6tables extension unit 243, and an NFQUEUE processing unit 244. In Embodiment 2, the ip6tables main body part 141 and the S / W packet transfer processing part 142 of the S / W transfer processing part 240 are the same as the ip6tables main body part 141 and the S / W packet transfer processing part 142 of the S / W transfer processing part 140 in Embodiment 1.

[0137] In response to an instruction from the ip6tables main body part 141, the ip6tables extension part 243 executes filtering by the destination MAC address in the chain PPOE1_WAN_TO_LAN_rule1 for destination MAC address resolution determination, which extends the processing in the ip6tables main body part 141. The ip6tables extension part 243 includes a DSTMAC processing part 243a and a routed-dst-mac processing part 143b. The routed-dst-mac processing part 143b of the ip6tables extension part 243 in Embodiment 2 is the same as the routed-dst-mac processing part 143b of the ip6tables extension part 143 in Embodiment 1.

[0138] The DSTMAC processing part 243a is activated to perform processing for resolving the destination MAC address from the destination IP address, and gives the received packet to the routed-dst-mac processing part 143b according to an evaluation rule configured such that the packet attempting to execute destination MAC filtering passes through the DSTMAC target. In Embodiment 2, the DSTMAC processing part 243a does not perform holding and retransmission of the received packet, and these processes are performed by the NFQUEUE processing part 244.

[0139] The NFQUEUE processing part 244 executes holding and retransmission of the received packet. For example, the NFQUEUE processing part 244 temporarily stores the packet before address resolution is executed in a memory (not shown) that functions as a temporary storage part. Note that this memory may be the memory 10 shown in FIG. 7(A), or may be provided separately from the memory 10.

[0140] As described above, in the second embodiment, when a packet is temporarily stored in the temporary storage unit via the NFQUEUE processing unit 244 in the ip6tables extension unit 243, the destination MAC address resolution of the packet is requested from the destination MAC resolution unit 142b, and after the address resolution of the packet is executed, MAC filtering is executed using the MAC address resolved by the address resolution.

[0141] In the second embodiment, the WAN-side filtering setting shown in FIG. 5 is expanded to the packet filtering operation inside the linux as shown in FIG. 16. The expansion shown in FIG. 16 is almost the same as the expansion shown in FIG. 10, but rule 45 in the expansion shown in FIG. 10 is changed to rule 47.

[0142] In rule 47, the operation for starting the destination MAC address resolution is expanded to NFQUEUE which is an existing extension target of iptables, and further, the ifindex which is the interface number of the LAN-side interface is specified by the parameter -queue-num.

[0143] Next, with reference to FIG. 17, in the second embodiment, the operation of the destination MAC address resolution when the NFQUEUE realizes the holding of the packet during the destination MAC address resolution will be described.

[0144] FIG. 17 shows a simplified view of the IP packet filtering process and the destination MAC address resolution process. In the second embodiment, according to the specification of rule 47 that requests the destination MAC address resolution, instead of the DSTMAC target, the NFQUEUE processing unit 244 that executes the NFQUEUE target operates.

[0145] Specifically, the NFQUEUE processing unit 244 holds the packet and transmits an NFQUEUE hold packet notification 53 to the DSTMAC processing unit 243a that executes the DSTMAC application in the user space.

[0146] When the DSTMAC processing unit 243a analyzes the destination IP address of the notified queued packet and the destination MAC address for the destination IP address is not being resolved, it sends a destination MAC address resolution request 50 to the destination MAC resolution unit 142b.

[0147] When the destination MAC resolution unit 142b finishes resolving the destination MAC address, it responds with a destination MAC address resolution response 51 to the DSTMAC processing unit 243a. As a result, the DSTMAC processing unit 243a sends a NFQUEUE reserved packet response 54 for all NFQUEUE reserved packet notifications 53 for the corresponding destination IP address to the NFQUEUE processing unit 244.

[0148] Upon receiving the NFQUEUE reserved packet response 54, the NFQUEUE processing unit 244 discards the packet or resumes the next rule evaluation based on the notification from the DSTMAC processing unit 243a.

[0149] FIG. 18 is a flowchart showing the operation of the DSTMAC processing unit 243a when packet holding during destination MAC resolution is realized by NFQUEUE in Embodiment 2.

[0150] When the DSTMAC processing unit 243a is notified of a packet reserved by the NFQUEUE processing unit 244 (S100), first, the DSTMAC processing unit 243a obtains the interface number of the destination interface from the queued packet queue number (S101).

[0151] Then, the DSTMAC processing unit 243a checks the type of the destination interface and determines whether the type of the destination interface is of Ether type (S102). If the type of the destination interface is not of Ether type (No in S102), the process proceeds to step S103. If the type of the destination interface is of Ether type (Yes in S102), the process proceeds to step S104.

[0152] In step S103, since the DSTMAC processing unit 243a does not need to resolve the destination MAC address, it notifies the NFQUEUE processing unit 244 of a hold packet response to proceed to the next rule. Then, the process proceeds to step S108, and the NGQUEUE hold packet processing ends.

[0153] On the other hand, if the type of the destination I / F is Ether type (Yes in S102), in step S104, the DSTMAC processing unit 243a determines whether or not to start resolving the destination MAC address for the destination IP address of the held packet. If the destination MAC address resolution has not been started (No in S104), the process proceeds to step S105. If the destination MAC address resolution has been started (Yes in S104), the process proceeds to step S106.

[0154] In step S105, the DSTMAC processing unit 243a sends a destination MAC address resolution request to the destination MAC resolution unit 142b. Then, the process proceeds to step S106.

[0155] In step S106, the DSTMAC processing unit 243a determines whether or not it has received a destination MAC address resolution response from the destination MAC resolution unit 142c. If the destination MAC address resolution response has been received (Yes in S106), the process proceeds to step S107.

[0156] In step S107, the DSTMAC processing unit 243a notifies the NFQUEUE processing unit 244 of a hold packet response to proceed to the next rule for all hold packet notifications having the destination IP address corresponding to the received destination MAC address resolution response. Then, the process proceeds to step S108, and the NFQUEUE hold packet processing ends.

[0157] As described above, in the HGW210 according to the second embodiment, instead of the DSTMAC target introduced in the first embodiment, an existing NFQUEUE target is used, and the DSTMAC processing unit 243a that receives the packet retention notification from the NFQUEUE target is made to execute destination MAC resolution. Therefore, the DSTMAC processing unit 243a does not need to have its own packet retention or retransmission logic, and the processing becomes simple.

[0158] An example of an application using the NFQUEUE target is described in the following document. Document: sample-helloworld.c, "Searched on December 16, 2021", URL: <https: / / github.com / irontec / netfilter-nfqueue-samples / blob / master / sample-helloworld.c>

[0159] As shown in this example, since the DSTMAC processing unit 243a is a process that operates in user space, there is an effect that it is easier to produce compared to the DSTMAC target created in kernel space.

[0160] Embodiment 3. In the first or second embodiment, a control method of the HGWs 110 and 210 equipped with a packet filter capable of specifying the MAC address of the LAN-side terminal was shown. In the third embodiment, high-speed IP packet transfer by H / W (Hardware) is enabled.

[0161] As shown in FIG. 1, a communication system 300 including an HGW310 which is an in-house communication device according to the third embodiment includes a plurality of terminals 101, a subscriber access server 102, a first ISP system 103A, a second ISP system 103B, and the HGW310.

[0162] The terminal 101, subscriber access server 102, first ISP system 103A, and second ISP system 103B in Communication System 300 in Embodiment 3 are the same as the terminal 101, subscriber access server 102, first ISP system 103A, and second ISP system 103B in Communication System 100 in Embodiment 1.

[0163] The HGW 310 includes a LAN I / F section 111, a WAN I / F section 112, and a network processing section 320. The LAN I / F section 111 and WAN I / F section 112 of the HGW 310 according to Embodiment 3 are the same as the LAN I / F section 111 and WAN I / F section 112 of the HGW 110 according to Embodiment 1.

[0164] The network processing section 320 controls the processing in the HGW 310. For example, the network processing section 320 controls the relay processing of outputting packets from the subscriber communication network 105 to the LAN 104 and outputting packets from the LAN 104 to the subscriber communication network 105. Here, it is assumed that the network processing section 320 supports IPv6.

[0165] The network processing section 320 includes a PPPoE v6 client function section 121, a DHCP v6 client function section 122, a DHCP v6 server function section 123, an IPv6 router advertisement server function section 124, and an IPv6 packet filter function section 325. The PPPoE v6 client function section 121, DHCP v6 client function section 122, DHCP v6 server function section 123, and IPv6 router advertisement server function section 124 of the network processing section 320 in Embodiment 3 are the same as the PPPoE v6 client function section 121, DHCP v6 client function section 122, DHCP v6 server function section 123, and IPv6 router advertisement server function section 124 of the network processing section 120 in Embodiment 1.

[0166] The IPv6 packet filter function unit 325 performs filtering on the packets from the LAN 104 side received by the LANI / F unit 111 and the packets from the subscriber communication network 105 side received by the WANI / F unit 112.

[0167] FIG. 19 is a block diagram schematically showing the configuration of the IPv6 packet filter function unit 325 in Embodiment 3. The IPv6 packet filter function unit 325 includes an S / W transfer setting control unit 130, an S / W transfer processing unit 340 executed by software, and an H / W transfer processing unit 350 executed by hardware.

[0168] The S / W transfer processing unit 340 includes an S / W packet transfer processing unit 342 that performs filter processing combining the IP address and the MAC address described in Embodiment 1 or 2, and an IP flow management unit 345. The S / W packet transfer processing unit 342 includes a destination MAC resolution unit 342b.

[0169] Note that since the internal configuration of the H / W transfer processing unit 350 varies, only the basic operation parts related to the packet filter operation and the IP packet transfer in Embodiment 3 are described here.

[0170] The H / W transfer processing unit 350 includes a packet header extraction unit 351, an IP flow match determination unit 352, a packet header editing unit 353, an H / W IP flow management unit 354, and an H / W destination MAC management unit 355.

[0171] The packet header extraction unit 351 examines the IP header of the IP packet received by the LANI / F unit 111 or the WANI / F unit 112 which is the reception I / F, and extracts {source IP address, destination IP address, protocol, source port number, destination port number} in the IP header. The information combining these five values within {} is basic configuration information for identifying to which connection the packet belongs, and is called session information or IP flow information.

[0172] This session information or IP flow information is information used to perform consistent processing on IP packets belonging to the same session. For example, in NAT (Network Address Translation) processing or NAPT (Network Address Port Translation) processing, when converting the source address or source port number, all IP packets belonging to the same session must be converted with the same source address or source port number.

[0173] To achieve this, the source address or source port number for NAPT conversion in the first packet is determined, and subsequent packets with the same session information or IP flow information are all converted to have the same source address or source port number as that first packet. Also, this session information or IP flow information corresponds to management information called conntrack information in the network stack in, for example, Linux, and is managed by the IP flow management unit 345. Specifically, the IP flow management unit 345 stores the session information or IP flow information in a memory (not shown) that functions as a storage unit. Note that this memory may be the memory 10 shown in Fig. 7(A), or may be provided separately from the memory 10.

[0174] The IP flow matching determination unit 352 determines whether the flow information extracted by the packet header extraction unit 351 matches an entry registered in the H / W IP flow management unit 354 within the H / W transfer processing unit 350.

[0175] Since the first packet of the session has no IP flow information registered in the H / W IP flow management unit 354, the IP flow matching determination unit 352 sends that packet to the S / W transfer processing unit 340 as having no flow information for H / W transfer processing.

[0176] The S / W transfer processing unit 340 that has received the packet performs destination route resolution and filtering processing in the S / W packet transfer processing unit 342. The processing in the S / W packet transfer processing unit 362 is as described with reference to FIG. 11. In other words, the processing in the S / W packet transfer processing unit 362 is a combination of packet filtering and destination route resolution, as described in the first embodiment.

[0177] In the packet filtering process, the S / W packet transfer processing unit 342 can perform filtering based on the MAC address of the LAN-side terminal shown in the first embodiment.

[0178] Here, if the S / W packet transfer processing unit 342 determines to discard the first packet in the filtering process, the IP flow information of the packet is not registered in the IP flow management unit 345 within the S / W transfer processing unit 340, and no entry is registered in the H / W IP flow management unit 354 either. Therefore, subsequent packets are similarly sent to the S / W transfer processing unit 340, and are similarly determined to be discarded by the S / W transfer processing unit 340, and subsequent packets belonging to that IP flow are not transferred.

[0179] On the other hand, if the S / W packet transfer processing unit 342 determines that the first packet passes through the filtering process, the IP flow information of that packet is registered in the IP flow management unit 345 within the S / W transfer processing unit 340. At this time, the IP flow management unit 345 causes the H / W IP flow management unit 354 to also register that IP flow information.

[0180] Thereafter, the destination MAC resolution unit 342b of the S / W packet transfer processing unit 342 performs destination MAC resolution processing on the first packet and returns the packet to the H / W transfer processing unit 350.

[0181] Then, the H / W transfer processing unit 350 transmits the packet from the LAN I / F unit 111 or the WAN I / F unit 112, which is the transmission I / F on the opposite side.

[0182] Here, the destination MAC address resolution unit 342b of the S / W packet transfer processing unit 342 registers the MAC address resolved for the IP address so as to always be synchronized with the H / W destination MAC management unit 355 of the H / W transfer processing unit 350.

[0183] Next, when a subsequent packet is received, the packet header extraction unit 351 examines the header of the subsequent packet in the same manner as the first packet, and extracts {source IP address, destination IP address, protocol, source port number, destination port number} in the IP header.

[0184] Next, the IP flow matching determination unit 352 determines whether the extracted flow information matches the registered entry in the H / W IP flow management unit 354 within the H / W transfer processing unit 350. Here, since the IP flow information of the subsequent packets of the session is registered in the H / W IP flow management unit 354, the IP flow matching determination unit 352 determines that the flow information matches.

[0185] The packets determined to match the flow information here are sent to the subsequent packet header editing unit 353, except for some packets that require processing in the S / W transfer processing unit 340 or some exception packets that cannot be processed in the H / W transfer processing unit 350. Some packets that require processing in the S / W transfer processing unit 340 are, for example, control packets with the SYN flag, FIN flag, or RST flag of TCP (Transmission Control Protocol), etc.

[0186] The packet header editing unit 353 performs necessary packet header editing processing based on the editing information of the IP flow held by the H / W IP flow management unit 354 and the MAC address held by the H / W destination MAC management unit 355. For example, the packet header editing unit 353 performs processing such as updating the address or port number of the packet for NAT processing, updating the source MAC based on the transmission I / F, or updating the destination MAC address for the next hop after routing.

[0187] After the packet header editing process, the subsequent packet is processed only by the H / W transfer processing unit 350 from the LAN I / F unit 111 or the WAN I / F unit 112, which is the transmission I / F on the opposite side at the end. In other words, it is transmitted without passing through the S / W transfer processing unit 340.

[0188] The H / W transfer processing unit 350 described above can be realized by, for example, the processing circuit 12 shown in FIG. 7(B).

[0189] As described above, in the HGW310 according to the third embodiment, determination using the MAC address of the LAN-side terminal is performed on the leading packet. When it is determined that the leading packet passes, subsequent packets are transferred by H / W using the IP flow information. Therefore, even a general H / W transfer processing unit (Network Processor) that does not have a filtering function using the MAC address can realize a filtering operation using the MAC address of the LAN-side terminal and a high-speed IP packet transfer operation by H / W.

[0190] In other words, in the third embodiment, the HGW310 further includes the H / W transfer processing unit 350 that functions as a hardware transfer unit for routing packets using hardware. The ip6tables extension unit 143 performs MAC filtering on the leading packet of the session. When the leading packet passes through the MAC filtering, the subsequent packets that are subsequent packets of the same session as the leading packet are routed to the H / W transfer processing unit 350, and MAC filtering can be prevented from being performed on the subsequent packets.

[0191] Note that the configuration of the third embodiment is based on the configuration of the first embodiment, but the configuration of the third embodiment may be configured based on the configuration of the second embodiment.

Explanation of Reference Numerals

[0192] 100, 200, 300 communication system, 101 terminal, 102 subscriber access server, 103A first ISP system, 103B second ISP system, 110 HGW, 111 LANI / F section, 112 WANI / F section, 120, 220, 320 network processing section, 121 PPPoEv6 client function section, 122 DHCPv6 client function section, 123 DHCPv6 server function section, 124 IPv6 router advertisement server function section, 125, 225, 325 IPv6 packet filter function section, 130 S / W transfer setting control section, 131 ipv6 packet filter GUI processing section, 132 ipv6tables rule expansion AP execution section, 140, 240, 340 S / W transfer processing section, 141 ip6tables main body section, 141a PRE ROUTING execution section, 141b FORWARDING execution section, 141c POST ROUTING execution section, 142, 342 S / W packet transfer processing section, 142a route resolution section, 142b, 342b destination MAC resolution section, 143, 243 ip6tables extension section, 143a, 243a DSTMAC processing section, 143b routed-dst-mac processing section, 244 NFQUEUE processing section, 345 IP flow management section, 350 H / W transfer processing section, 351 packet header extraction section, 352 IP flow matching judgment section, 353 packet header editing section, 354 H / W IP flow management section, 355 H / W destination MAC management section.

Claims

1. A receiving interface for receiving packets from a WAN (Wide Area Network), a transfer unit that performs address resolution of the packet and routes the packet to a LAN (Local Area Network), an extension function unit that executes MAC filtering, which is filtering of the destination MAC (Media Access Control) address of the packet after the routing, according to the rules of an IP (Internet Protocol) packet filter, wherein the extension function unit executes the MAC filtering on the destination MAC address that designates the MAC address of the terminal without using the IP address of the terminal connected to the LAN, and a home communication device characterized by the above.

2. The home communication device according to claim 1, wherein the transfer unit sends the packet to the extension function unit when the destination of the packet is the terminal as a result of the routing.

3. In the home communication device according to claim 2, which is the self-device, the transfer unit sends the packet to the application of the self-device when the destination of the packet is the self-device as a result of the routing. and a home communication device characterized by the above.

4. The home communication device according to claim 3, wherein the extension function unit executes the MAC filtering on the transmitted packet sent from the application of the self-device in the same manner as the packet.

5. The home communication device according to claim 4, wherein the transfer unit routes the transmitted packet sent from the application of the self-device and then sends the transmitted packet to the extension function unit.

6. The rules execute the address resolution of the packet after the routing, and execute the MAC filtering by the destination MAC address resolved by the address resolution. The extension function unit causes the transfer unit to execute the address resolution according to the rules, and execute the MAC filtering by the resolved destination MAC address. The in-house communication device according to any one of claims 1 to 5, characterized in that.

7. It further includes a temporary storage unit that temporarily stores the packet before the address resolution is executed. When the packet is temporarily stored in the temporary storage unit, the extension function unit requests the transfer unit to perform the address resolution of the packet, and after the address resolution of the packet is executed, the MAC filtering is performed by the destination MAC address resolved by the address resolution. The in-house communication device according to claim 6, characterized in that.

8. The rules have a first filtering rule for conditions not including the destination MAC address, a second filtering rule for conditions including the destination MAC address, and a third filtering rule for instructing the destination MAC address resolution. The third filtering rule instructs the destination MAC address resolution when evaluating the second filtering rule. The in-house communication device according to claim 1, characterized in that.

9. The rules have a fourth filtering rule for conditions not including the destination MAC address and conditions including the destination MAC address. When the fourth filtering rule matches the condition not including the destination MAC address, it causes the destination MAC address resolution to be performed and then causes the determination process of the condition including the destination MAC address to be performed. The in-house communication device according to claim 1, characterized in that.

10. An IP address distribution unit that distributes the IP address to the terminal. A filtering execution unit that executes IP filtering, which is filtering using the IP address, and further includes The in-house communication device according to any one of claims 1 to 5, 8, and 9, characterized in that

11. The IP address distribution unit distributes the IP address included in the IPv6 (Internet Protocol version 6) address band corresponding to the IPv6 prefix acquired from the WAN to the terminal The in-house communication device according to claim 10, characterized in that

12. An IP address advertisement unit that generates the IP address in the terminal by advertising an IPv6 address band corresponding to the IPv6 prefix acquired from the WAN to the terminal, and A filtering execution unit that executes IP filtering, which is filtering using the IP address, and further includes The in-house communication device according to any one of claims 1 to 5, 8, and 9, characterized in that

13. Further includes a hardware transfer unit that performs routing of the packet using hardware, The extension function unit executes the MAC filtering on the first packet of the session as the packet, and when the first packet passes through the MAC filtering, the subsequent packets that are the subsequent packets of the same session as the first packet are routed to the hardware transfer unit, and the MAC filtering is not performed on the subsequent packets The in-house communication device according to claim 6, characterized in that

14. Further includes a hardware transfer unit that performs routing of the packet using hardware, The extension function unit executes the MAC filtering on the packet that is the first packet of the session as the packet, and when the first packet passes through the MAC filtering, the hardware transfer unit is made to perform routing on the subsequent packet that is a packet subsequent to the first packet in the same session, and the MAC filtering is not performed on the subsequent packet. The in-house communication device according to claim 7, characterized by the above.

Citation Information

Patent Citations

  • Device and method for transferring packet

    JP2005347969A

  • Communication apparatus and control method thereof

    JP2009010772A

  • Communication device, communication control system, communication control method, and communication control program

    JP2019176323A

  • IP packet relay method and gateway device in communication network

    WO2006051594A1