CN113206792B - Message forwarding method and device - Google Patents

Message forwarding method and device Download PDF

Info

Publication number
CN113206792B
CN113206792B CN202110264827.3A CN202110264827A CN113206792B CN 113206792 B CN113206792 B CN 113206792B CN 202110264827 A CN202110264827 A CN 202110264827A CN 113206792 B CN113206792 B CN 113206792B
Authority
CN
China
Prior art keywords
address
message
hardware
table entry
mac address
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Active
Application number
CN202110264827.3A
Other languages
Chinese (zh)
Other versions
CN113206792A (en
Inventor
吕一丹
阳进
梁学伟
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
New H3C Security Technologies Co Ltd
Original Assignee
New H3C Security Technologies Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by New H3C Security Technologies Co Ltd filed Critical New H3C Security Technologies Co Ltd
Priority to CN202110264827.3A priority Critical patent/CN113206792B/en
Publication of CN113206792A publication Critical patent/CN113206792A/en
Application granted granted Critical
Publication of CN113206792B publication Critical patent/CN113206792B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L45/00Routing or path finding of packets in data switching networks
    • H04L45/74Address processing for routing
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L45/00Routing or path finding of packets in data switching networks
    • H04L45/74Address processing for routing
    • H04L45/745Address table lookup; Address filtering
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L61/00Network arrangements, protocols or services for addressing or naming
    • H04L61/09Mapping addresses
    • H04L61/10Mapping addresses of different types
    • H04L61/103Mapping addresses of different types across network layers, e.g. resolution of network layer into physical layer addresses or address resolution protocol [ARP]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L2101/00Indexing scheme associated with group H04L61/00
    • H04L2101/60Types of network addresses
    • H04L2101/618Details of network addresses
    • H04L2101/622Layer-2 addresses, e.g. medium access control [MAC] addresses

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

The application provides a message forwarding method and device. The message forwarding method comprises the following steps: sending a hardware address request message based on a mirror image message of a roaming wireless user; generating an address mapping software table entry according to the hardware address response message; wherein, the address mapping software table entry comprises the IP address of the roaming wireless user corresponding to the MAC address of the roaming wireless user and the local receiving port of the hardware address response protocol message; generating an MAC address software table entry according to the address mapping software table entry; synchronizing MAC address software table entries into MAC address hardware table entries of a two-layer hardware forwarding table; and sending the downlink message matched with the MAC address hardware table entry to the roaming wireless user.

Description

Message forwarding method and device
Technical Field
The present application relates to communications technologies, and in particular, to a method and a device for forwarding a packet.
Background
When the wireless user roams, the gateway and the wireless user's own IP address change, and the data stream received and transmitted by the wireless user is interrupted for a period of time. In order to ensure the rapid migration of wireless users, the (Access Point) gateways of the AP devices are unified, so that the gateways and the user IP can be kept unchanged during roaming.
In a wireless network, an AP device having an ARP (Address Resolution Protocol) message generation function sends a gratuitous ARP Protocol message instead of a roaming wireless Access user, an Access switch receives the gratuitous ARP Protocol message generated by the AP device, refreshes a Media Access Control (MAC) Address table entry, and updates an IP Source Guard (IPSG) table entry.
However, once the AP device does not have the capability of sending an ARP protocol packet for a roaming wireless user, the access switch after roaming cannot update the MAC address entry and the IPSG entry, cannot send a downlink packet to the roaming wireless user, and cannot perform security check on whether the uplink packet is from the roaming wireless user.
Disclosure of Invention
The application aims to provide a message forwarding method and device, which ensure the migration of data traffic of a roaming wireless user.
In order to achieve the above object, the present application provides a packet forwarding method, including: sending a hardware address request message based on a mirror image message of a roaming wireless user; generating an address mapping software table entry according to the hardware address response message; wherein, the address mapping software table entry comprises the IP address of the roaming wireless user corresponding to the MAC address of the roaming wireless user and the local receiving port of the hardware address response protocol message; generating an MAC address software table entry according to the address mapping software table entry; synchronizing MAC address software table entries into MAC address hardware table entries of a two-layer hardware forwarding table; and sending the downlink message matched with the MAC address hardware table entry to the roaming wireless user.
The application also provides a message forwarding device, which includes: the address mapping software table entry module is used for sending a hardware address request message based on the mirror image message; generating an address mapping software table entry according to a hardware address response message of the hardware address request message; wherein, the address mapping software table entry comprises the IP address of the roaming wireless user corresponding to the MAC address of the roaming wireless user and the local receiving port of the hardware address response protocol message; the forwarding software table entry module is used for generating an MAC address software table entry according to the address mapping software table entry; synchronizing MAC address software table entries into MAC address hardware table entries of a two-layer hardware forwarding table of a hardware forwarding unit; wherein, the MAC address software table entry comprises a local receiving port corresponding to the MAC address; and the hardware forwarding unit is used for sending the downlink message matched with the MAC address hardware table entry through the local receiving port.
The method has the advantages that the access switch can actively learn the mapping table items of the IP address and the MAC address of the roaming wireless user and the MAC address hardware table items by actively triggering the roaming wireless user to respond to the hardware address request message, so that the flow migration of the roaming wireless user is ensured.
Drawings
Fig. 1 is a flowchart illustrating a message forwarding method according to an embodiment of the present application;
fig. 2 is a schematic diagram illustrating message forwarding of a roaming user according to the present application;
fig. 3 is a flowchart illustrating an embodiment of a message forwarding device provided in the present application.
Detailed Description
A detailed description will be given of a number of examples shown in a number of figures. In the following detailed description, numerous specific details are set forth in order to provide a thorough understanding of the present application. Well-known methods, procedures, components and circuits have not been described in detail so as not to obscure the examples.
Where the terms are used, the terms "include" and "comprise" mean including but not limited to; the term "comprising" means including but not limited to; the terms "above," "within," and "below" include the instant numbers; the terms "greater than" and "less than" mean that the number is not included. The term "based on" means based on at least a portion thereof.
Fig. 1 is a flowchart illustrating an embodiment of a message forwarding method provided in the present application, where the method includes:
step 101, sending a hardware address request message based on a mirror image message of a roaming wireless user;
102, generating an address mapping software table entry according to the hardware address response message;
the address mapping software table entry records: the IP address of the roaming wireless user corresponds to the MAC address of the roaming wireless user and a local receiving port of a hardware address response protocol message;
103, generating an MAC address software table according to the address mapping software table;
step 104, synchronizing MAC address software table entries into MAC address hardware table entries of a two-layer hardware forwarding table;
and 105, sending the downlink message matched with the MAC address hardware table item to the roaming wireless user.
The method has the advantages that the access switch can actively learn the mapping table items of the IP address and the MAC address of the roaming wireless user and the MAC address hardware table items by actively triggering the roaming wireless user to respond to the hardware address request message, so that the flow migration of the roaming wireless user is ensured.
Fig. 2 shows that in the wireless network provided by the embodiment of the present application, the client a accesses the AP1, and the client B accesses the AP 2. The access switch 1 stores the learned MAC address table entry and IP source table entry of the client a. The access switch 1 synchronizes the IP source table entries of the clients to the access switch 2.
When client a roams from the accessed AP1 to AP2, the IP addresses of gateway switches 3 and 4 do not change, nor does the IP address of client a.
The client a sends an uplink message 20, and the AP2 sends the uplink message 20 to the access switch 2 after receiving the uplink message 20.
The switching chip of the access switch 2 receives the uplink message 20 and looks up it in the MAC address table according to the source MAC address. In the present application, when the access switch 2 does not find the MAC address entry matching the source MAC address, source MAC address learning is not performed, and the uplink message 20 serving as the source unknown message is copied according to the mirror message entry set at the port receiving the uplink message 2 to generate a mirror message, and the mirror message is sent to the processor of the access switch 2 for software processing.
A processor of the access switch 2 analyzes the uplink message 20, extracts a source IP address, a source MAC address, a VLAN identifier and a receiving PORT PORT carried by the uplink message 20, and generates an ARP request message 21 according to the extracted message characteristic information; wherein, the IP address of the sending end is the source IP address obtained from the uplink message 20 by parsing.
The processor of the access switch 2 sends the ARP request message 21 and the port information, namely the port receiving the uplink message 20, to the switch chip; the switching chip of the access switch 2 sends an ARP request message 21 through the sending port. The AP2 receives the ARP request message 21 and broadcasts it. The client a receives the ARP request message 21 broadcasted by the AP2, and sends an ARP response message 22. The AP2 sends the received ARP response message 22 to the access switch 2.
The switching chip of the access switch 2 receives the ARP response message 22, and sends the ARP response message 22 and the receiving port information to the processor for processing. The processor of the access switch 2 generates an ARP software entry according to the sender IP address (IP address IPA of the client a), the sender MAC address (MAC address MAC a of the client a), and the receiving port of the ARP response packet 22, where the receiving port of the ARP response packet 22 and the MAC address corresponding to the IP a are recorded.
The processor of the access switch 2 generates an MAC address hardware table entry according to the ARP software table entry, and records the receiving port of the ARP response packet 22 corresponding to the MAC a. The processor of the access switch 2 synchronizes the MAC address software table entries to the MAC address table entries of the MAC table of the switch chip.
The access switch 2 generates a local IP source guard entry according to the synchronous IP source guard entry of the previous access switch 1 and the receiving port of the ARP response message 22, and configures the local IP source guard entry at the receiving port of the ARP response message 22.
The matching item of the IP source guard table entry in the application at least comprises the IP address IP A of the client A, and can also be the MAC address MAC A and VLAN identification of the client A.
When the access switch 2 is configured with an IP source guard table entry port to receive the uplink message, the switch chip checks whether the IP source guard table entry is matched; if yes, forwarding according to the destination MAC address; if not, discarding.
In the application, the access switch is used as a two-layer switch, when a source unknown MAC address is received, source MAC address learning is not performed, the access switch 2 is triggered by a mirror image message to actively send an ARP request message to a roaming client A, and after three-layer forwarded ARP software table entries are generated by processor software, two-layer forwarded MAC address table entries are generated and synchronized to a switch chip. Therefore, the method and the device are not limited by whether the AP equipment has the ARP proxy function or not, the flow of the roaming unlimited user is quickly switched to a new access switch, and the flow interruption of the roaming unlimited user is avoided.
In order to achieve the above object, the present application further provides a message forwarding device 30, where the message forwarding device 30 includes: a plurality of ports, a switch chip as a hardware forwarding unit, a processor, and a memory. The processor is used for executing the address mapping software table entry module, the forwarding software table entry module and the source protection software module by calling the processor executable instruction recorded in the memory.
The address mapping software table entry module is used for sending a hardware address request message based on the mirror image message; generating an address mapping software table entry according to a hardware address response message of the hardware address request message; wherein, the address mapping software table entry comprises the IP address of the roaming wireless user corresponding to the MAC address of the roaming wireless user and the local receiving port of the hardware address response protocol message; a source protection software module.
The forwarding software table entry module is used for generating an MAC address software table entry according to the address mapping software table entry; synchronizing MAC address software table entries into MAC address hardware table entries of a two-layer hardware forwarding table of a hardware forwarding unit; wherein, the MAC address software table entry comprises a local receiving port corresponding to the MAC address; and the hardware forwarding unit is used for sending the downlink message matched with the MAC address hardware table entry through the local receiving port.
The hardware forwarding unit is also used for receiving the uplink message; searching a two-layer hardware forwarding table according to a source MAC address of the uplink message; determining a two-layer MAC address hardware table item which is not matched with the source MAC address of the uplink message; and copying the uplink message into a mirror image message according to a preset mirror image message table entry, and sending the mirror image message to an address mapping software table entry module.
And the source protection software module is used for generating a local source protection table item at least comprising an IP address according to the synchronous source protection table item and the address mapping software table item, and synchronizing the local source protection table item to the hardware forwarding unit.
And the hardware forwarding unit is also used for configuring a local source protection table entry for the local receiving port.
And the hardware forwarding unit is also used for discarding the uplink message which is received by the local receiving port and does not match with the local source protection table entry.
The present invention is not intended to be limited to the particular embodiments shown, but is to be accorded the widest scope consistent with the principles and spirit of the present invention.

Claims (8)

1. A message forwarding method is applied to an access switch, and is characterized in that the method comprises the following steps:
sending a hardware address request message based on a mirror image message generated by an uplink message sent by a roaming wireless user;
generating an address mapping software table entry according to a hardware address response message of the hardware address request message; wherein, the address mapping software table entry comprises the IP address of the roaming wireless user corresponding to the MAC address of the roaming wireless user and the local receiving port of the hardware address response protocol message;
generating an MAC address software table entry according to the address mapping software table entry;
synchronizing the MAC address software table entries into MAC address hardware table entries of a two-layer hardware forwarding table;
and sending the downlink message matched with the MAC address hardware table item to the roaming wireless user.
2. The method of claim 1, wherein prior to sending the hardware address request message based on the mirror message of the roaming wireless subscriber, the method further comprises:
receiving an uplink message from the roaming wireless user;
searching the two-layer hardware forwarding table according to the source MAC address of the uplink message;
determining a hardware table entry of a second-layer MAC address which is not matched with the source MAC address of the uplink message;
and copying the uplink message into the mirror image message according to a preset mirror image message table entry.
3. The method of claim 1, further comprising:
generating a local source protection table item at least comprising the IP address according to the synchronous source protection table item and the address mapping software table item;
and configuring the local source protection table entry for the local receiving port.
4. The method of claim 3, further comprising:
and discarding the uplink message which is received by the local receiving port and does not match the local source protection table entry.
5. A message forwarding device applied to an access switch is characterized in that the device comprises:
the address mapping software table entry module is used for sending a hardware address request message based on a source IP address in a mirror image message generated by an uplink message sent by a roaming wireless user; generating an address mapping software table entry according to a hardware address response message of the hardware address request message; wherein, the address mapping software table entry comprises the IP address of the roaming wireless user corresponding to the MAC address of the roaming wireless user and the local receiving port of the hardware address response protocol message;
the forwarding software table entry module is used for generating an MAC address software table entry according to the address mapping software table entry; synchronizing the MAC address software table entries into MAC address hardware table entries of a two-layer hardware forwarding table of a hardware forwarding unit; wherein, the MAC address software table entry comprises that the MAC address corresponds to the local receiving port;
and the hardware forwarding unit is used for sending the downlink message matched with the MAC address hardware table entry through the local receiving port.
6. The apparatus of claim 5, wherein the hardware forwarding unit is further configured to receive an uplink packet; searching the two-layer hardware forwarding table according to the source MAC address of the uplink message; determining a hardware table entry of a second-layer MAC address which is not matched with the source MAC address of the uplink message; and copying the uplink message into the mirror image message according to a preset mirror image message table entry, and sending the mirror image message to the address mapping software table entry module.
7. The apparatus of claim 5, further comprising:
a source protection software module, configured to generate a local source protection table entry including at least the IP address according to the synchronized source protection table entry and the address mapping software table entry, and synchronize the local source protection table entry to the hardware forwarding unit;
the hardware forwarding unit is further configured to configure the local source protection table entry for the local receiving port.
8. The apparatus of claim 7, further comprising:
the hardware forwarding unit is further configured to discard the uplink packet that is received by the local receiving port and does not match the local source protection table entry.
CN202110264827.3A 2021-03-11 2021-03-11 Message forwarding method and device Active CN113206792B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN202110264827.3A CN113206792B (en) 2021-03-11 2021-03-11 Message forwarding method and device

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN202110264827.3A CN113206792B (en) 2021-03-11 2021-03-11 Message forwarding method and device

Publications (2)

Publication Number Publication Date
CN113206792A CN113206792A (en) 2021-08-03
CN113206792B true CN113206792B (en) 2022-05-27

Family

ID=77025379

Family Applications (1)

Application Number Title Priority Date Filing Date
CN202110264827.3A Active CN113206792B (en) 2021-03-11 2021-03-11 Message forwarding method and device

Country Status (1)

Country Link
CN (1) CN113206792B (en)

Citations (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1996948A (en) * 2006-12-28 2007-07-11 杭州华为三康技术有限公司 Message forwarding method and device based on the media access control layer
CN103118148A (en) * 2013-01-31 2013-05-22 杭州华三通信技术有限公司 Method and device for updating ARP (address resolution protocol) cache
CN103227843A (en) * 2012-08-31 2013-07-31 杭州华三通信技术有限公司 Physical link address management method and device
CN103326918A (en) * 2013-05-17 2013-09-25 杭州华三通信技术有限公司 Message forwarding method and message forwarding equipment
CN105451221A (en) * 2015-11-06 2016-03-30 迈普通信技术股份有限公司 Terminal roaming realization method, system and wireless access point
CN106102122A (en) * 2016-05-16 2016-11-09 杭州华三通信技术有限公司 MAC Address list item update method and device
CN108833604A (en) * 2018-05-28 2018-11-16 新华三技术有限公司 A kind of list item update method and device

Family Cites Families (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US7885180B2 (en) * 2006-12-15 2011-02-08 Check Point Software Technologies Inc. Address resolution request mirroring

Patent Citations (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1996948A (en) * 2006-12-28 2007-07-11 杭州华为三康技术有限公司 Message forwarding method and device based on the media access control layer
CN103227843A (en) * 2012-08-31 2013-07-31 杭州华三通信技术有限公司 Physical link address management method and device
CN103118148A (en) * 2013-01-31 2013-05-22 杭州华三通信技术有限公司 Method and device for updating ARP (address resolution protocol) cache
CN103326918A (en) * 2013-05-17 2013-09-25 杭州华三通信技术有限公司 Message forwarding method and message forwarding equipment
CN105451221A (en) * 2015-11-06 2016-03-30 迈普通信技术股份有限公司 Terminal roaming realization method, system and wireless access point
CN106102122A (en) * 2016-05-16 2016-11-09 杭州华三通信技术有限公司 MAC Address list item update method and device
CN108833604A (en) * 2018-05-28 2018-11-16 新华三技术有限公司 A kind of list item update method and device

Also Published As

Publication number Publication date
CN113206792A (en) 2021-08-03

Similar Documents

Publication Publication Date Title
EP1250791B1 (en) System and method for using an ip address as a wireless unit identifier
CN109257265B (en) Flooding suppression method, VXLAN bridge, gateway and system
EP2213080B1 (en) Vrrp and learning bridge cpe
EP1189411B1 (en) Packet transfer scheme using mobile terminal and router for preventing attacks using global address
WO2009094928A1 (en) A method and equipment for transmitting a message based on the layer-2 tunnel protocol
EP2753029B1 (en) Message learning method, device and system
JP2002538690A (en) Apparatus and method for effectively transferring multicast data in a personal access communication system (PAC)
CN107094110B (en) DHCP message forwarding method and device
WO2010072096A1 (en) Method and broadband access device for improving the security of neighbor discovery in ipv6 environment
US20220141176A1 (en) Supporting dynamic host configuration protocol-based customer premises equipment in fifth generation wireline and wireless convergence
CN111654485B (en) Client authentication method and device
US20160080318A1 (en) Dynamic host configuration protocol release on behalf of a user
JP4920878B2 (en) Authentication system, network line concentrator, authentication method used therefor, and program thereof
CN112867086B (en) Message processing method and device
CN111953607B (en) Method and device for updating route
US20230146807A1 (en) Supporting dynamic host configuration protocol-based customer premises equipment in fifth generation wireline and wireless convergence
CN113726632B (en) Message forwarding method and device
KR20200020544A (en) Method and system for private network service in 5g communication network
CN113206792B (en) Message forwarding method and device
CN115769634A (en) Method and apparatus for directing a session to an application server
JP6417720B2 (en) Communication apparatus, network system, address resolution control method and program
CN112996077B (en) Message processing method and device
Liang et al. Key Issue Analysis on 5G Inter-networks Roaming
WO2019123630A1 (en) Communication device and communication method
KR101469434B1 (en) method for transferring local IP address from SDN to femto cell

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination
GR01 Patent grant
GR01 Patent grant