Summary of the invention
The invention provides data forwarding system, method and network forwarding equipment,, improve networking flexibility to reduce the Networking Design cost.
Technical scheme of the present invention is achieved in that
A kind of data forwarding system comprises: control unit, forward processing unit and application traffic processing unit, wherein:
Control unit, be used for client port, network forwarding equipment and all kinds of application ports that are connected with the servers of application type differentiation that the configuration network forwarding unit is connected with client, port is handled in application traffic between configuration forward processing unit and the application traffic processing unit, port information is handled in client port information, application port information and the application traffic of configuration sent to forward processing unit and application traffic processing unit;
Forward processing unit receives that client sends message, and this message is sent to the application traffic processing unit, and the server identification that returns according to the application traffic processing unit, and the application port of message from self corresponding with this sign sent;
The application traffic processing unit, be used to receive the message that forward processing unit is sent from client, if detect and self preserve and this message corresponding response conversational list, the server identification in this response session table is carried in this message sends to forward processing unit; Otherwise, determine the server identification that this message should mail to according to the application characteristic information of this message, this sign is carried in this message sends to forward processing unit, and preserve the response session table.
Described forward processing unit and application traffic processing unit are positioned within the network forwarding equipment, and described control unit is positioned within the network forwarding equipment or is independent of outside the network forwarding equipment.
Described response session table comprises: server identification, protocol information that the source IP address of message, source port number, purpose IP address, destination slogan, the client identification that sends this message, this message should mail to.
Described application traffic processing unit is further used for, and the purpose IP address that detects in the message that forward processing unit sends is a virtual IP address, and this virtual IP address is replaced with real IP address.
Described forward processing unit is further used for, and the message that server is sent sends to the application traffic processing unit, and the client identification that returns according to the application traffic processing unit sends the client port of this message from self corresponding with this sign;
Described application traffic processing unit is further used for, receive the message that forward processing unit is sent from server, the response session table of preserving according to self is determined the sign of the client that this message should mail to, and this sign is carried in this message sends to forward processing unit.
Described application traffic processing unit is further used for, and the source IP address that detects in the message that forward processing unit sends is real IP address, should replace with virtual IP address in reality IP address.
Described application traffic processing unit comprises: load balance process unit and contents searching unit, wherein:
The load balance process unit, be used for detect self do not preserve with forward processing unit send from the message corresponding response conversational list of client the time, this message is issued contents searching unit, and the application type that returns according to the contents searching unit sign and the default load balancing principle of self preserving, identifying server of selection in corresponding server with this application type, client identification with in the sign replacement message of this server sends to forward processing unit with this message;
Contents searching unit is used for the message that the balancing received load processing unit is sent, and according to the application characteristic information of this message, determines the application type sign of this message, and this application type sign is sent to the load balance process unit.
Pass through the peripheral component interconnect standard interface between described load balance process unit and contents searching unit
(PCI)-X or PCI-E bus link to each other.
Link to each other by pci bus between described control unit and forward processing unit.
Link to each other by Attachment Unit Interface (XAUI) bus between described forward processing unit and application traffic processing unit.
A kind of data forwarding method is applied in the network with application type Differentiated Services device, has the application port that is connected with the server of different application type on the network forwarding equipment, comprising:
Network forwarding equipment is received the message that client is sent, self preserve and this message corresponding response conversational list if detect, replace client identification in this message with the server identification in this response session table, and determine the application port that of this message message to be sent from this application port according to server identification; Otherwise, application characteristic information according to this message, determine the application type of this message, in self port, select an application port corresponding with this application type, replace client identification in this message with the sign of this application port corresponding server, message is sent from this application port.
Described network forwarding equipment selects an application port corresponding with this application type to comprise in self port: network forwarding equipment is according to the conversational list of this message and default load balancing principle, application port corresponding with this application type of selection in self port.
Described network forwarding equipment is selected after the application port in self port, message was further comprised before this application port sends: the purpose IP address that network forwarding equipment detects this message is a virtual IP address, then the empty purpose IP address of replacing this message with the real IP address of this application port corresponding server of self preserving.
Described network forwarding equipment further comprises after replacing client identification in this message with the sign of this application port corresponding application server: network forwarding equipment is set up the response session table of the source IP address that comprises this message, source port number, purpose IP address, destination slogan, client identification, server identification, protocol information.
Described method further comprises: network forwarding equipment is received the message that server is sent, judge self whether to preserve and this message corresponding response conversational list, if preserve, then, the client port of this message from self sent according to this client identification with the server identification in the replacement of the client identification in the response session table message.
Described network forwarding equipment judge self preserve with this message corresponding response conversational list after, this message was further comprised before client port sends: the source IP address that network forwarding equipment detects this message is real IP address, the then real IP address of preserving according to self and the corresponding relation of virtual IP address replace with virtual IP address with the actual source IP address of this message.
Described network forwarding equipment is preserved the corresponding relation of application type sign and application characteristic sign, and the regular expression of preserving each application characteristic sign comprises: whether positional information and this application characteristic sign that application characteristic is identified in the message cross over the information that message is preserved;
Described network forwarding equipment determines that the application type of message comprises: network forwarding equipment is according to the regular expression of each application characteristic sign, determine the application characteristic sign that message carries, according to the corresponding relation of application type sign, determine the application type sign of message correspondence then with the application characteristic sign.
Described server identification is the Virtual Local Area Network sign of server, or is medium access control (MAC) address information of server.
A kind of network forwarding equipment has the application port that is connected with the server of distinguishing with application type, comprising: forward processing unit and application traffic processing unit, wherein:
Forward processing unit receives that client sends message, and this message is sent to the application traffic processing unit, and the server identification in the message that returns according to the application traffic processing unit, and the application port of this message from self sent;
The application traffic processing unit, be used to receive the message that forward processing unit is sent from client, if detect and self preserve and this message corresponding response conversational list, the server identification in this response session table is carried in this message sends to forward processing unit; Otherwise, determine the sign of the server that this message should mail to according to the application characteristic information of this message, this server identification is carried in this message sends to forward processing unit.
Compared with prior art, the present invention has the server of different application function by design, and the application port that configuration is connected with all kinds of servers on network forwarding equipment, after network forwarding equipment is received the message that client sends, self do not preserve the message corresponding response conversational list that forward processing unit is sent if detect from client, then the application characteristic information according to this message sends the application port of this message from correspondence, make networking more flexible, and can be according to the practical application functional requirement of networking, the server of different application type is connected with network forwarding equipment, has reduced the design cost of networking; And when the capacity of a certain application function in network can not be met consumers' demand, only needing increased the server with this application function again, and the application port that configuration links to each other with this server on network forwarding equipment gets final product, and had reduced the equipment cost of dilatation.
Embodiment
Among the present invention, when design server, difference according to application type, design different servers promptly: different servers has different application functions, thereby server can be divided into different application types according to the difference of the application function that is had, as: file transfer protocol (FTP) (FTP) server, internet remote login service agreement (Telnet) server, ip voice (VOIP) server etc., the server of different application type can corresponding different applying virtual local area network (LAN) (VLAN), can comprise a plurality of VLANs with a kind of applying virtual local area network (LAN); Simultaneously, the port that network forwarding equipment is linked to each other with server, difference according to the application type of server is divided into different application ports, for example: port one~3 are divided into the port that is connected with ftp server, and port one links to each other with ftp server 1 with 2 simultaneously, and port 3 links to each other with ftp server 2, then port one and 2 can be called ftp VLAN1 port, port 3 is called ftp VLAN2 port; Port 4~7 is divided into the port that links to each other with the telnet server, and port 4 links to each other with telnet server 1 with 5 simultaneously, and port 6 links to each other with telnet server 2 with 7 simultaneously, then port 4 and 5 is called telnet VLAN1 port, port 6 and 7 is called the telnetVLAN2 port.
The present invention is further described in more detail below in conjunction with drawings and the specific embodiments.
Fig. 1 is the composition schematic diagram of data forwarding system provided by the invention, and as shown in Figure 1, it mainly comprises: control unit 11, forward processing unit 12 and application traffic processing unit 13.Wherein, forward processing unit 12 and application traffic processing unit 13 are arranged in network forwarding equipment as switch, and control unit 11 can be arranged in network forwarding equipment, also can be independent of outside the network forwarding equipment, and the concrete function of each unit is as follows:
Control unit 11: be used for the physical port of network forwarding equipment is divided into: be used for client port that is connected with client and the application port that is used for linking to each other with the server of each application type, and network forwarding equipment carried out port arrangement, configuration information is sent to forward processing unit 12 and application traffic processing unit 13; Port is handled in the application traffic that configuration links to each other with application traffic processing unit 13 on the forward processing unit 12 of network forwarding equipment simultaneously, and configuration information is sent to forward processing unit 12 and application traffic processing unit 13.
With the switch is example, division to the physical port of 11 pairs of switches of control unit describes, as shown in Figure 2, have physical port Eth0~12 if carry out two layers of application-specific integrated circuit (ASIC) (ASIC) chip of message forwarding processing in the switch, control unit 11 is divided the physical port of two layers of asic chip of switch as follows: Eth0~3 are the client-side vlan port, vlan port is handled for application traffic in Eth4~7, and Eth8~12 are for using vlan port; More specifically, Eth0~1 is the port of client-side vlan 1, and Eth2~3 are the port of client-side vlan 2, and Eth8~10 are for using the port of VLAN5, and Eth11~12 are for using the port of VLAN6.Wherein, application traffic is handled inside vlan port that vlan port is configured to switch as the VLAN4093 port, and control unit 11 is relaying (TRUNK) pattern with the attribute configuration of application traffic processing unit 13.
Forward processing unit 12: according to the configuration information that control unit 11 is sent to the physical port of self place network forwarding equipment, the corresponding relation that record port numbers and client-side vlan sign, port numbers and application VLAN identify; After receiving message from the client-side vlan port, this message is carried this client-side vlan sign send to application traffic processing unit 13, and after receiving the message that application traffic processing unit 13 returns, the application VLAN sign of the server that carries according to this message, self finding outgoing interface information, the application port of this message from this outgoing interface information points sent.
Further, forward processing unit 12 is used for, after receiving message from application port, this message is sent to application traffic processing unit 13, and the client-side vlan that carries in the message that returns according to application traffic processing unit 13 sign, determine the outgoing interface information of message, the client port of this message from this outgoing interface information points sent.
Application traffic processing unit 13: be used for after receiving that forward processing unit 12 is transmitted the next message from client, judge the corresponding response conversational lists of self whether preserving with this message such as purpose IP address, destination slogan, source IP address, source port number and protocol information, if, the client-side vlan of replacing in the message with the sign of the application VLAN in this response session table identifies, and this message is sent to forward processing unit 12; Otherwise, the application characteristic that carries according to this message identifies, in the corresponding relation that application characteristic sign of self preserving and application type identify, find corresponding application type sign, then according to the conversational list and the predefined load balancing principle of this message, in that self preserve and application VLAN this application type sign corresponding server, select one to use VLAN, identify with this client-side vlan of using in the VLAN sign replacement message, and preserve the client-side vlan sign and use the corresponding relation that VLAN identifies, and foundation comprises the source IP address of this message, source port number, purpose IP address, the destination slogan, the client-side vlan sign, the application VLAN sign of server, the response session table of protocol information etc. sends to forward processing unit 12 with this message then.
Further, application traffic processing unit 13 is further used for, preserve the virtual IP address of each server and the corresponding relation of real IP address, after receiving that forward processing unit 12 is transmitted the next message from client, if detecting the purpose IP address that this message carries is virtual IP address, then, replace the empty purpose IP address of message with the real IP address that finds in the real IP address of self searching this virtual IP address correspondence.
Virtual IP address refers to the domain name addresses of application server, as: www.sohu.com.
Network forwarding equipment may link to each other with the more than one server that belongs to certain application type, for example: network forwarding equipment may link to each other with more than one Ftp server simultaneously, at this moment, application traffic processing unit 13 is preserved the corresponding relation of the application VLAN sign of Ftp application type sign and each Ftp server, further can preserve the real IP address of each Ftp server and the corresponding relation of virtual IP address.
Application traffic processing unit 13 is further used for, after receiving the message that forward processing unit 12 is sent from server, at the corresponding response conversational lists of self searching with this message such as purpose IP address, destination slogan, source IP address, source port number and protocol information, if find, then the application VLAN according to the server in this response session table identifies the corresponding relation that identifies with client-side vlan, application VLAN in this message sign is replaced with the client-side vlan sign, then this message is sent to forward processing unit 12.
Further, application traffic processing unit 13 is used for, preserve the virtual IP address of application server and the corresponding relation of real IP address, after receiving that forward processing unit 12 is transmitted the next message from server, if detecting the source IP address that this message carries is real IP address, then, replace the actual source IP address of message with the virtual IP address that finds at the virtual IP address of self searching this reality IP address correspondence.
Further, as shown in Figure 1, application traffic processing unit 13 comprises: load balance process unit 131 and contents searching unit 132, wherein:
Load balance process unit 131: be used to receive the message that forward processing unit 12 is sent from client, judge the corresponding response conversational lists of self whether preserving with this message such as purpose IP address, destination slogan, source IP address, source port number and protocol information, if, the client-side vlan of replacing in the message with the application VLAN sign of the server in this response session table identifies, and this message is sent to forward processing unit 12; Otherwise, this message is transmitted to contents searching unit 132, after receiving the application type sign that contents searching unit 131 is sent, according to the conversational list of the message of sending from forward processing unit 12 and the load balancing principle of self preserving, in the application VLAN corresponding, select one to use VLAN with this application type sign, identify with this client-side vlan of using in this message of VLAN sign replacement, this message is sent to forward processing unit 12, and foundation simultaneously comprises: the source IP address of message, source port number, purpose IP address, the destination slogan, the client-side vlan sign, the application VLAN sign of server, the response session table of protocol information etc.
Further, load balance process unit 131 is used for, preserve the virtual IP address of server and the corresponding relation of real IP address, after receiving that forward processing unit 12 is transmitted the next message from client, if detecting the purpose IP address that this message carries is virtual IP address, then, replace the empty purpose IP address of message with the real IP address that finds in the real IP address of self searching this virtual IP address correspondence.
Load balance process unit 131 is further used for, after receiving the message that forward processing unit 12 is sent from server, self searching and corresponding response conversational lists such as the application VLAN sign of the purpose IP address of this message, destination slogan, source IP address, source port number, server, protocol information, if find, then according to sign of the application VLAN in the response session table of self preserving and client-side vlan sign, application VLAN in message sign is replaced with the client-side vlan sign, then this message is sent to forward processing unit 12.
Further, load balance process unit 131 is used for, preserve the virtual IP address of server and the corresponding relation of real IP address, after receiving that forward processing unit 12 is transmitted the next message from server, if detecting the source IP address that this message carries is real IP address, then, replace the actual source IP address of message with the virtual IP address that finds at the virtual IP address of self searching this reality IP address correspondence.
Contents searching unit 132: the corresponding relation that is used to preserve application characteristic sign and application type sign, after receiving the message that load balance process unit 131 is sent, self finding the corresponding application type sign of application characteristic sign that this message carries, this application type sign is sent to load balance process unit 131.
Among the present invention, can be connected by peripheral component interconnect standard interface (PCI) bus between control unit 11 and the forward processing unit 12, can be connected by local buss such as PCI-X or PCI-E between load balance process unit 131 and the contents searching unit 132, be connected by gigabit Attachment Unit Interface (XAUI) bus between load balance process unit 131 and the forward processing unit 12.Usually, more than one gigabit XAUI bus port just can form an application traffic and handle VLAN.
As can be seen: because the server among the present invention is distinguished with application type, therefore, can design server in advance with different application function, when networking, only need according to the required application function that has of this network, on network forwarding equipment, dispose each application port, get final product with server connection with corresponding application function.When the capacity of the server with certain application function can't satisfy the customer service demand, only needing increased the application port that is connected with such server on network forwarding equipment, and the corresponding server with this application function that increases gets final product.
Fig. 3 is in data forwarding system provided by the invention, the flow chart of the specific embodiment that the message that client is sent is handled, and as shown in Figure 3, its concrete steps are as follows:
Step 301: network forwarding equipment receives message from the client port of self.
Step 302: network forwarding equipment judges whether this message needs to carry out the IP reorganization, if, execution in step 303; Otherwise, execution in step 304.
Step 303: network forwarding equipment carries out the IP reorganization to message.
Step 304: network forwarding equipment judges whether message exists the out of order phenomenon of transmission control protocol (TCP), if, execution in step 305; Otherwise, execution in step 306.
Step 305: network forwarding equipment carries out the out of order adjustment of TCP to this message.
Step 306: the message that the forward processing unit of network forwarding equipment will carry the client-side vlan sign of the port that receives this message sends to the load balance process unit.
Step 307: after this message is received in the load balance process unit, judge the corresponding response conversational lists of self whether preserving with this message such as purpose IP address, destination slogan, source IP address, source port number and protocol information, if, execution in step 308; Otherwise, execution in step 309.
Step 308: the client-side vlan that the load balance process unit is replaced in the message with the sign of the application VLAN in this response session table identifies, and goes to step 317.
This step further comprises, it is virtual IP address that the load balance process unit detects the purpose IP address that this message carries, the then virtual IP address of the application VLAN that preserves according to self and the corresponding relation of real IP address, the empty purpose IP address of replacing this message with the real IP address of this application VLAN of self preservation.
Step 309: the load balance process unit is transmitted to contents searching unit with this message.
Step 310: contents searching unit is searched the corresponding application type sign of application characteristic sign that this message carries in the corresponding relation that application characteristic sign of self preserving and application type identify.
What the application characteristic sign characterized is the application characteristic information of message, application characteristic information refers to the information of the application characteristic that can characterize message, for example: ftp information, telnet information, voip information etc., application characteristic information is carried in the message with the form of application characteristic sign, different application characteristic signs may be carried in the different field of message, and the application characteristic sign that is used for characterizing with a kind of application characteristic may be dispersed in different messages.Therefore, contents searching unit must be preserved the corresponding relation of application type sign and application characteristic sign, and the regular expression of preserving each application characteristic sign comprises: whether positional information and this application characteristic sign that application characteristic is identified in the message cross over the information that message is preserved.After contents searching unit is received message, at first according to the regular expression of each application characteristic sign, determine the application characteristic sign that message carries,, determine the application type sign of message correspondence then according to the corresponding relation of application type sign with the application characteristic sign.
Step 311: contents searching unit judges whether to find the application type sign, if, execution in step 313; Otherwise, execution in step 312.
Step 312: contents searching unit is returned to the load balance process unit and is searched the failure indication, after the load balance process unit receives that this searches failure indication, return the dropping packets indication to forward processing unit, and log information, after forward processing unit is received this indication, abandon this message, this flow process finishes.
Step 313: contents searching unit is returned the application type sign of this message correspondence to the load balance process unit.
Step 314: the load balance process unit comprises according to the conversational list that this message carries: source IP address, source port number, destination slogan, purpose IP address and protocol information etc. and predefined load balancing principle, and in the application VLAN corresponding, select one to use VLAN with the application type sign.
Step 315: the client-side vlan that the load balance process unit is replaced in the message with this selected application VLAN sign identifies.
This step further comprises, if it is virtual IP address that the load balance process unit detects the purpose IP address that this message carries, the then virtual IP address of the application VLAN that preserves according to self and the corresponding relation of real IP address, the empty purpose IP address of replacing this message with the real IP address of this application VLAN of self preservation.
Step 316: the response session table of the application VLAN sign, protocol information of the source IP address comprise this message, source port number, purpose IP address, destination slogan, client-side vlan sign, server etc. is created in the load balance process unit.
Step 317: the load balance process unit sends to forward processing unit with message.
Step 318: after forward processing unit was received message, the application VLAN sign of carrying according to this message found outgoing interface information, and the application port of this message from this outgoing interface information points sent.
Fig. 4 is in data forwarding system provided by the invention, the flow chart of the specific embodiment that the message that server is sent is handled, and as shown in Figure 4, its concrete steps are as follows:
Step 401: network forwarding equipment receives message from server from self application vlan port.
Step 402: the forward processing unit of network forwarding equipment carries the message of using the VLAN sign with this and is transmitted to the load balance process unit.
Step 403: whether load balance process unit judges self has been preserved the source IP address that carries with this message, source port number, purpose IP address, destination slogan, has been used corresponding response conversational lists such as VLAN sign, protocol information, if, execution in step 405; Otherwise, execution in step 404.
Step 404: the load balance process unit returns the dropping packets indication to forward processing unit, and log information, after forward processing unit is received this indication, abandons this message, and this flow process finishes.
Step 405: the load balance process unit identifies with using VLAN according to the sign of the client-side vlan in the response session table of self preserving, and the application VLAN sign that this message is carried replaces with clients corresponding VLAN sign.
This step further comprises: it is real IP address that the load balance process unit detects the source IP address that this message carries, and then according to the virtual IP address of self preserving and the corresponding relation of real IP address, the actual source IP address transition of this message is become virtual source IP address.
Virtual IP address can corresponding real IP address, also can be corresponding real IP address more than.
Step 406: the load balance process unit sends to forward processing unit with this message.
Step 407: after forward processing unit was received this message, the client-side vlan sign of carrying according to this message found outgoing interface information, and the client port of this message from this outgoing interface information points sent.
In above embodiment, each server identifies with VLAN and distinguishes, and in actual applications, also can be directly waits with the mac address information of server and distinguishes.
The above only is process of the present invention and method embodiment, in order to restriction the present invention, all any modifications of being made within the spirit and principles in the present invention, is not equal to replacement, improvement etc., all should be included within protection scope of the present invention.