Summary of the invention
The technical problem to be solved in the present invention provides a kind of data processing method and device, to discharge address translation feature from the main control module of Gateway Network Element, to alleviate the burden of main control module.
In order to solve the problems of the technologies described above, the invention provides a kind of data processing method, comprising:
After gateway module in the Gateway Network Element receives the data message of appointment, described data message is carried out address transition process;
Data message after processing is sent to main control module or Network Management Equipment in the described Gateway Network Element.
Further, said method also has following characteristics: described gateway module carries out the address transition processing and comprises:
Described gateway module is revised as the MAC Address of described gateway module with the address, source media access control (MAC) in the data message of described appointment, and the data message of described appointment sends to described main control module after then will revising;
After described gateway module receives the response message that described main control module returns, source MAC in the described response message is revised as the MAC Address of described gateway module, target MAC (Media Access Control) address in the described response message is revised as the MAC Address of described Network Management Equipment, then described response message is sent to described Network Management Equipment;
The data message of described appointment comprises: arp request message, transmission control protocol message or the User Datagram Protocol message of described Network Management Equipment broadcasting.
Further, said method also has following characteristics: also comprise:
After described main control module receives instruction, send configuration information to described gateway module;
After described gateway module receives the configuration information of described main control module, be configured according to described configuration information.
Further, said method also has following characteristics: the described address transition of carrying out is processed and to be comprised:
The network address forwarding rule list that described gateway module search prestores mates, if without occurrence, then described data message is carried out the MAC Address conversion; If occurrence is arranged, then according to described occurrence described data message is carried out network address translation and MAC Address conversion.
Further, said method also has following characteristics: the described address transition of carrying out is processed and also to be comprised:
Described data message is carried out the virtual local area network tags conversion.
In order to address the above problem, the present invention also provides a kind of Gateway Network Element, comprising: gateway module and main control module, and wherein, described gateway module comprises:
Exchange chip is used for receiving the data message of appointment, and the data message of described appointment is sent to processing unit; Be used for the data message after the described processing unit processes is sent to described main control module or Network Management Equipment;
Described processing unit is used for the data message of described appointment is carried out the address transition processing, and the data message after processing is sent to described exchange chip.
Further, above-mentioned Gateway Network Element also has following characteristics:
Described processing unit, then the concrete MAC Address that is used for the address, source media access control (MAC) of the data message of described appointment is revised as described gateway module sends to described exchange chip with amended described data message; After receiving the response message that described exchange chip sends, source MAC in the described response message is revised as the MAC Address of described gateway module, target MAC (Media Access Control) address in the described response message is revised as the MAC Address of described Network Management Equipment, then amended described response message is sent to described exchange chip;
Described exchange chip, concrete being used for sends to described main control module with described data message; After receiving the response message that described main control module returns, described response message is sent to described processing unit; The amended described response message of described processing unit is sent to described Network Management Equipment;
Described main control module after being used for data message to described appointment and carrying out dissection process, returns response message to described exchange chip;
The data message of described appointment comprises: arp request message, transmission control protocol message or the User Datagram Protocol message of described Network Management Equipment broadcasting.
Further, above-mentioned Gateway Network Element also has following characteristics: described gateway module also comprises configuration module,
Described main control module also is used for sending configuration information to described configuration module;
Described configuration module after being used for receiving described configuration information, is configured according to described configuration information.
Further, above-mentioned Gateway Network Element also has following characteristics:
Described processing unit, the data message of described appointment is carried out address transition process and comprise: the network address that search prestores is transmitted rule list and is mated, if without occurrence, then described data message is carried out the MAC Address conversion; If occurrence is arranged, then according to described occurrence described data message is carried out network address translation and MAC Address conversion.
Further, above-mentioned Gateway Network Element also has following characteristics:
Described processing unit carries out address transition to the data message of described appointment and processes and also comprise: described data message is carried out the virtual local area network tags conversion.
To sum up, the invention provides a kind of data processing method and Gateway Network Element, it mainly is the address transition that realizes data message with two layers of chip at link layer, this method is faster, more stable with respect to the method speed of using three layers of routing forwarding to realize, and is more economical, more flexible with respect to hard-wired method.
Embodiment
For making the purpose, technical solutions and advantages of the present invention clearer, hereinafter in connection with accompanying drawing embodiments of the invention are elaborated.Need to prove that in the situation of not conflicting, the embodiment among the application and the feature among the embodiment be combination in any mutually.
Fig. 2 is the schematic diagram of the communication system of the embodiment of the invention, as shown in Figure 2, the Gateway Network Element of present embodiment comprises gateway module and main control module, gateway module in the Gateway Network Element is present between the data channel of non-gateway network element and webmaster, and the data message between webmaster and the non-network element is carried out the NAT conversion.
As shown in Figure 3, the gateway module of the Gateway Network Element of present embodiment comprises exchange chip and processing unit, described processing unit can be realized VLAN (Virtual Local Area Network, VLAN) conversion, MAC (media access control) address transition (ARP (address resolution protocol) Cheating Technology), transmitting-receiving bag drive winding, are to utilize two layers of chip to realize the key technology of gateway module.
Wherein, exchange chip is used for receiving the data message of appointment, and the data message of described appointment is sent to processing unit; Be used for the data message after the described processing unit processes is sent to described main control module or Network Management Equipment;
Described processing unit is used for the data message of described appointment is carried out the address transition processing, and the data message after processing is sent to described exchange chip.
If the data message of described appointment is the arp request message of described Network Management Equipment broadcasting,
Described processing unit, then the concrete MAC Address that is used for the address, source media access control (MAC) of the data message of described appointment is revised as described gateway module sends to described exchange chip with amended described data message; After receiving the response message that described exchange chip sends, source MAC in the described response message is revised as the MAC Address of described gateway module, target MAC (Media Access Control) address in the described response message is revised as the MAC Address of described Network Management Equipment, then amended described response message is sent to described exchange chip;
Described exchange chip, concrete being used for sends to described main control module with described data message; After receiving the response message that described main control module returns, described response message is sent to described processing unit; The amended described response message of described processing unit is sent to described Network Management Equipment;
Described main control module after described data message is carried out dissection process, returns response message to described exchange chip.
The data message of described appointment includes but not limited to: arp request (ARP request) message, transmission control protocol (TCP) message or User Datagram Protocol (UDP) message of described Network Management Equipment broadcasting.
In the present embodiment, described gateway module can also comprise configuration module,
Described main control module also is used for sending configuration information to described configuration module;
Described configuration module after being used for receiving described configuration information, is configured according to described configuration information.As gateway module software and hardware function and NAT transformation rule etc. are set.
Wherein, described processing unit, the data message of described appointment is carried out address transition process and comprise: the network address that search prestores is transmitted rule list and is mated, if without occurrence, then described data message is carried out the MAC Address conversion; If occurrence is arranged, then according to described occurrence described data message is carried out NAT and MAC Address conversion.
Such as the NAT module among Fig. 3, it is the nucleus module that gateway module carries out network address translation, be responsible for carrying out network address translation from the outer net receive data according to the NAT transformation rule and send to the internal network, the data based NAT transformation rule that Intranet is sent carries out network address translation and sends in the external network.
Described processing unit, the data message of described appointment is carried out address transition to be processed and can also comprise: described data message is carried out the virtual local area network tags conversion, to realize that the message that receives from VLAN A sends to VLAN B, the message that receives from VLAN B sends to VLAN A, can shield internal network and external network.
Comprise in the NAT rule list: equipment serial number, purpose IP address, port sequence number, destination slogan.For example, among Fig. 6, after gateway module receives data, from destination interface 20480, calculate equipment serial number and port sequence number, search the NAT rule list according to equipment serial number, find out purpose IP address and destination slogan, finish the NAT conversion according to the content of searching.
Fig. 4 is the flow chart of the data processing method of the embodiment of the invention, and as shown in Figure 4, the method for present embodiment comprises following step:
After gateway module in S01, the Gateway Network Element receives the data message of appointment, described data message is carried out address transition process;
S02, the data message after will processing send to main control module or Network Management Equipment in the described Gateway Network Element.
The below is the flow chart of data processing that the present invention one uses example, comprises the steps:
Step 11, outer net equipment (such as webmaster PC) send Arp request message to Gateway Network Element, carry out MAC Address conversion and VLAN conversion behind gateway module (can be that the network interface card drives) receive data, send from same network interface card by transmitting-receiving bag winding, send to main control module.
Step 12, main control module receive the Arp request message after the conversion, and send Arp reply message to gateway module according to source MAC.
After step 13, gateway module receive Arp reply message, in network interface card drives, carry out MAC Address conversion and VLAN conversion, send from same network interface card by transmitting-receiving bag winding, send to webmaster PC.
Step 14, webmaster PC receive Arp reply message, obtain the MAC Address of this gateway module.
Step 15, webmaster PC arrange the NAT transformation rule in gateway module, send the data of specifying tcp port according to rule and arrive gateway module.
Step 16, gateway module network interface card carry out MAC Address conversion, VLAN conversion, NAT conversion after driving the message that receives specific data, send from same network interface card by transmitting-receiving bag winding.
This specific data includes but not limited to, some well-known port data of TCP are supported dynamic port simultaneously; Some well-known port data of UDP are supported dynamic port simultaneously, i.e. data between webmaster or other management maintenance software and the equipment, and remainder data does not carry out the NAT conversion.
Step 17, main control module receive after the data non-gateway network element that sends to this network element according to destination address or be forwarded to lower extension by DCN.
Main control module receives the data that webmaster sends, and carries out command analysis, configuration data etc.; Other software such as TELNET/FTP software then carry out respective handling.
Step 18, purpose network element receive data, and the application program answer data message of finishing dealing with sends to main control module, and main control module sends this data message to gateway module.
Step 19, gateway module network interface card carry out MAC Address conversion, VLAN conversion, NAT conversion after driving and receiving data, send from same network interface card by transmitting-receiving bag winding.
Step 20, outer net equipment receive data and finish dealing with and one take turns data communication.
The below is take Gateway Network Element communication and non-gateway network element communication as example, be described in further detail of the present invention by reference to the accompanying drawings, the supposition Network Management Equipment has got access to the MAC Address of gateway module among the embodiment, embodiment 1 describes the data flow that webmaster and Gateway Network Element equipment carry out communication, and embodiment 2 describes the data flow that webmaster and non-gateway network element equipment carry out communication:
Embodiment 1, as shown in Figure 5:
Step 101, webmaster (IP address: 10.1.1.1) send the ARP Receive message to the MAC Address (00:0D:0D:10:10:03) of gateway module (10.1.1.2).
Step 102, webmaster send the TCP message to gateway module;
Destination address is 10.1.1.2, and the purpose tcp port is 8050, and source MAC is (00:13:46:90:82:64), and target MAC (Media Access Control) address is (00:0D:0D:10:10:03).
After step 103, gateway module receive data (VLAN 2), search NAT rule list, the coupling transformation rule, as look into without the rule of mating, changing target MAC (Media Access Control) address through MAC Address is (00:D0:D0:10:10:01), source MAC extends this as (00:0D:0D:10:10:03), is converted to VLAN 3 data messages through VLAN, sends to main control module by transmitting-receiving bag winding.
Comprise in the NAT rule list: equipment serial number, purpose IP address, port sequence number, destination slogan etc., gateway module obtains equipment serial number and port sequence number according to the destination interface that sends to gateway module, and search NAT rule list obtains purpose IP address and destination slogan.If search illustrates then that less than occurrence the message destination belongs to this network element or other messages, all sends to this network element main control module and processes.
After step 104, main control module application program are processed, send response data to gateway module, source MAC is (00:D0:D0:10:10:01), and target MAC (Media Access Control) address is (00:0D:0D:10:10:03).
After step 105, gateway module drive and receive data (VLAN 3), search NAT transmits rule list, the coupling transformation rule, without this rule, changing target MAC (Media Access Control) address through MAC Address is (00:13:46:90:82:64), source MAC extends this as (00:0D:0D:10:10:03), is converted to VLAN 2 data messages through VLAN, sends to Network Management Equipment by transmitting-receiving bag winding.
Step 106, webmaster receive the data of gateway module transmission and process, and finish data communication one time.
Embodiment 2: as shown in Figure 6, comprise following step:
Step 201, webmaster (10.1.1.1) send the ARP Receive message to the MAC Address (00:0D:0D:10:10:03) of gateway module (10.1.1.2).
Step 202, webmaster send the TCP link building messages to gateway module;
Purpose IP address is (10.1.1.2), source IP address is (10.1.1.1), and the purpose tcp port is 20480, and source tcp port is 1126, source MAC is (00:13:46:90:82:64), and target MAC (Media Access Control) address is (00:0D:0D:10:10:03).
After step 203, gateway module receive data (VLAN 2), search NAT transmits rule list, the coupling transformation rule, carry out the NAT conversion, revising destination address is (2.2.2.2), and the purpose tcp port is 8050, changing target MAC (Media Access Control) address through MAC Address is (00:D0:D0:10:10:01), source MAC extends this as (00:0D:0D:10:10:03), is converted to VLAN 3 data messages through VLAN, sends to main control module by transmitting-receiving bag winding.
Step 204, main control module receive judges that destination address is miscellaneous equipment after the data, by DCN (Digital Communication Network, digital communication network) with this data retransmission to destination device.
After step 205, destination device main control module application program are processed, send response data to gateway module by DCN;
Source MAC is (00:D0:D0:10:10:01), and target MAC (Media Access Control) address is (00:0D:0D:10:10:03), and source address is (2.2.2.2), and destination address is (10.1.1.1), and the purpose tcp port is 1126, and source tcp port is 8050.
After step 206, gateway module receive data (VLAN 3), search NAT transmits rule list, the coupling transformation rule, carry out the NAT conversion, revising destination address is (10.1.1.1), source IP address is (10.1.1.2), the purpose tcp port is 1126, source tcp port is 20480, changing target MAC (Media Access Control) address through MAC Address is (00:13:46:90:82:64), source MAC extends this as (00:0D:0D:10:10:03), is converted to VLAN 2 data messages through VLAN, sends to Network Management Equipment by transmitting-receiving bag winding.
Step 207, webmaster receive data and process, and finish data communication one time.
One of ordinary skill in the art will appreciate that all or part of step in the said method can come the instruction related hardware to finish by program, described program can be stored in the computer-readable recording medium, such as read-only memory, disk or CD etc.Alternatively, all or part of step of above-described embodiment also can realize with one or more integrated circuits.Correspondingly, each the module/unit in above-described embodiment can adopt the form of hardware to realize, also can adopt the form of software function module to realize.The present invention is not restricted to the combination of the hardware and software of any particular form.
Below only be the preferred embodiments of the present invention; certainly; the present invention also can have other various embodiments; in the situation that does not deviate from spirit of the present invention and essence thereof; those of ordinary skill in the art work as can make according to the present invention various corresponding changes and distortion, but these corresponding changes and distortion all should belong to the protection range of the appended claim of the present invention.