A kind of data processing method and Gateway Network Element
Technical field
The present invention relates to the communications field, especially relate to a kind of data processing method and Gateway Network Element.
Background technology
Network address translation (Network Address Translation is called for short NAT) is a kind of at IP
Source IP address and TCP (Transmission Control is rewritten when packet is by router or fire wall
Protocol, transmission control protocol) technology of port, such as Fig. 1.One local network use one is proprietary
The appointment subnet (such as 157.155.x.x) of network, in subnet, one of them routing device occupies this net
One proprietary address (such as 157.155.1.1) of network address space, the most also occupies a publicly-owned IP
The address (such as 10.x.x.x) of address or other proprietary network.When data from present networks to global network or
During other network delivery, source address and the port of data are converted by this routing device, when data are returned
Hui Shi, distinguishes the conversion carrying out source address and port by port.
NAT technology typically realizes in route or firewall box, carries out turning by ICP/IP protocol stack
Change the way of escape by forwarding, in prior art, by realizing NAT on WMG, so that media
Global network can be mail to the IP message of private network and carry out routing forwarding by gateway, and all messages of the program need
Processing through ICP/IP protocol stack, add handling process, the program need to realize at main control module simultaneously,
Increase the weight of main control module CPU burden, affect remaining task of main control module and process;Also there is use hardware technology real
Existing method, as a kind of directly at FPGA (Field Programmable Gate Array, scene in provided
Programmable gate array)/CPLD (Complex Programmable Logic Device, patrol by complex programmable
Collect device), ASIC (Application Specific Intergrated Circuits, special IC)
Deng the method for network address translation realized on hardware foundation, the program increases hardware cost, uses hardware side
Case realizes being not easy to maintenance process and what's new and carrying out configuration interactive with main control module.
Summary of the invention
The technical problem to be solved in the present invention is to provide a kind of data processing method and device, with from gateway net
The main control module of unit discharges address translation feature, to alleviate the burden of main control module.
In order to solve above-mentioned technical problem, the invention provides a kind of data processing method, in Gateway Network Element
Gateway module be arranged between non-gateway network element and the data channel of Network Management Equipment, including:
After gateway module in Gateway Network Element receives the data message specified, described data message is carried out
Address conversion process;
Data message after processing is sent to the main control module in described Gateway Network Element or Network Management Equipment;
Described gateway module carries out address conversion process and includes:
Described gateway module is by source medium education (MAC) address in the described data message specified
It is revised as the MAC Address of described gateway module, then the data message specified described after amendment is sent
To described main control module;
After described gateway module receives the response message that described main control module returns, by described response message
In source MAC be revised as the MAC Address of described gateway module, by described response message
Target MAC (Media Access Control) address is revised as the MAC Address of described Network Management Equipment, is then sent out by described response message
Give described Network Management Equipment.
Further, said method also has a following feature:
The described data message specified includes: described Network Management Equipment broadcast arp request message,
Transmission control protocol message or User Datagram Protocol message.
Further, said method also has following feature: also include:
After described main control module receives instruction, send configuration information to described gateway module;
After described gateway module receives the configuration information of described main control module, enter according to described configuration information
Row configuration.
Further, said method also has a following feature: described in carry out address conversion process and include:
The network address that the search of described gateway module prestores forwards rule list to mate, if without occurrence,
Then described data message is carried out MAC Address conversion;If there being occurrence, then according to described occurrence pair
Described data message carries out network address translation and MAC Address conversion.
Further, said method also has a following feature: described in carry out address conversion process and also include:
Described data message is carried out virtual local area network tags conversion.
In order to solve the problems referred to above, present invention also offers a kind of Gateway Network Element, including: gateway module and
Main control module, wherein, described gateway module be arranged at non-gateway network element and Network Management Equipment data channel it
Between, described gateway module includes:
Exchange chip, for receiving the data message specified, is sent to the described data message specified
Processing unit;For the data message after described processing unit processes is sent to described main control module or net
Tube apparatus;
Described processing unit, for the described data message specified carries out address conversion process, will process
After data message be sent to described exchange chip;
Described processing unit, specifically for by the source medium education in the described data message specified
(MAC) MAC Address of described gateway module is revised as in address, then by amended described data
Message is sent to described exchange chip;After receiving the response message that described exchange chip is sent, by described
Source MAC in response message is revised as the MAC Address of described gateway module, by described response
Target MAC (Media Access Control) address in message is revised as the MAC Address of described Network Management Equipment, after then revising
Described response message be sent to described exchange chip.
Further, above-mentioned Gateway Network Element also has a following feature:
Described exchange chip, specifically for being sent to described main control module by described data message;Receive
After the response message that described main control module returns, described response message is sent to described processing unit;Will
The amended described response message of described processing unit is sent to described Network Management Equipment;
Described main control module, after the described data message specified is carried out dissection process, to described friendship
Change chip and return response message;
The described data message specified includes: described Network Management Equipment broadcast arp request message,
Transmission control protocol message or User Datagram Protocol message.
Further, above-mentioned Gateway Network Element also has following feature: described gateway module also includes configuring mould
Block,
Described main control module, is additionally operable to send configuration information to described configuration module;
Described configuration module, after being used for receiving described configuration information, joins according to described configuration information
Put.
Further, above-mentioned Gateway Network Element also has a following feature:
Described processing unit, carries out address conversion process to the described data message specified and includes: search is pre-
The network address deposited forwards rule list to mate, if without occurrence, then carries out described data message
MAC Address is changed;If there being occurrence, then according to described occurrence, described data message is carried out network
Address conversion and MAC Address are changed.
Further, above-mentioned Gateway Network Element also has a following feature:
Described processing unit, carries out address conversion process to the described data message specified and also includes: to institute
State data message and carry out virtual local area network tags conversion.
To sum up, the present invention provides a kind of data processing method and Gateway Network Element, mainly uses two layers of chip
Realize the address conversion of data message at link layer, this method is real relative to using three-layer routing to forward
Existing method speed faster, more stable, more economical relative to hard-wired method, more flexible.
Accompanying drawing explanation
Fig. 1 is general NAT technical schematic diagram;
Fig. 2 is the schematic diagram of the communication system of the embodiment of the present invention;
Fig. 3 is the schematic diagram of the Gateway Network Element of the embodiment of the present invention;
Fig. 4 is the flow chart of the data processing method of the embodiment of the present invention;
Fig. 5 is the flow chart of the data processing method of the embodiment of the present invention one;
Fig. 6 is the flow chart of the data processing method of the embodiment of the present invention two.
Detailed description of the invention
For making the object, technical solutions and advantages of the present invention clearer, below in conjunction with accompanying drawing
Embodiments of the invention are described in detail.It should be noted that in the case of not conflicting, this Shen
Embodiment in please and the feature in embodiment can mutual combination in any.
Fig. 2 is the schematic diagram of the communication system of the embodiment of the present invention, as in figure 2 it is shown, the net of the present embodiment
Closing network element and include gateway module and main control module, the gateway module in Gateway Network Element is present in non-gateway network element
And between the data channel of webmaster, the data message between webmaster and non-network element is carried out NAT conversion.
As it is shown on figure 3, the gateway module of the Gateway Network Element of the present embodiment includes exchange chip and processing unit,
Described processing unit is capable of VLAN (Virtual Local Area Network, VLAN) and turns
Change, MAC (medium education) address conversion (ARP (address resolution protocol) Cheating Technology),
Transmitting-receiving Packet driven winding, is the key technology utilizing two layers of chip to realize gateway module.
Wherein, exchange chip, for receiving the data message specified, by the described data message specified
It is sent to processing unit;For the data message after described processing unit processes is sent to described master control mould
Block or Network Management Equipment;
Described processing unit, for the described data message specified carries out address conversion process, will process
After data message be sent to described exchange chip.
If the described arp request message that data message is the broadcast of described Network Management Equipment specified,
Described processing unit, specifically for by the source medium education in the described data message specified
(MAC) MAC Address of described gateway module is revised as in address, then by amended described data
Message is sent to described exchange chip;After receiving the response message that described exchange chip is sent, by described
Source MAC in response message is revised as the MAC Address of described gateway module, by described response
Target MAC (Media Access Control) address in message is revised as the MAC Address of described Network Management Equipment, after then revising
Described response message be sent to described exchange chip;
Described exchange chip, specifically for being sent to described main control module by described data message;Receive
After the response message that described main control module returns, described response message is sent to described processing unit;Will
The amended described response message of described processing unit is sent to described Network Management Equipment;
Described main control module, after described data message is carried out dissection process, to described exchange chip
Return response message.
The described data message specified includes but not limited to: the address resolution protocol of described Network Management Equipment broadcast
Request (ARP request) message, transmission control protocol (TCP) message or User Datagram Protocol (UDP)
Message.
In the present embodiment, described gateway module can also include configuring module,
Described main control module, is additionally operable to send configuration information to described configuration module;
Described configuration module, after being used for receiving described configuration information, joins according to described configuration information
Put.As arranged gateway module software and hardware function and NAT transformational rule etc..
Wherein, described processing unit, the described data message specified is carried out address conversion process and includes:
The network address that search prestores forwards rule list to mate, if without occurrence, then to described data message
Carry out MAC Address conversion;If there being occurrence, then according to described occurrence, described data message is carried out
NAT and MAC Address conversion.
Such as the NAT module in Fig. 3, it is the gateway module nucleus module that carries out network address translation, negative
Duty carries out network address translation from outer net reception data according to NAT transformational rule and is sent to internal network,
The data sending Intranet carry out network address translation according to NAT transformational rule and are sent in external network.
Described processing unit, the described data message specified is carried out address conversion process can also include:
Described data message is carried out virtual local area network tags conversion, the message received with realization from VLAN A
Being sent to VLAN B, the message received from VLAN B is sent to VLAN A, in can shielding
Portion's network and external network.
NAT rule list comprises: equipment serial number, purpose IP address, port sequence number, destination slogan.
Such as, in Fig. 6, after gateway module receives data, from destination interface 20480, calculate equipment sequence
Number and port sequence number, according to equipment serial number search NAT rule list, find out purpose IP address and purpose
Port numbers, completes NAT conversion according to the content searched.
Fig. 4 is the flow chart of the data processing method of the embodiment of the present invention, as shown in Figure 4, the present embodiment
Method include below step:
After gateway module in S21, Gateway Network Element receives the data message specified, to described datagram
Literary composition carries out address conversion process;
S22, will process after data message be sent to the main control module in described Gateway Network Element or webmaster sets
Standby.
The flow chart of data processing of the present invention one application example is presented herein below, comprises the steps:
Step 11, outer net equipment (such as webmaster PC) send Arp request message to Gateway Network Element, net
Close and after module (can be trawl performance) receives data, carry out MAC Address conversion and VLAN conversion,
Sent from same network interface card by transmitting-receiving bag winding, be sent to main control module.
Step 12, main control module receive the Arp request message after conversion, and according to source MAC ground
Location sends Arp reply message to gateway module.
After step 13, gateway module receive Arp reply message, trawl performance carries out MAC ground
Location conversion and VLAN change, and are sent from same network interface card by transmitting-receiving bag winding, are sent to webmaster
PC。
Step 14, webmaster PC receive Arp reply message, it is thus achieved that the MAC Address of this gateway module.
Step 15, webmaster PC arrange NAT transformational rule in gateway module, send according to rule and specify
The data of tcp port are to gateway module.
Step 16, gateway module trawl performance carry out MAC Address after receiving the message specifying data and turn
Change, VLAN changes, NAT conversion, is sent from same network interface card by transmitting-receiving bag winding.
These appointment data, include but not limited to, some well-known port data of TCP, support dynamic end simultaneously
Mouthful;Some well-known port data of UDP, support that dynamic port, i.e. webmaster or other management are safeguarded soft simultaneously
Data between part and equipment, remainder data does not carry out NAT conversion.
Step 17, main control module are sent to this network element according to destination address after receiving data or pass through DCN
It is forwarded to the non-gateway network element of lower extension.
Main control module receives the data that webmaster sends, and carries out command analysis, configuration data etc.;Other is soft
Part such as TELNET/FTP software, then carry out respective handling.
Step 18, purpose network element receive data, and application program has processed reply data message, sends
To main control module, main control module sends this data message to gateway module.
Step 19, gateway module trawl performance carry out MAC Address conversion, VLAN after receiving data
Conversion, NAT conversion, sent from same network interface card by transmitting-receiving bag winding.
Step 20, outer net equipment receive data to carry out process and completes one and take turns data communication.
Below as a example by Gateway Network Element communication and non-gateway network element communication, in conjunction with accompanying drawing, the work of the present invention is entered
The detailed description of one step, supposes in embodiment that Network Management Equipment has got the MAC Address of gateway module,
Embodiment 1 describes webmaster and Gateway Network Element equipment and carries out the data flow of communication, and embodiment 2 describes webmaster
With the data flow that non-gateway network element equipment carries out communication:
Embodiment 1, as shown in Figure 5:
Step 101, webmaster (IP address: 10.1.1.1) send ARP Receive message to gateway module
(10.1.1.2) MAC Address (00:0D:0D:10:10:03).
Step 102, webmaster send TCP message to gateway module;
Destination address is 10.1.1.2, and purpose tcp port is 8050, source MAC be (00:13:
46:90:82:64), target MAC (Media Access Control) address is (00:0D:0D:10:10:03).
After step 103, gateway module receive data (VLAN 2), search for NAT rule list,
Join transformational rule, as look into without coupling rule, through MAC Address conversion target MAC (Media Access Control) address be (00:
D0:D0:10:10:01), source MAC extends this as (00:0D:0D:10:10:03),
Be converted to VLAN 3 data message through VLAN, be sent to main control module by transmitting-receiving bag winding.
NAT rule list comprises: equipment serial number, purpose IP address, port sequence number, destination slogan
Deng, gateway module obtains equipment serial number and port sequence number according to the destination interface being sent to gateway module, searches
Rope NAT rule list obtains purpose IP address and destination slogan.If search is less than occurrence, then illustrate
Message destination belongs to this network element or other messages, is all sent to this network element main control module and processes.
After step 104, main control module application program process, send response data to gateway module,
Source MAC is (00:D0:D0:10:10:01), target MAC (Media Access Control) address be (00:0D:
0D:10:10:03).
Step 105, gateway module drive after receiving data (VLAN 3), and search NAT forwards rule
Then table, mate transformational rule, without this rule, through MAC Address conversion target MAC (Media Access Control) address be (00:
13:46:90:82:64), source MAC extends this as (00:0D:0D:10:10:03),
Be converted to VLAN 2 data message through VLAN, be sent to Network Management Equipment by transmitting-receiving bag winding.
Step 106, webmaster receive the data of gateway module transmission and process, and complete a secondary data and lead to
News.
Embodiment 2: as shown in Figure 6, including below step:
Step 201, webmaster (10.1.1.1) send ARP Receive message to gateway module (10.1.1.2)
MAC Address (00:0D:0D:10:10:03).
Step 202, webmaster send TCP link building messages to gateway module;
Purpose IP address is (10.1.1.2), and source IP address is (10.1.1.1), purpose tcp port
Being 20480, source tcp port is 1126, and source MAC is (00:13:46:90:82:64),
Target MAC (Media Access Control) address is (00:0D:0D:10:10:03).
After step 203, gateway module receive data (VLAN 2), search NAT forwards rule list,
Coupling transformational rule, carries out NAT conversion, and amendment destination address is (2.2.2.2), purpose TCP end
Mouthful be 8050, through MAC Address conversion target MAC (Media Access Control) address be (00:D0:D0:10:10:
01), source MAC extends this as (00:0D:0D:10:10:03), changes through VLAN
For VLAN 3 data message, it is sent to main control module by transmitting-receiving bag winding.
Step 204, main control module judge after receiving data that destination address is miscellaneous equipment, passes through DCN
These data are forwarded to purpose equipment by (Digital Communication Network, digital communication network).
After step 205, purpose equipment main control module application program process, being sent back by DCN should
Data are to gateway module;
Source MAC is (00:D0:D0:10:10:01), target MAC (Media Access Control) address be (00:
0D:0D:10:10:03), source address is (2.2.2.2), and destination address is (10.1.1.1), mesh
Tcp port be 1126, source tcp port is 8050.
After step 206, gateway module receive data (VLAN 3), search NAT forwards rule list,
Coupling transformational rule, carries out NAT conversion, and amendment destination address is (10.1.1.1), and source IP address is
(10.1.1.2), purpose tcp port is 1126, and source tcp port is 20480, through MAC ground
Location conversion target MAC (Media Access Control) address is (00:13:46:90:82:64), and source MAC is filled in
For (00:0D:0D:10:10:03), be converted to VLAN 2 data message through VLAN,
It is sent to Network Management Equipment by transmitting-receiving bag winding.
Step 207, webmaster receive data and process, and complete a data communication.
One of ordinary skill in the art will appreciate that all or part of step in said method can pass through program
Instructing related hardware to complete, described program can be stored in computer-readable recording medium, as read-only
Memorizer, disk or CD etc..Alternatively, all or part of step of above-described embodiment can also use
One or more integrated circuits realize.Correspondingly, each module/unit in above-described embodiment can use
The form of hardware realizes, it would however also be possible to employ the form of software function module realizes.The present invention is not restricted to appoint
The combination of the hardware and software of what particular form.
These are only the preferred embodiments of the present invention, certainly, the present invention also can have other various embodiments,
In the case of without departing substantially from present invention spirit and essence thereof, those of ordinary skill in the art work as can be according to this
Various corresponding change and deformation are made in invention, but these change accordingly and deformation all should belong to the present invention
Appended scope of the claims.