CN105939292A - Control strategy generation method and device - Google Patents

Control strategy generation method and device Download PDF

Info

Publication number
CN105939292A
CN105939292A CN201510631993.7A CN201510631993A CN105939292A CN 105939292 A CN105939292 A CN 105939292A CN 201510631993 A CN201510631993 A CN 201510631993A CN 105939292 A CN105939292 A CN 105939292A
Authority
CN
China
Prior art keywords
forwarding
data message
control strategy
message
business
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Granted
Application number
CN201510631993.7A
Other languages
Chinese (zh)
Other versions
CN105939292B (en
Inventor
李飞朋
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Hangzhou DPTech Technologies Co Ltd
Original Assignee
Hangzhou DPTech Technologies Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Hangzhou DPTech Technologies Co Ltd filed Critical Hangzhou DPTech Technologies Co Ltd
Priority to CN201510631993.7A priority Critical patent/CN105939292B/en
Publication of CN105939292A publication Critical patent/CN105939292A/en
Application granted granted Critical
Publication of CN105939292B publication Critical patent/CN105939292B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L49/00Packet switching elements
    • H04L49/10Packet switching elements characterised by the switching fabric construction
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L47/00Traffic control in data switching networks
    • H04L47/10Flow control; Congestion control
    • H04L47/12Avoiding congestion; Recovering from congestion
    • H04L47/125Avoiding congestion; Recovering from congestion by balancing the load, e.g. traffic engineering
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L49/00Packet switching elements
    • H04L49/20Support for services

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

The invention provides a control strategy generation method and a control strategy generation device. The method comprises the steps of generating at least a forwarding control strategy which is used for finding a corresponding output port in a pre-stored routing forwarding table entries according to the message information of a data message, and judging whether the output port is configured with safety business after a forwarding chip of an interface board receives the data message, if yes, determining that the data message is the message to be sent to a business board for implementing business treatment, and sending the data message to the corresponding business board by the forwarding chip according to the output port; and issuing the forwarding control strategy to the forwarding chip, thus after the interface board receives the data message, processing the data message by the forwarding chip according to the forwarding control strategy. According to the method, the business treatment pressure of the business boards is reduced, the forwarding efficiency of the data message is improved, the quantity of the deployed business boards is decreased, and the cost is saved for the user.

Description

Control strategy generates method and device
Technical field
The present invention relates to communication technical field, particularly relate to a kind of control strategy and generate method and device.
Background technology
The distributed network equipment includes master control borad, interface board and miscellaneous service plate.Master control borad can pass through The mode issuing configuration issues control strategy to the forwarding chip of business board and interface board, controls to forward core Different data messages is drained to different business boards by sheet, and by business board, message is carried out Business Processing.
In prior art, owing to the distributed network equipment is often deployed in the access port of network, institute There is a need to the data message of outer net be required for entering the network equipment and do safety service, outside dangerous to prevent Data message enter internal network.Further, the distributed network equipment has again the function of switch, institute It is also required to through the network equipment with the data message exchanged visits in inside.
But, the internal data message exchanged visits is general the biggest, and is substantially safe, it is not necessary to do big The safety service of amount, therefore, if (including Intranet exchanging visit data message and visit by the message received from interface board Ask the data message of outer net) data message that then can cause business board on the business board all delivered to is excessive, and then Increase the pressure of business board, reduce the performance of business board.
Summary of the invention
For the defect of prior art, the invention provides a kind of control strategy and generate method and device.
The present invention provides a kind of control strategy to generate method, is applied to the master control borad of the network equipment, described network Equipment also includes business board and has the interface board of forwarding chip, and wherein the method includes:
Generating at least one forwarding control strategy, described forwarding control strategy is for the forwarding chip at interface board After receiving data message, search in the route forwarding table items prestored according to the message information of this data message Corresponding goes out port, and goes out whether port is configured with safety service described in judgement, if having, determines this datagram Literary composition carries out the message of Business Processing for sending to business board, and by described forwarding chip according to described in go out port general Described data message sends to corresponding business board;
Described forwarding control strategy is issued to forwarding chip, so that after described interface board receives data message, Described data message is processed according to described forwarding control strategy by described forwarding chip.
The present invention also provides for a kind of control strategy generating means, is applied to the network equipment and has master control borad, described The network equipment also includes business board and has the interface board of forwarding chip, and described device includes:
Signal generating unit, for generating at least one forwarding control strategy, described forwarding control strategy is for connecing After the forwarding chip of oralia receives data message, according to the message information of this data message in the route prestored Forwarding-table item is searched the corresponding port that goes out, and goes out whether port is configured with safety service described in judgement, if having, Determine that this data message is to send to business board to carry out the message of Business Processing, and by described forwarding chip according to Described go out port described data message is sent to corresponding business board;
Issue unit, for described forwarding control strategy being issued to forwarding chip, so that described interface board connects After receiving data message, described forwarding chip process described data message according to described forwarding control strategy.
The control strategy that the present invention provides generates method and device, by under the forwarding control strategy that will generate Send to forwarding chip, so that after interface board receives data message, however, it is determined that the port that goes out of this data message is joined Put safety service, then by described forwarding chip according to forwarding control strategy by this data message forwarding to corresponding Business board process, it can be seen that, present invention, avoiding by receive all data messages all send to business Plate processes, and then reduces the service processing pressure of business board, improves the forward efficiency of data message, reduces The quantity that business board is disposed, has saved cost for user.
Accompanying drawing explanation
Fig. 1 is that in the embodiment of the present invention, a kind of control strategy generates method application scenarios schematic diagram;
Fig. 2 is that in the embodiment of the present invention, a kind of control strategy generates method flow schematic diagram;
Fig. 3 is the logical structure schematic diagram of a kind of control strategy generating means in the embodiment of the present invention;
Fig. 4 is the hardware structure signal of the control strategy generating means place network equipment in the embodiment of the present invention Figure.
Detailed description of the invention
For making the purpose of the application, technical scheme and advantage clearer, referring to the drawings to this Shen Please scheme be described in further detail.
In order to solve problems of the prior art, the invention provides a kind of control strategy generate method with And device.
Fig. 1 shows the network environment schematic diagram that the inventive method is applied, including being positioned at same LAN Multiple main frames (such as Host1 and Host2), the distributed network equipment and externally-located network remote End server, wherein this network equipment can be the distributed network equipment of frame, has multiple port (example Such as Port1, Port2, Port3 and Port4).
Refer to Fig. 2, for the handling process schematic diagram of the control strategy generation method that the present invention provides, this control Strategy-generating method is applied to the master control borad of the network equipment, this network equipment also include business board and have turn Send out the interface board of chip.Wherein, this control strategy generation method comprises the following steps:
Step 201, generates at least one forwarding control strategy, and described forwarding control strategy is at interface board After forwarding chip receives data message, according to the message information of this data message at the route forwarding table prestored Searching the corresponding port that goes out in Xiang, and go out whether port is configured with safety service described in judgement, if having, determining This data message is the message that transmission to business board carries out Business Processing, and by described forwarding chip according to described Go out port to send described data message to corresponding business board;
In actual application, master control borad can be to business board and the forwarding of interface board by the way of issuing configuration Chip issues control strategy, controls forwarding chip and different data messages is drained to different business boards. The embodiment of the present invention can utilize master control borad to control forwarding chip enter data message by issuing control strategy The feature that row processes, generates at least one forwarding control strategy, controls interface board and receiving data message After, forwarding chip the data message received is carried out Business Processing according to whether needs and make a distinction, and By needing the message carrying out Business Processing to send to corresponding business board, the report of Business Processing will be made without Literary composition directly forwards, to solve, in prior art, (message received from interface board is included Intranet exchanging visit datagram Literary composition and access the data message of outer net) data message that causes business board on the business board all delivered to is excessive, The problem reducing the performance of business board.
In the embodiment of the present invention, the control strategy that master control borad generates can include at least one forwarding control strategy.
This forwarding control strategy is particularly used for after interface board receives data message, controls forwarding chip root Go out port according to what the message information of this data message searched correspondence in the route forwarding table items prestored, and judge Described go out port whether be configured with safety service, if having, determine that this data message is carried out for sending to business board The message of Business Processing, and by described forwarding chip according to described in go out port described data message sent to the most right The business board answered.
Wherein, this forwarding control strategy can be ACL (Access Control List accesses and controls list), Can certainly be other strategies of the prior art, such as, control the forwarding etc. of message by configuring list item, This is limited by the present invention without concrete.
Step 202, is issued to forwarding chip by described forwarding control strategy, so that described interface board receives number After message, described forwarding chip process described data message according to described forwarding control strategy.
The control strategy of generation, after generating forwarding control strategy, can be issued to forwarding chip by master control borad, The data message received is processed according to this forwarding control strategy by forwarding chip.
The forwarding chip of interface board prestores route forwarding table items, and in this route forwarding table items, record has and data What the message information of message was corresponding goes out port.As shown in table 1:
Source IP address Purpose IP address Inbound port Go out port
Host1-IP Host2-IP Port1 Port2
Host1-IP Far-end server-IP Port1 Port3
Host2-IP Far-end server-IP Port2 Port4
Table 1
Table 1 illustrates route forwarding table items, is only the example for being further appreciated by the present invention, is not limited to The particular content of route forwarding table items in the embodiment of the present invention.
In order to ensure the safety of business in network, can also be the most in advance for referring in the embodiment of the present invention Fixed goes out port configuration safety service, and preserves out port and the safety service information for its configuration.Such as, It is referred to shown in table 2:
Go out port Business board identifies Safety service information
Port3 Business board 1 Packet filtering
Port4 Business board 2 Attack-defending
Table 2
Table 2 shows out port and the safety service information for its configuration, is only for being further appreciated by this Bright example, is not limited in the embodiment of the present invention go out port and the safety service information for its configuration Particular content.
At the forwarding chip of interface board after receiving data message, first, obtain the message of this data message Information, this message information can be source IP address and the purpose IP address of this data message.
Afterwards, the source IP address of this data message and purpose IP address are carried out in route forwarding table items Joining, search whether correspondence goes out port.
If having, then further determine whether that going out port for this is configured with safety service, it may be assumed that go out port and For the information (table 2) of its safety service configured searching whether go out the safety service letter that port is corresponding with this Breath, if having, determining that this goes out port and is configured with safety service, and having hit forwarding control strategy, illustrates to receive Data message be the message (usually accessing the data message of outer net) needing to carry out Business Processing, then can The transmission of this data message is pacified to the most corresponding business board according to the business board mark going out port with this corresponding Full-service processes, and according to correspondence after corresponding business board carries out safety service process to this data message Go out port and forward this data message;If it is determined that do not go out port for this to be configured with safety service, it may be assumed that going out port And for its configuration safety service information (table 2) in do not search go out with this port corresponding safety service letter Breath, determines that this goes out port and does not configures safety service, illustrates that the data message received is for being made without at business The message (data message that typically internal network is exchanged visits) of reason, then can be by forwarding chip by this datagram Literary composition is forwarded by the port that goes out corresponding in this route forwarding table items.
So, after forwarding chip receives data message, i.e. can be by the data message received Make a distinction, determine that mailing to business board carries out the message of Business Processing and directly forwarded by forwarding chip Message, and only the message (such as accessing the data message of outer net) carrying out Business Processing will be needed to send to industry Business plate processes, by straight for the message (the such as internal data message exchanged visits) being made without Business Processing The port that goes out connecting correspondence forwards, and then the pressure of business board is greatly reduced, and improves business board Forward efficiency.
It addition, after described interface board receives data message, if forwarding chip is according to the source of this data message After IP address and purpose IP address are mated in the route forwarding table items prestored, do not search going out of correspondence Port, it may be determined that this data message is unknown data message, then can be by this unknown data packet loss.
It should be noted that the content shown in above-mentioned table 2 can also be added to route forwarding table items, connecing After receiving data message, can according to route forwarding table items search whether correspondence go out port and for go out end The safety service information of mouth configuration.
In sum, the control strategy that the present invention provides generates method, by the forwarding control strategy that will generate Be issued to forwarding chip, so that after interface board receives data message, however, it is determined that this data message go out port It is configured with safety service, then by described forwarding chip according to forwarding control strategy by this data message forwarding to right The business board answered processes, it can be seen that, present invention, avoiding and all data messages received all are sent to industry Business plate processes, and then reduces the service processing pressure of business board, improves the forward efficiency of data message, subtracts Lack the quantity that business board is disposed, save cost for user.
The present invention also provides for a kind of control strategy generating means, and Fig. 3 is the structure of this control strategy generating means Schematic diagram, this device can apply to the network equipment, and this control strategy generating means can include signal generating unit 301 and issue unit 302, wherein:
Signal generating unit 301, for generating at least one forwarding control strategy, described forwarding control strategy is used for After the forwarding chip of interface board receives data message, according to the message information of this data message on the road prestored By forwarding-table item is searched the corresponding port that goes out, and go out whether port is configured with safety service described in judgement, if Have, determine that this data message is the message that transmission to business board carries out Business Processing, and by described forwarding chip According to described go out port described data message is sent to corresponding business board;
Issue unit 302, for described forwarding control strategy is issued to forwarding chip, so that described interface board After receiving data message, described forwarding chip process described data message according to described forwarding control strategy.
Further, described signal generating unit 301 is additionally operable to generate at least one and abandons control strategy, described in lose Abandon control strategy after receiving data message at described interface board, if described forwarding chip is in routing forwarding That does not finds correspondence in list item goes out port, then abandon described data message.
Further, described forwarding control strategy is additionally operable to believe according to the message of this data message at forwarding chip Breath find in route forwarding table items correspondence go out port after, however, it is determined that described in go out port and be not configured with safety Business, then forwarded described data message by forwarding chip according to the port that goes out of described correspondence.
Further, described forwarding control strategy is ACL.
The present invention is applied to the control strategy generating means of the network equipment can be with in concrete handling process The handling process that above-mentioned control strategy generates method is consistent, does not repeats them here.
Said apparatus can be realized by software, it is also possible to is realized by hardware, and control strategy of the present invention generates The hardware structure schematic diagram of the device place network equipment all refers to shown in Fig. 4, and its basic hardware environment includes Central processor CPU, forwarding chip, memorizer and other hardware, wherein memory device includes machine Instructions, CPU reads and performs machine readable instructions and performs the function of each unit in Fig. 3.
From the embodiment of any of the above method and apparatus it can be seen that the embodiment of the present invention provide control Strategy-generating method and device, by being issued to forwarding chip by the forwarding control strategy of generation, so that connecing After oralia receives data message, however, it is determined that the port that goes out of this data message is configured with safety service, then by institute State forwarding chip this data message forwarding to be processed to corresponding business board according to forwarding control strategy, thus may be used See, present invention, avoiding and all data messages received all are sent to business board process, and then reduce industry The service processing pressure of business plate, improves the forward efficiency of data message, decreases the quantity that business board is disposed, Cost has been saved for user.
The foregoing is only presently preferred embodiments of the present invention, not in order to limit the present invention, all at this Within the spirit of invention and principle, any modification, equivalent substitution and improvement etc. done, should be included in Within the scope of protection of the invention.

Claims (6)

1. control strategy generates a method, is applied to the master control borad of the network equipment, and the described network equipment also includes Business board and there is the interface board of forwarding chip, it is characterised in that described method includes:
Generating at least one forwarding control strategy, described forwarding control strategy is for the forwarding chip at interface board After receiving data message, search in the route forwarding table items prestored according to the message information of this data message Corresponding goes out port, and goes out whether port is configured with safety service described in judgement, if having, determines this datagram Literary composition carries out the message of Business Processing for sending to business board, and by described forwarding chip according to described in go out port general Described data message sends to corresponding business board;
Described forwarding control strategy is issued to forwarding chip, so that after described interface board receives data message, Described data message is processed according to described forwarding control strategy by described forwarding chip.
2. the method for claim 1, it is characterised in that described forwarding control strategy is additionally operable to turning Send out chip according to the message information of this data message find in route forwarding table items correspondence go out port after, Go out port described in if it is determined that and be not configured with safety service, then turned according to the port that goes out of described correspondence by forwarding chip Send out data message described.
3. the method for claim 1, it is characterised in that described forwarding control strategy controls for accessing List ACL.
4. a control strategy generating means, is applied to the network equipment and has master control borad, and the described network equipment is also Including business board and the interface board with forwarding chip, it is characterised in that described device includes:
Signal generating unit, for generating at least one forwarding control strategy, described forwarding control strategy is for connecing After the forwarding chip of oralia receives data message, according to the message information of this data message in the route prestored Forwarding-table item is searched the corresponding port that goes out, and goes out whether port is configured with safety service described in judgement, if having, Determine that this data message is to send to business board to carry out the message of Business Processing, and by described forwarding chip according to Described go out port described data message is sent to corresponding business board;
Issue unit, for described forwarding control strategy being issued to forwarding chip, so that described interface board connects After receiving data message, described forwarding chip process described data message according to described forwarding control strategy.
5. device as claimed in claim 4, it is characterised in that described forwarding control strategy is additionally operable to turning Send out chip according to the message information of this data message find in route forwarding table items correspondence go out port after, Go out port described in if it is determined that and be not configured with safety service, then turned according to the port that goes out of described correspondence by forwarding chip Send out data message described.
6. device as claimed in claim 4, it is characterised in that described forwarding control strategy is ACL.
CN201510631993.7A 2015-09-29 2015-09-29 Control strategy generation method and device Active CN105939292B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201510631993.7A CN105939292B (en) 2015-09-29 2015-09-29 Control strategy generation method and device

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201510631993.7A CN105939292B (en) 2015-09-29 2015-09-29 Control strategy generation method and device

Publications (2)

Publication Number Publication Date
CN105939292A true CN105939292A (en) 2016-09-14
CN105939292B CN105939292B (en) 2019-07-09

Family

ID=57153019

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201510631993.7A Active CN105939292B (en) 2015-09-29 2015-09-29 Control strategy generation method and device

Country Status (1)

Country Link
CN (1) CN105939292B (en)

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN106603523A (en) * 2016-12-09 2017-04-26 北京东土军悦科技有限公司 Message forwarding method and network switching device
CN106953807A (en) * 2017-03-02 2017-07-14 北京星网锐捷网络技术有限公司 Message forwarding method and device
CN110673995A (en) * 2019-09-24 2020-01-10 杭州迪普科技股份有限公司 Method, device and equipment for testing configuration result of drainage strategy

Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1838609A (en) * 2005-03-22 2006-09-27 杭州华为三康技术有限公司 Centralized service processing method and route apparatus
US20060268877A1 (en) * 1999-07-13 2006-11-30 Gollamudi Ramana V Method and apparatus for providing distributed communication routing
US20070201357A1 (en) * 2002-11-27 2007-08-30 Smethurst Adrian C Control plane security and traffic flow management
CN101267437A (en) * 2008-04-28 2008-09-17 杭州华三通信技术有限公司 Packet access control method and system for network devices
CN103001793A (en) * 2012-10-26 2013-03-27 杭州迪普科技有限公司 Method and device for managing ACL (access control list)
CN104811400A (en) * 2014-01-26 2015-07-29 杭州迪普科技有限公司 Distributed network apparatus

Patent Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20060268877A1 (en) * 1999-07-13 2006-11-30 Gollamudi Ramana V Method and apparatus for providing distributed communication routing
US20070201357A1 (en) * 2002-11-27 2007-08-30 Smethurst Adrian C Control plane security and traffic flow management
CN1838609A (en) * 2005-03-22 2006-09-27 杭州华为三康技术有限公司 Centralized service processing method and route apparatus
CN101267437A (en) * 2008-04-28 2008-09-17 杭州华三通信技术有限公司 Packet access control method and system for network devices
CN103001793A (en) * 2012-10-26 2013-03-27 杭州迪普科技有限公司 Method and device for managing ACL (access control list)
CN104811400A (en) * 2014-01-26 2015-07-29 杭州迪普科技有限公司 Distributed network apparatus

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN106603523A (en) * 2016-12-09 2017-04-26 北京东土军悦科技有限公司 Message forwarding method and network switching device
CN106953807A (en) * 2017-03-02 2017-07-14 北京星网锐捷网络技术有限公司 Message forwarding method and device
CN110673995A (en) * 2019-09-24 2020-01-10 杭州迪普科技股份有限公司 Method, device and equipment for testing configuration result of drainage strategy
CN110673995B (en) * 2019-09-24 2023-05-26 杭州迪普科技股份有限公司 Method, device and equipment for testing drainage strategy configuration result

Also Published As

Publication number Publication date
CN105939292B (en) 2019-07-09

Similar Documents

Publication Publication Date Title
CN108449282B (en) Load balancing method and device
US7519004B1 (en) Loopback testing of a network interface device from a user-space software layer
CN104219340A (en) ARP (Address Resolution Protocol) response proxy method and apparatus
CN101388800A (en) Method, device and system for pressed test to network performance of server
CN105939292A (en) Control strategy generation method and device
CN105991444A (en) Business processing method and business processing apparatus
CN105939291A (en) Message processing unit and network device
US9467372B2 (en) Methods and systems for processing internet protocol packets
CN105704036A (en) Message forwarding method, apparatus, and system
CN104022973A (en) Message forwarding method, switching module, firewall card and switch
CN106101297B (en) A kind of message answer method and device
CN103220255A (en) Method and device for realizing unicast reverse path forwarding (URPF) examination
CN109728972B (en) Network connection detection method and device
CN105939267A (en) Out-of-band management method and device
CN104486226B (en) A kind of message processing method and device
CN104683501A (en) Method and device for domain name resolution
CN105530188A (en) Multicast forwarding method and device
CN105516302A (en) Data processing method and network device
CN104660597A (en) Three-layer authentication method and device as well as three-layer authentication exchanger
CN100553222C (en) A kind of method and device that ensures that message hardware is transmitted
CN112751724B (en) Method and device for detecting link state
CN101505478A (en) Method, apparatus and system for filtering packets
CN103701690B (en) A kind of method and system for setting up voice communication
CN106059929A (en) Message responding method and device
US10129147B2 (en) Network-on-chip flit transmission method and apparatus

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
CB02 Change of applicant information

Address after: Binjiang District and Hangzhou city in Zhejiang Province Road 310051 No. 68 in the 6 storey building

Applicant after: Hangzhou Dipu Polytron Technologies Inc

Address before: Binjiang District and Hangzhou city in Zhejiang Province Road 310051 No. 68 in the 6 storey building

Applicant before: Hangzhou Dipu Technology Co., Ltd.

CB02 Change of applicant information
GR01 Patent grant
GR01 Patent grant