CN108123857A - A kind of connection control method and device - Google Patents

A kind of connection control method and device Download PDF

Info

Publication number
CN108123857A
CN108123857A CN201711430183.0A CN201711430183A CN108123857A CN 108123857 A CN108123857 A CN 108123857A CN 201711430183 A CN201711430183 A CN 201711430183A CN 108123857 A CN108123857 A CN 108123857A
Authority
CN
China
Prior art keywords
address
host
bras
ipv6 addresses
suffix
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
CN201711430183.0A
Other languages
Chinese (zh)
Inventor
王阳
廖以顺
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
New H3C Technologies Co Ltd
Original Assignee
New H3C Technologies Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by New H3C Technologies Co Ltd filed Critical New H3C Technologies Co Ltd
Priority to CN201711430183.0A priority Critical patent/CN108123857A/en
Publication of CN108123857A publication Critical patent/CN108123857A/en
Pending legal-status Critical Current

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L12/00Data switching networks
    • H04L12/28Data switching networks characterised by path configuration, e.g. LAN [Local Area Networks] or WAN [Wide Area Networks]
    • H04L12/2854Wide area networks, e.g. public data networks
    • H04L12/2856Access arrangements, e.g. Internet access
    • H04L12/2869Operational details of access network equipments
    • H04L12/287Remote access server, e.g. BRAS
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L12/00Data switching networks
    • H04L12/28Data switching networks characterised by path configuration, e.g. LAN [Local Area Networks] or WAN [Wide Area Networks]
    • H04L12/46Interconnection of networks
    • H04L12/4641Virtual LANs, VLANs, e.g. virtual private networks [VPN]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L61/00Network arrangements, protocols or services for addressing or naming
    • H04L61/50Address allocation
    • H04L61/5007Internet protocol [IP] addresses
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L61/00Network arrangements, protocols or services for addressing or naming
    • H04L61/50Address allocation
    • H04L61/5076Update or notification mechanisms, e.g. DynDNS
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L2101/00Indexing scheme associated with group H04L61/00
    • H04L2101/60Types of network addresses
    • H04L2101/618Details of network addresses
    • H04L2101/622Layer-2 addresses, e.g. medium access control [MAC] addresses

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Security & Cryptography (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

This application involves network communication technology fields, more particularly to a kind of connection control method and device, to notify to give Broadband Remote Access Server BRAS in the IPv6 addresses for generating host, so that the IPv6 addresses that BRAS is generated according to host provide access service for host, avoid due to network access abnormal problem caused by the IPv6 addresses difference that the IPv6 addresses that host generates are generated with BRAS.This method includes:The address that BRAS is sent according to the host received obtains request, generates address prefix;Address prefix is sent to host, to trigger host generation Internet protocol IP v6 addresses, and the address notification message for carrying the IPv6 addresses is fed back to BRAS;IPv6 addresses are made of the address suffix that the BRAS address prefixes sent and host generate;According to the address notification message of reception, access service is provided for host.

Description

A kind of connection control method and device
Technical field
This application involves network communication technology field more particularly to a kind of connection control methods and device.
Background technology
Broadband Remote Access Server (Broadband Remote Access Server, BRAS) is a kind of towards broadband The access webmaster of network application is the bridge between broadband access network and backbone network, basic access is provided for broadband access network Means and management function;Host is based on the 6th generation Internet protocol (Internet Protocol Version 6, IPv6) , it is necessary to by Stateless Address Auto-configuration or by dynamic host configuration machine when the networking of the BRAS certifications is accessed in location System carries out host ip v6 address configurations.
There are the IPv6 addresses differences that the IPv6 addresses that host generates are generated with BRAS to cause for current IPv6 generation methods Network access abnormal problem.
The content of the invention
The embodiment of the present application provides a kind of connection control method and device, in the IPv6 addresses notice for generating host To BRAS, so that the IPv6 addresses that BRAS is generated according to host provide access service for host, avoid due to host generation Network access abnormal problem caused by the IPv6 addresses difference that IPv6 addresses are generated with BRAS.
In a first aspect, providing a kind of connection control method, this method includes:
The address that Broadband Remote Access Server BRAS is sent according to the host received obtains request, before generating address Sew;
Described address prefix is sent to the host, to trigger the host with generating the 6th generation Internet protocol IP v6 Location, and the address notification message for carrying the IPv6 addresses is fed back to the BRAS;The IPv6 addresses are sent by the BRAS Address prefix and the host generation address suffix composition;
According to the described address notification message of reception, access service is provided for the host.
Second aspect provides a kind of connection control method, and this method includes:
Host sends address to Broadband Remote Access Server BRAS and obtains request;
Receive the address prefix that the BRAS obtains request return according to described address;
Address suffix is generated, and the described address prefix received from the BRAS and described address suffix are combined into IPv6 addresses;
Address notification message is sent to the BRAS;The IPv6 addresses are carried in described address notification message.
The third aspect provides a kind of access control apparatus, which includes:
First generation module after the address for being sent in BRAS according to the host received obtains request, generates address Prefix;
First sending module, for described address prefix to be sent to the host, to trigger the host generation the 6th For Internet protocol IP v6 addresses, and the address notification message for carrying the IPv6 addresses is fed back to the BRAS;The IPv6 Address is made of the address suffix that the BRAS address prefixes sent and the host generate;
For the described address notification message according to reception, access service is provided for the host for access service module.
Fourth aspect provides a kind of access control apparatus, which includes:
Second sending module sends address to Broadband Remote Access Server BRAS for host and obtains request;
Second receiving module obtains the address prefix of request return for receiving the BRAS according to described address;
Second generation module, for generating address suffix, and by the described address prefix received from the BRAS and institute It states address suffix and is combined into IPv6 addresses;
Second sending module is additionally operable to send address notification message to the BRAS;It is carried in described address notification message The IPv6 addresses.
In the embodiment of the present application, after the address that BRAS receives host transmission obtains request, address prefix is generated, and will Address prefix is sent to host;Host generates IPv6 addresses after the address prefix transmitted by BRAS is received, and anti-to BRAS Feedback carries the address notification message of the IPv6 addresses;BRAS provides access service according to the address notification message for host, During being somebody's turn to do, host is by the way that BRAS feedback addresses notification messages, the address suffix that host generates is notified to BRAS, BRAS bases Access service is provided for host in the address suffix of host notification, therefore is not in that the IPv6 addresses of host generation and BRAS give birth to Into IPv6 addresses difference caused by network access it is abnormal the problem of.
Description of the drawings
It, below will be to the application in order to clearly illustrate the embodiment of the present application or technical solution of the prior art Required attached drawing does simple introduction in embodiment or description of the prior art.It should be evident that the accompanying drawings in the following description Only some embodiments described in the application, for those of ordinary skill in the art, can also be according to these attached drawings Obtain other attached drawings.
Fig. 1 shows a kind of certification networking schematic diagram of BRAS management;;
Fig. 2 shows the flow diagram of control cut-in method provided by the embodiments of the present application;
Fig. 3 shows the flow diagram for the control cut-in method that another embodiment of the application provides;
Fig. 4 shows the structure diagram of control access device provided by the embodiments of the present application;
Fig. 5 shows the structure diagram for the control access device that another embodiment of the application provides;
Fig. 6 shows the structure diagram of computer equipment provided by the embodiments of the present application.
Specific embodiment
In Stateless Address Auto-configuration, host is when reaching the standard grade access authentication networking, first by direct-connected therewith Interchanger actively to BRAS send address obtain request;It, can base after the address that BRAS is received transmitted by host obtains request In certain rule 64 bit address prefixes of generation, and address prefix is returned into host;Host, will after address prefix is received With local based on it is certain rule generation 64 bit address suffix combine, form the IPv6 addresses of the host.BRAS to While host feedback addresses prefix, session (SESSION) list item corresponding with the host can be locally generated;It is generating During SESSION list items, with first having to the MAC carried in the acquisition request of the address transmitted by Intrusion Detection based on host or address acquisition request Location generates the address suffix of the IPv6 addresses of the host, and by the BRAS address prefixes returned and the address suffix knot locally generated It closes, forms the IPv6 addresses of the host, which is carried in the SESSION list items.
In the certification networking example of BRAS management as shown in Figure 1, host (user) 1 and user2 are exchanged by LAN Machine (Local Area Network Switch, LSW) accesses BRAS;Wherein, user1 and user2 is same virtual LAN User in (Virtual Local Area Network, VLAN).When user1 should using the access of stateless address acquisition modes During certification networking, router solicitation (Router Solicit, RS) message is sent to BRAS by LSW first.BRAS is being received To user1 send RS messages after, by the source medium access control carried in RS messages (Media Access Control, MAC) address, the host name as the host be sent to verification, authorization and accounting (Authentication, Authorization, Accounting, AAA) server is authenticated.Receive aaa server return certification by After information, the address prefix and address suffix of user1 can be generated, and the address prefix of user1 and address suffix are merged into shape The SESSION list items in BRAS generations are carried into IPv6 addresses of the user1 on BRAS, and by the IPv6 addresses of the user1 In, the SESSION list items are then issued to interface chip, to provide access service as host according to the SESSION list items. While generating SESSION list items, BRAS is also reported to response of host router advertisement (Router Advertisement, RA) Text carries the address prefix of BRAS generations in RA messages.User1 is after RA messages are received, according to preset rule 64 bit address suffix are then generated, and the address suffix of the address prefix carried in RA messages and generation is combined, are formed IPv6 addresses.
In above process, once the mode of BRAS generation address suffix and the mode of user1 generation address suffix differ Sample can cause the IPv6 addresses that host is generated different with the IPv6 addresses of user1 in SESSION list items, so as to cause network It is abnormal.
For application scheme when realizing the access networking of host access band, host is before the address transmitted by BRAS is received Sew, behind generation IPv6 addresses, the address notification message of the IPv6 addresses can be carried to BRAS feedbacks.BRAS leads to according to the address Know message, access service is provided for host, realize host and notify the IPv6 addresses of generation on BRAS so that in BRAS IPv6 addresses in SESSION list items are as the IPv6 addresses that host is preserved, so as to eliminate what is generated by host IPv6 addresses and the IPv6 addresses difference of host in SESSION list items cause Network Abnormal.
It is below in conjunction with the accompanying drawings and specific real to enable the above-mentioned purpose of the application, feature and advantage more obvious understandable It applies mode and optional detailed description is done to the application.
In the embodiment of the present application, as shown in Fig. 2, be the connection control method flow chart that a kind of embodiment of the application provides, In the embodiment of the present application, the main body for being responsible for performing connection control method can be BRAS.This method comprises the following steps:
S201:The address that BRAS is sent according to the host received obtains request, generates address prefix.
S202:Address prefix is sent to host, to trigger host generation Internet protocol IP v6 addresses, and it is anti-to BRAS Feedback carries the address notification message of the Internet protocol IP v6 addresses;IPv6 addresses are by the BRAS address prefixes sent and host The address suffix composition of generation.
S203:According to the address notification message of reception, access service is provided for host.
When specific implementation, host sends address to LSW first and obtains request when access authentication networking. Address obtains the VLAN marks carried in request belonging to the MAC Address and host of host.LSW is receiving address acquisition After request, address can be obtained request and be transmitted to BRAS.For BRAS after receiving the address and obtaining request, being obtained according to address please The MAC Address of middle carrying is asked to initiate certification request to certificate server.Certificate server after certification request is received, according to The MAC Address carried in certification request carries out host machine authentication.
Certificate server first verifies that whether host can be recognized when host machine authentication is carried out according to MAC Address Demonstrate,prove the access rights of networking.After verification host can obtain the access rights of certification networking, clothes that authorization host can use Business, then feeds back to BRAS by certification by information;BRAS receive certification by information after, based on itself configuration ground Location prefix generation method generation address prefix and temporary address suffix, and address prefix and temporary address suffix are stored in life Into SESSION list items corresponding with the host in.If certificate server verification host is unable to gain access, to BRAS return authentication failure informations;BRAS performs host machine authentication failure handling after authentication failure message is received.
It herein, in the application in one embodiment, can will be after address prefix that BRAS is generated and temporary address Sew and be separately maintained in SESSION list items, it is convenient subsequently will temporary address suffix in the address notification message transmitted by host The address suffix carried in the IPv6 addresses of carrying is compared.
In the application in one embodiment, BRAS is the ground based on itself configuration when address prefix is generated Location prefix create-rule generation.
Herein, it should be noted that the SESSION list items corresponding to the temporary address suffix are only interim list item, no Hardware can be issued to, that is, the interface of BRAS will not provide access service based on the temporary address suffix for host.Only when Address suffix in SESSION list items is converted into formal address suffix by temporary address suffix or is with the addition of formal ground Location suffix, just can be using the corresponding SESSION list items of formal address suffix as formal SESSION list items, and will be formal SESSION list items are issued to hardware.
BRAS is that the MAC Address generation carried in request, example are obtained based on address when temporary address suffix is generated MAC Address is such as converted into 64 Bits Expanding unique identifiers (64-bit Extended Unique Identifier, EUI64), Using the EUI64 as the temporary address suffix in the application.
It is noted herein that the address that the temporary address suffix that BRAS is generated is generally based on transmitted by host is obtained Take MAC Address generation entrained in request.By same access server BRAS reach the standard grade certification networking host may have it is more A, for different hosts, certificate server is different for the address prefix of these hosts generation, that is, each master Machine corresponds to unique address prefix.Each host can be based on after the address prefix transmitted by access server BRAS is received The address suffix create-rule generation address suffix of itself configuration, thereby increases and it is possible to multiple address suffix are generated, to form the host pair The multiple IPv6 addresses answered.
Specifically, the differentiation of the different hosts identical to these MAC Address can not be often realized using MAC Address, but The address prefix of host, the MAC Address of host, the VLAN marks of the affiliated virtual LAN of host, certificate server is combined to connect The receiving port for receiving each information of host transmission identifies to uniquely determine a host.Therefore the application one of them In embodiment, BRAS preserves generated address prefix, address obtains request after generation address prefix and temporary address suffix MAC Address and the VLAN mark of middle carrying and address obtain the correspondence between the receiving port mark of request.It is preserving When correspondence between above-mentioned a few persons, SESSION tables may be employed, and will be each and initiate address to BRAS and obtain The host of request is taken to generate a SESSION list item.
Such as shown in used SESSION list items the following table 1:
Table 1
Wherein, in the SESSION tables, Index is the number of session entry;Mac is the MAC Address of host; Interface is the receiving port mark that address obtains request;The VLAN that Vlan is the affiliated VLAN of host is identified;Prefix is ground Location prefix;ID is address suffix;Type is used to identify the type of the address suffix, and when Type is T, identifying the address suffix is Temporary address suffix;When Type is F, the address suffix is identified as formal address suffix.The SESSION for being 1 in the number In list item, MAC Address mac1;Receiving port is identified as port1;VLAN is identified as Vlan1;Address prefix is 2001::, face When address suffix be 1;Formal address suffix is 2.
BRAS after address prefix is generated, can by prefix be sent to host.Host receives the ground of BRAS transmissions After the prefix of location, can address suffix, and the address prefix that BRAS is sent be generated based on the address suffix create-rule of itself configuration The IPv6 addresses of the host, Ran Houxiang are combined into the address suffix of the address suffix create-rule generation configured based on itself BRAS feedback addresses notification messages.In the address notification message, carry the affiliated VLAN's of MAC Address, host of host The IPv6 addresses that VLAN is identified and host is generated.
It, when BRAS receives the address feedback message of host transmission based on the IPv6 carried in the feedback message of address Location provides access service for host.
Specifically, address prefix is extracted in the IPv6 addresses that BRAS is carried from the notification message of address first, is then detected MAC Address and the VLAN mark and BRAS carried in the address prefix that is extracted from IPv6 addresses, address notification message connects It receives and whether meets the correspondence of preservation between the receiving port mark of the address notification message, and meeting correspondence When, based on IPv6 addresses access service is provided for host.
The VLAN marks of the affiliated VLAN of MAC Address, host carried during wherein, address acquisition is asked due to BRAS, The temporary address suffix correspondence that location obtains the receiving port mark of request, address prefix and BRAS are generated is stored in same In SESSION list items, then detection is extracted from IPv6 addresses address prefix, the MAC Address carried in the notification message of address and VLAN is identified and BRAS receive the receiving port mark of the address notification message between whether meet the correspondence of preservation When, be by the MAC Address and VLAN that are carried in the address prefix extracted from IPv6 addresses, address notification message mark and The receiving port mark that BRAS receives the address notification message is matched with SESSION list items;If with to certain SESSION MAC Address, VLAN marks, receiving port mark and address prefix all same in list item, then it is assumed that the address obtains request Hit the SESSION list items.
The address prefix extracted from IPV6 addresses, the MAC Address that address notification message carries and VLAN marks are detected, with And the process of correspondence between the receiving port mark of address notification message whether meeting preservation has following two kinds of realization sides Formula:
I, the MAC Address that there is correspondence with the address prefix of extraction, VLAN marks are searched from SESSION list items, And address obtains the receiving port mark of request;
The MAC Address found from SESSION list items, VLAN marks and receiving port mark are detected, is led to address Know the MAC Address carried in message, VLAN mark and described address notification message receiving port identify whether it is identical;Such as Fruit is identical, then meets correspondence.If it is not the same, correspondence is not met then.
Ⅱ:MAC Address, VLAN marks and the address with being carried in the notification message of address are searched from SESSION list items Address prefix of the receiving port mark with correspondence of notification message;
Detect the address prefix that is found from SESSION list items and the address prefix that is extracted from IPv6 addresses whether phase Together;If identical, meet correspondence.If identical, meet correspondence, if it is not the same, not meeting correspondence then.
BRAS is actually carried when providing access service for host according to the corresponding SESSION list items of host for host For session control, BRAS can will be issued to port chip for the session entry that host generates, and port chip is corresponded to according to the host Session entry realize session between the host and other hosts.In order to provide conversational services to host, needed in session entry Preserve the IPv6 addresses of the host.Once in the datagram IPv6 addresses used herein and session entry transmitted by host IPv6 addresses are different, can not just complete the access service to host.
Therefore, in the embodiment of the present application, can by the SESSION list items generated by address prefix and temporary address Suffix is retained separately, in order to ensure the address suffix in SESSION list items and the address suffix in the IPv6 addresses of host generation Unanimously, when providing access service in the IPv6 addresses of Intrusion Detection based on host generation for the host, detection host generation is first had to IPv6 addresses in the address suffix that carries, whether be consistent with the temporary address suffix found from SESSION list items.
If the address suffix carried in the IPv6 addresses of host generation, interim with being found from SESSION list items Address suffix is consistent, then is based on SESSION list items and provides access service for the host.Based on SESSION tables When item provides access service for the host, based on the temporary address suffix in SESSION list items, access clothes are provided for host Business, that is, temporary address suffix can be converted into formal address suffix, such as in table 1 above, behind the address for being 1 by ID Sew corresponding Type and F is changed to by T so that BRAS can provide access service for the address suffix of F based on the Type for host.
If the address suffix carried in the IPv6 addresses of host generation, interim with being found from SESSION list items Address suffix is not consistent, and the address suffix extracted from IPv6 addresses is added in SESSION list items, and based on institute It states newly added address suffix in SESSION list items and provides access service for host, that is, will extracted from IPv6 addresses When address suffix is added in SESSION list items, the type of the address suffix is formal address suffix, will the address The corresponding Type of suffix is arranged to F so that BRAS can provide access service for the address suffix of F based on the Type for host.
Such as:After BRAS obtains request in the address for receiving host transmission, SESSION list items such as the following table 2 institute of generation Show:
Table 2
Index Mac Interface Vlan Prefix ID Type
1 mac1 port1 vlan1 2001:: 1 T
Wherein, session entry is one in conversational list.In the conversational list, Index is the number of session entry;Mac is MAC Address;Interface identifies for receiving port;Vlan identifies for VLAN;Prefix is address prefix;ID is address suffix, And Type corresponding with the ID is T, identifies the address suffix as temporary address suffix.In the session entry that the number is 1, MAC Address is mac1;Receiving port is identified as port1;Vlan is vlan1;Address prefix is 2001::;Temporary address suffix is 1。
When the address notification message for receiving host transmission, and during the definite address notification message match this session entry, If the IPv6 addresses carried in the notification message of address are:2001::0005.It is carried in the address notification message in IPv6 addresses The address suffix of carrying is 5, different from temporary address suffix, therefore, the address suffix that BRAS can will be extracted from IPv6 addresses It is added in the SESSION list items, at this point, the SESSION list items such as the following table 3.
Table 3
At this point, it is mac1, Interface port1, Vlan vlan1, Prefix 2001 based on MAC Address::、ID For 5 SESSION list items access service is provided for host.
SESSION list items in the above-described embodiments deposit following difference with SESSION list items in the prior art:The application is real It applies in the SESSION list items generated in example, address suffix and the host of the final session entry that access is provided for host generate IPv6 addresses in address suffix it is necessarily identical;And the IPv6 addresses in SESSION list items are one in the prior art A entirety, and the address suffix in the IPv6 addresses that might not be generated with host is identical.
In the connection control method of the present embodiment, after the address that BRAS receives host transmission obtains request, generation ground Location prefix, and address prefix is sent to host;Host is after the address prefix transmitted by BRAS is received, with generating IPv6 Location, and the address notification message for carrying the IPv6 addresses is fed back to BRAS;BRAS is carried according to the address notification message for host For access service, in this process, host is by the way that BRAS feedback addresses notification messages, the address suffix of host generation is notified To BRAS, the address suffix of BRAS Intrusion Detection based on host notice provides access service for host, therefore is not in what host generated The problem of IPv6 addresses and abnormal network access caused by the IPv6 addresses difference of BRAS generations.
In addition, in the application in one embodiment, have in order to prevent disabled user pretend to be validated user identity to BRAS sends address notification message, first when providing access service for the host in the described address notification message according to reception First according to carried in the notification message of address IPv6 addresses, MAC Address, VLAN mark, address notification message receiving port mark Know, probe message is sent to host;If receiving the feedback message that host is sent according to probe message in preset time, According to the described address notification message of reception, access service is provided for the host.If do not receive master in preset time The feedback message that machine is sent according to probe message then abandons the address notification message.
Shown in Figure 3, the application also provides another connection control method, in this embodiment, performs access controlling party The main body of method is host.This method comprises the following steps:
S301:Host sends address to BRAS and obtains request.
S302:It receives BRAS and the address prefix that the MAC Address carried in request returns is obtained according to address.
S303:Address suffix is generated, and the address suffix of the address prefix received from BRAS and generation is combined into IPv6 addresses;
S304:Address notification message is sent to BRAS;IPv6 addresses are carried in the notification message of address.
When specific implementation, when host will access some certification networking, first having to the acquisition of generation address please It asks and is sent to BRAS, to obtain the address prefix of BRAS returns.BRAS can send address prefix after address prefix is generated To host.After host receives the address prefix of BRAS transmissions, the address suffix generation method based on itself configuration generates address Suffix, and address prefix and address suffix are combined, the IPv6 addresses of host are formed, then carry this to BRAS feedbacks The address notification message of IPv6 addresses.
Herein, address is obtained request and notifies to disappear with address to be typically sent to BRAS in the form of message, is obtained in address In request and address notification message, the MAC Address of host, the mark for the VLAN that host to be added in are carried.
In the present embodiment, after host receives the address prefix of BRAS transmissions, address suffix is generated, and by address prefix IPv6 addresses are collectively constituted with address suffix, the address notification message of the IPv6 addresses is then carried to BRAS feedbacks so that The IPv6 addresses of host generation can be informed to BRAS so that the IPv6 addresses that BRAS is generated according to host provide for host Access service, avoid due to host generation IPv6 addresses generated with BRAS IPv6 addresses difference when caused network access Abnormal problem.
In addition, after address notification message is sent to BRAS, host can also receive the probe message of BRAS transmissions;It is visiting It surveys in message and carries IPv6 addresses, MAC Address, VLAN marks.Host can will carry IPv6 addresses, MAC in probe message Address, the IPv6 addresses of VLAN marks and the generation of itself, MAC Address, VLAN marks are compared one by one, if the knot compared Fruit is consistent, then in preset time, feedback message is sent to BRAS, so that BRAS is carried after receiving institute's feedback message for host For access service.
Connection control method provided by the embodiments of the present application is applied in the certification networking of BRAS management shown in FIG. 1, Wherein user1 and user2 accesses BRAS by LSW, and the MAC Address that has of user1 is mac1, the MAC Address that user2 has For mac2.The interface that the BRAS connects the LSW is port1;Wherein, user1 and user2 is the user in same VLAN, should The VLAN that VLAN has is identified as vlan1.
When user1 accesses the certification networking, address is sent to LSW first and obtain request;The address obtains at this time The MAC Address mac1 of the user1 is carried in request.
When LSW obtains request in the address for receiving user1 transmissions, obtain in request and added belonging to user1 for address The VLAN mark vlan1 of VLAN, and the address for being with the addition of VLAN marks is obtained into request and is sent to BRAS.
The address that BRAS receives user1 transmissions by port1 obtains request, therefrom obtains the MAC Address of user1, hair It send to aaa server and verifies.
BRAS in aaa server to mac authentication by rear, according to itself configuration address prefix generation method generate address Prefix Prefix is 2003::, and it is 3 to generate address suffix ID, the type Type of the address suffix is behind temporary address at this time Sew, identified with T, and VLAN marks vlan1, BRAS of the affiliated VLAN of MAC Address mac1, user1 of user1 are received into address Obtain the address prefix 2003 of receiving port mark port1, BRAS generation of request::, address suffix 3 is stored in one In SESSION list items, the SESSION list items generated are as shown in table 4 below:
Table 4
Index Mac Interface Vlan Prefix ID Type
1 mac1 port1 vlan1 2003:: 3 T
BRAS is in generation address prefix 2003::Afterwards, which is sent to user1 by LSW.
User1 is receiving the address prefix 2003 transmitted by BRAS::Afterwards, the address suffix generation based on itself configuration Mode generates address suffix 2, and by address prefix 2003::An IPv6 address is combined into address suffix 2:2003::2.
User1 is in generation IPv6 addresses:2003::After 2, address notification message is sent to BRAS by LSW.
In the address notification message that BRAS is received, the IPv6 addresses are carried:2003::Belonging to the 2 and user1 The VLAN mark vlan1 of VLAN, and the receiving port for receiving the address notification message is identified as port1.
After the address notification message that BRAS is received, according to the address in the IPv6 addresses carried in the address notification message Prefix 2003::, VLAN mark vlan1 and receiving port identify port1, from the detection of SESSION tables and the address notification message Corresponding SESSION list items, the SESSION list items have and the address notification message identical address prefix 2003::, VLAN marks Know vlan1 and receiving port mark port1.
If corresponding SESSION list items are not detected, which is abandoned or is sent into its of BRAS The processing of its function module.
If detect corresponding SESSION list items, the IPv6 addresses that user1 is generated:2003::Address in 2 Suffix therefrom parses, which is compared with the temporary address suffix in detected SESSION list items.
Address suffix in the IPv6 addresses generated by user1 is 2, and behind the temporary address in SESSION list items To sew for 3, the two is different, then address suffix 2 is added in the SESSION list items, and by the class of newly added address suffix 2 Type is set to indicate that the mark F that the address suffix 2 is formal address suffix, as shown in table 5:
Table 5
It is then based on the address suffix 2 and provides access service for user1.
Similar, user1 is receiving the address prefix 2003 transmitted by BRAS::Afterwards, if based on the ground of itself configuration Location suffix generating mode generates address suffix 3, and by address prefix 2003::An IPv6 address is combined into address suffix 3: 2003::3.
User1 is in generation IPv6 addresses:2003::After 3, address notification message is sent to BRAS by LSW.
In the address notification message that BRAS is received, the IPv6 addresses are carried:2003::Belonging to the 3 and user1 The VLAN mark vlan1 of VLAN, and the receiving port for receiving the address notification message is identified as port1.
After the address notification message that BRAS is received, according to the address in the IPv6 addresses carried in the address notification message Prefix 2003::, VLAN mark vlan1 and receiving port identify port1, from the detection of SESSION tables and the address notification message Corresponding SESSION list items, SESSION tool list items have and the address notification message identical address prefix 2003::, VLAN marks Know vlan1 and receiving port mark port1.
If corresponding SESSION list items are not detected, which is abandoned or is sent into its of BRAS The processing of its function module.
If detect corresponding SESSION list items, the IPv6 addresses that user1 is generated:2003::Address in 3 Suffix therefrom parses, which is compared with the temporary address suffix in detected SESSION list items.
Address suffix in the IPv6 addresses generated by user1 is 3, and behind the temporary address in SESSION list items Sew for 3, the two is identical, then the type of the temporary address suffix in SESSION list items is changed to F by T, also i.e. by temporary address Suffix makes formal address suffix into, as shown in table 6:
Table 6
Index Mac Interface Vlan Prefix ID Type
1 mac1 port1 vlan1 2003:: 3 F
It is then based on this and makes formal address suffix 3 by temporary address suffix providing access service for user1.
By above-described embodiment, can realize the address to be generated in the address suffix and host of host generation in BRAS Suffix is united, that is, the IPv6 addresses that BRAS is generated according to host is made to provide access service for host, is avoided due to host Network access abnormal problem caused by the IPv6 addresses difference that the IPv6 addresses of generation are generated with BRAS.
Based on same inventive concept, access control dress corresponding with connection control method is additionally provided in the embodiment of the present application It puts, since the principle that the device in the embodiment of the present application solves the problems, such as is similar to the above-mentioned connection control method of the embodiment of the present application, Therefore the implementation of device may refer to the implementation of method, and overlaps will not be repeated.
Access control apparatus shown in Figure 4, that the embodiment of the present application is provided, including:
First generation module 401, after the address for being sent in BRAS according to the host received obtains request, generation ground Location prefix;
For address prefix to be sent to host, the 6th generation internet protocol is generated to trigger host for first sending module 402 IPv6 addresses are discussed, and the address notification message for carrying IPv6 addresses is fed back to BRAS;Before the address that IPv6 addresses are sent by BRAS Sew the address suffix composition with host generation;
For the address notification message according to reception, access service is provided for host for access service module 403.
The access control apparatus that the embodiment of the present application is provided, when the address that BRAS receives host transmission obtains request Afterwards, address prefix is generated, and address prefix is sent to host;Host is raw after the address prefix transmitted by BRAS is received Into IPv6 addresses, and the address notification message for carrying the IPv6 addresses is fed back to BRAS;BRAS according to the address notification message, Access service is provided for host, in this process, host passes through address that BRAS feedback addresses notification messages, host is generated Suffix notifies that, to BRAS, the address suffix of BRAS Intrusion Detection based on host notice provides access service for host, therefore is not in host The problem of IPv6 addresses of generation and abnormal network access caused by the IPv6 addresses difference of BRAS generations.
In the application in one embodiment, the first generation module 401, be additionally operable to for generate address prefix it Afterwards, address prefix is preserved, address obtains the MAC Address carried in request and the reception of VLAN marks and address acquisition request Correspondence between port-mark.
Access service module 403, is specifically used for:Address prefix is extracted from the IPv6 addresses that address notification message carries;
The address prefix extracted from IPv6 addresses, the MAC Address that address notification message carries and VLAN marks are detected, with And whether meet the correspondence of preservation between the receiving port mark of address notification message;
When meeting correspondence, access service is provided for host based on IPv6 addresses.
In the application in one embodiment, the first generation module 401 is specifically used for:Based on address prefix and ground Location obtains the MAC Address carried in request and VLAN marks and address obtains the receiving port mark generation software meeting of request Talk about list item;
Access service module 403, is specifically used for:IPv6 addresses are added in software sessions list item, and based on software meeting Words list item provides access service for host.
In the application in one embodiment, the first generation module 401, is additionally operable to:It obtains the address that receiving host is sent After taking request, temporary address suffix is generated;Request is obtained based on address prefix, the temporary address suffix of generation and address MAC Address and the VLAN mark of middle carrying and address obtain the receiving port mark generation software sessions list item of request;
Access service module 403, is specifically used for:The address suffix carried in detection IPv6 addresses, with the MAC that finds In software sessions SESSION list items where the receiving port mark of location, VLAN marks and address acquisition request provisionally Whether location suffix is consistent;
If consistent, access service is provided for host based on the temporary address suffix in software sessions list item;
If it is inconsistent, the address suffix extracted from IPv6 is added in software sessions list item, and based on software The newly added address suffix of session entry provides access service for host.
In the application in one embodiment, access service module 403, is specifically used for:According in the notification message of address The IPv6 addresses of carrying, MAC Address, VLAN marks, end is received from corresponding with the receiving port of address notification message mark Mouthful, send probe message to host;
If the feedback message that host is sent according to probe message is received in preset time, according to the address of reception Notification message provides access service for host.
In the application in one embodiment, the first generation module 401 is taken specifically for being obtained according to address in request The medium access control MAC Address of band initiates certification request to certificate server, and is receiving recognizing for certificate server feedback Card after information by generating address prefix.
Access control apparatus shown in Figure 5, that the embodiment of the present application is provided, including:
Second sending module 501 sends address to BRAS for host and obtains request;
Second receiving module 502 obtains the address prefix of request return for receiving BRAS according to address;
Second generation module 503, for generating address suffix, and the address prefix and address suffix that will be received from BRAS It is combined into IPv6 addresses;
Second sending module 501 is additionally operable to send address notification message to BRAS;IPv6 is carried in the notification message of address Location.
The device further includes:Feedback module is detected, for receiving the probe message of BRAS transmissions;It is carried in probe message IPv6 addresses, MAC Address, VLAN marks;
In preset time, identified according to IPv6 addresses, MAC Address, VLAN to BRAS and send feedback message, so that BRAS It receives and provides access service for host after feedback message.
As shown in fig. 6, the embodiment of the present application also provides a kind of computer equipment, which includes memory 1000, processing Device 2000 and the computer program that can be run on the memory 1000 and on the processor 2000 is stored in, wherein, above-mentioned place The step of reason device 2000 realizes above-mentioned connection control method when performing above computer program.
Specifically, above-mentioned memory 1000 and processor 2000 can be general memory and processor, not do here It is specific to limit, when the computer program of 2000 run memory 1000 of processor storage, it is able to carry out above-mentioned access controlling party Method, so as to solve the problems, such as to adopt the address suffix of BRAS and host generation it is inconsistent when caused network access it is abnormal, Jin Erda It is notified to the IPv6 addresses that host is generated to server is included in, so that BRAS is connect according to the IPv6 addresses of host notification Enter control, avoid the problem that since network access caused by the host ip v6 addresses difference that BRAS and host preserve is abnormal.
The connection control method and the computer program product of device that the embodiment of the present application is provided, including storing journey The computer readable storage medium of sequence code, the instruction that program code includes can be used for performing the side in previous methods embodiment Method, specific implementation can be found in embodiment of the method, and details are not described herein.
It is apparent to those skilled in the art that for convenience and simplicity of description, the system of foregoing description With the specific work process of device, the corresponding process in preceding method embodiment is may be referred to, details are not described herein.
If function is realized in the form of SFU software functional unit and is independent production marketing or in use, can store In a computer read/write memory medium.Based on such understanding, the technical solution of the application is substantially in other words to existing The part for having part that technology contributes or the technical solution can be embodied in the form of software product, the computer Software product is stored in a storage medium, is used including some instructions so that a computer equipment (can be personal meter Calculation machine, server or network equipment etc.) perform each embodiment the method for the application all or part of step.It is and preceding The storage medium stated includes:USB flash disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory The various media that can store program code such as (RAM, Random Access Memory), magnetic disc or CD.
The above is only the specific embodiment of the application, but the protection domain of the application is not limited thereto, any In the technical scope that those familiar with the art discloses in the application, change or replacement can be readily occurred in, should all be contained It covers within the protection domain of the application.Therefore, the protection domain of the application described should be subject to the protection scope in claims.

Claims (16)

1. a kind of connection control method, which is characterized in that this method includes:
The address that Broadband Remote Access Server BRAS is sent according to the host received obtains request, generates address prefix;
Described address prefix is sent to the host, the 6th generation Internet protocol IP v6 address is generated to trigger the host, And the address notification message of the IPv6 addresses is carried to BRAS feedbacks;The ground that the IPv6 addresses are sent by the BRAS Location prefix and the address suffix composition of host generation;
According to the described address notification message of reception, access service is provided for the host.
2. according to the method described in claim 1, it is characterized in that, after generation address prefix, further include:
Preserve described address prefix, described address obtains the MAC Address carried in request and VLAN is identified and described address obtains Take the correspondence between the receiving port mark of request;
The address notification message according to reception provides access service for the host, specifically includes:
Address prefix is extracted from the IPv6 addresses that described address notification message carries;
The address prefix extracted from IPv6 addresses, the MAC Address that described address notification message carries and VLAN marks are detected, with And whether meet the correspondence of preservation between the receiving port mark of address notification message;
When meeting the correspondence, access service is provided for the host based on the IPv6 addresses.
3. according to the method described in claim 2, it is characterized in that, the preservation described address prefix, described address are obtained and asked The correspondence between the MAC Address of middle carrying and VLAN marks and the receiving port mark of described address acquisition request is sought, It specifically includes:
The MAC Address carried in request and VLAN marks, Yi Jisuo are obtained based on described address prefix and described address State the receiving port mark generation software sessions list item that address obtains request;
It is described to provide access service based on the IPv6 addresses for the host, including:
The IPv6 addresses are added in the software sessions list item, and are carried based on the software sessions list item for the host For access service.
4. according to the method described in claim 2, it is characterized in that, the receiving host send address obtain request after, It further includes:
Generate temporary address suffix;
It is described preserve described address prefix, described address obtains the MAC Address carried in request and VLAN marks and described Location obtains the correspondence between the receiving port mark of request, specifically includes:
It is obtained based on described address prefix, the temporary address suffix of generation and described address described in being carried in request MAC Address and VLAN marks and described address obtain the receiving port mark generation software sessions SESSION list items of request;
It is described to provide access service based on the IPv6 addresses for the host, including:
The described address suffix carried in the IPv6 addresses is detected, is identified with MAC Address, the VLAN found and described Whether the temporary address suffix that address is obtained in the software sessions list item at the receiving port mark place of request is consistent;
If consistent, access service is provided for the host based on the temporary address suffix in the software sessions list item;
If it is inconsistent, the described address suffix extracted from the IPv6 is added in the software sessions list item, and Based on the newly added address suffix of software sessions list item access service is provided for the host.
5. according to the method described in claim 1, it is characterized in that, the described address notification message according to reception, for institute It states host and access service is provided, specifically include:
According to carried in described address notification message IPv6 addresses, MAC Address, VLAN mark, from described address notice disappear The receiving port of breath identifies corresponding receiving port, and probe message is sent to the host;
If the feedback message that host is sent according to the probe message is received in preset time, according to reception Address notification message provides access service for the host.
6. according to the method described in claim 1, it is characterized in that, the generation address prefix, specifically includes:
The medium access control MAC Address carried in request is obtained according to described address, certification request is initiated to certificate server, And receive certificate server feedback certification by information after generate described address prefix.
7. a kind of connection control method, which is characterized in that this method includes:
Host sends address to Broadband Remote Access Server BRAS and obtains request;
Receive the address prefix that the BRAS obtains request return according to described address;
Address suffix is generated, and by the described address prefix received from the BRAS and described address suffix with being combined into IPv6 Location;
Address notification message is sent to the BRAS;The IPv6 addresses are carried in described address notification message.
8. the method according to the description of claim 7 is characterized in that this method further includes:
Receive the probe message that BRAS is sent;IPv6 addresses, MAC Address, VLAN marks are carried in the probe message;
In preset time, identified according to the IPv6 addresses, MAC Address, VLAN to the BRAS and send feedback message, so that The BRAS is received and is provided access service for the host after the feedback message.
9. a kind of access control apparatus, which is characterized in that the device includes:
First generation module, please for being obtained in the address that Broadband Remote Access Server BRAS is sent according to the host received After asking, address prefix is generated;
First sending module, for described address prefix to be sent to the host, to trigger the host generation internet protocol IPv6 addresses are discussed, and the address notification message of the IPv6 addresses is carried to BRAS feedbacks;The IPv6 addresses are by described The address prefix and the address suffix composition of host generation that BRAS is sent;
For the described address notification message according to reception, access service is provided for the host for access service module.
10. device according to claim 9, which is characterized in that first generation module is additionally operable to:Generate address prefix Afterwards, described address prefix is preserved, described address obtains the MAC Address carried in request and VLAN is identified and described address Obtain the correspondence between the receiving port mark of request;
The access service module, is specifically used for:Address prefix is extracted from the IPv6 addresses that described address notification message carries;
The address prefix extracted from IPv6 addresses, the MAC Address that described address notification message carries and VLAN marks are detected, with And whether meet the correspondence of preservation between the receiving port mark of address notification message;
When meeting the correspondence, access service is provided for the host based on the IPv6 addresses.
11. device according to claim 10, which is characterized in that first generation module is specifically used for:Based on described Address prefix and described address obtain the MAC Address carried in request and VLAN marks and described address is obtained and asked The receiving port mark generation software sessions list item asked;
The access service module, is specifically used for:The IPv6 addresses are added in the software sessions list item, and based on institute It states software sessions list item and provides access service for the host.
12. device according to claim 10, which is characterized in that first generation module is additionally operable to:It is described to receive master After the address that machine is sent obtains request, temporary address suffix is generated;The temporary address based on described address prefix, generation Suffix and described address obtain the MAC Address carried in request and VLAN marks and described address obtains request Receiving port mark generation software sessions SESSION list items;
The access service module, is specifically used for:The described address suffix carried in the IPv6 addresses is detected, with finding MAC Address, VLAN marks and described address are obtained in the software sessions list item at receiving port mark place of request Whether temporary address suffix is consistent;
If consistent, access service is provided for the host based on the temporary address suffix in the software sessions list item;
If it is inconsistent, the described address suffix extracted from the IPv6 is added in the software sessions list item, and Based on the newly added address suffix of software sessions list item access service is provided for the host.
13. device according to claim 9, which is characterized in that the access service module is specifically used for:According to described The IPv6 addresses that are carried in the notification message of address, MAC Address, VLAN marks, from the reception with described address notification message The corresponding receiving port of port-mark sends probe message to the host;
If the feedback message that host is sent according to the probe message is received in preset time, according to reception Address notification message provides access service for the host.
14. device according to claim 9, which is characterized in that first generation module, specifically for according to described Location obtains the medium access control MAC Address carried in request, initiates certification request to certificate server, and is receiving certification The certification of server feedback is by generating described address prefix after information.
15. a kind of access control apparatus, which is characterized in that the device includes:
Second sending module sends address to Broadband Remote Access Server BRAS for host and obtains request;
Second receiving module obtains the address prefix of request return for receiving the BRAS according to described address;
Second generation module, for generating address suffix, and by the described address prefix received from the BRAS and described Location suffix is combined into IPv6 addresses;
Second sending module is additionally operable to send address notification message to the BRAS;Described in being carried in described address notification message IPv6 addresses.
16. device according to claim 15, which is characterized in that the device further includes:Feedback module is detected, receives BRAS The probe message of transmission;IPv6 addresses, MAC Address, VLAN marks are carried in the probe message;
In preset time, identified according to the IPv6 addresses, MAC Address, VLAN to the BRAS and send feedback message, so that The BRAS is received and is provided access service for the host after the feedback message.
CN201711430183.0A 2017-12-26 2017-12-26 A kind of connection control method and device Pending CN108123857A (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201711430183.0A CN108123857A (en) 2017-12-26 2017-12-26 A kind of connection control method and device

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201711430183.0A CN108123857A (en) 2017-12-26 2017-12-26 A kind of connection control method and device

Publications (1)

Publication Number Publication Date
CN108123857A true CN108123857A (en) 2018-06-05

Family

ID=62231740

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201711430183.0A Pending CN108123857A (en) 2017-12-26 2017-12-26 A kind of connection control method and device

Country Status (1)

Country Link
CN (1) CN108123857A (en)

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN109327558A (en) * 2018-10-30 2019-02-12 新华三技术有限公司合肥分公司 Address management method and device
CN111586197A (en) * 2020-04-23 2020-08-25 中国信息通信研究院 Method and device for redistributing address prefixes
CN112995103A (en) * 2019-12-17 2021-06-18 中国电信股份有限公司 Data verification method, device and computer readable storage medium
CN115277138A (en) * 2022-07-15 2022-11-01 绿盟科技集团股份有限公司 Mandatory access control method and device

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102143050A (en) * 2010-09-29 2011-08-03 华为终端有限公司 Network connection processing method and device for internet protocol version 6 (IPv6) network
EP2482500A1 (en) * 2009-10-26 2012-08-01 ZTE Corporation Method for performing dynamic tunnel message forwarding and switch thereof
CN104639439A (en) * 2015-01-27 2015-05-20 杭州华三通信技术有限公司 Service message processing method and service message processing device

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP2482500A1 (en) * 2009-10-26 2012-08-01 ZTE Corporation Method for performing dynamic tunnel message forwarding and switch thereof
CN102143050A (en) * 2010-09-29 2011-08-03 华为终端有限公司 Network connection processing method and device for internet protocol version 6 (IPv6) network
CN104639439A (en) * 2015-01-27 2015-05-20 杭州华三通信技术有限公司 Service message processing method and service message processing device

Cited By (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN109327558A (en) * 2018-10-30 2019-02-12 新华三技术有限公司合肥分公司 Address management method and device
CN112995103A (en) * 2019-12-17 2021-06-18 中国电信股份有限公司 Data verification method, device and computer readable storage medium
CN112995103B (en) * 2019-12-17 2022-08-02 中国电信股份有限公司 Data verification method, device and computer readable storage medium
CN111586197A (en) * 2020-04-23 2020-08-25 中国信息通信研究院 Method and device for redistributing address prefixes
CN111586197B (en) * 2020-04-23 2022-04-15 中国信息通信研究院 Method and device for redistributing address prefixes
CN115277138A (en) * 2022-07-15 2022-11-01 绿盟科技集团股份有限公司 Mandatory access control method and device
CN115277138B (en) * 2022-07-15 2023-09-22 绿盟科技集团股份有限公司 Forced access control method and device

Similar Documents

Publication Publication Date Title
US8984112B2 (en) Internet address information processing method, apparatus, and internet system
CN108123857A (en) A kind of connection control method and device
CN108259299B (en) Forwarding table item generating method and device and machine-readable storage medium
CN104219340A (en) ARP (Address Resolution Protocol) response proxy method and apparatus
US10372775B2 (en) Anonymous identity in identity oriented networks and protocols
US20130067043A1 (en) Recording Stateless IP Addresses
CN106559292A (en) A kind of broad band access method and device
US9769113B1 (en) Socket-based internet protocol for wireless networks
US9148401B2 (en) Method for obtaining IP address of DHCPV6 server, DHCPV6 server, and DHCPV6 communication system
CN106921578B (en) Method and device for generating forwarding table item
US9479490B2 (en) Methods and systems for single sign-on while protecting user privacy
CN103763195B (en) A kind of method and device of transmitting message
CN107547528A (en) IPv6 stateless address distribution method and device
US8381301B1 (en) Split-flow attack detection
CN107623757A (en) Entry updating method and apparatus
CN106302353A (en) Identity identifying method, identity authorization system and relevant device
WO2014142258A1 (en) Communication system, control device, address allocation method, and program
CN105939519A (en) Authentication method and device
CN107517129B (en) Method and device for configuring uplink interface of equipment based on OpenStack
CN104253878A (en) VLAN (Virtual Local Area Network) information management system and method of DHCP (Dynamic Host Configuration Protocol) RELAY termination sub-interface
WO2014040279A1 (en) Information processing method and load balancing device
CN114422474B (en) User IPv6 address generating method based on RADIUS server
US10044672B2 (en) IPv6 address assignment method and apparatus
WO2017219816A1 (en) Data transmission method and network address translation device
CN105072669B (en) The connection control method and device of website

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination
RJ01 Rejection of invention patent application after publication

Application publication date: 20180605

RJ01 Rejection of invention patent application after publication