WO2012083655A1 - 一种跨虚拟局域网的组播业务处理方法及设备 - Google Patents

一种跨虚拟局域网的组播业务处理方法及设备 Download PDF

Info

Publication number
WO2012083655A1
WO2012083655A1 PCT/CN2011/075931 CN2011075931W WO2012083655A1 WO 2012083655 A1 WO2012083655 A1 WO 2012083655A1 CN 2011075931 W CN2011075931 W CN 2011075931W WO 2012083655 A1 WO2012083655 A1 WO 2012083655A1
Authority
WO
WIPO (PCT)
Prior art keywords
vlan
multicast
multicast service
destination
mapping relationship
Prior art date
Application number
PCT/CN2011/075931
Other languages
English (en)
French (fr)
Inventor
吴志辉
Original Assignee
中兴通讯股份有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 中兴通讯股份有限公司 filed Critical 中兴通讯股份有限公司
Publication of WO2012083655A1 publication Critical patent/WO2012083655A1/zh

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L12/00Data switching networks
    • H04L12/02Details
    • H04L12/16Arrangements for providing special services to substations
    • H04L12/18Arrangements for providing special services to substations for broadcast or conference, e.g. multicast

Definitions

  • the present invention belongs to the field of communications technologies, and in particular, to a multicast service processing method and device across a virtual local area network. Background technique
  • IPTV Interactive Personality TV
  • IGMP Internet Group Management Protocol
  • VLAN Virtual Local Area Network
  • Most operators use port division 802.1q.
  • VLANs are used to isolate and locate users. Therefore, when multicast is implemented, users are usually in different VLANs. If standard IGMP Snooping is used at this time, a multicast will be established inside each VLAN. The flow can not achieve the effect of saving network bandwidth.
  • the cross-VLAN multicast technology can solve this problem well.
  • FIG. 1 is a schematic diagram of the IPTV service networking.
  • a multicast program source A is from the network.
  • the side VLAN 2600 is sent to the DSLAM (Digital Subscriber Line Access Multiplexer).
  • the DSLAM is shown as an example of the ZXDSL9806.
  • For the user 1 belonging to VLAN 3601 and the user belonging to VLAN 3602 2 For example, when they order program A, DSLAM will copy the stream of program A from VLAN 2600 to User 1 and User 2.
  • program A there is always only one data stream between the DSLAM and the upper device, thus achieving the maximum bandwidth saving. Therefore, cross-VLAN multicasting in the access network is an essential function of the DSLAM or access node.
  • the access network devices support the inter-VLAN multicast technology.
  • the multicast group field in the packet is verified, and the multicast to be added is parsed.
  • the VLAN is used to achieve the purpose of requesting cross-VLAN multicast by the user side.
  • the disadvantage of this type of processing is that: Allowing multicast requests from any VLAN on the user side has certain hidden dangers for network security. Summary of the invention
  • the technical problem to be solved by the present invention is to provide a method and a device for processing multicast services across a virtual local area network, so as to improve security in providing multicast services across virtual local area networks.
  • a method for processing a multicast service across a virtual local area network (VLAN) is provided in the embodiment of the present invention, where the method includes:
  • VID virtual local area network identifier
  • the embodiment of the present invention further provides a multicast service processing device across a virtual local area network, where the device includes:
  • mapping relationship module configured to maintain a mapping relationship between a source VLAN that provides a multicast service and a destination VLAN that receives the multicast service
  • the judging module is configured to obtain the VID in the multicast request packet and parse the VLAN to be added to the multicast according to the multicast group address in the multicast request packet, and if the source VLAN of the mapping relationship is successfully matched, If the VLAN that joins the multicast matches the destination VLAN of the mapping relationship, If the source VLAN of the mapping relationship fails to be matched, or the VLAN to be added to the multicast VLAN fails to match the destination VLAN of the mapping relationship, the packet is discarded.
  • the first is to maintain a mapping relationship between a source VLAN that provides a multicast service and a destination VLAN that receives the multicast service; and then obtain a multicast request, the VID in the message, and the multicast request.
  • the multicast group address in the text is back-analyzed to the VLAN to be added to the multicast. If the source VLAN of the mapping relationship between the VID and the mapping is successful, and the destination VLAN to be added to the multicast VLAN matches the destination VLAN, the multicast service is provided. If the source VLAN of the mapping relationship fails to match or the VLAN to be added to the multicast fails to match the destination VLAN of the mapping, the packet is discarded.
  • the access network device supports the inter-VLAN multicast processing of the multicast protocol packet on the user side, the VID field of the packet and the multicast VLAN to be joined must be verified, instead of the prior art.
  • the technical solution provided by the embodiment of the present invention can improve the security of the network.
  • FIG. 1 is a schematic diagram of networking of an IPTV service in the background art
  • FIG. 2 is a schematic flow chart of a method for processing a multicast service across a virtual local area network according to an embodiment of the present invention
  • FIG. 3 is a schematic flowchart of implementing a cross-VLAN multicast service processing method of a ZXDSL 9806H access device according to an embodiment of the present invention
  • FIG. 4 is a schematic structural diagram of a multicast service processing device across a virtual local area network according to an embodiment of the present invention. detailed description
  • VID Virtual Local Area Network Identification
  • the technical solution provided by the embodiment of the present invention is to perform a purposeful check on the VID field of the multicast protocol packet on the user side, and allow a legitimate user VLAN to make a request, but is illegal.
  • the VLANs are directly discarded, thereby enabling controllable user multicast request management.
  • FIG. 2 is a schematic diagram of a process for implementing a multicast service processing method across a virtual local area network. As shown in FIG. 2, the method includes the following steps:
  • Step 201 Maintain a mapping relationship between a source VLAN that provides the multicast service and a destination VLAN that receives the multicast service.
  • Step 202 Obtain a VID in the multicast request message, and parse the VLAN to be added to the multicast according to the multicast group address in the multicast request. If the source VLAN of the VID and the mapping relationship are successfully matched, the group wants to join the group. If the matching VLAN is successfully matched with the destination VLAN of the mapping relationship, the multicast service is provided. If the matching between the VID and the source VLAN of the mapping relationship fails, or the destination VLAN of the VLAN to be added to the multicast relationship fails to match, the destination VLAN is invalid. throw away.
  • the multicast request message may be an IGMP message
  • the IGMP message includes a report message and/or a leave message.
  • the method may further include: starting a cross-VLAN multicast service.
  • the network device maintains a mapping table between the source VLAN list and the destination VLAN list, and serves as a global control table for verifying the VID field of the user-side multicast packet, and simultaneously opens the cross-VLAN multicast function.
  • the network device extracts the user-side IGMP message (including the report and/or the leave message), and matches the VID in the packet with the source VLAN list of the mapping table. If the matching succeeds, the destination VLAN list is matched. Otherwise, the request fails. Discard According to the multicast group address in the text, the multicast VLAN to be added is matched with the VLAN list of the mapping entry, and the match is successfully entered into the multicast group request. Otherwise, the request fails and the packet is discarded.
  • mapping between the source VLAN that provides the multicast service and the destination VLAN that receives the multicast service when the mapping between the source VLAN that provides the multicast service and the destination VLAN that receives the multicast service is maintained, the mapping between the source VLAN that provides the multicast service and the destination VLAN that receives the multicast service can be maintained for each user.
  • control table can be maintained for each user at the same time without affecting the performance of the device.
  • the user-side IGMP message For the user-side IGMP message to be checked globally and at the port level, the user can be further differentiated. control.
  • a commercially available network device on which the present invention (and related inventions) can be implemented is a ZXDSL 9806H access device produced by ZTE Corporation, and the following is combined with the ZXDSL 9806H access device for the present invention.
  • the embodiment is further described in detail to better understand the implementation of the present invention.
  • the ZXDSL 9806H access device is taken as an example because the device is widely used, and the device can be used as a small-sized DSLAM device.
  • the broadband integrated access platform of the capacity Multi-Play service, so the ZXDSL 9806H access device is taken as an example here; however, in theory, other network devices are also possible, as long as it can maintain the source VLAN and destination VLAN of the user.
  • the ZXDSL 9806H access device is only used to explain to the person skilled in the art how to implement the invention, but it does not mean that only the ZXDSL 9806H access device can be used.
  • all IGMP-enabled broadband access devices including ONUs ( Optical Network Unit, Optical Network Unit, MDU (Multiple User Residential Unit), EOC (Ethernet over Coax, Ethernet data transmission via coaxial cable), etc., can be determined in practice The corresponding network device.
  • the multicast stream A (the multicast group IP is 224.1.1.1) sent by the multicast server is in VLAN 2600, and the VLANs designated for User 1 and User 2 are 3601 and 3602 respectively; 9806H devices
  • the configuration is as follows:
  • User port 2 is a multicast VLAN receiving port.
  • User port 1 configure VLAN mapping table T1 "3601 to 2600”
  • user port 2 configure VLAN mapping table T2 "3602 to 2600”
  • FIG. 3 is a schematic flowchart of a method for processing a cross-VLAN multicast service on a ZXDSL 9806H access device.
  • the processing procedure includes the following steps. :
  • Step 301 The user port receives the multicast request packet.
  • Step 302 Determine whether the user VLAN is consistent with the configured multicast VLAN. If yes, go to step 307. If no, go to step 303.
  • Step 303 Determine whether to initiate cross-VLAN multicasting. If yes, go to step 304. If no, go to step 308.
  • Step 304 Determine whether the user VLAN matches the configured VLAN mapping table. If yes, go to step 305. If no, go to step 308.
  • the VID in the multicast request packet is matched with the source VLAN in the mapping table T and T1. If the matching succeeds, the process proceeds to step 305. Otherwise, the packet is discarded.
  • Step 305 Parse the multicast VLAN to be joined.
  • Step 306 Determine whether the multicast VLAN matches the configured VLAN mapping table. If yes, go to step 307. If no, go to step 308.
  • the multicast protocol is parsed, and the multicast VLAN 2600 in which the multicast group 224.1.1.1 is located is parsed, and the destination VLANs in the mapping tables T and T1 are matched. Go to step 307, otherwise exit and the message is discarded.
  • Step 307 Enter the multicast protocol processing.
  • Step 308 The packet is discarded.
  • steps 307 and 308 standard multicast protocol processing is performed according to the above-mentioned judgment flow, and the user 1 is allowed or denied to receive the multicast stream A.
  • VLAN mapping tables T, Tl, and ⁇ 2 configured by the above 9806H devices, it can be ensured that the multicast requests from User 1 and User 2 must go through VLAN 3601 and VLAN 3602 respectively, which can better manage multicast users.
  • the embodiment of the present invention further provides a multicast service processing device across a virtual local area network.
  • the principle of the device solving the problem is similar to that of a multicast service processing method across a virtual local area network.
  • Implementation can refer to the implementation of the method, and the repetition will not be repeated.
  • FIG. 4 is a schematic diagram of the structure of a multicast service processing device across a virtual local area network. As shown in Figure 4, the multicast service processing device across the virtual local area network includes:
  • the mapping relationship module 401 is configured to maintain a mapping relationship between a source VLAN that provides a multicast service and a destination VLAN that receives the multicast service.
  • the determining module 402 is configured to obtain the VID in the multicast request packet, and inversely parse the VLAN to be added to the multicast according to the multicast group address in the multicast request packet, if the source VLAN of the VID and the mapping relationship is successfully matched, and If the destination VLAN of the VLAN to be added to the multicast match is successful, the multicast service is provided. If the source VLAN of the mapping relationship fails to match, or the destination VLAN to be added to the multicast VLAN fails to match the destination VLAN, 4 ⁇ text discarded.
  • the judging module can also be used to perform matching judgment according to the IGMP message.
  • the determining module may be further configured to perform matching determination according to the report message and/or the leave message in the IGMP message.
  • the mapping relationship module is also used to maintain the source VLAN and receive the multicast service.
  • the mapping between the source VLAN of the multicast service and the destination VLAN of the receiving multicast service is maintained for each user.
  • the judging module can also be used to start the cross-VLAN multicast service before the matching judgment.
  • the first is to maintain a mapping relationship between a source VLAN that provides a multicast service and a destination VLAN that receives the multicast service; and then obtain a VID in the multicast request packet.
  • the VLAN to be added to the multicast is reversely parsed according to the multicast group address in the multicast request packet. If the source VLAN of the mapping relationship between the VID and the mapping is successful, and the destination VLAN of the mapping relationship is successfully matched, If the matching of the source VLAN of the mapping between the VID and the mapping fails, or if the VLAN to be added to the multicast fails to match the destination VLAN of the mapping, the packet is discarded.
  • the access network device supports the cross-VLAN multicast processing on the user-side multicast protocol
  • the VID field of the packet and the multicast VLAN to be added must be verified, instead of the prior art.
  • the technical solution provided by the embodiment of the present invention can improve the security of the network.
  • embodiments of the present invention can be provided as a method, system, or computer program product. Accordingly, the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment, or a combination of software and hardware. Moreover, the invention can be embodied in the form of one or more computer program products embodied on a computer-usable storage medium (including but not limited to disk storage, CD-ROM, optical storage, etc.) in which computer usable program code is embodied.
  • a computer-usable storage medium including but not limited to disk storage, CD-ROM, optical storage, etc.
  • the present invention is directed to a method, apparatus (system), and computer program in accordance with an embodiment of the present invention.
  • the flow chart and/or block diagram of the product is described. It will be understood that each flow and/or block of the flowchart illustrations and/or FIG.
  • These computer program instructions can be provided to a processor of a general purpose computer, special purpose computer, embedded processor, or other programmable data processing device to produce a machine for the execution of instructions for execution by a processor of a computer or other programmable data processing device.
  • the computer program instructions can also be stored in a computer readable memory that can direct a computer or other programmable data processing device to operate in a particular manner, such that instructions stored in the computer readable memory produce an article of manufacture comprising the instruction device.
  • a device implements the functions specified in one or more blocks of a flow or a flow and/or block diagram of a flowchart.
  • These computer program instructions can also be loaded onto a computer or other programmable data processing device such that a series of operational steps are performed on a computer or other programmable device to produce computer-implemented processing for execution on a computer or other programmable device.
  • the instructions provide steps for implementing the functions specified in one or more of the flow or in a block or blocks of a flow diagram.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Small-Scale Networks (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Description

一种跨虚拟局域网的组播业务处理方法及设备 技术领域
本发明属于通信技术领域, 尤其涉及一种跨虚拟局域网的组播业务处 理方法及设备。 背景技术
随着宽带接入技术和 IPTV ( Interactive Personality TV, 个性化的互动 的电视)业务的迅猛发展, IPTV对接入网络的要求也越来越高, 一方面要 求接入网设备更灵活的支持组播业务, 另一方面又要考虑到网络安全的问 题。 标准 IGMP Snooping ( IGMP探听, IGMP: Internet Group Management Protocol, 因特网组管理协议)功能只提供同一 VLAN ( Virtual Local Area Network,虚拟局域网)内的组播功能,而大多数运营商釆用端口划分 802.1q VLAN 的方式进行用户的隔离与定位, 因此在实施组播的时候, 用户通常 是处于不同 VLAN之中的, 如果这时候还釆用标准 IGMP Snooping, 会导 致每个 VLAN内部都要建立一条组播流, 最终无法达到节省网络带宽的效 果; 釆用跨 VLAN组播技术则可以很好地解决这个问题, 图 1为 IPTV业 务组网示意图, 如图 1所示, 某组播节目源 A从网络侧 VLAN 2600下发到 DSLAM ( Digital Subscriber Line Access Multiplexer, 数字用户线接入复用 器),图中 DSLAM是以 ZXDSL9806为例进行示意的,对于属于 VLAN 3601 的用户 1和属于 VLAN 3602的用户 2来说 ,当他们点播了节目 A时, DSLAM 就会将节目 A的数据流从 VLAN 2600复制给用户 1和用户 2。 对于节目 A 来说, DSLAM与上层设备之间一直只存在一个数据流, 这样就达到了最大 程度节省带宽的目的。 因此, 在接入网络实现跨 VLAN组播是 DSLAM或 接入节点必不可少的功能。 目前大多数的接入网设备都支持跨 VLAN组播技术, 在处理用户侧的 组播协议报文时, 通过对报文中的组播组字段进行校验, 反解析出需要加 入的组播 VLAN, 从而达到用户侧请求跨 VLAN组播的目的。 但是这种处 理方式的不足在于: 允许用户侧任意 VLAN过来的组播请求, 对于网络安 全存在着一定隐患。 发明内容
有鉴于此, 本发明所解决的技术问题在于提供一种跨虚拟局域网的组 播业务处理方法及设备, 用以提高提供跨虚拟局域网组播业务过程中的安 全性。
本发明实施例中提供了一种跨虚拟局域网(VLAN )的组播业务处理方 法, 该方法包括:
维护提供组播业务的源 VLAN与接收组播业务的目的 VLAN的映射关 系;
获取组播请求报文中的虚拟局域网标识 VID以及根据组播请求报文中 的组播组地址反解析出欲加入组播的 VLAN,若 VID与映射关系的源 VLAN 匹配成功, 且欲加入组播的 VLAN与映射关系的目的 VLAN匹配成功, 则 提供组播业务, 若 VID与映射关系的源 VLAN匹配失败, 或欲加入组播的 VLAN与映射关系的目的 VLAN匹配失败, 则将 4艮文丟弃。
本发明实施例中还提供一种跨虚拟局域网的组播业务处理设备, 该设 备包括:
映射关系模块, 用于维护提供组播业务的源 VLAN与接收组播业务的 目的 VLAN的映射关系;
判断模块, 用于获取组播请求报文中的 VID以及根据组播请求报文中 的组播组地址反解析出欲加入组播的 VLAN,若 VID与映射关系的源 VLAN 匹配成功, 且欲加入组播的 VLAN与映射关系的目的 VLAN匹配成功, 则 提供组播业务, 若 VID与映射关系的源 VLAN匹配失败, 或欲加入组播的 VLAN与映射关系的目的 VLAN匹配失败, 则将 4艮文丟弃。
本发明有益效果如下:
由于在本发明实施例提供的技术方案中, 首先是维护提供组播业务的 源 VLAN与接收组播业务的目的 VLAN的映射关系; 然后在获取组播请求 才艮文中的 VID以及根据组播请求 ^艮文中的组播组地址反解析出欲加入组播 的 VLAN,若 VID与映射关系的源 VLAN匹配成功且欲加入组播的 VLAN 与映射关系的目的 VLAN匹配成功, 则提供组播业务, 若 VID与映射关系 的源 VLAN匹配失败或欲加入组播的 VLAN与映射关系的目的 VLAN匹配 失败, 则将报文丟弃。 也即, 接入网设备在支持跨 VLAN组播处理用户侧 的组播协议报文时, 对报文的 VID字段、 以及需要加入的组播 VLAN都要 进行校验, 而不是如现有技术般允许用户侧任意 VLAN过来的组播请求, 显然, 本发明实施例提供的技术方案能够提高网络的安全性。 附图说明
图 1为背景技术中 IPTV业务组网示意图;
图 2为本发明实施例中跨虚拟局域网的组播业务处理方法实施流程示 意图;
图 3为本发明实施例中 ZXDSL 9806H接入设备的跨 VLAN的组播业 务处理方法实施流程示意图;
图 4为本发明实施例中跨虚拟局域网的组播业务处理设备结构示意图。 具体实施方式
发明人在发明过程中注意到: 目前大多数的接入网设备都支持跨 VLAN组播技术, 但是, 在处理用户侧的组播协议报文时, 对报文的 VID (虚拟局域网标识) 字段不进行校验, 而是通过对报文中的组播组字段进 行校验, 反解析出需要加入的组播 VLAN , 从而达到用户侧请求跨 VLAN 组播的目的。这种处理方式允许用户侧任意 VLAN过来的组播请求, 显然, 这种处理方式对于网络安全来说是存在着一定隐患的。
本发明实施例提供的技术方案是在跨 VLAN组播的基础上, 通过对用 户侧的组播协议报文的 VID 字段进行有目的性的校验, 允许合法的用户 VLAN进行请求, 而对于非法的 VLAN直接丟弃, 从而实现可控制的用户 组播请求管理。 下面结合附图对本发明的具体实施方式进行说明。
图 2为跨虚拟局域网的组播业务处理方法实施流程示意图, 如图 2所 示, 该方法包括如下步骤:
步骤 201、维护提供组播业务的源 VLAN与接收组播业务的目的 VLAN 的映射关系;
步骤 202、 获取组播请求 4艮文中的 VID 以及根据组播请求 ^艮文中的组 播组地址反解析出欲加入组播的 VLAN, 若 VID与映射关系的源 VLAN匹 配成功, 且欲加入组播的 VLAN与映射关系的目的 VLAN匹配成功, 则提 供组播业务, 若 VID与映射关系的源 VLAN 匹配失败, 或欲加入组播的 VLAN与映射关系的目的 VLAN匹配失败, 则将 4艮文丟弃。
实施中, 组播请求报文可以是 IGMP报文, 该 IGMP报文包括 report (报告 )报文和 /或 leave (离开)报文。
实施中, 在匹配判断之前, 还可以包括: 启动跨 VLAN组播业务。 具体的,网络设备维护一张源 VLAN列表与目的 VLAN列表的映射表, 作为校验用户侧组播报文 VID字段的全局控制表, 同时打开跨 VLAN组播 功能;
然后, 网络设备提取用户侧 IGMP报文(包括 report和 /或 leave报文), 将报文中的 VID与映射表源 VLAN 列表进行匹配, 匹配成功则进行目的 VLAN列表匹配, 否则请求失败, 报文丟弃; 根据 4艮文中的组播组地址反解析出欲加入的组播 VLAN与映射表目的 VLAN 列表进行匹配, 匹配成功进入组播组请求, 否则请求失败, 报文丟 弃;
实施中, 在维护提供组播业务的源 VLAN 与接收组播业务的目的 VLAN的映射关系时, 可以为每一个用户维护提供组播业务的源 VLAN与 接收组播业务的目的 VLAN的映射关系。
具体的, 在不影响设备性能的条件下, 还可以同时为每一个用户维护 一张控制表, 对于用户侧 IGMP报文进行全局和端口级的校验, 可以进一 步对每一个用户进行有区分的控制。
一个市场上可买到的可在其上实现本发明 (以及相关发明) 实施例的 网络设备是来自中兴通讯股份有限公司生产的 ZXDSL 9806H接入设备,下 面结合 ZXDSL 9806H接入设备对本发明的具体实施方式做进一步详细说 明, 以便更好的理解本发明的实施, 在实施中以 ZXDSL 9806H接入设备为 例是因为该设备运用较为广泛, 该设备可以作为小型 DSLAM设备, 是主 流的下一代小容量 Multi-Play业务的宽带综合接入平台,所以这里以 ZXDSL 9806H接入设备为例; 但是, 从理论上来说, 用其它的网络设备也是可以 的, 只要其能够维护用户的源 VLAN与目的 VLAN的映射关系列表, 并获 取组播请求 4艮文中的 VID以及根据组播请求 ^艮文中的组播组地址反解析出 欲加入组播的 VLAN , 且具备与映射关系列表中的内容进行匹配比较的判 断能力既可。 ZXDSL 9806H接入设备仅用于向本领域技术人员解释具体如 何实施本发明, 但不意味仅能使用 ZXDSL 9806H接入设备这一设备, 事 实上, 所有支持 IGMP的宽带接入设备, 包括 ONU ( Optical Network Unit , 光网络单元)、 MDU ( Multiple Dwelling Unit, 多用户居住单元)、 EOC ( Ethernet over Coax, 以太网数据通过同轴电缆传输)等设备都可以, 实施 过程中可以结合实践需要来确定相应的网络设备。 以图 1所示环境为例, 假设组播服务器发出的组播流 A (组播组 IP为 224.1.1.1 )在 VLAN 2600, 为用户 1和用户 2指定的 VLAN分别为 3601 和 3602; 9806H设备配置如下:
1、 创建组播 VLAN 2600, 组播组 224.1.1.1;
2、 添加用户端口 1、 用户端口 2为组播 VLAN接收端口;
3、启动跨 VLAN组播,配置全局 VLAN映射表 T"3601~3602 to 2600" ;
4、 用户端口 1配置 VLAN映射表 T1 "3601 to 2600" , 用户端口 2配 置 VLAN映射表 T2 "3602 to 2600" ,
图 3为 ZXDSL 9806H接入设备的跨 VLAN的组播业务处理方法实施 流程示意图, 如图 3所示, 当 9806H设备收到用户 1对组播流 A的组播请 求时, 处理流程包括如下步骤:
步骤 301、 用户端口收到组播请求报文。
步骤 302、 判断用户 VLAN是否与配置的组播 VLAN—致, 如果是, 转入步骤 307, 如果否, 转入步骤 303。
步骤 303、 判断是否启动跨 VLAN组播, 如果是, 转入步骤 304, 如果 否, 转入步骤 308。
步骤 304、判断用户 VLAN是否与配置的 VLAN映射表匹配,如果是, 转入步骤 305 , 如果否, 转入步骤 308。
本步骤中, 将组播请求报文中的 VID与映射表 T和 T1中的源 VLAN 进行匹配, 匹配成功的话, 进入步骤 305, 否则退出, 4艮文丟弃。
步骤 305、 解析出欲加入的组播 VLAN。
步骤 306、判断组播 VLAN是否与配置的 VLAN映射表匹配,如果是, 转入步骤 307, 如果否, 转入步骤 308。
本步骤中, 进行组播^艮文解析流程, 解析出组播组 224.1.1.1所在的组 播 VLAN2600 , 与映射表 T和 T1中的目的 VLAN进行匹配, 如果匹配成 功, 进入步骤 307, 否则退出, 报文丟弃。
步骤 307、 进入组播协议处理。
步骤 308、 报文丟弃。
在步骤 307、 308中, 根据上述判断流程进行标准的组播协议处理, 允 许或拒绝用户 1接收组播流 A。
通过以上 9806H设备配置的 VLAN映射表 T、 Tl、 Τ2, 就可以保证从 用户 1和用户 2过来的组播请求必须分别走 VLAN 3601和 VLAN 3602,可 以更好地对组播用户进行管理。
基于同一发明构思, 本发明实施例中还提供了一种跨虚拟局域网的组 播业务处理设备, 由于该设备解决问题的原理与一种跨虚拟局域网的组播 业务处理方法相似, 因此该设备的实施可以参见方法的实施, 重复之处不 再赘述。
图 4为跨虚拟局域网的组播业务处理设备结构示意图, 如图 4所示, 跨虚拟局域网的组播业务处理设备包括:
映射关系模块 401 , 用于维护提供组播业务的源 VLAN与接收组播业 务的目的 VLAN的映射关系;
判断模块 402, 用于获取组播请求报文中的 VID以及根据组播请求报 文中的组播组地址反解析出欲加入组播的 VLAN , 若 VID与映射关系的源 VLAN匹配成功, 且欲加入组播的 VLAN与映射关系的目的 VLAN匹配成 功, 则提供组播业务, 若 VID与映射关系的源 VLAN匹配失败, 或欲加入 组播的 VLAN与映射关系的目的 VLAN匹配失败, 则将 4艮文丟弃。
实施中, 判断模块还可以用于根据 IGMP报文进行匹配判断。
实施中, 判断模块还可以用于根据所述 IGMP报文中的 report报文和 / 或 leave 4艮文进行匹配判断。
实施中, 映射关系模块还用于在维护提供组播业务的源 VLAN与接收 组播业务的目的 VLAN的映射关系时, 为每一个用户维护提供组播业务的 源 VLAN与接收组播业务的目的 VLAN的映射关系。
实施中, 判断模块还可以用于在匹配判断之前, 启动跨 VLAN组播业 务。
为了描述的方便, 以上所述设备的各部分以功能分为各种模块或单元 分别描述。 当然, 在实施本发明时可以把各模块或单元的功能在同一个或 多个软件或硬件中实现。
由上述实施例可见, 在本发明实施例提供的技术方案中, 首先是维护 提供组播业务的源 VLAN与接收组播业务的目的 VLAN的映射关系; 然后 在获取组播请求报文中的 VID以及根据组播请求报文中的组播组地址反解 析出欲加入组播的 VLAN, 若 VID与映射关系的源 VLAN匹配成功且欲加 入组播的 VLAN与映射关系的目的 VLAN匹配成功, 则提供组播业务, 若 VID与映射关系的源 VLAN匹配失败或欲加入组播的 VLAN与映射关系的 目的 VLAN匹配失败, 则将 4艮文丟弃。 也即, 接入网设备在支持跨 VLAN 组播处理用户侧的组播协议 文时, 对 ^艮文的 VID字段、 以及需要加入的 组播 VLAN都要进行校验, 而不是如现有技术般允许用户侧任意 VLAN过 来的组播请求, 显然, 本发明实施例提供的技术方案能够提高网络的安全 性。
本领域内的技术人员应明白, 本发明的实施例可提供为方法、 系统、 或计算机程序产品。 因此, 本发明可釆用完全硬件实施例、 完全软件实施 例、 或结合软件和硬件方面的实施例的形式。 而且, 本发明可釆用在一个 或多个其中包含有计算机可用程序代码的计算机可用存储介质 (包括但不 限于磁盘存储器、 CD-ROM、 光学存储器等)上实施的计算机程序产品的 形式。
本发明是参照根据本发明实施例的方法、 设备(系统)、 和计算机程序 产品的流程图和 /或方框图来描述的。 应理解可由计算机程序指令实现流 程图和 /或方框图中的每一流程和 /或方框、 以及流程图和 /或方框图中 的流程和 /或方框的结合。 可提供这些计算机程序指令到通用计算机、 专 用计算机、 嵌入式处理机或其他可编程数据处理设备的处理器以产生一个 机器, 使得通过计算机或其他可编程数据处理设备的处理器执行的指令产 生用于实现在流程图一个流程或多个流程和 /或方框图一个方框或多个方 框中指定的功能的设备。
这些计算机程序指令也可存储在能引导计算机或其他可编程数据处理 设备以特定方式工作的计算机可读存储器中, 使得存储在该计算机可读存 储器中的指令产生包括指令设备的制造品, 该指令设备实现在流程图一个 流程或多个流程和 /或方框图一个方框或多个方框中指定的功能。
这些计算机程序指令也可装载到计算机或其他可编程数据处理设备 上, 使得在计算机或其他可编程设备上执行一系列操作步骤以产生计算机 实现的处理, 从而在计算机或其他可编程设备上执行的指令提供用于实现 在流程图一个流程或多个流程和 /或方框图一个方框或多个方框中指定的 功能的步骤。
尽管已描述了本发明的优选实施例, 但本领域内的技术人员一旦得知 了基本创造性概念, 则可对这些实施例作出另外的变更和修改。 所以, 所 附权利要求意欲解释为包括优选实施例以及落入本发明范围的所有变更和 修改。 本发明的精神和范围。 这样, 倘若本发明的这些修改和变型属于本发明权 利要求及其等同技术的范围之内, 则本发明也意图包含这些改动和变型在 内。

Claims

权利要求书
1、 一种跨虚拟局域网 (VLAN ) 的组播业务处理方法, 其特征在于, 该方法包括:
维护提供组播业务的源 VLAN与接收组播业务的目的 VLAN的映射关 系;
获取组播请求报文中的虚拟局域网标识 VID以及根据组播请求报文中 的组播组地址反解析出欲加入组播的 VLAN,若 VID与映射关系的源 VLAN 匹配成功, 且欲加入组播的 VLAN与映射关系的目的 VLAN匹配成功, 则 提供组播业务, 若 VID与映射关系的源 VLAN匹配失败, 或欲加入组播的 VLAN与映射关系的目的 VLAN匹配失败, 则将 4艮文丟弃。
2、 如权利要求 1所述的方法, 其特征在于, 所述组播请求报文是因特 网组管理协议 IGMP报文。
3、 如权利要求 2所述的方法, 其特征在于, 所述 IGMP报文包括报告 report才艮文和 /或离开 leave才艮文。
4、 如权利要求 1所述的方法, 其特征在于, 在维护提供组播业务的源 VLAN与接收组播业务的目的 VLAN的映射关系时, 为每一个用户维护提 供组播业务的源 VLAN与接收组播业务的目的 VLAN的映射关系。
5、 如权利要求 1至 4任一项所述的方法, 其特征在于, 在匹配判断之 前, 该方法还包括:
启动跨 VLAN组播业务。
6、一种跨虚拟局域网的组播业务处理设备,其特征在于,该设备包括: 映射关系模块, 用于维护提供组播业务的源 VLAN与接收组播业务的 目的 VLAN的映射关系;
判断模块, 用于获取组播请求报文中的 VID以及根据组播请求报文中 的组播组地址反解析出欲加入组播的 VLAN,若 VID与映射关系的源 VLAN 匹配成功, 且欲加入组播的 VLAN与映射关系的目的 VLAN匹配成功, 则 提供组播业务, 若 VID与映射关系的源 VLAN匹配失败, 或欲加入组播的 VLAN与映射关系的目的 VLAN匹配失败, 则将 4艮文丟弃。
7、 如权利要求 6所述的设备, 其特征在于, 所述判断模块还用于, 根 据 IGMP ^艮文进行匹配判断。
8、 如权利要求 7所述的设备, 其特征在于, 所述判断模块还用于, 根 据所述 IGMP报文中的 report报文和 /或 leave报文进行匹配判断。
9、如权利要求 6所述的设备,其特征在于, 所述映射关系模块还用于, 在维护提供组播业务的源 VLAN与接收组播业务的目的 VLAN的映射关系 时, 为每一个用户维护提供组播业务的源 VLAN 与接收组播业务的目的 VLAN的映射关系。
10、 如权利要求 6至 9任一项所述的设备, 其特征在于, 所述判断模 块还用于, 在匹配判断之前, 启动跨 VLAN组播业务。
PCT/CN2011/075931 2010-12-23 2011-06-20 一种跨虚拟局域网的组播业务处理方法及设备 WO2012083655A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201010603463.9A CN102025523B (zh) 2010-12-23 2010-12-23 一种跨虚拟局域网的组播业务处理方法及设备
CN201010603463.9 2010-12-23

Publications (1)

Publication Number Publication Date
WO2012083655A1 true WO2012083655A1 (zh) 2012-06-28

Family

ID=43866417

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2011/075931 WO2012083655A1 (zh) 2010-12-23 2011-06-20 一种跨虚拟局域网的组播业务处理方法及设备

Country Status (2)

Country Link
CN (1) CN102025523B (zh)
WO (1) WO2012083655A1 (zh)

Families Citing this family (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102025523B (zh) * 2010-12-23 2015-06-03 中兴通讯股份有限公司 一种跨虚拟局域网的组播业务处理方法及设备
CN103078778B (zh) * 2011-10-25 2017-04-26 中兴通讯股份有限公司 一种虚拟局域网信息传输方法及装置

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1543132A (zh) * 2003-04-29 2004-11-03 华为技术有限公司 跨虚拟局域网组播的实现方法
CN101083546A (zh) * 2007-07-18 2007-12-05 中兴通讯股份有限公司 一种接入设备的组播管理方法
CN101478477A (zh) * 2008-12-01 2009-07-08 北京星网锐捷网络技术有限公司 一种组播报文转发方法及装置
CN102025523A (zh) * 2010-12-23 2011-04-20 中兴通讯股份有限公司 一种跨虚拟局域网的组播业务处理方法及设备

Family Cites Families (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101453399B (zh) * 2007-11-30 2012-07-04 华为技术有限公司 虚拟网络配置方法及系统
CN101771901B (zh) * 2008-12-31 2013-04-24 华为技术有限公司 一种无源光网络中组播权限控制的方法、系统及多住户单元
US8238340B2 (en) * 2009-03-06 2012-08-07 Futurewei Technologies, Inc. Transport multiplexer—mechanisms to force ethernet traffic from one domain to be switched in a different (external) domain

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1543132A (zh) * 2003-04-29 2004-11-03 华为技术有限公司 跨虚拟局域网组播的实现方法
CN101083546A (zh) * 2007-07-18 2007-12-05 中兴通讯股份有限公司 一种接入设备的组播管理方法
CN101478477A (zh) * 2008-12-01 2009-07-08 北京星网锐捷网络技术有限公司 一种组播报文转发方法及装置
CN102025523A (zh) * 2010-12-23 2011-04-20 中兴通讯股份有限公司 一种跨虚拟局域网的组播业务处理方法及设备

Also Published As

Publication number Publication date
CN102025523B (zh) 2015-06-03
CN102025523A (zh) 2011-04-20

Similar Documents

Publication Publication Date Title
CN110430043B (zh) 一种认证方法、系统及装置和存储介质
CN109451264B (zh) 一种监控设备入会的方法和系统
CN110768817B (zh) 视联网终端的升级方法和装置
US8254385B2 (en) Internet protocol multicast content delivery
CN108574818B (zh) 一种信息显示的方法、装置和服务器
US8813115B2 (en) Service access method, device, and system
CN109040658B (zh) 会议控制方法和装置
JP2004515158A (ja) ビデオ及び他のサービスを伝達するための拡張アクセス制御
US20100199321A1 (en) Method, device and system for starting iptv service
CN109672664B (zh) 一种视联网终端的认证方法和系统
WO2009036685A1 (fr) Procédé et appareil pour implémenter une authentification de multidiffusion
WO2009021460A1 (fr) Procédé de rapport d'un résultat de mise en œuvre de politique, système de communication par réseau et équipement
WO2008138238A1 (fr) Procédé, dispositif et système servant à réaliser un contrôle d'admission d'une connexion de multidiffusion
CN108965227A (zh) 一种数据处理方法及视联网会议服务器
US20100322420A1 (en) Duplicate Address Detection Proxy in Edge Devices
WO2014101185A1 (zh) 组播通道的性能检测方法、装置和系统
CN110661784A (zh) 一种用户的认证方法、装置和存储介质
WO2012083655A1 (zh) 一种跨虚拟局域网的组播业务处理方法及设备
WO2008052475A1 (fr) Procédé, système et dispositif pour une authentification de multidiffusion
WO2012100620A1 (zh) 连接接纳控制方法、装置及无源光网络系统
CN110417792B (zh) 通信方法、系统、网关设备及存储介质
WO2009003383A1 (fr) Procédé de multidiffusion, dispositif de réseau et système de multidiffusion
CN110049269B (zh) 一种视联网会议管理的方法、服务器及客户端
CN110493193A (zh) 数据传输方法和装置
CN112291592B (zh) 基于控制面协议的安全视频通信方法、装置、设备及介质

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 11851444

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 11851444

Country of ref document: EP

Kind code of ref document: A1