WO2016184028A1 - 一种交换机设备的组播报文转发控制方法及装置 - Google Patents

一种交换机设备的组播报文转发控制方法及装置 Download PDF

Info

Publication number
WO2016184028A1
WO2016184028A1 PCT/CN2015/092329 CN2015092329W WO2016184028A1 WO 2016184028 A1 WO2016184028 A1 WO 2016184028A1 CN 2015092329 W CN2015092329 W CN 2015092329W WO 2016184028 A1 WO2016184028 A1 WO 2016184028A1
Authority
WO
WIPO (PCT)
Prior art keywords
address
destination
source
multicast group
preset
Prior art date
Application number
PCT/CN2015/092329
Other languages
English (en)
French (fr)
Inventor
唐利
Original Assignee
中兴通讯股份有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 中兴通讯股份有限公司 filed Critical 中兴通讯股份有限公司
Publication of WO2016184028A1 publication Critical patent/WO2016184028A1/zh

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L49/00Packet switching elements
    • H04L49/20Support for services
    • H04L49/201Multicast operation; Broadcast operation

Definitions

  • the present invention relates to the field of communications, and in particular, to a multicast packet forwarding control method and apparatus for a switch device.
  • Multicast technology effectively solves the problem of single-point transmission and multi-point reception, and realizes efficient data transmission in point-to-multipoint in IP networks, which can save a lot of network bandwidth and reduce network load.
  • the significance of multicast is not only here, but more importantly, it can easily provide some new value-added services by using the multicast characteristics of the network, including online live broadcast, network TV, and remote.
  • the multicast technology is implemented by establishing an association between a multicast group and a member through the Internet Group Management Protocol (IGMP), and then forwarding the multicast according to the relationship.
  • IGMP Internet Group Management Protocol
  • the embodiment of the invention provides a method and a device for controlling multicast packet forwarding of a switch device, which are used to solve at least the problem that the switch sends harmful or useless information to the user in the current multicast technology.
  • a multicast packet forwarding control method for a switch device includes: obtaining a protocol IP address and a destination of interconnection between source networks of a multicast group from received IGMP messages The IP address is matched with the source IP address and the destination IP address of the multicast group. If the match is successful, the IGMP message is forbidden. If the match fails, the switch will fail. The IGMP message is forwarded to the IGMP Snooping module to establish a relationship between the multicast group and the group member.
  • the pre-configured source IP address and the destination IP address are stored in a preset configuration file.
  • the pre-configured configuration file includes at least one of the following information: the source IP address and the destination IP address of the multicast group to be filtered.
  • the method further includes: sorting, merging, or separating control entries in a preset configuration file according to the received control command before obtaining the source IP address and the destination IP address of the multicast group from the received IGMP message. .
  • the matching between the source IP address and the destination IP address of the multicast group and the preset source IP address and the destination IP address includes: reading the preset filtering content in the configuration file, and forming the read content into a linked list; Each control entry of the linked list is traversed, and the source IP address and the destination IP address in each control entry are matched with the source IP address and the destination IP address of the multicast group.
  • the source IP address and the destination IP address of the multicast group are matched with the preset source IP address and the destination IP address, including: determining whether the source IP address of the multicast group is the same as the preset source IP address or falling into the destination IP address. Pre-set the source IP address range, or determine whether the destination IP address of the multicast group is the same as the preset destination IP address or falls within the preset destination IP address range, or determine the source IP address and destination IP address of the multicast group. Whether it is the same as the preset source IP address and destination IP address or falls within the preset source IP address range and destination IP address range; if the determination is yes, the source IP address and destination IP address of the multicast group are determined. The source IP address and the destination IP address are matched. If no, the source IP address and destination IP address of the multicast group do not match the preset source IP address and destination IP address.
  • a multicast packet forwarding control apparatus for a switch device, comprising: an obtaining module, configured to obtain an interconnection between source networks of a multicast group from received IGMP messages The protocol IP address and the destination IP address; the matching module is configured to match the source IP address and the destination IP address of the multicast group with the preset source IP address and the destination IP address; and the control module is set to be successful in the matching. If the IGMP message is forwarded, the IGMP message is forwarded to the IGMP Snooping module to establish a relationship between the multicast group and the group member.
  • the pre-configured source IP address and the destination IP address are stored in a preset configuration file.
  • the pre-configured configuration file includes at least one of the following information: the source IP address and the destination IP address of the multicast group to be filtered.
  • the device further includes: a setting module, configured to: before obtaining the source IP address and the destination IP address of the multicast group from the received IGMP message, perform the control entry in the preset configuration file according to the received control command. Sort, merge, or separate.
  • the matching module includes: a reading unit configured to read a preset filtering content in the configuration file, and form the linked content into a linked list; the matching unit is configured to traverse each control entry of the linked list, and each The source IP address and destination IP address in the control entry are matched with the source IP address and destination IP address of the multicast group.
  • the matching module includes: a determining unit, configured to determine whether a source IP address of the multicast group is the same as a preset source IP address or falls within a preset source IP address range, or determines a destination IP address of the multicast group. Whether it is the same as the preset destination IP address or falls within the preset destination IP address range, or determines whether the source IP address and destination IP address of the multicast group are the same as or fall in the preset source IP address and destination IP address respectively.
  • a determining unit configured to determine whether a source IP address of the multicast group is the same as a preset source IP address or falls within a preset source IP address range, or determines a destination IP address of the multicast group.
  • the preset source IP address range and the destination IP address range; the determining unit is configured to determine the source IP address and the destination IP address of the multicast group and the preset source IP address when the judgment unit determines that the result is yes If the judgment result of the judgment unit is no, the source IP address and the destination IP address of the multicast group do not match the preset source IP address and the destination IP address.
  • the multicast packet forwarding control method of the switch device before the relationship between the multicast group and the group member, the source IP address and the destination IP address and the source IP address and destination IP address of the multicast group data are set in advance.
  • the address is matched, and the multicast group data is filtered according to the matching result, so as to control the multicast member forwarding, thereby filtering some identified harmful or useless multicast data, thereby saving not only broadband and switches. Resources can also enhance the security and user experience of the switch.
  • FIG. 1 is a flowchart of a multicast packet forwarding control method of a switch device according to Embodiment 1 of the present invention
  • FIG. 2 is a flowchart of a multicast packet forwarding control method of a switch device according to Embodiment 2 of the present invention
  • FIG. 3 is a flowchart of a process of forming a multicast control entry list in Embodiment 2 of the present invention.
  • FIG. 4 is a flowchart of a process of controlling establishment of a relationship between a multicast group and a group in Embodiment 2 of the present invention
  • FIG. 5 is a flowchart of a process for forwarding a multicast stream by group and group membership in Embodiment 2 of the present invention
  • FIG. 6 is a structural block diagram of a multicast packet forwarding control apparatus of a switch device according to Embodiment 3 of the present invention.
  • the embodiment of the present invention provides a multicast packet forwarding control method and device for the switch device, which are described below with reference to the accompanying drawings.
  • the present invention will be described in further detail. It is understood that the specific embodiments described herein are merely illustrative of the invention and are not intended to limit the invention.
  • This embodiment provides a method for controlling multicast packet forwarding of a switch device.
  • the method is used to control multicast forwarding to filter some unsafe or meaningless information.
  • the multicast forwarding is divided into the following two phases. : Establish the group and group membership phase; the root membership relationship is forwarded accordingly. In the second phase, the relationship between the multicast group and the group is established, and the corresponding multicast stream is sent to the corresponding member port. In this case, the ACL can be controlled, but this consumes a large number of ACL entries and switch resources.
  • the purpose of controlling multicast forwarding is controlled by controlling the establishment of a multicast group and a group membership relationship.
  • FIG. 1 is a flowchart of a multicast packet forwarding control method of a switch device according to Embodiment 1 of the present invention. As shown in FIG. 1, the method includes the following steps:
  • Step 101 Obtain an IP address and a destination IP address of the multicast group from the received IGMP message.
  • the preset source IP address and destination IP address involved in the step are stored in a preset configuration file.
  • the preset configuration file includes at least one of the following information: the source IP address of the multicast group data to be filtered and The destination IP address, the source port of the multicast group data to be filtered, and the virtual LAN VLAN used for the multicast group data to be filtered.
  • the configuration file can be set by the user according to the requirements. Based on the information in the configuration file, IGMP is used. In the process of packet forwarding control, the source IP address and destination IP address of the multicast group can be forwarded and controlled, and the source port of the multicast group data to be filtered and the multicast to be filtered.
  • the information of the virtual local area network (VLAN) used by the group data is matched to the corresponding information of the multicast group of the IGMP message, so as to control the IGMP message forwarding.
  • VLAN virtual local area network
  • Sorting, merging, or separating entries in a preset configuration file according to the received control command for example, if The user added a filtered IP address segment.
  • the number of IP addresses, which can cause the originally separated IP address segments to be merged into a larger IP address segment then these IP address segments can be merged, if the user restores one or some IP address segments that were previously set to be disabled to allow , the original continuous IP address segment can be separated into multiple independent IP address segments.
  • Step 102 Match the source IP address and the destination IP address of the multicast group with the preset source IP address and destination IP address.
  • the IP address matching operation may be performed in an orderly manner according to the traversal list. Based on this, the source IP address and the destination IP address of the multicast group are respectively set with the preset source IP address and destination IP address.
  • the matching includes: reading the preset filtering content in the configuration file, forming the linked content into a linked list; and traversing each control item of the linked list to match the source IP address and the destination IP address of the multicast group.
  • the source IP address and destination IP address of the multicast group match the preset source IP address and destination IP address, including the following three cases:
  • Set the destination IP address range or determine whether the source IP address and destination IP address of the multicast group are the same as the preset source IP address and destination IP address, or fall within the preset source IP address range and destination IP address range. If yes, determine that the source IP address and destination IP address of the multicast group match the preset source IP address and destination IP address. If not, determine the source IP address and destination IP address of the multicast group and the preset IP address. The source IP address and destination IP address do not match.
  • Step 103 If the matching is successful, the IGMP message is forbidden to be forwarded. If the matching fails, the IGMP message is forwarded to the IGMP Snooping module to establish a relationship between the multicast group and the group member.
  • the method described in this embodiment can complete the control of multicast member learning, thereby controlling multicast forwarding, and filtering some identified harmful or useless multicasts, which not only saves broadband and switch resources, but also enhances Switch security and user experience.
  • This embodiment describes the multicast packet forwarding control method of the switch device provided in Embodiment 1 in detail by disclosing more technical details.
  • the multicast packet forwarding control method of the switch device includes the following steps:
  • each control entry is written into the configuration file in a certain format
  • the packet is processed according to the action defined in the control entry, that is, the packet is allowed to be forwarded or the packet is forbidden. If the match fails, the packet is forwarded to the next processing module.
  • the first stage forming a multicast control entry list
  • the processing flow is shown in Figure 3, and the specific steps are as follows:
  • the second phase is to filter the IGMP packets based on the multicast source IP address and the destination IP address, and control the establishment of the relationship between the multicast group and the group membership.
  • the process is as shown in Figure 4. The specific steps are as follows:
  • the switch port receives IGMP messages.
  • Each control entry is read out from the control entry list in turn, and compared with the obtained source IP and destination IP;
  • the IGMP message is sent to the IGMP Snooping module. If it is forbidden, the IGMP message is discarded.
  • the IGMP Snooping module establishes group and group membership based on packet information.
  • the third stage the multicast stream is forwarded according to the group and group membership.
  • the processing flow is shown in Figure 5. The specific steps are as follows:
  • the device starts up and each component is initialized.
  • the port receives the multicast stream
  • the embodiment provides a multicast packet forwarding control device for a switch device, and the device is configured to implement the multicast packet forwarding control method of the switch device provided in the foregoing Embodiment 1 and Embodiment 2.
  • the device may be configured on the switch. Inside.
  • FIG. 6 is a structural block diagram of a multicast packet forwarding control apparatus of a switch device according to Embodiment 3 of the present invention. As shown in FIG. 6, the apparatus 60 includes the following components:
  • the obtaining module 61 is configured to obtain, from the received IGMP message, a protocol IP address and a destination IP address that are interconnected between the source networks of the multicast group.
  • the matching module 62 is configured to match the source IP address and the destination IP address of the multicast group with the preset source IP address and the destination IP address;
  • the control module 63 is configured to prevent the IGMP message from being forwarded when the matching is successful. If the matching fails, the IGMP message is forwarded to the IGMP Snooping module to establish a relationship between the multicast group and the group member.
  • the preset source IP address and the destination IP address are stored in a preset configuration file, and the preset configuration file includes at least one of the following information:
  • the device 60 further includes: a setting module, configured to receive the control according to the received Internet Group Management Protocol IGMP message before the multicast group is obtained.
  • the instructions sort, merge, or separate entries in a pre-configured configuration file.
  • the matching module 62 includes:
  • the reading unit is configured to read the preset filtering content in the configuration file, and form the read content into a linked list;
  • Matching unit set to traverse each control entry of the linked list with the source IP address of the multicast group and
  • the matching module 62 includes: a determining unit, configured to determine whether the source IP address of the multicast group is the same as the preset source IP address or falls within a preset source IP address range, or determines whether the destination IP address of the multicast group is The preset destination IP address is the same or falls within the preset destination IP address range, or whether the source IP address and the destination IP address of the multicast group are the same as the preset source IP address and destination IP address, respectively, or fall into the preset.
  • a determining unit configured to determine whether the source IP address of the multicast group is the same as the preset source IP address or falls within a preset source IP address range, or determines whether the destination IP address of the multicast group is The preset destination IP address is the same or falls within the preset destination IP address range, or whether the source IP address and the destination IP address of the multicast group are the same as the preset source IP address and destination IP address, respectively, or fall into the preset.
  • the source IP address range and the destination IP address range; the determining unit is configured to determine the source IP address and the destination IP address of the multicast group and the preset source IP address and destination IP when the judgment unit determines that the result is yes If the judgment result of the judgment unit is negative, it is determined that the source IP address and the destination IP address of the multicast group do not match the preset source IP address and the destination IP address.
  • the multicast packet forwarding control method and apparatus of the switch device provided by the embodiment of the present invention have the following beneficial effects: before the relationship between the multicast group and the group member is established, the source IP address and the destination are preset.
  • the IP address matches the source IP address and the destination IP address of the multicast group data, and determines whether to filter the multicast group data according to the matching result, so as to implement the control of the multicast member forwarding, thereby implementing some harmful or Unwanted multicast data is filtered, which not only saves bandwidth and switch resources, but also enhances the security and user experience of the switch.

Abstract

本发明提供一种交换机设备的组播报文转发控制方法及装置,用以解决目前组播技术中,交换机会将有害或无用信息发送到用户的问题。该方法包括:从接收到的IGMP报文中获取组播组的源网络之间互连的协议IP地址以及目的IP地址;将组播组的源IP地址与目的IP地址与预先设置的源IP地址以及目的IP地址进行匹配;在匹配成功的情况下,禁止转发IGMP报文,在匹配失败的情况下,将IGMP报文转发至IGMP Snooping模块使得组播组与组员建立关系,该方案实现对一些已识别有害的或无用的组播进行过滤,保证了用户数据的安全性。

Description

一种交换机设备的组播报文转发控制方法及装置 技术领域
本发明涉及通讯领域,特别是涉及一种交换机设备的组播报文转发控制方法及装置。
背景技术
组播技术有效地解决了单点发送、多点接收的问题,实现了IP网络中点到多点的高效数据传送,能够大量节约网络带宽、降低网络负载。作为一种与单播和广播并列的通信方式,组播的意义不仅在于此,更重要的是,可以利用网络的组播特性方便地提供一些新的增值业务,包括在线直播、网络电视、远程教育、远程医疗、网络电台、实时视频会议等互联网的信息服务领域。组播技术的实现是通过IGMP(Internet Group Management Protocol,Internet组管理协议)建立起组播组与成员的对应关系,然后根据这种关系进行组播的转发。目前主流的交换机产品都已支持IGMPV2.0,通过IGMP Snooping功能建立组与组成员的关系。但是交换机对这种关系的建立并没有进行必要的控制,即只要端口收到IGMP协议报文,交换机就会根据协议内容进行组与组成员关系的建立并进行相应的组播转发,这样则会造成一些有害的或无用的信息被转发到用户,对用户造成危害。
发明内容
本发明实施例提供一种交换机设备的组播报文转发控制方法及装置,用以至少解决目前组播技术中,交换机会将有害或无用信息发送到用户的问题。
根据本发明的一个实施例,提供了一种交换机设备的组播报文转发控制方法,包括:从接收到的IGMP报文中获取组播组的源网络之间互连的协议IP地址以及目的IP地址;将组播组的源IP地址与目的IP地址与预先设置的源IP地址以及目的IP地址进行匹配;在匹配成功的情况下,禁止转发IGMP报文,在匹配失败的情况下,将IGMP报文转发至IGMP Snooping模块使得组播组与组员建立关系。
其中,预先设置的源IP地址以及目的IP地址存储于预先设置的配置文件中,预先设置的配置文件中至少包括以下一种信息:需过滤组播组的源IP地址以及目的IP地址、需过滤组播组的源端口以及需过滤的组播组使用的虚拟局域网VLAN。
上述方法还包括:在从接收到的IGMP报文中获取组播组的源IP地址以及目的IP地址之前,根据接收到的控制指令对预先设置的配置文件中的控制条目进行排序、合并或分离。
其中,将组播组的源IP地址与目的IP地址与预先设置的源IP地址以及目的IP地址进行匹配,包括:读取配置文件中预先设置的过滤内容,将读取到的内容形成链表;遍历链表的每个控制条目,并将每个控制条目中的源IP地址、目的IP地址与组播组的源IP地址以及目的IP地址进行匹配。
其中,将组播组的源IP地址与目的IP地址与预先设置的源IP地址以及目的IP地址进行匹配,包括:判断组播组的源IP地址是否与预先设置的源IP地址相同或落入预先设置的源IP地址范围,或判断组播组的目的IP地址是否与预先设置的目的IP地址相同或落入预先设置的目的IP地址范围,或判断组播组的源IP地址以及目的IP地址是否分别与预先设置的源IP地址以及目的IP地址相同或落入预先设置的源IP地址范围以及目的IP地址范围中;如果判断为是,则确定组播组的源IP地址和目的IP地址与预先设置的源IP地址以及目的IP地址匹配,如果否,则确定组播组的源IP地址和目的IP地址与预先设置的源IP地址以及目的IP地址不匹配。
根据本发明的另一个实施例,提供了一种交换机设备的组播报文转发控制装置,包括:获取模块,设置为从接收到的IGMP报文中获取组播组的源网络之间互连的协议IP地址以及目的IP地址;匹配模块,设置为将组播组的源IP地址与目的IP地址与预先设置的源IP地址以及目的IP地址进行匹配;控制模块,设置为在匹配成功的情况下,禁止转发IGMP报文,在匹配失败的情况下,将IGMP报文转发至IGMP Snooping模块使得组播组与组员建立关系。
其中,预先设置的源IP地址以及目的IP地址存储于预先设置的配置文件中,预先设置的配置文件中至少包括以下一种信息:需过滤组播组的源IP地址以及目的IP地址、需过滤组播组的源端口以及需过滤的组播组使用的虚拟局域网VLAN。
上述装置还包括:设置模块,设置为在从接收到的IGMP报文中获取组播组的源IP地址以及目的IP地址之前,根据接收到的控制指令对预先设置的配置文件中的控制条目进行排序、合并或分离。
其中,上述匹配模块包括:读取单元,设置为读取配置文件中预先设置的过滤内容,将读取到的内容形成链表;匹配单元,设置为遍历链表的每个控制条目,并将每个控制条目中的源IP地址、目的IP地址与组播组的源IP地址以及目的IP地址进行匹配。
其中,上述匹配模块,包括:判断单元,设置为判断组播组的源IP地址是否与预先设置的源IP地址相同或落入预先设置的源IP地址范围,或判断组播组的目的IP地址是否与预先设置的目的IP地址相同或落入预先设置的目的IP地址范围,或判断组播组的源IP地址以及目的IP地址是否分别与预先设置的源IP地址以及目的IP地址相同或落入预先设置的源IP地址范围以及目的IP地址范围中;确定单元,设置为在判断单元的判断结果为是时,则确定组播组的源IP地址和目的IP地址与预先设置的源IP地址以及目的IP地址匹配,如果在判断单元的判断结果为否时,则确定组播组的源IP地址和目的IP地址与预先设置的源IP地址以及目的IP地址不匹配。
本实施例提供的交换机设备的组播报文转发控制方法,在组播组与组成员建立关系之前,通过预先设置的源IP地址以及目的IP地址与组播组数据的源IP地址以及目的IP地址进行匹配,根据匹配结果确定是否对组播组数据进行过滤,从而实现对组播成员转发的控制,从而实现对一些已识别有害的或无用的组播数据进行过滤,进而不仅节省宽带及交换机资源,还可以增强交换机的安全性及用户体验。
附图说明
图1是本发明实施例1提供的交换机设备的组播报文转发控制方法的流程图;
图2是本发明实施例2提供的交换机设备的组播报文转发控制方法的流程图;
图3是本发明实施例2中形成组播控制条目链表的处理流程图;
图4是本发明实施例2中控制组播组与组成员关系的建立的处理流程图;
图5是本发明实施例2中组播流按组与组成员关系进行转发的处理流程图;
图6是本发明实施例3提供的交换机设备的组播报文转发控制装置的结构框图。
具体实施方式
为了解决相关技术目前组播技术中,交换机会将有害或无用信息发送到用户的问题,本发明实施例提供了一种交换机设备的组播报文转发控制方法及装置,以下结合附图以及实施例,对本发明进行进一步详细说明。应当理解,此处所描述的具体实施例仅仅用以解释本发明,并不限定本发明。
实施例1
本实施例提供了一种交换机设备的组播报文转发控制方法,该方法用于对组播转发进行控制,以过滤一些不安全或无意义的信息,由于组播转发分为以下两个阶段:建立组与组成员关系阶段;根椐成员关系进行相应的转发阶段。在第二个阶段,组播组与组成员关系已建立,相应的组播流会发送到相应的成员端口,此时可以通过ACL进行控制,但这会消耗大量的ACL条目及交换机资源,所以本实施例通过控制组播组与组成员关系的建立以达到控制组播转发的目地。
图1是本发明实施例1提供的交换机设备的组播报文转发控制方法的流程图,如图1所示,该方法包括如下步骤:
步骤101:从接收到的IGMP报文中获取组播组的IP地址以及目的IP地址;
该步骤中涉及到的预先设置的源IP地址以及目的IP地址存储于预先设置的配置文件中,预先设置的配置文件中至少包括以下一种信息:需过滤的组播组数据的源IP地址以及目的IP地址、需过滤的组播组数据的源端口以及需过滤的组播组数据使用的虚拟局域网VLAN,该配置文件可以由用户根据需求进行设置,基于配置文件中的这些信息,在对IGMP报文进行转发控制的过程中,不仅可以组播组的源IP地址以及目的IP地址实现对IGMP报文的转发控制,还可以根据需过滤的组播组数据的源端口以及需过滤的组播组数据使用的虚拟局域网VLAN等信息来对IGMP报文的组播组的相应信息进行匹配,从而实现IGMP报文转发的控制,具体地,在获取组播组的因特网组管理协议IGMP报文之前,根据接收到的控制指令对预先设置的配置文件中的条目进行排序、合并或分离,例如,如果用户增加了过滤IP地址段 的IP地址数量,导致原本分离的IP地址段可以合并为一个范围较大的IP地址段,则可以合并这些IP地址段,如果用户将之前设置为禁止的某一个或一些IP地址段恢复为允许,则可以将原本连续的IP地址段分离为多个独立的IP地址段。
步骤102:将组播组的源IP地址与目的IP地址与预先设置的源IP地址以及目的IP地址进行匹配;
为了提高IP地址匹配的效率,可以按照遍历链表的形式有序的进行IP地址匹配操作,基于此,将组播组的源IP地址与目的IP地址分别与预先设置的源IP地址以及目的IP地址进行匹配,包括:读取配置文件中预先设置的过滤内容,将读取到的内容形成链表;遍历链表的每个控制条目与组播组的源IP地址以及目的IP地址进行匹配。
在该步骤中组播组的源IP地址和目的IP地址与预先设置的源IP地址以及目的IP地址匹配,包括以下三种情况:
判断组播组的源IP地址是否与预先设置的源IP地址相同或落入预先设置的源IP地址范围,或判断组播组的目的IP地址是否与预先设置的目的IP地址相同或落入预先设置的目的IP地址范围,或判断组播组的源IP地址以及目的IP地址是否分别与预先设置的源IP地址以及目的IP地址相同或落入预先设置的源IP地址范围以及目的IP地址范围中;如果是,则确定组播组的源IP地址和目的IP地址与预先设置的源IP地址以及目的IP地址匹配,如果否,则确定组播组的源IP地址和目的IP地址与预先设置的源IP地址以及目的IP地址不匹配。
步骤103:在匹配成功的情况下,禁止转发IGMP报文,在匹配失败的情况下,将IGMP报文转发至IGMP Snooping模块使得组播组与组员建立关系。
由本实施例所描述的方法,可以完成对组播成员学习的控制,从而控制组播的转发,可以对一些已识别有害的或无用的组播进行过滤,不仅节省宽带及交换机资源,还可以增强交换机的安全性及用户体验。
实施例2
本实施例通过公开更多的技术细节来对上述实施例1中提供的交换机设备的组播报文转发控制方法进行详细说明。
如图2所示,本实施例提供的交换机设备的组播报文转发控制方法包括如下步骤:
建立设置为过滤组播报文的各控制条目相应的配置文件,为用户提供配置接口;
根据用户的配置,将各控制条目按一定格式写入配置文件;
在IGMP报文进入IGMP Snooping模块之前获取IGMP报文,得到组播源IP及目地IP。
读出配置文件中的配置内容,形成链表;
遍历链表并将每个控制条目与上述步骤中得到的组播源IP与目地IP进行比较;
如果匹配成功,则按照控制条目中定义的动作进行处理,即,允许报文转发,或禁止报文转发,匹配失败,则将报文转入到下一处理模块。
下面结合详细附图对本实施例提供的控制组播转发方法的各阶段进行详细描述:
第一阶段:形成组播控制条目链表,其处理流程如图3所示,实现的具体如下步骤:
创建配置文件;
通过用户接口写入控制条目;
对控制条目进行排序、合并或分离;
读出控制条目,形成一个控制链表;
本次流程结束。
第二阶段:基于组播源IP、目的IP对IGMP报文进行过滤,控制组播组与组成员关系的建立,其处理流程如图4所示,实现的具体步骤如下:
本次处理流程开始;
交换机端口接收IGMP报文;
将IGMP报文上传到CPU处理,获取组播源IP、目地IP;
依次从控制条目链表中读出各控制条目,并与获取到的源IP、目地IP进行比较;
如果匹配,则按控制条目指定动作进行处理,即允许报文转发或禁止报文转发;
如果允许报文转发,则将IGMP报文传送到IGMP Snooping模块处理;如果禁止,则丢弃IGMP报文;
IGMP Snooping模块根据报文信息建立组与组成员关系。
第三阶段:组播流按组与组成员关系进行转发,其处理流程如图5所示,实现的具体步骤如下:
本次处理流程开始;
设备启动,各组件初始化;
端口接收组播流;
读取组与组成员关系表;
将组播流转发至各成员端口;
本次流程结束。
实施例3
本实施例提供了一种交换机设备的组播报文转发控制装置,该装置设置为实现上述实施例1以及实施例2提供的交换机设备的组播报文转发控制方法,该装置可以设置于交换机内。
图6是本发明实施例3提供的交换机设备的组播报文转发控制装置的结构框图,如图6所示,该装置60包括如下组成部分:
获取模块61,设置为从接收到的IGMP报文中获取组播组的源网络之间互连的协议IP地址以及目的IP地址;
匹配模块62,设置为将组播组的源IP地址与目的IP地址与预先设置的源IP地址以及目的IP地址进行匹配;
控制模块63,设置为在匹配成功的情况下,禁止转发IGMP报文,在匹配失败的情况下,将IGMP报文转发至IGMP Snooping模块使得组播组与组员建立关系。
其中,上述预先设置的源IP地址以及目的IP地址存储于预先设置的配置文件中,预先设置的配置文件中至少包括以下一种信息:
需过滤组播组的源IP地址以及目的IP地址、需过滤组播组的源端口以及需过滤的组播组使用的虚拟局域网VLAN。
为了根据用户的需求对过滤组播组的配置文件进行设置,进一步的,上述装置60还包括:设置模块,设置为在获取组播组的因特网组管理协议IGMP报文之前,根据接收到的控制指令对预先设置的配置文件中的条目进行排序、合并或分离。
其中,上述匹配模块62包括:
读取单元,设置为读取配置文件中预先设置的过滤内容,将读取到的内容形成链表;
匹配单元,设置为遍历链表的每个控制条目与组播组的源IP地址以及所
上述匹配模块62包括:判断单元,设置为判断组播组的源IP地址是否与预先设置的源IP地址相同或落入预先设置的源IP地址范围,或判断组播组的目的IP地址是否与预先设置的目的IP地址相同或落入预先设置的目的IP地址范围,或判断组播组的源IP地址以及目的IP地址是否分别与预先设置的源IP地址以及目的IP地址相同或落入预先设置的源IP地址范围以及目的IP地址范围中;确定单元,设置为在判断单元的判断结果为是时,则确定组播组的源IP地址和目的IP地址与预先设置的源IP地址以及目的IP地址匹配,在判断单元的判断结果为否时,则确定组播组的源IP地址和目的IP地址与预先设置的源IP地址以及目的IP地址不匹配。
尽管为示例目的,已经公开了本发明的优选实施例,本领域的技术人员将意识到各种改进、增加和取代也是可能的,因此,本发明的范围应当不限于上述实施例。
工业实用性
如上所述,本发明实施例提供的一种交换机设备的组播报文转发控制方法及装置,具有以下有益效果:在组播组与组成员建立关系之前,通过预先设置的源IP地址以及目的IP地址与组播组数据的源IP地址以及目的IP地址进行匹配,根据匹配结果确定是否对组播组数据进行过滤,从而实现对组播成员转发的控制,从而实现对一些已识别有害的或无用的组播数据进行过滤,进而不仅节省宽带及交换机资源,还可以增强交换机的安全性及用户体验。

Claims (10)

  1. 一种交换机设备的组播报文转发控制方法,包括:
    从接收到的IGMP报文中获取组播组的源网络之间互连的协议IP地址以及目的IP地址;
    将所述组播组的源IP地址与目的IP地址与预先设置的源IP地址以及目的IP地址进行匹配;
    在匹配成功的情况下,禁止转发所述IGMP报文,在匹配失败的情况下,将所述IGMP报文转发至IGMP Snooping模块使得组播组与组员建立关系。
  2. 根据权利要求1所述的方法,其中,所述预先设置的源IP地址以及目的IP地址存储于预先设置的配置文件中,所述预先设置的配置文件中至少包括以下一种信息:
    需过滤组播组的源IP地址以及目的IP地址、需过滤组播组的源端口以及需过滤的组播组使用的虚拟局域网VLAN。
  3. 根据权利要求2所述的方法,其中,所述方法还包括:
    在从接收到的IGMP报文中获取组播组的源IP地址以及目的IP地址之前,根据接收到的控制指令对所述预先设置的配置文件中的控制条目进行排序、合并或分离。
  4. 根据权利要求1所述的方法,其中,所述将所述组播组的源IP地址与目的IP地址与预先设置的源IP地址以及目的IP地址进行匹配,包括:
    读取配置文件中预先设置的过滤内容,将读取到的内容形成链表;
    遍历所述链表的每个控制条目,并将每个控制条目中的源IP地址、目的IP地址与所述组播组的源IP地址以及目的IP地址进行匹配。
  5. 根据权利要求1所述的方法,其中,所述将所述组播组的源IP地址与目的IP地址与预先设置的源IP地址以及目的IP地址进行匹配,包括:
    判断所述组播组的源IP地址是否与预先设置的源IP地址相同或落入预先设置的源IP地址范围,或判断所述组播组的目的IP地址是否与预先设置的目的IP地址相同或落入预先设置的目的IP地址范围,或判断所述组播组的源IP地址以及目的IP地址是否分别与预先设置的源IP地址以及目的IP地址相同或落入预先设置的源IP地址范围以及目的IP地址范围中;
    如果判断为是,则确定所述组播组的源IP地址和目的IP地址与预先设置的源IP地址以及目的IP地址匹配,如果否,则确定所述组播组的源IP地址和目的IP地址与预先设置的源IP地址以及目的IP地址不匹配。
  6. 一种交换机设备的组播报文转发控制装置,包括:
    获取模块,设置为从接收到的IGMP报文中获取组播组的源网络之间互连的协议IP 地址以及目的IP地址;
    匹配模块,设置为将所述组播组的源IP地址与目的IP地址与预先设置的源IP地址以及目的IP地址进行匹配;
    控制模块,设置为在匹配成功的情况下,禁止转发所述IGMP报文,在匹配失败的情况下,将所述IGMP报文转发至IGMP Snooping模块使得组播组与组员建立关系。
  7. 根据权利要求6所述的装置,其中,所述预先设置的源IP地址以及目的IP地址存储于预先设置的配置文件中,所述预先设置的配置文件中至少包括以下一种信息:
    需过滤组播组的源IP地址以及目的IP地址、需过滤组播组的源端口以及需过滤的组播组使用的虚拟局域网VLAN。
  8. 根据权利要求7所述的装置,其中,所述装置还包括:
    设置模块,设置为从接收到的IGMP报文中获取组播组的源IP地址以及目的IP地址之前,根据接收到的控制指令对所述预先设置的配置文件中的控制条目进行排序、合并或分离。
  9. 根据权利要求6所述的装置,其中,所述匹配模块包括:
    读取单元,设置为读取配置文件中预先设置的过滤内容,将读取到的内容形成链表;
    匹配单元,设置为遍历所述链表的每个控制条目,并将每个控制条目中的源IP地址、目的IP地址与所述组播组的源IP地址以及目的IP地址进行匹配。
  10. 根据权利要求6所述的装置,其中,所述匹配模块,包括:
    判断单元,设置为判断所述组播组的源IP地址是否与预先设置的源IP地址相同或落入预先设置的源IP地址范围,或判断所述组播组的目的IP地址是否与预先设置的目的IP地址相同或落入预先设置的目的IP地址范围,或判断所述组播组的源IP地址以及目的IP地址是否分别与预先设置的源IP地址以及目的IP地址相同或落入预先设置的源IP地址范围以及目的IP地址范围中;
    确定单元,设置为在所述判断单元的判断结果为是时,则确定所述组播组的源IP地址和目的IP地址与预先设置的源IP地址以及目的IP地址匹配,如果在所述判断单元的判断结果为否时,则确定所述组播组的源IP地址和目的IP地址与预先设置的源IP地址以及目的IP地址不匹配。
PCT/CN2015/092329 2015-05-18 2015-10-20 一种交换机设备的组播报文转发控制方法及装置 WO2016184028A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201510253336.3A CN106302188A (zh) 2015-05-18 2015-05-18 一种交换机设备的组播报文转发控制方法及装置
CN201510253336.3 2015-05-18

Publications (1)

Publication Number Publication Date
WO2016184028A1 true WO2016184028A1 (zh) 2016-11-24

Family

ID=57319242

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2015/092329 WO2016184028A1 (zh) 2015-05-18 2015-10-20 一种交换机设备的组播报文转发控制方法及装置

Country Status (2)

Country Link
CN (1) CN106302188A (zh)
WO (1) WO2016184028A1 (zh)

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN107484037A (zh) * 2017-09-22 2017-12-15 上海斐讯数据通信技术有限公司 一种实现无线接入设备控制视频流的方法及系统
CN113037704A (zh) * 2019-12-25 2021-06-25 阿自倍尔株式会社 检测装置以及检测方法

Families Citing this family (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN111866008B (zh) * 2017-07-14 2022-05-31 创新先进技术有限公司 一种业务数据处理方法、业务处理方法及设备
CN109391551B (zh) * 2017-08-14 2021-10-12 中兴通讯股份有限公司 一种多端口组播方法、设备及计算机可读存储介质

Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101480010A (zh) * 2006-11-17 2009-07-08 中兴通讯股份有限公司 特定源组播方法
CN101771611A (zh) * 2009-12-31 2010-07-07 迈普通信技术股份有限公司 在vlan内精确转发ip组播数据的方法和转发设备

Family Cites Families (8)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1232081C (zh) * 2002-08-06 2005-12-14 华为技术有限公司 网络通信中组播报文的转发方法
JP4681620B2 (ja) * 2005-02-18 2011-05-11 フランス・テレコム マルチキャストipフローへのアクセスを制御するための方法および装置
CN101001249A (zh) * 2006-12-31 2007-07-18 华为技术有限公司 一种防igmp报文攻击的方法和装置
CN101051923A (zh) * 2007-04-05 2007-10-10 中兴通讯股份有限公司 以太无源光网络中的组播控制方法
CN100505631C (zh) * 2007-06-14 2009-06-24 中兴通讯股份有限公司 Gpon系统中的组播处理方法
CN101345641B (zh) * 2008-08-21 2011-05-25 中兴通讯股份有限公司 一种组播接入设备及方法
CN101426014B (zh) * 2008-12-02 2013-04-03 中兴通讯股份有限公司 防止组播源攻击的方法及系统
CN104202174B (zh) * 2014-08-13 2017-12-19 上海斐讯数据通信技术有限公司 一种精确转发ip特定源组播数据的实现方法

Patent Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101480010A (zh) * 2006-11-17 2009-07-08 中兴通讯股份有限公司 特定源组播方法
CN101771611A (zh) * 2009-12-31 2010-07-07 迈普通信技术股份有限公司 在vlan内精确转发ip组播数据的方法和转发设备

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN107484037A (zh) * 2017-09-22 2017-12-15 上海斐讯数据通信技术有限公司 一种实现无线接入设备控制视频流的方法及系统
CN113037704A (zh) * 2019-12-25 2021-06-25 阿自倍尔株式会社 检测装置以及检测方法
CN113037704B (zh) * 2019-12-25 2023-10-31 阿自倍尔株式会社 检测装置以及检测方法

Also Published As

Publication number Publication date
CN106302188A (zh) 2017-01-04

Similar Documents

Publication Publication Date Title
US7590116B2 (en) Method for forwarding multicast message in network communication
EP3677013B1 (en) Replication with dedicated metal deployment in a cloud
US9100203B2 (en) IP multicast over multi-chassis trunk
WO2016184028A1 (zh) 一种交换机设备的组播报文转发控制方法及装置
CN107124366B (zh) 一种实现服务质量控制的方法、装置及系统
US9306758B2 (en) Dynamic adjustment of MLDP tunnel and PIM binding
CN105338003A (zh) 一种应用于软件定义网络的防火墙实现方法
US10057121B2 (en) Triggering PIM assert re-election to honor network configuration changes
US20140241351A1 (en) Dynamic determination of the root node of an mldp tunnel
EP3176987B1 (en) Communication control device, communication control method and communication system
EP3121995B1 (en) Method and device for maintaining multicast members in a software defined network
CN105429881B (zh) 一种组播报文转发方法和装置
US10708196B2 (en) Modifications of headend forwarding rules to join wide area network branch hosts to multicast groups
EP2981036A1 (en) Multicast communication method and aggregation switch
KR20130121164A (ko) 분산 시스템 아키텍처에서의 효율적인 멀티캐스팅 방법
US20140092902A1 (en) Method for processing multicast group, dci router and system
WO2017124712A1 (zh) 报文生成方法、报文转发方法及装置
WO2012075832A1 (zh) 转发组播数据报文的方法和提供商边缘设备
US10560359B2 (en) Method and device for reducing multicast flow joint latency
WO2014199924A1 (ja) 制御装置、通信システム、中継装置の制御方法及びプログラム
US11018886B1 (en) Methods and apparatus for selectively filtering an IP multicast data stream for selected group members of a multicast group
Cisco IP Multicast Streamlines Delivery of Multicast Applications
CN103595645B (zh) 一种组播流量管理方法及装置
CN102710745A (zh) 一种实况轮切方法及装置
CN102377639B (zh) 组播剪枝方法及协议无关组播路由器、组管理窥探交换机

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 15892406

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 15892406

Country of ref document: EP

Kind code of ref document: A1