Packet relay processing apparatus
Abstract
This record has no abstract on file.
Term
Projected expiry 1 November 2026.
- Priority
- Filed
- Granted
- Today
- Projected expiry
1 claim: 1 independent, 0 dependent
- 1ネットワーク接続装置を有するパケット中継処理装置であって、 前記ネットワーク接続装置がセッションを管理するセッション管理部と、前記セッション管理部によるセッション管理に基づいてパケットを中継するパケット処理部を備え、 前記パケット中継処理装置は、更に、サーバを備え、 前記サーバは上記セッションを管理する外部セッション管理部を備え、 前記セッション管理部は、与えられた条件に応じて前記セッションに関するセッション情報を前記サーバに転送し、前記外部セッション管理部は、受信した前記セッション情報に基づいて前記セッションを管理する、 ことを特徴とするパケット中継処理装置。
193 paragraphs, as filed
The present invention relates to a packet relay processing device for optimizing a server having server load balancing control, NAT (Network Address Translation), bandwidth control, VPN (Virtual Private Network), and firewall service function.
Currently, the Internet is rapidly expanding in scale due to the spread of packet communication services in WWW (World Wide Web), E-mail, and mobile phones. Along with this, there is an increasing demand for higher speed networks and higher functionality such as security. The current execution mode of network services is generally composed of a server and a network connection device such as a NIC (Network Interface Card). Network services are becoming more complex these days, and the server platform is suitable because it can flexibly respond to various and new demands.
FIG. 39 shows the configuration of the conventional packet relay processing device. The figure shows a general configuration in which a server and a network connection device realize services on a network. Arrows indicate the flow of control information, and thick arrows indicate packet information.
In the figure, 100 is a server, and includes a packet processing unit 101, a service 1 processing unit to a service n processing unit 102, and a service 1 control unit to a service n control unit 103. The service 1 processing unit to the service n processing unit 102 performs session management and routing according to the policy defined by the service 1 control unit to the service n control unit 103, and also performs service processing such as filtering and load balancing.
Reference numeral 104 denotes a network connection device, and packets input from the network via the network connection unit are sent to the packet processing unit 101 of the server 100 via the network connection device 104 and the packet communication unit 105, and the packets are processed. ..<patcit num="1"><text>Japanese Unexamined Patent Publication No. 2000-349851</text></patcit><patcit num="2"><text>Japanese Unexamined Patent Publication No. 11-4261</text></patcit><patcit num="3"><text>Japanese Unexamined Patent Publication No. 2001-16254</text></patcit>
<p> Due to the recent rapid growth of the Internet, the amount of packets flowing through the network is showing exponential growth. For this reason, the conventional server cannot meet the required processing speed, and a technique for speeding up the server is required. Also, in creating a new platform, I want to keep the point that many services of the server can be integrated as much as possible.</p><p> The present invention has been made to solve the above problem, and it is intended to speed up the service processing of the server by arranging the common processing used in many network warbis in the network connection device. The purpose.</p>
<p> FIG. 1 is a diagram illustrating an outline of the present invention. In the figure, 1 is a server and 2 is a network connection device. In the present invention, the network connection device is integrated, and the packet processing unit and the session management unit previously arranged on the server are arranged on the network connection device 2 to form the packet relay processing unit, and the packet relay processing unit is configured. Therefore, packet relay processing based on session management is performed on the network connection device 2.</p><p> Further, a processing distribution unit 2c and a plurality of service processing units 2d are provided on the network connection device 2, and the processing distribution unit 2c manages sessions to a plurality of service processing units 2d according to the policy set by the server 1. Sort based on.</p><p> Further, it is also possible to provide an external session management function on the server 1 so that the server 1 manages the sessions when the number of sessions exceeds the number registered in the session table of the network connection device 2.</p><p> Further, an external service processing unit is provided on the server 1, and the processing distribution unit 2c transfers the packet to the server 1 so that the external service processing unit of the server 1 executes the service processing, or the packet is sent to the server 1. A detailed analysis unit is provided, the server 1 analyzes the packet, determines the service, sets the determined service content in the network connection device 2, and the network connection device 2 subsequently determines the service content for the same session. It is also possible to perform relay processing based on.</p><p> As described above, in the present invention, the above-mentioned problems are solved as follows. (1) The network connection device 2 is provided with a packet relay processing unit based on session management, which is composed of a packet processing unit 2a and a session management unit 2b, and the network connection device 2 performs relay processing based on session management.</p><p> As described above, since the function previously arranged on the server is performed by the network connection device 2, the CPU usage rate of the server 1 can be reduced. In addition, since session management is performed by network connection device 2 and the output destination is registered in the session table at the start of the session, even if the routing table is changed in the middle of the session, consistency is maintained for the currently ongoing session. Can be retained. (2) In (1) above, the server 1 of the packet relay processing device is provided with an external session management function, and the network connection device 2 transfers the session information to the server 1 according to the given conditions, and the server 1 transfers the session information to the server 1. Manage sessions.</p><p> As a result, even if the number of sessions exceeds the number of sessions registered in the network connection device 2, the overflow of the network connection device 2 can be managed by the server 1. (3) In (1) above, the network connection device 2 is provided with the processing distribution unit 2c and a plurality of service processing units 2d, and the processing distribution unit 2c distributes packets to the plurality of service processing units 2d. Perform service processing.</p><p> As described above, by arranging the processing distribution unit 2c and the plurality of service processing units 2d in the network connection device 2 that can process faster than the server 1, the CPU usage rate of the server 1 can be reduced and the CPU usage rate of the server 1 can be reduced. Service processing can be speeded up. (4) In (3) above, an external service processing unit is provided on the server 1, and the processing distribution unit 2c distributes packets according to given conditions and executes service processing on the external service processing unit of the server 1. Let me.</p><p> By enabling the service processing to be executed on both the network connection device 2 and the server 1 as described above, the service processing that is difficult to realize on the network connection device 2 can be performed on the server 1, and the network. Even if the service requires complicated processing, it can be handled. (5) In (1) above, the network connection device 2 is provided with the distribution processing unit 2c and the service processing unit 2d, and the server 1 is provided with the packet detailed analysis unit (not shown). The packet is forwarded to the server 1 according to the given conditions, the server 1 analyzes the packet, determines the service, sets the determined service content in the network connection device 2, and the network connection device 2 subsequently performs the same session. The relay process is performed based on the service content set above.</p><p> As described above, the server 1 analyzes the packet to determine the service, sets the determined service content in the network connection device 2, and thereafter the network connection device 2 determines the service content for the same session based on the determined service content. By performing the relay processing, it is possible to realize the service processing at a higher speed than when all the processing is performed by the server 1.</p>
<p> According to the present invention, since the function previously arranged on the server is performed by the network connection device 2, the CPU usage rate of the server 1 can be reduced.</p>
FIG. 2 is a diagram showing a configuration of a packet relay processing device according to a first embodiment of the present invention. In the figure, reference numeral 11 denotes a server, which includes a network control unit 12, and the network control unit 12 writes the routing information input by the administrator into the routing table 23a of the network connection device 20 through the control information communication unit 31. .. The control information communication unit 31 is, for example, a PCI (Peripheral Components Interconnect) bus or a serial interface.
Reference numeral 20 denotes a network connection device, and the network connection device 20 of this embodiment integrates a plurality of network connection devices 104 shown in FIG. 39, and includes a packet processing unit 21, a session management unit 22, and a session table 22a. The network connection device 20 performs packet processing, session management, routing processing, and the like performed by the server of FIG. 38, which includes the routing processing unit 23 and the routing table 23a.
In FIG. 2, the packet shown in FIG. 3 input from the network is sent to the packet processing unit 21 of the network connection device 20 through the network connection unit 30. The network connection 30 is, for example, an Ethernet® controller.
The packet processing unit 21 performs the processing shown in the flowchart of FIG. 4 to be described later, and sends the packet to the session management unit 22. The session management unit 22 manages the session as shown in the flowchart of FIG. 5 described later, and passes the packet to the packet processing unit 21.
The packet processing unit 21 processes the packet as shown in FIG. 4 described later, and outputs the packet to the network via the network connection unit 30. FIG. 4 shows the processing flow of the packet processing unit.
As shown in the figure, the packet processing unit 21 buffers the packet input from the network (step S1) and checks the checksum (step S2). Next, the packet processing unit 21 defragmentes the packet (step S3) and sends the packet to the session management unit 22 (step S4).
Then, the packet processing unit 21 performs fragmentation of the packet sent from the session management unit 22 (step S5), recalculates the checksum (step S6), and outputs the packet to the network. The processing in the packet processing unit 21 is the same as the processing in the conventional packet processing unit.
Figure 5 shows the processing flow of the session management unit 22. As shown in the figure, when a packet is sent to the session management unit 22, the session management unit 22 searches the session data corresponding to the packet from the session table 22a (step S11). Session table 22a is a table that stores session data for managing sessions. Figure 6 shows a configuration example of session table 22a. As shown in Figure 6, the session data includes the session ID (IDentifier) that identifies the session, the session search key (destination / source address, destination / source port, protocol) for uniquely determining the session, and the session. It has the status and output destination as items.
In step S11, the session management unit 22 searches the session table 22a using information such as the source / destination IP address in the IP header of the packet, the protocol in the TCP header, the source / destination port, and the like as keys.
If the session data whose session search key matches the information in the header of the packet sent to the session management unit 22 is not registered in the session table 22a (step S12: No), the sent packet Is the first packet of a session, so the session management unit 22 registers the session data related to that session in the session table 22a (step S13). That is, in step S13, the session management unit 22 displays the session search key (destination / source address, destination / source port, etc.) in the session table 22a shown in FIG. 6 based on the information in the header of the sent packet. Write the protocol) and session status.
Next, the routing processing unit 23 searches the routing table 23a, and writes the output destination obtained as a result of the search to the session table 22a (step S14). On the other hand, if session data whose session search key matches the information in the header of the packet is registered in the session table 22a (step S12: Yes), the session management unit 22 inspects the status of the session. Then, it is determined whether or not the state changes (step S15). Then, when the state changes (step S15: Yes), the session management unit 22 rewrites the session state in the session table 22a (step S16).
Then, when the session state transition is completed and the session is closed, that is, when the session states are TIME_WAIT and CLOSED (step S17: Yes), the session management unit 22 sets the session search key, the session state, and the session state regarding the session. Delete the output destination etc. from the entry in session table 22a (step S18). Then, the processed packet is sent to the output destination. If the session status is not session closed (step S17: No), the session management unit 22 does not perform step S18, and the processed packet is sent to the output destination.
The judgment of the above state transition differs between TCP and other protocols. Hereinafter, TCP and other protocols will be described separately. Figure 7 shows the session status in the case of TCP. For TCP, session state As shown in Fig. 7, six states of CLOSED, SYN_RECV, ESTAB, FIN_RECV, FIN_SENT, and TIME_WAIT are set in.
As shown in FIG. 6, in the session state of the session table 22a, which of the above five states excluding CLOSED is written. When the session is not registered, the state is CLOSED, and if a SYN packet arrives in this state, the session state transitions to SYN_RECV. At that time, the session management unit 22 rewrites the "session state" of the session table 22a to SYN_RECV. Then, the session state transitions to the ESTAB <Established> state, and packets are sent and received. Then, the session ends with the FIN packet. By detecting the arrival of the SYN packet and the FIN packet in the same manner below, the session management unit 22 can detect the start and end of the session.
Figure 8 shows an example of the state transition from the start of the session to the end of the session in the case of TCP. As shown in the figure, when communicating between the client and the server, the client first sends a SYN packet. Then, the server returns a SYN_ACK packet, and in response, the client sends an ACK packet to the server. As a result, the session state changes from the SYN state to the ESTAB (Established) state, and thereafter, the client and the server send and receive packets to and from each other. Then, when terminating the session, for example, the client sends a FIN packet to the server, the server sends a FIN_ACK packet to the client, and in response, the client sends an ACK packet to the server, thereby terminating the session ( CLOSED state).
On the other hand, except for TCP, there are no SYN or FIN flags in the packet. Figure 9 shows the state transition in the case of UDP as an example. When a packet belonging to a session not registered in the session table 22a arrives as shown in FIG. 9, the session management unit 22 sets the session status to ESTAB. Since the end of the session cannot be detected, the session management unit 22 responds by deleting the session from the session table 22a when the packet does not pass for a certain period of time by the timer.
As described above, in the present embodiment, the network connection device 20 is provided with a packet relay processing function based on session management, and the network connection device 20 fulfills the function previously arranged on the server 11. The CPU usage of server 11 can be reduced.
In addition, since the session management unit 22 is provided in the network connection device 20 and the output destination is registered in the session table 22a at the start of the session, even if the entry in the routing table 23a is changed in the middle of the session, the session is currently ongoing. Can be consistent.
FIG. 10 is a diagram showing a configuration of a packet relay processing device according to a second embodiment of the present invention. In this embodiment, in the packet relay processing device of the first embodiment shown in FIG. 2, the server transfer unit 24 that transfers session information to the server 11, the session information communication unit 32 that communicates session information, and an external session. The management unit 13 and the external session table 13a are provided. Then, when the session table 22a of the network connection device 20 becomes full, the external session management unit 13 provided in the server 11 manages the session. Other operations are the same as in the first embodiment.
FIG. 11 shows the processing flow in the session management unit and the external session management unit in this embodiment. As shown in the figure, when a packet is sent to the session management unit 22, the session management unit 22 and the external session management unit 13 use the information stored in the header of the packet as a search key in the session table 22a and the external session. Search table 13a (step S21). The session tables 22a and 13a are tables that store information for managing the session described with reference to FIG.
If the session data whose session search key matches the information in the header of the packet sent to the session management unit 22 is not registered in the session table 22a and the external session table 13a (step S22: No), the packet Is the first packet of a session, so the session management unit 22 first checks whether the session table 22a is full (step S23).
If the session table 22a is not full (step S23: No), the session management unit 22 registers the session data of the session in the session table 22a as described above (step S24). Then, the routing processing unit 23 searches the routing table 23a, and writes the output destination to the session table 22a (step S25).
If session data whose session search key matches the information in the packet header is registered in the session table 22a (step S22: Yes), the session management unit 22 inspects the session status and status. Determines if is transitioning (step S26). Then, when the state changes (step S26: Yes), the session management unit 22 rewrites the session state of the session data stored in the session table 22a (step S27).
Then, after the session state transition is completed, in the case of session closing (step S28: Yes), the session management unit 22 deletes the session data from the entry in the session table 22a (step S29). The processed packet is sent to the output destination.
On the other hand, when registering the first packet of the session, if the session table 22a is full (step S23: Yes), the external session management unit 13 of the server 11 performs the same process as above.
That is, as described in step S24 and step S25, the external session management unit 13 registers the session data of the session of the packet in the external session table 13a (step S30), and the routing processing unit 23 uses the routing table. And write the output destination to the external session table 13a (step S31).
If session data whose session search key matches the information in the header of the packet is registered in the external session table 13a (step S22: Yes), the external session management unit 13 uses the external session table 13a. The session state is inspected to determine if the session state transitions (step S26). When the state changes, the external session management unit 13 rewrites the session state of the external session table 13a (step S27). Then, after the session state transition is completed, in the case of session closing (step S28: Yes), the external session management unit 13 deletes the session data from the entry in the session table 13a (step S29).
As described above, in the present embodiment, the network connection device 20 is provided with a packet relay processing function based on session management, and the network connection device 20 fulfills the function previously arranged on the server 11. Similar to the first embodiment, the CPU usage rate of the server 11 can be reduced. Further, as in the first embodiment, even if the routing table is changed in the middle of the session, the consistency can be maintained for the currently ongoing session.
Further, when the number of sessions exceeds the number that can be registered in the session table of the network connection device 20, since the external session management unit 13 provided in the server 11 manages the sessions, the amount overflowed by the network connection device 20 is used as the server. It will be possible to manage with 11.
In the above description, the external session management unit 13 is provided in the server 11 and the session management is performed by the server 11, but only the external session table 13a is provided in the server 11 and the session management is performed by the session management unit 22 of the network connection device 20. The session overflowing with the session table 22a may be registered in the above external session table 13a.
FIG. 12 is a diagram showing a configuration of a packet relay processing device according to a third embodiment of the present invention. According to this embodiment, the processing distribution unit 26, the service processing unit 27, and the policy table 25 are provided in the network connection device 20, and the network connection device 20 performs filtering, load balancing, NAT, etc. according to the policy set by the server 11. Execute the service processing of.
In the figure, 11 is a server, the server 11 includes a service control unit 14, and the service control unit 14 writes a policy to the policy table 25 of the network connection device 20 through the control information communication unit 31. Here, the policy is a rule for executing services such as filtering and load balancing. For example, in the case of filtering, whether to discard or pass packets within the range of the policy search key is set based on the policy. In the case of load balancing, the virtual (representative) IP address: port number and the IP address: port number of all the distribution destination servers are set based on the policy. In the case of NAT, the translated IP address: port number is set based on the policy.
Reference numeral 20 denotes a network connection device, and the network connection device 20 of the present embodiment includes a packet processing unit 21, a session management unit 22, and a session table 22a'as in the first embodiment. It includes a processing distribution unit 26 and a plurality of service processing units 27. A plurality of service processing units 27 are provided according to the type of service applied to the packet.
According to this embodiment, when the session management unit 22 receives the packet, the session management unit 22 searches the session data from the session table 22a'using the information in the header of the received packet. Then, when the session data indicated by the information in the header of the packet is registered in the session table 22a', almost the same processing as above is performed.
On the other hand, if the session data indicated by the information in the header of the packet is not registered in session table 22a', the session management unit 22 refers to policy table 25 and is based on the policy to be applied to the packet. , Create session data and store the created session data in session table 22a'.
The processing distribution unit 26 determines the application service for the packet based on the session data stored in the session table 22a', and distributes the processing to the service processing unit 27 corresponding to the determined application service. The plurality of service processing units 27 perform processing required for each service.
Hereinafter, the session table 22a'and the policy table 25 according to this embodiment will be described with reference to FIGS. 13 and 14. FIG. 13 shows a structural example of the session table 22a'related to this embodiment. The session table 22a'is a table for storing session data for managing the session as described above. The session data includes the session ID, session search key (destination / source address and port, protocol, etc.), session status, output destination, and the like as items. In this embodiment, as shown in FIG. 13, in addition to the above information, the session data includes the applicable service type (filtering, load balancing, etc.), its service-specific information (distribution destination address, etc.), and consistency. Includes retention time, event flag, etc. as items. The applicable service type indicates the service to be applied to the packet. Service-specific information indicates information specific to the service to be applied. For example, when the applicable service type is load balancing, the distribution destination address can be considered as service-specific information. Consistency retention time indicates the amount of time that session data should be retained after the session ends. That is, session data is not deleted from session table 22a'at the end of the session until the consistency retention time elapses. The event flag indicates whether to log the packet or the packet header. If the event flag is "on", the packet or packet header is forwarded to the server and logged by the server.
Figure 14 shows a configuration example of the policy table. The policy table stores policies that are rules for executing services on packets. As shown in Figure 14, the policy includes policy ID, policy search key, applicable service type, service-specific information, priority, group ID, event flags, consistency retention time and number of policy hits.
The policy ID is information that identifies the policy. The policy search key is information for determining the policy to be applied to the packet. The applicable service type indicates the service applied to the packet based on the policy. Service-specific information, like session data, indicates information specific to the applicable service. The priority is a numerical value indicating the priority of the policy. The lower the priority value, the higher the policy. The priority is used to determine which policy should be prioritized if the information in the packet header matches the policy search keys of multiple policies. The group ID is information that identifies the group to which the policy belongs. The event flag and consistency retention time are the same as the session data. The number of policy hits stores the count value of the session corresponding to the policy.
The description of the processing using the event flag, the consistency retention time, the group ID, and the number of policy hits will be described later as a modification of each modification. Hereinafter, the operation of the packet relay processing apparatus according to the third embodiment shown in FIG. 12 will be described with reference to FIGS. 15 to 19.
First, in the packet relay processing device shown in FIG. 12, the packet input from the network passes through the network connection unit 30 and is sent to the packet processing unit 21. As shown in the processing flow of FIG. 4 described above, the packet processing unit 21 performs buffering of the input packet, checks the checksum, and defragmentation, and then sends the packet to the session management unit 22. Then, the packet processing unit 21 performs fragment and checksum recalculation for the packet sent from the session management unit 22, and outputs the packet to the network via the network connection device 30.
FIG. 15 shows the processing flow of the session management unit 22 of this embodiment. As shown in the figure, when a packet is sent to the session management unit 22, the session management unit 22 searches the session data from the session table 22a'shown in FIG. 13 using the information in the header of the packet. (Step S41).
Similar to the first embodiment, the session table is searched by using the source / destination IP address in the IP header of the packet, the protocol in the TCP header, and the source / destination port information as keys.
If the session data whose session search key matches the information in the packet header is not registered in the session table 22a'(step S42: No), it is the first packet of the session, and the session management unit 22 performs the session. The policy is searched from the policy table 25 shown in FIG. 14 using the information in the header of the packet in order to determine the application service for (step S43).
The policy table 25 has routing information, as well as a policy search key (destination / source address and port, protocol, which can be arbitrary or ranged) and an applied service type (filtering discard or load balancing) that specifies the range to which the service applies. , Etc.), information specific to the service (all distribution destination addresses, etc.), and priority.
As a result of the search, if the entry in policy table 25 matches the information in the packet header, write the policy in the applicable service type column of session table 22a'. That is, the session management unit 22 acquires a policy having a policy search key that matches the information stored in the header of the packet from the policy table 25. Subsequently, the session management unit 22 creates session data using the information in the packet header as the session search key, and registers the session data in the session table 22a'. Further, the session management unit 22 writes the applicable service type and the service-specific information included in the policy in the applied service type column and the service-specific information column of the registered session data, respectively (step S44).
However, if multiple policies are matched, the policy table 25 is processed in descending order of priority. If the same service matches multiple times, the one with the highest priority is adopted and the rest are invalidated.
Hereinafter, when a policy table 25 is searched, the processing when there are a plurality of policies having a policy search key that matches the information stored in the packet header will be described more specifically.
First, if the applied service types included in the acquired policies do not conflict with each other, the session management unit 22 selects the multiple applied service types in ascending order of priority (that is, in descending order of priority). Write in the application service type column of session data. As a result, the packet receives a plurality of applicable services in descending order of priority.
In addition, when the applied service types included in the acquired multiple policies conflict with each other, the session management unit 22 selects only the applied service type of the policy having the lowest policy priority value among the multiple policies in the session data. Fill in the applicable service type field. This ensures that the packet receives only the highest priority applicable service.
Hereinafter, a specific example will be described. It is assumed that the following 6 policies are acquired as policies having a policy search key that matches the information stored in the header of a packet. Policy 1: Apply service = filter pass, priority = 10 Policy 2: Apply service = filter pass, priority = 100 Policy 3: Apply Services = Filtered, Priority = 200 Policy 4: Apply Services = Load Balancing, Priority = 1000 Policy 5: Apply Services = Load Balancing, Priority = 2000 Policy 6: Apply Services = Load Balancing, Priority = 3000 In this case, filter passing and load balancing are applicable service types that do not conflict with each other. Also, since all applicable service types from policy 1 to policy 3 pass the filter, they conflict with each other. Similarly, all applicable service types from Policy 4 to Policy 6 are load balanced and therefore conflict with each other. The session management unit 22 has the policy 1 with the lowest priority value among the policies whose applied service type is filtered, and the policy 4 with the lowest priority value among the policies whose applied service type is filtered. Is adopted. Next, since the filter pass priority of policy 1 is lower than the load balancing priority of policy 4, the session management unit 22 filters the filter pass first in the session data application service type column. Write pass and load balance. This causes the packet to receive a load balancing service after passing through the filter.
The process related to the session state transition from step S45 to step S48 performed when Yes is set in step S42 is the same as that described in the first embodiment. That is, when the session data is registered in the session table 22a', the session management unit 22 inspects the session state of the session table 22a'and determines whether or not the state changes (step S45). Then, when the session state changes (step S45: Yes), the session management unit 22 rewrites the state of the session table 22a'(step S46). Then, after the session state transition is completed, the session management unit 22 deletes the session data of the session from the entry of the session table 22a'(step S48). The processed packet is sent to the processing distribution unit 26 (step S49).
FIG. 16 shows the processing flow of the processing distribution unit 26 / service processing unit 27. The processing distribution unit 26 / service processing unit 27 determines the applicable service for the packet and performs the processing required for each service.
In FIG. 16, when a packet is input to the processing distribution unit 26, the processing distribution unit 26 searches the session table 22a'using the information in the header of the packet for the session data corresponding to the input packet. To do. When the applicable service type indicated by the session data obtained as a result of the search is routing processing (step S51), the processing distribution unit 26 distributes the processing to the service processing unit 27 that performs the routing processing.
If the routing destination is not written in the session table 22a'corresponding to the input packet, the routing table (not shown) of the policy table 25 is pulled and the output destination interface and the destination MAC address are written in the session table 22a'.
More specifically, the processing distribution unit 26 determines whether or not the session data includes a routing destination (step S51). If the session data does not include a routing destination (step S51: Yes), the service processing unit 27 to which the processing is assigned uses the destination IP address included in the session data in the routing table (not shown in FIG. 12). Is searched, the output destination interface and the destination MAC address obtained as a result of the search are determined as the routing destination (step S52), and the determined routing destination is written to the session data (step S53). After that, the packet of the session corresponding to the session data is forwarded to the determined routing destination. Subsequently, the service processing unit 27 proceeds to step S56.
Further, the processing distribution unit 26 refers to the application service type column of the session data obtained as a result of searching the session table 22a', and the input packet is a packet that should receive the load balancing service and is distributed to the session data. When it is determined that the distribution destination server is not included, that is, it is determined that the distribution destination server has not been determined yet (step S56: Yes), the processing distribution unit 26 performs service processing for load balancing processing. Allocate processing to part 27. The service processing unit 27 to which the processing is distributed determines the distribution destination server (step S57), writes the determined distribution destination address in the service-specific information column of the corresponding session table 22a'(step S58), and then Proceed to step S61.
Further, if the processing distribution unit 26 refers to the application service type column of the session data obtained as a result of searching the session table 22a'and determines that the input packet is a packet that should receive the filtering discard service (step). S61: Yes), the processing distribution unit 26 distributes the processing to the service processing unit 27 that performs packet discard processing. The service processing unit 27 to which the processing is distributed discards the packet (step S62) and ends the processing. If the determination in step S61 is No, the process proceeds to step S63.
The processing distribution unit 26 refers to the application service type column of the session data obtained as a result of searching the session table 22a', and if the input packet is a packet that executes load balancing or NAT service, the input packet is a header. Determine that the packet should be rewritten (step S63: Yes). The processing distribution unit 26 distributes the processing to the service processing unit 27 that performs the header rewriting processing. The service processing unit 27 to which the processing is distributed rewrites the IP header of the packet, the source / destination IP address, the source / destination port, etc. on the TCP header according to the session data stored in the session table 22a'. Step S64) End the process. When a plurality of application services are stored in the session data, the plurality of application services are executed in the input packet in the order in which they are stored.
As described above, in this embodiment, as in the first embodiment, the CPU usage rate of the server 11 can be reduced, and even if the routing table is changed in the middle of the session, it is currently ongoing. Consistency can be maintained for sessions.
Further, since the processing distribution unit 26 and the plurality of service processing units 27 corresponding to the plurality of services are arranged in the network connection device 20 capable of processing faster than the server 11, the CPU usage rate of the server can be reduced. At the same time, the service processing can be speeded up.
Further, according to the present embodiment, the network connection device 20 is provided with a plurality of service processing units 27 according to the service. As a result, when a new service is required, a flexible configuration that can be easily handled by adding a new service processing unit 27 corresponding to the required service to the network connection device 20 can be provided. Realize. For example, when a new VPN (Virtual Private Network) encryption service or decryption service is required, a service processing unit 27 that performs the VPN encryption service and a service processing unit 27 that performs the decryption service are newly added. It is possible to deal with this by doing so.
Hereinafter, the header rewriting process will be described in more detail with reference to FIG. FIG. 17 shows a packet flow when the network connection device 20 performs the load balancing service in this embodiment. The packet flow shown in FIG. 17 corresponds to the session data in which the session IDs are 2 and 3 in the session table 22a'shown in FIG. The direction of the arrow indicates the direction in which the packet is transmitted.
When a packet is sent from a client with an address of 10.25.1.230 to a server with an address of 192.168.100.75, first, as shown by arrow A1, the client sends a "destination address: 192.168.100.75, send" to the network connection device 20. The packet P1 containing "original address: 10.25.1.230" in the header is transmitted. The session management unit 22 of the network connection device 20 refers to the session table 22a'shown in FIG. 13 using the source address 10.25.1.230 and the destination address 192.168.100.75 included in the packet P1 as keys, and the session ID = 3. Get session data.
Since the applicable service type in the acquired session data is "header rewriting", the processing distribution unit 26 in the network connection device 20 distributes the processing to the service processing unit 27 that performs the header rewriting processing. Since the unique information in the session data is "destination address: 192.168.100.100", the service processing unit 27 to which the processing is distributed changes the destination address in the packet P1 from "192.168.100.75" to "192.168.100.100". rewrite. As a result, as shown by arrow A2, the packet P2 in which "destination address: 192.168.100.100, source address: 10.25.1.230" is stored in the header from the network connection device 20 to the distribution destination server whose address is 192.168.100.100. Is sent.
Conversely, when a packet is sent from the distribution destination server with the address 192.168.100.100 to the client with the address 10.25.1.230, first, as shown by arrow A3, the distribution destination server goes to the network connection device 20. The packet P3 containing "destination address: 10.25.1.230, source address: 192.168.100.100" in the header is transmitted. The session management unit 22 of the network connection device 20 refers to the session table 22a'shown in FIG. 13 using the source address and the destination address included in the packet P3 as keys, and acquires the session data in which the session ID = 2.
Since the entry in the applicable service type column in the acquired session data is "header rewriting", the processing distribution unit 26 in the network connection device 20 distributes the processing to the service processing unit 27 that performs the header rewriting processing. The service processing unit 27 to which the processing is distributed rewrites the source address in the packet from "192.168.100.100" to "192.168.100.75" based on the unique information in the session data. As a result, as shown by arrow A4, packet P4 containing "destination address: 10.25.1.230, source address: 192.168.100.75" in the header is transmitted from the network connection device 20 to the client whose address is 10.25.1.230. To. In this way, the network connection device 20 can distribute the load on the destination server of the packet by rewriting the header of the packet.
FIG. 18 is a diagram showing a configuration of a packet relay processing device according to a fourth embodiment of the present invention. In this embodiment, in the packet relay processing device of the third embodiment, the processing distribution unit 26 is provided with a server transfer function, and the server 11 is provided with an external service processing unit 15 to perform service processing by the network connection device 20. It can be executed on both server 11 and server 11. In this embodiment, when the service process is executed on the server 11, it is set in the policy table 25 that not only the contents of the service but also the transfer to the server 11 is performed. Other operations are the same as in the third embodiment.
As shown in FIG. 18, the external service processing unit 15 is provided with a plurality of external service processing units 15 in the server 11 according to the applicable service type, similarly to the service processing unit 27 according to the third embodiment. Therefore, similarly to the service processing unit 27 in the third embodiment, when a new service type is required, it is easy to add a new external service processing unit 15 corresponding to the new service type to the server 11. It is possible to correspond to.
Since the configurations of the session table 22a'and the policy table 25 related to this embodiment are almost the same as those of the third embodiment, detailed description thereof will be omitted. The difference is that, according to the fourth embodiment, in addition to the content of the service performed by the service processing unit 27, the content of the service transferred to the server 11 and performed by the external service processing unit 15 is described in the session table 22a'and the policy table 25. Can be set to.
Hereinafter, FIG. 19 shows the processing procedure in the processing distribution unit 26, the service processing unit 27, and the external service processing unit 15 of this embodiment. In FIG. 19, the processes from step S51 to step S64 are the same as those in FIG. For example, in the session data in the session table 22a'corresponding to the input packet, when the applicable service type is "routing" and the routing destination is not written, the service processing unit 27 performs the routing of the policy table 25. Look up the table and write the output destination interface and destination MAC address to the session data in session table 22a'.
In this way, referring to the applicable service type in session table 22a', if server transfer is not set in the applied service type, processing is performed according to the applied service type as described in FIG. In the case of a header rewriting packet, the header is rewritten.
Further, according to this embodiment, a part of the service is performed by the external service processing unit 15 in the server 11. Therefore, the processing distribution unit 26 performs the following procedure in addition to the processing of steps S51 to S64 in FIG.
That is, the processing distribution unit 26 refers to the application service type column of the session data obtained by searching the session table 22a'and determines whether or not the input packet is a packet to be transferred to the server 11. (Step S71). When "Server transfer: ON" and the applicable service type are set in the application service type field of the session data (step S71: Yes), the processing distribution unit 26 performs a process of attaching a transfer header to the packet. Allocate the processing to the service processing unit 27. The service processing unit 27 to which the processing is distributed attaches a transfer header to the packet. The contents of the transfer header are, for example, the applicable service type, the session ID of the session data of the packet, and the input interface. Subsequently, the service processing unit 27 transfers the packet to the external service processing unit 15 of the server 11 via the packet communication unit 33 (step S72). The external service processing unit 15 corresponding to the applicable service type processes the received packet (step S73).
The processing flow of the external service processing unit 15 is the same as that in FIG. 16 described above. For example, when the routing destination is undecided in the session data, the external service processing unit 15 determines the routing destination and writes the output destination interface and the destination MAC address in the session table 22a'.
If the input packet is a packet that should receive the load balancing service and the distribution destination has not yet been determined in the session data, the external service processing unit 15 determines the distribution destination server and the corresponding session table. Write in the service-specific information field of the session data in 22a'. If the input packet is a packet that should receive the filtering discard service, the external service processing unit 15 discards the packet.
If the input packet is a packet that should receive load distribution or NAT service, the external service processing unit 15 sets the IP header of the packet, the source / destination IP address on the TCP header, the source / destination port, and the like. Rewrite according to the session data in session table 22a'.
In the above, the case where the external service processing unit 15 performs the same service as the service content in the network connection device 20 has been described. However, in the external service processing unit 15, for example, encryption, decryption, proxy, content conversion, Service processing that is not performed on the network connection device 20 such as protocol conversion may be performed.
As described above, in the present embodiment, the network connection device 20 is provided with a packet relay processing function based on session management so that the network connection device 20 fulfills the functions conventionally arranged on the server. As a result, the CPU usage rate of the server can be reduced as in the first embodiment. Further, as in the first embodiment, even if the routing table is changed in the middle of the session, the consistency can be maintained for the currently ongoing session. Further, the processing distribution unit 26 is provided with a function of forwarding packets to the server, and the server 11 is provided with an external service processing unit 15 so that service processing can be executed by both the network connection device 20 and the server 11. , Service processing that is difficult to realize on the network connection device 20 can be performed on the server 11, and even if the network service requires complicated processing, it can be handled.
Next, the fifth embodiment will be described. FIG. 20 is a diagram showing a configuration of a packet relay processing device according to a fifth embodiment of the present invention. As shown in FIG. 21, the packet relay processing device according to the present embodiment further includes a packet detailed analysis unit 16 in the server 11 constituting the packet relay processing device according to the third embodiment. With this configuration, the processing distribution unit 26 of the network connection device 20 forwards the packet to the server 11 according to the given conditions, and the packet detail analysis unit 16 in the server 11 analyzes the packet and provides the service. Determined and set the determined service content in the network connection device 20. Then, for the same session after the setting, the network connection device 20 performs relay processing based on the service content determined above.
In FIG. 20, reference numeral 11 denotes a server, the server 11 includes a service control unit 14 as in the third and fourth embodiments, and the service control unit 14 passes through the control information communication unit 31 as described above. , Write the policy to the policy table 25 of the network connection device 20. Further, the service control unit 14 also writes the policy in the detailed analysis policy table (not shown in FIG. 20) provided in the server 11.
Further, the server 11 includes a packet detailed analysis unit 16, and the packet detailed analysis unit 16 analyzes a packet based on a session table and a policy table for packet detailed analysis (not shown), and for a session including the packet. Determine the service, and reset the session data of the session table 22a'of the network connection device 20 for the determined service content. After resetting, the network connection device 20 performs relay processing based on the above service content. The data structure of the session table and policy table for detailed analysis will be described later.
Similar to the service processing unit 27 and the external service processing unit 15 of the third and fourth embodiments, a plurality of packet detailed analysis units 16 are also provided in the server 11 according to the applicable service type. Therefore, when a new service type is required, it can be easily handled by adding a new packet detail analysis unit 16 corresponding to the new service type to the server 11.
Reference numeral 20 denotes a network connection device, and the network connection device 20 of this embodiment has a packet processing unit 21, a session management unit 22, a session table 22a', a policy table 25, and a processing distribution unit 26, as in the third embodiment. , The service processing unit 27 is provided, and the processing distribution unit 26 has a function of forwarding packets to the server.
The operations of the packet processing unit 21, the session management unit 22, the processing distribution unit 26, and the service processing unit 27 are the same as those in the third embodiment. Since the data structure of the policy table 25 related to this embodiment is the same as that of the third embodiment, the description thereof will be omitted. The data structure of the session table 22a'related to this embodiment will be described later.
Further, in this embodiment, the packet to be transferred to the packet detail analysis unit 16 by the server 11 in advance in the applicable service column of the policy table 25 and the applicable range of the applied service (for example, http is a packet to which URL filtering is applied). Etc.). The processing distribution unit 26 refers to the policy table 25 to determine the packet to be transferred to the server 11, and attaches the type of applicable service type to the header of the packet, as described in the fourth embodiment. After that, the packet is transferred to the packet detailed analysis unit 16 of the server 11 via the packet communication path 33.
Hereinafter, the data structure of each table related to this embodiment will be described with reference to FIGS. 21 to 26. First, the session table 22a'related to this embodiment will be described with reference to FIGS. 21 to 24. As shown in FIGS. 21 to 24, the items included in the session data stored in the session table 22a'are the same as those in the session table 22a' shown in FIG. However, according to this embodiment, after the session data is registered in the session table 22a', the packet detail analysis unit 16 analyzes the packet and resets the session data in the session table 22a' based on the analysis result. ..
21 and 22 show an example of the session table 22a'when the session management unit 22 registers the session data based on the policy table 25. As shown in FIGS. 21 to 22, since the analysis by the packet detail analysis unit 16 has not been performed yet, "Server transfer: ON" is displayed in the applicable service type column of each session data. Therefore, the session packet corresponding to the session data is transferred to the server 11.
23 and 24 show an example of the session table 22a'after the packet detail analysis unit 16 resets the session data based on the packet analysis result. As shown in FIGS. 23 and 24, since the analysis was performed by the packet detailed analysis unit 16, "server transfer: OFF" is displayed in the applicable service type column of each session data. Therefore, thereafter, the session packet corresponding to each session data will not be forwarded to the server 11.
Further, as a result of the session data being reset by the packet detailed analysis unit 16, the session table 22a'shown in FIGS. 21 and 22 and the session table 22a'shown in FIGS. 23 and 24 further have the following points. different.
-As shown in Fig. 21, "URL filtering" is stored in the column of the application service type of session data with session ID = 0 and 1. On the other hand, as a result of packet analysis by the packet detail analysis unit 16, it was decided to pass the packet. Therefore, filtering pass is stored in the same column of the session data of the same session ID shown in FIG. 23.
-As shown in Fig. 21, "URL load balancing" is stored in the application service type column of the session data with session ID = 2 to 5, but the information about the distribution destination server is stored in the unique information column. It has not been. On the other hand, as a result of packet analysis by the packet detailed analysis unit 16, the distribution destination server is determined. Therefore, as shown in FIG. 23, the session data having session IDs = 3 and 4 is deleted, and session IDs = 2 and 5 are used. "Header rewriting" is stored in the application service type column of a certain session data, and information about the distribution destination server is stored in the unique information column.
-As shown in Fig. 22, "FTP (File Transfer Protocol) filtering" is stored in the column of the application service type of the session data with session IDs = 6 and 7. After that, as a result of packet analysis by the packet detail analysis unit 16, it was decided to pass the packet of that session. Therefore, as shown in FIG. 24, in addition to the session data for the control connection with session IDs = 6 and 7, in addition to the session data. Session data for a data connection with session IDs = 8 and 9 is newly registered, and "filtering pass" is stored in the applicable service type column of the session data.
Next, the table provided in the packet detailed analysis unit 16 will be described with reference to FIGS. 25 and 26. The packet detailed analysis unit 16 includes a session table for detailed analysis and a policy table for detailed analysis in order to analyze the packet.
Figure 25 shows a configuration example of the session table for detailed analysis. The session table for detailed analysis shown in FIG. 25 corresponds to the session table 22a'shown in FIGS. 21 and 22. As shown in FIG. 25, the session data stored in the session table for detailed analysis includes the session ID, the session search key, the session state, the related session, and the applicable service type as items. Items other than related sessions are the same as the session data stored in session table 22a'. The related session is the session ID of the session determined to be related as a result of the packet detail analysis unit 16 analyzing the packet. The session data in the detailed analysis session table is registered by the packet detailed analysis unit 16 when performing detailed analysis based on the session data stored in the session table 22a', and when the detailed analysis is completed, the packet detailed analysis unit 16 Will be deleted by.
Figure 26 shows a configuration example of the policy table for detailed analysis. The detailed analysis policy table shown in FIG. 26 stores more detailed policies than the policy table 25 shown in FIG. For example, for URL filtering, a URL filtering URL table indicating whether to discard packets for each URL is provided in the detailed analysis policy table. Further, for example, for FTP filtering, an FTP filtering table indicating whether packets should be passed or discarded is provided for each IP address and port number. Furthermore, for example, for URL load balancing, a URL load balancing table or the like showing a candidate IP address of the distribution destination server and a distribution method is provided for each URL. The session table for detailed analysis shown in FIG. 25 corresponds to the session table 22a'shown in FIGS. 21 to 24.
Hereinafter, the operation concept of the packet relay processing device according to the fifth embodiment will be described with reference to FIG. 27. In FIG. 27, the solid arrow indicates the direction in which the packet travels, and the dashed arrow indicates the reading of data in the table and the writing of data to the table.
First, the service control unit 14 in the server 11 writes a policy to the policy table 25 of the network connection device 20 and the policy table for detailed analysis in the packet detailed analysis unit 16 via the control information communication unit 31 (arrow A11). ).
Subsequently, when a packet is input to the network connection device 20, the session management unit 22 refers to the policy table 25 using the information stored in the header of the packet, and the information in the header matches the policy search key. Gets the policy, creates session data based on that policy, and stores it in session table 22a'(arrow A12).
When "Server transfer: ON" is stored in the application service type column of the session data, the processing distribution unit 26 transfers the packet to the packet detailed analysis unit 16 via the packet communication unit 33. The packet detailed analysis 16 analyzes the packet using the detailed analysis policy table and the detailed analysis session table (arrow A13). The packet detail analysis unit 16 resets the session data stored in the session table 22a'in the network connection device 20 based on the packet analysis result (arrow A14). After the packet is analyzed, the packet input to the network connection device 20 is processed by the service processing unit 27 without being analyzed by the packet detail analysis unit 16 and output from the network connection device 20 (arrow A15).
Hereinafter, the operation of the packet relay processing device according to the fifth embodiment will be described. Since the processing procedure by the packet processing unit 21 and the session management unit 22 is the same as that in the first to fourth embodiments, the description thereof will be omitted. Hereinafter, the processing procedure by the processing distribution unit 26, the service processing unit 27, and the packet detailed analysis unit 16 will be described with emphasis.
FIG. 28 is a diagram showing a processing flow of the processing distribution unit 26 and the service processing unit 27. Of the processes shown in FIG. 28, the processes up to the header rewriting process (step S64) are the same as those in FIG. Further, according to the fifth embodiment, the processing distribution unit 26 determines whether or not the input packet is the corresponding packet to be forwarded to the server 11 based on the applicable service type included in the session data (step). S81). When "Server forwarding: ON" and the applicable service type are set in the applicable service type, the distribution processing unit 26 determines that the packet should be forwarded to the server 11 (step S81: Yes). ), The processing is distributed to the service processing unit 27 that performs the processing of attaching the forwarding header to the packet. The service processing unit 27 to which the processing is distributed attaches a transfer header to the packet. The content of the transfer header is the same as that of the fourth embodiment. The packet with the forwarding header is forwarded to the packet detailed analysis unit 16 of the server 11 via the packet communication unit 33 (step S82). The packet detail analysis unit 16 analyzes the received packet, and resets the session data stored in the session table 22a'via the control information communication unit 31 based on the analysis result (step S83).
FIG. 29 is a flowchart showing the processing procedure of the packet detailed analysis unit 16. The process shown in FIG. 29 corresponds to step S83 in FIG. 28. In this embodiment, a case where URL filtering, URL load balancing, and FTP filtering services are provided by using the packet detailed analysis unit 16 will be described as an example.
First, the URL filtering service will be described. In advance, the service control unit 14 of the server 11 sets the policy of "forwarding the packet to the packet detail analysis unit 16 and performing URL filtering" in the policy table 25 via the control communication information unit 31.
From the set conditions, the processing distribution unit 26 of the network connection device 20 transfers the corresponding packet to the packet detail analysis unit 16. The packet detail analysis unit 16 determines that the packet should receive the URL filtering service based on the applied service type "URL filtering" included in the forwarding header of the received packet. The packet detailed analysis unit 16 creates session data based on the information contained in the received packet and stores it in the detailed analysis session table (step S91: Yes). After that, the packet detail analysis unit 16 manages the state of the session and outputs the received packet to the network as it is until the HTTP GET request is received.
When an HTTP GET request is received after the session status becomes ESTAB (step S92: Yes), the packet detail analysis unit 16 determines the URL and determines the passage / discard of the packet. That is, the packet detailed analysis unit 16 determines the passage / discard of the packet by referring to the URL filtering URL table included in the preset detailed analysis policy table using the URL included in the packet. (Step S93).
If it is determined that the packet is to be discarded (step S93: Yes), the packet detail analysis unit 16 discards the packet for that session (step S103). Further, the packet detail analysis unit 16 refers to the session table 22a'using the session ID included in the packet, and sets the column of the application service type of the session data corresponding to the session ID to "Server forwarding: ON / URL filtering". Rewrite from to "discard" (not shown).
If it is determined that the packet is to be passed (step S93: No), the packet detail analysis unit 16 refers to the session table 22a'and applies the session data corresponding to the session ID included in the packet. Rewrite the column of "Server transfer: ON / URL filtering" to "Pass filtering" (step S94). The session data with session ID = 0 and 1 in the session table 22a'shown in FIGS. 21 and 23 are examples of session data before and after packet analysis in the case of URL filtering, respectively.
After resetting the session data in the session table 22a', the packet detailed analysis unit 16 deletes the session data corresponding to the session ID from the detailed analysis session table (not shown).
As described above, the packet detail analysis unit 16 resets the application service type of the session data in the session table 22a'of the network connection device 20 from "server transfer: ON" to "filtering pass" or "discard". Then, the network connection device 20 processes the subsequent packets according to the above passage conditions. That is, the network connection device 20 passes or discards the packet without forwarding the packet to the packet detail analysis unit 16 of the server 11.
FIG. 30 is a diagram illustrating the operation of the URL filtering. Exchange SYN, SYN_ACK, and ACK packets between the client and server. Until the session transitions to the ESTAB state, those packets are transferred from the network connection device 20 to the packet detailed analysis unit 16, and the packet detailed analysis unit 16 manages the state of the session. That is, the processing is performed by the "network connection device 20" and the "server 11".
When the session transitions to the ESTAB state and receives an HTTP GET request (with a URL such as GET "http://www.xxx.co.jp"), the packet detail analysis unit 16 of the server 11 , Refer to the URL filtering URL table included in the detailed analysis policy to determine whether the packet with the above URL is a packet to be discarded or a packet to be passed, and based on the determination result, the session table 22a' Rewrite the entry in the Applicable Service Type column to "Discard" or "Pass".
After that, the network connection device 20 discards or passes the packet until the end of the session, depending on the applicable service type set in the session table 22a'. That is, the processing is performed by the "network connection device 20".
Next, returning to FIG. 29, the URL load balancing service will be described. In URL load balancing, for example, after a client accesses a representative server, another server connected to the representative server is determined as the distribution destination server based on the URL, and the session is distributed to the distribution destination server. , The load can be distributed to multiple distribution destination servers.
When performing URL load balancing, the service control unit 14 of the server 11 first applies the policy of "forwarding packets to the packet detail analysis unit 16 to perform URL load balancing" in the policy table 25 via the control communication information unit 31. Set in the applicable service type field.
From the set conditions, the processing distribution unit 26 of the network connection device 20 transfers the corresponding packet to the packet detail analysis unit 16 of the server 11. The packet detail analysis unit 16 determines that the packet is a packet that should receive the URL load balancing service based on the applied service type URL load balancing included in the received packet. The packet detailed analysis unit 16 creates session data based on the information contained in the received packet and stores it in the detailed analysis session table in the same manner as in the case of URL filtering. Further, the packet detail analysis unit 16 makes a proxy response based on the source address, destination address, port number, etc. included in the header of the packet, registers the session data related to each other, and the related session column of the session data. Stores the session ID of the associated session data in (step S95: Yes).
In the session table for detailed analysis shown in FIG. 25, the session data with session IDs = 2 to 5 is an example of session data in the case of URL load balancing. In FIG. 25, session data with session ID = 2 correlates with session data with session ID = 4, and session data with session ID = 3 correlates with session data with session ID = 5. You can see that you are doing it.
The packet detail analysis unit 16 establishes a connection between the client and the server 11, and subsequently manages the session status. In addition, the packet detail analysis unit 16 has a function of terminating TCP (Transmission Control Protocol), and the packet detail analysis unit 16 responds to the client instead of the distribution destination server until the distribution destination server is determined. Do. When the packet detail analysis unit 16 receives an HTTP GET request after the session status becomes ESTAB (step S96: Yes), the packet detail analysis unit 16 sets in advance using the URL included in the packet. The distribution destination server is determined by referring to the URL load balancing table included in the detailed analysis policy table (step S97). After that, the server 11 establishes a connection with the distribution destination server by exchanging SYN, SYN_ACK, and ACK packets.
Further, the packet detail analysis unit 16 refers to the session data 22a'of the network connection device 20 and acquires the session data corresponding to the session ID included in the packet. Then, the packet detail analysis unit 16 rewrites the applicable service type included in the acquired session data from "server transfer: ON / URL load balancing" to "server transfer: OFF / header rewriting". Further, the packet detail analysis unit 16 sets the IP address: port number and the sequence number / ACK number difference in the session data unique information column according to the determined IP address of the distribution destination server and the like (step S98). ). As a result, the two session data determined to be related to each other are combined into one session data, so that the two connections can be treated as one connection. Further, the packet detail analysis unit 16 deletes the remaining two unnecessary data out of the four session data from the session table 22a'.
After resetting the session data in the session table 22a', the packet detailed analysis unit 16 deletes the session data corresponding to the session ID from the detailed analysis session table (not shown). Then, the server 11 sends an HTTP GET request to the distribution destination server.
The session data with session IDs = 2 to 5 in the session table 22a'shown in FIGS. 21 and 23 are examples of session data before and after packet analysis in the case of URL load balancing, respectively. The two connections represented by the two session data with session IDs = 2 and 4 in FIG. 21 are combined into one connection represented by the session data with session ID = 2 in FIG. 23. Similarly, the two connections represented by the two session data with session IDs = 3 and 5 in FIG. 21 are combined into one connection represented by the session data with session ID = 5 in FIG. 23.
After parsing the packet, the packet is not sent to the packet detail analysis unit 16. The service processing unit 27 that performs header rewriting processing of the network connection device 20 rewrites the IP address: port number, sequence number, and ACK number in the packet based on the unique information in the session data stored in the session table 22a'. After that, the packet is output to the network.
FIG. 31 is a diagram illustrating the operation of the URL load balancing service. As shown in FIG. 31, SYN, SYN_ACK, and ACK packets are exchanged between the client and the packet relay processing device. When the session transitions to the ESTAB state and receives an HTTP GET request, the packet detail analysis unit 16 determines the URL of the GET request and determines the distribution destination server.
Then, in the same manner as above, the SYN, SYN_ACK, and ACK packets are exchanged between the packet relay processing device and the distribution destination server, and an HTTP GET request is sent to the distribution destination server. Up to this point, processing is performed by "network connection device 20" + "server 11".
After sending an HTTP GET request from the packet relay processing device to the distribution destination server, the network connection device 20 sends the distribution destination to the client based on the session data stored in the session table 22a'until the session ends. Perform relay processing with the server.
Next, returning to FIG. 29, the FTP filtering service will be described. FTP consists of multiple TCP connections, one for control and one for data transfer.
In advance, the service control unit 14 of the server 11 sets the policy of "forwarding the packet to the packet detail analysis unit 16 and performing FTP filtering" in the policy table 25 via the control communication information unit.
From the set conditions, the processing distribution unit 26 of the network connection device 20 transfers the corresponding packet to the detailed analysis unit 16. As in the case of URL filtering, the packet detail analysis unit 16 determines that the packet should receive the FTP filtering service based on the applicable service type included in the received packet, and determines that the packet should receive the FTP filtering service, and the packet detail analysis unit 16 Stores session data in the session table for detailed analysis (step S99: Yes). Subsequently, the packet detail analysis unit 16 manages the session state and outputs the received packet to the network as it is.
When the ACK packet of the FTP PORT instruction or PASV instruction is received (step S100: Yes) after the session state becomes ESTAB, as shown in FIG. 32, the packet detailed analysis unit 16 receives the IP included in the packet. The address and port number are determined, and based on the determination result, it is determined whether to pass or discard the packet of the session (step S101).
That is, the packet detailed analysis unit 16 refers to the FTP filtering table in the detailed analysis policy table set in advance using the IP address and the port number, and determines whether to pass or discard the packet of the session. To do. When it is decided to discard the packet (step S101: Yes), the packet detail analysis unit 16 acquires the session data corresponding to the session ID included in the packet transfer header from the session table 22a', and the session data is obtained. Set "discard" in the applicable service type field of, and discard the packet (step S103).
If it is determined to pass the packet (step S101: No), the packet detail analysis unit 16 uses the IP address and port number described in the data part of the ACK packet of the previous PORT instruction or PASV instruction. Based on, the session data about the data connection is registered in the session table 22a', and "filtering pass" is set in the field of the applicable service type of the session data (step S102).
When the packet detail analysis unit 16 resets the session data in the session table 22a'as described above, the network connection device 20 processes the packets related to the subsequent data connections according to the above passage conditions. That is, the packet is passed or discarded without being forwarded to the packet detail analysis unit 16 of the server 11.
FIG. 32 is a diagram illustrating the operation of the FTP filtering. Until the SYN, SYN_ACK, and ACK packets are exchanged between the client and server 11 and the state transitions to the ESTAB state, the packet is transferred to the packet detailed analysis unit 16 and the "network connection device 20" + "server 11" Processing is done.
When the session status changes to the ESTAB status and the ACK (with IP address and port number) of the FTP PORT instruction or PASV instruction is received, the packet detail analysis unit 16 uses the IP address and port included in the packet. Refer to the detailed analysis policy table using the number and decide whether to discard or pass the packet. When deciding to discard the packet, the packet detail analysis unit 16 sets the session data in the session table 22a'to discard the packet. When deciding to pass the packet, the packet detail analysis unit 16 registers the session data about the data connection in the session table 22a'and resets "pass" in the applicable service type column. After that, the network connection device 20 performs packet discard processing or data connection packet passage processing.
Finally, when the packet relay processing device receives the FIN packet of the control connection from the client, the packet is transferred from the network connection device 20 to the session detailed analysis unit 16 of the server 11 via the packet communication unit 33. The server 11 closes the session via the session detailed analysis unit 16. Further, the session detailed analysis unit 16 deletes the session data regarding the session to be closed based on the session ID included in the packet transfer header.
Hereinafter, with reference to FIGS. 33 and 34, the packet flow in the fifth embodiment will be described by taking the case of the URL load balancing service as an example. Each figure corresponds to the session data of session ID = 2 to 5 stored in the session table shown in FIGS. 21, 23, and 25. FIG. 33 shows the packet flow before the session data is reset by the packet detail analysis unit 16.
Before the session data is reset, as shown by arrow A21, the client whose address: port number is 192.168.30.30:11950 sends "destination address: port number = 192.168.200.1:http, to network connection device 20". The packet P11 containing "original address: port number = 192.168.30.30:11950" in the header is transmitted. The session management unit 22 of the network connection device 20 refers to the policy table 25, acquires a policy in which the information in the header matches the policy search key, and creates session data with session ID = 2 based on the policy. , Store in session table 22a'.
Since the applicable service type in the session data is "server transfer: ON / URL load balancing", the processing distribution unit 26 in the network connection device 20 distributes the processing to the service processing unit 27 that performs the server transfer processing. After the service processing unit 27 to which the processing is distributed attaches a forwarding header to the packet, the packet is forwarded to the server 11 as shown by arrow A22. The packet detailed analysis unit 16 of the server 11 registers the session data in the detailed analysis session table based on the information contained in the transferred packet.
Similarly, when packets P12, P13 and P14 are output from the server 11 to the client via the route shown by arrows A23 to A28, the session data with session ID = 3, 4 and 5, respectively, is the session. The session management unit 22 stores the session data in the table 22a', and the packet detailed analysis unit 16 stores the corresponding session data in the detailed analysis session table.
After registering the session data in each session table, the packet detail analysis unit 16 manages the state of each session until an HTTP GET request is received, and network the received packets based on the packet flow shown in FIG. 33. Output to.
After that, when the HTTP GET request is received after the session status becomes ESTAB, the packet detail analysis unit 16 analyzes the packet and sets the session data stored in the session table 22a'based on the analysis result. fix. The session data after resetting is as shown in FIG. 23.
FIG. 34 shows the packet flow after the session data is reset by the packet detail analysis unit 16. After the session data is reset, as shown by arrow A31, from the distribution destination server to the network connection device 20, "Destination address: 192.168.200.1:3333 as port number, source address: 192.168.200.10 as port number" When the packet P14 containing ": 8080" in the header is transmitted, the processing distribution unit 26 of the network connection device 20 refers to the session table 22a'using the information contained in the header of the packet, and the session ID = The session data of 5 is acquired, and the processing is distributed to the service processing unit 27 that performs the header rewriting processing based on the session data. Based on the session data, the service processing unit 27 sets the destination address and port number in the header of the packet to "192.168.30.30:11950" and the client address and port number to "192.168.200.1:http". Is rewritten to create packet P12. After that, as shown by arrow A32, the network connection device 20 outputs the packet P12 to the distribution destination server.
Similarly, as shown by arrow A33, from the client whose address: port number is 192.168.30.30:11950 to network connection device 20, "destination address: port number = 192.168.200.1: http, source address: port number = 192.168". .30.30:11 950 The packet P11 containing "" in the header is transmitted. The processing distribution unit 26 of the network connection device 20 refers to the session table 22a'using the information included in the header of the packet, and acquires the session data in which the session ID = 2. In the case of this example, since "server transfer: OFF / header rewriting" is stored in the applied service type column of the acquired session data, the processing distribution unit 26 processes the service processing unit 27 that performs the header rewriting processing. Sort out. Based on the session data, the service processing unit 27 rewrites the destination address and port number in the header of the packet to the address and port number of the distribution destination server to "192.168.200.10:8080", thereby transmitting the packet P13. create. After that, the network connection device 20 outputs the packet P13 to the distribution destination server as shown by the arrow A34.
In this way, after the session detailed analysis unit 16 rewrites the session data based on the packet analysis result, the network connection device 20 performs the packet relay processing without going through the server 11.
As described above, in the present embodiment, the network connection device 20 is provided with a packet relay processing function based on session management, and the network connection device 20 fulfills the function previously arranged on the server. Similar to the embodiment of, the CPU usage rate of the server 11 can be reduced. Further, as in the first embodiment, even if the routing table is changed in the middle of the session, the consistency can be maintained for the currently ongoing session.
Further, according to the fifth embodiment, the packet detail analysis unit 16 of the server 11 analyzes the packet to determine the service, sets the determined service content in the network connection device 20, and then connects to the network for the same session. The device 20 performs relay processing based on the service content determined above. Therefore, the service processing can be realized at a higher speed than the case where all the processing is performed by the server 11.
Hereinafter, modifications of each embodiment will be described. First, the first modification will be described. By applying the first modification in the first to fifth embodiments, the session data is not deleted immediately after the session ends, but the session data is transferred to the session table 22a'after a certain period of time has elapsed. You may do it.
To that end, according to the first variant, the entries in policy table 25 and session table 22a'also include a consistency retention time, as shown in FIGS. 13 and 14, 21-24. Hereinafter, the processing performed by the packet relay processing device according to the first modification will be described. In the first modification, a part of the processing performed by the session management unit 22 is different from that in the first to fifth embodiments. The processing performed by the session management unit 22 when the first modification is applied will be described with reference to FIG.
In step S17 of FIG. 5, when the session management unit 22 determines that a session is closed (step S17: Yes), the session management unit 22 sets a timer. After waiting for the consistency retention time included in the session data, the session management unit 22 proceeds to step S18 in FIG. 5 and deletes the session data from the session table 22a'.
As a result, if the session is reestablished after the session ends and before the consistency retention time elapses, the session management unit 22 advances the session if there is no change in the session search key. It will be possible to treat it as the same session as the session that ended in. For example, in the load balancing service, it is possible to distribute packets to the same distribution destination server between a session that has ended once and a session that has been established again. As a result, it is possible to omit the search of the policy table 25 by the session management unit 22 and the transfer of the packet to the server 11 by the processing distribution unit 26, so that the packet can be processed at high speed.
Next, a second modification will be described. By applying the second modification in the third to fifth embodiments, it may be possible to easily switch the policy applied to the session. Therefore, according to the second variant, multiple policies are divided into several groups. Further, as shown in FIG. 14, the policy stored in the policy table 25 further includes, as an item, a group ID that identifies the group to which the policy belongs, and the network connection device 20 further includes the flag table shown in FIG. 35. ..
Hereinafter, the data structure of the flag table will be described with reference to FIG. 35. As shown in FIG. 35, the flag table stores flags indicating whether the policy is valid or invalid, corresponding to the group ID. In FIG. 35, as an example, the policy is invalid when the flag is "off (0)" and the policy is valid when the flag is "on (1)".
Hereinafter, the processing performed by the packet relay processing device according to the second modification will be described. In the second modification, a part of the processing performed by the session management unit 22 is different from that in the third to fifth embodiments. As an example, referring to FIG. 15 showing the processing performed by the session management unit 22 related to the third embodiment, the processing performed by the session management unit 22 changes by applying the second modification to each embodiment. The points will be explained in detail.
In the second modification, the session management unit 22 further performs the following processing between steps S43 and S44 of FIG. First, in step S43, the session management unit 22 searches the policy table 25 and obtains a policy having a policy search key that matches the information stored in the header of the packet. The session management unit 22 refers to the flag table using the group ID included in the obtained policy, and determines whether the flag corresponding to the group ID is on or off.
If the result of the determination is that the flag is off, the session management unit 22 does not adopt the policy. On the other hand, when the flag is on, the session management unit 22 adopts the policy. In step S44, the session management unit 22 creates session data based on the policy and stores it in the session table 22a'. This makes it possible to switch the policy to be adopted for each group.
For example, when a plurality of normal policies and a plurality of emergency policies are created, according to the second variant, the normal group consisting of the normal policies and the emergency policy consisting of the emergency policies are prepared in advance. Define a group and register both normal policy and emergency policy in policy table 25. Also, in the flag table, turn on the flag corresponding to the group that the user of the packet relay processing device wants to enable, that is, the group for either normal use or emergency use. This makes it possible to easily switch between the normal policy and the emergency policy for each group.
Next, a third modification will be described. In the third to fifth embodiments, the packet log may be collected by applying the third modification. Therefore, according to the third modification, the session data and the policy stored in the policy table 25 and the session table 22a'shown in FIGS. 13 and 14 and 21 to 24 further include an event flag as an item. ..
Event flags include event flags related to packets and event flags related to headers. If the event flag for a packet is "on (1)", the packet is forwarded to server 11 for log (history) collection. If the event flag for the header is on, the header of the packet is forwarded to server 11 for logging. The server 11 analyzes the transferred packet or the header of the packet and collects a log. As a result, for example, when a system failure occurs, it is possible to obtain useful information for recovering from the failure by analyzing the collected logs using network management software.
Next, a fourth modification will be described. According to the fourth modification, the network connection device 20 according to the first to fifth embodiments further includes a counter (not shown) in order to acquire statistical information about the packet. The network control unit 12 or the service control unit 14 of the server 11 refers to the value of the counter. As statistical information, for example, the number of packet inputs and the number of outputs for each interface can be considered. This statistical information can be used when charging a client or the like.
Further, for the third to fifth embodiments, as statistical information, for each policy stored in the policy table 25, the number of sessions to which the policy is applied, that is, the number of times the policy is hit. It is also possible to obtain the number of policy hits.
Therefore, according to the fourth modification, as shown in FIG. 14, the policy stored in the policy table 25 further includes the number of policy hits as an item. Then, when the session management unit 22 acquires the policy to be applied by referring to the policy table 25 in order to register the session data related to the new session in the session table 22a', the counter is a policy hit of the acquired policy. Increment the number. As a result, the network administrator can obtain information for determining whether or not the policy is effectively used.
Further, for the third to fifth embodiments, as statistical information, the number of distribution destination hits indicating the number of times the session is distributed is obtained for each distribution destination server in the load balancing service. Is also good.
Therefore, the policy related to the load balancing service stored in the policy table 25 shown in FIG. 14 or the policy table for detailed analysis shown in FIG. 26 further includes the number of distribution destination hits for each distribution destination server address as an item. Including. Then, each time the service processing unit 27 or the packet detail analysis unit 16 performs a process of determining the distribution destination server of the session, the counter determines the number of distribution destination hits corresponding to the server determined as the distribution destination server. Increment. This makes it possible for the network administrator to obtain information for determining whether or not the load balancing distribution method is operating effectively.
The programs indicating the processes performed by each part constituting the network connection device 20 and each part constituting the server 11 described in the present embodiment are recorded in memories such as RAM (Random Access Memory) and ROM (Read Only Memory), respectively. The packet relay processing device may be provided as hardware or software. This case will be described below.
FIG. 36 shows the configuration of a computer (information processing device). As shown in FIG. 36, the computer 40 includes at least a CPU 41 and a memory 42. Further, the computer 40 may include an input device 43, an output device 44, an external storage device 45, a medium drive device 46, and a network interface 47. Each device is connected to each other by a bus 48.
The memory 42 includes, for example, ROM, RAM, and the like, and stores programs and data used for processing. The CPU 41 performs necessary processing by executing a program using the memory 42.
When two or more computers 40 are to realize the functions corresponding to the server 11 and the network connection device 20 that constitute the packet relay processing device, first, the packet relay processing devices shown in FIGS. 2, 10, 12, 18, and 20 are configured. Prepare a program that shows the processing performed by each part. Then, a program indicating processing performed by each part provided in the server 11 (hereinafter, referred to as a program for the server 11) is stored in a specific program code segment of the memory 42 in the computer in which the server 11 should be realized.
In addition, a program (hereinafter referred to as a program for the network connection device 20) indicating processing performed by each part provided in the network connection device 20 is a specific program code segment of the memory 42 in the computer in which the network connection device 20 should be realized. Store in. Here, the CPU of the computer that should realize the network connection device 20 is, for example, a network processor. The processing performed by each of the above-mentioned parts is described above by using each flowchart.
The input device 43 is, for example, a keyboard, a pointing device, a touch panel, or the like, and is used for inputting an instruction or information from a user. The output device 44 is, for example, a display, a printer, or the like, and is used for making inquiries to users of the computer 40, outputting processing results, and the like.
The external storage device 45 is, for example, a magnetic disk device, an optical disk device, a magneto-optical disk device, or the like. The above-mentioned programs and data can be stored in the external storage device 45, and if necessary, they can be loaded into the memory 42 for use.
The medium driving device 46 drives the portable recording medium 49 and accesses the recorded contents. The portable recording medium 49 includes a memory card, a memory stick, a flexible disc, a CD-ROM (Compact Disc Read Only Memory), an optical disc, a photomagnetic disc, a DVD (Digital Versatile Disk), and the like, which can be read by any computer. A medium is used. The above-mentioned programs and data can be stored in the portable recording medium 49, and if necessary, they can be loaded into the memory 42 and used.
The network interface 47 communicates with an external device via an arbitrary network (line) such as LAN or WAN, and performs data conversion associated with the communication. Further, if necessary, the above-mentioned programs and data can be received from an external device and loaded into the memory 42 for use.
FIG. 37 is a diagram illustrating a computer-readable recording medium and transmission signal capable of supplying programs and data to the computer of FIG. 36. Packet relay processing to two or more computers by supplying the above-mentioned programs and data stored in each table to a computer that should realize the server 11 and a computer that should realize the network connection device 20 using a recording medium. It is also possible to perform a function corresponding to the device.
For that purpose, the above-mentioned programs and data are stored in advance in a computer-readable recording medium 49. Then, as shown in FIG. 37, the medium driving device 46 is used to read the program or the like for the server 11 from the recording medium 49 to the computer that should realize the server 11, and the memory 42 of the computer (server 11) is read. It is temporarily stored in the external storage device 45, and the CPU 41 of the computer (server 11) reads out the stored program and executes it.
Similarly, a program or the like for the network connection device 20 is temporarily stored in the memory 42 or the like of the computer that should realize the network connection device 20 from the recording medium 49, and the program stored in the CPU 41 of the computer (network connection device 20). Is read and executed.
Further, instead of having the computer that should realize the server 11 and the computer that should realize the network connection device 20 read the program or the like from the recording medium 49, the communication line (network) is transmitted from the DB 50 owned by the program (data) provider. The program may be downloaded to each computer via 51. In this case, for example, in a computer having a DB50 and transmitting a program, the program data representing the above program is converted into a program data signal, and the converted program data signal is modulated by using a modem. The transmission signal is obtained and the obtained transmission signal is output to the communication line 51 (transmission medium). The computer that receives the program obtains the program data signal by demodulating the received transmission signal using a modem, and obtains the program data by converting the obtained program data signal.
Next, with reference to FIG. 38, the loading of programs and data into the computer that should realize the server 11 and the computer that should realize the network connection device 20 will be described in more detail with an example.
As shown in FIG. 38, the computers that should realize the server 11 and the network connection device 20 each have a CPU and a memory, and are connected via the control information communication unit 31 described above. Further, for example, when the control information communication unit 31 is a PCI bus, the network connection device 20 may be realized as a NIC (Network Interface Card) for PCI.
For example, when there is a recording medium on which a program or the like for the server 11 and a program or the like (firmware) for the network connection device 20 are recorded, first, a medium drive device (not shown) provided in the computer to realize the server 11 is used. Then, the program for the server 11 and the program for the network connection device 20 are loaded from the recording medium into the memory of the server 11 (arrow A41). Subsequently, the program or the like for the network connection device 20 stored in the memory of the server 11 is loaded into the memory of the network connection device 20 via the control information communication unit 31 (arrow 42). In this way, it is possible to supply the necessary programs and the like to the computer that should realize the server 11 and the computer that should realize the network connection device 20. The CPU of the server 11 executes the program for the server 11 loaded in the memory of the server 11, and the CPU of the network connection device 20 executes the program for the network connection device 20 loaded in the memory of the network connection device 20. To do.
Needless to say, instead of loading the program or the like from the recording medium as described above, it may be recorded in the ROM or the like in advance. Further, a transmission signal may be used instead of the recording medium to supply a program or the like to the computer that should realize the server 11.
Further, in the network connection device 20, ASIC (Application Specific Integrated Circuit) may be used instead of the CPU, and each part constituting the network connection device 20 may be configured by hardware.
Although the embodiments of the present invention have been described above, the present invention is not limited to the above-described embodiments, and various other modifications are possible. As described above, the following effects can be obtained in the present invention. (1) A packet relay processing unit based on session management is provided in the network connection device, and the network connection device performs relay processing based on session management. As a result, the CPU usage rate of the server can be reduced. In addition, by managing the session on the network connection device and registering the output destination in the session table at the start of the session, even if the routing table is changed in the middle of the session, the consistency is maintained for the currently ongoing session. it can. (2) The number of sessions is the number registered in the session table of the network connection device by providing an external session management function on the server of the packet relay processing device, transferring session information from the network connection device to the above server, and managing the session by the server. Even if the number exceeds the above, the server can manage the amount overflowed by the network connection device. <3> By arranging the processing distribution unit and multiple service processing units in a network connection device that can process faster than the server, the CPU usage rate of the server can be reduced and the service processing can be speeded up. be able to. (4) By providing an external service processing unit on the server so that the service processing can be executed by both the network connection device and the server, the service processing that is difficult to realize on the network connection device 2 is performed on the server. By enabling the network connection device to perform relay processing based on the service content determined above, it is possible to realize service processing at a higher speed than when all processing is performed by the server. (Appendix 1) A packet relay processing device that has a network connection device. The session management unit where the above network connection device manages sessions, and It has a packet processing unit that relays packets based on session management by the session management unit. A packet relay processing device characterized by this. (Appendix 2) The network connection device further includes a routing table for storing routing information regarding the routing destination of the packet, and a routing table. Further, a routing processing unit for determining the routing destination of the packet based on the routing information at the start of the session is provided. The packet processing unit outputs the packet to the routing destination. The packet relay processing device according to Appendix 1, wherein the packet relay processing device is described. (Appendix 3) The packet relay processing device further includes a server. The server includes a network control unit that writes the routing information in the routing table. The packet relay processing device according to Appendix 1, wherein the packet relay processing device is described. (Appendix 4) The packet relay processing device further includes a server. The server includes an external session management unit that manages the session. The session management unit transfers the session information related to the session to the server according to the given conditions, and then transfers the session information to the server. The external session management unit manages the session based on the received session information. The packet relay processing device according to Appendix 1, wherein the packet relay processing device is described. (Appendix 5) The above network connection device further includes a processing distribution unit and a plurality of service processing units. The processing distribution unit distributes the packet to at least one of the plurality of service processing units based on the content of the service for the packet. The service processing unit to which the packet is distributed executes the service processing for the packet. The packet relay processing device according to Appendix 1, wherein the packet relay processing device is described. (Appendix 6) The packet relay processing device is further equipped with a server. The above server is equipped with an external service processing unit. The processing distribution unit forwards the packet to the server according to the given conditions, and then transfers the packet to the server. The external service processing unit executes a service for the received packet. The packet relay processing device of Appendix 5 characterized by this. (Appendix 7) The packet relay processing device is further equipped with a server. The above server is equipped with a packet detailed analysis unit. The network connection device further includes a processing distribution unit and a service processing unit. The processing distribution unit transfers the packet to the packet detailed analysis unit according to a given condition, and then transfers the packet to the packet detail analysis unit. The packet detail analysis unit determines the service content for the packet by analyzing the packet, sets the determined service content in the network connection device, and sets the determined service content in the network connection device. After the above setting, the network connection device processes the packet based on the determined service content. The packet relay processing device according to Appendix 1, wherein the packet relay processing device is described. (Appendix 8) The packet relay processing device according to Appendix 5, wherein the service processing unit has a function of rewriting the header of the packet. (Appendix 9) The packet relay processing device according to Appendix 5, wherein the service processing unit has a function of discarding packets. (Appendix 10) The packet relay processing device according to Appendix 5, wherein the service processing unit has a function of determining a load distribution destination for load balancing of the server. (Appendix 11) The network connection device includes a session table that stores session information related to the session and a policy table that stores a policy that describes a rule for executing a service for the packet. When the session management unit receives the packet, the session management unit searches the session table using the information contained in the packet as a search key. If the corresponding session information is not registered in the session table as a result of the above search, the session management unit further acquires the above policy from the above policy table based on the search key for the information contained in the above packet. Then, based on the obtained policy, write the session information to the session table, If the corresponding session information is registered in the session table as a result of the above search, the session management unit manages the session information stored in the session table based on the state of the session. The packet relay processing device according to Appendix 5, which is a feature. (Appendix 12) The above packet relay processing device is equipped with a server. The server includes a service control unit that writes the policy to the policy table. The packet relay processing device according to Appendix 11, wherein the packet relay processing device is described. (Appendix 13) The description in Appendix 11, wherein the search key for searching the session table includes the destination and source IP address of the IP packet, the protocol, the destination and source port numbers, and the input interface. Packet relay processing device. (Supplementary note 14) The packet relay processing device according to Supplementary note 11, wherein the session table has the search key, the state of the session, the applicable service, and information unique to the applicable service as entries. (Appendix 15) The policy table is characterized by having the destination and source IP address of the IP packet, the protocol, the destination and the source port number, the applicable service and the information unique to the applicable service, and the priority as an entry. The packet relay processing device according to Appendix 11. (Appendix 16) The packet relay processing device according to Appendix 1, wherein the session management unit further deletes session information related to the completed session from the session table after a predetermined time has elapsed from the end of the session. (Appendix 17) The packet relay processing apparatus according to Appendix 1, wherein the network connection device further includes a counter for acquiring statistical information about the packet. (Appendix 18) Multiple policies are divided into multiple groups. The packet relay processing device according to Appendix 11, wherein the network connection device further sets whether or not each policy is valid for each group. (Supplementary Note 19) The packet relay processing device according to Appendix 12, wherein the network connection device further transfers at least a part of the packet to the server in order to collect a log of the packet. (Appendix 20) The packet relay processing device according to Appendix 18, wherein a part of the packet is a header of the packet. (Appendix 21) The session information includes server transfer instruction information indicating whether or not the packet should be transferred to the server, and the processing distribution unit transfers the packet to the server based on the server transfer instruction information. The packet relay processing apparatus according to Appendix 12, characterized in that it determines whether or not to perform the above. (Appendix 22) Further, when the packet transferred to the server is an HTTP protocol GET packet, the packet detailed analysis unit provides a service for the packet based on the URL (Uniform Resource Locator) included in the packet. To decide, The packet relay processing device according to Appendix 7, wherein the packet relay processing device is described. (Appendix 23) If the packet transferred to the server is an ACK of the FTP protocol PORT instruction or PASV instruction, the packet detailed analysis unit is based on the IP address and port number of the data connection of the session. To determine the service for the above packet, The packet relay processing device according to Appendix 7, wherein the packet relay processing device is described. (Appendix 24) When performing the process of distributing the load of the server, the packet detail analysis unit is characterized in that it responds on behalf of the distribution destination server until the distribution destination server to be the distribution destination of the load is determined. The packet relay processing device according to Appendix 7. (Appendix 25) By analyzing the packet, the packet detail analysis unit writes the service type, conversion IP address and port number, sequence number, and ACK number difference for the packet in the session table. The packet relay processing device according to Appendix 21, wherein the packet relay processing device is described. (Appendix 26) A network connection device in a packet relay processing device. The session management unit where the above network connection device manages sessions, and It has a packet processing unit that relays packets based on session management by the session management unit. A network connection device characterized by that. (Appendix 27) The network connection device includes a server transfer unit that transfers session information related to the session to a server provided in the packet relay processing device according to a given condition . The server manages the session based on the transferred session information. The network connection device of Appendix 26, which is characterized in that. (Appendix 28) The above network connection device further includes a processing distribution unit and a plurality of service processing units. The processing distribution unit distributes the packet to at least one of the plurality of service processing units based on the content of the service for the packet. The service processing unit to which the packet is distributed executes the service processing for the packet. The network connection device of Appendix 26, which is characterized in that. (Appendix 29) The processing distribution unit transfers the packet to a server provided in the packet relay processing device according to a given condition, and causes the server to execute service processing for the packet. The network connection device of Appendix 26, which is characterized in that. (Appendix 30) The above network connection device further includes a processing distribution unit and a service processing unit. The processing distribution unit forwards the packet to a server provided in the packet relay processing device according to a given condition in order to determine a service for the packet. After the service is determined by the server, the service processing unit processes the packet of the session based on the service content determined by the server. The network connection device of Appendix 26, which is characterized in that. (Appendix 31) A program that causes a computer equipped with a network connection device to execute control for relaying packets. Manage sessions and Relay the packet based on the session management A program characterized by causing the above-mentioned computer to execute a process including the above. (Appendix 32) Transfer the session information about the session to the server connected to the network connection device according to the given conditions so that the server can manage the session. The program according to Appendix 31, wherein the computer is made to execute a process including the above. (Appendix 33) Based on the content of the service for the packet, the packet is distributed to the device or program segment that performs the processing corresponding to the service. The program according to Appendix 31, wherein the computer is made to execute a process including the above. (Appendix 34) The packet is forwarded to a server connected to the network connection device in order to cause the server to execute a service for the packet according to a given condition. The program according to Appendix 33, wherein the computer is made to execute a process including the above. (Appendix 35) Depending on the given conditions, the packet is forwarded to the server connected to the network connection device in order to determine the service for the packet. After the service for the packet is determined by the server, the packet is processed based on the determined service content. The program according to Appendix 31, which comprises causing the above-mentioned computer to execute a process including the above. (Appendix 36) A program to be executed by a server connected to a network connection device that has a function of relaying packets. In order for the network connection device to process the packet, a policy describing a rule for executing a service for the packet is set in the network connection device. A program characterized by causing the above server to execute a process including the above. (Appendix 37) Receive the packet transferred from the network connection device, and execute the service for the received packet. The program according to Appendix 36, which comprises causing the above-mentioned server to execute a process including the above. (Appendix 38) A program to be executed by a server connected to a network connection device that has a function of relaying packets. Upon receiving the packet transferred from the network connection device, By analyzing the packet, the content of the service for the packet is determined. In order for the network connection device to process the packet based on the determined service content, the content of the determined service is set in the network connection device. A program characterized by causing the above server to execute a process including the above. (Appendix 39) A recording medium that records a program that causes a computer installed in a network connection device to execute control for relaying packets. Manage sessions and Relay the packet based on the session management A recording medium that records a program that causes the computer to execute processing including the above. (Appendix 40) Transfer the session information about the session to the server connected to the network connection device according to the given conditions so that the server can manage the session. The recording medium according to Appendix 39, which records a program for causing the computer to execute a process including the above. (Appendix 41) Based on the content of the service for the packet, the packet is distributed to the device or program segment that performs the processing corresponding to the service. The recording medium according to Appendix 39, which records a program for causing the computer to execute a process including the above. (Appendix 42) The packet is forwarded to a server connected to the network connection device in order to cause the server to execute a service for the packet according to a given condition. The recording medium according to Appendix 39, which records a program for causing the computer to execute a process including the above. (Appendix 43) Depending on the given conditions, the packet is forwarded to the server connected to the network connection device in order to determine the service for the packet. After the service for the packet is determined by the server, the packet is processed based on the determined service content. The recording medium according to Appendix 39, which records a program for causing the computer to execute a process including the above. (Appendix 44) A recording medium that records a program to be executed by a server connected to a network connection device that has a function of relaying packets. In order for the network connection device to process the packet, a policy describing a rule for executing a service for the packet is set in the network connection device. A recording medium that records a program that causes the above server to execute processing including the above. (Appendix 45) Receive the packet transferred from the network connection device, and execute the service for the received packet. The recording medium according to Appendix 44, which records a program for causing the server to execute a process including the above. (Appendix 46) A recording medium that records a program to be executed by a server connected to a network connection device that has a function of relaying packets. Upon receiving the packet transferred from the network connection device, By analyzing the packet, the content of the service for the packet is determined. In order for the network connection device to process the packet based on the determined service content, the content of the determined service is set in the network connection device. A recording medium that records a program that causes the above server to execute processing including the above.
<figref num="1">It is a figure explaining the outline of this invention.</figref><figref num="2">It is a figure which shows the structure of the packet relay processing apparatus of 1st Example of this invention.</figref><figref num="3">It is a figure which shows the frame structure of the forwarded packet.</figref><figref num="4">It is a figure which shows the processing flow of a packet processing part.</figref><figref num="5">It is a figure which shows the processing flow of a session management part.</figref><figref num="6">It is a figure which shows the configuration example of a session table.</figref><figref num="7">It is a figure which shows the state transition of TCP.</figref><figref num="8">It is a figure explaining the state transition from the start of a TCP session to the end of a session.</figref><figref num="9">It is a figure which shows the state transition of UDP.</figref><figref num="10">It is a figure which shows the structure of the packet relay processing apparatus of the 2nd Example of this invention.</figref><figref num="11">It is a figure which shows the processing flow in the session management part and the external session management part of the 2nd Example.</figref><figref num="12">It is a figure which shows the structure of the packet relay processing apparatus of the 3rd Example of this invention.</figref><figref num="13">It is a figure which shows the structural example of the session table which concerns on 3rd Example.</figref><figref num="14">It is a figure which shows the configuration example of the policy table which concerns on 3rd Example.</figref><figref num="15">It is a figure which shows the processing flow of the session management part of the 3rd Example of this invention.</figref><figref num="16">It is a figure which shows the processing flow in the processing distribution part and the service processing part of the 3rd Example.</figref><figref num="17">It is a figure which shows the packet flow in the load balancing service after the policy search is completed in the 3rd Example.</figref><figref num="18">It is a figure which shows the structure of the packet relay processing apparatus of 4th Example of this invention.</figref><figref num="19">It is a flowchart which shows the processing procedure in the processing distribution part, the service processing part and the external service processing part which concerns on 4th Example.</figref><figref num="20">It is a figure which shows the structure of the packet relay processing apparatus of the 5th Example of this invention.</figref><figref num="21">It is a figure (the 1) which shows an example of the session table which concerns on 5th Example.</figref><figref num="22">It is a figure (the 2) which shows an example of the session table which concerns on 5th Example.</figref><figref num="23">It is a figure (the 1) which shows an example of the session table after the completion of the packet detailed analysis in the 5th Example.</figref><figref num="24">It is a figure (the 2) which shows an example of the session table after the completion of the packet detailed analysis in the 5th Example.</figref><figref num="25">It is a figure which shows the configuration example of the session table for detailed analysis.</figref><figref num="26">It is a figure which shows the configuration example of the policy table for detailed analysis.</figref><figref num="27">It is a figure which shows the operation concept of the packet relay processing apparatus which concerns on 5th Example.</figref><figref num="28">It is a flowchart which shows the processing procedure in the processing distribution part, the service processing part and the packet detailed analysis part which concerns on 5th Example.</figref><figref num="29">It is a flowchart which shows the processing procedure in a packet detail analysis part.</figref><figref num="30">It is a figure explaining the operation of URL filtering.</figref><figref num="31">It is a figure explaining the operation of the URL load balancing service.</figref><figref num="32">It is a figure explaining the operation of FTP filtering.</figref><figref num="33">It is a figure which shows the packet flow in the URL load balancing service before detailed analysis in 5th Example.</figref><figref num="34">It is a figure which shows the packet flow in the URL load balancing service after detailed analysis in 5th Example.</figref><figref num="35">It is a figure which shows an example of the data structure of a flag table.</figref><figref num="36">It is a block diagram of a computer.</figref><figref num="37">It is a figure explaining the recording medium and transmission signal which supplies a program and data to a computer.</figref><figref num="38">It is a figure explaining the loading of a program and data to a server and a network connection device.</figref><figref num="39">It is a figure which shows the structure of the conventional packet relay processing apparatus.</figref>
Code description
1 server 2 Network connection device 11 server 12 Network control unit 13 External Session Management Department 13a External session table 14 Service control unit 15 External service processing unit 16 Packet detail analysis unit 20 Network connection device 21 Packet processing unit 22 Session Management Department 22a session table 22a'session table 23 Routing processing unit 23a Routing table 24 Server forwarding unit 25 Policy table 26 Processing distribution section 27 Service Processing Department 30 Network connection 31 Control Information and Communication Department 32 Session Information and Communication Department 33 Packet channel 40 computer 41 CPU 42 memory 43 Input device 44 Output device 45 External storage 46 Medium drive device 47 network interface 48 bus 49 Portable recording medium 50 database 51 lines A arrow P packet S step
Every citation, both ways
| Document | Relation | Office |
|---|---|---|
| JP200092119A | Cites | Japan |
10 members in 2 offices
Priority claims7
| Document | Office | Kind | Date |
|---|---|---|---|
| 2001090122 | Japan | A | |
| 2001090122 | Japan | A | |
| 2001090122 | Japan | – | |
| 2006297354 | Japan | A | |
| 2001200190122 | – | – | – |
| JP20010090122 | – | – | – |
| JP20060297354 | – | – | – |
Members10
| Document | Office | Kind | |
|---|---|---|---|
| US2002143955A1 | United States of America | A1 | |
| JP2002359637A | Japan | A | |
| US2006168328A1 | United States of America | A1 | |
| US7107348B2 | United States of America | B2 | |
| JP2007104700A | Japan | A | |
| JP3963690B2 | Japan | B2 | |
| US7433958B2 | United States of America | B2 | |
| JP2009217841A | Japan | A | |
| JP4365397B2This record | Japan | B2 | |
| JP5229109B2 | Japan | B2 |
12 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of no payment of annual feesLAPS | LAPS | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Report on retrievalJAPANESE INTERMEDIATE CODE: A971007A977 | A977 |
Numbers
- Publication
- 4365397
- Publication, DOCDB
- 4365397
- Publication, EPODOC
- JP4365397B
- Application
- 297354
- Application, DOCDB
- 2006297354
- Application, EPODOC
- JP20060297354
Titles2
- Japanese
- パケット中継処理装置
- English
- Packet relay processing device
Classification
- IPC, 2
- H04L12 56
- H04L12 70