Method, communication system and device for arp packet processing
Abstract
An Address Resolution Protocol (ARP) packet processing method, a communication system and a device are disclosed. The method includes: receiving an ARP packet, and judging the type of the ARP packet; when the ARP packet is an ARP request, responding to the ARP request if an entry corresponding to the ARP request is found in a locally configured ARP table; and when the ARP packet is an ARP response, reporting the ARP response if an entry corresponding to the ARP response is found in the locally configured ARP table and a reporting parameter in the entry indicates permission of reporting; or discarding the ARP response if no entry corresponding to the ARP response is found in the ARP table.

Term
1.5 yearsto projected expiry
Projected expiry 19 March 2028, counted from filing; an application has no term until it is granted.
- Priority
- Filed
- Published
- Today
- Projected expiry
15 claims: 5 independent, 10 dependent
- 1Um método de processamento de pacotes ARP (Address Resolution Protocol), caracterizado por compreender:a receção (101) de um pacote ARP e a avaliação do tipo do pacote ARP;quando o pacote ARP é um pedido ARP, a resposta (105) ao pedido ARP se uma entrada ARP correspondente ao pedido ARP for encontrada numa tabela ARP local;e quando o pacote ARP é uma resposta ARP, a comunicação (110) da resposta ARP se uma entrada ARP correspondente à resposta ARP for encontrada na tabela ARP local e um parâmetro de comunicação na entrada ARP correspondente à resposta ARP indicar permissão de comunicação;ou a rejeição (112) da resposta ARP se nenhuma entrada ARP correspondente à resposta ARP for encontrada na tabela ARP;em que a tabela ARP local é fornecida por um processador de plano de controlo a um processador de plano de encaminhamento ou configurada no processador de plano de encaminhamento diretamente.
- 2O método de processamento de pacotes ARP de acordo com a reivindicação 1, caracterizado por compreender ainda:quando o pacote ARP é o pedido ARP, a avaliação sobre se uma função ARP de proxy está ativada numa interface que recebe o pedido ARP se nenhuma entrada ARP correspondente ao pedido ARP for encontrada na tabela ARP;se a função ARP de proxy estiver ativada, a limitação da velocidade do pedido ARP e, em seguida, a comunicação do pedido ARP a um processador de plano de controlo;e se a função ARP de proxy não estiver ativada, a rejeição do pedido ARP.
- 30 método de processamento de pacotes ARP de acordo com a reivindicação 1, caracterizado por compreender ainda:quando o pacote ARP é a resposta ARP (301), se a entrada ARP correspondente à resposta ARP for encontrada na tabela ARP (302) e o parâmetro de comunicação na entrada ARP correspondente à resposta ARP indicar sem permissão de comunicação (304), a limitação (306) da velocidade da resposta ARP e, em seguida, a comunicação da resposta ARP a um processador de plano de controlo ou a rejeição (307) da resposta ARP.
- 4O método de processamento de pacotes ARP de acordo com qualquer uma das reivindicações 1 a 3, caracterizado por compreender ainda:se o pacote ARP for o pedido ARP, a procura da tabela ARP de acordo com um número de porta do pedido ARP, um ID VLAN (Virtual Local Area NetWork) e um endereço IP (Internet Protocol) de destino.
- 5O método de processamento de pacotes ARP de acordo com qualquer uma das reivindicações 1 a 3, em que antes da resposta ao pedido ARP, o método é caracterizado por compreender ainda:se a entrada ARP correspondente ao pedido ARP não for uma entrada ARP da porta de conexão ou uma entrada ARP de proxy (205), a rejeição do pedido ARP (207).
- 60 método de processamento de pacotes ARP de acordo com qualquer uma das reivindicações 1 a 3, caracterizado por compreender ainda:se o pacote ARP for uma resposta ARP, a procura da tabela ARP de acordo com um endereço IP (Internet Protocol) de origem da resposta ARP.
- 70 método de processamento de pacotes ARP de acordo com qualquer uma das reivindicações 1 a 3, em que após a comunicação da resposta ARP, o método é caracterizado por compreender ainda:a modificação do parâmetro de comunicação na entrada ARP correspondente à resposta ARP na tabela ARP para sem permissão de comunicação.
- 80 método de processamento de pacotes ARP de acordo com qualquer uma das reivindicações 1 ou 2, caracterizado por a entrada ARP correspondente ao pedido ARP compreender:a relação correspondente entre o endereço IP de uma interface da porta de conexão e o endereço MAC da porta de conexão.
- 90 método de processamento de pacotes ARP de acordo com qualquer uma das reivindicações 1 ou 3, caracterizado por a entrada ARP correspondente à resposta ARP compreender:o parâmetro de comunicação a indicar permissão de comunicação.
- 10Um sistema de comunicação, caracterizado por compreender:um processador de plano de encaminhamento (402), configurado para receber um pacote ARP (Address Resolution Protocol) e avaliar o tipo do pacote ARP;quando o pacote ARP é um pedido ARP, responder ao pedido ARP se uma entrada ARP correspondente ao pedido ARP for encontrada numa tabela ARP local;quando o pacote ARP é uma resposta ARP, comunicar a resposta ARP se uma entrada ARP correspondente à resposta ARP for encontrada na tabela ARP local e um parâmetro de comunicação na entrada ARP correspondente à resposta ARP indicar permissão de comunicação;ou rejeitar a resposta ARP se nenhuma entrada ARP correspondente à resposta ARP for encontrada na tabela ARP;e um processador de plano de controlo (403), configurado para receber a resposta ARP ou o pedido ARP comunicado pelo processador de plano de encaminhamento;em que a tabela ARP local é fornecida por um processador de plano de controlo a um processador de plano de encaminhamento ou configurada no processador de plano de encaminhamento diretamente.
- 11O sistema de comunicação de acordo com a reivindicação 10, caracterizado por o processador de plano de encaminhamento (402) compreender:uma unidade de avaliação (501), configurada para avaliar o tipo de um pacote ARP (Address Resolution Protocol) recebido;uma primeira unidade de procura (502), configurada para procurar uma tabela ARP local quando a unidade de avaliação determina que o pacote ARP é um pedido ARP;uma unidade de resposta (503), configurada para responder ao pedido ARP se a primeira unidade de procura encontrar uma entrada ARP correspondente ao pedido ARP;uma segunda unidade de procura (504), configurada para procurar a tabela ARP local quando a unidade de avaliação determina que o pacote ARP é uma resposta ARP;e uma unidade de rejeição (506), configurada para rejeitar a resposta ARP se a segunda unidade de procura não encontrar nenhuma entrada correspondente à resposta ARP.
- 12O sistema de comunicação de acordo com a reivindicação 11, caracterizado por o processador de plano de encaminhamento (402) compreender ainda:uma unidade de limitação de velocidade (509), configurada para limitar a velocidade do pacote ARP e comunicar o pacote ARP a um processador de plano de controlo;uma unidade de avaliação de interface (508), configurada para avaliar se uma função ARP de proxy está ativada numa interface que recebe o pedido ARP quando a primeira unidade de procura não encontra nenhuma entrada ARP correspondente ao pedido ARP recebido na tabela ARP;se a função ARP de proxy estiver ativada, dar instruções à unidade de limitação de velocidade para limitar a velocidade do pedido ARP e comunicar o pedido ARP;se a função ARP de proxy não estiver ativada, dar instruções à unidade de rejeição para rejeitar o pedido ARP.
- 13O sistema de comunicação de acordo com qualquer uma das reivindicações 11 ou 12, caracterizado por o processador de plano de encaminhamento (402) compreender ainda:uma unidade de verificação (505), confiqurada para avaliar se um parâmetro de comunicação na entrada ARP correspondente à resposta ARP indica permissão de comunicação quando a entrada ARP correspondente à resposta ARP é encontrada na tabela ARP;e uma unidade de comunicação (507), configurada para comunicar a resposta ARP quando o parâmetro de comunicação na entrada ARP correspondente à resposta ARP indica permissão de comunicação.
- 14O sistema de comunicação de acordo com qualquer uma das reivindicações 10 a 12, caracterizado por a entrada ARP correspondente ao pedido ARP compreender:a relação correspondente entre o endereço IP de uma interface da porta de conexão e o endereço MAC da porta de conexão.
- 150 sistema de comunicação de acordo com qualquer uma das reivindicações 10 a 13, caracterizado por a entrada ARP correspondente à resposta ARP compreender:o parâmetro de comunicação a indicar permissão de comunicação.
Independent claims15
138 paragraphs in 5 sections, as filed
(57) Summary:
A METHOD, COMMUNICATION SYSTEM AND ARP PACKAGE PROCESSING DEVICE ARE ADVERTISED (ADDRESS RESOLUTION PROTOCOL - ADDRESS RESOLUTION PROTOCOL). THE METHOD INCLUDES: THE RECEPTION OF AN ARP PACKAGE AND THE EVALUATION OF THE TYPE OF THE ARP PACKAGE; WHEN THE ARP PACKAGE IS AN ARP ORDER, THE RESPONSE TO THE ARP ORDER IF AN ENTRY CORRESPONDING TO THE ARP ORDER IS FOUND IN A LOCALLY CONFIGURED ARP TABLE; AND WHEN THE ARP PACKAGE IS AN ARP RESPONSE, THE ARP RESPONSE COMMUNICATION IF AN ENTRY CORRESPONDING TO THE ARP RESPONSE IS FOUND IN THE LOCALLY CONFIGURED ARP TABLE AND A COMMUNICATION PARAMETER IN THE INPUT INDICATE COMMUNICATION PERMISSION; OR REJECTION OF THE ARP RESPONSE IF NO ENTRY CORRESPONDING TO THE ARP RESPONSE IS FOUND IN THE ARP TABLE.
ABSTRACT
METHOD, COMMUNICATION SYSTEM AND DEVICE FOR PROCESSING ARP PACKAGES
A method, a communication system and an ARP (Address Resolution Protocol) packet processing device are disclosed. 0 method includes: receiving an ARP packet and evaluating the type of the ARP packet; when the ARP packet is an ARP request, the response to the ARP request if an entry corresponding to the ARP request is found in an ARP table configured locally; and when the ARP packet is an ARP response, the communication of the ARP response if an entry corresponding to the ARP response is found in the locally configured ARP table and a communication parameter in the input indicates communication permission; or the rejection of the ARP response if no entry corresponding to the ARP response is found in the ARP table.
Receive an ARP package
<img file="PT2139187E_D0001.tif" />
<img file="PT2139187E_D0002.tif" />
<img file="PT2139187E_D0003.tif" />
<img file="PT2139187E_D0004.tif" />
Perform other processes
<img file="PT2139187E_D0005.tif" />
Φ Reject ARP response
FIG. !
DESCRIPTION
METHOD, COMMUNICATION SYSTEM AND DEVICE FOR
ARP PACKAGE PROCESSING
Field of the Invention
The present invention relates to communications and, in particular, a method, a communication system and an ARP (Address Resolution Protocol) packet processing device.
Background of the Invention
ARP is one of the lower layer protocols in the TCP / IP protocol suite (Transmission Control Protocol / Internet Protocol). The ARP was designed to convert an IP address into a physical Ethernet address, namely a MAC (Media Access Control).
Communications between Ethernet devices use MAC addresses for addressing, while several TCP / IP applications use IP addresses for addressing. It is necessary that several data packets are finally encapsulated in Ethernet frames for transmission. Therefore, before making IP communications, it is necessary to obtain the MAC address on the other side by resolving the IP address on the other side. The protocol responsible for the resolution process is the ARP.
To speed up address translation, a network device uses ARP cache technology when implementing ARP and uses a table structure to cache a certain number of address mapping relationships locally. In general, the table is known as the ARP table.
However, in the existing network, there are usually ARP-based network attacks. From the perspective of the origin of the attack, ARP attacks are divided into the following two types:
1. Address fraud: the attacker sends an ARP request or an ARP response with the wrong address mapping relationship to alter the host or gateway ARP table. Therefore, the gateway or host sends the packet to the wrong physical address and the attack works.
two. DoS (Denial of Service) ARP attack: Usually, the DoS ARP attack targets gateway devices (such as a router or switch). ARP packets are generally processed in the device's control plane. Usually, the control plan uses a universal CPU as a processing engine. The universal CPU is characterized by sophisticated processing, but limited performance. Due to too many processing tasks, the CPU in the control plane has a tendency to become overloaded or malfunction. Given the previous weakness, the person carrying out the DoS ARP attack sends high-traffic ARP packets to the gateway device in order to make the device's control plan extremely busy and unable to process normal ARP packets, and the attack works.
Next, a method of processing ARP packets in the state of the art is presented:
First, the IP address of each ARP packet is verified in the routing plan and illegal ARP packets are rejected.
Verifying the IP address includes:
1. Verification of the destination IP address: verify that the destination IP address corresponds to the IP address in the network segment of the gateway; otherwise, reject the package; and
two. Verification of the source IP address: verify that the source IP address is a legal IP address. Legal means that the IP address has already been in the ARP table entries. For these packages, the shipping priority is high; for other ARP packets, the sending priority is low.
However, the prior technology is unable to prevent attacks with legal IP addresses.
To overcome the defect of the previous solution, another method of processing ARP packets in the prior art is:
the response to the ARP request in the routing plan directly using the high speed processing capacity of the network processor in the routing plan.
ARP packages are classified into ARP request and ARP response. The previous solution deals only with the ARP request and is unable to solve the problem of high traffic attacks using the ARP response. US patent application
2006/0209818 discloses methods and devices to prevent ARP cache corruption.
Summary of the Invention
The present invention provides a method, a communication system and an ARP packet processing device to prevent network attacks initiated with ARP packets.
As a first aspect of the invention, the ARP packet processing method includes:
receiving an ARP package and evaluating the type of the ARP package;
when the ARP packet is an ARP request, the response to the ARP request if an ARP entry corresponding to the ARP request is found in a local ARP table; and when the ARP packet is an ARP response, the communication of the ARP response if an ARP entry corresponding to the ARP response is found in the local ARP table and the communication parameter in the ARP corresponding to the ARP response entry indicates communication permission; or the rejection of the ARP response if no ARP entry corresponding to the ARP response is found in the ARP table; wherein the local ARP table is provided by a control plan processor to a routing plan processor or configured on the routing plan processor directly.
As a second aspect of the invention, the communication system includes:
a routing plan processor, configured to receive an ARP (Address Resolution Protocol) packet and evaluate the type of the ARP packet; when the ARP packet is an ARP request, respond to the ARP request if an ARP entry corresponding to the ARP request is found in a local ARP table; when the ARP packet is an ARP response, communicate the ARP response if an ARP entry corresponding to the ARP response is found in the local ARP table and a communication parameter in the ARP entry corresponding to the ARP response indicates communication permission; or reject the ARP response if no ARP entry corresponding to the ARP response is found in the ARP table; and a control plan processor, configured to receive the ARP response or ARP request communicated by the routing plan processor;
wherein the local ARP table is provided by a control plan processor to a routing plan processor or configured on the routing plan processor directly.
In accordance with the present invention, the routing plan processor can respond to an ARP request received directly instead of generating an ARP entry according to the ARP request, thereby eliminating the possibility of using the ARP request to practice address fraud in the ARP table. In addition, upon receiving an ARP response, the routing plan processor communicates only the ARP response with communication permission in the ARP table, thus eliminating the possibility of attacks using multiple ARP responses.
Brief Description of the Figures
FIG. 1 is a flow chart of an ARP packet processing method in an embodiment of the present invention.
FIG. 2 is a flow chart of processing an ARP order in an embodiment of the present invention.
FIG. 3 is a flow chart of processing an ARP response in an embodiment of the present invention.
FIG. 4 illustrates a communication system in an embodiment of the present invention.
FIG. 5 illustrates a routing plane processor in an embodiment of the present invention.
Detailed Description of the Invention
Embodiments of the present invention provide an ARP packet processing method, communication system and routing plan processor to prevent network attacks using ARP packets.
FIG. 1 is a flow chart of an ARP packet processing method in an embodiment of the present invention. The method includes:
101. Receive an ARP package.
routing plan processor receives an ARP packet sent by an external device.
In general, a high-end data communication device (such as high-end routers or switches) includes three relatively independent plans: control plan, routing plan and management plan.
The control plan generally uses a universal CPU as the processing engine and is responsible for processing sophisticated protocols (such as, for example, a targeting protocol).
routing plan is responsible for high speed data forwarding.
management plan is responsible for network management, command lines, records and alarms.
In this embodiment, the routing plan processor can be a processing system composed of a single-core or multi-core CPU, a network processor or an ASIC (Application Specific Integrated Circuit) processor and the peripherals necessary for the operation of these components. Some examples of peripherals are: Random Access Memory (RAM), Ternary Content Addressable Memory (TCAM) or Flash memory.
102. Evaluate the type of the ARP package. If the ARP packet is an ARP request, step 103 is performed; if the ARP packet is an ARP response, step 107 is performed.
How to assess the type of ARP package is based on the state of the art and is not described in more detail here.
103. Search for the ARP table.
The ARP table in the routing plan processor is searched according to the ARP request obtained.
In this embodiment, the ARP table in the routing plan processor can be supplied by the control plan processor to the routing plan processor or configured in the routing plan processor directly.
In this embodiment, the corresponding relationship between the gateway interface IP address and the MAC address is included in the ARP table entry. When the Virtual Router Redundancy Protocol (VRRP) protocol is enabled on the interface, the entry needs to be maintained according to the VRRP state change.
It is possible to set a signaling bit in an ARP table entry to indicate whether the entry is a gateway port ARP entry or a proxy ARP entry.
104. Assess whether an entry corresponding to the ARP request obtained is found in the ARP table; if so, step 105 is performed; otherwise, step 106 is performed.
How to assess will be detailed in the subsequent embodiment below.
105. Respond to the ARP request.
If an entry corresponding to the obtained ARP request is found in the ARP table, the routing plan processor responds to the ARP request. How to respond will be detailed in the subsequent embodiment below.
106. Perform other processes.
If no entry corresponding to the obtained ARP request is found in the ARP table, the routing plan processor performs other processes. These processes will be detailed in the subsequent embodiment below.
107. Search for the ARP table.
The ARP table in the routing plan processor is searched according to the ARP response obtained.
In this embodiment, the ARP table in the routing plan processor can be supplied by the control plan processor to the routing plan processor or configured in the routing plan processor directly.
108. Assess whether an entry corresponding to the ARP response obtained is found in the ARP table; if so, step 109 is performed; otherwise, step 112 is performed.
109. Assess whether the communication parameter in the corresponding entry indicates communication permission. If the communication parameter indicates permission, step 110 is performed; otherwise, step 111 is performed.
110. Communicate the ARP response.
When the communication parameter in the input corresponding to the ARP response indicates communication permission, the routing plan processor communicates the ARP response to the control plan processor.
111. Perform other processes.
If the communication parameter in the input corresponding to the ARP response indicates no communication permission, the routing plan processor performs other processes. These processes will be detailed in the subsequent embodiment below.
112. Reject the ARP response.
If no entry corresponding to the ARP response obtained exists in the ARP table, the ARP response is rejected.
In the previous embodiment, the routing plan processor responds to the ARP request received directly instead of generating an ARP entry according to the ARP request, thus eliminating the possibility of using the ARP request to practice address fraud in the ARP table. In addition, upon receiving an ARP response, the routing plan processor communicates only the ARP response with communication permission in the ARP table, thus eliminating the possibility of attacks using multiple ARP responses.
The method for processing each type of ARP packet is explained below in detail:
I. Process an ARP order
FIG. 2 is a flow chart of an ARP order processing method in an embodiment of the present invention. The method includes:
201. Receive an ARP order.
The routing plan processor receives an ARP request sent by an external device.
202. Filter the ARP request if the source MAC address of the ARP request is a non-unicast address.
The way to filter the ARP request is based on the state of the art and is not described in more detail here.
203. Search for the ARP table.
The parameters, such as the port number, the VLAN ID (Virtual Local Area NetWork) and the destination IP address are obtained from the received ARP request, and the ARP table stored locally in the routing plan processor. is sought according to the parameters obtained.
204. Assess whether an entry corresponding to the ARP request obtained is found in the ARP table; if so, step 205 is performed; otherwise, step 208 is performed.
205. Assess whether the ARP request is a gateway ARP request or a proxy ARP request; if so, step 206 is performed; otherwise, step 207 is performed.
The evaluation is implemented by checking if there is a signaling bit ARP input from the connection port or proxy ARP input at the corresponding input.
206. Respond to the ARP request.
If the ARP request is a gateway ARP request or a proxy ARP request, the routing plan processor responds to the ARP request for the external device. The response is implemented by editing the ARP request, in order to make the ARP request an ARP response, or by creating a new ARP response whose address
Source MAC is the MAC address in this ARP entry. The edited ARP response or the newly created ARP response is sent through a port specified in the ARP entry.
In this embodiment, in the process of responding to the ARP request, the routing plan processor does not generate an ARP entry according to the source IP address or the MAC address in the ARP request, but performs stateless processing for the ARP request.
207. Reject the ARP request.
ARP request received is rejected.
208. Assess whether the proxy ARP function is enabled on the interface that received the ARP request; if the ARP function is activated, step 209 is performed; otherwise, step 207 is performed.
209. Limit the speed of the ARP request and report the ARP request.
If the proxy ARP function is enabled on the interface that received the ARP request, the routing plan processor limits the speed of the ARP request and then communicates the ARP request to the control plan processor.
In this embodiment, the way to assess whether the ARP request is a gateway ARP request or a proxy ARP request can be implemented by looking for the routing table or other tables that include this information. The detailed process is similar to the previous embodiment.
In this embodiment, after the routing plan processor limits the speed of the received ARP request and communicates the ARP request to the control plan processor in step 209, the control plan processor handles the proxy ARP request and, in It then provides the proxy ARP entry to the routing plan processor according to the configuration. The MAC address in the proxy ARP entry is the gateway's MAC address. Subsequently, when the ARP request corresponding to the proxy ARP entry is received, the routing plan processor can handle the ARP request directly without sending it to the control plan processor. Therefore, the processing speed is increased, and the ability to prevent ARP request attacks is improved if the proxy ARP function is enabled.
In this embodiment, in the process of responding to the ARP request, the routing plan processor does not generate an ARP entry according to the source IP address or the MAC address in the ARP request, thus preventing ARP attacks using the ARP request. to practice MAC address fraud.
II. Process an ARP response
FIG. 3 is a flow chart of a method of processing ARP responses in an embodiment of the present invention. The method includes:
301. Receive an ARP response.
The routing plan processor receives an ARP response sent by an external device.
302. Search for the ARP table.
The source IP address is obtained from the ARP response received, and the ARP table stored locally in the routing plan processor is searched according to the source IP address obtained.
303. Assess whether an entry corresponding to the ARP response obtained is found in the ARP table; if so, step 304 is performed; otherwise, step 307 is performed.
304. Assess whether the communication parameter in the input corresponding to the ARP response indicates communication permission. If the communication parameter indicates permission, step 305 is performed; otherwise, step 306 or 307 is performed.
305. Communicate the ARP response.
When the communication parameter in the input corresponding to the ARP response indicates communication permission, the routing plan processor communicates the ARP response to the control plan processor.
In this embodiment, the routing plan processor communicates the ARP response to the control plan processor. The control plan processor handles the ARP response and then modifies the communication parameter in the entry corresponding to the ARP response to without permission to communicate in the ARP table.
306. Limit the speed of the ARP response and then report the ARP response.
routing plan processor limits the speed of the ARP response according to the predefined processing rule and then communicates the ARP response to the control plan processor.
307. Reject the ARP response.
In this embodiment, if the communication parameter in the input corresponding to the ARP response indicates no communication permission in step 304, it is chosen to perform step 306 or 307 according to the predefined processing rule. For example, under normal circumstances, the MAC address of the device does not change frequently. Therefore, it is possible to choose the rejection policy. In special circumstances where it is necessary for the MAC address to change frequently, it is possible to choose the speed limitation policy. The rejection policy is more effective than the speed limitation policy in preventing address fraud. Therefore, the rejection policy is preferred, except in special circumstances.
In this embodiment, the speed limitation policy or the rejection policy is implemented by looking for the relevant table. Agui, the type of the table is not limited.
As illustrated in FIG. 4, a communication system provided in an embodiment of the present invention includes:
an external device 401, adapted to send an ARP request and an ARP response;
a routing plan processor 402, adapted to evaluate the type of ARP packet received; when the package
ARP is an ARP request, search for the local ARP table and respond to the ARP request according to the corresponding ARP request entry in the ARP table; when the ARP packet is an ARP response, look for the local ARP table and assess whether the communication parameter in the entry corresponding to the ARP response indicates permission for communication according to the entry corresponding to the ARP response in the ARP table; if the communication parameter indicates communication permission, communicate the ARP response; if no entry corresponding to the ARP response is found in the ARP table, reject the ARP response; and a control plan processor 403, adapted to receive the ARP response or ARP request communicated by the routing plan processor 402.
FIG. 5 illustrates a routing plane processor in an embodiment of the present invention. The routing plan processor includes:
an evaluation unit 501, adapted to evaluate the type of an ARP packet received;
a first search unit 502, adapted to search the local ARP table when the ARP packet is an ARP request;
a response unit 503, adapted to respond to the ARP request if an entry corresponding to the ARP request is found in the ARP table;
a second search unit 504, adapted to search the local ARP table when the ARP packet is an ARP response;
a rejection unit 506, adapted to reject the ARP response if no entry corresponding to the ARP response is found in the ARP table;
a speed limitation unit 509, adapted to limit the speed of the ARP packet and communicate the ARP packet to the control plane processor;
an interface evaluation unit 508, adapted to assess whether the proxy ARP function is enabled on the interface receiving the ARP request if no entry corresponding to the received ARP request is found in the ARP table; if the proxy ARP function is enabled, instruct speed limitation unit 509 to limit the speed of the ARP packet and communicate the ARP packet; if the proxy ARP function is not activated, instruct the rejection unit 506 to reject the ARP request;
a verification unit 505, adapted to assess whether the communication parameter in the entry corresponding to the ARP response indicates permission for communication when an entry corresponding to the ARP response is found in the ARP table; and a communication unit 507, adapted to communicate the ARP response to the control plane processor when the communication parameter on the input corresponding to the ARP response indicates communication permission.
In practical application, several units that implement similar functions in the embodiments of the present invention can be combined in one unit. For example, the first search unit 502 and the second search unit 504 can be implemented in one unit.
It is evident to those skilled in the art that all or part of the steps of the method in the previous embodiments can be implemented using computer equipment that receives instructions from a program. The program can be stored on a computer-readable storage medium. When executed, the program performs these steps: the routing plan processor evaluates the type of an ARP packet received; when the ARP packet is an ARP request, the routing plan processor looks for the local ARP table and, if an entry corresponding to the ARP request is found in the ARP table, responds to the ARP request directly; when the ARP packet is an ARP response, the routing plan processor looks for the local ARP table and, if an entry corresponding to the ARP response is found in the ARP table, evaluates whether the communication parameter in the entry indicates communication permission; if the communication parameter indicates communication permission, the routing plan processor communicates the ARP response to the control plan processor; if no entry corresponding to the ARP response is found in the ARP table, the routing plan processor rejects the ARP response.
The storage medium can be a Read-Only Memory (ROM), a magnetic disk or a CD (Compact Disk).
A method, a communication system and an ARP packet routing plan processor according to the present invention are described above. Although the invention is described by several exemplary embodiments, the invention is not limited to those embodiments.
Contents5
9 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9
14 members in 7 offices
Priority claims4
| Document | Office | Kind | Date |
|---|---|---|---|
| 200710129994 | China | A | |
| 200710129994 | China | A | |
| 200710129994 | – | – | – |
| CN20071129994 | – | – | – |
Members14
| Document | Office | Kind | |
|---|---|---|---|
| CN101094236A | China | A | |
| WO2009012663A1 | World Intellectual Property Organization (WIPO) | A1 | |
| EP2139187A1 | European Patent Office (EPO) | A1 | |
| US2010054253A1 | United States of America | A1 | |
| EP2139187A4 | European Patent Office (EPO) | A4 | |
| CN101094236B | China | B | |
| EP2139187B1 | European Patent Office (EPO) | B1 | |
| AT523023T | Austria | T | |
| ATE523023T1 | Austria | T1 | |
| PT2139187EThis record | Portugal | E | |
| ES2371127T3 | Spain | T3 | |
| US8542684B2 | United States of America | B2 | |
| US2013336326A1 | United States of America | A1 | |
| US9148374B2 | United States of America | B2 |
Numbers
- Publication, DOCDB
- 2139187
- Publication, EPODOC
- PT2139187E
- Application
- 8715268
- Application, DOCDB
- 08715268
- Application, EPODOC
- PT20080715268T
Titles2
- English
- METHOD, COMMUNICATION SYSTEM AND DEVICE FOR ARP PACKET PROCESSING
- Portuguese
- MÉTODO, SISTEMA DE COMUNICAÇÃO E DISPOSITIVO PARA PROCESSAMENTO DE PACOTES ARP
Classification
- CPC, 4
- H04L61/103
- H04L63/1441
- H04L45/745
- H04L45/00
- IPC, 1
- H04L45 74