摘要:
A network node comprises at least one data plane processor (101) for handling data packets of a first type (144) and for redirecting and rate-limiting data packets of a second type (142). A control plane processor (102) in the network node handles the data packets of a second type (142) redirected by the data plane processor (101). In order to protect the control plane processor (102) against overload, e.g. caused by Denial of Service (DoS) attacks, individual flows of data packets of the second type are identified for enhanced rate-limiting by the data plane processor (101).
摘要:
An access node (1) that is preferably a Flow-Aware Ethernet DSLAM adapted to transmit Ethernet data frames between subscribers (2) and an aggregation network (3). The access node comprises a first memory (4) for storing classification rules and a second memory (6) for storing flow rules. These rules are applied by a classification agent (5) and by a service agent (7) to information extracted from incoming data frames in order to infer flow awareness information of outgoing frames corresponding to these incoming data frame. In this way, the subscriber access network evolves to a multi-service architecture by replacing ATM with Ethernet for cost reasons. The concept of “flow awareness” is applied to the present access node. With respect to known tunnel-based Ethernet DSLAMs, the present access node removes all dependency on correct encapsulation or labeling at the customer side and at the service provider side. By removing the need for tunnels, traffic may be inserted at any intermediate point, as may be required for multicast.