WO2014079335A1 - Ip报文处理方法、装置及网络系统 - Google Patents

Ip报文处理方法、装置及网络系统 Download PDF

Info

Publication number
WO2014079335A1
WO2014079335A1 PCT/CN2013/087051 CN2013087051W WO2014079335A1 WO 2014079335 A1 WO2014079335 A1 WO 2014079335A1 CN 2013087051 W CN2013087051 W CN 2013087051W WO 2014079335 A1 WO2014079335 A1 WO 2014079335A1
Authority
WO
WIPO (PCT)
Prior art keywords
intranet
address
operator
service gateway
service
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2013/087051
Other languages
English (en)
French (fr)
Inventor
胡寅亮
陈�光
陈建
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Huawei Technologies Co Ltd
Original Assignee
Huawei Technologies Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Huawei Technologies Co Ltd filed Critical Huawei Technologies Co Ltd
Priority to JP2015543279A priority Critical patent/JP6028269B2/ja
Priority to EP13857339.9A priority patent/EP2916499B1/en
Publication of WO2014079335A1 publication Critical patent/WO2014079335A1/zh
Priority to US14/721,839 priority patent/US10454880B2/en
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L61/00Network arrangements, protocols or services for addressing or naming
    • H04L61/50Address allocation
    • H04L61/5007Internet protocol [IP] addresses
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L12/00Data switching networks
    • H04L12/28Data switching networks characterised by path configuration, e.g. LAN [Local Area Networks] or WAN [Wide Area Networks]
    • H04L12/46Interconnection of networks
    • H04L12/4604LAN interconnection over a backbone network, e.g. Internet, Frame Relay
    • H04L12/462LAN interconnection over a bridge based backbone
    • H04L12/4625Single bridge functionality, e.g. connection of two networks over a single bridge
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L47/00Traffic control in data switching networks
    • H04L47/10Flow control; Congestion control
    • H04L47/24Traffic characterised by specific attributes, e.g. priority or QoS
    • H04L47/2441Traffic characterised by specific attributes, e.g. priority or QoS relying on flow classification, e.g. using integrated services [IntServ]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/02Network architectures or network communication protocols for network security for separating internal from external traffic, e.g. firewalls
    • H04L63/0272Virtual private networks
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L67/00Network arrangements or protocols for supporting network services or applications
    • H04L67/01Protocols
    • H04L67/10Protocols in which an application is distributed across nodes in the network
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/16Implementing security features at a particular protocol layer
    • H04L63/164Implementing security features at a particular protocol layer at the network layer

Definitions

  • the present invention relates to a communication technology, and in particular, to an IP packet processing method, apparatus, and network system. Background technique
  • IPSec VPN Internet Protocol Security Virtual Private Network
  • the existing internal network of the enterprise has complicated deployment problems, and further causes the management and maintenance of the internal network of the enterprise to be more difficult, the cost is higher, and the investment cost of the internal network hardware equipment update is higher.
  • the embodiments of the present invention provide an IP packet processing method, device, and network system, which are used to reduce the complexity of intranet deployment, reduce the difficulty and cost of management and maintenance of an internal network, and reduce internal network hardware device updates. cost of investment.
  • the first aspect of the present invention provides an IP packet processing method, including:
  • the carrier service gateway allocates an IP address to the first intranet of the enterprise
  • the operator service gateway processes the business interaction between the first intranet and the second intranet of the enterprise according to the IP address.
  • the operator service gateway allocates an IP address to the first intranet of the enterprise, including:
  • the operator service gateway allocates a public network IP address to the first intranet, and uses the public network IP
  • An IP security protocol IPSec negotiation is performed between an address of the operator service gateway or the router corresponding to the second internal network;
  • the operator service gateway allocates an intranet IP address to the user equipment in the first intranet, and the intranet IP address has a corresponding relationship with the public network IP address.
  • the operator service gateway allocates an intranet IP address to the user equipment in the first intranet, including: The operator service gateway receives an intranet address request message sent by the user equipment and forwarded by the user equipment;
  • the carrier service gateway is configured to the first intranet and the enterprise according to the IP address.
  • the service of the interaction between the second intranets is processed, including:
  • the operator service gateway receives the first service packet that is sent by the user equipment and is sent by the user equipment, where the first service packet includes the intranet IP address;
  • the operator service gateway performs IPSec encapsulation on the first service text, and the first service packet encapsulated in the IPSec includes the public network IP address;
  • the operator service gateway sends the IPSec encapsulated first service packet to the operator service gateway or router corresponding to the second intranet.
  • the sending, by the operator service gateway or the router corresponding to the second intranet, the first service report after the IPSec encapsulation After the article also includes:
  • the operator service gateway performs IPSec decapsulation on the second service packet
  • the intranet address request message and the intranet address response message include a virtual local area network (VLAN) VLAN identifier,
  • the VLAN identifier corresponds to the first intranet.
  • VLAN virtual local area network
  • the second aspect of the present invention provides an IP packet processing method, including:
  • the operator access device receives an intranet address request message sent by the user equipment in the first intranet of the enterprise;
  • the operator access device sends the intranet address request message to the operator service gateway, so that the operator service gateway allocates an intranet IP address to the user equipment.
  • the method further includes:
  • the operator access device sends the intranet address response message to the user equipment.
  • the intranet address request message before the sending, by the operator access device, the intranet address request message to the carrier service gateway, :
  • the operator access device adds a VLAN identifier to the intranet address request message, where the VLAN identifier corresponds to the first intranet;
  • the operator access device sends the internal network address response message to the user equipment, including:
  • the operator access device deletes the VLAN identifier included in the intranet address response message, and sends the intranet address response message to the user equipment in the first intranet corresponding to the VLAN identifier.
  • an embodiment of the present invention provides an operator service gateway, including:
  • An allocation module configured to allocate an IP address to the first intranet of the enterprise
  • a processing module configured to process, according to the IP address, a service that interacts between the first intranet and the second intranet of the enterprise.
  • the allocating module is specifically configured to: allocate a public network IP address to the first internal network, and use the public network IP address and the second The carrier service gateway or router corresponding to the intranet performs IP security protocol IPSec negotiation;
  • the allocation module is also used to:
  • the processing module is specifically configured to:
  • the first service packet is encapsulated by the IPSec, and the first service packet encapsulated by the IPSec includes the public network IP address.
  • the processing module is further configured to:
  • the operator service gateway or router corresponding to the second intranet is sent to receive the first The second service packet of the public network IP address of the second intranet;
  • the intranet address request message and the intranet address response message include a virtual local area network (VLAN) VLAN identifier, and the VLAN identifier is The first inner net corresponds to each other.
  • VLAN virtual local area network
  • an embodiment of the present invention provides an operator access device, including:
  • a receiving module configured to receive an intranet address request message sent by a user equipment in the first intranet of the enterprise
  • a sending module configured to send the intranet address request message to the operator service gateway, so that the carrier service gateway allocates an intranet IP address to the user equipment.
  • the receiving module is further configured to: after sending the intranet address request message to the operator service gateway, receive the sending by the carrier service gateway An intranet address response message including the intranet IP address;
  • the sending module is further configured to send the intranet address response message to the user equipment.
  • the method further includes:
  • a processing module configured to add a VLAN identifier to the intranet address request message, where the VLAN identifier corresponds to the first intranet, before sending the intranet address request message to the operator service gateway ;
  • the processing module is further configured to delete the VLAN identifier included in the intranet address response message;
  • the sending module is specifically configured to send the intranet address response message to the user equipment in the first intranet corresponding to the VLAN identifier.
  • the fifth aspect provides a network system, including the operator service gateway according to any one of the possible implementation manners of the third aspect or the third aspect, and any one of the fourth aspect or the fourth aspect.
  • the IP packet processing method, apparatus, and network system provided by the embodiment of the present invention allocates an IP address to the first intranet of the enterprise through the operator service gateway, and the first intranet and the enterprise are determined by the operator service gateway according to the IP address.
  • the service packets exchanged between the two internal networks are processed, which can reduce the complexity of the internal network deployment, reduce the difficulty and cost of the internal network management and maintenance, and reduce the investment cost of the internal network hardware equipment update.
  • Embodiment 1 is a flowchart of Embodiment 1 of an IP packet processing method according to the present invention
  • Embodiment 2 is a flowchart of Embodiment 2 of an IP packet processing method according to the present invention
  • Embodiment 3 is a flowchart of Embodiment 3 of an IP packet processing method provided by the present invention.
  • Embodiment 4 is a flowchart of Embodiment 4 of an IP packet processing method according to the present invention.
  • FIG. 5 is a schematic structural diagram of Embodiment 1 of an operator service gateway according to the present invention.
  • FIG. 6 is a schematic structural diagram of Embodiment 2 of an operator service gateway according to the present invention
  • FIG. 7 is a schematic structural diagram of Embodiment 1 of an operator access device according to the present invention
  • FIG. 8 is a schematic structural diagram of Embodiment 2 of an operator access device provided by the present invention
  • FIG. 9 is a schematic structural diagram of Embodiment 3 of an operator access device provided by the present invention.
  • Embodiment 1 is a schematic structural diagram of Embodiment 1 of a network system provided by the present invention.
  • FIG. 10B is a schematic diagram of an embodiment of the method for processing an IP packet provided by the network system shown in FIG. 10A.
  • FIG. 10C is a flowchart of a packet receiving and receiving phase in the embodiment of the IP packet processing method provided by the network system shown in FIG. 10A;
  • FIG. 11 is a schematic structural diagram of Embodiment 2 of a network system according to the present invention.
  • FIG. 11B is a schematic diagram of an embodiment of the method for processing an IP packet provided by the network system shown in FIG. 11A.
  • FIG. 11C is a flowchart of a packet receiving and receiving phase in the embodiment of the IP packet processing method provided by the network system shown in FIG. 11A.
  • FIG. 1 is a flowchart of Embodiment 1 of an IP packet processing method according to the present invention. As shown in FIG. 1 , the method for processing a ⁇ ⁇ ⁇ ⁇ , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , ,
  • the operator service gateway allocates an IP address to the first intranet of the enterprise.
  • the first intranet of the enterprise may be the internal network of the enterprise's headquarters organization or the internal network of the enterprise's branch office.
  • the first intranet needs to obtain an IP address that can be used to connect to the public network
  • the user equipment in the first intranet needs to obtain an intranet IP address that can be used for interworking with other user equipments in the intranet.
  • the operator service gateway allocates a public network IP address to the first intranet, and allocates an intranet IP address to the user equipment in the first intranet, and the assigned intranet IP address has a corresponding relationship with the allocated public network address.
  • the foregoing carrier service gateway may be an operator broadband network service gateway.
  • BNG Broadband Network Gateway
  • the first internal network obtains the public network IP address in the following manner: The access router set in the first internal network requests the public network IP address from the operator service gateway by dialing, and the carrier service gateway authenticates the request. Then, the public network IP address is returned to the access router in the first intranet.
  • the carrier service gateway allocates the public network IP address to the first intranet when the first intranet is registered, so The network in the first intranet in the embodiment of the present invention may be simplified. For example, the access router may not need to be set, or the functions of the access router or the like in the first intranet may be simplified.
  • S102 The service gateway of the carrier processes the service packet exchanged between the first intranet and the second intranet of the enterprise according to the IP address.
  • the interaction between the user equipment in the first intranet of the enterprise and the user equipment in the second intranet of the enterprise may be based on the first intranet of the enterprise and the first intranet of the enterprise.
  • the IP packets exchanged between the user equipment in the network and the user equipment in the second intranet are processed to implement information transmission between the user equipment in the first intranet and the user equipment in the second intranet.
  • the operation of the first intranet and the second intranet to perform IPSec negotiation using the public network IP and the sending of the packet to the IPSec tunnel are respectively set in the access routers respectively set in the first intranet and are set in the first
  • the access routers are configured to perform the IPSec negotiation between the first internal network and the second internal network, and the sending of the packets to the IPSec tunnel is performed in the first
  • the carrier service gateway corresponding to the intranet is completed between the access routers in the second intranet, and between the operator service gateway corresponding to the first intranet and the carrier service gateway corresponding to the second intranet. carry out.
  • the operator service gateway allocates an IP address to the first intranet, and processes the service packets exchanged between the first intranet and the second intranet of the enterprise according to the IP address, thereby reducing the complexity of the internal network deployment of the enterprise. Therefore, the difficulty and cost of the management and maintenance of the internal network of the enterprise can be reduced. Further, if the enterprise needs to upgrade the internal network due to an increase in service requirements or an increase in network traffic, only the operation for performing the IP packet processing method in this embodiment is required.
  • the business service gateway can implement the software update, which can reduce the replacement of the internal network hardware equipment of the enterprise in the prior art, thereby reducing the investment cost of the internal network hardware equipment update of the enterprise.
  • the method for processing the ⁇ provided by the embodiment is the first intranet of the enterprise through the operator service gateway.
  • the IP address is assigned, and the service provider gateway processes the service packets exchanged between the first intranet and the second intranet of the enterprise according to the IP address, thereby reducing the complexity of the intranet deployment and reducing the internal network of the enterprise.
  • FIG. 2 is a flowchart of a second embodiment of a method for processing a text according to the present invention. As shown in FIG. 2, the method for processing a text in the embodiment includes:
  • the service gateway of the carrier allocates a public network IP address to the first intranet, and uses the public network IP address to negotiate an IP security protocol IPSec with the carrier service gateway or router corresponding to the second intranet.
  • the operator service gateway allocates a public network IP address to the first intranet, which may be a static or dynamic public network IP address. If an access router is set in the second intranet, the carrier service gateway is used as The public network IP address assigned by the first intranet is negotiated with the access router in the second intranet for IPSec negotiation; if the access router is not set in the second intranet, the carrier service gateway is allocated for the first intranet. The public network IP address is negotiated with the carrier service gateway corresponding to the second intranet.
  • the result of the IPSec negotiation may include information such as an authentication protocol required to transmit the information and an encryption key required for the security mechanism.
  • the operator service gateway allocates an intranet IP address to the user equipment in the first intranet, and the intranet IP address has a corresponding relationship with the public network IP address.
  • the intranet IP address needs to be obtained.
  • the user equipment in this embodiment may be any device that may be used in the enterprise network, such as a personal computer (PC), etc., which is not limited in this embodiment.
  • PC personal computer
  • S202 can include:
  • the operator service gateway receives an intranet address request message sent by the user equipment forwarded by the operator access device;
  • the user equipment in the first intranet When the user equipment in the first intranet needs to obtain the intranet IP address, it will send an intranet address request message to the operator access device. After receiving the intranet address request message, the operator access device will set the intranet address. The request message is forwarded to the operator service gateway.
  • the operator service gateway needs to add the virtual local area network to the intranet address request message according to the ingress port number after receiving the intranet address request message.
  • VLAN Virtual Local Area Network
  • the VLAN identifier corresponds to the first intranet.
  • the operator service gateway sends an intranet address response message including the intranet IP address to the operator access device, so that the operator access device sends the intranet IP address to the user equipment.
  • the operator service gateway After receiving the intranet address request message, the operator service gateway sends an intranet address response message including the intranet IP address to the operator access device, so that the operator access device sends the intranet IP address to the first intranet.
  • the operator service gateway After receiving the intranet address request message, the operator service gateway sends an intranet address response message including the intranet IP address to the operator access device, so that the operator access device sends the intranet IP address to the first intranet.
  • the operator service gateway receives the first service packet that is sent by the user equipment and is forwarded by the user equipment, where the first service packet includes an intranet IP address.
  • the user equipment in the first intranet of the enterprise interacts with the user equipment in the second intranet of the enterprise, and the user equipment in the first intranet is based on the service information, the intranet IP address, and the second intranet of the peer end.
  • the internal network IP address of the user equipment generates the first service packet and sends the first service packet to the operator access device.
  • the carrier service gateway serves multiple intranet services, After receiving the first service packet, the operator access device adds the first service packet according to the inbound port number.
  • a VLAN identifier, the VLAN identifier corresponding to the first intranet, and the operator service gateway receives the first service packet with the VLAN identifier added by the operator access device.
  • the service gateway of the carrier performs IPSec encapsulation on the first service text, and the first service after the IPSec encapsulation includes the public network IP address.
  • the IPSec encapsulation needs to be removed before the IPSec encapsulation of the first service packet is performed.
  • the text includes the public network IP address of the first intranet and the public IP address of the second intranet of the peer end.
  • the operator service gateway sends the first service after the IPSec encapsulation to the operator service gateway or router corresponding to the second intranet.
  • the operator service gateway sends the first service packet after the IPSec encapsulation to the access router in the second intranet; if the access router is not set in the second intranet, The service service gateway sends the first service packet after the IPSec encapsulation to the carrier service gateway corresponding to the second intranet.
  • the operator service gateway receives the second service packet that is sent by the carrier service gateway or the router corresponding to the second intranet and includes the public network IP address of the second intranet.
  • the service gateway or the router corresponding to the second intranet is decapsulated by the IPSec and sent to the user equipment in the second intranet to make the second internal
  • the user equipment in the network generates the second service according to the feedback service information of the first service packet, the intranet IP address of the user equipment in the second intranet, and the intranet IP address of the user equipment in the first intranet.
  • sending the second service packet to the operator service gateway or the router corresponding to the second intranet, and the operator service gateway or the router corresponding to the second intranet encapsulates the received second service packet by IPSec.
  • the service gateway of the carrier performs IPSec decapsulation on the second service text.
  • the service provider gateway sends the IPSec decapsulated second service packet to the operator access device, so that the operator access device sends the second service packet to the user equipment of the first intranet.
  • the intranet address request message and the intranet address response message in this embodiment may include a virtual local area network (VLAN) VLAN identifier, and the VLAN identifier corresponds to the first intranet.
  • VLAN virtual local area network
  • the method for processing the text in the embodiment provides the public network IP address and the intranet IP address for the user equipment in the first intranet and the first intranet of the enterprise by the operator service gateway, respectively, and is operated by the operator.
  • the gateway performs IPSec encapsulation on the first service packet sent by the user equipment in the first intranet according to the public network IP address and the public intranet IP address, and transmits the information to the operator service gateway or router corresponding to the second intranet through the public network.
  • the IPSec decapsulated second service packet is sent to the operator access device, so that the operator access device sends the second service packet to the user equipment of the first intranet, thereby reducing the internal network deployment of the enterprise. Complexity, reduce the difficulty and cost of management and maintenance of the internal network of the enterprise, and reduce the investment cost of updating the internal network hardware equipment of the enterprise.
  • FIG. 3 is a flowchart of a third embodiment of a method for processing a file according to the present invention. As shown in FIG. 3, the method for processing a text according to the embodiment includes:
  • the operator access device receives an intranet address request message sent by the user equipment in the first intranet of the enterprise.
  • the user equipment in the first intranet When the user equipment in the first intranet needs to obtain the intranet IP address, it will send an intranet address request message to the operator access device. After receiving the intranet address request message, the operator access device will set the intranet address. The request message is forwarded to the operator service gateway.
  • the operator access device needs to add the VLAN identifier to the intranet address request message according to the ingress port number after receiving the intranet address request message.
  • the VLAN identifier corresponds to the first intranet.
  • the operator access device sends an intranet address request message to the operator service gateway, so that the carrier service gateway allocates an intranet IP address to the user equipment.
  • the user equipment in the first intranet obtains the intranet IP address through the interaction with the access router installed in the first intranet, and the IP packet processing method provided by the embodiment of the present invention is operated.
  • the Provider access device forwards the intranet address request message of the user equipment to the operator service gateway, and then sends the message
  • the intranet IP address assigned by the service gateway to the user equipment is forwarded to the user equipment, so that the user equipment is assigned to the intranet IP address.
  • the operator access device receives the intranet address request message sent by the user equipment in the first intranet of the enterprise, and sends the intranet address request message to the operator service gateway, to The carrier service gateway allocates the internal network IP address to the user equipment, which can reduce the complexity of the internal network deployment, reduce the difficulty and cost of the internal network management and maintenance, and reduce the investment cost of the internal network hardware equipment update.
  • FIG. 4 is a flowchart of Embodiment 4 of the method for processing a file according to the present invention. As shown in FIG. 4, the method for processing the file in the embodiment includes:
  • the operator access device receives an intranet address request message sent by the user equipment in the first intranet of the enterprise.
  • the operator access device sends an intranet address request message to the operator service gateway.
  • the operator access device receives an intranet address response message that is sent by the carrier service gateway and includes an intranet IP address.
  • the intranet address response message sent by the carrier service gateway including the intranet IP address includes the intranet IP address allocated for the first intranet user equipment.
  • the operator access device sends an intranet address response message to the user equipment.
  • the foregoing S402 includes: adding, by the operator access device, a VLAN identifier in the intranet address request message, where the VLAN identifier corresponds to the first intranet.
  • the S404 may be: the operator access device deletes the VLAN identifier included in the response message of the internal network address, and sends the response message of the internal network address to the user equipment in the first intranet corresponding to the VLAN identifier.
  • the operator access device receives the intranet address request message sent by the user equipment in the first intranet of the enterprise, and sends the intranet address request message to the operator service gateway, to The carrier service gateway allocates the internal network IP address to the user equipment, which can reduce the complexity of the internal network deployment, reduce the difficulty and cost of the internal network management and maintenance, and reduce the investment cost of the internal network hardware equipment update.
  • FIG. 5 is a schematic structural diagram of Embodiment 1 of an operator service gateway according to the present invention.
  • the operator service gateway of this embodiment includes an allocation module 51 and a processing module 52, where the allocation module 51 is configured to The first intranet of the enterprise allocates an IP address; the processing module 52 is configured to access the first intranet according to the IP address.
  • the service packet exchanged with the second intranet of the enterprise is processed.
  • the carrier service gateway provided in this embodiment may be a BNG.
  • the device in this embodiment may be used to implement the technical solution of the method embodiment shown in FIG. 1.
  • the implementation principle and technical effects are similar, and details are not described herein again.
  • the allocating module 51 is specifically configured to: allocate a public network IP address for the first intranet, and use the public network IP address and the operator service gateway corresponding to the second intranet or The router performs IP security protocol IPSec negotiation;
  • the intranet IP address is assigned to the user equipment in the first intranet, and the intranet IP address has a corresponding relationship with the public IP address.
  • the allocation module 51 is also used to:
  • the processing module 52 is specifically configured to:
  • the IPSec encapsulation is performed on the first service packet, and the first service packet encapsulated by the IPSec includes the public network IP address.
  • the IPSec encapsulated first service packet is sent to the carrier service gateway or router corresponding to the second intranet.
  • the processing module 52 is also used to:
  • the second service network or the public network corresponding to the second intranet is sent by the carrier service gateway or router.
  • the IPSec decapsulated second service packet is sent to the operator access device, so that the operator access device sends the second service packet to the user equipment of the first intranet.
  • the intranet address request message, the intranet address response message, the first service packet before the IPSec encapsulation, and the second service packet after the IPSec decapsulation include the virtual local area network VLAN identifier, the VLAN identifier, and the first intranet. Corresponding.
  • the device of this embodiment may be used to implement the technical solution of the method embodiment shown in FIG. 2, which is implemented.
  • the principle and technical effects are similar and will not be described here.
  • the operator service gateway shown in FIG. 5 can perform all operations or functions of the operator service gateway in the embodiment corresponding to any of the figures in FIG. 1 to FIG.
  • FIG. 6 is a schematic structural diagram of Embodiment 2 of an operator service gateway according to the present invention.
  • the carrier service gateway of this embodiment includes at least one processor 601, such as a central processing unit (Central Processing Unit, for short). CPU), at least one network interface 602 and other user interfaces 603, memory 604, at least one communication bus 605, and operating system 606.
  • Communication bus 605 is used to implement connection communication between these devices.
  • the memory 604 may include a high speed RAM memory, and may also include a non-volatile memory such as at least one disk memory.
  • the memory 604 can optionally include at least one storage device located remotely from the aforementioned processor 601.
  • the operating system 606 includes various programs for implementing various basic services and processing hardware-based tasks.
  • the processor 601 is configured to allocate an IP address to the first intranet of the enterprise;
  • the processor 601 is configured to process, according to the IP address, a service packet exchanged between the first intranet and the second intranet of the enterprise.
  • processor 601 is specifically configured to:
  • the intranet IP address is assigned to the user equipment in the first intranet, and the intranet IP address has a corresponding relationship with the public IP address.
  • processor 601 is further configured to:
  • processor 601 is specifically configured to:
  • the IPSec encapsulation is performed on the first service packet, and the first service packet encapsulated by the IPSec includes the public network IP address.
  • the IPSec encapsulated first service packet is sent to the carrier service gateway or router corresponding to the second intranet.
  • the processor 601 is further configured to: After the IPSec-encapsulated first service packet is sent to the operator service gateway or router corresponding to the second intranet, the second service network or the public network corresponding to the second intranet is sent by the carrier service gateway or router.
  • the IPSec decapsulated second service packet is sent to the operator access device, so that the operator access device sends the second service packet to the user equipment of the first intranet.
  • Some or all of the messages involved in this embodiment may be generated by the processor 601 of the operator service gateway or by other components/modules or by the processor 601 in combination with other components/modules.
  • Memory 604 can hold readable computer instructions or computer programs. The various operations performed by the at least one processor 601 in this embodiment may be performed in accordance with the computer instructions or computer program.
  • At least one processor 601 in the operator service gateway in this embodiment may also execute the embodiment corresponding to any one of FIG. 1 to FIG. 4 according to a readable computer instruction or a computer program stored in the memory 604. All operations or functions of the carrier's service gateway.
  • FIG. 6 is only a schematic diagram of a structure of an operator service gateway provided by the present invention, and the specific structure may be adjusted according to actual conditions.
  • FIG. 7 is a schematic structural diagram of Embodiment 1 of an operator access device according to the present invention.
  • the operator access device in this embodiment includes a receiving module 71 and a sending module 72, where the receiving module 71 is used.
  • the receiving the internal network address request message sent by the user equipment in the first internal network of the enterprise;
  • the sending module 72 is configured to send the internal network address request message to the operator service gateway, so that the carrier service gateway allocates the intranet to the user equipment. IP address.
  • the device in this embodiment may be used to implement the technical solution of the method embodiment shown in FIG. 3, and the implementation principle and technical effects are similar, and details are not described herein again.
  • FIG. 8 is a schematic structural diagram of Embodiment 2 of an operator access device according to the present invention.
  • the receiving module 71 is further configured to send an intranet address request message. After the service gateway is sent to the operator, the intranet address response message including the intranet IP address sent by the operator service gateway is received;
  • the sending module 72 is further configured to send an intranet address response message to the user equipment.
  • the operator access device of this embodiment further includes: a processing module 73, where the processing module 73 is configured to add a VLAN identifier, a VLAN identifier, and an identifier in the intranet address request message before sending the intranet address request message to the operator service gateway.
  • the first intranet corresponds;
  • the processing module 73 is further configured to delete the VLAN identifier included in the internal network address response message.
  • the sending module 72 is specifically configured to send an intranet address response message to the user equipment in the first intranet corresponding to the VLAN identifier.
  • the device in this embodiment may be used to implement the technical solution of the method embodiment shown in FIG. 4, and the implementation principle and the technical effect are similar, and details are not described herein again.
  • the operator access device shown in FIG. 7 or FIG. 8 can perform all operations or functions of the operator access device in the embodiment corresponding to any of the drawings in FIGS. 1 to 4.
  • FIG. 9 is a schematic structural diagram of Embodiment 3 of an operator access device according to the present invention.
  • the operator access device in this embodiment includes at least one processor 901, such as a CPU, and at least one network interface 902. And other user interfaces 903, memory 904, at least one communication bus 905, and operating system 906.
  • Communication bus 905 is used to implement connection communication between these devices.
  • Memory 904 may include high speed RAM memory and may also include non-volatile memory, such as at least one disk storage.
  • the memory 904 can optionally include at least one storage device located remotely from the aforementioned processor 901.
  • Operating system 906, which contains various programs for implementing various basic services and handling hardware-based tasks.
  • the network interface 902 is configured to receive an intranet address request message sent by the user equipment in the first intranet of the enterprise;
  • the network interface 902 is configured to send an intranet address request message to the operator service gateway, so that the operator service gateway allocates an intranet IP address to the user equipment.
  • the network interface 902 is further configured to: after transmitting the intranet address request message to the operation business gateway, receive an intranet address response message that is sent by the operator service gateway and includes an intranet IP address;
  • the network interface 902 is further configured to send an intranet address response message to the user equipment.
  • the processor 901 is configured to add a VLAN identifier to the intranet address request message before the intranet address request message is sent to the operator service gateway, where the VLAN identifier corresponds to the first intranet;
  • the processor 901 is further configured to: delete the VLAN identifier included in the intranet address response message; the network interface 902 is configured to send the intranet address response message to the user equipment in the first intranet corresponding to the VLAN identifier.
  • the generation of the message may be implemented by the processor 901 or other components/modules or the processor 901 of the operator access device in combination with other components/modules.
  • Memory 904 can hold readable computer instructions or computer programs. The various operations performed by the at least one processor 901 in this embodiment may be performed in accordance with the computer instructions or computer program.
  • At least one processor 901 in the operator service gateway in this embodiment may also execute the embodiment corresponding to any one of FIG. 1 to FIG. 4 according to a readable computer instruction or a computer program saved in the memory 904.
  • the operator accesses all operations or functions of the device.
  • FIG. 9 is only a schematic diagram of a structure of an operator access device provided by the present invention, and the specific structure may be adjusted according to actual conditions.
  • the network system provided by the embodiment of the present invention includes any one of the operator service gateways in the foregoing embodiments and any one of the foregoing embodiments.
  • the following takes the interworking of the enterprise A branch network and the enterprise A headquarters network as an example.
  • the enterprise A branch network may be the first intranet in the foregoing embodiment
  • the enterprise A headquarters network may be the second intranet in the foregoing embodiment
  • the technical solution of the embodiment of the present invention and the flow chart of the IP packet processing method are further described in detail in the following:
  • FIG. 10A is a schematic structural diagram of Embodiment 1 of a network system according to the present invention.
  • the network system in this embodiment is an operator network 300, and the carrier network 300 may include an operator service gateway 310 and an operator access device. 320.
  • the enterprise A may include an enterprise A branch network 100 and an enterprise A headquarters network 200.
  • the enterprise A branch network 100 includes only a PC and a switch for connecting each PC and connecting the network.
  • the PC may be the first in the foregoing embodiment.
  • the enterprise A headquarters network 200 includes an access router 210 in addition to a PC and a switch for connecting each PC and connecting to the network.
  • the scenario in this embodiment is that the enterprise A branch network 100 and the enterprise A headquarters network 100 are in the same area and access the same carrier service gateway.
  • enterprise A branch networks in addition to the enterprise A branch network 100, more enterprise A branch networks may be included, and in addition to the enterprise A branch network 100 and the enterprise A headquarters network 200, operations may also be performed.
  • the enterprise service gateway 310 and the carrier access device 320 in the embodiment can be simultaneously connected to multiple other enterprise networks, such as the enterprise B branch network or the enterprise B headquarters network.
  • Organization network assigns an IP address and then assigns an IP address to the organization
  • the services exchanged between the network of the organization are processed, and the operator service gateway 310 and the operator access device 320 can distinguish the plurality of organization networks by, for example, the VLAN identifier corresponding to each organization network.
  • FIG. 10B is a flowchart of an IP address allocation phase in the embodiment of the IP packet processing method provided by the network system shown in FIG. 10A. As shown in FIG. 10B and FIG. 10A, the IP packet processing method in this embodiment is IP.
  • the address allocation phase including:
  • the carrier service gateway allocates a public network IP address to the enterprise A branch network.
  • the carrier service gateway allocates the public network IP address to the enterprise A branch network.
  • the IP address can be a static or dynamic public network IP address.
  • the carrier service gateway uses the public network IP address to negotiate with the router corresponding to the enterprise A headquarters network for IP security protocol IPSec.
  • the public network IP address of the router corresponding to the enterprise A headquarters network is a fixed IP address.
  • the result of the IPSec negotiation may include information such as an authentication protocol required to transmit the information and an encryption key required for the security mechanism.
  • the PC in the enterprise A branch network sends an intranet IP address request message to the operator access device.
  • the operator access device adds a VLAN identifier to the intranet address request message according to the ingress port number, where the VLAN identifier corresponds to the enterprise A branch network.
  • the carrier service gateway serves multiple intranets, you need to add a VLAN ID corresponding to the enterprise A branch network.
  • the operator access device sends an intranet address request message including a VLAN identifier to the operator service gateway.
  • the carrier service gateway sends an intranet address response message including an intranet IP address to the operator access device, where the intranet address response message further carries a VLAN identifier corresponding to the enterprise A branch network.
  • the operator access device sends an intranet address response message to the PC in the enterprise A branch network according to the VLAN identifier, and removes the VLAN identifier.
  • the PC in the enterprise A branch network receives the intranet address response message.
  • FIG. 10C is a network packet processing method provided by the network system shown in FIG. 10A.
  • the flowchart of the packet transmission and reception phase in the embodiment is as shown in FIG. 10C and FIG. 1 OA.
  • the packet transmission and reception phase in the IP processing method of the embodiment includes:
  • the PC in the enterprise A branch network sends the first service packet to the operator access device.
  • the PC in the enterprise A branch network generates the first service text according to the service information, the intranet IP address, and the intranet IP address of the user equipment in the second intranet of the peer end.
  • the operator access device adds a VLAN identifier to the first service packet according to the inbound port number, where the VLAN identifier corresponds to the first intranet.
  • the operator service gateway performs IPSec encapsulation on the first service profile after removing the VLAN identifier.
  • the first service packet encapsulated by IPSec also includes the public IP address of the enterprise A branch network and the enterprise A headquarters network.
  • the service gateway of the carrier sends the first service after removing the VLAN identifier and the IPSec encapsulation to the router of the enterprise A headquarters network.
  • the router of the enterprise A headquarters network decapsulates the received first service packet and sends it to the PC in the A headquarters network.
  • the PC in the A headquarters network sends the second service packet to the router of the enterprise A headquarters network.
  • the PC in the network of the enterprise A headquarters generates the second service according to the feedback service information of the first service packet, the intranet IP address of the user equipment in the second intranet, and the intranet IP address of the user equipment in the first intranet. Message.
  • the router of the enterprise A headquarters network encapsulates the received second service packet by IPSec, and sends the second service text encapsulated by the IPSec to the carrier service gateway.
  • the service provider gateway decapsulates the received second service packet and adds the VLAN identifier corresponding to the enterprise A branch network to the operator access device.
  • the operator access device sends the decapsulated second service packet to the PC in the enterprise A branch network according to the VLAN identifier, and removes the VLAN identifier.
  • the PC in the enterprise A branch network receives the second service packet.
  • the enterprise A headquarters network 200 may not be provided with an access router, and the carrier service gateway 310 is the enterprise A headquarters network 200 and the enterprise A headquarters.
  • the PC in the network 200 allocates a public network IP address and an intranet IP address, and according to the IP address pair.
  • the service packets exchanged between the PC in the enterprise A headquarters network 200 and the PC in the enterprise A branch network 100 are processed.
  • the operator service gateway allocates a public network IP address and a public intranet IP address for the user equipment in the enterprise A branch network and the enterprise A branch network, respectively, and the carrier service gateway uses the public network IP address and the public network.
  • the IP address of the network is encapsulated in the IPSec packet sent by the user equipment of the enterprise A branch network, and is transmitted to the router corresponding to the A headquarters network of the enterprise through the public network. Then, the IPSec decapsulation is sent to the access device of the enterprise.
  • the second service packet is configured to enable the operator access device to send the second service packet to the user equipment of the enterprise A branch network, thereby reducing the complexity of the internal network deployment and reducing the difficulty of management and maintenance of the internal network of the enterprise. , cost, reduce the investment cost of enterprise internal network hardware equipment update.
  • FIG. 11 is a schematic structural diagram of a network system according to Embodiment 2 of the present invention.
  • the network system in this embodiment is an operator network 700, and the carrier network 700 may include a first carrier corresponding to the enterprise A branch network 500.
  • the enterprise A branch network 600 and the enterprise A headquarters network 700 only include a PC and a switch for connecting each PC and connecting to the network, and the PC may be the user in the first intranet or the second intranet in the foregoing embodiment. device.
  • the scenario in this embodiment is that the enterprise A branch network 500 and the enterprise A headquarters network 600 are in different areas and access different carrier service gateways.
  • enterprise A branch networks in addition to the enterprise A branch network 500, more enterprise A branch networks may be included, and in addition to the enterprise A branch network 500 and the enterprise A headquarters network 600, for example, A plurality of other organization network, such as the enterprise B branch network or the enterprise B headquarters network, and the first carrier service gateway 710 and the first carrier access device 730 or the second carrier service gateway 720 and the second operation in this embodiment.
  • the service access device 740 can simultaneously allocate an IP address to the plurality of organization networks, and process the service packets exchanged between the organization networks according to the assigned IP addresses.
  • the carrier service gateway and the operator access device can pass, for example, The VLAN identifier corresponding to each organization network distinguishes multiple organization networks.
  • FIG. 11B is a flowchart of the IP address allocation stage in the embodiment of the IP packet processing method provided by the network system shown in FIG. 11A, as shown in FIG. 11B and FIG. 11A, including:
  • the first carrier service gateway allocates a public network IP address to the enterprise A branch network.
  • the first carrier service gateway performs the public network IP address and the second carrier service gateway. IP security protocol IPSec negotiation.
  • the S1003 S1008 is similar and will not be described here.
  • FIG. 11C is a flowchart of the process of transmitting and receiving the data in the embodiment of the method for processing the network provided by the present invention, as shown in FIG. 11C and FIG.
  • S1109 ⁇ S1112 in the transmission and reception stage of the 4 ⁇ text is similar to S1009 ⁇ S1012 in FIG. 10C, and details are not described herein again.
  • the first carrier service gateway sends the first service packet after the IPSec encapsulation to the second carrier service gateway.
  • the second carrier service gateway decapsulates the received first service packet, adds the VLAN identifier, and sends the VLAN identifier to the second carrier access device.
  • the VLAN identifier added here is the VLAN corresponding to the enterprise A headquarters network. logo.
  • the second carrier access device sends the received first service packet to the PC in the network of the headquarters A of the enterprise according to the VLAN identifier, and removes the VLAN identifier.
  • the PC in the A headquarters network of the enterprise receives the first service packet sent by the second carrier access device.
  • the PC in the A headquarters network sends the second service packet to the second carrier access device.
  • the PC in the network of the enterprise A headquarters generates the second service according to the feedback service information of the first service packet, the intranet IP address of the user equipment in the second intranet, and the intranet IP address of the user equipment in the first intranet. Message.
  • the second carrier access device adds a VLAN identifier to the second service packet according to the inbound port number, where the VLAN identifier is a VLAN identifier corresponding to the enterprise A headquarters network.
  • the second carrier access device sends a second service packet with the VLAN identifier added to the second carrier service gateway.
  • the second carrier service gateway performs IPSec encapsulation on the received second service packet, and sends the IPSec encapsulated second service packet to the first carrier service gateway.
  • S1121 ⁇ S1123 are the same as S1017 ⁇ S1019 in FIG. 10C, and are not described here.
  • one of the enterprise A branch network 600 and the enterprise A headquarters network 700 can be configured to set an access router, and set the PC in the enterprise A network of the access router.
  • the network address is assigned by the access router and is determined by the access router based on the IP address.
  • the service packets exchanged between the PC in the enterprise A headquarters network 700 and the PC in the enterprise A branch network 600 are processed.
  • the first carrier service gateway allocates a public network IP address and a public intranet IP address to the user equipment in the enterprise A branch network and the enterprise A branch network, respectively, and the carrier service gateway uses the public network IP address and The IP address of the public network encapsulates the first service packet sent by the user equipment in the enterprise A branch network by IPSec, transmits the packet to the second carrier service gateway through the public network, and then sends the IPSec decapsulation to the operator access device.
  • the second service packet is used to enable the operator access device to send the second service packet to the user equipment of the enterprise A branch network, thereby further reducing the complexity of the internal network deployment of the enterprise and reducing the management of the internal network of the enterprise.
  • the difficulty and cost of maintenance reduce the investment cost of updating the internal network hardware equipment of the enterprise.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)
  • Small-Scale Networks (AREA)

Abstract

本发明实施例提供一种IP报文处理方法、装置及网络系统,该方法包括:运营商业务网关为企业的第一内网分配IP地址;运营商业务网关根据IP地址对第一内网与企业的第二内网之间交互的业务报文进行处理,本发明的技术方案,通过运营商业务网关为企业的第一内网分配IP地址,并且由运营商业务网关根据IP地址对第一内网与企业的第二内网之间交互的业务报文进行处理,从而可以降低企业内部网络部署的复杂度,降低企业内部网络的管理维护的难度、成本,降低企业内部网络硬件设备更新投资成本。

Description

IP报文处理方法、 装置及网絡系统 技术领域 本发明实施例涉及通信技术, 尤其涉及一种 IP报文处理方法、 装置及网络 系统。 背景技术
随着企业市场规模的不断扩大, 企业出现越来越多的分支机构, 企业由单 一地理位置扩展为多地协同办公,企业的网络管理和策略分发也变得越来越复 杂, 地理位置的扩展, 进一步的要求企业部署更多的网络业务。
企业分支和总部、 分支和分支之间需要实现互联互通时, 由于专线业务价 格昂贵, 对于中小企业, 往往通过互联网协议安全协议虚拟专用网络(Internet Protocol Security Virtual Private Network , 简称 IPSec VPN )来实现。
现有企业内部网络存在部署复杂的问题, 并进一步导致企业内部网络的管 理维护难度较大、成本较高,企业内部网络硬件设备更新投资成本较高的问题。 发明内容 本发明实施例提供一种 IP报文处理方法、 装置及网络系统, 用以降低企业 内部网络部署的复杂度, 降低企业内部网络的管理维护的难度、 成本, 降低企 业内部网络硬件设备更新投资成本。
第一方面, 本发明实施例提供一种 IP报文处理方法, 包括:
运营商业务网关为企业的第一内网分配 IP地址;
所述运营商业务网关根据所述 IP地址对所述第一内网与所述企业的第二 内网之间交互的业务才艮文进行处理。
在第一方面的第一种可能的实现方式中, 所述运营商业务网关为企业的第 一内网分配 IP地址, 包括:
所述运营商业务网关为所述第一内网分配公网 IP地址, 并釆用所述公网 IP 地址与所述第二内网对应的运营商业务网关或路由器进行 IP安全协议 IPSec协 商;
所述运营商业务网关为所述第一内网中的用户设备分配内网 IP地址, 所述 内网 IP地址与所述公网 IP地址具有对应关系。
在根据第一方面的第一种可能的实现方式的第二种可能的实现方式中, 所 述运营商业务网关为所述第一内网中的用户设备分配内网 IP地址, 包括: 所述运营商业务网关接收运营商接入设备转发的由所述用户设备发送的 内网地址请求消息;
所述运营商业务网关向所述运营商接入设备发送包含所述内网 IP地址的 内网地址响应消息, 以使所述运营商接入设备将所述内网 IP地址发送给所述用 户设备。
在根据第一方面的第一种或第二种可能的实现方式的第三种可能的实现 方式中, 所述运营商业务网关根据所述 IP地址对所述第一内网与所述企业的第 二内网之间交互的业务 4艮文进行处理, 包括:
所述运营商业务网关接收运营商接入设备转发的由所述用户设备发送的 第一业务报文, 所述第一业务报文中包含所述内网 IP地址;
所述运营商业务网关对所述第一业务 文进行 IPSec封装, IPSec封装后的 第一业务报文中包含所述公网 IP地址;
所述运营商业务网关向与所述第二内网对应的运营商业务网关或路由器 发送 IPSec封装后的第一业务报文。
在根据第一方面的第三种可能的实现方式的第四种可能的实现方式中, 所 述向与所述第二内网对应的运营商业务网关或路由器发送 IPSec封装后的第一 业务报文之后, 还包括:
所述运营商业务网关接收与所述第二内网对应的运营商业务网关或路由 器发送的包含所述第二内网的公网 IP地址的第二业务报文;
所述运营商业务网关对所述第二业务报文进行 IPSec解封装;
所述运营商业务网关向所述运营商接入设备发送 IPSec解封装后的第二业 务报文, 以使所述运营商接入设备将所述第二业务报文发送给所述第一内网的 所述用户设备。
在根据第一方面的第二种可能的实现方式的第五种可能的实现方式中, 所 述内网地址请求消息和所述内网地址响应消息中包含虚拟局域网 VLAN标识, 所述 VLAN标识与所述第一内网相对应。
第二方面, 本发明实施例提供一种 IP报文处理方法, 包括:
运营商接入设备接收企业的第一内网中的用户设备发送的内网地址请求 消息;
所述运营商接入设备将所述内网地址请求消息发送给所述运营商业务网 关, 以使所述运营商业务网关为所述用户设备分配内网 IP地址。
在第二方面的第一种可能的实现方式中, 所述运营商接入设备将所述内网 地址请求消息发送给所述运营商业务网关之后, 还包括:
所述运营商接入设备接收所述运营商业务网关发送的包含所述内网 IP地 址的内网地址响应消息;
所述运营商接入设备将所述内网地址响应消息发送给所述用户设备。 在根据第二方面的第一种可能的实现方式的第二种可能的实现方式中, 所 述运营商接入设备将所述内网地址请求消息发送给所述运营商业务网关之前, 还包括:
所述运营商接入设备在所述内网地址请求消息中添加 VLAN标识, 所述 VLAN标识与所述第一内网相对应;
所述运营商接入设备将所述内网地址响应消息发送给所述用户设备, 包 括:
所述运营商接入设备删除所述内网地址响应消息中包含的所述 VLAN标 识, 并将所述内网地址响应消息发送给与所述 VLAN标识对应的第一内网中的 用户设备。
第三方面, 本发明实施例提供一种运营商业务网关, 包括:
分配模块, 用于为企业的第一内网分配 IP地址;
处理模块, 用于根据所述 IP地址对所述第一内网与所述企业的第二内网之 间交互的业务 ^艮文进行处理。
在第三方面的第一种可能的实现方式中, 所述分配模块, 具体用于: 为所述第一内网分配公网 IP地址, 并釆用所述公网 IP地址与所述第二内网 对应的运营商业务网关或路由器进行 IP安全协议 IPSec协商;
为所述第一内网中的用户设备分配内网 IP地址, 所述内网 IP地址与所述公 网 IP地址具有对应关系。
在根据第三方面的第一种可能的实现方式的第二种可能的实现方式中, 所 述分配模块, 还用于:
接收运营商接入设备转发的由所述用户设备发送的内网地址请求消息; 向所述运营商接入设备发送包含所述内网 IP地址的内网地址响应消息, 以 使所述运营商接入设备将所述内网 IP地址发送给所述用户设备。
在根据第三方面的第一种或第二种可能的实现方式的第三种可能的实现 方式中, 所述处理模块, 具体用于:
接收运营商接入设备转发的由所述用户设备发送的第一业务报文, 所述第 一业务才艮文中包含所述内网 IP地址;
对所述第一业务报文进行 IPSec封装, IPSec封装后的第一业务报文中包含 所述公网 IP地址;
向与所述第二内网对应的运营商业务网关或路由器发送 IPSec封装后的第 一业务报文。
在根据第三方面的第三种可能的实现方式的第四种可能的实现方式中, 所 述处理模块, 还用于:
向与所述第二内网对应的运营商业务网关或路由器发送 IPSec封装后的第 一业务报文之后,接收与所述第二内网对应的运营商业务网关或路由器发送的 包含所述第二内网的公网 IP地址的第二业务报文;
对所述第二业务报文进行 IPSec解封装;
向所述运营商接入设备发送 IPSec解封装后的第二业务报文, 以使所述运 营商接入设备将所述第二业务报文发送给所述第一内网的所述用户设备。
在根据第三方面的第二种可能的实现方式的第五种可能的实现方式中, 所 述内网地址请求消息和所述内网地址响应消息中包含虚拟局域网 VLAN标识, 所述 VLAN标识与所述第一内网相对应。
第四方面, 本发明实施例提供一种运营商接入设备, 包括:
接收模块, 用于接收企业的第一内网中的用户设备发送的内网地址请求消 息;
发送模块, 用于将所述内网地址请求消息发送给所述运营商业务网关, 以 使所述运营商业务网关为所述用户设备分配内网 IP地址。
在第四方面的第一种可能的实现方式中, 所述接收模块, 还用于在将所述 内网地址请求消息发送给所述运营商业务网关之后,接收所述运营商业务网关 发送的包含所述内网 IP地址的内网地址响应消息; 所述发送模块, 还用于将所述内网地址响应消息发送给所述用户设备。 在根据第四方面的第一种可能的实现方式的第二种可能的实现方式中,还 包括:
处理模块, 用于在将所述内网地址请求消息发送给所述运营商业务网关之 前, 在所述内网地址请求消息中添加 VLAN标识 , 所述 VLAN标识与所述第一 内网相对应;
所述处理模块, 还用于删除所述内网地址响应消息中包含的所述 VLAN标 识;
所述发送模块, 具体用于将所述内网地址响应消息发送给与所述 VLAN标 识对应的第一内网中的用户设备。
第五方面, 本发明实施例提供一种网络系统, 包括第三方面或第三方面的 任一种可能的实现方式中所述的运营商业务网关和第四方面或第四方面的任 一种可能的实现方式中所述的运营商接入设备。
本发明实施例提供的 IP报文处理方法、 装置及网络系统, 通过运营商业务 网关为企业的第一内网分配 IP地址, 并且由运营商业务网关根据 IP地址对第一 内网与企业的第二内网之间交互的业务报文进行处理,从而可以降低企业内部 网络部署的复杂度, 降低企业内部网络的管理维护的难度、 成本, 降低企业内 部网络硬件设备更新投资成本。 附图说明 为了更清楚地说明本发明实施例或现有技术中的技术方案, 下面将对实施 例或现有技术描述中所需要使用的附图作一简单地介绍, 显而易见地, 下面描 述中的附图是本发明的一些实施例, 对于本领域普通技术人员来讲, 在不付出 创造性劳动性的前提下, 还可以根据这些附图获得其他的附图。
图 1为本发明提供的 IP报文处理方法实施例一的流程图;
图 2为本发明提供的 IP报文处理方法实施例二的流程图;
图 3为本发明提供的 IP报文处理方法实施例三的流程图;
图 4为本发明提供的 IP报文处理方法实施例四的流程图;
图 5为本发明提供的运营商业务网关实施例一的结构示意图;
图 6为本发明提供的运营商业务网关实施例二的结构示意图; 图 7为本发明提供的运营商接入设备实施例一的结构示意图; 图 8为本发明提供的运营商接入设备实施例二的结构示意图;
图 9为本发明提供的运营商接入设备实施例三的结构示意图;
图 1 OA为本发明提供的网络系统实施例一的结构示意图;
图 10B为图 10A所示网络系统实现本发明提供的 IP报文处理方法实施例中
IP地址分配阶段的流程图;
图 10C为图 10A所示网络系统实现本发明提供的 IP报文处理方法实施例中 报文收发阶段的流程图;
图 11 A为本发明提供的网络系统实施例二的结构示意图;
图 11B为图 11A所示网络系统实现本发明提供的 IP报文处理方法实施例中
IP地址分配阶段的流程图;
图 11C为图 11A所示网络系统实现本发明提供的 IP报文处理方法实施例中 报文收发阶段的流程图。 具体实施方式 为使本发明实施例的目的、 技术方案和优点更加清楚, 下面将结合本发明 实施例中的附图,对本发明实施例中的技术方案进行清楚、完整地描述,显然, 所描述的实施例是本发明一部分实施例, 而不是全部的实施例。 基于本发明中 的实施例, 本领域普通技术人员在没有作出创造性劳动前提下所获得的所有其 他实施例, 都属于本发明保护的范围。
图 1为本发明提供的 IP报文处理方法实施例一的流程图, 如图 1所示, 本实 施例的 ΙΡ· ^艮文处理方法, 包括:
S101、 运营商业务网关为企业的第一内网分配 IP地址。
具体来说,企业的第一内网可以是企业的总部机构的内部网络或企业的分 支机构的内部网络, 企业的分支机构和总部机构、 分支机构和分支机构之间通 过 IPSec VPN实现互联互通时, 第一内网需要获取可以用于连接公网的 IP地址, 而第一内网中的用户设备需要获取可以用于与其他内网中用户设备互通的内 网 IP地址, 本实施例可以由运营商业务网关为第一内网分配公网 IP地址, 并且 为第一内网中的用户设备分配与内网 IP地址, 所分配的内网 IP地址与上述分配 的公网地址具有对应关系。 举例来说, 上述运营商业务网关可以是运营商宽带网络业务网关
(Broadband Network Gateway , 简称 BNG)。
现有技术中, 第一内网获取公网 IP地址的方式为: 设置于第一内网中的接 入路由器通过拨号向运营商业务网关请求公网 IP地址, 运营商业务网关对请求 进行认证后, 再向第一内网中的接入路由器返回公网 IP地址, 而本发明实施例 中运营商业务网关在第一内网注册时就为第一内网分配了公网 IP地址, 所以本 发明实施例中的第一内网中的网络可以得到简化, 例如可以不需要设置接入路 由器, 或者可以简化第一内网中的接入路由器或类似设备的功能。
S102、运营商业务网关根据 IP地址对第一内网与企业的第二内网之间交互 的业务报文进行处理。
以企业的第一内网中的用户设备和企业的第二内网之间的用户设备进行 交互为例,运营商业务网关可以根据分别为企业的第一内网以及企业的第一内 网中的用户设备分配的公网 IP地址以及内网 IP地址和分别为企业的第二内网以 及企业的第二内网中的用户设备分配的公网 IP地址以及内网 IP地址, 对第一内 网中的用户设备和第二内网中的用户设备之间交互的 IP报文进行处理, 以实现 第一内网中的用户设备和第二内网中的用户设备之间的信息传输。
现有技术中第一内网与第二内网分别使用公网 IP进行 IPSec协商以及将报 文发送到 IPSec隧道发送的操作是在分别设置于第一内网中的接入路由器和设 置于第二内网中的接入路由器之间完成的, 本发明实施例第一内网与第二内网 分别使用公网 IP进行 IPSec协商以及将报文发送到 IPSec隧道发的操作送可以在 第一内网对应的运营商业务网关和设置于第二内网中的接入路由器之间完成, 也可以在第一内网对应的运营商业务网关和第二内网对应的运营商业务网关 之间完成。
而由运营商业务网关为第一内网分配 IP地址, 并根据 IP地址对第一内网与 企业的第二内网之间交互的业务报文进行处理, 可以降低企业内部网络部署的 复杂度, 从而可以降低企业内部网络的管理维护的难度、 成本, 进一步地, 若 企业由于业务需求增加或者网络流量增加需要升级内部网络时, 只需要对本实 施例中用以执行 IP报文处理方法的运营商业务网关进行软件更新即可实现, 可 以减少现有技术中对企业内部网络硬件设备的替换,从而可以降低企业内部网 络硬件设备更新投资成本。
本实施例提供的 ΙΡ· ^艮文处理方法, 通过运营商业务网关为企业的第一内网 分配 IP地址, 并且由运营商业务网关根据 IP地址对第一内网与企业的第二内网 之间交互的业务报文进行处理, 从而可以降低企业内部网络部署的复杂度, 降 低企业内部网络的管理维护的难度、 成本, 降低企业内部网络硬件设备更新投 资成本。
图 2为本发明提供的 ΙΡ·^艮文处理方法实施例二的流程图, 如图 2所示, 本实 施例的 ΙΡ· ^艮文处理方法, 包括:
5201、 运营商业务网关为第一内网分配公网 IP地址, 并釆用公网 IP地址与 第二内网对应的运营商业务网关或路由器进行 IP安全协议 IPSec协商。
具体来说, 运营商业务网关为第一内网分配公网 IP地址可以是静态的或动 态的公网 IP地址, 若第二内网中设置有接入路由器, 则运营商业务网关釆用为 第一内网分配的公网 IP地址与第二内网中的接入路由器进行 IPSec协商;若第二 内网中未设置接入路由器, 则运营商业务网关釆用为第一内网分配的公网 IP地 址与第二内网对应的运营商业务网关进行 IPSec协商。
IPSec协商的结果可以包括传输信息所需的认证协议以及安全机制所需的 加密密钥等信息。
5202、 运营商业务网关为第一内网中的用户设备分配内网 IP地址, 内网 IP 地址与公网 IP地址具有对应关系。
具体来说, 若第一内网中的用户设备需要与其他内网中的用户设备进行交 互, 则需获取内网 IP地址。
本实施例中所述的用户设备可以是企业网中所可能使用的任意设备, 例如 个人计算机(personal computer, 简称 PC )等, 本实施例不做限定。
进一步地, S202可以包括:
运营商业务网关接收运营商接入设备转发的由用户设备发送的内网地址 请求消息;
第一内网中的用户设备需要获取内网 IP地址时, 会向运营商接入设备发送 内网地址请求消息, 运营商接入设备接收到上述内网地址请求消息后, 会将内 网地址请求消息转发给运营商业务网关。
可以理解的是, 若运营商业务网关为多个企业内网服务, 则需要由运营商 接入设备接收到上述内网地址请求消息后,根据入端口号为该内网地址请求消 息添加虚拟局域网( Virtual Local Area Network , 简称 VLAN )标识, 该 VLAN 标识与第一内网相对应。 运营商业务网关向运营商接入设备发送包含内网 IP地址的内网地址响应 消息, 以使运营商接入设备将内网 IP地址发送给用户设备。
运营商业务网关接收到内网地址请求消息后, 向运营商接入设备发送包含 内网 IP地址的内网地址响应消息, 以使运营商接入设备将内网 IP地址发送给第 一内网中的用户设备。
S203、运营商业务网关接收运营商接入设备转发的由用户设备发送的第一 业务报文, 第一业务报文中包含内网 IP地址。
以企业的第一内网中的用户设备和企业的第二内网中的用户设备进行交 互为例, 第一内网中的用户设备根据业务信息、 内网 IP地址以及对端的第二内 网中用户设备的内网 IP地址, 生成第一业务报文, 并将第一业务报文发送给运 营商接入设备, 同样的, 若运营商业务网关为多个企业内网服务, 则需要由运 营商接入设备接收到上述第一业务报文后,根据入端口号为第一业务报文添加
VLAN标识, 该 VLAN标识与第一内网相对应, 运营商业务网关接收运营商接 入设备转发的添加有 VLAN标识的第一业务报文。
5204、 运营商业务网关对第一业务 文进行 IPSec封装, IPSec封装后的第 一业务 4艮文中包含公网 IP地址。
具体来说,若运营商业务网关接收到的第一业务报文中包含有 VLAN标识, 则在对第一业务报文进行 IPSec封装之前, 需去除 VLAN标识, IPSec封装后的 第一业务才艮文中包含第一内网的公网 IP地址和对端第二内网的公网 IP地址。
5205、运营商业务网关向与第二内网对应的运营商业务网关或路由器发送 IPSec封装后的第一业务 "^文。
若第二内网中设置有接入路由器, 则运营商业务网关向第二内网中的接入 路由器发送 IPSec封装后的第一业务报文; 若第二内网中未设置接入路由器, 则运营商业务网关向第二内网对应的运营商业务网关发送 IPSec封装后的第一 业务报文。
5206、运营商业务网关接收与第二内网对应的运营商业务网关或路由器发 送的包含第二内网的公网 IP地址的第二业务报文。
第二内网对应的运营商业务网关或路由器接收到上述 IPSec封装后的第一 业务报文后, 对其进行解除 IPSec封装, 并发送给第二内网中的用户设备, 以 使第二内网中的用户设备根据对第一业务报文的反馈业务信息、第二内网中的 用户设备的内网 IP地址和第一内网中的用户设备的内网 IP地址生成第二业务才艮 文, 并将第二业务报文发送给第二内网对应的运营商业务网关或路由器, 第二 内网对应的运营商业务网关或路由器对接收到的第二业务报文进行 IPSec封 装。
5207、 运营商业务网关对第二业务 文进行 IPSec解封装。
5208、 运营商业务网关向运营商接入设备发送 IPSec解封装后的第二业务 报文, 以使运营商接入设备将第二业务报文发送给第一内网的用户设备。
进一步地, 本实施例中的内网地址请求消息、 内网地址响应消息中可以包 含虚拟局域网 VLAN标识, VLAN标识与第一内网相对应。
本实施例提供的 ΙΡ·¾文处理方法, 通过运营商业务网关分别为企业的第一 内网及第一内网中的用户设备分配公网 IP地址和内网 IP地址, 并且由运营商业 务网关根据公网 IP地址和公内网 IP地址对第一内网中的用户设备发送的第一业 务报文进行 IPSec封装, 通过公网传送给第二内网对应的运营商业务网关或路 由器, 再向运营商接入设备发送 IPSec解封装后的第二业务报文, 以使运营商 接入设备将第二业务报文发送给第一内网的用户设备,从而可以降低企业内部 网络部署的复杂度, 降低企业内部网络的管理维护的难度、 成本, 降低企业内 部网络硬件设备更新投资成本。
图 3为本发明提供的 ΙΡ·^艮文处理方法实施例三的流程图, 如图 3所示, 本实 施例的 ΙΡ· ^艮文处理方法, 包括:
5301、运营商接入设备接收企业的第一内网中的用户设备发送的内网地址 请求消息。
第一内网中的用户设备需要获取内网 IP地址时, 会向运营商接入设备发送 内网地址请求消息, 运营商接入设备接收到上述内网地址请求消息后, 会将内 网地址请求消息转发给运营商业务网关。
可以理解的是, 若运营商业务网关为多个企业内网服务, 则需要由运营商 接入设备接收到上述内网地址请求消息后,根据入端口号为该内网地址请求消 息添加 VLAN标识, 该 VLAN标识与第一内网相对应。
5302、 运营商接入设备将内网地址请求消息发送给运营商业务网关, 以使 运营商业务网关为用户设备分配内网 IP地址。
现有技术中, 第一内网中的用户设备会通过与设置于第一内网中的接入路 由器的交互得到内网 IP地址, 而本发明实施例提供的 IP报文处理方法, 通过运 营商接入设备向运营商业务网关转发用户设备的内网地址请求消息, 再将由运 营商业务网关为用户设备分配的内网 IP地址转发给用户设备, 以使用户设备分 配到内网 IP地址。
本实施例提供的 IP报文处理方法, 通过运营商接入设备接收企业的第一内 网中的用户设备发送的内网地址请求消息,将内网地址请求消息发送给运营商 业务网关, 以使运营商业务网关为用户设备分配内网 IP地址, 从而可以降低企 业内部网络部署的复杂度, 降低企业内部网络的管理维护的难度、 成本, 降低 企业内部网络硬件设备更新投资成本。
图 4为本发明提供的 ΙΡ·^艮文处理方法实施例四的流程图, 如图 4所示, 本实 施例的 ΙΡ· ^艮文处理方法, 包括:
S401、运营商接入设备接收企业的第一内网中的用户设备发送的内网地址 请求消息。
5402、 运营商接入设备将内网地址请求消息发送给运营商业务网关。
5403、运营商接入设备接收运营商业务网关发送的包含内网 IP地址的内网 地址响应消息。
运营商业务网关发送的包含内网 IP地址的内网地址响应消息中包含有为 第一内网用户设备分配的内网 IP地址。
5404、 运营商接入设备将内网地址响应消息发送给用户设备。
进一步地, 若运营商业务网关为多个企业内网服务, 则上述 S402之前, 还 包括: 运营商接入设备在内网地址请求消息中添加 VLAN标识, VLAN标识与 第一内网相对应。
S404具体可以为: 运营商接入设备删除内网地址响应消息中包含的 VLAN 标识, 并将内网地址响应消息发送给与 VLAN标识对应的第一内网中的用户设 备。
本实施例提供的 IP报文处理方法, 通过运营商接入设备接收企业的第一内 网中的用户设备发送的内网地址请求消息,将内网地址请求消息发送给运营商 业务网关, 以使运营商业务网关为用户设备分配内网 IP地址, 从而可以降低企 业内部网络部署的复杂度, 降低企业内部网络的管理维护的难度、 成本, 降低 企业内部网络硬件设备更新投资成本。
图 5为本发明提供的运营商业务网关实施例一的结构示意图, 如图 5所示, 本实施例的运营商业务网关, 包括分配模块 51和处理模块 52, 其中, 分配模块 51用于为企业的第一内网分配 IP地址; 处理模块 52用于根据 IP地址对第一内网 与企业的第二内网之间交互的业务报文进行处理。
举例来说, 本实施例提供的运营商业务网关可以是 BNG。
本实施例的装置, 可以用于执行图 1所示方法实施例的技术方案, 其实现 原理和技术效果类似, 此处不再赘述。
本发明提供的运营商业务网关实施例二中, 分配模块 51具体用于: 为第一内网分配公网 IP地址, 并釆用公网 IP地址与第二内网对应的运营商 业务网关或路由器进行 IP安全协议 IPSec协商;
为第一内网中的用户设备分配内网 IP地址, 内网 IP地址与公网 IP地址具有 对应关系。
分配模块 51还用于:
接收运营商接入设备转发的由用户设备发送的内网地址请求消息; 向运营商接入设备发送包含内网 IP地址的内网地址响应消息, 以使运营商 接入设备将内网 IP地址发送给用户设备。
处理模块 52具体用于:
接收运营商接入设备转发的由用户设备发送的第一业务报文, 第一业务报 文中包含内网 IP地址;
对第一业务报文进行 IPSec封装, IPSec封装后的第一业务报文中包含公网 IP地址;
向与第二内网对应的运营商业务网关或路由器发送 IPSec封装后的第一业 务报文。
处理模块 52还用于:
向与第二内网对应的运营商业务网关或路由器发送 IPSec封装后的第一业 务报文之后,接收与第二内网对应的运营商业务网关或路由器发送的包含第二 内网的公网 IP地址的第二业务报文;
对第二业务报文进行 IPSec解封装;
向运营商接入设备发送 IPSec解封装后的第二业务报文, 以使运营商接入 设备将第二业务报文发送给第一内网的用户设备。
进一步地, 上述内网地址请求消息、 内网地址响应消息、 IPSec封装前的 第一业务报文以及 IPSec解封装后的第二业务报文中包含虚拟局域网 VLAN标 识, VLAN标识与第一内网相对应。
本实施例的装置, 可以用于执行图 2所示方法实施例的技术方案, 其实现 原理和技术效果类似, 此处不再赘述。
如图 5所示的运营商业务网关可以执行图 1 -图 4中任一附图所对应的实施 例中的运营商业务网关的全部操作或功能。
图 6为本发明提供的运营商业务网关实施例二的结构示意图, 如图 6所示, 本实施例的运营商业务网关, 包括至少一个处理器 601 , 例如中央处理单元 ( Central Processing Unit, 简称 CPU ) , 至少一个网络接口 602以及其他用户接 口 603 , 存储器 604, 至少一个通信总线 605以及操作系统 606。 通信总线 605用 于实现这些装置之间的连接通信。 存储器 604可能包含高速 RAM存储器, 也可 能还包括非易失性存储器( non-volatile memory ) , 例如至少一个磁盘存储器。 存储器 604可选的可以包含至少一个位于远离前述处理器 601的存储装置。操作 系统 606, 包含各种程序, 用于实现各种基础业务以及处理基于硬件的任务。
处理器 601 , 用于为企业的第一内网分配 IP地址;
处理器 601 , 用于根据 IP地址对第一内网与企业的第二内网之间交互的业 务报文进行处理。
进一步地, 处理器 601 , 具体用于:
为第一内网分配公网 IP地址, 并釆用公网 IP地址与第二内网对应的运营商 业务网关或路由器进行 IP安全协议 IPSec协商;
为第一内网中的用户设备分配内网 IP地址, 内网 IP地址与公网 IP地址具有 对应关系。
进一步地, 处理器 601 , 还用于:
接收运营商接入设备转发的由用户设备发送的内网地址请求消息; 向运营商接入设备发送包含内网 IP地址的内网地址响应消息, 以使运营商 接入设备将内网 IP地址发送给用户设备。
进一步地, 处理器 601 , 具体用于:
接收运营商接入设备转发的由用户设备发送的第一业务报文, 第一业务报 文中包含内网 IP地址;
对第一业务报文进行 IPSec封装, IPSec封装后的第一业务报文中包含公网 IP地址;
向与第二内网对应的运营商业务网关或路由器发送 IPSec封装后的第一业 务报文。
进一步地, 处理器 601 , 还用于: 向与第二内网对应的运营商业务网关或路由器发送 IPSec封装后的第一业 务报文之后,接收与第二内网对应的运营商业务网关或路由器发送的包含第二 内网的公网 IP地址的第二业务报文;
对第二业务报文进行 IPSec解封装;
向运营商接入设备发送 IPSec解封装后的第二业务报文, 以使运营商接入 设备将第二业务报文发送给第一内网的用户设备。
本实施例中所涉及到的部分或全部消息, 该消息的产生可以由运营商业务 网关的处理器 601或由其他部件 /模块或由处理器 601结合其他部件 /模块来实 现。
存储器 604可以保存有可读的计算机指令或计算机程序。 所述至少一个处 理器 601在本实施例中执行的各种操作可以是根据所述计算机指令或计算机程 序完成的。
本实施例中的运营商业务网关中的至少一个处理器 601还可以根据存储器 604中保存的可读的计算机指令或计算机程序, 执行图 1 -图 4中任一附图所对应 的实施例中的运营商业务网关的全部操作或功能。
本实施例提供的运营商业务网关, 可以用于执行图 1或图 2所示方法实施例 的技术方案中运营商业务网关对应执行的部分, 其实现原理和技术效果类似, 此处不再赘述。 图 6仅为本发明提供的运营商业务网关的结构的一种示意图, 具体结构可根据实际进行调整。
图 7为本发明提供的运营商接入设备实施例一的结构示意图, 如图 7所示, 本实施例的运营商接入设备, 包括接收模块 71和发送模块 72, 其中, 接收模块 71用于接收企业的第一内网中的用户设备发送的内网地址请求消息; 发送模块 72用于将内网地址请求消息发送给运营商业务网关, 以使运营商业务网关为用 户设备分配内网 IP地址。
本实施例的装置, 可以用于执行图 3所示方法实施例的技术方案, 其实现 原理和技术效果类似, 此处不再赘述。
图 8为本发明提供的运营商接入设备实施例二的结构示意图, 如图 8所示, 本实施例的运营商接入设备中,接收模块 71还用于在将内网地址请求消息发送 给运营商业务网关之后, 接收运营商业务网关发送的包含内网 IP地址的内网地 址响应消息;
发送模块 72还用于将内网地址响应消息发送给用户设备。 本实施例的运营商接入设备还包括: 处理模块 73 , 处理模块 73用于在将内 网地址请求消息发送给运营商业务网关之前, 在内网地址请求消息中添加 VLAN标识 , VLAN标识与第一内网相对应;
处理模块 73还用于删除内网地址响应消息中包含的 VLAN标识;
发送模块 72具体用于将内网地址响应消息发送给与 VLAN标识对应的第一 内网中的用户设备。
本实施例的装置, 可以用于执行图 4所示方法实施例的技术方案, 其实现 原理和技术效果类似, 此处不再赘述。
如图 7或图 8所示的运营商接入设备可以执行图 1 -图 4中任一附图所对应的 实施例中的运营商接入设备的全部操作或功能。
图 9为本发明提供的运营商接入设备实施例三的结构示意图, 如图 9所示, 本实施例的运营商接入设备, 包括至少一个处理器 901 , 例如 CPU, 至少一个 网络接口 902以及其他用户接口 903 , 存储器 904, 至少一个通信总线 905以及操 作系统 906。 通信总线 905用于实现这些装置之间的连接通信。 存储器 904可能 包含高速 RAM存储器,也可能还包括非易失性存储器,例如至少一个磁盘存储 器。 存储器 904可选的可以包含至少一个位于远离前述处理器 901的存储装置。 操作系统 906, 包含各种程序, 用于实现各种基础业务以及处理基于硬件的任 务。
网络接口 902 , 用于接收企业的第一内网中的用户设备发送的内网地址请 求消息;
网络接口 902, 用于将内网地址请求消息发送给运营商业务网关, 以使运 营商业务网关为用户设备分配内网 IP地址。
进一步地, 网络接口 902, 还用于在将内网地址请求消息发送给运营商业 务网关之后, 接收运营商业务网关发送的包含内网 IP地址的内网地址响应消 息;
进一步地, 网络接口 902 , 还用于将内网地址响应消息发送给用户设备。 处理器 901 , 用于在将内网地址请求消息发送给运营商业务网关之前, 在 内网地址请求消息中添加 VLAN标识 , VLAN标识与第一内网相对应;
处理器 901 , 还用于删除内网地址响应消息中包含的 VLAN标识; 网络接口 902 ,具体用于将内网地址响应消息发送给与 VLAN标识对应的第 一内网中的用户设备。 本实施例中所涉及到的部分或全部消息, 该消息的产生可以由运营商接入 设备的处理器 901或其他部件 /模块或处理器 901结合其他部件 /模块来实现。
存储器 904可以保存有可读的计算机指令或计算机程序。 所述至少一个处 理器 901在本实施例中执行的各种操作可以是根据所述计算机指令或计算机程 序完成的。
本实施例中的运营商业务网关中的至少一个处理器 901还可以根据存储器 904中保存的可读的计算机指令或计算机程序, 执行图 1 -图 4中任一附图所对应 的实施例中的运营商接入设备的全部操作或功能。
本实施例提供的运营商接入设备, 可以用于执行图 3或图 4所示方法实施例 的技术方案中运营商接入设备对应执行的部分, 其实现原理和技术效果类似, 此处不再赘述。 图 9仅为本发明提供的运营商接入设备的结构的一种示意图, 具体结构可根据实际进行调整。
本发明实施例提供的网络系统包括上述实施例中的任意一种运营商业务 网关和上述实施例中的任意一种运营商接入设备。
以下以企业 A分支网络和企业 A总部网络的互通为例,企业 A分支网络可以 为上述实施例中的第一内网,企业 A总部网络可以为上述实施例中的第二内网, 结合本发明实施例提供的网络系统实施例的结构示意图和 IP报文处理方法的 流程图, 对本发明实施例的技术方案进行进一步详细说明:
图 10 A为本发明提供的网络系统实施例一的结构示意图, 本实施例的网络 系统, 即为运营商网络 300, 该运营商网络 300中可以包括运营商业务网关 310 和运营商接入设备 320,企业 A可以包括一个企业 A分支网络 100和一个企业 A总 部网络 200,企业 A分支网络 100中仅包含 PC和用于连接各 PC并连接网络的交换 机, PC可以是上述实施例中第一内网或第二内网中的用户设备, 企业 A总部网 络 200除包含有 PC和用于连接各 PC并连接网络的交换机之外, 还包括一个接入 路由器 210。 本实施例所针对的场景为, 企业 A分支网络 100与企业 A总部网络 100处于相同的地域, 接入相同的运营商业务网关的情况。
可以理解的是, 本实施例中, 除企业 A分支网络 100之外, 还可以包括更多 的企业 A分支网络, 而且, 除企业 A分支网络 100、 企业 A总部网络 200以外, 还 可以在运营商网络中接入更多的企业网络, 例如企业 B分支网络或企业 B总部 网络等其他多个组织机构网络, 本实施例中的运营商业务网关 310和运营商接 入设备 320可同时为多个组织机构网络分配 IP地址、并才艮据分配的 IP地址对组织 机构网络之间交互的业务 ^艮文进行处理 , 运营商业务网关 310和运营商接入设 备 320例如可以通过各个组织机构网络对应的 VLAN标识对多个组织机构网络 进行区分。
图 10B为图 10A所示网络系统实现本发明提供的 IP报文处理方法实施例中 IP地址分配阶段的流程图, 如图 10B和图 10A所示, 本实施例的 IP报文处理方法 中 IP地址分配阶段, 包括:
51001、 运营商业务网关为企业 A分支网络分配公网 IP地址;
运营商业务网关为企业 A分支网络分配公网 IP地址可以是静态的或动态的 公网 IP地址。
51002、运营商业务网关釆用公网 IP地址与企业 A总部网络对应的路由器进 行 IP安全协议 IPSec协商。
上述企业 A总部网络对应的路由器的公网 IP地址为固定 IP地址。
IPSec协商的结果可以包括传输信息所需的认证协议以及安全机制所需的 加密密钥等信息。
51003、 企业 A分支网络中的 PC向运营商接入设备发送内网 IP地址请求消 息。
S 1004、 运营商接入设备根据入端口号为该内网地址请求消息添加 VLAN 标识, 该 VLAN标识与企业 A分支网络相对应。
若运营商业务网关为多个企业内网服务, 则需要添加与企业 A分支网络相 对应的 VLAN标识。
51005、 运营商接入设备向运营商业务网关发送包含有 VLAN标识的内网 地址请求消息。
51006、 运营商业务网关向运营商接入设备发送包含内网 IP地址的内网地 址响应消息, 该内网地址响应消息中还携带有与企业 A分支网络相对应的 VLAN标识。
51007、 运营商接入设备根据 VLAN标识, 将内网地址响应消息发送给企 业 A分支网络中的 PC, 同时去除 VLAN标识。
51008、 企业 A分支网络中的 PC接收内网地址响应消息。
本实施例经过上述步骤, 实现运营商业务网关为企业 A分支网络分配公网 进一步地,图 10C为图 10A所示网络系统实现本发明提供的 IP报文处理方法 实施例中 4艮文收发阶段的流程图,如图 10C和图 1 OA所示,本实施例的 IP^艮文处 理方法中报文收发阶段, 包括:
51009、 企业 A分支网络中的 PC将第一业务报文发送给运营商接入设备。 企业 A分支网络中的 PC根据业务信息、 内网 IP地址以及对端的第二内网中 用户设备的内网 IP地址, 生成第一业务 文。
51010、 运营商接入设备根据入端口号为第一业务报文添加 VLAN标识, 该 VLAN标识与第一内网相对应。
S 1011、 运营商接入设备添加有 VLAN标识的第一业务报文发送给运营商 业务网关。
51012、运营商业务网关对第一业务 文去除 VLAN标识后进行 IPSec封装。 IPSec封装后的第一业务报文中除业务信息外,还包含企业 A分支网络和企 业 A总部网络的公网 IP地址。
51013、 运营商业务网关向企业 A总部网络的路由器发送去除 VLAN标识、 IPSec封装后的第一业务 "^文。
51014、企业 A总部网络的路由器对接收到的第一业务报文解封装后发送给 企业 A总部网络中的 PC。
51015、企业 A总部网络中的 PC将第二业务报文发送给企业 A总部网络的路 由器。
企业 A总部网络中的 PC根据对第一业务报文的反馈业务信息、 第二内网中 的用户设备的内网 IP地址和第一内网中的用户设备的内网 IP地址生成第二业务 报文。
51016、企业 A总部网络的路由器对接收到的第二业务报文进行 IPSec封装, 并将 IPSec封装后的第二业务 文发送给运营商业务网关。
51017、 运营商业务网关对接收到的第二业务报文解封装、 添加与企业 A 分支网络相对应的 VLAN标识后发送给运营商接入设备。
51018、 运营商接入设备根据 VLAN标识, 将解封装后的第二业务报文发 送给企业 A分支网络中的 PC, 同时去除 VLAN标识。
51019、 企业 A分支网络中的 PC接收第二业务报文。
在上述图 10A~10C所示实施例的基础上, 可以理解的是, 企业 A总部网络 200中也可以不设置接入路由器,而由运营商业务网关 310为企业 A总部网络 200 以及企业 A总部网络 200中的 PC分配公网 IP地址和内网 IP地址,并根据 IP地址对 企业 A总部网络 200中的 PC与企业 A分支网络 100中 PC之间交互的业务报文进 行处理。
本实施例, 通过运营商业务网关分别为企业 A分支网络及企业 A分支网络 中的用户设备分配公网 IP地址和公内网 IP地址, 并且由运营商业务网关根据公 网 IP地址和公内网 IP地址对企业 A分支网络中的用户设备发送的第一业务 ^艮文 进行 IPSec封装, 通过公网传送给与企业 A总部网络对应的路由器, 再向运营商 接入设备发送 IPSec解封装后的第二业务报文, 以使运营商接入设备将第二业 务报文发送给企业 A分支网络的用户设备, 从而可以降低企业内部网络部署的 复杂度, 降低企业内部网络的管理维护的难度、 成本, 降低企业内部网络硬件 设备更新投资成本。
图 11 A为本发明提供的网络系统实施例二的结构示意图, 本实施例的网络 系统, 即为运营商网络 700, 该运营商网络 700可以包括与企业 A分支网络 500 对应的第一运营商业务网关 710、 与企业 A总部网络 600对应的第二运营商业务 网关 720、 与企业 A分支网络 500对应的第一运营商接入设备 730以及与企业 A总 部网络 600对应的第二运营商接入设备 740 , 企业 A分支网络 600和企业 A总部网 络 700中仅包含 PC和用于连接各 PC并连接网络的交换机, PC可以是上述实施例 中第一内网或第二内网中的用户设备。 本实施例所针对的场景为, 企业 A分支 网络 500与企业 A总部网络 600处于不同的地域, 分别接入不同的运营商业务网 关的情况。
可以理解的是, 本实施例中, 除企业 A分支网络 500之外, 还可以包括更多 的企业 A分支网络, 而且, 除企业 A分支网络 500、 企业 A总部网络 600以外, 还 可以包括例如企业 B分支网络或企业 B总部网络等其他多个组织机构网络, 本 实施例中的第一运营商业务网关 710和第一运营商接入设备 730或第二运营商 业务网关 720和第二运营商接入设备 740可同时为多个组织机构网络分配 IP地 址、 并根据分配的 IP地址对组织机构网络之间交互的业务报文进行处理, 运营 商业务网关和运营商接入设备例如可以通过各个组织机构网络对应的 VLAN标 识对多个组织机构网络进行区分。
图 11B为图 11A所示网络系统实现本发明提供的 IP报文处理方法实施例中 IP地址分配阶段的流程图, 如图 11B和图 11 A所示, 包括:
51101、 第一运营商业务网关为企业 A分支网络分配公网 IP地址。
51102、 第一运营商业务网关釆用公网 IP地址与第二运营商业务网关进行 IP安全协议 IPSec协商。 的 S1003 S1008相似, 此处不再赘述。
进一步地,图 11C为图 11 A所示网络系统实现本发明提供的 ΙΡ·^艮文处理方法 实施例中 4艮文收发阶段的流程图,如图 11 C和图 11 Α所示,本实施例的 IP^艮文处 理方法中 4艮文收发阶段中 S1109~S1112与图 10C中的 S1009~S1012相似, 此处不 再赘述。
51113、 第一运营商业务网关向第二运营商业务网关发送 IPSec封装后的第 一业务报文。
51114、第二运营商业务网关对接收到的第一业务报文解封装、添加 VLAN 标识后发送给第二运营商接入设备, 此处添加的 VLAN标识为与企业 A总部网 络相对应的 VLAN标识。
51115、 第二运营商接入设备根据 VLAN标识, 将接收到的第一业务报文 发送给企业 A总部网络中的 PC, 同时去除 VLAN标识。
51116、 企业 A总部网络中的 PC接收第二运营商接入设备发送的第一业务 报文。
51117、 企业 A总部网络中的 PC将第二业务报文发送给第二运营商接入设 备。
企业 A总部网络中的 PC根据对第一业务报文的反馈业务信息、 第二内网中 的用户设备的内网 IP地址和第一内网中的用户设备的内网 IP地址生成第二业务 报文。
51118、 第二运营商接入设备根据入端口号为该第二业务报文添加 VLAN 标识, 该 VLAN标识为与企业 A总部网络相对应的 VLAN标识。
51119、 第二运营商接入设备向第二运营商业务网关发送添加有 VLAN标 识的第二业务报文。
51120、 第二运营商业务网关对接收到的第二业务报文进行 IPSec封装, 并 将 IPSec封装后的第二业务报文发送给第一运营商业务网关。
S1121~S1123和图 10C中的 S1017~S1019相同, 此处不再赘述。
在上述图 11A 11C所示实施例的基础上, 可以理解的是, 企业 A分支网络 600和企业 A总部网络 700其中之一可以设置接入路由器, 设置接入路由器的企 业 A网络中 PC的内网地址则由接入路由器分配, 并由接入路由器根据 IP地址对 企业 A总部网络 700中的 PC与企业 A分支网络 600中 PC之间交互的业务报文进 行处理。
本实施例, 通过第一运营商业务网关分别为企业 A分支网络及企业 A分支 网络中的用户设备分配公网 IP地址和公内网 IP地址, 并且由运营商业务网关根 据公网 IP地址和公内网 IP地址对企业 A分支网络中的用户设备发送的第一业务 报文进行 IPSec封装, 通过公网传送给第二运营商业务网关, 再向运营商接入 设备发送 IPSec解封装后的第二业务报文, 以使运营商接入设备将第二业务报 文发送给企业 A分支网络的用户设备, 从而可以更近一步地降低企业内部网络 部署的复杂度, 降低企业内部网络的管理维护的难度、 成本, 降低企业内部网 络硬件设备更新投资成本。
本领域普通技术人员可以理解: 实现上述方法实施例的全部或部分步骤可 以通过程序指令相关的硬件来完成, 前述的程序可以存储于一计算机可读取存 储介质中, 该程序在执行时, 执行包括上述方法实施例的步骤; 而前述的存储 介质包括: ROM、 RAM, 磁碟或者光盘等各种可以存储程序代码的介质。
最后应说明的是: 以上各实施例仅用以说明本发明的技术方案, 而非对其 限制; 尽管参照前述各实施例对本发明进行了详细的说明, 本领域的普通技术 人员应当理解: 其依然可以对前述各实施例所记载的技术方案进行修改, 或者 对其中部分或者全部技术特征进行等同替换; 而这些修改或者替换, 并不使相 应技术方案的本质脱离本发明各实施例技术方案的范围。

Claims

权 利 要 求 书
1、 一种 ΙΡ·¾文处理方法, 其特征在于, 包括:
运营商业务网关为企业的第一内网分配 IP地址;
所述运营商业务网关根据所述 IP地址对所述第一内网与所述企业的第二 内网之间交互的业务才艮文进行处理。
2、 根据权利要求 1所述的方法, 其特征在于, 所述运营商业务网关为企业 的第一内网分配 IP地址, 包括:
所述运营商业务网关为所述第一内网分配公网 IP地址, 并釆用所述公网 IP 地址与所述第二内网对应的运营商业务网关或路由器进行 IP安全协议 IPSec协 商;
所述运营商业务网关为所述第一内网中的用户设备分配内网 IP地址, 所述 内网 IP地址与所述公网 IP地址具有对应关系。
3、 根据权利要求 2所述的方法, 其特征在于, 所述运营商业务网关为所述 第一内网中的用户设备分配内网 IP地址, 包括:
所述运营商业务网关接收运营商接入设备转发的由所述用户设备发送的 内网地址请求消息;
所述运营商业务网关向所述运营商接入设备发送包含所述内网 IP地址的 内网地址响应消息, 以使所述运营商接入设备将所述内网 IP地址发送给所述用 户设备。
4、 根据权利要求 2或 3所述的方法, 其特征在于, 所述运营商业务网关根 据所述 IP地址对所述第一内网与所述企业的第二内网之间交互的业务报文进 行处理, 包括:
所述运营商业务网关接收运营商接入设备转发的由所述用户设备发送的 第一业务报文, 所述第一业务报文中包含所述内网 IP地址;
所述运营商业务网关对所述第一业务 文进行 IPSec封装, IPSec封装后的 第一业务报文中包含所述公网 IP地址;
所述运营商业务网关向与所述第二内网对应的运营商业务网关或路由器 发送 IPSec封装后的第一业务报文。
5、 根据权利要求 4所述的方法, 其特征在于, 所述向与所述第二内网对应 的运营商业务网关或路由器发送 IPSec封装后的第一业务报文之后, 还包括: 所述运营商业务网关接收与所述第二内网对应的运营商业务网关或路由 器发送的包含所述第二内网的公网 IP地址的第二业务报文;
所述运营商业务网关对所述第二业务报文进行 IPSec解封装;
所述运营商业务网关向所述运营商接入设备发送 IPSec解封装后的第二业 务报文, 以使所述运营商接入设备将所述第二业务报文发送给所述第一内网的 所述用户设备。
6、 根据权利要求 3所述的方法, 其特征在于, 所述内网地址请求消息和所 述内网地址响应消息中包含虚拟局域网 VLAN标识, 所述 VLAN标识与所述第 一内网相对应。
7、 一种 ΙΡ·¾文处理方法, 其特征在于, 包括:
运营商接入设备接收企业的第一内网中的用户设备发送的内网地址请求 消息;
所述运营商接入设备将所述内网地址请求消息发送给所述运营商业务网 关, 以使所述运营商业务网关为所述用户设备分配内网 IP地址。
8、 根据权利要求 7所述的方法, 其特征在于, 所述运营商接入设备将所述 内网地址请求消息发送给所述运营商业务网关之后, 还包括:
所述运营商接入设备接收所述运营商业务网关发送的包含所述内网 IP地 址的内网地址响应消息;
所述运营商接入设备将所述内网地址响应消息发送给所述用户设备。
9、 根据权利要求 8所述的方法, 其特征在于, 所述运营商接入设备将所述 内网地址请求消息发送给所述运营商业务网关之前, 还包括:
所述运营商接入设备在所述内网地址请求消息中添加 VLAN标识, 所述 VLAN标识与所述第一内网相对应;
所述运营商接入设备将所述内网地址响应消息发送给所述用户设备, 包 括:
所述运营商接入设备删除所述内网地址响应消息中包含的所述 VLAN标 识, 并将所述内网地址响应消息发送给与所述 VLAN标识对应的第一内网中的 用户设备。
10、 一种运营商业务网关, 其特征在于, 包括:
分配模块, 用于为企业的第一内网分配 IP地址; 处理模块, 用于根据所述 IP地址对所述第一内网与所述企业的第二内网之 间交互的业务 4艮文进行处理。
11、根据权利要求 10所述的运营商业务网关,其特征在于, 所述分配模块, 具体用于:
为所述第一内网分配公网 IP地址, 并釆用所述公网 IP地址与所述第二内网 对应的运营商业务网关或路由器进行 IP安全协议 IPSec协商;
为所述第一内网中的用户设备分配内网 IP地址, 所述内网 IP地址与所述公 网 IP地址具有对应关系。
12、根据权利要求 11所述的运营商业务网关,其特征在于, 所述分配模块, 还用于:
接收运营商接入设备转发的由所述用户设备发送的内网地址请求消息; 向所述运营商接入设备发送包含所述内网 IP地址的内网地址响应消息, 以 使所述运营商接入设备将所述内网 IP地址发送给所述用户设备。
13、 根据权利要求 11或 12所述的运营商业务网关, 其特征在于, 所述处理 模块, 具体用于:
接收运营商接入设备转发的由所述用户设备发送的第一业务报文, 所述第 一业务才艮文中包含所述内网 IP地址;
对所述第一业务报文进行 IPSec封装, IPSec封装后的第一业务报文中包含 所述公网 IP地址;
向与所述第二内网对应的运营商业务网关或路由器发送 IPSec封装后的第 一业务报文。
14、根据权利要求 13所述的运营商业务网关,其特征在于, 所述处理模块, 还用于:
向与所述第二内网对应的运营商业务网关或路由器发送 IPSec封装后的第 一业务报文之后,接收与所述第二内网对应的运营商业务网关或路由器发送的 包含所述第二内网的公网 IP地址的第二业务报文;
对所述第二业务报文进行 IPSec解封装;
向所述运营商接入设备发送 IPSec解封装后的第二业务报文, 以使所述运 营商接入设备将所述第二业务报文发送给所述第一内网的所述用户设备。
15、 根据权利要求 12所述的运营商业务网关, 其特征在于, 所述内网地址 请求消息和所述内网地址响应消息中包含虚拟局域网 VLAN标识, 所述 VLAN 标识与所述第一内网相对应。
16、 一种运营商接入设备, 其特征在于, 包括:
接收模块, 用于接收企业的第一内网中的用户设备发送的内网地址请求消 息;
发送模块, 用于将所述内网地址请求消息发送给所述运营商业务网关, 以 使所述运营商业务网关为所述用户设备分配内网 IP地址。
17、根据权利要求 16所述的运营商接入设备,其特征在于, 所述接收模块, 还用于在将所述内网地址请求消息发送给所述运营商业务网关之后,接收所述 所述发送模块, 还用于将所述内网地址响应消息发送给所述用户设备。
18、 根据权利要求 17所述的运营商接入设备, 其特征在于, 还包括: 处理模块, 用于在将所述内网地址请求消息发送给所述运营商业务网关之 前, 在所述内网地址请求消息中添加 VLAN标识 , 所述 VLAN标识与所述第一 内网相对应;
所述处理模块, 还用于删除所述内网地址响应消息中包含的所述 VLAN标 识;
所述发送模块, 具体用于将所述内网地址响应消息发送给与所述 VLAN标 识对应的第一内网中的用户设备。
19、 一种网络系统, 其特征在于, 包括如权利要求 10~15任一项所述的运 营商业务网关和如权利要求 16~18任一项所述的运营商接入设备。
PCT/CN2013/087051 2012-11-26 2013-11-13 Ip报文处理方法、装置及网络系统 Ceased WO2014079335A1 (zh)

Priority Applications (3)

Application Number Priority Date Filing Date Title
JP2015543279A JP6028269B2 (ja) 2012-11-26 2013-11-13 Ipパケット処理方法および装置、ならびにネットワークシステム
EP13857339.9A EP2916499B1 (en) 2012-11-26 2013-11-13 Ip packet processing method, apparatus and network system
US14/721,839 US10454880B2 (en) 2012-11-26 2015-05-26 IP packet processing method and apparatus, and network system

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201210486610.8 2012-11-26
CN201210486610.8A CN103840995B (zh) 2012-11-26 2012-11-26 Ip报文处理方法、装置及网络系统

Related Child Applications (1)

Application Number Title Priority Date Filing Date
US14/721,839 Continuation US10454880B2 (en) 2012-11-26 2015-05-26 IP packet processing method and apparatus, and network system

Publications (1)

Publication Number Publication Date
WO2014079335A1 true WO2014079335A1 (zh) 2014-05-30

Family

ID=50775531

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2013/087051 Ceased WO2014079335A1 (zh) 2012-11-26 2013-11-13 Ip报文处理方法、装置及网络系统

Country Status (6)

Country Link
US (1) US10454880B2 (zh)
EP (1) EP2916499B1 (zh)
JP (1) JP6028269B2 (zh)
KR (1) KR101650831B1 (zh)
CN (1) CN103840995B (zh)
WO (1) WO2014079335A1 (zh)

Cited By (8)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2016128213A1 (en) 2015-02-11 2016-08-18 Sony Corporation Communications device, infrastructure equipment, and methods
US10106574B2 (en) 2015-08-13 2018-10-23 Merck Sharp & Dohme Corp. Cyclic di-nucleotide compounds as sting agonists
US10414747B2 (en) 2016-10-04 2019-09-17 Merck Sharp & Dohme Corp. Benzo[b]thiophene compounds as sting agonists
EP3554136A1 (en) 2015-02-11 2019-10-16 Sony Corporation Communications device, infrastructure equipment, mobile communications network and methods
US10793557B2 (en) 2018-04-03 2020-10-06 Merck Sharp & Dohme Corp. Sting agonist compounds
US11285131B2 (en) 2017-08-04 2022-03-29 Merck Sharp & Dohme Corp. Benzo[b]thiophene STING agonists for cancer treatment
CN114882631A (zh) * 2022-06-06 2022-08-09 创斯达科技集团(中国)有限责任公司 一种自适应智能闸机网络配置方法及闸机系统
US11466047B2 (en) 2017-05-12 2022-10-11 Merck Sharp & Dohme Llc Cyclic di-nucleotide compounds as sting agonists

Families Citing this family (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN105337894B (zh) * 2014-06-24 2018-11-30 华为技术有限公司 一种为业务报文提供服务质量QoS的装置、系统和方法
CN109218157B (zh) * 2017-07-04 2020-10-09 大唐移动通信设备有限公司 一种虚拟专用网络系统的数据处理方法、装置和系统
CN110365557B (zh) * 2018-03-26 2021-11-02 中兴通讯股份有限公司 一种网络互连的方法及装置
CN114281352B (zh) * 2020-09-28 2025-03-21 京东方科技集团股份有限公司 服务部署方法及相关设备
CN112261176B (zh) * 2020-12-24 2021-04-02 金锐同创(北京)科技股份有限公司 一种网络实际访问关系的获取方法及相关设备

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20050232273A1 (en) * 2004-03-19 2005-10-20 Nec Personal Products, Ltd. Communications system and a gateway device
CN101119273A (zh) * 2007-09-10 2008-02-06 杭州华三通信技术有限公司 实现通用路由封装隧道穿越的方法及设备
CN101499965A (zh) * 2008-02-29 2009-08-05 沈建军 一种基于IPSec安全关联的网络报文路由转发和地址转换方法
CN101534329A (zh) * 2009-04-16 2009-09-16 华为技术有限公司 一种ip地址分配方法及系统
CN102055816A (zh) * 2010-12-28 2011-05-11 华为技术有限公司 一种通信方法、业务服务器、中间设备、终端及通信系统

Family Cites Families (34)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP3490358B2 (ja) * 1999-11-04 2004-01-26 日本電信電話株式会社 ネットワーク間通信方法およびサーバ装置並びにネットワーク間通信システム
JP2003152768A (ja) * 2001-11-13 2003-05-23 Ntt Comware Corp 端末接続仲介方法、端末接続仲介装置およびプログラム
KR100479261B1 (ko) * 2002-10-12 2005-03-31 한국전자통신연구원 네트워크 주소 변환 상에서의 데이터 전송 방법 및 장치
JP3668731B2 (ja) * 2002-10-29 2005-07-06 株式会社Crcソリューションズ 仮想プライベートネットワーク(vpn)システム及び中継ノード
US7366188B2 (en) 2003-01-21 2008-04-29 Samsung Electronics Co., Ltd. Gateway for supporting communications between network devices of different private networks
US20050066035A1 (en) * 2003-09-19 2005-03-24 Williams Aidan Michael Method and apparatus for connecting privately addressed networks
JP4053967B2 (ja) * 2003-11-20 2008-02-27 株式会社日立コミュニケーションテクノロジー Vlanサーバ
EP1709780A1 (en) * 2004-01-15 2006-10-11 Interactive People Unplugged AB Device to facilitate the deployment of mobile virtual private networks for medium/large corporate networks
JP2006020085A (ja) * 2004-07-01 2006-01-19 Fujitsu Ltd ネットワークシステム、ネットワークブリッジ装置、ネットワーク管理装置およびネットワークアドレス解決方法
JP2006129090A (ja) * 2004-10-28 2006-05-18 Sky Com:Kk 通信装置、通信管理装置、通信方法および通信制御プログラム
CN101138205B (zh) * 2005-03-04 2012-04-11 富士通株式会社 数据包中继装置
US7903671B2 (en) * 2005-08-04 2011-03-08 Cisco Technology, Inc. Service for NAT traversal using IPSEC
ATE426283T1 (de) * 2005-12-15 2009-04-15 Nokia Corp Verfahren, apparat und computerprogrammprodukt zur beibehaltung von abbildungszuordnungen
US20080089323A1 (en) * 2006-10-13 2008-04-17 At&T Knowledge Ventures, L.P. System and method for assigning virtual local area networks
CN101325759B (zh) * 2007-06-15 2012-06-27 华为技术有限公司 一种用户终端接入ims早期鉴权的方法及系统
JP2009278261A (ja) * 2008-05-13 2009-11-26 Toshiba Corp 情報処理装置および通信制御方法
US7792046B2 (en) * 2008-06-05 2010-09-07 Vss Monitoring, Inc. Ethernet switch-based network monitoring system and methods
CN101674566B (zh) * 2008-09-08 2012-04-25 华为技术有限公司 一种无线接入设备的位置定位与验证方法、系统及归属服务器
CN101442565A (zh) * 2008-12-18 2009-05-27 成都市华为赛门铁克科技有限公司 一种固定虚拟网络地址的分配方法和网关
CN102714651B (zh) * 2009-07-01 2015-11-25 太阳涡轮股份有限公司 第一计算机网络与至少一个第二扩展计算机网络连接方法
CN102549977B (zh) * 2009-09-24 2014-11-05 日本电气株式会社 虚拟服务器间通信识别系统和虚拟服务器间通信识别方法
US9036504B1 (en) * 2009-12-07 2015-05-19 Amazon Technologies, Inc. Using virtual networking devices and routing information to associate network addresses with computing nodes
US8910300B2 (en) * 2010-12-30 2014-12-09 Fon Wireless Limited Secure tunneling platform system and method
JP5711392B2 (ja) * 2011-02-01 2015-04-30 テレフオンアクチーボラゲット エル エム エリクソン(パブル) Pdn−gw内のnat/naptを伴うシナリオについてのpccサポートのための方法及び装置
CN102724648B (zh) * 2011-03-30 2018-03-20 中兴通讯股份有限公司 一种隧道信息更新的方法和系统
WO2011144067A2 (zh) 2011-05-24 2011-11-24 华为技术有限公司 处理报文的方法和装置
WO2012162994A1 (zh) * 2011-09-30 2012-12-06 华为技术有限公司 对数据报文进行策略控制的方法和装置
US8661146B2 (en) * 2011-10-13 2014-02-25 Cisco Technology, Inc. Systems and methods for IP reachability in a communications network
US9521145B2 (en) * 2011-10-17 2016-12-13 Mitel Mobility Inc. Methods and apparatuses to provide secure communication between an untrusted wireless access network and a trusted controlled network
US9549317B2 (en) * 2011-10-17 2017-01-17 Mitel Mobility Inc. Methods and apparatuses to provide secure communication between an untrusted wireless access network and a trusted controlled network
US8832264B2 (en) * 2012-03-01 2014-09-09 Justin Pauley Network appliance for monitoring network requests for multimedia content
US9563480B2 (en) * 2012-08-21 2017-02-07 Rackspace Us, Inc. Multi-level cloud computing system
US9049114B2 (en) * 2012-08-31 2015-06-02 Cisco Technology, Inc. Network access device and method for automatically establishing connection to a wide area network
US8953592B2 (en) * 2012-09-28 2015-02-10 Juniper Networks, Inc. Network address translation for application of subscriber-aware services

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20050232273A1 (en) * 2004-03-19 2005-10-20 Nec Personal Products, Ltd. Communications system and a gateway device
CN101119273A (zh) * 2007-09-10 2008-02-06 杭州华三通信技术有限公司 实现通用路由封装隧道穿越的方法及设备
CN101499965A (zh) * 2008-02-29 2009-08-05 沈建军 一种基于IPSec安全关联的网络报文路由转发和地址转换方法
CN101534329A (zh) * 2009-04-16 2009-09-16 华为技术有限公司 一种ip地址分配方法及系统
CN102055816A (zh) * 2010-12-28 2011-05-11 华为技术有限公司 一种通信方法、业务服务器、中间设备、终端及通信系统

Cited By (14)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP3554136A1 (en) 2015-02-11 2019-10-16 Sony Corporation Communications device, infrastructure equipment, mobile communications network and methods
EP3843437A1 (en) 2015-02-11 2021-06-30 Sony Corporation Communications device, infrastructure equipment, and methods
WO2016128213A1 (en) 2015-02-11 2016-08-18 Sony Corporation Communications device, infrastructure equipment, and methods
US10738074B2 (en) 2015-08-13 2020-08-11 Merck Sharp & Dohme Corp. Cyclic di-nucleotide compounds as STING agonists
US10759825B2 (en) 2015-08-13 2020-09-01 Merck Sharp & Dohme Corp. Cyclic di-nucleotide compounds as STING agonists
US10766919B2 (en) 2015-08-13 2020-09-08 Merck Sharp & Dohme Corp. Cyclic di-nucleotide compounds as sting agonists
US10106574B2 (en) 2015-08-13 2018-10-23 Merck Sharp & Dohme Corp. Cyclic di-nucleotide compounds as sting agonists
US10703738B2 (en) 2016-10-04 2020-07-07 Merck Sharp & Dohme Corp. Benzo[b]thiophene compounds as STING agonists
US10730849B2 (en) 2016-10-04 2020-08-04 Merck Sharp & Dohme Corp. Benzo[b]thiophene compounds as STING agonists
US10414747B2 (en) 2016-10-04 2019-09-17 Merck Sharp & Dohme Corp. Benzo[b]thiophene compounds as sting agonists
US11466047B2 (en) 2017-05-12 2022-10-11 Merck Sharp & Dohme Llc Cyclic di-nucleotide compounds as sting agonists
US11285131B2 (en) 2017-08-04 2022-03-29 Merck Sharp & Dohme Corp. Benzo[b]thiophene STING agonists for cancer treatment
US10793557B2 (en) 2018-04-03 2020-10-06 Merck Sharp & Dohme Corp. Sting agonist compounds
CN114882631A (zh) * 2022-06-06 2022-08-09 创斯达科技集团(中国)有限责任公司 一种自适应智能闸机网络配置方法及闸机系统

Also Published As

Publication number Publication date
CN103840995B (zh) 2017-10-24
CN103840995A (zh) 2014-06-04
US20150288651A1 (en) 2015-10-08
JP6028269B2 (ja) 2016-11-16
EP2916499A1 (en) 2015-09-09
JP2016503627A (ja) 2016-02-04
EP2916499B1 (en) 2020-01-08
KR101650831B1 (ko) 2016-09-05
EP2916499A4 (en) 2015-12-09
KR20150086529A (ko) 2015-07-28
US10454880B2 (en) 2019-10-22

Similar Documents

Publication Publication Date Title
WO2014079335A1 (zh) Ip报文处理方法、装置及网络系统
CN114374581B (zh) 企业虚拟专用网络(vpn)与虚拟私有云(vpc)粘连
CN107580065B (zh) 一种私有云接入方法及设备
US9231918B2 (en) Use of virtual network interfaces and a websocket based transport mechanism to realize secure node-to-site and site-to-site virtual private network solutions
CN103379010B (zh) 一种虚拟网络实现方法及系统
CN116800712A (zh) 虚拟私有云与云下数据中心通信、配置方法及相关装置
CN105978708B (zh) 基于NFV实现vCPE虚拟化企业网络的系统及方法
EP2760174A1 (en) Virtual private cloud access authentication method and related apparatus
JP6395867B2 (ja) OpenFlow通信方法及びシステム、制御部、並びにサービスゲートウェイ
CN107959654A (zh) 一种数据传输方法、装置及混合云系统
CN107948086A (zh) 一种数据包发送方法、装置及混合云网络系统
US20140301396A1 (en) Method for constructing virtual private network, method for packet forwarding, and gateway apparatus using the methods
WO2014075312A1 (zh) 一种网络穿越服务的提供方法、装置及系统
JP5679343B2 (ja) クラウドシステム、ゲートウェイ装置、通信制御方法、及び通信制御プログラム
WO2011103840A2 (zh) 虚拟私云的连接方法及隧道代理服务器
CN104243608B (zh) 一种通信方法、云管理服务器及虚拟交换机
WO2009143729A1 (zh) 实现dhcp用户业务批发的方法、系统和设备
US12047481B1 (en) Systems and methods for altering the character of network traffic
CN105323229A (zh) 一种基于cpe的数据传输方法、网元、平台及系统
CN103051535A (zh) 一种数据接入方法、装置及数据接入系统
CN108259466B (zh) DDoS流量回注方法、SDN控制器及网络系统
WO2011113357A1 (zh) 路由映射的处理方法及运营商边界设备
CN107659930A (zh) 一种ap接入控制方法和装置
CN117527556A (zh) 多云平台间数据互通的方法、装置、电子设备及介质
CN103684968A (zh) 接入网的部署方法、终端设备、网络核心设备及系统

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 13857339

Country of ref document: EP

Kind code of ref document: A1

ENP Entry into the national phase

Ref document number: 2015543279

Country of ref document: JP

Kind code of ref document: A

NENP Non-entry into the national phase

Ref country code: DE

WWE Wipo information: entry into national phase

Ref document number: 2013857339

Country of ref document: EP

ENP Entry into the national phase

Ref document number: 20157016293

Country of ref document: KR

Kind code of ref document: A