[go: up one dir, main page]

CN106533883B - A kind of method for building up, the apparatus and system of network special line - Google Patents

A kind of method for building up, the apparatus and system of network special line Download PDF

Info

Publication number
CN106533883B
CN106533883B CN201611035277.3A CN201611035277A CN106533883B CN 106533883 B CN106533883 B CN 106533883B CN 201611035277 A CN201611035277 A CN 201611035277A CN 106533883 B CN106533883 B CN 106533883B
Authority
CN
China
Prior art keywords
cpe
vcpe
information
requesting
network
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Active
Application number
CN201611035277.3A
Other languages
Chinese (zh)
Other versions
CN106533883A (en
Inventor
李洪峰
赫罡
王瑾
霍龙社
高功应
马田丰
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
China United Network Communications Group Co Ltd
Original Assignee
China United Network Communications Group Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by China United Network Communications Group Co Ltd filed Critical China United Network Communications Group Co Ltd
Priority to CN201611035277.3A priority Critical patent/CN106533883B/en
Publication of CN106533883A publication Critical patent/CN106533883A/en
Application granted granted Critical
Publication of CN106533883B publication Critical patent/CN106533883B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L12/00Data switching networks
    • H04L12/28Data switching networks characterised by path configuration, e.g. LAN [Local Area Networks] or WAN [Wide Area Networks]
    • H04L12/46Interconnection of networks
    • H04L12/4641Virtual LANs, VLANs, e.g. virtual private networks [VPN]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L12/00Data switching networks
    • H04L12/28Data switching networks characterised by path configuration, e.g. LAN [Local Area Networks] or WAN [Wide Area Networks]
    • H04L12/46Interconnection of networks
    • H04L12/4633Interconnection of networks using encapsulation techniques, e.g. tunneling

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Security & Cryptography (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

本发明实施例提供了一种网络专线的建立方法、装置及系统,涉及网络通信技术领域,用以提供一种操作复杂度低的网络专线建立方法,包括在确定目标客户的网络专线业务开通时,接收第一策略信息;获取满足目标客户的网络专线的需求信息的虚拟客户终端设备vCPE的IP地址;接收所述至少两个CPE中任意一个请求CPE发送的建立连接请求消息;根据所述建立连接请求消息,获取第一vCPE的标识以及第一虚拟可扩展局域网VxLAN的配置,将第一vCPE的标识发送给每个对端CPE对应的vCPE,以及将第一VxLAN的配置发送给请求CPE和第一vCPE,最终实现目标客户的网络专线的点到点连通。

Embodiments of the present invention provide a method, device, and system for establishing a dedicated network line, which relate to the technical field of network communications, and are used to provide a method for establishing a dedicated network line with low operational complexity, including when determining that a target customer's dedicated network service is activated. , receive the first policy information; obtain the IP address of the virtual customer terminal equipment vCPE that meets the demand information of the network private line of the target customer; receive a connection establishment request message sent by any one of the at least two CPEs requesting the CPE to send; A connection request message, obtains the identifier of the first vCPE and the configuration of the first virtual extensible local area network VxLAN, sends the identifier of the first vCPE to the vCPE corresponding to each peer CPE, and sends the configuration of the first VxLAN to the requesting CPE and The first vCPE finally realizes the point-to-point connection of the target customer's dedicated network.

Description

A kind of method for building up, the apparatus and system of network special line
Technical field
The present embodiments relate to network communication technology field more particularly to a kind of method for building up, the devices of network special line And system.
Background technique
Network special line is (for example, point-to-point (Point to Point Protocol over Ethernet, PPPoE) is special Line) refer to and establishes dedicated network in the public network, data are propagated in the public network by " encrypted tunnel " of safety, network Individual line subscriber (for example, mechanism of enterprise, various regions) only needs to rent local network special line, the Internet of local in connection The network individual line subscriber of (internet), various regions can transmit mutually information.
In the prior art, net is usually realized by VLAN (Virtual Local Area Network, virtual LAN) The networking of network special line, it is often necessary to the user for establishing network special line proposes after opening network special line application to network operator, Network operator carries out service fulfillment to the demand information that the live user for establishing network special line as needed proposes, and passes through The mode of VLAN realizes point-to-point private line access, and VLAN uses two-layer VPN, and what is walked based on MAC Address is that two layers of transmission are logical There are a variety of IP networks and mainly walk double layer network if the mode based on VLAN is transmitted in road, still, access net, need to do very Two layers of special line are directly established in more static routing configuration, and it is more complicated to be related to across districts and cities meetings, therefore, are deposited in the deployment of IP network In certain difficulty, and CPE gateway is mainly ACS (Automatic Configuration Server, Automatic Configuration Server) It is managed by TR069 agreement, the work such as all configurations relevant to user equipment, diagnosis, upgrading is by unified pipe Server A CS is managed to complete.
The bandwidth of existing network special line be it is fixed, cannot generally modify, when user needs to update network strategy or net When network bandwidth, firstly, user needs to file a request to operator, then operator is according to the pipes of the request more new operators of user The original network strategy or network bandwidth of the user, relative complex in reason system, but the need of bandwidth that each enterprise uses It asks not identical, may wish to big bandwidth in short-term when the backup of the management system of operator, this transient demand is existing Network be it is very inappeasable, therefore, there is certain limitation on network adaptability, when the configuration for needing to update ACS, and need Increase more time and human cost, flexibility is poor.
Summary of the invention
The embodiment of the present invention provides method for building up, the apparatus and system of a kind of network special line, establishes network to reduce Operation complexity when special line.
In order to achieve the above objectives, the embodiment of the present invention adopts the following technical scheme that
In a first aspect, the embodiment of the present invention provides a kind of method for building up of network special line, comprising: determining user's Caytoniales When marking the network private line service of client, the first policy information is received;First policy information, which is used to indicate, establishes target customer's Network special line;Wherein, the network special line of target customer includes at least two customer terminal equipment CPE;It receives at least two CPE What any one request CPE was sent establishes connection request message;Wherein, this is established connection request message and is used to indicate foundation request Interface channel in CPE and at least one opposite end CPE between each opposite end CPE;According to connection request message is established, obtains and meet The mark of first vCPE of the demand information of the network special line of the target customer and the first virtual expansible local area network VxLAN Configuration;The configuration of the mark of first vCPE and the first VxLAN are sent to the request CPE and each opposite end The corresponding vCPE of CPE.
A kind of method for building up of network special line provided in an embodiment of the present invention is determining that user is open-minded by SDN controller When the network private line service of target customer, the first policy information is received;First policy information, which is used to indicate, establishes target customer Network special line;Wherein, the network special line of target customer includes at least two customer terminal equipment CPE;SDN controller receive to What any one request CPE was sent in few two CPE establishes connection request message;Wherein, this is established connection request message and is used for It indicates to establish the interface channel in request CPE and at least one opposite end CPE between each opposite end CPE;SDN controller is according to foundation Connection request message obtains the mark of the first vCPE and the configuration of the first virtual expansible local area network VxLAN;Wherein, first VCPE is the vCPE for meeting the demand information of network special line of target customer;The mark of first vCPE is sent to by SDN controller The corresponding vCPE of each opposite end CPE, and the configuration of the first VxLAN is sent to request CPE and the first vCPE, the present invention can be real The plug and play of existing cpe device, it is automatic open-minded, reduce human cost;It introduces SDN controller and increases special line flexibility, it can be with It is tactful quickly to modify product bandwidth and QoS etc. for centralized control;Cpe device only needs to have basic function, and additional function is by vCPE It realizes, cpe device cost and the cost of manual maintenance can be reduced.
With reference to first aspect, in the first possible implementation of the first aspect, side provided in an embodiment of the present invention Method further include: receive target service configuration information, carry target requirement information in the target service configuration information, which needs Ask information for being updated to the network special line of target customer;Target service configuration information is parsed, generation strategy is matched Confidence breath;The strategy configuration information is used to indicate request CPE and each opposite end CPE and is updated to its existing configuration information; To request CPE, the corresponding vCPE of request CPE, the corresponding vCPE sending strategy configuration information of each opposite end CPE, so as to call request Its existing configuration information update is tactful configuration information by CPE and each opposite end CPE, and the CPE that makes to call request corresponding VCPE and the corresponding vCPE of each opposite end CPE reformulate the plan for meeting target requirement information according to tactful configuration information Slightly.
With reference to first aspect or the first possible implementation of first aspect, second in first aspect are possible In implementation, before the network private line service for determining target customer is opened, the method provided in the embodiment of the present invention includes: The first authentication request message of the identification information for carrying the first CPE of the first CPE transmission is received, the first CPE is institute State any one at least two CPE;If it is determined that the identification information of the first CPE carried in the first authentication request message and pre- If the information matches in database, then the first certification instruction message is sent to the first CPE, and show service fulfillment prompting message, The first certification instruction message is used to indicate the first CPE and authenticates successfully, and whether which is used for prompt Open the network private line service of target customer;If it is determined that receiving the first instruction message, it is determined that the network special line of target customer Service fulfillment.
Any one possible implementation with reference to first aspect or in second of possible implementation of first aspect, In a third possible implementation of the first aspect, it is sent by the configuration of the mark of the first vCPE and the first VxLAN After the corresponding vCPE of opposite end CPE each in request CPE and at least one opposite end CPE, side provided in an embodiment of the present invention Method further include: if it is determined that the corresponding vCPE of request CPE vCPE phase corresponding with the first opposite end CPE in the CPE of at least one opposite end Together, then the request CPE being used to indicate to request CPE transmission, message to be sent is directly sent to the first opposite end CPE's Second indication information;If it is determined that the corresponding vCPE of request CPE is corresponding with the first opposite end CPE in the CPE of at least one opposite end VCPE is not identical, then is used to indicate the request CPE to request CPE transmission and the message to be sent is sent to request CPE's VCPE, so that the message to be sent is transmitted to the corresponding vCPE's of the first opposite end CPE by the vCPE of the request CPE Third indicates information.
The third possible implementation with reference to first aspect, in the 4th kind of possible implementation of first aspect In, it requests in the vCPE and at least one opposite end CPE of CPE between the corresponding vCPE of each opposite end CPE through VxLAN or GRE Tunnel is communicated.
Second aspect, what the embodiment of the present invention provided a kind of network special line establishes device, comprising: the first receiving unit is used In when determining that user opens the network private line service of target customer, reception is used to indicate the network special line for establishing target customer First policy information;The network special line of the target customer includes at least two customer terminal equipment CPE;Second receiving unit is used What any one request CPE was sent at least two CPE of reception establishes connection request message, this establishes connection request message use The interface channel in request CPE and at least one opposite end CPE between each opposite end CPE is established in instruction;Selecting unit is used for root According to connection request message is established, the mark of the first vCPE and the configuration of the first virtual expansible local area network VxLAN are obtained;Its In, the first vCPE is the vCPE for meeting the demand information of network special line of the target customer;First transmission unit, for by the The mark of one vCPE is sent to the corresponding vCPE of each opposite end CPE, and by the configuration of the first VxLAN be sent to request CPE and First vCPE.
In conjunction with the first possible implementation of second aspect, in second of possible implementation of second aspect In, the device in the embodiment of the present invention further include: third receiving unit, the target service that reception carries target requirement information are matched Confidence breath, the target requirement information is for being updated the network special line of the target customer;Resolution unit, for target Service configuration information is parsed, generation strategy configuration information;The strategy configuration information is used to indicate request CPE and each opposite end CPE is updated its existing configuration information;Second transmission unit is used for request CPE, requests the corresponding vCPE of CPE, every The corresponding vCPE sending strategy configuration information of a opposite end CPE, so that the request CPE and each opposite end CPE are had Configuration information update be tactful configuration information, and the corresponding vCPE of CPE and each opposite end CPE that makes to call request corresponding VCPE reformulates the strategy for meeting target requirement information according to the tactful configuration information.
In conjunction with the possible implementation of the first of second aspect or second aspect, second in second aspect is possible In implementation, device provided in an embodiment of the present invention further include: the 4th receiving unit, for receiving taking for the first CPE transmission First authentication request message of the identification information with the first CPE, the first CPE are appointing at least two CPE Meaning one;First judging unit, the identification information and present count of the first CPE for judging to carry in the first authentication request message Whether matched according to the information in library;Third transmission unit is taken for determining in the first authentication request message in the first judging unit When information matches in the identification information and presetting database of the first CPE of band, the first certification instruction is sent to the first CPE and is disappeared Breath, and show service fulfillment prompting message, which is used to indicate the first CPE and authenticates successfully, which opens Logical prompting message is used to prompt whether to open the network private line service of target customer;Determination unit, for receiving the determining When one instruction message, determine that the network private line service of target customer is open-minded.
In second of possible implementation in conjunction with second aspect to second aspect, the third in second aspect may Implementation in, device provided in an embodiment of the present invention further include: second judgment unit, for judge request CPE it is corresponding Whether vCPE vCPE corresponding with the first opposite end CPE in the CPE of at least one opposite end be identical;4th transmission unit, for the Two judging units determine the corresponding vCPE of the first opposite end CPE in the corresponding vCPE and at least one opposite end CPE of request CPE When identical, sent to request CPE and be used to indicate the second finger that message to be sent is directly sent to the first opposite end CPE by request CPE Show information;5th transmission unit, for determining the corresponding vCPE and at least one opposite end CPE of request CPE in second judgment unit In the corresponding vCPE of the first opposite end CPE it is not identical when, to request CPE transmission be used to indicate the request CPE will be described pending Text of delivering newspaper is sent to the vCPE of request CPE, so that the message to be sent is transmitted to described the by the vCPE of the request CPE The third of the corresponding vCPE of a pair of end CPE indicates information.
In conjunction with the third possible implementation of second aspect, in the 4th kind of possible implementation of second aspect In, it requests in the vCPE and at least one opposite end CPE of CPE between the corresponding vCPE of each opposite end CPE through VxLAN or GRE Tunnel is communicated.
The third aspect, what the embodiment of the present invention provided a kind of network special line establishes system, comprising: network layer, arranging service Layer and control layer;Operation has VNFM (Virtual Network Function Management, virtual net on control layer Network function management unit) and as any one is possible into the 5th kind of possible implementation of second aspect for second aspect Network special line establishes device described in implementation;Operation has request CPE in network layer, corresponding with request CPE VCPE, at least one opposite end CPE and the corresponding vCPE of each opposite end CPE;Wherein, arranging service layer, for receiving user's hair The first business request information sent carries the demand letter for opening the network special line of target customer in first business request information Breath, and for generating the first plan for meeting the demand information of network special line of target customer according to first business request information Slightly information, and device and VNFM are established for what the first policy information was sent to network special line, first policy information In including at least two CPE identification information and the target customer network special line demand information;VNFM is used for The first policy information is received, and establishes the network special line for meeting target customer in data center according to first policy information The vCPE of demand information;Network special line establishes device, for establishing the request CPE in network layer according to the first policy information Interface channel between vCPE corresponding with request CPE is established in the corresponding vCPE and at least one opposite end CPE of request CPE Channel between the corresponding vCPE of each opposite end CPE;And establish each opposite end CPE and institute in the CPE of at least one opposite end The channel between the corresponding vCPE of opposite end CPE is stated, and sends control instructions information to network layer, control instructions information is for referring to Show that the request CPE sends message each opposite end CPE at least one opposite end CPE;Network layer refers to for receiving control Show information, and according to the control instructions information, message is sent to each opposite end in the CPE of at least one opposite end from request CPE CPE。
In conjunction with the third aspect, in the first possible implementation of the third aspect, arranging service layer is also used to, and is received The second business request information that 2nd CPE is sent, the second business request information are used to indicate the network special line for updating target customer, And for generating target service configuration information according to the second business request information;And target service configuration information is sent to The network special line establishes device, and the 2nd CPE is any one at least two CPE.
In conjunction with the first possible implementation of the third aspect, in second of possible implementation of the third aspect In, arranging service layer is also used to generate the first authentication url request message, first certification chain according to the first business request information It connects request message and is used to indicate the certification completed to the 2nd CPE.
In conjunction with the first possible implementation of the third aspect or second of possible implementation of the third aspect, In the third possible implementation of the third aspect, control instructions information is second indication information, then requests CPE directly will report Text is sent to each opposite end CPE in the CPE of at least one opposite end;The control instructions information is that third indicates information, then requests The message is transmitted to the vCPE of the opposite end CPE by CPE by the vCPE of request CPE, so that the vCPE of the opposite end CPE After the message is carried out decapsulation and encapsulated again, it is transmitted to the opposite end CPE.
In conjunction with the third aspect to the third aspect the third possible implementation in any one possible implementation, In the fourth possible implementation of the third aspect, VNFM is also used to: receiving the target service configuration information;According to mesh Mark service configuration information, however, it is determined that there is no the target service configuration information resources of virtual machine is met, then according to the target Service configuration information establishes the first resources of virtual machine, and the first resources of virtual machine is meet the target service configuration information virtual Machine resource.
Detailed description of the invention
Fig. 1 is a kind of structural schematic diagram one for establishing system of network special line provided in an embodiment of the present invention;
Fig. 2 is a kind of flow diagram one of network special line method for building up provided in an embodiment of the present invention;
Fig. 3 is a kind of flow diagram two of network special line method for building up provided in an embodiment of the present invention;
Fig. 4 is the structural schematic diagram that a kind of network special line provided in an embodiment of the present invention establishes device;
Fig. 5 is a kind of structural schematic diagram two for establishing system of network special line provided in an embodiment of the present invention.
Specific embodiment
For the ease of clearly describing the technical solution of the embodiment of the present invention, in an embodiment of the present invention, use " the One ", the printed words such as " second ", " third " distinguish function and the essentially identical identical entry of effect or similar item, this field skill Art personnel are understood that the printed words such as " first ", " second ", " third " are not defined quantity and execution order.
The method for building up of network special line provided in an embodiment of the present invention can be applied to the establishing in system of network special line, such as Shown in Fig. 1, the system of establishing of the network special line includes: that arranging service layer 10, network special line establish device 20 and network layer 30, wherein the device 20 of establishing of network special line includes SND (Software Defined Networking, software defined network) Controller 201 and VNFM (Virtualised Network Function Manager, the network function module pipe of virtualization Manage device) 202.
Wherein, arranging service layer 10 can carry out policy distribution and the management of business, can be to 201 He of SDN controller VNFM202 is managed collectively.For example, arranging service layer 10 and Operation Support System (Operations Support System, OSS)/business support system (Business support system, BSS) docking, pass through for receiving user The first business request information and the second business request information that OSS/BSS is sent.
VNFM202 is the functional module of the network function module life cycle management for being virtualized.
Network layer 30 includes at least two CPE (Customer Premise Equipment, customer terminal equipment) (as schemed CPEA301 and CPEB303 shown in 1) and data center, wherein data center includes one or more VCPE, the VCPE It is established by VNFM according to the first policy information, wherein there are at least one to request CPE and opposite end at least two CPE CPE, request CPE and opposite end CPE be it is opposite, when message from CPEA301 to CPEB303 send when, CPEA301 be request CPE, CPEB303 is the opposite end CPE of CPEA301;When message is sent from CPEB303 to CPEA301, CPEB303 is request CPE, CPEA301 be opposite end CPE, when between CPEB303 and CPEA301 network special line establish after, message can from CPEB303 to CPEA301 is sent, and can also be sent from CPEA301 to CPEB303.
CPE uses general X86-based in the embodiment of the present invention, has basic routing function, supports DHCP, VxLAN tunnel Road is established and the functions such as ipsec encryption, and vCPE carries out Virtual Private Line foundation under the management of SDN controller, supports QoS (Quality of Service, service quality), the functions such as ACL (Access Control List, accesses control list), net Network special line establish SDN controller 301 in device 20 it is equal in network layer 30 each CPE (for example, CPEA301 and The centralized management control of the equipment such as the vCPE CPEB303) and in data center, VNFM202 are responsible for the foundation and deletion of virtual machine.
Specifically, a kind of method for building up of network special line is provided in conjunction with Fig. 1 embodiment of the present invention, as shown in Fig. 2, this method Include:
S301, SDN controller receive the first strategy letter when determining that user opens the network private line service of target customer Breath;First policy information is used to indicate the network special line for establishing target customer;Wherein, the network special line of target customer includes extremely Few two customer terminal equipment CPE;
What any one request CPE was sent at least two CPE of S302, SDN controller reception establishes connection request message; Wherein, this is established connection request message and is used to indicate in foundation request CPE and at least one opposite end CPE between each opposite end CPE Interface channel;
According to connection request message is established, the mark and first for obtaining the first vCPE can virtually expand S303, SDN controller Open up the configuration of local area network VxLAN;Wherein, the first vCPE is the vCPE for meeting the demand information of network special line of target customer;
The mark of first vCPE is sent to the corresponding vCPE of each opposite end CPE by S304, SDN controller, and by first The configuration of VxLAN is sent to request CPE and the first vCPE.
A kind of method for building up of network special line provided in an embodiment of the present invention is determining that user is open-minded by SDN controller When the network private line service of target customer, the first policy information is received;First policy information, which is used to indicate, establishes target customer Network special line;Wherein, the network special line of target customer includes at least two customer terminal equipment CPE;SDN controller receive to What any one request CPE was sent in few two CPE establishes connection request message;Wherein, this is established connection request message and is used for It indicates to establish the interface channel in request CPE and at least one opposite end CPE between each opposite end CPE;SDN controller is according to foundation Connection request message obtains the mark of the first vCPE and the configuration of the first virtual expansible local area network VxLAN;Wherein, first VCPE is the vCPE for meeting the demand information of network special line of target customer;SDN controller is by the mark of the first vCPE and The configuration of one VxLAN is sent to the request CPE and corresponding vCPE of each opposite end CPE, and what cpe device can be achieved in the present invention is Plug-and-play, it is automatic open-minded, reduce human cost;It introduces SDN controller and increases special line flexibility, it can be with centralized control, quickly It is tactful to modify product bandwidth and QoS etc.;Cpe device only needs to have basic function, and additional function is realized by vCPE, can reduce Cpe device cost and the cost of manual maintenance.
Specifically, the first policy information in the embodiment of the present invention includes the demand information of the network special line of target customer, The demand information of the network special line of target customer can be QoS (Quality of Service, Service Quality in the embodiment of the present invention Amount) information, for example, bandwidth required for target user, the information such as priority.
Wherein, request CPE can establish connection request message to the transmission of SND controller by openflow agreement.
Specifically, the embodiment of the present invention is to the identification information of above-mentioned CPE without restriction, the identification information use of each CPE In the unique identification CPE, illustratively, which can be MAC (the Medium Access of any one CPE Control, media access control protocol) address;Or the product identification code of the CPE.
VCPE is located at data center, and IP address is relatively fixed, so SDN controller meeting retrieved beforehand knows the IP of vCPE Address (or static addition), when receive that request CPE sends establishes connection request message, SDN controller can obtain CPE IP address, VxLAN establish element include information, the SDN controllers such as interface name, VNI (mark), far-end IP can be according to foundation Connection request message creates VxLAN, and distributes a VNI, and issue configuration message, informs its opposite end CPE and vCPE IP respectively The information such as address and VNI, to establish the first VxLAN.
Illustratively, the mark of the first vCPE in the embodiment of the present invention can be the IP address of the first vCPE.
As long as VxLAN IP is up to can transmit in the embodiment of the present invention, as long as knowing in the starting point of VxLAN and clearing end The mutual interface in road, IP address and VNI can establish the tunnel VxLAN, and the VxLAN of different sections is that previous VxLAN removes UDP Behind packet header, as starting point, the tunnel VxLAN is re-established with next clearing end, VNI can change can also be constant, therefore Property associated with each other is little, therefore carries out the IP management between the IP management and domain of same area, is not necessarily intended to know the IP address of the whole network.
Wherein, the network special line of target customer refers to the communication channel of linking objective Client Enterprise branch, so that target It can be communicated, should be included at least each positioned at the target customer by the communication channel between the enterprise branch of client CPE at enterprise branch.For example, the enterprise branch of target customer is located at different districts and cities, then the network of the target customer is special The enterprise branch that line will also be located at different address is connected by specific communication channel, so that being located at different districts and cities Enterprise branch can be communicated by the communication channel.Illustratively, if the enterprise branch of a target customer is located at Then a CPE should be arranged at the enterprise branch in Xi'an in Beijing and Xi'an, and the enterprise branch at Beijing should also be set A CPE is set, the network special line of the target customer in this way, which also refers to, will be located at the CPE of Xi'an bifurcation and be located at Beijing bifurcation CPE connected by communication channel.
It can be from the vCPE of data center's acquisition the first policy information of satisfaction, the data center in specific step S302 Including at least one vCPE.Wherein, vCPE can be had more powerful processing function, can be used based on server with better function In the forward process of mass data.VCPE in the data center is what VNFM was established according to the first policy information.
In order to facilitate the business change request etc. to the bandwidth of target network special line or QoS required for it of user voluntarily It changes, method provided in an embodiment of the present invention further include:
S305, target service configuration information is received, carries target requirement information in the target service configuration information, the mesh Mark demand information is for being updated the network special line of target customer;
Wherein, above-mentioned target service configuration information is sent by arranging service layer.
S306, target service configuration information is parsed, generation strategy configuration information;The strategy configuration information is for referring to Show that request CPE and each opposite end CPE is updated its existing configuration information;
S307, match confidence to request CPE, the corresponding vCPE of request CPE, the corresponding vCPE sending strategy of each opposite end CPE Breath so that its existing configuration information update is tactful configuration information by the CPE and each opposite end CPE that calls request, and makes Request CPE corresponding vCPE and the corresponding vCPE of each opposite end CPE are reformulated according to tactful configuration information and are met the mesh Mark the strategy of demand information.
The change to target network special line can be thus achieved in S306-S307 to the embodiment of the present invention through the above steps, thus Improve the operating efficiency for establishing network special line.
The embodiment of the present invention is before step S301 further include:
S308, the first authentication request message that the first CPE is sent is received, is carried in first authentication request message State the identification information of the first CPE;First CPE is any one at least two CPE;
S309, if it is determined that the first CPE carried in first authentication request message identification information and present count According to the information matches in library, then the first certification instruction message is sent to the first CPE, and show service fulfillment prompting message, The first certification instruction message is used to indicate the first CPE and authenticates successfully, and the service fulfillment prompting message is for prompting Whether the network private line service of target customer is opened;
S310, if it is determined that receiving the first instruction message, it is determined that the network private line service of the target customer is open-minded.
Specifically, arranging service layer buys demand information when product business according to user after user buys product business Corresponding policy information is generated, SDN controller and VNFM are sent to, and generates First Certificate message and is sent to user.
Wherein, which can generate in the form of a link, while be sent to user's in the form of mail The mailbox registered when buying product business is sent to user in the form of short message and buys the mobile phone registered when product business Number after user takes cpe device, accesses LAN mouthfuls by WAN mouthfuls of access networks, then with equipment such as PCs, cpe device meeting It addresses the Dynamic Host Configuration Protocol server of default and distributes to one IP address of cpe device after Dynamic Host Configuration Protocol server certification.User logs in browser, The authentication informations such as the MAC Address of cpe device are reported to SDN controller, SDN controller and database ratio by input authentication link It after errorless, sent to cpe device and authenticates successful message, if it is not, sending the message of authentification failure.Cpe device is recognized After demonstrate,proving successfully, the prompt for opening private line service whether at once can be jumped to, if SDN controller receives the first of user's transmission Instruction message, it is determined that target network special line is opened in user's agreement, then opens target network special line immediately.
Illustratively, which can be that target network is opened in " agreement " being shown on PC webpage Special line and " disagreeing " open the printed words of target network special line, for example, " YES " or " NO " printed words, the embodiment of the present invention is to this Without limiting.
After step S304, method provided in an embodiment of the present invention further include:
S311, if it is determined that the first opposite end CPE in the corresponding vCPE and at least one opposite end CPE of the request CPE Corresponding vCPE is identical, then sends second indication information to the request CPE, and the second indication information is used to indicate described ask Ask CPE that message to be sent is directly sent to the first opposite end CPE;
S314, if it is determined that the first opposite end CPE in the corresponding vCPE and at least one opposite end CPE of the request CPE Corresponding vCPE is not identical, then sends third to the request CPE and indicate that information, the third instruction information are used to indicate described The message to be sent is sent to the vCPE of request CPE by request CPE, so that the vCPE of the request CPE will be described pending Text of delivering newspaper is transmitted to the corresponding vCPE of the first opposite end CPE.
Specifically, requesting CPE pairs of each opposite end in the vCPE and at least one opposite end CPE of CPE in the embodiment of the present invention It is communicated between the vCPE answered by VxLAN or gre tunneling.
As shown in figure 3, illustrating a kind of network special line provided in an embodiment of the present invention below by another specific embodiment Method for building up.
Order when S401, arranging service layer buy service product according to user generates the network special line for meeting target customer Demand information the first policy information and generate the first authentication url request message, wherein first authentication url request Message is used to indicate the certification completed to CPE;
Wherein, SDN controller IP address and relevant policy information are carried in the first authentication url request message.
S402, the first policy information is sent to SDN controller and VNFM, and by the first authentication url request message The mailing address registered when being sent to user's transacting business.
S403, SDN controller receive user by above-mentioned first certification connection request message transmission comprising request CPE's First authentication request message of identification information;
Whether S404, SDN controller judge to store in the identification information and presetting database of request CPE consistent;
S405, SDN controller determine stored in the identification information and presetting database of request CPE it is consistent, then to asking It asks CPE to send the first certification instruction message, and shows service fulfillment prompting message, which is used to indicate the One CPE is authenticated successfully, which is used to prompt whether to open the network private line service of target customer;
Wherein, which is shown in user's checking first in the form of the page and authenticates connection request message Window in.
S406, SDN controller determine stored in the identification information and presetting database of request CPE it is inconsistent, then to CPE is requested to send authentification failure message;
After sending authentification failure message, it can carry in the authentification failure message in the embodiment of the present invention and request again The message that user authenticates cpe device.After user's confirmation no longer authenticates cpe device, this certification is terminated.
S407, VNFM establish the need for meeting the network special line of the target customer according to the first policy information in data center Seek the vCPE of information;
For S408, SDN controller after receiving the first instruction message, SDN controller then determines that user opens target visitor The network private line service at family, and the demand for meeting the network special line of target customer is obtained from data center according to the first policy information The IP address of the virtual client terminal device vCPE of information;
What any one request CPE was sent at least two CPE of S409, SDN controller reception establishes connection request message; Wherein, the identification information that at least one opposite end CPE is carried in connection request message is established;
Illustratively, target customer's network special line includes positioned at the CPE in Xi'an and positioned at Pekinese CPE, then target is objective Family network special line namely establish the CPE in Xi'an and the network special line between Pekinese CPE, if then request CPE be positioned at What the CPE in Xi'an was sent, then the identification information positioned at Pekinese CPE should be carried by establishing in connection request message.
Specifically, each cpe device in target network special line should access and establish target in the actual operation process In the network specified when network special line.,
S410, SDN controller can virtually expand according to the mark and first that establish the link the first vCPE of request message acquisition Open up the configuration of local area network VxLAN;Wherein, the first vCPE is the demand information for meeting the network special line of the target customer vCPE;
The mark of first vCPE is sent to the corresponding vCPE of each opposite end CPE by S411, SDN controller, and by first The configuration of VxLAN is sent to the request CPE and the first vCPE.
As shown in figure 4, the embodiment of the present invention a kind of network special line is provided establish device, comprising:
First receiving unit 501, for receiving the first plan when determining that user opens the network private line service of target customer Slightly information;First policy information is used to indicate the network special line for establishing target customer;Wherein, the network special line of the target customer Including at least two customer terminal equipment CPE;
Second receiving unit 502 is asked for receiving the connection of establishing that any one request CPE is sent at least two CPE Seek message, this establish connection request message be used to indicate foundation request CPE and at least one opposite end CPE in each opposite end CPE it Between interface channel;
Selecting unit 503, for according to connection request message is established, the mark and first for obtaining the first vCPE virtually may be used Extend the configuration of local area network VxLAN;Wherein, the first vCPE is the vCPE for meeting the demand information of network special line of target customer;
First transmission unit 504, for the mark of the first vCPE to be sent to the corresponding vCPE of each opposite end CPE, and The configuration of first VxLAN is sent to request CPE and the first vCPE.
Optionally, device provided in an embodiment of the present invention further include:
Third receiving unit receives target service configuration information, carries target requirement in the target service configuration information Information, the target requirement information is for being updated the network special line of target customer;
Resolution unit, for being parsed to target service configuration information, generation strategy configuration information;The strategy configuration Information be used to indicate in the request CPE and at least one opposite end CPE each opposite end CPE to its existing configuration information into Row updates;
Second transmission unit, for being sent out to request CPE, the corresponding vCPE of request CPE, the corresponding vCPE of each opposite end CPE Tactful configuration information is sent, so that its existing configuration information update is strategy configuration by the CPE and each opposite end CPE that calls request Information, and the corresponding vCPE of the CPE and corresponding vCPE of each opposite end CPE that makes to call request make again according to tactful configuration information Surely meet the strategy of target requirement information.
Optionally, device provided in an embodiment of the present invention further include:
4th receiving unit, for receiving the first authentication request message of the first CPE transmission, first authentication request message In carry the identification information of the first CPE;First CPE is any one at least two CPE;
First judging unit, the identification information of the first CPE for judging to carry in the first authentication request message and default Whether the information in database matches;
Third transmission unit, for determining the first CPE's carried in the first authentication request message in the first judging unit When information matches in identification information and presetting database, the first certification instruction message is sent to the first CPE, and show that business is opened Logical prompting message, the first certification instruction message are used to indicate the first CPE and authenticate successfully, which uses The network private line service of target customer whether is opened in prompt;
Determination unit, for determining the network special line industry of the target customer when determination receives the first instruction message It is engaged in open-minded.
Optionally, shown device further include:
Second judgment unit requests the first opposite end in CPE corresponding vCPE and at least one opposite end CPE for judging Whether the corresponding vCPE of CPE is identical;
4th transmission unit, for determining the corresponding vCPE and at least one opposite end CPE of request CPE in second judgment unit In the corresponding vCPE of the first opposite end CPE it is identical when, send second indication information to request CPE, which is used for Message to be sent is directly sent to the first opposite end CPE by instruction request CPE;
5th transmission unit, for determining the corresponding vCPE and at least one opposite end CPE of request CPE in second judgment unit In the corresponding vCPE of the first opposite end CPE it is not identical when, to request CPE send third indicate information, the third indicate information use Message to be sent is sent to the vCPE of request CPE in instruction request CPE, so that the vCPE for the CPE that calls request is by message to be sent It is transmitted to the corresponding vCPE of the first opposite end CPE.
Optionally, it requests to lead between the corresponding vCPE of each opposite end CPE in the vCPE and at least one opposite end CPE of CPE It crosses VxLAN or gre tunneling is communicated.
As shown in figure 5, the embodiment of the present invention, which provides a kind of network special line, establishes system, including arranging service layer, control layer And network layer.
Wherein, the arranging service layer, for the first business request information of reception, and for according to the first service request Message generates the first policy information for meeting the demand information of network special line of target customer, and by first policy information Be sent to the network special line establishes device and the VNFM, includes described at least two in first policy information The demand information of the identification information of CPE and the network special line of the target customer;Wherein, it is carried in the first business request information There is the demand information for the network special line for opening target customer;
VNFM meets institute in data center's foundation for receiving first policy information, and according to the first policy information State the vCPE of the demand information of the network special line of target customer;
Network special line establishes device (namely SDN controller), for establishing in network layer according to the first policy information The interface channel between CPE and vCPE corresponding with request CPE is requested, it is right at least one to establish the corresponding vCPE of request CPE Hold the channel in CPE between the corresponding vCPE of each opposite end CPE;And establish each opposite end in the CPE of at least one opposite end Channel between CPE vCPE corresponding with the opposite end CPE, and control instructions information, control instructions letter are sent to network layer Breath is used to indicate the request CPE and sends message each opposite end CPE at least one opposite end CPE;
Network layer, for receiving control instructions information, and according to control instructions information, by message from the request CPE It is sent to each opposite end CPE at least one opposite end CPE.
Optionally, arranging service layer is also used to, and receives the second business request information that the 2nd CPE is sent, second industry Business request message is used to indicate the network special line for updating the target customer, and for according to second business request information Generate target service configuration information;And device is established by what the target service configuration information was sent to the network special line, 2nd CPE is any one at least two CPE.
Optionally, arranging service layer is also used to generate the request of the first authentication url according to first business request information Message, the first authentication url request message are used to indicate the certification completed to the 2nd CPE.
Optionally, control instructions information is second indication information, then the message is directly sent to institute by the request CPE State each opposite end CPE in the CPE of at least one opposite end;
The control instructions information is that third indicates information, then the message is passed through the request CPE by the request CPE VCPE be transmitted to the vCPE of the opposite end CPE so that the vCPE of the opposite end CPE carries out decapsulation and again to the message After encapsulation, it is transmitted to the opposite end CPE.
Optionally, VNFM is also used to:
Receive the target service configuration information;
According to the target service configuration information, however, it is determined that there is no meet the target service configuration information virtual machine money Source, then establish the first resources of virtual machine according to the target service configuration information, and first resources of virtual machine is described in satisfaction The resources of virtual machine of target service configuration information.
In several embodiments provided herein, it should be understood that disclosed system, device and method can be with It realizes by another way.For example, the apparatus embodiments described above are merely exemplary, for example, the unit It divides, only a kind of logical function partition, there may be another division manner in actual implementation, such as multiple units or components It can be combined or can be integrated into another system, or some features can be ignored or not executed.Another point, it is shown or The mutual coupling, direct-coupling or communication connection discussed can be through some interfaces, the indirect coupling of device or unit It closes or communicates to connect, can be electrical property, mechanical or other forms.
The unit as illustrated by the separation member may or may not be physically separated, aobvious as unit The component shown may or may not be physical unit, it can and it is in one place, or may be distributed over multiple In network unit.It can select some or all of unit therein according to the actual needs to realize the mesh of this embodiment scheme 's.
It, can also be in addition, the functional units in various embodiments of the present invention may be integrated into one processing unit It is that the independent physics of each unit includes, can also be integrated in one unit with two or more units.Above-mentioned integrated list Member both can take the form of hardware realization, can also realize in the form of hardware adds SFU software functional unit.
The above-mentioned integrated unit being realized in the form of SFU software functional unit can store and computer-readable deposit at one In storage media.Above-mentioned SFU software functional unit is stored in a storage medium, including some instructions are used so that a computer Equipment (can be personal computer, server or the network equipment etc.) executes the portion of each embodiment the method for the present invention Step by step.And storage medium above-mentioned includes: USB flash disk, mobile hard disk, read-only memory (Read-Only Memory, abbreviation ROM), random access memory (Random Access Memory, abbreviation RAM), magnetic or disk etc. are various can store The medium of program code.
Finally, it should be noted that the above embodiments are merely illustrative of the technical solutions of the present invention, rather than its limitations;Although Present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that: it still may be used To modify the technical solutions described in the foregoing embodiments or equivalent replacement of some of the technical features; And these are modified or replaceed, technical solution of various embodiments of the present invention that it does not separate the essence of the corresponding technical solution spirit and Range.

Claims (13)

1.一种网络专线的建立方法,其特征在于,包括:1. a method for establishing a dedicated network line, comprising: 在确定用户开通目标客户的网络专线业务时,接收第一策略信息;所述第一策略信息用于指示建立目标客户的网络专线;其中,所述目标客户的网络专线包括至少两个客户终端设备CPE;When it is determined that the user activates the network private line service of the target customer, first policy information is received; the first policy information is used to instruct the establishment of the target customer's network private line; wherein, the target customer's network private line includes at least two client terminal devices CPE; 接收所述至少两个CPE中任意一个请求CPE发送的建立连接请求消息;其中,所述建立连接请求消息用于指示建立所述请求CPE和至少一个对端CPE中每个对端CPE之间的连接通道;Receive a connection establishment request message sent by any one of the at least two CPEs requesting the CPE; wherein, the connection establishment request message is used to indicate the establishment of a connection between the requesting CPE and each of the at least one opposite-end CPE. connection channel; 根据所述建立连接请求消息,获取第一vCPE的标识以及第一虚拟可扩展局域网VxLAN的配置;其中,所述第一vCPE为满足所述目标客户的网络专线的需求信息的vCPE;Obtain the identifier of the first vCPE and the configuration of the first virtual extensible local area network VxLAN according to the connection establishment request message; wherein, the first vCPE is a vCPE that satisfies the demand information of the network dedicated line of the target customer; 将所述第一vCPE的标识发送给所述每个对端CPE对应的vCPE,以及将所述第一VxLAN的配置发送给所述请求CPE和所述第一vCPE。The identifier of the first vCPE is sent to the vCPE corresponding to each peer CPE, and the configuration of the first VxLAN is sent to the requesting CPE and the first vCPE. 2.根据权利要求1所述的方法,其特征在于,在所述将所述第一vCPE的标识以及所述第一VxLAN的配置发送给所述请求CPE、以及所述至少一个对端CPE中每个对端CPE对应的vCPE之后,所述方法还包括:2. The method according to claim 1, wherein in the sending the identifier of the first vCPE and the configuration of the first VxLAN to the requesting CPE and the at least one peer CPE After the vCPE corresponding to each peer CPE, the method further includes: 接收目标业务配置信息,所述目标业务配置信息中携带有目标需求信息,所述目标需求信息用于对所述目标客户的网络专线进行更新;receiving target service configuration information, where the target service configuration information carries target demand information, and the target demand information is used to update the network dedicated line of the target customer; 对所述目标业务配置信息进行解析,生成策略配置信息;所述策略配置信息用于指示所述请求CPE及所述每个对端CPE对其已有的配置信息进行更新;Parsing the target service configuration information to generate policy configuration information; the policy configuration information is used to instruct the requesting CPE and each peer CPE to update its existing configuration information; 向所述请求CPE、所述请求CPE对应的vCPE、所述每个对端CPE对应的vCPE发送所述策略配置信息,以使得所述请求CPE、以及所述每个对端CPE将其已有的配置信息更新为所述策略配置信息,以及使得所述请求CPE对应的vCPE以及所述每个对端CPE对应的vCPE根据所述策略配置信息重新制定满足所述目标需求信息的策略。Send the policy configuration information to the requesting CPE, the vCPE corresponding to the requesting CPE, and the vCPE corresponding to each peer CPE, so that the requesting CPE and each peer CPE use the existing The configuration information of the CPE is updated to the policy configuration information, and the vCPE corresponding to the requesting CPE and the vCPE corresponding to each peer CPE can re-formulate a policy that meets the target requirement information according to the policy configuration information. 3.根据权利要求1或2所述的方法,其特征在于,所述确定目标客户的网络专线业务开通之前,所述方法包括:3. The method according to claim 1 or 2, characterized in that, before the network private line service of the determined target customer is activated, the method comprises: 接收第一CPE发送的第一认证请求消息,所述第一认证请求消息中携带有所述第一CPE的标识信息;所述第一CPE为所述至少两个CPE中的任意一个;receiving a first authentication request message sent by a first CPE, where the first authentication request message carries the identification information of the first CPE; the first CPE is any one of the at least two CPEs; 若确定所述第一认证请求消息中携带的所述第一CPE的标识信息与预设数据库中的信息匹配,则向所述第一CPE发送第一认证指示消息,并展示业务开通提示消息,所述第一认证指示消息用于指示所述第一CPE认证成功,所述业务开通提示消息用于提示是否开通目标客户的网络专线业务;If it is determined that the identification information of the first CPE carried in the first authentication request message matches the information in the preset database, a first authentication indication message is sent to the first CPE, and a service activation prompt message is displayed, The first authentication indication message is used to indicate that the first CPE is authenticated successfully, and the service activation prompt message is used to prompt whether to activate the network private line service of the target customer; 若确定接收到第一指示消息,则确定所述目标客户的网络专线业务开通。If it is determined that the first indication message is received, it is determined that the network dedicated line service of the target customer is activated. 4.根据权利要求1或2所述的方法,其特征在于,在所述将所述第一vCPE的标识以及所述第一VxLAN的配置发送给所述请求CPE、以及所述至少一个对端CPE中每个对端CPE对应的vCPE之后,所述方法还包括:4. The method according to claim 1 or 2, wherein, in the process of sending the identifier of the first vCPE and the configuration of the first VxLAN to the requesting CPE and the at least one peer After the vCPE corresponding to each peer CPE in the CPE, the method further includes: 若确定所述请求CPE对应的vCPE和所述至少一个对端CPE中的第一对端CPE对应的vCPE相同,则向所述请求CPE发送第二指示信息,所述第二指示信息用于指示所述请求CPE直接将待发送报文发送给所述第一对端CPE;If it is determined that the vCPE corresponding to the requesting CPE is the same as the vCPE corresponding to the first peer CPE in the at least one peer CPE, second indication information is sent to the requesting CPE, where the second indication information is used to indicate The requesting CPE directly sends the to-be-sent message to the first peer CPE; 若确定所述请求CPE对应的vCPE和所述至少一个对端CPE中的第一对端CPE对应的vCPE不相同,则向所述请求CPE发送第三指示信息,所述第三指示信息用于指示所述请求CPE将所述待发送报文发送给请求CPE的vCPE,以使得所述请求CPE的vCPE将所述待发送报文传递到所述第一对端CPE对应的vCPE。If it is determined that the vCPE corresponding to the requesting CPE is different from the vCPE corresponding to the first peer CPE in the at least one peer CPE, third indication information is sent to the requesting CPE, and the third indication information is used for Instructing the requesting CPE to send the message to be sent to the vCPE requesting the CPE, so that the vCPE requesting the CPE delivers the message to be sent to the vCPE corresponding to the first peer CPE. 5.根据权利要求4所述的方法,其特征在于,所述请求CPE的vCPE和至少一个对端CPE的中每个对端CPE对应的vCPE之间通过VxLAN或GRE隧道进行通信。5 . The method according to claim 4 , wherein the vCPE requesting the CPE and the vCPE corresponding to each of the at least one peer CPE communicate through a VxLAN or a GRE tunnel. 6 . 6.一种网络专线的建立装置,其特征在于,包括:6. A device for establishing a dedicated network line, comprising: 第一接收单元,用于在确定用户开通目标客户的网络专线业务时,接收第一策略信息;所述第一策略信息用于指示建立目标客户的网络专线;其中,所述目标客户的网络专线包括至少两个客户终端设备CPE;a first receiving unit, configured to receive first policy information when it is determined that the user activates the network dedicated line service of the target customer; the first policy information is used to instruct the establishment of the dedicated network line of the target customer; wherein, the dedicated network line of the target customer Including at least two customer terminal equipment CPE; 第二接收单元,用于接收所述至少两个CPE中任意一个请求CPE发送的建立连接请求消息,所述建立连接请求消息用于指示建立所述请求CPE和至少一个对端CPE中每个对端CPE之间的连接通道;The second receiving unit is configured to receive a connection establishment request message sent by any one of the at least two CPEs requesting the CPE, where the connection establishment request message is used to indicate the establishment of each pair of the requesting CPE and the at least one opposite-end CPE. Connection channel between end CPEs; 选择单元,用于根据所述建立连接请求消息,获取第一vCPE的标识以及第一虚拟可扩展局域网VxLAN的配置;其中,所述第一vCPE为满足所述目标客户的网络专线的需求信息的vCPE;A selection unit, configured to obtain the identifier of the first vCPE and the configuration of the first virtual extensible local area network VxLAN according to the connection establishment request message; wherein, the first vCPE is the one that meets the demand information of the network dedicated line of the target customer vCPE; 第一发送单元,用于将所述第一vCPE的标识发送给所述每个对端CPE对应的vCPE,以及将所述第一VxLAN的配置发送给所述请求CPE和所述第一vCPE。A first sending unit, configured to send the identifier of the first vCPE to the vCPE corresponding to each peer CPE, and send the configuration of the first VxLAN to the requesting CPE and the first vCPE. 7.根据权利要求6所述的装置,其特征在于,所述装置还包括:7. The apparatus of claim 6, wherein the apparatus further comprises: 第三接收单元,接收目标业务配置信息,所述目标业务配置信息中携带有目标需求信息,所述目标需求信息用于对所述目标客户的网络专线进行更新;a third receiving unit, receiving target service configuration information, where the target service configuration information carries target demand information, and the target demand information is used to update the network dedicated line of the target customer; 解析单元,用于对所述目标业务配置信息进行解析,生成策略配置信息;所述策略配置信息用于指示所述请求CPE及所述每个对端CPE对其已有的配置信息进行更新;a parsing unit, configured to parse the target service configuration information to generate policy configuration information; the policy configuration information is used to instruct the requesting CPE and each peer CPE to update its existing configuration information; 第二发送单元,用于向所述请求CPE、所述请求CPE对应的vCPE、所述每个对端CPE对应的vCPE发送所述策略配置信息,以使得所述请求CPE、以及所述每个对端CPE将其已有的配置信息更新为所述策略配置信息,以及使得所述请求CPE对应的vCPE以及所述每个对端CPE对应的vCPE根据所述策略配置信息重新制定满足所述目标需求信息的策略。a second sending unit, configured to send the policy configuration information to the requesting CPE, the vCPE corresponding to the requesting CPE, and the vCPE corresponding to each peer CPE, so that the requesting CPE and each The peer CPE updates its existing configuration information to the policy configuration information, and causes the vCPE corresponding to the requesting CPE and the vCPE corresponding to each peer CPE to re-formulate according to the policy configuration information to meet the target strategy for requesting information. 8.根据权利要求6或7所述的装置,其特征在于,所述装置还包括:8. The device according to claim 6 or 7, wherein the device further comprises: 第四接收单元,用于接收第一CPE发送的第一认证请求消息,所述第一认证请求消息中携带有所述第一CPE的标识信息;所述第一CPE为所述至少两个CPE中的任意一个;a fourth receiving unit, configured to receive a first authentication request message sent by a first CPE, where the first authentication request message carries identification information of the first CPE; the first CPE is the at least two CPEs any one of; 第一判断单元,用于判断所述第一认证请求消息中携带的所述第一CPE的标识信息与预设数据库中的信息是否匹配;a first judging unit, configured to judge whether the identification information of the first CPE carried in the first authentication request message matches the information in the preset database; 第三发送单元,用于在所述第一判断单元确定所述第一认证请求消息中携带的所述第一CPE的标识信息与预设数据库中的信息匹配时,向所述第一CPE发送第一认证指示消息,并展示业务开通提示消息,所述第一认证指示消息用于指示所述第一CPE认证成功,所述业务开通提示消息用于提示是否开通目标客户的网络专线业务;a third sending unit, configured to send to the first CPE when the first judgment unit determines that the identification information of the first CPE carried in the first authentication request message matches the information in the preset database a first authentication instruction message, and a service activation prompt message is displayed, the first authentication instruction message is used to indicate that the first CPE authentication is successful, and the service activation prompt message is used to prompt whether to activate the network private line service of the target customer; 确定单元,用于在确定接收到第一指示消息时,确定所述目标客户的网络专线业务开通。The determining unit is configured to determine, when determining that the first indication message is received, to determine that the network dedicated line service of the target customer is activated. 9.根据权利要求6或7所述的装置,其特征在于,所述装置还包括:9. The device according to claim 6 or 7, wherein the device further comprises: 第二判断单元,用于判断所述请求CPE对应的vCPE和所述至少一个对端CPE中的第一对端CPE对应的vCPE是否相同;a second judgment unit, configured to judge whether the vCPE corresponding to the request CPE and the vCPE corresponding to the first opposite CPE in the at least one opposite CPE are the same; 第四发送单元,用于在所述第二判断单元确定所述请求CPE对应的vCPE和所述至少一个对端CPE中的第一对端CPE对应的vCPE相同时,向所述请求CPE发送第二指示信息,所述第二指示信息用于指示所述请求CPE直接将待发送报文发送给所述第一对端CPE;The fourth sending unit is configured to send the first sending unit to the requesting CPE when the second judging unit determines that the vCPE corresponding to the requesting CPE is the same as the vCPE corresponding to the first opposite CPE in the at least one opposite CPE. Two indication information, where the second indication information is used to instruct the requesting CPE to directly send the to-be-sent message to the first peer CPE; 第五发送单元,用于在所述第二判断单元确定所述请求CPE对应的vCPE和所述至少一个对端CPE中的第一对端CPE对应的vCPE不相同时,向所述请求CPE发送第三指示信息,所述第三指示信息用于指示所述请求CPE将所述待发送报文发送给请求CPE的vCPE,以使得所述请求CPE的vCPE将所述待发送报文传递到所述第一对端CPE对应的vCPE。a fifth sending unit, configured to send the requesting CPE to the requesting CPE when the second judging unit determines that the vCPE corresponding to the requesting CPE is different from the vCPE corresponding to the first opposite CPE in the at least one opposite CPE third indication information, where the third indication information is used to instruct the requesting CPE to send the message to be sent to the vCPE requesting the CPE, so that the vCPE requesting the CPE delivers the message to be sent to the Describe the vCPE corresponding to the first peer CPE. 10.一种网络专线的建立系统,其特征在于,包括:网络层、业务编排层以及控制层;10. A system for establishing a dedicated network line, comprising: a network layer, a service orchestration layer and a control layer; 所述控制层上运行有如权利要求6-9任意一项所述的网络专线的建立装置以及VNFM;The device for establishing a dedicated network line and the VNFM according to any one of claims 6-9 run on the control layer; 所述网络层上运行有请求CPE,与请求CPE对应的vCPE,至少一个对端CPE以及每个所述对端CPE对应的vCPE;The network layer runs a request CPE, a vCPE corresponding to the request CPE, at least one peer CPE, and a vCPE corresponding to each peer CPE; 其中,所述业务编排层,用于接收第一业务请求消息,以及用于根据第一业务请求消息生成满足目标客户的网络专线的需求信息的第一策略信息,以及用于将所述第一策略信息发送给所述网络专线的建立装置以及所述VNFM,所述第一策略信息用于指示建立目标客户的网络专线;其中,所述第一业务请求消息中携带有开通目标客户的网络专线的需求信息;Wherein, the service orchestration layer is used to receive a first service request message, and used to generate, according to the first service request message, first policy information that satisfies the demand information of the network dedicated line of the target customer, and is used to convert the first service request message. The policy information is sent to the device for establishing a dedicated network line and the VNFM, and the first policy information is used to instruct the establishment of a dedicated network line for the target customer; wherein, the first service request message carries the opening of the dedicated network line for the target customer needs information; 所述VNFM,用于接收所述第一策略信息,以及根据所述第一策略信息在数据中心建立满足所述目标客户的网络专线的需求信息的vCPE;the VNFM, configured to receive the first policy information, and establish a vCPE in the data center that meets the demand information of the network dedicated line of the target customer according to the first policy information; 所述网络专线的建立装置,用于根据所述第一策略信息,建立所述网络层中的请求CPE和与所述请求CPE对应的vCPE之间的连接通道,建立所述请求CPE对应的vCPE与所述至少一个对端CPE中每个对端CPE对应的vCPE之间的通道;以及建立所述至少一个对端CPE中每个所述对端CPE与所述对端CPE对应的vCPE之间的通道,以及向所述网络层发送控制指示信息,所述控制指示信息用于指示所述请求CPE发送报文至所述至少一个对端CPE中每个对端CPE;The device for establishing a dedicated network line is configured to, according to the first policy information, establish a connection channel between the requesting CPE in the network layer and the vCPE corresponding to the requesting CPE, and establish the vCPE corresponding to the requesting CPE and establishing a channel between each of the at least one peer CPE and the vCPE corresponding to each peer CPE in the at least one peer CPE and the vCPE corresponding to the peer CPE channel, and send control indication information to the network layer, where the control indication information is used to instruct the requesting CPE to send a message to each peer CPE in the at least one peer CPE; 所述网络层,用于接收所述控制指示信息,以及根据所述控制指示信息,将所述报文从所述请求CPE发送至所述至少一个对端CPE中每个对端CPE。The network layer is configured to receive the control indication information, and send the message from the requesting CPE to each of the at least one opposite CPE according to the control indication information. 11.根据权利要求10所述的系统,其特征在于,11. The system of claim 10, wherein 所述业务编排层还用于,接收第二CPE发送的第二业务请求消息,所述第二业务请求消息用于指示更新所述目标客户的网络专线,以及用于根据所述第二业务请求消息生成目标业务配置信息,以及用于将所述目标业务配置信息发送给所述网络专线的建立装置以及所述VNFM,所述第二CPE为所述至少两个CPE中的任意一个。The service orchestration layer is further configured to receive a second service request message sent by the second CPE, where the second service request message is used to instruct to update the dedicated network line of the target customer, and is used to request a network according to the second service request The message generates target service configuration information, and is used for sending the target service configuration information to the network dedicated line establishment device and the VNFM, and the second CPE is any one of the at least two CPEs. 12.根据权利要求10或11所述的系统,其特征在于,所述控制指示信息为第二指示信息,则所述请求CPE直接将所述报文发送给所述至少一个对端CPE中每个所述对端CPE;12. The system according to claim 10 or 11, wherein the control indication information is the second indication information, and the requesting CPE directly sends the message to each of the at least one peer CPE. the peer CPEs; 所述控制指示信息为第三指示信息,则所述请求CPE将所述报文通过所述请求CPE的vCPE传递到所述对端CPE的vCPE,以使得所述对端CPE的vCPE对所述报文进行解封装和再封装之后,传给所述对端CPE。The control indication information is the third indication information, then the requesting CPE transmits the message to the vCPE of the opposite end CPE through the vCPE of the requesting CPE, so that the vCPE of the opposite end CPE is aware of the After the packet is decapsulated and re-encapsulated, it is transmitted to the peer CPE. 13.根据权利要求10或11所述的系统,其特征在于,所述VNFM还用于:13. The system according to claim 10 or 11, wherein the VNFM is further used for: 接收所述目标业务配置信息;receiving the target service configuration information; 根据所述目标业务配置信息,若确定不存在满足所述目标业务配置信息虚拟机资源,则根据所述目标业务配置信息建立第一虚拟机资源,所述第一虚拟机资源为满足所述目标业务配置信息的虚拟机资源。According to the target service configuration information, if it is determined that there is no virtual machine resource that satisfies the target service configuration information, a first virtual machine resource is established according to the target service configuration information, and the first virtual machine resource is to satisfy the target service configuration information. Virtual machine resources for business configuration information.
CN201611035277.3A 2016-11-16 2016-11-16 A kind of method for building up, the apparatus and system of network special line Active CN106533883B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201611035277.3A CN106533883B (en) 2016-11-16 2016-11-16 A kind of method for building up, the apparatus and system of network special line

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201611035277.3A CN106533883B (en) 2016-11-16 2016-11-16 A kind of method for building up, the apparatus and system of network special line

Publications (2)

Publication Number Publication Date
CN106533883A CN106533883A (en) 2017-03-22
CN106533883B true CN106533883B (en) 2019-05-28

Family

ID=58356347

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201611035277.3A Active CN106533883B (en) 2016-11-16 2016-11-16 A kind of method for building up, the apparatus and system of network special line

Country Status (1)

Country Link
CN (1) CN106533883B (en)

Families Citing this family (22)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN109428751A (en) * 2017-08-29 2019-03-05 中兴通讯股份有限公司 A kind of method and device of SDN management network access equipment
CN107786636A (en) * 2017-09-26 2018-03-09 平安科技(深圳)有限公司 Private line network building method and system
CN109962831B (en) * 2017-12-14 2021-08-17 中国电信股份有限公司 Virtual client terminal device, router, storage medium, and communication method
CN108092893B (en) * 2017-12-20 2020-12-08 中国联合网络通信集团有限公司 Method and device for opening a dedicated line
CN108306807B (en) * 2018-02-28 2021-04-27 新华三技术有限公司 Account opening management method and device
CN108964985B (en) * 2018-06-14 2020-07-28 烽火通信科技股份有限公司 Method for managing virtual client terminal equipment using protocol message
CN108650144A (en) * 2018-08-27 2018-10-12 郑州云海信息技术有限公司 A kind of management method and device of Virtual NE
CN109218099A (en) * 2018-09-20 2019-01-15 犀思云(苏州)云计算有限公司 A kind of cloud exchange network platform based on SDN/NFV
CN110971626B (en) * 2018-09-28 2024-01-19 贵州白山云科技股份有限公司 Enterprise branch office access request processing method, device and system
CN111106991B (en) * 2018-10-29 2022-05-06 中国移动通信集团浙江有限公司 Cloud special line system and service issuing and opening method thereof
CN109194578B (en) * 2018-10-29 2020-12-15 中国联合网络通信集团有限公司 Method and device for opening a private line service
CN109462537B (en) * 2018-12-04 2021-04-30 中国联合网络通信集团有限公司 Cross-network intercommunication method and device
CN111092930B (en) * 2019-11-15 2021-03-16 中盈优创资讯科技有限公司 Service opening method and device
CN112866048B (en) * 2019-11-28 2023-04-28 中盈优创资讯科技有限公司 Detection method and device for special line of Internet of things
CN111163499B (en) * 2019-11-29 2022-01-04 联通物联网有限责任公司 Access method, device, electronic equipment and storage medium
CN112995007B (en) * 2019-12-18 2022-04-15 中国移动通信集团陕西有限公司 Cloud private line connection method and system
CN113068083B (en) * 2020-01-02 2022-07-29 中国移动通信有限公司研究院 A method, apparatus, device and computer-readable storage medium for establishing a connection
CN111277481B (en) * 2020-01-09 2021-09-24 奇安信科技集团股份有限公司 A method, apparatus, device and storage medium for establishing a VPN tunnel
CN111741512B (en) * 2020-06-02 2022-08-12 中国联合网络通信集团有限公司 A kind of private network access method and device
CN112203172B (en) * 2020-10-09 2022-11-01 中国联合网络通信集团有限公司 Method and device for opening a dedicated line
CN114500260B (en) * 2022-01-07 2022-11-08 广东云下汇金科技有限公司 Method, equipment and medium for building two-layer virtual private line network
CN115633014B (en) * 2022-10-21 2025-06-10 成都西加云杉科技有限公司 Networking method based on vCPE and related components

Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN105323229A (en) * 2014-07-31 2016-02-10 中国移动通信集团公司 CPE-based data transmission method, network element, platform and system
CN105978708A (en) * 2016-04-27 2016-09-28 赛特斯信息科技股份有限公司 System of realizing vCPE virtualization enterprise network based on NFV and method thereof

Family Cites Families (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US10110710B2 (en) * 2014-04-03 2018-10-23 Centurylink Intellectual Property Llc System and method for implementing extension of customer LAN at provider network service point

Patent Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN105323229A (en) * 2014-07-31 2016-02-10 中国移动通信集团公司 CPE-based data transmission method, network element, platform and system
CN105978708A (en) * 2016-04-27 2016-09-28 赛特斯信息科技股份有限公司 System of realizing vCPE virtualization enterprise network based on NFV and method thereof

Also Published As

Publication number Publication date
CN106533883A (en) 2017-03-22

Similar Documents

Publication Publication Date Title
CN106533883B (en) A kind of method for building up, the apparatus and system of network special line
US9137105B2 (en) Method and system for deploying at least one virtual network on the fly and on demand
EP3425945B1 (en) Methods and apparatus for a self-organized layer-2 enterprise network architecture
CN103580980B (en) The method and device thereof that virtual network finds and automatically configures automatically
US9264403B2 (en) Virtualization platform
CN104506670B (en) Establish method, equipment and the system of network game connection
US10454880B2 (en) IP packet processing method and apparatus, and network system
CN103685026A (en) Virtual network access method and system
CN112422397B (en) Service forwarding method and communication device
CN110290093A (en) The SD-WAN network architecture and network-building method, message forwarding method
CN112804112B (en) A method for multi-cloud access in SD-WAN network environment
WO2019178756A1 (en) Sd-wan system, use method of sd-wan system, and related apparatus
CN108063761B (en) Network processing method, cloud platform and software-defined network SDN controller
CN103166909B (en) The cut-in method of a kind of Virtual Networking System, device and system
CN112866077A (en) Large-scale automatic networking method, management system, equipment and storage medium for modality fusion
CN107770012A (en) A kind of broad band access method, device and virtual broadband RAS system
CN108390774A (en) A kind of wide area network network-building method and system based on software definition
WO2018039901A1 (en) Method, device and system for ip address allocation, and computer program product
CN107659930A (en) A kind of AP connection control methods and device
CN105208072B (en) The long-range control method and device of virtual switch
CN112671811B (en) Network access method and equipment
CN106357443B (en) A kind of method and apparatus of network configuration
WO2016065920A1 (en) Method and system for providing virtual network service
CN114884771B (en) Identity network construction method, device and system based on zero trust concept
CN107566476B (en) Access method, SDN controller, forwarding equipment and user access system

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination
GR01 Patent grant
GR01 Patent grant