CN102186168A - Private network access method, device and system - Google Patents
Private network access method, device and system Download PDFInfo
- Publication number
- CN102186168A CN102186168A CN201110119748XA CN201110119748A CN102186168A CN 102186168 A CN102186168 A CN 102186168A CN 201110119748X A CN201110119748X A CN 201110119748XA CN 201110119748 A CN201110119748 A CN 201110119748A CN 102186168 A CN102186168 A CN 102186168A
- Authority
- CN
- China
- Prior art keywords
- router
- network
- couple
- client
- private network
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Granted
Links
- 238000000034 method Methods 0.000 title claims abstract description 39
- 230000005540 biological transmission Effects 0.000 claims abstract description 8
- 238000004891 communication Methods 0.000 abstract description 23
- 230000005641 tunneling Effects 0.000 abstract description 4
- 238000010586 diagram Methods 0.000 description 10
- 238000005516 engineering process Methods 0.000 description 4
- 238000005538 encapsulation Methods 0.000 description 2
- 230000007774 longterm Effects 0.000 description 2
- 238000013507 mapping Methods 0.000 description 2
- 238000012986 modification Methods 0.000 description 2
- 230000004048 modification Effects 0.000 description 2
- 239000013307 optical fiber Substances 0.000 description 2
- 230000001360 synchronised effect Effects 0.000 description 2
- 238000012423 maintenance Methods 0.000 description 1
- 238000010295 mobile communication Methods 0.000 description 1
- 230000006855 networking Effects 0.000 description 1
- 230000003287 optical effect Effects 0.000 description 1
- 238000012545 processing Methods 0.000 description 1
Images
Landscapes
- Mobile Radio Communication Systems (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
Abstract
Description
技术领域technical field
本发明涉及通信技术,尤其涉及一种专用网接入方法、装置和系统。The present invention relates to communication technology, in particular to a dedicated network access method, device and system.
背景技术Background technique
目前,固网数据业务中,面向企业提供的国际专线以及多协议标签交换(Multi-Protocol Label Switching,MPLS)虚拟专用网(Virtual Private Network,VPN)组网服务,即专用网,通常是以同步数字体系(Synchronous Digital Hierarchy,SDH)、数字数据网(Digital Data Network,DDN)、以太专线等方式作为客户端的接入方式。然而,客户处于成本考虑,通常会租用一条接入电路作为专线电路,而不会同时租用两条物理隔离的专线电路,因此,在专线电路出现故障时,客户端的接入节点将无法正常连接到专用网,导致客户无法正常访问专用网。At present, in the fixed network data business, the international leased line and multi-protocol label switching (Multi-Protocol Label Switching, MPLS) virtual private network (Virtual Private Network, VPN) networking service provided for enterprises, that is, the private network, is usually based on a synchronous Digital system (Synchronous Digital Hierarchy, SDH), digital data network (Digital Data Network, DDN), Ethernet leased line and other methods are used as the access method of the client. However, due to cost considerations, customers usually rent one access circuit as a leased line circuit instead of renting two physically isolated leased line circuits at the same time. Therefore, when the leased line circuit fails, the access node of the client cannot be connected to the Private network, causing customers to be unable to access the private network normally.
随着无线网络的普及,现有技术也提出了一种通过无线网络接入专用网的无线接入方式,作为专线电路的备份,以便在专线电路故障时,可通过无线接入方式接入到专线网的接入节点,确保客户可正常访问专线网。现有基于无线接入方式实现MPLS VPN应用中,是通过因特网协议安全性(IPsec)网关的模式实现的,具体地,在客户端的接入路由器与专用网的接入路由器之间的专线电路故障时,客户端的接入路由器可接入到无线网络中,并通过IPsec网关接入到公网中,从而通过无线网络和公网,在客户端和专用网之间建立连接,使得客户端可正常访问专用网。With the popularization of wireless networks, the existing technology also proposes a wireless access method to access the private network through the wireless network, as a backup of the dedicated line circuit, so that when the dedicated line circuit fails, it can be accessed through the wireless access method. The access node of the private line network ensures that customers can normally access the private line network. In the existing MPLS VPN application based on wireless access, it is realized through the mode of Internet Protocol Security (IPsec) gateway. Specifically, the dedicated line circuit between the access router of the client and the access router of the private network is faulty. At this time, the access router of the client can be connected to the wireless network, and connected to the public network through the IPsec gateway, so as to establish a connection between the client and the private network through the wireless network and the public network, so that the client can work normally. Access to the private network.
但是,现有采用IPsec网关的模式来实现专用网的无线接入方式中,是通过无线网络接入到公网,由于专用网是一种保密性要求较好的私有网络,而公网的保密性相对较差,通过公网接入专用网时,专用网上的数据通过公网传输时,容易遭到攻击,易造成信息的泄露,从而降低了数据传输的安全性,无法满足专用网的安全性;同时,通过公网接入专用网过程中,公网路由的收敛耗时较多,专用线路故障时,网络切换时间较长,不利于客户端与专用网之间的快速切换,影响用户的使用体验。However, in the existing wireless access mode that uses the IPsec gateway mode to realize the private network, it is to access the public network through the wireless network. Since the private network is a private network with good confidentiality requirements, and the public network's confidentiality Relatively poor performance, when accessing the private network through the public network, when the data on the private network is transmitted through the public network, it is easy to be attacked and easily cause information leakage, thereby reducing the security of data transmission and failing to meet the security requirements of the private network At the same time, in the process of accessing the private network through the public network, the convergence of public network routes takes more time. When the private line fails, the network switching time is longer, which is not conducive to the rapid switching between the client and the private network, affecting users use experience.
综上,现有基于无线接入方式作为专线电路的备份电路技术,是采用IPsec网关模式来实现,接入专用网时,需要通过公网接入,导致网络的安全性较差,无法满足专用网的安全性;同时,由于公网路由收敛耗时较多,专用线路故障时网络切换时间较长,影响用户使用体验。To sum up, the existing backup circuit technology based on the wireless access method as a private line circuit is realized by using the IPsec gateway mode. Network security; at the same time, due to the time-consuming convergence of public network routes, the network switching time is longer when the private line fails, which affects the user experience.
发明内容Contents of the invention
本发明提供一种专用网接入方法、装置和系统,可在专线电路故障时,在客户端和专用网之间建立通信连接,并可有效提高网络数据传输的安全性,降低网络切换时间。The invention provides a private network access method, device and system, which can establish a communication connection between a client and a private network when a dedicated line circuit fails, effectively improve the security of network data transmission, and reduce network switching time.
本发明提供一种专用网接入方法,包括:The present invention provides a private network access method, including:
检测到接入专用网的专线电路故障时,自动接入无线网络,以确定所述无线网络中为客户端的接入路由器分配的核心网分组域设备;When detecting the failure of the dedicated line circuit for accessing the private network, automatically access the wireless network to determine the core network packet domain device allocated for the client's access router in the wireless network;
通过所述核心网分组域设备,在所述客户端的接入路由器和LNS服务器之间建立第二层隧道协议L2TP隧道,其中,所述LNS服务器通过IP承载网与所述核心网分组域设备和专用网的接入路由器连接;Establishing a
通过所述L2TP隧道和LNS服务器,接入所述专用网的接入路由器,建立客户端与专用网之间的通信连接。Through the L2TP tunnel and the LNS server, access the access router of the private network, and establish a communication connection between the client and the private network.
本发明提供一种专用网接入装置,包括:The present invention provides a private network access device, including:
无线接入单元,用于检测到接入专用网的专线电路故障时,自动接入无线网络,以确定所述无线网络中为客户端的接入路由器分配的核心网分组域设备;The wireless access unit is used to automatically access the wireless network when detecting a failure of the dedicated line circuit for accessing the private network, so as to determine the core network packet domain device allocated for the client's access router in the wireless network;
L2TP隧道建立单元,用于通过所述核心网分组域设备,在所述客户端的接入路由器和LNS服务器之间建立L2TP隧道,其中,所述LNS服务器通过IP承载网与所述核心网分组域设备和专用网的接入路由器连接;An L2TP tunnel establishment unit, configured to establish an L2TP tunnel between the access router of the client and an LNS server through the core network packet domain device, wherein the LNS server communicates with the core network packet domain through an IP bearer network The device is connected to the access router of the private network;
专用网接入单元,用于通过所述L2TP隧道和LNS服务器,接入所述专用网的接入路由器,建立客户端与专用网之间的通信连接。The private network access unit is configured to access the access router of the private network through the L2TP tunnel and the LNS server, and establish a communication connection between the client and the private network.
本发明提供一种专用网接入系统,包括:客户端的接入路由器、专用网的接入路由器和LNS服务器,所述客户端的接入路由器部署在专用网的客户端;所述专用网的接入路由器和LNS服务器部署在专用网,所述LNS服务器与所述专用网的接入路由器连接;The present invention provides a private network access system, including: a client access router, a private network access router and an LNS server, the client access router is deployed on the private network client; the private network access The ingress router and the LNS server are deployed in the private network, and the LNS server is connected to the access router of the private network;
所述客户端的接入路由器,用于检测到接入专用网的专线电路故障时,自动接入无线网络,并通过所述无线网络中为所述客户端的接入路由器分配的核心网分组域设备,建立和所述LNS服务器之间的L2TP隧道;The access router of the client is configured to automatically access the wireless network when detecting a failure of the dedicated line circuit for accessing the private network, and pass through the core network packet domain device allocated for the access router of the client in the wireless network , establishing an L2TP tunnel with the LNS server;
所述LNS服务器,用于与所述客户端的接入路由器之间建立协商建立所述L2TP隧道,并将所述L2TP隧道映射到专用网;The LNS server is configured to negotiate with the access router of the client to establish the L2TP tunnel, and map the L2TP tunnel to a private network;
所述客户端的接入路由器,还用于通过所述L2TP隧道和所述LNS服务器接入所述专用网的接入路由器,从而建立所述客户端和专用网之间的通信连接。The access router of the client is further configured to access the access router of the private network through the L2TP tunnel and the LNS server, so as to establish a communication connection between the client and the private network.
本发明提供的专用网接入方法、装置和系统,在接入专用网的专线电路故障时,通过利用无线网络,在客户端的接入路由器和LNS服务器之间建立端到端的L2TP隧道,并利用该L2TP隧道和LNS服务器接入到专用网的接入路由器,实现客户端和专用网之间的通信连接,数据传输过程中不会通过公网,可有效保障客户数据信息的保密性和安全性,满足专用网的安全性需要,同时,可有效降低网络切换时间,提高用户的使用体验。The private network access method, device and system provided by the present invention establish an end-to-end L2TP tunnel between the client's access router and the LNS server by utilizing the wireless network when the dedicated line circuit for accessing the private network fails, and utilize The L2TP tunnel and LNS server are connected to the access router of the private network to realize the communication connection between the client and the private network. The data transmission process will not pass through the public network, which can effectively guarantee the confidentiality and security of customer data information , to meet the security needs of the private network, and at the same time, it can effectively reduce the network switching time and improve the user experience.
附图说明Description of drawings
图1为本发明专用网接入方法实施例一的流程示意图;FIG. 1 is a schematic flow diagram of
图2为本发明专用网接入方法实施例二的流程示意图;FIG. 2 is a schematic flow diagram of
图3为本发明专用网接入方法实施例二的应用环境示意图;3 is a schematic diagram of the application environment of
图4为本发明专用网接入装置实施例一的结构示意图;FIG. 4 is a schematic structural diagram of
图5为本发明专用网接入装置实施例二中L2TP隧道建立单元的结构示意图;5 is a schematic structural diagram of the L2TP tunnel establishment unit in
图6为本发明专用网接入系统实施例的结构示意图。Fig. 6 is a schematic structural diagram of an embodiment of a private network access system according to the present invention.
具体实施方式Detailed ways
为使本发明实施例的目的、技术方案和优点更加清楚,下面将结合本发明实施例中的附图,对本发明实施例中的技术方案进行清楚、完整地描述,显然,所描述的实施例是本发明一部分实施例,而不是全部的实施例。基于本发明中的实施例,本领域普通技术人员在没有作出创造性劳动前提下所获得的所有其他实施例,都属于本发明保护的范围。In order to make the purpose, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments It is a part of embodiments of the present invention, but not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by persons of ordinary skill in the art without creative efforts fall within the protection scope of the present invention.
图1为本发明专用网接入方法实施例一的流程示意图。如图1所示,本实施例专用网接入方法可包括以下步骤:FIG. 1 is a schematic flowchart of
步骤101、客户端的接入路由器检测到接入专用网的专线电路故障时,自动接入无线网络,以确定无线网络中为该客户端的接入路由器分配的核心网分组域设备;
步骤102、客户端的接入路由器通过该核心网分组域设备,在客户端的接入路由器和基于L2TP的网络服务器(LNS服务器)之间建立第二层隧道协议(Layer2 Tunneling Protocol,L2TP)隧道,其中,LNS服务器是部署在专用网侧,并分别通过IP承载网与核心网分组域设备和专用网的接入路由器连接;
步骤103、客户端的接入路由器通过建立的L2TP隧道和LNS服务器,接入专用网的接入路由器,建立客户端与专用网之间的通信连接。
本实施例可应用于专用网的连接中,在客户端与专用网之间的专线电路故障时,可通过无线网络建立客户端与专用网之间的通信连接。具体地,当客户端与专用网之间设定的固网,即专线电路故障时,客户端的接入路由器可接入到无线网络,并通过无线网络中的核心分组域设备,在客户端的接入路由器和部署在专用网一侧的LNS服务器之间建立端到端的L2TP隧道,从而可利用该建立的L2TP隧道和LNS服务器接入到专用网的接入路由器,实现客户端和专用网之间的通信连接。This embodiment can be applied to the connection of the private network. When the dedicated line circuit between the client and the private network fails, a communication connection between the client and the private network can be established through the wireless network. Specifically, when the fixed network set between the client and the private network, that is, the private line circuit fails, the access router of the client can access the wireless network, and through the core packet domain equipment in the wireless network, Establish an end-to-end L2TP tunnel between the ingress router and the LNS server deployed on the side of the private network, so that the established L2TP tunnel and the LNS server can be used to access the access router of the private network to realize the connection between the client and the private network. communication connection.
本实施例中,当客户端接入到专线网的专线电路故障时,可在客户端的接入路由器和专用网一侧的LNS服务器之间建立L2TP隧道,从而可利用该建立的L2TP隧道,实现客户端和专用网之间的通信,客户端和专用网之间的通信是通过建立的L2TP隧道,不需要通过公网,因此,在数据传输的过程中,可在全程最大限度的保障客户数据信息的保密性和安全性,满足专用网的安全需要;同时,在网络切换过程,即重新建立客户端和专用网之间的通信连接中,由于不需要通过公网接入专用网,因此不会存在现有技术中因公网收敛耗时较长而造成的延时问题,可有效降低网络倒换,即网络切换时间,使得专线电路故障时,可快速建立客户端和专用网之间的通信连接,保证客户端快速访问专用网,可有效提高用户的使用体验。In this embodiment, when the private line circuit of the private line network that the client accesses fails, an L2TP tunnel can be established between the client's access router and the LNS server on the private network side, so that the established L2TP tunnel can be used to realize The communication between the client and the private network, the communication between the client and the private network is through the established L2TP tunnel, and does not need to pass through the public network. Therefore, in the process of data transmission, the customer data can be guaranteed to the greatest extent throughout the process The confidentiality and security of information meet the security needs of the private network; at the same time, in the process of network switching, that is, to re-establish the communication connection between the client and the private network, since there is no need to access the private network through the public network, there is no need to There will be a delay problem caused by the long time-consuming public network convergence in the existing technology, which can effectively reduce the network switching time, that is, the network switching time, so that when the private line circuit fails, the communication between the client and the private network can be quickly established Connection, to ensure that the client quickly accesses the private network, which can effectively improve the user experience.
综上,本发明实施例提供的专用网接入方法,在接入专用网的专线电路故障时,通过利用无线网络,在客户端的接入路由器和LNS服务器之间建立端到端的L2TP隧道,并利用该L2TP隧道和LNS服务器接入到专用网的接入路由器,实现客户端和专用网之间的通信连接,数据传输过程中不会通过公网,可有效保障客户数据信息的保密性和安全性,满足专用网的安全性需要,同时,可有效降低网络切换时间,提高用户的使用体验。To sum up, the private network access method provided by the embodiment of the present invention establishes an end-to-end L2TP tunnel between the client access router and the LNS server by using the wireless network when the private line circuit for accessing the private network fails, and Use the L2TP tunnel and the LNS server to connect to the access router of the private network to realize the communication connection between the client and the private network. The data transmission process will not pass through the public network, which can effectively guarantee the confidentiality and security of customer data information It meets the security needs of the private network, and at the same time, it can effectively reduce the network switching time and improve the user experience.
本实施例中,客户端接入专用网的无线网络可以是全球移动通信系统(global system for mobile communications,GSM)、宽带码分多址(文Wideband Code Division Multiple Access,WCDMA)或者长期演进(Long Term Evolution,LTE)网络,其中,该无线网络为GSM或WCDMA网络时,上述的核心网分组域设备可以是网关GPRS支持节点(Gateway GPRS Support Node,GGSN),该无线网络为LTE网络时,上述的核心网分组域设备可以是系统架构演进网关(System Architechure Evolut ion,SAE-GW)。下面将以WCDMA网络作为无线网络,并以其中的GGSN作为核心分组域设备,对客户端通过该WCDMA网络接入专用网的过程进行说明。In this embodiment, the wireless network through which the client accesses the private network may be Global System for Mobile Communications (GSM), Wideband Code Division Multiple Access (WCDMA) or Long Term Evolution (Long Term Evolution). Term Evolution, LTE) network, wherein, when the wireless network is a GSM or WCDMA network, the above-mentioned core network packet domain device can be a gateway GPRS support node (Gateway GPRS Support Node, GGSN), and when the wireless network is an LTE network, the above-mentioned The core network packet domain device may be a system architecture evolution gateway (System Architecture Evolution, SAE-GW). In the following, the WCDMA network will be used as the wireless network, and the GGSN in it will be used as the core packet domain device, and the process of the client accessing the private network through the WCDMA network will be described.
图2为本发明专用网接入方法实施例二的流程示意图;图3为本发明专用网接入方法实施例二的应用环境示意图。本实施例中,如图3所示,客户端所在的分支网络A,与专用网B之间通过固定网C这一专线电路进行通信连接;位于分支网络A侧的客户端的接入路由器10具有无线接入功能,可通过WCDMA网络的基站D接入到WCDMA网络,且该客户端的接入路由器10可支持L2TP隧道协议,可与支持L2TP隧道协议的设备之间建立L2TP隧道,本实施例中也可将客户端的接入路由器10称为L2TP接入路由器;专用网B的一侧设置有LNS服务器30,并与专用网B中的专用网接入路由器PE 40连接,该LNS服务器30为基于L2TP隧道协议的设备;WCDMA网络预先为客户端的接入路由器10内置的USIM卡分配一个专用的APN,作为用户信息保存在HLR70中,这样,客户端的接入路由器10接入网络中时,SSGN 60就会通过查询HLR,获得该专用的APN,就可以确定将客户端的接入路由器10连接到专用网侧的LNS服务器30的核心网分组域设备GGSN 20,其中,该GGSN 20为WCDMA网络中预先设置的可与LNS服务器连接的设备,当客户端的接入路由器10接入WCDMA网络时,即可通过该GGSN 20建立与LNS服务器的连接。其中,客户端的接入路由器10通过固定网C与专用网的接入路由器PE 50之间是通过光纤链路连接,客户端的接入路由器10与基站D之间通过无线网络连接,且基站D、SGSN 60、GGSN 20、LNS服务器30和专用网的接入路由器PE 40通过光纤链路,而客户端的接入路由器10接入到无线网络后,可以通过无线网络中的网络设备,建立到LNS服务器30之间的L2TP隧道。FIG. 2 is a schematic flowchart of
本实施例中,客户端的接入路由器、WCDMA网络和LNS服务器,可以作为固定网C的备份,以便固定网C故障时,使得客户端的接入路由器可通过WCDMA网络和LNS服务器接入到专用网的接入路由器。具体地,正常情况下,客户端的接入路由器10会通过固定网C连接到专用网的接入路由器PE 50,使得用户可通过该固定网C访问专用网B;当固定网C故障时,即可启动无线路由,即通过本实施例技术方案在客户端的接入路由器10与LNS服务器30建立L2TP隧道,客户端的接入路由器10会通过该L2TP隧道和LNS服务器30接入到专用网的接入路由器PE 40,使得用户可通过该L2TP隧道访问专用网,具体地,如图2所示,客户端的接入路由器通过WCDMA网络接入专用网的接入路由器具体可包括以下步骤:In this embodiment, the client's access router, WCDMA network and LNS server can be used as the backup of the fixed network C, so that when the fixed network C fails, the client's access router can be connected to the private network through the WCDMA network and the LNS server access router. Specifically, under normal circumstances, the access router 10 of the client will be connected to the access router PE 50 of the private network through the fixed network C, so that the user can access the private network B through the fixed network C; when the fixed network C fails, the Wireless routing can be started, that is, through the technical solution of this embodiment, an L2TP tunnel is established between the access router 10 of the client and the LNS server 30, and the access router 10 of the client will access the private network through the L2TP tunnel and the LNS server 30. The router PE 40 enables the user to access the private network through the L2TP tunnel. Specifically, as shown in Figure 2, the access router of the client accessing the private network through the WCDMA network may specifically include the following steps:
步骤201、客户端的接入路由器检测到接入到固定网宕机时,启动无线接入,自动接入到WCDMA网络中;
步骤202、WCDMA网络中的GPRS服务支持节点(SERVICING GPRS SUPPORTNODE,SGSN)通过归属位置寄存器(Home Location Register,HLR)查询客户端的接入路由器的APN,以确定WCDMA网络分配给该客户端的接入路由器的GGSN;
步骤203、GGSN根据该客户端的接入路由器的APN,判断该客户端的接入路由器为专用网用户,为客户端的接入路由器分配私有IP地址;
步骤204、客户端的接入路由器通过GGSN分配的私有IP地址,接入到LNS服务器,建立与LNS服务器之间的会话和协商;
步骤205、LNS服务器为客户端的接入路由器分配新的IP地址;
步骤206、客户端的接入路由器通过该新的IP地址,在客户端的接入路由器和LNS服务器之间建立L2TP隧道;
步骤207、LNS服务器完成建立的L2TP隧道与专用网的映射;
步骤208、客户端的接入路由器通过该L2TP隧道和LNS服务器,接入到专用网的接入路由器。
上述步骤201~步骤203中,当客户端的接入路由器检测到固定网宕机,即专线电路故障时,可发起附着流程,在SGSN上注册移动性管理MM上下文信息,接入到WCDMA网络;SGSN可向HLR查询用户信息,查询到WCDMA网络分配给客户端的接入路由器的APN,通过APN解析,即可确定为该客户端的接入路由器提供服务的GGSN;客户端的接入路由器可通过该GGSN进行分组数据协议上下文(PDP上下文)激活,由GGSN为客户端的接入路由器分配私有I P地址。In the
上述步骤204~步骤208中,客户端的接入路由器可通过分配的私有IP地址,通过GGSN与LNS服务器之间建立会话连接;LNS服务器可以为客户端的接入路由器分配新的IP地址,从而可通过该新的IP地址,在客户端的接入路由器和LNS服务器之间建立端到端的L2TP隧道;客户端的接入路由器可通过L2TP隧道,将其自身下挂的路由信息宣告至LNS服务器,其中,该LNS服务器支持边界网关协议(Border Gateway Protocol,BGP)功能,从而可通过该BGP功能,完成L2TP隧道与专用网的映射;LNS服务器可作为通信终端(Communication Edge,CE)接入到网络,将相关的路由信息宣告至专用网的接入路由器PE,由此,客户端的接入路由器就可以接入到专用网的接入路由器PE,从而在客户端和专用网之间建立会话通道,客户端的用户即可以通过该会话通道来访问专用网。In the
本实施例中,客户端和专用网之间的会话通道,即通信连接建立后,就可以进行数据报文的转发,具体地,对于上行的IP数据报文,客户端的接入路由器可将接收的上行IP数据报文,通过WCDMA网络和SGSN传递至GGSN,并由GGSN透传至LNS服务器,最后由LNS服务器将IP数据报文发送到专用网的接入路由器PE,在此过程中,IP数据报文是通过L2TP隧道封装的方式发送至专用网的接入路由器PE,WCDMA网络对IP数据报文无需处理,只需要透传即可;对于下行的IP数据报文,LNS服务器需要在IP数据报文中识别客户端的接入路由器中配置的IP网段,根据L2TP会话找到对应的客户端接入路由器,将下行IP数据报文,通过L2TP隧道封装的方式发送至客户端的接入路由器,下行IP数据报文的发送过程中,WCDMA网络仅进行IP数据报文的透传,中间不需要进行报文处理等操作,可有效减轻GGSN的工作负荷。In this embodiment, the session channel between the client and the private network, that is, after the communication connection is established, the data message can be forwarded. Specifically, for the uplink IP data message, the access router of the client can send the received The uplink IP data packet is transmitted to the GGSN through the WCDMA network and SGSN, and transparently transmitted by the GGSN to the LNS server. Finally, the LNS server sends the IP data packet to the access router PE of the private network. During this process, the IP Data packets are sent to the access router PE of the private network through L2TP tunnel encapsulation. The WCDMA network does not need to process IP data packets, but only needs to be transparently transmitted; for downlink IP data packets, the LNS server needs to be in the IP Identify the IP network segment configured in the client's access router in the data message, find the corresponding client access router according to the L2TP session, and send the downlink IP data message to the client's access router through L2TP tunnel encapsulation. During the sending process of the downlink IP data message, the WCDMA network only performs the transparent transmission of the IP data message, and does not need to perform operations such as message processing in the middle, which can effectively reduce the workload of the GGSN.
图4为本发明专用网接入装置实施例一的结构示意图。如图4所示,本实施例专用网接入装置包括无线接入单元1、L2TP隧道建立单元2和专用网接入单元3,其中:FIG. 4 is a schematic structural diagram of
无线接入单元1,用于检测到接入专用网的专线电路故障时,自动接入无线网络,以确定无线网络中为客户端的接入路由器分配的核心网分组域设备;The
L2TP隧道建立单元2,用于通过核心网分组域设备,在客户端的接入路由器和LNS服务器之间建立L2TP隧道,其中,该LNS服务器通过IP承载网与核心网分组域设备和专用网的接入路由器连接;The L2TP
专用网接入单元3,用于通过L2TP隧道和LNS服务器,接入专用网的接入路由器,建立客户端与专用网之间的通信连接。The private
本实施例专用网的接入装置可以作为客户端的接入路由器,以便在客户端连接到专用网之间的专线电路故障时,可通过无线网络自动接入到专用网,确保客户端与专线网之间的通信连接,其具体实现过程可参见上述本发明方法实施例的说明,在此不再赘述。The access device of the private network in this embodiment can be used as the access router of the client, so that when the private line circuit between the client and the private network fails, it can be automatically connected to the private network through the wireless network to ensure that the client is connected to the private network. For the specific implementation process of the communication connection between them, reference may be made to the above description of the method embodiment of the present invention, which will not be repeated here.
图5为本发明专用网接入装置实施例二中L2TP隧道建立单元的结构示意图。在上述图4所示实施例技术方案的基础上,如图5所示,L2TP隧道建立单元2具体可包括第一获取模块21、协商建立模块22、第二获取模块23和L2TP隧道建立模块24,其中:FIG. 5 is a schematic structural diagram of the L2TP tunnel establishment unit in
第一获取模块21,用于获取核心网络分组域设备为客户端的接入路由器分配的私有IP地址;The first obtaining
协商建立模块22,用于通过该获得的私有IP地址,在客户端的接入路由器和LNS服务器之间建立协商;A
第二获取模块23,用于获取LNS服务器为客户端的接入路由器分配的IP地址;The second obtaining
L2TP隧道建立模块24,用于通过LNS服务器分配的IP地址,在客户端的接入路由器和LNS服务器之间建立L2TP隧道。The L2TP
本实施例中,上述的专用网接入单元具体可用于通过L2TP隧道,将客户端的接入路由器自身下挂的路由信息宣告至LNS服务器,以便由LNS服务器将路由信息宣告至专用网的接入路由器,以将客户端的接入路由器接入到专用网的接入路由器。上述的无线接入单元具体可用于检测到接入专用网的专线电路故障时,自动接入无线网络,以便通过SGSN向HLR查询为客户端的接入路由器分配的接入节点APN,以便根据APN确定无线网络中为客户端的接入路由器分配的核心分组域设备。In this embodiment, the above-mentioned private network access unit can be specifically used to announce the routing information attached to the client's access router itself to the LNS server through the L2TP tunnel, so that the LNS server can announce the routing information to the private network access Router, to connect the access router of the client to the access router of the private network. The above-mentioned wireless access unit can be specifically used to automatically access the wireless network when a fault is detected in the dedicated line circuit for accessing the private network, so as to inquire the HLR through the SGSN of the access node APN allocated for the client's access router, so as to determine the APN according to the APN. The core packet domain device assigned to the client's access router in the wireless network.
图6为本发明专用网接入系统实施例的结构示意图。如图6所示,本实施例专用网接入系统包括:客户端的接入路由器100、专用网的接入路由器200和LNS服务器300,该客户端的接入路由器100部署在专用网的客户端;专用网的接入路由器200和LNS服务器300部署在专用网,LNS服务器300和专用网的接入路由器200连接,客户端的接入路由器100和LNS服务器之间通过无线网络连接。Fig. 6 is a schematic structural diagram of an embodiment of a private network access system according to the present invention. As shown in Figure 6, the private network access system of this embodiment includes: an
其中,客户端的接入路由器100用于检测到接入专用网的专线电路故障时,自动接入无线网络,并通过无线网络中为客户端的接入路由器100分配的核心网分组域设备,建立和LNS服务器300之间的L2TP隧道;LNS服务器300用于与客户端的接入路由器100协商,配合建立二者之间的L2TP隧道,并将L2TP隧道映射到专用网;客户端的接入路由器100还用于通过建立的L2TP隧道和LNS服务器300接入专用网的接入路由器200,从而建立客户端和专用网之间的通信连接。Wherein, the
本实施例中,LNS服务器300是与专用网的接入路由器200的一个端口对应连接,而专用网的接入路由器的每个端口又具有多个子接口,因此,LNS服务器300还可将L2TP隧道映射到专用网的接入路由器200的子接口,从而使得LNS服务器300接收到客户端的接入路由器通过L2TP隧道发送的数据后,可直接将数据发送至专用网的接入路由器200的子接口中。具体地,由于专用网的客户是一定的,因此,可在LNS服务器上维护一张对应关系表,将每个客户端的接入路由器建立到LNS服务器L2TP隧道映射到专用网的接入路由器的各子接口上,这样,当有新客户接入节点增加时,只需要在LNS服务器配置相应的数据,即对LNS服务器上的对应关系表进行修改,建立新客户接入节点与专用网的接入路由器的子接口的对应关系即可,这样,不需要在专用网的接入路由器上进行数据配置,可有效便于网络的维护和管理,不会因为增加新客户接入节点而频繁对专用网的接入路由器进行数据配置,可便于网络的部署。In this embodiment, the
本实施例专线网接入系统中,客户端的接入路由器100可在客户端接入到专用网的专线电路故障时,可通过无线网络中的核心网分组域设备,建立客户端的接入路由器100和LNS服务器300之间的L2TP隧道,从而使得客户端的接入路由器100可通过L2TP隧道和LNS服务器接入到专用网的接入路由器200,建立客户端和专用网之间的通信连接,其中,客户端的接入路由器100具体可以为上述本发明实施例提供的专用网接入装置,其具体结构和实现方式可参见上述本发明方法和装置实施例的说明,在此不再赘述。In the private line network access system of this embodiment, the client's
本领域普通技术人员可以理解:实现上述方法实施例的全部或部分步骤可以通过程序指令相关的硬件来完成,前述的程序可以存储于一计算机可读取存储介质中,该程序在执行时,执行包括上述方法实施例的步骤;而前述的存储介质包括:ROM、RAM、磁碟或者光盘等各种可以存储程序代码的介质。Those of ordinary skill in the art can understand that all or part of the steps for realizing the above-mentioned method embodiments can be completed by hardware related to program instructions, and the aforementioned program can be stored in a computer-readable storage medium. When the program is executed, the It includes the steps of the above method embodiments; and the aforementioned storage medium includes: ROM, RAM, magnetic disk or optical disk and other various media that can store program codes.
最后应说明的是:以上实施例仅用以说明本发明的技术方案,而非对其限制;尽管参照前述实施例对本发明进行了详细的说明,本领域的普通技术人员应当理解:其依然可以对前述各实施例所记载的技术方案进行修改,或者对其中部分技术特征进行等同替换;而这些修改或者替换,并不使相应技术方案的本质脱离本发明各实施例技术方案的精神和范围。Finally, it should be noted that: the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: it can still be Modifications are made to the technical solutions described in the foregoing embodiments, or equivalent replacements are made to some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the various embodiments of the present invention.
Claims (10)
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN201110119748.XA CN102186168B (en) | 2011-05-10 | 2011-05-10 | Private network access method, device and system |
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN201110119748.XA CN102186168B (en) | 2011-05-10 | 2011-05-10 | Private network access method, device and system |
Publications (2)
| Publication Number | Publication Date |
|---|---|
| CN102186168A true CN102186168A (en) | 2011-09-14 |
| CN102186168B CN102186168B (en) | 2013-08-14 |
Family
ID=44572226
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| CN201110119748.XA Active CN102186168B (en) | 2011-05-10 | 2011-05-10 | Private network access method, device and system |
Country Status (1)
| Country | Link |
|---|---|
| CN (1) | CN102186168B (en) |
Cited By (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN102523583A (en) * | 2011-12-07 | 2012-06-27 | 福建星网锐捷网络有限公司 | VPDN multi-access point backup access method and equipment |
| CN106686077A (en) * | 2016-12-24 | 2017-05-17 | 上海七牛信息技术有限公司 | System and method for processing network requests across double-layer proxies of data centers in computer rooms |
| CN116633428A (en) * | 2023-06-20 | 2023-08-22 | 中国电信股份有限公司 | Method, device, electronic equipment and storage medium for emergency repair of communication line failure |
Citations (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US6996110B1 (en) * | 2001-08-31 | 2006-02-07 | 3Com Corporation | Distributed MPLS architecture |
| CN102045198A (en) * | 2010-12-15 | 2011-05-04 | 中国联合网络通信集团有限公司 | Fixed-network multiprotocol label-switching virtual private network backup transmission method and system |
-
2011
- 2011-05-10 CN CN201110119748.XA patent/CN102186168B/en active Active
Patent Citations (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US6996110B1 (en) * | 2001-08-31 | 2006-02-07 | 3Com Corporation | Distributed MPLS architecture |
| CN102045198A (en) * | 2010-12-15 | 2011-05-04 | 中国联合网络通信集团有限公司 | Fixed-network multiprotocol label-switching virtual private network backup transmission method and system |
Cited By (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN102523583A (en) * | 2011-12-07 | 2012-06-27 | 福建星网锐捷网络有限公司 | VPDN multi-access point backup access method and equipment |
| CN106686077A (en) * | 2016-12-24 | 2017-05-17 | 上海七牛信息技术有限公司 | System and method for processing network requests across double-layer proxies of data centers in computer rooms |
| CN116633428A (en) * | 2023-06-20 | 2023-08-22 | 中国电信股份有限公司 | Method, device, electronic equipment and storage medium for emergency repair of communication line failure |
Also Published As
| Publication number | Publication date |
|---|---|
| CN102186168B (en) | 2013-08-14 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| EP2720415B1 (en) | Routing control method, apparatus and system of layer 3 virtual private network | |
| CN102882699B (en) | The distribution method of fringe node and device and fringe node controller | |
| US11575649B2 (en) | Supporting dynamic host configuration protocol-based customer premises equipment in fifth generation wireline and wireless convergence | |
| US9084108B2 (en) | Method, apparatus, and system for mobile virtual private network communication | |
| CN114079613B (en) | A communication method and related equipment | |
| US9967751B2 (en) | Mobile network-based tenant network service implementation method, system, and network element | |
| US9622143B1 (en) | Access point name mappings for a layer two wireless access network | |
| US12463771B2 (en) | Mobile network user plane with access network user plane function | |
| WO2013182066A1 (en) | Label distribution method and device | |
| CN109088823B (en) | Method and device for realizing terminal interconnection | |
| US20230146807A1 (en) | Supporting dynamic host configuration protocol-based customer premises equipment in fifth generation wireline and wireless convergence | |
| CN102045233B (en) | Method and device for controlling message forwarding in network communication | |
| CN111988227A (en) | Traffic processing method and related equipment, and method and device for establishing forwarding table | |
| WO2012136006A1 (en) | Routing method and device for host in multi-homing site | |
| CN102186168B (en) | Private network access method, device and system | |
| CN113938353B (en) | Multi-PDN implementation method and storage medium between indoor and outdoor units | |
| EP4395262A1 (en) | Bgp signaling for access network-user plane function | |
| CN102025549B (en) | Backup transmission method and system for fixed network multi-protocol label switching virtual private network | |
| CN102025547B (en) | MPLS (Multiple Protocol Label Switching) VPN (Virtual Private Network) routing backup method and system based on wireless mode | |
| US10367658B2 (en) | Wireless network session establishment method and apparatus utilizing a virtual local area network label | |
| CN102045198B (en) | Fixed-network multiprotocol label-switching virtual private network backup transmission method and system | |
| CN102685263B (en) | Recover method, AFTR and B4 of the dynamic mapping of AFTR | |
| CN104660446A (en) | DHCP relay implementation system and method in N: 1 protection scenario | |
| EP4546748A1 (en) | Virtual internet protocol address associated with subscriber group | |
| EP4546722A1 (en) | Providing a multiple dwelling unit fixed wireless access mechanism |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| C06 | Publication | ||
| PB01 | Publication | ||
| C10 | Entry into substantive examination | ||
| SE01 | Entry into force of request for substantive examination | ||
| C14 | Grant of patent or utility model | ||
| GR01 | Patent grant |