CN103118147A - Method, equipment and system for accessing intranet server - Google Patents

Method, equipment and system for accessing intranet server Download PDF

Info

Publication number
CN103118147A
CN103118147A CN2013100275758A CN201310027575A CN103118147A CN 103118147 A CN103118147 A CN 103118147A CN 2013100275758 A CN2013100275758 A CN 2013100275758A CN 201310027575 A CN201310027575 A CN 201310027575A CN 103118147 A CN103118147 A CN 103118147A
Authority
CN
China
Prior art keywords
address
application
port
public network
network
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
CN2013100275758A
Other languages
Chinese (zh)
Inventor
解克
冯立华
冀哲
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
China United Network Communications Group Co Ltd
Original Assignee
China United Network Communications Group Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by China United Network Communications Group Co Ltd filed Critical China United Network Communications Group Co Ltd
Priority to CN2013100275758A priority Critical patent/CN103118147A/en
Publication of CN103118147A publication Critical patent/CN103118147A/en
Pending legal-status Critical Current

Links

Images

Landscapes

  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

The invention provides a method, equipment and a system for accessing an intranet server. The method includes enabling CGN [carrier-grade NAT (network address translation)] equipment to preliminarily configure a public network IP (internet protocol) address and a public network port identifier according to application information of an internal server, and storing configuration information in an access list of the internal server; judging whether first configuration information matched with network access information is available in the access list of the internal server or not when the network access information which is transmitted by an extranet user terminal and contains a destination IP address, a destination port identifier and a transmission protocol is received; and enabling a port corresponding to a first public network port identifier to forward the network access information to a port which is located on the intranet server corresponding to a first private network IP address and corresponds to a first application port identifier if the first configuration information is available in the access list of the internal server. The application information of the internal server is transmitted by an intranet user terminal, and the public network IP address and the public network port identifier correspond to a private network IP address, an application port identifier and an application transmission protocol. The method, the equipment and the system have the advantage that extranet users can actively access the internal server via the address translation technology by the aid of the CGN equipment.

Description

Intranet server access method, apparatus and system
Technical field
The embodiment of the invention relates to communication technical field, relates in particular to a kind of Intranet server access method, apparatus and system.
Background technology
Development along with the Internet, number of broadband customers increases sharply, IP has closed on exhaustion in publicly-owned address, for solving the problem of shortage of ip address, network address translation (Network Address Translation has been proposed, NAT) technology and use carrier class network address transition (Carrier-Grade NAT, CGN) equipment and support multi-terminal equipment to carry out access to netwoks.
At present, mainly solved the problem of Intranet user (being the private net address user) access outer net based on the NAT technology of CGN equipment, but, when Intranet user is built into the internal server of wishing the external user access with oneself user terminal, because the private network IP address of Intranet user terminal can't be identified by external user on public network, therefore, NAT technology based on present CGN equipment can't solve the problem that external user is initiatively accessed internal server, and prior art can solve the problem that the rear internal server of NAT conversion is used by the mapping of IP address.Be about to the information that a public network address accepts and all be mapped to a private net address, but realization will cause a private net address need to take whole ports of a public network address like this, has lost NAT conversion meaning.
Summary of the invention
For the defects of prior art, the embodiment of the invention provides a kind of Intranet server access method, apparatus and system.
One aspect of the present invention provides a kind of Intranet server access method, comprising:
CGN equipment receives the internal server solicitation message that the Intranet user terminal sends, described internal server solicitation message comprises: the private network IP address of described Intranet user terminal, and application port sign and the application transport agreement corresponding with the network application of described internal server opening;
Described CGN equipment disposes public network IP address and the public network port-mark corresponding with described private network IP address, described application port sign and described application transport agreement, and stores configuration information into the internal server access list;
Comprise purpose IP address when what described CGN equipment received that the external user terminal sends, during the access to netwoks message of destination interface sign and host-host protocol, determine whether have with described purpose IP the address in the described internal server access list, the first configuration information of described destination interface sign and described host-host protocol coupling, described the first configuration information comprises: the first private network IP address, the corresponding relation of the first application port sign and the first application transport agreement and the first public network IP address and the first public network port-mark, wherein, described the first application port sign is identical with described destination interface sign, described the first application transport agreement is identical with described host-host protocol, and described the first public network IP address is identical with described purpose IP address;
If described CGN equipment determines to have described the first configuration information, then use the port corresponding with described the first public network port-mark to interior network server corresponding to described the first private network IP address on, identify the corresponding described access to netwoks message of port repeat with described the first application port.
The present invention provides a kind of CGN equipment on the other hand, comprising:
Receiver module, be used for receiving the internal server solicitation message that the Intranet user terminal sends, described internal server solicitation message comprises: the private network IP address of described Intranet user terminal, and application port sign and the application transport agreement corresponding with the network application of described internal server opening;
Configuration module is used for configuration public network IP address and the public network port-mark corresponding with described private network IP address, described application port sign and described application transport agreement, and stores configuration information into the internal server access list;
Enquiry module, be used for comprising purpose IP address when what receive that the external user terminal sends, during the access to netwoks message of destination interface sign and host-host protocol, determine whether have with described purpose IP the address in the described internal server access list, the first configuration information of described destination interface sign and described host-host protocol coupling, described the first configuration information comprises: the first private network IP address, the corresponding relation of the first application port sign and the first application transport agreement and the first public network IP address and the first public network port-mark, wherein, described the first application port sign is identical with described destination interface sign, described the first application transport agreement is identical with described host-host protocol, and described the first public network IP address is identical with described purpose IP address;
Processing module, if be used for determining to have described the first configuration information, then use the port corresponding with described the first public network port-mark to interior network server corresponding to described the first private network IP address on, identify the corresponding described access to netwoks message of port repeat with described the first application port.
Another aspect of the invention provides a kind of Intranet server access system, comprises the external user terminal and as the Intranet user terminal of internal server, and above-mentioned CGN equipment.
The Intranet server access method that the embodiment of the invention provides, equipment and system, identify and the application transport agreement according to the private network IP address in the internal server solicitation message of Intranet user terminal transmission and open application port corresponding to network application of internal server in advance by CGN equipment, public network IP address and public network port-mark that configuration is corresponding, and store configuration information into the internal server access list, comprise purpose IP address when what receive that the external user terminal sends, during the access to netwoks message of destination interface sign and host-host protocol, determine whether to have in the internal server access list with purpose IP the address, the first configuration information of destination interface sign and host-host protocol coupling, if, illustrate that then the first application port sign in the first configuration information is identical with the destination interface sign, the first application transport agreement is identical with host-host protocol, and the first public network IP address is identical with purpose IP address, then use the port corresponding with the first public network port-mark to interior network server corresponding to the first private network IP address on, the port repeat access to netwoks message corresponding with the first application port sign.Thereby CGN equipment utilization address transition technology has solved external user when initiatively accessing the problem of internal server, guarantees the access of the external network server of Intranet user terminal.
Description of drawings
The flow chart of the Intranet server access method that Fig. 1 provides for the embodiment of the invention;
The structural representation of the CGN equipment that Fig. 2 provides for the embodiment of the invention;
The structural representation of the Intranet server access system that Fig. 3 provides for the embodiment of the invention.
Embodiment
The flow chart of the Intranet server access method that Fig. 1 provides for the embodiment of the invention, as shown in Figure 1, the method comprises:
Step 100, CGN equipment receives the internal server solicitation message that the Intranet user terminal sends, described internal server solicitation message comprises: the private network IP address of described Intranet user terminal, and application port sign and the application transport agreement corresponding with the network application of described internal server opening;
Have a plurality of public network IP address on the CGN equipment, and the public network port of the some corresponding with each public network IP address, when the Intranet user terminal is utilized by Broadband Remote Access Server (Broadband Remote Access Server, during the private network IP address access external server that BRAS) distributes, add that the packet header that comprises public network IP address sends to corresponding external server on the network access request of that CGN sends the Intranet user terminal, as to comprise private network IP address and external server to be visited IP address.Thereby CGN equipment makes a plurality of Intranet user terminals share the external network server of public network IP address by the NAT technology and conducts interviews, solved public ip address problem in short supply.In actual applications, the Intranet user terminal can be built into internal server according to using the user terminal of needs with self, internal server is supported one or more network applications, concrete network application can comprise: the http access, the smtp mail server, the ftp data access, the telnet service access and etc., the application port that different network applications is corresponding different, support different application transport agreements, because the Intranet user terminal does not have public network IP address, therefore, the Intranet user terminal sends the internal server solicitation message to CGN equipment, this internal server solicitation message comprises: the private network IP address of Intranet user terminal, and application port sign and the application transport agreement corresponding to the network application of external user open-destination with internal server, wherein, the form of expression of application port sign is numeral, for example the application port of http access is 80, the application port of smtp mail server access is 25, the application port of ftp data access is 21, the application port of telnet service access is 23 etc., and the application transport agreement specifically comprises: the application transport agreement of smtp mail server support is the POP3 agreement, the application transport agreement of NM server support is snmp protocol etc.CGN equipment is resolved the private network IP address that obtains the Intranet user terminal to the internal server solicitation message that the Intranet user terminal sends, and to application port sign and the application transport agreement of the network application of external user open-destination.Need to prove, when having at least two internal server applications identical with the application transport agreement to the application port of the network application of external user open-destination sign, CGN equipment selects the application of one of them internal server to process according to default selection strategy, concrete selection strategy comprises: the first to file strategy, be that CGN equipment is processed the internal server of first to file according to time sequencing, after processing, sends refusal the internal server of application, if many internal servers are applied for simultaneously, then refusal request indicates each internal server again to apply for; Perhaps, priority policy, even many internal servers are applied for simultaneously, CGN equipment is selected the high internal server of priority is processed according to the priority of internal server.CGN equipment can arrange concrete selection strategy according to the application needs of reality, and present embodiment is not restricted this.
Step 101, described CGN equipment dispose public network IP address and the public network port-mark corresponding with described private network IP address, described application port sign and described application transport agreement, and store configuration information into the internal server access list;
After the internal server solicitation message that CGN device parses Intranet user terminal sends, dispose application port sign and corresponding public network IP address and the public network port-mark of application transport agreement of the network application of opening with the private network IP address that obtains and internal server, and storing configuration information into the internal server access list, configuration information just refers to private network IP address, application port sign and and the corresponding relation of application transport agreement and public network IP address and public network port-mark.
Step 102, comprise purpose IP address when what described CGN equipment received that the external user terminal sends, during the access to netwoks message of destination interface sign and host-host protocol, determine whether have with described purpose IP the address in the described internal server access list, the first configuration information of described destination interface sign and described host-host protocol coupling, described the first configuration information comprises: the first private network IP address, the corresponding relation of the first application port sign and the first application transport agreement and the first public network IP address and the first public network port-mark, wherein, described the first application port sign is identical with described destination interface sign, described the first application transport agreement is identical with described host-host protocol, and described the first public network IP address is identical with described purpose IP address;
Comprise purpose IP address when what CGN equipment received that the external user terminal sends, during the access to netwoks message of destination interface sign and host-host protocol, whether has the address with purpose IP in the internal server access list of setting up before determining, the first configuration information of destination interface sign and host-host protocol coupling, described the first configuration information comprises: the first private network IP address, the corresponding relation of the first application port sign and the first application transport agreement and the first public network IP address and the first public network port-mark, wherein, the first application port sign is identical with the destination interface sign, and the first application transport agreement is identical with host-host protocol and the first public network IP address is identical with purpose IP address.Because the mode of store configuration information is different in the internal server access list, the mode whether CGN equipment is determined to have in the internal server access list with marking matched the first configuration information of purpose IP address and destination interface comprises inquiry, relatively waits, for example mode one: the corresponding relation of private network IP address and application port sign and public network IP address and public network port-mark is stored successively, and example is as shown in table 1:
Table 1
Figure BDA00002774832100051
Perhaps, mode two: private network IP address, the application port corresponding take public network IP address as index stores identify and the public network port-mark, and example is as shown in table 2:
Table 2
Public network IP address Private network IP address The application port sign The public network port-mark Host-host protocol
1.1 101.100.2 25 80 The POP3 agreement
? 102.105.6 23 50 Snmp protocol
1.2 101.103.3 80 26 Transmission Control Protocol
Need to prove that the concrete manifestation form of the private network IP address in the above-mentioned table and public network IP address is just for the content of simplicity of explanation configuration information, do not represent the form of expression of private network IP address and public network IP address in the practical application.
Storage mode for table 1 is fit to inquiry, storage mode for table 2 is fit to relatively, specify CGN equipment as an example of table 2 example and determine whether to have in the internal server access list process with marking matched the first configuration information of purpose IP address and destination interface: the configuration information in the CGN equipment query internal server access list, judge whether to have first public network IP address identical with purpose IP address, if judge whether to have with application port sign corresponding to the first public network IP address and application transport agreement to identify first application port identical with host-host protocol with destination interface and identify and the first application transport agreement.
Step 103, if described CGN equipment determines to have described the first configuration information, then use the port corresponding with described the first public network port-mark to interior network server corresponding to described the first private network IP address on, identify the corresponding described access to netwoks message of port repeat with described the first application port.
If CGN equipment determines to have in the internal server access list first configuration information marking matched with purpose IP address and destination interface, then use the port corresponding with the first public network port-mark to interior network server corresponding to the first private network IP address on, with the access to netwoks message of port repeat external user terminal transmission corresponding to the first application port sign, thereby the external user terminal can be accessed on the internal server and identified corresponding network application with destination interface.
Further, if CGN equipment determines not have in the internal server access list first configuration information marking matched with purpose IP address and destination interface, then send the access to netwoks refuse information to the external user terminal.
The Intranet server access method that present embodiment provides, identify and the application transport agreement according to the private network IP address in the internal server solicitation message of Intranet user terminal transmission and open application port corresponding to network application of internal server in advance by CGN equipment, public network IP address and public network port-mark that configuration is corresponding, and store configuration information into the internal server access list, comprise purpose IP address when what receive that the external user terminal sends, during the access to netwoks message of destination interface sign and host-host protocol, determine whether to have in the internal server access list with purpose IP the address, the first configuration information of destination interface sign and host-host protocol coupling, if, illustrate that then the first application port sign in the first configuration information is identical with the destination interface sign, the first application transport agreement is identical with host-host protocol, and the first public network IP address is identical with purpose IP address, then use the port corresponding with the first public network port-mark to interior network server corresponding to the first private network IP address on, the port repeat access to netwoks message corresponding with the first application port sign.Thereby CGN equipment utilization address transition technology has solved external user when initiatively accessing the problem of internal server, guarantees the access of the external network server of Intranet user terminal.
One of ordinary skill in the art will appreciate that: all or part of step that realizes said method embodiment can be finished by the relevant hardware of program command, aforesaid program can be stored in the computer read/write memory medium, this program is carried out the step that comprises said method embodiment when carrying out; And aforesaid storage medium comprises: the various media that can be program code stored such as ROM, RAM, magnetic disc or CD.
The structural representation of the CGN equipment that Fig. 2 provides for the embodiment of the invention, as shown in Figure 2, this CGN equipment comprises: receiver module 11, configuration module 12, enquiry module 13 and processing module 14, wherein, receiver module 11 is used for receiving the internal server solicitation message that the Intranet user terminal sends, described internal server solicitation message comprises: the private network IP address of described Intranet user terminal, and application port sign and the application transport agreement corresponding with the network application of described internal server opening; Configuration module 12 is used for configuration public network IP address and the public network port-mark corresponding with described private network IP address, described application port sign and described application transport agreement, and stores configuration information into the internal server access list; Enquiry module 13 is used for comprising purpose IP address when what receive that the external user terminal sends, during the access to netwoks message of destination interface sign and host-host protocol, determine whether have with described purpose IP the address in the described internal server access list, the first configuration information of described destination interface sign and described host-host protocol coupling, described the first configuration information comprises: the first private network IP address, the corresponding relation of the first application port sign and the first application transport agreement and the first public network IP address and the first public network port-mark, wherein, described the first application port sign is identical with described destination interface sign, described the first application transport agreement is identical with described host-host protocol, and described the first public network IP address is identical with described purpose IP address; If processing module 14 is used for determining to have described the first configuration information, then use the port corresponding with described the first public network port-mark to interior network server corresponding to described the first private network IP address on, identify the corresponding described access to netwoks message of port repeat with described the first application port.
Wherein, enquiry module 13 specifically is used for: the configuration information of inquiring about described internal server access list, judge whether to have first public network IP address identical with described purpose IP address, if judge whether to have with application port sign corresponding to described the first public network IP address and host-host protocol to identify first application port identical with described host-host protocol with described destination interface and identify and the first application transport agreement.
Further, processing module 14 also is used for: if determine not have described the first configuration information, then send the access to netwoks refuse information to described external user terminal.
Function and the handling process of each module in the CGN equipment that present embodiment provides can be referring to above-mentioned embodiments of the method shown in Figure 1, and its realization principle and technique effect are similar, repeat no more herein.
The structural representation of the Intranet server access system that Fig. 3 provides for the embodiment of the invention, as shown in Figure 3, this system comprises: external user terminal 1 and as the Intranet user terminal 2 of internal server, and CGN equipment 3.Wherein, the CGN equipment that provides in the above embodiment of the present invention can be provided CGN equipment 3, external user terminal 1 and can adopt external user terminal related in the above embodiment of the present invention and Intranet user terminal as the Intranet user terminal 2 of internal server.
Function and the handling process of each module in the Intranet server access system that present embodiment provides can be referring to the embodiments of the method shown in above-mentioned, and it realizes that principle and technique effect are similar, repeats no more herein.
It should be noted that at last: above embodiment only in order to technical scheme of the present invention to be described, is not intended to limit; Although with reference to previous embodiment the present invention is had been described in detail, those of ordinary skill in the art is to be understood that: it still can be made amendment to the technical scheme that aforementioned each embodiment puts down in writing, and perhaps part technical characterictic wherein is equal to replacement; And these modifications or replacement do not make the essence of appropriate technical solution break away from the spirit and scope of various embodiments of the present invention technical scheme.

Claims (7)

1. an Intranet server access method is characterized in that, comprising:
CGN equipment receives the internal server solicitation message that the Intranet user terminal sends, described internal server solicitation message comprises: the private network IP address of described Intranet user terminal, and application port sign and the application transport agreement corresponding with the network application of described internal server opening;
Described CGN equipment disposes public network IP address and the public network port-mark corresponding with described private network IP address, described application port sign and described application transport agreement, and stores configuration information into the internal server access list;
Comprise purpose IP address when what described CGN equipment received that the external user terminal sends, during the access to netwoks message of destination interface sign and host-host protocol, determine whether have with described purpose IP the address in the described internal server access list, the first configuration information of described destination interface sign and described host-host protocol coupling, described the first configuration information comprises: the first private network IP address, the corresponding relation of the first application port sign and the first application transport agreement and the first public network IP address and the first public network port-mark, wherein, described the first application port sign is identical with described destination interface sign, described the first application transport agreement is identical with described host-host protocol, and described the first public network IP address is identical with described purpose IP address;
If described CGN equipment determines to have described the first configuration information, then use the port corresponding with described the first public network port-mark to interior network server corresponding to described the first private network IP address on, identify the corresponding described access to netwoks message of port repeat with described the first application port.
2. Intranet server access method according to claim 1, it is characterized in that whether having the first configuration information that mates with described purpose IP address, described destination interface sign and described host-host protocol in described definite described internal server access list and comprise:
Inquire about the configuration information in the described internal server access list, judge whether to have first public network IP address identical with described purpose IP address, if judge whether to have with application port sign corresponding to described the first public network IP address and host-host protocol to identify first application port identical with described host-host protocol with described destination interface and identify and the first application transport agreement.
3. Intranet server access method according to claim 1 and 2 is characterized in that described method also comprises:
If described CGN equipment determines not have described the first configuration information, then send the access to netwoks refuse information to described external user terminal.
4. a CGN equipment is characterized in that, comprising:
Receiver module, be used for receiving the internal server solicitation message that the Intranet user terminal sends, described internal server solicitation message comprises: the private network IP address of described Intranet user terminal, and application port sign and the application transport agreement corresponding with the network application of described internal server opening;
Configuration module is used for configuration public network IP address and the public network port-mark corresponding with described private network IP address, described application port sign and described application transport agreement, and stores configuration information into the internal server access list;
Enquiry module, be used for comprising purpose IP address when what receive that the external user terminal sends, during the access to netwoks message of destination interface sign and host-host protocol, determine whether have with described purpose IP the address in the described internal server access list, the first configuration information of described destination interface sign and described host-host protocol coupling, described the first configuration information comprises: the first private network IP address, the corresponding relation of the first application port sign and the first application transport agreement and the first public network IP address and the first public network port-mark, wherein, described the first application port sign is identical with described destination interface sign, described the first application transport agreement is identical with described host-host protocol, and described the first public network IP address is identical with described purpose IP address;
Processing module, if be used for determining to have described the first configuration information, then use the port corresponding with described the first public network port-mark to interior network server corresponding to described the first private network IP address on, identify the corresponding described access to netwoks message of port repeat with described the first application port.
5. CGN equipment according to claim 4 is characterized in that, described enquiry module specifically is used for:
Inquire about the configuration information in the described internal server access list, judge whether to have first public network IP address identical with described purpose IP address, if judge whether to have with application port sign corresponding to described the first public network IP address and host-host protocol to identify first application port identical with described host-host protocol with described destination interface and identify and the first application transport agreement.
6. according to claim 4 or 5 described CGN equipment, it is characterized in that described processing module also is used for:
If determine not have described the first configuration information, then send the access to netwoks refuse information to described external user terminal.
7. an Intranet server access system is characterized in that, comprising: external user terminal and as the Intranet user terminal of internal server, and such as each described CGN equipment of claim 4 ~ 6.
CN2013100275758A 2013-01-24 2013-01-24 Method, equipment and system for accessing intranet server Pending CN103118147A (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN2013100275758A CN103118147A (en) 2013-01-24 2013-01-24 Method, equipment and system for accessing intranet server

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN2013100275758A CN103118147A (en) 2013-01-24 2013-01-24 Method, equipment and system for accessing intranet server

Publications (1)

Publication Number Publication Date
CN103118147A true CN103118147A (en) 2013-05-22

Family

ID=48416417

Family Applications (1)

Application Number Title Priority Date Filing Date
CN2013100275758A Pending CN103118147A (en) 2013-01-24 2013-01-24 Method, equipment and system for accessing intranet server

Country Status (1)

Country Link
CN (1) CN103118147A (en)

Cited By (22)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103841221A (en) * 2014-02-24 2014-06-04 华为技术有限公司 Strategy execution method, system and equipment, and control equipment
CN104219334A (en) * 2013-05-30 2014-12-17 中国联合网络通信集团有限公司 User tracing method and device and broadband access server
CN105049541A (en) * 2014-04-17 2015-11-11 财团法人资讯工业策进会 Network address translation traversal system and method for real-time communications
CN106506297A (en) * 2016-11-18 2017-03-15 杭州华三通信技术有限公司 A kind of control method of flowing of access and device
CN106550041A (en) * 2016-11-09 2017-03-29 浙江和仁科技股份有限公司 A kind of medical information integration engine
CN106559509A (en) * 2015-09-30 2017-04-05 中国电信股份有限公司 Registration server, CGN equipment, service provider system and index, retransmission method
CN106790764A (en) * 2017-01-24 2017-05-31 广州捷轻信息技术有限公司 A kind of method and system based on outer net port locations IP address of internal network
CN106921528A (en) * 2017-05-09 2017-07-04 深信服科技股份有限公司 A kind of branch equipment configures system
CN107018154A (en) * 2017-05-31 2017-08-04 南京燚麒智能科技有限公司 A kind of router and method for routing for being used to connect Intranet and outer net based on application layer
CN107018155A (en) * 2017-05-31 2017-08-04 南京燚麒智能科技有限公司 A kind of outer net terminal security accesses the method and system of the specific data of Intranet
CN108696546A (en) * 2017-02-15 2018-10-23 中兴通讯股份有限公司 A kind of method and device of the user terminal access public network of Enterprise Mobile private network
CN111131538A (en) * 2019-12-20 2020-05-08 国久大数据有限公司 Access control method and access control system
CN111371741A (en) * 2020-02-19 2020-07-03 中国平安人寿保险股份有限公司 Method and device for transmitting data of external network to internal network, computer equipment and storage medium
CN111385250A (en) * 2018-12-28 2020-07-07 浙江宇视科技有限公司 Safe access method and system for equipment port
CN111814084A (en) * 2020-06-18 2020-10-23 北京天空卫士网络安全技术有限公司 Data access management method, device and system
CN112087596A (en) * 2019-06-14 2020-12-15 杭州海康威视系统技术有限公司 Method for determining media stream transmission mode and media stream transmission system
CN113794788A (en) * 2021-09-14 2021-12-14 北京百度网讯科技有限公司 Gateway diversion method, system, device, equipment, storage medium and product
CN113973006A (en) * 2021-09-18 2022-01-25 重庆云华科技有限公司 Intranet data access management method and system
CN114449027A (en) * 2021-12-20 2022-05-06 北京网神洞鉴科技有限公司 Remote evidence obtaining method and device, electronic equipment and storage medium
CN115834230A (en) * 2022-12-20 2023-03-21 天翼爱音乐文化科技有限公司 Internal network penetration configuration method, system, equipment and medium
WO2023246443A1 (en) * 2022-06-24 2023-12-28 中兴通讯股份有限公司 Information processing method, information processing system, information processing apparatus, and storage medium
CN115834230B (en) * 2022-12-20 2024-05-28 天翼爱音乐文化科技有限公司 Internal network penetration configuration method, system, equipment and medium

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1414746A (en) * 2002-05-15 2003-04-30 华为技术有限公司 Method of providing internal service apparatus in network for saving IP address
CN101262504A (en) * 2008-05-13 2008-09-10 杭州华三通信技术有限公司 A method, device and system for source and destination IP address translation
CN102148879A (en) * 2010-10-22 2011-08-10 华为技术有限公司 Port mapping method and device and communication system
CN102447630A (en) * 2011-12-28 2012-05-09 中兴通讯股份有限公司 Protocol message transmission method, home gateway and CGN (carrier grade network switch) device

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1414746A (en) * 2002-05-15 2003-04-30 华为技术有限公司 Method of providing internal service apparatus in network for saving IP address
CN101262504A (en) * 2008-05-13 2008-09-10 杭州华三通信技术有限公司 A method, device and system for source and destination IP address translation
CN102148879A (en) * 2010-10-22 2011-08-10 华为技术有限公司 Port mapping method and device and communication system
CN102447630A (en) * 2011-12-28 2012-05-09 中兴通讯股份有限公司 Protocol message transmission method, home gateway and CGN (carrier grade network switch) device

Cited By (35)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN104219334A (en) * 2013-05-30 2014-12-17 中国联合网络通信集团有限公司 User tracing method and device and broadband access server
CN104219334B (en) * 2013-05-30 2017-09-29 中国联合网络通信集团有限公司 User's source tracing method, device and BAS Broadband Access Server
CN103841221A (en) * 2014-02-24 2014-06-04 华为技术有限公司 Strategy execution method, system and equipment, and control equipment
WO2015124043A1 (en) * 2014-02-24 2015-08-27 华为技术有限公司 Policy enforcement method, system and device, and control device
CN103841221B (en) * 2014-02-24 2018-01-02 华为技术有限公司 Policy execution method, system, strategy execution equipment and control device
CN105049541A (en) * 2014-04-17 2015-11-11 财团法人资讯工业策进会 Network address translation traversal system and method for real-time communications
CN105049541B (en) * 2014-04-17 2018-06-22 财团法人资讯工业策进会 For the network address conversion penetrating system and method for real-time Communication for Power
CN106559509A (en) * 2015-09-30 2017-04-05 中国电信股份有限公司 Registration server, CGN equipment, service provider system and index, retransmission method
CN106559509B (en) * 2015-09-30 2019-10-22 中国电信股份有限公司 Registration server, CGN equipment, service provider system and index, retransmission method
CN106550041B (en) * 2016-11-09 2020-02-28 浙江和仁科技股份有限公司 Medical information integration engine
CN106550041A (en) * 2016-11-09 2017-03-29 浙江和仁科技股份有限公司 A kind of medical information integration engine
CN106506297A (en) * 2016-11-18 2017-03-15 杭州华三通信技术有限公司 A kind of control method of flowing of access and device
CN106790764A (en) * 2017-01-24 2017-05-31 广州捷轻信息技术有限公司 A kind of method and system based on outer net port locations IP address of internal network
CN108696546A (en) * 2017-02-15 2018-10-23 中兴通讯股份有限公司 A kind of method and device of the user terminal access public network of Enterprise Mobile private network
CN106921528A (en) * 2017-05-09 2017-07-04 深信服科技股份有限公司 A kind of branch equipment configures system
CN107018155B (en) * 2017-05-31 2020-06-19 南京燚麒智能科技有限公司 Method and system for safely accessing specific data of intranet by extranet terminal
CN107018154A (en) * 2017-05-31 2017-08-04 南京燚麒智能科技有限公司 A kind of router and method for routing for being used to connect Intranet and outer net based on application layer
CN107018155A (en) * 2017-05-31 2017-08-04 南京燚麒智能科技有限公司 A kind of outer net terminal security accesses the method and system of the specific data of Intranet
CN107018154B (en) * 2017-05-31 2020-06-05 南京燚麒智能科技有限公司 Router and routing method for connecting intranet and extranet based on application layer
CN111385250A (en) * 2018-12-28 2020-07-07 浙江宇视科技有限公司 Safe access method and system for equipment port
CN111385250B (en) * 2018-12-28 2022-07-19 浙江宇视科技有限公司 Safe access method and system for equipment port
CN112087596A (en) * 2019-06-14 2020-12-15 杭州海康威视系统技术有限公司 Method for determining media stream transmission mode and media stream transmission system
CN112087596B (en) * 2019-06-14 2023-03-14 杭州海康威视系统技术有限公司 Method for determining media stream transmission mode and media stream transmission system
CN111131538A (en) * 2019-12-20 2020-05-08 国久大数据有限公司 Access control method and access control system
CN111131538B (en) * 2019-12-20 2022-07-22 国久大数据有限公司 Access control method and access control system
CN111371741A (en) * 2020-02-19 2020-07-03 中国平安人寿保险股份有限公司 Method and device for transmitting data of external network to internal network, computer equipment and storage medium
CN111371741B (en) * 2020-02-19 2024-04-26 中国平安人寿保险股份有限公司 Method, device, computer equipment and storage medium for transmitting external network data to internal network
CN111814084A (en) * 2020-06-18 2020-10-23 北京天空卫士网络安全技术有限公司 Data access management method, device and system
CN113794788B (en) * 2021-09-14 2023-07-25 北京百度网讯科技有限公司 Gateway diversion method, system, device, equipment, storage medium and product
CN113794788A (en) * 2021-09-14 2021-12-14 北京百度网讯科技有限公司 Gateway diversion method, system, device, equipment, storage medium and product
CN113973006A (en) * 2021-09-18 2022-01-25 重庆云华科技有限公司 Intranet data access management method and system
CN114449027A (en) * 2021-12-20 2022-05-06 北京网神洞鉴科技有限公司 Remote evidence obtaining method and device, electronic equipment and storage medium
WO2023246443A1 (en) * 2022-06-24 2023-12-28 中兴通讯股份有限公司 Information processing method, information processing system, information processing apparatus, and storage medium
CN115834230A (en) * 2022-12-20 2023-03-21 天翼爱音乐文化科技有限公司 Internal network penetration configuration method, system, equipment and medium
CN115834230B (en) * 2022-12-20 2024-05-28 天翼爱音乐文化科技有限公司 Internal network penetration configuration method, system, equipment and medium

Similar Documents

Publication Publication Date Title
CN103118147A (en) Method, equipment and system for accessing intranet server
CN103200281A (en) Method, device and system for accessing intranet server
CN102291320B (en) MAC (media access control) address learning method and edge device
CN102215273B (en) Method and device for providing external network access for internal network user
EP2544402A1 (en) Method for obtaining dns and tunnel gateway device
CN103200209A (en) Access method of member resources, group server and member devices
CN102148879A (en) Port mapping method and device and communication system
CN101800690B (en) Method and device for realizing source address conversion by using address pool
CN107580079A (en) A kind of message transmitting method and device
CN104333610A (en) IPv6 address allocation method and device
CN112437168B (en) Intranet penetration system
CN102820977A (en) Multicast method, multicast device and network device
CN103618801A (en) Method, device and system for sharing P2P (Peer-to-Peer) resources
CN106411742B (en) A kind of method and apparatus of message transmissions
CN101771732A (en) Message processing method, device and network equipment
CA2770391C (en) System and method for sharing a payload among multiple homed networks
CN102857547B (en) The method and apparatus of distributed caching
CN102611623B (en) Port configuration processing method, port configuration processing device and port configuration processing system on basis of network access
CN104202398A (en) Remote control method, device and system
CN104253878A (en) VLAN (Virtual Local Area Network) information management system and method of DHCP (Dynamic Host Configuration Protocol) RELAY termination sub-interface
CN102594886A (en) Method and device for direct communication between browsers, and communication system
CN102143241A (en) Access method, device and system between hosts
CN103973753B (en) A kind of method and apparatus of data processing
CN104735073B (en) IPv4-IPv6 transition protocols dispatching method and device
CN102316176B (en) Packet processing and tracing methods, apparatuses thereof and systems thereof

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
C12 Rejection of a patent application after its publication
RJ01 Rejection of invention patent application after publication

Application publication date: 20130522