WO2010099680A1 - 私网用户对同侧私网设备访问的实现方法及系统 - Google Patents

私网用户对同侧私网设备访问的实现方法及系统 Download PDF

Info

Publication number
WO2010099680A1
WO2010099680A1 PCT/CN2009/073533 CN2009073533W WO2010099680A1 WO 2010099680 A1 WO2010099680 A1 WO 2010099680A1 CN 2009073533 W CN2009073533 W CN 2009073533W WO 2010099680 A1 WO2010099680 A1 WO 2010099680A1
Authority
WO
WIPO (PCT)
Prior art keywords
access
private network
information
gateway
user
Prior art date
Application number
PCT/CN2009/073533
Other languages
English (en)
French (fr)
Inventor
蒋伟
Original Assignee
中兴通讯股份有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 中兴通讯股份有限公司 filed Critical 中兴通讯股份有限公司
Publication of WO2010099680A1 publication Critical patent/WO2010099680A1/zh

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/10Network architectures or network communication protocols for network security for controlling access to devices or network resources
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L61/00Network arrangements, protocols or services for addressing or naming
    • H04L61/09Mapping addresses
    • H04L61/25Mapping addresses of the same type
    • H04L61/2503Translation of Internet protocol [IP] addresses
    • H04L61/2514Translation of Internet protocol [IP] addresses between local and global IP addresses

Definitions

  • the present invention relates to the field of access technologies in the field of computer network communication, and in particular, to a method and system for implementing public network access of a private network device on a private network under a gateway.
  • BACKGROUND With the continuous development of the Internet and its application technologies, people have gained more and more applications and monthly services through the Internet. As a gateway to people's access to the Internet, gateways are also becoming more and more popular. The emergence of the gateway makes the network private and public, that is, the private network and the public network. The private network is located inside the gateway and is the network environment protected by the gateway. Since the networking information inside the private network is blocked by the gateway, the information is not known to users outside the private network, and thus the network security of the private network is high.
  • NAT Network Address Translation
  • the networking technologies provided by the gateway are generally implemented in the following scenarios: private network devices, gateways, and public network users.
  • Private network devices are network service devices that provide services.
  • the access requirement in the networking scenario is that the public network user can access the private network device.
  • the solution is as follows: The public network user accesses the public network address on the gateway or the public network address through the NAT technology provided by the gateway.
  • the service port is mapped to access to the private network device on the private network or the network monthly service provided on the private network device.
  • the networking scenarios include: private network users, private network devices, gateways, and public network users.
  • the networking scenario is the networking scenario where the private network accesses the public network and then maps to the private network.
  • the access requirements in the networking scenario are as follows:
  • the private network user implements public network access to the peer private network device.
  • private network users on the private network want to access the location The same private network device or different private network devices on the same gateway, and the network services provided by the same private network device or different private network devices.
  • the private network user does not know the private network address information of the network service, or the networking.
  • the private network user is not allowed to access the private network device by bypassing the gateway. Therefore, the private network user wants to access the private network device indirectly through access to the public network of the gateway.
  • the main object of the present invention is to provide a method and a system for implementing a private network user to access a private network device on the same side, which is used to meet the requirement of a private network user to implement public network access to the private network device on the same side. Enables users on the private network to access the private network devices on the same side by accessing the public network of the gateway.
  • a method for implementing access to a peer private network device by a private network user includes: configuring the access rule configuration information by the gateway; the access rule configuration information includes: the private network user accessing the public network of the same side by accessing the public network of the gateway The gateway controls the private network user to access the peer private network device according to the access rule configuration information.
  • the configuration requirement of the foregoing access rule configuration information is derived from: a user and/or an operator.
  • the gateway configuration access rule configuration information includes: actively sending the access rule configuration information to the gateway in the form of a configuration file, the gateway parsing the configuration file, obtaining the access rule configuration information, and configuring; or, the gateway is from the user and/or the operation.
  • the commerce department passively obtains access rule configuration information and configures it; or, the gateway dynamically generates access rule configuration information according to network networking conditions and configures it.
  • the foregoing access rule configuration information further includes: private network user information, public network information, and ipsilateral private network device information; There is a mapping relationship between the private network user information, the public network information, and the peer-side private network device information.
  • the mapping relationship is in the form of all data structures of the identifier mapping relationship, including a table or an array.
  • the private network user information is the information that uniquely identifies the private network user, and includes: the address information of the private network user or the access device information of the private network user; the public network information is a public network that uniquely identifies the public network.
  • the information includes: the public network access address information, or the protocol information and port information used by the private network user to access the public network to access the access packets of the peer private network device;
  • the information about the services provided by the network device or the private network device including: address information of the private network device, or related information of the service provided on the private network device.
  • the gateway controls the access of the private network user to the peer private network device according to the access rule configuration information.
  • the gateway obtains the access message from the private network user, extracts the valid information in the access message, and matches the valid information with the access rule configuration information; if the matching access rule configuration information is retrieved, B is executed; End the current control of the private network user to access the peer private network device;
  • the gateway uses the matching access rule configuration information to modify the address information forwarded by the network address translation NAT mechanism, and controls the access to the public network, and then forwards it to the public network.
  • Side private network equipment The valid information is information that uniquely identifies the access message, and includes: media access control address information of the access message, source address information/destination address information of accessing the message, and access device information of the access message. Accessing the field information of the configuration information carried in the dynamic host configuration protocol of the 4 ⁇ ⁇ , or accessing the domain name information accessed by the ⁇ ; The access message is: the private network user requests to access the public network to access the same side private network. Access to the device is 4 texts.
  • the source address information of the access information in the valid information is specifically the address information of the private network user, and the destination address information is the public network access address information.
  • the matching access rule configuration information includes: Address information, public network access address information, and address information of the private network device;
  • Step B is specifically: Bl, before the route, through the NAT mechanism, the gateway will change the destination address information of the access message to the address information of the private network device;
  • the gateway determines that the access packet needs to be forwarded to the peer private network device.
  • the gateway uses the NAT mechanism to access the source address information of the packet as the public network access address information.
  • the routing mechanism forwards the access message after the source address information and the destination address information are modified to the peer-side private network device.
  • the access rule configuration information is further updated according to the networking mode and the service mode; the update is manually updated in a static manner or automatically updated in a dynamic manner.
  • an implementation system for a private network user to access a peer private network device includes: a configuration unit and a control unit, where the configuration unit is configured to configure access rule configuration information for the gateway; and the control unit is configured to configure the gateway according to the access rule Information that controls private network users to access peer-to-peer private network devices.
  • the configuration unit is further configured to actively send the access rule configuration information to the gateway in the form of a configuration file, and the gateway parses the configuration file to obtain the access rule configuration information and configures; or, the gateway is passive from the user and/or the operator. Obtain the access rule configuration information and configure it. Alternatively, the gateway dynamically generates access rule configuration information according to the network networking status and configures it. The invention configures and saves the access rule configuration information at the gateway.
  • the access rule configuration information includes: The private network user accesses the public network of the gateway to access the information of the peer private network device. The gateway controls the private network user to access the private network device on the same side of the private network user according to the access rule configuration information.
  • the NAT mechanism provided by the gateway itself is used to modify the address information of the packet to and from the round-trip, and the access packet of the private network user is controlled according to the access rule.
  • the correct round-trip path of the configuration information is forwarded to the public network through the routing mechanism provided by the gateway itself, and then forwarded by the public network to the private network device on the same side of the private network user.
  • the access of the private network user is as follows: The private network user requests access to the public network to access the access packets of the peer private network device.
  • the private network user can be controlled to request the access to the peer-side private network device to be forwarded and transmitted according to the correct round-trip path, which satisfies the realization of the private network user.
  • the requirement for the public network access of the private network device enables the users on the private network to access the private network devices on the same side by accessing the public network of the gateway.
  • FIG. 1 is a schematic diagram of an implementation process of a method according to the present invention
  • FIG. 2 is a schematic diagram of a networking structure of an example of a networking scenario used in the present invention
  • FIG. 3 is a schematic flowchart of an implementation of a method according to an embodiment of the present invention.
  • DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENT The present invention implements the access rule configuration information of the peer-side private network device by accessing the public network of the gateway according to the private network user, and the gateway controls and implements the private network user to the same side of the private network user. Access to private network devices.
  • FIG. 1 is a flow chart of implementing private network users accessing devices on the same side of the private network.
  • Step 101 Initialize the gateway, and construct a networking environment of the private network and the public network.
  • the gateway is the only channel through which the private network and the public network connected to the gateway communicate with each other. That is, all private network users and private network devices on the private network side finally communicate with the public network through the gateway.
  • the gateway For a private network located on the inside of the gateway, the gateway provides at least one private network access point. Normally, multiple private network access points can be provided. Private network users and private networks on the private network side of the private network access point. The device accesses the gateway.
  • the private network access point is configured with the private network address information provided by the gateway for the private network user and the private network device.
  • the gateway can support multiple subnetting functions of the private network.
  • the gateway externally blocks the networking information of the private network.
  • For the public network located outside the gateway at least one public network access point for accessing the outside world can be established on the gateway.
  • multiple public network access points can be provided, and at least one public access point is set on the public network access point.
  • the gateway itself provides a route forwarding mechanism to implement packet routing and forwarding.
  • the gateway itself also provides a NAT mechanism, which can implement address translation of source address information and destination address information of packets.
  • the source address information may be information in the address plus port format, and the destination address information may also be information in the address port format.
  • private network users refer to: Any network device that can work on the Internet is a client role in the client/server model.
  • a private network device refers to: Any network device that can work on the Internet is a server role in the client/server model.
  • the private network user and the private network device can be located on the same subnet of the same private network or on different subnets of the same private network.
  • the so-called private network on the same side means that both the private network user and the private network device are connected to each other through the public network connected to the outside by the same gateway and gateway.
  • the private network user does not require or can directly access the private network device.
  • the private network user knows the public network address of the gateway.
  • Step 102 The gateway configures the access rule configuration information and saves the information on the gateway.
  • the access rule configuration information includes: The private network user accesses the public network of the gateway to access the information of the private network device on the same side of the private network.
  • the specific implementation process of the gateway configuring the access rule configuration information includes the following three manners.
  • the first mode is as follows: The user and/or the operator actively obtain the access rule configuration information and send it to the gateway in the form of a configuration file. The gateway parses the configuration file, obtains the access rule configuration information, and configures.
  • the second way is: The gateway passively obtains access rule configuration information from the user and/or the operator through the network and configures.
  • the third mode is as follows: The gateway dynamically generates access rule configuration information according to network networking conditions and configures it.
  • the networking situation described in the third mode refers to: the networking situation of the network where the gateway is located, such as the network device environment of the attached network or the routing information on the gateway.
  • the specific processing procedure for the gateway to dynamically generate the access rule configuration information according to the network networking condition is as follows: The gateway can know the user information of the connected user through its own dynamic host configuration (DHCP, Dynamic Host Configuration Protocol) monthly service. The address information of the attached device and the capability information of the devices that can provide the monthly service.
  • DHCP Dynamic Host Configuration Protocol
  • the gateway can associate the connected user with the attached device accordingly. Dynamically formulate or adjust the corresponding access rule configuration information.
  • the configuration requirements of the access rule configuration information are derived from: a user and/or an operator.
  • the access rule configuration information further includes: private network user information, public network information, and private network device information; private network user information, public network information, and private network device information have a mapping relationship, and the performance of the mapping relationship All forms of data structures in the form of identity mappings, including tables or arrays.
  • the private network user information is information that uniquely identifies the private network user, including: address information of the private network user, or access device information of the private network user.
  • the public network information is the public network information that uniquely identifies the public network, including: the public network access address information, or the protocol information used by the private network user to access the public network to access the access packets of the peer private network device. Port information.
  • the private network device information is information that uniquely identifies the service provided by the private network device or the private network device, and includes: address information of the private network device, or related information about the service provided on the private network device.
  • the information about the service provided on the private network device may be protocol information and port information of the service.
  • Step 103 The gateway controls the private network user to access the private network device on the same side of the private network user according to the access rule configuration information.
  • the access rule configuration information is updated according to the networking mode and the service mode, and the update is manually updated in a static manner or automatically updated in a dynamic manner; the gateway controls the private network user according to the updated access rule configuration information. Access to the private network device on the same side of the private network user.
  • the update adopts the static mode it can be manually updated by manual configuration;
  • the new dynamic mode it can be automatically updated based on changes in the network environment.
  • the automatic update based on the change of the network environment includes: adding or deleting update of the access rule brought by the online or offline of the device in the network; updating the content of the access rule brought by the service on the device in the network or the like, and the like.
  • Step 1031 The gateway obtains the access packet from the private network user, and extracts the valid information in the access packet.
  • the valid information is matched with the access rule configuration information. If the matching access rule configuration information is retrieved, step 1032 is performed; otherwise, the current private network user is controlled to access the private network device.
  • the valid information is information that uniquely identifies the access message, and includes: accessing media access control (MAC, Media Access Control) address information, accessing source address information/destination address information, accessing The access device information of the packet, the field information of the DHCP Option for accessing the packet, or the domain name information accessed by the access packet.
  • MAC media access control
  • the DHCP Option is a set of configuration information carried in the dynamic host configuration protocol.
  • the access message is: The private network user requests access to the public network to access the access packet of the peer private network device.
  • Step 1032 Corresponding to the matching access rule configuration information, the NAT mechanism provided by the gateway itself is used to modify the address information of the access packet, and the gateway control access message is forwarded to the public network according to the matching access rule configuration information. And then forwarded by the public network to the private network device on the same side of the private network user.
  • step 1031 when the source address information of the access information in the valid information is specifically the address information of the private network user, the destination address information is the public network access address information; and the matching access rule configuration information is: User address information, public network access address information, and address information of the private network device; then step 1032 is specifically (step 10321 - step 10324): Step 10321, before routing, through the NAT mechanism provided by the gateway itself, the gateway will access The destination address information of the packet is modified as: The address information of the private network device in the matching access rule configuration information. Step 10322: The gateway determines that the access packet needs to be forwarded to the private network device through the routing mechanism provided by the gateway itself.
  • Step 10323 After the route is forwarded and the access packet is forwarded, the NAT machine provided by the gateway itself is used.
  • the gateway modifies the source address information of the access packet to: public network access address information in the matching access rule configuration information.
  • Step 10324 The gateway forwards the access message after the source address information and the destination address information are modified to the private network device by using the routing mechanism provided by the gateway.
  • FIG. 2 is a schematic diagram of a networking structure of an example of a networking scenario used in the present invention.
  • gateway 41 and Public network 61 including: private network user 11 and private network device 21 on the same subnet of the same private network, private network user 12 and private network device 22 under different subnets of the same private network, gateway 41 and Public network 61.
  • the public network is the Internet.
  • both the private network user 11 and the private network device 21 access the gateway 41 through the private network access point 31; the private network user 12 accesses the gateway 41 through the private network access point 32; and the private network device 22 accesses the private network access point.
  • 33 access gateway 41.
  • the gateway 41 is connected to the public network 61, and two public network access points that access the outside world are established on the gateway 41, and are identified by 51 and 52, respectively.
  • Step 201 The gateway 41 is initialized to construct a networking environment of the private network and the public network 61.
  • the private network access point is usually provided with a private network address information provided by the gateway for the private network user and the private network device. At least one public network address information is set on the network access point.
  • the gateway 41 is activated, and the gateway 41 accesses all private network users and private network devices; around the gateway 41, the gateway 41 establishes public network address information on all public network access points, and on all private networks.
  • the private network address information is set up on the access point to establish a complete private network and public network networking environment.
  • Step 202 After the gateway 41 is initialized and a complete networking environment is established, the access rules of the private network device can be accessed by configuring the private network user to access the public network address of the gateway on the gateway 41 according to the requirements of the user or the operator.
  • Configuration information may be an access rule configuration table, and includes multiple entries. After the access gateway obtains the access message of the private network user, the subsequent entries in the access rule configuration table are retrieved. If the matching entry is retrieved, the address information of the access message is modified by the NAT mechanism according to the content of the entry.
  • Step 203 The private network user 11 sends an access message.
  • the access message is used by: the private network user 11 accesses the public network access point 51 of the gateway 41.
  • the public network access address information further implements access to the private network device 21.
  • the address information further implements access to the private network device 21; here, the access information refers to the original access 4, that is, the access to the gateway.
  • the valid information of the access message includes: source address information of the access message and destination address information of the access message.
  • the source address information of the access message is: address information of the private network user 11; the destination address information of the access message is: public network access address information of the public network access point 51.
  • Step 205 retrieve each entry in the access rule configuration table, and find an entry that matches the valid information of the access message.
  • Step 206 Configure the access rule according to the matching entry found in step 205, and pass the gateway.
  • the NAT mechanism the gateway changes the destination address information of the access device, and is modified to match the address information of the service 1 of the private network device 21 described by the entry; it should be noted that the private network device and the private network device provide The service is a one-to-many relationship, that is, multiple services can be provided on a private network device.
  • the access rule configuration table includes three items, and the three items have a mapping relationship.
  • the first item is the address information of the private network user;
  • the second item is the public network access address information;
  • the third item is the address information of the monthly service provided on the private network device.
  • Step 1 Step 207: The routing mechanism of the gateway itself determines that the access packet will be sent to the private The network device 21; Step 208: After determining the route direction of the access message, and before the access is actually sent, according to the access rule configuration described by the matching entry found in step 205, the NAT mechanism is modified through the gateway. Accessing the source address information of the packet, and modifying the public network access address information of the public network access point 51 described by the matching entry; Step 209: Passing the access packet after modifying the source address information and the destination address information The routing mechanism on the gateway is sent to the private network device 21; Step 210, the interaction between the subsequent private network user 11 and the private network device 21 continues to be configured according to the access rules described in the matching entry found in step 205.
  • the private network user 11 accesses the public network access address information of the public network access point 51 of the gateway 41 to implement access to the private network.
  • the processing can be performed by using the technical principles disclosed in the technical solutions of steps 201 to 210 above, and is not specifically described herein. According to an embodiment of the present invention, an implementation system for accessing a peer private network device by a private network user is also provided.
  • An implementation system for accessing a peer private network device by a private network user includes: a configuration unit and a control unit.
  • the configuration unit is configured to configure access rule configuration information for the gateway.
  • the control unit is connected to the configuration unit.
  • the control unit is configured to control the access of the private network to the private network device on the private network.
  • the configuration unit is further configured to actively send the access rule configuration information to the gateway in the form of a configuration file, and the gateway parses the configuration file to obtain the access rule configuration information and configures.
  • the gateway passively obtains access rule configuration information from the user and/or the operator and configures it.
  • the gateway dynamically generates access rule configuration information according to the network networking situation and configures it.
  • the embodiment of the present invention is based on the access rule configuration information, and the NAT mechanism provided by the gateway itself is used to modify the address information of the packet to and from the round-trip, and the access packet of the private network user is controlled according to the access rule configuration information.
  • Correct round-trip path, routing mechanism provided by the gateway itself The packet is forwarded to the public network first, and then forwarded by the public network to the private network device on the same side of the private network user.
  • the access of the private network user is as follows: The private network user requests access to the public network to access the access packets of the peer private network device.
  • the packet of the private network user can be controlled to be forwarded and transmitted according to the correct round-trip path, which satisfies the private network user.
  • the access to the private network device on the same side is achieved by accessing the public network of the gateway.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Hardware Design (AREA)
  • Computer Security & Cryptography (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

FIG. 1 : 101 A GATEWAY INITIATES AND BUILDS NETWORKING ENVIRONMENT OF A PRIVATE NETWORK AND A PUBLIC NETWORK 102 THE GATEWAY CONFIGURES CONFIGURATION INFORMATION OF ACCESS RULES AND STORES IT ON ON THE GATEWAY. THE CONFIGURATION INFORMATION OF ACCESS RULES INCLUDES INFORMATION OF ENABLING THE PRIVATE NETWORK USER TO ACCESS THE PRIVATE NETWORK DEVICE AT THE SAME SIDE OF THE PRIVATE NETWORK USER THROUGH ACCESSING A PUBLIC NETWORK OF THE GATEWAY 103 THE GATEWAY CONTROLS THE PRIVATE NETWORK USER AND ENABLES THE PRIVATE NETWORK USER TO ACCESS THE PRlVATE NETWORK DEVICE AT THE SAME SIDE OF THE PRIVATE NETWOR USER ACCORDING TO THE CONFIGURATION INFORMATION OF ACCESS RULES

Description

私网用户对同侧私网设备访问的实现方法及系统
技术领域 本发明涉及计算机网络通信领域的访问技术领域,尤其涉及一种网关下 私网用户对同侧私网设备公网化访问的实现方法及系统。 背景技术 随着互联网及其应用技术的不断发展 ,人们通过互联网获得了越来越丰 富的应用与月 务。 作为人们访问互联网的门户——网关, 也得到了越来越普 遍的使用。 网关的出现, 使得网络出现私用和公用之分, 即私网和公网之分。 私网位于网关的内侧, 是被网关所保护的网络环境。 由于私网内部的组 网信息被网关屏蔽, 因此这些信息是不被私网以外用户所知晓的, 从而私网 的网络安全性较高。 而公网则相反, 公网位于网关的外侧, 由于公网的组网 信息是开放的, 因此为所有用户所知晓, 从而公网的网络安全性较低。 由于 私网和公网的差别 , 越来越多的网络月 务被安置在位于私网一侧的私网设备 上, 并提供给外界访问。 一般的, 为了解决私网网络信息的私密性问题, 同 时也满足私网上的网络服务设备的可访问要求 ,网络地址转换( NAT , Network Address Translation )技术被普遍使用。 NAT技术是在网关上提供的技术, 通 过 NAT技术, 私网用户以外用户, 也可以理解为公网用户通过访问网关提供 的公网性的网络地址 , 就可以映射到网关内侧私网上提供服务的特定网络服 务设备, 从而实现私网设备的可访问性。 目前网关上提供的 NAT技术, 普遍解决的组网场景包括: 私网设备, 网关和公网用户 , 私网设备是提供服务的网络服务设备。 该组网场景下的访 问需求是公网用户实现私网设备的可访问性 , 其解决方案是: 公网用户通过 网关提供的 NAT技术, 访问网关上的公网地址、 或公网地址力口服务端口, 从 而映射到对私网上的私网设备或该私网设备上提供的网络月 务的访问。 然而, 以下的组网场景和需求, 目前的网关产品还无法解决。 组网场景 包括: 私网用户、 私网设备, 网关和公网用户, 该组网场景为私网访问公网 再映射到私网的组网场景。 该组网场景下的访问需求是: 私网用户实现对同 侧私网设备的公网化访问。 也就是说, 位于私网上的私网用户想要访问位于 同一网关内侧的相同私网设备或不同私网设备 , 以及相同私网设备或不同私 网设备所提供的网络服务; 而且, 由于私网用户不知道该网络服务的私网地 址信息、 或者组网场景不允许私网用户绕开网关直接地访问私网设备, 因此 私网用户希望通过访问网关的公网来间接地访问到该私网设备。 随着网络业 务的普及和发展, 这种私网访问公网再映射到私网的组网场景和访问需求将 会越来越普遍, 而对这种访问需求的解决, 也越来越有实际意义和迫切性。 发明内容 有鉴于此,本发明的主要目的在于提供一种私网用户对同侧私网设备访 问的实现方法及系统, 用于满足私网用户实现对同侧私网设备公网化访问的 需求, 使位于私网的用户通过访问网关的公网的方式实现对位于同侧私网设 备的访问。 为达到上述目的, 本发明的技术方案是这样实现的: 根据本发明的一个方面,提供了一种私网用户对同侧私网设备访问的实 现方法。 根据本发明的私网用户对同侧私网设备访问的实现方法, 包括: 网关配置访问规则配置信息; 访问规则配置信息包括: 私网用户通过访 问网关的公网来实现访问同侧私网设备的信息; 网关根据访问规则配置信息, 控制私网用户实现对同侧私网设备的访 问。 其中, 上述访问规则配置信息的配置需求来源于: 用户和 /或运营商。 其中 , 上述网关配置访问规则配置信息具体包括: 主动将访问规则配置 信息以配置文件的形式下发给网关, 网关解析配置文件, 获取访问规则配置 信息并配置; 或者, 网关从用户和 /或运营商处, 被动获取访问规则配置信息并配置; 或者, 网关根据网络组网情况动态生成访问规则配置信息并配置。 其中, 上述访问规则配置信息进一步包括: 私网用户信息、 公网信息和 同侧私网设备信息; 上述私网用户信息、公网信息、 和同侧私网设备信息三者之间存在映射 关系, 该映射关系的表现形式为标识映射关系的所有数据结构形式, 包括表 或数组。 其中, 上述私网用户信息为唯一标识所述私网用户的信息, 包括: 私网 用户的地址信息、 或私网用户的接入设备信息; 公网信息为唯一标识所述公网的公网信息, 包括: 公网接入地址信息、 或私网用户请求访问公网来实现访问同侧私网设备的访问报文所使用的协议 信息和端口信息; 同侧私网设备信息为唯一标识私网设备或所述私网设备上所提供服务 的信息, 包括: 私网设备的地址信息、 或私网设备上所提供服务的相关信息。 其中,上述网关根据访问规则配置信息控制私网用户实现对同侧私网设 备的访问具体为:
A、 网关从所述私网用户获取访问报文,提取出访问报文中的有效信息, 将该有效信息与访问规则配置信息匹配; 如果检索到匹配的访问规则配置信 息, 则执行 B; 否则, 结束当前控制私网用户实现对同侧私网设备的访问;
B、 网关才艮据匹配的访问规则配置信息, 通过网络地址转换 NAT 机制 修改访问 4艮文转发的地址信息, 控制访问 4艮文先转发到所述公网, 然后再由 公网转发到同侧私网设备。 其中, 上述有效信息为唯一标识所述访问报文的信息, 包括: 访问报文 的媒介访问控制地址信息、 访问 4艮文的源地址信息 /目的地址信息、 访问 4艮文 的接入设备信息、 访问 4艮文的动态主机配置协议中所携带配置信息的字段信 息、 或访问 4艮文所访问的域名信息; 上述访问报文为:私网用户请求访问公网来实现访问同侧私网设备的访 问 4艮文。 其中, 步骤 A 中, 有效信息中访问 4艮文的源地址信息具体为私网用户 的地址信息 , 目的地址信息为公网接入地址信息; 匹配的访问规则配置信息 具体包括: 私网用户的地址信息、 公网接入地址信息、 和私网设备的地址信 息; 则步骤 B具体为: Bl、 路由前, 通过 NAT机制, 网关将访问 4艮文的目的地址信息^ ·改为 私网设备的地址信息;
Β2、 通过路由机制, 网关确定需将访问报文转发到同侧私网设备上;
Β3、 路由后且转发访问报文前, 通过 NAT机制, 网关将访问报文的源 地址信息 4爹丈为公网接入地址信息;
B4、 通过路由机制, 网关将修改源地址信息和目的地址信息后的访问 报文转发到同侧私网设备上。 其中, 访问规则配置信息进一步根据组网方式以及业务方式进行更新; 更新以静态方式手动更新或者以动态方式自动更新。 根据本发明的另一个方面,还提供了一种私网用户对同侧私网设备访问 的实现系统。 根据本发明的私网用户对同侧私网设备访问的实现系统, 包括: 配置单 元和控制单元, 其中, 配置单元, 用于网关配置访问规则配置信息; 控制单元, 用于网关根据访问规则配置信息 , 控制私网用户实现对同侧 私网设备的访问。 其中, 上述配置单元, 进一步用于主动将访问规则配置信息以配置文件 的形式下发给网关, 网关解析配置文件, 获取访问规则配置信息并配置; 或 者, 网关从用户和 /或运营商处被动获取访问规则配置信息并配置; 或者, 网关根据网络组网情况动态生成访问规则配置信息并配置。 本发明在网关配置并保存访问规则配置信息, 该访问规则配置信息包 括: 私网用户通过访问网关的公网来实现访问同侧私网设备的信息。 网关才艮 据该访问规则配置信息,控制私网用户实现对私网用户同侧私网设备的访问。 由于本发明基于该访问规则配置信息 , 通过网关自身提供的 NAT机制 修改报文往返时的地址信息, 控制私网用户的访问报文按照符合该访问规则 配置信息的正确往返路径 , 通过网关自身提供的路由机制将报文先转发到公 网, 然后再由公网转发到私网用户同侧私网设备。 其中, 私网用户的访问 4艮 文为: 私网用户请求访问公网来实现访问同侧私网设备的访问报文。 因此, 采用本发明 , 根据网关上保存的访问规则配置信息 , 能控制私网用户请求实 现访问同侧私网设备的 4艮文按照正确的往返路径转发及传递, 满足了私网用 户实现对同侧私网设备公网化访问的需求, 使位于私网的用户通过访问网关 的公网的方式实现对位于同侧私网设备的访问。 本发明的其它特征和优点将在随后的说明书中阐述, 并且, 部分地从说 明书中变得显而易见, 或者通过实施本发明而了解。 本发明的目的和其他优 点可通过在所写的说明书、 权利要求书、 以及附图中所特别指出的结构来实 现和获得。 附图说明 此处所说明的附图用来提供对本发明的进一步理解 ,构成本申请的一部 分, 本发明的示意性实施例及其说明用于解释本发明, 并不构成对本发明的 不当限定。 在附图中: 图 1为本发明方法的实现流程示意图; 图 2为本发明所使用的组网场景一实例的组网结构示意图; 图 3为本发明一方法实施例的实现流程示意图。 具体实施方式 功能相无述 本发明实施例才艮据私网用户通过访问网关的公网来实现访问同侧私网 设备的访问规则配置信息, 网关控制并实现私网用户对私网用户同侧私网设 备的访问。 下面结合附图对技术方案的实施作进一步的详细描述。 根据本发明实施例,首先提供了一种私网用户对同侧私网设备访问的实 现方法。 图 1是私网用户对同侧私网设备访问的实现流程图。该流程的实现具体 包括以下步骤 (步骤 101 - 步骤 103 ): 步骤 101、 网关初始化, 并构建私网和公网的组网环境。 这里, 针对网关而言, 该网关是私网与网关所接入外界的公网进行沟通 的唯一通道, 即私网侧的所有私网用户和私网设备最终都通过该网关与公网 沟通。 针对位于网关内侧的私网而言, 网关上提供至少一个私网接入点, 正常 情况下可以提供多个私网接入点, 通过私网接入点私网侧的私网用户和私网 设备接入网关。 在私网接入点设置有网关为私网用户和私网设备所提供的私 网地址信息; 网关可以支持私网的多个子网划分功能; 网关对外屏蔽私网的 组网信息。 针对位于网关外侧的公网而言,网关上可以建立至少一个接入外界的公 网接入点, 正常情况下可以提供多个公网接入点, 公网接入点上设置有至少 一个公网地址信息。 网关自身提供路由转发机制实现报文的路由选择和转发。网关自身还提 供 NAT机制 , 可以实现报文的源地址信息与目的地址信息的地址转换功能。 源地址信息可以为地址加端口格式的信息 , 目的地址信息也可以为地址力口端 口格式的信息。 其中, #尤私网侧的私网用户和私网设备而言, 私网用户指: 任何可以工 作于互联网的网络设备 ,是客户端 /服务器模型中的客户端角色。私网设备指: 任何可以工作于互联网的网络设备 , 是客户端 /服务器模型中的服务器角色。 而且, 私网用户和私网设备既可以位于同侧私网的同一子网下, 又可以位于 同侧私网的不同子网下。 这里, 所谓同侧私网指: 私网用户和私网设备都是 通过同一个网关与网关所接入外界的公网相互联系的。 私网用户不要求或者 不可以直接访问私网设备; 而且私网用户知道网关的公网地址信息, 即私网 用户想要或者必须通过访问网关的公网地址的方式才能访问到私网设备。 步骤 102、 网关配置访问规则配置信息并保存在网关上; 该访问规则配 置信息包括: 私网用户通过访问网关的公网的方式实现访问私网用户同侧私 网设备的信息。 这里, 步骤 102中, 网关配置访问规则配置信息的具体实现过程包括以 下三种方式。 第一种方式为: 用户和 /或运营商主动^)夺访问规则配置信息以配 置文件的形式下发给网关, 网关解析配置文件, 获取访问规则配置信息并配 置。 第二种方式为: 网关通过网络从用户和 /或运营商处被动获取访问规则配 置信息并配置。 第三种方式为: 网关根据网络组网情况动态生成访问规则配 置信息并配置。 其中, 第三种方式中描述的组网情况指: 网关所处网络的组 网情况, 比如下挂的网络设备环境或网关上的路由信息等等。 而网关根据网 络组网情况动态生成访问规则配置信息的具体处理过程为: 网关通过其自身 的动态主机配置十办议 ( DHCP, Dynamic Host Configuration Protocol ) 月 务, 可以知道下挂用户的用户信息, 下挂设备的地址信息以及这些设备所能提供 月 务的能力信息。 继而, 网关据此可以将下挂用户与下挂设备进行关联。 动 态的制定或者调整对应的访问规则配置信息。 这里, 访问规则配置信息的配置需求来源于: 用户和 /或运营商。 这里, 访问规则配置信息进一步包括: 私网用户信息、 公网信息和私网 设备信息; 私网用户信息、 公网信息、 和私网设备信息这三者之间存在映射 关系 , 映射关系的表现形式为标识映射关系的所有数据结构形式 , 包括表或 数组。 这里, 私网用户信息为唯一标识所述私网用户的信息, 包括: 私网用户 的地址信息、 或私网用户的接入设备信息。 公网信息为唯一标识所述公网的 公网信息, 包括: 公网接入地址信息、 或私网用户请求访问公网来实现访问 同侧私网设备的访问报文所使用的协议信息和端口信息。 私网设备信息为唯 一标识所述私网设备或所述私网设备上所提供服务的信息, 包括: 私网设备 的地址信息、 或私网设备上所提供服务的相关信息。 其中, 私网设备上所提 供服务的相关信息可以为该服务的协议信息和端口信息。 步骤 103、 网关根据该访问规则配置信息, 控制私网用户实现对私网用 户同侧私网设备的访问。 步骤 103后还包括:访问规则配置信息根据组网方式以及业务方式进行 更新, 更新以静态方式手动更新或者以动态方式自动更新; 网关才艮据更新的 访问规则配置信息, 控制私网用户实现对私网用户同侧私网设备的访问。 其中, 当更新采用静态方式时, 可以采用人工配置方式手动更新; 当更 新采用动态方式时, 可以基于网络环境变化的自动更新。 这里, 基于网络环 境变化的自动更新包括: 网络中设备的上线或下线所带来访问规则的添加或 删除更新;网络中设备上的服务启用或终止所带来访问规则的内容更新等等。 以上由步骤 101〜步骤 103构成的技术方案中, 步骤 103的具体处理过 程包括 (步骤 1031 -步骤 1032 ): 步骤 1031、 网关从私网用户获取访问报文, 提取出访问报文中的有效 信息 , 将有效信息与访问规则配置信息匹配; 如果检索到匹配的访问规则配 置信息, 则执行步骤 1032; 否则, 结束当前控制私网用户实现对私网设备的 访问。 这里, 该有效信息为唯一标识所述访问报文的信息, 包括: 访问 4艮文的 媒介访问控制 (MAC, Media Access Control )地址信息、 访问 4艮文的源地址 信息 /目的地址信息、 访问报文的接入设备信息、 访问报文的 DHCP Option 的字段信息、 或访问 4艮文所访问的域名信息。 其中, DHCP Option是动态主 机配置协议中所携带的一组配置信息。 而且, 该访问 4艮文为: 私网用户请求 访问公网来实现访问同侧私网设备的访问报文。 步骤 1032、 相应于检索到匹配的访问规则配置信息, 通过网关自身提 供的 NAT机制修改访问报文转发的地址信息,网关控制访问报文根据检索到 匹配的访问规则配置信息, 先转发到公网, 然后再由公网转发到私网用户同 侧的私网设备。 这里, 步骤 1031 中, 当有效信息中访问 4艮文的源地址信息具体为私网 用户的地址信息 , 目的地址信息为公网接入地址信息; 检索到匹配的访问规 则配置信息包括: 私网用户的地址信息、 公网接入地址信息、 和私网设备的 地址信息; 则步骤 1032具体为 (步骤 10321 - 步骤 10324 ): 步骤 10321、 路由前, 通过网关自身提供的 NAT机制, 网关将访问报 文的目的地址信息修改为: 该匹配的访问规则配置信息中的私网设备的地址 信息。 步骤 10322、 通过网关自身提供的路由机制, 网关确定需将访问报文转 发到私网设备上。 步骤 10323、 路由后且转发访问报文前, 通过网关自身提供的 NAT机 制 , 网关将访问报文的源地址信息修改为: 该匹配的访问规则配置信息中的 公网接入地址信息。 步骤 10324、 通过网关自身提供的路由机制 , 网关将修改了源地址信息 和目的地址信息后的访问报文转发到私网设备上。 如图 2所示为本发明所使用的组网场景的一实例的组网结构示意图,图
2中 , 包括: 位于同侧私网的同一子网下的私网用户 11和私网设备 21 , 位于 同侧私网的不同子网下的私网用户 12和私网设备 22, 网关 41和公网 61。 公网即为互联网。 而且, 私网用户 11 和私网设备 21都通过私网接入点 31 接入网关 41; 私网用户 12通过私网接入点 32接入网关 41; 私网设备 22通 过私网接入点 33接入网关 41。 网关 41接入公网 61 , 而且网关 41上建立两 个接入外界的公网接入点 , 分别以 51和 52标识。 方法实施例: 参考图 2所示的组网结构示意图, 本方法实施例中, 私网 用户对同侧私网设备访问的实现流程如图 3所示, 包括以下步骤 (步骤 201 - 步骤 210 ): 步骤 201、 网关 41初始化, 构建私网和公网 61的组网环境; 这里 ,通常在私网接入点设置有网关为私网用户和私网设备所提供的私 网地址信息, 在公网接入点上设置有至少一个公网地址信息。 则当网关 41 初始化时, 网关 41启动, 网关 41接入所有的私网用户和私网设备; 围绕网 关 41 , 网关 41在所有公网接入点上建立公网地址信息, 以及在所有私网接 入点上建立私网地址信息 , 从而搭建好完备的私网和公网的组网环境。 步骤 202、 网关 41初始化完毕, 建立起完备的组网环境后, 按照用户 或者运营商要求, 在网关 41 上配置私网用户通过访问网关的公网地址的方 式从而可以访问私网设备的访问规则配置信息; 这里, 访问规则配置信息可以为访问规则配置表, 包含多个条目。 后续 网关获取私网用户的访问报文后 , 检索该访问规则配置表中的各个条目 , 如 果检索到匹配的条目 , 则按照条目中的内容, 通过 NAT机制对访问报文的地 址信息进行修改。 步骤 203、 私网用户 11发出访问 4艮文; 这里, 该访问报文用于: 私网用户 11访问网关 41的公网接入点 51的 公网接入地址信息进而实现访问私网设备 21。 步骤 204、 访问规则配置表开始工作, 检测步骤 203发出的访问报文 , 通过提取访问报文中的有效信息,以便于筛选出私网用户 11请求访问公网接 入点 51的公网接入地址信息进而实现访问私网设备 21的访问 4艮文; 这里, 该访问 4艮文指原始访问 4艮文, 即刚刚进入网关的访问 4艮文。 这里, 该访问报文的有效信息中包括: 该访问报文的源地址信息和该访 问 4艮文的目的地址信息。 且该访问 4艮文的源地址信息为: 私网用户 11的地址 信息; 该访问报文的的目的地址信息为: 公网接入点 51 的公网接入地址信 息。 步骤 205、 检索访问规则配置表中的各个条目 , 并找到与该访问报文的 有效信息相匹配的条目; 步骤 206、 根据步骤 205中所找到的匹配条目描述的访问规则配置, 通 过网关上的 NAT机制 , 网关对访问 4艮文的目的地址信息进行更改, 且修改为 匹配条目所描述的私网设备 21的服务 1的地址信息; 这里需要指出的是, 私网设备与私网设备所提供的服务是一对多的关 系, 即一个私网设备上可以提供多个服务。 则如以下的表 1所示为访问规则 配置表的一个示例 , 访问规则配置表包括三项内容, 这三项内容存在映射关 系。 表 1中, 由左至右, 第一项内容为私网用户的地址信息; 第二项内容为 公网接入地址信息; 第三项内容为私网设备上所提供月 务的地址信息。
Figure imgf000012_0001
表 1 步骤 207、 通过网关自身的路由机制, 会决定该访问报文将会发往该私 网设备 21 ; 步骤 208、 在决定了该访问报文的路由走向之后, 以及该访问真正发送 之前, 再次根据步骤 205中所找到的匹配条目描述的访问规则配置, 通过网 关上的 NAT机制 ,修改访问报文的源地址信息 , 且修改为匹配条目所描述的 公网接入点 51的公网接入地址信息; 步骤 209、 将修改了源地址信息和目的地址信息后的访问报文, 通过网 关上的路由机制 , 发送到私网设备 21; 步骤 210、 后续的私网用户 11与私网设备 21之间的交互 4艮文会继续依 据步骤 205 中所找到的匹配条目描述的访问规则配置, 以及网关上的 NAT 机制和路由机制, 进行 4艮文地址更改和转发处理,从而实现私网用户 11通过 访问网关 41的公网接入点 51的公网接入地址信息进而实现访问私网设备 21 上所提供服务的目的。 需要指出的是,私网用户 11访问除私网设备 21以外的其他私网设备或 私网设备上所提供的月 务, 以及私网用户 21 访问私网设备或私网设备上所 提供的服务,都可以采用以上步骤 201〜步骤 210构成的技术方案所揭示的技 术原理进行处理, 在此不 ^故具体阐述。 根据本发明的实施例,还提供了一种私网用户对同侧私网设备访问的实 现系统。 才艮据本发明的实施例的私网用户对同侧私网设备访问的实现系统 , 包 括: 配置单元和控制单元。 其中, 配置单元用于网关配置访问规则配置信息。 控制单元与配置单元相连, 控制单元用于网关根据访问规则配置信息, 控制 私网用户实现对私网同侧私网设备的访问。 这里, 配置单元, 进一步用于主动将访问规则配置信息以配置文件的形 式下发给网关, 网关解析配置文件, 获取访问规则配置信息并配置。 或者网 关从用户和 /或运营商处被动获取访问规则配置信息并配置。或者网关才艮据网 络组网情况动态生成访问规则配置信息并配置。 综上所述, 由于本发明实施例是基于该访问规则配置信息, 通过网关自 身提供的 NAT机制修改报文往返时的地址信息,控制私网用户的访问报文按 照符合该访问规则配置信息的正确往返路径, 通过网关自身提供的路由机制 将报文先转发到公网 , 然后再由公网转发到私网用户同侧私网设备。 其中, 私网用户的访问 4艮文为: 私网用户请求访问公网来实现访问同侧私网设备的 访问报文。 因此, 采用本发明实施例, 根据网关上保存的访问规则配置信息, 能控制私网用户请求实现访问同侧私网设备的报文按照正确的往返路径转发 及传递, 满足了私网用户实现对同侧私网设备公网化访问的需求, 使位于私 网的用户通过访问网关的公网的方式实现对位于同侧私网设备的访问。 以上所述, 仅为本发明的较佳实施例而已, 并非用于限定本发明的保护 范围, 对于本领域的技术人员来说, 本发明可以有各种更改和变化。 凡在本 发明的精神和原则之内, 所作的任何修改、 等同替换、 ?丈进等, 均应包含在 本发明的保护范围之内。

Claims

权 利 要 求 书
1. 一种私网用户对同侧私网设备访问的实现方法, 其特征在于, 该方法 包括:
网关配置访问规则配置信息; 所述访问规则配置信息包括: 私网 用户通过访问所述网关的公网来实现访问同侧私网设备的信息;
网关才艮据所述访问规则配置信息 , 控制所述私网用户实现对所述 同侧私网设备的访问。
2. 根据权利要求 1所述的方法, 其特征在于, 所述访问规则配置信息的 配置需求来源于: 用户和 /或运营商。
3. 根据权利要求 1所述的方法, 其特征在于, 所述网关配置访问规则配 置信息具体包括: 主动将所述访问规则配置信息以配置文件的形式下 发给所述网关 , 网关解析所述配置文件 , 获取访问规则配置信息并配 置; 或者,
网关从用户和 /或运营商处, 被动获取访问规则配置信息并配置; 或者,
网关根据网络组网情况动态生成访问规则配置信息并配置。
4. 根据权利要求 1所述的方法, 其特征在于, 所述访问规则配置信息进 一步包括: 私网用户信息、 公网信息和同侧私网设备信息;
所述私网用户信息、 所述公网信息、 和所述同侧私网设备信息三 者之间存在映射关系, 所述映射关系的表现形式为标识映射关系的所 有数据结构形式, 包括表或数组。
5. 根据权利要求 4所述的方法, 其特征在于 , 所述私网用户信息为唯一 标识所述私网用户的信息, 包括: 私网用户的地址信息、 或私网用户 的接入设备信息;
所述公网信息为唯一标识所述公网的公网信息, 包括: 公网接入 地址信息、 或私网用户请求访问公网来实现访问同侧私网设备的访问 •t艮文所使用的协议信息和端口信息;
所述同侧私网设备信息为唯一标识所述私网设备或所述私网设 备上所提供服务的信息, 包括: 私网设备的地址信息、 或私网设备上 所提供服务的相关信息。
6. 根据权利要求 1所述的方法, 其特征在于 , 所述网关根据访问规则配 置信息控制私网用户实现对所述同侧私网设备的访问具体为:
A、 网关从所述私网用户获取访问报文, 提取出所述访问报文中 的有效信息, 将所述有效信息与所述访问规则配置信息匹配; 如果检 索到匹配的访问规则配置信息, 则执行 B; 否则, 结束当前控制私网 用户实现对同侧私网设备的访问;
B、 网关根据所述匹配的访问规则配置信息, 通过网络地址转换 NAT机制修改访问报文转发的地址信息 , 控制访问报文先转发到所述 公网 , 然后再由公网转发到所述同侧私网设备。
7. 根据权利要求 6所述的方法, 其特征在于, 所述有效信息为唯一标识 所述访问报文的信息, 包括: 所述访问报文的媒介访问控制地址信息、 访问报文的源地址信息 /目的地址信息、 访问报文的接入设备信息、 访 问报文的动态主机配置协议中所携带配置信息的字段信息、 或访问报 文所访问的域名信息;
所述访问 4艮文为: 私网用户请求访问公网来实现访问同侧私网设 备的访问报文。
8. 根据权利要求 7所述的方法, 其特征在于, 步骤 A中, 所述有效信息 中访问 4艮文的源地址信息具体为私网用户的地址信息 , 目的地址信息 为公网接入地址信息; 所述匹配的访问规则配置信息具体包括: 私网 用户的地址信息、 公网接入地址信息、 和私网设备的地址信息; 则步 骤 B具体为:
B 1、 路由前, 通过 NAT机制 , 网关将访问 4艮文的目的地址信息 修改为所述私网设备的地址信息;
B2、 通过路由机制, 网关确定需将访问报文转发到同侧私网设备 上;
B3、 路由后且转发访问 4艮文前 , 通过 NAT机制 , 网关将访问 艮 文的源地址信息修改为所述公网接入地址信息;
B4、 通过路由机制, 网关将修改源地址信息和目的地址信息后的 访问报文转发到同侧私网设备上。
9. 根据权利要求 1至 8中任一项所述的方法, 其特征在于, 所述访问规 则配置信息进一步才艮据组网方式以及业务方式进行更新; 所述更新以 静态方式手动更新或者以动态方式自动更新。
10. 一种私网用户对同侧私网设备访问的实现系统, 其特征在于, 该系统 包括: 配置单元和控制单元; 其中,
配置单元, 用于网关配置访问规则配置信息;
控制单元, 用于网关根据所述访问规则配置信息 , 控制私网用户 实现对同侧私网设备的访问。
11. 根据权利要求 10所述的系统, 其特征在于, 所述配置单元, 进一步用 于主动将所述访问规则配置信息以配置文件的形式下发给所述网关 , 网关解析所述配置文件, 获取访问规则配置信息并配置; 或者,
网关从用户和 /或运营商处被动获取访问规则配置信息并配置;或 者,
网关根据网络组网情况动态生成访问规则配置信息并配置。
PCT/CN2009/073533 2009-03-06 2009-08-26 私网用户对同侧私网设备访问的实现方法及系统 WO2010099680A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN200910079705A CN101483657B (zh) 2009-03-06 2009-03-06 一种私网用户对同侧私网设备访问的实现方法及系统
CN200910079705.6 2009-03-06

Publications (1)

Publication Number Publication Date
WO2010099680A1 true WO2010099680A1 (zh) 2010-09-10

Family

ID=40880584

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2009/073533 WO2010099680A1 (zh) 2009-03-06 2009-08-26 私网用户对同侧私网设备访问的实现方法及系统

Country Status (2)

Country Link
CN (1) CN101483657B (zh)
WO (1) WO2010099680A1 (zh)

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN104468280A (zh) * 2014-12-19 2015-03-25 上海市共进通信技术有限公司 实现智能网关中下挂设备上下线状态快速侦测的方法
WO2022063121A1 (zh) * 2020-09-22 2022-03-31 华为云计算技术有限公司 一种基于私有网络的网络互通方法、设备以及计算机集群
CN114340046A (zh) * 2021-11-19 2022-04-12 南京瀚元科技有限公司 一种基于Android系统的多网卡设备组网通信方法

Families Citing this family (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101483657B (zh) * 2009-03-06 2012-10-10 中兴通讯股份有限公司 一种私网用户对同侧私网设备访问的实现方法及系统
CN102447747A (zh) * 2010-10-09 2012-05-09 中国移动通信集团公司 一种与私有网络的交互方法、装置及系统
CN105376309B (zh) * 2015-10-30 2021-08-13 青岛海尔智能家电科技有限公司 接入网关分配方法及装置
CN107547687B (zh) * 2017-08-31 2021-02-26 新华三技术有限公司 一种报文传输方法和装置
CN114007193B (zh) * 2021-12-31 2022-05-13 亿次网联(杭州)科技有限公司 一种分布式网络节点的通信方法和系统

Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101060493A (zh) * 2007-05-14 2007-10-24 中兴通讯股份有限公司 一种私网内用户通过域名访问私网内服务器的方法
CN101483657A (zh) * 2009-03-06 2009-07-15 中兴通讯股份有限公司 一种私网用户对同侧私网设备访问的实现方法及系统

Patent Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101060493A (zh) * 2007-05-14 2007-10-24 中兴通讯股份有限公司 一种私网内用户通过域名访问私网内服务器的方法
CN101483657A (zh) * 2009-03-06 2009-07-15 中兴通讯股份有限公司 一种私网用户对同侧私网设备访问的实现方法及系统

Cited By (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN104468280A (zh) * 2014-12-19 2015-03-25 上海市共进通信技术有限公司 实现智能网关中下挂设备上下线状态快速侦测的方法
CN104468280B (zh) * 2014-12-19 2018-04-06 上海市共进通信技术有限公司 实现智能网关中下挂设备上下线状态快速侦测的方法
WO2022063121A1 (zh) * 2020-09-22 2022-03-31 华为云计算技术有限公司 一种基于私有网络的网络互通方法、设备以及计算机集群
CN114340046A (zh) * 2021-11-19 2022-04-12 南京瀚元科技有限公司 一种基于Android系统的多网卡设备组网通信方法
CN114340046B (zh) * 2021-11-19 2024-03-29 南京瀚元科技有限公司 一种基于Android系统的多网卡设备组网通信方法

Also Published As

Publication number Publication date
CN101483657B (zh) 2012-10-10
CN101483657A (zh) 2009-07-15

Similar Documents

Publication Publication Date Title
WO2010099680A1 (zh) 私网用户对同侧私网设备访问的实现方法及系统
US20050240758A1 (en) Controlling devices on an internal network from an external network
JP5790775B2 (ja) ルーティング方法およびネットワーク伝送装置
WO2015117337A1 (zh) 网络规则条目的设置方法及装置
WO2010139238A1 (zh) 实现强制mac转发功能的方法和装置
Bjorklund A YANG data model for IP management
WO2005027438A1 (ja) パケット中継装置
KR20060044435A (ko) 이동 컴퓨팅 장치를 위한 가상사설망 구조 재사용
WO2016192608A2 (zh) 身份认证方法、身份认证系统和相关设备
WO2015109478A1 (zh) 实现arp的方法、交换设备及控制设备
JP5331655B2 (ja) 通信システム、制御サーバ
TWI450535B (zh) 存取系統及其中之方法
WO2011032450A1 (zh) 网络互通的实现方法和系统
WO2011107052A2 (zh) 一种防止地址冲突的方法及接入节点
JP2002141953A (ja) 通信中継装置、通信中継方法、および通信端末装置、並びにプログラム記憶媒体
JP2008066907A (ja) パケット通信装置
JP4494279B2 (ja) マルチキャスト制御方法、マルチキャスト制御装置、及びコンテンツ属性情報管理装置、並びにプログラム
JP4292897B2 (ja) 中継装置とポートフォワード設定方法
WO2014173235A1 (zh) 转发路径的生成方法、控制器和系统
US7237025B1 (en) System, device, and method for communicating user identification information over a communications network
JP2012527794A (ja) ホストアイデンティティタグ取得のための方法およびシステム
US11196666B2 (en) Receiver directed anonymization of identifier flows in identity enabled networks
JP2013201621A (ja) ポート開閉制御システム
JP4498968B2 (ja) 認証ゲートウェイ装置及びそのプログラム
JP4361446B2 (ja) マルチキャスト制御方法、マルチキャストエリア管理装置、及びマルチキャスト制御装置、並びにプログラム

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 09841013

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 09841013

Country of ref document: EP

Kind code of ref document: A1