WO2012079536A1 - 私网服务器访问方法及光网络单元 - Google Patents
私网服务器访问方法及光网络单元 Download PDFInfo
- Publication number
- WO2012079536A1 WO2012079536A1 PCT/CN2011/084148 CN2011084148W WO2012079536A1 WO 2012079536 A1 WO2012079536 A1 WO 2012079536A1 CN 2011084148 W CN2011084148 W CN 2011084148W WO 2012079536 A1 WO2012079536 A1 WO 2012079536A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- onu
- private network
- configuration information
- network server
- address
- Prior art date
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04J—MULTIPLEX COMMUNICATION
- H04J3/00—Time-division multiplex systems
- H04J3/16—Time-division multiplex systems in which the time allocation to individual channels within a transmission cycle is variable, e.g. to accommodate varying complexity of signals, to vary number of channels transmitted
- H04J3/1694—Allocation of channels in TDM/TDMA networks, e.g. distributed multiplexers
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L41/00—Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
- H04L41/08—Configuration management of networks or network elements
- H04L41/0803—Configuration setting
- H04L41/0806—Configuration setting for initial configuration or provisioning, e.g. plug-and-play
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L61/00—Network arrangements, protocols or services for addressing or naming
- H04L61/09—Mapping addresses
- H04L61/25—Mapping addresses of the same type
- H04L61/2503—Translation of Internet protocol [IP] addresses
- H04L61/256—NAT traversal
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04Q—SELECTING
- H04Q11/00—Selecting arrangements for multiplex systems
- H04Q11/0001—Selecting arrangements for multiplex systems using optical switching
- H04Q11/0062—Network aspects
- H04Q11/0067—Provisions for optical access or distribution networks, e.g. Gigabit Ethernet Passive Optical Network (GE-PON), ATM-based Passive Optical Network (A-PON), PON-Ring
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04Q—SELECTING
- H04Q11/00—Selecting arrangements for multiplex systems
- H04Q11/0001—Selecting arrangements for multiplex systems using optical switching
- H04Q11/0062—Network aspects
- H04Q2011/0079—Operation or maintenance aspects
Definitions
- the present invention relates to the field of communications, and in particular to a private network server access method and an optical network unit.
- ONU Optical Network Unit
- GPON GPON Encapsulation Method
- GEM GPON Encapsulation Method
- broadband access technology that provides a variety of integrated services.
- GPON consists of three parts: optical line terminal (OLT), user equipment ONU, and optical distribution network (ODN).
- OLT optical line terminal
- ODN optical distribution network
- the user may need to access the private network server on the ONU on the public network.
- the related access policy can be manually configured on the ONU through the administrator. Otherwise, the user cannot access the private network under the ONU on the public network.
- the server thus causes great inconvenience to the user, which is time consuming and labor intensive and inconvenient to maintain.
- the present invention provides a method for accessing a private network server and an optical network unit, so as to at least solve the problem that the access policy of the public network server accessing the private network server in the related art can only achieve high maintenance cost due to the configuration of the station.
- a private network server access method including: an ONU receiving configuration information from an OLT, where the configuration information includes: indicating that the private network under the ONU is accessed through a public network address Information about the channel used by the server; the ONU configuration uses the channel indicated by the configuration information to access the private network server under the ONU.
- the information for indicating a channel used when accessing a private network server under the ONU by using a public network address comprises: an IP host pointer pointing to an IP host config data entity, where the IP host config data corresponds to IP host channel used when accessing the private network server under the ONU through the public network address.
- the method further includes: determining, by the ONU, an IP corresponding to the IP host config data pointed by the IP host pointer Whether the host channel has been established, and if so, the subsequent processing is continued; otherwise, the processing ends.
- the method further includes: the ONU configuration mapping relationship, where the mapping relationship is used to map the public network protocol IP address and the public network port to the private network server under the ONU Private network IP address and private network port.
- the mapping relationship is sent by the OLT to the ONU by using the configuration information.
- the configuration information further includes at least one of the following: a protocol type used when accessing the private network server in the ONU by the public network address, an IP address of the private network server corresponding to the configuration information, and the configuration information.
- a protocol type used when accessing the private network server in the ONU by the public network address an IP address of the private network server corresponding to the configuration information
- the configuration information the configuration information.
- the range of port numbers allowed to be accessed in the corresponding private network server the range of public IP addresses that are allowed to initiate access, and the range of public network ports that are allowed to initiate access.
- the method further includes: the ONU receiving the private network server sent to the ONU a packet, determining whether the destination port number of the packet is within a range of the port number to be accessed, and if yes, forwarding the packet to the destination port number of the private network server, otherwise, Discard the message.
- the method further includes: the ONU receiving the packet sent to the private network server in the ONU, and determining the packet.
- the 0NU receiving the configuration information from the OLT includes: the ONU receiving the management entity ME interface information carrying the configuration information from the OLT through the optical network terminal management and control interface OMCI.
- an optical network unit including: a receiving module, configured to receive configuration information from an optical line terminal OLT, wherein the configuration information includes: The information about the channel used by the private network server in the ONU; the configuration module is configured to access the private network server under the ONU by using the channel indicated by the configuration information.
- the configuration information is sent to the 0NU by using the 0LT, including accessing configuration information such as a channel used when accessing the private network server under the 0NU through the public network address, and the 0NU accessing the configuration according to the received configuration information.
- FIG. 2 is a structural block diagram of an ONU according to an embodiment of the present invention
- FIG. 3 is a preferred structure of an ONU according to an embodiment of the present invention.
- 4 is a schematic diagram of a relationship between an ME interface and a standard ME interface entity according to Embodiment 2 of the present invention
- FIG. 5 is a flowchart of a configuration process for implementing a public network address access private network server according to Embodiment 2 of the present invention.
- Step S102 The ONU receives the configuration information from the OLT, where the configuration information includes: information used to indicate a channel used when accessing the private network server under the ONU through the public network address.
- Step S104 The ONU configures the channel indicated by the configuration information to access the private network server under the ONU.
- the OLT sends the configuration information (including the access configuration information such as the channel used when accessing the private network server under the ONU through the public network address) to the ONU.
- the ONU accesses the configuration according to the received configuration information, and solves the related technology.
- the access policy of the public network server accessing the private network server can only achieve the problem of high maintenance cost by the configuration of the station.
- the automatic configuration of the access rules of the private network server accessing the ONU through the public network address is realized, and the remote real-time maintenance is convenient.
- the specific information used to indicate the channel may be determined according to the resolution capability of the ONU. This embodiment provides a preferred method for indicating that the private network server under the ONU is accessed through the public network address.
- the form of the channel information including: pointing to the Internet host configuration data (IP host config data, in the ITU-T G984.4 standard, IP host config data is the entity name defined on the standard, mainly used to configure the ONU to provide IP service)
- IP host pointer of the entity which is an attribute of the management entity defined in this embodiment, which is used to associate with an instance of the entity host config data
- IP host config The data corresponds to the IP host channel used when accessing the private network server under the 0NU through the public network address. This kind of indication method is convenient for analysis and easy to implement.
- the 0NU can be guaranteed to access the private address through the public network address. Supported by the web server, and the configuration process can be completed by 0LT remote configuration. Considering that there may be cases where the channel is not established or failed to be established, in order to prevent subsequent access failures due to the absence of available channels, you can perform the judgment before the 0NU configures the channel indicated by the configuration information to access the private network server under the 0NU.
- the process includes: 0NU determines whether the IP host channel corresponding to the IP host config data pointed to by the IP host pointer has been established, and if so, continues the subsequent processing; otherwise, the processing ends.
- the 0NU configuration uses the channel indicated by the configuration information to access the private network server in the ONU, the following can also include: 0NU configuration mapping relationship, which is used to set the public network protocol (Internet Protocol, IP address) and the public network port. Maps to the private IP address and private network port of the private network server under 0NU.
- the mapping relationship may be sent by the OLT to the ONU through the configuration information, or may be created by the ONU itself.
- the configuration information may further include at least one of the following: When accessing the private network server under the 0NU through the public network address The type of the protocol to be used, the IP address of the private network server corresponding to the configuration information, the range of port numbers allowed to be accessed on the private network server corresponding to the configuration information, the range of public IP addresses that are allowed to initiate access, and the public network that allows access. The range of ports. These configuration information can improve the security of access.
- the processing on the 0NU side can include:
- the 0NU receives the packet sent to the private network server under the 0NU, and determines whether the destination port number of the packet is Within the range of the port number that is allowed to be accessed, if yes, the packet is forwarded to the destination port number of the private network server. Otherwise, the packet is discarded.
- the configuration information includes the range of the public network IP address that is allowed to be accessed
- the ONU receives the packet sent to the private network server under the ONU, and determines whether the source IP address of the packet is allowed to be accessed. Within the range of the IP address of the network, if yes, the packet is forwarded; otherwise, the packet is discarded.
- the ONU receives the packet sent to the private network server under the ONU, and determines whether the source port of the packet is in the public network port that is allowed to initiate the access. Within the scope, if yes, the packet is forwarded, otherwise, the packet is discarded.
- the existing interface can be used to transmit the configuration information.
- the ONU receives the configuration information carried by the OLT through the optical network termination management and control interface (OMCI).
- OMCI optical network termination management and control interface
- ME Management entity
- the ONU includes: a receiving module 22, configured to receive configuration information from an OLT, where the configuration information includes: indicating to access a private network under the ONU through a public network address
- the information of the channel used by the server; the configuration module 24 is configured to access the private network server under the ONU by using the channel indicated by the configuration information.
- the information used to indicate the channel used when accessing the private network server under the ONU through the public network address comprises: an IP host pointer pointing to the IP host config data entity, where the IP host config data corresponds to accessing the ONU through the public network address IP host channel used when the private network server is down.
- 3 is a block diagram of a preferred structure of an ONU according to an embodiment of the present invention. As shown in FIG.
- the ONU further includes: a determining module 32, configured to determine whether an IP host channel corresponding to the IP host config data pointed to by the IP host pointer has been Established, if yes, the configuration module 24 is called, otherwise, the processing ends.
- the configuration module 24 is further configured to configure a mapping relationship for mapping the public network IP address and the public network port to the private network IP address and the private network port of the private network server under the ONU. The above mappings can be sent to the ONU through configuration information.
- the configuration information further includes at least one of the following: a protocol type used when accessing the private network server of the ONU through the public network address, an IP address of the private network server corresponding to the configuration information, and a private network server corresponding to the configuration information allowed to be
- a protocol type used when accessing the private network server of the ONU through the public network address an IP address of the private network server corresponding to the configuration information
- the range of port numbers that are accessed the range of public IP addresses that are allowed to initiate access, and the range of public network ports that are allowed to initiate access.
- Example 1 This embodiment provides an OMCI implementation method for accessing a private network server by a public network address, and the ME in the G984.4 standard is expanded in the method.
- the ME interface defined in this embodiment is Port Forwarding-G, and the entity class (ME Class, recorded as Meclass) is defined as 65285.
- the ME is created, deleted, and modified by the OLT.
- the following nine attributes are defined: Procotol: Whether the protocol type is TCP or UDP;
- IP host pointer points to an IP host config data entity
- Lan host ip address private network IP address
- Lan host end port The private network terminates the port number; Wan host start ip address: the public network start IP address;
- Wan host end ip address Public network termination IP address
- Wan start port the starting port number of the public network
- Wan end port The public network terminates the port number.
- the ME interface can be configured with the IP address range and port range of the public network, the IP address and port range of the private network, and the IP host config data entity associated with the rule.
- Embodiment 2 This embodiment describes the pointing and association relationship of the 0MCI entity.
- FIG. 4 is a diagram showing the relationship between the ME interface and the standard ME interface entity according to Embodiment 2 of the present invention, as shown in FIG. 4: Port Forwarding. -G) The IP address of the public IP address and the port are mapped to the private IP address and port through the associated IP host channel and the configured IP forwarding channel. Web server.
- Step S502 the 0NU receives the 0MCI message created or set by the Port Forwarding-G entity.
- Step S504 obtaining a value of the Port Forwarding-G entity attribute IP host pointer.
- Step S506 determining whether the IP host channel associated with the attribute IP host pointer is established, if yes, proceeding to step S508, otherwise doing nothing.
- Step S508 creating a Port Forwarding rule. After the port forwarding rule is created, the public network IP address and port can be mapped to the private network IP address and port to implement public network address access to the private network server.
- the solution provided by the embodiment of the present invention implements automatic configuration of access rules for accessing the private network server under the ONU through the public network address, and facilitates remote real-time maintenance.
- modules or steps of the present invention can be implemented by a general-purpose computing device, which can be concentrated on a single computing device or distributed over a network composed of multiple computing devices.
- they may be implemented by program code executable by the computing device so that they may be stored in the storage device by the computing device, or they may be separately fabricated into individual integrated circuit modules, or Multiple modules or steps are made into a single integrated circuit module.
- the invention is not limited to any specific combination of hardware and software.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
- Small-Scale Networks (AREA)
Description
私网服务器访问方法及光网络单元 技术领域 本发明涉及通信领域, 具体而言, 涉及一种私网服务器访问方法及光网络单元
( Optical Network Unit, 简称为 ONU )。 背景技术 吉比特无源光网络 (Gigabit Passive Optical Network, 简称为 GPON) 是一种采用 点到多点网络结构、 无源光纤传输方式、 基于 GP0N封装方法 (GPON Encapsulation Method, 简称为 GEM) 帧封装和提供多种综合业务的宽带接入技术。
GPON由局端设备光线路终端(Optical Line Terminal, 简称为 OLT)、用户端设备 ONU和连接线路光分配网络 (Optical Distribute Network, 简称为 ODN)三部分组成。 在实际应用中, 可能存在用户需要在公网上访问 ONU下的私网服务器的情况, 相关的访问策略仅能够通过管理人员人工到 ONU上进行配置, 否则用户无法在公网 上访问 ONU下的私网服务器从而给用户的使用带来很大的不便, 这种方式费时费力, 且不便于维护。 发明内容 本发明提供了一种私网服务器访问方法及光网络单元, 以至少解决相关技术中公 网地址访问私网服务器的访问策略仅能到站配置导致维护成本高的问题。 根据本发明的一个方面, 提供了一种私网服务器访问方法, 包括: ONU接收来自 OLT 的配置信息, 其中, 所述配置信息包括: 用于指示通过公网地址访问所述 ONU 下的私网服务器时使用的通道的信息; 所述 ONU配置采用所述配置信息指示的通道 来访问所述 ONU下的私网服务器。 优选地, 所述用于指示通过公网地址访问所述 ONU下的私网服务器时使用的通 道的信息包括:指向 IP host config data实体的 IP host pointer,其中,所述 IP host config data对应于通过公网地址访问所述 ONU下的私网服务器时使用的 IP host通道。
优选地,在所述 ONU配置采用所述配置信息指示的通道来访问所述 ONU下的私 网服务器之前, 还包括: 所述 ONU判断所述 IP host pointer指向的 IP host config data 所对应的 IP host通道是否已建立, 若是, 则继续后续处理, 否则, 结束处理。 优选地, 在 ONU接收来自 OLT的配置信息之后, 还包括: 所述 ONU配置映射 关系, 所述映射关系用于将公网网络协议 IP地址和公网端口映射到所述 ONU下的私 网服务器的私网 IP地址和私网端口。 优选地, 所述映射关系由所述 OLT通过所述配置信息下发至所述 ONU。 优选地, 所述配置信息还包括以下至少之一: 通过公网地址访问所述 0NU下的 私网服务器时使用的协议类型、所述配置信息对应的私网服务器的 IP地址、所述配置 信息对应的私网服务器中允许被访问的端口号的范围、允许发起访问的公网 IP地址的 范围、 允许发起访问的公网端口的范围。 优选地, 在所述配置信息包括所述配置信息对应的私网服务器中允许被访问的端 口号的范围的情况下, 还包括: 所述 0NU接收到发往所述 0NU下的私网服务器的报 文, 判断所述报文的目的端口号是否在所述允许被访问的端口号的范围内, 若是, 则 将所述报文转发到所述私网服务器的所述目的端口号, 否则, 丢弃所述报文。 优选地, 在所述配置信息包括允许发起访问的公网 IP地址的范围的情况下, 还包 括: 所述 0NU接收到发往所述 0NU下的私网服务器的报文, 判断所述报文的源 IP 地址是否在允许发起访问的公网 IP地址的范围内, 若是, 则转发所述报文, 否则, 丢 弃所述报文; 在所述配置信息包括允许发起访问的公网端口的范围的情况下,还包括: 所述 0NU接收到发往所述 0NU下的私网服务器的报文,判断所述报文的源端口是否 在允许发起访问的公网端口的范围内, 若是, 则转发所述报文, 否则, 丢弃所述报文。 优选地, 0NU接收来自 0LT的配置信息包括: 所述 0NU通过光网络终端管理和 控制接口 0MCI接收来自 0LT的携带有配置信息的管理实体 ME接口信息。 根据本发明的另一个方面, 提供了一种光网络单元, 包括: 接收模块, 设置为接 收来自光线路终端 0LT的配置信息, 其中, 所述配置信息包括: 用于指示通过公网地 址访问所述 0NU下的私网服务器时使用的通道的信息; 配置模块, 设置为采用所述 配置信息指示的通道来访问所述 0NU下的私网服务器。 通过本发明, 采用 0LT向 0NU下发配置信息, 包括通过公网地址访问 0NU下 的私网服务器时使用的通道等访问配置信息, 0NU按照接收到的配置信息进行访问配
置, 解决了相关技术中公网地址访问私网服务器的访问策略仅能到站配置导致维护成 本高的问题, 实现了对通过公网地址访问 ONU下的私网服务器的访问规则的自动配 置, 且便于远程实时维护。 附图说明 此处所说明的附图用来提供对本发明的进一步理解, 构成本申请的一部分, 本发 明的示意性实施例及其说明用于解释本发明, 并不构成对本发明的不当限定。 在附图 中: 图 1是根据本发明实施例的私网服务器访问方法的流程图; 图 2是根据本发明实施例的 ONU的结构框图; 图 3是根据本发明实施例的 ONU的优选结构框图; 图 4是根据本发明实施例 2的 ME接口与标准 ME接口实体关系示意图; 图 5是根据本发明实施例 2实现公网地址访问私网服务器配置处理流程图。 具体实施方式 下文中将参考附图并结合实施例来详细说明本发明。 需要说明的是, 在不冲突的 情况下, 本申请中的实施例及实施例中的特征可以相互组合。 图 1是根据本发明实施例的私网服务器访问方法的流程图, 如图 1所示, 该方法 包括如下的步骤 S102至步骤 S104。 步骤 S102, ONU接收来自 OLT的配置信息, 其中, 配置信息包括: 用于指示通 过公网地址访问 ONU下的私网服务器时使用的通道的信息。 步骤 S104, ONU配置采用配置信息指示的通道来访问 ONU下的私网服务器。 通过以上的方法, OLT向 ONU下发配置信息(包括通过公网地址访问 ONU下的 私网服务器时使用的通道等访问配置信息), ONU按照接收到的配置信息进行访问配 置, 解决了相关技术中公网地址访问私网服务器的访问策略仅能到站配置导致维护成 本高的问题, 实现了对通过公网地址访问 ONU下的私网服务器的访问规则的自动配 置, 且便于远程实时维护。
在实际应用中, 可以根据 ONU 的解析能力来确定具体的用于指示通道的信息的 形式, 本实施例给出一种优选的用于指示通过公网地址访问 ONU下的私网服务器时 使用的通道的信息的形式,该信息包括:指向互联网主机配置数据(IP host config data, 在 ITU-T的 G984.4标准中, IP host config data是标准上定义的实体名字, 主要用来配 置 ONU提供的 IP服务) 实体的互联网主机指针 (IP host pointer, 其是本实施例中定 义的管理实体的一个属性, 这个属性是用来关联到实体 host config data 的一个实例 的), 其中, IP host config data对应于通过公网地址访问 0NU下的私网服务器时使用 的 IP host (IP主机) 通道。 这种指示方式具体解析方便, 容易实现的优点。 需要说明 的是, 无论采取何种形式的指示信息, 只要该信息能够指示一个或多个通过公网地址 访问 0NU下的私网服务器时使用的通道,就可以保证 0NU对于通过公网地址访问私 网服务器的支持, 并且该配置过程能够通过 0LT远程配置的方式完成。 考虑到可能存在通道未建立或建立失败的情况, 为了防止后续出现由于不存在可 用通道导致访问失败的问题, 可以在 0NU配置采用配置信息指示的通道来访问 0NU 下的私网服务器之前, 执行判断过程, 包括: 0NU判断 IP host pointer指向的 IP host config data所对应的 IP host通道是否已建立, 若是, 则继续后续处理, 否则, 结束处 理。 在 0NU配置采用配置信息指示的通道来访问 0NU下的私网服务器之后,还可以 包括: 0NU配置映射关系, 映射关系用于将公网网络协议 (Internet Protocol, 简称为 IP)地址和公网端口映射到 0NU下的私网服务器的私网 IP地址和私网端口。优选地, 该映射关系可以由 0LT通过配置信息下发至 0NU, 也可以由 0NU自身进行创建。 在以上配置信息内容的基础上, 为了提高 0LT对 0NU私网访问策略的管理的灵 活性及可控性, 配置信息可以进一步包括以下至少之一: 通过公网地址访问 0NU下 的私网服务器时使用的协议类型、配置信息对应的私网服务器的 IP地址、配置信息对 应的私网服务器中允许被访问的端口号的范围、 允许发起访问的公网 IP地址的范围、 允许发起访问的公网端口的范围。这些配置信息能够提高访问的安全性, 0NU侧的处 理可以包括:
( 1 )在配置信息包括配置信息对应的私网服务器中允许被访问的端口号的范围的 情况下, 0NU接收到发往 0NU下的私网服务器的报文, 判断报文的目的端口号是否 在允许被访问的端口号的范围内, 若是, 则将报文转发到私网服务器的目的端口号, 否则, 丢弃报文。
(2)在配置信息包括允许发起访问的公网 IP地址的范围的情况下, ONU接收到 发往 ONU下的私网服务器的报文, 判断报文的源 IP地址是否在允许发起访问的公网 IP地址的范围内, 若是, 则转发报文, 否则, 丢弃报文。
(3 ) 在配置信息包括允许发起访问的公网端口的范围的情况下, ONU接收到发 往 ONU下的私网服务器的报文, 判断报文的源端口是否在允许发起访问的公网端口 的范围内, 若是, 则转发报文, 否则, 丢弃报文。 为了使得配置更加简便, 可以服用现有的接口进行配置信息的传递, 例如, ONU 通过光网络终端管理和控制接口 (Optical network termination Management and Control Interface,简称为 OMCI)接收来自 OLT的携带有配置信息的管理实体 (Managed Entity, 简称为 ME) 接口信息。 图 2是根据本发明实施例的 ONU的结构框图, 该 ONU包括: 接收模块 22, 设置 为接收来自 OLT的配置信息,其中,配置信息包括:用于指示通过公网地址访问 ONU 下的私网服务器时使用的通道的信息; 配置模块 24, 设置为采用配置信息指示的通道 来访问 ONU下的私网服务器。 优选地, 用于指示通过公网地址访问 ONU下的私网服务器时使用的通道的信息 包括: 指向 IP host config data实体的 IP host pointer, 其中, IP host config data对应于 通过公网地址访问 ONU下的私网服务器时使用的 IP host通道。 图 3是根据本发明实施例的 ONU的优选结构框图,如图 3所示,该 ONU还包括: 判断模块 32, 设置为判断 IP host pointer指向的 IP host config data所对应的 IP host通 道是否已建立, 若是, 则调用配置模块 24, 否则, 结束处理。 优选地, 配置模块 24还设置为配置映射关系, 映射关系用于将公网 IP地址和公 网端口映射到 ONU下的私网服务器的私网 IP地址和私网端口。 以上的映射关系可以 通过配置信息下发至 ONU。 优选地, 配置信息还包括以下至少之一: 通过公网地址访问 ONU下的私网服务 器时使用的协议类型、配置信息对应的私网服务器的 IP地址、配置信息对应的私网服 务器中允许被访问的端口号的范围、允许发起访问的公网 IP地址的范围、允许发起访 问的公网端口的范围。 以下描述的实施例 1-2, 综合了上述多个优选实施例的技术方案。 实施例 1
本实施例提供了一种公网地址访问私网服务器的 OMCI 实现方法, 该方法中对 G984.4标准中的 ME进行了扩充。 本实施例定义的 ME接口是 Port Forwarding-G, 实 体类(ME Class, 记为 Meclass)值定义为 65285, 该 ME是由 OLT来创建、 删除和修 改, 定义了如下九个属性: Procotol: 指明协议类型是 TCP还是 UDP的;
IP host pointer: 指向一个 IP host config data实体;
Lan host ip address: 私网 IP地址;
Lan host start port: 私网起始端口号;
Lan host end port: 私网终止端口号; Wan host start ip address: 公网起始 IP地址;
Wan host end ip address: 公网终止 IP地址;
Wan start port: 公网起始端口号;
Wan end port: 公网终止端口号。 通该 ME接口, 可以配置公网 IP地址范围和端口范围, 私网 IP地址和端口范围 以及规则所关联的 IP host config data 实体。 实施例 2 本实施例描述了 0MCI实体的指向和关联关系, 图 4是根据本发明实施例 2 的 ME接口与标准 ME接口实体关系图,如图 4所示:实体端口推进 -G( Port Forwarding-G) 通过属性 IP host pointer指向实体 IP host config data,通过关联的 IP host通道以及配置 的 Port Forwarding规则, 完成公网 IP地址和端口映射到私网 IP地址和端口, 实现公 网地址访问私网服务器。 图 5是根据本发明实施例 2实现公网地址访问私网服务器配置处理流程图, 如图 5所示, 包括以下的步骤 S502至步骤 S508。 步骤 S502, 0NU收到了 Port Forwarding-G实体的创建或设置的 0MCI消息。 步骤 S504, 获取 Port Forwarding-G实体属性 IP host pointer的值。
步骤 S506, 判断属性 IP host pointer关联的 IP host通道是否建立, 如果建立则继 续步骤 S508, 否则什么都不做。 步骤 S508, 创建端口推进 (Port Forwarding) 规则。 创建了 Port Forwarding规则后, 就可把公网 IP地址和端口映射到私网 IP地址和 端口, 实现公网地址访问私网服务器。 从以上的描述中, 可以看出, 本发明实施例提供的方案实现了对通过公网地址访 问 ONU下的私网服务器的访问规则的自动配置, 且便于远程实时维护。 显然, 本领域的技术人员应该明白, 上述的本发明的各模块或各步骤可以用通用 的计算装置来实现, 它们可以集中在单个的计算装置上, 或者分布在多个计算装置所 组成的网络上, 可选地, 它们可以用计算装置可执行的程序代码来实现, 从而可以将 它们存储在存储装置中由计算装置来执行,或者将它们分别制作成各个集成电路模块, 或者将它们中的多个模块或步骤制作成单个集成电路模块来实现。 这样, 本发明不限 制于任何特定的硬件和软件结合。 以上所述仅为本发明的优选实施例而已, 并不用于限制本发明, 对于本领域的技 术人员来说, 本发明可以有各种更改和变化。 凡在本发明的精神和原则之内, 所作的 任何修改、 等同替换、 改进等, 均应包含在本发明的保护范围之内。
Claims
1. 一种私网服务器访问方法, 包括:
光网络单元 0NU接收来自光线路终端 0LT的配置信息, 其中, 所述配置 信息包括: 用于指示通过公网地址访问所述 ONU下的私网服务器时使用的通 道的信息;
所述 ONU配置采用所述配置信息指示的通道来访问所述 ONU下的私网服 务器。
2. 根据权利要求 1所述的方法, 其中, 所述用于指示通过公网地址访问所述 ONU 下的私网服务器时使用的通道的信息包括:
指向互联网主机配置数据 IP host config data实体的互联网主机指针 IP host pointer,其中,所述 IP host config data对应于通过公网地址访问所述 ONU下的 私网服务器时使用的互联网主机 IP host通道。
3. 根据权利要求 2所述的方法, 其中, 在所述 ONU配置采用所述配置信息指示 的通道来访问所述 ONU下的私网服务器之前, 还包括:
所述 0NU判断所述 IP host pointer指向的 IP host config data所对应的 IP host通道是否已建立, 若是, 则继续后续处理, 否则, 结束处理。
4. 根据权利要求 1所述的方法, 其中, 在 0NU接收来自 0LT的配置信息之后, 还包括:
所述 0NU配置映射关系, 所述映射关系用于将公网网络协议 IP地址和公 网端口映射到所述 0NU下的私网服务器的私网 IP地址和私网端口。
5. 根据权利要求 4所述的方法, 其中, 所述映射关系由所述 0LT通过所述配置信 息下发至所述 0NU。
6. 根据权利要求 1所述的方法, 其中, 所述配置信息还包括以下至少之一: 通过 公网地址访问所述 0NU下的私网服务器时使用的协议类型、 所述配置信息对 应的私网服务器的 IP地址、所述配置信息对应的私网服务器中允许被访问的端 口号的范围、允许发起访问的公网 IP地址的范围、允许发起访问的公网端口的 范围。 根据权利要求 6所述的方法, 其中, 在所述配置信息包括所述配置信息对应的 私网服务器中允许被访问的端口号的范围的情况下, 还包括:
所述 ONU接收到发往所述 ONU下的私网服务器的报文,判断所述报文的 目的端口号是否在所述允许被访问的端口号的范围内, 若是, 则将所述报文转 发到所述私网服务器的所述目的端口号, 否则, 丢弃所述报文。 根据权利要求 6所述的方法, 其中, 在所述配置信息包括允许发起访问的公网 IP 地址的范围的情况下, 还包 括: 所述 ONU接收到发往所述 ONU下的私网服务器的报文, 判断所述报文的 源 IP地址是否在允许发起访问的公网 IP地址的范围内, 若是, 则转发所述报 文, 否则, 丢弃所述报文;
在所述配置信息包括允许发起访问的公网端口的范围的情况下, 还包括: 所述 ONU接收到发往所述 ONU下的私网服务器的报文,判断所述报文的源端 口是否在允许发起访问的公网端口的范围内, 若是, 则转发所述报文, 否则, 丢弃所述报文。 根据权利要求 1至 8中任一项所述的方法, 其中, ONU接收来自 OLT的配置 信息包括:
所述 ONU通过光网络终端管理和控制接口 OMCI接收来自 OLT的携带有 配置信息的管理实体 ME接口信息。 一种光网络单元 ONU, 包括:
接收模块, 设置为接收来自光线路终端 OLT的配置信息, 其中, 所述配置 信息包括: 用于指示通过公网地址访问所述 ONU下的私网服务器时使用的通 道的信息;
配置模块, 设置为采用所述配置信息指示的通道来访问所述 ONU下的私 网服务器。
Applications Claiming Priority (2)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201010593563.8 | 2010-12-17 | ||
CN201010593563.8A CN102572617B (zh) | 2010-12-17 | 2010-12-17 | 私网服务器访问方法及光网络单元 |
Publications (1)
Publication Number | Publication Date |
---|---|
WO2012079536A1 true WO2012079536A1 (zh) | 2012-06-21 |
Family
ID=46244120
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
PCT/CN2011/084148 WO2012079536A1 (zh) | 2010-12-17 | 2011-12-16 | 私网服务器访问方法及光网络单元 |
Country Status (2)
Country | Link |
---|---|
CN (1) | CN102572617B (zh) |
WO (1) | WO2012079536A1 (zh) |
Cited By (2)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
WO2014079261A1 (zh) * | 2012-11-23 | 2014-05-30 | 中兴通讯股份有限公司 | 一种无源光网络的业务配置方法和系统 |
CN109151084A (zh) * | 2017-06-15 | 2019-01-04 | 中兴通讯股份有限公司 | 报文发送方法及装置、系统、cgn设备 |
Families Citing this family (1)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN109688100B (zh) * | 2018-09-07 | 2022-06-17 | 平安科技(深圳)有限公司 | Nat穿透方法、装置、设备及存储介质 |
Citations (4)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN1713624A (zh) * | 2004-06-23 | 2005-12-28 | 日本电气株式会社 | Ip电话接入系统、用户终接装置和ip电话接入方法 |
CN101034938A (zh) * | 2007-04-05 | 2007-09-12 | 中兴通讯股份有限公司 | Epon网络中onu的远程管理ip地址的配置方法 |
US20080232804A1 (en) * | 2007-03-19 | 2008-09-25 | Luc Absillis | Pon with protected cross-connect forwarding |
CN101299698A (zh) * | 2007-04-30 | 2008-11-05 | 华为技术有限公司 | 通信代理的方法及装置及系统 |
Family Cites Families (6)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN101047450B (zh) * | 2006-05-11 | 2011-04-20 | 华为技术有限公司 | 一种对光纤接入终端设备零配置业务发放的方法 |
CN101047454B (zh) * | 2006-05-11 | 2010-08-04 | 华为技术有限公司 | 一种无源光网络系统中的流量映射方法 |
CN102379095B (zh) * | 2009-04-01 | 2014-08-27 | 泰克诺沃斯公司 | 多个以太网无源光网络中链路共享的方法及装置 |
CN101860771B (zh) * | 2010-06-02 | 2014-06-11 | 中兴通讯股份有限公司 | 家庭网关识别入网的方法及系统 |
CN101877803B (zh) * | 2010-06-29 | 2015-10-21 | 中兴通讯股份有限公司 | 一种实现组播预览的方法、系统及装置 |
CN101888575B (zh) * | 2010-07-28 | 2015-04-01 | 中兴通讯股份有限公司 | 一种实现端口地址绑定的配置方法和系统 |
-
2010
- 2010-12-17 CN CN201010593563.8A patent/CN102572617B/zh active Active
-
2011
- 2011-12-16 WO PCT/CN2011/084148 patent/WO2012079536A1/zh active Application Filing
Patent Citations (4)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN1713624A (zh) * | 2004-06-23 | 2005-12-28 | 日本电气株式会社 | Ip电话接入系统、用户终接装置和ip电话接入方法 |
US20080232804A1 (en) * | 2007-03-19 | 2008-09-25 | Luc Absillis | Pon with protected cross-connect forwarding |
CN101034938A (zh) * | 2007-04-05 | 2007-09-12 | 中兴通讯股份有限公司 | Epon网络中onu的远程管理ip地址的配置方法 |
CN101299698A (zh) * | 2007-04-30 | 2008-11-05 | 华为技术有限公司 | 通信代理的方法及装置及系统 |
Cited By (2)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
WO2014079261A1 (zh) * | 2012-11-23 | 2014-05-30 | 中兴通讯股份有限公司 | 一种无源光网络的业务配置方法和系统 |
CN109151084A (zh) * | 2017-06-15 | 2019-01-04 | 中兴通讯股份有限公司 | 报文发送方法及装置、系统、cgn设备 |
Also Published As
Publication number | Publication date |
---|---|
CN102572617B (zh) | 2015-06-03 |
CN102572617A (zh) | 2012-07-11 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
US11038751B2 (en) | Information processing method, network node, authentication method, and server | |
US10728214B2 (en) | Method for access network virtualization and proxy node | |
US10367693B2 (en) | Service configuration data processing method and apparatus | |
US10523562B2 (en) | Method for processing packet in access network and network device | |
WO2012139453A1 (zh) | 一种dpoe系统及基于该系统业务自动配置方法和网络 | |
WO2011150620A1 (zh) | 家庭网关识别入网的方法及系统 | |
WO2008098456A1 (fr) | Procédé, dispositif et système de distribution de service | |
US10505637B2 (en) | Service processing method and apparatus and optical line terminal | |
WO2007082478A1 (fr) | Procédé permettant d'établir une correspondance entre un flux de service et un canal de transmission de service, système et terminateur de réseau optique associés | |
WO2015196922A1 (zh) | 报文处理方法及装置 | |
WO2014079261A1 (zh) | 一种无源光网络的业务配置方法和系统 | |
WO2016101525A1 (zh) | 光网络单元dpu设备管理方法、装置及系统 | |
US7894437B2 (en) | Determining transmission port in a GPON network | |
US10178085B2 (en) | Establishing a secure file transfer session for secure file transfer to a demarcation device | |
WO2010028578A1 (zh) | 一种光网络设备上感知服务提供商的方法、设备和系统 | |
JP2022545879A (ja) | サービス設定方法及び装置 | |
WO2018120179A1 (zh) | 一种管理光网络单元onu的方法、装置及系统 | |
WO2012079536A1 (zh) | 私网服务器访问方法及光网络单元 | |
WO2017219856A1 (zh) | 电路认证处理方法、系统、控制器和计算机存储介质 | |
CN105591956B (zh) | 基于用户网络接口uni的流量控制方法和设备 | |
CN108833284B (zh) | 一种云平台和idc网络的通信方法及装置 | |
WO2014121600A1 (zh) | 一种光电混合系统中下行报文的发送方法及光同轴单元 | |
WO2011094994A1 (zh) | 控制访问光网络单元权限的方法、设备和系统 | |
US9985795B2 (en) | Method and apparatus for optical network unit ONU overall rate limiting | |
CN104468369A (zh) | 一种基于sdn技术的epon终端接入自动感知方法及系统 |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 11848035 Country of ref document: EP Kind code of ref document: A1 |
|
NENP | Non-entry into the national phase |
Ref country code: DE |
|
122 | Ep: pct application non-entry in european phase |
Ref document number: 11848035 Country of ref document: EP Kind code of ref document: A1 |