摘要:
This application discloses a method and an apparatus for accessing a gateway, and pertains to the field of communications technologies. In this application, an SLA level may be obtained based on user information of a terminal, and further a UP device corresponding to the terminal is determined based on the SLA level of the terminal. In this way, terminals with different SLA levels may be allocated to different UP devices for bearing, so that a specific terminal may access a specified UP device. This resolves a problem in a related technology that a terminal relatively randomly accesses a UP device. In addition, because an SLA level may be used to indicate a level of quality of service of a terminal, after terminals with different SLA levels access different UP devices, differentiated services may be provided on the different UP devices. Therefore, user requirements are met, and revenues are increased.
摘要:
This application discloses a communication method, apparatus, device, and system, and a computer-readable storage medium, and relates to the field of communication technologies. The method includes: A CP device receives a first packet that is sent by a first UP device and that carries source information of a first user terminal; searches, based on the source information of the first user terminal, a correspondence between source information of a user terminal and a location identifier of the user terminal accessing a network, to determine a first location identifier of the first user terminal accessing a network; and sends the first location identifier to a USF device, so that the USF device can determine that the first user terminal accesses the network from a first physical port on a first SF device, and configure a second SF device by using a controller, to switch traffic from the first user terminal from a first sub-interface that is on the first SF device and that corresponds to the first UP device to a second sub-interface that is on the second SF device and that corresponds to a second UP device, thereby sending traffic of a static user to an appropriate UP device.
摘要:
This application provides a packet processing method, a UP device, and a CP device, and belongs to the field of communication technologies, to prevent a CP device from being attacked in a scenario in which a BNG with CU disaggregated performs access authentication. In the method, when receiving a packet, a UP device matches information in the packet with information about a user having a fixed IP address. If the matching succeeds, the UP device sends the packet to a CP device. Because a task of checking whether the packet comes from the user having the fixed IP address is sunk from the CP device to the UP device, resource overheads caused by checking the packet by the CP device are avoided, and load of the CP device is reduced. Especially, if a malicious IP packet flow initiates a network attack, because the CP device does not need to perform a task of checking whether the malicious IP packet flow comes from the user having the fixed IP address, a risk that the CP device is attacked by the malicious IP packet flow is reduced.
摘要:
This application discloses a BRAS system-based packet encapsulation method and apparatus, and pertains to the field of communications technologies. The method includes: obtaining user access information corresponding to a user access protocol packet when receiving the user access protocol packet; and performing VXLAN GPE encapsulation on the user access protocol packet based on the user access information, where a value of an encapsulation protocol field of a VXLAN GPE header in a VXLAN GPE encapsulation structure is a preset value, the preset value is used to indicate that the encapsulation structure includes a user information header that is used to store the user access information, the user information header is located immediately after the VXLAN GPE header, and a quantity of bytes occupied by the user information header is less than or equal to 12. In this application, the foregoing encapsulation structure is used to encapsulate a packet, and an encapsulated packet has backward compatibility. In addition, because the quantity of bytes occupied by the user information header is less than a quantity of bytes occupied by an NSH that carries the user access information, encapsulation overheads are saved.
摘要:
Embodiments of this application disclose a network attack defense policy sending method and apparatus, and a network attack defending method and apparatus. The network attack defense policy sending method may include: receiving attack information, where the attack information includes a target Internet Protocol IP address, and the attack information is used to indicate that a network attack packet whose destination address is the target IP address exists in a first network; determining that the network attack packet enters the first network through a first edge network device, where the first edge network device is an edge device in the first network; sending a defense policy to the first edge network device, where the defense policy is used to instruct the first edge network device to process, according to the defense policy, a packet whose destination address is the target IP address. By means of this application, network resources occupied by a network attack packet can be reduced, and an effect of defending against the network attack packet can be improved.
摘要:
Embodiments of the present invention provide a service processing method and a network device, and the method includes: receiving a request message for a first service sent by user equipment; determining a service requested by the request message for the first service; and sending the request message for the first service to a first value added service server. According to the method and the device provided by the embodiments of the present invention, a request message for a service may be directly sent to a value added service server configured to provide a value added service corresponding to the request message for the service. This can reduce a delay caused by processing of an unnecessary value added service server, and increase a processing speed of providing the value added service for the request message for the service.
摘要:
Embodiments of the present invention relate to a method for acquiring an IP address and a network access device. The method includes: after receiving a first IP address acquiring message from a first network, assigning a first IP address to the first network by using a process and associating an identifier of the first network with a first session, so that the network access device is capable of mapping the first IP address to a first private network IP address and sending the same to the first network, thereby avoiding the problem of complex implementation in the prior art resulted from a process where a gateway configured for a family network or an enterprise network needs to initiate an IPoE dial-up process. In this way, the gateway configured for the family network or the enterprise network is simplified, operation and maintenance costs are reduced, and flat networks are further implemented.
摘要:
This application discloses a method for controlling subscriber access to a network, a device, and a system. A control plane device receives a first access request packet of a first subscriber, determines, based on a first correspondence, a first household to which the first subscriber belongs, then determines a first user plane device based on a second correspondence, and indicates the first subscriber to access the network through the first user plane device. The control plane device allocates, to a same user plane device, a subscriber who belongs to a same household and who accesses the network, so that the same user plane device provides a broadband network access service for the subscriber who belongs to the same household and who accesses the network. In this way, unified management may be performed through one user plane device on a plurality of subscribers who belong to a same household and who access the network, a process of managing the plurality of subscribers who belong to the same household and who access the network may be simplified, and efficiency of managing the plurality of subscribers who belong to the same household and who access the network may be improved.
摘要:
This application discloses a method for controlling user equipment to access a network. After receiving a request packet sent by a gateway control plane device, a control device obtains, by parsing the request packet, a home identifier corresponding to first user equipment. The control device determines, based on the home identifier, a corresponding first target gateway user plane device when the first user equipment goes online, so that a plurality of user equipments corresponding to a same home identifier all go online through the first target gateway user plane device. It can be learned that, in embodiments of this application, a plurality of sessions of a same home are managed based on a home identifier, so that different user equipments in a same home go online through a same gateway user plane device, thereby implementing unified rate limiting in the home.