摘要:
The present invention discloses a virtual private network (VPN) implementation method and system. The implementation of the VPN is based on the Location/ID separation network, and the corresponding VPN attribute is added to the mapping relation between the ID identifier and the location identifier. When performing the mapping processing, if the VPN attribute of the source host is judged to be the same as that of the destination host, the location identifier of the destination host is inquired, thereby the forwarding of the data packets is implemented according to the location identifier of the destination host; if the VPN attributes are not same, an unavailable message is replied. Thus, the virtual private network is implemented efficiently, the convenience and safety of the host communication of the VPN side are ensured, and the user requirement to the virtual private network is satisfied.
摘要:
The present invention provides a method, an access node and a system for processing a data message implemented based on an identity-locator-separation network. The method includes: A. a source end host transmitting a Domain Name System (DNS) inquiry message carrying a domain name of a destination end host to a DNS server, and the DNS server returning a DNS response message including an Access Identifier (AID) of the destination end host to the source end host; B. an Access Service Node (ASN) monitoring the DNS response message to obtain the AID of the destination end host in the monitored response message; C. the ASN inquiring of a mapping server according to the AID of the destination end host to obtain a Router Identifier (RID)of the destination end host; and D. after receiving a data message transmitted by the source end host to the destination end host, the ASN forwarding the data message according to the RID of the destination end host. The present invention can enhance the efficiency of forwarding the data message of the source end host by the ASN and improve the forwarding performance of the ASN.
摘要:
An implementation method and system of a virtual private network (VPN) are provided. The implementation method and system store an appropriative mapping table of the VPN in the mapping plane of the identity and location separating network, determine whether to implement the communication between the VPN end host users in the VPN according to the appropriative mapping table, and thus implement the virtual private network effectively in the identity and location separating network. The method and system meet the user requirement for the VPN, and eliminate the impact of the technical solution of the identity and location separation on the traditional VPN service, and reduce the changes of the existing equipment and software while implementing the VPN.