Dynamic virtual private network (DVPN) based data transmission method and device
A data transmission method and data technology, applied in the field of communication, can solve the problem of setting up a VPN, and the communication end cannot know the public network address in advance, etc., and achieve the effect of small overhead and reduced forwarding delay
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Publication Date
- 2013-04-03
Smart Images
Figure 1 Figure 2 Figure 3
Abstract
Description
technical field
[0001] The present invention relates to the field of communication technologies, in particular to a data transmission method and device based on a DVPN (Dynamic Virtual Private Network, dynamic virtual private network). Background technique
[0002] More and more enterprises hope to use the public network to set up a VPN (Virtual Private Network, virtual private network) to connect multiple branches in different geographical locations; however, the enterprise branches usually use dynamic addresses to access the public network, making it impossible for one end of the communication to connect to the public network. Knowing the public network address of the opposite end in advance poses a problem for establishing a VPN. To this end, DVPN technology is proposed, which collects, maintains and distributes dynamically changing public network address information through NHRP (Next Hop Resolution Protocol) or VAM (VPN Address Management, VPN Address Management) When ...
Examples
Embodiment approach
[0047] Specifically, in order to maintain the neighbor Cost table on each Spoke, a preferred implementation manner is as follows:
[0048] Each Spoke receives a registration response message (Register replay message) from the server during the process of initiating registration with the server. The registration response message carries a TTL (Time To Live, time to live) value N; the TTL value N is the TTL value of the Full-Mesh network, and the registration response message sent by the server to each Spoke in the Full-Mesh network carries the same TTL value N.
[0049] After each Spoke obtains the TTL value N from the server, if each Spoke establishes a Full-Mesh tunnel connection (that is, a direct tunnel is established between all Spokes), each Spoke sends a Keepalive (keep alive) report to the neighboring Spoke of the device. (Keepalive packets can be sent regularly), and the IP header of the Keepalive packet carries the TTL value N; for example, Spoke1 sends a Keepalive pa...