Traffic processing method and network equipment

Through the pUP module and traffic shunt technology in vBRAS devices, traffic type is judged based on the MAC address and QINQ/VPN is configured for isolation, which solves the problems of poor vCPE forwarding performance and traffic detours, and realizes high-speed, large-bandwidth forwarding, meeting the digital transformation needs of home users and small and medium-sized enterprises.

CN120499062APending Publication Date: 2025-08-15NEW H3C TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510857330.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-25
Publication Date
2025-08-15

AI Technical Summary

Technical Problem

The existing vCPE virtualized network element forwarding performance based on x86 architecture is poor, and it requires dialing to vBRAS. The process is long and the traffic is detoured, which cannot meet the needs of large bandwidth and high-speed forwarding.

Method used

The pending traffic is obtained through the pUP module in the vBRAS device, the traffic type is judged according to the destination MAC address, the QINQ/VPN is configured for isolation, and the traffic is diverted with the edge cloud or L2VE/L3VE interface through VSI, eliminating the PPPoE dialing process.

Benefits of technology

It has realized the ability to forward high-speed and large bandwidth, solved the problem of business diversion, reduced traffic detours, and met the digital transformation needs of home users and small and medium-sized enterprises.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120499062A_ABST
    Figure CN120499062A_ABST
Patent Text Reader

Abstract

The invention provides a traffic processing method and network equipment, and the method comprises the steps: a pUP obtains to-be-processed traffic from a user side through a user AC port of a VSI, judges whether the to-be-processed traffic is cloud access traffic according to a target MAC address of the to-be-processed traffic, if yes, sends the to-be-processed traffic to an edge cloud through a first AC port corresponding to the edge cloud in the VSI, and if not, sends the to-be-processed traffic to the edge cloud through a second AC port corresponding to the edge cloud in the VSI; and if yes, the traffic is sent to a public network through a bridging interface of the L2VE and the L3VE in the VSI. According to the method, the problems of cloud access, Internet access and multi-address mutual access service shunting of the fusion edge service can be solved, and the high-speed large-bandwidth forwarding capability is provided.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This specification relates to the field of communication technology, and in particular to a method for processing traffic and a network device. Background Art

[0002] Following the agricultural and industrial economies, the digital economy has become the dominant economic form. It takes data resources as its core element, uses modern information networks as its primary carrier, and is driven by the deep integration of information and communications technologies and the digital transformation of all factors, promoting the organic combination of fairness and efficiency. In the new era, digital services have become a key channel for meeting people's needs for a better life. They effectively break through spatial and temporal constraints, improve resource accessibility, greatly facilitate people's lives, and meet diverse and personalized needs. The development of the digital economy is bringing tangible benefits to the general public. For the 2H and 2B market segments, targeting 570 million household broadband users, 48 million small and medium-sized enterprises, and hundreds of millions of individual businesses, they require simple, standardized, and innovative solutions to rapidly achieve digital transformation.

[0003] Against this backdrop, China Telecom has proposed a new technology form of cloud-network converged edge (referred to as "converged edge"), focusing on the digital transformation of the large-scale 2H / 2B market (small and micro customers). This technology fully leverages the capabilities of cloud-network convergence and forms differentiated business advantages. Through the integrated innovation of cloud-network elements such as new metropolitan area networks, computing power, cloud storage, and security, a cloud-network service different from the traditional public cloud is provided, achieving a near-source, real-time, secure, and self-service service experience. Based on this architecture, users can enjoy a variety of innovative scenarios such as multimedia services, collaborative office, and multi-store / multi-family networking. In addition, by superimposing security capabilities on the edge, end-to-end security services covering cloud, network, edge, and end can be provided, further enhancing China Telecom's differentiated advantages on the access side.

[0004] like Figure 1 As shown in the figure, the converged edge cloud uses gigabit optical networks and new metropolitan area networks to connect homes to the edge cloud at Layer 2. Traffic is fully transferred to the cloud in one hop, connecting to edge computing power. Using edge cloud gateways, users' intranet traffic and internet traffic are separated.

[0005] Intranet management is moved upward to uniformly manage user home and edge networks, and isolate them from other users. A general computing base is provided at the edge, bringing services close to users. Traffic is closed in the edge loop, providing an intranet experience, and user data does not leave the intranet. At the same time, security capabilities are comprehensively superimposed from the aspects of resources, traffic, applications, and terminals, which can realize multi-site Layer 2 networking in the same city and multi-site resource sharing.

[0006] However, most current vCPEs are virtualized network elements based on the x86 architecture, with poor forwarding performance. Furthermore, the vCPEs need to dial up to the vBRAS, which is a lengthy process and requires traffic to be routed in a roundabout way. Summary of the Invention

[0007] To overcome the problems existing in the related art, this specification provides a method for processing traffic and a network device.

[0008] According to a first aspect of an embodiment of this specification, a method for processing traffic is provided, the method being applied to a vBRAS-enabled device, the method comprising:

[0009] pUP obtains traffic to be processed from the user end through the user AC port of the VSI;

[0010] Determine whether the traffic to be processed is inbound to the cloud based on the destination MAC address of the traffic to be processed.

[0011] If yes, the traffic to be processed is sent to the edge cloud through the first AC port in the VSI corresponding to the edge cloud;

[0012] If not, the traffic is sent to the public network through the L2VE and L3VE bridge interface in the VSI.

[0013] The method further comprises:

[0014] Configure QINQ / VPN on each user AC port of the pUP through CP, so that different user AC ports are configured with different QINQ / VPN.

[0015] The method further comprises:

[0016] The VSI receives the first address request sent by the user to DHCP through the user AC port and transparently transmits it to the DHCP server.

[0017] The first IP address allocated by the DHCP server according to the first address application request is received, and the first IP address is transparently transmitted to the user through the corresponding user AC port.

[0018] The method further comprises:

[0019] The AC port connected to the edge cloud sends a second address request to DHCP through the VSI and transparently transmits it to the DHCP server;

[0020] Receive the second IP address allocated by the DHCP server according to the second application address request, and transparently transmit the second IP address to the edge cloud through the AC port connected to the edge cloud.

[0021] The determining whether the traffic to be processed is inbound cloud traffic based on the destination MAC address of the traffic to be processed includes:

[0022] Check the destination MAC address through the VPLS instance to see if it points to the edge cloud.

[0023] If so, it is determined to be inbound cloud traffic.

[0024] The method of sending the traffic to be processed to the edge cloud through the first AC port corresponding to the edge cloud in the VSI includes:

[0025] The traffic to be processed is sent to the vHOST through the AC port connected to the edge cloud, and the traffic to be processed is sent to the edge cloud server through the vHOST.

[0026] Traffic is sent to the public network through the L2VE and L3VE bridge interfaces in the VSI, including:

[0027] Through ARP / NS requests, the traffic to be processed is bridged via L2VE to the L3VE port and sent to the public network.

[0028] The method further comprises:

[0029] Obtain the destination MAC address and query the Layer 2 forwarding table to determine whether it is multi-address inter-access traffic;

[0030] If yes, then establish a correspondence between the QINQ of the user AC port that obtains the traffic to be processed and the QINQ of the user AC port corresponding to the destination MAC address;

[0031] The traffic to be processed is sent to the destination user corresponding to the destination MAC address according to the corresponding relationship.

[0032] It can be seen from the above embodiments that the solution provided in this example can solve the service diversion problem of the operator's value-added scenario, eliminate the PPPoE dial-up process, reduce traffic detours, and meet the large bandwidth and high-speed forwarding capabilities.

[0033] According to a second aspect of an embodiment of this specification, a network device is provided, wherein a vBRAS is enabled in the network device, and the network device includes:

[0034] The acquisition module is used to enable the pUP unit to obtain the traffic to be processed from the user end through the user AC port of the VSI module;

[0035] A judgment module is used to determine whether the traffic to be processed is inbound to the cloud based on the destination MAC address of the traffic;

[0036] A processing module, configured to send the traffic to be processed to the edge cloud via the first AC port corresponding to the edge cloud in the VSI when the traffic is determined to be inbound cloud traffic; or

[0037] If the traffic is determined to be non-cloud-bound, it is sent to the public network through the L2VE and L3VE bridge interface in the VSI.

[0038] Wherein, the network device further includes:

[0039] The configuration module is used to configure QINQ / VPN to each user AC port of the pUP through the CP, so that different user AC ports are configured with different QINQ / VPN.

[0040] Wherein, the network device further includes:

[0041] The application module is used to receive the first address application request sent by the user to DHCP through the user AC port of the VSI and transparently transmit it to the DHCP server;

[0042] Receive the first IP address allocated by the DHCP server according to the first address application request, and transparently transmit the first IP address to the user through the corresponding user AC port;

[0043] The AC port connected to the edge cloud sends a second address request to DHCP through the VSI and transparently transmits it to the DHCP server;

[0044] Receive the second IP address allocated by the DHCP server according to the second application address request, and transparently transmit the second IP address to the edge cloud through the AC port connected to the edge cloud.

[0045] The judgment module is further configured to obtain the destination MAC address and query the Layer 2 forwarding table to determine whether the traffic is multi-access traffic.

[0046] The processing module is further configured to, when determining that the traffic is multi-access traffic, establish a correspondence between the QINQ of the user AC port that obtains the traffic to be processed and the QINQ of the user AC port corresponding to the destination MAC address, and send the traffic to be processed to the destination user corresponding to the destination MAC address according to the correspondence.

[0047] It should be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS

[0048] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the specification and, together with the description, serve to explain the principles of the specification.

[0049] Figure 1 This is a schematic diagram of a framework of a fused edge cloud according to an exemplary embodiment of this specification.

[0050] Figure 2This is a flow chart of a method for processing traffic according to an exemplary embodiment of the present specification.

[0051] Figure 3 It is a schematic diagram of the framework of a converged edge cloud gateway according to an exemplary embodiment of this specification. DETAILED DESCRIPTION

[0052] Exemplary embodiments will be described in detail herein, with examples illustrated in the accompanying drawings. In the following description, when referring to the drawings, identical numerals in different figures represent identical or similar elements unless otherwise indicated. The embodiments described in the following exemplary embodiments are not intended to represent all embodiments consistent with this specification. Rather, they are merely examples of apparatus and methods consistent with certain aspects of this specification, as detailed in the appended claims.

[0053] The terms used in this specification are for the purpose of describing specific embodiments only and are not intended to limit this specification. As used in this specification and the appended claims, the singular forms "a," "an," "the," and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise. It should also be understood that the term "and / or" as used herein refers to and encompasses any and all possible combinations of one or more of the associated listed items.

[0054] It should be understood that although the terms first, second, third, etc. may be used in this specification to describe various information, such information should not be limited to these terms. These terms are merely used to distinguish information of the same type from one another. For example, first information may also be referred to as second information, and similarly, second information may also be referred to as first information without departing from the scope of this specification. Depending on the context, the term "if" as used herein may be interpreted as "when," "when," or "in response to determining."

[0055] Currently, home optical modems are set to bridge mode, with a vCPE (vCPE) gateway deployed at the edge cloud. Inbound traffic is routed through the vCPE's MAC table and then to the edge cloud. After internet traffic reaches the vCPE, it obtains a public network address from the pUP via PPPoE. The vCPE acts as a DHCP server on the client side, assigning IP addresses to home users and enabling them to access the public network.

[0056] The above method shows that vCPE is a virtualized network element based on the x86 architecture, with poor forwarding performance. It also needs to dial up to the vBRAS, which is a long process and requires traffic to be detoured.

[0057] To solve the above technical problems, the present disclosure provides a method for processing traffic, which is applied to a device that enables vBRAS, such as Figure 2 As shown, the method includes:

[0058] S201 pUP obtains traffic to be processed from the user end through the user AC port of the VSI;

[0059] S202 determines whether the traffic to be processed is inbound cloud traffic based on the destination MAC address of the traffic to be processed;

[0060] If yes, then send the traffic to be processed to the edge cloud via the first AC port in the VSI corresponding to the edge cloud.

[0061] If not, in S204 , the traffic is sent to the public network through the bridge interface between L2VE and L3VE in the VSI.

[0062] In this embodiment, the administrator can configure QINQ / VPN on each user AC port of the pUP through the CP, so that different user AC ports are configured with different QINQ / VPN, thereby achieving isolation of different users.

[0063] When a user (family) comes online, the first address request sent by the user to DHCP is received through the user AC port of the VSI and transparently transmitted to the DHCP server.

[0064] The DHCP server allocates a first IP address to the user according to the first address application request. The VSI receives the first IP address allocated by the DHCP server according to the first address application request and transparently transmits the first IP address to the user through the corresponding user AC port.

[0065] In this embodiment, the edge cloud is connected to the VSI through the AC port of the VSI. Specifically, the edge cloud may include: an application management part, an application proxy gateway part, and a cloud NAS application part. The application proxy gateway may send a second application address request to the DHCP server, and transparently transmit it to the DHCP server through the VSI. The VSI receives the second IP address allocated by the DHCP server according to the second application address request, and transparently transmits the second IP address to the edge cloud through the AC port connected to the edge cloud, wherein the second IP address and the first IP address belong to the same network segment.

[0066] In this embodiment, after pUP obtains the to-be-processed traffic from the user end through the user AC port of VSI, it queries the destination MAC address of the to-be-processed traffic through the VPLS instance to see whether it points to the edge cloud. If so, it can be determined that the traffic is cloud traffic. At this time, the to-be-processed traffic can be sent to vHOST through the AC port connected to the edge cloud, and the to-be-processed traffic can be sent to the edge cloud server through vHOST.

[0067] In another example, if the traffic is identified as inbound traffic, the traffic to be processed can be sent to the public network via the L2VE bridge to the L3VE port through an ARP / NS request.

[0068] In another example, the destination MAC address is queried. If it is determined that the traffic is multi-access traffic, a correspondence is established between the QINQ of the user AC port of the traffic to be processed and the QINQ of the user AC port corresponding to the destination MAC address, and the traffic to be processed is sent to the destination user corresponding to the destination MAC address according to the correspondence.

[0069] To illustrate the technical solution in the present disclosure in detail, the present disclosure provides an example, such as Figure 3 The figure shows a framework that enables this solution. Traffic is distributed using the vBRAS-pUP device (a high-performance router based on NP) in a new metropolitan area network, with traffic entering through the VPLS AC port. For traffic accessing the edge cloud, the MAC address is queried and forwarded through the AC port on the cloud side. For Internet traffic, it is forwarded through the L2VE port (also an AC port), enters the L3VE port, and accesses the public network via Layer 3. For multi-access traffic, the MAC address is queried and forwarded through the corresponding AC port. Meanwhile, the QINQ is modified. This method solves the traffic distribution issues of converged edge services entering the cloud, Internet access, and multi-access services, providing high-speed, high-bandwidth forwarding capabilities.

[0070] The interface dedicated line is configured. The administrator plans and issues the account opening dedicated line configuration. Each L3VE sub-interface (QINQ) is configured for each household and each VPN, and is bound to an address pool. The gateway is configured under the DHCP address pool, and the interface dedicated line is bound to the VPN.

[0071] The third-party terminal management system acts as a DHCP server. The terminal initiates an address request, which is forwarded at Layer 2 by the VSI and then requested from the terminal management system. The terminal's gateway is on the pUP. The gateway IP address is in the same network segment as the DHCP server, but it has a different IP address.

[0072] Suppose a home terminal wants to access the Internet. It sends an ARP / NS request, which is then bridged via the VSI L2VE interface to the L3VE interface, triggering the user's online access. After NAT translation, the user accesses the Internet. V6 is a public network, so NAT is not required.

[0073] Assume that a home terminal wants to access the edge cloud. It directly searches the Layer 2 table in the VSI and forwards the request to the vHOST.

[0074] Specifically,

[0075] 1. When a home terminal (user) comes online, it requests an address from the terminal management (DHCP server). The DHCP message is forwarded by the intermediate pUP to the terminal management via the VSI Layer 2, and the terminal management assigns an address to the home terminal.

[0076] 2. Simultaneously, a dedicated line interface is configured on the CP. When the interface goes up, AAA authentication is triggered. After authentication passes, a dedicated line session is issued to the pUP, one per household. The pUP also applies for port block resources and reports the port information to the CP via the CUSP channel to complete AAA billing. At this point, a household is online.

[0077] 3. The terminal is triggered to go online through ARP. After pUP receives the ARP message from the terminal, it sends it to CP through VxLAN, inherits the family authorization information, and sends the sub-user session and forwarding table items to pUP.

[0078] 4. After the Internet data reaches pUP, the upstream source address is converted to access the public network according to QINQ and source IP gateway matching home user table. The downstream Internet data is sent to the terminal after the destination address is converted in pUP.

[0079] Among them, the traffic between the home terminal and the edge cloud is forwarded according to the destination MAC within the VPLS instance.

[0080] Specifically, for Internet traffic:

[0081] Uplink traffic:

[0082] 1. The home terminal encapsulates the destination IP address to the public network destination address and the destination MAC address to the gateway MAC address. The packet is marked with QINQ. The packet is encapsulated as SRv6 in the A-leaf, decapsulated in the S-leaf, and sent to the Layer 2 forwarding instance of the converged gateway.

[0083] 2. Query the MAC table in the VSI Layer 2 forwarding instance and send the packet from the L2VE port to the L3VE port.

[0084] 3. After the packet enters the L3VE interface, the destination MAC address is checked for the gateway, which requires a Layer 3 process. The packet is matched against the session table based on the QINQ and source IP network segment. Rate limiting and NAT are then applied, and the source IP address is translated. The packet is then forwarded using IP Global over SRv6. Note: If the terminal's IPv6 source address is a public network address, NAT is not required.

[0085] Downstream traffic:

[0086] 1. The packet is forwarded to the converged edge gateway via IP Global over SRv6. After decapsulation, the destination address is queried. After performing destination IP NAT, the terminal's detailed route is retrieved under the tenant VPN. The source and destination MAC addresses and QINQ are encapsulated and forwarded from the L3VE interface to the L2VE interface. Note: The terminal's IPv6 destination address is a public network address, so NAT is not required.

[0087] 2. After the message enters the L2VE port, it queries the MAC table in the VSI Layer 2 forwarding instance and sends it out from the corresponding AC port.

[0088] 3. The message is encapsulated as SRv6 in the S-leaf, decapsulated as SRv6 in the A-leaf, and then the MAC table is checked. The message is forwarded out of the AC port, and then the inner VLAN is decrypted by the OLT and ONU and transmitted to the home terminal.

[0089] For multi-site intercommunication traffic, the QinQs of multiple homes may differ, requiring VLAN rewriting on the converged edge gateway. For example, intercommunication traffic from Terminal 1 in Home 2 to Terminal 1 in Home 1 enters the converged edge gateway's Layer 2 VPN instance through the bearer network. The MAC address in the Layer 2 VPN instance is then searched to identify the outbound interface. At the outbound interface, the MQC is matched and a QINQ mapping is performed. The traffic is then sent out through the interface.

[0090] It can be seen from the above embodiments that the network architecture and solutions provided in this disclosure can solve the service diversion problem of operators' value-added scenarios, eliminate the PPPoE dial-up process, reduce traffic detours, meet large-bandwidth high-speed forwarding capabilities, carry a large number of users, and can be promoted and applied on a large scale.

[0091] Specifically, through the technical solution disclosed in this disclosure, L2VE to L3VE technology can be used to achieve the diversion of Layer 2 (cloud access, multi-address mutual access) and Layer 3 (Internet access) service traffic. Through the interface dedicated line, the gateway is configured under the DHCP address pool, the interface dedicated line is bound to the VPN, each L3VE sub-interface (QINQ) each household each VPN (each dedicated line represents a household, and the terminals in the household are sub-users), and are respectively bound to the address pool to solve the Internet access problem and cancel PPPoE dial-up at the same time. By adapting the v6 user Internet access process, the interface dedicated line configuration is issued. After the interface is UP, the household user goes online and an RA prefix is allocated to the terminal. After receiving the NS of the terminal, the prefix is notified to the terminal to initiate an NS request, triggering the sub-user to go online. At the same time, each NAT port block of each household is adapted, and the upstream and downstream Internet access traffic is converted by NAT.

[0092] Based on the above method embodiments, the present disclosure further provides a network device, which may be a routing device, a switching device, etc., wherein a vBRAS is enabled in the network device, and the network device includes:

[0093] The acquisition module is used to enable the pUP unit to obtain the traffic to be processed from the user end through the user AC port of the VSI module;

[0094] A judgment module is used to determine whether the traffic to be processed is inbound to the cloud based on the destination MAC address of the traffic;

[0095] A processing module, configured to send the traffic to be processed to the edge cloud via the first AC port corresponding to the edge cloud in the VSI when the traffic is determined to be inbound cloud traffic; or

[0096] If the traffic is determined to be non-cloud-bound, it is sent to the public network through the L2VE and L3VE bridge interface in the VSI.

[0097] Wherein, the network device further includes:

[0098] The configuration module is used to configure QINQ / VPN to each user AC port of the pUP through the CP, so that different user AC ports are configured with different QINQ / VPN.

[0099] Wherein, the network device further includes:

[0100] The application module is used to receive the first address application request sent by the user to DHCP through the user AC port of the VSI and transparently transmit it to the DHCP server;

[0101] Receive the first IP address allocated by the DHCP server according to the first address application request, and transparently transmit the first IP address to the user through the corresponding user AC port;

[0102] The AC port connected to the edge cloud sends a second address request to DHCP through the VSI and transparently transmits it to the DHCP server;

[0103] Receive the second IP address allocated by the DHCP server according to the second application address request, and transparently transmit the second IP address to the edge cloud through the AC port connected to the edge cloud.

[0104] The judgment module is further configured to obtain the destination MAC address and query the Layer 2 forwarding table to determine whether the traffic is multi-access traffic.

[0105] The processing module is further configured to, when determining that the traffic is multi-access traffic, establish a correspondence between the QINQ of the user AC port that obtains the traffic to be processed and the QINQ of the user AC port corresponding to the destination MAC address, and send the traffic to be processed to the destination user corresponding to the destination MAC address according to the correspondence.

[0106] For the device embodiments, since they basically correspond to the method embodiments, the relevant parts can be referred to the partial description of the method embodiments. The device embodiments described above are merely illustrative, wherein the modules described as separate components may or may not be physically separated, and the components displayed as modules may or may not be physical modules, that is, they may be located in one place, or they may be distributed on multiple network modules. Some or all of the modules may be selected according to actual needs to achieve the purpose of the scheme of this specification. A person of ordinary skill in the art can understand and implement it without paying any creative work.

[0107] The foregoing description of this specification describes specific embodiments. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims can be performed in an order different from that described in the embodiments and still achieve the desired results. Furthermore, the processes depicted in the accompanying drawings do not necessarily require the specific order shown or the sequential order to achieve the desired results. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0108] Other embodiments of the present invention will readily occur to those skilled in the art upon consideration of the present invention and practice of the invention claimed herein. This specification is intended to cover any variations, uses, or adaptations of the present invention that follow the general principles of this specification and include common knowledge or customary techniques in the art not claimed herein. The description and examples are to be considered as exemplary only, with the true scope and spirit of the present invention being indicated by the following claims.

[0109] It should be understood that the present description is not limited to the exact structure that has been described above and shown in the drawings, and that various modifications and changes may be made without departing from the scope thereof. The scope of the present description is limited only by the appended claims.

[0110] The above description is only a preferred embodiment of this specification and is not intended to limit this specification. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of this specification should be included in the scope of protection of this specification.

Claims

1. A method for processing traffic, characterized in that: The method is applied to a device enabling vBRAS, and the method includes: pUP obtains traffic to be processed from the user end through the user AC port of the VSI; Determine whether the traffic to be processed is inbound to the cloud based on the destination MAC address of the traffic to be processed. If yes, the traffic to be processed is sent to the edge cloud through the first AC port in the VSI corresponding to the edge cloud; If not, the traffic is sent to the public network through the L2VE and L3VE bridge interface in the VSI.

2. The method according to claim 1, characterized in that The method further comprises: Configure QINQ / VPN on each user AC port of the pUP through CP, so that different user AC ports are configured with different QINQ / VPN.

3. The method according to claim 1, further characterized in that: The method further comprises: The VSI receives the first address request sent by the user to DHCP through the user AC port and transparently transmits it to the DHCP server. The first IP address allocated by the DHCP server according to the first address application request is received, and the first IP address is transparently transmitted to the user through the corresponding user AC port.

4. The method according to claim 1, wherein The method further comprises: The AC port connected to the edge cloud sends a second address request to DHCP through the VSI and transparently transmits it to the DHCP server; Receive the second IP address allocated by the DHCP server according to the second application address request, and transparently transmit the second IP address to the edge cloud through the AC port connected to the edge cloud.

5. The method according to claim 1, wherein The determining whether the traffic to be processed is inbound cloud traffic based on the destination MAC address of the traffic to be processed includes: Check the destination MAC address through the VPLS instance to see if it points to the edge cloud. If so, it is determined to be inbound cloud traffic.

6. The method according to claim 1, characterized in that The method of sending the traffic to be processed to the edge cloud through the first AC port corresponding to the edge cloud in the VSI includes: The traffic to be processed is sent to the vHOST through the AC port connected to the edge cloud, and the traffic to be processed is sent to the edge cloud server through the vHOST.

7. The method according to claim 1, characterized in that Traffic is sent to the public network through the L2VE and L3VE bridge interfaces in the VSI, including: Through ARP / NS requests, the traffic to be processed is bridged via L2VE to the L3VE port and sent to the public network.

8. The method according to claim 1, characterized in that The method further comprises: Obtain the destination MAC address and query the Layer 2 forwarding table to determine whether it is multi-address inter-access traffic; If yes, then establish a correspondence between the QINQ of the user AC port that obtains the traffic to be processed and the QINQ of the user AC port corresponding to the destination MAC address; The traffic to be processed is sent to the destination user corresponding to the destination MAC address according to the corresponding relationship.

9. A network device, characterized in that: The vBRAS is enabled in the network device, and the network device includes: The acquisition module is used to enable the pUP unit to obtain the traffic to be processed from the user end through the user AC port of the VSI module; A judgment module is used to determine whether the traffic to be processed is inbound to the cloud based on the destination MAC address of the traffic; A processing module, configured to send the traffic to be processed to the edge cloud via the first AC port corresponding to the edge cloud in the VSI when the traffic is determined to be inbound cloud traffic; or If the traffic is determined to be non-cloud-bound, it is sent to the public network through the L2VE and L3VE bridge interface in the VSI.

10. The network device according to claim 9, characterized in that The network device further includes: The configuration module is used to configure QINQ / VPN to each user AC port of the pUP through the CP, so that different user AC ports are configured with different QINQ / VPN.

11. The network device according to claim 9, wherein: The network device further includes: The application module is used to receive the first address application request sent by the user to DHCP through the user AC port of the VSI and transparently transmit it to the DHCP server; Receive the first IP address allocated by the DHCP server according to the first address application request, and transparently transmit the first IP address to the user through the corresponding user AC port; The AC port connected to the edge cloud sends a second address request to DHCP through the VSI and transparently transmits it to the DHCP server; Receive the second IP address allocated by the DHCP server according to the second application address request, and transparently transmit the second IP address to the edge cloud through the AC port connected to the edge cloud.

12. The network device according to claim 9, wherein: The judgment module is further used to obtain the destination MAC address and query the Layer 2 forwarding table to determine whether it is multi-access traffic; The processing module is further configured to, when determining that the traffic is multi-access traffic, establish a correspondence between the QINQ of the user AC port that obtains the traffic to be processed and the QINQ of the user AC port corresponding to the destination MAC address, and send the traffic to be processed to the destination user corresponding to the destination MAC address according to the correspondence.