Communication method, device, equipment, computer readable storage medium and program product
Accessing the Wi-Fi network through SD-WAN access devices solves the scenario limitations caused by reliance on DHCP servers and SIM cards in existing technologies. This enables flexible and efficient device deployment and establishment of uplink escape paths in different scenarios, reducing labor and deployment costs.
Patent Information
- Application Number
- CN202410361378.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-03-25
- Publication Date
- 2025-09-26
AI Technical Summary
Existing technologies have scenario limitations during the deployment of SD-WAN access devices. They rely on DHCP servers or SIM cards, which prevents devices from automatically connecting to the Internet and achieving zero-touch deployment, increasing labor and deployment costs.
Access Wi-Fi networks, especially hotspots or public Wi-Fi networks shared by mobile terminals, through SD-WAN access devices to automatically obtain Internet connections and establish uplink escape paths, achieving zero-touch deployment and eliminating dependence on DHCP servers and SIM cards.
It enables flexible, simple, and efficient Internet access and uplink escape path establishment for SD-WAN access devices in different scenarios, reduces manual configuration costs, and improves startup efficiency and device configuration consistency.
Smart Images

Figure CN120711486A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of communication technology, and in particular to communication methods, devices, equipment, computer-readable storage media, and program products. Background Art
[0002] In the field of communications technology, after startup, a device can establish a connection with the Internet, thereby establishing connections with different devices through the Internet to meet the various communication needs of the devices based on the established connections. For example, in a software-defined wide area network (SD-WAN), if the SD-WAN access device needs to be provisioned, the SD-WAN access device can establish a connection with a control device. Through the established connection, the SD-WAN access device can receive a provisioning file including system software, patch files, and other files sent by the control device, and perform configuration based on the provisioning file to achieve zero-touch provisioning (ZTP) provisioning. Summary of the Invention
[0003] This application provides a communication method, apparatus, device, computer-readable storage medium, and program product that can flexibly connect SD-WAN access devices to the Internet and enable deployment or escape through the connection to the Internet. The technical solution is as follows:
[0004] In a first aspect, a communication method is provided, which is applied to an SD-WAN access device, and the method includes: the SD-WAN access device accesses a first wireless network communication technology (Wi-Fi) network; the SD-WAN access device accesses the Internet through the first Wi-Fi network to achieve ZTP start.
[0005] In this application, the SD-WAN access device can automatically connect to the first available Wi-Fi network after startup, and access the Internet through the first Wi-Fi network, thereby achieving ZTP deployment of the SD-WAN access device through the connection to the Internet. In this application, the way the SD-WAN access device accesses the Internet during deployment is flexible, simple, and efficient.
[0006] In one possible implementation, the method further includes establishing an uplink escape path between the SD-WAN access device and the SD-WAN hub (HUB) via a second Wi-Fi network. The SD-WAN access device automatically establishes the uplink escape path via the second Wi-Fi network, providing a flexible, simple, and efficient method for establishing the uplink escape path.
[0007] In one possible implementation, the first Wi-Fi network includes a hotspot shared by mobile terminals or a public Wi-Fi network, where a public Wi-Fi network is a Wi-Fi network shared by devices in a public place. In this application, the types of the first Wi-Fi networks in different scenarios are different, which can improve the flexibility of the SD-WAN access device in accessing the Internet through the first Wi-Fi network and avoid limiting the scenarios in which the SD-WAN access device can access the Internet.
[0008] In one possible implementation, the first Wi-Fi network and the second Wi-Fi network are the same Wi-Fi network. In this application, the deployment of the SD-WAN access device and the establishment of the uplink escape path can be in the same scenario, so the first Wi-Fi network used to implement the deployment of the SD-WAN access device and the second Wi-Fi network used to implement the establishment of the uplink escape path can be the same Wi-Fi network.
[0009] In one possible implementation, ZTP deployment is a registration center deployment. After the SD-WAN access device is connected to the Internet, it can automatically obtain the deployment file for deployment through the registration center deployment method, flexibly implementing ZTP deployment.
[0010] In a second aspect, a communication method is provided, which is applied to an SD-WAN access device, and the method includes: the SD-WAN access device accesses a second Wi-Fi network; and establishing an uplink escape path between the SD-WAN access device and the SD-WAN HUB through the second Wi-Fi network.
[0011] In this application, the SD-WAN access device can automatically access an available second Wi-Fi network and access the Internet through the second Wi-Fi network, and then establish an uplink escape path for the SD-WAN access device through the connection with the Internet. The method of establishing the uplink escape path is flexible, simple and efficient.
[0012] In one possible implementation, based on the method provided in the first aspect or the second aspect, the method further includes: in response to a failure of the wired wide area network (WAN) link between the SD-WAN access device and the SD-WAN HUB, switching the transmission path of the upstream traffic of the SD-WAN access device from the wired WAN link to the upstream escape path. In the present application, if the wired WAN link fails and the SD-WAN access device is unable to access the Internet and communicate with the SD-WAN HUB through the wired WAN link, the SD-WAN access device can avoid the problem of the SD-WAN access device being unable to communicate with the HUB due to the failure of the wired WAN link by switching the transmission path of the upstream traffic of the SD-WAN access device from the wired WAN link to the upstream escape path, thereby ensuring the normal transmission of the upstream traffic of the SD-WAN access device.
[0013] In one possible implementation, based on the method provided in the first or second aspect, the second Wi-Fi network includes a hotspot shared by mobile terminals or a public Wi-Fi network, where a public Wi-Fi network is a Wi-Fi network shared by devices in a public place. In this application, the type of the second Wi-Fi network varies in different scenarios, thereby increasing the flexibility of the SD-WAN access device in accessing the Internet through the second Wi-Fi network and avoiding limiting the scenarios in which the SD-WAN access device can access the Internet.
[0014] In one possible implementation, based on the method provided by the first aspect or the second aspect, the second Wi-Fi network is a public Wi-Fi network, and an uplink escape path is established between the SD-WAN access device and the software-defined wide area network center SD-WAN HUB through the second Wi-Fi network, including: obtaining the account and password of the public Wi-Fi network through a hotspot shared by a mobile terminal; connecting to the public Wi-Fi network based on the account and password; and establishing the uplink escape path through the public Wi-Fi network. The SD-WAN access device obtains the account and password of the public Wi-Fi network through the hotspot shared by the mobile terminal, allowing the SD-WAN access device to successfully access the public Wi-Fi network, and then connect to the Internet through the public Wi-Fi network, thereby flexibly establishing an uplink escape path through the connection to the Internet.
[0015] In one possible implementation, based on the method provided in the first aspect or the second aspect, before establishing an uplink escape path between the SD-WAN access device and the software-defined wide area network center SD-WAN HUB through a second Wi-Fi network, the method further includes: cutting off the wireless connection between the SD-WAN access device and the wireless terminal, the wireless connection being established based on a first frequency band supported by the SD-WAN access device; and establishing an uplink escape path between the SD-WAN access device and the software-defined wide area network center SD-WAN HUB through the second Wi-Fi network, including: establishing an uplink escape path based on the first frequency band through the second Wi-Fi network. If the first frequency band is used to establish a wireless connection between the SD-WAN access device and the wireless terminal, then before establishing the uplink escape path between the SD-WAN access device and the SD-WAN HUB, cutting off the wireless connection between the SD-WAN access device and the wireless terminal, releasing the first frequency band, and then establishing the uplink escape path based on the first frequency band can avoid conflicts in the use of the first frequency band and ensure the successful establishment of the uplink escape path.
[0016] In one possible implementation, based on the method provided in the first aspect or the second aspect, the SD-WAN access device is a Wi-Fi-enabled customer premises equipment (CPE) access gateway or a Wi-Fi-enabled wireless access point (AP). The SD-WAN access device in this application can be a variety of types of devices, making the communication method provided in this application applicable to a variety of scenarios and avoiding scenario limitations.
[0017] In a third aspect, a communication device is provided, which is applied to an SD-WAN access device. The device includes: a first access module for accessing a first Wi-Fi network; and a deployment module for accessing the Internet through the first Wi-Fi network to implement ZTP deployment.
[0018] In one possible implementation, the apparatus further includes an establishment module configured to establish an uplink escape path between the SD-WAN access device and the SD-WAN HUB through a second Wi-Fi network.
[0019] In one possible implementation, the device also includes a switching module, which is used to switch the transmission path of the upstream traffic of the SD-WAN access device from the wired WAN link to the upstream escape path in response to a failure of the wired wide area network (WAN) link between the SD-WAN access device and the SD-WAN HUB.
[0020] In one possible implementation, the SD-WAN access device is a CPE access gateway that supports Wi-Fi or a wireless AP that supports Wi-Fi.
[0021] In a possible implementation, the first Wi-Fi network includes a hotspot shared by mobile terminals or a public Wi-Fi network, where the public Wi-Fi network is a Wi-Fi network shared by devices in a public place.
[0022] In one possible implementation, the second Wi-Fi network is a public Wi-Fi network, and a module is established for obtaining an account and password of the public Wi-Fi network through a hotspot shared by a mobile terminal; connecting to the public Wi-Fi network based on the account and password; and establishing an uplink escape path through the public Wi-Fi network.
[0023] In a possible implementation, the first Wi-Fi network and the second Wi-Fi network are the same Wi-Fi network.
[0024] In a possible implementation, ZTP initiation is initiated by the registration center.
[0025] In one possible implementation, the device also includes a disconnection module, which is used to disconnect the wireless connection between the SD-WAN access device and the wireless terminal, where the wireless connection is established based on a first frequency band supported by the SD-WAN access device; and an establishment module, which is used to establish an uplink escape path through a second Wi-Fi network based on the first frequency band.
[0026] In a fourth aspect, a communication device is provided, which is applied to an SD-WAN access device, and the device includes: a second access module for accessing a second Wi-Fi network; and an establishment module for establishing an uplink escape path between the SD-WAN access device and the SD-WAN HUB through the second Wi-Fi network.
[0027] In one possible implementation, the device also includes a switching module, which is used to switch the transmission path of the upstream traffic of the SD-WAN access device from the wired WAN link to the upstream escape path in response to a failure of the wired wide area network (WAN) link between the SD-WAN access device and the SD-WAN HUB.
[0028] In one possible implementation, the SD-WAN access device is a CPE access gateway that supports Wi-Fi or a wireless AP that supports Wi-Fi.
[0029] In a possible implementation, the second Wi-Fi network includes a hotspot shared by mobile terminals or a public Wi-Fi network, where the public Wi-Fi network is a Wi-Fi network shared by devices in a public place.
[0030] In one possible implementation, the second Wi-Fi network is a public Wi-Fi network, and a module is established for obtaining an account and password of the public Wi-Fi network through a hotspot shared by a mobile terminal; connecting to the public Wi-Fi network based on the account and password; and establishing an uplink escape path through the public Wi-Fi network.
[0031] In one possible implementation, the apparatus further includes a disconnection module, which is used to disconnect the wireless connection between the SD-WAN access device and the wireless terminal, where the wireless connection is established based on a first frequency band supported by the SD-WAN access device; and an establishment module, which is used to establish an uplink escape path based on the first frequency band through a second Wi-Fi network.
[0032] In a fifth aspect, a communication system is provided, which includes the device in the third aspect or any possible implementation of the third aspect, or the system includes the device in the fourth aspect or any possible implementation of the fourth aspect and a control device that interacts with the device.
[0033] In the sixth aspect, a computer program (product) is provided, which includes: computer program code, which, when run by a computer, enables the computer to execute the method in the above-mentioned first aspect or any possible implementation of the first aspect and the method in the above-mentioned second aspect or any possible implementation of the second aspect.
[0034] In the seventh aspect, a computer-readable storage medium is provided, which stores a program or instruction. When the program or instruction is run on a computer, the method in the above-mentioned first aspect or any possible implementation of the first aspect and the method in the above-mentioned second aspect or any possible implementation of the second aspect are executed.
[0035] In an eighth aspect, a chip is provided, comprising a processor for calling and executing instructions stored in a memory from a memory, so that a computer equipped with the chip executes the method in the above-mentioned first aspect or any possible implementation of the first aspect and the method in the above-mentioned second aspect or any possible implementation of the second aspect.
[0036] In the ninth aspect, another chip is provided, comprising: an input interface, an output interface, a processor and a memory, wherein the input interface, the output interface, the processor and the memory are connected through an internal connection path, and the processor is used to execute the code in the memory. When the code is executed, a computer equipped with the chip executes the method in the above-mentioned first aspect or any possible implementation of the first aspect and the method in the above-mentioned second aspect or any possible implementation of the second aspect.
[0037] It should be understood that the beneficial effects achieved by the technical solutions of the third to ninth aspects of this application and the corresponding possible implementation methods can be found in the above-mentioned technical effects of the first or second aspect, as well as any possible implementation method of the first or second aspect, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0038] Figure 1 A schematic diagram of an SD-WAN architecture provided for related technologies;
[0039] Figure 2 A flowchart of a game start process provided for related technologies;
[0040] Figure 3 A flow chart for related technologies;
[0041] Figure 4 Another flow chart provided for related technologies;
[0042] Figure 5 An implementation scenario diagram provided for an embodiment of the present application;
[0043] Figure 6 A flow chart of a communication method provided in an embodiment of the present application;
[0044] Figure 7 A schematic diagram of a communication process provided by an embodiment of the present application;
[0045] Figure 8 A schematic diagram of another communication process provided in an embodiment of the present application;
[0046] Figure 9 A schematic diagram of a process for establishing an upward escape path provided in an embodiment of the present application;
[0047] Figure 10 A schematic diagram of another process for establishing an upward escape path provided in an embodiment of the present application;
[0048] Figure 11 A schematic diagram of a process for establishing a first connection and an uplink escape path provided in an embodiment of the present application;
[0049] Figure 12 A schematic diagram of an SD-WAN architecture provided in an embodiment of the present application;
[0050] Figure 13 A flowchart of another communication method provided in an embodiment of the present application;
[0051] Figure 14 A schematic structural diagram of a communication device provided in an embodiment of the present application;
[0052] Figure 15 A schematic structural diagram of a communication device provided in an embodiment of the present application;
[0053] Figure 16 A schematic diagram of the structure of a communication device provided in an embodiment of the present application;
[0054] Figure 17 A schematic diagram of the structure of another communication device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0055] The terms used in the implementation section of this application are only used to explain the specific embodiments of this application and are not intended to limit this application.
[0056] With the continuous advancement of digital communications technology, enterprise applications are migrating to the cloud, leading to a continuous increase in wide area network (WAN) egress traffic at each enterprise site. For example, as traditional office work models and local data storage models evolve towards the cloud, enterprises are sending office and local data to the internet via WAN egress, increasing WAN egress traffic.
[0057] A WAN is a long-distance network that connects local area networks (LANs) or metropolitan area networks (MANs) in different regions for computer communications. It can provide long-distance communications for multiple connected areas within its coverage area, such as cities, countries, or continents. Enterprises typically build WANs by leasing line resources provided by carriers. For example, they may lease a multi-service transport platform (MSTP) point-to-point dedicated line to build a WAN connection between a branch site and the corporate headquarters, or they may lease a carrier's Internet line to connect branch sites to the corporate headquarters or data center through an Internet protocol security (IPsec) virtual private network (VPN).
[0058] In addition, cloud computing has become the underlying technology and foundation for the development of many emerging technologies. The development and application of technologies such as virtual reality (VR), artificial intelligence, driverless cars, and blockchain are all closely related to cloud computing. The rapid development of cloud computing will also accelerate the cloudification of traditional office models and local data storage models of enterprises, further increasing the WAN egress traffic of enterprises.
[0059] SD-WAN has emerged as a response to the trend of cloud-based enterprise services. SD-WAN is a collection of technologies, primarily applying software-defined networking (SDN) to wide area network management. Features of SD-WAN include, but are not limited to, the ability to leverage public and private WAN networks in an active-active manner; zero-configuration deployment based on business models; unified service orchestration in multi-cloud environments; on-demand hybrid network expansion; dynamic application-based network adjustments; reduced network connectivity costs; and the flexible use of a variety of WAN links, such as various types of digital subscriber lines (DSL), long-term evolution (LTE) or fifth-generation mobile communication technology (5G) links, multi-protocol label switching (MPLS) links, or the Internet.
[0060] See also Figure 1 , shows an SD-WAN architecture provided by related technologies, which includes a service presentation layer, a network orchestration / control layer, and a network connection layer. The service presentation layer includes systems for providing communication services, such as the business support system (BSS) and the operation support system (OSS), as well as a self-service portal and a value-added service (VAS) store. The SD-WAN manager and controller are centrally deployed to achieve centralized SD-WAN network management and control.
[0061] The network orchestration / control layer includes open application programming interfaces (APIs) and one or more route reflectors (RRs) that can be provided by the cloud.
[0062] RR is the central point for storing and forwarding routing entries in the SD-WAN architecture, and can connect various software-defined branches (SD-Branch) in the SD-WAN architecture, such as Figure 1 In the example, RRs connect Branch A, Branch B, and Branch C. SD-Branch is an extension of SD-WAN to the LAN side. SD-Branch allows the network functions of multiple branches to be managed as a single structure. SD-Branch supports four network functions: WAN gateway, wired switching, WLAN, and firewall; unified configuration, policy, reporting, visualization, and automation across these four functions through a single console; zero-touch provisioning (ZTP) configuration for initial configuration and automated operational tasks; and fully supported, documented, and published APIs.
[0063] Each branch can be considered as a site of the enterprise, and SD-WAN edge devices are deployed at the WAN exit of each site. For example, Figure 1 The CPE in each branch is the SD-WAN Edge device deployed at the WAN exit of each site. The Edge devices between multiple sites of the enterprise are based on the WAN network (such as Figure 1 SD-WAN overlay tunnels are established using MPLS, Internet, and LTE (as shown in the figure) to enable inter-site service access. SD-branch complements SD-WAN, and the SD-branch solution can manage SD-WAN products. Furthermore, SD-branch technology enables enterprises to centrally deploy a single policy, which is automatically deployed to multiple devices at a site or across multiple sites.
[0064] The aforementioned ZTP function automatically loads deployment files during the power-up of newly shipped or blank-configured devices. These files can include system software, patches, and configuration files. By running ZTP, information technology (IT) personnel and network operators who deploy devices can deploy them without having to manually configure them, reducing the time and errors associated with manual configuration. Especially when configuring large numbers of devices, running ZTP can speed up deployment, minimize errors, and ensure consistent configuration across multiple devices.
[0065] Various devices and tools in the SD-WAN architecture can run the ZTP function, such as network switches (SW), routers, wireless access points, and firewalls. All of these devices and tools can achieve automatic deployment by running the ZTP function. Figure 2 This figure shows a ZTP-based deployment process flow diagram provided by related technologies. After a new or unconfigured device is physically connected and powered on, it runs the ZTP function to automatically discover and retrieve the deployment file. The deployment file is then automatically loaded and provisioned, completing the deployment. ZTP eliminates the need for on-site device configuration and deployment, reducing labor costs, improving deployment efficiency, and enabling plug-and-play (PnP) deployment.
[0066] In the field of communications technology, there are various ways to implement automatic deployment based on the ZTP function. Below, several related technologies for implementing automatic deployment based on the ZTP function are described with reference to the accompanying drawings.
[0067] Related technology 1 is the registration center start method, see Figure 3 , shows a flow chart of the related technology 1. In step 31, the network administrator uses the client to control the campus network management control system ( Figure 3 The network cloud system for campus management (iMaster network cloud engine-campus, iMaster NCE-Campus, referred to as NCE) is used to complete the deployment of various devices to be deployed within the site (such as Figure 3The network configuration and deployment of the CPE (CPE in the site) is completed, and the ZTP configuration of each device to be deployed is completed through the NCE connection to the registration center. In step 32, the site deployment personnel (such as installation or maintenance engineers) complete the physical wiring of the CPE, and the CPE is powered on and started. In step 33, the WAN side interface of the site's CPE applies for an Internet Protocol (IP) address from the DHCP server through the Dynamic Host Configuration Protocol (DHCP), and DHCP assigns an IP address to the CPE. The CPE also resolves the domain name to the registration center through the Domain Name System (DNS) server. In step 34, based on the obtained IP address, the CPE connects to the WAN network through the underlying (underlay) connection and sends a query request to the registration center to obtain the NCE address and port number. In step 35, the CPE automatically registers with the NCE according to the NCE address and port number. After registration, it receives the deployment file sent by the NCE and completes the deployment according to the deployment file.
[0068] Related technology 1 relies on a DHCP server to assign IP addresses to CPEs. The CPE can only initiate a registration request to the NCE after accessing the WAN network through the underlay network based on the IP address, thereby obtaining the deployment file and implementing deployment. However, in some scenarios, a DHCP server is not deployed, making it difficult for the CPE to obtain an IP address and access the WAN, making it difficult to establish a connection between the CPE and the NCE network, and further difficult to obtain the deployment file and implement deployment through the connection between the CPE and the NCE. Related technology 1 has certain scenario limitations.
[0069] Related technology 2 is the DHCP option (option) opening method, see Figure 4, showing a flow chart of related technology 2. In step 41, the network administrator completes the network configuration deployment of the CPE to be deployed at the site on the NCE through the client, and implements the ZTP configuration of the CPE. In step 42, the network administrator completes the configuration of allocating IP addresses, gateways, NCE's southbound IP addresses, port numbers and other information to the CPE interfaces on the DHCP server. In step 43, the site deployment personnel (such as installation or maintenance engineers) complete the physical wiring of the CPE, and the CPE starts after powering on. In step 44, the device interface of the CPE applies for an IP address from the DHCP server through DHCP. The DHCP server allocates an IP address to the CPE and passes information such as the NCE's address and port number to the CPE through the Option of the DHCP message. In step 45, after the CPE accesses the WAN network through the Underlay connection based on the IP address access, it automatically registers with the NCE and completes the deployment according to the deployment file returned by the NCE.
[0070] Related Technology 2 relies not only on a DHCP server but also on pre-configured DHCP Option 148 parameters for the DHCP server. This makes it applicable in scenarios where carriers provide lines. However, in scenarios where enterprises build their own SD-WAN architecture and their CPEs connect to the carrier's internet, since enterprises do not pre-configure DHCP Option 148 parameters on the DHCP server when building their own SD-WAN architecture, Related Technology 2 is not applicable and has scenario limitations.
[0071] In response to the problems of related technologies 1 and 2, when the WAN side access is a device with a fixed IP address or a device with a point-to-point protocol over Ethernet (PPPOE) dial-up function, it is not necessary to rely on the IP address assigned by DHCP. However, devices configured with IP addresses and devices with PPPOE dial-up function are not empty configuration devices, and therefore cannot be started based on the ZTP function.
[0072] In addition, related technology 3 provides a device equipped with a long-term evolution (LTE) module. Related technology 3 also does not rely on the IP address assigned by the DHCP server during deployment. After inserting a subscriber identity module (SIM) card and powering on, the device equipped with the LTE module automatically connects to the WAN and sends a registration request to the registration center to obtain information such as the address and port number of the NCE. Based on the address and port number of the NCE, the device registers with the NCE, obtains the deployment file, and then deploys the network.
[0073] Related technology 3 requires site staff to not only complete the physical wiring but also insert the SIM card during device deployment. Inserting the SIM card into the LTE module is a complex process, increasing labor costs. Furthermore, related technology 3 requires companies to purchase additional SIM cards, further increasing deployment costs.
[0074] In summary, the problems encountered during device provisioning in Related Technologies 1 to 3 include, but are not limited to, reliance on a DHCP server, which limits the use of specific scenarios, and the need for a SIM card, which results in high labor and provisioning costs. The present invention provides a communication method that enables devices to automatically connect to the Internet and implement ZTP provisioning without relying on a DHCP server or SIM card.
[0075] For example, see Figure 5 , shows an implementation scenario diagram provided by an embodiment of the present application, which can be used to execute the communication method provided by an embodiment of the present application. Figure 5 As shown, the implementation scenario includes an SD-WAN access device 51, and a connection is to be established between the SD-WAN access device 51 and the Internet for the SD-WAN access device to implement ZTP start-up.
[0076] Optionally, the SD-WAN access device 51 can be any Wi-Fi-enabled network device waiting to be deployed in any site such as an enterprise branch, headquarters, data center (DC), and cloud in the SD-WAN architecture. For example, the SD-WAN access device can be a Wi-Fi-enabled CPE access gateway or a Wi-Fi-enabled wireless AP. The SD-WAN access device 51 belongs to the network layer in the SD-WAN architecture and can provide a network connection foundation for enterprise branch sites, meeting the business needs of terminal devices in the enterprise branch sites for Internet access, mutual access, and cloud computing. In addition, the SD-WAN access device 51 can also have the function of providing SD-WAN value-added services.
[0077] In addition, the implementation scenario may also include a registration center 52, a control device 53, an SD-WAN HUB54 and a wireless terminal 55. The SD-WAN access device 51 can access the Internet through a first Wi-Fi network, and communicate with the registration center 52 and the control device 53 respectively to realize the ZTP start of the SD-WAN access device. Moreover, the SD-WAN access device 51 can also establish an uplink escape path with the SD-WAN HUB54 through a second Wi-Fi network. After accessing the Internet, the SD-WAN access device can also share the LAN so that the wireless terminal 55 within the site can also access the Internet, realizing communication between the wireless terminal 55 and various devices connected to the Internet. Regarding the various devices in this implementation scenario and the communication process between the SD-WAN access device 51 and various devices, please refer to the description in the following embodiments, which will not be elaborated here.
[0078] See also Figure 6 , shows a flow chart of the communication method provided by the embodiment of the present application. The method can be applied to Figure 5 The SD-WAN access device 51 in the illustrated implementation scenario is as follows: Figure 6 As shown, the method includes but is not limited to the following S601 to S602.
[0079] S601, the SD-WAN access device accesses the first Wi-Fi network.
[0080] After the SD-WAN access device is physically wired and powered on, it enters the startup process. Physical wiring of the SD-WAN access device includes, but is not limited to, power cables and serial cables. After the SD-WAN access device boots up, it enters the deployment process. The first step in SD-WAN access device deployment is obtaining the deployment file. Since the SD-WAN access device is a blank-configuration device—that is, no deployment file is configured on it—it connects to the internet and obtains the deployment file over the internet, enabling ZTP deployment of the SD-WAN access device.
[0081] In an embodiment of the present application, the SD-WAN access device is a device that supports Wi-Fi. After startup, the SD-WAN access device can access a first Wi-Fi network connected to the Internet based on Wi-Fi. Optionally, the first Wi-Fi network includes a hotspot shared by mobile terminals or a public Wi-Fi network. The public Wi-Fi network is a Wi-Fi network shared by devices in a public place. The mobile terminal can be a mobile terminal device such as a mobile phone, tablet, or portable computer that can enable a hotspot function. By enabling the hotspot function, the mobile terminal provides the first Wi-Fi network to the SD-WAN access device, allowing the SD-WAN access device to access the first Wi-Fi network. The public Wi-Fi network can be provided by any device in the public place. For example, the public Wi-Fi network can be provided by a router in the place. The devices in the public place provide the first Wi-Fi network to the SD-WAN access device by enabling the Wi-Fi function, allowing the SD-WAN access device to access the first Wi-Fi network. Exemplarily, the type of the first Wi-Fi network can be WLAN.
[0082] The embodiments of the present application do not limit the manner in which the SD-WAN access device accesses the first Wi-Fi network. For example, the SD-WAN access device accessing the first Wi-Fi network may include: accessing the first Wi-Fi network indicated by the first Wi-Fi network information according to the first Wi-Fi network information. The first Wi-Fi network information may include a service set identifier (SSID) and a password for the first Wi-Fi network. The SSID of the first Wi-Fi network may also be referred to as an account for the first Wi-Fi network.
[0083] Before the SD-WAN access device accesses the first Wi-Fi network based on the first Wi-Fi network information, the SD-WAN access device must first obtain the first Wi-Fi network information. Optionally, the first Wi-Fi network information can be configured on the SD-WAN access device or sent by a terminal to the SD-WAN access device. The following describes how the SD-WAN access device obtains the first Wi-Fi network information, using Cases 11 and 12 as examples.
[0084] Case 11: The first Wi-Fi network information is configured on the SD-WAN access device.
[0085] In scenario 11, the SD-WAN access device can search for a Wi-Fi network that matches the first Wi-Fi network information using the configured first Wi-Fi network information, and access the first Wi-Fi network according to the instructions of the first Wi-Fi network information. For example, if the first Wi-Fi network information includes account 1 and password 1 corresponding to the first Wi-Fi network, the SD-WAN access device can automatically search for a Wi-Fi network with account 1 after startup. This Wi-Fi network is the first Wi-Fi network, and the SD-WAN access device can then access the first Wi-Fi network using password 1.
[0086] In this case, not only does the first Wi-Fi network information need to be configured on the SD-WAN access device, but the corresponding first Wi-Fi network information also needs to be configured on the device providing the first Wi-Fi network to ensure that the SD-WAN access device can find and access the first Wi-Fi network that matches the first Wi-Fi network information. For example, if the first Wi-Fi network information includes Account 2 and Password 2 for the first Wi-Fi network, the account for the Wi-Fi network provided by the site staff via the mobile hotspot can be configured as Account 2, and the password can be configured as Password 2. After startup, the SD-WAN access device can use the first Wi-Fi network information to find the Wi-Fi network with Account 2. This Wi-Fi network is the first Wi-Fi network, and the SD-WAN access device can then access the first Wi-Fi network using Password 2.
[0087] Case 12: The first Wi-Fi network information is sent by the terminal to the SD-WAN access device.
[0088] In scenario 12, the SD-WAN access device can first connect to the Wi-Fi network provided by the terminal via the hotspot, establish a connection between the SD-WAN access device and the terminal, and receive the first Wi-Fi network information sent by the terminal via the connection. In this scenario, the first Wi-Fi network information can be a public Wi-Fi network. The SD-WAN access device first establishes a connection with the terminal, obtains the first Wi-Fi network information, and then connects to the first Wi-Fi network based on the first Wi-Fi network information.
[0089] For example, site staff can provide Wi-Fi network 1 through a mobile phone hotspot, and Wi-Fi network 1 is a Wi-Fi network that can be accessed without a password. After startup, the SD-WAN access device searches for accessible Wi-Fi networks. When Wi-Fi network 1 is found, it attempts to access it. Since Wi-Fi network 1 is a Wi-Fi network that can be accessed without a password, the SD-WAN access device can successfully access Wi-Fi network 1. In response to the SD-WAN access device having accessed Wi-Fi network 1, the site staff sends the account number 3 and password 3 of the public Wi-Fi network 3 to the SD-WAN access device via mobile phone. After receiving the account number 3 and password 3 of the public Wi-Fi network 3, the SD-WAN access device can cancel access to Wi-Fi network 1 and search for Wi-Fi network 3 with the account number 3. After finding Wi-Fi network 3, the SD-WAN access device accesses Wi-Fi network 3 based on password 3. Among them, the account 3 and password 3 of the public Wi-Fi network 3 are the first Wi-Fi network information, the Wi-Fi network 3 is the first Wi-Fi network, and the public Wi-Fi network is the first Wi-Fi network.
[0090] S602: The SD-WAN access device accesses the Internet through the first Wi-Fi network, achieving ZTP deployment.
[0091] Based on the previous description of the relevant technology, it can be seen that ZTP deployment can be achieved through various deployment methods. The embodiment of the present application does not limit the method for implementing ZTP deployment on the SD-WAN access device. The following uses ZTP deployment as an example to illustrate the process of the SD-WAN access device accessing the Internet through the first Wi-Fi network and implementing ZTP deployment.
[0092] During the process of registration center startup of the SD-WAN access device, the SD-WAN access device needs to obtain the startup file from the control device connected to the Internet. Therefore, the SD-WAN access device needs to establish a connection and communicate with the control device to obtain the startup file. Among them, the control device can be a device that can provide startup files for the SD-WAN access device, such as NCE, a device that supports NCE, a hardware component or software component of a device that supports NCE, and an SD-Branch unified management platform (or network management platform). The control device belongs to the management layer in the SD-WAN architecture. The management layer includes not only the control device, but also optional components such as NCE-Campus Network Analyzer (Campus Insight). The management layer has the ability to perform configuration management, network service management, orchestration or operation and maintenance, service maintenance, fault detection, network performance control and visualization functions, and security threat analysis on the WAN network within the SD-WAN architecture.
[0093] After enterprise users at the network layer subscribe to management services from the management layer, the management layer can provide management services to network layer users. For example, in an embodiment of the present application, an SD-WAN access device, acting as an enterprise user, can access a Wi-Fi network connected to the Internet, thereby accessing the Internet and establishing a connection with an Internet-connected control device. The SD-WAN access device then obtains the provisioning files for the SD-WAN access device, which were deployed on the control device based on the ZTP provisioning service, from the control device through the ZTP provisioning service it subscribed to.
[0094] Exemplarily, establishing a connection between the SD-WAN access device and the control device may include: the SD-WAN access device sends a first registration request to the registration center; receiving the IP address of the control device sent by the registration center based on the first registration request; and establishing a first connection based on the IP address of the control device, where the first connection is the connection between the SD-WAN access device and the control device.
[0095] Before the SD-WAN access device sends the first registration request to the registration center, the SD-WAN access device may first establish a connection with the registration device in the registration center. The process of establishing a connection between the SD-WAN access device and the registration device in the registration center may include: obtaining the address of the registration device; and establishing a connection between the SD-WAN access device and the registration device based on the address of the registration device. The embodiment of the present application does not limit the manner in which the SD-WAN access device obtains the address of the registration device. For example, the address of the registration device may be configured for the SD-WAN access device manually or by a configuration device before the SD-WAN access device leaves the factory.
[0096] In one possible implementation, after the SD-WAN access device obtains the address of the registration device, it can establish a connection between the SD-WAN access device and the registration device according to the address of the registration device.
[0097] The embodiments of the present application do not limit the type of connection established between the SD-WAN access device and the registration device. For example, the connection established between the SD-WAN access device and the registration device can be a configuration distribution channel based on the network configuration protocol over secure shell (Netconf over SSH) and a performance data reporting channel based on the hypertext transfer protocol (HTTP) 2.0.
[0098] For example, see Figure 7, showing a schematic diagram of a communication process. The access router (AR) is the SD-WAN access device in the site. After the AR is powered on, the site staff turns on the mobile phone hotspot (i.e., the first Wi-Fi network), which is configured according to the first Wi-Fi network information. Afterwards, the AR connects to the first Wi-Fi network according to the instructions of the first Wi-Fi network information and accesses the Internet through the first Wi-Fi network. Afterwards, the SD-WAN access device sends a connection request to the registration device in the registration center connected to the Internet to establish a connection between the AR and the registration device.
[0099] See also Figure 8 , showing a schematic diagram of another communication process. AR is an SD-WAN access device in the site. After the AR is powered on, the staff of the site turns on the mobile phone hotspot and shares the Wi-Fi network 1, which is configured according to the specifications (including account and password) in the default Wi-Fi network information. AR accesses the Wi-Fi network 1 according to the default configuration and establishes a connection with the mobile phone for communication. The mobile phone sends the first Wi-Fi network information to the AR through the connection between the mobile phone and the AR, and the first Wi-Fi network information includes information about the public Wi-Fi network. Based on the information about the public Wi-Fi network, the AR accesses the public Wi-Fi network and accesses the Internet through the Internet access service provided by the Internet access provider (ISP) 1. In addition, the registration device in the registration center can access the Internet according to the Internet access service provided by ISP2. ISP1 and ISP2 can be the same ISP or different ISPs, and this embodiment of the present application does not limit this. Afterwards, the AR can send a connection request to the registration device and establish a connection with the registration device according to the connection request.
[0100] After the connection between the SD-WAN access device and the registration device is established, the SD-WAN access device may send a first registration request to the registration center to which the registration device belongs based on the connection between the registration device. Optionally, the first registration request may include identification information of the SD-WAN access device, and the SD-WAN access device may send the first registration request to the registration center based on the Link Layer Discovery Protocol (LLDP).
[0101] The identification information of the SD-WAN access device may be any information capable of identifying the SD-WAN access device, such as an equipment serial number (ESN) or a media access control (MAC) address of the SD-WAN access device. The identification information is used by the registration center to determine the IP address of the control device based on a stored first mapping relationship, where the first mapping relationship includes a mapping relationship between the identification information and the IP address of the control device.
[0102] The embodiment of the present application does not limit the manner in which the registration center obtains the first mapping relationship. For example, the first mapping relationship can be sent by the control device to the registration center, or can be generated autonomously by the registration center. Regardless of whether the first mapping relationship is generated by the control device and sent to the registration center, or is generated autonomously by the registration center, before generating the first mapping relationship, the control device needs to obtain the identification information of the SD-WAN access device, so that the registration center or the control device generates the first mapping relationship based on the identification information of the SD-WAN access device. For example, before the SD-WAN access device leaves the factory, the staff can input the identification information of the SD-WAN access device on the control device, indicating that the SD-WAN access device is a legal device that can establish a connection with the control device, thereby enabling the control device to obtain the identification information of the SD-WAN access device. In addition, the site services carried by the SD-WAN access device and the startup files of the SD-WAN access device can also be configured on the control device.
[0103] Taking the example of the first mapping relationship being sent by the control device to the registration center, after the control device obtains the identification information of the SD-WAN access device, the control device can generate the first mapping relationship based on the identification information of the SD-WAN access device and the IP address of the control device. In one possible implementation, the first mapping relationship can include not only the mapping relationship between the tag information of the SD-WAN access device and the IP address of the control device, but also the mapping relationship between the identification information of the SD-WAN access device and other information, such as the port number or domain name of the control device.
[0104] For example, if the first mapping information includes a mapping relationship between the identification information of the SD-WAN access device and the IP address and port number of the control device, the control device can determine the type of the SD-WAN access device based on the identification information of the SD-WAN access device, and according to the type of the SD-WAN access device, determine the port on the control device that can communicate with the device of this type, and then assign the port number of the port to the SD-WAN access device, generate a first mapping relationship including the mapping relationship between the identification information of the SD-WAN access device and the IP address and port number of the control device, and send the first mapping relationship to the registration center.
[0105] Alternatively, taking the example of the first mapping relationship being autonomously generated by the registration center, after obtaining the identification information of the SD-WAN access device, the control device may synchronize the identification information of the SD-WAN access device with the registration center and send the IP address of the control device to the registration center. Optionally, the control device may also send one or more port numbers of the control device to the registration center. The registration center may then autonomously generate the first mapping relationship based on the information sent by the control device.
[0106] Regardless of how the registration center obtains the first mapping relationship, the registration center can determine the IP address of the control device based on the identification information of the SD-WAN access device and the first mapping relationship, and return the IP address of the control device to the SD-WAN access device. Optionally, the registration center can also determine the port number of the control device corresponding to the SD-WAN access device based on the first mapping relationship, and return it to the SD-WAN access device together with the IP address of the control device. After receiving the IP address of the control device sent by the registration center, the SD-WAN access device can establish a first connection with the control device based on the IP address of the control device. Alternatively, the SD-WAN access device can establish a first connection with the control device based on the IP address and port number of the control device.
[0107] In one possible implementation, establishing a first connection with the control device based on the IP address of the control device may include: sending a connection request to the control device based on the IP address of the control device; and establishing a connection between the SD-WAN access device and the control device based on the connection request. The process for the SD-WAN access device to establish the first connection with the control device based on the connection request may refer to the process for the SD-WAN access device to establish a connection with the registration device based on the connection request, and is not further described here.
[0108] Continue to see Figure 7After the AR accesses the mobile phone hotspot and establishes a connection with the registration device, since the registration device stores a first mapping relationship corresponding to the AR, the registration device can send a control device (i.e. Figure 7 Afterwards, the AR may send a connection request to the NCE based on the IP address of the NCE, and after receiving the information sent by the NCE agreeing to establish the connection, establish a first connection with the NCE.
[0109] Accordingly, based on the above Figure 8 According to the description, after the AR accesses the public Wi-Fi network and establishes a connection with the registration device, the registration device can also send the IP address of the NCE to the AR according to the first mapping relationship, so that the AR sends a connection establishment request to the NCE according to the IP address of the NCE to establish the first connection between the AR and the NCE.
[0110] After the SD-WAN access device establishes a connection with the control device, it can request a deployment file from the control device to implement ZTP deployment. In one possible implementation, the SD-WAN access device requests the deployment file from the control device, including: sending a second registration request to the control device based on the first connection; receiving the deployment file returned by the control device based on the second registration request; and configuring the SD-WAN access device according to the deployment file to complete the deployment of the SD-WAN access device.
[0111] As can be seen from the foregoing description, before the SD-WAN access device leaves the factory, a staff member can configure the SD-WAN access device's provisioning file on the control device. Thus, after the control device receives the second registration request from the SD-WAN access device, it can return the provisioning file to the SD-WAN access device. Optionally, the second registration request can include identification information of the SD-WAN access device, enabling the control device to accurately determine the provisioning file for the SD-WAN access device based on the identification information of the SD-WAN access device.
[0112] After receiving the deployment file from the control unit, the SD-WAN access device can configure itself according to the deployment file, achieving ZTP deployment of the SD-WAN access device. For example, the SD-WAN access device can patch and update the SD-WAN access device based on the patch file in the deployment file; or automatically install the corresponding system software based on the system software installation package in the deployment file. In this embodiment of the present application, deployment of the SD-WAN access device does not require a professional engineer to be on-site. Site staff can simply perform simple operations to achieve ZTP deployment of the SD-WAN access device, achieving plug-and-play operation of the SD-WAN access device.
[0113] After the start-up, the SD-WAN access device can be put into use to carry various businesses within the site. In addition, after the SD-WAN access device is connected to the Internet through the first Wi-Fi network, it can establish connections with various devices connected to the Internet according to business needs, so as to communicate with various devices through the established connections and realize business-related operations. For example, if the SD-WAN access device is an AR in an enterprise branch site, the SD-WAN access device can establish a connection with the SD-WAN HUB in the enterprise headquarters to exchange data with the enterprise headquarters through the connection between the SD-WAN HUB and grant the user on the SD-WAN access device the network permission to access the headquarters' data.
[0114] In some cases, the SD-WAN access device can establish multiple connections with the SD-WAN HUB to ensure normal communication between the SD-WAN access device and the SD-WAN HUB by switching different connections in different situations. For example, the SD-WAN access device can establish two tunnels with the SD-WAN HUB: a primary tunnel and a backup tunnel. The backup tunnel can also be called an uplink escape path or escape tunnel. It is used by the SD-WAN access device to send uplink traffic to the SD-WAN HUB when the primary tunnel fails.
[0115] The embodiment of the present application does not limit the manner in which the SD-WAN access device establishes an uplink escape path. For example, the SD-WAN access device can establish an uplink escape path between the SD-WAN access device and the SD-WAN HUB through a second Wi-Fi network.
[0116] The second Wi-Fi network includes a hotspot or a public Wi-Fi network shared by mobile terminals. Since the two processes of SD-WAN access device deployment and establishment of an uplink escape path can be implemented in the same scenario, the first Wi-Fi network used to implement SD-WAN access device deployment and the second Wi-Fi network used to implement the uplink escape path establishment can be the same Wi-Fi network, or the first Wi-Fi network and the second Wi-Fi network can also be different Wi-Fi networks, which is not limited in this embodiment of the present application.
[0117] Exemplarily, the SD-WAN access device accessing the second Wi-Fi network includes: accessing the second Wi-Fi network indicated by the second Wi-Fi network information via the second Wi-Fi network according to the second Wi-Fi network information, where the second Wi-Fi network information is configured on the SD-WAN access device or sent by the terminal to the SD-WAN access device. The process of the SD-WAN access device accessing the second Wi-Fi network via the second Wi-Fi network can refer to the process of the SD-WAN access device accessing the first Wi-Fi network via the first Wi-Fi network, and is not further described here.
[0118] Taking the second Wi-Fi network as a public Wi-Fi network as an example, an uplink escape path is established between the SD-WAN access device and the software-defined wide area network center SD-WAN HUB through the second Wi-Fi network, including: obtaining the public Wi-Fi network account and password through the hotspot shared by the mobile terminal; connecting to the public Wi-Fi network based on the account and password; and establishing an uplink escape path through the public Wi-Fi network. The process of the SD-WAN access device obtaining the public Wi-Fi network account and password through the hotspot shared by the mobile terminal and connecting to the public Wi-Fi network can be referred to the description in the above situation 12 and will not be repeated here.
[0119] In the process of the SD-WAN access device establishing an uplink escape path through a public Wi-Fi network, the SD-WAN access device may also first access the Internet through the public Wi-Fi network, and then establish an uplink escape path with the SD-WAN HUB connected to the Internet. The embodiment of the present application does not limit the type of the uplink escape path. For example, the type of the uplink escape path can be a generic routing encapsulation (GRE) tunnel, a generic routing encapsulation over internet protocol security (GRE over IPsec) tunnel, or a virtual extensible local area network (VxLAN) tunnel.
[0120] Taking the uplink escape path type as GRE tunnel as an example, the tunnel protocol, tunnel source address, tunnel destination address and static route (route-static) pointing to the tunnel are configured on the SD-WAN access device; the tunnel protocol, tunnel source address, tunnel destination address and static route pointing to the tunnel are configured on the SD-WAN HUB; based on the configuration of the SD-WAN access device and the configuration of the SD-WAN HUB, a GRE tunnel is established between the SD-WAN access device and the SD-WAN HUB.
[0121] Among them, the tunnel protocol configured on the SD-WAN access device and the SD-WAN HUB is the GRE protocol, the tunnel source address configured on the SD-WAN access device is the IP address of the SD-WAN access device, the tunnel destination address configured on the SD-WAN access device is the IP address of the SD-WAN HUB, and the static route pointing to the tunnel configured on the SD-WAN access device is a static route that can point to the tunnel interface created on the SD-WAN access device. The tunnel source address configured on the SD-WAN HUB is the IP address of the SD-WAN HUB, the tunnel destination address configured on the SD-WAN HUB is the IP address of the SD-WAN access device, and the static route pointing to the tunnel configured on the SD-WAN HUB is a static route that can point to the tunnel interface created on the SD-WAN HUB.
[0122] For example, taking the configuration on the SD-WAN access device as an example, the tunnel interface created on the SD-WAN access device is interface Tunnel0 / 0 / 1, the tunnel protocol is configured as tunnel-protocol gre, the tunnel source address is configured as source 10.1.12.1, the tunnel destination address is specified as destination 10.1.12.2, and a static route pointing to the tunnel is configured as ip route-static 192.168.2.0 24Tunnel 0 / 0 / 1.
[0123] After the configuration is completed, the SD-WAN access device can use the Internet packet explorer (Ping) to test whether data packets can be exchanged between the SD-WAN access device and the SD-WAN HUB. If the data packets sent by the SD-WAN access device to the SD-WAN HUB can be received by the SD-WAN HUB, and the SD-WAN access device can receive the data packets sent by the SD-WAN HUB, it means that the tunnel between the SD-WAN access device and the SD-WAN HUB has been successfully established.
[0124] In an embodiment of the present application, an uplink escape tunnel can be established not only after the SD-WAN access device is put into operation, but also when the wired WAN link through which the SD-WAN access device accesses the Internet fails, an uplink escape tunnel can be established. This way, when the SD-WAN access device cannot access the Internet based on the wired WAN link, the transmission of uplink traffic between the SD-WAN access device and the SD-WAN HUB can be maintained through the uplink escape tunnel.
[0125] The wired WAN link used by the SD-WAN access device to access the Internet can be connected when the SD-WAN access device is powered on. After the wired WAN link is connected, it cannot be directly used for the SD-WAN access device to access the Internet. Therefore, after the wired WAN link is connected, the wired WAN link must be configured so that the SD-WAN access device can access the Internet based on the wired WAN link. Exemplarily, after sending a second registration request to the control device based on the first connection, the method further includes: receiving link configuration information sent by the control device; and configuring the wired WAN link used by the SD-WAN access device to access the Internet based on the link configuration information, so that the SD-WAN access device can access the Internet through the wired WAN link.
[0126] The link configuration information can be sent by the control device together with the deployment file to the SD-WAN access device, or can be sent by the control device alone to the SD-WAN access device. The embodiment of the present application does not limit the content of the link configuration information. For example, the link configuration information can include the IP address of the SD-WAN access device, so that the SD-WAN access device can access the Internet through an Underlay connection based on a wired WAN link based on the IP address of the SD-WAN access device.
[0127] Optionally, the second registration request may include identification information of the SD-WAN access device. The identification information may be used by the control device to determine link configuration information of the SD-WAN access device based on a stored second mapping relationship. The second mapping relationship includes a mapping relationship between the identification information and the link configuration information. The second mapping relationship may be generated by the control device or statically configured on the control device by a staff member.
[0128] In one possible implementation, if the site to which the SD-WAN access device belongs has only one wired WAN link and this wired WAN link fails, the SD-WAN access device will be unable to access the Internet and communicate with various Internet-connected devices. Services within the site cannot proceed normally, resulting in a service interruption. In this case, the SD-WAN access device needs to access the Internet through other means to maintain normal operation of some services within the site.
[0129] For example, in response to a failure of the wired WAN link between the SD-WAN access device and the SD-WAN HUB, the SD-WAN access device may switch the transmission path of the upstream traffic of the SD-WAN access device from the wired WAN link to the upstream escape path.
[0130] In this application, if the wired WAN link fails and the SD-WAN access device cannot access the Internet through the wired WAN link, the SD-WAN access device can switch the transmission path of the SD-WAN access device's uplink traffic from the wired WAN link to the wireless uplink escape path to avoid the problem of the SD-WAN access device being unable to communicate with the HUB due to the failure of the wired WAN link, thereby ensuring the normal transmission of the SD-WAN access device's uplink traffic.
[0131] For example, see Figure 9 , showing a schematic diagram of the process of establishing an uplink escape path provided by an embodiment of the present application. In the event of a failure of the wired WAN link between the AR and the Internet, the AR cannot access the Internet based on the wired WAN link. In this case, the AR establishes an uplink escape path with the SD-WAN HUB to ensure that users on the AR can go online normally on the headquarters server connected to the SD-WAN HUB via LAN. After determining that the wired WAN link between the AR and the Internet has failed, the site staff turns on the mobile phone hotspot, shares the second Wi-Fi network, and the AR accesses the second Wi-Fi network. Afterwards, the AR establishes an uplink escape path with the SD-WAN HUB (for example Figure 9 The escape tunnel shown in FIG) and switches the transmission path of the upstream traffic from the wired WAN link to the upstream escape path.
[0132] Figure 10 A schematic diagram of another process of establishing an uplink escape path provided by an embodiment of the present application is shown. Figure 10 and Figure 9 The difference is that Figure 10In the process shown, the second Wi-Fi network accessed by SD-WAN is a public Wi-Fi network, thereby establishing an uplink escape path with the SD-WAN HUB and switching the transmission path of the uplink traffic from the wired WAN link to the uplink escape path.
[0133] Regardless of the method used by the SD-WAN access device to establish an uplink escape path with the SD-WAN HUB, the SD-WAN access device can establish an uplink escape path based on the resources on the SD-WAN access device. Among them, the resource refers to a wireless resource that can be used for the SD-WAN access device to communicate with the headquarters SD-WAN HUB to achieve the establishment and interaction of an uplink escape path. For example, if the SD-WAN access device communicates with the SD-WAN HUB through radio electromagnetic waves, the resource can be the frequency range (referred to as frequency band) of radio electromagnetic waves that the SD-WAN access device can transmit and receive. In the field of communication technology, the frequency bands used for wireless communication are typically 2.4 gigahertz (GHz) and 5 GHz, but the embodiments of the present application do not limit the frequency bands used by the SD-WAN access device for wireless communication.
[0134] In one possible implementation, the SD-WAN access device may support the establishment of wireless connections through one or more frequency bands. Below, taking Case 21 and Case 22 as examples, the two cases of the SD-WAN access device supporting the establishment of wireless connections through one frequency band and supporting the establishment of wireless connections through multiple frequency bands are respectively exemplified.
[0135] Case 21: The SD-WAN access device supports wireless connection establishment via a frequency band, which is the first frequency band. Before the wired WAN link fails, the first frequency band is used to establish a wireless connection between the SD-WAN access device and the wireless terminal. For example, Figures 7 to 10 In the example, the cash register is a wireless terminal within the site. A wireless connection can be established between the cash register and the AR based on the first frequency band, so that the cash register can access the Wi-Fi network shared by the AR and then access the Internet based on the Wi-Fi network.
[0136] In situation 21, because the SD-WAN access device only supports establishing wireless connections through the first frequency band, and the SD-WAN access device has already established a wireless connection between the SD-WAN access device and the wireless terminal based on the first frequency band, the SD-WAN access device can no longer establish an uplink escape path with the SD-WAN HUB based on the first resource. Therefore, before the SD-WAN access device establishes an uplink escape path between the SD-WAN access device and the SD-WAN HUB through the second Wi-Fi network, it also includes: severing the wireless connection between the SD-WAN access device and the wireless terminal, which wireless connection is established based on the first frequency band supported by the SD-WAN access device. After the SD-WAN access device severs the wireless connection between the SD-WAN access device and the wireless terminal, the first frequency band is released, and the first frequency band can then be used by the SD-WAN access device to establish an uplink escape path. That is, the SD-WAN access device can establish an uplink escape path through the second Wi-Fi network based on the first frequency band.
[0137] For example, the first frequency band is 2.4GHz. Before the wired WAN link fails, the SD-WAN access device establishes a wireless connection with the wireless terminal through radio electromagnetic waves with a frequency band of 2.4GHz. When the SD-WAN access device wants to establish an uplink escape path with the SD-WAN HUB, the SD-WAN access device no longer sends signals to the wireless terminal through radio electromagnetic waves with a frequency band of 2.4GHz, nor does it receive signals sent by the wireless terminal through radio electromagnetic waves with a frequency band of 2.4GHz, so as to cut off the wireless connection between the SD-WAN access device and the wireless terminal. After cutting off the wireless connection between the SD-WAN access device and the wireless terminal, the SD-WAN access device can perform the aforementioned process of establishing an uplink escape path between the SD-WAN access device and the SD-WAN HUB through radio electromagnetic waves with a frequency band of 2.4GHz.
[0138] If the first frequency band is used to establish a wireless connection between the SD-WAN access device and the wireless terminal, then before the SD-WAN access device and the SD-WAN HUB establish an uplink escape path, the wireless connection between the SD-WAN access device and the wireless terminal is cut off, the first frequency band is released, and then the uplink escape path is established based on the first frequency band. This can avoid conflicts in the use of the first frequency band and ensure the successful establishment of the uplink escape path.
[0139] To ensure that the wireless terminal can transmit uplink traffic via the uplink escape path, in scenario 21, the SD-WAN access device may time-division multiplex the first frequency band. For example, the SD-WAN access device may switch, at a specified frequency, between establishing a wireless connection between the SD-WAN access device and the wireless terminal based on the first frequency band and establishing an uplink escape path based on the first frequency band. For example, at time t1, the SD-WAN access device uses the first frequency band to establish a wireless connection between the SD-WAN access device and the wireless terminal and receives traffic sent by the wireless terminal over this wireless connection. At time t2, the SD-WAN access device disconnects the wireless connection between the SD-WAN access device and the wireless terminal and establishes an uplink escape path based on the first frequency band, transmitting the traffic sent by the wireless terminal at time t1 to the SD-WAN hub. At time t3, the uplink escape path is disconnected again, and a wireless connection is established between the SD-WAN access device and the wireless terminal based on the first frequency band to again receive traffic sent by the wireless terminal. This process is repeated in this way to implement frequency division multiplexing of the first frequency band, thereby ensuring that the wireless terminal can transmit uplink traffic through the uplink escape path.
[0140] Case 22: The SD-WAN access device supports establishing wireless connections through both the first frequency band and the second frequency band.
[0141] In scenario 22, since the SD-WAN access device supports establishing wireless connections not only through the first frequency band but also through the second frequency band, even if the first frequency band has been used to establish a wireless connection between the SD-WAN access device and the wireless terminal, when establishing an uplink escape path with the SD-WAN hub, the SD-WAN access device may not cut off the wireless connection between the SD-WAN access device and the wireless terminal, but may instead establish an uplink escape path with the SD-WAN hub based on the second frequency band. In other words, the SD-WAN access device can establish an uplink escape path through the second Wi-Fi network based on the second frequency band.
[0142] For example, the first resource is a radio electromagnetic wave with a frequency band of 2.4GHz, and the second resource is a radio electromagnetic wave with a frequency band of 5GHz. The SD-WAN access device establishes a wireless connection with the wireless terminal through the radio electromagnetic wave with a frequency band of 2.4GHz. When the SD-WAN access device establishes an uplink escape path with the SD-WAN HUB, the SD-WAN access device can continue to send signals to the terminal through the radio electromagnetic wave with a frequency band of 2.4GHz, and continue to receive signals sent by the terminal through the radio electromagnetic wave with a frequency band of 2.4GHz, to meet the local Internet access needs of the wireless terminal. The SD-WAN access device can perform the aforementioned process of establishing an uplink escape path between the SD-WAN access device and the SD-WAN HUB through the radio electromagnetic wave with a frequency band of 5GHz.
[0143] See also Figure 11 , showing a schematic diagram of the process of establishing a first connection and an uplink escape path provided by an embodiment of the present application. The embodiment of the present application can access the first Wi-Fi network when the SD-WAN access device in the site is started, establish a connection with the registration device in the registration center connected to the Internet, and use the IP address of the control device returned by the registration center. The first connection between the control device connected to the Internet is established, the start-up file is obtained from the control device, and the ZTP start-up of the SD-WAN access device is realized. In addition, the SD-WAN access device can also access the Internet through a wired WAN link, carry the services within the site, and share the LAN for the wireless terminals within the site to realize local Internet access for the wireless terminals within the site. In addition, the embodiment of the present application can also access the second Wi-Fi network when the primary tunnel between the SD-WAN access device and the SD-WAN HUB cannot be used due to a wired WAN link failure, establish an uplink escape path with the SD-WAN HUB, realize data interaction with the headquarters server, and then realize escape.
[0144] The communication method provided in the embodiment of the present application can be applied to various scenarios, for example, scenarios with relatively low reliability requirements and low business traffic. Figure 12 , shows a schematic diagram of an SD-WAN architecture, which can be the SD-WAN architecture in scenarios such as most enterprise branches, retail stores, and managed service providers (MSPs) reselling CPE overlay LAN management services.
[0145] The SD-WAN architecture includes a headquarters data center and multiple sites. The multiple sites are multiple enterprise branches in the SD-WAN architecture, and are temporarily shown as site 1 and site 2 in the figure. The headquarters DC includes multiple routers and headquarters servers. The multiple routers are, for example, router 1 and router 2. The multiple routers are the SD-WAN HUB in the embodiment of the present application. Multiple headquarters servers can be interconnected to realize data exchange, and multiple headquarters servers and multiple routers at the headquarters can also be interconnected to realize communication. The composition of each site is basically the same. Taking site 1 as an example, the site is equipped with routers (such as router 3) and terminals. The number of routers and terminals can be one or more. One router can be connected to multiple terminals, and one terminal can also be connected to multiple routers. The routers in the site are the SD-WAN access devices in the embodiment of the present application. Various terminals can be, for example, Figure 12 The notebook, mobile phone, personal computer and IP phone shown in FIG.
[0146] In addition, the SD-WAN architecture can also include NCE and registration center. Figure 12 In the SD-WAN architecture shown, the routers in the site can access the Wi-Fi network connected to the Internet, and then establish connections with the routers in the NCE, registration center, and headquarters DC to meet different communication needs.
[0147] In summary, in the embodiments of the present application, the SD-WAN access device can automatically connect to the first available Wi-Fi network after startup, and access the Internet through the first Wi-Fi network, thereby achieving ZTP deployment of the SD-WAN access device through the connection with the Internet. In this application, the method for the SD-WAN access device to access the Internet during the ZTP deployment process is flexible, simple, and efficient.
[0148] The embodiment of the present application also provides a communication method that enables the SD-WAN access device to flexibly and efficiently establish an uplink escape path, see Figure 13 The flow chart of the communication method shown is as follows, which includes but is not limited to the following S1301 to S1302.
[0149] S1301: The SD-WAN access device accesses the second Wi-Fi network.
[0150] The SD-WAN access device is a Wi-Fi-enabled CPE access gateway or a Wi-Fi-enabled wireless AP. The second Wi-Fi network includes a hotspot shared by mobile terminals or a public Wi-Fi network, which is a Wi-Fi network shared by devices in public places.
[0151] Optionally, the second Wi-Fi network is a public Wi-Fi network, and the SD-WAN access device establishes an uplink escape path between the SD-WAN access device and the SD-WAN HUB through the second Wi-Fi network, including: obtaining the account and password of the public Wi-Fi network through the hotspot shared by the mobile terminal; connecting to the public Wi-Fi network according to the account and password; and establishing an uplink escape path through the public Wi-Fi network.
[0152] S1302, the SD-WAN access device establishes an uplink escape path between the SD-WAN access device and the SD-WAN HUB through the second Wi-Fi network.
[0153] In one possible implementation, the method further includes: in response to a failure of the wired WAN link between the SD-WAN access device and the SD-WAN HUB, switching the transmission path of the upstream traffic of the SD-WAN access device from the wired WAN link to the upstream escape path.
[0154] Among them, the wired WAN link can be established during or after the startup of the SD-WAN access device. In the embodiments described in S1301 to S1302, the startup method of the SD-WAN access device is not limited. The SD-WAN access device can be started according to the startup method in the embodiments described in S601 to S602 above, or it can be started based on the startup method in the relevant technology. Regardless of the method used by the SD-WAN access device to achieve startup, and regardless of whether the startup of the SD-WAN access device is a ZTP startup, the SD-WAN access device can establish an uplink escape path based on the communication method in the embodiments described in S1301 to S1302.
[0155] In some cases, before establishing an uplink escape path between the SD-WAN access device and the software-defined wide area network center SD-WAN HUB, it also includes: cutting off the wireless connection between the SD-WAN access device and the wireless terminal, and the wireless connection is established based on the first frequency band supported by the SD-WAN access device; establishing an uplink escape path between the SD-WAN access device and the SD-WAN HUB, including: establishing an uplink escape path based on the first frequency band through a second Wi-Fi network.
[0156] For the description of S1301 to S1302, reference may be made to the description of S601 to S602 above, which will not be repeated here.
[0157] The above describes the communication method provided by the embodiment of the present application. Corresponding to the above method, the embodiment of the present application also provides a communication device. The device is applied to the SD-WAN access device. The device is used to Figure 14The modules shown above perform the Figure 6 The communication method performed by the SD-WAN access device. Figure 14 As shown, the communication device provided in the embodiment of the present application includes the following modules.
[0158] The first access module 1401 is used to access a first Wi-Fi network; the deployment module 1402 is used to access the Internet through the first Wi-Fi network to implement ZTP deployment.
[0159] In one possible implementation, the apparatus further includes an establishment module configured to establish an uplink escape path between the SD-WAN access device and the SD-WAN HUB through a second Wi-Fi network.
[0160] In one possible implementation, the device also includes a switching module, which is used to switch the transmission path of the upstream traffic of the SD-WAN access device from the wired WAN link to the upstream escape path in response to a failure of the wired wide area network (WAN) link between the SD-WAN access device and the SD-WAN HUB.
[0161] In one possible implementation, the SD-WAN access device is a CPE access gateway that supports Wi-Fi or a wireless AP that supports Wi-Fi.
[0162] In a possible implementation, the first Wi-Fi network includes a hotspot shared by mobile terminals or a public Wi-Fi network, where the public Wi-Fi network is a Wi-Fi network shared by devices in a public place.
[0163] In one possible implementation, the second Wi-Fi network is a public Wi-Fi network, and a module is established for obtaining an account and password of the public Wi-Fi network through a hotspot shared by a mobile terminal; connecting to the public Wi-Fi network based on the account and password; and establishing an uplink escape path through the public Wi-Fi network.
[0164] In a possible implementation, the first Wi-Fi network and the second Wi-Fi network are the same Wi-Fi network.
[0165] In a possible implementation, ZTP initiation is initiated by the registration center.
[0166] In one possible implementation, the device also includes a disconnection module, which is used to disconnect the wireless connection between the SD-WAN access device and the wireless terminal, where the wireless connection is established based on a first frequency band supported by the SD-WAN access device; and an establishment module, which is used to establish an uplink escape path through a second Wi-Fi network based on the first frequency band.
[0167] It should be understood that the above Figure 14 The device provided has the following beneficial effects when realizing its function: Figure 6 The beneficial effects of the communication method provided are the same and will not be described here in detail. Figure 14 The provided device is illustrated only by the division of the above-mentioned functional modules when implementing its functions. In actual applications, the above-mentioned functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. In addition, the device and method embodiments provided in the above embodiments are based on the same concept. The specific implementation process is detailed in the method embodiment and will not be repeated here.
[0168] The embodiment of the present application also provides a communication device. The device is applied to SD-WAN access equipment. The device is used to Figure 15 The modules shown above perform the Figure 13 The communication method performed by the SD-WAN access device. Figure 15 As shown, the communication device provided in the embodiment of the present application includes the following modules.
[0169] The second access module 1501 is used to access the second wireless network communication technology Wi-Fi network; the establishment module 1502 is used to access the Internet through the second Wi-Fi network and establish an uplink escape path between the SD-WAN access device and the SD-WAN HUB.
[0170] In one possible implementation, the device also includes a switching module, which is used to switch the transmission path of the upstream traffic of the SD-WAN access device from the wired WAN link to the upstream escape path in response to a failure of the wired wide area network (WAN) link between the SD-WAN access device and the SD-WAN HUB.
[0171] In one possible implementation, the SD-WAN access device is a CPE access gateway that supports Wi-Fi or a wireless AP that supports Wi-Fi.
[0172] In a possible implementation, the second Wi-Fi network includes a hotspot shared by mobile terminals or a public Wi-Fi network, where the public Wi-Fi network is a Wi-Fi network shared by devices in a public place.
[0173] In one possible implementation, the second Wi-Fi network is a public Wi-Fi network, and module 1502 is established to obtain an account and password of the public Wi-Fi network through a hotspot shared by the mobile terminal; connect to the public Wi-Fi network based on the account and password; and establish an uplink escape path through the public Wi-Fi network.
[0174] In one possible implementation, the device also includes a disconnection module, which is used to disconnect the wireless connection between the SD-WAN access device and the wireless terminal, where the wireless connection is established based on a first frequency band supported by the SD-WAN access device; and an establishment module 1502, which is used to establish an uplink escape path based on the first frequency band through a second Wi-Fi network.
[0175] See also Figure 16 , Figure 16 A structural diagram of an exemplary communication device 1600 of the present application is shown. The communication device 1600 includes at least one processor 1601, a memory 1603, and at least one network interface 1604. The communication device 1600 can be an example of an SD-WAN access device in an embodiment of the present application.
[0176] The processor 1601 is, for example, a general-purpose central processing unit (CPU), a digital signal processor (DSP), a network processor (NP), a GPU, a neural-network processing unit (NPU), a data processing unit (DPU), a microprocessor, or one or more integrated circuits or application-specific integrated circuits (ASICs) for implementing the solution of the present application, a programmable logic device (PLD), other general-purpose processors or other programmable logic devices, discrete gates, transistor logic devices, discrete hardware components, or any combination thereof. The PLD is, for example, a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof. The general-purpose processor can be a microprocessor or any conventional processor. It is worth noting that the processor can be a processor that supports the advanced reduced instruction set machine (ARM) architecture. It can implement or execute the various logic blocks, modules, and circuits described in conjunction with the disclosure of this application. The processor may also be a combination that implements computing functions, such as a combination of one or more microprocessors, a combination of a DSP and a microprocessor, and so on.
[0177] Optionally, the communication device 1600 further includes a bus 1602. The bus 1602 is used to transmit information between the components of the communication device 1600. The bus 1602 may be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus. The bus 1602 may be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 16 The fact that only one line is used does not mean that there is only one bus or one type of bus.
[0178] The memory 1603 may be, for example, a volatile memory or a nonvolatile memory, or may include both volatile and nonvolatile memories. The nonvolatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache.
[0179] By way of example and not limitation, many forms of ROM and RAM are available. For example, ROM is a compact disc read-only memory (CD-ROM). RAM includes, but is not limited to, static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct rambus RAM (DR RAM).
[0180] The memory 1603 may also be other types of storage devices that can store static information and instructions. Or it may be other types of dynamic storage devices that can store information and instructions. Or it may be other optical disk storage, optical disk storage (including compact disc, laser disc, optical disc, digital versatile disc, Blu-ray disc, etc.), magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited to this. The memory 1603 is, for example, independent and connected to the processor 1601 via the bus 1602. The memory 1603 may also be integrated with the processor 1601.
[0181] The network interface 1604 uses any transceiver-like device for communicating with other devices or communication networks, and the communication network can be Ethernet, a radio access network (RAN), or WLAN, etc. The network interface 1604 can include a wired network interface or a wireless network interface. Specifically, the network interface 1604 can be an Ethernet interface, such as a Fast Ethernet (FE) interface, a Gigabit Ethernet (GE) interface, an Asynchronous Transfer Mode (ATM) interface, a WLAN interface, a cellular network interface, or a combination thereof. The Ethernet interface can be an optical interface, an electrical interface, or a combination thereof. In some embodiments of the present application, the network interface 1604 can be used for the communication device 1600 to communicate with other devices.
[0182] In a specific implementation, as some embodiments, the processor 1601 may include one or more CPUs, such as Figure 16 0 and CPU1 are shown in FIG. Each of these processors can be a single-core processor or a multi-core processor. A processor herein can refer to one or more devices, circuits, and / or processing cores for processing data (e.g., computer program instructions).
[0183] In a specific implementation, as some embodiments, the communication device 1600 may include multiple processors, such as Figure 16 1 and 1605. Each of these processors can be a single-core processor or a multi-core processor. A processor herein can refer to one or more devices, circuits, and / or processing cores for processing data (such as computer program instructions).
[0184] In some implementations, the memory 1603 is used to store program instructions 1610 for executing the solution of the present application, and the processor 1601 can execute the program instructions 1610 stored in the memory 1603. That is, the communication device 1600 can implement the method provided in the method embodiment through the processor 1601 and the program instructions 1610 in the memory 1603, that is, Figure 6 or Figure 13 The program instructions 1610 may include one or more software modules. Optionally, the processor 1601 itself may also store program instructions for executing the solution of the present application.
[0185] The communication device 1600 may also correspond to the above Figure 14 or Figure 15 The device shown, Figure 14 or Figure 15 Each functional module in the apparatus shown is implemented using software of the communication device 1600. In other words, Figure 14 or Figure 15 The functional modules included in the apparatus shown are generated after the processor 1601 of the communication device 1600 reads the program instructions 1610 stored in the memory 1603 .
[0186] in, Figure 6 or Figure 13 Each step of the method shown is completed by hardware integrated logic circuits or software instructions in the processor of the communication device 1600. The steps of the method embodiments disclosed in this application can be directly embodied as being executed by a hardware processor, or can be executed by a combination of hardware and software modules in the processor. The software module can be located in a storage medium mature in the art, such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory, or an electrically erasable programmable memory, a register, etc. The storage medium is located in the memory, and the processor reads the information in the memory and completes the steps of the above method embodiments in combination with its hardware. To avoid repetition, they are not described in detail here.
[0187] See also Figure 17 , Figure 17 FIG2 shows a schematic structural diagram of an exemplary communication device 1700 of the present application. The communication device 1700 includes a main control board 1710 and an interface board 1730 . Figure 17 The communication device 1700 shown is used to perform the above Figure 6 or Figure 13 The operations involved in the communication method shown. The communication device 1700 is, for example, a switch, a router, etc. The communication device 1700 can be an example of an SD-WAN access device.
[0188] Main control board 1710, also known as the main processing unit (MPU) or route processor card, is responsible for controlling and managing various components in communication device 1700, including routing calculation, device management, device maintenance, and protocol processing. Main control board 1710 includes a central processing unit 1711 and memory 1712.
[0189] Interface board 1730 is also known as a line processing unit (LPU), line card, or service board. It provides various service interfaces and implements data packet forwarding. Service interfaces include, but are not limited to, Ethernet interfaces and POS (Packet over SONET / SDH) interfaces. Ethernet interfaces, for example, are interfaces for flexible Ethernet clients (FlexE Clients). Interface board 1730 includes a central processing unit (CPU) 1731, a network processor (NPU) 1732, a forwarding table memory 1734, and a physical interface card (PIC) 1733.
[0190] The central processing unit 1731 on the interface board 1730 is used to control and manage the interface board 1730 and communicate with the central processing unit 1711 on the main control board 1710 .
[0191] The network processor 1732 is used to implement message forwarding processing. The network processor 1732 can be in the form of a forwarding chip. Specifically, the network processor 1732 is used to forward received messages based on the forwarding table stored in the forwarding table memory 1734. If the destination address of the message is the address of the communication device 1700, the message is sent to the CPU (such as the central processing unit 1711) for processing; if the destination address of the message is not the address of the communication device 1700, the next hop and outgoing interface corresponding to the destination address are searched in the forwarding table based on the destination address, and the message is forwarded to the outgoing interface corresponding to the destination address. The processing of uplink messages includes: processing of the message input interface, forwarding table search; processing of downlink messages: forwarding table search, etc.
[0192] Physical interface card 1733 implements the physical layer interconnection function. Raw traffic enters interface board 1730 through this card, and processed packets are sent out from this physical interface card 1733. Physical interface card 1733, also known as a daughter card, can be installed on interface board 1730. It is responsible for converting optical and electrical signals into packets, performing a validity check on these packets, and forwarding them to network processor 1732 for processing. In some embodiments, a central processing unit can also perform the functions of network processor 1732, such as implementing software forwarding based on a general-purpose CPU, thus eliminating the need for network processor 1732 in physical interface card 1733.
[0193] Optionally, the communication device 1700 includes multiple interface boards. For example, the communication device 1700 further includes an interface board 1740 . The interface board 1740 includes a central processing unit 1741 , a network processor 1742 , a forwarding table entry memory 1744 , and a physical interface card 1743 .
[0194] Optionally, the communication device 1700 further includes a switching fabric board 1720. This switching fabric board 1720 may also be referred to as a switch fabric unit (SFU). If the communication device includes multiple interface boards 1730, the switching fabric board 1720 is used to exchange data between the interface boards. For example, the interface board 1730 and the interface board 1740 can communicate via the switching fabric board 1720.
[0195] The main control board 1710 and the interface board 1730 are coupled. For example, the main control board 1710, the interface board 1730, the interface board 1740, and the switching network board 1720 are connected to the system backplane via a system bus to achieve intercommunication. In one possible implementation, an inter-process communication (IPC) channel is established between the main control board 1710 and the interface board 1730, and communication between the main control board 1710 and the interface board 1730 is performed via the IPC channel.
[0196] Logically, communication device 1700 comprises a control plane and a forwarding plane. The control plane includes a main control board 1710 and a central processing unit 1731. The forwarding plane includes various components that perform forwarding, such as a forwarding table entry memory 1734, a physical interface card 1733, and a network processor 1732. The control plane performs routing functions, generates forwarding tables, processes signaling and protocol messages, and configures and maintains device status. The control plane sends the generated forwarding tables to the forwarding plane. On the forwarding plane, the network processor 1732 forwards messages received by the physical interface card 1733 based on the forwarding tables sent by the control plane. The forwarding tables sent by the control plane can be stored in the forwarding table entry memory 1734. In some embodiments, the control plane and forwarding plane can be completely separate and not located on the same device.
[0197] It's worth noting that there may be one or more main control boards (SBUs), which can include both active and standby SBUs. There may also be one or more interface boards. The higher the data processing capabilities of a communications device, the more interface boards it provides. Interface boards can also have one or more physical interface cards. There may be no SBUs, one or more SBUs, and multiple SBUs can be used to achieve load balancing and redundant backup. In a centralized forwarding architecture, communications equipment may not require SBUs; the interface boards handle service data processing for the entire system. In a distributed forwarding architecture, communications equipment can have at least one SBU, which enables data exchange between multiple interface boards, providing high-capacity data exchange and processing capabilities. Therefore, communications equipment with a distributed architecture offers greater data access and processing capabilities than equipment with a centralized architecture. Alternatively, a communications device can consist of a single board, without a switching network board (SBU), integrating the functions of the interface board and the main control board. In this case, the central processing unit (CPU) on the interface board and the CPU on the main control board can be combined into a single CPU on this board, performing the combined functions of the two. This type of device has lower data exchange and processing capabilities (for example, low-end switches or routers). The specific architecture used depends on the specific networking deployment scenario and is not specified here.
[0198] In an exemplary embodiment, a connection system is provided, which includes an SD-WAN access device, the SD-WAN access device being configured to perform Figure 6 or Figure 13 The method shown.
[0199] In an exemplary embodiment, a computer program (product) is provided, the computer program (product) comprising: a computer program code, when the computer program code is executed by a computer, causing the computer to execute Figure 6 or Figure 13 The method in .
[0200] In an exemplary embodiment, a computer-readable storage medium is provided, which stores a program or instruction. When the program or instruction is executed on a computer, the computer executes the above-mentioned Figure 6 or Figure 13 The method in .
[0201] In an exemplary embodiment, a chip is provided, comprising a processor for calling and executing instructions stored in a memory, so that a computer equipped with the chip executes Figure 6 or Figure 13 The method in .
[0202] In an exemplary embodiment, another chip is provided, including: an input interface, an output interface, a processor and a memory, wherein the input interface, the output interface, the processor and the memory are connected via an internal connection path, and the processor is used to execute the code in the memory. When the code is executed, the computer equipped with the chip executes Figure 6 or Figure 13 The method in .
[0203] In the above embodiments, all or part of the embodiments may be implemented by software, hardware, firmware, or any combination thereof. When implemented using software, all or part of the embodiments may be implemented in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described herein are generated. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions may be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via a wired (e.g., coaxial cable, optical fiber, digital subscriber line) or wireless (e.g., infrared, wireless, microwave, etc.) method. The computer-readable storage medium may be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more available media integrated therein. The available medium may be a magnetic medium (e.g., a floppy disk, a hard disk, a magnetic tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid-state drive).
[0204] In this application, the terms "first," "second," and the like are used to distinguish between identical or similar items having substantially the same function or effect. It should be understood that "first," "second," and "nth" do not have a logical or temporal dependency, nor do they limit the quantity or order of execution. It should also be understood that although the following description uses the terms "first," "second," and the like to describe various elements, these elements should not be limited by these terms. These terms are simply used to distinguish one element from another.
[0205] It should also be understood that in the various embodiments of the present application, the size of the serial number of each process does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
[0206] In this application, the term "at least one" means one or more, and the term "plurality" means two or more. For example, "plurality of second devices" means two or more second devices. The terms "system" and "network" are often used interchangeably herein.
[0207] It should be understood that the terminology used in the description of the various examples herein is for the purpose of describing particular examples only and is not intended to be limiting. As used in the description of the various examples and the appended claims, the singular forms "a," "an," and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise.
[0208] It should also be understood that the term "and / or" as used herein refers to and encompasses any and all possible combinations of one or more of the listed items. The term "and / or" describes an association between associated objects, indicating that three possible relationships exist. For example, "A and / or B" can represent: A exists alone, A and B exist simultaneously, or B exists alone. Furthermore, the character " / " in this application generally indicates that the associated objects are in an "or" relationship.
[0209] It should also be understood that the terms “if” and “if” may be interpreted to mean “when” or “upon” or “in response to determining” or “in response to detecting.” Similarly, the phrases “if it is determined that ” or “if [stated condition or event] is detected” may be interpreted to mean “upon determining ” or “in response to determining ” or “upon detecting [stated condition or event]” or “in response to detecting [stated condition or event],” depending on the context.
[0210] The above description is merely an embodiment of the present application and is not intended to limit the present application. Any modifications, equivalent replacements, improvements, etc. made within the principles of the present application shall be included in the scope of protection of the present application.
Claims
1. A communication method, characterized in that: The method is applied to a software-defined wide area network (SD-WAN) access device, and the method includes: The SD-WAN access device accesses a first wireless network communication technology Wi-Fi network; The SD-WAN access device accesses the Internet through the first Wi-Fi network to achieve zero-touch deployment (ZTP) deployment.
2. The method according to claim 1, characterized in that The method further comprises: An uplink escape path is established between the SD-WAN access device and the software-defined wide area network center SD-WAN HUB through the second Wi-Fi network.
3. The method according to claim 1 or 2, characterized in that The first Wi-Fi network includes a hotspot shared by mobile terminals or a public Wi-Fi network. The public Wi-Fi network is a Wi-Fi network shared by devices in a public place.
4. The method according to claim 2 or 3, characterized in that The first Wi-Fi network and the second Wi-Fi network are the same Wi-Fi network.
5. The method according to any one of claims 1 to 4, characterized in that: The ZTP start is a registration center start.
6. A communication method, characterized in that: The method is applied to a software-defined wide area network (SD-WAN) access device, and the method includes: The SD-WAN access device accesses a second wireless network communication technology Wi-Fi network; An uplink escape path is established between the SD-WAN access device and the software-defined wide area network center SD-WAN HUB through the second Wi-Fi network.
7. The method according to any one of claims 2 to 6, characterized in that: The method further comprises: In response to a failure of the wired wide area network (WAN) link between the SD-WAN access device and the SD-WAN HUB, the transmission path of the upstream traffic of the SD-WAN access device is switched from the wired WAN link to the upstream escape path.
8. The method according to claim 6 or 7, characterized in that The second Wi-Fi network includes a hotspot shared by mobile terminals or a public Wi-Fi network, and the public Wi-Fi network is a Wi-Fi network shared by devices in a public place.
9. The method according to claim 3, 4 or 8, characterized in that The second Wi-Fi network is a public Wi-Fi network, and establishing an uplink escape path between the SD-WAN access device and the software-defined wide area network center SD-WAN HUB through the second Wi-Fi network includes: Obtaining the account and password of the public Wi-Fi network through the hotspot shared by the mobile terminal; Connecting to the public Wi-Fi network using the account and password; The uplink escape path is established through the public Wi-Fi network.
10. The method according to any one of claims 2 to 9, characterized in that: Before establishing an uplink escape path between the SD-WAN access device and the software-defined wide area network center SD-WAN HUB through the second Wi-Fi network, the method further includes: Cutting off a wireless connection between the SD-WAN access device and the wireless terminal, where the wireless connection is established based on a first frequency band supported by the SD-WAN access device; The establishing of an uplink escape path between the SD-WAN access device and the software-defined wide area network center SD-WANHUB through the second Wi-Fi network includes: The uplink escape path is established based on the first frequency band through the second Wi-Fi network.
11. The method according to any one of claims 1 to 10, characterized in that: The SD-WAN access device is a customer terminal device CPE access gateway that supports Wi-Fi or a wireless access point AP that supports Wi-Fi.
12. A communication device, characterized in that: The device is applied to a software-defined wide area network (SD-WAN) access device, and the device includes: A first access module, configured to access a first wireless network communication technology Wi-Fi network; The deployment module is used to access the Internet through the first Wi-Fi network to achieve zero-touch deployment (ZTP) deployment.
13. A communication device, characterized in that: The device is applied to a software-defined wide area network (SD-WAN) access device, and the device includes: A second access module is used to access a second wireless network communication technology Wi-Fi network; An establishment module is used to establish an uplink escape path between the SD-WAN access device and the software-defined wide area network center SD-WAN HUB through a second Wi-Fi network.
14. A communication device, characterized in that: The device includes a processor coupled to a memory; the memory stores at least one instruction, and the at least one instruction is loaded and executed by the processor so that the communication device implements the communication method described in any one of claims 1-5, 7-11 or the communication method described in any one of claims 6-11.
15. A computer-readable storage medium, characterized in that The computer-readable storage medium stores at least one instruction, which is loaded and executed by the processor to implement the communication method according to any one of claims 1-5, 7-11 or any one of claims 6-11.
16. A computer program product, characterized in that The computer program product includes a computer program / instructions, which are executed by a processor to enable a computer to implement the communication method described in any one of claims 1 to 5, 7 to 11 or the communication method described in any one of claims 6 to 11.