Method for accessing home intranet, edge access gateway, system, medium and product
Edge access gateways solve the problem of public IP and third-party server bandwidth limitations in remote access for home network devices by resolving and replacing the MAC and IP addresses of access packets, enabling low-cost, high-speed private network mobile communication and improving the access experience.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-31
- Publication Date
- 2026-04-14
AI Technical Summary
Existing technologies rely on scarce and expensive public IP resources or are limited by third-party server bandwidth when remotely accessing devices on home networks, resulting in high costs, slow speeds, and difficulty in widespread adoption and practical application.
By acquiring home terminal information through the edge access gateway, parsing the MAC and IP addresses of access packets, and replacing the addresses using a pre-stored forwarding table, private network mobile communication is achieved without the need for public IP addresses or third-party servers, enabling direct communication between internal and external networks.
It enables low-cost, high-speed access to home intranets, reducing user costs, improving access speed, reducing third-party relay latency, and ensuring traffic stability and security.
Smart Images

Figure CN121864759A_ABST
Abstract
Description
Technical Field
[0001] This application belongs to the field of communication technology, and in particular relates to a method, edge access gateway, system, medium and product for accessing a home intranet. Background Technology
[0002] When external terminals access home network devices, some related technologies rely on scarce and expensive public IP addresses. Since home broadband users are typically only allocated private internal network IP addresses, applying for a separate public IP address would significantly increase user costs if cross-network access were to be achieved. This limitation is particularly pronounced in the current climate of increasingly scarce IP address resources.
[0003] Some related technologies require traffic to be relayed through third-party relay servers. Due to the limited bandwidth capacity of these servers, transmission speeds can be restricted and access can be slow, especially in high-bandwidth scenarios such as high-definition video streaming and large file transfers, making it difficult to meet users' requirements for a smooth access experience.
[0004] Therefore, when users remotely access devices on their home network, they have to bear the high cost of leasing public IP addresses or accept the degradation in transmission quality caused by the bandwidth limitations of relay servers. As a result, the remote access function in home network scenarios is difficult to truly become widespread and practical due to technical limitations. Summary of the Invention
[0005] This application provides a method, edge access gateway, system, medium, and product for accessing a home intranet, enabling low-cost, high-speed private network mobile communication, and making remote access functionality in home network scenarios truly widespread and practical.
[0006] In a first aspect, embodiments of this application provide a method for accessing a home intranet based on an edge access gateway, the method comprising: Obtain information about the home terminal obtained after completing an Ethernet point-to-point protocol dial-up connection; When an access message is received from a cloud core network device, and the access message meets the preset conditions based on the source IP address of the inner message in the access message, the inner destination MAC address and destination IP address in the access message are parsed and used as the WAN MAC address and terminal IP address of the corresponding broadband user. The pre-stored uplink traffic forwarding table is queried based on the WAN MAC address and the terminal IP address to obtain the corresponding gateway MAC address and terminal MAC address. The source and destination MAC addresses of the access packet are replaced with the gateway MAC address and the terminal MAC address, respectively, and the access packet is sent to the home terminal.
[0007] In one possible embodiment of the first aspect, the method further includes: Upon receiving a message returned by a home terminal, if the destination IP in the message meets the preset conditions, the source MAC address and user information in the message are parsed out. The WAN MAC address and the MAC address of the cloud core network device are obtained by querying the pre-stored downlink traffic forwarding table. The inner source MAC address in the message is replaced with the WAN MAC address, and the destination MAC address is replaced with the MAC address of the cloud core network device. The VxLAN tunnel of the cloud core network device is then encapsulated to achieve traffic forwarding.
[0008] In one possible embodiment of the first aspect, before querying the pre-stored uplink traffic forwarding table based on the WAN MAC address and the terminal IP address to obtain the corresponding gateway MAC address and terminal MAC address, and replacing the source and destination MAC addresses of the access packet with the gateway MAC address and the terminal MAC address respectively before sending it to the home terminal, the method further includes: After completing the Ethernet point-to-point protocol dialing and the DHCP IP address allocation for the home terminal, the user-related information is reported to the management platform for the management platform to generate summary information. The system receives aggregated information from the management platform and generates an uplink traffic forwarding table based on the aggregated information. The uplink traffic forwarding table is a key-value structure, with the WAN MAC address and terminal IP address as keys, and the gateway MAC address, terminal MAC address, and user information as values.
[0009] In one possible embodiment of the first aspect, the method further includes: Obtain the MAC address and network identifier of the cloud core network device from the access message sent by the cloud core network device; Obtain the terminal MAC address, WAN MAC address, and user information from the uplink traffic forwarding table; Based on the MAC address of the cloud core network device, the network identifier of the cloud core network device, the terminal MAC address, the WAN MAC address, and user information, a downlink traffic forwarding table is generated. The downlink traffic forwarding table is a key-value structure, where the keys are the terminal MAC and user information, and the values are the WAN MAC, the MAC of the cloud core network device, and the network identifier of the cloud core network device.
[0010] In one possible embodiment of the first aspect, the edge access gateway is logically deployed between the broadband access server and the cloud core network equipment in the form of a board or physical server; sending access messages to the home terminal includes: The access message is sent to the home terminal through the broadband access server.
[0011] In one possible embodiment of the first aspect, sending the access message to the home terminal via a broadband access server includes: The broadband access server sends access messages to the home gateway in bridged mode, so that the home gateway can then send the access messages to the home terminals.
[0012] In one possible embodiment of the first aspect, the preset conditions include that the source IP address of the inner message in the access message belongs to the IP address of a pre-configured cloud core network device.
[0013] Based on the same inventive concept, in a second aspect, embodiments of this application also provide an edge access gateway, which includes control plane network elements and user plane network elements; The control plane network element is used to send the information of the home terminal obtained from the Ethernet point-to-point protocol dialing completion to the user plane network element; The user plane network element is used to receive access packets sent by the cloud core network device. When the access packet meets the preset conditions based on the source IP address of the inner packet in the access packet, the inner destination MAC address and destination IP address in the access packet are parsed and used as the WAN MAC address and terminal IP address of the corresponding broadband user. The user plane network element is also used to query the pre-stored uplink traffic forwarding table based on the WAN MAC address and the terminal IP address, obtain the corresponding gateway MAC address and terminal MAC address, replace the source and destination MAC addresses of the access packet with the gateway MAC address and the terminal MAC address respectively, and send the access packet to the home terminal.
[0014] Based on the same inventive concept, in a third aspect, embodiments of this application also provide a home intranet access system, including a home terminal, a home gateway, a broadband access server, an edge access gateway, and a cloud core network device; the edge access gateway includes control plane network elements and user plane network elements; The control plane network element is used to send the information of the home terminal obtained from the Ethernet point-to-point protocol dialing completion to the user plane network element; The user plane network element is used to receive access packets sent by the cloud core network device. When the access packet meets the preset conditions based on the source IP address of the inner packet in the access packet, the inner destination MAC address and destination IP address in the access packet are parsed and used as the WAN MAC address and terminal IP address of the corresponding broadband user. The user plane network element is also used to query the pre-stored uplink traffic forwarding table based on the WAN MAC address and the terminal IP address, obtain the corresponding gateway MAC address and terminal MAC address, replace the source and destination MAC addresses of the access packet with the gateway MAC address and the terminal MAC address respectively, and send the access packet to the home terminal.
[0015] Based on the same inventive concept, in a fourth aspect, embodiments of this application also provide a computer-readable storage medium storing computer program instructions, which, when executed by a processor, implement the method for accessing a home intranet based on an edge access gateway as described in any embodiment of the first aspect.
[0016] Based on the same inventive concept, in a fifth aspect, embodiments of this application also provide a computer program product, wherein instructions in the computer program product, when executed by a device's processor, enable the device to perform the method for accessing a home intranet based on an edge access gateway as described in any embodiment of the first aspect.
[0017] According to the method, edge access gateway, system, medium, and product for accessing a home intranet provided in this application, the edge access gateway first obtains information about the home terminal obtained after completing an Ethernet point-to-point protocol dial-up connection. Then, it receives access packets sent by the cloud core network device. Based on the source IP address of the inner layer of the access packet, it determines whether it is a private network accompanying packet. If so, it parses the inner destination MAC and IP addresses as the broadband user's WAN MAC address and terminal IP address. Then, it queries a pre-stored uplink traffic forwarding table to obtain the gateway MAC address and terminal MAC address, replaces the source and destination MAC addresses of the access packet, and sends it to the home terminal. Through a combination of technical features such as judging, parsing, querying the forwarding table, and replacing the MAC address based on the inner layer information of the access packet, internal and external network communication can be completed without a public IP address or a third-party server, reducing third-party relay latency, improving access speed, and significantly reducing costs. Attached Figure Description
[0018] Other features, objects, and advantages of this application will become more apparent from the following detailed description of non-limiting embodiments with reference to the accompanying drawings, in which the same or similar reference numerals denote the same or similar features, and the drawings are not drawn to scale.
[0019] Figure 1 This is a schematic diagram of a home intranet access system provided in an embodiment of this application; Figure 2 This is a flowchart illustrating a method for accessing a home intranet provided in an embodiment of this application; Figure 3 This is another flowchart illustrating the method for accessing a home intranet provided in this application embodiment; Figure 4 This is another flowchart illustrating the method for accessing a home intranet provided in this application embodiment; Figure 5 This is another flowchart illustrating the method for accessing a home intranet provided in this application embodiment; Figure 6This is another flowchart illustrating the method for accessing a home intranet provided in this application embodiment; Figure 7 This is another flowchart illustrating the method for accessing a home intranet provided in this application embodiment; Figure 8 This is another structural diagram of the home intranet access system provided in the embodiments of this application; Figure 9 This is a schematic diagram of the structure of an edge access gateway provided in an embodiment of this application. Detailed Implementation
[0020] The features and exemplary embodiments of various aspects of this application will now be described in detail. To make the objectives, technical solutions, and advantages of this application clearer, the application will be further described in detail below with reference to the accompanying drawings and specific embodiments. It should be understood that the specific embodiments described herein are only configured to explain this application and are not configured to limit this application. For those skilled in the art, this application can be implemented without some of these specific details. The following description of the embodiments is merely to provide a better understanding of this application by illustrating examples of this application.
[0021] It should be noted that, in this document, relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising..." does not exclude the presence of additional identical elements in the process, method, article, or apparatus that includes said element.
[0022] It should be understood that the term "and / or" used in this article is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. Additionally, the character " / " in this article generally indicates that the preceding and following related objects have an "or" relationship.
[0023] Various modifications and variations can be made to this application without departing from its spirit or scope, which will be apparent to those skilled in the art. Therefore, this application is intended to cover modifications and variations falling within the scope of the corresponding claims (the claimed technical solutions) and their equivalents. It should be noted that the implementation methods provided in the embodiments of this application can be combined with each other without contradiction.
[0024] It should be noted that the acquisition, storage, use, and processing of data in this application embodiment all comply with the relevant provisions of national laws and regulations.
[0025] It should also be noted that in the embodiments of this application, certain software, components, models and other existing solutions in the industry may be mentioned. These should be regarded as exemplary and are only intended to illustrate the feasibility of implementing the technical solution of this application. However, it does not mean that the applicant has used or necessarily used the solution.
[0026] Before describing the technical solutions provided in the embodiments of this application, in order to facilitate understanding of the embodiments of this application, this application first specifically explains the problems existing in the related technologies: When external terminals access home network devices, some related technologies rely on scarce and expensive public IP addresses. Since home broadband users are typically only allocated private internal network IP addresses, applying for a separate public IP address would significantly increase user costs if cross-network access were to be achieved. This limitation is particularly pronounced in the current climate of increasingly scarce IP address resources.
[0027] For example, related technologies are implemented through Virtual Private Networks (VPNs) or port forwarding, but both require users to have independent public IP addresses. However, public IP address resources are scarce, and home broadband users all use internal network IP addresses. Applying for a public IP address separately would be very expensive.
[0028] A Virtual Private Network (VPN) is a technology that establishes an encrypted channel over a public network (such as the Internet), allowing users to securely access remote network resources or protect the privacy of data transmission. Mobile devices connect to the home network via VPN dial-up to access home resources. This method requires enabling the VPN service on the home router and installing a VPN client on the mobile device.
[0029] Port mapping: Use a public IP address on a home network device (such as a router) and configure destination port mapping to map the port to the corresponding home device. Mobile terminals access the public IP address and destination port of the home device, and the router performs destination IP translation based on the configuration to enable access to internal network resources.
[0030] Some related technologies require traffic to be relayed through third-party relay servers. Limited by the bandwidth capacity of these servers, transmission speeds can be restricted, leading to buffering and stuttering, especially noticeable in high-bandwidth scenarios such as high-definition video streaming and large file transfers, making it difficult to meet users' demands for a smooth access experience. For example, technologies using remote desktops or cloud services are subject to bandwidth limitations imposed by third-party servers, significantly impacting the user experience.
[0031] Remote desktop software: Install remote desktop software (such as ToDesk, Sunflower, TeamViewer, etc.) on the computer on the home intranet, set a key and enable unattended access. Mobile terminals can access the desktop and applications of the home terminal through the corresponding user code and key.
[0032] Cloud services: This refers to using cloud servers as intermediaries, where home devices transfer data such as files, photos, and videos to the cloud, and mobile devices access the cloud server through its IP address or application.
[0033] Therefore, when external network devices want to access internal network devices, the traffic either needs to pass through the internet (requiring the purchase of a public IP address) or needs to be relayed through a third-party server (with speed limits). As a result, when users remotely access their home network devices, they have to bear the high cost of leasing public IP addresses or accept the degradation in transmission quality caused by the bandwidth limitations of relay servers. Consequently, remote access functionality in home network scenarios is difficult to truly popularize and become practical due to technical limitations.
[0034] Based on this, embodiments of this application provide a method, edge access gateway, system, medium, and product for accessing a home intranet. Based on the edge access gateway, users can quickly access home terminals without needing a public IP address, and the traffic does not need to pass through third-party devices. This enables low-cost, high-speed private network mobile communication, making remote access functionality in home network scenarios truly widespread and practical.
[0035] Taking a home intranet access system as an example, such as Figure 1 As shown, the home intranet access system includes components such as home terminals, home gateways, optical line terminals (OLTs), broadband access servers (BRAS), edge access gateways, and cloud core network devices (eUPFs). This system can be called a Broadband Edge Computing Gateway (BCG). It moves the Layer 3 network capabilities from the home terminal gateway to the edge access gateway. The management platform connects northward to the provincial IT support system and southward to relevant BCG network elements, enabling unified management, resource allocation, and network orchestration, providing configuration management and service monitoring for service activation.
[0036] Edge access gateways are logically deployed in front of the Broadband Access Server (BRAS) in the form of boards or physical servers. Based on their functions, they can be divided into two modules: control plane network element vCPE and user plane network element vSwitch.
[0037] The control plane network element vCPE is responsible for the control plane part, completing the processing of user control protocol messages. It is mainly responsible for multi-tenant management, DHCP IP address allocation, PPPoE dialing (legality verification of edge access gateways), Domain Name System (DNS) proxy, etc.
[0038] The user plane network element vSwitch is a core network element at the network layer. It has routing, access control list (ACL) and network address translation (NAT) capabilities, as well as commonly used layer 2 and 3 tunneling capabilities. It is responsible for tunnel encapsulation and decapsulation, user identification, traffic forwarding, policy traffic redirection and handling, network address translation and other functions.
[0039] In the BCG architecture, the home gateway changes from a traditional routing mode to a bridging mode. Packets from home terminals are transparently transmitted through the home gateway and the Optical Line Terminal (OLT) to the Broadband Access Server (BRAS), then encapsulated into VXLAN tunnels to the edge access gateway. The edge access gateway distinguishes users at the VXLAN+Q granularity and processes packets according to their type through different pipelines. (See also...) Figure 1 The specific processing procedure is as follows: 1) Information dissemination.
[0040] The management platform sends user information to the control plane network element vCPE of the edge access gateway, including the user's corresponding QinQ, VNI, PPPoE username and password, DHCP address pool, DNS and other information.
[0041] 2) PPPoE dialing.
[0042] The management platform issues dialing commands to the control plane network element vCPE of the edge access gateway. The control plane network element vCPE of the edge access gateway initiates PPPoE proxy dialing according to the user granularity, completes authentication with the broadband access server BRAS to obtain the user's WAN-side IP address, and sends the session information to the user plane network element vSwitch of the edge access gateway.
[0043] 3) DHCP IP address allocation for home terminals.
[0044] When a home terminal initiates a DHCP dial-up connection, the control plane network element vCPE of the edge access gateway acts as a DHCP server to assign a LAN-side IP address to the home terminal.
[0045] 4) Normal internet access.
[0046] When a home terminal is accessing the internet normally, packets arrive at the user plane network element vSwitch of the edge access gateway, where the VXLAN tunnel is decapsulated. Based on the LAN-side VNI+QINQ information and the corresponding forwarding policy, the source IP is SNATed to the WAN-side IP, and PPPoE, QinQ, and VXLAN tunnel are encapsulated before being sent to the Broadband Access Server (BRAS). The BRAS decapsulates the VXLAN tunnel, QinQ, and PPPoE headers, and forwards them at Layer 3 to the appropriate external network server. The downlink packet process is the reverse of the above and will not be described further.
[0047] The above process describes the workflow for enabling normal internet access for users in the BCG system, designed to help readers better understand the overall network element architecture and packet forwarding methods of BCG. The following content presents the core technical solution of this application: enabling mutual access between mobile terminals and users' home network devices. This function can be called "Private Network Companion." This application requires external network devices to use a mobile operator's SIM card and bind the number to the operator's home broadband account. The cloud core network device eUPF interacts with the broadband access server BRAS (or interacts with the management platform) to obtain information about home broadband users who have completed PPPoE dialing. The traffic of the Private Network Companion is then processed for address translation and sent to the edge access gateway. The specific implementation of the cloud core network device eUPF is not detailed in this application's embodiments; this application's embodiments focus on introducing the implementation of the edge access gateway.
[0048] The embodiments of this application mainly have three key technical points: First, the management platform links the user's WAN-side dial-up information and LAN-side home terminal information into a single data entry, breaking down network isolation between the public and private networks. Specifically, after the edge access gateway's control plane element (vCPE) completes the user's PPPoE dial-up and terminal DHCP IP address allocation, it reports all relevant user information to the management platform, including the WAN MAC address, gateway MAC address, MAC and IP addresses of the connected home terminals, and user information (such as VNI and QINQ). The management platform then aggregates and distributes this information to the edge access gateway's user plane element (vSwitch). Upon receiving this information, the edge access gateway's user plane element (vSwitch) generates an uplink traffic forwarding table to handle user traffic accessing the home intranet. The key of this table is WAN MAC address + terminal IP address, and the value is terminal MAC address + gateway MAC address + VNI + QINQ.
[0049] Second, the user plane network element vSwitch of the edge access gateway determines the private network traffic by the source IP address and identifies the unique home terminal by the destination IP + destination MAC (i.e., home terminal IP + WAN MAC). Specifically, after receiving private network access VxLAN traffic from the cloud core network device eUPF, the user plane network element vSwitch of the edge access gateway compares the source IP address of the inner packet (the pre-configured real IP address of the cloud core network device eUPF) to determine if the packet is a private network traffic. If it is, the inner destination MAC and destination IP in the packet are parsed out, corresponding to the user's WAN MAC and terminal IP address respectively. These are used as keys to query the uplink traffic forwarding table, and based on the query results, the source and destination MAC addresses of the packet are replaced with the gateway MAC and terminal MAC respectively. The packet is then encapsulated with the user's QinQ and VXLAN tunnel and sent to the home terminal.
[0050] Third, the user plane network element vSwitch of the edge access gateway generates a downlink traffic forwarding table during packet forwarding. While processing user access to the intranet traffic, the user plane network element vSwitch of the edge access gateway extracts the source MAC address (eUPF MAC) and the network identifier VNI (eUPF VxLAN) of the cloud core network device from the received packets. It then combines this information with a portion of the data in the uplink traffic forwarding table to generate a corresponding downlink traffic forwarding table for processing packets returned from the home intranet. The key of this table is the terminal MAC + user information (VNI + QINQ), and the value is the WAN MAC + eUPF MAC + eUPF VNI. The user plane network element vSwitch of the edge access gateway uses the terminal MAC address + user information (VNI + QINQ) as a unique identifier to correctly forward home backhaul traffic: After receiving the packet returned by the home terminal, it determines that it is a private network follow-up packet by the destination IP address, then parses the source MAC address and user information (VNI + QINQ) in the packet and uses them as the key value to query the downlink traffic forwarding table. It replaces the inner source MAC address in the original packet with the WAN MAC address, replaces the destination MAC address with the eUPF MAC address, and encapsulates it with an eUPF VxLAN tunnel before sending it to the cloud core network device.
[0051] The product carrier of this application embodiment is a home edge computing gateway. Compared with the original traditional home broadband, it emphasizes the combination of computing power and network. As a BASIC6 related technology product, it has been piloted in many cities with good results, and is planned to be commercially deployed in Shandong, Hunan and other provinces.
[0052] The Private Network on the Go service requires mobile terminals to use China Mobile's network. Mobile terminals only need to know the home terminal's private network IP address to access it, eliminating the need for software installation on the home or mobile terminal, additional configuration, and separate configuration of the home gateway and terminals (reducing configuration complexity). Traffic access speed is not limited by public cloud or third-party vendor speed limits, enabling fast interaction.
[0053] This application embodiment enables local area network traffic interconnection between internal and external network users. In the future, value-added services can be developed based on this application embodiment, such as providing users with functions like family file sharing, TV screen casting, and document printing, to enhance the user experience.
[0054] The method for accessing a home intranet based on an edge access gateway, as provided in the embodiments of this application, will be described in detail below with reference to the accompanying drawings.
[0055] Figure 2 This is a flowchart illustrating a method for accessing a home intranet based on an edge access gateway, as provided in an embodiment of this application. Figure 2 As shown, the method may include steps S110 to S130.
[0056] S110: Obtain information about the home terminal obtained after completing the Ethernet point-to-point protocol PPPoE dialing.
[0057] Specifically, after completing the PPPoE dial-up connection, the edge access gateway can obtain information about the home terminal corresponding to the broadband user.
[0058] For example, the process of dialing up with Ethernet Point-to-Point Protocol over Ethernet (PPPOE) is as follows: the user dials up with the broadband access server using a username and password. The broadband access server then authenticates the edge access gateway based on the username and password. Only after successful authentication can normal communication be established.
[0059] It should be noted that before step S120 is executed, the Ethernet Point-to-Point Protocol (PPPoE) dialing needs to be completed, that is, the DHCP IP address needs to be assigned to the home terminal. For example, the process of assigning a DHCP IP address to the home terminal is as follows: the home terminal sends an IP address assignment request to the edge access gateway, and the edge access gateway assigns a dynamic IP address to the home terminal through a network management protocol (such as Dynamic Host Configuration Protocol, DHCP).
[0060] It should also be noted that DHCP IP address allocation information can be used to generate uplink traffic forwarding tables. After assigning an IP address to a home terminal, the destination IP address of access packets sent by broadband users when accessing the home terminal must be the home terminal's IP address.
[0061] S120 receives access packets sent by cloud core network devices. When the access packet meets the preset conditions based on the source IP address of the inner packet in the access packet, it parses the inner destination MAC address and destination IP address in the access packet as the WAN MAC address and terminal IP address of the corresponding broadband user.
[0062] Specifically, when receiving an access message sent by a cloud core network device, it is necessary to first determine whether the access message is a private network accompanying message: first, based on the source IP address of the inner message in the access message, if the access message meets the preset conditions, it means that the access message is a private network accompanying message. Then, the inner destination MAC address and destination IP address in the access message can be parsed and used as the WAN MAC address and terminal IP address of the corresponding user, respectively.
[0063] For example, the preset conditions include the IP address of a pre-configured cloud core network device. For instance, if the source IP address of the inner packet in the access packet belongs to the pre-configured IP address of the cloud core network device, it indicates that the packet is a private network accompanying the message.
[0064] S130 queries the pre-stored uplink traffic forwarding table based on the WAN MAC address and the terminal IP address to obtain the corresponding gateway MAC address and terminal MAC address. It then replaces the source and destination MAC addresses of the access packet with the gateway MAC address and the terminal MAC address, respectively, and sends the access packet to the home terminal.
[0065] Specifically, address translation is performed on the access packets: the pre-stored uplink traffic forwarding table is queried based on the WAN MAC address and the terminal IP address to obtain the corresponding gateway MAC address and terminal MAC address. The source and destination MAC addresses of the access packets are replaced with the gateway MAC address and the terminal MAC address, respectively, and the access packets are sent to the home terminal, thereby enabling access to the home intranet.
[0066] For example, the uplink traffic forwarding table is a key-value structure, where the keys are the WAN MAC address and the terminal IP address, and the values are the gateway MAC address, the terminal MAC address, and user information.
[0067] Throughout the entire traffic forwarding process, packets do not need to use public IP addresses to achieve communication between internal and external networks, reducing costs and lowering the price threshold for users.
[0068] According to the method for accessing a home intranet provided in this application embodiment, the information of the home terminal after dialing up via Ethernet point-to-point protocol is obtained through the edge access gateway. Then, based on the source IP address of the inner packet of the access packet, it is determined whether it is a private network accompanying packet. If so, the inner destination MAC and IP address are parsed as the WAN MAC address and the terminal IP address. Based on this, the pre-stored uplink traffic forwarding table is queried to obtain the gateway and terminal MAC addresses, and the source and destination MAC addresses of the access packet are replaced before being sent to the home terminal. Therefore, internal and external network interconnection can be completed without public IP or third-party servers, reducing third-party relay delay, improving access speed and significantly reducing costs.
[0069] In some embodiments, such as Figure 3 As shown, the method further includes step S140: S140: Receives the message returned by the home terminal. If the destination IP in the message meets the preset conditions, it parses the source MAC address and user information in the message, queries the pre-stored downlink traffic forwarding table to obtain the WAN MAC address and the MAC address of the cloud core network device, replaces the inner source MAC address in the message with the WAN MAC address, replaces the destination MAC address with the MAC address of the cloud core network device, and encapsulates the VxLAN tunnel of the cloud core network device to achieve traffic forwarding.
[0070] Specifically, the process of forwarding packets returned by the home terminal is as follows: receiving packets returned by the home terminal, determining whether the returned packet is a private network packet based on the destination IP in the packet; if so, address translation begins: parsing out the source MAC address and user information in the packet, querying the pre-stored downlink traffic forwarding table to obtain the WAN MAC address and the MAC address of the cloud core network device, replacing the inner source MAC address in the packet with the WAN MAC address, replacing the destination MAC address with the MAC address of the cloud core network device, and encapsulating the VxLAN tunnel of the cloud core network device to achieve traffic forwarding.
[0071] For example, the preset conditions include the pre-configured IP address of the cloud core network device. For instance, if the destination IP address in the returned message is the pre-configured IP address of the cloud core network device, it indicates that the returned message is a private network accompanying message.
[0072] In this embodiment, after receiving a message returned by a home terminal, the edge access gateway can accurately determine whether preset conditions are met based on the destination IP of the message (such as the destination IP being the IP address of a real cloud core network device). It then parses the source MAC address and user information, queries the downlink traffic forwarding table to obtain the WAN MAC address and the cloud core network device MAC address, completes the replacement of the source and destination MAC addresses within the message, and encapsulates a VxLAN tunnel to achieve traffic forwarding. This process requires no complex configuration, efficiently and accurately processes private network accompanying messages, and ensures stable, fast, and secure interaction between internal and external network traffic.
[0073] In some embodiments, such as Figure 4 As shown, in step S130, the method may further include steps S151 and S152 before querying the pre-stored uplink traffic forwarding table based on the WAN MAC address and terminal IP address to obtain the corresponding gateway MAC address and terminal MAC address, replacing the source and destination MAC addresses of the access packet with the gateway MAC address and terminal MAC address respectively, and sending the access packet to the home terminal: S151, after completing the Ethernet point-to-point protocol PPPOE dialing and the DHCP IP address allocation for the home terminal, reports the relevant user information to the management platform for the management platform to generate summary information. S152, receive the summary information sent by the management platform, and generate an uplink traffic forwarding table based on the summary information. The uplink traffic forwarding table is a key-value structure. The keys of the uplink traffic forwarding table are the WAN MAC address and the terminal IP address, and the values are the gateway MAC address, the terminal MAC address, and user information (VNI, QINQ).
[0074] The user-related information may include WAN MAC, gateway MAC, MAC and IP addresses of connected home terminals, and user information (such as VNI and QINQ).
[0075] The aggregated information generated by the management platform includes at least user-related information, and may also include other information, such as the actual IP address of the cloud core network device. The home terminal gateway can use the actual IP address of the cloud core network device as a preset condition for determining whether a packet is a private network accompanying packet.
[0076] For example, after the control plane network element vCPE of the edge access gateway completes the user's PPPoE dialing and terminal DHCP IP address allocation, it reports all user-related information to the management platform, including the WAN MAC, gateway MAC, MAC and IP addresses of the connected home terminals, and user information (such as VNI and QINQ). The management platform summarizes the information and distributes it uniformly to the user plane network element vSwitch of the edge access gateway. After receiving this information, the user plane network element vSwitch of the edge access gateway generates an uplink traffic forwarding table to handle traffic from users accessing the home intranet. The key of this table is WAN MAC + terminal IP, and the value is terminal MAC + gateway MAC + VNI + QINQ.
[0077] In this embodiment, after completing PPPoE dialing and terminal DHCP IP address allocation, user-related information is reported to the management platform to generate summary information. Then, the summary information is received and used to generate a key-value structured uplink traffic forwarding table, with the WAN MAC address and terminal IP address as keys, and the gateway MAC address, terminal MAC address, and user information (VNI, QINQ) as values. This process achieves centralized management and efficient distribution of information, enabling the uplink traffic forwarding table to accurately guide packet processing and ensuring the accuracy and efficiency of home intranet access traffic forwarding.
[0078] In some embodiments, such as Figure 5 As shown, the method may further include steps S161 to S163: S161, obtain the MAC address of the cloud core network device and the network identifier VNI (eUPF VxLAN) of the cloud core network device in the access message sent by the cloud core network device. S162, retrieve the terminal MAC address, WAN MAC address, and user information from the uplink traffic forwarding table; S163. Based on the MAC address of the cloud core network device, the network identifier of the cloud core network device, the terminal MAC address, the WAN MAC address, and user information, a downlink traffic forwarding table is generated. The downlink traffic forwarding table is a key-value structure, where the keys are the terminal MAC and user information, and the values are the WAN MAC, the MAC of the cloud core network device, and the network identifier of the cloud core network device.
[0079] Among them, the network identifier VNI is the VXLAN network identifier, which is a core parameter in VXLAN technology and is used to uniquely identify different virtual networks or VXLAN network segments in a virtual network.
[0080] Specifically, the MAC address and network identifier of the cloud core network device (eUPF) are first obtained from the access packets sent by the eUPF. Then, the terminal MAC address, WAN MAC address, and user information are obtained from the uplink traffic forwarding table. Finally, a downlink traffic forwarding table is generated based on the obtained information. This table adopts a key-value structure, with the terminal MAC and user information as keys, and the WAN MAC, cloud core network device MAC address, and cloud core network device eUPF network identifier as values, providing accurate reference for subsequent traffic forwarding.
[0081] This application embodiment can generate a downlink traffic forwarding table during packet forwarding. While the edge access gateway processes user access to the intranet traffic, it extracts the source MAC address (eUPF MAC) and the network identifier VNI (eUPF VxLAN) of the cloud core network device from the received packets. Then, it combines a portion of the data in the uplink traffic forwarding table to generate a corresponding downlink traffic forwarding table for processing packets returned from the home intranet. The key of this table is terminal MAC + user information (VNI + QINQ), and the value is WAN MAC + eUPF MAC + eUPF VNI. The edge access gateway uses the terminal MAC address plus user information (VNI+QINQ) as a unique identifier to correctly forward home backhaul traffic. Upon receiving a packet from a home terminal, it identifies it as a private network follow-up packet based on the destination IP. It then parses the source MAC address and user information (VNI+QINQ) from the packet and uses them as the key to query the downlink traffic forwarding table. The gateway replaces the inner source MAC address in the original packet with the WAN MAC address and the destination MAC address with the eUPF MAC address, encapsulates it with an eUPF VxLAN tunnel, and sends it to the cloud core network device. Therefore, by generating the downlink traffic forwarding table, it can accurately construct a basis for traffic forwarding, ensuring accurate and efficient traffic forwarding.
[0082] In some embodiments, such as Figure 6 As shown, the edge access gateway is logically deployed between the Broadband Access Server (BRAS) and the cloud core network device (eUPF) in the form of a board or physical server; in step S130, the pre-stored uplink traffic forwarding table is queried according to the WAN MAC address and the terminal IP address to obtain the corresponding gateway MAC address and terminal MAC address, the source and destination MAC addresses of the access packet are replaced with the gateway MAC address and the terminal MAC address respectively, and the access packet is sent to the home terminal, which may include steps S131 and S132: S131: Query the pre-stored uplink traffic forwarding table based on the WAN MAC address and terminal IP address to obtain the corresponding gateway MAC address and terminal MAC address, and replace the source and destination MAC addresses of the access packet with the gateway MAC address and terminal MAC address respectively. S132 sends the access message to the home terminal via the Broadband Access Server (BRAS).
[0083] In this embodiment, the edge access gateway is logically deployed as a board or physical server between the Broadband Access Server (BRAS) and the Cloud Core Network Equipment (eUPF). This deployment method cleverly utilizes the existing network architecture layers, enabling the reuse of existing carrier equipment (BRAS and eUPF) without relying on third-party vendor servers for forwarding, thus reducing traffic paths and lowering latency.
[0084] In some embodiments, such as Figure 7 As shown, step S132, which sends the access message to the home terminal through the Broadband Access Server (BRAS), may include step S1321: S1321 sends access messages to the home gateway in bridge mode through the Broadband Access Server (BRAS), so that the home gateway can send the access messages to the home terminal.
[0085] In this case, the home gateway needs to be changed from the traditional routing mode to the bridging mode.
[0086] In one example, packets from the home terminal are transparently transmitted to the Broadband Access Server (BRAS) via the home gateway and the Optical Line Terminal (OLT), and then encapsulated into a VXLAN tunnel to the edge access gateway. The edge access gateway distinguishes users at the VXLAN+Q granularity and processes them in different pipelines according to the packet type.
[0087] In this embodiment, the edge access gateway sends access packets to the home gateway in bridge mode via the broadband access server (BRAS) and then forwards them to the home terminal. The home gateway is also switched to bridge mode, which improves the processing speed.
[0088] In one example, such as Figure 8 As shown, the edge access gateway includes a control plane network element vCPE and a user plane network element vSwitch. The home terminal is a storage device NAS, with the home terminal IP address being 192.168.100.209 and the home terminal MAC address being 11:22:33:44:55:66. The home gateway MAC address is 11:22:33:44:55:77, and the home gateway's WAN MAC address is 11:22:33:44:55:88. The user information (VNI+QINQ) is vni1001+ctag 100+stag 200. The cloud core network device IP address is 10.10.10.10, and the cloud core network device MAC address is aa.bb.cc.dd.ee.ff. Specifically: 1) Legality authentication: The control plane network element vCPE completes the user's PPPoE dialing, and the broadband access server BRAS synchronizes the user's dialing information to the cloud core network equipment.
[0089] 2) DHCP IP address allocation for home terminal: The control plane network element vCPE assigns the IP address 192.168.100.209 to the home terminal NAS via the DHCP protocol, records the MAC address of the home terminal NAS as 11:22:33:44:55:66, and reports it to the management platform.
[0090] 3) The management platform associates the user's WAN-side dialing information and LAN-side terminal information into a single data entry, including user information (VNI+QINQ), WAN MAC, home terminal IP, home terminal MAC, LAN MAC, etc., and sends it to the user's network element vSwitch and generates an uplink traffic forwarding table.
[0091] 4) When a user accesses the IP address 192.168.100.209 of their home NAS from the external network, an access packet is generated. This packet is processed by the cloud core network device, which encapsulates the corresponding WAN MAC address (11:22:33:44:55:88) and sends it through the VxLAN 2001 tunnel to the user plane network element vSwitch of the edge access gateway. The user plane network element vSwitch of the edge access gateway determines that the packet is private network traffic based on the source IP address (10.10.10.10) in the packet. It then uses the WAN MAC address and the terminal IP address as an index to query the correlation in the uplink traffic forwarding table, identifying the unique home terminal. The source MAC address of the access packet is replaced with the queried LAN MAC address (11:22:33:44:55:77), and the destination MAC address is replaced with the MAC address of the internal network device (11:22:33:44:55:66). User information is then encapsulated, such as an inner ctag 100 and an outer stag. The VxLAN 1001 on the LAN side and the 200 on the LAN side are sent to the home terminal NAS through the tunnel. At the same time, the user plane network element vSwitch of the edge access gateway generates a downlink traffic forwarding table based on the existing information. The main purpose is to record the MAC (aa:bb:cc:dd:ee:ff) and VxLAN (VNI2001) information of the cloud core network device in order to process the return packets of the home terminal.
[0092] 5) The home terminal NAS receives the packet and replies with a return packet. The user plane network element vSwitch determines that the packet is a downlink packet from the private network by the destination IP (10.10.10.10) in the return packet. Then, it uses the MAC address of the home terminal NAS and user information (QINQ+VNI) to query the downlink traffic forwarding table, replaces the source MAC with the WAN MAC (11:22:33:44:55:88), changes the destination IP to the MAC of the cloud core network device (aa:bb:cc:dd:ee:ff), and encapsulates it into the VxLAN2001 tunnel of the cloud core network device and sends it back to the cloud core network device.
[0093] This application embodiment enables communication between mobile terminals and home network devices on the home broadband access network side, empowering the edge access gateway and breaking down network isolation between the public and private networks. Compared to related technologies, home broadband places greater emphasis on the combination of computing power and network. In this application embodiment, the home terminal gateway and terminal do not require additional configuration of a Virtual Private Network (VPN) (VPN is a technology that builds an encrypted channel over a public network (such as the Internet),) reducing configuration complexity.
[0094] Based on the same inventive concept, such as Figure 9 As shown, this application embodiment also provides an edge access gateway 900, which includes a control plane network element 910 and a user plane network element 920; The control plane network element 910 is used to send the information of the home broadband terminal obtained from the completion of the Ethernet point-to-point protocol dialing to the user plane network element. The user plane network element 920 is used to receive access packets sent by cloud core network devices. When the access packet meets the preset conditions based on the source IP address of the inner packet in the access packet, it parses the inner destination MAC address and destination IP address in the access packet as the WAN MAC address and terminal IP address of the corresponding broadband user. The user plane network element 920 is also used to query the pre-stored uplink traffic forwarding table based on the WAN MAC address and the terminal IP address, obtain the corresponding gateway MAC address and terminal MAC address, replace the source and destination MAC addresses of the access packet with the gateway MAC address and the terminal MAC address respectively, and send the access packet to the home terminal.
[0095] User plane element 920 is responsible for forwarding uplink and downlink traffic, which consists of two parts: first, determining whether a packet is traveling from a private network; and then performing specific operations. The judgment and execution operations for uplink and downlink traffic are different.
[0096] According to the edge access gateway provided in the embodiments of this application, the edge access gateway includes control plane network elements and user plane network elements. The control plane network elements in the edge access gateway transmit the DHCP IP address allocation information of the home broadband user and terminal after Ethernet point-to-point protocol dialing to the user plane network elements. The user plane network elements determine whether it is a private network accompanying packet based on the source IP address of the inner packet of the access packet. If so, they parse the inner destination MAC and IP address as the WAN MAC address and terminal IP address, and then query the pre-stored uplink traffic forwarding table to obtain the gateway and terminal MAC addresses, replace the source and destination MAC addresses of the access packet, and send it to the home terminal. Therefore, internal and external network interconnection can be completed without a public IP address or a third-party server, reducing third-party relay latency, improving access speed, and significantly reducing costs.
[0097] Based on the same inventive concept, this application also provides a home intranet access system, which can be further referred to... Figure 1 This includes home terminals, home gateways, broadband access servers, edge access gateways, and cloud core network equipment; edge access gateways include control plane network elements and user plane network elements. The control plane network element is used to send the information of the home terminal obtained from the Ethernet point-to-point protocol dialing completion to the user plane network element; The user plane network element is used to receive access packets sent by the cloud core network device. When the access packet meets the preset conditions based on the source IP address of the inner packet in the access packet, the inner destination MAC address and destination IP address in the access packet are parsed and used as the WAN MAC address and terminal IP address of the corresponding user. The user plane network element is also used to query the pre-stored uplink traffic forwarding table based on the WAN MAC address and the terminal IP address, obtain the corresponding gateway MAC address and terminal MAC address, replace the source and destination MAC addresses of the access packet with the gateway MAC address and the terminal MAC address respectively, and send the access packet to the home terminal.
[0098] The home intranet access system provided in this application embodiment can achieve... Figures 2 to 7 The functions of each step in the method for accessing the home intranet based on the edge access gateway, and the corresponding technical effects provided, will not be elaborated here for the sake of brevity.
[0099] Furthermore, in conjunction with the methods for accessing a home intranet based on an edge access gateway in the above embodiments, this application embodiment can provide a computer storage medium for implementation. This computer storage medium stores computer program instructions; when these computer program instructions are executed by a processor, they implement any of the methods for accessing a home intranet based on an edge access gateway in the above embodiments.
[0100] This application also provides a computer program product in which the instructions, when executed by the processor of an electronic device, cause the electronic device to perform various processes implementing any of the above-described method embodiments for accessing a home intranet based on an edge access gateway.
[0101] It should be clarified that this application is not limited to the specific configurations and processes described above and shown in the figures. For the sake of brevity, detailed descriptions of known methods are omitted here. In the above embodiments, several specific steps are described and shown as examples. However, the method process of this application is not limited to the specific steps described and shown. Those skilled in the art can make various changes, modifications, and additions, or change the order of steps, after understanding the spirit of this application.
[0102] The functional blocks shown in the above-described structural diagram can be implemented as hardware, software, firmware, or a combination thereof. When implemented in hardware, they can be, for example, electronic circuits, application-specific integrated circuits (ASICs), appropriate firmware, plug-ins, function cards, etc. When implemented in software, the elements of this application are programs or code segments used to perform the required tasks. Programs or code segments can be stored on a machine-readable medium or transmitted over a transmission medium or communication link via data signals carried on a carrier wave. "Machine-readable medium" can include any medium capable of storing or transmitting information. Examples of machine-readable media include electronic circuits, semiconductor memory devices, read-only memory (ROM), flash memory, erasable read-only memory (EROM), floppy disks, compact disc read-only memory (CD-ROM), optical disks, hard disks, fiber optic media, radio frequency (RF) links, etc. Code segments can be downloaded via computer networks such as the Internet, intranets, etc.
[0103] It should also be noted that the exemplary embodiments mentioned in this application describe methods or systems based on a series of steps or apparatus. However, this application is not limited to the order of the above steps; that is, the steps can be performed in the order mentioned in the embodiments, or in a different order, or several steps can be performed simultaneously.
[0104] The aspects of this disclosure have been described above with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this disclosure. It should be understood that each block in the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus to produce a machine such that these instructions, executable via the processor of the computer or other programmable data processing apparatus, enable the implementation of the functions / actions specified in one or more blocks of the flowchart illustrations and / or block diagrams. Such a processor can be, but is not limited to, a general-purpose processor, a special-purpose processor, a special application processor, or a field-programmable logic circuit. It is also understood that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can also be implemented by special-purpose hardware performing the specified functions or actions, or can be implemented by a combination of special-purpose hardware and computer instructions.
[0105] The above are merely specific embodiments of this application. Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, modules, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here. It should be understood that the protection scope of this application is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in this application, and these modifications or substitutions should all be covered within the protection scope of this application.
Claims
1. A method for accessing a home intranet based on an edge access gateway, characterized in that, The method includes: Obtain information about the home terminal obtained after completing an Ethernet point-to-point protocol dial-up connection; When an access message is received from a cloud core network device, and the access message is determined to meet a preset condition based on the source IP address of the inner message in the access message, the inner destination MAC address and destination IP address in the access message are parsed and used as the WAN MAC address and terminal IP address of the corresponding broadband user. The pre-stored uplink traffic forwarding table is queried based on the WAN MAC address and the terminal IP address to obtain the corresponding gateway MAC address and terminal MAC address. The source and destination MAC addresses of the access packet are replaced with the gateway MAC address and the terminal MAC address, respectively, and the access packet is sent to the home terminal.
2. The method according to claim 1, characterized in that, The method further includes: Upon receiving the message returned by the home terminal, if the destination IP in the message meets the preset conditions, the source MAC address and user information in the message are parsed, and the WAN MAC address and the MAC address of the cloud core network device are obtained by querying the pre-stored downlink traffic forwarding table. The inner source MAC address in the message is replaced with the WAN MAC address, and the destination MAC address is replaced with the MAC address of the cloud core network device. The VxLAN tunnel of the cloud core network device is then encapsulated to achieve traffic forwarding.
3. The method according to claim 1, characterized in that, Before querying the pre-stored uplink traffic forwarding table based on the WAN MAC address and the terminal IP address to obtain the corresponding gateway MAC address and terminal MAC address, and replacing the source and destination MAC addresses of the access packet with the gateway MAC address and terminal MAC address respectively before sending it to the home terminal, the method further includes: After completing the Ethernet point-to-point protocol dialing and the DHCP IP address allocation for the home terminal, the user-related information is reported to the management platform for the management platform to generate summary information. The system receives the aggregated information sent by the management platform and generates an uplink traffic forwarding table based on the aggregated information. The uplink traffic forwarding table is a key-value structure, where the keys are the WAN MAC address and the terminal IP address, and the values are the gateway MAC address, the terminal MAC address, and the user information.
4. The method according to claim 2, characterized in that, The method further includes: Obtain the MAC address and network identifier of the cloud core network device from the access message sent by the cloud core network device; Obtain the terminal MAC address, WAN MAC address, and user information from the uplink traffic forwarding table; Based on the MAC address of the cloud core network device, the network identifier of the cloud core network device, the terminal MAC address, the WAN MAC address, and the user information, a downlink traffic forwarding table is generated. The downlink traffic forwarding table is a key-value structure, where the keys are the terminal MAC address and the user information, and the values are the WAN MAC address, the MAC address of the cloud core network device, and the network identifier of the cloud core network device.
5. The method according to any one of claims 1 to 4, characterized in that, The edge access gateway is logically deployed between the broadband access server and the cloud core network device in the form of a board or physical server; sending the access message to the home terminal includes: The access message is sent to the home terminal through the broadband access server.
6. The method according to claim 5, characterized in that, Sending the access message to the home terminal through the broadband access server includes: The broadband access server sends the access message to the home gateway in bridge mode, so that the home gateway can send the access message to the home terminal.
7. The method according to claim 1, characterized in that, The preset condition includes that the source IP address of the inner message in the access message belongs to the IP address of a pre-configured cloud core network device.
8. An edge access gateway, characterized in that, The edge access gateway includes control plane network elements and user plane network elements; The control plane network element is configured to send the information of the home terminal obtained from the completed Ethernet point-to-point protocol dialing to the user plane network element. The user plane network element is configured to receive access packets sent by the cloud core network device. When the access packet meets the preset conditions based on the source IP address of the inner packet in the access packet, the inner destination MAC address and destination IP address in the access packet are parsed as the WAN MAC address and terminal IP address of the corresponding broadband user. The user plane network element is also configured to query a pre-stored uplink traffic forwarding table based on the WAN MAC address and the terminal IP address to obtain the corresponding gateway MAC address and terminal MAC address, replace the source and destination MAC addresses of the access packet with the gateway MAC address and terminal MAC address respectively, and send the access packet to the home terminal.
9. A home intranet access system, characterized in that, It includes home terminals, home gateways, broadband access servers, edge access gateways, and cloud core network equipment; the edge access gateway includes control plane network elements and user plane network elements; The control plane network element is used to send the information of the home terminal obtained from the completed Ethernet point-to-point protocol dialing to the user plane network element. The user plane network element is used to receive access packets sent by the cloud core network device. When the access packet meets the preset conditions based on the source IP address of the inner packet in the access packet, the inner destination MAC address and destination IP address in the access packet are parsed as the WAN MAC address and terminal IP address of the corresponding broadband user. The user plane network element is also used to query a pre-stored uplink traffic forwarding table based on the WAN MAC address and the terminal IP address to obtain the corresponding gateway MAC address and terminal MAC address, replace the source and destination MAC addresses of the access packet with the gateway MAC address and terminal MAC address respectively, and send the access packet to the home terminal.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer program instructions that, when executed by a processor, implement the method for accessing a home intranet based on an edge access gateway as described in any one of claims 1 to 7.
11. A computer program product, characterized in that, When the instructions in the computer program product are executed by the processor of the device, the device is able to perform the method for accessing a home intranet based on an edge access gateway as described in any one of claims 1 to 7.