Device and method for constructing virtual enterprise network
The present disclosure relates to a 5th (5G) generation or pre-5G communication system for supporting a higher data transmission rate beyond a 4th (4G) generation communication system such as long term evolution (LTE). According to embodiments of the present disclosure, a method performed by a packet classifier for a virtual enterprise network (VEN), in a wireless communication system, may include receiving an Ethernet packet from a user plane function (UPF), obtaining a source medium access control (MAC) address and virtual local area network (VLAN) identification information of the Ethernet packet, identifying a virtual switch (VSW) of an enterprise corresponding to the source MAC address and the VLAN identification information, forwarding the Ethernet packet to the VSW, and authenticating a member of a virtual network group based on a MAC address.
1 . A method performed by a packet classifier for a virtual enterprise network (VEN), in a wireless communication system, comprising:
receiving an Ethernet packet from a user plane function (UPF) entity;
obtaining a source medium access control (MAC) address and virtual local area network (VLAN) identification information of the Ethernet packet;
identifying whether the source MAC address and the VLAN identification information of the Ethernet packet are included in a table;
if the source MAC address and the VLAN identification information of the Ethernet packet are included in the table, identifying a virtual switch (VSW) of an enterprise corresponding to the source MAC address and the VLAN identification information among the plurality of VSWs;
if the source MAC address and the VLAN identification information of the Ethernet packet are not included in the table, registering the source MAC address and the VLAN identification information of the Ethernet packet to the table; and
forwarding the Ethernet packet to the VSW of the enterprise.
2 . The method of claim 1 , wherein the packet classifier is connected to the UPF entity through general packet radio service (GPRS) tunneling protocol user data (GTP-U) tunneling on an N6 interface or an N9 interface, and
connected with the VSW based on the GTP-U tunneling.
3 . The method of claim 1 , further comprising:
receiving a downlink (DL) Ethernet packet from a server for the VEN;
identifying whether the DL Ethernet packet is a unicast packet;
based on the DL Ethernet packet being the unicast packet, obtaining a destination MAC address of the DL Ethernet packet;
identifying destination tunnel information based on the destination MAC address; and
forwarding the DL Ethernet packet based on the destination tunnel information.
4 . The method of claim 3 , further comprising:
based on the DL Ethernet packet being the broadcast packet, transmitting the DL Ethernet packet to all terminals in the same virtual network group.
5 . The method of claim 1 , further comprising:
receiving an Ethernet packet from a customer premises equipment (CPE) through tunneling; and
obtaining a source MAC address and VLAN identification information of the Ethernet packet.
6 . The method of claim 1 , further comprising:
based on receiving an internet protocol (IP) packet from a packet gateway (P-GW) or the UPF entity through the tunneling, mapping an IP address to Ethernet, and forwarding the packet to the VSW according to the mapped address; and
based on a session of the Ethernet packet received from the VSW being mapped to the IP address, mapping the Ethernet packet to the IP packet, and forwarding the IP packet to a P-GW or a UPF entity corresponding to the IP packet.
7 . The method of claim 1 , further comprising:
receiving a query message from an unauthorized communication device;
performing redirection to a captive portal server, in response to the query message; and
transmitting a response message according to the redirection to the communication device.
8 . An apparatus of a packet classifier for a virtual enterprise network (VEN), in a wireless communication system, comprising:
at least one processor comprising processing circuitry; and
at least one transceiver,
wherein the at least one processor is configured, individually and/or collectively, to:
receive an Ethernet packet from a user plane function (UPF) entity,
obtain a source medium access control (MAC) address and virtual local area network (VLAN) identification information of the Ethernet packet,
identify whether the source MAC address and the VLAN identification information of the Ethernet packet are included in a table,
if the source MAC address and the VLAN identification information of the Ethernet packet are included in the table,
identify a virtual switch (VSW) of an enterprise corresponding to the source MAC address and the VLAN identification information among the plurality of VSWs, and
if the source MAC address and the VLAN identification information of the Ethernet packet are not included in the table, registering the source MAC address and the VLAN identification information of the Ethernet packet to the table; and
forward the Ethernet packet to the identified VSW of the enterprise.
9 . The apparatus of 8 , wherein the packet classifier is connected to the UPF entity through general packet radio service (GPRS) tunneling protocol user data (GTP-U) tunneling on an N6 interface or an N9 interface, and
connected with the VSW based on the GTP-U tunneling.
10 . The apparatus of 8 , wherein the at least one processor is further configured, individually and/or collectively, to:
receive a downlink (DL) Ethernet packet from a server for the VEN,
identify whether the DL Ethernet packet is a unicast packet,
based on the DL Ethernet packet being the unicast packet, obtain a destination MAC address of the DL Ethernet packet,
identify destination tunnel information based on the destination MAC address,
forward the DL Ethernet packet based on the destination tunnel information,
based on the DL Ethernet packet being the broadcast packet, transmit the DL Ethernet packet to all terminals in the same virtual network group.
11 . The apparatus of 8 , wherein the at least one processor is further configured, individually and/or collectively, to:
receive an Ethernet packet from a customer premises equipment (CPE) through tunneling, and
obtain a source MAC address and VLAN identification information of the Ethernet packet.
12 . The apparatus of 8 , wherein the at least one processor is further configured, individually and/or collectively, to:
based on receiving an internet protocol (IP) packet from a packet gateway (P-GW) or the UPF entity through the tunneling, map an IP address to Ethernet, and forwarding the packet to the VSW according to the mapped address, and
based on a session of the Ethernet packet received from the VSW being mapped to the IP address, map the Ethernet packet to the IP packet, and forwarding the IP packet to a P-GW or a UPF entity corresponding to the IP packet.