Äú¿ÉÒÔ¾èÖú£¬Ö§³ÖÎÒÃǵĹ«ÒæÊÂÒµ¡£

1Ôª 10Ôª 50Ôª





ÈÏÖ¤Â룺  ÑéÖ¤Âë,¿´²»Çå³þ?Çëµã»÷Ë¢ÐÂÑéÖ¤Âë ±ØÌî



  ÇóÖª ÎÄÕ ÎÄ¿â Lib ÊÓÆµ iPerson ¿Î³Ì ÈÏÖ¤ ×Éѯ ¹¤¾ß ½²×ù Model Center   Code  
»áÔ±   
   
 
     
   
 ¶©ÔÄ
  ¾èÖú
SD-WAN¼¼ÊõʵÏÖ·½°¸£¨Ï¸½Ú£©
 
×÷ÕߣºÃ»ÓкÏÊʵÄ
  3506  次浏览      27
2020-11-17 
 
±à¼­ÍƼö:
±¾ÎÄÖ÷Òª½éÉÜÁË×éÍøÄ£ÐÍ¡¢¼¼Êõ¼Ü¹¹¡¢È«¾Ö½¥½øÊÓͼµÈÏà¹ØÄÚÈÝ¡£
±¾ÎÄÀ´×ÔÓÚcsdn£¬ÓÉ»ðÁú¹ûÈí¼þAnna±à¼­ÍƼö¡£

1×éÍøÄ£ÐÍ

1.1×éÍø³¡¾°(underlay)

±±¾©HUB£ºCPEË«Ïß½ÓÈëMPLSÍøÂçºÍ¿í´øÍøÂ磬¿í´øÍøÂç¾ßÓÐÈ«ÇòIP¡£

º¼ÖÝHUB£ºCPEË«Ïß½ÓÈëMPLSÍøÂçºÍÒÆ¶¯ÍøÂ磬¿í´øÍøÂç¾ßÓÐÈ«ÇòIP¡£

SPOKE1£ºµ¥ÏßÅÔ¹Ò½ÓÈëÕ¾µãºËÐĽ»»»»ú£¬ÎÞÈ«ÇòIP¡£

SPOKE2£ºCPEË«Ïß½ÓÈëMPLSÍøÂçºÍ¿í´øÍøÂ磬¿í´øÍøÂç¾ßÓÐÈ«ÇòIP¡£

SPOKE3£ºCPEË«Ïß½ÓÈëMPLSÍøÂçºÍÒÆ¶¯ÍøÂç£¬ÒÆ¶¯ÍøÂçÎÞÈ«ÇòIP¡£

MPLS×éÍøÇé¿ö£º±±¾©HUB-º¼ÖÝHUB»¥Áª¡¢±±¾©HUB-SPOKE1»¥Áª£¬±±¾©HUB-SPOKE2»¥Áª¡£

¿í´ø×éÍøÇé¿ö£º±±¾©HUB-º¼ÖÝHUB-SPOKE1-SPOKE2-SPOKE3È«»¥Áª¡£

ÒÆ¶¯×éÍøÇé¿ö£ºº¼ÖÝHUB-SPOKE3»¥Áª¡£

1.2ͨÐÅÄ£ÐÍ(overlay)

×éÍøÒªÇó£ºÂú×ã¸ßÓÅÏȼ¶ÒôÊÓÆµ´«ÊäÖÊÁ¿£¬Í¬Ê±½µµÍMPLSÏß·×Ê·Ñ¡£

×éÍøËµÃ÷£º³ýSPOKE1ºÍSPOKE2Ö®¼äΪ¶¯Ì¬ËíµÀÍ⣬ÆäËü¶¼ÊǾ²Ì¬ËíµÀ£¬SPOKE3Ó뺼ÖÝHUBÖ®¼ä´æÔÚÒ»ÌõLTEÀàÐ͵ÄÔÖ±¸ËíµÀ£¬Èç¹ûº¼ÖÝHUB²»¾ß±¸LTEµÄ¹«ÍøIP£¬ÔòÁ÷Á¿¾­LTEÍøÂçÈÆÐе½Internet½ÓÈ뺼ÖÝHUB¼´¿É¡£

2¼¼Êõ¼Ü¹¹

¼¼ÊõÑ¡ÐÍ£º¿¼ÂÇSD-WANµÄSDÌØÐÔ£¬ÕûÌå¿ò¼ÜÒÔSDN¼Ü¹¹Îª»ù´¡£¬ÄÏÏòÅäÖÃЭÒé²ÉÓÃNETCONF£¬ÒµÎñ¿ØÖÆÆ÷¾ß±¸ÉϵÛÊӽǣ¬ÎªÂú×ãÇá¿ìÐÔ½«¿ØÖÆÐ­Òé˽Óл¯£»±±Ïò¿ª·ÅWEB API£»¶«Î÷Ïò¿¼Âǵ½WANÁé»î×éÍøÒªÇó½«Â·ÓÉЭÒé´ÓÒµÎñ¿ØÖÆÆ÷ÖаþÀ룬ϳÁÖÁCPE¡£

¹ÜÀíÃæ£ºÄÏÏòʹÓÃÍø¹Ü£¬ÅäÖòÉÓÃNETCONF£¬²¿·Ö¼à¿Ø¶Ô½ÓÒµÎñ¿ØÖÆÆ÷£»±±ÏòʹÓÃWEB£¬¿ª·Å²éѯºÍÅäÖÃÒ³Ãæ¡£

¿ØÖÆÃ棺ҵÎñ¿ØÖÆÆ÷ʹÓÃ˽ÓÐЭÒé¹ÜÀíÒµÎñ״̬ºÍת·¢×´Ì¬£¬ÓÉIPSEC±£Ö¤Í¨ÐŰ²È«£»½ö·ÓɲÉÓÃ×Ôѧϰ·½Ê½Ï·ŵ½CPE²ãÃæ£¬ÆôÓÃBGPЭÒé¡£

ÒµÎñÃæ£º²Î¿¼»ªÎªDSVPN·½°¸£¬Âú×ãHUB-SPOKE×éÍøºÍFull Mesh×éÍø¡£×ª·¢²ãͬʱ°üÀ¨DPI¡¢ÖÇÄÜѡ·£¬´«Ê䰲ȫÐÔÓÉIPSEC±£Ö¤£¬ÓëFW×é³É·þÎñÁ´£¬Îª¿ÉÑ¡×é¼þ¡£

2.1¹ÜÀíÄ£ÐÍ

2.1.1¿ª¾Ö¹ÜÀí(ZTP)

¶¨Ò壺վµã¿ª¾ÖÊôÓÚÏßÏ£¨ÀëÏߣ©¹ÜÀíÓëÅäÖõÄÒ»²¿·Ö£¬ÎªCPEÈëÍøÌṩ±ØÒªÌõ¼þ¡£

×÷Ó㺱ÜÃâÔËάÈËÔ±ÔÚµãÅäÖã¬Ê¹É豸ÓÐЧ¡¢°²È«ÈëÍø¡£

ÀàÐÍ£ºUÅÌ¿ª¾Ö¡¢Óʼþ¿ª¾Ö¡¢¶ÌÐÅ¿ª¾ÖµÈ¡£

Èë¿Ú£ºCPE×°±¸Íê³É¡¢Ïß·½ÓÈë¾ÍÐ÷¡£

³ö¿Ú£ºCPE³É¹¦ÈëÍø(Internet)£¬²¢ÓÚ¿ØÖÆÆ÷³É¹¦Í¨ÐÅ¡£

¿ª¾ÖÁ÷³Ì£º

1¡¢ ÍøÂç¹ÜÀíÔ±¸ù¾ÝCPEËùÔÚÕ¾µã»·¾³ÅäÖÃ×¼ÈëÍøÉ豸µÄÍøÂç»ù´¡ÅäÖ㬰üÀ¨É豸±êʶ¼°ÀàÐÍ¡¢ÊÚȨ֤Êé¡¢DHCP·þÎñÆ÷»ò¾²Ì¬IP¼°Underlay·ÓÉЭÒéÅäÖ㨶þѡһ£©»òÆäËü£¨ÖÃÓÚ×éÍø¹ÜÀí£©£¬²¢Éú³ÉZTP¿ª¾ÖÅäÖã¬ÓÉϵͳ°²È«¼ÓÃܺóµ¼ÈëUÅÌ»òÓʼþ·þÎñÆ÷»ò¶ÌÐÅÍø¹ØÖС£

2¡¢ ×°±¸ÈËÔ±²åÈëUÅÌ»òʹÓÃCPE·ÃÎÊÓʼþURLÓÉCPE×Ô¶¯»ñÈ¡ZTPÅäÖ㬻ò·¢ËͰ²È«Ö¸Áîµ½¶ÌÐÅ·þÎñÆ÷ºó»ñÈ¡ÅäÖò¢Ê¹ÓÃCPE WEBÅäÖÃÒ³´æÈë¡£

3¡¢ CPE¼ÓÔØZTPÅäÖú󣬳¢ÊÔÉêÇëÈëÍø¡£ÕâÀïÖ¸SD-WANÍøÂ磬Ö÷ÒªÊÇ¿ØÖÆÖÐÐÄ£¨¿ÉÄÜÊÇÍø¹Ø£©¶ÔCPE½øÈëSD-WANÍøÂçµÄÈÏÖ¤ÊÚȨ£¬¶øÈç´òͨInternetĬÈÏͨ¹ýDHCP»ò¾²Ì¬IPÅäÖÿÉÒÔʵÏÖ£¬ÓÉ×°±¸ÈËԱͨ¹ýCPE×Ô´øÍøÂçÁªÍ¨ÐÔ¼ì²â¹¦ÄܲâÊÔ¡£

4¡¢ ¿ØÖÆÖÐÐĸù¾ÝCPE·¢¹ýÀ´µÄÇëÇóÈëÍøÐÅÏ¢£¬Ð£Ñé²¢ÈÏÖ¤£¬·¢ËÍÈëÍø×´Ì¬£¬²¢±£´æCPEÈëÍø×´Ì¬ÒÔ¹©²éѯ¡£CPE¸ùé§ÈëÍø×´Ì¬´¦Àí£¬°üÀ¨ÈëÍø³É¹¦¡¢Ê§°Ü(ERRNO)¡¢³¬Ê±µÈ¡£

5¡¢ CPEÊÕµ½ÈëÍø³É¹¦ºó£¬½øÈë¾ÍÐ÷״̬£¬´Ëʱ¿ÉÓÉ¿ØÖÆÖÐÐÄÏ·¢×éÍøÅäÖã¬ÈÃCPE½ÓÈëSD-WANÍøÂ磨´Ë²¿·ÖÖÃÓÚµÚ¶þÅäÖý׶Σ©¡£

2.1.2×éÍø¹ÜÀí

¶¨Ò壺CPE½ÓÈëSD-WANÍøÂ粢Ϊ´òÍ¨Ë½ÍøÍøÂç½øÐеĽÓÈëÅäÖúÍ·ÓÉÅäÖã¬ÎªÒµÎñOverlayת·¢Ìṩͨ·±£ÕÏ£¨²¿·Ö¿ÉÖÃÓÚZTP£©¡£

×÷Ó㺱ÜÃâZTP¿ª¾Ö¹ýÓÚ·±ÔÓ£¬ÒÔ¼°ÅäÖð²È«£¬Í¬Ê±Âú×ãºóÆÚµÄ¿É±ä¸üÐÔ¡£

ÄÚÈÝ£ºÅäÖðüÀ¨£ºÍøÂçÐÅÏ¢¡¢VPN½ÓÈëÅäÖá¢Â·ÓÉЭÒéÅäÖá£

Èë¿Ú£ºZTP¿ª¾Ö³É¹¦¡£

³ö¿Ú£ºCPE½ÓÈëSD-WANÍøÂç³É¹¦£¬Ë½ÍøÊý¾Ý¿É´ï¡£

×éÍø¹ý³Ì£º

1¡¢ HUB¸ù¾Ý±¾ÇøÓòÍøÂçÀàÐÍÑ¡ÔñºÏÊʵÄת·¢Ä£Ê½£¬ÈçHUB-SPOKE»òFULL MESH£¨Çø·Ö[no] Shortcut£©£¨HUB¼äÊôÓڹǸÉ×éÍø£¬ÅäÖÿɹ̻¯£©¡£

2¡¢ ¡¾¿ÉÑ¡¡¿CPE¸ù¾Ý¶þ½×¶ÎÅäÖÃÁ¬½Óµ½Ö¸¶¨ÒµÎñ¿ØÖÆÆ÷£¬´¦Àí¼¯ÖÐÐÍÒµÎñ¡£

3¡¢ CPE¸ù¾Ý¶þ½×¶ÎÅäÖÃÖðÒ»´´½¨MGRE½Ó¿Ú£¨¶¯Ì¬²¦ºÅ´´½¨»ò¾²Ì¬ÅäÖ㩼°ÔËÐвÎÊý£¬²¢ÔÚ½Ó¿ÚÉÏʹÄÜIPSEC£¬ÆôÓÃNHRPÏòHUB×¢²á£¨»òÏòÒµÎñ¿ØÖÆÆ÷×¢²áÔÙ·´É仨HUB£©£¬Éú³ÉMGRE½Ó¿ÚÍøÂç¡£

4¡¢ CPE¸ù¾Ý¶þ½×¶ÎÅäÖÃÔÚMGREËùÓÐÍø¶ÎºÍÄÚ²¿Ë½ÍøÍø¶ÎʹÄÜ·ÓÉЭÒ飨ÈçBGP£©£¬Í¨¸æ±¾Ë½ÍøÂ·Óɲ¢Ñ§Ï°ÆäËüË½ÍøÂ·ÓÉ£¬ÔÙÏòת·¢Ãæ°²×°ÓÅѡ·ÓÉ¡£

5¡¢ CPE¸ù¾Ý¶þ½×¶ÎÅäÖÃͬ²½Ê¹ÄÜÏß·¼ì²âÄ£¿é¿ªÆôÖÊÁ¿»òÁ÷Á¿¼ì²â¡£

6¡¢ CPE¸ù¾Ý¶þ½×¶ÎÅäÖÃͬ²½Ó¦ÓÃÁ÷ת·¢²ßÂÔ£¬ÆôÓÃDPIºÍÖÇÄÜѡ·¹¤×÷¡£

2.1.3ÏßÉϹÜÀí

¶¨Ò壺¿ØÖÆÖÐÐÄÔÚÏßµÄÒµÎñ¹ÜÀí£¨²¿·Ö¿ÉÖÃÓÚ×éÍø¹ÜÀí£©¡£

×÷ÓãºÎªÖ§³ÖÈí¼þ¶¨Òå·þÎñÌṩ±ØÒªÌõ¼þ¡£

ÄÚÈÝ£ºÊµÊ±±ä¸ü×éÍøÅäÖá¢É豸¹Ü¿Ø¡¢ÔËά¼à¿Ø¡£

¹ÜÀí°üÀ¨£º

×éÍøÅäÖ㺱ä¸üIPSEC°²È«ÃÜÔ¿¡¢±ä¸üת·¢Ä£Ê½¡¢±ä¸üÈëÍøÏß·¼°²ÎÊý¡¢±ä¸üÁ÷ת·¢²ßÂÔ¡¢±ä¸ü·ÓÉЭÒé²ÎÊýµÈ¡£

É豸¹Ü¿Ø£ºÉ豸°æ±¾Éý½µ¼¶»ò×é¼þÈȲ¹¶¡¡¢Ïß·×è¶Ï»òÇл»¡¢µ¯ÐÔÉìËõµÈ¡£

ÔËά¼à¿Ø£ºÊÕ¼¯ÈÕÖ¾¡¢ÊÕ¼¯Ïß·ÖÊÁ¿»òÁ÷Á¿×´Ì¬¡¢ÊÕ¼¯ÏµÍ³¸ººÉ(CPU¡¢ÄÚ´æ¡¢IO)ÐÅÏ¢µÈ¡£

2.2¿ØÖÆÄ£ÐÍ

¿ØÖƵÄ×÷ÓÃÖ÷ÒªÊÇʵÏÖËùÓÐSD-WANÍøÔªµÄЭͬ¹¤×÷£¬ÒÔ´ËÀ´ÊµÏÖ×îÓÅ×éÍø¡£

·½°¸²ÉÓûìºÏ¿ØÖÆÄ£ÐÍ£¬²¿·ÖÒµÎñÒÀÀµÓÚÒµÎñ¿ØÖÆÆ÷½øÐÐͳһµ÷¶È£¬²¿·ÖÒµÎñ³öÓÚÐÔÄܺÍת·¢ÐèҪϳÁÖÁCPE£¨Èç¿§·Èɫͨ·£©£¬°üÀ¨Â·ÓÉЭÒéºÍNHRPЭÒé¡£

2.2.1·ÖÉ¢¿ØÖÆ

ÓÉÓÚCPEÐèÒªÂú×ãLAN²àµÄ×éÍøÐèÇ󣬲¢ÇÒÐèÒª¶Ô½ÓTier 1ÔËÓªÉÌÍøÂ磬ÐèÒª±£ÁôIGP»òBGPЭÒ飻ͬʱSD-WANת·¢²ãÖÇÄÜѡ·¾ö¶¨£¬Â·ÓÉ¿ØÖƲã½öά³Ö·ÓɵÄÎÞ»·ÐԺͿɴïÐÔ¼´¿É£¬ÎȳÖÒ»¶¨µÄºã̬£»ÖÐÐÄ·ÓÉ·½Ê½Ï£¬ÒµÎñ¿ØÖÆÆ÷ÐèÒªÓëËùÓÐCPEÈ·Á¢ÁÚ¾Ó¹ØÏµ£¬´ó¹æÄ£×éÍøÊÜÏÞ£»ÁíÍ⣬CPEÈÔÈ»ÐèҪ·ÓÉЭÒé»ò´úÀíЭÒé·Ö·¢À´×ÔÒµÎñ¿ØÖÆÆ÷µÄ·ÓÉ¡£ËùÒÔ£¬²ÉÓô«Í³Â·ÓÉЭÒéOverlayµÄ·½Ê½±È½ÏºÏÊÊ¡£

ÁíÍ⣬ÓÉÓÚ²ÉÓÃMGRE½Ó¿Ú³ÐÔØOverlayÒµÎñ£¬Æäp2mpÀàÐÍÐèÒªÃ÷È·ÖªµÀËùÔÚÓòµÄ¡°ÁÚ½Ó¡±¹ØÏµ£¬ÒÔ½¨Á¢MGRE¡°Óò¡°£¬´ËʱÒÀÀµÓÚCPE¡°×¢²á¡°£¬¶øNHRPЭÒé¾ß±¸×¢²á¹ý³ÌÂú×ã´ËÐèÇó¡£ÁíÒ»ÖÖ·½·¨£¬²ÉÓÃÖÐÐÄÊÕ¼¯·Ö·¢µÄ·½Ê½Ò²ÄÜÂú×㣬µ«²»Ì«ÍêÃÀ£¬Ô­ÒòÊÇCPEµ½HUBË«ÏòÎïÀíÁªÍ¨ÐÔÊÇÎÞ·¨Ô¤ÖªµÄ£¬¶øNHRP×¢²áµÄͬʱҲ֤Ã÷ÁËÁªÍ¨ÐÔ¡£ÕâÊÇËùÓм¯ÖпØÖÆ·½Ê½ÐèÒª¿¼ÂǵÄÌõ¼þÖ®Ò»¡£

±¸×¢£ºÒµÎñ¿ØÖÆÆ÷ÓëÍø¹ÜËù´¦Í¬Ò»Âß¼­²ã´Î£¬µ«²¢²»Òâζ×ÅÁ½ÕßÍêÈ«°ó¶¨£¬ÒµÎñ¿ØÖÆÆ÷ÓÉÓÚÓëÒµÎñÇ¿Ïà¹Ø£¬Ò»°ã¿ÉÒÔÖÃÓÚHUB´¦£¬»ò×÷ΪHUBÖеÄÒ»¸ö·þÎñ×é¼þ¡£

2.2.2¼¯ÖпØÖÆ

ÒµÎñÊÇ·ñÐèÒª·ÅÔÚÒµÎñ¿ØÖÆÆ÷ÒÀÀµÓÚÒµÎñÊÇ·ñÐèÒª¾ß±¸¡±ÉϵÛÊӽǡ°-È«¾Ö¿É²éÐÔºÍÈ«¾Ö¿É¿ØÐÔ£¬ÈçTE¹¤³Ì¡£ÀýÈ磬ҵÎñ¿ØÖÆÆ÷ÊÕ¼¯È«ÍøCPEÐÅÏ¢£¬°üÀ¨Ïß·ÖÊÁ¿ÐÅÏ¢ºÍÁ÷Á¿Í³¼ÆÐÅÏ¢£¬ÒÔ¼°CPEϵͳ¸ººÉµÈ£¬ÊÕ¼¯Êý¾Ý²¢×ÛºÏÔËËãµÃµ½²ßÂÔ£¬²¢½«²ßÂÔÏ·¢µ½¹ØÁªµÄCPE£¬¿ØÖÆÁ÷ת·¢Â·¾¶¡£

±¾·½°¸Öн«Ïß·¼ì²âÖÃÓÚÒµÎñ¿ØÖÆÃ棨À¶É«Í¨Â·£©£¬SD-WANÍøÂçÖÐËùÓÐCPE·Ö¶ÎÊÕ¼¯Æä¡°ÏàÁÚ¡°µ¥ÏòÏß·ÖÊÁ¿ºÍÁ÷Á¿×´¿ö²¢Éϱ¨µ½ÒµÎñ¿ØÖÆÆ÷£¬ÓÉÒµÎñ¿ØÖÆÆ÷¼ÆËãÕûÍøÖÊÁ¿Çé¿ö£¬»ã×ܸøÍø¹Ü»òÏ·¢Á÷Çл»Ö¸Áî¡£

2.3·ÓÉÄ£ÐÍ

2.3.1 HUB-SPOKE×éÍø

·ÓÉÌØµã£º¼¯ÖÐת·¢Ä£ÐÍ£¬¿çSPOKEͨÐÅÁ÷Á¿¾­HUBÈÆÐС£

±¸×¢£º²»Í¬ÔËÓªÉÌÑ¡Óò»Í¬µÄÄÚ²¿GREÍøÂ磬һ·½ÃæÔÚѡ·ҵÎñÉϲ»Í¬µÄÔËÓªÉÌÏß·¾ß±¸²»Í¬µÄ´«ÊäÌØÐÔ£»ÁíÒ»·½ÃæÔÚºó¼ÌÕ½ÚʵÏÖFULLMESHʱ¿É±ÜÃâÄϱ±Ïß·ÎÊÌâÒÔ¼°VPN FULL MESHÎÊÌâ¡£

´ËÖÖ×éÍøÄ£ÐÍÏ£¬ËùÓÐSPOKE¼äͨО­HUBÈÆÐУ¬Ò»·½ÃæSPOKE²àÐÔÄܽÏÈõÎÞ·¨´¦Àí´óÁ¿Â·ÓÉ»ò½¨Á¢´óÁ¿ËíµÀ£»ÁíÒ»·½Ãæ¾­HUB¿É³ä·ÖÀûÓÃÏÖÍø×¨Ïߣ¬ÑÓ³Ù»òÐí²»ÊÇ×îÓÅ£¬µ«´«ÊäÖÊÁ¿¸ü¿É¿¿¸üÎȶ¨¡£

ÉÏÊö×éÍøÖУ¬ÓÉHUB¸ù¾Ýµ±Ç°×éÍøÄ£ÐÍ£¬ÏòSPOKEͨ¸æ¾ÛºÏ·ÓÉÀ´¼õÉÙ·ÓɹæÄ££¬²¢½«ËùÓзÓɵÄÏÂÒ»ÌøÖ¸ÏòHUB£»SPOKEÔÚ·ÓɲãÃæÐγÉË«Ï߸ºÔØÉÏÐС£

2.3.2 FULL-MESH×éÍø

·ÓÉÌØµã£ºÖ§³ÖSPOKE¼äÖ±½¨DVPN½øÐÐͨÐÅ£¬±ÜÃâÁ÷Á¿¾­HUBÈÆÐС£

SHUTCUT

´ËÖÖ×éÍø¶ÔÉ豸ºÍ×éÍøµÄÒªÇóÓëHUB-SPOKE×éÍø´óÖÂÏàͬ£¬½öÔÚijЩSPOKE¼äÓÐÐèÒªÖ±½¨VPNͨÐŵÄÐèÇóʱÆôÓã¬Ò»°ãÇé¿öÏÂSPOKE¼äÓÐרÓÐÖÐËÙÏß·£¬¶ø²»ÊÇʹÓõÍËÙ¿í´øÏß·£¨µ±È»Èç¹û²¿ÊðʱÄÜÈ·ÈÏÁ½SPOKEËùÊôÏàͬ¿í´øÍøÂç²¢ÇÒͨОàÀë½Ï½ü¿ÉÒÔÔÚ²ßÂÔÉÏʹÓôËÖÖͨÐÅ·½°¸~FULL-MESHÔÚÏÖÍøÖв¿ÊðʵÓÃÒâÒå²»´ó£¬¸ü¶àÊǼ¼ÊõÒâÒ壩¡£

·ÓÉЭÒé×éÖ¯ÉÏÓëHUB-SPOKEÏàͬ£¬ÌØÊâÐÔÔÚNHRPÉÏ¡£´ËģʽÏ£¬³õʼÁ÷Á¿¾­HUBÈÆÐУ¬Í¬Ê±SPOKEÔÚ·Óɺó(¾ö²ß)´¥·¢NHRP²éѯÇëÇó£¬HUBʹÓÃNHRP·µ»ØÏÂÒ»ÌøÐÅÏ¢£¬½èÓôËÐÅÏ¢ÏòSPOKEͬʱ±í´ïÖØ¶¨Ïò·ÓÉ»ò²»¿É´ïÐÅÏ¢£»SPOKEÊÕµ½NHRPÖØ¶¨Ïò·ÓÉÏìӦʱÕýʱ´¥·¢¶¯Ì¬ËíµÀ´´½¨£¬´´½¨³É¹¦ºó¸üÐÂת·¢±í(³È»ÆÉ«±íÏî£¬ÌØ±ð£ºÖض¨Ïò·ÓÉ¿ÉÒÔÖ¸ÏòHUB±¾Éí)£¬½«Á÷µ¼Èë´Ëͨ·£»SPOKEÊÕµ½²»¿É´ïÐÅϢʱ£¬Öжϱ¾µØÁ÷ת·¢£¨»òÏòLAN²àÉ豸ͨµÀICMP·Óɲ»¿É´ïÐÅÏ¢£©¡£

¶¯Ì¬ËíµÀÔÚÒµÎñÁ÷Á¿ÖжÏÒ»¶¨Ê±¼äºó£¬×Ô¶¯²ð³ý¶¯Ì¬ËíµÀ£»²¢ÇÒÖ÷¶¯ÏìÓ¦ËíµÀ¶Ï¿ªÊ¼þ£¬²¢·´Ïò²ð³ý·ÓÉ¡£

NO SHUTCUT

´ËÖÖ×éÍøÄ£ÐÍÏ£¬ÒµÎñÁ÷Á¿ÓëSHORTCUT´óÖÂÏàͬ£¬²»Í¬µãÔÚÓÚ³õʼÁ÷Á¿µÄ´¦Àí-SHORTCUTģʽÏÂÁ÷Á¿¾­HUBÈÆÐÐת·¢£¬¶ø´ËģʽÏ£¬Á÷Á¿Ö±½ÓÓÉSPOKEת·¢£¬¹Ê¶ø´æÔÚ³õʼÁ÷Á¿µÄÑÓ³Ù»òÕßµô°ü¡£¹Ê¶ø£¬FULL-MESHģʽ¶¼ÒªÇóSPOKEÓëSPOKE´æÔÚÒ»ÌõרÓÐÏß·֧³Å£¬DVPN½öÀûÓÃÁ½ÕßµÄ¿í´øÍøÂçʵÏÖ½µ·Ñ¡£

·ÓÉЭÒé²ãÃæ½«ÏòSPOKEÏ·¢Ã÷ϸ·ÓÉ£¬²¢ÇÒ²»ÐÞ¸ÄÏÂÒ»Ìø£¬ÕâÑùSPOKE¿ÉÒÔ»¥Ïàѧϰµ½Ã÷ϸ·ÓÉ£¬¶ø²¿·ÖµÍ¹¦ºÄ»ú-ÈçÊÝCPE£¬¿ÉÒÔ½«Â·ÓÉÔٴξۺϣ¬»òÖ±½ÓÒ»ÌõOverlayȱʡ·Óɵ½HUB¡£

ÒµÎñÁ÷Á¿ÈÔÈ»»á´¥·¢NHRPѧϰÏÂÒ»ÌøÐÅÏ¢£¬Í¬Ê±Ñ§Ï°µ½ºóµÄNHRPÐÅÏ¢ÈÔÈ»¿ÉÒÔ´´½¨Â·ÓÉÐÅÏ¢£¬¾ß±¸Ã÷ϸ·ÓɵÄCPEÓÅѡһ´Î·Óɼ´¿É£¬ÎÞÃ÷ϸ·ÓɵÄÊÝCPE²àÖ±½Ó¼ÓÈëת·¢²ã¡£

2.4½Ó¿ÚÄ£ÐÍ

ÕûÍøÐèÒªÖ§³Ö°üÀ¨µ¥²¥¡¢×é²¥ÌØÐÔ£¬²ÉÓÃmGRE½Ó¿ÚÀ´³ÐÔØ´ËÀàÒµÎñ¡£´ËÖÖ½Ó¿ÚÀàÐÍÊôÓÚp2mpÀàÐÍ-¶ÔHUB²à¶øÑÔÊôÓÚBroadÀàÐÍ£»¶ÔÓÚSPOKE¶øÑÔÊôÓÚP2PÀàÐÍ¡£

mGRE½Ó¿ÚÊôÓÚ¶¯Ì¬½Ó¿Ú£¬ÓÉSPOKE CPEÉÏÏߺóʹÓÃNHRPÏòHUB×¢²á£¨ÕûÌå¹ý³ÌÉæ¼°HUB mGREºÍDHCP Server½»»¥£©£¬½ø¶ø·ÖÅäµ½Ë½ÍøIPµØÖ·£¬¶ømGREÁª¶¯NHRP»ñµÃÏòP2MPÓò×¢²áµÄËùÓÐCPE£¬´Ó¶ø½¨Á¢½Ó¿ÚÂß¼­¹ØÏµ¡£

ÒµÎñÁ÷Á¿¾­mGRE¿Úʱ£¬½«´¥·¢NHRPÔÙѧϰȫ¾ÖÏÂÒ»ÌøIP£¨³¢ÊÔ»ñÈ¡×îÐÂÈ«¾ÖÏÂÒ»ÌøIP£©£¬ÓÃÓÚ·â×°GREÍâ²ãÍ·²¿¡£×é²¥±¨Îľ­mGRE½Ó¿Úºó·¢Ë͵½ËùÓÐNHRPÓòÄÚCPE£¬µ¥²¥±¨ÎÄÔò¾­¹ý·ÓÉת·¢ºóµÝ½»µ½Ö¸¶¨ÏÂÒ»Ìø¡£

ͨ¹ýInternet´«ÊäµÄ±¨ÎÄÒ»°ãÐèҪͨ¹ýIPSEC½øÐмÓÃܱ£»¤£¬ÓÉIPSEC¹ØÁªmGRE½Ó¿Ú£¬GRE½«Á÷Á¿µÝ½»¸øGigabit½Ó¿Úʱ£¬ÓÉIPSEC½Ø»ñ½øÐÐ͸Ã÷¼ÓÃÜ£¬²¢¸ù¾ÝÓ¦Ó󡾰ʹÓô«Êäģʽ»òËíµÀģʽ¡£

2.5ת·¢Ä£ÐÍ

2.5.1±¾µØË½Íø»¥Í¨

´ËʱCPE LAN²àϹҶà¸öÍø¶ÎµÄ×ÓÍø£¬CPEΪL3Íø¹Ø½ÇÉ«£¬Á÷Á¿¾­ÆÕͨ·Óɺóת·¢µ½ÁíÒ»¸ö×ÓÍø¡£LAN²àÈÔÈ»¿ÉÒÔϹҷÓÉÆ÷£¬²¢Ê¹Ó÷ÓÉЭÒéÓëCPE»¥Ñ§Â·ÓÉ£»²»Í¬×ÓÍøÈÔÈ»¿ÉÒÔ³ÐÔØÔÚͬһ¸öÎïÀí¶Ë¿ÚÉϲ¢Ê¹ÓÃTAGÇø·Ö£¬´ËʱCPE¿ÉÄÜÉæ¼°L2×éÍøÐèÇ󣬰üÀ¨Port AggºÍSTP¡£

2.5.2±¾µØ·ÃÎÊInternet

Ö§³Ö·ÃÎÊInternetµÄÁ÷Á¿Í¨¹ý¡°½ÓÈ롱CPEºó·¢Ë͵½Internet£¬CPEÔÚ·ÓɲãÃæÈÔȻΪL3Íø¹Ø½ÇÉ«¡£²»Í¬ÓÚ±¾µØË½Íø»¥Í¨£¬·ÃÎÊInternetµÄÁ÷Á¿½«¶îÍâ¾­¹ý·ÃÎÊ¿ØÖƲßÂÔÒÔ¼°ÖÊÁ¿·þÎñ±£ÕÏ£¬¾ß±¸FW¹¦ÄܵÄCPE½«Í¬Ê±½øÐа²È«ÐÔ¿ØÖÆ£¬²»¾ß±¸FW¹¦ÄܵÄCPE½«Í¨¹ý·þÎñÁ´µÝ½»µ½FWͳһ´¦Àí£¬¶ø´ÓInternet·µ»ØµÄÁ÷Á¿¹ýFWºóÖ±½Ó°´ÆÕͨL3ת·¢½øÐС£

2.5.3±¾µØTRAP±¨ÎÄ

ÓëÆÕͨRouter TRAP±¨ÎÄ´¦ÀíÁ÷³ÌÏàͬ£ºÁ÷Á¿¾­Çý¶¯½ÓÊÕºóÅжÏΪ±¾»ú±¨ÎÄ£¬¸ù¾ÝTRAP²ßÂԺͱ¨ÎÄÓÅÏȼ¶½øÐÐÉϽ»£¬Ð­ÒéÕ»Âýת´¦ÀíL3±¨ÎÄʱ£¬ÅжÏSOCKETÒѰ󶨴ËÁ÷Á¿£¬Ôò½»SOCKET´¦Àí£¬´Ó¶øµÝ½»Êý¾Ýµ½Ó¦Óá£

2.5.4ÒìµØË½Íø»¥Í¨

ÒìµØË½Íø»¥Í¨½«Í¨¹ýÕû¸öOverlayת·¢Â·¾¶£º1£©LAN²à±¨Îľ­×ª·¢Ñ°Â·ºó£¬ÓÉÖÇÄÜѡ·¾ö²ß£¨¸ù¾ÝÏß·QOSºÍÏß·ÖÊÁ¿Çé¿ö£¬ÇҾ߱¸Ò»¶¨¶èÐÔ£©ºóÑ¡ÔñÒ»ÌõËíµÀGRE³ö¿ÚºÍ·ÓÉÏÂÒ»Ìø£¬ÓÉGRE½Ó¿ÚÇý¶¯¸ù¾ÝNHRP±íÏî·â×°Íâ²ãIP£¬ÔÙÈëת·¢½Úµã½øÐжþ´Îѡ·ºó×ßÎïÀí½Ó¿Ú·¢ËÍ£¨Èç¹ûijËíµÀÒÑÆôÓð²È«±£»¤£¬ÔòÓÉIPSEC½øÐÐ͸Ã÷¼ÓÃÜ´¦Àíºó·¢ËÍ£©£»2£©WAN²àͨ¹ýÎïÀí¿Ú½ÓÊÕOverlay±¾»ú±¨ÎÄ£¬Ê×ÏÈ¿ÉÄܾ­IPSECÕýÈ·½âÃÜ´¦ÀíºóÔÙ½»GRE½Ó¿Ú´¦Àí°þ³öÄÚ²ãË½ÍøÊý¾Ý£¬µ¥²¥×é²¥Êý¾Ý¶¼¾­×ª·¢¾ö²ßºóͨ¹ýLAN²àÎïÀí¿Ú·¢³ö¡£Õû¸ö±¨ÎÄ´¦Àí¹ý³Ì£¬°üÀ¨ARPѧϰ¡¢QOSÓ¦ÓÃÓëUnderlay´¦ÀíÏàͬ¡£

QOSÓ¦ÓÿÉÒÔÔÚËíµÀ¿ÚÕë¶ÔOverlay²ãÁ÷Á¿£¬Í¬Ê±Õë¶ÔÎïÀí³ö¿ÚÈÔÈ»ÐèÒªÓ¦ÓÃQOS£¬ÌرðÊÇÎïÀí¿Úͬʱ³ÐÔØÉÏÍøÁ÷Á¿Ê±£»ÖÇÄÜѡ·ÒÀÀµÓÚÏß·ÖÊÁ¿Çé¿ö£¬µ«Í¬Ê±ÐèÒª½áºÏÏß·Éϸ÷ÒµÎñµÄQOSÐèÇó£¬ÁíÍâÖÇÄÜѡ·¿ÉÄÜÐèҪ˫Ïòͬ²½£¬¹Ê¶øÑ¡Â·±ê¼Ç¿ÉÄÜͨ¹ýÁ÷ͬ²½µ½¶Ô¶Ë¡£

ʵ¼ÊÎïÀí½Ó¿ÚÔÚͬһ̨CPEÉÏ¿ÉÒÔÊǶà¸ö»òÕ߸´ÓÃÒ»¸ö£¬°üÀ¨LAN²àºÍWAN²à¡£

2.5.5ÒìµØ·ÃÎÊInternet

ÒìµØ·ÃÎÊInternet = ÒìµØË½Íø»¥Í¨+±¾µØ·ÃÎÊInternet

ijЩ×éÍø¿ÉÄܲÉÓÃÄÚÖÃFW·½Ê½£¬´ËʱHUB/SPOKE½«¶Ô³ö¿ÚInternetÁ÷Á¿½øÐÐNAT£¬¹Ê¶øNATÐèÒªÔÚInternet³ö¿Ú¶ÔË½ÍøÍø¶ÎÉúЧ¡£

2.5.6ÒìµØTRAP±¨ÎÄ

ÒìµØTRAP±¨ÎÄÖ÷ÒªÌåÏÖÔÚCPE¿ØÖÆÐ­ÒéÖ®¼äµÄͨÐÅ£¬ÈçÉÏÊöOSPFЭÒé¡£Á÷³ÌÓëÒìµØË½Íø»¥Í¨»ù±¾Ïàͬ£¬½ö½«Á½µØLAN²à½Ó¿Ú¼äµÄͨÐű任ΪÁ½²àЭÒéÕ»Ö®¼äµÄͨÐÅ¡£

2.6¿É¿¿ÐÔÄ£ÐÍ

2.6.1 LAN²à

2.6.1.1 VRRPÖ÷±¸

ÓÉVRRPͨ¹ýÐéÄâÍø¹Ø½«Ë«CPEÉ豸³éÏóΪһ̨É豸£¨Ò»Ö÷Ò»±¸£©£¬LAN²àÍøÂçÅäÖþ²Ì¬Íø¹ØÖ¸ÏòVRRPÍø¹Ø¼´¿É£¬Ï¹Ҷà¸ö×ÓÍøÊ±CPEÐèÒªÖ§³Ö×Ó½Ó¿Ú¡£

2.6.1.2 ·ÓÉÖ÷±¸

LAN²àÍø¹ØÓÉCPE±äΪֱÁ¬Â·ÓÉÆ÷£¨»òL3½»»»»ú£©£¬Â·ÓÉÆ÷ÓëË«CPE¼äÆôÓÃIGP·ÓÉЭÒ飬ÓÉ·ÓÉЭÒé×Ô¶¯ÐγÉÖ÷±¸Ïß·¡£

2.6.1.3 VRRPË«¹é

L3²ãÃæÓë¡¶VRRPÖ÷±¸¡·ÏàËÆ£¬ÔÚL2²ãÃæ£¬ÓÉL2 SWÅäÖÃPort Agg¶ÔÁ÷Á¿½øÐиºÔØ£¬CPE1,CPE2,L2 SWÖ®¼äËùÊôͬһ¸öÍø¶Î²¢ÅäÖÃSTP·À»·£¬Á÷Á¿¿ÉÒÔ¾­CPE2¹ýL2ת·¢µ½CPE1£¨Ö÷Íø¹Ø£©£¬¶ÔLAN²àÐγÉL3Ö÷±¸¿É¿¿ÐÔµÄͬʱÔö¼ÓL2Ïß·µÄ¸ºÔؿɿ¿ÐÔ¡£

2.6.1.4 ·ÓÉË«¹é

Ó롶·ÓÉÖ÷±¸¡·×éÍøÏàËÆ£¬²»Í¬ÔÚÓÚRouter½«À´×ÔCPE1ºÍCPE2µÄ·ÓÉÐγɸºÔØ£¬²¢ÇÒCPE1ÓëCPE2»¥Ïàͨ¸æÂ·ÓÉ¡£´ËÖÖ×éÍø³ýLAN²à¸ºÔØÉÏÐÐÍ⣬ͬʱ¶ÔWAN²àOverlayÏß·ÐγÉÖ÷±¸±£»¤£¬ÈçCPE2ÉÏÐÐWAN²à·ÓɶϿª£¬¿É×ÔÖ÷Çл»Â·Óɵ½CPE1¡£

2.6.2 WAN²à

2.6.2.1 SPOKEÖ÷±¸Ë«ÏßË«ËíµÀ

Á½Ì¨CPE·Ö±ðË«Ïß½ÓÈëÔËÓªÉÌ£¬¸÷×Ô·Ö±ðͨ¹ýÁ½¸öÔËÓªÉÌÓëHUB½¨Á¢ËíµÀ¡£WAN²àͬʱÆôÓ÷ÓÉЭÒéÓëHUB½¨Á¬£¬Èç¹ûLAN²àÖ÷±¸£¬ÔòWAN²àHUBÒ²»áÓÅÑ¡ÆäÖÐÒ»¸öCPE×÷ΪÖ÷Ïß·£»Èç¹ûLAN²à¸ºÔØ£¬ÔòWAN²àHUBÈÔÈ»¿ÉÒÔÐγÉËÄÏ߸ºÔØ£»Á÷Á¿¶Ô³ÆÐÔÎÊÌâÓÉÖÇÄÜѡ·¹æ»®¡£

2.6.2.2 SPOKEÖ÷±¸µ¥ÏßË«ËíµÀ

Underlay£ºÁ½Ì¨CPE¸÷×Ôµ¥ÏßÈ벻ͬÔËÓªÉÌ£¬HUBË«Ïß½ÓÈëÔËÓªÉÌ¡£Overlay£ºÁ½Ì¨CPE·Ö±ðÓëHUB½¨Á¢Á½ÌõËíµÀ£¬¹Ê¶øÁ½Ì¨CPE»¥ÎªWAN²àÍø¹Ø£¬ÒªÇóCPE»¥Ïà´òͨ¸÷×ÔÔËÓªÉÌ·ÓÉ£¬²¢ÒªÇóËíµÀÖ§³Ö´´½¨Í¬Ô´(IP)Ë«ËíµÀ¡£

Ë«ËíµÀģʽÏ£¬Ò»ÌõÊÇʹÓÃCPE±¾µØÔËÓªÉÌÁ¬½Ó£¬ÁíÒ»ÌõʹÓöԶËCPEÔËÓªÉÌÏß·£¬¹Ê¶ø¶Ô¶ËCPE½ö×÷ΪÁíÒ»¸öÔËÓªÉ̵ijö¿ÚÍø¹Ø£¬¹Ê¶øÐèÒª×öNAT¡£

2.6.2.3 HUB¸ºÔØË«ËíµÀ

HUB Ë«CPEË«ÏßÈëÍø£¬SPOKEµ¥CPEË«ÏßÈëÍø²¢Í¬Ê±ÓëHUBË«CPE½¨Á¢¸÷×Ô½¨Á¢Á½ÌõËíµÀ¡£ÓÉÓÚ·ÓÉЭÒé¿É¿ØÖÆÔÚCPEÐγÉËÄÌõ¸ºÔØ£¬µ«¿¼ÂÇʵ¼Ê×éÍøÐèÒª£¬Ò»°ãHUBË«CPEÐγÉÖ÷±¸¼´¿É¡£

2.6.2.4 HUB¸ºÔص¥ËíµÀ

HUBË«CPE¸÷×Ôµ¥Ïß½ÓÈ벻ͬÔËÓªÉÌ£»SPOKEµ¥CPEË«Ïß½ÓÈ룬·Ö±ðͨ¹ý²»Í¬ÔËÓªÉÌÓ벻ͬHUB CPE½¨Á¢ËíµÀ£»HUB CPE¼ä¿É´òͨ·ÓÉΪÂú×ãËùÓнÓÈ벻ͬÔËÓªÉ̵ÄSPOKE CPEÖ®¼äµÄͨÐÅ£¬Í¬Ê±Ò²ÎªHUB LANÌṩ˫Á´Â·±¸·Ý¡£

3È«¾Ö½¥½øÊÓͼ

3.1´´½¨Õ¾µã

Õ¾µã´´½¨ÎªÔ¤¿ªÆôÕ¾µãÔ¶³Ì´´½¨ÅäÖÃÄ£°å£¬²¢½«Ä£°å¼ÓÃÜÉÏ´«ÖÁ¿ª¾ÖUÅÌÖУ¬Ö§³ÖÅúÁ¿¿ª¾Ö¡£

Ê×ÏÈÓÉÍøÂç¹ÜÀíԱΪָ¶¨°ìÊ´¦»ò·ÖÖ§»ú¹¹´´½¨ÈëÍøÅäÖ㬳õʼÅäÖÃÄ¿µØÓÃÓÚ´òͨWAN²àÍøÂ磬²¢½ÓÈëLAN²àÍøÂç¡£

È»ºóÓÉÍøÂç¹ÜÀíԱΪ·ÖÖ§Õ¾µãÉèÖõڶþ½×¶ÎÅäÖã¬Ê¹SPOKE³É¹¦ÈëOverlayÍøÂ磺

±¸×¢£ºÎª±£Ö¤ÅäÖõÄÕýÈ·ÐÔ£¬ÍøÂç¹ÜÀíÔ±ÐèÒªÔÚ²âÊÔÍøÂç»òÐéÄâÍøÂçÖвâÊÔÑéÖ¤ºóµ¼³öÅäÖÃÄ£°åµ½UÅÌ»òÍø¹ÜÅäÖÃÊý¾Ý¿â¡£

3.2 UÅÌ¿ª¾Ö

¹¤³Ì×°±¸ÈËÔ±ÔÚ²¿ÊðÉ豸»ò²¼ÏßÍê³Éºó£¬²åÈëZTP¿ª¾ÖUÅÌ£¬É豸×Ô¶¯Ê¶±ðUÅ̲¢³¢ÊÔ¼ÓÔØÆäÄڵĺϷ¨ÅäÖã¬Ö÷Òª°üÀ¨»ñµÃWAN¿ÚIP»ò·ÓÉÀ´Á¬½ÓÍøÂ磬²¢µÇÂ¼Íø¹ÜʵÏÖÕ¾µãÉ豸ÈÏÖ¤¡£

3.3½ÓÈë¹Ü¿Ø

CPE¼ÓÔØUÅÌÅäÖúó³É¹¦½ÓÈ뻥ÁªÍø£¬²¢³¢ÊÔ½ÓÈëÍø¹Ü·þÎñȺ£¬ÉêÇë¼ÓÈëOverlayÍøÂç¡£CPEЯ´øÊÚȨ֤ÊéÏòÖ÷Íø¹Ü·¢ËÍÉêÇ룬Èç¹ûÖ÷Íø¹ÜδÏìÓ¦£¬ÔòÇл»µ½±¸Íø¹Ü£»Íø¹Ü¶ÔÊÚȨ֤Êé½øÐÐÓÐЧÐÔ¼ì²é£¬²¢Í¬Ê±¼ì²éÈëÍø²ßÂÔ£¨ÔÊÐí¡¢ÑÓÆÚ¡¢½ûÖ¹µÈ£©ºó·´À¡¸øCPE£¬CPEÊÕµ½ÓÐЧÊÚȨºóÆôÓÃ×ÊÔ´¼°×é¼þ¡£

3.4»ñÈ¡ÅäÖÃ

CPEÈëÍø³É¹¦²¢¾ÍÐ÷ºóÍø¹Ü½«ÏòCPEÏ·¢ÆäÔ¤ÖÃÅäÖ㬰üÀ¨GRE½Ó¿ÚÅäÖá¢NHRPÅäÖá¢Â·ÓÉЭÒéÅäÖã¨ÈçBGP£©¡¢×éÍø¼°×ª·¢Ä£Ê½¡¢Ó¦ÓÃת·¢²ßÂÔ¼°QOS¡¢NTPµÈ£¬Ê¹CPE³É¹¦½ÓÈëOverlayÍøÂç¡£

3.5 Underlay·ÓÉѧϰ

CPEÈç¹û²ÉÓÃÔËÓªÉÌ·ÖÅäµÄ¾²Ì¬IP·½Ê½ÈëÍø£¬ÔòÐèÒªÆôÓÃÓëÔËÓªÉÌÏàͬµÄ·ÓÉЭÒ齫´ËIP·ÓÉ·Ö·¢µ½ÔËÓªÉÌÍøÂ磬ÓÃÓÚCPEÈ«Çò×éÍø¡£²»Í¬ÔËÓªÉÌ¿ÉÄÜÆôÓò»Í¬µÄ·ÓÉЭÒ飬ͬʱ²»ÒªÇóCPE»¥µ¼ÔËÓªÉÌ·ÓÉ£¨½ö×÷ΪCE½ÓÈ룩£¬µ±CPEÔÚ·ÓÉÑ¡ÔñÉÏ£¬Òª±£Ö¤Â·ÓÉ×îÓÅ£¬Èç·ÃÎʵçÐŵÄIP£¬Ò»¶¨ÐèÒª´ÓµçÐŵÄÍøÂç³öÈ¥¡£

3.6 VPN½ÓÈëHUB

ÓÉÓÚËùÓÐCPEÅäÖÃÒÑͨ¹ýÍø¹ÜÏ·¢£¬ËùÒÔSPOKE½ÓÈëÖ¸¶¨HUB£¨Ò»¸öCPE»ò¶à¸öCPE£©µÄ·½Ê½²ÉÓá°¾²Ì¬VPN¡±¼´¿É£¬¼´¹Ì¶¨µÄHUB½ÓÈëµãÒÔ¼°VPNËíµÀÐÅÏ¢£¬µ«ÐèÒªÓÉNHRP RegisterÏòHUB×¢²á¼ÓÈëµ½mGREÓò£¬×¢²á±¨ÎÄͬʱͨ¹ý¶àÌõËíµÀ×¢²á£¬¶øInternet VPN½«Í¨¹ýIPSec½øÐмÓÃܱ£»¤¡£

3.7 Overlay·ÓÉѧϰ

ÔÚSPOKEºÍHUBÖ®¼äµÄ»ù´¡VPN½¨Á¢³É¹¦ºó£¨¼´¿ÉÒÔPingͨ¶Ô¶ËTUN¿ÚIP£©£¬°üÀ¨Â·ÓÉЭÒé¡¢NHRPЭÒéÔÚÄÚµÄËùÓÐOverlay²ã¿ØÖÆÐ­Òé¼´¿É¿ªÊ¼¹¤×÷¡£

·ÓÉЭÒ鸲¸Ç±¾µØË½ÍøÍø¶Î£¬½«Æäͨ¹ýËíµÀ¿ÚÁÚ¾Ó·¢Ë͵½OverlayÍøÂ磬ÓÉHUBѧϰ²¢×ª·¢µ½ÆäËüSPOKE¡£SPOKE¸ù¾Ýת·¢Ä£Ê½µÄ²»Í¬°²×°²»Í¬µÄÀàÐ͵Ä·ÓÉ£¬ÈçHUB-SPOKE×éÍø»òFull MeshµÄShutcutģʽ°²×°¾ÛºÏ·ÓÉ£¬Â·ÓÉÏÂÒ»Ìø½ÔÖ¸ÏòHUB; No ShutcutģʽÏ£¬ÓÉHUBͨ¸æSPOKE-SPOKEÃ÷ϸ·ÓÉ£¬Í¬Ê±½«Â·ÓɾۺϺóͨ¸æ¸øSPOKE£¬SPOKEÊÕµ½Â·Óɺóͬʱ½«Ã÷ϸ·Óɺ;ۺϰ²×°µ½×ª·¢²ã£¬¾ÙÀýÈçÏ£¨SPOKE1£©£º

172.168.1.3²éÕÒÒÀÀµ°´Â·ÓɹØÏµ»á¶¨Î»µ½192.168.1.0/24·ÓÉ£¬´Ëʱ»áÈÏΪ192.168.3.0/24ÓÐЧ¶ø±»°²×°µ½×ª·¢²ã£¬µ«Êµ¼ÊӦʱÓÉÓڵײã²ÉÓÃDVPN·½Ê½£¬´Ëʱת·¢ÊDz»ÕýÈ·µÄ£¬Ò»°ã¿Éͨ¹ýDVPN´´½¨³É¹¦ºó²ÉÓ÷´Ïò×¢Èë·ÓÉ·½Ê½ÐγÉ172.168.1.3µÄÖ÷»ú·ÓÉ¡£

3.8 ÒµÎñÁ÷Á¿

Óû§ÒµÎñÁ÷Á¿¾­LAN²à½Ó¿Ú½øÈëCPEʱ£¬CPE½ÇÉ«×÷Ϊһ¸öÈý²ãÍø¹Ø½«¸ù¾Ý·Óɾö¶¨Á÷Á¿·½Ïò£¬ÀàÐͰüÀ¨OverlayºÍUnderlay¡£OverlayÒÔËíµÀ½Ó¿ÚÐÎʽÌåÏÖ£¬Underlay×÷ÓÃÔÚ¾ßÌåµÄÎïÀí³ö¿Ú£¬ÈçÉÏͼËùʾ£¬Í¬ÖÖÀàÐ͵ijö¿Ú¿ÉÄÜ´æÔÚÒ»¸ö»ò¶à¸ö¡£

3.9 Ó¦ÓÃʶ±ð

Ó¦ÓÃʶ±ð×÷ÓÃÓÚWAN²à³ö¿ÚÁ÷Á¿£¬¼´¾­×ª·¢ºó³ö¿ÚΪËíµÀ¿Ú»òWAN¿Ú£¨±¾µØÉÏÍø£©£¬²»°üº¬Local Network»ò±¾»úÁ÷Á¿¡£

ʶ±ð³öÐèÒªDPIµÄÁ÷Á¿ºóͬ²½½»DPI×é¼þ½øÐÐÔ¤´¦Àí£¨¾²Ì¬·½Ê½£©£¬´ó¶àÊýÁ÷Á¿¿ÉÒÔͨ¹ýÔ¤´¦Àí·½Ê½½øÐÐʶ±ð£¬Ô¤´¦ÀíºóµÄÁ÷Á¿ÊµÊ±×ª·¢£»²¿·ÖÁ÷Á¿ÐèÒª½øÐиüÉîÈëDPI¾ö²ß£¬Á÷Á¿³õʼ¼¸¸ö±¨ÎĽ«ÁÙʱ·ÅÐУ¬Èç¹ûʶ±ð³¬Ê±½«ÖÐÖ¹²¢ÉÏ´«Á÷ÌØÕ÷£»Ê¶±ð½á¹û½«Í¬²½»òÒì²½¸üÐÂÁ÷²ßÂÔ±íÒÔÖ¸µ¼ºóÐø×ª·¢¡£

¸üÉîÈëµÄDPIʶ±ð¿ÉÄÜÐèҪ˫ÏòЭÖú£¬ÒÀÀµÓÚÒµÎñ¿ØÖÆÆ÷¼¯ÖÐÊÕ¼¯»ò·ÖÎö¡£µ«SD-WAN£¨ÆóÒµ²à£©ÖÐÁ÷Á¿Ò»°ã±È½ÏÃ÷È·£¬»ùÓÚ¾²Ì¬DPIµÄ·½Ê½»ù±¾ÄÜʶ±ðÈ«²¿Ó¦Óã»»ùÓÚÉÏÍøÐÐΪ¼ì²âºÍ¿ØÖƵÄDPIʵÏÖ¸ü¸´ÔÓ£¬ÊÇÒ»ÖÖеĽâ¾ö·½°¸¡£

3.10Ïß·¼ì²â

ÖÇÄÜѡ·ÌåÏÖÔÚOverlay²à£¬¹Ê¶øÏß·ÖÊÁ¿¼ì²âÐèÒª¶ÔËíµÀ»òËíµÀÍøÂç½øÐÐÖÊÁ¿Ì½²â¡£ÔÚÆóÒµSD-WANÖУ¬CPEͨ·ÎÞ·ÇÊÇHUBת·¢»òFULL MESHת·¢£¨¶þѡһ£©£¬¹Ê¶øÏß·¼ì²â½öÐèÒª¼ì²â¶ÎÄÚÖÊÁ¿Êý¾Ý£¬»ùÓÚHUBµÄÈ«ÍøÖÊÁ¿Êý¾ÝÐèÇó²¢²»Ã÷ÏÔ¡£

Ïß·¼ì²âÓÐÁ½ÖÖ·½Ê½£¬Ò»ÖÖÊÇ»ùÓÚPINGPONGµÄ»ØÂ·¼ì²â£¬Ò»ÖÖÊÇ»ùÓÚÖÐÐÄЭµ÷¼ì²â¡£Ç°ÕßÊôÓÚ×ÔÊÊÓ¦ÐÔ¼ì²â£¬Â³°ôÐÔºÜÇ¿£¬µ«¾«¶ÈÂԲºóÕßÊôÓÚ¼¯ÖÐͬ²½Ê½¼ì²â£¬¾«¶È¸ß£¬Â³°ôÐÔ²»×ã¡£

Ïß·¼ì²â¶ÔʵʱÐԺʹø¿íÌá³öÁËÌôÕ½£¬È·±£ÊµÏÖSD-WAN¡°ÌáËÙ½µ·Ñ¡±µÄÄ¿±ê¡£

3.11ÖÇÄÜѡ·¼°QOS

3.11.1¶à·¾¶Ñ¡Â·

ÔÚÆóÒµSD-WAN×éÍøÖУ¬ÎÒÃDzÉÓô¿IPÖðÌø×ª·¢£¨ÁíÍâÒ»ÖÖIPԴ·ÓÉ£¬ÊÊÓÃÓÚÔËÓªÉÌSD-WAN£©£¬¹Ê¶ø²ÉÓöÎÄÚÖÊÁ¿¼ì²â£¬ÖÇÄÜѡ·¾Í»ùÓڷֶεķ½Ê½£¬ÕâÖÖ·½Ê½ÍêÈ«¿ÉÒÔÂú×ãÆóÒµµÄ×éÍøÐèÇó¡£

ÔÚ¶à·¾¶Ï£¬Õë¶Ôµ±Ç°Ó¦ÓÃÁ÷Á¿µÄת·¢ÐèÇó£¬ÓÅѡһÌõ·ûºÏת·¢ÖÊÁ¿µÄ·¾¶¡£Í¬Ê±ÐèÒª±ÜÃâÁ÷Á¿ÖжϻòƵ·±Çл»£¬ÒÔ¼°¶ÔÆäËüÒµÎñµÄÓ°Ïì¡£

3.11.2Á÷Á¿Æ½»¬Çл»

¸ºÔØË«ÏßË«CPEÉÏÐÐʱÐèÒª¿¼ÂÇÁ÷Á¿Çл»ÊÇ·ñ»áÖжÏÏÖÓÐÒµÎñ£¬ÌرðÊǾ­¹ýÈô¸ÉNATÉ豸µÄÇé¿ö£¬²¿·ÖÒµÎñ¿ÉÄÜÐèҪ˫CPEµÄÈȱ¸¿¼ÂÇ¡£

3.11.3ͨµÀÈ«Á÷Á¿±£ÕÏ

Á÷Á¿Çл»ºó¶ÔÐÂͨµÀËù³ÐÔØÒµÎñµÄÓ°Ï죬ÕâÒ»²½Ó¦¸ÃÊÇÁ÷Á¿Çл»µÄÔ¤ÅÐÌõ¼þÖ®Ò»¡£Çл»ºóÐèÒªÅäºÏQOS¶ÔÐÂÒµÎñÁ÷Á¿µÄÖÊÁ¿±£ÕÏ£¬Í¬Ê±ÐèҪȷ±£ÆäËüÒµÎñÔÚÒ»¶¨µÄÖÊÁ¿¿É¿¿·¶Î§¡£Á÷Á¿»ØÇÐÈÔÈ»ÊÇͬÑùµÄ²ßÂÔ¡£

3.12Êý¾Ý°²È«

Ë½Íø°ì¹«Êý¾Ý¾­¹«Íø´«Êäʱ£¬ÎªÁË·ÃÖ¹±©Â¶ÄÚ²¿°ì¹«Ó¦Óã¬Í¬Ê±±£»¤Êý¾Ý°²È«ÐèÒª¶ÔË½ÍøÊý¾Ý½øÐмÓÃܱ£»¤¡£³£ÓõÄÓÐSSL/TLSºÍIPSec£¬¶ø¶ÔÆóÒµÀ´Ëµ£¬Ê¹Óð²È«¼¶±ð×î¸ßµÄIPSecÊôÓÚ×î¼ÑÑ¡Ôñ¡£

ÒµÎñÁ÷Á¿¾­×ª·¢¹ýMGREËíµÀºó£¬ÓÉIPSecÕë¶Ô·¢ÍùInternetµÄÁ÷Á¿½øÐÐ͸Ã÷¼ÓÃܱ£»¤£¬¹Ê¶øÔÚ´«Êäʱ³ö¿ÚMTUÐèÒª½«¼ÓÃܺóµÄÊý¾Ý³¤¶È¿¼ÂǽøÈ¥¡£¶øÕë¶Ô·ÇInternetÁ÷Á¿£¬ÈçMPLSË½ÍøÒѱ£Ö¤ÁË×â»§ÐÅÏ¢µÄ¸ôÀëºÍ°²È«£¬Ò»°ã²»ÐèÒª¿ªÆô¼ÓÃܱ£»¤¡£

3.13 NAT´©Ô½

ÕâÀïµÄNAT´©Ô½ÊÇSPOKEºÍHUBÖ®¼äͨ¹ýNATÉ豸µÄͨÐÅ£¬²»°üÀ¨SPOKEºÍSPOKEË«·½¶¼ÔÚNATÖ®ºóµÄ´ò¶´³¡¾°¡£

¶ÔÓÚ´ó¶àÊý¿ØÖÆÐ­Ò飬¶¼ÐèҪά³Ö¡°»á»°¡±¹ØÏµ£¬¹Ê¶øÍ¨ÐÅÊÇË«ÏòËæ»úµÄ£¬ÕâÖÖÐèÇóʹ˫·½¶¼ÐèÒª»ñÈ¡GIP¡£¶øÊý¾ÝÔÚ´©Ô½NATÖ®ºó£¬Ô´IP»òÔ´PORT½«·¢Éú¸Ä±ä£¬µ¥´¿ÒÀÀµÆÕͨͨÐÅÍ·²¿À´½øÐд«ÊäµÄ¿ØÖÆÐ­Ò齫ʧЧ£¬Èç¹ûÒªÖ§³ÖNAT´©Ô½£¬Ð­ÒéÐèҪͬ²½Ö§³ÖNAT¼ì²âºÍNAT´©Í¸¡£

´©Ô½NATÒ»°ã½»¸ø×îÍâ²ãʵʩ£¬SD-WANÔÚInternet´«Êäʱ¿ªÆôIPSEC¼ÓÃܱ£»¤£¬¹Ê×îÍâ²ãΪIPSEC£¬ÓÉIPSEC¿ªÆôNAT-T¼´¿ÉʵÏÖNAT´©Ô½£»¿ØÖƲãÃæ£¬ÅäÖÃЭÒéNetConfÌìÉúÖ§³ÖNAT£¬Ò²ÄÜÂú×ã´ËÐèÇ󣻯äËü˽ÓÐЭÒéÈç¹ûÐèÒª´©Ô½NAT£¬ÔòÒ»°ãͨ¹ýÔÚÍ·²¿ÖÐÔö¼ÓUDPÍ·²¿À´ÊµÏÖ¡£

MPLSË½ÍøÖв»´æÔÚNATÉ豸£¬¹Ê¶ø²»ÐèÒªÖ§³ÖNAT´©Ô½¡£ÌØÊâµÄ£¬¶ÔÓÚʹÓÃMPLSÉϷõij¡¾°ÔòÐèÒª¿¼ÂÇ¡£

3.14¿ÉÊÓÔËά

¿ÉÊÓÒªÇó½«OverlayÍøÂçµÄ¹¤×÷Çé¿öת»»ÎªÓû§¿É¼ûµÄ¹¤×÷״̬£¬²¢ÇÒÂú×ãÓû§Êӽǡ£ÈçÏß·״̬-°üÀ¨Ïß·ÖÊÁ¿Êý¾Ý¡¢Á÷Á¿Êý¾Ý¡¢Óµ¼·Çé¿ö£»É豸״̬-°üÀ¨É豸IOʹÓÃÂÊ¡¢ÄÚ´æÊ¹ÓÃÂÊ¡¢CPUʹÓÃÂʵȣ»Ó¦ÓÃ״̬-°üÀ¨Ó¦ÓÃÖÖÀà¡¢Ó¦Ó÷ֲ¼µÈ¡£³ý¿ÉÊӿɲéµÄÐèÇóÍ⣬ÔÚ´Ë»ù´¡ÉÏÒªÇóµÄ¡°Ëù¼û¼´ËùµÃ¡±£¬ÈçÕë¶ÔijOverlayÏß·µ÷Õû´ø¿í»òCost¡¢¹Ø±ÕijÌõÏß·¡¢À©ÈÝij¸öCPEµÈ£¬ÔÚÈ«¾Ö¿ÉÊÓµØÍ¼ÉÏÐèҪʵʱ»ã×ÜÕâЩÇé¿ö£¬²¢¿ÉÒÔÔÚÆäÉϽøÐпÉÊÓ»¯²Ù×÷¡£

3.15Èí¼þ¶¨ÒåÍøÂç

Èí¼þ¶¨ÒåÌåÏÖÔڿɱà³ÌÐÔ£¬¾ßÌå°üÀ¨£º¿ÉÀ©Õ¹ÐÔ¡¢ÒײٿØÐÔ¡¢¿ÉÊÓÐÔ£¬SD-WAN×éÍøÔÚÂú×ã´«Êä×éÍøÖ®ÉÏÐèҪʵÏÖµÄÈí¼þ×Ô¶¨Ò岿·Ö£¬Èí¼þ×Ô¶¨Òå±íÏÖÔÚÓû§×Ô¶¨ÒåÉÏ¡£ÈçÓû§¿ÉÒÔËæÊ±Õë¶ÔÓ¦ÓÃÁ÷Á¿Â·¾¶½øÐй滮»òµ÷ÓÅ£¬Ä³É豸ѹÁ¦¶à´óʱµÄ¶¯Ì¬À©Èݼ°×ÊÔ´ÖØ·ÖÅ䣬É豸ÔÚÏßÈÈÉý¼¶¡¢»¹ÓаüÀ¨ÉÏÊö¿ÉÊÓÔËάµÄ²¿·Ö¡£

SD-WANÊÇSDNµÄ×Ó¼¯£¬µ«ÓëSDN²»ÍêÈ«Ïàͬ£¬¿ÉÒÔ˵ÆäÊÇÒ»¸ö»ìѪ¶ù£¬°üÀ¨´«Í³×éÍøºÍSDN×éÍøµÄÓŵ㣬²¢°ÑÕâЩÓŵ㼯ÖÐÀ´½â¾öWAN´«ÊäµÄÎÊÌâ¡£

4.ÆäËü

SD-WAN¼¼ÊõÏÖÔÚ¸÷¸ö³§ÉÌʵÏֱȽϷÖÉ¢£¬»¹Î´³öÏÖһͳ½­ºþµÄRFCÎݸ£¬µ«¾Ý˵SD-WAN RFC²Ý°¸ÒÑÌá³ö£¬×ݹ۸÷³§ÉÌ·½°¸£¬¸öÈ˾õµÃ£¬H3CµÄAD-WAN·½°¸±È»ªÎªµÄSD-WAN·½°¸¸ü½øÒ»²½£¬ÊǺóÐøSD-WANµÄ¼¼ÊõÇ÷ÊÆ¡£

SD-WAN×îÎü½ðµÄµØ·½»¹ÊÇÌåÏÖÔÚÔËÓªÉ̲࣬ÆóÒµ²àÔòÌåÏÖÔÚÉÙÊýÕþÆóÐÐÒµ¡£SD-WAN×î´óµÄÓ¦ÓÃÊг¡¼¯ÖÐÔÚÖйú£¬ÊÇʵÏÖ¡°¶à¿ìºÃÊ¡¡±¡°ÌáËÙ½µ·Ñ¡±µÄ¼¼ÊõÊֶΡ£

   
3506 ´Îä¯ÀÀ       27
????

HTTP????
nginx??????
SD-WAN???
5G?????
 
????

??????????
IPv6???????
??????????
???????
????

????????
????????
???????????????
??????????
×îл¼Æ»®
DeepSeekÔÚÈí¼þ²âÊÔÓ¦ÓÃʵ¼ù 4-12[ÔÚÏß]
DeepSeek´óÄ£ÐÍÓ¦Óÿª·¢Êµ¼ù 4-19[ÔÚÏß]
UAF¼Ü¹¹ÌåϵÓëʵ¼ù 4-11[±±¾©]
AIÖÇÄÜ»¯Èí¼þ²âÊÔ·½·¨Óëʵ¼ù 5-23[ÉϺ£]
»ùÓÚ UML ºÍEA½øÐзÖÎöÉè¼Æ 4-26[±±¾©]
ÒµÎñ¼Ü¹¹Éè¼ÆÓ뽨ģ 4-18[±±¾©]
 
×îÐÂÎÄÕÂ
ÔÆÔ­Éú¼Ü¹¹¸ÅÊö
K8S¸ß¿ÉÓü¯Èº¼Ü¹¹ÊµÏÖ
ÈÝÆ÷ÔÆ¹ÜÀíÖ®K8S¼¯Èº¸ÅÊö
k8s-ÕûÌå¸ÅÊöºÍ¼Ü¹¹
Ê®·ÖÖÓѧ»áÓÃdocker²¿Êð΢·þÎñ
×îпγÌ
ÔÆ¼ÆË㡢΢·þÎñÓë·Ö²¼Ê½¼Ü¹¹
Æóҵ˽ÓÐÔÆÔ­ÀíÓë¹¹½¨
»ùÓÚKubernetesµÄDevOpsʵ¼ù
ÔÆÆ½Ì¨¼Ü¹¹ÓëÓ¦Ó㨰¢ÀïÔÆ£©
Docker²¿Êð±»²âϵͳÓë×Ô¶¯»¯¿ò¼Üʵ¼ù
³É¹¦°¸Àý
±±¾© ÔÆÆ½Ì¨Óë΢·þÎñ¼Ü¹¹Éè¼Æ
ͨÓù«Ë¾GE DockerÔ­ÀíÓëʵ¼ùÅàѵ
ij¾ü¹¤Ñо¿µ¥Î» MDA£¨Ä£ÐÍÇý¶¯¼Ü¹¹£©
ÖªÃûÏû·Ñ½ðÈÚ¹«Ë¾ ÁìÓòÇý¶¯Éè¼Æ
ÉîÛÚijÆû³µÆóÒµ Ä£ÐÍÇý¶¯µÄ·ÖÎöÉè¼Æ