Today, we will reveal the differences between the internal functions of a vswitch. We do not know much about the internal functions of a vswitch. This article will give a detailed introduction to the internal functions of vswitches. When you select a vswitch, you can view its function list. However, putting the internal function lists of vswitches of different brands together is like a bunch of identical triplets, which look exactly the same. In fact, those are external ones. If you understand their internal structure, you will find that there is actually a lot of difference.
When testing the security product, colleagues want to mirror the traffic of the two vswitch ports, but the internal function of the vswitch can only mirror one port at the same time. In the "Support Port image" column of the function list, this switch is filled with "support ".
I used Spanning Tree Load Balancing for the user group network. When I got the internal function of another switch, its "Weapon spectrum" also indicated that Multiple Spanning Tree groups are supported. It was later found that although many spanning trees can be created, Trunk ports carrying multiple VLAN information can only be placed in one spanning tree. What can be done with the Spanning Tree is redundancy.
Currently, none of the common layer-3 switches raise their hands and say "I don't support VRRP ". However, some can only put the ports related to the internal functions of the two switches in the same VLAN, because VRRP packets are broadcast packets. Some support non-VLAN redundancy. VRRP information can be transmitted between two routing ports. The former provides fewer options, but it is not reflected in the menu.
If the switch says it is helpless against DoS attacks, the current situation is that it has to break down in the warehouse. So how much does a "security switch" provide for security? Some switch functions discard the stream forwarding mechanism, which makes a variety of DoS attacks not worth mentioning, but its hardware costs also increase.
Some switches receive traffic from a valid address through the ACL, and all others are lost. This method sounds like it will affect the flexibility of the network, and it is troublesome to configure. Compared with the previous "Security Switch", it is simply another extreme. Some other internal functions of the switch can speed up certain traffic, perform Reverse Address Resolution, limit the number of MAC addresses learned from a port, and set the threshold for scanning certain IP network segments, the manufacturer has paid a lot of attention.
In addition, you certainly do not like the "Security Switch" that does not allow you to view CPU utilization or send email alerts ". Therefore, the word "security" should be carefully identified by the user. Some users buy a vendor's network solution to view the company's network management. Someone who buys a layer-3 Switch also enjoys its Web management interface. They can see the internal function panel of the switch and perform common operations on the panel. This method is often based on Java. Different vendors have different practices, and some are not suitable for use during peak network hours.
No layer-3 switch is willing to admit that it does not support "QoS". This is also true and is supported by everyone. However, the intensity is different. However, this difference may make your QoS plan messy. The fewer queues are supported, the more rough the difference between QoS implementation. The fewer queuing algorithms, the more QoS scenarios are supported. When "DiffServ is supported" is shown in the table, you need to take a closer look.
The price of machines that have done well in all projects is generally superior. When selecting a vswitch, it is best to meet the current requirements and adapt to the future. However, I think we should abandon what we don't need. I think IPv6 and BGP are ignored. In a small network, OSPF seems redundant. QoS may not be required too much. If you have a video conference, it is a common practice to set port speed limits for multicast sources to ensure bandwidth.
Although this configuration will cause idle bandwidth when the multicast source is "Resting", after all, this reduces the requirements for the internal functions of the switch and the network may not be affected. It is not recommended that you buy the most "thin" or "strong" Switch internal functions, but want to tell you, when everyone faces look like, think about what you want to pay attention, you don't have to pay for the unused features, but you want to buy the part to see if it gets a discount.