In recent years, the Core IP address and network market have undergone many changes. We are constantly seeing more and more new technologies, such as VoIP and wireless networks for on-demand applications. These new applications and services will change the way you do business. At least this is the direction that many companies and providers are currently working on. With the new growth in these new markets, people focus more on the concept of intelligence, rather than simply focusing on more bandwidth. Engineers and Architects are looking for new ways to merge multiple services into a shared backbone network. This leads to the topic of this article: A general technology that isolates customers from shared infrastructure and devices.
Where did you start?
When every new "greatest" technology is introduced, CIOs and business people will find a reason to change the face and focus of their business through this new technology. It is very important to realize this. As usual, engineers and architects need to find ways to make this technology work, while reducing the impact on initial investment. This means to integrate these new technologies into existing infrastructure without increasing costs and unnecessary lines. Temporarily put our service integration tasks aside. Let's focus on a common task first. This task is the foundation for a bigger and better future: isolation.
Assumptions
Assume that you are a service provider with only two customers. Depending on the size of your company, you choose to pay only for one physical Internet connection (through another provider ). Your customers must share the connection.
Customer A and Customer B have chosen OSPF (Open Shortest Path First) to exchange routing information with your vro. This will allow all routers on the Internet to know the network of each of your customers. However, if you use OSPF for two customers, can they see each other's route or anything in the other's network? Oh, you may see that if you don't choose to isolate them.
Therefore, as a service provider, how do you isolate the sensitive information of customers?
Virtual routing and forwarding
A vro and a forwarding instance are all logical routers. A virtual route and forwarding includes an IP route table, a sending table, a set of interfaces using the sending table, and a set of rules and routing protocols for determining the content of the sending table.
The most small service provider, you can use this "logical Router" to completely isolate Customer A and Customer B. You can also simplify the management and troubleshooting of various customers and improve performance in the future. In this case, the Service Provider Router uses different OSPF instances for each customer. Here I am referring to the edge router of the service provider. The following figure shows the situation.
This solves the first phase of isolation. It is very easy to connect two physical interfaces to each customer. It is difficult to isolate Customer A from customer B on the link connecting to the Internet. In my next technical guide, I will introduce you to how to set this situation and provide you with alternative methods to handle this internet connection.