In general, enterprise network devices need to be changed and upgraded within three to five years. Among the many reasons for replacement, the equipment is still outdated, and the main reason is that it cannot adapt to the development of network applications. Similarly, the trend of changing a non-Network-managed switch (also known as a "silly" Switch) of network edge devices to a smart switch is becoming more and more obvious.
What is "intelligence"
At present, the industry does not have an accurate definition of edge smart switches, but many industry experts believe that the characteristics of edge smart switches will be determined by network applications. Network applications can be classified into three types: data, voice, and video. Therefore, edge switches must be stable, secure, and versatile, at the same time, the ease of use of network devices cannot be ignored.
Hybrid transmission of data streams, voice streams, and video streams has a great impact on Network stability, and these applications are initiated on the edge of the network, therefore, the switch must be able to differentiate different business flows and assign different bandwidth based on different priorities. As a result, the smart switches launched by many manufacturers support VLAN division, 802.1 p (mandatory priority), CAR (traffic monitoring) and other service policies.
At present, the network is facing various security threats, and these security threats are characteristic of mixed attacks. Edge switches must be able to effectively prevent malicious attacks and illegal intrusion. MAC address authentication and 802.1x authentication can help users complete necessary identity authentication when accessing the network to effectively prevent unauthorized users from accessing the network. The ACL access control capability depends entirely on the stream classification capability, therefore, it is required that the edge smart switch can be based on the user's source MAC, destination MAC, source physical port number, destination physical port number, source IP address, destination IP address, source CIDR block address, destination CIDR block address, and layer-4 protocol. type (socket) data businesses are classified by user-defined rules, and different service quality or ACL control are provided for different business flows based on these classifications, that is, forwarding of a specific stream is prohibited or allowed.
Network applications such as voice and video, as well as a wide range of Wireless LAN devices require the versatility of edge switches. The new edge switch product launched by the manufacturer integrates the hardware Voice Gateway, mpls vpn and other services, and supports the PoE function, so that users can deploy IP communication and Wireless AP devices.
Small and medium-sized enterprises account for a large proportion of edge switch users. The particularity of the network requirements of small and medium-sized enterprises determines that the "intelligence" of edge switches should also be reflected in the ease of management and use. This is also the case. Some industry experts believe that smart edge switches, in terms of technical features, will surpass the network-managed switches in some ways. Liang zhengbo, manager of yihailante Technology Department, has a certain representativeness. "edge smart switches are actually based on the original manageable switch technology, and their internal software technologies are more functional, vswitches that are more suitable for applications."
When to become mainstream
The living space of a smart switch is that most users only use 20% of all functions when using a fully-managed switch, and almost never use other functions, this results in users spending money to purchase unnecessary functions. The functions of non-network management switches are too simple to meet users' common needs, such as remote network management SNMP and VLAN division.
With the continuous development of broadband networks, broadband services, and multimedia applications, edge smart switches will replace the "silly" switch to ensure support for key services and achieve end-to-end service quality, it will become the development trend of the network in the future.
Compared with the "silly" Switch Equipment, the advantages of Security and maintenance costs, the application of smart switches to network edge will undoubtedly be welcomed by users. However, in the current situation, channel partners and most vendors believe that smart switches cannot become the mainstream of edge network devices.
Liang zhengbo believes: "In the long term, edge smart switches can replace the 'dump' switch, but it is not possible at present, mainly because the price gap between smart switches and non-NMS switches is large. According to the development trend, smart switches may seize the existing market of most silly switches in two years ."
Huawei 3Com believes that, when deploying edge smart switches, edge products are distributed in a large quantity. Therefore, users need to consider obtaining an optimal balance between the overall and distributed policies. Edge smart switches have incomparable advantages in various services, especially smart management services. However, for enterprise networks, the key lies in how to build an integrated unified strategy for security, reliability, management, scalability, and data forwarding performance through edge devices, which is crucial to the overall network performance and maintenance. We believe that in the future, edge smart switches will coexist with traditional L2 switches, regardless of business needs or user investment protection, users should pay attention to how to build an "ELASTIC" intelligent network to ensure the reliable operation of enterprise services.
"Currently, edge smart switches and non-NMS switches have relatively small coincidence ranges in the target market," said Yang zijiang, CTO of NETGEAR. "It will not quickly replace the traditional 'dump' switch. Currently, edge smart switch market space is part of the traditional fully-managed switch, because these users do not need so many complex functions ."
According to the information disclosed by ruijie, its edge smart switch has been delivered more than a "dumb" switch and has become the main sales product of the access layer switch. The main reason is that the user's application model has changed, so the demand is also changing, the network is no longer quiet, and a large number of viruses, security attacks, and a large number of devices are not managed in a unified and effective manner, video and voice data packets are increasingly used in daily data exchanges. The common "Dummies" switch is only responsible for data forwarding and cannot provide protection for such increasingly complex networks. Moreover, the price of the edge smart switch is gradually approaching the "dumb" switch. Therefore, in the future, it will soon come to replace the "dumb" switch.
Annett: intelligent exchange is spreading towards the network edge
Annett believes that with the rapid development of the network, the need for intelligent Exchange began to spread from the core to the edge. Edge smart switches should have comprehensive security policies, multi-layer intelligent control, and ease of management. In this way, they can eliminate unstable factors such as attacks at the bottom of the network, on the other hand, it can reduce the workload of aggregation and even core switches and ensure fast data exchange.
Annett's edge smart switch represents the AT-8500 series. Its main selling points include comprehensive security control to the edge, supporting management security such as Radius/TACACS +, SSH, SSL, and SNMPv3; built-in six most common DoS attack defense, port bandwidth control, broadcast storm control, support 802.1x, L2-L4ACL, port security; L2-L7 hardware stream classification, supports flexible classification based on VLAN, ToS, 802.1 p, TCP flags, and IP protocols, supports traffic speed limiting based on data streams, stack management, DC power supply, and POE and redundant power supply; 802.1s helps achieve more effective multi-Vlan link redundancy.
It is expected that in the future, edge switches will become more and more intelligent, including providing simple routing and other functions, integrates features such as service quality, access control, policy routing, dynamic VLAN, and security control to implement an end-to-end smart network, in this way, the entire network not only has global connection capabilities, but also has global network intelligence. The bandwidth will also be extended from the current mainstream MB access to gigabit, and the extended switching performance can transmit high-quality sound, video, and data files at high speed at the edge layer, it provides conditions for various flexible network applications.
Cisco: Smart will simplify the network division
Cisco product manager Zhang dongwei said: In the past, small and medium-sized enterprises used to purchase switches without any configuration. However, as enterprise network applications keep growing, such enterprise users need to set network devices, and perform regular maintenance. However, the staffing and capital allocation of these enterprises cannot be equipped with a professional network service team. Cisco's core solution for small and medium-sized enterprise network edge applications is the Catalyst Express 500 series switches. This series of switches features 3 S (Smart, Simple, and Secure.
CE500 has the following major advantages: based on standard high-performance LAN switching, CE500 uses Cisco's new technology in a platform customized for SMB, providing line rate switching and other standard features, for example, 802.1d Spanning Tree, 802.1x authentication, and 802.3ad link aggregation; supports IEEE 802.3af PoE standard, powered by IP phones, wireless access points, video surveillance cameras, and other new devices, this facilitates the launch of new network services. Smartports Advisor can automatically detect connected Cisco devices and provide suggestions on the preset configurations of switch ports connected to the devices, this feature simplifies network deployment, enables customers and partners to focus on high-tech deployment, and provides three optional security levels, enables customers and channel partners to quickly and conveniently deploy integrated security features to protect networks from unauthorized access; provides Cisco network assistant-a gui-based free management tool, supports configuration, management, and troubleshooting. It not only facilitates the management of switches, but also manages high-tech technologies such as IP communication and wireless.
D-Link: security should be at the top of smart features
Chen qiyan, general manager of D-Link product marketing department, believes that the security of smart switches on the network edge is extremely important for users. With a variety of security mechanisms, the D-Link smart switch provides more comprehensive protection for users' networks. At present, enterprise users are increasingly dependent on the network, and network security issues are becoming increasingly prominent. The D-Link smart switch provides a wide range of security policies, including VLANs, 802.1x, ACL (Access Control List), IGMP (Internet Group Management), and broadcast control functions; this reduces the possibility that intruders can obtain user information from SNMP Packets, effectively resist attacks initiated by computer viruses such as worms, and limit the intra-group traffic of broadcast domains and Intranet segments, block malicious data flooding and implement authentication and management of user identities.
In the current development situation, Intelligent switches cannot replace the "silly" Switch (non-NMS switch) location in the short term. This is mainly due to price constraints, because the price of chips used by smart switches is relatively expensive, but as users demand more and more smart switches, the chip price will decline. Smart switches will gradually replace the market position of non-NMS switches.
The DES-1526 is a 24-port Smart quasi-Smart switch that supports 802.3af remote power supply and a maximum length of 100 meters. Because DES-1526 combined with a variety of functions, simple and easy to use, and cost-effective, so this product is very suitable for small and medium enterprises. In addition to the integration of remote power supply functions, DES-1526 also provides VLAN, priority, port aggregation and Simple Network Management functions, so this can have security, QoS, PoE and other functions of the switch at the same time. The VLAN function of DES-1526 can enhance network security and improve network efficiency. Broadcast storms in VLAN-restricted networks are located in their own network segments, and 802.1q VLAN tags are used to divide devices, workstations, and servers in the network into multiple sub-networks, to improve network performance.