Static Routing and direct-connected network segment redistribution Technology

Source: Internet
Author: User
Tags switches firewall

On the issue of protocol converters we have said a lot, but also to promote the development of routing technology, now, network construction has been in-depth to the various branches of the industry, such as the power industry, such as rural power Information network.

General Enterprise use of Ethernet switch network is mainly divided into two categories, one is to use the protocol converter to switch to Ethernet access switches, the second is to rent bare fiber directly. Specifically, the three-tier switch selected in 三、四级 network can only be configured with simple dynamic routing protocol, simple Policy Routing, QoS and simple access control functions, and in fact, this location on the requirements of device functions and more than that, the use of Ethernet switch network need to pay attention to the following issues.

(1) Security

Now more and more online virus, network virus caused by the loss of more and more, a network of export equipment does not have a certain firewall function is unthinkable. Low-end switches have no firewall features at all, ACL access control is also poor, and for routers, even the lowest-end routers support stateful ACL control, allowing users to filter configuration based on the type and characteristics of network viruses, and limit the maximum number of links per IP address to prevent exceptions.

(2) Business support flexibility

Some networks need to have asymmetric access control over the servers within the network, that is, to accept requests from outside, but they cannot initiate requests to the extranet, which helps prevent the server from being used as a hacker tool or leading to leaks. The router can judge the state of the related session based on the ACL configuration so that it is not only in, and the low-end switch cannot implement the business because all message forwarding is done at the ASCI.

(3) Network expansion, sustainable development

Industry Network now or in the future must be connected to the local E-government network, at this time, in addition to the security of their own network, must also consider and other relevant industries and government interoperability issues, you may need to L2TP, GRE, Nat and other features to achieve secure access to different private networks. Some industries in the network need to run a variety of different security levels of the business, the resource requirements are not the same, in addition to the QoS may need to encrypt the individual business or even special tunnel transmission. In fact, all of these feature switches are not supported and are not supported by upgrades, while routers are basically supported.

(4) network reliability

Some projects lease the operator's 2MB or NX2MB line, but in the access location with the protocol converter to the 2MB line into Ethernet access to the three-tier switch. The protocol converter itself has a low cost and reliability design is impossible to complete, which adds a point of failure for the network. In fact, protocol converter failure is one of the most common problems in project implementation.

(5) Integrated cost

Some projects link using 10/100MB bare fiber to achieve vertical link, using switch networking. This reduces the cost of network equipment procurement, but the link cost than the ordinary 2MB line is too high, even if the operators because of promotions at a lower price, but the future link tension users enjoy the bandwidth and services will definitely be greatly reduced.

(6) Link Services

using a dedicated link vertical mechanism, the dedicated line to enjoy the end of the full range of closed services, users can always see their own network conditions without the operator to provide assistance. When the link fails in a few seconds with the export network equipment to monitor and immediately automatically start the backup link, the network outage time is second level, the business generally will not be interrupted. If the use of a protocol converter, switch access, link state changes are blocked by the protocol converter, users can only detect business interruption to detect, and then can not locate the fault, so the network interruption time will be calculated in hours. Comprehensive analysis of the above we can see that the router in the function is far better than the three-tier switch, considering the network management, line situation, network investment and other aspects, we think:

(1) in its own transmission of optical fiber, because the stability of the transmission link is guaranteed, The use of switch networking can save investment, but need to be in the network security and network management to make corresponding input.

(2) in the case of leased carrier lines, the use of router networking can save a lot of later maintenance, management costs, compared to the use of the switch networking has a greater advantage.

 

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.