Two-layer structure and three-layer structure in large LAN

Source: Internet
Author: User

Two-layer structure and three-layer structure in large LAN

Large-scale LAN structure is ever changing. The planning of the network is inseparable from the environment and application types of the campus. For the time being, the network structure is divided into sophomores and three-storey structures. The future direction is to move towards Sdn, my personal view is the automation network, can achieve business-based configuration automation, but also can achieve fault self-healing and. In terms of structure, there are no two or three levels, I think that is a layer of network. Vertical virtualization is a very good embodiment of a layer of network.

Today mainly summarizes the sophomore and three-storey structure


A two-tier network does not converge or logically converge, and the gateway is at the core. The data exchange between the different VLANs is directly from the core. Network redundancy is also achieved using MSTP+VRRP technology. The sophomore network often appears in the data center, because the data center equipment mainly emphasizes high-speed switching, high fault tolerance, security is responsible for the firewall, different VLANs between the relatively small number of different VLAN access is also less. This structure is also common in some small hospitals because PACs data requires high bandwidth for fast transmission, so two layers are more suitable. And the relationship between each department is relatively close, two-tier network VLAN has a global significance, more suitable for such an environment.
Many reference books treat the three-tier network as a standard network architecture. The access layer is responsible for user access, the aggregation layer is responsible for aggregation of user data and policy control, the core layer is focused on high-speed packet switching. Quite perfect, in some departments are far apart and the relationship between the environment is often a three-layer network, such as a head office under a lot of factories. Such a network access layer redundancy requirements are not high. There are more data exchanges between different departments. The core can use OSPF, and there is the use of OSPF+VRRP (aggregation does not support OSPF to do so), this environment VLAN only has local meaning after the route hop after the VLAN is going to the global significance. Different strategies can be used to achieve different results for each department. At the same time after special treatment, the local network turbulence will not affect the core.


1 Network Reliability
The second layer: the access layer switch is connected to the core switch, and the VRRP+MSTP technology is used to make the main spare line and improve the system reliability.
Layer Three: The access layer switch is connected to the core switch, and the system reliability is improved by setting the OSFP cost value to form the main spare line.
2 load Sharing
The second layer: all three-layer switching tasks are completed by the core layer, the core layer load is added, the access layer switch is used only two layer, performance can not be fully utilized.
Layer Three: The three-layer gateway is dispersed across all regions, reducing the core pressure, while also enabling the performance of all devices to be brought into play.
3 Link Oscillation time
Second layer: The STP protocol is used between the access switch and the core switch, the STP convergence speed is slow and the oscillation time is long.
Layer Three: The OSPF protocol is used between the convergence switch and the core switch, and the OSPF protocol converges fast and has short oscillation time.
4 Route hop count
Tier Two: The three-layer gateway is set directly on the core switch, reducing the number of route hops for three-level visits.
Three layer: Three layer gateway is set on the floor switch, so that the number of three-level visits to the route of the hop to increase the corresponding jump, reducing the access speed.
4 Route hop count
Tier Two: The three-layer gateway is set directly on the core switch, reducing the number of route hops for three-level visits.
Three layer: Three layer gateway is set on the floor switch, so that the number of three-level visits to the route of the hop to increase the corresponding jump, reducing the access speed.
5 Virus Infection Range
The second layer: Broadcast storms are confined to the same department; Once a virus attack occurs on a VLAN, more than one switch containing the VLAN can cause some difficulty in locating the fault, and it will affect the core switch.
Layer Three: Broadcast storms are confined to the wiring room; The virus is positioned accurately, and in the event of a virus attack, you can quickly locate the switch on which the VLAN resides (because the VLAN does not appear on other switches) without impacting the core switch.
6 Manageability
The second layer: management is troublesome, once the user changes, to configure the appropriate switch port. or a jumper.
Layer three: Easy to manage, new or changed equipment simply plug the cable into the corresponding switch, regardless of the port configuration.

Computer systems have undergone centralization, separation, and centralization. The network is no exception with the development of vertical horizontal virtualization technology in recent years, more enterprises have adopted the structure of the sophomore layer. Because virtualization technology enables high availability without the use of MSTP. As for the development of new control technology for network turbulence, more technology has emerged, and the second-tier network is catching up. But what architecture to adopt is based on the flexibility of the environment.

This article is from the "Network Cockroach" blog, please be sure to keep this source http://fenggao.blog.51cto.com/8119616/1582958

Two-layer structure and three-layer structure in large LAN

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.