企业网络解决方案.ppt
《企业网络解决方案.ppt》由会员分享,可在线阅读,更多相关《企业网络解决方案.ppt(81页珍藏版)》请在三一办公上搜索。
1、八:企业网络解决方案,中小型企业网络解决方案,适合24用户,采用24口交换机构建一个一级的小型局域网。主服务器与交换机,之间的链路数据流量较大,因此它采用2个100M高速交换端口连接服务器,以免形成传输瓶颈。24个10M交换端口最多可连接24个桌面用户。此外,它还通过10M接口连接共享网络打印机,普通打印机也可以通过打印服务器的方式共享。该方案的安全措施可采用路由器内置的软件防火墙,它使路由器在承担远程连接的同时实施数据包检验和过滤,防止非法用户侵入到内部局域网中。,中型企业网络解决方案,方案引入了二级联网的方式,骨干层交换机采用了1000M高速交换端口与服务器连接,以满足大容量数据的传输需求
2、。接入层交换机以10/100M自适应交换端口连接桌面用户。这样便很容易扩充桌面用户数。骨干交换机和接入交换机的连接则采用了快速以太网通道(FEC)技术,有效地扩展了网络的带宽。这项技术能够把2-4个物理链路聚合在一起,在全双工工作模式下达到400M-800M的带宽。安全措施:可采用路由器内置的软件防火墙,也可以采用功能更强大的专用防火墙,根据企业对安全性的要求级别来决定。,Redundant Uplinks,Redundant Uplinks,大型企业网络解决方案,采用三级模式:接入层、汇接层、核心层。接入层交换机是面向桌面用户。汇接层交换机是多台接入层交换机的集合点,汇接层交换机一般能够通过
3、路由处理器进行三层交换。如Catalyst5000系列交换机。接入层交换机到汇接层交换机采用双冗余连接。核心层交换机完成整个网络数据快速交换。核心层可采用双核心的冗余连接。,VLAN 介绍,Ethernet Broadcast Domain,In a flat network,every device sees every transmitted packet,VLANs,A VLAN is a broadcast domain,VLANs,EngineeringVLAN,MarketingVLAN,SalesVLAN,Floor#1,Floor#2,Floor#3,Physical Laye
4、rLAN Switch,Human Layer,Network Layer,Routing FunctionInterconnects VLANs,Data-Link LayerBroadcastDomains,VLANs Establish Broadcast Domains,Broadcast Domain 1,Broadcast Domain 2,Scaling the Switch Block with VLANs,3,4,1,2,5,6,7,8,9,10,Decisions include how many VLANs exist in a switch block and wher
5、e these devices are placed.,Server Block,Core,Layer 2 End-to-End VLAN,DistributionLayer,Core Layer,Fast or Gigabit Ethernet,WiringCloset,Fast Ethernet,Fast Ethernet,WorkgroupServers,Switched Ethernet,Enterprise Servers,Inter-VLANRouting,Local VLANs,STP Blocked Links,STP Blocked Links,Redundant Uplin
6、ks,RedundantUplinks,Redundant Uplinks,HSRPPeers,HSRPPeers,Establishing VLAN Membership,Port-Based,VLAN1,VLAN2,VLAN3,MACAddresses,MACAddresses,VLAN2,MAC-Based,VLAN1,MAC Address-Driven(Layer 2),Port-Driven,Static,Dynamic,Membership by Port,Maximizes Forwarding Performance,VLAN 2,VLAN 1,VLAN 3,VLAN的特征,
7、一个vlan中的所有设备处于同一个广播域一个VLAN是一个逻辑的子网或由定义的成员所组成的一个网络段,VLAN之间通信必须要进行路由VLAN的成员通常是基于交换机的端口号,但也可基于设备的MAC地址而动态设置.,VLAN解决的问题,有效的带宽利用增强了安全性,VLAN间通信,可利用路由器的安全和过虑功能负载均衡多条路径,可利用路由协议进行负载均衡.,Link Types,接入链路Access Links,An access link is a link that is a member of only one VLAN,Link Types(Cont.),干道链路Trunk Links,A t
8、runk link is capable of carrying multiple VLANs,VLAN Frame Identification,Specifically developed for multi-VLAN,inter-switch communicationsPlaces a unique identifier in the header of each frame,functions at Layer 2 VLAN identification options:Cisco ISLIEEE 802.1Q,VLAN1,VLAN1,VLAN2,VLAN2,VLAN3,VLAN3,
9、Backbone,VLAN1,VLAN2,VLAN3,VLAN Identification Using ISL,Trunk Link,VLAN100,VLAN200(Port C),VLAN200(Port A),Trunk LinksVLAN200(Access Link),X,Z,Y,W,Trunk Link,Trunk Link,Frame,1,2,Frame,3,VLAN200(Port B),ISL maintains VLAN information as frames travel between switches on trunk links,Y,Frame,ISL,VLAN
10、 Identification Using IEEE 802.1Q,2-byte tag protocol identifier(TPID)A fixed value of 0 x8100.This TPID value indicates that the frame carries the 802.1Q/802.1p tag information.2-byte tag control information(TCI),Initial MACAddress,Initial Type/Data,New CRC,2-Byte TPID2-Byte TCI,Configuring Trunkin
11、g,Switch(config-if)#trunk on|off|desirable|auto|nonegotiate,Catalyst 1900,Catalyst 2900,Switch(config-if)#switchport mode trunkSwitch(config-if)#switchport trunk encapsulation isl|dot1q,Catalyst 5500,Switch(enable)set trunk on|off|desirable|auto|nonegotiate range isl|dot1q|dot10|lane|negotiate,Addin
12、g a VLAN,Switch(config)#vlan name,Catalyst 1900,Catalyst 2900,Switch#vlan database Switch(vlan)#vlan name,Catalyst 5500,Switch(enable)set vlan name,Assigning Switch Ports to a VLAN,Switch(config-if)#vlan-membership static|dynamic,Catalyst 1900,Catalyst 2900,Switch(config-if)#switchport access vlan v
13、lan#,Catalyst 5500,Switch(enable)set vlan,Verifying a Trunk,Catalyst 2900,Switch#show interface switchport,Switch#show trunk A|B,Catalyst 1900,Switch(enable)show trunk mod/port,Catalyst 5500,Verifying a VLAN/VLAN Membership,Catalyst 2900,Switch#show vlan vlan#Switch#show vlan brief,Switch#show vlan
14、vlan#Swotch#show vlan-membership,Catalyst 1900,Switch(enable)show vlan,Catalyst 5500,VLAN 的路由,Problem:Isolated Broadcast Domains,VLAN10,VLAN20,VLAN30,Because of their nature,VLANs inhibit communication between VLANs.,Solution:Routing Between VLANs,VLAN10,VLAN20,VLAN30,Communications between VLANs re
15、quire a routing processor,Problem:Finding the Route,VLAN10,VLAN20,I need to send this packet to 172.16.20.4.That address is not on my local segment.,Where can end-user stations send nonlocal packets?,Solution:Defining a Default Gateway,VLAN10,VLAN20,I know where network 172.16.20.0 is!,End-user stat
16、ions send nonlocal packets to a default router,I will send the packet tomy default router.,VLAN20,VLAN10,Problem:Supporting Multiple VLAN Traffic,VLAN30,I have three distinct streams of traffic destined for the same place!,?,?,I need informationfrom File Server A.,I need informationfrom File Server
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- 企业 网络 解决方案
链接地址:https://www.31ppt.com/p-5222677.html