神州数码IPV6实施部署方案.docx
《神州数码IPV6实施部署方案.docx》由会员分享,可在线阅读,更多相关《神州数码IPV6实施部署方案.docx(60页珍藏版)》请在冰点文库上搜索。
神州数码IPV6实施部署方案
神州数码IPV6实施部署方
案(总46页)
本页仅作为文档封面,使用时可以删除
Thisdocumentisforreferenceonly-rar21year.March
XXOpenRouter功能介绍新核心部署方案
实施前拓扑图
老核心配宜文件••••••.••
实施方案描述
需求分析
替换方案
新核心配置脚本
老核心修改…••…
测试新核心工作状态
一、XXOpenRouter功能介绍
XX创新研发的OpenRouter的架构,由openrouter交换机、控制器、网络协议管理模块组成。
其中最下层是交换机硬件设备,作为数据转发层,本项LI中采用神州数码OpenRouter;中间为控制器,作为网络操作系统,屏蔽的底层硬件的不同,可以在上面运行不同网络协议管理模块;最上层为网络协议管理模块,它的运算结果通过控制器控制下发到底层硬件,控制其转发行为,本系统中对应的是IPv6网络管控模块OFCPF;
网络中0penRouter交换机在端口定期采样报文,并将其接口、IPv6地址和路山信息定期发送给控制器,控制器端域内源地址验证系统通过控制器集中讣算全局网络拓扑得到报文的正确传输路径(即源地址前缀,LI的地址前缀,入接口),最上层的IPv6网络管控模块根据已经计算好的正确传输路径,判断报文IPv6源地址是否真实,如果发现假冒,则马上报警,并将过滤表通过控制器下发到交换机的ACL中,阻断网络中非法IPv6源地址伪造报文的传输。
二、新核心部署方案
实施前拓扑图
松园拓扑示意图
2.2老核心配置文件
2.3实施方案描述
23.1需求分析
本项目神码交换机按照XXOpenRouter架构的要求进行针对性的软件开发,
配合硬件服务器及在它上面运行的控制器及IPV6网络管控模块OFCPF实现对发
现IPV6假冒IP攻击进行立即
报警,动态产生相应的ACL过滤虚假的IP源数据流,实现在攻击源头直接阻断IP欺骗攻击的LI的。
山于XX采购的服务器的服务器尚未到位,訂前OpenRouter交换机的按照相关技术要求先行进行部署,从底层为控制器和IPV6网络管控模块提供OpenRouter功能测试所需的基本环境和必备条件。
设备部署要求:
1.交换机启三层路由功能;
2.汇聚下端有IPv6的流量;
3.交换机与XX的控制器(IPV4地址)路山可达;
XX区老核心目前启动了很多功能,且XX用户量大概两千左右,同时神码新核心交换机DCRS-7608E本项LI除了业务模块外只配了一块管理引擎和一块电源模块,所以不建议作为整个XX区的核心交换机对老核心进行整机替换。
2.3.2替换方案
根据对XX区老核心配置的分析及前面章节的考虑,实施方案采用:
1)将老核心IPV6部分的网关地址迁移到神码OpenRouter新交换机上
2)老核心其它部分配置包括链路连接关系都保持不变
3)新老核心之间互联的端口设置为trunk模式
4)新核心直接和老核心的上一级核心交换机进行互联。
5)新核心上联端口同时配苣IPV6和IPV4地址,下联用户vlan只配置IPV6地址
6)新核心暂时启用IPV6dhcpserver功能,由于IPV6用户量比较大(1500用户以上)将会占用交换机较大CPU和内存,建议后期设麗专门的DHCPSERVER,交换机只启用DHCPv6RELAY功能以减少交换机压力。
拓扑图如下:
区openrouter实施后拓扑示意
接入
神州数码7608
OpenRoute咬换机
上级核心交换
松园区
老核心
23.3新核心配置脚本
enablepasswordlevel150wlzxly_1507
usernameadminprivilege15password0wlzxly_1507snmp-serverenable
snmp-servercommunityro0public
vlan2-220
vlan1501-1505
vlan600
exit
interfaceethernetl/1
switchportmodetrunk
desTO-HuaWei
interfaceethernetl/2
switchportaccessvlan600
exit
ipv6dhcppoolv6pool-vlanl3
network-address2001:
DA8:
5000:
4C00:
0:
0:
2:
0112
dns-server2001:
4860:
4860:
:
8888
exit
ipv6dhcppoolv6pool-vlanl4
network-address2001:
DA8:
5000:
4C00:
0:
0:
3:
0112
dns-server2001:
4860:
4860:
:
8888
exit
ipv6dhcppoolv6pool-vlanl5
network-address2001:
DA&5000:
4C00:
0:
0:
4:
0112
dns-server2001:
4860:
4860:
:
8888
exit
ipv6dhcppoolv6pool-vlanl6
network-address2001:
DA8:
5000:
4C00:
0:
0:
5:
0112
dns-server2001:
4860:
4860:
:
8888
exit
ipv6dhcppoolv6pool-vlan21
network-address2001:
DA&5000:
4C00:
0:
0:
6:
0112
dns-server2001:
4860:
4860:
:
8888
exit
ipv6dhcppoolv6pool-vlan22
network-address2001:
DA&5000:
4C00:
0:
0:
7:
0112
dns-server2001:
4860:
4860:
:
8888
exit
ipv6dhcppoolv6pool-vlan23
network-address2001:
DA&5000:
4C00:
0:
0:
&0112
dns-server2001:
4860:
4860:
:
8888
exit
ipv6dhcppoolv6pool-vlan24
network-address2001:
DA&5000:
4C00:
0:
0:
9:
0112
dns-server2001:
4860:
4860:
:
8888
exit
ipv6dhcppoolv6pool-vlan25
network-address2001:
DA&5000:
4C00:
0:
0:
A:
0112
dns-server2001:
4860:
4860:
:
8888
exit
ipv6dhcppoolv6pool-vlan26
network-address2001:
DA&5000:
4C00:
0:
0:
B:
0112
exit
ipv6dhcppoolv6pool-vlan32
network-address2001:
DA8:
5000:
4C00:
0:
0:
D:
0112
dns-server2001:
4860:
4860:
:
8888
exit
ipv6dhcppoolv6pool-vlan33
network-address2001:
DA8:
5000:
4C00:
0:
0:
E:
0112
dns-server2001:
4860:
4860:
:
8888
exit
ipv6dhcppoolv6pool-vlan34
network-address2001:
DA8:
5000:
4C00:
0:
0:
F:
0112
dns-server2001:
4860:
4860:
:
8888
exit
ipv6dhcppoolv6pool-vlan35
network-address2001:
DA8:
5000:
4C00:
0:
l:
0:
0112
dns-server2001:
4860:
4860:
:
8888
exit
ipv6dhcppoolv6pool-vlan36
network-address2001:
DA8:
5000:
4C00:
0:
l:
l:
0112
dns-server2001:
4860:
4860:
:
8888
exit
ipv6dhcppoolv6pool-vlan41
network-address2001:
DA8:
5000:
4C00:
0:
l:
2:
0112
dns-server2001:
4860:
4860:
:
8888
exit
ipv6dhcppoolv6pool-vlan42
network-address2001:
DA8:
5000:
4C00:
0:
l:
3:
0112
dns-server2001:
4860:
4860:
:
8888
exit
ipv6dhcppoolv6pool-vlan43
network-address2001:
DA8:
5000:
4C00:
0:
l:
4:
0112
dns-server2001:
4860:
4860:
:
8888
exit
ipv6dhcppoolv6pool-vlan44
network-address2001:
DA8:
5000:
4C00:
0:
l:
5:
0112
dns-server2001:
4860:
4860:
:
8888
exit
ipv6dhcppoolv6pool-vlan45
network-address2001:
DA8:
5000:
4C00:
0:
l:
6:
0112
exit
ipv6dhcppoolv6pool-vlan51
network-address2001:
DA8:
5000:
4C00:
0:
l:
8:
0112
dns-server2001:
4860:
4860:
:
8888
exit
ipv6dhcppoolv6pool-vlan52
network-address2001:
DA8:
5000:
4C00:
0:
l:
9:
0112
dns-server2001:
4860:
4860:
:
8888
exit
ipv6dhcppoolv6pool-vlan53
network-address2001:
DA&5000:
4C00:
0:
l:
A:
0112
dns-server2001:
4860:
4860:
:
8888
exit
ipv6dhcppoolv6pool-vlan54
network-address2001:
DA8:
5000:
4C00:
0:
l:
B:
0112
dns-server2001:
4860:
4860:
:
8888
exit
ipv6dhcppoolv6pool-vlan55
network-address2001:
DA8:
5000:
4C00:
0:
l:
C:
0112
dns-server2001:
4860:
4860:
:
8888
exit
ipv6dhcppoolv6pool-vlan56
network-address2001:
DA&5000:
4C00:
0:
l:
D:
0112
dns-server2001:
4860:
4860:
:
8888
exit
ipv6dhcppoolv6pool-vlan61
network-address2001:
DA8:
5000:
4C00:
0:
l:
E:
0112
dns-server2001:
4860:
4860:
:
8888
exit
ipv6dhcppoolv6pool-vlan62
network-address2001:
DA8:
5000:
4C00:
0:
l:
F:
0112
dns-server2001:
4860:
4860:
:
8888
exit
ipv6dhcppoolv6pool-vlan63
network-address2001:
DA&5000:
4C00:
0:
2:
0:
0112
dns-server2001:
4860:
4860:
:
8888
exit
ipv6dhcppoolv6pool-vlan64
network-address2001:
DA8:
5000:
4C00:
0:
2:
l:
0112
exit
ipv6dhcppoolv6pool-vlan66
network-address2001:
DA8:
5000:
4C00:
0:
2:
3:
0112
dns-server2001:
4860:
4860:
:
8888
exit
ipv6dhcppoolv6pool-vlan71
network-address2001:
DA8:
5000:
4C00:
0:
2:
4:
0112
dns-server2001:
4860:
4860:
:
8888
exit
ipv6dhcppoolv6pool-vlan72
network-address2001:
DA8:
5000:
4C00:
0:
2:
5:
0112
dns-server2001:
4860:
4860:
:
8888
exit
ipv6dhcppoolv6pool-vlan73
network-address2001:
DA8:
5000:
4C00:
0:
2:
6:
0112
dns-server2001:
4860:
4860:
:
8888
exit
ipv6dhcppoolv6pool-vlan74
network-address2001:
DA&5000:
4C00:
0:
2:
7:
0112
dns-server2001:
4860:
4860:
:
8888
exit
ipv6dhcppoolv6pool-vlan75
network-address2001:
DA8:
5000:
4C00:
0:
2:
8:
0112
dns-server2001:
4860:
4860:
:
8888
exit
ipv6dhcppoolv6pool-vlan76
network-address2001:
DA&5000:
4C00:
0:
2:
9:
0112
dns-server2001:
4860:
4860:
:
8888
exit
ipv6dhcppoolv6pool-vlan81
network-address2001:
DA&5000:
4C00:
0:
2:
A:
0112
dns-server2001:
4860:
4860:
:
8888
exit
ipv6dhcppoolv6pool-vlan82
network-address2001:
DA8:
5000:
4C00:
0:
2:
B:
0112
dns-server2001:
4860:
4860:
:
8888
exit
ipv6dhcppoolv6pool-vlan83
network-address2001:
DA&5000:
4C00:
0:
2:
C:
0112
exit
ipv6dhcppoolv6pool-vlan85
network-address2001:
DA8:
5000:
4C00:
0:
2:
E:
0112
dns-server2001:
4860:
4860:
:
8888
exit
ipv6dhcppoolv6pool-vlan86
network-address2001:
DA8:
5000:
4C00:
0:
2:
F:
0112
dns-server2001:
4860:
4860:
:
8888
exit
ipv6dhcppoolv6pool-vlan91
network-address2001:
DA&5000:
4C00:
0:
3:
0:
0112
dns-server2001:
4860:
4860:
:
8888
exit
ipv6dhcppoolv6pool-vlan92
network-address2001:
DA8:
5000:
4C00:
0:
3:
l:
0112
dns-server2001:
4860:
4860:
:
8888
exit
ipv6dhcppoolv6pool-vlan93
network-address2001:
DA8:
5000:
4C00:
0:
3:
2:
0112
dns-server2001:
4860:
4860:
:
8888
exit
ipv6dhcppoolv6pool-vlan94
network-address2001:
DA8:
5000:
4C00:
0:
3:
3:
0112
dns-server2001:
4860:
4860:
:
8888
exit
ipv6dhcppoolv6pool-vlan95
network-address2001:
DA&5000:
4C00:
0:
3:
4:
0112
dns-server2001:
4860:
4860:
:
8888
exit
ipv6dhcppoolv6pool-vlan96
network-address2001:
DA8:
5000:
4C00:
0:
3:
5:
0112
dns-server2001:
4860:
4860:
:
8888
exit
ipv6dhcppoolv6pool-vlanl01
network-address2001:
DA8:
5000:
4C00:
0:
3:
6:
0112
dns-server2001:
4860:
4860:
:
8888
exit
ipv6dhcppoolv6pool-vlanl02
network-address2001:
DA8:
5000:
4C00:
0:
3:
7:
0112
exit
ipv6dhcppoolv6pool-vlanl04
network-address2001:
DA8:
5000:
4C00:
0:
3:
9:
0112
dns-server2001:
4860:
4860:
:
8888
exit
ipv6dhcppoolv6pool-vlanl05
network-address2001:
DA8:
5000:
4C00:
0:
3:
A:
0112
dns-server2001:
4860:
4860:
:
8888
exit
ipv6dhcppoolv6pool-vlanl06
network-address2001:
DA8:
5000:
4C00:
0:
3:
B:
0112
dns-server2001:
4860:
4860:
:
8888
exit
ipv6dhcppoolv6pool-vlanlll
network-address2001:
DA8:
5000:
4C00:
0:
3:
C:
0112
dns-server2001:
4860:
4860:
:
8888
exit
ipv6dhcppoolv6pool-vlanll2
network-address2001:
DA&5000:
4C00:
0:
3:
D:
0112
dns-server2001:
4860:
4860:
:
8888
exit
ipv6dhcppoolv6pool-vlanll3
network-address2001:
DA8:
5000:
4C00:
0:
3:
E:
0112
dns-server2001:
4860:
4860:
:
8888
exit
ipv6dhcppoolv6pool-vlanll4
network-address2001:
DA8:
5000:
4C00:
0:
3:
F:
0112
dns-server2001:
4860:
4860:
:
8888
exit
ipv6dhcppoolv6pool-vlanll5
network-address2001:
DA&5000:
4C00:
0:
4:
0:
0112
dns-server2001:
4860:
4860:
:
8888
exit
ipv6dhcppoolv6pool-vlanll6
network-address2001:
DA&5000:
4C00:
0:
4:
l:
0112
dns-server2001:
4860:
4860:
:
8888
exit
ipv6dhcppoolv6pool-vlanl21
network-address2001:
DA&5000:
4C00:
0:
4:
2:
0112
exit
ipv6dhcppoolv6pool-vlanl23
network-address2001:
DA8:
5000:
4C00:
0:
4:
4:
0112
dns-server2001:
4860:
4860:
:
8888
exit
ipv6dhcppoolv6pool-vlanl24
network-address2001:
DA8:
5000:
4C00:
0:
4:
5:
0112
dns-server2001:
4860:
4860:
:
8888
exit
ipv6dhcppoolv6pool-vlanl25
network-address2001:
DA&5000:
4C00:
0:
4:
6:
0112
dns-server2001:
4860:
4860:
:
8888
exit
ipv6dhcppoolv6pool-vlanl26
network-address2001:
DA8:
5000:
4C00:
0:
4:
7:
0112
dns-server2001:
4860:
4860:
:
8888
exit
ipv6dhcppoolv6pool-vlanl31
network-address2001:
DA&5000:
4C00:
0:
4:
&0112
dns-server2001:
4860:
4860:
:
8888
exit
ipv6dhcppoolv6pool-vlanl32
network-address2001:
DA&5000:
4C00:
0:
4:
9:
0112
dns-server2001:
4860:
4860:
:
8888
exit
ipv6dhcppoolv6pool-vlanl33
network-address2001:
DA&5000:
4C00:
0:
4:
A:
0112
dns-server2001:
4860:
4860:
:
8888
exit
ipv6dhcppoolv6pool-vlanl34
network-address2001:
DA8:
5000:
4C00:
0:
4:
B:
0112
dns-server2001:
4860:
4860:
:
8888
exit
ipv6dhcppoolv6pool-vlanl35
network-address2001:
DA&5000:
4C00:
0:
4:
C:
0112
dns-server2001:
4860:
4860:
:
8888
exit
ipv6dhcppoolv6pool-vlanl36
network-address2001:
DA&5000:
4C00:
0:
4:
D:
0112
exit
ipv6dhcppoolv6pool-vlanl42
network-address2001:
DA8:
5000:
4C00:
0:
4:
F:
0112
dns-server2001:
4860:
4860:
:
8888
exit
ipv6dhcppoolv6pool-vlanl43