CRNET与城域网建设技术交流思科北京公司喻超CCIE #5329CRNET网络概况及建网思路和原则MPLS VPN的业务及关键技术L2 二层VPN的应用汇报提纲

广东省在CRNET 骨干网网络的位置CRNET 建网思路和城域网建设指导原则1.CRNET坚持全程全网,统一管理2.初期不建设独立的省网,城域网和CRNET直接相连3.各城域网为CRNET密不可分的组成部分,城域网是骨干网业务在城域的无缝延伸4.在CRNET的基础上,提供全国范围的MPLS VPN服务5.将CRNET扩展成可提供综合多业务的数据平台6.CRNET部分权力将下放到分公司,总部保留相对全力和监管能力

区域网络连接拓扑图(华南)B类节点A类节点C类节点长沙怀化株州郴州常德衡阳娄底岳阳柳州深圳东莞肇庆 茂名 中山汕头佛山顺德华南区(广州)湛江桂林南宁155M622MCH3CH4昆明CH3CH3CH4CH4CH4CH4CH4CH4CH4CH4CH4武汉广州广州铁通网络与CRNET 骨干网


ethernet622M STM-4100BaseT155M STM-1图例:CH3FECH4CH1GECisco 7200高速 接入/.

B类节点结构图(深圳)带外管理电源控制口以太深圳 CR-B拨号接入 专线接入(64K-8M)FR 接入IP Phone城域网业务类型: 以太接入/宽带接入DNSFR/DDN/专线接入/.Cache/Netflow城域网/宽带接入MPLSPEPEVPN用户接入深圳AR1AR4SW1SW3SW3DLCIsubinterfaceIP Phone北京1G ethernet 622M STM-4100BaseT2M/V.35图例:B-CRGSR12406AR1GSR12406AR4SW1说明:1.图中实线框内设备为既有。2.图中虚框内设备不在本工程内提供。3.至C类节点通道采用STM-1或捆绑2M。Cisco7200Siwtch拨号接入NASAS 5300AS 5300B 类节点拓扑结构图CH3GE 155M STM-1FECH4CH3GECH4FEGEFEFEFE

说明:图中虚框内设备不在本工程内提供。图例:AR5SW4Cisco 7200Switch155M STM-1/N2M10/100BaseT2M/V.35/V.24用户网络VLAN2-VLANnAR5SW4DSU/CSUDSU/CSUVLAN1NAS拨号接入广州CRCR带外管理电源控制口以太1G ethernetC 类节点网络拓扑图CH4GEFEGEFEFECH4AR5CH4其他C类节点结构图

城域网建设的服务模式综合多业务服务

话音业务 200-300元/电话(企业)100 元/电话 (个人)internet接入 100元 /家庭1000元 /企业VPN业务1000-2000元/节点Video业务60元/小时/节点 内容提供业务视内容来确定提高在单一数据线路上的业务收入来源/ARPU电话传真单一数据线接入视频会议终端IP电话个人用户/网上游戏服务一线通 多业务服务平台VPN业务/互联网业务数据存储/信息共享综合多业务服务是电信网络的必然之路

杭州CNC案例

杭州CNC网络状况开展的业务企业虚拟专用内部网/虚拟专用外部网因特网访问主机托管/虚拟主机VOD/远程教育/交互式电视/远程医疗呼叫中心IP电话/可视IP电话电子抄表家庭保安远程监控网上游戏/网上炒股信息点播(气象/交通/旅游/新闻)用户情况有线电视用户150万。市区46万目前上网人数:6万多户 3000多企业虚拟网接入节点内容服务, IDC数据中心服务IP电话超市盈利 10万/天绑定销售/销售电脑赠宽带目前1000万/月的盈利

CNC Connect案例

城域网建设的服务模式多业务服务

城域网建设的服务模式多业务服务

全业务提供铁通城域网服务质量保证应用托管内容托管无线互联网主机托管视频会议软交换从接入层到骨干网业务业务汇聚汇聚点点IP IP 语音语音数据专线数据专线互联网接入互联网接入内容推送内容推送铁通城域网铁通城域网DSL无线帧中继ATM专线以太网接入层长途多业务平台长途波分ATMATMCRNETCRNET核心数据网核心数据网集成的模型集成的模型专注于业务开展专注于业务开展城域 DWDMDWDM城域DPTDPTSDH多业务平台以太网MSTPMSTP

全国范围的MPLS VPN服务业务目标市场高端企业用户(ARPU值)MPLS VPN作为接入的手段基于MPLS VPN的增值服务是源源不断的利润来源具有铁通优势和特点的全国MPLS VPN服务是制胜的关键有针对性的扩大覆盖面,逐步实施

基于CRNET全国范围的MPLS VPN业务CRNET 宽带数据网铁道部 北京VPN北京总部铁道部 上海VPN上海分部吉林分部武汉分部广州分部铁道部 成都VPN

MPLS VPN业务及相关技术


多业务服务的具体实现MPLS VPN的安全性

互联网大楼A小区BInternet 高速接入业务铁通铁通IPIP宽带宽带城域城域网网络络企业C学校D互联网FE/GEFE/GELRE/ADSLLRE/ADSLWirelessWirelessHFCHFC端口带宽

用户端设备用户端设备A用户1A用户2使用原有私有地址使用原有私有地址宽带互连宽带互连10/10010/10010/10010/100MMMM以太网,低成本,高带宽以太网,低成本,高带宽MPLS VPN 企业内联网用户内部网络互连增加虚拟专用网A的路由IPIPIPIP宽带宽带城域城域网络平网络平同时可轻松提供针对不同业务的多同时可轻松提供针对不同业务的多VPNVPNVPNVPN服务服务如语音,视频,财务,人事等如语音,视频,财务,人事等

互联网A用户1A用户2虚拟专用网A路由

Classical Internet Access AddressingThe Customer can use private address space.The firewall provides Network Address Translation (NAT) between the private address space and the small portion of public address space assigned to the customer.Private addressesPublic addresses

Internet Access from Every SiteAddressingTwo addressing options:Every CE router performs NAT functionalitya small part of the public address space has to be assigned to each CE router.The customer uses only public IP addresses in the private networknot realistic for many customers.Private addressesPublic addresses

Central Firewall ServiceTraffic FlowInternetInternet Access VPNVPNCustomer ACE-A1CE-A2VPNCustomer BCE-B1CE-B2CentralFirewallTraffic between sites of one customer should flow inside the VPN.Traffic between customers is not allowed; a security breach could occur.Traffic can flow from customer sites to the Internet and back; customer sites are protected by a central firewall.

Combining Internet Access with VPN ServicesTwo major design models:Internet access offered through yet another VPNInternet access offered through global routing on the PE routers

Internet Access in a VPNBenefits:The provider backbone is isolated from the Internet; increased security is realized.Drawbacks:All Internet routes are carried as VPN routes; full Internet routing cannot be implemented because of scalability problems.

Internet Access Through Global RoutingTwo implementation options:Internet access is implemented via separate interfaces that are not placed in any VPN routing/forwarding instance (VRF) (traditional Internet access setup).Packet leaking between a VRF and the global table is achieved through special configuration commands.

Internet Access Through Packet LeakingBenefits:This method can be implemented over any WAN or LAN media.Drawbacks:Internet and VPN traffic is mixed over the same link; security issues arise.More complex Internet connectivity options (for example, full Internet routing for customers) are hard to implement.

Packet Leaking in ActionPEPE InternetSite-1PE-IGSite-2Network VRF0.0.0.0/0 (global)Site-1 routesSite-2 routesGlobal Table and FIB192.168.1.1/32 Label=3192.168.1.2/32 Label=5.IP packetD=Label = 3 IP packetD=IP packetD=

Internet Access Through a Dedicated SubinterfaceTraffic FlowPEPESite-1PE-IGSite-2Network routing tableSite-2 routes - Serial0.1Internet routes - Serial0.2IP packetD=PE Global TableInternet routes -, Label=3 InternetLabel = 3 IP packetD=IP packetD=

互联网A用户1A用户2虚拟专用网路由互联网访问路由增加虚拟专用网B的部分路由互联网访问B用户1增加虚拟专用网A的部分路由用户端设备用户端设备用户端设备用户端设备在提供企业内联网,互联网访问业在提供企业内联网,互联网访问业务基础上,利用同一线路,统一的务基础上,利用同一线路,统一的IPIPIPIP宽带网络平台提供企业外联网业宽带网络平台提供企业外联网业务。务。IPIPIPIP宽带网络平台宽带网络平台MPLS VPN 企业外联网外部网互连

运营商之运营商业务

运营商之运营商Customer-ISP 不运行 MPLSCRNETPE-1PE-2CE-1CE-2中经网 沈阳 IGP中经网 北京 IGPISP customersASBR-1ASBR-2ISP customersNetwork = NIPDest=NIPDest=N 1 IPDest=NIPDest=NIPDest=NIPDest=N 2 IPDest=NIPDest=N 1 6

Carrier BackbonePE-1PE-2CE-1CE-2ISP customersASBR-1ASBR-2ISP customersNetwork = NIPDest=NIPDest=NIPDest=NIPDest=N 3 IPDest=N 2 IPDest=N 1 6 IPDest=N 1 IPDest=N 15 IPDest=N 7 运营商之运营商Customer-ISP 运行 MPLS中竟网 沈阳 IGP中经网 北京 IGP

运营商之运营商Customer-ISP 运行MPLS-VPNCarrier BackbonePE-1PE-2CE-1CE-2I-PE1I-PE2Network = NIPDest=NIPDest=NIPDest=N 12 3 IPDest=N 12 2 IPDest=N 1 6 12 IPDest=N 1 12 IPDest=N 25 12 IPDest=N 7 12 IPDest=N

38、分路由B B用户用户1 1IPIP电话电话 通道通道V V网关网关PSTN/GSMPSTN/GSM国家级长途国家级长途VOIPVOIP智能软交换关守智能软交换关守IPIP电话电话传统电话传统电话(铁通号码)铁通号码)(铁通号码)铁通号码)互联网互联网互联网互联网访问访问电视会议电视会议用户端设备用户端设备在提供企业内联网,互联网在提供企业内联网,互联网在提供企业内联网,互联网在提供企业内联网,互联网访问业务,企业外联网业务访问业务,企业外联网业务访问业务,企业外联网业务访问业务,企业外联网业务基础上,利用同一线路,统基础上,利用同一线路,统基础上,利用同一线路,统基础上,利用同一线路,统一的一

39、的一的一的IPIPIPIP宽带网络平台提供企宽带网络平台提供企宽带网络平台提供企宽带网络平台提供企业业业业IPIPIPIP电话业务。电话业务。电话业务。电话业务。IPIPIPIP宽带网络平台宽带网络平台宽带网络平台宽带网络平台MPLS VPNMPLS VPN语音语音/ /电视会议专用电视会议专用VPNVPN电视会议电视会议Presentation_ID 2001, Cisco Systems, Inc. All rights reserved.414141与广电基于与广电基于Voice Over CableVoice Over Cable的合作的合作HFCHFCGatekeeperGateke

40、eperPSTNPSTNV VCATV IP CATV IP MANMANIPIP电话电话 VPNVPN铁通城域铁通城域IPIP网络网络IPIP电话电话 VPNVPN智能软交换智能软交换智能软交换智能软交换CMTSCMTSCable Cable ModemModem成本投入成本投入: :SoftSwitch SoftSwitch 每线的成本每线的成本 10-20$10-20$所有的用户接入的电所有的用户接入的电话话Cable ModemCable Modem由由CATVCATV投资投资收入收入: :15-2015-20¥/ /每月每月/ /用户市话收费用户市话收费一年内即可通过市话费收回投资,

41、以后的一年内即可通过市话费收回投资,以后的收入即纯利润收入即纯利润用户的长途话务可通过铁通的用户的长途话务可通过铁通的PSTNPSTN长途长途骨干或骨干或VoIPVoIP骨干,假设骨干,假设3030¥/ /每月每月/ /用户,用户,20002000用户可每年给铁通带来额外的用户可每年给铁通带来额外的 2000*30*12=722000*30*12=72万万 ¥卖点卖点: :CATV CATV 在提供数据的同时,为在提供数据的同时,为用户提供话音,帮铁通放号用户提供话音,帮铁通放号铁通在最小的成本情况下,扩铁通在最小的成本情况下,扩大铁通的用户覆盖范围大铁通的用户覆盖范围用户在享受数据,语音,用

42、户在享受数据,语音,是铁通,广电,用户三赢的局是铁通,广电,用户三赢的局面面Presentation_ID 2001, Cisco Systems, Inc. All rights reserved.424242城域城域MPLS VPNMPLS VPN网吧联盟网吧联盟网吧联盟网吧联盟2 2接入接入上网上网网吧联盟网吧联盟1 1接入接入上网话音上网话音网吧联盟网吧联盟1 1接入接入上网上网网吧联盟网吧联盟2 2接入接入上网话音上网话音CRNETCRNET骨干骨干PEPEPEPEP PP P铁通城域网铁通城域网PEPEV V话音话音VPNVPN普通接入点普通接入点话音话音Site 1Site 1S

43、ite 2Site 2Site 3Site 3Site 4Site 4Site 5Site 5Site 6Site 6普通上网普通上网Site 7Site 7,8 8网吧间共享资源网吧间共享资源/ /联网游联网游戏戏/ /VoIPVoIP通话通话/ /可视聊天可视聊天Presentation_ID 2001, Cisco Systems, Inc. All rights reserved.434343铁通铁通铁通铁通城域城域城域城域网网网网企业具体业务分析企业具体业务分析城城城城域域域域宽带宽带宽带宽带IPIP网络网络网络网络平台平台平台平台以太网交换机以太网交换机以太网交换机以太网交换机互联

44、网互联网互联网互联网某企业分部某企业分部某企业分部某企业分部/ /某大楼某大楼某大楼某大楼MPLS VPNMPLS VPN连接本部和连接本部和连接本部和连接本部和分部分部分部分部电视会议电视会议电视会议电视会议企业企业企业企业A AIPIP电话电话电话电话企业企业企业企业A A分分分分部部部部电视会议电视会议电视会议电视会议IPIP电话电话电话电话企业企业企业企业A A总部总部总部总部MPLS VPNMPLS VPN连接本部和连接本部和连接本部和连接本部和分部分部分部分部IDCIDC数据中心数据中心数据中心数据中心主机托管主机托管主机托管主机托管二级运营商二级运营商二级运营商二级运营商/ /内

45、容提供商内容提供商内容提供商内容提供商网上教学网上教学网上教学网上教学/ /学习学习学习学习内部信息共享内部信息共享内部信息共享内部信息共享视频点播视频点播视频点播视频点播Presentation_ID 2001, Cisco Systems, Inc. All rights reserved.444444互联网互联网用户端设备用户端设备银行银行证券公司证券公司金融用户金融用户透明传送业务高带宽,高安全性透明传送业务高带宽,高安全性连接用户的以太接口为二层接口,无连接用户的以太接口为二层接口,无IPIP地址地址Ethernet, ATM, Frame Relay etcEthernet, AT

46、M, Frame Relay etc同一网段同一网段同一局域网同一局域网银行银行证券公司证券公司金融用户金融用户用户端设备用户端设备IPIPIPIP宽带网络平台宽带网络平台宽带网络平台宽带网络平台L2 VPNL2 VPN服务服务L2 VPN L2 VPN 安全、透明网络通道传输业务安全、透明网络通道传输业务A A用户用户1 1A A用户用户2 2Presentation_ID 2001, Cisco Systems, Inc. All rights reserved.454545L2 VPNL2 VPN业务及技术业务及技术1.AToM2.L2TPPresentation_ID 2001, Ci

47、sco Systems, Inc. All rights reserved.464646IP VPN技术技术Complete L2 and L3 VPN Solutions for both IP and MPLS L2L3MPLSAToM (draft-martini)RFC 2547 VPN (MPLS VPN)IPUTI/L2TPv3TBD RFC 2547?Presentation_ID 2001, Cisco Systems, Inc. All rights reserved.474747 Any Transport over MPLS (AToM)Provides ability

48、to transport layer 2 traffic across MPLS packet-based core networks, extending the richness of MPLS capabilities to L2 VPNsA scalable architecture that supports the multiplexing of subscriber connectionsA standards based (draft-martini) open architecture allows extensibility to many transport typesD

49、esigned for Any-to-Any connectivitySP does not participate in customer routingMPLS CoreMPLS CoreAToMFrame RelayATMLeased LineEthernetFrame RelayATMLeased LineEthernetAllows SPs to combine with Cisco IOS QoS and MPLS Traffic Engineering to provide “Virtual leased line” like servicesPresentation_ID 20

50、01, Cisco Systems, Inc. All rights reserved.484848AToM 数据流程数据流程PE1MPLS BackbonePE2Any Transport over MPLS (AToM) TunnelMPLS LSPFrame RelayCPE Router, FRADDLCI 101CPE Router, FRADFrame RelayDLCI 201Directed LDPLabel Exchange for VC1 Label 10Label Exchange for VC2 Label 21VC1 Connects DLCI 101 to DLCI

51、 201VC2 Connects DLCI 102 to DLCI 202DLCI 202DLCI 102Neighbor LDP Label 50Neighbor LDP Label 9010110 5010110 9010221 5010221 90Presentation_ID 2001, Cisco Systems, Inc. All rights reserved.494949IETF IETF 标准化标准化IETF working group PWE3 Pseudo Wire Emulation Edge to Edge;Requirements detailed in draft

52、-ietf-pwe3-requirements Develop standards for the encapsulation & service emulation of “pseudo wires”Across a packet switched backboneFocused on Point-to-Point circuit emulationPSN tunnel - GRE, MPLS, L2TPService - Ethernet, ATM, PPP, FR, HDLC and so on .Presentation_ID 2001, Cisco Systems, Inc. All

53、 rights reserved.505050L2TP 协议参考模型协议参考模型L2TPv2L2TPv3IP or MPLSCoreL2TPv3 TunnelsCECEPE1PE2CECEProvider EdgeSP IP CoreProvider EdgeIP or MPLSCoreL2TPv2 TunnelsLNS ISP 1LACDial UserDSL UserLNS ISP 2EthernetEthernetFrame RelayFrame RelaySP IP CorePresentation_ID 2001, Cisco Systems, Inc. All rights res

54、erved.515151L2TPv3 for customers that prefer a native IP network Provides ability to transport layer 2 traffic across IP packet-based core networks Based on a well-established lineage of protocols:L2TPv2 and pre-standards Cisco innovation Universal Transport Interface (UTI)A standards based open arc

55、hitecture allows extensibility to many transport typesIP CoreIP CoreL2TPv3Frame RelayATMLeased LineEthernetFrame RelayATMLeased LineEthernetLayer 2 Tunneling Protocol - version 3Efficient header for high performance decapsulationConfiguration on Edge routers onlyPresentation_ID 2001, Cisco Systems,

56、Inc. All rights reserved.525252L2TPv3 L2TPv3 包的封装包的封装 Delivery header - The delivery header is the header needed to carry the L2TPv3 packet across the delivery network. This is an IPv4 header. The delivery header is 20 bytes. L2TPv3 header - The L2TPv3 payload independent header contains the necessa

57、ry and sufficient information needed to uniquely identify the tunnel context at the de-encapsulation point. The payload independent header is 12 bytes. Payload - Payload to be transported by L2TPv3. It may be a link layer frame or a network layer packet.Presentation_ID 2001, Cisco Systems, Inc. All

58、rights reserved.535353IP or MPLSCoreIP CoreL2TPv3 L2TPv3 数据包的流程数据包的流程Description: Two Ethernet Segments are joined over an IP core viaL2TPv3. To end user devices, the two physical Ethernet networks appear as a single segment.R2R1L2TPv3 TunnelServer BWorkstation AStep #2 R1 takes Ethernet frame and e

59、ncapsulates it in L2TP and routes it to tunnel destinationStep #1 Workstation A sends packet destined for Server BStep #3 R2 receives IP/L2TP/Ethernet Packet and removes the IP/L2TPv3 headers. The remaining Ethernet frame is forwarded to Server B. Presentation_ID 2001, Cisco Systems, Inc. All rights

60、 reserved.545454IETF IETF 标准化标准化L2TPv3 is currently an IETF standards track draft document. See draft-ietf-l2tpext-l2tp-base-01.txtL2TPv3 has been presented at the IETF meetings in London (August 2001) and Salt Lake City (December 2001). It was warmly received at both venues.We are continuing the st

61、andards push at the IETF meeting in Minneapolis, MN (March 2002)We anticipate standards ratification by Q1 of 2003.Presentation_ID 2001, Cisco Systems, Inc. All rights reserved.555555统一化统一化VPN VPN 的好处的好处Decreased CostDecreased CAPEX & OPEX : Simplify core, maintain L2 revenue streams & operate fewer

62、 networks Increased utilization of Packet NetworksEfficient Global ReachLeverage a MPLS / IP backbone for global reach Does not require complexity of multiple expensive partnerships to deliver global service Faster Time to Service Less complex circuit provisioning times Decreased CostIf in-sourced decreased CAPEX & OPEX to maintain & operate fewer VPNs If out-sourced wider selection of Service Providers offering access services Efficient Global ReachMay work with single Service Provider to obtain global VPN services Flexible DemarcationsSelectively retain control or outsource their networks



