《神州数码IPV6实施部署方案方针v2.doc》由会员分享,可在线阅读,更多相关《神州数码IPV6实施部署方案方针v2.doc(75页珍藏版)》请在得力文库 - 分享文档赚钱的网站上搜索。
1、+目 录一、XXOpenRouter功能介绍2二、新核心部署方案32.1实施前拓扑图32.2老核心配置文件32.3实施方案描述32.3.1需求分析32.3.2替换方案42.3.3新核心配置脚本52.3.4老核心修改33三、测试新核心工作状态33一、 XXOpenRouter功能介绍XX创新研发的OpenRouter的架构,由openrouter交换机、控制器、网络协议管理模块组成。其中最下层是交换机硬件设备,作为数据转发层,本项目中采用神州数码OpenRouter;中间为控制器,作为网络操作系统,屏蔽的底层硬件的不同,可以在上面运行不同网络协议管理模块;最上层为网络协议管理模块,它的运算结果通
2、过控制器控制下发到底层硬件,控制其转发行为,本系统中对应的是IPv6网络管控模块OFCPF;网络中OpenRouter交换机在端口定期采样报文,并将其接口、IPv6地址和路由信息定期发送给控制器,控制器端域内源地址验证系统通过控制器集中计算全局网络拓扑得到报文的正确传输路径(即源地址前缀,目的地址前缀,入接口),最上层的IPv6网络管控模块根据已经计算好的正确传输路径,判断报文IPv6源地址是否真实,如果发现假冒,则马上报警,并将过滤表通过控制器下发到交换机的ACL中,阻断网络中非法IPv6源地址伪造报文的传输。二、 新核心部署方案2.1 实施前拓扑图2.2 老核心配置文件2.3 实施方案描述
3、2.3.1 需求分析本项目神码交换机按照XX OpenRouter架构的要求进行针对性的软件开发,配合硬件服务器及在它上面运行的控制器及IPV6网络管控模块OFCPF实现对发现IPV6假冒IP攻击进行立即报警,动态产生相应的ACL过滤虚假的IP源数据流,实现在攻击源头直接阻断IP欺骗攻击的目的。由于XX采购的服务器的服务器尚未到位,目前OpenRouter交换机的按照相关技术要求先行进行部署,从底层为控制器和IPV6网络管控模块提供OpenRouter功能测试所需的基本环境和必备条件。设备部署要求:1. 交换机启三层路由功能;2. 汇聚下端有IPv6的流量;3. 交换机与XX的控制器(IPV4
4、地址)路由可达;XX区老核心目前启动了很多功能,且XX用户量大概两千左右,同时神码新核心交换机DCRS-7608E本项目除了业务模块外只配了一块管理引擎和一块电源模块,所以不建议作为整个XX区的核心交换机对老核心进行整机替换。2.3.2 替换方案 根据对XX区老核心配置的分析及前面章节的考虑,实施方案采用:1) 将老核心IPV6部分的网关地址迁移到神码OpenRouter新交换机上2) 老核心其它部分配置包括链路连接关系都保持不变3) 新老核心之间互联的端口设置为trunk模式4) 新核心直接和老核心的上一级核心交换机进行互联。5) 新核心上联端口同时配置IPV6和IPV4地址,下联用户vla
5、n只配置IPV6地址6) 新核心暂时启用IPV6 dhcp server功能,由于IPV6用户量比较大(1500用户以上)将会占用交换机较大CPU和内存,建议后期设置专门的DHCP SERVER,交换机只启用DHCPv6 RELAY功能以减少交换机压力。拓扑图如下:2.3.3 新核心配置脚本enable password level 15 0 wlzxly_1507username admin privilege 15 password 0 wlzxly_1507snmp-server enablesnmp-server community ro 0 publicvlan 2-220vlan
6、1501-1505vlan 600exitinterface ethernet1/1switchport mode trunkdes TO-HuaWeiinterface ethernet1/2switchport access vlan 600des TO-SW2exit/ 全局启用dhcpv6 service dhcpv6/ 配置各vlan的ipv6 dhcp poolipv6 dhcp pool v6pool-vlan11 network-address 2001:DA8:5000:4C00:0:0:0:0 112 dns-server 2001:4860:4860:8888 exiti
7、pv6 dhcp pool v6pool-vlan12 network-address 2001:DA8:5000:4C00:0:0:1:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan13 network-address 2001:DA8:5000:4C00:0:0:2:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan14 network-address 2001:DA8:5000:4C00:0:0:3:0 112 dns
8、-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan15 network-address 2001:DA8:5000:4C00:0:0:4:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan16 network-address 2001:DA8:5000:4C00:0:0:5:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan21 network-address 2
9、001:DA8:5000:4C00:0:0:6:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan22 network-address 2001:DA8:5000:4C00:0:0:7:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan23 network-address 2001:DA8:5000:4C00:0:0:8:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp poo
10、l v6pool-vlan24 network-address 2001:DA8:5000:4C00:0:0:9:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan25 network-address 2001:DA8:5000:4C00:0:0:A:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan26 network-address 2001:DA8:5000:4C00:0:0:B:0 112 dns-server 2001
11、:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan31 network-address 2001:DA8:5000:4C00:0:0:C:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan32 network-address 2001:DA8:5000:4C00:0:0:D:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan33 network-address 2001:DA8:5000
12、:4C00:0:0:E:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan34 network-address 2001:DA8:5000:4C00:0:0:F:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan35 network-address 2001:DA8:5000:4C00:0:1:0:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vla
13、n36 network-address 2001:DA8:5000:4C00:0:1:1:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan41 network-address 2001:DA8:5000:4C00:0:1:2:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan42 network-address 2001:DA8:5000:4C00:0:1:3:0 112 dns-server 2001:4860:4860:8
14、888 exitipv6 dhcp pool v6pool-vlan43 network-address 2001:DA8:5000:4C00:0:1:4:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan44 network-address 2001:DA8:5000:4C00:0:1:5:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan45 network-address 2001:DA8:5000:4C00:0:1:6:
15、0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan46 network-address 2001:DA8:5000:4C00:0:1:7:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan51 network-address 2001:DA8:5000:4C00:0:1:8:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan52 network-
16、address 2001:DA8:5000:4C00:0:1:9:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan53 network-address 2001:DA8:5000:4C00:0:1:A:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan54 network-address 2001:DA8:5000:4C00:0:1:B:0 112 dns-server 2001:4860:4860:8888 exitipv6
17、 dhcp pool v6pool-vlan55 network-address 2001:DA8:5000:4C00:0:1:C:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan56 network-address 2001:DA8:5000:4C00:0:1:D:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan61 network-address 2001:DA8:5000:4C00:0:1:E:0 112 dns-se
18、rver 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan62 network-address 2001:DA8:5000:4C00:0:1:F:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan63 network-address 2001:DA8:5000:4C00:0:2:0:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan64 network-address 2001
19、:DA8:5000:4C00:0:2:1:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan65 network-address 2001:DA8:5000:4C00:0:2:2:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan66 network-address 2001:DA8:5000:4C00:0:2:3:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v
20、6pool-vlan71 network-address 2001:DA8:5000:4C00:0:2:4:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan72 network-address 2001:DA8:5000:4C00:0:2:5:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan73 network-address 2001:DA8:5000:4C00:0:2:6:0 112 dns-server 2001:48
21、60:4860:8888 exitipv6 dhcp pool v6pool-vlan74 network-address 2001:DA8:5000:4C00:0:2:7:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan75 network-address 2001:DA8:5000:4C00:0:2:8:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan76 network-address 2001:DA8:5000:4C
22、00:0:2:9:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan81 network-address 2001:DA8:5000:4C00:0:2:A:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan82 network-address 2001:DA8:5000:4C00:0:2:B:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan83
23、 network-address 2001:DA8:5000:4C00:0:2:C:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan84 network-address 2001:DA8:5000:4C00:0:2:D:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan85 network-address 2001:DA8:5000:4C00:0:2:E:0 112 dns-server 2001:4860:4860:8888
24、 exitipv6 dhcp pool v6pool-vlan86 network-address 2001:DA8:5000:4C00:0:2:F:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan91 network-address 2001:DA8:5000:4C00:0:3:0:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan92 network-address 2001:DA8:5000:4C00:0:3:1:0 1
25、12 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan93 network-address 2001:DA8:5000:4C00:0:3:2:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan94 network-address 2001:DA8:5000:4C00:0:3:3:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan95 network-add
26、ress 2001:DA8:5000:4C00:0:3:4:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan96 network-address 2001:DA8:5000:4C00:0:3:5:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan101 network-address 2001:DA8:5000:4C00:0:3:6:0 112 dns-server 2001:4860:4860:8888 exitipv6 d
27、hcp pool v6pool-vlan102 network-address 2001:DA8:5000:4C00:0:3:7:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan103 network-address 2001:DA8:5000:4C00:0:3:8:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan104 network-address 2001:DA8:5000:4C00:0:3:9:0 112 dns-s
28、erver 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan105 network-address 2001:DA8:5000:4C00:0:3:A:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan106 network-address 2001:DA8:5000:4C00:0:3:B:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan111 network-address
29、2001:DA8:5000:4C00:0:3:C:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan112 network-address 2001:DA8:5000:4C00:0:3:D:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan113 network-address 2001:DA8:5000:4C00:0:3:E:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp
30、pool v6pool-vlan114 network-address 2001:DA8:5000:4C00:0:3:F:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan115 network-address 2001:DA8:5000:4C00:0:4:0:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan116 network-address 2001:DA8:5000:4C00:0:4:1:0 112 dns-serve
31、r 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan121 network-address 2001:DA8:5000:4C00:0:4:2:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan122 network-address 2001:DA8:5000:4C00:0:4:3:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan123 network-address 2001
32、:DA8:5000:4C00:0:4:4:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan124 network-address 2001:DA8:5000:4C00:0:4:5:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan125 network-address 2001:DA8:5000:4C00:0:4:6:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool
33、 v6pool-vlan126 network-address 2001:DA8:5000:4C00:0:4:7:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan131 network-address 2001:DA8:5000:4C00:0:4:8:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan132 network-address 2001:DA8:5000:4C00:0:4:9:0 112 dns-server 20
34、01:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan133 network-address 2001:DA8:5000:4C00:0:4:A:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan134 network-address 2001:DA8:5000:4C00:0:4:B:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan135 network-address 2001:DA8
35、:5000:4C00:0:4:C:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan136 network-address 2001:DA8:5000:4C00:0:4:D:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan141 network-address 2001:DA8:5000:4C00:0:4:E:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6p
36、ool-vlan142 network-address 2001:DA8:5000:4C00:0:4:F:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan143 network-address 2001:DA8:5000:4C00:0:5:0:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan144 network-address 2001:DA8:5000:4C00:0:5:1:0 112 dns-server 2001:4
37、860:4860:8888 exitipv6 dhcp pool v6pool-vlan145 network-address 2001:DA8:5000:4C00:0:5:2:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan151 network-address 2001:DA8:5000:4C00:0:5:3:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan152 network-address 2001:DA8:500
38、0:4C00:0:5:4:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan161 network-address 2001:DA8:5000:4C00:0:5:5:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan162 network-address 2001:DA8:5000:4C00:0:5:6:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-
39、vlan163 network-address 2001:DA8:5000:4C00:0:5:7:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan164 network-address 2001:DA8:5000:4C00:0:5:8:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan165 network-address 2001:DA8:5000:4C00:0:5:9:0 112 dns-server 2001:4860:
40、4860:8888 exitipv6 dhcp pool v6pool-vlan166 network-address 2001:DA8:5000:4C00:0:5:A:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan171 network-address 2001:DA8:5000:4C00:0:5:B:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan172 network-address 2001:DA8:5000:4C
41、00:0:5:C:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan173 network-address 2001:DA8:5000:4C00:0:5:D:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan174 network-address 2001:DA8:5000:4C00:0:5:E:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan
42、175 network-address 2001:DA8:5000:4C00:0:5:F:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan176 network-address 2001:DA8:5000:4C00:0:6:0:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan181 network-address 2001:DA8:5000:4C00:0:6:1:0 112 dns-server 2001:4860:4860
43、:8888 exitipv6 dhcp pool v6pool-vlan182 network-address 2001:DA8:5000:4C00:0:6:2:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan183 network-address 2001:DA8:5000:4C00:0:6:3:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan184 network-address 2001:DA8:5000:4C00:0
44、:6:4:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan185 network-address 2001:DA8:5000:4C00:0:6:5:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan186 network-address 2001:DA8:5000:4C00:0:6:6:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan191
45、network-address 2001:DA8:5000:4C00:0:6:7:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan192 network-address 2001:DA8:5000:4C00:0:6:8:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan193 network-address 2001:DA8:5000:4C00:0:6:9:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan194 network-address 2001:DA8:5000:4C00:0:6:A:0 112 dns-server 2001:4860:4860:8888 exitipv6 dhcp pool v6pool-vlan195 network-addre