ZXR10 8900E series Core Switch Product Description
60
© 2013ZTE CORPORATION. All rights reserved.
ZTE Confidential Proprietary
route sent by MBGP neighbor based on certain strategy. In this instance, the route
selected is distributed by PE-A. Only the route information distributed by PE-A (including
forwarding prefix, inner layer label, selected outer layer LSP tunnel) is filled in the
forwarding item used by forwarding engine to direct the forwarding.
When PE-A node fails, PE-E perceives PE-A’s failure (BGP neighbor is DOWN or outer
layer LSP tunnel is unavailable), it re-select a route distributed by PE-B, re-distribute
forwarding item, and complete service end-to-end convergence. Before PE-E
re-distributes forwarding item corresponding to route that distributed by PE-B, since the
destination of outer layer LSP tunnel that forwarding item of forwarding engine directs is
PE-A, and PE-A node fails, during this period, CE-B cannot get access CE-A. End-to-end
services are interrupted. In traditional technology, end-to-end service convergence time
covers: 1) PE-E perceives PE-A failure. 2) PE-E re-selects VPN V4 route distributed by
PE-B. 3) PE-E distributes new forwarding item to the forwarding engine. Obviously, step
2 and step 3 goes depending on the scale of VPN V4 route.
ZXR10 8900E switch can firstly download the route information distributed by PE-B to the
forwarding engine as the second choice. It adopts BFD to check the link between PE-E
and PE-A. Discovering failure, PE-E quickly switch the route to hte link between PE-E
and PE-B. Packets will be switched to CE-B via PE-B to recover services between CE-B
and CE-A and realize fast switching.
3.8
Security and Authentication
3.8.1
ACL
In order to filter data, the netework needs to set lots of matching rules. After identifying
special objects, the corresponding packets can be allowed or forbidden to pass as per
the preset rules. ACL (Access Control List) is used to realize these services.
By using ACL, message filtering, policy route and special traffic control can be realized.
One ACL can contain one or more than more rules for one special type of packet. These
rules tell the switch if the selected packets are allowed or forbidden to pass.
The rules defined by ACL can also be used in other scenario, e.g. traffic classification in
QoS.
ZXR10 8900E series switch provides the following 4 types of ACL. Besides, it gives
support to two sorts of Ipv6 ACL.
Basic ACL: match source IP address only.
Extended ACL: Match source IP address, destination IP address, IP protocol type,
TCP source port number, TCP destination port number, UDP source port number,
UDP destination port number, ICMP type, ICMP Code, DSCP (DiffServ Code Point),
ToS and Precedence.
Содержание ZXR10 8900E series
Страница 1: ...Operator Logo ZXR10 8900E series Core Switch Product Description ...
Страница 2: ......
Страница 10: ......