2013年9月16日星期一

The difference between VRRP and HSRP

VRRP: Virtual Router Redundancy Protocol HP JC691A   (VRRP:Virtual Router Redundancy Protocol)
Virtual Router Redundancy Protocol (VRRP) is a kind of routing protocol, it can put theresponsibility of a dynamic virtual router assigned to the VRRP router in a lan. VRRP router control virtual router IP address called the main router, which is responsible for forwarding data packets to the virtual IP address. Once the master router is not available, the selection process provides dynamic failover mechanism, which allows the virtual router IP addresscan be used as the terminal host's default first hop router. The advantage of using VRRP is the availability of a default path of the higher without at each end host configuration dynamic routing or route discovery protocol. The VRRP package in the IP package to send.
Using VRRP, you can manually or DHCP as the default router is set with a virtual IP address.Virtual IP address sharing between routers, one designated as a router and the other is thebackup router. If the router is not available, the virtual IP address will be mapped to a backuprouter IP address (the backup router becomes the master router). VRRP can also be used for load balancing. VRRP is part of IPv4 and IPv6.
VRRP is neither UDP, nor TCP, VRRP packets encapsulated in the IP package to send, the agreement is 112, the VRRP control message only a notice (advertisement): VRRP. It uses IP packet is encapsulated multicast group address, 224.0.0.18, distribution scope limited to the same lan.
VRRP and ICMP, ARP of these protocols are similar, carrying on IP agreement, the agreement is 112, so to be between three layers of equipment to establish VRRP master-slave relationship must be in the same local area network, two layer exchange. So the twolayer three devices, if the switch port trunk, must be interconnected, and allow the establishment of master-slave relationship by VLAN. If the two router or firewall, among the general will be connected to a two layer switch, wherein the two layer switch and even the user access switch.
The work principle of VRRP protocol and the CISCO HSRP (Hot Standby Routing Protocol)has many similarities. But the main difference between the two is in the CISCO HSRP, need to separately configure a IP address as the virtual router external manifestation of address,this address is not interface address any member of a group.
The use of the VRRP protocol, without rebuilding the existing network structure, the maximum protection of the current investment, with minimal overhead, has greatly improved the network performance, has important application value
HSRP: Hot Standby Router Protocol (HSRP:Hot Standby Router Protocol)
Hot Standby Router Protocol (HSRP) is designed to support a specific instances of the IPflow failure cause confusion, and allows the host using a single router transfer will not, can still maintain the connectivity between routers and failure even in the first hop router underactual. In other words, when the source host can not dynamically know first hop router's IPaddress, the HSRP protocol can fault protection first hop router not. The agreement contains a variety of router, corresponding to a virtual router. The HSRP protocol supports only onerouter represents the virtual router packet forwarding process. The terminal host will eachdata packet is forwarded to the virtual router.
Responsible for forwarding router packet called active router (Active Router). Once the active router fails, HSRP will activate the backup router (Standby Routers) to replace the active router. The HSRP protocol provides a decision to use the active router or backup router mechanisms, and specify a virtual IP address as the default gateway address network system. If the active router fails, the backup router (StandbyRouters) all tasks to undertakeactive router, and will not lead to host communication interruption.
HSRP running on UDP, the port number 1985. The router forwards the source address of packet using the actual IP address, not the virtual address, is based on this point, the mutualrecognition of HSRP router.
The difference between VRRP and HSRP
1 the function of VRRP and HSRP are very similar, but in terms of security, a major advantage of VRRP on HSRP: it allows establishing authentication mechanism in group VRRP devices. And unlike the HSRP requirements of virtual router is not one of the IP address of the router, but VRRP allows for this to happen (if "with" virtual router addressrouter is up and running, you should always by the virtual router management - equivalent to HSRP in the active router), but in order to ensure that in the event of failure when the terminal host does not need to learn the MAC address, it specifies the use of the MAC address 00-00-5e-00-01-VRID, where VRID is the virtual router ID (equivalent to a HSRP group identifier).
2 another difference is that VRRP does not use HSRP in a coup or an equivalent message,the state machine of VRRP is simpler than HSRP, HSRP has 6 states (initial state learning(Initial), (Learn), listening (Listen) state, dialogue (Speak) state, backup (Standby) stateactivity (Active), state) and 8 events, VRRP only 3 states (initial state (Initialize), the main state (Master), backup state (Backup)) and 5 events.
3 HSRP three message, but there are three state can send a message to call (Hello)message / leave (Resign) message / mutation (Coup) message, VRRP has a message,broadcast message, by the master router timed out notice of its existence, the use of thesemessages can be of various parameters of virtual router detection, can also be used for the master router election.
4 HSRP message in the UDP message, and VRRP load in TCP message (HSRP uses UDP1985 port, 224.0.0.2 Hello message is sent to a multicast address. )
5 VRRP security: VRRP protocol includes three main authentication method: noauthentication; simple cleartext password; authentication using MD5HMACip authentication;
6 strong authentication method using IP authentication header (AH) protocol. AH is used in the IPSEC the same protocol, AH provides a method for authentication in a VRRP packetand packet header. The use of MD5HMAC that is used to generate hash values using a shared secret key. The router sends a VRRP packet generation MD5hash value, and put it into to send a notice, when receiving, the receiving party using the key and the same MD5 value, content of the packet and the packet header to calculate hash value, if the results are the same, this news is true from a trusted host, if not the same, it must be discarded, it canprevent attackers from accessing LAN can affect the choice of a notification messageprocess or some other method of interrupt network. In addition, VRRP includes a mechanism to protect VRRP packet will not be another remote network add content (TTLvalue =255, and in an examination), which limits most defects can be local attack. On the other hand, the HSRP used in its message of TTL value is 1. 6. The collapse of VRRPinterval: 3* advertisement interval + delay time (skew-time).

7 HSRP is private, VRRP does not support JC691A interface tracking mechanism.
More information about switch and router, please view : http://demoploo.tumblr.com

2013年9月12日星期四

Question about the HP S5500-EI switch spanning tree STP

Questionthe S5500 STP opens the HP JC694A  do loop on port 5500, the loop will be automatically banned.
But if a Dlink switch connect in the S5500, then make a loop on the dlink switch, open the S5500 in the STP will not work.
Are there any ways to make them work: can prohibit loop in S5500, but also can prohibit loop common switch S5500 caused?

Answer: Network environment is simple, some divided into several segments need, such as 5500 each port make one or several VLAN, and then on 5500 ports properly set  the broadcast message storm,
It can not guarantee all broken network, the VLAN and only loop or the 2VLAN network anomaly. Other ports are not affected, 5500 will not die.
[TEST-Ethernet1/0/1]broadcast-suppression?
INTEGER<1-100> The max-ratio of broadcast
BPS Specify port storm control by BPS
Specify the broadcast storm control by PPS PPS
[TEST-Ethernet1/0/1]broadcast-suppression

HP S5500-EI series switch is HP company newly developed enhancedIPv6 layer three Gigabit Ethernet switch products industry, have thecassette switch hardware processing capacity of the most advanced and the most abundant business characteristics. Support up to 4 Gigabitexpansion interface, hardware support for IPv4/IPv6 dual stack and line speed forwarding, enabling customers to take time for the upcoming IPv6 era; in addition, its excellent safety, reliability and multi service support capability to become a large enterprise network and campus networkconvergence, the first choice for small and medium-sized enterprises, JC694A core network and network edge equipment.
More information, please view : http://www.h3network.com


2013年9月11日星期三

H3C release high-end cloud service router SR6600-X series

Recently, the global IP network leading manufacturers H3C JD663B once again madecloud computing network, launched a dedicated cloud business applications in high end router SR6600-X series products. With virtualization service processing capability and innovation performance, the rich, the SR6600-X series router to meet the current and future application of cloud computingneeds well, will become the preferred route equipment high-end enterprise network convergence and operator edge. The launch of the SR6600-X series of high-end products, making H3CNGIP a new generation of Internet solution is more abundant, but also further expand in the field of routing device H3Coverall advantage.
With the popularization of cloud computing applications, users of the routing device "threshold" is getting higher and higher. Not only requires theequipment with high capacity and high forwarding performance, and also couldgather more users and traffic, and ensure the safety and reliability of cloudconnected user. In addition, the convergence layer or the networkenvironment, users on multiple devices proposed redundancy high reliabilityrequirements. Therefore, the traditional routing equipment in these areas are often difficult to meet the requirements of.
SR6600-X Series Router H3C new targeted to solve the problem. SR6600-Xadopts the whole business distributed processing architecture, business allbuilt without a separate card, and have the elastic expansion of businessprocessing ability, compatible with the SR66 router board and interface card at the same time, set by the independent research and development of routingforwarding and processing in one of the Apollo hardware chip core, the introduction of higher performance of a new generation business engine,maximum per slot 80GE line speed forwarding. At the same time, SR6600-Xalso innovative H3C technologies based on IRF2, realize the high-end routervirtualization, in lifting equipment performance at the same time, so that the entire network convergence speed, and to simplify the configuration, reduce operation and maintenance costs, improve network reliability. In addition,through the integrated high performance encryption and secure business process, provide safe and reliable data center connectivity. The prominent feature of the SR6600-X industry, and comparing with other similar devices,have obvious advantages.
As the routing equipment focus on the future of cloud applicationdevelopment, SR6600-X series product positioning in the 40G~100G platform,target positioning in the high-end enterprise network users and operators,especially designed for large capacity user and complex flow, fully meet the requirements of high standards of present and future development of cloud computing services, is the preferred product user clouds and cloudinterconnection. H3C SR6600-X throughout the series includes SR6602-X,SR6604-X, SR6608-X, SR6616-X four product types, to fully meet the needs of different application environment needs of users.
It is worth mentioning that, the launch of the SR6602-X products not onlygreatly improve performance, in hardware, built-in support pluggable power redundancy design, and provides the AC or DC power input, and all theinterface module support hot plug, ensure that the user businessuninterrupted operation. SR6602-X will launch this SR6602-X1 and the SR6602-X2 two product, the host are integrated 4GECombo and 4GECombo+210GE interface, to meet the demand for high-end enterprise user density access large branches and operator user.
At the beginning of 2011 H3C has launched the main operator oriented cloud computing applications high end router CR16000 series product, once introduced to obtain the telecommunication broadcasting market recognition.The SR6600-X series of high-end cloud service router release, making H3Cfor cloud solutions has been further strengthened. Sun De, vice president ofH3C product line and said, in H3C proposed a new generation of Internet NGIP roadmap, solution oriented cloud is one of the most important part of. The release of the SR6600-X series of products, in the latest move around the concept of NGIP h3c. The SR6600-X came out in high-end router, will helpH3C computing network JF228A applications in the cloud, occupy a more importantposition.

 More information, please view: http://www.h3network.com