EGS N308-3 2005 12 15 3 3 3 101 1 01084029795 01084029792 13911274117 yuyt@cesi.ac.cn
...1...1...1...1 ISO/OSI...2...4...7...7...7...8...12...13 2.4.4 VPN...15 2.4.5 IP...20 2.4.6...22 2.4.7...28 2.4.8...28...33...35...35...35...36...38...39 3.3.1 IP over SDH...39...39 VPN...40...40...41...41...41 IP...44 3.5.1...44...44...44...45...45...45...46...46 i
...46...48...49...49...50 3.9.1 AAA...50 3.9.2 AAA...51 3.9.3...51...52...52 :...55...59 IP...59 IP over SDH...61 IP VPN...61 MPLSVPN...62...64...68...69...72...72 IP...75...78...78...82...86 VPN...88...91...93...95 ii
1) 2 3 IP IP IP 2.1.1 SDH ATM ATM MPLS VPNPVCSVC IP 1
2 I P IP ISO/OSI 2.1.1 IP
3
2.2.1 ISO/OSI IP 4
5 IP IP IPv4 IP IP IP - IP IP IP IP IPV4 FTP HTTPSOCKET IP TCP 2.3.1 V P N IP A A A
IP PPP IP IP IP IP IP IP IP MPLS 6
ADSLHDSLVDSL AAARADIUS SNMP IP VPN / 1 YD/T 1170-2001 2 YD/T 1171-2001 IP - IP IP IP IP IP - Y.1540 IPv4 IP Internet protocol data Communication service- IP packet transfer and QoS 7
3 YD/T 1190-2002 4 YD/T 1163-2001 5 YDC 007-2002 availability performance parameters IP IP IP RFC2764(2000) IP IP IP A Framework for IP-VPN IP-VPN IP Based Vitrual VR Private Networks BGP [Informational]( VPDN IP VPN ) IP-VPN IP-VPN IP - IP IP IP / 1 RFC959 File Transfer Protocol RFC2640 IP 8
Internationalization of the File Transfer Protocol 2 RFC2821 Simple Mail Transfer Protocol IP IP 3 4 HTTP 5 SOCKET RFC854 Telnet ProtocolTelnet IP RFC1945 IP Hypertext Transfer Protocol -- HTTP/1.0 HTTP/1.0 RFC2817 Upgrading to TLS Within HTTP/1.1 TLS RFC1928 IP SOCKS Protocol Version 5 SOCKS 5 6 RFC2402 IP Authentication Header IP RFC1828 IP Authentication using Keyed IP MD5 IP IP MD5 MD5 IP 7 TCP RFC793 Transmission Control Protocol RFC1144 Compressing TCP/IP headers for low-speed serial links TCP/IP 8 RFC768 User Datagram Protocol 9 IP 9
IP Internet Protocol 10 RFC1812 Requirements for IP Version 4 Routers IPv4 11 RFC2765 Stateless IP/ICMP Translation Algorithm (SIIT) IP/ICMP 12 RFC3260 New Terminology and Clarifications for Diffserv RFC3175 Aggregation of RSVP for IPv4 and IPv6 Reservations IPv4 IPv6 RSVP RFC3168 The Addition of Explicit Congestion Notification (ECN) to IP IP RFC2873 TCP Processing of the IPv4 Precedence Field IPv4 TCP 13 RFC2004 Minimal Encapsulation within IP IP RFC2002 IP Encapsulation within IP IP IP 14 RFC1055 Nonstandard for transmission of PPP IP datagrams over serial lines: SLIP IP SLIP RFC1332 The PPP Internet Protocol Control Protocol (IPCP) PPP 15 RFC 2328 OSPF Version 2 OSPF 2 IP IP IP 10
OSPF 16 RFC2453 RIP Version 2 RIP RFC2082 RIP-2 MD5 Authentication 17 RFC3065 BGP Autonomous System Confederations for BGP BGP RFC2918 Route Refresh Capability for BGP-4 BGP4 RFC2796 BGP Route Reflection - An Alternative to Full Mesh BGP BGP BGP RFC1772 Application of the Border Gateway Protocol BGPin the Internet BGP RFC1771 A Border Gateway Protocol 4 (BGP-4) 4 18 YD/T IP IPv4 1177-2002 19 IP 20 RFC2362 (PIM-SM) Protocol Independent Multicast- Sparse Mode (PIM-SM): 11
21 22 Protocol Specification PIMSM RFCv3618 Multicast Source Discovery Protocol (MSDP) MSDP / 1 2 3 4 RFC826 Ethernet Address Resolution Protocol IP IP RFC903 Revers Address Resolution Protocol IP RFC3022 Traditional IP Network Address IP Translator (Traditional NAT) IP RFC3021 Using 31-Bit Prefixes on IPv4 Point-to-Point Links IPv4 31 RFC2766 Network Address Translation Protocol Translation (NAT-PT) RFC3007 Secure Domain Name System (DNS) Dynamic Update DNS RFC1035 Domain names - implementation and specification RFC1034 IP Domain names - concepts and facilities 12
IP SDHIP over SDHATMIP over ATM IP over Ethernet / 1 2 Internet Protocol Version 6 over MAPOS (Multiple Access Protocol Over SONET/SDH) IPv6 MAPOS SONET/SDH 3 Generic Framing Procedure (GFP) (Dec. 2003)() / 1 Af-lane-0038.000 13
2 ATM MPOA 3 CE 4 ATM 5 ATM SDH/ Sonet LAN Emulation Client Management Specification( ) Af-lane-0057.000 LANE Servers Management Spec v1.0 1.0 Af-lane-0084.000 LANE v2.0 LUNI Interface 2.0 Af-mpoa-0114.000 Multi-protocol Over ATM Specification, Version 1.1 (MPOA1.1) ATM 1.1 Af-mpoa-0129.000 MPOA v1.1 Addendum on VPN Support ( VPN MPOA 1.1 ) Af-saa-0032.000 Circuit Emulation ( ) Af-fbatm-0139.001 Frame-based ATM Transport over Ethernet (FATE) ( ATM ) Af-fbatm-0151.000 Frame Based ATM over Sonet/SDH ( SONET/SDH ATM ) MPOA MPC MPOA MPS / / 1 14
2 3 ISO 8802.2-1994 ISO/IEC 8802.2-1998 2 4 4 RFC0895 Standard for the transmission of IP datagrams over experimental Ethernet networks( IP ) IP 2.4.4 VPN / 1 15
VPN 2 SP VPN VPN IP VPN IPTunnelIPIPSecIP MPLSVPNVPN / 1 2 16
3 4 / 1 17
2 MD5 SHA DES NULL AH / 1 YD/T BGP/MPLS draft-libin-hierarchy-pe-bgp-mpls-vpn-01.tx XXXX-2 VPN t BGP/MPLS 003 Hierarchy of Provider Edge Device in VPN BGP/MPLS VPN BGP/MPLS VPN BGP/MPLS VPN RFC3343 The Application Exchange (APEX) Presence Service (MPLS Label Stack Encoding ) RFC2547 BGP/MPLS VPNs BPG/MPLS RFC2917bis-00.txt A Core MPLS IP VPN ArchitectureNov.2000 MPLS IP-VPN 18
2 MPLS-VPN draft-mpls-vpn-mib-00.txt MPLS/BGP Virtual Private Network Management Information Base Using SMIv2Nov.2000 RFC 3032 MPLS Label Stack Encoding MPLS 3 MPLS-VPN RFC 2702 VPN Requirements for Traffic Engineering Over MPLS MPLS RFC 3037 LDP Applicability. RFC 3346 Applicability Statement for Traffic Engineering with MPLS. MPLS 4 MPLS-V draft-mpls-l2vpn-02.txt MPLS PN MPLS-based Layer2 VPNsNov.2000 MPLS VPN GRE /L2TP IPSEC MPLS VPN VPN () QOS CPU MPLS VPN 19
2.4.5 IP / 1 GB/Txxxxx- 2003 IP RFC3344 IP IP / 1 GB/Txxxxx. 01-2003 IP RFC2003 IP Encapsulation within IP RFC2004 Minimal Encapsulation within IP RFC1701 Generic Routing Encapsulation (GRE) RFC3024 Reverse Tunneling for Mobile IP IP / 20
1 GB/Txxxxx. IP RFC1256 IP 02-2003 ICMP Router Discovery Messages RFC 768 IP User Datagram Protocol RFC1700 Assigned Numbers RFC2794 Mobile IP Network Access IP Identifier Extension for IPv4 RFC1112 Host Extensions for IP Multicasting RFC826 Ethernet Address Resolution Protocol RFC925 Multi-LAN Address Resolution / 4 GB/Txxxxx. 03-2003 IP RFC2006 The Definitions of Managed Objects for IP Mobility Support using SMIv2 / 21
5 GB/Txxxxx. IP RFC 2104 IP 04-2003 HMAC: Keyed-Hashing for Message Authentication HMAC-MD5 RFC1321 IP The MD5 Message-Digest Algorithm RFC1750 Randomness Recommendations for Security RFC1305 Network Time Protocol (Version 3) Specification, Implementation 2.4.6 IP IP IP xdsl WLAN 22
1 YD/T RFC3031 MPLS 1162.1-2001 MPLS Multiprotocol label switching Architecture Jan.2001 MPLS MPLS MPLS 2 YD/T ATM RFC3035 ATM MPLS 1162.2-2001 MPLS MPLS using LDP and ATM VC Switching ATM 3 YD/T MPLS 1162.3-2001 MPLS 1 YD/T 1160-2001 - 23
2 YD/T 1240-2002 -- 3 YD/T 1099-2001 4 YD/T XXXX-2002 5 YD/T 1141-2001 6 YD/T XXXX-2003 7 YD/T XXXX-2003 8 IEEE 802.3a 10BASE2 9 IEEE 802.3I 10BASE-T 10 IEEE 802.3j 10BASE-F 11 IEEE 802.3u 100BASE-T 12 IEEE 802.3z 13 IEEE 802.3ab 1000BASE-T 24
14 IEEE 802.3ae 10G 100BASE-TX 100BASE-FX 1000BASE-LX 1000BASE-SX 1000BASE-T 1 GB15629. 11-2003 2 GB15629.1101-2003 5GHz 3 GB15629. 1102-2003 2.4GHz 4 GB15629. 1103-2003 MAC 5GHz 2.4GHz IEEE 802.11e Wireless LAN Medium Access Control (MAC) and Physical Layer (PHY) MAC specificationsmac Enhancements for Quality of Service 25
5 GB15629. IEEE 802.11f 1104-2003 Wireless LAN Medium Access Control (MAC) and Physical Layer (PHY) specifications Recommended Practice for Inter Access Point Protocol 6 GB15629. IEEE 802.11g 1105-2003 Wireless LAN Medium Access Control (MAC) and Physical Layer 2.4GHz (PHY) specificationsstandard for (20+ Mbps) Higher Rate (20+ Mbps) Extensions in the 2.4GHz Band 7 IEEE802.11h-2003 5GHz 8 GB15629. IEEE 802.11i 1106-2003 Wireless LAN Medium Access Control (MAC) and Physical Layer MAC (PHY) specifications MAC Enhancements for Enhanced Security 9 GB15629.1107- IEEE 802.11k 2003 Wireless LAN Medium Access Control (MAC) and Physical Layer (PHY) specifications Radio Resource Measurement Enhancements GB 15629.1104-2003 2.4GHz (20+ Mbps) MAC xdsl ADSLHDSL VDSL 1 YD/T 118 8-2002 ATM ADSL 26
2 YD/T 1147-2001 ADSL 3 YDN 078-1998 - ADSL 4 YDN 059-1997 (HDSL) ( ) 5 YD/T 1239-2002 -- VDSL 6 YDN 056-1997 (HDSL)( ) 7 YD/T 1185-2002 SHDSL 8 YD/T XXXX-2004 DSL 9 G.992.1 10 27
2 3 4 2.4.7 2.4.8 / 28
1 2 29
3 SNMP 4 / 1 RFC 2863 The Interfaces Group MIB using SMIv2 SMIv2 IP IP 30
RFC 2096 CIDR IP Forwarding Table MIBIP IP CIDR CIDR IP RFC 2013 UDP SNMPv2 Management Information Base for the User Datagram Protocol using SMIv2 SMIv2 UDP SNMPv2 RFC 2012 SNMPv2 Management Information Base for the Transmission Control Protocol using SMIv2 SMIv2 TCP SNMPv2 RFC 2011 SNMPv2 Management Information Base for the Internet Protocol using SMIv2 SMIv2 IP SNMPv2 RFC 1850 OSPF Version 2 Management Information BaseOSPF V2 RFC 1724 RIPv2 MIB RFC 1657 Definitions of Managed Objects for the Fourth Version of the Border Gateway Protocol (BGP-4) using SMIv2 TCP TCP IPICMP IP IP IP IP OSPFv2 RIP2 v2 RIP BGP-4 BGP BGP BGP-4 31
BGP-4, RADIUS, RADIUS WWW Modem DNS RFC 2790 Host Resources MIB 2000 RFC 2789 Mail Monitoring MIB 2000 Message,2000 Transfer AgentsMTA RFC 2619 RADIUS Authentication Server MIB 1999 RADIUS,1999 RFC 2618 RADIUS Authentication Client MIB 1998 RADIUS,1998 RFC 2594 WWW Definitions of Managed Objects for WWW DTP Services1999 (WWW,1999) DTP FTP/HTTP WWW RFC 1696 Modem Modem Management Information Base (MIB) using SMIv2 1998 Modem,1998 RFC 1611 DNS DNS Server MIB Extensions1994DNS 32
,1994 ITU-T H.341 Multimedia management information base1999,1999 H.323 H.320 IP IP CMIP CORBA SNMP IP IP / 1 RFC3588 Diameter Base Protocol AAA AAA 33
2 RFC3575 IANA Considerations for RADIUS (Remote Authentication Dial In User Service) 3 RFC3579 RADIUS (Remote Authentication Dial In User Service) Support For Extensible Authentication Protocol (EAP) 4 RFC3539 Authentication, Authorization and Accounting (AAA) Transport Profile RFC2903 Generic AAA Architecture RFC2869 RADIUS Extensions RADIUS RFC2868 RADIUS Attributes for Tunnel Protocol Support RADIUS RFC2866 RADIUS Accounting RADIUS RFC2865 Remote Authentication Dial In User Service (RADIUS) RFC2402 IP Authentication Header IP RFC2138 Remote Authentication Dial In User Service (RADIUS) RFC1994 PPP Challenge Handshake Authentication Protocol (CHAP) PPP IEEEStd 802.1x Network Access Control Based on Ports IP 34
RFC1828 IP Authentication using Keyed MD5 MD5 IP RFC1704 On Internet Authentication YD/T 1170-2001 IP - IP IP IP IP YD/T 1171-2001 IP - IPv4 IP QoS IP IP YD/T 1190-2002 IP IP-VPN IP IP IP-VPN VR BGP VPDN 35
VPN IP-VPN IP-VPN YD/T 1163-2001 - IP IP IP YDC 007-2002 IP RFC959 File Transfer Protocol IP RFC959 RFC2821 Simple Mail Transfer Protocol IP RFC2821 RFC1945 Hypertext Transfer Protocol -- HTTP/1.0 HTTP/1.0 RFC2138 Remote Authentication Dial In User Service 36
(RADIUS) RFC1928 SOCKS Protocol Version 5 SOCKS 5 RFC793 Transmission Control ProtocolIP RFC793 RFC768 User Datagram Protocol Internet Protocol IP RFC1812 Requirements for IP Version 4 Routers IPv4 RFC1332 The PPP Internet Protocol Control Protocol (IPCP) PPP RFC 2328 OSPF Version 2 OSPF 2 37
EFC2328 RFC2453 RIP Version 2 RFC1771 A Border Gateway Protocol 4 (BGP-4) 4 RFC826 Ethernet Address Resolution Protocol IP IP IP RFC791 IP IP RFC903 Reverse Address Resolution Protocol IP RFC3022 Traditional IP Network Address Translator (Traditional NAT) IP IPv4 IP RFC1035 Domain names - implementation and specification IP 10 38
88665544 10 8866 5544 5544 108866 IP IP RFC 1035 tinghua.edu.cntinghua edu cn IP COM EDU GOV RFC1035 IP 3.3.1 IP over SDH 39
100Base-X/1000Base-X IEEE802/ VPN 40
YD/T XXXX-2003 BGP/MPLS VPN BGP/MPLS VPN MPLS VPN PE SP PE CE MPLS VPN MPLS L3 VPN MPLS L2 VPNMPLS L3 VPN VPN CE SITE PE VPN 41
BGP/MPLS VPN MPLS L2 VPN VPN CE VPN BGP/MPLS VPN BGP/MPLS VPN VPNA VPNA VPNA MP-IBGP 10.255.245.48 LDP LDP 10.255.245.47 VPNB VPNB 42
HUB-CE ge-0/0/0.0 ge-0/0/0.1 fe-1/1/2.0 fe-1/0/0.0 fe-1/1/0.0 SPOKE-CE 10.255.14.174 fe-1/0/1.0 SPOKE-CE 10.255.14.180 10.255.14.182 VPN CE PE VPN ASBR ASBR PE CE VPN AS PE AS PE 43
MPLS VPN MPLS VPN AS MPLS VPN IP 3.5.1 GB/Txxxxx-2003 IP IP IP IP IP IP RFC3344 IPv4 IP IP IP 44
YD/T 1162.1-2001 MPLS MPLS MPLS MPLS MPLS YD/T 1099-2001 YD/T 1160-2001 - 45
GB 15629.11-2003 46
1 ATM STM1 10/100Mbps E1 2 ATM STM1 STM-4 POS STM1 STM-4 / 3 : FRAME RELAY LMI ANSI T1.617 Annex D/ITU-T Q.933 Annex A PPPOE PPPOA PPPIFR PPP LAN IEEE 802.3/IEEE 802.3u FRAME RELAY RFC 1490 AAL5 RFC 1483 LAN IEEE 802.3zL2TP IP over SDH RFC2615 47
IP over WDM TCP/IP IP IPSec RIP v2 / OSPF v2 /BGP4 RADIUS 48
NMS SNMP SNMP 3.8.1.1 Agent/Manager RFC 2863 The Interfaces Group MIB using SMIv2 SMIv2 RFC2863 IP IP 49
1 2 3 4 5 6 7 8 9 * 8 # 3.8.1.1 IETF RFC2790 P C P C Mode m Mode m PSTN/ISDN IETF RFC1696 IETF RFC2127 IETF RFC2495 IETF RFC2618 A S IETF RFC2790 IETF RFC2790 IETF RFC2790 IETF RFC1611 IETF RFC2789 IETF RFC2594 DNS AAA IETF RFC2618 IETF RFC2619 3.9.1 AAA RFC3588 Diameter Base Protocol RADIUS IETF AAA AAA Diameter 50
3.9.2 AAA RFC2903 Generic AAA Architecture AAA RFC3539 Authentication, Authorization and Accounting (AAA) Transport Profile AAA 3.9.3 RFC2865 Remote Authentication Dial In User Service (RADIUS) RFC3575 IANA Considerations for RADIUS (Remote Authentication Dial In User Service) IP 51
52
IP IP 53
2 2 VLAN 2 54
: Access Control List CAR Committed Access Rate CBWFQ Class-Based Weighted Fair Queuing 55
CRTP Compressed Real-time Transport Protocol GTS Guaranteed Traffic Service 56
LFI Link Fragmentation and Interleaving LLQ Low-Latency Queuing 57
) Secure 58
UDP User Datagram Protocol nicast Reverse Path Forwarding WRED Weighted Random Early Drop IP IP IP YD/T11702001 IP 1 IP 59
2 3 IP over SDH IP over ATM 4 Email SMTP FTP HTTPVPN PPTP L2TP GREIP IPSec 5 IP IP IP 6 QoSIP 7 60
IP over SDH IP VPN 61
MPLSVPN VPN Sites IP BGP VPN MPLS VPN VPN VPN RFC1918 62
MPLS/BGP VPN VPN VPN RD VPN VPN VPN VPN BGP/MPLS VPN VPN BGP RFC2547 3 VPN VPN VPN PE RT PE VPN VPN PE VPN-IPv4 RD VPNs VPN RD VPN-IPv4 VPN-IPv4 PE /*RD /draft-ietf-13vpn-rfc2547bis-01 Type Field 2-byte Administrator Field Assigned Number Field Assigned Number RD Type 0 ASN2-byte Assigned Number Field 4-byte 63
Type 1 IP 4-byte Assigned Number Field 2-byte AS. RD VPN 8 RD 2 ADM 2 64
65
( 66
67
68
1 69
IP IP IP MAC IP MAC 2 PPPPPPoE WEB 802.1x PPP PAP CHAP IP PPPoE PPPoE CHAP WEB Web DHCP IP Web Portal 802.1x 802.1x IEEE (port based net access control) 3 VLan Vlan 70
IP DHCP server 4 IP MAC MAC MAC MAC IP MAC 5 ICMP TCPUDP ICMPHTTPSMTPRSTP IP 6 IP 71
QOS 72
PPP Server Radius Radius 73
74
IP IP NAPT NAPT 2 2 NAPT Mobile IP 75
LAN 3 3 NAPT Mobile IP IP IP IP IP IP IP IP 1 Tunneling 76
2 3 2 OSI PPTP L2TP L2F 2 2 PPP 3 OSI IPIPIP over IP IPSec 3 IP IP IP IP IP IPIP IPUDP UDPinIP IP 2 IP ARP ARP IP IP 77
TCP 3 IP IP IP 3 IP QOS (VPN) 78
() 3 155Mbit/s POS 79
3 GE GE 4 96 MPPs POS/ATM/FE/GE MPLS VPN 2.4 Mpps POS\CPOS\ATM\GE\E1 RIP\OSPF\BGP MPLS VPN E1 SMTPESMTPPOP3 IMAP4MIME LDAP Web-Mail 80
5000 IP IP IP 2000 16 PCM WEB 81
IPTV IPTV 60 82
83
3 MPLS LER( ) LSR P LSP GW GKIAD SoftX VPN VPN VPN QoS 84
3 PE COS PQ CQWFQ LSP QoS 85
2.5G 622M DNS DPT/RPR 100M 155M 5 86
VPNVoIPVideo over IP VoIP, Video over IP 87
VPN 6 88
7 IP 89
8 VPN 90
10 91
DNS IPSec IPSec 10 IPSec VPN 92
93
11 94
95
RFC1945 HTTP RFC959 FTP RFC2821 SMTP RFC2138 RADIUS RFC2903(3539) AAA RFC1035 RFC1925 SOCKs RFC2570 RFC2407(2408) RFC2403(2404) RFC2863 MD5DESNULL RFC793 TCP RFC768 UDP RFC791 IP YD/T10972001 RFC3022 RFC1812 IPv4 YD/T1190 2002 RFC2764 YD/T10962001 YD/T1162-2001 MPLS IP VPN RFC1771 BGP4 RFC2328 RFC2453 RFC1701/1702 OSPF RIP GRE( VPN RFC1332 RFC903 RFC826 PPP RFC2661 YD/Tx xxx-20 03 BGP/ MPLS VPN YD/T1170 2001 IP YD/1171 2001 IP YD/T1190 02002 IP VPN YD/T11002001 SDH IP ITUTG.783G.709 G.703 SDH YD/T1160 GB/T15629.3-1995 YD/T11482001 YD/Txxxx.1-2003 YDN0781998 ADSL PSTN 1