Professional Documents
Culture Documents
;
w
]
ib
i
I !' ^l
T r s chnh T r s chnh
Mng ring o
<Q
5
CQ
o
Hnh 2.1: Mng ring, mng chung v mng ring o
O
2.1.2 Phn loai
Phn ny a ra mt s nh ngha v cc loi VPN v cc tiu
ch phn bit chng. Khi la chn cc tiu ch ngi ta phi
chp nhn mt s tha hip no v kh c th s dng mt tiu
ch c th a ra mt loi VPN hon ton khc bit vi cc loi
khc. Khi thc hin phn loi chng ta s thy, phn loi VPN theo
mt tiu ch ny li c th bao hm cc VPN c phn loi theo
mt tiu ch khc.
2.1.2.1 Phn loai theo m hnh kt ni
- Mng ring o truy cp t xa (Remote Access VPN): Trong
m hnh ny ngi s dng thay v quay s trc tip vo mng ca
doanh nghip s s dng kt ni Internet to ra mt kt ni VPN
vo mng ca doanh nghip. Hai im cui ca ng hm
(turniel) s chnh l my tnh v thit b truy cp mng ring o t
ti mng doanh nghip. y l m hnh c p dng cho ngi i
cng tc xa, cng tc vin, V.V....
- Mng ring o t v tr n v tr (Site-to-Ste VPN)'. Trong
m hnh ny mi mt v tr u c cc thit b truy cp mng
ring o, cc thit b ny thng c cc kt ni TC tip vo
Internet. Hai im cui ca ng hm chnh l hai thit b truy
cp mng ring o. M hnh ny c p dng kt ni mng
doanh nghip vi mng ti cc chi nhnh hoc mng doanh nghip
vi mng ca i tc.
2. . 2.2 Phn loi theo quyn truy nhp
- Mng ring o trong (Intranet VPN): L khi nim ch mt
mng ring o c to ra ch dnh ring cho ngi s dng ca
36____________________ Cng ngh MPLS p dng trong mng MEN (MAN-E)
doanh nghip, n hon ton khng lin quan n m hnh hay cng
ngh c p dng.
- Mng ring o ngoi (Extranet VPN): Cng nh mng ring
o trong, loi mng ny khng lin quan n m hnh kt ni hay
cng ngh c p dng, m chi l mt khi nim ch mt mng
ring o trong c m rng quyn truy nhp cho ngi s dng
bn ngoi doanh nghip, v d khch hng hay nh cung cp, V.V....
2.1.2.3 Phn loi theo nguyn tc hot ng
- Mng ring o an ton (Secure VFN): Mng ring o an ton
bao gm tt c cc loi mng ring o m trong tnh ring t
c m bo nh vo cc k thut an ninh, m ha. Thuc v
phn loi ny bao gm cc mng ring o s dng cc giao thc
GRE, L2TP, PPTP, IPSec, V . V . . . .
- Mng ring o tin cv (Trusted VPN): Mng ring o tin cy
bao gm tt c cc mng ring o m trong tnh ring t c
m bo thng qua vic duy tr s ton vn ca knh thng tin.
Thuc v phn loi ny bao gm tt c cc mng ring o s dng
FR, ATM, MPLS L2, MPLS L3, V.V....
2.1.2.4 Phn loi theo cng ngh p dng
Cch thc phn loi ny da vo mt cng ngh hay mt giao
thc c th c p dng to ra ng hm. Hai ci tn c
trng nht trong cc loi cng ngh mng ring o c lit k
di y.
- Mng ring o da trn giao thc an ton mng IPSec
(IPSec VPN)
Chng 2: Mng ring o _____________________ ^
- Mng ring o da trn chuyn mch nhn a giao thc
MPLS (MPLS VPN)
2.1.2.5 Phn loai theo m hnh OSI
- Mng ring o lp 2 (L2 VPN): L tt c cc mng ring o
c to ra da vo cc cng ngh, cc giao thc hot ng lp 2
ong m hnh OSI. Mt s loi mng ring o ph bin ieo cch
phn loi ny l cc mng ring o da trn ATM, L2TP, PPTP.
- Mng ring o lp 3 (L3 VPN): L tt c cc mng ring o
c to ra da vo cc cng ngh, cc giao thc hot ng lp 3
trong m hnh OSI. Mt s cc loi mng ring o ph bin theo
cch phn loi ny l cc mng ring o da trn giao thc cng
bin/chuyn mch nhn a giao thc (BGP/MPLS), giao thc an
ton mng (IPSec).
2.1.2.6 Phn loi theo m hnh qun lt khai thc
- Mng ring o khch hng khai thc (customer-provisioned
VPN): i vi cc mng ring o ny khch hng phi t qun l
v khai thc mng ring o ca mnh bao gm c vic qun l v
cu hnh cc thit b u cui. Nh cung cp y ch ng vai tr
l nh cung cp kt ni.
- Mng ring o nh cung cp khai thc (provider-provisioned
VPN): i vi cc mng ring o loi ny, nh cung cp s qun l
v khai thc ton b mng bao gm c vic cu hnh cc thit b
u cui. Mng ring o y c coi nh l mt dch v c
nh cung cp mang n cho khch hng. Hnh 2.2 a ra s
phn loi mng ring o theo tiu ch ny. Ngi ta c th thy
ngay rng cc tiu ch phn loi khc nh m t cc phn
trc li c trn ln trong tiu ch phn loi ny.
38____________________ Cng ngh MPLS p dng trong mng MEN (MAN-E)
Chng 2: Mng ring o 39
VPWS: Vitual Private Wire Service: Dch v cp ring o
VPLS: Vltual Private LAN Service: Dch v LAH ring o
IPLS: IP ony ^N - like Service: Dch v IP-^N tng thch
BGP/MPLS: Border Gateway Protocx)l/Multi Protocol Label Switch Internet
Protocol: Giao thc cng bin/ chuyn mch nhn a giao thc
Vltual Router: B nh tuyn o
!P See: IP Security: Giao thc mng an ton
Hnh 2.2: Phn loi mng ring o nh cung cp khai thc
2.2 NGUYN TC HOAT NG
#
Nh chng ta bit, mt mng ring o l s m rng ca
mt mng ring bao gm cc iin kt kt ni vi cc mng chia s
hoc mng cng cng. R rng l khch hng s dng mng ring
o i hi phi c mt phng thc no m bo tnh ring t
khi d liu ca khch hng di chuyn qua mt mng cng cng.
Ngoi vic m bo tnh ring t cho thng tin, cc k thut mng
ring ang tn ti c xy dng trn cc cng ngh lp 1 hay lp
2 u c ch nng m bo cht lng dch v. Cc ng thu
ring hoc cc ng quay s u m bo bng thng v tr,
trong khi cc cng ngh kt ni nh FR (Frame Relay) hay ATM
40 Cng ngh MPLS p dng trong mng MEN (MAN-E)
(ASynchronouns Transfer Mode) cn c cc c ch rng ri m
bo cht lng dch v.
c th thc hin c iu cc mng ring o phi c
trin khai nh vo mt hnh thc no ca k thut to ng
hm, cc khun dng gi v/hoc a ch s dng cho mng
ring o khng lin quan n ci c s dng nh tuvn cc
gi xuyn qua ng hm qua mt mng xng sng. Cc ng
hm nh vy c th mang li mt mc an ninh thc t no ,
mng chung c s drig nh mng ring.
_ im cui ng hm ___
Thit bj
mng ring o
Mng trung gian
Thit b
.......... ^7)
ng hm
Hnh 2.3: Khi nim ng hm
Mt ng hm kt ni hai im cui mng ring o chnh l
thnh phn c bn nht m t ngi ta c th xy dng nn cc
loi mng ring o khc nhau. Mt ng hm IP hot ng chng
ln qua mt mng xng sng IP v lu lng c gi qua mt
ng hm l hon ton m i vi mng xng sng pha di.
Nh th mng xng sng IP c s dng nh l cng ngh lp 2
v Tig hm to ra mt lin kt im ti im nh l mt lin kt
ring. C nhiu k thut to Tig hm khc nhau nh IP/IP
(IP ng gi trong IP), GRE (Generic Routing Encapsulation: ng
gi nh tuyn chung), PPTP (Point to Point Tunneling Protocol:
giao thc ng hm im - im, L2TP (Layer 2 Tunneling
Protocol: giao thc ng hm lp 2), IPSec v MPLS [6]. Cun
sch ny cp n k thut s dng MPLS to ra cc mng
ring o.
2.3 SO SNH MT s M HNH MPLS
I
124 Cng ngh MPLS p dng trong mng M&4 (MAN-E)
- Lp mng bin khch hng (Subscriber Edge): ng vai
tr bin mng pha khch hng, cung cp kt ni ti lp truy cp
ca nh cung cp dch v v cung cp dch v cho nhng ngi
s dng bn trong mng.
Phng n ny s trang b cho vin thng tnh/thnh ph c
s h tng cn thit hon thin phn lp tp trung lu lng
(IP/MPLS aggregation) trong kin trc mng Carrier Eiemet
tng th, kt ni ln BRAS v tch hp vo mng core IP/MPLS
ca VNPT, cng nh kt ni td cc IP DSLAM, UMTS, v.v...,
ang s dng cung cp dch v xung khch hng.
6.2.7 e xut mt s vn k thut
6.2.7.1 Thit b phn cng
Ta c th xem xt nghin cu i vi Vin thng H Ni.
Mt s thit b n mng MEN ca Vin thng H Ni c
cho bng 6.1.
Bng 6.1: Cc thit b trn mng MEN ca Vin thng H Ni
Chc
nng
Thit b a im lp t
Core
switch
Cisco 7609
02x SUP 720 3BXL
02x PS 2500 w (DC)
SIP 600 +2x1 OGE
SIP600 + 10XGE
ws 6724 SFP
4 thit b c lp t t cu Giy,
inh Tin Hong, c Giang v
Thng nh
Chng 6: Thc th trin khai ti Vit Nam 125
Access
switch
Cisco 7609
02x SUP 720 3B
iJ2xPS 2500 w (DC)
SIP 400 +2x1 GE
ws 6724 SFP
ws 6748 GE-TX
16 thit b c lp t ti cu Giy,
inh Tin Hong, c Giang,
Thng inh, Gip Bt, Trn Kht
Chn, Nguyn Du, Tru Qui, Ph L,
ng Anh, Ch Da, Hng
Vng, Kim Lin, Lng Trung, Nam
Thng Long, Thanh Tr.
6.2.7.2 Giao thc nh tuyn
Cc giao thc nh tuyn c s dng trn mng bao gm
IGP: dng giao thc OSPF (mang cc thng tin v cc
tuyn mg ni b v cc a ch loopback ca mng).
EGP: S dng giao thc BGPv4.
VPN: S dng giao thc MP - BGP.
6.2.7 Mt phng a ch
Hin ti Vin thng H Ni ang s dvmg di a ch IP
ring 172.16.0.0/12, ch dnh cho mc ch qun l thit b
trong mng (qua giao thc SNMP hoc Telnet).
V d: C th phn b nh sau:
Cc di a ch qun l IP DSLAM
- Vng TDH
- Vng DGG
- Vng CGY
- Vng DTH
172.24.0.0/12
172.23.0.0/12
172.22.0.0/12
172.21.0.0/12
Di a ch qun l li v truy nhp chuyn mch (Siemens)
v BRAS;
- 172.20.0.0/12
Khi thc hin mng MEN mi, cc thit b chy trn L3
P, v vy cn quy hoch cc di a ch b sung (high level)
nh sau:
- a ch s dng li cho cc thit b chuyn mch MEN
- a chi cho cc kt ni lin kt im - im WAN gia
cc chuyn mch MEN
- a chi qun l cho cc IP DSLAM v BRAS
- a ch cp pht cho khch hng (dch v E-Line v
E-LAN).
- a ch cp pht cho khch hng dng dch v L3 VPN.
C th:
- Gi nguyn a ch qun l ca cc IP DSLAM ti cc vng
- a ch qun l BRAS: 172.20.0.0/12
- a ch loopback cho cc chuyn mch MEN: 172.31.0.0/12
- a ch cho cc kt ni ng WAN: 192.168.0.0/24
6.3. CUNG CP DCH v MNG RING o TI VIN
THNG TNH, THNH PH
6.3.1 Cu hnh mt VPN cho khch hng
6.3.1.1 T khch hng n PE
Nh m t phn trn, cc thit b BRAS t ti Vin
thng cc tnh s ng vai tr cc PE trn mng. Hin ti, n
mng c 04 BRAS s dng sn phm ERX 1410 ca hng
Juniper.
126_________________Cng ngh MPLS p dng trong mng MEN (MAN-E)
Chng 6: Thc th trin khai ti Vit Nam 127
Trn thit b BRAS, chng ta to ra mt nh tuyn v
chuyn tip VRF cho mt bng VPN no . Cc VRP ny ng
vai tr nh cc router o kt ni cc v tr VPN lin kt trc
tip n n. Cc v tr VPN c kt ni n VRF ny thng
qua cc ng xDSL (ADSL hoc SHDSL). Pha khch hng,
MODEM xDSL kt ni n mng ni b ca khch hng ti v
tr VPN thng qua giao din EthemePast Ethernet (cn c
gi l giao din LAN trn m-em), giao din xDSL (thng c
gi l giao din WAN) c kt ni n PE ca nh cung cp.
VNP Site 1
DSLAM
V Tinh
DSLAM
HUB
Hnh 6.5: M hnh kt ni t v tri n PE
Cc thit b ghp knh truy nhp (DSLAM) c chc nng
to mt knh ATM ing sut kt ni t PE n CE. Knh
ATM ny hot ng nh mt lin kt mng din rng WAN.
Lin kt ATM ny c to ra chy trn cc lp vt l khc
nhau t CE n PE thng qua cc DSLAM. Do khng phi bt
k mt DSLAM no cng c kt ni trc tip vo PE nn
tuyn ng t CE n PE c th phi i qua nhiu DSLAM
khc nhau, cc DSLAM ny c u ni theo m hnh thc
nc (hnh 6.5).
128_________________Cng ngh MPLS p dng trong mg MEN (MAN-E)
Site 1
Ch 1483
Routed IP
l A N IP
10.10.1 1/24
WAN
Interface
Y R F
Site 2
Ch 1483
Routed IP
LAN IP
10.10.2 1/24
WAN
interface
Hnh 6.6: M-em hot ng ch b h tuyn
Thit b u cui khch hng c th hot ng ch
nh tuyn hoc cu ni, nh tuyn trung gian l nt VRF nm
trn BRAS, cc kt ni WAN l cc kt ni ATvl t CE n
BRAS thng qua cc DSLAM. Trn hnh 6.6 lm hnh kt
ni khi cc thit b u cui khch hng hot ng ch
nh tuyn.
Cu hnh trn thit b BRAS
1. To mt ip vrf, v d l myvpn
BRAS#confg t
BRAS(config)#ip vrf myvpn
2. Trong VRF myvpn to mt loopback interface
BRAS(config)#virtual-router :myvpn
BRAS:myvpn(config)#interface loopback 0
BRAS :myvpn(config-if)#ip
address 172.16.1.1 255.255.255.255
3. Cu hnh mt subinterface ATM ti khch hng;
BRAS(config)#interface atm 10/1.1101110999 point-to-
point
BRAS:myvpn(config-if)#atm pvc 1101110999 11 999
aalSsnap 0 0 0
4. Nu cu hnh ch bridge, cn cu hnh cho giao din:
BRAS:myvpn(confg-if)#encapsulation bridge 1483
5. t a ch IP cho giao din ATM ny:
BRAS:myvpn(config-if)#ip
address 192.168.1.1 255.255.255.252
Hoc gn a ch IP ca giao din loopback cho giao din
ATM ny:
BRAS;)#ip route 10.10.1.0 255.255.255.0 192.168.1.
myvpn(config-if)i^ip unnumbered loopback 0
6. nh tuyn tnh t BRAS td cc lp mng pha khch hng
(LAN v WAN):
BRAS:myvpn(config)#ip route 172.16.1. 255.255.255.255
192.168.1.2 atm 10/U101110999
BRAS:myvpn(config2 atm 10/1.1101110999
Cu hnh knh ATM thng sut n khch hng trn
cc thit b DSLAM
Cc thng s lu lng phi thng nht trn ton tuyn.
Cc thng s VPI, VCI u khch hng phi trng khp vi
tham s cu hnh trn MODEM, cc thng s ny ti giao din
Chng 6: Thc th trin khai ti Vit Nam_________________________129
cui cng (trong chui cc DSLAM) ng ln phi trng
khp vi cc thng s c cu hnh cho giao din ATM trn
thit b PE.
Cu hnh tai u cui
Cu hnh MODEM vi cc thng s VPI, VCI, a chi
WAN IP, Gateway t nh cung cp, chn Encapsulation l 1483
IP c nh tuyn (hnh 6.7).
WAN- WANSetup - ProHie 2
Name myvpn
130________________ Cng ngh MPLS p dng trong mng NEN (MAN-E)
Aciiy ( Yes *!
Mod* [ Routing 3
Em:p#uIIoo f 1483 Rout ed IP
MoHipl** tTc~3
Virtual CifctMt lO
VPI f
vct p6
ATM OoS Typ (uBR
c* Rt
Peak Can Rt p ci)/tac
Sustain Cfl Rat |o ceil/sac
MaximumBurst Siza |o
IP Adrfni
P Addmas {mltoTz
Subnat Mask |256 255 255 252
Galaway |192 168 1t
Back I Appiy I D>ata I Raaat I
Hnh 6.7: cu hnh ti u cui khch hang
6.3.1.2 Lin kt gia cc VRF trn cc thit b PE
Do cc thit b BRAS c cu hnh h tr MPLS v
kt ni vi mng MPLS ca VNPT nn cc ng hm MPLS
c to ra kt ni cc thit b BRAS vi ihau. cc
VRP c phn b c bng nh tuyn ta cn cu hinh cc thng
s RD v RT cho chng. Tham s RD l tham s phn bit
cc VRP trn cng mt iit b PE. Da vo than s ny, cc
VPN khc nhau s dng cc VRF khc nhau c th s dng
cng mt lp a ch m khng b s xung t. Tham s ny
thng c cu thnh t mt ASN (c qun l bi lANA)
v mt s (c qun l bi nh cung cp). Trong v d trn
65400 l ASN ca VPNT v 1000 l mt s c gn bi nh
cung cp (Vin thng H Ni).
BRAS(config)#ip vrf myvpn
BRAS(config)#rd 65400:1000
Tham s RT cng c nh dng ging nh tham s RD,
di dng ASN: number hoc di dng IP address; number.
Tham s RT export l tham s c gn vo ong bn tin qung
co cc lp mng c gi i qua BGP. Tham s RT import
c VRF dng cp nht vo bng nh tuyn ca mnh cc
b nh tuyn trm cc bn tin qung co c RT export trng
vi RT import ca n.
BRAS:myvpn(config)#route-target export 65400:10000
BRAS:myvpn(cong)#route-target import 65400:10000
Trong ng hp cu hnh theo m hnh full-mesh (hn
hp), hai tham s RT ny ging nhau nn ta c th thay hai
dng lnh trn bng lnh:
BRAS:myvpn(config)#route-target both 65400:10000
Trong trng hp cu hnh theo m hnh hnh cy (hub-
and-spoke), hai tham s ny khc nhau, do cn cu hnh y
nh trn.
VRF c th qung co cc lp mng ca minh thng
qua BGP, ng thi vi vic cu hnh cc tham s RD v RT,
cn cu hnh BGP VPN c th qung co cc lp mng ca
mnh thng qua BGP.
Chng 6: Thc th trin khai ti Vit Nam________________________ 131
BRAS(config)#router bgp 65400
BRAS(config)#address-family ipv4 vrf myvpn
BRAS :myvpn(config)#redistribute static
BRAS :my vpn(confg)#redistribute connected
Cc bc cu hnh va c m t trn phi c ic hin
ti tt c cc BRAS c kt ni vi bt k mt v tr no ca VPN.
6.3.2 Mt s m hnh cung cp dch v ti Vin thng tnh,
thnh ph
6.3.2.1 Mng ring o v truy nhp Internet trn cng mt
ng xDSL
Kt hp cung cp hai dch v, mng ring o v truy nhp
Internet trn cng mt i cp ng. Vic ny s tit kim cho
khch hng khi ch cn s dng mt thit b MODEM u cui.
Vic cu hnh cho cc my tnh cng d dng hcm do ch c mt
cng ngm nh (default gateway). Tuy nhin vic cu hnh thit
b MODEM v cc thit b pha nh cung cp dch v c phc
tp hn.
To hai knh ATM t thit b BRAS n khch hng, ng
vai tr nh hai kt ni WAN n b nh tuyn u cui. Hai
lin kt logic ny cng chy trn lin kt vt l xDSL t u
cui khch hng n b ghp knh DSLAM, ti y, chng
c to kt ni cho vo hai lin kt ATM t DSLAM ln thit
b BRAS. Hai knh ATM ny cng vi cc knh ATM khc
cng t DSLAM ln thit b BRAS c ghp chung vo v
chy trn lin kt vt l t DSLAM n BRAS. Ti thit b
BRAS, c hai giao din con ATM c to ra kt cui hai
132________________Cng ngh MPLS p dng trong mng MEN (MAN-E)
Chng 6: Thc th trin khai ti Vit Nam 133
knh ATM ny. Knh ATM c dng cho dch v mng
ring o s c kt cui ti giao din con ATM trong VRF
tng ng vi mng ring o . Knh ATM dng cung
cp dch v Internet s c kt cui ti router o dng cho
truy cp Internet.
Mng LAN
Khch hng
WAN 1
PPPoE/
PPPoA
WAN 2
Routed
1483 IP
Hnh 6.8: Hai kt ni ng thi t mt thit b u cui
Hnh 6.8 m t r hn vic kt hp ny. v vt l, hai kt
ni WAN 1 v WAN 2 bt u v kt thc trn cng giao din
vt l v chng cng c ghp chung cng chy trn mt
rng vt l t MODEM khch hng n thit b BRAS. Tuy
nhin, v logic, l lp 3, y l hai lin kt c lp bt u hai
giao din ATM khc nhau trn MODEM v kt cui trn hai
router khc .nhau pha nh cung cp dch v.
6.3.3.2 M hnh ful-mesh
Trng hp thng thng v ph bin nht, chng ta mun
t bt c mt v tr no trong VPN no cng c th kt ni n
trc tip n tt c cc v tr cn li. M hnh ny chnh l m
hnh fiill-mesh (hnh 6 9). Tt c cc VRF thuc VPN u c
b tham s RT nh nhau vi hai tham s RT export v RT
import l trng nhau. Do hai tiam s ny ng nhau v ging
nhau tt c cc VRF nn VRP no cng cp nht cc route ca
tt c cc VRF cn li vo bng nh tuyn ca mnh. Do ta
c th kt ni t mt v tr VPN bt k n cc tt c cc v tr
VPN cn li.
O
Z
O
H
c
o
r *
w
00
0
<Q
3
1
CO
iQ
I
Q>
:3
<Q
s
1
. i
Chng 6: Thc th trin khai ti Vit Nam 139
Dch v HSI cung cp kh nng truy cp Internet gin tip
cho khch hng thng qua mng Metro Ethernet. Mt mg
hm s dng giao thc Ethernet qua MPLS c to ra qua
mng MEN kt ni thit b ca khch hng ti BRAS. Khch
hng s quay s s dng Internet thng qua giao thc PPPoE.
6.4.2 Dch v knh thu ring Ethernet
Sr