H3C S5800 IPSACG插卡开局指导书

更新时间:2023-10-13 03:31:01 阅读量: 综合文库 文档下载

说明:文章内容仅供预览,部分内容可能不全。下载后的文档,内容与下面显示的完全一致。下载之前请确认下面内容是否您想要的,是否完整无缺。

H3C S5800 IPS&ACG插卡开局指导书

H3C S5800 IPS&ACG插卡开局指导书

(IPS、ACG使用B31平台软件版本)

杭州华三通信技术有限公司

Hangzhou H3C Technologies Co., Ltd.

版权所有 侵权必究 All rights reserved

杭州华三通信技术有限公司

www.h3c.com.cn

第i页

H3C S5800 IPS&ACG插卡开局指导书 目 录

1 SECBLADE安全插卡概述 ······································································································································· 2

1.1 产品简介 ·················································································································································· 2 1.2 主要特点 ·················································································································································· 3 2 SECBLADE IPS命令行登录方式 ··························································································································· 4 3 方案一:单台S5800典型配置 ································································································································· 5

3.1 三层转发方案 ·········································································································································· 5

3.1.1 组网图 ·········································································································································· 5 3.1.2 用户需求 ······································································································································ 5 3.1.3 S5800主控板相关配置 ················································································································· 5 3.1.4 IPS插卡配置 ································································································································· 6 3.2 二层转发方案 ·········································································································································· 8 4 方案二:S5800 IRF典型配置 ································································································································· 8

4.1 2台S5800 IRF+1块SECBLADE IPS插卡 ··································································································· 8

4.1.1 组网图 ·········································································································································· 8 4.1.2 用户需求 ······································································································································ 8 4.1.3 S5800相关配置 ····························································································································· 9 4.1.4 IPS插卡相关配置 ······················································································································· 10 4.2 两台S5800堆叠+IPS插卡+FW插卡 ····································································································· 12

4.2.1 组网图 ········································································································································ 12 4.2.2 用户需求 ···································································································································· 12 4.2.3 S5800相关配置 ··························································································································· 13 4.2.4 FW插卡相关配置 ······················································································································· 14 4.2.5 IPS插卡相关配置 ······················································································································· 15

5 开局常见注意事项 ··················································································································································16

5.1 S5800/S5820X系列交换机部署OAA引流的几个特点 ········································································ 16

5.1.1 对OAA板卡的支持情况 ··········································································································· 16 5.1.2 流量转发与重定向 ···················································································································· 16 5.1.3 对未知单播、组播、广播、ARP报文的处理 ········································································· 16 5.2 ANY域问题 ············································································································································· 16 5.3 OAA引流策略与PORTAL共存问题 ······································································································· 17

杭州华三通信技术有限公司

www.h3c.com.cn 第ii页

H3C S5800 IPS插卡开局指导书 关键词Key words:IPS插卡、FW插卡、OAA、堆叠 摘 要Abstract:

本文主要描述了SecBlade IPS,配合S5800及SecBlade II FW在不同组网环境下的典型组网及配置方案,以及在实际部署过程中的注意事项,供插卡开局同学参考。

缩略语清单List of abbreviations:

Abbreviations缩略语 Full spelling 英文全名 Chinese explanation 中文解释 IPS ACG FW

Intrusion Prevention System Application Control Gateway FireWall 入侵防御系统 应用控制网关 防火墙 杭州华三通信技术有限公司

www.h3c.com.cn 第1页

H3C S5800 IPS插卡开局指导书 1 SecBlade安全插卡概述

1.1 产品简介

H3C SecBlade IPS、H3C SecBlade ACG插卡产品采用H3C公司最新硬件平台和体系架构,支持分布式部署和集中管理,可灵活扩展。通过基于Web浏览器的管理界面,管理员可以快速熟悉系统的操作管理。H3C SecBlade IPS/ACG插卡,可以和S5800/S5820X系列低端交换机、S7500E/S10500系列中端交换机、S9500系列/S9500E系列/S12500系列高端交换机以及SR6600/SR8800路由器配合使用;可以在已使用该交换机/路由器的用户网络中快速部署,满足对流量运营管理的需要。

H3C SecBlade IPS单板类型:

? ? ? ? ? ? ?

LSWM1IPS10:适用于H3C S5800/S5820X系列交换机 LSQ1IPSSC0:适用于H3C S7500E系列交换机 LSB1IPS1A0:适用于H3C S9500系列交换机 LSR1IPS1A1:适用于H3C S9500E系列交换机 LST1IPS1A1:适用于H3C S12500系列交换机 SPE-IPS-200:适用于H3C SR6600系列路由器 IM-IPS:适用于H3C SR8800系列路由器

H3C SecBlade ACG单板类型:

? ? ? ? ? ? ?

LSWM1IPS10:适用于H3C S5800/S5820X系列交换机 LSQ1IPSSC0:适用于H3C S7500E系列交换机 LSB1IPS1A0:适用于H3C S9500系列交换机 LSR1IPS1A1:适用于H3C S9500E系列交换机 LST1IPS1A1:适用于H3C S12500系列交换机 SPE-IPS-200:适用于H3C SR6600系列路由器 IM-IPS:适用于H3C SR8800系列路由器

H3C SecBlade II 防火墙插卡采用H3C公司最新的硬件平台和体系架构,是H3C公司面向大型企业和运营商客户开发的新一代电信级防火墙产品。SecBlade II 防火墙插卡采用了专用多核多线程高性能处理器和高速存储器,在高速处理安全业务的同时,交换机的原有业务处理不会受到任何影响。

插卡式H3C SecBlade II防火墙单板类型:

? ?

LSWM1IPS10:适用于H3C S5800/S5820X系列交换机 LSQ1IPSSC0:适用于H3C S7500E系列交换机

www.h3c.com.cn

第2页

杭州华三通信技术有限公司

? ? ? ? ?

H3C S5800 IPS插卡开局指导书 LSB1IPS1A0:适用于H3C S9500系列交换机 LSR1IPS1A1:适用于H3C S9500E系列交换机 LST1IPS1A1:适用于H3C S12500系列交换机 SPE-IPS-200:适用于H3C SR6600系列路由器 IM-IPS:适用于H3C SR8800系列路由器

1.2 主要特点

?

将主网络设备的转发业务和安全处理有机融合在一起,在实现主网络设备高性能数据转发的同时,能够根据组网的特点处理安全业务,实现安全防护和监控。

?

SecBlade IPS/ACG插卡基于H3C公司领先的OAA(Open Application Architecture)架构开发,通过内部10GE以太网接口与主网络设备相连。H3C主网络设备的线速转发能力,保证了其与安全业务插卡之间的高速数据转发。

?

SecBlade IPS/ACG插卡采用了专用多核多线程高性能处理器和高速存储器,在高速处理安全业务的同时,主网络设备的原有业务处理不会受到任何影响。

?

SecBlade IPS/ACG插卡可以插在主网络设备上的多个槽位,并且在一台主网络设备上可插入多块插卡进行性能扩展,轻松适应不断升级的企业和电信运营商网络。

杭州华三通信技术有限公司

www.h3c.com.cn 第3页

本文来源:https://www.bwwdw.com/article/koef.html

Top