H3C SR6600-X Cloud Service Aggregation Router
The H3C SR6600-X series products (hereinafter referred to as SR6600-X) are high-end aggregation routers independently developed by H3C for the needs of the new generation of cloud services. With the widespread adoption of cloud computing applications, users have increasingly high requirements for routing devices. In addition to high performance and large capacity, virtualization networks also require the ability to aggregate more users and business traffic, and to finely differentiate and ensure QoS for various cloud based data flows, ensuring the security and reliability of network interconnection. Traditional routing devices often struggle to meet these requirements. The newly launched SR6600-X series router by H3C has addressed the aforementioned issues in a targeted manner. The H3C SR6600-X adopts a full service distributed processing architecture, with all services built in without the need to purchase additional business cards. It also has elastic and scalable business processing capabilities, and uses the independently developed Apollo hardware chip core that integrates routing forwarding and business processing to achieve high-performance business line speed forwarding. At the same time, SR6600-X innovatively utilizes IRF2 technology to achieve wide area network aggregation virtualization, which significantly improves network reliability while reducing operation and management costs. The SR6600-X series products support the advanced network operating system Comware V7, which seamlessly integrates with SR6600 in terms of multi-core CPU support, distributed computing, modular design, high availability architecture, virtualization, openness, etc., further improving the performance and reliability of the entire system and having better scalability.
The H3C SR6600-X series products are positioned on the 240G platform and are suitable for large-scale industry network core aggregation, enterprise remote data center interconnection, and operator edge access. Especially designed for large capacity users and complex traffic, they fully meet the high standard requirements of current and future cloud computing business development, and are the best choice for user cloud to cloud and cloud to cloud interconnection. SR6600-X, together with H3C's full range of network products, can provide comprehensive network solutions for government, power, finance, public utilities, operators, and large and medium-sized enterprise users.
H3C SR6600-X includes three fully distributed products: SR6604-X, SR6608-X, and SR6616-X.
Product Features
New generation network operating system
The SR6600-X control plane adopts multi-core and SMP (Symmetric Multi Processing) technology, advanced operating system Comware V7, and each software module has independent processes and running space, which can be dynamically loaded and upgraded separately. This refined management is more conducive to the overall stability and performance of the system.
Comware V7 can ensure critical business performance and real-time performance. Support running a specified set of processes on a dedicated CPU Set to provide better resource protection for critical tasks. At the same time, in conjunction with thread preemptive scheduling, reasonable priority settings, and other means, it ensures that functions with real-time requirements can still respond to events in a timely manner when the system CPU load is high.
Comware V7 supports distributed computing. Global protocol modules such as MPLS, BGP, etc. can run on designated main control CPU systems, distributing the main programs of various global services to different main control systems, effectively sharing the pressure on each CPU and improving the overall performance of the system. A global service can achieve distributed computing by further disassembling sub functions and distributing them to different main CPU systems for operation.
Advanced full service distributed processing architecture
The H3C SR6600-X series router adopts an advanced full service distributed processing architecture, with hardware separation of routing engine, business engine, and forwarding engine, and separation of control plane and business plane, ensuring that business and control do not interfere with each other when the system is running at full speed, and business is not interrupted when switching between primary and backup; All services (such as tunneling services, NAT address translation, network flow analysis, message encryption, etc.) can be processed at high speed directly on the supported line cards of the device without the need for any additional business cards. The business processing capacity increases linearly with the increase of line cards. Compared with traditional high-end routers that rely on dedicated boards for business processing, it not only eliminates the bandwidth bottleneck of dedicated business boards, but also reduces the total cost of ownership for users.
Independently developed Apollo hardware core
With the rise of cloud computing services, the surge in network users, and the continuous enrichment and development of network services, the network architecture has undergone fundamental changes, and edge aggregation devices are facing new challenges in improving business performance. Commercial ASIC chips and network processors can no longer meet the needs of current industry networks and operator networks. H3C Company, with over a decade of professional experience in the router field, has dedicated five years to creating Apollo professional communication processing hardware cores that integrate routing forwarding and business processing, specifically tailored to the characteristics of high-end router business models, fully meeting users' high-performance business processing needs. Apollo can support multiple wide area network interface cards, support line speed QoS, GRE tunneling Netstream、 The business capabilities of strategy routing, ACL, BRAS, etc. can be implemented through hardware to reduce packet delay and jitter in traditional wide area network services. At the same time, Apollo supports large queues and interface caching to meet users' demanding network requirements for voice, video, and other services. In addition, the multicast replication unit of the Apollo hardware core cooperates with the multicast replication of the switching matrix to form a three-level multicast replication architecture for routers, including upstream multicast replication, switching network multicast replication, and downstream multicast replication. The hierarchical and refined multicast replication architecture avoids the unnecessary bandwidth occupation and waste of voice, video, and other services in multicast situations, thereby ensuring the smooth operation of multicast services.
Powerful routing capability
The H3C SR6600-X series router supports ultra large capacity routing table entries, as well as rich routing strategies and powerful policy routing functions, which can flexibly control and schedule network traffic to meet the different business characteristics requirements of industry and operator users. In addition, the H3C SR6600-X series router fully supports static and dynamic routing protocols based on IPv4/IPv6, such as RIP/RIPng, OSPF/OSPF v3, IS-IS/IS-IS v6, BGP/BGP4+, etc.
Support wide area network IRF2 virtualization
Traditional wide area network connections often use dual line and dual machine backup methods for high reliability. Although reliability is enhanced, the utilization of lines and equipment is not high, and maintenance and management are complex. H3C, based on the virtualization requirements of future cloud computing networks, has taken the lead in supporting IRF2 (Second Generation Intelligent Elastic Architecture) technology on wide area network devices, virtualizing two physical devices into one logical device, greatly reducing the operation and maintenance costs of user networks, improving link bandwidth utilization and device utilization. After supporting wide area network IRF2 technology, the H3C SR6600-X series router will provide users with richer business capabilities:
Through distributed cross device link aggregation technology, load sharing and mutual backup of multiple uplink links are achieved, thereby improving the reliability of the entire network architecture and the utilization of link resources. Additionally, rich services such as QoS, network flow analysis, NAT translation, data encryption, etc. are supported on the cross device aggregation links;
Multiple SR6600-X devices are virtualized as a logical device using IRF2 technology, sharing a management channel to simplify network device management, simplify network topology management, improve operational efficiency, and reduce maintenance costs;
By removing routing hot backup technology, real-time backup and uninterrupted three-layer forwarding of all information in the control plane and data plane are achieved throughout the entire virtual architecture, greatly enhancing the reliability and high performance of the virtual architecture, while eliminating single points of failure and avoiding business interruption.
Support one virtual multiple MDC virtualization
SR6600-X not only supports horizontal virtualization IRF2 technology, but also supports virtual router MDC technology. MDC technology can virtualize an SR6600-X into multiple logical network devices through software. On the hardware side, virtual devices have independent resources such as CPU, memory, and boards, while on the software side, virtual devices have independent control planes, data planes, and management planes. Virtual routers are independent and do not affect each other, providing users with an elastic and scalable leased logical network.
Rich professional VPN features
The H3C SR6600-X series router supports comprehensive L2TP, IPSec, and GRE tunneling technologies, and supports independent hardware encryption cores. It can provide high-performance encryption capabilities and a large tunnel capacity to meet the requirements of various large encryption gateways without increasing user investment, ensuring the secure transmission of user data in wide area networks.
In addition, traditional VPN technology still has shortcomings in flexibility and maintainability. For example, enterprise branches usually use dynamic addresses from public networks to access the internal network of the enterprise. The core access devices of the enterprise cannot know the public network address of the other end in advance, and there are issues with configuring connections when all branches of the enterprise are fully connected. H3C provides a professional ADVPN (Auto Discovery Virtual Private Network) solution to meet the business needs of the aforementioned users. Through the VAM (VPN Address Management) protocol, it collects, maintains, and distributes dynamically changing public network addresses and other information to solve the problem of not being able to obtain the public network address of the communication partner in advance. ADVPN can automatically establish tunnels for transmission between various branches of the enterprise network when they use dynamic addresses to access the public network. Not only does it improve the flexibility of networking and reduce maintenance workload, but it also provides many rich features, such as NAT traversal of ADVPN packets, security authentication, IPSec packet encryption, and multiple VPN domains, etc.
The H3C SR6600-X series router also supports comprehensive MPLS protocol, supports layer 2 and layer 3 VPN services, and supports MPLS TE and other functions. Being able to form a powerful MPLS network with other network products from H3C, providing high-performance, secure, and multi-level MPLS VPN solutions.
Comprehensive network security protection
The H3C SR6600-X series router is equipped with multiple security features, providing users with comprehensive security protection for their networks
The SR6600-X, combined with the new FIP line card and Comware V7 software, can complete all traditional business card functions with FIP line cards, eliminating the need to purchase business cards separately. On the premise of completing the same functions and achieving the same performance, it further saves users' investment costs and simplifies management.
Comprehensive firewall function: supports packet filtering firewall, status firewall, filters various attack messages, and can provide filtering logs. The unique ACL acceleration algorithm eliminates the impact of the number of ACL filtering rules on firewall performance;
Comprehensive built-in anti attack measures:
→ Support various ARP anti attack techniques, such as ARP speed limit ARP Proxy、 Authorizing ARP, ARP active confirmation, ARP source MAC consistency check, etc. can effectively prevent the increasingly rampant ARP attacks in the intranet and ensure the stability of network business operation;
Single packet attack prevention: can be used to Fraggle、ICMP Redirect、ICMP Unreachable、LAND、Large ICMP、Route Record、Smurf、Source Route、TCP Flag、Tracert、WinNuke Effectively prevent single packet attacks;
Scan attack prevention: Attackers use scanning tools to scan the host address or port of the network, accurately locate the location of potential targets, detect the network topology and enabled service types of the target system, and prepare for further intrusion into the target system;
Flood attack prevention: effectively prevent SYN Flood attacks, ICMP Flood attacks UDP Flood
Blacklist function: an attack prevention feature that filters packets based on their source IP address. Compared to packet filtering based on ACL (Access Control List), the method of matching packets using blacklist is simpler and can achieve high-speed filtering of packets, effectively blocking packets sent from specific IP addresses;
Traffic statistics assisted attack prevention: mainly used for statistical analysis of session establishment between internal and external networks, with a certain degree of real-time performance, can help network administrators timely grasp the statistical values of various types of sessions in the network, and can serve as an effective basis for formulating attack prevention strategies;
○ Support firewall, intrusion prevention system, and application control business modules integrated with routers to simplify management and eliminate single points of failure
Complete user behavior tracking and recording: Supports comprehensive logging functions, combined with H3C's iMC UBAS (User Behavior Audit) solution, allowing network administrators to easily monitor the behavior of internet users and ensure network security operation.
Intelligent management of business bandwidth
The wide area network carries a significant amount of business traffic for enterprises. However, due to the high convergence ratio, congestion, and latency inherent in the wide area network, how to maximize the utilization of network bandwidth resources and improve the reliability of system transmission applications in these insufficient environments is an important issue faced by wide area network equipment. H3C has provided users with a comprehensive business bandwidth management mechanism through years of experience in enterprise network construction.
It mainly includes the following aspects:
Bandwidth management of primary and backup networks: Fully utilize backup network resources. In situations where primary network resources are tight, according to pre-set strategies, a portion of data traffic is rerouted to the backup network for data transmission, allowing idle resources to be fully utilized to achieve 100% utilization;
UCMP Unbalanced Link Load Balancing: UCMP differs from traditional ECMP in that its biggest feature is the use of weight values to differentiate the use of bandwidth, allowing two different bandwidth outlets to handle different data traffic transmissions based on the size of the bandwidth;
Bandwidth reservation and resource sharing: The network can allocate a certain amount of exclusive bandwidth for each department to ensure the quality of critical services. The remaining bandwidth is shared bandwidth, which can be used when it exceeds the exclusive bandwidth to meet sudden traffic demands;
Hierarchical CAR improves bandwidth utilization: traditional one layer CAR technology is implemented with multi-level processing, which enables bandwidth reallocation and significantly improves business transmission bandwidth utilization;
Intelligent overload traffic scheduling: Unlike traditional traffic scheduling methods, intelligent overload traffic scheduling can guide the overloaded portion of traffic to other exit paths when the high-quality exit bandwidth is fully occupied. This way, customers can make full use of high-quality exits and ensure the stability of their business;
Advanced Hierarchical Quality of Service (HQQoS): With the expansion of user scale and the increase of business types, network devices are required not only to further refine and distinguish business traffic, but also to manage and schedule multiple users, multiple businesses, multiple traffic and other transmission objects in a unified manner. Obviously, these applications are difficult to implement for traditional QoS technologies. HQQoS divides the scheduling queue into multiple scheduling levels such as physical level, logical level, application or business level, etc. Each level can use different features for traffic management, achieving multi-level traffic management and better helping operators achieve multi-user and multi business service management.
Operational level reliability design
The H3C SR6600-X series router provides users with comprehensive reliability assurance.
Firstly, in terms of hardware, a distributed architecture is adopted, supporting redundant controllers, redundant forwarding engines, redundant power supplies, and hot swappable designs; Separate the control plane from the business plane; Support automatic isolation technology when a hardware component fails, to avoid the occurrence of cascading failures caused by a hardware failure; All business processing engines and interface modules support hot plugging and will not affect other engines or modules. Support RPR (Resilient Packet Ring), which can achieve fast fault protection of 50ms.
Secondly, in terms of software, the H3C SR6600-X series router supports rich reliability features to ensure uninterrupted business operation of network devices. The reliability features on these software include:
○ Support software hot patching, ISSU, achieve smooth software upgrades, and ensure that business will not be interrupted during software upgrades;
○ Support NSR to ensure uninterrupted data forwarding of the main control board during primary/backup switching;
Support link detection protocols such as BFD and NQA to ensure timely convergence of upper layer protocols in the event of a wide area link failure, reducing business interruption time caused by link failures;
○ Support FRR (Fast Routing Backup) with Fast Routing Backup (FRB) feature, combined with BFD function, to achieve fast switching of faulty links;
○ Supports IP FRR (Fast ReRoute), which can be linked with static routing/policy routing/RIP/IS-IS/OSPF, and can be combined with BFD function to achieve fast routing switching of faulty links;
Support VRRP virtual routing redundancy protocol, combined with BFD fault detection mechanism, to achieve fast VRRP switching capability.
○ Support GR (Graceful Restart) function to achieve uninterrupted forwarding during primary and backup engine switching;
○ Support fast convergence of IGP routing;
○ A virtualization software system that supports IRF2 technology as the cornerstone of the system
○ Support EAA embedded automation rack