H3C SR6600 Open Multi Core Router
H3C SR6600 Open Multi Core Router (hereinafter referred to as SR6600) is a core router independently developed by H3C, tailored for user networks such as operators, governments, power, finance, education, and enterprises. As the industry's first router product based on multi-core and multi-threaded processor technology architecture, its new hardware platform and business oriented design concept interpret a new solution for data communication business, fully meeting the diversified needs of users for future business expansion, and in line with the current situation and development trend of IT construction in operators and various industries. H3C SR6600 adopts a full service distributed processing architecture, supporting all services to be built in without the need to purchase additional business cards, and also has elastic and scalable business processing capabilities. In order to meet the demand of users for higher business performance, SR6600 has added support for H3C's independently developed Apollo hardware chip core that integrates routing forwarding and business processing on the basis of multi-core, achieving higher performance business line speed forwarding. The SR6600 series products support the advanced network operating system Comware V7, which seamlessly integrates with SR6600 in terms of multi-core CPU support, distributed computing, modular design, high availability architecture, virtualization, openness, etc., further improving the performance and reliability of the entire system and having better scalability. The SR6600 currently includes three hosts: SR6604, SR6608, and SR6616. The product is positioned as an access or aggregation device for large and medium-sized networks in various industries.
Product Features
The industry's first multi-core high-end router
SR6600 is the industry's first mid to high end router based on multi-core and multi-threaded technology architecture, featuring high performance, easy programming, and flexible L4-L7 layer business applications. The application of multi-core and multi-threaded processors greatly improves the performance and flexibility of network devices. Its good programmability and ease of use enable SR6600 to quickly respond to future new services and have good adaptability, meeting the needs of users to achieve multi service expansion on routers. The SR6600 router utilizes hardware to accelerate the processing of link layer and security services in its system architecture design, allowing multi-core processor core resources to focus more on critical L4-7 deep service processing.
New generation network operating system
The SR6600 control plane adopts multi-core and SMP (Symmetric Multi Processing) technology, advanced operating system Comware V7, and each software module has independent processes and running space, which can be dynamically loaded and upgraded separately. This refined management is more conducive to the overall stability and performance of the system.
Comware V7 can ensure critical business performance and real-time performance. Support running a specified set of processes on a dedicated CPU Set to provide better resource protection for critical tasks. At the same time, in conjunction with thread preemptive scheduling, reasonable priority settings, and other means, it ensures that functions with real-time requirements can still respond to events in a timely manner when the system CPU load is high.
Comware V7 supports distributed computing. Global protocol modules such as MPLS, BGP, etc. can run on designated main control CPU systems, distributing the main programs of various global services to different main control systems, effectively sharing the pressure on each CPU and improving the overall performance of the system. A global service can achieve distributed computing by further disassembling sub functions and distributing them to different main CPU systems for operation.
Advanced fully distributed processing architecture
SR6604, SR6608, and SR6616 adopt a fully distributed processing architecture, with hardware separation of routing engine, forwarding engine, and business engine. The control plane and business plane are separated on all engines to ensure that business and control do not interfere with each other when the system is running at full speed, and business is not interrupted during primary and backup switching; Each business engine can independently complete distributed processing of NAT, IPSec, Netstream and other businesses, improving the overall processing capability of the system while ensuring high reliability of each business.
Independently developed Apollo hardware core
With the rise of cloud computing services, the surge in network users, and the continuous enrichment and development of network services, the network architecture has undergone fundamental changes, and edge aggregation devices are facing new challenges in improving business performance. Commercial ASIC chips and network processors can no longer meet the needs of current industry networks and operator networks. H3C Company, with over a decade of professional experience in the router field, has dedicated five years to creating the Apollo professional communication processing hardware core that integrates routing forwarding and business processing, tailored to the characteristics of mid to high end router business models, fully meeting the high-performance business processing needs of users. Apollo can support multiple wide area network interface cards, support line speed QoS, GRE tunneling Netstream、 The business capabilities of strategy routing, ACL, BRAS, etc. can be implemented through hardware to reduce packet delay and jitter in traditional wide area network services. At the same time, Apollo supports large queues and interface caching to meet users' demanding network requirements for voice, video, and other services. In addition, the multicast replication unit of the Apollo hardware core cooperates with the multicast replication of the switching matrix to form a three-level multicast replication architecture for routers, including upstream multicast replication, switching network multicast replication, and downstream multicast replication. The hierarchical and refined multicast replication architecture avoids the unnecessary bandwidth occupation and waste of voice, video, and other services in multicast situations, thereby ensuring the smooth operation of multicast services.
Support wide area network IRF2 virtualization
Traditional wide area network connections often use dual line and dual machine backup methods for high reliability. Although reliability is enhanced, the utilization of lines and equipment is not high, and maintenance and management are complex. H3C, based on the virtualization requirements of future cloud computing networks, has taken the lead in supporting IRF2 (Second Generation Intelligent Elastic Architecture) technology on wide area network devices, virtualizing two physical devices into one logical device, greatly reducing the operation and maintenance costs of user networks, improving link bandwidth utilization and device utilization. After supporting wide area network IRF2 technology, the H3C SR6600 series router will provide users with richer business capabilities:
Through distributed cross device link aggregation technology, load sharing and mutual backup of multiple uplink links are achieved, thereby improving the reliability of the entire network architecture and the utilization of link resources. Additionally, rich services such as QoS, network flow analysis, NAT translation, data encryption, etc. are supported on the cross device aggregation links;
Multiple SR6600 devices are virtualized as a logical device using IRF2 technology, sharing a management channel, unified management interface, and forwarding table entries, simplifying network device management, simplifying network topology management, improving operational efficiency, and reducing maintenance costs;
Through patented routing hot backup technology, real-time backup and uninterrupted three-layer forwarding of all information in the control plane and data plane are achieved within the entire virtual architecture, greatly enhancing the reliability and high performance of the virtual architecture, while eliminating single points of failure and avoiding business interruptions.
Support one virtual multiple MDC virtualization
SR6600 not only supports horizontal virtualization IRF2 technology, but also supports virtual router MDC technology. MDC technology can virtualize an SR6600 into multiple logical network devices through software. On the hardware side, virtual devices have independent resources such as CPU, memory, and boards, while on the software side, virtual devices have independent control planes, data planes, and management planes. Virtual routers are independent and do not affect each other, providing users with an elastic and scalable leased logical network.
Higher interface density and aggregation capability
SR6604, SR6608, and SR6616 can support 8, 16, and 32 high-speed MIC-X interface cards respectively, achieving the highest wide area network interface aggregation capability in the same class.
The SR6600 router can provide high-density OC-3/STM-1 channelized POS interfaces and support channelization to E1/T1 or DS0, providing industry-leading, high-density E1 and DS0 line speed aggregation capabilities. Its narrowband access capacity, density, and performance all reach industry-leading levels. SR6600 also supports new SAP line cards, which provide high-density Ethernet access while offering stronger business capabilities.
Hardware supports PPP multi link bundling
The high-speed CPOS module provided by SR6600 can provide users with hardware MP functionality. When SR6600 is used as a wide area network aggregation node, users implement hardware PPP multi link bundling for downlink E1 or T1 links by adopting high-performance CPOS modules; Implement functions such as MP packet reassembly and fragmentation while ensuring data line speed forwarding.
Industry leading encryption performance
All business engines of SR6604, SR6608, and SR6616 have achieved high-performance IPSec encryption through built-in hardware encryption. Provide powerful data encryption capabilities without increasing any investment from users, ensuring the secure transmission of user data over wide area networks and internal networks.
Powerful routing processing capability
SR6600 supports static and dynamic routing protocols for IPv4/IPV6, including RIP/RIPng, OSPF/OSPFv3, IS-IS/IS-ISv6, and BGP/BGP4+.
SR6600 supports rich policy routing and routing strategies, and can flexibly control, schedule, and charge based on network traffic to meet the networking needs of enterprise networks and operators.
SR6600 supports SR/SRv6 features, which simplify network protocols, provide good scalability, programmability, and high reliability, helping customers build sustainable networks.
Rich professional VPN features
The H3C SR6600 series router supports comprehensive L2TP, IPSec, and GRE tunneling technologies, and supports independent hardware encryption cores. It can provide high-performance encryption capabilities and a large tunnel capacity to meet the requirements of various large encryption gateways without increasing user investment, ensuring the secure transmission of user data in wide area networks.
In addition, traditional VPN technology still has shortcomings in flexibility and maintainability. For example, enterprise branches usually use dynamic addresses to access public networks, and the communicating party cannot know the other end's public network address in advance, as well as configuration issues during full connection. H3C provides a professional ADVPN (Auto Discovery Virtual Private Network) solution to meet the business needs of the above-mentioned users. ADVPN can establish VPNs between various branches of the enterprise network by using dynamic addresses to access the public network. The flexibility of networking and the simplification of maintenance workload have been greatly improved. In addition, it also provides many rich features, such as NAT traversal of ADVPN packets, security authentication, packet encryption of IPSec, and multiple VPN domains.
To address the issue of establishing IKE SA and IPsec SA between each pair of communication peers with a management complexity of n ², SR66 provides the latest GDVPN solution, while Group Domain VPN offers a group based IPsec security model. Compared to traditional IPsec VPN, Group Domain VPN does not require modifying the IP header of the packet. The new IP header encapsulated in the outer layer of the packet is exactly the same as the original IP header in the inner layer. Therefore, there is no need to change the original deployed route, and QoS processing can be better achieved during network transmission. Group Domain VPN is a tunneling free connection that only requires encrypting multicast messages once. The local end does not need to send encrypted messages separately to each other, resulting in high multicast efficiency.
The H3C SR6600 series router also supports comprehensive MPLS protocol, supports layer 2 and layer 3 VPN services, and supports MPLS TE and other functions. Being able to form a powerful MPLS network with other network products from H3C, providing high-performance, secure, and multi-level MPLS VPN solutions.
Comprehensive network security protection
The H3C SR6600 series router is equipped with multiple security features, providing users with comprehensive security protection for their networks
The SR6600, in conjunction with the new FIP line card and Comware V7 software, can complete all traditional business card functions with FIP line cards, eliminating the need to purchase business cards separately. On the premise of completing the same functions and achieving the same performance, it further saves users' investment costs and simplifies management.
Comprehensive firewall function: supports packet filtering firewall, status firewall, filters various attack messages, and can provide filtering logs. The unique ACL acceleration algorithm eliminates the impact of the number of ACL filtering rules on firewall performance;
Comprehensive built-in anti attack measures:
○ Support various ARP anti attack techniques, such as ARP speed limit ARP Proxy、 Authorizing ARP, ARP active confirmation, ARP source MAC consistency check, etc. can effectively prevent the increasingly rampant ARP attacks in the intranet and ensure the stability of network business operation;
Single packet attack prevention: can be used to Fraggle、ICMP Redirect、ICMP Unreachable、LAND、Large ICMP、Route Record、Smurf、Source Route、TCP Flag、Tracert、WinNuke Effectively prevent single packet attacks;
Scan attack prevention: Attackers use scanning tools to scan the host address or port of the network, accurately locate the location of potential targets, detect the network topology and enabled service types of the target system, and prepare for further intrusion into the target system;
Flood attack prevention: effectively prevent SYN Flood attacks, ICMP Flood attacks UDP Flood
Blacklist function: an attack prevention feature that filters packets based on their source IP address. Compared to packet filtering based on ACL (Access Control List), the method of matching packets using blacklist is simpler and can achieve high-speed filtering of packets, effectively blocking packets sent from specific IP addresses;
Traffic statistics assisted attack prevention: mainly used for statistical analysis of session establishment between internal and external networks, with a certain degree of real-time performance, can help network administrators timely grasp the statistical values of various types of sessions in the network, and can serve as an effective basis for formulating attack prevention strategies;
Complete user behavior tracking and recording: Supports comprehensive logging functions, combined with H3C's iMC UBAS (User Behavior Audit) solution, allowing network administrators to easily monitor the behavior of internet users and ensure network security operation.
Intelligent management of business bandwidth
The wide area network carries a significant amount of business traffic for enterprises. However, due to the high convergence ratio, congestion, and latency inherent in the wide area network, how to maximize the utilization of network bandwidth resources and improve the reliability of system transmission applications in these insufficient environments is an important issue faced by wide area network equipment. H3C has provided users with a comprehensive business bandwidth management mechanism through years of experience in enterprise network construction.
Mainly including the following aspects:
Bandwidth management of primary and backup networks: Fully utilize backup network resources. In situations where primary network resources are tight, according to pre-set strategies, a portion of data traffic is rerouted to the backup network for data transmission, allowing idle resources to be fully utilized to achieve 100% utilization;
○ UCMP Unbalanced Link Load Balancing: UCMP differs from traditional ECMP in that its biggest feature is the use of weight values to differentiate the use of bandwidth, allowing two outlets with different bandwidths to handle different data traffic transmissions based on their bandwidth sizes;
○ Bandwidth reservation and resource sharing: The network can allocate a certain amount of exclusive bandwidth for each department to ensure the quality of critical business, and the remaining bandwidth is shared bandwidth, which can be used when exceeding the exclusive bandwidth to meet sudden traffic demands;
○ Hierarchical CAR improves bandwidth utilization: Traditional one layer CAR technology is implemented with multi-level processing, which enables bandwidth reallocation and significantly improves business transmission bandwidth utilization;
Intelligent overload traffic scheduling: Unlike traditional traffic scheduling methods, intelligent overload traffic scheduling can guide the overloaded portion of traffic to other exit paths when the high-quality exit bandwidth is fully occupied. This ensures that customers make full use of high-quality exits, thereby ensuring the stability of customer business operations;
Advanced Hierarchical Quality of Service (HQQoS): With the expansion of user scale and the increase of business types, network devices are required not only to further refine and distinguish business traffic, but also to manage and schedule multiple users, multiple businesses, multiple traffic and other transmission objects in a unified manner. Obviously, these applications are difficult to implement for traditional QoS technologies. HQQoS divides the scheduling queue into multiple scheduling levels such as physical level, logical level, application or business level, etc. Each level can use different features for traffic management, achieving multi-level traffic management and better helping operators achieve multi-user and multi business service management.
Operational level reliability design
The H3C SR6600 series router provides users with comprehensive reliability assurance.
In terms of hardware, a distributed architecture is adopted, supporting redundant controllers, redundant forwarding engines, redundant power supplies, and hot swappable designs; Separate the control plane from the business plane; Support automatic isolation technology when a hardware component fails, to avoid the occurrence of cascading failures caused by a hardware failure; All business processing engines and interface modules support hot plugging and will not affect other engines or modules. The power supply realizes redundant backup, and in the event of a single power input failure or a single power supply failure, the power supply of the whole machine is not affected, and the output current and power remain unchanged.
In terms of software, the H3C SR6600 series router supports rich reliability features to ensure uninterrupted business operation of network devices. The reliability features on these software include:
○ Support software hot patching, ISSU, achieve smooth software upgrades, and ensure that business will not be interrupted during software upgrades;
○ Support NSR to ensure uninterrupted data forwarding of the main control board during primary/backup switching;
Support link detection protocols such as BFD and NQA to ensure timely convergence of upper layer protocols in the event of a wide area link failure, reducing business interruption time caused by link failures;
○ Support FRR (Fast Routing Backup) with Fast Routing Backup (FRB) feature, combined with BFD function, to achieve fast switching of faulty links;
○ Supports IP FRR (Fast ReRoute), which can be linked with static routing/policy routing/RIP/IS-IS/OSPF, and can be combined with BFD function to achieve fast routing switching of faulty links;
○ Support VRRP virtual routing redundancy protocol, combined with BFD fault detection mechanism, to achieve fast VRRP switching capability;
○ Support GR (Graceful Restart) function to achieve uninterrupted forwarding during primary and backup engine switching;
○ Support fast convergence of IGP routing;
○ A virtualization software system that supports IRF2 technology as the cornerstone of the system;
○ Support EAA embedded automation architecture.