The multi-layer switches of integrated fire compartment wall
Affiliated technical field:
The invention belongs to data communication field, relate in particular to a kind of multi-layer switches of integrated fire compartment wall.
Background technology:
Along with the scale of IP data communications net is increasing, level is more and more, and operation maintenance cost also goes up thereupon, and the maintenance management technology is also complicated more, operator wishes that IP Telecommunication Network is simple more, reliable, can safeguard, so that the network configuration flattening is an operator is desirable.
Multi-layer switches combine the high bandwidth and the complicated flexible processing ability of router of switch, can replace them, are widely used in network design, have promoted the flattening of network configuration widely.
Internet worm forces fire compartment wall to become the essential equipment of enterprise network with attack, and common fire compartment wall generally as the outlet of enterprise network, filters virus, takes precautions against functions such as attack and execution encryption, deciphering, the protection enterprise information security.
The introducing of fire compartment wall has increased enterprise information security, but has increased network configuration level and maintenance complexity, has also reduced the enterprise network outlet bandwidth simultaneously, has also increased many network investments.
Enterprise network typical case fire compartment wall networking structure as shown in Figure 1, firewall box has interior network interface, three kinds of network interfaces of DMZ (demilitarized zone) and outer network interface, the fire compartment wall major function is to protect Intranet.
The key point that is connected to become network egress between fire compartment wall and the internal network, for reliability and the fail safe that strengthens network, as shown in Figure 2, important enterprise network generally at export deployment redundancy, backup fire compartment wall, has increased network complexity and cost widely.
Summary of the invention:
The object of the present invention is to provide a kind of multi-layer switches of integrated fire compartment wall, simplify network configuration, reduce the network equipment, reduce network investment, strengthen stability of network.
The multi-layer switches of integrated fire compartment wall of the present invention comprise the master control module and the backboard of multi-layer switches, establish control channel and data channel on the backboard; Switching Module; And FWSM; Wherein Switching Module is established network physical port and Intranet port; FWSM is established Intranet, DMZ and outer network interface; The master control module of multi-layer switches is configured the route switching processing unit of Switching Module and the fire compartment wall processing unit of FWSM by the control channel of backboard; Switching Module and FWSM are by the data channel Data transmission of backboard.
FWSM itself can not established Intranet, DMZ and outer network interface, and the network physical port of Switching Module is defined as the Intranet of FWSM, DMZ and outer network interface.
Switching Module and FWSM are respectively established CPU, and the master control module of multi-layer switches is connected with each CPU by backboard control channel, and the route switching processing unit of Switching Module and the fire compartment wall processing unit of FWSM are configured respectively.
The present invention is with the business module of fire compartment wall as the frame switch, in the control plane and datum plane that the control plane and the datum plane of fire compartment wall is incorporated into switch (as shown in Figure 3), that routing and switching function and firewall functionality is integrated in an equipment.The multi-layer switches of integrated fire compartment wall can be simplified network configuration, reduce the network equipment, reduce network investment, owing to there has not been the connection line of fire compartment wall and internal network, have reduced the possible critical failure point of network, have strengthened stability of network.
Description of drawings:
Fig. 1 enterprise network typical case fire compartment wall networking structure schematic diagram
The 1---router; The 2---multi-layer switches; The 3---fire compartment wall;
Fig. 2 disposes the enterprise network typical case fire compartment wall networking structure schematic diagram of redundancy, backup fire compartment wall
The 4---active link; The 5---reserve link;
Fig. 3 structural representation of the present invention
Fig. 4 logical construction block diagram of the present invention
Fig. 5 fire compartment wall processing unit of the present invention configuration schematic diagram
Fig. 6 data flow of the present invention, control flows schematic diagram
Embodiment:
As shown in Figure 4, be logic diagram of the present invention.
The control of fire compartment wall is finished by the CPU of this module board, and the manager signs in to the CPU of FWSM by the control structure passage of architecture for exchanging, thereby the fire compartment wall processing unit is configured.
The function of fire compartment wall comprises filtration, ACL, NAT, VPN, IDS and encrypting and decrypting, the configuration management order is very many, and its configuration management mode is also different with switch, so two kinds of configurations should not be mixed, but under same interface, provide two configuration surroundings, come configuration switch and fire compartment wall respectively, as shown in Figure 5.
For streamlining management and system complexity, FWSM itself does not externally provide physical network port, but fire compartment wall still has in-house network, DMZ and three kinds of interfaces of extranets, these three kinds of interfaces use the physical network port of other Switching Modules, and the port that can define as required on the Switching Module is certain interface of fire compartment wall.
As shown in Figure 6, enter switch from the packet of outer net Internet from the outer net port, by the high-speed data channel on forwarding chip and the backboard, Switching Module is given FWSM with packet; FWSM to data filter etc. handle after, safe data are delivered to Switching Module by backboard; Switching Module is given the enterprise network Intranet user packet by the Intranet port, and data communication internal by this flow process fire compartment wall, outer network has played the effect of monitoring, has protected the information security of Intranet.