基于MPLS和BGP的跨域VPN研究與應(yīng)用
[Abstract]:The virtual private network constructed by multi-protocol label exchange and border gateway protocol is dynamic and extensible with the help of this technology, and it can effectively solve the problems of different VPN user address conflicts, exchange access control, data isolation, etc. Has been more and more favored by various industries. In recent years, with the increasing of enterprise scale, enterprise networks need to be interconnected across autonomous systems. However, the existing VPN network based on MPLS and BGP technology does not support cross-autonomous systems. How to build VPN network across autonomous system domain or across operators has become a problem of Internet working group. The main contents of this paper are as follows: firstly, a VPN scheme based on MPLS and BGP is proposed to overcome the shortcomings in scalability, manageability, address reuse and security of the virtual private network constructed by traditional VPN technology. In the scheme, the label forwarding path with dynamic characteristics is formed through the assignment of MPLS label. Build a "bridge" in the public network, for the private network data traversing the public network. Using the same private address for different VPN users, the operator edge devices connected with different VPN users can learn two identical address information, which will cause the problem of address conflict. Using VRF (Virtual routing Technology) to solve the problems of address reuse, data separation and VPN access control of different VPN users, the solution of the VRF VPN instance and the RDLBLE attribute of BGP is presented, which fully explains the feasibility of the scheme. Secondly, aiming at the existing problems of VPN network constructed by an organization, this paper analyzes the root causes of these problems, and puts forward a scheme of network transformation of cross-domain platform based on back-to-back. Before the implementation of the scheme, the IP address of the device named and the RTRD attribute of the routing protocol BGP are specifically planned, which provides the guarantee for the smooth implementation of the scheme. The test results show that the scheme is superior to the traditional VPN in reliability, manageability, expansibility and security. Finally, aiming at the VPN network system constructed by MPLS and BGP, there are two problems in the cross autonomous domain platform, such as the overburden of the network equipment of the autonomous system boundary and the unable to form the label forwarding path. According to the principle of MPLS label assignment and the analysis of data forwarding plane, the causes of these problems are analyzed. By analyzing the root of the problem, two solutions are put forward. Optimization scheme one does not need to maintain a large number of links and interfaces, effectively reducing the workload of network managers in cross-domain platform construction. In the network system of cross-domain platform, the optimization scheme makes the public network data and the private network data of different VPN users bear by different device types, thus lightens the burden of the boundary equipment of the autonomous system, and expands the application field of the VPN technology.
【學(xué)位授予單位】:國(guó)防科學(xué)技術(shù)大學(xué)
【學(xué)位級(jí)別】:碩士
【學(xué)位授予年份】:2014
【分類號(hào)】:TP393.01
【參考文獻(xiàn)】
中國(guó)期刊全文數(shù)據(jù)庫(kù) 前10條
1 李衛(wèi);陳旭東;周飛;;通過(guò)移動(dòng)網(wǎng)絡(luò)實(shí)現(xiàn)MPLS VPN專網(wǎng)接入備份研究[J];移動(dòng)通信;2013年18期
2 任韜松;余江;?;施繼紅;羅忠成;;基于MPLS的快速重路由故障恢復(fù)綜合模型[J];計(jì)算機(jī)工程;2012年23期
3 盧眾寧;蘇厚勤;;MPLS-VPN在企業(yè)ERP實(shí)施過(guò)程中的應(yīng)用研究[J];計(jì)算機(jī)應(yīng)用與軟件;2012年02期
4 李海華;;BGP MPLS VPN數(shù)據(jù)轉(zhuǎn)發(fā)過(guò)程分析[J];計(jì)算機(jī)技術(shù)與發(fā)展;2011年06期
5 曾文龍;王晟;王雄;;IGP/MPLS混合的IP網(wǎng)絡(luò)不確定流量規(guī)劃方法[J];計(jì)算機(jī)應(yīng)用;2011年05期
6 侯劍鋒;馬明凱;;MPLS VPN中PE-CE互連仿真研究[J];計(jì)算機(jī)工程;2010年12期
7 江勇;胡松華;;匯聚組播:新型MPLS服務(wù)質(zhì)量組播體系結(jié)構(gòu)[J];軟件學(xué)報(bào);2010年04期
8 張成;石雪萍;任林源;;基于GRE VPN的校園網(wǎng)接入方式及實(shí)現(xiàn)[J];現(xiàn)代電子技術(shù);2010年06期
9 劉化君;;基于IPSec的VPN技術(shù)應(yīng)用與實(shí)現(xiàn)[J];電腦開發(fā)與應(yīng)用;2010年03期
10 侯劍鋒;馬明凱;李向紅;;MPLS VPN中動(dòng)態(tài)服務(wù)質(zhì)量機(jī)制的應(yīng)用[J];計(jì)算機(jī)工程;2010年03期
,本文編號(hào):2130170
本文鏈接:http://sikaile.net/guanlilunwen/ydhl/2130170.html