63
Vigor 3300 VigorAccess Product Introduction August, 2005 August, 2005

Vigor 3300 VigorAccess Product Introduction August, 2005

  • View
    217

  • Download
    0

Embed Size (px)

Citation preview

Page 1: Vigor 3300 VigorAccess Product Introduction August, 2005

Vigor 3300VigorAccess

Product Introduction

August, 2005August, 2005

Page 2: Vigor 3300 VigorAccess Product Introduction August, 2005

Outline

• SME Solution-Vigor 3300V SeriesSME Solution-Vigor 3300V Series

• Broadband Access Solution-Vigor Access

Page 3: Vigor 3300 VigorAccess Product Introduction August, 2005

3

SME Solution SME Solution 3300V Series3300V Series

Page 4: Vigor 3300 VigorAccess Product Introduction August, 2005

Product Feature Product Feature • Load Balance• QoS• High Availability• Firewall / URL Filtering• Physical DMZ/VLAN• VPN• VoIP

4

Page 5: Vigor 3300 VigorAccess Product Introduction August, 2005

• Reduce Enterprise High Speed Trunk Fee.• Redundancy.• Intelligently Distribute Network Traffic to the Internet.

Load Balancing

5

Page 6: Vigor 3300 VigorAccess Product Introduction August, 2005

– Allows the Network Administrator to Monitor, Analyze, and Allocate Bandwidth for Various Types of Network Traffic in Real Time and/or for Business-Critical Traffic.

– 8 Priority Queue.– Low Latency Queuing (LLQ).– 802.1p, DiffServ-Codepoint Marking.– Management by IP Address, Application, Service-

Oriented.

Quality of Service

6

Page 7: Vigor 3300 VigorAccess Product Introduction August, 2005

High Availability

7

• 7x24x365 Service.

• Uninterrupted Network Access in the Event of Hardware Failure.

• Apply on Master Maintenance.

Page 8: Vigor 3300 VigorAccess Product Introduction August, 2005

• Allows Users to Access Multiple Public Servers (e.g. Web, FTP, Mail servers) via Internet while Maintaining Security of Private LAN

De-Militarized Zone

8

Page 9: Vigor 3300 VigorAccess Product Introduction August, 2005

• Protect the Trusted Network from Various Types Attacks that Explore Protocol Security Holes.

• Benefit of Vigor Firewall– IP-based Packet Filtering.– URL Filtering.– Denial of Service (Dos) Prevention.

– NAT : Port Redirection, Open port, DMZ.

Firewall

9

Page 10: Vigor 3300 VigorAccess Product Introduction August, 2005

• Inappropriate content blocking.– Improve Staff Working Efficiency.

• Benefit of Vigor Content Filtering– Malicious Code Prevention.

(Java,ActiveX,Cookie,exe,zip, ...etc.)– Filtering based on Access List, Keywords, or Time

of Day.

• Bundle with Surf Control Scan Mechanism

URL Filtering

10

Page 11: Vigor 3300 VigorAccess Product Introduction August, 2005

URL Filtering

11

Page 12: Vigor 3300 VigorAccess Product Introduction August, 2005

• Router-based Port Security can be used to Restrict Access to each VLAN as Required.

• Benefit of Vigor VLAN– Isolate Users into the Different VLANs.

Virtual LAN Security

12

Page 13: Vigor 3300 VigorAccess Product Introduction August, 2005

VLAN Architecture

13

Page 14: Vigor 3300 VigorAccess Product Introduction August, 2005

– ICSA IPSec Certification (Vigor3300 series).– Supports 200 IPSec Tunnels.– Hardware-based accelerator of DES/3DES,

AES/HMAC-SHA-1/HMAC-MD5 Encryption.– IPSec, PPTP, L2TP, L2TP over IPSec.– 30Mbps throughput in AES/3DES.– Preshared key and Certificate Authority (X.509 v3)

Authentication.– DHCP over IPsec

– RADIUS client support.

DrayTek VPN Solution

14

Page 15: Vigor 3300 VigorAccess Product Introduction August, 2005

• LAN-to-LAN VPN connection (Gateway-to-Gateway) Made by two Routers to Connect two Portions of Private Networks. The Vigor router support IPSec tunnel protocols.

• Remote Dial-in VPN connection (Host-to-Gateway) Made by a remote access client, or a single user computer, that connects to a private network. In this type of connection, the Vigor router support IPSec tunnel for DHCP over IPsec protocols.

DrayTek VPN Solution

15

To Optical Connection

Page 16: Vigor 3300 VigorAccess Product Introduction August, 2005

• For Windows2000/XP.• Simplifies the Procedures to Create IPSec Tunnel with

the Vigor Router by Easy-to-Use GUI.

Smart VPN Client

16

Page 17: Vigor 3300 VigorAccess Product Introduction August, 2005

VPN Scenario

17

Page 18: Vigor 3300 VigorAccess Product Introduction August, 2005

• VoIP -VoIP - FXO on-net/off-net calling

VoIP ApplicationVoIP Application

18

Page 19: Vigor 3300 VigorAccess Product Introduction August, 2005

• VoIP -VoIP - Integrate FXO to PBX

Case1. From VoIP to Extension

1) David dials the VoIP number of Vigor3300V.2) After connection success, presses Linda’s extension 611.

VoIP ApplicationVoIP Application

19

DavidDavid

LindaLinda

Page 20: Vigor 3300 VigorAccess Product Introduction August, 2005

• VoIP -VoIP - Integrate FXO to PBX

Case2. From VoIP to PSTN (Off-Net Calling)

1) David dials the VoIP number of Vigor3300V.2) After connection success, presses prefix number (e.g. “0”) to

choose exterior line – PSTN.3) Then dials Linda’s PSTN number.

VoIP ApplicationVoIP Application

20

DavidDavid

LindaLinda

Page 21: Vigor 3300 VigorAccess Product Introduction August, 2005

• VoIP -VoIP - Integrate FXO to PBX

Case3. From Extension to VoIP

1) Linda presses extension 610 to connect to Vigor3300V.2) After connection success, dials David’s VoIP number.

VoIP ApplicationVoIP Application

21

DavidDavid

LindaLinda

Page 22: Vigor 3300 VigorAccess Product Introduction August, 2005

• VoIP -VoIP - Integrate FXO to PBX

Case4. From PSTN to VoIP (On-Net Calling)

1) Linda dials to PBX.2) After connection success, presses extension 610 to connect

to Vigor3300V.3) Then dials David’s VoIP number.

VoIP ApplicationVoIP Application

22

DavidDavid

LindaLinda

Page 23: Vigor 3300 VigorAccess Product Introduction August, 2005

• VoIP - VoIP - Integrate FXS to PBX

Case1. From VoIP to Extension

1) David dials the VoIP number of Vigor3300V.2) After connection success, presses Linda’s extension 610.

VoIP ApplicationVoIP Application

23

DavidDavid

LindaLinda

Page 24: Vigor 3300 VigorAccess Product Introduction August, 2005

• VoIP VoIP - - Integrate FXS to PBX

Case1. From VoIP to Extension

VoIP ApplicationVoIP Application

24

DavidDavid

LindaLinda

Page 25: Vigor 3300 VigorAccess Product Introduction August, 2005

• VoIP -VoIP - Integrate FXS to PBX

Case2. From Extension to VoIP

1) Linda presses prefix number (e.g. “7”) to choose exterior line – FXS of Vigor3300V.

2) Then dials David’s VoIP number.

VoIP ApplicationVoIP Application

25

DavidDavid

LindaLinda

Page 26: Vigor 3300 VigorAccess Product Introduction August, 2005

• VoIPVoIP - - Integrate FXS to PBX

Case2. From Extension to VoIP

VoIP ApplicationVoIP Application

26

DavidDavid

LindaLinda

Note: The FXS model can’t provide on-net/off-net calling applications.

Page 27: Vigor 3300 VigorAccess Product Introduction August, 2005

VoIP ApplicationVoIP Application

Secure VoIP– VoIP over VPN– sRTP (Secure Real-Time Transport Protocol)

• Encrypts the Payload of VoIP Packets• Compatible with RTP

Page 28: Vigor 3300 VigorAccess Product Introduction August, 2005

VoIP -VoIP - Integrated Scenario

VoIP ApplicationVoIP Application

28

Page 29: Vigor 3300 VigorAccess Product Introduction August, 2005

Broadband Access Broadband Access Solution Solution

VigorAccessVigorAccess

Page 30: Vigor 3300 VigorAccess Product Introduction August, 2005

• System Benefit

• Product Architecture

• Broadband Application Scenario

• IPDLSAM Advance Feature

• Vigor CMS Feature Description

Page 31: Vigor 3300 VigorAccess Product Introduction August, 2005

System Benefit

New Technology DSL -ADSL2/+

ScalableInventory Saving

Friendly EMS

Reliability Multimedia

QoS

Page 32: Vigor 3300 VigorAccess Product Introduction August, 2005

Product Architecture• Target on Medium-Size CO • up to 168 ADSL2/+• Service and Signaling

– Supports Voice & Data • Modular Flexibility

– 24/48 Ports DSL/Splitter– WAN for FE or GE Interface

• Network Resource Saving• EMS Management and Email Altering • Inventory Savings – Common Equipment on CO & Outside Plant Deployments• Firewall/Security/QoS Optional Support• Ready on April

To MDF

To Optical Fiber

Page 33: Vigor 3300 VigorAccess Product Introduction August, 2005

Features

• Target on Outdoor and Small-Size CO• 19” Rack Mountable Chassis, 1U Height • 24 G.dmt/G.lite/ ADSL/ADSL2/+, and

Splitter build in• WAN Ethernet 10/100 Base-T Interface• MPoA, IPoA• IP ToS• Remote TFTP/FTP

Firmware/Configuration • RS-232 & Telnet Command Line Interface • SNMP In-Band Management Support• Web-based GUI • EMS

– IP Multicast: IGMP Snooping

• Security/Firewall

– Access Control List, Packet Filtering

– Password Protected System

– 512 VLAN (802.1Q)

Page 34: Vigor 3300 VigorAccess Product Introduction August, 2005

Master Feature 2 Selectable WAN Interface - 802.3, 802.3ab Ethernet Standard - 1000 Base-SX Module (SC connector)  - 1000 Base-FX Module(SC connector)  - 1000 Base-T Module(RJ45 connector) - 100 Base-T RJ45 Connector MGN Interface - 1 port RJ45 10/100 Base-T L2 Switch Function - IEEE 802.1d Spanning-Tree Protocol - IEEE 802.3x Flow Control - IEEE 802.1q VLAN - IEEE 802.1p Class of Service (CoS) Prioritization - 4-level Prioritization- 802.1ad Port Trucking/Link Aggregation

Network Operation and Management - User Friendly Web-Based Interface - Telnet Server for Remote Management - TFTP Software Upgrade Utility - Console CLI for Local Management - SNMPv1,v2 - MIBII, Bridge MIB, Ethernet Like MIB, Private MIB, RMON 1,2,3,9 Groups Q.o.S

- Packet filter and Classification.

Page 35: Vigor 3300 VigorAccess Product Introduction August, 2005

Slave FeatureNetwork Interface - Two 10/100M Fast Ethernet Interfaces or one Cascade Link is Gigabit Copper Interface Capacity– It Supports 24 ADSL 2/+ Ports.Security – It Supports Packet Filter, and Password Protection.Splitter Build in – It Supports 24 port xDSL/Splitter.Inventory Savings - Common Equipment across Central Office and Outside Plant DeploymentsManagement – It is managed by IP-DSLAM Master Unit.Q.o.S - Packet Filter and Classification.

Page 36: Vigor 3300 VigorAccess Product Introduction August, 2005

• System Benefit

• Product Architecture

• Broadband Application Scenario

• IPDLSAM Advance Feature

• Vigor CMS Feature Description

Page 37: Vigor 3300 VigorAccess Product Introduction August, 2005

Broadband FTTB Application Scenario

Page 38: Vigor 3300 VigorAccess Product Introduction August, 2005

Broadband Enterprise Application

Page 39: Vigor 3300 VigorAccess Product Introduction August, 2005

Broadband Application Scenario-DSL Extension

Page 40: Vigor 3300 VigorAccess Product Introduction August, 2005

Campus Application

Page 41: Vigor 3300 VigorAccess Product Introduction August, 2005

Hotel Application

Page 42: Vigor 3300 VigorAccess Product Introduction August, 2005

IPDSLAM PPPoE

PPPoE

MAC

PHY

MAC

PHY

ATM

ADSL2/+

1483B MAC

PHY

ATM

ADSL2/+

MAC

PHY

1483B

PPPoE

Page 43: Vigor 3300 VigorAccess Product Introduction August, 2005

PPPoA to PPPoE

IP

MAC

PHY

MAC

PHY

ATM

ADSL2/+

PPPPPP

PHY

ATM

ADSL2/+

IP

MAC

PHY

IP IP

MAC

PPPoE PPPoE

Page 44: Vigor 3300 VigorAccess Product Introduction August, 2005

Static IP Application

Intranet

IP

MAC

PHY

MAC

PHY

ATM

ADSL2/+

1483BMAC

(VLAN)

PHY

ATM

ADSL2/+

1483B

IP

MAC(VLAN)

PHY

Page 45: Vigor 3300 VigorAccess Product Introduction August, 2005

• System Benefit

• Product Architecture

• Broadband Application Scenario

• IPDLSAM Advance Feature

• Vigor CMS Feature Description

Page 46: Vigor 3300 VigorAccess Product Introduction August, 2005

<= 16 MAC Address

16 MAC Address

Limited on One Port

>16 MAC Address

MAC limit -Port Security

Page 47: Vigor 3300 VigorAccess Product Introduction August, 2005

‧ Ethernet

‧ TCP

‧ UDP

‧ ICMP

‧ IGMP

‧ PPP or

‧ Packet Offset

Generic Filter Mechanism

Page 48: Vigor 3300 VigorAccess Product Introduction August, 2005

o Source MAC address

o Destination MAC addresses

o EtherType

o VLAN ID

o Priority Tag

o Destination Service Access Point (DSAP) of 802.2 LLC frame

o Source Service Access Point (SSAP) of 802.2 LLC frame.

Ethernet Type Filter

Page 49: Vigor 3300 VigorAccess Product Introduction August, 2005

‧ IP Layer

o Destination IP Address

o Source IP Address

o IP Protocol type.

‧ TCP Layer

o Destination Port

o Source Port.

‧ UDP Layer

o Destination Port

o Source Port.

‧ ICMP Layer

o ICMP type

o ICMP code.

‧ IGMP Layer

o IGMP Type

o IGMP Code

o Group Address.

‧ PPP Layer

o PPP Protocol type

‧ Packet Offset.

IP/TCP/UDP/ICMP/ PPP/Packet Offset Filter

Page 50: Vigor 3300 VigorAccess Product Introduction August, 2005

‧ Downstream Bandwidth Limit per PVC

‧ Upstream Bandwidth Limit per PVC

‧ 802.1p mapping to Class to Service

‧ Scheduling , Shaper and policing

IP QoS Mechanism

Page 51: Vigor 3300 VigorAccess Product Introduction August, 2005

TR-069 WAN CPE Management

Page 52: Vigor 3300 VigorAccess Product Introduction August, 2005

• Can Limit Incoming Broadcast Packet Rate to Avoid Broadcast Storm

Avoiding Broadcast Storm

Page 53: Vigor 3300 VigorAccess Product Introduction August, 2005

• General class is prohibited to access Luxurious class content

InternetGeneral class

Luxurious Class

General Channel Extra Channel

Triple Play –Channel Classification IPTV

Page 54: Vigor 3300 VigorAccess Product Introduction August, 2005

Agenda

• System Benefit

• Product Architecture

• Broadband Application Scenario

• IPDLSAM Advance Feature

• Vigor CMS Feature Description

Page 55: Vigor 3300 VigorAccess Product Introduction August, 2005

Vigor CMS Scenario Manage SME, Mini DSLAM and Large Scale DSManage SME, Mini DSLAM and Large Scale DSLAMLAM。。 Efficiency Security Management from 1,000 to Efficiency Security Management from 1,000 to 10,000 NEs10,000 NEs

Page 56: Vigor 3300 VigorAccess Product Introduction August, 2005

Vigor CMS Capability

• SNMP In-band through the IP network

• Authentication and Security Management

• Software Download

• Configuration Backup/Restore

• Alarm, Diagnostics, Status Update

• Fault and Performance Management

Page 57: Vigor 3300 VigorAccess Product Introduction August, 2005

– Configuration Management• Auto Provisioning, Firmware Upgrade

– Deployment Management• Configuration Backup/Restore.

– Topology Management• Auto Discovery for Managing Devices. (eg. Add

or Delete from Layer Structure Subnets) – Security Management

• Authentication, Resource Control– Monitor management

• Fault Management, Device Polling

Vigor CMS Vigor CMS Benefit

57

Page 58: Vigor 3300 VigorAccess Product Introduction August, 2005

– Backend Storage Management• Store Alarms, Events and User Activities.

– Interoperability• User Authentication Message that Forwarded to

RADIUS Server could be integrated with Enterprise Security Management.

– Northbound Interface to Bundle with Billing System

• All SNMP Compliant NMS can Receive and Collect Devices Status Information from Vigor CMS through Northbound Interface.

Vigor CMS BenefitVigor CMS Benefit

58

Page 59: Vigor 3300 VigorAccess Product Introduction August, 2005

Status Report

Page 60: Vigor 3300 VigorAccess Product Introduction August, 2005

Alarm Management

Page 61: Vigor 3300 VigorAccess Product Introduction August, 2005

Configuration Management

Page 62: Vigor 3300 VigorAccess Product Introduction August, 2005

Performance Management

Page 63: Vigor 3300 VigorAccess Product Introduction August, 2005

Monitor Management