33 · Introducing QoS認識 QoS

QoS MechanismsQoS 機制

QoS mechanisms refer to the set of tools and techniques to manage network resources and are considered the key enabling technology for network convergence. The objective of QoS mechanisms is to make voice, video and data convergence appear transparent to end users. QoS mechanisms allow different types of traffic to contend inequitably for network resources. Voice, video, and critical data applications may be granted priority or preferential services from network devices so that the quality of these strategic applications does not degrade to the point of being unusable. Therefore, QoS is a critical, intrinsic element for successful network convergence.

QoS 機制是指用來管理網路資源的一套工具與技術,被視為實現網路匯流(convergence)的關鍵技術。QoS 機制的目標是讓語音、視訊與資料的匯流對終端使用者而言呈現透明化。QoS 機制允許不同類型的流量以不公平的方式競爭網路資源。語音、視訊及關鍵資料應用程式可從網路裝置獲得優先或優先服務,使這些策略性應用程式的品質不至於降級到無法使用的程度。因此,QoS 是成功實現網路匯流的關鍵且內在的元素。

Several important mechanisms are used to implement a QoS policy in an IP network:

在 IP 網路中實作 QoS 政策時,會使用幾個重要的機制:

  • Classification分類
  • Marking標記
  • Policing and shaping管制與整形
  • Congestion management壅塞管理
  • Congestion avoidance壅塞避免
  • Link efficiency鏈路效率

The following mechanisms are used to implement QoS in a network:

以下機制用於在網路中實作 QoS:

  • Classification:Packet identification and classification determine which treatment that traffic should receive according to behavior and business policies. In a QoS-enabled network, all traffic is typically classified at the input interface of a QoS-aware device at the access layer and network edge.分類:封包識別與分類決定流量應根據行為與業務政策獲得何種處理方式。在啟用 QoS 的網路中,所有流量通常在存取層與網路邊緣的 QoS 感知裝置輸入介面上進行分類。
  • Marking:Packets are marked based upon classification, metering, or both so that other network devices have a mechanism of easily identifying the required treatment. Marking is typically performed as close to the network edge as possible.標記:根據分類、計量或兩者,對封包進行標記,讓其他網路裝置有一種簡單的機制來識別所需的處理方式。標記通常盡可能靠近網路邊緣執行。
  • Congestion management: Each interface must have a queuing mechanism to prioritize the transmission of packets based on the packet marking. Congestion management is normally implemented on all output interfaces in a QoS-enabled network.壅塞管理:每個介面都必須有一套佇列機制,依封包標記優先傳送封包。壅塞管理通常在啟用 QoS 的網路中的所有輸出介面上實作。
  • Congestion avoidance:Specific packets are dropped early, based on marking, in order to avoid congestion on the network. Congestion avoidance mechanisms are typically implemented on output interfaces wherever a high-speed link or set of links feeds into a lower-speed link (such as a LAN feeding into a slower WAN link).壅塞避免:依標記提早捨棄特定封包,以避免網路發生壅塞。壅塞避免機制通常實作於輸出介面上,特別是在高速鏈路或多條鏈路匯入較低速鏈路之處(例如區域網路匯入較慢的 WAN 鏈路)。
  • Policing and shaping:Traffic conditioning mechanisms police traffic by dropping misbehaving traffic to maintain network integrity or shape traffic to control bursts. These mechanisms are used to enforce a rate limit that is based on metering, with excess traffic being dropped, marked, or delayed. Policing mechanisms can be used at either input or output interfaces, while shaping mechanisms are only used on output interfaces.管制與整形:流量調節機制透過捨棄違規流量以維持網路完整性,或透過整形流量來控制突發流量。這些機制用來依計量結果強制執行速率限制,超出的流量會被捨棄、標記或延遲。管制機制可用於輸入或輸出介面,而整形機制僅用於輸出介面。
  • Link efficiency:Link efficiency mechanisms improve bandwidth efficiency or the serialization delay impact of low-speed links through compression and link fragmentation and interleaving. These mechanisms are normally implemented on low-speed WAN links.鏈路效率:鏈路效率機制透過壓縮以及鏈路分片與交錯,改善頻寬效率或降低低速鏈路的序列化延遲影響。這些機制通常實作於低速 WAN 鏈路上。

Cisco network devices can provide a complete toolset of QoS features and solutions for addressing the diverse needs of voice, video and multiple classes of data applications. QoS mechanisms allow complex network control and predictable service for a variety of networked applications and traffic types. They can effectively control bandwidth, delay, jitter, and packet loss. By ensuring the desired results, the QoS mechanisms lead to efficient, predictable services for business-critical applications.

Cisco 網路裝置可提供完整的 QoS 功能與解決方案工具集,以滿足語音、視訊及多種資料應用程式類別的多元需求。QoS 機制能為各種網路應用程式與流量類型提供複雜的網路控制與可預測的服務。它們可有效控制頻寬、延遲、抖動與封包遺失。透過確保預期結果,QoS 機制為關鍵業務應用程式帶來高效且可預測的服務。

Classification and Marking

分類與標記

In any network in which networked applications require differentiated levels of service, traffic must be sorted into different classes upon which QoS is applied. Classification and marking are two critical functions of any successful QoS implementation. Classification allows network devices to identify traffic as belonging to a specific class with specific QoS requirements, as determined by an administrative QoS policy. After network traffic is sorted, individual packets are marked (also called colored) so that other network devices can apply QoS features uniformly to those packets in compliance with the defined QoS policy.

在任何需要為網路應用程式提供差異化服務等級的網路中,流量必須先分類為不同的類別,才能套用 QoS。分類與標記是任何成功 QoS 實作的兩項關鍵功能。分類讓網路裝置能依管理員制定的 QoS 政策,識別出流量屬於具有特定 QoS 需求的特定類別。流量分類完成後,個別封包會被標記(也稱為著色),使其他網路裝置能依已定義的 QoS 政策,對這些封包一致地套用 QoS 功能。

A classifier is a tool that inspects packets within a flow to identify the type of traffic that the packet is carrying. Traffic is then marked so that a policy enforcement mechanism will implement the policy for that type of traffic.

分類器(classifier)是一種工具,用來檢查流量中的封包,以識別封包所承載的流量類型。流量經識別後會被標記,以便政策執行機制能對該類型的流量執行相對應的政策。

Classification is the identifying and splitting of traffic into different classes.

分類是將流量識別並區分為不同類別的過程。

  • It is the most fundamental QoS building block.它是最基本的 QoS 構成要素。
  • Traffic can be classified by various means.流量可透過多種方式進行分類。
  • Without classification, all packets are treated the same.若未進行分類,所有封包都會被同等對待。

Commonly used traffic descriptors include CoS at layer 2, incoming interface, IP Precedence, Differentiated Services Code Point (DSCP) at layer 3, source or destination address, and application. After the packet has been classified, the packet is then available for QoS handling on the network.

常用的流量描述符包括第 2 層的 CoS、輸入介面、IP 優先權(IP Precedence)、第 3 層的差異化服務代碼點(DSCP),以及來源或目的位址、應用程式。封包經分類後,即可在網路中進行 QoS 處理。

Using packet classification, you can partition network traffic into multiple priority levels or classes of service. When traffic descriptors are used to classify traffic, the source agrees to adhere to the contracted terms and the network promises a QoS. Different QoS mechanisms, such as traffic policing, traffic shaping, and queuing techniques, use the classification of the packet to ensure adherence to this agreement.

透過封包分類,你可以將網路流量劃分為多個優先等級或服務類別。當使用流量描述符來分類流量時,來源方同意遵守約定的條款,網路則承諾提供對應的 QoS。不同的 QoS 機制,例如流量管制、流量整形與佇列技術,都會使用封包的分類結果來確保遵守此協議。

Classification should take place at the network edge, typically in the wiring closet, in IP phones or at network endpoints. It is recommended that classification occur as close to the source of the traffic as possible.

分類應在網路邊緣進行,通常是在配線間、IP 電話或網路端點上。建議分類盡可能靠近流量來源進行。

The concept of trust is key for deploying QoS. When an end device (such as a workstation or an IP phone) marks a packet with CoS or DSCP, a switch or router has the option of accepting or not accepting values from the end device. If the switch or router chooses to accept the values, the switch or router trusts the end device. If the switch or router trusts the end device, it does not need to do any reclassification of packets coming from this interface. If the switch or router does not trust the interface, it must perform a reclassification to determine the appropriate QoS value for the packets coming from this interface. Switches and routers are generally set to not trust end devices and must specifically be configured to trust packets coming from an interface.

信任(trust)的概念是部署 QoS 的關鍵。當終端裝置(例如工作站或 IP 電話)以 CoS 或 DSCP 標記封包時,交換器或路由器可以選擇接受或不接受來自該終端裝置的值。若交換器或路由器選擇接受這些值,即表示交換器或路由器信任該終端裝置。若交換器或路由器信任該終端裝置,就不需要對來自該介面的封包進行重新分類。若交換器或路由器不信任該介面,就必須執行重新分類,以判斷來自該介面封包的適當 QoS 值。交換器與路由器通常預設不信任終端裝置,必須特別設定才能信任來自某介面的封包。

Marking is related to classification and allows network devices to classify a packet or frame, based on a specific traffic descriptor.

標記與分類相關,讓網路裝置能依特定流量描述符對封包或框架進行分類。

Marking, also known as coloring, marks each packet as a member of a network class so that the packet class can be quickly recognized throughout the rest of the network.

標記,亦稱為著色,會將每個封包標記為某個網路類別的成員,以便該封包類別能在網路其餘部分被快速識別。

Marking a packet or frame with its classification allows network devices to easily distinguish the marked packet or frame as belonging to a specific class. After the packets or frames are identified as belonging to a specific class, other QoS mechanisms can use these markings to uniformly apply QoS policies.

以類別標記封包或框架,可讓網路裝置輕易分辨該封包或框架屬於特定類別。封包或框架被識別為屬於特定類別後,其他 QoS 機制即可利用這些標記一致地套用 QoS 政策。

CoS, Type of Service (ToS), DSCP, Class Selector, and Traffic Identifier (TID) are different terms to describe designated fields in a frame or packet header. How devices treat packets in your network depends on the field values.

CoS、服務類型(ToS)、DSCP、類別選擇器與流量識別碼(TID)是用來描述框架或封包標頭中指定欄位的不同術語。你的網路裝置如何處理封包,取決於這些欄位的值。

  • CoS is usually used with Ethernet 802.1q frames and contains 3 bits.CoS 通常用於乙太網路 802.1q 框架,佔 3 個位元。
  • ToS is generally used to indicate the Layer 3 IPv4 packet field and comprises 8 bits, 3 of which are designated as the IP Precedence field. IPv6 changes the terminology for the same field in the packet header to "Traffic Class."ToS 通常用來表示第 3 層 IPv4 封包欄位,共 8 個位元,其中 3 個位元被指定為 IP 優先權欄位。IPv6 將封包標頭中相同欄位的術語改為「流量類別(Traffic Class)」。
  • DSCP is a set of 6-bit values that can describe the meaning of the Layer 3 IPv4 ToS field. While IP Precedence is the old way to mark ToS, DSCP is the new way. The transition from IP Precedence to DSCP was made because IP Precedence only offers 3 bits, or eight different values, to describe different classes of traffic. DSCP is backward-compatible with IP Precedence.DSCP 是一組 6 位元的值,可用來描述第 3 層 IPv4 ToS 欄位的意義。IP 優先權是舊有的 ToS 標記方式,DSCP 則是新的方式。從 IP 優先權轉換到 DSCP 的原因是,IP 優先權只提供 3 個位元、即 8 種不同的值來描述不同的流量類別。DSCP 與 IP 優先權向下相容。
  • Class Selectoris a term that is used to indicate a 3-bit subset of DSCP values. The class selector designates the same 3 bits of the field as IP Precedence.類別選擇器(Class Selector)是用來表示 DSCP 值中 3 位元子集的術語。類別選擇器指定的位元與 IP 優先權相同。
  • TID is a term that is used to describe a 4-bit field in the QoS control field of wireless frames (802.11 MAC frame). TID is used for wireless connections, and CoS is used for wired Ethernet connections.TID 是用來描述無線框架(802.11 MAC 框架)QoS 控制欄位中 4 位元欄位的術語。TID 用於無線連線,CoS 則用於有線乙太網路連線。

Ultimately, there are various Layer 2 and Layer 3 mechanisms that are used in the network for marking traffic.

最終,網路中會使用多種第 2 層與第 3 層機制來進行流量標記。

Layer 3 packet marking with IP Precedence and DSCP is the most widely deployed marking option because Layer 3 packet markings have end-to-end significance. Layer 3 markings can also be easily translated to and from Layer 2 markings.

使用 IP 優先權與 DSCP 進行的第 3 層封包標記,是最廣泛部署的標記方式,因為第 3 層封包標記具有端到端的意義。第 3 層標記也可輕易與第 2 層標記互相轉換。

DSCP Encoding

DSCP 編碼

DSCP is encoded in the header of both IPv4 and IPv6 packets.

DSCP 編碼於 IPv4 與 IPv6 封包的標頭中。

DiffServ uses the DiffServ (DS) field in the IP header to mark packets according to their classification. The DS field occupies the eight-bit ToS field in the IPv4 header or the Traffic Class field in the IPv6 header.

DiffServ 使用 IP 標頭中的 DiffServ(DS)欄位,依分類結果標記封包。DS 欄位佔用 IPv4 標頭中 8 位元的 ToS 欄位,或 IPv6 標頭中的流量類別欄位。

The following three IETF standards describe the purpose of the eight bits of the DS field:

以下三項 IETF 標準說明了 DS 欄位 8 個位元的用途:

  1. RFC 791 includes specification of the ToS field, where the high-order three bits are used for IP precedence. The other bits are used for delay, throughput, reliability, and cost.RFC 791 包含 ToS 欄位的規範,其中高位的 3 個位元用於 IP 優先權,其餘位元則用於延遲、吞吐量、可靠性與成本。
  2. RFC 1812 modifies the meaning of the ToS field by removing meaning from the five low-order bits (which should all be "0"). This gained widespread use and became known as the original IP precedence.RFC 1812 修改了 ToS 欄位的意義,移除了低位 5 個位元的意義(應全部為「0」)。此做法被廣泛採用,成為原始的 IP 優先權。
  3. RFC 2474 replaces the ToS field with the DS field, where the six high-order bits are used for the DSCP. The remaining two bits are used for explicit congestion notification. RFC 3260 (New Terminology and Clarifications for DiffServ) updates RFC 2474 and provides terminology clarifications.RFC 2474 以 DS 欄位取代 ToS 欄位,其中高位的 6 個位元用於 DSCP,其餘 2 個位元用於顯式壅塞通知。RFC 3260(DiffServ 新術語與釐清)更新了 RFC 2474,並提供術語上的釐清。

Policing and Shaping

管制與整形

Within a network, different forms of connectivity can have significantly different costs for an organization. Because WAN bandwidth is relatively expensive, many organizations would like to limit the amount of traffic that specific applications can send. This is especially true when enterprise networks use internet connections for connectivity to remote sites and the extranet. Downloading nonbusiness-critical images, music, and movie files can greatly reduce the amount of bandwidth that is available for other mission-critical applications. Traffic policing and traffic shaping are two QoS techniques that can limit the amount of bandwidth that a specific application, user, or class of traffic can use on a link.

在網路中,不同形式的連線對組織而言可能有截然不同的成本。由於 WAN 頻寬相對昂貴,許多組織希望限制特定應用程式可傳送的流量。在企業網路使用網際網路連線連接遠端站點與外部網路時,這一點尤其重要。下載非業務關鍵的圖片、音樂與影片檔案,可能會大幅減少其他關鍵業務應用程式可用的頻寬。流量管制(policing)與流量整形(shaping)是兩種 QoS 技術,可限制特定應用程式、使用者或流量類別在鏈路上可使用的頻寬。

Policers and shapers are both rate-limiters, but they differ in how they treat excess traffic; policers drop it and shapers delay it.

管制器(policer)與整形器(shaper)都是速率限制器,但兩者處理超額流量的方式不同:管制器會捨棄超額流量,整形器則會延遲超額流量。

Policers and shapers are tools that identify and respond to traffic violations. They usually identify traffic violations in a similar manner, but they differ in their response:

管制器與整形器是用來識別並回應流量違規的工具。它們通常以類似的方式識別流量違規,但回應方式不同:

  • Policers perform checks for traffic violations against a configured rate. The action that they take in response is either dropping or re-marking the excess traffic. Policers do not delay traffic; they only check traffic and take action if needed.管制器會針對配置的速率檢查流量是否違規。若發現違規,其採取的動作是捨棄或重新標記超額流量。管制器不會延遲流量,只會檢查流量並在需要時採取動作。
  • Shapers are traffic-smoothing tools that work in cooperation with buffering mechanisms. A shaper does not drop traffic, but it smooths it out so it never exceeds the configured rate. Shapers are usually used to meet service level agreements (SLAs). Whenever the traffic spikes above the contracted rate, the excess traffic is buffered and thus delayed until the offered traffic goes below the contracted rate.整形器是與緩衝機制搭配運作的流量平滑工具。整形器不會捨棄流量,而是將流量平滑化,使其不超過設定的速率。整形器通常用來符合服務等級協議(SLA)。每當流量超出約定速率時,超額流量會被緩衝,因此會延遲,直到提供的流量降到約定速率以下為止。

You can use traffic policing to control the maximum rate of traffic that is sent or received on an interface. Traffic policing is often configured on interfaces at the edge of a network to limit traffic into or out of the network. You can use traffic shaping to control the traffic going out an interface in order to match its flow to the speed of the remote target interface and to ensure that the traffic conforms to policies contracted for it.

你可以使用流量管制來控制介面上傳送或接收流量的最大速率。流量管制通常設定在網路邊緣的介面上,以限制進出網路的流量。你可以使用流量整形來控制介面輸出的流量,使其流量與遠端目標介面的速度相符,並確保流量符合為其約定的政策。

Policer characteristics

管制器的特性

  • They are ideally placed as ingress tools (drop it as soon as possible so you do not waste resources).它們最適合部署為入口(ingress)工具(盡早捨棄,以免浪費資源)。
  • They can be placed at egress to control the amount of traffic per class.它們也可部署在出口(egress),以控制每個類別的流量量。
  • When traffic is exceeded, policers can either drop traffic or remark it.當流量超出時,管制器可選擇捨棄流量或重新標記流量。
  • Significant number of TCP re-sends can occur.可能會發生大量的 TCP 重傳。
  • They do not introduce jitter or delay.不會引入抖動或延遲。

Shaper characteristics

整形器的特性

  • They are usually deployed between enterprise network and the service provider to make sure that enterprise traffic is under contracted rate.通常部署在企業網路與服務提供商之間,以確保企業流量維持在約定速率之內。
  • There are fewer TCP re-sends than with policers.相較於管制器,TCP 重傳次數較少。
  • Shapers introduce delay and jitter.整形器會引入延遲與抖動。

Policers make instantaneous decisions and are thus optimally deployed as ingress tools. The logic is that if you are going to drop the packet, you might as well drop it before spending valuable bandwidth and CPU cycles on it. However, policers can also be deployed at egress to control the bandwidth that a particular class of traffic uses. Such decisions sometimes cannot be made until the packet reaches the egress interface.

管制器會做出即時決策,因此最適合部署為入口工具。其邏輯是:既然要捨棄封包,不如在耗費寶貴的頻寬與 CPU 資源之前就先捨棄它。不過,管制器也可以部署在出口,用來控制特定類別流量所使用的頻寬。有時這類決策要到封包抵達出口介面時才能做出。

When traffic exceeds the allocated rate, the policer can take one of two actions. It can either drop traffic or re-mark it to another class of service. The new class usually has a higher drop probability, which means packets in this new class will be discarded earlier than packets in classes with higher priority.

當流量超出配置的速率時,管制器可採取兩種動作之一:捨棄流量,或將其重新標記為另一個服務類別。新類別通常有較高的捨棄機率,這表示這個新類別中的封包,會比優先等級較高類別中的封包更早被捨棄。

Shapers are commonly deployed on enterprise-to-service provider links on the enterprise egress side. Shapers ensure that traffic going to the service provider does not exceed the contracted rate. If the traffic exceeds the contracted rate, it would get policed by the service provider and likely dropped.

整形器通常部署在企業對服務提供商鏈路的企業出口端。整形器可確保傳送到服務提供商的流量不超過約定速率。若流量超過約定速率,就可能被服務提供商管制並極可能被捨棄。

While policers can cause a significant number of TCP re-sends when traffic is dropped, shaping involves fewer TCP re-sends. Policing does not cause delay or jitter in a traffic stream, but shaping does.

雖然管制器在捨棄流量時可能導致大量 TCP 重傳,但整形涉及的 TCP 重傳較少。管制不會造成流量的延遲或抖動,但整形會。

Traffic-policing mechanisms such as class-based policing also have marking capabilities in addition to rate-limiting capabilities. Instead of dropping the excess traffic, traffic policing can alternatively mark and then send the excess traffic. Excess traffic can be re-marked with a lower priority before the excess traffic is sent out. Traffic shapers, on the other hand, do not re-mark traffic; these only delay excess traffic bursts to conform to a specified rate.

類別式管制(class-based policing)等流量管制機制,除了速率限制能力外,也具備標記能力。流量管制可以不捨棄超額流量,而是改為標記後再傳送超額流量。超額流量在傳送出去之前,可以被重新標記為較低優先權。相對地,流量整形器不會重新標記流量,只會延遲超額流量突發,使其符合指定速率。

Tools for Managing Congestion

壅塞管理工具

Congestion occurs anytime an interface is presented with more traffic than it is able to transmit. Aggressive traffic can fill interface queues and starve more fragile flows such as voice, video, and interactive traffic. The results can be devastating for delay-sensitive traffic types, making it difficult to meet the service-level requirements that these applications require. There are many congestion management techniques available on Cisco platforms that can provide effective means to manage software queues and to allocate the required bandwidth to specific applications when congestion exists.

只要介面收到的流量超過其可傳送的量,就會發生壅塞。過於激進的流量可能會填滿介面佇列,並排擠語音、視訊與互動式流量等較脆弱的流量。對延遲敏感的流量類型而言,這種情況可能造成嚴重後果,使其難以滿足所需的服務等級要求。Cisco 平台上有許多壅塞管理技術,可有效管理軟體佇列,並在發生壅塞時將所需頻寬分配給特定應用程式。

Whenever a packet arrives at an exit interface faster than it can exit, the potential for congestion exists. If there is no congestion, packets are sent when they arrive at the exit interface. If congestion occurs, congestion management tools are activated.

每當封包抵達出口介面的速度快過其可離開的速度時,就存在發生壅塞的可能性。若沒有壅塞,封包抵達出口介面時即會被傳送。若發生壅塞,壅塞管理工具就會啟動。

Congestion management tools include the following:

壅塞管理工具包括:

  • Scheduling is a process of deciding which packet should be sent out next. Scheduling occurs regardless of whether there is congestion on the link; if there is no congestion, packets are sent as they arrive at the interface.排程(Scheduling)是決定接下來應傳送哪個封包的過程。無論鏈路上是否發生壅塞,排程都會進行;若無壅塞,封包抵達介面時即會被傳送。
  • Queuing (or buffering) is the logic of ordering packets in output buffers. It is only activated when congestion occurs. When queues fill up, packets can be reordered so that the higher-priority packets can be sent out of the exit interface sooner than the lower-priority packets.佇列(Queuing)(或稱緩衝)是在輸出緩衝區中對封包排序的邏輯。只有在發生壅塞時才會啟動。當佇列填滿時,封包可能會被重新排序,使優先權較高的封包能比優先權較低的封包更早從出口介面送出。

Traffic scheduling is the methodical output of packets at a desired frequency to accomplish a consistent flow of traffic. You can apply traffic scheduling to different traffic classes to weight the traffic by priority. Different scheduling mechanisms exist. The following are three basic examples:

流量排程是以理想的頻率有系統地輸出封包,以達成一致的流量傳輸。你可以將流量排程套用於不同的流量類別,依優先權為流量加權。存在多種不同的排程機制,以下是三個基本範例:

  • Strict priority:The queues with lower priority are only served when the higher-priority queues are empty. There is a risk with this kind of scheduler that the lower-priority traffic will never be processed. This situation is commonly referred to as traffic starvation.嚴格優先權(Strict priority):只有在優先權較高的佇列為空時,才會服務優先權較低的佇列。這種排程器有一種風險,就是優先權較低的流量可能永遠不會被處理,此情況通常稱為流量餓死(starvation)。
  • Round-robin:Packets in queues are served in a set sequence. There is no starvation with this scheduler, but delays can badly affect the real-time traffic.循環(Round-robin):佇列中的封包依固定順序被服務。這種排程器不會有餓死問題,但延遲可能嚴重影響即時流量。
  • Weighted fair: Queues are weighted, so that some are served more frequently than others. This method thus solves starvation and also gives priority to real-time traffic. One drawback is that this method does not provide bandwidth guarantees. The resulting bandwidth per flow varies based on the number of flows present and the weights of each of the other flows加權公平(Weighted fair):佇列會被加權,使某些佇列被服務的頻率高於其他佇列。這種方法因此解決了餓死問題,也優先處理即時流量。其缺點是無法保證頻寬,每個流量的最終頻寬會依當下存在的流量數量與各流量的權重而異。

The scheduling tools that you use for QoS deployments therefore offer a combination of these algorithms and various ways to mitigate their downsides. This combination allows you to best tune your network for the actual traffic flows that are present.

因此,你在 QoS 部署中使用的排程工具,會結合這些演算法並以各種方式緩解其缺點。這種組合可讓你依照實際存在的流量狀況,最佳化你的網路。

Queuing algorithms are one of the primary ways to manage congestion in a network. Network devices handle an overflow of arriving traffic by using a queuing algorithm to sort traffic and determine a method of prioritizing the traffic onto an output link. Each queuing algorithm was designed to solve a specific network traffic problem and has a particular effect on network performance.

佇列演算法是管理網路壅塞的主要方式之一。網路裝置透過佇列演算法對流量進行排序,並決定將流量優先送上輸出鏈路的方法,以處理湧入流量的溢出。每種佇列演算法都是為解決特定的網路流量問題而設計,對網路效能有其特定影響。

There are many different queuing mechanisms. Older methods are insufficient for modern rich-media networks. However, you need to understand these older methods to comprehend the newer methods:

佇列機制種類繁多。較舊的方法已不足以應付現代豐富媒體網路,但你仍須了解這些較舊的方法,才能理解較新的方法:

  • First-In, First-Out (FIFO) is a single queue with packets that are sent in the exact order that they arrived.先進先出(First-In, First-Out,FIFO)是一種單一佇列,封包依抵達的確切順序被傳送。
  • Priority Queuing (PQ) is a set of four queues that are served in strict-priority order. By enforcing strict priority, the lower-priority queues are served only when the higher-priority queues are empty. This method can starve traffic in the lower-priority queues.優先權佇列(Priority Queuing,PQ)是一組 4 個佇列,依嚴格優先順序被服務。由於強制執行嚴格優先權,只有在優先權較高的佇列為空時,才會服務優先權較低的佇列。此方法可能導致優先權較低佇列中的流量餓死。
  • Custom Queueing (CQ) is a set of 16 queues with a round-robin scheduler. To prevent traffic starvation, it provides traffic guarantees. The drawback of this method is that it does not provide strict priority for real-time traffic.自訂佇列(Custom Queueing,CQ)是一組 16 個佇列,搭配循環排程器。為防止流量餓死,它提供流量保證。此方法的缺點是無法為即時流量提供嚴格優先權。
  • Weighted Fair Queuing (WFQ) is an algorithm that divides the interface bandwidth by the number of flows, thus ensuring proper distribution of the bandwidth for all applications. This method provides a good service for the real-time traffic, but there are no guarantees for a particular flow.加權公平佇列(Weighted Fair Queuing,WFQ)是一種依流量數量劃分介面頻寬的演算法,確保所有應用程式都能獲得妥善分配的頻寬。此方法可為即時流量提供良好的服務,但無法為特定流量提供保證。

Here are two examples of newer queuing mechanisms that are recommended for rich-media networks:

以下是兩個適用於豐富媒體網路的新式佇列機制範例:

  • CBWFQ is a combination of bandwidth guarantee with dynamic fairness of other flows. It does not provide latency guarantee and is only suitable for data traffic management.CBWFQ 結合了頻寬保證與其他流量的動態公平性,但不提供延遲保證,僅適用於資料流量管理。
  • LLQ is a method that is essentially CBWFQ with strict priority. This method is suitable for mixes of data and real-time traffic. LLQ provides both latency and bandwidth guarantees.LLQ 本質上是具有嚴格優先權的 CBWFQ。此方法適用於資料與即時流量混合的情況,可同時提供延遲與頻寬保證。

With CBWFQ, you define the traffic classes based on match criteria, including protocols, Access Control Lists (ACLs), and input interfaces. Packets satisfying the match criteria for a class constitute the traffic for that class. A queue is reserved for each class, and traffic belonging to a class is directed to that class queue.

使用 CBWFQ 時,你可依比對條件(包括通訊協定、存取控制清單(ACL)與輸入介面)定義流量類別。符合某類別比對條件的封包即構成該類別的流量。每個類別都會保留一個佇列,屬於該類別的流量會被導向該類別佇列。

After a class has been defined according to its match criteria, you can assign characteristics to it. To characterize a class, you assign it the minimum bandwidth that it will be delivered during congestion.

類別依其比對條件定義完成後,你可以為其指派特性。為某類別設定特性時,你會指派它在壅塞期間應獲得傳送的最小頻寬。

To characterize a class, you also specify the queue limit for that class, which is the maximum number of packets allowed to accumulate in the class queue. Packets belonging to a class are subject to the bandwidth and queue limits that characterize the class. After a queue has reached its configured queue limit, enqueuing of additional packets to the class causes tail drop or random packet drop to take effect, depending on how the class policy is configured.

為類別設定特性時,你也要指定該類別的佇列限制,也就是該類別佇列中允許累積封包的最大數量。屬於某類別的封包受該類別所設定的頻寬與佇列限制約束。佇列一旦達到設定的佇列限制,再將封包排入該類別,就會觸發尾端捨棄(tail drop)或隨機封包捨棄,視類別政策的設定而定。

For CBWFQ, the weight for a packet belonging to a specific class is derived from the bandwidth that you assigned to the class when you configured it. Therefore, the bandwidth assigned to the packets of a class determines the order in which packets are sent. All packets are serviced fairly based on weight; no class of packets may be granted strict priority. This scheme poses problems for voice traffic, which is largely intolerant of delay, especially jitter.

對 CBWFQ 而言,屬於某特定類別封包的權重是依你在設定該類別時指派的頻寬而定。因此,指派給某類別封包的頻寬決定了封包被傳送的順序。所有封包都依權重公平地被服務,沒有任何類別的封包能獲得嚴格優先權。這種方式對語音流量而言會有問題,因為語音流量對延遲、尤其是抖動的容忍度很低。

The LLQ brings strict priority queuing to CBWFQ. Strict priority queuing allows delay-sensitive data such as voice to be dequeued and sent first (before packets in other queues are dequeued), giving delay-sensitive data preferential treatment over other traffic.

LLQ 為 CBWFQ 帶來了嚴格優先權佇列。嚴格優先權佇列讓語音等對延遲敏感的資料能優先被取出並傳送(早於其他佇列中封包被取出之前),使對延遲敏感的資料獲得優於其他流量的優先處理。

Tools for Congestion Avoidance

壅塞避免工具

Congestion is a normal occurrence in networks. Whether congestion occurs as a result of a lack of buffer space, network aggregation points, or a low-speed wide-area link, many congestion management techniques exist to ensure that specific applications and traffic classes are given their share of available bandwidth when congestion occurs. When congestion occurs, some traffic is delayed or even dropped at the expense of other traffic. When drops occur, different problems may arise that can exacerbate the congestion, such as retransmissions and TCP global synchronization in TCP/IP networks. Network administrators can use congestion avoidance mechanisms to reduce the negative effects of congestion by penalizing the most aggressive traffic streams as software queues begin to fill.

壅塞是網路中的正常現象。無論壅塞是由於緩衝空間不足、網路匯聚點,還是低速廣域鏈路所造成,都存在許多壅塞管理技術,可確保特定應用程式與流量類別在發生壅塞時獲得應有的可用頻寬份額。發生壅塞時,部分流量會被延遲,甚至以犧牲其他流量為代價而被捨棄。發生捨棄時,可能引發其他問題,進而加劇壅塞,例如 TCP/IP 網路中的重傳與 TCP 全域同步。網路管理員可使用壅塞避免機制,在軟體佇列開始填滿時懲罰最激進的流量流,以降低壅塞的負面影響。

TCP has built-in flow control mechanisms that operate by increasing the transmission rates of traffic flows until packet loss occurs. When packet loss occurs, TCP drastically slows down the transmission rate and then again begins to increase the transmission rate. Because of TCP behavior, tail drop of traffic can result in suboptimal bandwidth utilization. TCP global synchronization is a phenomenon that can happen to TCP flows during periods of congestion because each sender will reduce the transmission rate at the same time when packet loss occurs

TCP 具有內建的流量控制機制,其運作方式是持續提高流量流的傳輸速率,直到發生封包遺失為止。發生封包遺失時,TCP 會大幅降低傳輸速率,然後再度開始提高傳輸速率。由於 TCP 的這種行為,流量的尾端捨棄可能導致頻寬使用效率不佳。TCP 全域同步是一種現象,可能發生在壅塞期間的 TCP 流量中,因為當封包遺失發生時,每個傳送端會同時降低傳輸速率。

Congestion avoidance techniques are advanced packet-discard techniques that monitor network traffic loads in an effort to anticipate and avoid congestion at common network bottleneck points.

壅塞避免技術是一種進階的封包捨棄技術,會監控網路流量負載,以嘗試預測並避免在常見網路瓶頸點發生壅塞。

Queues are finite on any interface. Devices can either wait for queues to fill up and then start dropping packets, or drop packets before the queues fill up. Dropping packets as they arrive is called tail drop. Selective dropping of packets while queues are filling up is called congestion avoidance. Queuing algorithms manage the front of the queue, and congestion mechanisms manage the back of the queue.

任何介面上的佇列容量都是有限的。裝置可以等待佇列填滿後才開始捨棄封包,也可以在佇列填滿之前就先捨棄封包。封包一到達就被捨棄稱為尾端捨棄(tail drop);在佇列填滿過程中選擇性地捨棄封包則稱為壅塞避免。佇列演算法管理佇列的前端,壅塞機制則管理佇列的後端。

Randomly dropping packets instead of dropping them all at once, as it is done in a tail drop, avoids global synchronization of TCP streams. One such mechanism that randomly drops packets is random early detection (RED). RED monitors the buffer depth and performs early discards (drops) on random packets when the minimum defined queue threshold is exceeded.

與尾端捨棄一次性全部捨棄不同,隨機捨棄封包可避免 TCP 流量的全域同步。其中一種隨機捨棄封包的機制是隨機早期偵測(Random Early Detection,RED)。RED 會監控緩衝區深度,並在超過所定義的最小佇列門檻時,對隨機封包執行早期捨棄。

Cisco IOS Software does not support pure RED, but does support WRED. The principle is the same as with RED, except that the traffic weights skew the randomness of the packet drop. In other words, traffic that is more important will be less likely to be dropped than less important traffic.

Cisco IOS 軟體不支援純粹的 RED,但支援 WRED。其原理與 RED 相同,差別在於流量權重會使封包捨棄的隨機性產生偏斜。換句話說,較重要的流量被捨棄的機率會低於較不重要的流量。

The idea behind using WRED is both to maintain the queue length at a level somewhere between the minimum and maximum thresholds and to implement different drop policies for different classes of traffic. WRED can selectively discard lower-priority traffic when the interface becomes congested, and it can provide differentiated performance characteristics for different classes of service.

使用 WRED 的用意,一是將佇列長度維持在最小與最大門檻之間的某個水準,二是為不同類別的流量實作不同的捨棄政策。當介面發生壅塞時,WRED 可以選擇性地捨棄優先權較低的流量,並為不同服務類別提供差異化的效能特性。

The figure shows how WRED is implemented, as well as the parameters that WRED uses to influence packet-drop decisions.

此圖顯示 WRED 的實作方式,以及 WRED 用來影響封包捨棄決策的參數。

WRED Building Blocks

WRED 的構成要素

The router constantly updates the WRED algorithm with the calculated average queue length, which is based on the recent history of queue lengths.

路由器會持續以計算出的平均佇列長度更新 WRED 演算法,此平均值是依最近的佇列長度歷史記錄計算而得。

When a packet arrives at the output queue, the QoS marking value is used to select the correct WRED profile for the packet. The packet is then passed to WRED for processing. Based on the selected traffic profile and the average queue length, WRED calculates the probability for dropping the current packet (Probability Denominator). If the average queue length is greater than the minimum threshold but less than the maximum threshold, WRED will either queue the packet or perform a random drop. If the average queue length is less than the minimum threshold, the packet is passed to the output queue.

當封包抵達輸出佇列時,會使用 QoS 標記值來選擇適用於該封包的正確 WRED 設定檔。接著封包會被傳遞給 WRED 進行處理。根據所選的流量設定檔與平均佇列長度,WRED 會計算捨棄目前封包的機率(機率分母)。若平均佇列長度大於最小門檻但小於最大門檻,WRED 會將封包排入佇列或執行隨機捨棄。若平均佇列長度小於最小門檻,封包會被傳遞至輸出佇列。

If the queue is already full, the packet is tail-dropped. Otherwise, the packet will eventually be transmitted out onto the interface.

若佇列已滿,封包會被尾端捨棄。否則,封包最終會被傳送到該介面上。

Link Efficiency Mechanisms

鏈路效率機制

Increasing the bandwidth of WAN links can be expensive. An alternative is to use QoS techniques to improve the efficiency of low-bandwidth links, which, in this context, typically refer to links with speeds less than or equal to 768 kbps. Header compression and payload compression mechanisms reduce the sizes of packets, reducing delay and increasing available bandwidth on a link. Other QoS link efficiency techniques, such as Link Fragmentation and Interleaving (LFI), allow traffic types, such as voice and interactive traffic, to be sent either ahead or interleaved with larger, more aggressive flows. These techniques decrease latency and assist in meeting the service-level requirements of delay-sensitive traffic.

提升 WAN 鏈路的頻寬可能成本高昂。另一種方式是使用 QoS 技術來改善低頻寬鏈路的效率,在此情境下,低頻寬鏈路通常是指速率小於或等於 768 kbps 的鏈路。標頭壓縮與承載資料壓縮機制可縮小封包大小,減少延遲並增加鏈路上的可用頻寬。其他 QoS 鏈路效率技術,例如鏈路分片與交錯(Link Fragmentation and Interleaving,LFI),可讓語音與互動式流量等流量類型,在較大、較激進的流量之前或與其交錯傳送。這些技術可降低延遲,有助於滿足對延遲敏感流量的服務等級要求。

While many QoS mechanisms exist for optimizing throughput and reducing delay in network traffic, QoS mechanisms do not create bandwidth. QoS mechanisms optimize the use of existing resources, and they enable the differentiation of traffic according to a policy. Link efficiency QoS mechanisms such as payload compression, header compression, and LFI are deployed on WAN links to optimize the use of WAN links.

雖然存在許多用於最佳化吞吐量並降低網路流量延遲的 QoS 機制,但 QoS 機制並不會創造頻寬。QoS 機制是最佳化既有資源的使用,並依政策實現流量的差異化處理。承載資料壓縮、標頭壓縮與 LFI 等鏈路效率 QoS 機制,會部署在 WAN 鏈路上,以最佳化 WAN 鏈路的使用。

Payload compression increases the amount of data that can be sent through a transmission resource. Payload compression is primarily performed on Layer 2 frames and therefore compresses the entire Layer 3 packet. The Layer 2 payload compression methods include Stacker, Predictor, and Microsoft Point-to-Point Compression (MPPC).

承載資料壓縮可增加透過傳輸資源傳送的資料量。承載資料壓縮主要在第 2 層框架上執行,因此會壓縮整個第 3 層封包。第 2 層承載資料壓縮方法包括 Stacker、Predictor 與 Microsoft 點對點壓縮(MPPC)。

Compression methods are based on eliminating redundancy. The protocol header is an item of repeated data. The protocol header information in each packet in the same flow does not change much over the lifetime of that flow. Using header compression mechanisms, most header information can be sent only at the beginning of the session, stored in a dictionary, and then referenced in later packets by a short dictionary index. Cisco IOS header compression methods include TCP header compression, Real-Time Transport Protocol (RTP) header compression, class-based TCP header compression, and class-based RTP header compression.

壓縮方法的基礎在於消除冗餘。通訊協定標頭是一種重複出現的資料項目。同一流量中每個封包的通訊協定標頭資訊,在該流量的生命週期內變化不大。使用標頭壓縮機制,大部分的標頭資訊只需在會話開始時傳送一次,儲存於字典中,之後的封包只需以簡短的字典索引來參照即可。Cisco IOS 的標頭壓縮方法包括 TCP 標頭壓縮、即時傳輸協定(RTP)標頭壓縮、類別式 TCP 標頭壓縮,以及類別式 RTP 標頭壓縮。

It is important to note that Layer 2 payload compression and header compression are performed on a link-by-link basis. These compression techniques cannot be performed across multiple routers because routers need full Layer 3 header information to be able to route packets to the next hop.

值得注意的是,第 2 層承載資料壓縮與標頭壓縮是以逐段鏈路為基礎執行的。這些壓縮技術無法跨越多台路由器執行,因為路由器需要完整的第 3 層標頭資訊才能將封包路由到下一跳。

LFI is a Layer 2 technique in which large frames are broken into smaller, equally sized fragments and then transmitted over the link in an interleaved fashion with more latency-sensitive traffic flows (like Voice over IP). Using LFI, smaller frames are prioritized, and a mixture of fragments is sent over the link. LFI reduces the queuing delay of small frames because the frames are sent almost immediately. Link fragmentation, therefore, reduces delay and jitter by expediting the transfer of smaller frames through the hardware transmit queue.

LFI 是一種第 2 層技術,將大型框架切割成較小、大小相等的片段,再以交錯方式與延遲敏感度較高的流量流(例如 VoIP)一起透過鏈路傳送。使用 LFI 後,較小的框架會被優先處理,並在鏈路上傳送混合的片段。由於框架幾乎能立即被傳送,LFI 降低了小型框架的佇列延遲。因此,鏈路分片可透過加速小型框架通過硬體傳輸佇列,降低延遲與抖動。

Which QoS mechanism will delay traffic if a session uses more than the allotted bandwidth?當某個工作階段使用的頻寬超過分配額度時,哪一種 QoS 機制會延遲流量?
Which statement regarding QoS mechanisms is correct?關於 QoS 機制,下列哪一項敘述正確?
Which queuing mechanism has a single queue and sends packets in the exact order that they arrived?哪一種佇列機制只有單一佇列,並依封包抵達的確切順序傳送?
Which option is a congestion avoidance mechanism?下列何者是壅塞避免機制?