35 · Introducing Architectures and Virtualization架構與虛擬化簡介

Enterprise Three-Tier Hierarchical Network Design企業三層式階層網路設計

Tiered network design models use a hierarchical design. The key principle of a hierarchical design is that each element in the hierarchy has a specific set of functions and services that it offers and a specific role to play in the design, which allows you to choose the right devices, systems, and features for the layer.

分層網路設計模型採用階層式設計。階層式設計的核心原則是:階層中的每個元素都有一組特定的功能與服務,以及在整體設計中要扮演的特定角色,這讓你能為每一層選擇合適的裝置、系統與功能。

A tiered design brings these benefits:

分層式設計帶來以下優點:

  • A tiered design allows you to better understand the features that may be needed, where they will be needed, and which devices need them within your final solution. Knowing which feature goes where helps when choosing the needed devices.分層式設計能幫助你更了解最終解決方案中可能需要哪些功能、需要在哪裡使用,以及哪些裝置需要這些功能。知道哪個功能該放在哪一層,有助於選擇所需的裝置。
  • A tiered design has stood the test of time, because it can be upgraded as technology changes and it evolves as needs grow. This adaptability allows a corporation to continue with a design philosophy and reuse (or repurpose) equipment, perhaps at a different level, as they upgrade over time.分層式設計經得起時間考驗,因為它可隨技術變化升級,也能隨需求成長而演進。這種適應性讓企業能延續其設計理念,並在升級過程中重複使用(或改用於其他用途)設備,或許是放到不同的層級。
  • A tiered design makes it easy to discuss and learn about a particular part of the solution.分層式設計讓討論與學習解決方案中的特定部分變得容易。
  • The modularity of tiered models is based on designing in layers, each with its own functionalities and devices. The network can expand by adding additional devices in different layers and interconnecting them.分層模型的模組化,建立在依層級設計、各層有各自功能與裝置的基礎上。網路可以透過在不同層加入更多裝置並互連來擴充。

The hierarchical three-tier model includes access, distribution, and core layers.

此階層式三層模型包含存取層、分佈層與核心層。

  • The access layer provides physical connection for devices to access the network. The distribution layer is designed to aggregate traffic from the access layer.存取層提供裝置連上網路的實體連線。分佈層則負責彙整來自存取層的流量。
  • The distribution layer is also called the aggregation layer. As such, it represents a point that most of the traffic traverses. Such a transitory position is appropriate for applying policies, such as QoS, routing, or security policies.分佈層也稱為彙整層。因此,它代表了大部分流量會經過的一個節點。這種轉接性質的位置,非常適合套用政策,例如 QoS、路由或安全性政策。
  • The core layer provides fast transport between distribution layer devices and it is an aggregation point for the rest of the network. All distribution layer devices connect to the core layer. The core layer provides high-speed packet forwarding and redundancy.核心層在分佈層裝置之間提供快速傳輸,並作為整個網路的彙整點。所有分佈層裝置都會連接到核心層。核心層提供高速封包轉送與備援。

If you choose a hierarchical tiered architecture, the exact number of tiers that you would implement in a network depends on the characteristics of the deployment site. For example, a site that occupies a single building might only require two layers while a larger campus of multiple buildings will most likely require three layers. In smaller networks, core and distribution layers are combined and the resulting architecture is called a collapsed core architecture.

若你選擇階層式分層架構,實際要在網路中實作的層級數量,取決於部署地點的特性。例如,占用單一建築的地點可能只需要兩層,而涵蓋多棟建築的較大型園區,則很可能需要三層。在較小型網路中,核心層與分佈層會合併,這種架構稱為折疊核心架構

End devices on the LAN communicate with end devices on the same or separate network segments. If the destination end device is on the same network segment, the request will get switched directly to the connected host. If the destination end device is in another segment, the request traverses one or more extra networks hops, through the distribution layer to the core, which introduces latency. The communication of end devices that flows through other tiers (goes "up and down" the devices) are said to have a "north-south" nature.

LAN 上的終端裝置會與相同或不同網路區段上的終端裝置通訊。若目的終端裝置位於同一網路區段,請求會直接被交換至連接的主機。若目的終端裝置位於另一個區段,請求就要經過一或多個額外的網路跳點,透過分佈層到達核心層,這會帶來延遲。這種流經其他層級(在裝置間「上上下下」)的終端裝置通訊,被稱為具有「南北向」性質。

Typically, devices placed in distribution and core layers are required to be more resilient, have better performance characteristics, and support more features. They are usually termed high-end or higher-end devices in contrast to low-end devices often found in the access layer, which provide only basic functions and features.

一般而言,放置在分佈層與核心層的裝置,需要具備更高的韌性、更佳的效能特性,並支援更多功能。相較於存取層常見、僅提供基本功能的低階裝置,這些裝置通常被稱為高階或更高階裝置。

The three-tier model is usually applied for server and desktop connectivity in a campus. The model has evolved to include a design for small and midsize environments. For example, the figure shows a data center that provides dedicated network services. Note that the figure has the access layer at the top instead of the bottom. Network topologies may have the layers in different positions. However, what is important is the function of each layer, not its position in a diagram. The network provides access to all services available in the data center, such as IP Telephony services, wireless controller services, and network management. It can also include computing and data storage services, located within the data center.

三層式模型通常用於園區中的伺服器與桌上型電腦連線。此模型也演進出適用於中小型環境的設計。舉例來說,圖中展示了一個提供專屬網路服務的資料中心。請注意,圖中將存取層放在頂端而非底部。網路拓樸中的各層可能位於不同位置,然而重要的是各層的功能,而非其在圖中的位置。此網路提供資料中心內所有可用服務的存取,例如 IP 電話服務、無線控制器服務與網路管理。它也可包含位於資料中心內的運算與資料儲存服務。

The three-tier approach is also used for private and public external connections, for instance, in an enterprise edge module that includes private WAN and virtual private network (VPN) connections, and public internet connectivity.

三層式方法也用於私有及公有的外部連線,例如在企業邊緣模組中,包含私有 WAN 與虛擬私人網路(VPN)連線,以及公有網際網路連線。

Access Layer

存取層

The main purpose of the access layer is to enable end devices to connect to the network via high-bandwidth links. It attaches endpoints and devices that extend the network, such as IP phones and wireless APs. The access layer handles different types of traffic, including voice and video that has different demands on network resources.

存取層的主要目的,是讓終端裝置能透過高頻寬鏈路連上網路。它連接端點裝置及延伸網路的設備,例如 IP 電話與無線 AP。存取層會處理不同類型的流量,包括對網路資源需求不同的語音與視訊流量。

The access layer serves several functions, including network access control such as:

存取層提供多項功能,包括如下的網路存取控制:

  • Port security and VLANs連接埠安全性與 VLAN
  • Access control lists (ACLs)存取控制清單(ACL)
  • DHCP snoopingDHCP 窺探
  • Address Resolution Protocol (ARP) inspection位址解析協定(ARP)檢查
  • QoS classification and markingQoS 分類與標記
  • Support for multicast delivery, Power over Ethernet (PoE), and auxiliary VLANs for VoIP支援群播傳送、乙太網路供電(PoE),以及用於 VoIP 的輔助 VLAN

From the device perspective, the access layer is the entry point to the rest of the network and provides redundant uplinks leading to the distribution layer.

從裝置的角度來看,存取層是進入網路其餘部分的入口,並提供通往分佈層的備援上行鏈路。

The access layer can be designed with only Layer 2 devices, or it can include Layer 3 routing. When it provides only Layer 2 switching, VLANs expand up to the distribution layer, where they are terminated. Redundant uplinks between access and distribution layers are blocked due to the Spanning Tree Protocol (STP) operation, which means that available links are underutilized. If the access layer introduces Layer 3 functions, VLANs are terminated on the access layer devices, which participate in routing with distribution devices. Using higher-end switches in the access layer offers greater control over the traffic before it enters the distribution and core layers.

存取層可僅以第 2 層裝置設計,也可包含第 3 層路由。當它僅提供第 2 層交換時,VLAN 會延伸至分佈層並在該處終止。存取層與分佈層之間的備援上行鏈路,因生成樹協定(STP)運作而被阻斷,這表示可用鏈路未被充分利用。若存取層加入第 3 層功能,VLAN 就會在存取層裝置上終止,並與分佈層裝置一起參與路由。在存取層使用更高階的交換器,能在流量進入分佈層與核心層之前提供更好的流量控管。

Distribution Layer

分佈層

At sites with two or more access layer devices, it is impractical to interconnect all access switches. The three-tier architecture model does not interconnect access layer switches. The distribution layer aggregates the high number of connected ports from the access layer below into the core layer above. All traffic generated at the access layer that is not destined to the same access switch traverses a distribution layer device. The distribution layer facilitates connectivity that needs to traverse the LAN end-to-end, whether between different access layer devices or from an access layer device to the WAN or internet. The distribution layer supports many important services.

在有兩台以上存取層裝置的站點,將所有存取交換器互連並不實際。三層式架構模型不會將存取層交換器互連。分佈層會彙整來自下方存取層大量連接埠的流量,並送往上方的核心層。所有在存取層產生、且目的地不是同一台存取交換器的流量,都會經過分佈層裝置。分佈層促成需要橫跨整個 LAN 的連線,無論是不同存取層裝置之間,或存取層裝置到 WAN 或網際網路之間。分佈層支援許多重要服務。

Because of its centralized position in data flows, the distribution layer is the place where routing and packet manipulation are performed and can act as a routing boundary between the access and core layers. The distribution layer performs tasks, such as routing decision-making and filtering to implement policy-based connectivity and QoS.

由於分佈層在資料流中處於核心位置,路由與封包處理都在此進行,並可作為存取層與核心層之間的路由邊界。分佈層執行諸如路由決策及過濾等工作,以實作以政策為基礎的連線與 QoS。

For some networks, the distribution layer offers a default route to access layer routers and runs dynamic routing protocols when communicating with core routers.

在某些網路中,分佈層會為存取層路由器提供預設路由,並在與核心路由器通訊時執行動態路由協定。

The distribution layer uses a combination of Layer 2 switching and Layer 3 routing to segment the network and isolate network problems, preventing these problems from affecting the core layer and other access network segments. This segmentation creates smaller failure domains that compartmentalize network issues.

分佈層結合第 2 層交換與第 3 層路由,將網路分段並隔離網路問題,防止這些問題影響核心層與其他存取網路區段。這種分段會建立較小的故障網域,將網路問題劃分開來。

The network services distribution layer is commonly used to terminate VLANs from access layer switches, also referred to as Layer 2 boundaries. It is often the first point of routing in the physical network and a central point for configuration of Layer 3 features, such as route summarization, DHCP relay, and ACLs.

網路服務分佈層通常用來終止來自存取層交換器的 VLAN,也稱為第 2 層邊界。它通常是實體網路中第一個進行路由的節點,也是設定第 3 層功能(例如路由彙總、DHCP 中繼與 ACL)的核心位置。

The distribution layer implements policies regarding QoS, security, traffic loading, and routing. The distribution layer provides default gateway redundancy by using a First Hop Redundancy Protocol (FHRP), such as Hot Standby Router Protocol (HSRP), Virtual Router Redundancy Protocol (VRRP), or Gateway Load Balancing Protocol (GLBP).

分佈層實作有關 QoS、安全性、流量負載與路由的政策。分佈層透過第一跳備援協定(FHRP),例如熱備援路由器協定(HSRP)、虛擬路由器備援協定(VRRP)或閘道負載平衡協定(GLBP),提供預設閘道的備援。

Core Layer

核心層

The core layer, also called the backbone, binds together all the elements of the campus architecture. The core layer provides fast packet transport for all connecting access and aggregation segments of the entire corporate network (switch blocks) and is the boundary for the corporation when connecting to the outside world.

核心層,也稱為骨幹,將整個園區架構的所有元素連結在一起。核心層為整個企業網路(交換器區塊)中所有互連的存取與彙整區段提供快速封包傳輸,並在連接到外部世界時作為企業的邊界。

The core layer interconnects distribution layer switches. A large LAN environment often has multiple distribution layer switches. When access layer switches are located in multiple geographically dispersed buildings, each location has a distribution layer switch. When the number of access layer switches connecting to a single distribution switch exceeds the performance limits of the distribution switch, then an extra distribution switch is required. In a modular and scalable design, you can colocate distribution layers for the data center, WAN connectivity, or internet edge services.

核心層負責互連分佈層交換器。大型 LAN 環境通常有多台分佈層交換器。當存取層交換器分佈在地理上分散的多棟建築中時,每個地點都會有一台分佈層交換器。當連接到單一分佈層交換器的存取層交換器數量超過該分佈交換器的效能上限時,就需要增加一台額外的分佈交換器。在模組化且可擴充的設計中,你可以將資料中心、WAN 連線或網際網路邊緣服務的分佈層集中放置。

In environments where multiple distribution layer switches exist in proximity and where fiber optics provide the ability for high-bandwidth interconnects, a core layer reduces the network complexity, as the figure shows. Without a core layer, the distribution layer switches will need to be fully meshed. This design is difficult to scale, and increases the cabling as well as port requirements. The routing complexity of a full-mesh design increases as you expand the network.

如圖所示,在多台分佈層交換器彼此鄰近、且光纖能提供高頻寬互連能力的環境中,核心層可降低網路複雜度。若沒有核心層,分佈層交換器就必須採用全網狀連接。這種設計難以擴充,也會增加纜線與連接埠的需求。全網狀設計的路由複雜度,會隨著網路擴充而提高。

The main purpose of the core layer is to provide scalability to reduce the risk from failures while simplifying moves, adds, and changes in the campus. In general, a network that requires routine configuration changes to the core devices does not yet have the appropriate degree of design modularization. As the network increases in size or complexity and changes begin to affect the core devices, it often points out design reasons for physically separating the core and distribution layer functions into a different physical device.

核心層的主要目的,是提供可擴充性以降低故障風險,同時簡化園區中的移動、新增與變更作業。一般而言,若某個網路需要對核心裝置做例行性的設定變更,就代表其設計模組化程度尚未達到應有水準。隨著網路規模或複雜度增加,且變更開始影響核心裝置時,這通常意味著有設計上的理由,需要將核心與分佈層功能實體分離到不同的實體裝置上。

The core layer is, in some ways, the simplest yet most critical part of the campus. It provides a very limited set of services but is redundant and is ideally always online. In the modern business world, it is becoming ever more vital that the core of the network operates as a nonstop, always available system. The core should also have sufficient resources to handle the required data flow capacities of the corporate network.

就某些方面而言,核心層是園區中最簡單卻也最關鍵的部分。它提供的服務相當有限,但必須具備備援,並理想上要永遠保持連線。在現今商業世界中,網路核心要能以不停機、始終可用的系統方式運作,變得日益重要。核心也應具備足夠資源,以應付企業網路所需的資料流量承載能力。

The key design objectives for the core layer are based on providing the appropriate level of redundancy to allow for near-immediate data-flow recovery in the event of the failure of any hardware component. The network design must also permit the occasional, but necessary, hardware and software upgrades or changes to be made without disrupting network operation.

核心層的關鍵設計目標,是提供適當程度的備援,以便在任何硬體元件故障時,能近乎即時地恢復資料流。網路設計也必須允許偶爾但必要的硬體與軟體升級或變更,且不中斷網路運作。

The core layer of the network should not implement any complex policy services, nor should it have any directly attached user or server connections to keep the core of the network manageable, fast, and secure.

為了讓網路核心保持易於管理、快速且安全,核心層不應實作任何複雜的政策服務,也不應直接連接任何使用者或伺服器。

Which three options are common functions of the distribution layer in a three-tier hierarchical model? (Choose three.)在三層式階層模型中,以下哪三項是分佈層的常見功能?(選三項。)