企業(yè)監(jiān)控網(wǎng)絡(luò)系統(tǒng)升級(jí)改造
原創(chuàng)【51CTO專稿】我單位因?yàn)榘踩a(chǎn)需要,部署了涉及整個(gè)下級(jí)生產(chǎn)部門及各生產(chǎn)崗位的全天候監(jiān)控系統(tǒng)。同時(shí)該系統(tǒng)也負(fù)責(zé)向上級(jí)管理單位提供視頻監(jiān)控的實(shí)時(shí)查看以及錄像資料調(diào)取和上傳功能。因?yàn)閱挝坏乩砦恢梅稚?,主干網(wǎng)絡(luò)采用了廣域網(wǎng)技術(shù)進(jìn)行實(shí)施,為了支持7X24小時(shí)應(yīng)用的需求,網(wǎng)絡(luò)在鏈路層被設(shè)計(jì)為星環(huán)網(wǎng)結(jié)構(gòu)。但方案實(shí)施后發(fā)現(xiàn),因?yàn)樵缙谕度氲牟蛔阋约霸O(shè)計(jì)上的缺陷,網(wǎng)絡(luò)依然不能很好的支持7X24應(yīng)用的要求,經(jīng)常發(fā)生網(wǎng)絡(luò)中斷或者下級(jí)單位硬盤錄像機(jī)無法回傳圖像等問題。尤其是作為網(wǎng)絡(luò)核心層的匯聚路由器,因?yàn)樯婕暗南录?jí)單位2M接入端口多,只能使用多臺(tái)路由器進(jìn)行匯聚,再將各路由器通過交換機(jī)進(jìn)行連接,同時(shí)其中一臺(tái)路由器需要擔(dān)當(dāng)網(wǎng)絡(luò)邊界路由器功能,為處于辦公網(wǎng)絡(luò)環(huán)境中的各主機(jī)節(jié)點(diǎn)以及上級(jí)單位用戶提供視頻監(jiān)控服務(wù)功能,交換機(jī)因此長期處于高負(fù)荷狀態(tài),同時(shí)因?yàn)閰R聚路由器只能相對(duì)單獨(dú)工作,其中某一路由器故障后,在其上所有的接入點(diǎn)網(wǎng)絡(luò)都將故障,導(dǎo)致該視頻監(jiān)控系統(tǒng)不能很好的穩(wěn)定工作,影響視頻監(jiān)控的圖像回傳質(zhì)量和效果。
需求分析
通過技術(shù)部門對(duì)前期網(wǎng)絡(luò)存在問題的分析以及對(duì)未來網(wǎng)絡(luò)必須滿足7X24小時(shí)應(yīng)用的強(qiáng)實(shí)時(shí)要求,此次項(xiàng)目升級(jí)改造目標(biāo)是構(gòu)建一個(gè)"安全穩(wěn)定,實(shí)時(shí)有效,高效負(fù)載"的系統(tǒng)架構(gòu)。以達(dá)到安全生產(chǎn)監(jiān)控系統(tǒng)對(duì)安全工作實(shí)時(shí)有效的監(jiān)控和管理,此次網(wǎng)絡(luò)改造主要是對(duì)網(wǎng)絡(luò)匯聚核心層從新設(shè)計(jì)和部署,同時(shí)從新規(guī)劃主干網(wǎng)絡(luò)中星環(huán)網(wǎng)的拓?fù)洌⒃趨R聚核心層提供路由器的在線熱負(fù)載備份模式。
實(shí)施方案
1、網(wǎng)絡(luò)核心層規(guī)劃:
將原核心層路由器由4臺(tái)接入層普通路由器更換為2臺(tái)H3C MSR36-20匯聚路由器,并在核心層路由器中使用VRRP路由熱負(fù)載技術(shù)對(duì)該兩臺(tái)核心路由器進(jìn)行LAN口熱備模式設(shè)置,將其中的一個(gè)LAN口設(shè)置為WLAN口地址進(jìn)行WLAN口數(shù)據(jù)的直接交換。核心層路由器核心參數(shù)分別配置如下:
1.1、Master路由器配置:
- sysname MASTER_JiangKong_2
- #
- telnet server enable
- #
- router id 196.*.*.5
- #
- ospf 196
- peer 196.*.*.50
- peer 196.*.*.62
- peer 196.*.*.86
- peer 196.*.*.106
- peer 196.*.*.122
- peer 196.*.*.126
- peer 196.*.*.142
- peer 196.*.*.154
- peer 196.*.*.241
- area 0.0.0.0
- network 10.*.*.0 0.0.0.255
- network 196.*.*.0 0.0.0.255
- network 196.*.*.48 0.0.0.3
- network 196.*.*.60 0.0.0.3
- network 196.*.*.84 0.0.0.3
- network 196.*.*.104 0.0.0.3
- network 196.*.*.120 0.0.0.3
- network 196.*.*.124 0.0.0.3
- network 196.*.*.140 0.0.0.3
- network 196.*.*.152 0.0.0.3
- network 196.*.*.240 0.0.0.3
- #
- system-working-mode
- password-recovery enable
- #
- vlan 1
- #
- controller Cellular0/0
- #
- controller Cellular0/1
- #
- interface Aux0
- #
- interface Serial5/0
- fe1 unframed
- ip address 196.*.*.49 255.255.255.252
- ospf network-type p2p
- #
- interface Serial5/1
- fe1 unframed
- ip address 196.*.*.61 255.255.255.252
- ospf network-type p2p
- #
- interface Serial5/2
- fe1 unframed
- ip address 196.*.*.85 255.255.255.252
- ospf network-type p2p
- #
- interface Serial5/3
- fe1 unframed
- ip address 196.*.*.105 255.255.255.252
- ospf network-type p2p
- #
- interface Serial6/0
- fe1 unframed
- ip address 196.*.*.121 255.255.255.252
- ospf network-type p2p
- #
- interface Serial6/1
- fe1 unframed
- ip address 196.*.*.153 255.255.255.252
- ospf network-type p2p
- #
- interface Serial6/2
- fe1 unframed
- ip address 196.*.*.141 255.255.255.252
- ospf network-type p2p
- #
- interface Serial6/3
- fe1 unframed
- ip address 196.*.*.125 255.255.255.252
- ospf network-type p2p
- #
- interface NULL0
- #
- interface GigabitEthernet0/0
- port link-mode route
- combo enable copper
- ip address 196.*.*.5 255.255.255.0
- vrrp vrid 1 virtual-ip 196.*.*.1
- vrrp vrid 1 priority 120
- vrrp vrid 1 preempt-mode delay 5
- #
- interface GigabitEthernet0/1
- port link-mode route
- ip address 196.*.*.242 255.255.255.252
- #
- interface GigabitEthernet0/2
- port link-mode route
- ip address 10.*.*.252 255.255.255.0
- vrrp vrid 2 virtual-ip 10.*.*.2
- vrrp vrid 2 priority 120
- vrrp vrid 2 preempt-mode delay 5
- #
1.2、Backup路由器重要參數(shù)配置:
- sysname BACKUP_JianKong_1
- #
- telnet server enable
- #
- router id 196.*.*.4
- #
- ospf 196
- peer 196.*.*.5
- peer 196.*.*.9
- peer 196.*.*.14
- peer 196.*.*.18
- peer 196.*.*.26
- peer 196.*.*.46
- peer 196.*.*.66
- peer 196.*.*.82
- peer 196.*.*.158
- peer 196.*.*.174
- peer 196.*.*.178
- peer 196.*.*.194
- peer 196.*.*.198
- peer 196.*.*.210
- peer 196.*.*.214
- peer 196.*.*.230
- peer 196.*.*.242
- area 0.0.0.0
- network 10.*.*.0 0.0.0.255
- network 196.*.*.0 0.0.0.255
- network 196.*.*.4 0.0.0.3
- network 196.*.*.8 0.0.0.3
- network 196.*.*.12 0.0.0.3
- network 196.*.*.16 0.0.0.3
- network 196.*.*.24 0.0.0.3
- network 196.*.*.44 0.0.0.3
- network 196.*.*.64 0.0.0.3
- network 196.*.*.80 0.0.0.3
- network 196.*.*.156 0.0.0.3
- network 196.*.*.172 0.0.0.3
- network 196.*.*.176 0.0.0.3
- network 196.*.*.192 0.0.0.3
- network 196.*.*.196 0.0.0.3
- network 196.*.*.208 0.0.0.3
- network 196.*.*.212 0.0.0.3
- network 196.*.*.228 0.0.0.3
- network 196.*.*.240 0.0.0.3
- #
- ip unreachables enable
- ip ttl-expires enable
- #
- system-working-mode
- password-recovery enable
- #
- vlan 1
- #
- controller Cellular0/0
- #
- controller Cellular0/1
- #
- interface Aux0
- #
- interface Serial5/0
- fe1 unframed
- ip address 196.*.*.197 255.255.255.252
- ospf network-type p2p
- #
- interface Serial5/1
- fe1 unframed
- ip address 196.*.*.209 255.255.255.252
- ospf network-type p2p
- #
- interface Serial5/2
- fe1 unframed
- ip address 196.*.*.177 255.255.255.252
- ospf network-type p2p
- #
- interface Serial5/3
- fe1 unframed
- ip address 196.*.*.193 255.255.255.252
- #
- interface Serial5/4
- fe1 unframed
- ip address 196.*.*.157 255.255.255.252
- ospf network-type p2p
- #
- interface Serial5/5
- fe1 unframed
- ip address 196.*.*.173 255.255.255.252
- ospf network-type p2p
- #
- interface Serial5/6
- fe1 unframed
- ip address 196.*.*.25 255.255.255.252
- ospf network-type p2p
- #
- interface Serial5/7
- fe1 unframed
- ip address 196.*.*.45 255.255.255.252
- ospf network-type p2p
- #
- interface Serial6/0
- fe1 unframed
- ip address 196.*.*.17 255.255.255.252
- ospf network-type p2p
- #
- interface Serial6/1
- fe1 unframed
- ip address 196.*.*.13 255.255.255.252
- ospf network-type p2p
- #
- interface Serial6/2
- fe1 unframed
- ip address 196.*.*.6 255.255.255.252
- ospf network-type p2p
- #
- interface Serial6/3
- fe1 unframed
- ip address 196.*.*.10 255.255.255.252
- ospf network-type p2p
- #
- interface Serial6/4
- fe1 unframed
- ip address 196.*.*.229 255.255.255.252
- ospf network-type p2p
- #
- interface Serial6/5
- fe1 unframed
- ip address 196.*.*.213 255.255.255.252
- ospf network-type p2p
- #
- interface Serial6/6
- fe1 unframed
- ip address 196.*.*.65 255.255.255.252
- ospf network-type p2p
- #
- interface Serial6/7
- fe1 unframed
- ip address 196.*.*.81 255.255.255.252
- ospf network-type p2p
- #
- interface NULL0
- #
- interface GigabitEthernet0/0
- port link-mode route
- combo enable copper
- ip address 196.*.*.4 255.255.255.0
- vrrp vrid 1 virtual-ip 196.*.*.1
- #
- interface GigabitEthernet0/1
- port link-mode route
- ip address 196.*.*.241 255.255.255.252
- #
- interface GigabitEthernet0/2
- port link-mode route
- ip address 10.*.*.254 255.255.255.0
- vrrp vrid 2 virtual-ip 10.*.*.2
2、修改網(wǎng)絡(luò)拓?fù)浣Y(jié)構(gòu)
將下級(jí)單位12個(gè)環(huán)網(wǎng)中的24個(gè)鏈路定義為出口及入口個(gè)12個(gè),分別交叉接入接入MASTER及BACKUP路由器的WLAN端口進(jìn)行物理環(huán)路保護(hù)。增設(shè)監(jiān)控網(wǎng)絡(luò)核心交換機(jī),從網(wǎng)絡(luò)層隔離監(jiān)控網(wǎng)絡(luò)及辦公網(wǎng)絡(luò)數(shù)據(jù)包,同時(shí)也減輕了原核心交換機(jī)高負(fù)載壓力。改造前后拓?fù)鋱D如下:
后記
該網(wǎng)絡(luò)改造方案中重新將單位安全監(jiān)控網(wǎng)絡(luò)核心路由器由4臺(tái)減少為了兩臺(tái),并將兩臺(tái)理由器對(duì)辦公網(wǎng)絡(luò)以及監(jiān)控網(wǎng)絡(luò)都通過VRRP技術(shù)進(jìn)行了LAN網(wǎng)絡(luò)接口的熱備負(fù)載模式,將下級(jí)單位中環(huán)網(wǎng)的出口及入口鏈路分別匯聚在兩臺(tái)熱備路由器中。這樣可以保證即使兩臺(tái)路由器中的一臺(tái)完全宕機(jī),監(jiān)控網(wǎng)絡(luò)也可以通過另一臺(tái)路由器的工作完成應(yīng)用的良好可訪問性以及各下級(jí)單位視頻圖像的有效實(shí)時(shí)回傳。從而達(dá)到了更新改造需要達(dá)到的各項(xiàng)技術(shù)指標(biāo)。同時(shí)因?yàn)樵趦膳_(tái)路由器中進(jìn)行了1000MEthernet端口的路由模式直連,使得數(shù)據(jù)路由時(shí)間大大提高。網(wǎng)絡(luò)延時(shí)明顯減少,原網(wǎng)絡(luò)中從視頻服務(wù)器到各下級(jí)單位路由器平均延時(shí)在12MS,經(jīng)過改造后該延時(shí)減少到7MS以內(nèi)。