路由器如何選購(gòu)
本文將為大家揭開(kāi)路由器的神秘面紗,歡迎大家閱讀,希望能幫到你。
路由器(Router),是連接因特網(wǎng)中各局域網(wǎng)、廣域網(wǎng)的設(shè)備,它會(huì)根據(jù)信道的情況自動(dòng)選擇和設(shè)定路由,以最佳路徑,按前后順序發(fā)送信號(hào)。 路由器是互聯(lián)網(wǎng)絡(luò)的樞紐,"交通警察"。目前路由器已經(jīng)廣泛應(yīng)用于各行各業(yè),各種不同檔次的產(chǎn)品已成為實(shí)現(xiàn)各種骨干網(wǎng)內(nèi)部連接、骨干網(wǎng)間互聯(lián)和骨干網(wǎng)與互聯(lián)網(wǎng)互聯(lián)互通業(yè)務(wù)的主力軍。路由和交換機(jī)之間的主要區(qū)別就是交換機(jī)發(fā)生在OSI參考模型第二層(數(shù)據(jù)鏈路層),而路由發(fā)生在第三層,即網(wǎng)絡(luò)層。這一區(qū)別決定了路由和交換機(jī)在移動(dòng)信息的過(guò)程中需使用不同的控制信息,所以兩者實(shí)現(xiàn)各自功能的方式是不同的。
簡(jiǎn)介:
路由器(Router)又稱網(wǎng)關(guān)設(shè)備(Gateway)是用于連接多個(gè)邏輯上分開(kāi)的網(wǎng)絡(luò),所謂邏輯網(wǎng)絡(luò)是代表一個(gè)單獨(dú)的網(wǎng)絡(luò)或者一個(gè)子網(wǎng)。當(dāng)數(shù)據(jù)從一個(gè)子網(wǎng)傳輸?shù)搅硪粋€(gè)子網(wǎng)時(shí),可通過(guò)路由器的路由功能來(lái)完成。因此,路由器具有判斷網(wǎng)絡(luò)地址和選擇IP路徑的功能,它能在多網(wǎng)絡(luò)互聯(lián)環(huán)境中,建立靈活的連接,可用完全不同的數(shù)據(jù)分組和介質(zhì)訪問(wèn)方法連接各種子網(wǎng),路由器只接受源站或其他路由器的信息,屬網(wǎng)絡(luò)層的一種互聯(lián)設(shè)備。
選購(gòu)要點(diǎn)
選擇路由器時(shí)應(yīng)注意安全性、控制軟件、網(wǎng)絡(luò)擴(kuò)展能力、網(wǎng)管系統(tǒng)、帶電插拔能力等方面。
1.由于路由器是網(wǎng)絡(luò)中比較關(guān)鍵的設(shè)備,針對(duì)網(wǎng)絡(luò)存在的各種安全隱患,路由器必須具有如下的安全特性:
(1)可靠性與線路安全 可靠性要求是針對(duì)故障恢復(fù)和負(fù)載能力而提出來(lái)的。對(duì)于路由器來(lái)說(shuō),可靠性主要體現(xiàn)在接口故障和網(wǎng)絡(luò)流量增大兩種情況下,為此,備份是路由器不可或缺的手段之一。當(dāng)主接口出現(xiàn)故障時(shí),備份接口自動(dòng)投入工作,保證網(wǎng)絡(luò)的正常運(yùn)行。當(dāng)網(wǎng)絡(luò)流量增大時(shí),備份接口又可承當(dāng)負(fù)載分擔(dān)的任務(wù)。
(2)身份認(rèn)證 路由器中的身份認(rèn)證主要包括訪問(wèn)路由器時(shí)的身份認(rèn)證、對(duì)端路由器的身份認(rèn)證和路由信息的身份認(rèn)證。
(3)訪問(wèn)控制 對(duì)于路由器的訪問(wèn)控制,需要進(jìn)行口令的分級(jí)保護(hù)。有基于IP地址的訪問(wèn)控制和基于用戶的訪問(wèn)控制。
(4)信息隱藏 與對(duì)端通信時(shí),不一定需要用真實(shí)身份進(jìn)行通信。通過(guò)地址轉(zhuǎn)換,可以做到隱藏網(wǎng)內(nèi)地址,只以公共地址的方式訪問(wèn)外部網(wǎng)絡(luò)。除了由內(nèi)部網(wǎng)絡(luò)首先發(fā)起的連接,網(wǎng)外用戶不能通過(guò)地址轉(zhuǎn)換直接訪問(wèn)網(wǎng)內(nèi)資源。
(5)數(shù)據(jù)加密
(6)攻擊探測(cè)和防范
(7)安全管理
2.路由器的控制軟件是路由器發(fā)揮功能的一個(gè)關(guān)鍵環(huán)節(jié)。從軟件的安裝、參數(shù)自動(dòng)設(shè)置,到軟件版本的升級(jí)都是必不可少的。軟件安裝、參數(shù)設(shè)置及調(diào)試越方便,用戶使用就越容易掌握,就能更好地應(yīng)用。
3.隨著計(jì)算機(jī)網(wǎng)絡(luò)應(yīng)用的逐漸增加,現(xiàn)有的網(wǎng)絡(luò)規(guī)模有可能不能滿足實(shí)際需要,會(huì)產(chǎn)生擴(kuò)大網(wǎng)絡(luò)規(guī)模的要求,因此擴(kuò)展能力是一個(gè)網(wǎng)絡(luò)在設(shè)計(jì)和建設(shè)過(guò)程中必須要考慮的。擴(kuò)展能力的大小主要看路由器支持的擴(kuò)展槽數(shù)目或者擴(kuò)展端口數(shù)目。
4.隨著網(wǎng)絡(luò)的建設(shè),網(wǎng)絡(luò)規(guī)模會(huì)越來(lái)越大,網(wǎng)絡(luò)的維護(hù)和管理就越難進(jìn)行,所以網(wǎng)絡(luò)管理顯得尤為重要。 5.在我們安裝、調(diào)試、檢修和維護(hù)或者擴(kuò)展計(jì)算機(jī)網(wǎng)絡(luò)的過(guò)程中,免不了要給網(wǎng)絡(luò)中增減設(shè)備,也就是說(shuō)可能會(huì)要插拔網(wǎng)絡(luò)部件。那么路由器能否支持帶電插拔,是路由器的一個(gè)重要的性能指標(biāo)。
外型尺寸的選擇
如果網(wǎng)絡(luò)已完成樓宇級(jí)的綜合布線,工程要求網(wǎng)絡(luò)設(shè)備上機(jī)式集中管理,應(yīng)選擇19英寸寬的機(jī)架式路由器,如Cisco2509、華為2501(配置同Cisco2501)。如果沒(méi)有上述需求,桌面型的路由器如Intel的8100和Cisco的1600系列,具有更高的性能價(jià)格比。
協(xié)議的選擇
由于最初局域網(wǎng)并沒(méi)先出標(biāo)準(zhǔn)后出產(chǎn)品,所以很多廠商如Apple和IBM都提出了自己的標(biāo)準(zhǔn),產(chǎn)生了如AppleTalk和IBM協(xié)議,Novell公司的網(wǎng)絡(luò)操作系統(tǒng)運(yùn)行IPX/SPX協(xié)議,在連接這些異構(gòu)網(wǎng)絡(luò)時(shí)需要路由器對(duì)這些協(xié)議提供支持。Intel9100系列和9200系列的路由器可提供免費(fèi)支持,3Com的系列路由產(chǎn)品也提供較廣泛的協(xié)議支持。
路由器作為網(wǎng)絡(luò)設(shè)備中的“黑匣子”,工作在后臺(tái)。用戶選擇路由器時(shí),多從技術(shù)角度來(lái)考慮,如可延展性、路由協(xié)議互操作性、廣域數(shù)據(jù)服務(wù)支持、內(nèi)部ATM支持、SAN集成能力等。另外,選擇路由器還應(yīng)遵循如下基本原則:即標(biāo)準(zhǔn)化原則、技術(shù)簡(jiǎn)單性原則、環(huán)境適應(yīng)性原則、可管理性原則和容錯(cuò)冗余性原則。對(duì)于高端路由器,更多的還應(yīng)該考慮是否和如何適應(yīng)骨干網(wǎng)對(duì)網(wǎng)絡(luò)高可靠性、接口高擴(kuò)展性以及路由查找和數(shù)據(jù)轉(zhuǎn)發(fā)的高性能要求。高可靠性、高擴(kuò)展性和高性能的“三高”特性是高端路由器區(qū)別于中、低端路由器的關(guān)鍵所在。
CISCO路由器初始配置簡(jiǎn)介
很多初學(xué)路由器知識(shí)的網(wǎng)友對(duì)路由器的初始配置可能感到很陌生,本人在初學(xué)時(shí)也很困惑,因?yàn)橐幌鲁鰜?lái)很多提問(wèn)不知如何是好,下面將最近剛調(diào)試的一臺(tái)CISCO3640的初始配置整理出來(lái)與各位網(wǎng)友交流,如有疏漏之處,還請(qǐng)大家指正。
1.用CISCO隨機(jī)帶CONSOLE線,一端連在CISCO路由器的CONSOLE口,一端連在計(jì)算機(jī)的COM口。
2.打開(kāi)電腦,啟動(dòng)超級(jí)終端.為您的連接取個(gè)名字,比如CISCO_SETUP,下一步選定連接時(shí)用COM1,下一步選定第秒位數(shù)9600,數(shù)據(jù)位8,奇偶校驗(yàn)無(wú),停止位1,數(shù)據(jù)流控制無(wú).最后選確定。
3.打開(kāi)路由器電源,這時(shí)超級(jí)終端將出現(xiàn)以下畫(huà)面:
System Bootstrap, Version 11.1(20)AA2, EARLY DEPLOYMENT RELEASE SOFTWARE (fc1)
Copyright (c) 1999 by cisco Systems, Inc.C3600 processor with 32768 Kbytes of main memory Main memory is configured to 64 bit mode with parity disabled
program load complete, entry point: 0x80008000, size: 0x4ed478 Self decompressing the image :
###################################################################
###################################################################
###################################################################
###################################################################
###################################################################
###################################################################
###################################################################
[OK]
Restricted Rights Legend
Use, duplication, or disclosure by the Government is
subject to restrictions as set forth in subparagraph
(c) of the Commercial Computer Software - Restricted
Rights clause at FAR sec. 52.227-19 and subparagraph
(c) (1) (ii) of the Rights in Technical Data and Computer
Software clause at DFARS sec. 252.227-7013.
cisco Systems, Inc.
170 West Tasman Drive
San Jose, California 95134-1706
Cisco Internetwork Operating System Software
IOS (tm) 3600 Software (C3640-I-M), Version 12.1(2)T, RELEASE SOFTWARE (fc1)
Copyright (c) 1986-2000 by cisco Systems, Inc.
Compiled Tue 16-May-00 12:26 by ccai
Image text-base: 0x600088F0, data-base: 0x60924000
cisco 3640 (R4700) processor (revision 0x00) with 24576K/8192K bytes of memory.
Processor board ID 25125768
R4700 CPU at 100Mhz, Implementation 33, Rev 1.0
Bridging software.
X.25 software, Version 3.0.0.
2 FastEthernet/IEEE 802.3 interface(s)
1 Serial network interface(s)
DRAM configuration is 64 bits wide with parity disabled.
125K bytes of non-volatile configuration memory.
8192K bytes of processor board System flash (Read/Write)
--- System Configuration Dialog ---
Would you like to enter the initial configuration dialog? [yes/no]: y
您是否進(jìn)入初始化配置對(duì)話,選Y
At any point you may enter a question mark '?' for help.
Use ctrl-c to abort configuration dialog at any prompt.
Default settings are in square brackets '[]'.Basic management setup configures only enough connectivity
for management of the system, extended setup will ask you
to configure each interface on the system
Would you like to enter basic management setup? [yes/no]: n
您是否進(jìn)入基本配置安裝,選N
First, would you like to see the current interface summary? [yes]: y
首先,您是否看一下當(dāng)前端口狀態(tài)
Any interface listed with OK? value "NO" does not have a valid configuration
Interface IP-Address OK? Method Status Protocol
FastEthernet0/0unassigned NO unset up down
Serial0/0 unassigned NO unset down down
FastEthernet0/1unassigned NO unset up down
Configuring global parameters:
Enter host name [Router]:RouterA
輸入路由器的名字
The enable secret is a password used to protect access to
privileged EXEC and configuration modes. This password, after
entered, becomes encrypted in the configuration.
Enter enable secret: aaa
輸入密文
The enable password is used when you do not specify an
enable secret password, with some older software versions, and
some boot images.
Enter enable password: bbb
輸入密碼(不能和密文相同)
The virtual terminal password is used to protect
access to the router over a network interface.
Enter virtual terminal password: ccc
輸入虛擬終端的密碼(以備遠(yuǎn)程登錄)
Configure SNMP Network Management? [yes]: n
配置簡(jiǎn)單網(wǎng)管嗎?選N
Configure IP? [yes]: y
配置IP嗎?選Y
Configure IGRP routing? [yes]: n
配置IGRP路由選擇協(xié)議嗎?選N
Configure RIP routing? [no]:
配置IGRP路由選擇協(xié)議嗎?選N
Configure bridging? [no]:
配置橋接嗎?選N
Async lines accept incoming modems calls. If you will have
users dialing in via modems, configure these lines.
Configure Async lines? [yes]: n
配置異步線路嗎?選N
Configuring interface parameters:
Do you want to configure FastEthernet0/0 interface? [yes]: y
您是否想配置fastethernet0/0接口?選Y
Use the 100 Base-TX (RJ-45) connector? [yes]: y
用RJ45的連接器嗎?選Y
Operate in full-duplex mode? [no]: y
選用全雙工模式?選Y
Configure IP on this interface? [yes]: y
在這個(gè)接口上配置IP嗎?選Y
IP address for this interface: 192.168.0.1
配置該接口的IP地址(在此地址為192.168.0.1
Subnet mask for this interface [255.255.255.0] :
配置該接口的子網(wǎng)掩碼.(默認(rèn)的是255.255.255.0,可以手工輸入修改)
Class C network is 192.168.0.0, 24 subnet bits; mask is /24
Do you want to configure Serial0/0 interface? [yes]: y
您想配置serial0/0接口嗎?選Y
Some supported encapsulations are
ppp/hdlc/frame-relay/lapb/x25/atm-dxi/smds
Choose encapsulation type [hdlc]:
選擇封裝方式(默認(rèn)的封裝方式是HDLC,您可根據(jù)與您的路由器相連選用的封裝類型來(lái)決定用什么樣的封裝類型
No serial cable seen.
Choose mode from (dce/dte) [dte]:
(因?yàn)闆](méi)有連串口線所以會(huì)讓您選擇設(shè)備類型)
Configure IP on this interface? [yes]: y
(在接口上配置IP)
Configure IP unnumbered on this interface? [no]:
IP address for this interface: 172.16.0.5
配置該接口的IP地址(在此地址為172.16.0.5)
Subnet mask for this interface [255.255.0.0] : 255.255.255.252
配置該接口的子網(wǎng)掩碼.(默認(rèn)的是255.255.0.0,可以手工輸入修改為255.255.255.252)
Class B network is 172.16.0.0, 30 subnet bits; mask is /30
(以下配置同上)
Do you want to configure FastEthernet0/1 interface? [yes]:
Use the 100 Base-TX (RJ-45) connector? [yes]:
Operate in full-duplex mode? [no]: y
Configure IP on this interface? [yes]: y
IP address for this interface: 172.16.0.9
Subnet mask for this interface [255.255.0.0] : 255.255.255.252 Class B network is 172.16.0.0, 30 subnet bits; mask is /30
The following configuration command script was created:
(把您的配置顯示出來(lái))
hostname aaa
enable secret 5 $ul/V$ezbZFgvzGHD.YPSieC0Ew/
enable password RouterA
line vty 0 4
password ccc
no snmp-server
!
ip routing
no bridge 1
!
interface FastEthernet0/0
media-type 100BaseX
full-duplex
ip address 192.168.0.1 255.255.255.0
!
interface Serial0/0
encapsulation hdlc
ip address 172.16.0.5 255.255.255.252
!
interface FastEthernet0/1
media-type 100BaseX
full-duplex
ip address 172.16.0.9 255.255.255.252
dialer-list 1 protocol ip permit
dialer-list 1 protocol ipx permit
!
end
以下提示您是否保存這次設(shè)置
[0] Go to the IOS command prompt without saving this config.
[1] Return back to the setup without saving this config.
[2] Save this configuration to nvram and exit.
Enter your selection [2]: 2
選擇2保存設(shè)置并存入NVRAM中
Building configuration...
[OK] Use the enabled mode 'configure' command to modify this configuration.
Press RETURN to get started!
路由器重新啟動(dòng)
00:00:08: %LINK-3-UPDOWN: Interface Serial0/0, changed state to down
00:00:08: %LINK-3-UPDOWN: Interface FastEthernet0/0, changed state to up
00:00:08: %LINK-3-UPDOWN: Interface FastEthernet0/1, changed state to up
00:00:09: %LINEPROTO-5-UPDOWN: Line protocol on Interface Serial0/0, changed state to down
00:00:09: %LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/0, changed state to down
00:00:09: %LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/1, changed state to down
00:03:18: %IP-5-WEBINST_KILL: Terminating DNS process
00:03:24: %SYS-5-RESTART: System restarted --
Cisco Internetwork Operating System Software
IOS (tm) 3600 Software (C3640-I-M), Version 12.1(2)T, RELEASE SOFTWARE (fc1)
Copyright (c) 1986-2000 by cisco Systems, Inc.
Compiled Tue 16-May-00 12:26 by ccai
RouterA>
進(jìn)入用戶模式
RouterA>en
Password:
RouterA#
進(jìn)入全局模式
RouterA#sh run
查看現(xiàn)在運(yùn)行的配置
Building configuration...
Current configuration:
!
version 12.1
service timestamps debug uptime
service timestamps log uptime
no service password-encryption
!
hostname RouterA
!
enable secret 5 $ul/V$ezbZFgvzGHD.YPSieC0Ew/
enable password bbb
!
memory-size iomem 25
ip subnet-zero
!
interface FastEthernet0/0
ip address 192.168.0.1 255.255.255.0
speed auto
full-duplex
!
interface Serial0/0
ip address 172.16.0.5 255.255.255.252
clockrate 2000000
!
interface FastEthernet0/1
ip address 172.16.0.9 255.255.255.252
speed auto
full-duplex
!
ip classless
no ip http server
!
dialer-list 1 protocol ip permit
dialer-list 1 protocol ipx permit
!
line con 0
transport input none
line aux 0
line vty 0 4
password ccc
login
!
end
現(xiàn)在您就完成了了一個(gè)新路由器的基本配置,接下來(lái)就可以進(jìn)行進(jìn)一步的詳細(xì)配置了