路由器如何選購
本文將為大家揭開路由器的神秘面紗,歡迎大家閱讀,希望能幫到你。
路由器(Router),是連接因特網(wǎng)中各局域網(wǎng)、廣域網(wǎng)的設備,它會根據(jù)信道的情況自動選擇和設定路由,以最佳路徑,按前后順序發(fā)送信號。 路由器是互聯(lián)網(wǎng)絡的樞紐,"交通警察"。目前路由器已經(jīng)廣泛應用于各行各業(yè),各種不同檔次的產(chǎn)品已成為實現(xiàn)各種骨干網(wǎng)內部連接、骨干網(wǎng)間互聯(lián)和骨干網(wǎng)與互聯(lián)網(wǎng)互聯(lián)互通業(yè)務的主力軍。路由和交換機之間的主要區(qū)別就是交換機發(fā)生在OSI參考模型第二層(數(shù)據(jù)鏈路層),而路由發(fā)生在第三層,即網(wǎng)絡層。這一區(qū)別決定了路由和交換機在移動信息的過程中需使用不同的控制信息,所以兩者實現(xiàn)各自功能的方式是不同的。
簡介:
路由器(Router)又稱網(wǎng)關設備(Gateway)是用于連接多個邏輯上分開的網(wǎng)絡,所謂邏輯網(wǎng)絡是代表一個單獨的網(wǎng)絡或者一個子網(wǎng)。當數(shù)據(jù)從一個子網(wǎng)傳輸?shù)搅硪粋€子網(wǎng)時,可通過路由器的路由功能來完成。因此,路由器具有判斷網(wǎng)絡地址和選擇IP路徑的功能,它能在多網(wǎng)絡互聯(lián)環(huán)境中,建立靈活的連接,可用完全不同的數(shù)據(jù)分組和介質訪問方法連接各種子網(wǎng),路由器只接受源站或其他路由器的信息,屬網(wǎng)絡層的一種互聯(lián)設備。
選購要點
選擇路由器時應注意安全性、控制軟件、網(wǎng)絡擴展能力、網(wǎng)管系統(tǒng)、帶電插拔能力等方面。
1.由于路由器是網(wǎng)絡中比較關鍵的設備,針對網(wǎng)絡存在的各種安全隱患,路由器必須具有如下的安全特性:
(1)可靠性與線路安全 可靠性要求是針對故障恢復和負載能力而提出來的。對于路由器來說,可靠性主要體現(xiàn)在接口故障和網(wǎng)絡流量增大兩種情況下,為此,備份是路由器不可或缺的手段之一。當主接口出現(xiàn)故障時,備份接口自動投入工作,保證網(wǎng)絡的正常運行。當網(wǎng)絡流量增大時,備份接口又可承當負載分擔的任務。
(2)身份認證 路由器中的身份認證主要包括訪問路由器時的身份認證、對端路由器的身份認證和路由信息的身份認證。
(3)訪問控制 對于路由器的訪問控制,需要進行口令的分級保護。有基于IP地址的訪問控制和基于用戶的訪問控制。
(4)信息隱藏 與對端通信時,不一定需要用真實身份進行通信。通過地址轉換,可以做到隱藏網(wǎng)內地址,只以公共地址的方式訪問外部網(wǎng)絡。除了由內部網(wǎng)絡首先發(fā)起的連接,網(wǎng)外用戶不能通過地址轉換直接訪問網(wǎng)內資源。
(5)數(shù)據(jù)加密
(6)攻擊探測和防范
(7)安全管理
2.路由器的控制軟件是路由器發(fā)揮功能的一個關鍵環(huán)節(jié)。從軟件的安裝、參數(shù)自動設置,到軟件版本的升級都是必不可少的。軟件安裝、參數(shù)設置及調試越方便,用戶使用就越容易掌握,就能更好地應用。
3.隨著計算機網(wǎng)絡應用的逐漸增加,現(xiàn)有的網(wǎng)絡規(guī)模有可能不能滿足實際需要,會產(chǎn)生擴大網(wǎng)絡規(guī)模的要求,因此擴展能力是一個網(wǎng)絡在設計和建設過程中必須要考慮的。擴展能力的大小主要看路由器支持的擴展槽數(shù)目或者擴展端口數(shù)目。
4.隨著網(wǎng)絡的建設,網(wǎng)絡規(guī)模會越來越大,網(wǎng)絡的維護和管理就越難進行,所以網(wǎng)絡管理顯得尤為重要。 5.在我們安裝、調試、檢修和維護或者擴展計算機網(wǎng)絡的過程中,免不了要給網(wǎng)絡中增減設備,也就是說可能會要插拔網(wǎng)絡部件。那么路由器能否支持帶電插拔,是路由器的一個重要的性能指標。
外型尺寸的選擇
如果網(wǎng)絡已完成樓宇級的綜合布線,工程要求網(wǎng)絡設備上機式集中管理,應選擇19英寸寬的機架式路由器,如Cisco2509、華為2501(配置同Cisco2501)。如果沒有上述需求,桌面型的路由器如Intel的8100和Cisco的1600系列,具有更高的性能價格比。
協(xié)議的選擇
由于最初局域網(wǎng)并沒先出標準后出產(chǎn)品,所以很多廠商如Apple和IBM都提出了自己的標準,產(chǎn)生了如AppleTalk和IBM協(xié)議,Novell公司的網(wǎng)絡操作系統(tǒng)運行IPX/SPX協(xié)議,在連接這些異構網(wǎng)絡時需要路由器對這些協(xié)議提供支持。Intel9100系列和9200系列的路由器可提供免費支持,3Com的系列路由產(chǎn)品也提供較廣泛的協(xié)議支持。
路由器作為網(wǎng)絡設備中的“黑匣子”,工作在后臺。用戶選擇路由器時,多從技術角度來考慮,如可延展性、路由協(xié)議互操作性、廣域數(shù)據(jù)服務支持、內部ATM支持、SAN集成能力等。另外,選擇路由器還應遵循如下基本原則:即標準化原則、技術簡單性原則、環(huán)境適應性原則、可管理性原則和容錯冗余性原則。對于高端路由器,更多的還應該考慮是否和如何適應骨干網(wǎng)對網(wǎng)絡高可靠性、接口高擴展性以及路由查找和數(shù)據(jù)轉發(fā)的高性能要求。高可靠性、高擴展性和高性能的“三高”特性是高端路由器區(qū)別于中、低端路由器的關鍵所在。
CISCO路由器初始配置簡介
很多初學路由器知識的網(wǎng)友對路由器的初始配置可能感到很陌生,本人在初學時也很困惑,因為一下出來很多提問不知如何是好,下面將最近剛調試的一臺CISCO3640的初始配置整理出來與各位網(wǎng)友交流,如有疏漏之處,還請大家指正。
1.用CISCO隨機帶CONSOLE線,一端連在CISCO路由器的CONSOLE口,一端連在計算機的COM口。
2.打開電腦,啟動超級終端.為您的連接取個名字,比如CISCO_SETUP,下一步選定連接時用COM1,下一步選定第秒位數(shù)9600,數(shù)據(jù)位8,奇偶校驗無,停止位1,數(shù)據(jù)流控制無.最后選確定。
3.打開路由器電源,這時超級終端將出現(xiàn)以下畫面:
System Bootstrap, Version 11.1(20)AA2, EARLY DEPLOYMENT RELEASE SOFTWARE (fc1)
Copyright (c) 1999 by cisco Systems, Inc.C3600 processor with 32768 Kbytes of main memory Main memory is configured to 64 bit mode with parity disabled
program load complete, entry point: 0x80008000, size: 0x4ed478 Self decompressing the image :
###################################################################
###################################################################
###################################################################
###################################################################
###################################################################
###################################################################
###################################################################
[OK]
Restricted Rights Legend
Use, duplication, or disclosure by the Government is
subject to restrictions as set forth in subparagraph
(c) of the Commercial Computer Software - Restricted
Rights clause at FAR sec. 52.227-19 and subparagraph
(c) (1) (ii) of the Rights in Technical Data and Computer
Software clause at DFARS sec. 252.227-7013.
cisco Systems, Inc.
170 West Tasman Drive
San Jose, California 95134-1706
Cisco Internetwork Operating System Software
IOS (tm) 3600 Software (C3640-I-M), Version 12.1(2)T, RELEASE SOFTWARE (fc1)
Copyright (c) 1986-2000 by cisco Systems, Inc.
Compiled Tue 16-May-00 12:26 by ccai
Image text-base: 0x600088F0, data-base: 0x60924000
cisco 3640 (R4700) processor (revision 0x00) with 24576K/8192K bytes of memory.
Processor board ID 25125768
R4700 CPU at 100Mhz, Implementation 33, Rev 1.0
Bridging software.
X.25 software, Version 3.0.0.
2 FastEthernet/IEEE 802.3 interface(s)
1 Serial network interface(s)
DRAM configuration is 64 bits wide with parity disabled.
125K bytes of non-volatile configuration memory.
8192K bytes of processor board System flash (Read/Write)
--- System Configuration Dialog ---
Would you like to enter the initial configuration dialog? [yes/no]: y
您是否進入初始化配置對話,選Y
At any point you may enter a question mark '?' for help.
Use ctrl-c to abort configuration dialog at any prompt.
Default settings are in square brackets '[]'.Basic management setup configures only enough connectivity
for management of the system, extended setup will ask you
to configure each interface on the system
Would you like to enter basic management setup? [yes/no]: n
您是否進入基本配置安裝,選N
First, would you like to see the current interface summary? [yes]: y
首先,您是否看一下當前端口狀態(tài)
Any interface listed with OK? value "NO" does not have a valid configuration
Interface IP-Address OK? Method Status Protocol
FastEthernet0/0unassigned NO unset up down
Serial0/0 unassigned NO unset down down
FastEthernet0/1unassigned NO unset up down
Configuring global parameters:
Enter host name [Router]:RouterA
輸入路由器的名字
The enable secret is a password used to protect access to
privileged EXEC and configuration modes. This password, after
entered, becomes encrypted in the configuration.
Enter enable secret: aaa
輸入密文
The enable password is used when you do not specify an
enable secret password, with some older software versions, and
some boot images.
Enter enable password: bbb
輸入密碼(不能和密文相同)
The virtual terminal password is used to protect
access to the router over a network interface.
Enter virtual terminal password: ccc
輸入虛擬終端的密碼(以備遠程登錄)
Configure SNMP Network Management? [yes]: n
配置簡單網(wǎng)管嗎?選N
Configure IP? [yes]: y
配置IP嗎?選Y
Configure IGRP routing? [yes]: n
配置IGRP路由選擇協(xié)議嗎?選N
Configure RIP routing? [no]:
配置IGRP路由選擇協(xié)議嗎?選N
Configure bridging? [no]:
配置橋接嗎?選N
Async lines accept incoming modems calls. If you will have
users dialing in via modems, configure these lines.
Configure Async lines? [yes]: n
配置異步線路嗎?選N
Configuring interface parameters:
Do you want to configure FastEthernet0/0 interface? [yes]: y
您是否想配置fastethernet0/0接口?選Y
Use the 100 Base-TX (RJ-45) connector? [yes]: y
用RJ45的連接器嗎?選Y
Operate in full-duplex mode? [no]: y
選用全雙工模式?選Y
Configure IP on this interface? [yes]: y
在這個接口上配置IP嗎?選Y
IP address for this interface: 192.168.0.1
配置該接口的IP地址(在此地址為192.168.0.1
Subnet mask for this interface [255.255.255.0] :
配置該接口的子網(wǎng)掩碼.(默認的是255.255.255.0,可以手工輸入修改)
Class C network is 192.168.0.0, 24 subnet bits; mask is /24
Do you want to configure Serial0/0 interface? [yes]: y
您想配置serial0/0接口嗎?選Y
Some supported encapsulations are
ppp/hdlc/frame-relay/lapb/x25/atm-dxi/smds
Choose encapsulation type [hdlc]:
選擇封裝方式(默認的封裝方式是HDLC,您可根據(jù)與您的路由器相連選用的封裝類型來決定用什么樣的封裝類型
No serial cable seen.
Choose mode from (dce/dte) [dte]:
(因為沒有連串口線所以會讓您選擇設備類型)
Configure IP on this interface? [yes]: y
(在接口上配置IP)
Configure IP unnumbered on this interface? [no]:
IP address for this interface: 172.16.0.5
配置該接口的IP地址(在此地址為172.16.0.5)
Subnet mask for this interface [255.255.0.0] : 255.255.255.252
配置該接口的子網(wǎng)掩碼.(默認的是255.255.0.0,可以手工輸入修改為255.255.255.252)
Class B network is 172.16.0.0, 30 subnet bits; mask is /30
(以下配置同上)
Do you want to configure FastEthernet0/1 interface? [yes]:
Use the 100 Base-TX (RJ-45) connector? [yes]:
Operate in full-duplex mode? [no]: y
Configure IP on this interface? [yes]: y
IP address for this interface: 172.16.0.9
Subnet mask for this interface [255.255.0.0] : 255.255.255.252 Class B network is 172.16.0.0, 30 subnet bits; mask is /30
The following configuration command script was created:
(把您的配置顯示出來)
hostname aaa
enable secret 5 $ul/V$ezbZFgvzGHD.YPSieC0Ew/
enable password RouterA
line vty 0 4
password ccc
no snmp-server
!
ip routing
no bridge 1
!
interface FastEthernet0/0
media-type 100BaseX
full-duplex
ip address 192.168.0.1 255.255.255.0
!
interface Serial0/0
encapsulation hdlc
ip address 172.16.0.5 255.255.255.252
!
interface FastEthernet0/1
media-type 100BaseX
full-duplex
ip address 172.16.0.9 255.255.255.252
dialer-list 1 protocol ip permit
dialer-list 1 protocol ipx permit
!
end
以下提示您是否保存這次設置
[0] Go to the IOS command prompt without saving this config.
[1] Return back to the setup without saving this config.
[2] Save this configuration to nvram and exit.
Enter your selection [2]: 2
選擇2保存設置并存入NVRAM中
Building configuration...
[OK] Use the enabled mode 'configure' command to modify this configuration.
Press RETURN to get started!
路由器重新啟動
00:00:08: %LINK-3-UPDOWN: Interface Serial0/0, changed state to down
00:00:08: %LINK-3-UPDOWN: Interface FastEthernet0/0, changed state to up
00:00:08: %LINK-3-UPDOWN: Interface FastEthernet0/1, changed state to up
00:00:09: %LINEPROTO-5-UPDOWN: Line protocol on Interface Serial0/0, changed state to down
00:00:09: %LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/0, changed state to down
00:00:09: %LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/1, changed state to down
00:03:18: %IP-5-WEBINST_KILL: Terminating DNS process
00:03:24: %SYS-5-RESTART: System restarted --
Cisco Internetwork Operating System Software
IOS (tm) 3600 Software (C3640-I-M), Version 12.1(2)T, RELEASE SOFTWARE (fc1)
Copyright (c) 1986-2000 by cisco Systems, Inc.
Compiled Tue 16-May-00 12:26 by ccai
RouterA>
進入用戶模式
RouterA>en
Password:
RouterA#
進入全局模式
RouterA#sh run
查看現(xiàn)在運行的配置
Building configuration...
Current configuration:
!
version 12.1
service timestamps debug uptime
service timestamps log uptime
no service password-encryption
!
hostname RouterA
!
enable secret 5 $ul/V$ezbZFgvzGHD.YPSieC0Ew/
enable password bbb
!
memory-size iomem 25
ip subnet-zero
!
interface FastEthernet0/0
ip address 192.168.0.1 255.255.255.0
speed auto
full-duplex
!
interface Serial0/0
ip address 172.16.0.5 255.255.255.252
clockrate 2000000
!
interface FastEthernet0/1
ip address 172.16.0.9 255.255.255.252
speed auto
full-duplex
!
ip classless
no ip http server
!
dialer-list 1 protocol ip permit
dialer-list 1 protocol ipx permit
!
line con 0
transport input none
line aux 0
line vty 0 4
password ccc
login
!
end
現(xiàn)在您就完成了了一個新路由器的基本配置,接下來就可以進行進一步的詳細配置了