With the large-scale application of cloud services, the WAN has also undergone major changes to support these applications. Users have put forward new requirements for traditional routing devices, which are mainly reflected in the following aspects:
Advanced technical support
H3C's mature Comware network operating system provides a smarter service scheduling management mechanism, supports the loose coupling of business modularization, and enables dynamic loading of processes and patches.
Superior high-performance multi-core CPU processor with non-blocking switching architecture to greatly enhance multi-service concurrent processing
Support OAA open application architecture, support cloud business platform CVK, VMWARE, WAN optimization (WAN), Lync collaborative office, customer third-party business and other open applications
The self-innovated intelligent link engine CUBE technology not only improves the bus bandwidth of the SIC card, but also automatically and flexibly allocates interface resources.
Powerful security features
Business security
Packet filtering, which supports state filtering, MAC address filtering, IP and port number filtering, time range filtering, etc.
Support real-time analysis of business traffic, etc.
cyber security
Diversified VPN technologies, including IPsec, L2TP, GRE, ADVPN, MPLS VPN, and overlaying of multiple VPN technologies
Supports router protocol security protection, supports OSPF/RIP/IS-IS/BGP dynamic routing protocol authentication, supports OSPFv3/RIPng/IS-ISv6/BGP IPSec encryption, and supports rich routing policy control functions.
Terminal access security
Integrated terminal access binding authentication, including EAD security check authentication, 802.1x authentication, terminal MAC address authentication, WEB-based Portal authentication, terminal access static binding, and MAC automatic learning binding.
ARP attack defense, including source MAC address fixation, ARP packet attack defense, address conflict detection and protection, ARP port rate limit, ARP detection, ARP source MAC address consistency check, ARP source suppression, ARP active acknowledgement mechanism, etc.
Device management security
Support role-based rights management, resource allocation based on roles, user-to-role correspondence, and two-dimensional assignment of rights
Supports control plane traffic limiting, and supports traffic control and filtering based on protocol types, different queues, known protocol packets, and specified protocol packets.
Remote security management, support SNMPv3, support SSH, HTTPS remote management, etc.
Management behavior control audit, support AAA server centralized verification, execute command line authorization, real-time reporting of operation records, etc.
National Secret Office encryption algorithm
Support SM1, SM2, SM3, SM4 encryption algorithms proposed by the National Cryptography Administration
Refined business control
Through fine-grained identification and refined control (such as: identification and control of IM applications, streaming applications, stock financing, game applications, P2P applications), the speed limit and bandwidth guarantee for application layer services are realized. Filtering, Accounting, and other functions, and guide network optimization through refined statistics
Supports equal link load sharing (ECMP) and non-equivalent link load sharing (UCMP). UCMP supports load sharing based on link bandwidth ratio.
The service intelligent routing adopts technologies such as asymmetric link load balancing, traffic intelligent load balancing, and multi-topology dynamic routing to achieve full utilization of network links in different scenarios, load balancing based on bandwidth ratio, and load sharing based on users and user groups. And load sharing based on business and applications
Supports flexible sharing of network bandwidth based on multiple modes, including service-based elastic sharing, user- and user-group-based elastic sharing, link-based elastic bandwidth sharing, and user-based bandwidth limiting
Support SDN scheme, support RAN-related technologies such as SegmentRouting and BGP-LS
Wired and wireless integration
Support wireless controller function to manage wireless AP
Intelligent network management
Complete network management mode, support command line, SNMP, etc.
Supports zero-configuration deployment, enabling batch device deployment in zero-configuration mode, enabling zero-distribution of devices through wireless SMS, and automatically implementing device configuration rollback in case of misconfiguration
Comware's built-in EAA function monitors the internal events and status of the system's hardware and software components. When problems occur, it collects site information and attempts to automatically repair it, and can send the site information to the specified email address.
Support U disk system automatic startup, U disk configuration automatic import and USB Console interface
High reliability
Independent hardware processing module monitoring system, programmable devices support online upgrade and automatic loading to enhance product reliability
The link millisecond-level fast fault detection technology (BFD) can implement association with static routes, RIP/OSPF/BGP/ISIS dynamic routing, MPLS, VRRP, and interface backup to implement fast route and link switching.
Network Service Quality Intelligent Detection (NQA), which can be linked to static routes, VRRP, and interface backup.
Support HMIM slot hot swap
Support redundant backup and load sharing (VRRP/VRRPE) for multiple devices
Supports fast reroute, reliability technologies such as GR/NSR
Network virtualization
To reduce the complexity of user networking and improve management efficiency, the company firstly supports IRF2 (second-generation intelligent elastic architecture) technology on WAN devices, and virtualizes two physical devices into one logical device, which greatly reduces the user network. Operation and maintenance costs, improve link bandwidth utilization and device utilization.
Supports the inter-device Ethernet link aggregation technology to implement load balancing and mutual backup of multiple uplinks, thereby improving the reliability of the entire network architecture and the utilization of link resources.
Inter-cloud interconnection
Support for scalable virtual local area network VxLAN technology to complete data center Layer 2 interconnection needs. The VxLAN solution is simple and low-cost. It only needs to deploy one or more VxLAN-enabled devices at the edge of the site, and the enterprise network and service provider network do not need to be changed. At the same time, the VxLAN solution also provides data. A combined solution for encrypting IPsec technology to improve the security of data center data transmission over public networks
Green
Fully meet RoHS standards
Advanced air duct isolation design, power supply and system air duct isolation design, unique double L-shaped air duct design, power air duct and system air duct, two L-shaped air ducts improve space utilization
Fan-level redundant backup design, multi-stage fan speed control scheme, the system will determine the fan speed required by the system according to the internal temperature of the product, which can reduce the fan noise and energy consumption as much as possible.
Intelligent power-saving management, flexible definition of HMIM / main control board / forwarding board power saving strategy, to minimize equipment energy consumption