 
              H3C S5500-EI 10G IPv6 Switches
Content  Introduction  Highlight Features  Typical Solutions www.h3c.com.cn 2
Content  Introduction  Highlight Features  Typical Solutions www.h3c.com.cn 3
Hardware Specification S5500-28C-SI / S5500-28C-PWR-SI Console Port 2 Extended slots 4 × 1000 Base-X SFP DC Power Connector (non-PoE) (combo) 24 × 10/100/1000Base-T AC Power Connector Port Highlights  Switch Capacity:128Gbps / Throughput 95.2Mpps  IPv4/IPv6 dual stack and hardware forwarding  L3+ function: Static Routing, RIP, OSPF, BGP  Full wire speed GE ports and 10GE uplink  PoE (S5500-28C-PWR-SI) www.h3c.com.cn 4
Hardware Specification S5500-52C-SI / S5500-52C-PWR-SI 2 Extended slots Console Port 4 × 1000 Base-X SFP AC Power Connector (combo) 48 × 10/100/1000Base-T DC Power Connector (PoE) Port Highlights  Switch Capacity:176Gbps / Throughput 130.9Mpps  IPv4/IPv6 dual stack and hardware forwarding  L3+ function: Static Routing, RIP, OSPF, BGP  Full wire speed GE ports and 10GE uplink  PoE(S5500-52C-PWR-SI) www.h3c.com.cn 5
Hardware Specification S5500-28F-EI 2 Extended slots Console Port Modular power slots (AC/DC) 8 x 10/100/100Base-T Port (combo) Modular power slots (AC/DC) 24 x 1000Base-X SFP Port Highlights  Switch Capacity:128Gbps / Throughput 95.2Mpps  IPv4/IPv6 dual stack and hardware forwarding  L3+ function: Static Routing, RIP, OSPF, BGP  Full wire speed GE ports and 10GE uplink www.h3c.com.cn 6
Content  Introduction  Highlight Features  Typical Solutions www.h3c.com.cn 7
Highlights of S5500-EI  Up to 4 10GE uplinks Performance  128G/176G switching capacity  Full wire speed L2/L3 switching and forwarding  32K MAC, 12K routing table  IPv4/IPv6 dual stack IPv6  RIP, OSPF, BGP, RIPng, OSPFv3, BGP4+  IGMP, PIM SM/DM, MLD, PIM6 SM/DM  IPv4/IPv6 Policy Based Routing  IPv6 Ready phase-II certification  4K L2-L4 hardware based ACL  Ingress and EGRESS ACL Securit y  VLAN and port based ACL  uRPF  ARP detection  RRPP (Rapid Ring Network Protect Protocol) Reliability  SMARTLINK  VRRP  Redundant power supply  SNMPv1/v2/v3  sFlow Management  VCT, DLDP S5500-EI & Maintenance  LDT www.h3c.com.cn 8
Benefits From IPv6 Lower network administration costs: The auto-configuration and hierarchical addressing features of IPv6 will make networks easy to manage. Optimized for next generation networks: Getting rid of NAT re-enables the peer-to-peer model and helps in deploying new applications. E.g. communications and mobility solutions such as VoIP Protection of company assets: Integrated IPSEC makes IPv6 inherently secure and provides for a unified security strategy for the entire network. Investment protection: The transition and translation suite of protocols helps in easy and planned migration from IPv4 and IPv6, while allowing for co-existence in the transition phase. www.h3c.com.cn 9
IPv6 Protocols & Applications IPv4 Static Routing IPv6 Static Routing IPv4/IPv6 Routing & RIPv1/RIPv2 RIPng Multicast Protocols OSPF v1/v2 OSPF v3 BGP4 BGP4+ for IPv6 VRRP VRRP v3 Policy based routing IPv6 policy based routing IGMP-snooping MLD-snooping IGMP MLD PIM SM/DM PIM6 SM/DM Telnet Telnet6 IPv4/IPv6 Applications Ping Ping6 TFTP TFTP6 DNS DNS6 www.h3c.com.cn 10
IPv6 Tunnel Dual Stack Dual Stack Router Router IPv4 Network IPv6 IPv6 Network Network Tunnel IPv6 Host IPv6 Host IPv6 Header IPv6 Data IPv6 Header IPv6 Data IPv4 Header IPv6 Header IPv6 Data S5500-EI supports the following tunneling types:  Manual Tunnel  6 to 4 Tunnel  ISATAP Tunnel www.h3c.com.cn 11
IPv6 Multicast Multicast packet Multicast packet transmission transmission without MLD snooping when MLD snooping runs Multicast Multicast Router Router Video stream Video stream VOD Server VOD Server S5500-EI S5500-EI Non-Multicast Multicast Non-Multicast Non-Multicast Multicast Non-Multicast Group member Group member Group member Group member Group member Group member www.h3c.com.cn 12
Bi-directional ACL Support not only common ingress ACL, but also EGRESS ACL, which brings two advantages to users:  Simplify configuration and improve the network convenience;  Save ACL hardware resource Serve verFa rFarm A rm A UserG rGrou roup p A UserG rGrou roup p B Other erUse Users rs Serve verFa rFarm B rm B www.h3c.com.cn 13
Bi-directional ACL Port A t A: ServerFarm A: ServerFarm A: Permit UserGroup A To ServerFarm A Port B t B: Only permit UserGroup A Only permit UserGroup A & & UserGroup UserGroup Permit UserGroup B To ServerFarm A Permit UserGroup A To ServerFarm A Port C t C: B, and B, and deny all deny all others others Permit Any To ServerFarm B Permit UserGroup B To ServerFarm A Permit UserGroup A To ServerFarm A Deny UserGroup B To ServerFarm B Permit Any To ServerFarm B Permit UserGroup B To ServerFarm A Deny Any To Any Deny UserGroup B To ServerFarm B Permit Any To ServerFarm B Deny Any To Any Deny UserGroup B To ServerFarm B ServerFarm B: ServerFarm B: Deny Any To Any Serve verFa rFarm A rm A Only deny UserGroup B , and permit Only deny UserGroup and permit all others all others UserG rGrou roup p A UserG rGrou roup p B Other erUse Users rs Serve verFa rFarm B rm B Without Egress ACL, users have to configure complicated Egress policy to realize the function; with the expand of network scale, the network configuration process will become more and more complicated and difficult, and there must be more and more configuration errors can’t be avoid www.h3c.com.cn 14
Bi-directional ACL Port A t A:  Permit UserGroup A To ServerFarm A Port B t B: Permit UserGroup B To ServerFarm A Permit UserGroup A To ServerFarm A Port C t C: Permit Any To ServerFarm B Permit UserGroup B To ServerFarm A Permit UserGroup A To ServerFarm A Deny UserGroup B To ServerFarm B Permit Any To ServerFarm B Permit UserGroup B To ServerFarm A Deny Any To Any Deny UserGroup B To ServerFarm B Permit Any To ServerFarm B Deny Any To Any Deny UserGroup B To ServerFarm B Deny Any To Any Serve verFa rFarm A rm A UserG rGrou roup p A UserG rGrou roup p B Other erUse Users rs Serve verFa rFarm B rm B UserG rGrou roup p C Without Egress ACL, once the network topology got changed, all the current configuration need to be designed again, which does brings great risks www.h3c.com.cn 15
Bi-directional ACL ServerFarm A: ServerFarm A: Only permit UserGroup A Only permit UserGroup A & & UserGroup UserGroup Port A: Port A: B, and B, and deny all deny all others others Permit UserGroup A/B To Permit UserGroup A/B To ServerFarm A ServerFarm A Deny Any Deny Any ServerFarm B: ServerFarm B: Serve verFa rFarm A rm A Only deny UserGroup B, Only deny UserGroup B, and and permit permit UserG rGrou roup p A all others all others UserG rGrou roup p B Other erUse Users rs Port B: Port B: Serve verFa rFarm B rm B Deny Deny UserGroup B UserGroup B To To ServerFarm B ServerFarm B Permit Any Permit Any  Simplify ACL configuration process  Save ACL hardware resource www.h3c.com.cn 16
VLAN Based ACL  Traditional ACL policy is configured based on port, so users have to configure ACL policy on all ports one by one;  S5500-EI supports VLAN based ACL policy. Therefore users can define ACL policy easily and flexibly VLAN based ACL VLAN based ACL Traditional port based ACL: # # Interface Port 1> Vlan 100> Deny ftp Deny ftp Permit any Permit any # # Interface Port 2> Deny ftp Permit any # Interface Port 3> Deny ftp Permit any # Interface Port 3> Deny ftp Permit any # … www.h3c.com.cn 17
Smart Link B S7800 Backup Link Active Link S7800 Blocking Metro Ethernet DSLAM I P/ MPLS Core Network A LSW Blocking CE Backup Link Active Link S7800 C AMG  Suitable for dual uplink circumstances, better than Spanning tree technology for brings higher reliability to the network;  Working in the active/standby mode, once active link gets failed, standby link will be enabled, and the recovery time is less than 50ms; www.h3c.com.cn 18
RRPP (Rapid Ring Network Protec) Master Major Control Transit VLAN Major Ring Edge S5500-EI Secondary Sub Ring Control VLAN Transit Master S5500-EI  High performance price ratio RING network solution  High reliability with 50ms recovery time www.h3c.com.cn 19
N : 4 Port Mirroring  For most switch products, one source port can only be mirrored to one target port traffic monitoring  S5500-EI supports N:4 port mirroring, so that one port can be mirrored to up to 4 target ports, that means multi actions can be done at the same time, such as IPS, IDS, Netstream, and activity monitoring IPS IDS S5500-EI Netstream Activity monitoring www.h3c.com.cn 20
VCT – Virtual Cable Test S5500-EI VCT (Virtual Cable Test) testing items include: whether short or open circuit exists in the Rx/Tx direction of the cable, and what is the length of the cable in normal X status or the length from the port to the fault point of the cable. S3100 [S5500-Ethernet0/4]virtual-cable-test Cable pair: RX Status:Open Cable Error lenth:5 metres Cable pair: TX Status:Open Cable Error lenth:5 metres www.h3c.com.cn 21
Recommend
More recommend