Vyatta Router/Firewall/VPN

20
Cooperative Education – Networking Spring 2010 Network Team Saigon Institute of Technology

Transcript of Vyatta Router/Firewall/VPN

Page 1: Vyatta Router/Firewall/VPN

Cooperative Education – Networking

Spring 2010

Network TeamSaigon Institute of Technology

Page 2: Vyatta Router/Firewall/VPN

Introduction to Vyatta

A.Overview

B.Feature

Page 3: Vyatta Router/Firewall/VPN

A. Overview

Open-source networking solutions: enterprise-class Router/Firewall/VPN

Vyatta solutions offerBetter value

Better performance

Better scalability

Better flexibility

Better ecosystem

The word "vyatta" is ancient Sanskrit and means "open“

Pronounced vee-AH-tah

Page 4: Vyatta Router/Firewall/VPN

B. Features

1. Subscription Services2. Interactive3. Hardware Support4. Virtualization5. Interfaces6. IP/Routing Protocols7. Performance Optimization8. IP Address Management9. Encapsulation10. Security11. High Availability12. Logging & Monitoring13. Debugging

Page 5: Vyatta Router/Firewall/VPN

1. Subscription Services

Stable software Regular updates Regular bug fixes All new features All enhancements Technical support Web knowledge-base

Page 6: Vyatta Router/Firewall/VPN

2. Interactive

Command Line– Integrated CLI

– Single configuration file

– Telnet

– SSHv2

Page 7: Vyatta Router/Firewall/VPN

Web-Based GUI

Page 8: Vyatta Router/Firewall/VPN

3. Hardware Support

Standard 32-bt x86 processors and systems

http://www.vyatta.com/products/hardware_cat.php

http://www.vyatta.com/documentation/general/Vyatta_Cisco_Replacement_Guide.pdf

http://www.vyatta.com/documentation/general/Vyatta_Hardware_Guidelines_v1.0.pdf

Page 9: Vyatta Router/Firewall/VPN

4. Virtualization

Page 10: Vyatta Router/Firewall/VPN

5. Interfaces

LAN interfaces: 10/100/1000 Ethernet NICs WAN interfaces: T1/E1, T3/E3 cards http://vyatta.org/hardware/interfaces

Page 11: Vyatta Router/Firewall/VPN

6. Advance Routing Protocols

IPIPv4

IPv6

Routing protocolsOSPFv2 (Open Shortest Path First)- Support for the most popular interior

routing protocol for large networks

BGP-4 (Border Gateway Protocol) - Support for the core routing protocol of

the Internet

RIPv2 (Routing Information Protocol) - Easily build and connect internal

networks

Static routes - Simplifies basic router configurations

VRRP

Page 12: Vyatta Router/Firewall/VPN

7. Performance Optimization

WAN Load Balancing Ethernet Link Bonding QoS ECMP MLPPP Web Caching

Page 13: Vyatta Router/Firewall/VPN

8. IP Address Management

Static/Dynamic IP Address DHCP Server DHCP Relay

Page 14: Vyatta Router/Firewall/VPN

9. Encapsulations

LAN encapsulationsEthernet

802.1Q VLANs

WAN encapsulationsPPP (point to Point Protocol)

Multilink PPP

Frame Relay

HDLC

WAN encapsulations PPP (point to Point Protocol)

Multilink PPP

Frame Relay

HDLC

Page 15: Vyatta Router/Firewall/VPN

10. Security

Stateful inspection firewall Network address translation (NAT) IPsec VPN SSL-Based OpenVPN Intrusion Prevention URL Filtering Individual user accounts and passwords

Page 16: Vyatta Router/Firewall/VPN

11. High Availability

VRRP (Virtual Router Redundancy Protocol) IPSec VPN Clustering Support for multiple power supplies Each protocol sandboxed from others,

providing fault isolation

Page 17: Vyatta Router/Firewall/VPN

12. Logging & Monitoring

Syslog SNMPv2c - Simple Network

Monitoring ProtocolManage network performance

Find and solve network problems

Plan for network growth.

Page 18: Vyatta Router/Firewall/VPN

13. Debugging

Tcpdump Wireshark

Page 19: Vyatta Router/Firewall/VPN

Reference

Vyatta home page: http://www.vyatta.com http://www.vyatta.org http://www.vyatta.com/products/demo.php http://www.vietnamnet.vn/cntt/2006/03/548

351/ http://www.vyatta.org/documentation

Page 20: Vyatta Router/Firewall/VPN

Slide History

Author: Nguyen Hai Son, Network Team, Saigon Institute of Technology

Created: Jan 30th, 2008 Last modify:Feb. 26th, 2010