ÕªÒª£º±¾ÎÄÌÖÂÛÁËÔÚ¿í´ø½ÓÈë»·¾³Ï£¬½ÓÈëÉ豸¡¢½ÓÈëÍøÂçÃæÁٵĸ÷ÖÖ°²È«Íþв£¬ÒÔ¼°Õë¶ÔÕâЩ°²È«ÎÊÌâÒµ½çÌá³öµÄ¸÷ÖÖ½â¾ö·½°¸£¬²¢ÇÒ¶Ô½ÓÈëÍøδÀ´µÄ°²È«Ñо¿×öÁËÒ»µãÕ¹Íû¡£
¹Ø¼ü´Ê£º¿í´ø½ÓÈ룬°²È«£¬¿í´ø½ÓÈë·þÎñÆ÷£¬½ÓÈë½Úµã£¬DSL½ÓÈ븴ÓÃÆ÷
Abstract: This paper describes variant security threats to broadband access network. Different solutions to these threats are brought forward and weighted. Meanwhile, a prospect of research on broadband access network research is made.
Keyword: Broadband access, Security, BRAS, AN, DSLAM
×î½ü10Ä꣬¿í´ø½ÓÈëÍøÂçÔÚÈ«ÇòÅ·¢Õ¹£¬Ô½À´Ô½¶àµÄ¸öÈËÓû§ºÍÆóÒµÓû§Í¨¹ý¿í´ø½ÓÈëÁ¬½Óµ½ÁËInternet¡£Í¬Ê±£¬Óû§µÄÉÏÍøÌåÑéÔ½À´Ô½Ï¸Ä壬ËûÃDz»ÔÙÂú×ãÓÚ½ÓÈëÄÜÁ¦¡¢³©Í¨ÎÞ×èµÄ¸ß´ø¿í£¬¶øÖ𽥶ԷþÎñµÄÖÊÁ¿Ìá³öÁ˸ü¸ßµÄÒªÇó¡£ÔÚ·þÎñÖÊÁ¿ÖУ¬Ò»¸öÖØÒªµÄ¡¢²»ÄܺöÊӵĿÎÌâ¾ÍÊÇ °²È«±£Ö¤¡£
1 ¿í´ø½ÓÈ밲ȫÐÔÎÊÌâ
½ÓÈëÍøÂçµÄÅ·¢Õ¹´øÀ´Á˳ɱ¶µÄÓû§£¬µ«ÊÇҲʹµÃÍøÂçÔâÊÜ°²È«¹¥»÷µÄ¿ÉÄÜÐÔ´ó´óÔö¼Ó¡£ÌرðÊÇÒýÈëÒÔÌ«Íø¼¼Êõ¡¢IP¼¼Êõºó£¬½ÓÈëÍø°²È«ÐÔÎÊÌâÈÕÒæ͹ÏÖ£¬¼àÌýËûÈËÐÅÏ¢£¬µÁÈ¡ÒµÎñ£¨Theft of Service£©£¬ÉõÖÁÔì³ÉËûÈËÔâÊܾܾø·þÎñ£¨Denial of Service£©¹¥»÷[3]µÈ°²È«ÐÔÎÊÌâʱÓз¢Éú¡£Ìṩ'µçÐÅÔËÓª¼¶'µÄ½ÓÈëÍøÂ磬ΪÓû§Ìṩ°²È«µÄ½ÓÈë·þÎñ£¬¼ì²â·Ç·¨ÒµÎñ£¬±£Ö¤ÍøÂçÉ豸Õý³£ÔËÐУ¬¾Í³ÉΪÉ豸É̺ÍÔËÓªÉ̹²Í¬¹Ø×¢µÄÎÊÌâ¡£
¡¡¡¡¿í´ø½ÓÈë¼¼Êõ³ÊÏÖ¶àÑù»¯Ç÷ÊÆ£¬°üÀ¨xDSL¡¢HFC¡¢xPONºÍWimaxÎÞÏß½ÓÈëµÈµÈ£¬ËûÃÇ´óÖ¶¼¾ßÓÐÏÂÃæµÄÍøÂç¼Ü¹¹[1]£º
ͼ 1 ¿í´ø½ÓÈëÍøÂçµÄ¼Ü¹¹
°üÀ¨ÒÔϼ¸¸ö×é³É²¿·Ö£º
1£® Óû§×Ô×éÍøÂç Customer Prem. Net¡£xDSLÊǵ±Ç°×îÆÕ±éµÄÓû§½ÓÈ뷽ʽ¡£
2£® ½ÓÈë½Úµã AN£¨Access Node£©¡£Íê³ÉÓû§ÏßÀµÄÎïÀíÖսᣬ»òÕßÎÞÏßÐŵÀµÄÖսᡣAN×î¿¿½üÓû§£¬ÊÇ°²È«·À»¤µÄµÚÒ»µÀÃÅÀ¸¡£ÔÚ½ÓÈëÍø°²È«ÖУ¬ANÕ¼ÓÐÖØÒªµÄµØλ¡£
3£® ÒÔÌ«Íø»ã¾ÛÍøÂç Ethernet Aggregation Network¡£Ëü½øÒ»²½¶Ô»ã¾ÛÊý¾Ý£¬Í¬Ê±Ò²¼ç¸ºÍøÂçÄÚ²¿Êý¾Ý½»»»µÄÈÎÎñ¡£
4£® ¿í´øÍøÂçÍø¹Ø Broadband Network Geteway £¬Ëü°üÀ¨ºÜ¶à¹¦ÄÜ£ºÖÕ½áÒÔÌ«²ã¼°Æä¶ÔÓ¦µÄ·â×°¡¢Óû§ÈÏÖ¤£¨½áºÏÈÏÖ¤·þÎñÆ÷£©¡¢Óû§¶Ë×Ô¶¯ÅäÖá¢QoSÒµÎñ±£Ö¤¡¢Ä¬ÈÏÍø¹ØµÈµÈ¡£
½ÓÈë½Úµã¡¢ÒÔÌ«»ã¾ÛÍøÂçºÍ¿í´øÍøÂçÍø¹ØÊôÓÚÔËÓªÉÌËùÓУ¬ÕâЩÉ豸»òÕßÍøÂç¶ÔÔËÓªÉ̶øÑÔ¶¼ÊÇ¿ÉÐŵġ£Óû§×Ô×éÍøÂç¹éÓû§×Ô¼ºËùÓкÍʹÓã¬Óû§×ÔÖ÷Íø·¶ÔÔËÓªÉÌÊDz»¿ÉÐŵġ£ÓÐʱ°²È«ÎÊÌâ²úÉúÓÚÐÅÈÎÓòÄÚ£¬µ«ÊÇ°²È«Íþв´ó¶¼À´×Ô²»ÐÅÈÎÍøÂçÄÚ¶ñÒâÓû§»òÕß³ÌÐòµÄ¹¥»÷¡£¹éÄÉÆðÀ´£¬µ±Ç°£¬½ÓÈëÍøÂçÖÐÖ÷ÒªÓÐÏÂÃæµÄһЩ°²È«ÎÊÌ⣺
1£® ·Ç·¨Óû§µÄ½ÓÈë
2£® ·Ç·¨±¨ÎĺͶñÒⱨÎÄ·¢ËÍ
3£® MAC/IPµØÖ·ÆÛÆ£¬Ã°ÓÃMACµØÖ·»òÕßIPµØÖ·£¬ÍµÈ¡ËûÈ˵ÄÒµÎñ·þÎñ»òÕßÔì³ÉDoS¹¥»÷
ÏÂÃæ±¾ÎÄÒÀ´Î¶ÔÉÏÊöÎÊÌâÒÔ¼°Æä¶ÔÓ¦µÄ½â¾ö·½°¸Õ¹¿ªÂÛÊö¡£
2 ·Ç·¨Óû§½ÓÈë
·Ç·¨Óû§½ÓÈëÐÔÖÊÑÏÖØ£¬Ö±½ÓËðº¦ÔËÓªÉ̵ÄÔËÓªÊÕÒæ¡£Èç¹û²»¶ÔÓû§½øÐÐʶ±ðºÍÈÏÖ¤£¬ÄÇô·Ç·¨Óû§½ÓÈë¾Í»á´óÁ¿´æÔÚ¡£
Óû§Ê¶±ðÓëÈÏÖ¤¼¼ÊõÒѾ·Ç³£µÄ³ÉÊ죬±ÈÈçPPPoE¡¢DHCP+WebºÍ802.1xµÈÒѾ±»ÆÕ±éʹÓá£Òµ½çµ±Ç°ÆÕ±é¹Ø×¢µÄÎÊÌâÊÇ£º¶ÔÓû§¶Ë¿Ú£¨Ò²³ÆΪÓû§Ïß·£©µÄʶ±ð¡£Èç¹ûÈÏÖ¤·þÎñÆ÷Ö»ÊÇͨ¹ýÓû§ÃûÀ´Ê¶±ðÓû§£¬ÄÇôÓû§¿ÉÒÔ°Ñ×Ô¼ºµÄÓû§ÃûºÍÃÜÂë¹²Ïí¸øÆäËûÓû§£¬ÆäËûÓû§Ò²ÄÜÉÏÍø£¬ÕâÊÇÔËÓªÉ̲»Ï£Íû¿´µ½µÄ¡£
¹ýÈ¥ÔÚPPPoAΪÖ÷Òª½ÓÈ뷽ʽʱ£¬Óû§VCÔÚBRASÉÏÖսᣬÒò´Ë£¬Óû§µÄ¶Ë¿ÚÐÅÏ¢Ö±½Ó¾Í¿ÉÒÔÔÚBRASÉÏ»ñÈ¡¡£ÏÖÔÚ£¬PPPoEºÍIPoAÊÇÖ÷ÒªµÄ½ÓÈ뷽ʽ¡£ÕâÁ½ÖÖ½ÓÈ뷽ʽÏ£¬Ã»Óа취ÈÃBRASÖ±½Ó»ñÈ¡¶Ë¿ÚÐÅÏ¢¡£µ±Ç°£¬ÓжàÖÖÓû§¶Ë¿Ú£¨»òÕßÓû§Ïß·£©Ê¶±ð·½°¸±»Ìá³öÀ´£º
* DHCP option82 DHCP Option82£¨RFC3046£©ÔÚDHCP£¨RFC2131£©µÄ»ù´¡ÉÏ£¬¶ÔDHCPÐÒéÁ÷³Ì½øÐÐÁËÀ©³ä¡£ANÐèÒª½Ø»ñDHCPÉÏÏÂÐÐÐÒ鱨ÎÄ£¬°çÑÝ2²ãDHCP Relay AgentµÄ½ÇÉ«¡£ÉÏÐз½Ïò£¬½«¶Ë¿ÚÐÅÏ¢²åÈëµ½option82×Ö¶ÎÖУ»ÏÂÐз½Ïò£¬°þÀë´Ë×Ö¶ÎÐÅÏ¢£¨¿ÉÑ¡£©¡£ÏÂͼΪÐÒé½»»¥Í¼£º
ͼ 2 DHCP Option82ÐÒé½»»¥Í¼
* PPPoE+ ÓÖ³ÆΪPPPoE Intermediate Agent£¬ºÍDHCP option82ÀàËÆ£¬Ëü¶ÔPPPoEÐÒ鱨ÎĽøÐÐÁËÀ©³ä¡£AN½Ø»ñPPPoEËÑË÷½×¶ÎµÄÐÒ鱨ÎÄ£¬ÉÏÐвåÈë¶Ë¿ÚÐÅÏ¢¡£ÏÂͼΪÆäÐÒé½»»¥Í¼£º
ͼ 3 PPPoE+ÐÒé½»»¥Í¼
* VBAS ºÍPPPoE+ÂÔÓв»Í¬£¬VBASÐÞ¸ÄPPPoEµÄÁ÷³Ì£¬ÔÚÓû§ÓëBRASÐÒé½»»¥ÖУ¬²åÈëBRASÓëANµÄ½»»¥£¬»ñÈ¡¶Ë¿ÚÐÅÏ¢¡£ÐÒé½»»¥Í¼ÈçÏ£º
ͼ 4 VBASÐÒé½»»¥Í¼
* VLAN Stacking Ò²¾ÍÊÇË«Tag£¬Ê¹ÓÃÄÚ²ãVLANÀ´Î¨Ò»±êʶÓû§¶Ë¿ÚÐÅÏ¢¡£
* VMAC ¸Ã·½·¨¶Ôÿ¸öÓû§Êý¾Ý±¨ÎĵÄÔ´MACµØÖ·°´ÕÕÌض¨¹æÔò½øÐзÒ룬·ÒëºóµÄMACµØÖ·°üº¬ÁËÓû§¶Ë¿ÚÐÅÏ¢¡£ÕâÑùBRASÔÚPPPoEÐÒé½»»¥Ê±£¬¾Í¿ÉÒÔÖ±½Ó´ÓÔ´MACµØÖ·ÐÅÏ¢ÖлñÈ¡µ½Óû§¶Ë¿ÚÐÅÏ¢¡£
¸÷ÖÖʵÏÖ·½Ê½µÄÓÅȱµãÈçÏ£º
±í¸ñ 1 ¶Ë¿Úʶ±ð¼¼ÊõÓÅȱµã¶Ô±È
3 ·Ç·¨±¨Îĺ͹ýÁ¿±¨ÎÄ
ÉÏÐз½Ïò£¬ÒòΪÓû§×Ô×éÍøÂç²»ÊÜ¿Ø£¬Èç¹û¶ñÒâÓû§¹¹Ôì·Ç·¨ÐÒ鱨ÎÄ£¬ÏòÉÏ·¢ËÍ£¬¾Í»áµ¼ÖÂÍøÂçÉ豸´¦ÀíÐÔÄÜϽµ£¬ÓÐʱ»¹Ôì³ÉÍøÂçÉ豸ϵͳÎÉÂÒ£¬ÉõÖÁËÀ»ú¡£Èç¹û¶ñÒâÓû§¹ýÁ¿µØÉÏÐз¢ËÍÐÒé¡¢¹ã²¥±¨ÎÄ£¬ÎÞÂÛÊǺϷ¨»¹ÊÇ·Ç·¨£¬¶¼»áÔì³ÉϵͳÉ豸ÐÔÄÜÃ÷ÏÔϽµ£¬ÒòΪÐÒé¡¢¹ã²¥µÈ±¨ÎĵĴ¦Àí·Ç³£ÏûºÄÉ豸×ÊÔ´¡£
ÏÂÐз½Ïò£¬¾¡¹Ü´¦ÓڿɿصÄÍøÂçÓòÄÚ£¬µ«ÊÇÒòΪÉ豸×ÔÉíÎȶ¨ÐÔÎÊÌ⣬ÒÔ¼°ÍøÂ縴ÔÓÐÔÎÊÌ⣬Ҳ¿ÉÄÜ»á³öÏÖ·Ç·¨»òÕß¹ýÁ¿±¨ÎÄ·¢ËÍ£¬Ò²ÐèÒª½øÐзÀ·¶¡£
¹éÄÉÆðÀ´£¬·Ç·¨±¨ÎÄ°üÀ¨£º
1. ·Ç·¨Ô´MACµØÖ·±¨ÎÄ¡£Ô´MACµØÖ·²»ÄÜÊǹ㲥»òÕß×é²¥µØÖ·£»ÓÐЩMACµØÖ·ÒѾ±»±ê×¼×éÖ¯ËùÔ¤Áô£¬²»Äܱ»ÆÕͨÓû§Ê¹Óá£
2. ·Ç·¨ÐÒ鱨ÎÄ¡£´ÓÀíÂÛÉÏ·ÖÎö£¬IGMPÐÒéÉÏÐз½Ïò²»¿ÉÄÜÓÐQuery±¨ÎÄ£¬ÏÂÐз½Ïò²»¿ÉÄÜÓÐReport/Leave/Join±¨ÎÄ£»DHCPÐÒéÉÏÐв»¿ÉÄܳöÏÖOffer/Ack±¨ÎÄ£¬ÏÂÐв»¿ÉÄܳöÏÖDiscover/Request£»PPPoEÐÒéÉÏÐв»»áÓÐPADOºÍPADS±¨ÎÄ£¬ÏÂÐв»»áÓÐPADIºÍPADR±¨ÎÄ£»Â·ÓÉÐÒ鱨Îĵȡ£¸ù¾ÝÐèÒª£¬¶ÔÕâЩ±¨ÎĶ¼¿ÉÒÔÀ¹½Ø¹ýÂË¡£
3. ³¬³¤±¨ÎÄ¡¢³¬¶Ì±¨ÎÄ»òÕßУÑé´í±¨ÎÄ¡£µÍÓÚ64×ֽڵı¨ÎÄ»òÕß´óÓÚ1518×ֽڵı¨ÎÄ¡£Ìض¨Çé¿öÏ£¬³¬³¤±¨ÎÄ£¨jumbo frame£©ÊÇÔÊÐíµÄ¡£
¹ýÁ¿±¨ÎÄÀàÐÍÒ»°ã·Ö³ÉÒÔϼ¸Àࣺ
1. ¹ýÁ¿µÄÐÒ鱨ÎÄ
2. ¹ýÁ¿µÄ¹ã²¥±¨ÎÄ
3. ¹ýÁ¿µÄ×é²¥±¨ÎÄ
4. ¹ýÁ¿²»Í¬Ô´MACµØÖ·µÄ±¨ÎÄ
Ç°ÃæÈýÖÖ¹ýÁ¿±¨ÎÄÀàÐÍ»á´óÁ¿ÍÌÊÉÉ豸´¦Àí×ÊÔ´£¬µÚËÄÖÖ»áÕ¼Óý»»»Ð¾Æ¬ÓÐÏÞµÄMACµØÖ·±í×ÊÔ´£¬¶¼ÐèÒª½øÐпØÖÆ¡£
Ç°ÈýÖÖ¹ýÁ¿±¨ÎĵĴ¦Àí²½ÖèÒ»°ãÈçÏ£º
1. Æ¥ÅäÌض¨ÀàÐ͵ı¨ÎÄ ÌØÕ÷ÊÇ£ºÌض¨µÄÐÒ鱨ÎÄ¡¢¹ã²¥±¨ÎÄ£¨»òÕßijÖÖ¸ü¾ßÌåÌØÕ÷µÄ¹ã²¥±¨ÎÄ£©¡¢×é²¥±¨ÎÄ£¨»òÕßijÖÖ¸ü¾ßÌåÌØÕ÷µÄ×é²¥±¨ÎÄ£©
2. ͳ¼Æ´ËÀ౨Îĵķ¢ËÍËÙÂÊ
3. Èç¹û·¢ËÍËÙÂʳ¬¹ýÔ¤¶¨ÒåµÄËÙÂÊ£¬Å×Æú±¨ÎÄ
´¦Àí¹ýÁ¿ÐÒé¡¢¹ã²¥ºÍ×é²¥±¨Îĵļ¼ÊõÓÖ³ÆΪ±¨ÎÄÒÖÖÆ¡£
½â¾ö¹ýÁ¿Ô´MACµØÖ·ÎÊÌâ±È½Ï¼òµ¥£º¿ÉÉ趨Óû§²à¶Ë¿ÚѧϰMACµØÖ·¸öÊýµÄÉÏÏÞ¡£ÕâÑù£¬Ò»µ©¶Ë¿Ú´ïµ½Ô¤¶¨ÒåµÄMACµØÖ·¸öÊý£¬ºóÐø´øÓÐÐÂMACµØÖ·µÄ±¨ÎÄÒ»Âɱ»¶ªÆú¡£
4 MAC/IPµØÖ·ÆÛÆ
MAC/IPµØÖ·ÆÛÆÊǷdz£ÑÏÖصݲȫÍþв¡£
MACµØÖ·ÆÛƵı¾ÖÊÊÇ»á³öÏÖÖظ´µÄMACµØÖ·£¬Ôì³É½»»»Ð¾Æ¬MACѧϰǨÒÆ£¬²¿·ÖÓû§ÎÞ·¨ÉÏÍø¡£MACµØÖ·ÆÛÆ¿ÉÒÔ·Ö³ÉÏÂÃæÁ½ÖÖÀàÐÍ£º
1£® Óû§µÄMACµØÖ·ÆÛÆ£»
2£® ÉÏÓÎÍøÂçÒµÎñ·þÎñÆ÷£¨ÈçBRAS£¬DHCP Server/Relay£¬Ä¬ÈÏÍø¹ØµÈ£©µÄMACµØÖ·ÆÛÆ£»
ÒÔÌ«ÍøÖÐMACµØÖ·ÐÅÏ¢»ù±¾Êǹ«¿ªµÄ£¬Í¨¹ýɨÃ蹤¾ß£¬Óû§Ò²¿ÉÒÔ½ÏÈÝÒ׵ػñÈ¡ÆäËüÓû§µÄMACµØÖ·ÐÅÏ¢¡£Èç¹ûÏàͬµÄMACµØÖ·³öÏÖÔÚÉ豸µÄ²»Í¬Óû§¶Ë¿ÚÉÏ£¬¾Í»áÔì³ÉMACµØַѧϰ·¢ÉúÎÉÂÒ£¬µ¼ÖÂÓû§ÎÞ·¨ÉÏÍø¡£
ΪÁËÔöÇ¿°²È«ÐÔ£¬ÔÚ½ÓÈëÍøÂ磬һ°ãÒªÇóÔÚAN´¦ÊµÏÖÓû§¶Ë¿Ú¸ôÀ룺ÔÚͬһ¸öVLANϵÄÓû§Ö®¼äÏ໥²»ÄÜͨÐÅ£¬¶øÖ»ÄܺÍÉÏÐлã¾Û¿Ú»¥Í¨¡£Óû§¶Ë¿Ú¸ôÀë¿ÉÒÔͨ¹ýPVLAN£¨Private VLAN£©¼¼ÊõÀ´ÊµÏÖ¡£
ͼ 5 PVLAN
¼Ù¶¨PortA¡¢PortBµ½PortF¶¼ÊôÓÚÒ»¸öVLAN£¬PortAÊÇÉÏÁª¿Ú¡£Èç¹ûÉèÖÃΪPVLAN£¬ÄÇôÉÏÐУ¬Óû§¿ÚÖ»ÄܺÍPortA»¥Í¨£»ÏÂÐÐPortA¿ÉÒÔºÍPortBµ½PortFÓû§¶Ë¿ÚÏàͨ¡£
²»ÊÇËùÓеĽ»»»Ð¾Æ¬¶¼Ö§³ÖPVLANµÄ¹¦ÄÜ£¬¼´Ê¹Ö§³ÖPVLANµÄ¹¦ÄÜ£¬Ò²ÓпÉÄÜÒòΪÉ豸MACµØÖ·ÉèÖò»µ±Ôì³ÉMACµØÖ·Öظ´ÎÊÌ⣬»òÕßÓû§Í¨¹ýÆäËûÇþµÀ»ñµÃÆäËûÓû§µÄMAC£¨±ÈÈç'±©Á¦'MAC³¢ÊÔ£©¡£PVLAN¼¼Êõ±¾Éí²»×ãÒÔÍêÈ«½â¾öÓû§²àMACµØÖ·ÆÛÆÎÊÌâ¡£½â¾öÓû§²àMACµØÖ·ÆÛÆ£¬´æÔÚ²»Í¬µÄ½â¾ö·½·¨£¬ÓÅȱµã¸÷²»Ïàͬ£º
1. VMAC ÔÚAN´¦£¬ÉÏÐз½Ïò£¬¸øÿ¸ö<ÎïÀí¶Ë¿Ú, MAC>·ÖÅä»òÕßÉú³ÉÒ»¸ö¶ÀÒ»ÎÞ¶þµÄÐéÄâMAC£¨Virtual MAC£¬¼ò³ÆVMAC£©µØÖ·¡£±»½âÊÍÒÔºóµÄMACµØÖ·ÒòΪÊÇÉ豸×Ô¼º²úÉúµÄ£¬Òò´ËÊÇ¿ÉÐŵģ¬¶øÇÒÈ·±£²»»á³öÏÖÓû§²àMACµØÖ·Öظ´µÄÏÖÏó¡£Ê¹ÓÃVMACµØÖ·´úÌ汨ÎĵÄÔ´MACµØÖ·¡£ÏÂÐз½Ïò£¬¸ù¾ÝVMAC²éÕÒµ½¶ÔÓ¦µÄÔʼµÄMACµØÖ·£¬È»ºóʹÓÃÔʼMACµØÖ·´úÌæVMACµØÖ·¡£VMAC²»½ö½ö¿ÉÓÃÀ´·ÀÖ¹Óû§MACµØÖ·ÆÛÆ£¬»¹¿É·ÀÖ¹¶ÔÒµÎñ·þÎñÆ÷MACµØÖ·µÄÆÛÆ£¬²¢ÇÒÒ²¿ÉÒÔÓÃÓÚÓû§¶Ë¿Úʶ±ð¡£È±µãÊÇÓ°ÏìÓëMACµØÖ·Ïà¹ØµÄÐÒ飬´¦Àí¸´ÔÓ¡£
2. MACµØÖ·°ó¶¨ ½«MACµØÖ·¾²Ì¬°ó¶¨µ½Óû§¶Ë¿Ú£¬Èç¹ûÊý¾Ý±¨ÎĵÄÔ´MACµØÖ·ºÍ°ó¶¨µÄMACµØÖ·²»Í¬£¬ÄÇô±»¶ªÆú¡£´Ë·½·¨·Ç³£¼òµ¥£¬µ«´æÔÚ¹ÜÀíÄѵÄÎÊÌâ¡£
3. »ùÓÚPPPoE Session¸ÐÖªµÄÊý¾Ý±¨ÎÄת·¢ Ó¦ÓÃÓÚPPPoE½ÓÈë»·¾³¡£Ã¿¸öÓû§¶¼¶ÔÓ¦¶ÀÒ»µÄPPPoE_SessionID¡£ÎÒÃÇ¿ÉÒÔÔÚANÉϼǼһÕÅµÄ±í£¬ÉÏÐÐÖ±½Ó»ã¾Û£¬ÏÂÐпÉÒԲ鿴¸Ã±íÀ´½øÐÐÊý¾Ýת·¢¡£ÕâÑù£¬Êý¾Ý±¨ÎĵÄת·¢ÍêÈ«¿ÉÒÔ²»Ê¹ÓÃMACµØÖ·£¬Ò²¾Í²»ÐèҪѧϰ£¬´Ó¶øÒ²¾Í²»´æÔÚMACµØÖ·Öظ´ÎÊÌâ¡£
4. »ùÓÚIP¸ÐÖªµÄÊý¾Ý±¨ÎÄת·¢ Ó¦ÓÃÓÚIPoEµÄ½ÓÈë»·¾³¡£ÔÚANÉÏ£¬½¨Á¢Ò»ÕÅ±í£¬ÒòΪIPÊÇΨһµÄ£¬ËùÒÔ²»»á´æÔÚIPÖظ´µÄÏÖÏó£¬Êý¾Ý±¨ÎÄÏÂÐÐת·¢Ã»ÓÐÎÊÌâ¡£ºÍ»ùÓÚPPPoE SessionµÄÊý¾Ý±¨ÎÄת·¢Ò»Ñù£¬ANÉÏÒ²²»ÐèÒªMACѧϰ¡£
ÀûÓÃPPPoE Session»òÕßIP¸ÐÖªµÄ·½Ê½ºÍ´«Í³µÄ¶þ²ã½»»»»úµÄת·¢»úÖÆÒѾÓÐÖʵIJ»Í¬£¬Ò»°ãµÄ½»»»Ð¾Æ¬ÄÑÒÔʵÏÖ¡£ËûÃǵÄÓŵãÊÇ£¬²»ÓÃÐÞ¸ÄÊý¾Ý±¨ÎÄ£¬²»»áÓ°ÏìÆäËüÐÒé¡£
ÒµÎñ·þÎñÆ÷µÄMACµØÖ·ÆÛƽ«»áʹµÃÍøÂçÉ豸µÄÒµÎñ·þÎñÆ÷MACµØַѧϰ·¢ÉúǨÒÆ£¬´Ó¶øÔì³ÉÉ豸ϵIJ¿·ÖÓû§ÎÞ·¨ÉÏÍø¡£ÒµÎñ·þÎñÆ÷MACµØÖ··ÀÆÛÆ¿ÉÒÔʹÓÃÏÂÃæµÄ¼¼ÊõÀ´½â¾ö£º
1. VMAC ʹÓÃVMAC¿ÉÒÔ½â¾öÔÚ¸÷ÖÖ½ÓÈë»·¾³ÏµÄÒµÎñ·þÎñÆ÷MACÆÛÆ¡£
2. ÒµÎñ·þÎñÆ÷MACµØÖ·¾²Ì¬ÅäÖà ÊÖ¶¯½«ÒµÎñ·þÎñÆ÷µÄMACÅäÖõ½AN½»»»Ð¾Æ¬µÄ¾²Ì¬MACµØÖ·±íÉÏ£¬ÕâÑùÒµÎñ·þÎñÆ÷MACµØַѧϰ¾Í²»»á·¢ÉúǨÒÆ¡£
3. ÒµÎñ·þÎñÆ÷MACµØÖ·×Ô¶¯ÅäÖà »ù±¾Ë¼ÏëÊÇ£¬ÈÃAN³äµ±PPPoE»òÕßDHCP¿Í»§¶Ë£¬¶¨ÆÚ·¢ÆðPPPoE»òÕßDHCPÇëÇó£¬ÕâÑù¾Í¿ÉÒÔ¶¯Ì¬µÄ»ñÈ¡BRASºÍDHCP Server/RelayµÄMACµØÖ·¡£ÆäÓŵã·Ç³£Ã÷ÏÔ£ºÀûÓÃÏÖÓеÄÐÒ飬²»ÓÃÊÖ¶¯ÅäÖ㬲»ÐÞ¸ÄÊý¾Ý±¨ÎÄ£¬²»Ó°ÏìÆäËüÐÒé¡£
IPÆÛÆ´æÔÚÓÚIPoE½ÓÈ볡¾°Ï£¬Ã°ÓÃËûÈËIPµØÖ·£¬µÁÈ¡·þÎñ£¬»òÕßûÓÐͨ¹ýDHCP»ñµÃÅäÖÃÐÅÏ¢µÄÇé¿öϽÓÈëÍøÂ磬·Á°ÁËÔËÓªÉ̵Äͳһ¹ÜÀí¡£½â¾öÕâ¸öÎÊÌâÐèÒªÔÚANÉÏʵÏÖDHCP IP Source Guard¡£Ëü¼àÌýÀ´ÍùÓÚÓû§ºÍDHCP Server/RelayµÄÐÒ鱨ÎÄ£¬ÔÚÓû§Ã»ÓлñÈ¡ÅäÖÃÐÅÏ¢ÒÔÇ°£¬³ýÁËDHCPÐÒ鱨ÎÄ£¬ÆäËûÉÏÐб¨ÎÄͳͳÅ×Æú¡£Ò»µ©¼àÌýµ½DHCP Ack±¨ÎÄ£¬¾Í°ó¶¨<·ÖÅäµÄIP, Óû§MAC>µ½Óû§¶Ë¿Ú£¬Ê¹ÄÜÉÏÐÐÊý¾Ý±¨Îĵķ¢ËÍ£¬Í¬Ê±±£Ö¤ÉÏÐÐÊý¾Ý±¨ÎĵĺͰ󶨵Ä<·ÖÅäµÄIP, Óû§MAC>Ò»Ö¡£ÔÚDHCP×âÓõ½ÆÚºó£¬È¡ÏûÕâÖÖÀ¦°ó£¬²¢ÇÒÍ£Ö¹ÉÏÐзÇDHCPÐÒ鱨Îĵķ¢ËÍ¡£
5 ÖÐÐË¿í´ø½ÓÈëÉ豸µÄ°²È«¹¦Äܼ°Ìصã
¾¹ý¶àÄêµÄ»ýÀÛ£¬ÖÐÐËͨѶµÄ¿í´ø½ÓÈëÉ豸ÒѾÔÚ¹ú¼Ê¹úÄÚ´ó¹æģʹÓá£Ãæ¶Ô¸÷ÖÖ²»Í¬µÄ°²È«ÒªÇ󳡾°£¬ÖÐÐËͨѶµÄ¿í´ø½ÓÈëÉ豸¶¼¾ÊÜסÁ˸÷ÖÖ¸÷ÑùµÄ¿¼Ñé¡£
Ç°ÃæÃèÊöµÄ¼¼ÊõÎÊÌ⣬ÊÇÄ¿Ç°Òµ½ç±È½Ï¹Ø×¢µÄÎÊÌâ¡£³ýÁËÌṩ¶ÔÕâЩÎÊÌâµÄ½â¾ö·½·¨Í⣬ÖÐÐËͨÐÅ¿í´ø½ÓÈëÉ豸»¹Ö§³ÖºÜ¶àÆäËûÖØÒªµÄ°²È«¹¦ÄÜ¡£¾ßÌåÈçÏ£º
1. Óû§±êʶ¹¦ÄÜ£¨Ò²¾ÍÊÇÇ°Ãæ˵µÄ·Ç·¨Óû§½ÓÈ룩
* DHCP Option82
* PPPoE+
* VBAS
* VLAN Stacking
2. ÈÏÖ¤
* 802.1x
* Radius client
3. MAC/IPµØÖ·ÆÛÆ
* MACµØÖ·°ó¶¨£¬Í¨¹ý°ó¶¨MACµØÖ·À´·ÀÖ¹MACµØÖ·ÆÛÆ¡£
* IPµØÖ·°ó¶¨£¬Í¨¹ý°ó¶¨IPµØÖ·À´·ÀÖ¹IPµØÖ·ÆÛÆ¡£
* MACµØÖ·¸öÊýÏÞÖÆ£¬ÏÞÖÆMACµØÖ·¸öÊý¿ÉÒÔ¼õÉÙMACµØÖ·ÆÛƵĿÉÄÜÐÔ¡£
* IPµØÖ·¸öÊýÏÞÖÆ£¬ÏÞÖÆIPµØÖ·¸öÊý¿ÉÒÔ¼õÉÙIPµØÖ·ÆÛƵĿÉÄÜÐÔ¡£
* DHCP Snooping Guard£¬¶¯Ì¬°ó¶¨IP/MACµØÖ·µ½¶Ë¿Ú¡£
4. ¹ýÁ¿ºÍ·Ç·¨±¨ÎÄ
* ¹ã²¥±¨ÎÄÒÖÖÆ/×é²¥±¨ÎÄÒÖÖÆ/δ֪µ¥²¥±¨ÎÄÒÖÖÆ
* Êý¾ÝÁ÷ÏÞËÙ
* ·Ç·¨ÐÒ鱨ÎĹýÂË£¬PPPoE·Ç·¨ÐÒ鱨ÎĹýÂ˺ÍIGMP·Ç·¨ÐÒé¹ýÂË
* δ֪×é²¥±¨ÎĹýÂË
5. ×é²¥°²È«
* IGMPÐÒ鱨ÎÄÒÖÖÆ£¬»ùÓڶ˿ںͻùÓÚVLAN¡£
* Óû§¶Ë¿Ú×é²¥×é¹ýÂË£¬Óû§¶Ë¿Ú×é²¥×é¸öÊýÏÞÖÆ
* ×é²¥×é¸öÊýÏÞÖÆ
* ×é²¥VLAN£¬ÆäËûVLAN²»ÅÜ×é²¥ÒµÎñ
6. ¸ß²ãÐÒ鰲ȫ
* SNMP v3
* SSHv2
* ·ÓÉÐÒéÈÏÖ¤£¬°üÀ¨RIP/OSPF/IS-IS/BGPµÄ¸÷ÖÖÈÏÖ¤
7. ÆäËû
* ACL£¬Ç¿´óµÄL2µ½L7¶à²ã´Î±¨ÎÄʶ±ð¹¦ÄÜ¡£
* PVLAN
* Íø¹ÜIPµØÖ·ÏÞÖÆ£¬Ö»ÓÐÌض¨µÄIPµØÖ·²ÅÄÜSNMP·ÃÎÊÉ豸¡£
* Telnet IPµØÖ·ÏÞÖÆ£¬Ö»ÓÐÌض¨µÄIPµØÖ·²ÅÄÜTelnet·ÃÎÊÉ豸¡£
* ¶à¼¶Óû§È¨Ï޺ͿÚÁî±£»¤
6 ½áÊøÓï
¶ÔÓÚ½ÓÈëÍøÂçµÄÉÌÒµÓ¦Ó㬰²È«ÊÇÒ»¸öÖØÒªµÄ²»ÈݻرܵÄÎÊÌ⣬°²È«Ò²ÊÇÒ»¸öËæ×Åʱ¼ä¶¯Ì¬±ä»¯µÄ¿ÎÌâ¡£²»½öÔËÓªÉ̸߶ÈÖØÊÓ°²È«ÎÊÌ⣬°üÀ¨ÖÐÐËͨѶÔÚÄÚµÄÍøÂçÉ豸ÌṩÉ̶԰²È«ÎÊÌâÒ²ÊÇÒì³£ÖØÊÓ£¬ÖÐÐËͨѶÌṩµÄDSLAMÉ豸ÌṩÁ˽ÓÈë²ã´ÎµÄÇ¿´óµÄ°²È«½â¾ö·½°¸¡£
²Î¿¼ÎÄÏ×£º
[1] http://www.dslforum.org/ftparchive/Working_Texts/WT-101v11.doc, 2006
[2] http://www.greatbit.com/.
[3] James Pike. ¡¶Cisco ÍøÂ簲ȫ¡·, ±±¾©£ºÇ廪´óѧ³ö°æÉç, 2004-09.