Core (P) · Provider edge (PE) · Peering

開放 IP 核心與對等路由器

開放式 IP 核心與對等互連路由器承載 full internet BGP table for transit and peering and runs the SR-MPLS or SRv6 core between sites. IP Infusion delivers it complete: validated open hardware, OcNOS-SP pre-loaded, supported under one contract.

參考架構

核心與對等互連路由器的四種角色。

同一台 OcNOS-SP 路由器涵蓋每一種核心角色,因此電信業者只需執行單一映像檔與單一支援合約,無需為邊緣、核心、對等互連與路由反射各自採購不同的設備。

IP core and peering topology: P routers running an SR-MPLS or SRv6 core, PE routers at the service edge, and a peering router holding the full internet BGP table to an IXP with RPKI origin validation.
IP core and peering: OcNOS-SP P routers on an SR-MPLS or SRv6 core, PE routers at the service edge, and a peering router to Internet transit and an IXP.

同一份路由器映像檔執行全部四種角色,並依角色進行授權與規格配置。

Open IP core

Core router

您可在單一 underlay 上、以整個產品組合所能提供的最高容量,承載站點間的每一項服務:UfiSpace S9610-36D at 14.4 Tbps, with a single SR-MPLS or SRv6 core doing the forwarding.

冗餘雙平面在鏈路或節點復原期間仍讓該核心持續承載流量,因此網路中段的故障絕不會演變成服務中斷。

Provider / transit

P router

在核心中,P 路由器交換帶標籤的流量且不持有客戶路由,因此將全部資源用於容量與快速重繞,而非路由狀態。 OcNOS-SP runs it with Flex-Algo, TI-LFA, and BFD.

由於該層僅維持標籤運作,您可單憑轉送容量擴充核心。

Provider edge

PE router

PE 路由器是客戶站點接入核心層之處:它會加上傳輸標籤並保有 L3VPN 與 EVPN 服務狀態,因此承載了 P 層從不觸及的 VPN 規模。

在此之後,它會將 service edge 交接給 metro 匯聚,讓核心維持乾淨,並讓服務狀態留在其所屬的邊緣。

Internet edge

Peering router

對等互連路由器是您通往轉接供應商與網際網路交換中心的門戶,並為兩者承載完整的網際網路 BGP 表。 OcNOS-SP validates every route with RPKI and applies your route policy right at the edge.

隨著對等數量成長,路由反射器在其後保持 iBGP 控制平面的可擴展性。

Route scale

在硬體中保存完整的網際網路 BGP 表。

對等互連路由器承載 full internet BGP table for transit and settlement-free peering, IPv4 and IPv6 dual-stack, held in hardware on merchant silicon. For the largest tables, the design uses a platform with a large external TCAM.

完整表轉送

完整路由表、雙協定堆疊,於硬體中承載

對等互連路由器承載一個 full internet BGP table for transit and settlement-free peering, IPv4 and IPv6 from day one, on a platform sized with a large external TCAM. Graceful restart and TI-LFA keep forwarding stable while the control plane reconverges.

路由反射器在核心路由器之間承載 iBGP 表,讓客戶端不必建立 full mesh,從而在網路成長時保持控制平面的可擴展性。

外部 TCAM 路徑

適用於最大路由表的大型外部 TCAM

當路由器需要在大型硬體轉發路徑中承載完整的全域路由表時,設計上會採用具備 external TCAM 的平台。NWP Services 正是這樣運行的:一台 UfiSpace S9600-72XC with OP2 external TCAM, dual-stack, with OcNOS-SP handling RPKI and route policy.

IP Infusion 驗證、預先載入並支援該路由器,因此完整路由表的轉送路徑會以單一受支援系統交付。

對等邊緣工程

在網際網路邊緣的路由安全與流量控制。

對等互連路由器會驗證其所接受的路由、過濾其所通告的內容,並在攻擊期間將緩解措施推送至邊緣。RPKI、BGP FlowSpec、遠端觸發黑洞路由與 BGP communities,為網際網路邊緣提供路由安全控制。

RFC 8210

RPKI 無效路由拒絕

路由器執行 RPKI route-origin validation and rejects invalid routes at the edge, with prefix filtering aligned with MANRS practices, so hijacked and leaked prefixes are dropped before they enter the table.

RFC 8955

用於 DDoS 緩解的 BGP FlowSpec

BGP FlowSpec distributes match-and-action filters across the edge, so a volumetric attack is dropped or rate-limited in the forwarding path as a routing workflow, without a per-router touch.

RFC 7999

遠端觸發黑洞

路由器使用下列方式將受攻擊的目的地導入黑洞: RFC 7999 blackhole community, so a single route announcement steers attack traffic to a discard next-hop across the peering edge.

RFC 1997 / 8092

用於對等政策的 BGP community

BGP communities, including large communities per RFC 8092, tag and classify routes so peering, transit, and customer policy is applied consistently across the edge and inside the AS.

RFC 7752 / 8571

BGP-LS 拓撲與出口流量工程

BGP-LS exports the link-state topology to a PCE or controller, and SR BGP egress peer engineering steers traffic to a chosen peer, so egress selection becomes a controllable decision.

RFC 4456 / 5065

路由反射與 confederation

Route reflectors per RFC 4456 or BGP confederations per RFC 5065 scale the iBGP control plane, so the peering and core routers share the table without a full iBGP mesh.

SR core design

雙平面 SR-MPLS 核心,並行搭配 SRv6。

核心路由器以具備區段路由擴充的 IS-IS 作為其預設 IGP,因此單一標籤交換路徑即可承載每項服務。Flexible Algorithm 會在相同拓撲上,於預設平面之外另建一個低延遲平面,而 TI-LFA 則提供 50ms 以內的快速重新導向。

IGP 與標籤規劃

採用 SR 的 IS-IS,並規劃 SRGB

IS-IS SR 為預設的 IGP,且每個節點共用同一組 SRGB so a prefix-SID maps to the same label everywhere. The default SRGB range is 16000 to 23999.

Dual plane

Flex-Algo 低延遲平面

Flexible Algorithm per RFC 9350 builds a second forwarding plane, tuned for low latency, alongside the default shortest-path plane on the same physical topology, with no overlay.

Fast reroute

Sub-50ms TI-LFA

TI-LFA precomputes a loop-free backup path for every destination, so the core reroutes in under 50ms around a link or node failure while IS-IS reconverges.

Traffic engineering

搭配 PCE 的 SR-TE

SR-TE policies steer traffic on explicit paths, computed by a stateful PCE over PCEP, including egress steering at the peering edge for a chosen exit.

SRGB 規劃,依 OcNOS-SP 區段路由設定指南辦理: a prefix-SID index of 1000 on a loopback maps to label 17000 when the SRGB base is 16000. Using an identical SRGB on every node keeps the same label for a prefix on every node, which simplifies operations.

Platform sizing

哪一款已驗證路由器對應哪個角色。

IP Infusion 交付核心與對等互連路由器,採用 43 validated platforms from Edgecore and UfiSpace, each lab-qualified per ASIC stepping with OcNOS-SP pre-loaded. The core sizes on forwarding capacity and buffering; the full-table edge sizes on the forwarding path that holds the table.

依核心與 peering 角色驗證的路由器。最後驗證:2026 年 7 月。
角色 Validated router 晶片與容量 它為何適合此角色
核心 / P 路由器
UfiSpace S9610-36D open core router, 14.4 TbpsUfiSpace S9610-36D
Broadcom Jericho2C+ (BCM88850), 14.4 Tbps, 36×400G, deep buffer 最高轉送容量,具備深緩衝以及備援熱插拔電源與風扇,適用於核心與網際網路邊緣。
完整表 peering 邊緣
UfiSpace S9600-72XC open peering router with OP2 external TCAMUfiSpace S9600-72XC + OP2
外部 TCAM 轉送路徑,dual-stack 在大型的外部 TCAM 轉送路徑中保存完整的網際網路 BGP 表。這正是 NWP Services 為完整表多歸屬所部署的路由器。
業務邊緣(PE)
UfiSpace S9600-56DX open service-edge routerUfiSpace S9600-56DX
Broadcom Qumran2C, 4.8 Tbps, 8×400G plus 100G access 施加傳輸標籤並保持 L3VPN 與 EVPN 狀態,透過 400G 上行鏈路接入核心。在支援的晶片層上支援 SRv6 與 SR-MPLS 並行運行。
緊湊型業務邊緣
UfiSpace S9600-28DX compact service-edge routerUfiSpace S9600-28DX
Broadcom Qumran2C,2.4 Tbps,雙棧 適用於仍需要 SR-MPLS 傳輸以及 L3VPN 與 EVPN 服務的小型站點的緊湊型業務邊緣,運行於支援 SRv6 的晶片層上。
核心之下的匯聚層
UfiSpace S9600-56DX open aggregation router, 4.8 TbpsUfiSpace S9600-56DX
Broadcom Qumran2c, 4.8 Tbps, 8×400G + 48×100G 以 400G 上行饋入核心。匯聚設計歸屬於 都會乙太網路 page.

採用完整路由表外部 TCAM 的路由器,即為 NWP Services 所部署平台的引用範例。檢視所有驗證平台,請前往 硬體相容性清單,並於下列將功能對應至硬體,即 功能矩陣.

如何評估核心與對等互連路由器的規模

  • 現在就用完整表,或保留成長餘裕。 以現今即可在硬體中承載完整網際網路 BGP 表的路由器來規劃對等邊緣,或在需要擴充路由表空間時採用大型外部 TCAM 方案。
  • 核心容量與緩衝能力。 依轉發容量與可因應網際網路邊緣微突發的深層緩衝來規劃核心層,而非依路由狀態,因為 P 層並不承載客戶路由。
  • 單機或叢集化核心。 將核心設計為冗餘對,使 TI-LFA 具備備用路徑。冗餘平面在發生故障時仍持續轉發流量。
  • SR-MPLS or SRv6. 以 SR-MPLS 作為預設核心,並在您的傳輸策略有此需求之處讓 SRv6 與其並行,供應狀況視平台與版本而定。
  • Route reflection. 部署路由反射器以擴展 iBGP:在較小的網路中將其內建於核心路由器上,或隨著對等數量成長改採專用反射器。
  • 直接對等或路由伺服器。 為實現控制,與大流量網路直接對等,並為免結算對等體的長尾使用 IXP 路由伺服器。
  • One contract. IP Infusion 將每個角色驗證並支援為單一路由器,硬體與軟體則依各自獨立的週期汰換。
組態:route-reflector 叢集

設定 route-reflector 叢集。

您無需 full mesh 即可擴充 iBGP,做法是讓 client 指向 reflector,並由 reflector 在彼此之間傳遞路由。下方的 OcNOS-SP 組態正是如此:三個 iBGP 鄰居,其中兩個在 IPv4 unicast address family 中被指定為 route-reflector-client。

OcNOS-SP · route reflector
! Reflector: reflect routes between iBGP clients
configure terminal
router bgp 200
 neighbor 3.3.3.3 remote-as 200
 neighbor 2.2.2.2 remote-as 200
 neighbor 6.6.6.6 remote-as 200
 address-family ipv4 unicast
  neighbor 3.3.3.3 route-reflector-client
  neighbor 2.2.2.2 route-reflector-client

每一行的作用

  1. router bgp 200 enters BGP for the autonomous system that the core and peering routers share.
  2. The three neighbor ... remote-as 200 lines form the iBGP sessions. 6.6.6.6 is a plain iBGP peer, so it does not get the route-reflector-client line below.
  3. route-reflector-client designates each client per address family, here IPv4 unicast, and the same pattern applies to VPNv4, VPNv6, and L2VPN EVPN.
  4. 若要建置備援 reflector,請加入共享的 cluster 身分,使用 bgp cluster-id command in router bgp mode, a separate step not shown in this minimal example, so clients see one cluster. Clients need no reflector-specific configuration.

Commands follow the OcNOS-SP Layer 3 configuration guide, documentation.ipinfusion.com.

分階段移轉

以每次一個角色的方式移轉核心。

開放核心路由器能與既有的 Cisco、Juniper 或 Nokia 網路互通,因此您可以逐一節點遷移。Segment routing 與 LDP 和 RSVP-TE 並行運作,讓既有與新的傳輸在轉換期間並存。

01 / Interop

與既有網路建立對等

全新的開放式路由器與既有設備建立 IS-IS、OSPF 與 BGP 鄰接關係 Cisco、Juniper 與 Nokia nodes, so it joins the core without a redesign. Targo migrated this way, interoperating with its installed Cisco, MikroTik, and Ubiquiti equipment.

02/將 SR 導入 LDP 網域

為既有節點通告 prefix-SID

An SR Mapping Server advertises prefix-SIDs on behalf of the LDP-only nodes, so segment routing and LDP forward across one domain during the conversion. LDP and SR interworking, with LDP and RSVP-TE graceful restart, adds SR-MPLS without a flag-day cutover.

03/依角色切換

先轉換 P,再轉換 PE,最後轉換 peering

先轉換核心 P 路由器,再轉換 PE 邊緣,最後轉換 peering 路由器,在承載正式流量前先驗證每一台。Graceful restart 與 TI-LFA 讓完整的網際網路 BGP 表在每次切換過程中持續轉送。IP Infusion 在每一步都提供路由器支援。

提供 Cisco IOS-XR 至 OcNOS 的 CLI 轉換協助,以加速組態轉換。請參閱 OcNOS-SP 相較於 Cisco comparison for capability and licensing detail.

開放對比專有

開放核心與對等路由器對比專有核心。

核心層真正的問題在於,開放式路由器能否像 Cisco 或 Juniper 設備一樣承載完整的對等路由表與 SR-MPLS 核心。答案是可以,而且它能做到這一點,同時讓電信業者向不只一家供應商採購硬體,並維持單一支援合約。

運行 OcNOS-SP 的開放核心與對等路由器對比專有核心平台。最後查證:2026 年 7 月。
核心 / peering 能力 開放路由器(OcNOS-SP) 專有機箱(Cisco / Juniper / Nokia)
完整的網際網路 BGP 表(transit 與 peering)
RPKI 無效路由拒絕,符合 MANRS 的過濾 details →
BGP FlowSpec, RTBH, BGP-LS
SR-MPLS 搭配 Flex-Algo 與 TI-LFA details →
SRv6(與 SR-MPLS 同時支援) details →
路由反射與 confederation
硬體採購 來自多家供應商的開放通用晶片 單一供應商機箱
交付與支援 完整路由器,單一支援合約,硬體與軟體分別汰換 Vendor-bundled
Core capacity 採用 Broadcom Jericho2C+,14.4 Tbps,深層緩衝 通用晶片與客製晶片

Cisco、IOS-XR、Cisco 8000、Juniper、Junos、Nokia 與 SR OS 均為各自所有者的商標。IP Infusion 與這些供應商並無隸屬關係,亦不對其背書;本比較反映的是可在下列來源驗證的 OcNOS-SP 能力: 功能矩陣. To replace a proprietary core, see the OcNOS-SP 相較於 Cisco comparison.

在您評估之前

關於核心與對等邊緣的問題。

IP Infusion 將 P、PE 與對等互連路由器整合為單一系統交付:採用 Edgecore 或 UfiSpace 經驗證的開放式硬體,預先載入 OcNOS-SP,並針對各平台與 ASIC 版本進行實驗室驗證,同時提供以 ZTP 上線的已驗證 Day 0 基準。單一供應商在同一份支援合約下承擔軟體、硬體與 RMA,因此由同一團隊負責修復。您仍可依各自獨立的週期選擇與汰換設備與軟體。
在核心中,您以同一份路由器映像檔運行兩種角色。供應商邊緣(PE)連接客戶站點並加上傳輸標籤,因此持有客戶所見的 L3VPN 與 EVPN 服務狀態。供應商(P)路由器在各 PE 路由器之間交換帶標籤的封包,但不持有客戶路由,因此將容量用於轉送與快速重繞。由於兩種角色皆以同一份映像檔運行,PE 終結服務,P 路由器則將其承載於 SR-MPLS 或 SRv6 核心之上,且兩者只需備料與授權同一款平台。
是的。peering 路由器承載完整網際網路 BGP 路由表以進行 transit 與 settlement-free peering,IPv4 與 IPv6 雙堆疊,並在通用晶片的硬體中保存。當您需要容納最大型的路由表時,可在具備大型 external TCAM 的平台上規劃 peering 邊緣的容量。NWP Services 正是在一台搭配 OP2 external TCAM 的 UfiSpace S9600-72XC 上這樣運行,自第一天起即為雙堆疊,並由 OcNOS-SP 處理 RPKI 與路由政策。
路由反射器讓您無需 iBGP full mesh 即可擴展核心:客戶端只與反射器建立對等,再由反射器在彼此之間傳遞路由。OcNOS-SP 依 RFC 4456 執行 BGP 路由反射,並具備 cluster 識別,使冗餘反射器對客戶端呈現為單一 cluster,還可針對 IPv4 unicast、VPNv4、VPNv6 與 L2VPN EVPN 進行每 address-family 的客戶端指定。您可以用路由反射,或依 RFC 5065 以 BGP confederation 來擴展該控制平面,視網路而定擇一採用。
是的。peering 路由器依 RFC 8210 執行 RPKI invalid-route 拒收,因此未通過來源驗證的路由會在網際網路邊緣被丟棄,並套用符合 MANRS 實務的前綴過濾。依 RFC 8955 的 BGP FlowSpec 將 DDoS 緩解過濾規則推送至邊緣,而 remote-triggered black-holing 則使用 RFC 7999 的 blackhole community。BGP community,包含依 RFC 8092 的 large community,驅動 peering 政策。
核心路由器以具備區段路由擴充的 IS-IS 作為 IGP,因此單一標籤交換路徑即可在站點之間承載每項服務。依 RFC 9350 的 Flexible Algorithm 會在相同拓撲上,於預設最短路徑平面之外另建一個低延遲平面,而 TI-LFA 則提供 50ms 以內的快速重新導向。搭配 PCE 的 SR-TE 策略可計算明確路徑,包含對等邊緣的出口導引。SRGB 規劃在每個節點上皆採用預設的 16000 至 23999 範圍。
核心層在資料平面進行重新導向。TI-LFA 會為每個目的地預先計算無迴圈的備援路徑,因此當鏈路或節點故障時,核心層會在 50ms 內切換至備援路徑,同時 IS-IS 在背景重新收斂。BGP、OSPF 與 IS-IS 的優雅重啟能在該重新收斂期間持續轉發完整的網際網路 BGP 表,而 BFD 則能在單躍點、多躍點與 SR 路徑上快速偵測故障。備援雙平面以及可熱插拔的電源與風扇,讓設備在硬體事件期間仍持續承載流量。
SR-MPLS 是預設的核心資料平面,而在網路想要 IPv6 資料平面又不想另設 MPLS 控制平面之處,支援的平台與版本上提供 SRv6。由於兩者運行於同一份路由器映像檔與 IGP,電信業者可將底層遷移至 SRv6,而無需重新歸置其上的 L3VPN 與 EVPN 服務。SRv6 的供應狀況取決於平台與版本,因此請與我們聯絡以確認您硬體的功能集。
評估路由器

檢視開放式核心與對等互連路由器。

了解 IP Infusion 如何交付 P、PE 與對等互連路由器,或與我們聯絡,將您的核心與對等邊緣對應到合適的驗證平台與授權方案。