Page 1 of 16
Network Configuration Management
Configuration Management
UCI 102: COMPUTER COMMUNICATION SYSTEMS
Topic 5
MASENO UNIVERSITY
[Link]
Page 2 of 16
Network Configuration Management
Ta ble of Conte nts
Table of Contents .................................................................................................................................................... 2
Objectives ........................................................................................................................................................... 3
What is Configuration Management? ...................................................................................................................... 4
Why Is Configuration Management Important? .................................................................................................. 6
Best Practices for Configuration Management ................................................................................................... 6
Network Documentation and Diagrams .............................................................................................................. 7
Managing Risk .................................................................................................................................................... 7
Time to Resolve .................................................................................................................................................. 8
Developing Configuration Management Capabilities .......................................................................................... 9
Asset Management ........................................................................................................................................... 10
Review Questions ................................................................................................................................................. 16
[Link]
Page 3 of 16
Network Configuration Management
Objectives
Many operational problems facing network managers today result from a lack of configuration
management capabilities. Configuration management is an essential operational capability. It is
foundational for other network management functions and crucial for service management.
This topic introduces you to configuration management and its importance for operations and network
management.
At the end of this lesson, the learner will be able to:
1. Explain configuration management and its importance in a network environment.
2. Identify best practices for configuration management.
3. Demonstrate capability to develop a configuration management capability in an organization.
Page 4 of 16
Network Configuration Management
Wha t i s Confi gur a ti o n M a na ge m e nt?
Configuration management falls under the network operations function of network management.
It involves a wide number of areas, including the following:
x Setting and managing configuration of network devices.
x Collecting and maintaining an inventory of software and hardware devices.
x Device software management.
x Conducting backup of device configurations, and the viewing, archiving and comparison of
configuration information.
x Detecting any changes to the configuration of hardware, or software.
x Implementing any configuration changes, and
x Providing support for change management.
The IT Infrastructure Library (ITIL) is a framework for service management to help ensure that the IT
department and the business group in an organization are aligned. It is a comprehensive framework
covering many topics related to operations and network management. ITIL defines a set of processes,
of which one is configuration management.
ITIL outlines the goals of configuration management to be the following:
x To account for all IT assets
x To provide accurate information to support other service management processes
Page 5 of 16
Network Configuration Management
x To provide a sound basis for incident, problem, change, and release management
x To verify records against infrastructure and to correct exceptions
Configuration management is the C from the FCAPS (fault, configuration, accounting, performance, and
security) model. Configuration management is a key function of this model.
Some of the problems that may arise due to lack of configuration management capabilities in an
organization include the following:
x The engineer who makes a configuration change is not available when the impact is realized.
For example, Impact of a change effected on Sunday, may not be noticed until the next
Tuesday by another engineer when, say, end of month processing causes high load.
x An approved change is implemented, but not in the manner that was agreed to when the
change was approved by the change approval committee. When this change later adversely
impacts on the business impact, the committee is held accountable, yet there exists no audit
trail, nor recourse.
x Security alerts indicate impacted devices and workarounds, but the manual effort takes
considerable time to determine the exposure, and the possible risk. A lot of time is therefore
expended to implement the required workaround and software upgrades.
x Configuration changes are made on the network, without management being aware.
[Link]
Page 6 of 16
Network Configuration Management
Why Is Configuration Management Important?
Some of the benefits of an effective configuration management system are:
x Reduced downtime through rapid change impact identification
x Productivity improvement for making configuration changes
x Helps ensure compliance for device configuration, software versions, and hardware
x Quick impact determination of security alerts
x Improved visibility and accountability at all levels
x Improved process and approval implementation
Best Practices for Configuration Management
The recommended best practices to avoid configuration management problems include:
x Maintain a master device list
x Maintain correct credentials and manageability at 100 percent
x Create relevance for users and management
x Achieve differentiated management; "not all devices are equal"
x Address people, processes, and technology, not just technology
x Develop processes to work for your company
x Commit resources; this is not a project, it is a system.
Failure to adhere to any of the above key factors has been known to cause configuration management
problems in the past.
[Link]
Page 7 of 16
Network Configuration Management
Network Documentation and Diagrams
Network documentation is a critical part of network configuration. It provides a static record of the state
of the network at a point in time. Static, because its useful life is limited up to until the first change is
made on any of the elements contained in the documentation.
Like network documentation, network diagrams are critical, but they are again a static record of the
desired state of the network and have no reflection of the current configured or operational state.
Documentation and diagrams form part of the network configuration in that they can provide information
when troubleshooting network outages;
An effective configuration management capability will provide up-to-date information on the configured
state of the network and will be updated dynamically as the network changes. When combined with
static documentation and diagrams, it provides more relevant information to support network
operations.
Managing Risk
A key issue with network management is the rapid increase in the number of network elements. As the
organization grows to capitalize on emerging opportunities, the network infrastructure must continually
change to support business growth –that is it must scale up communication services. This implies more
devices, software versions, and configuration combinations, and increased risk exposure. This requires
coordinated effort so that the risk can be understood and expediently mitigated as required.
[Link]
Page 8 of 16
Network Configuration Management
Time to Resolve
A key measure in many service levels is time taken from occurrence of an incident to resolution
Common causes of network outage include the following:
● Network medium failure (leased line, fiber cut, and so on)
● Physical infrastructure failure, power, air conditioning
● Hardware failure, power supply, chassis, or module, device failure
● Software failure, due to memory leak or bug
● Security exploit, causing Denial of service (DOS) or software failure
● A change in configuration, either logical (e.g. Introduction of a new feature) or physical (e.g.
installation of new hardware or connections)
In general, a network outage can be caused by a change in state or configuration of any of the network
components.
Configuration management assists reduce the time to resolution by providing the necessary information
to support troubleshooting and decision making. This is especially true of a configuration change.
If a network outage is caused by a configuration change, this needs to be eliminated as the root
cause early in the resolution effort.
Effectively applied, configuration management is a system that contributes to the overall availability of
the network.
[Link]
Page 9 of 16
Network Configuration Management
Developing Configuration Management Capabilities
Developing capabilities in configuration management requires a combination of:
● People
● Processes
● Technology
Configuration management as with most network management functions is not a isolated function, but
rather calls for integration of a number of components, that must corporate to achieve the overall
objective.
For instance, whereas technology is available as packaged products that incorporate many of the
required features, it must be combined with people and processes; else its utility is lost.
For example, the technology will produce the required reports, but unless the people read the reports,
determine any actions needed, then kick off the necessary processes to carry out the actions, the
reports are quite useless. This is one of the factors that contribute to many network management
systems often failing to deliver a suitable return on investment.
This section details how to develop configuration management capabilities by identifying the high level
requirements of configuration management, some of the policies that need to be developed, and some
of the necessary processes of which the configuration management functions will be part.
High-Level Requirements
The following is a list of requirements that define the essence of configuration management. These
requirements are not purely technical. They are both technical and functional requirements to support a
full configuration management solution.
The requirements for configuration management are:
● Collect network inventory, including chassis and modules as well as serial numbers
[Link]
Page 10 of 16
Network Configuration Management
● Report on collected network inventory
● Collect device configurations
● Keep multiple versions of device configurations
● Allow comparison between the multiple versions of device configurations
● Detect changes in device configurations (event or polling based)
● Determine which user made changes to device configurations
● Report on configuration changes
● Allow configuration changes to be batched and scheduled
● Report on existing software versions deployed on devices
● Keep a repository of device software versions
● Support upgrading of device software
● Audit configuration to help ensure compliance
● Search device configurations, software, and hardware
● Store or link to static documentation and diagrams
● Support the approval processes and workflows
Asset Management
If the configuration management system needs to support asset management, then the additional
requirements needed to support business accounting processes, such as depreciation, are:
● Purchase date
● Purchase price
● Asset number
● Purchasing details, company-specific information (purchase order number, vendor, and so on)
[Link]
Page 11 of 16
Network Configuration Management
Carrier Service Management
If the configuration management system needs to support carrier service management, then additional
requirements that support carrier service management and contract renewal are needed. Some of
these requirements are:
● Service number
● Carrier (Telecommunications Company)
● Contract start date
● Contract period
● Currency
● Cost per month
Federated Database
From the requirements, it is clear that a database is needed to store and manage the configuration
data. It may be difficult to find a single system that supports all of these requirements, so a federated
database model may need to be considered. This means that not all the data has to be in one
database, but if there is more than one database, the databases should be linked in some way.
Policies
There are a number of policies that need to be implemented within a configuration management
system. A policy in this context is a documented management decision on what and more possibly how
the system should work. The policy will determine how the configuration management system itself is
configured or set up.
[Link]
Page 12 of 16
Network Configuration Management
This list is by no means comprehensive but serves as a guide for what needs to be documented as part
of a company’s configuration management policy. The minimum management policies needed to build
a configuration management platform are:
● Length of time device configurations should be kept
● How many versions of device configurations should be kept
● Frequency of full configuration collection
● Frequency of configuration change polling
● Frequency of full inventory collection
● Frequency of inventory change polling
● Length of time inventory changes are kept
● Frequency of device configuration compliance checking
● Which configuration changes can be made automatically
Processes
Processes are important for a successful configuration management system. ITIL provides a good
framework for processes relevant to configuration management. There are more generic or general
processes that are needed for configuration management in a network.
Related ITIL Processes
The following are the directly related ITIL processes that network configuration management
supports:
● Configuration Management including the Configuration Management Data Base (CMDB)
● Change Management
● Incident Management
● Problem Management
[Link]
Page 13 of 16
Network Configuration Management
● Capacity Management
Configuration Management
Network configuration management is synonymous with ITIL Configuration Management, which defines
the important elements of configuration management a network needs.
Change Management
Without effective configuration management, change management is somewhat pointless. Currently
many organizations implement change management on a trust basis with no real means to audit
approved changes against actual configuration changes.
Change management calls for IT to coordinate its efforts with the business group to help ensure that
the business impact is minimized or avoided.
Incident Management
As discussed in the section “Time to Resolve,” configuration management is important for incident
management. It provides up-to-date information about the network.
Capacity Management
This is specifically related to the physical capacity of the network. Inventory data provides information
about the spare capacity for interfaces, ports, modules, slots, and so on.
Configuration Change Auditing
This process aims at ensuring that accountability is enforced with network changes. The two main
aspects of this process are:
● Support the change management and have in place mechanism to ensure that any changes on the
network go through an approval process, and those that have been approved are implemented as
described
[Link]
Page 14 of 16
Network Configuration Management
● Audit configuration changes and make sure they are any effected changes were subject to the
approval process.
Vulnerability Management
A process that scans for vulnerabilities in network components and determines which ones pose serius
risk, and possible impacts to the business.
For devices that are vulnerable, we need to determine if a software upgrade is necessary or if a
configuration workaround is sufficient to mitigate the risk.
End of Life Management
Audit the collected inventory for devices that may be out of depreciation or at the end of support by the
vendor or maintenance provider. Determine what the potential risk is and, when necessary, instigate
projects to upgrade equipment.
Maintenance
Use the collected inventory information to audit against vendor or partner maintenance and determine
that maintenance agreements are correct and that maintenance is not being paid on devices that are
no longer in production.
Testing, Change, Configuration, and Release Management
To effectively manage a large network, testing is crucial. Without testing and verification of changes,
especially for large changes, business impact should be expected. The tests are conducted in a test lab
The principles are simple and are considered as best practices by the industry. The test lab should
include a representative small scale topology of the network derived from the main network, and
changes to the configuration or software should be tested in this test lab.
[Link]
Page 15 of 16
Network Configuration Management
As part of the project to deploy the new network, a test plan should be developed. This test plan should
be made of unit tests, regression tests, and acceptance tests. After deployment, these tests will be
repeated as part of the release management process.
[Link]
Page 16 of 16
Network Configuration Management
R ev i ew Qu es t i on s
1. What is configuration management, and why is it necessary?
2. What are some of the operational issues that could result from lack of configuration management
capabilities in an organization?
3. Identify the key factors that are known to have caused configuration problems in the past.
4. You have been contracted as a consultant by Maseno University to develop configuration management
capabilities at its ICT directorate. Explain how you would go about formulating one.