0% found this document useful (0 votes)
26 views17 pages

Designing Effective Remote Connectivity

Chapter Four discusses the design of remote connectivity and WANs, emphasizing the importance of balancing security, usability, performance, scalability, and manageability. It outlines key components such as VPNs, WAN technologies, and considerations for enterprise edge design, including hardware and software selection. The chapter also highlights the need for effective planning to meet organizational requirements and optimize network performance.

Uploaded by

markosmerhun55
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
26 views17 pages

Designing Effective Remote Connectivity

Chapter Four discusses the design of remote connectivity and WANs, emphasizing the importance of balancing security, usability, performance, scalability, and manageability. It outlines key components such as VPNs, WAN technologies, and considerations for enterprise edge design, including hardware and software selection. The chapter also highlights the need for effective planning to meet organizational requirements and optimize network performance.

Uploaded by

markosmerhun55
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Chapter Four

Network Design

1
Chapter Four Outlines!
 Designing Remote Connectivity
Enterprise Edge WAN Technologies
WAN Design and Using WAN Technologies
Enterprise Edge WAN and MAN Architecture
Selecting Enterprise Edge Components
Enterprise Teleworker Design

2
Designing Remote Connectivity
Designing effective remote connectivity requires a strategic approach
balancing security, usability, performance, scalability, and manageability.
This allows remote users to access resources, data, and services as if they
were physically present in the same location.
Here are some steps to consider when designing remote connectivity:
Assess Requirements: Consider factors such as the number of remote users,
the type of applications and services they need to access, and the level of
security required.
Identify Requirements: Before you start designing your network
architecture, you need to identify your requirements and goals.
For example, you need to know how many users and devices will access your
network remotely, what kind of applications and data they will use, what level
of security and encryption you need, and what budget and resources you have.
3
Designing Remote Connectivity…
What is VPN?
A VPN (Virtual Private Network) is a service that creates a secure, encrypted
connection between your device (like a computer, phone, or tablet) and the internet.
Think of it as a private tunnel through the public internet.
Basic functions of VPN:
Encryption: When you connect to a VPN, all the data traveling between your
device and the VPN server is scrambled (encrypted).
IP Address Masking: Your IP address is a unique number that identifies your device
and your approximate physical location on the internet.
A VPN hides your real IP address and replaces it with the IP address of the VPN
server you're connected to.
Bypassing Geo-Restrictions: Access content that is blocked or restricted in your
physical locations .
Secure Remote Work: Allows employees to securely connect to their company's
4
internal network and resources.
Designing Remote Connectivity…
Choose a VPN protocol: A VPN protocol is a set of rules and standards that
define how your remote devices communicate with your network over the
internet.
Here are some basic types of VPN:
Open VPN is a popular and secure open-source protocol that uses SSL/TLS
encryption and supports various authentication methods.
IPsec (Internet Protocol Security) is a suite of protocols designed to secure
communications over IP networks (like the internet).
It operates at the network layer (Layer 3) of the OSI model, providing
confidentiality, integrity, authentication, and Availability for IP packets.
IPsec is not a single protocol. 5
Designing Remote Connectivity…
Remote Access VPN (Client-to-Site) Connects individual users/devices
(clients) securely to a central corporate network over the internet
Site-to-Site VPN (Gateway-to-Gateway or Router-to-Router)
Securely connects entire networks (e.g., branch offices, data centers) to each
other over the internet.
L2TP (Layer 2 Tunneling Protocol) is a protocol used to establish
virtual private networks (VPNs) or provide remote access to private
networks.

It is commonly used in combination with IPsec (IP Security) for


secure communication.
6
VPN Applications
VPNs can be grouped according to their applications:
Access VPN: Access VPNs provide access to a corporate intranet (or extranet) over
a shared infrastructure and have the same policies as a private network
Intranet VPN: Intranet VPNs link remote offices by extending the corporate
network across a shared infrastructure.
Extranet VPN: Extranet VPNs extend the connectivity to business partners,
suppliers, and customers across the Internet or an SP’s network.
Benefits of VPNs
The benefits of using VPNs include the following:
Flexibility: VPNs offer flexibility because site-to-site and remote-access
connections can be set up quickly and over existing infrastructure to extend the
network to remote users.
Scalability: VPNs allow an organization to leverage and extend the classic WAN to
more remote and external users.
Lower network communication cost: Lower cost is a primary reason for migrating
from traditional connectivity options to a VPN connection.
7
Introduction to WANs
 A WAN is a data communications network that covers a relatively broad
geographic area.
A WAN typically uses the transmission facilities provided by service
providers (SP) (also called carriers), such as telephone companies.
Designing a WAN is a challenging task.
The first design step is to understand the WAN’s networking requirements,
which are driven by two primary goals:
Service level agreement (SLA): Organizations need to define the level of
service, such as bandwidth, allowed latency, packet loss, and so forth, that is
acceptable for the applications running across the WAN.
Cost of investment and usage: WAN designs are always subject to budget
limitations.
Selecting the right type of WAN technology is critical to providing reliable
services for end-user applications in a cost-effective and efficient 8
Introduction to WANs…
Objectives of an effective WAN design:

An effective Wide Area Network (WAN) design aims to connect


geographically distributed sites (e.g., branch offices, data centers, cloud
resources) while optimizing performance, security, cost, and scalability.

A well-designed WAN must reflect the goals, characteristics, and policies of


an organization.

The selected WAN technology should be sufficient for current and, to some
extent, future application requirements.

The associated costs of investment and usage should stay within the budget
limits. 9
Traditional WAN technologies
Traditional WAN technologies include the following:
Leased lines: Leased lines are a point-to-point connections that are
permanently reserved for data transmission, providing a dedicated and
continuous link between two locations.
The dedicated nature of leased lines means that they are always on.
The carrier establishes the connection by dedicating a physical wire.
Circuit-switched networks: are a type of telecommunications network that
establish a dedicated communication path, or circuit, between two parties for
the duration of a communication session.
In a circuit-switched network, a connection is established before data
transmission can occur, and the connection remains active until it is
terminated.
Circuit-switched networks were widely used in traditional telephone systems,
where a dedicated circuit was established for each individual call. 10
Traditional WAN technologies…
Packet-Switched Networks: Packet-switched networks break data into
small packets and transmit them independently over a shared network
infrastructure.
Each packet contains a portion of the data, along with information such as the
source and destination addresses.
These packets can take different routes through the network and may arrive
at the destination out of order.
However, the destination device reassembles the packets into the original data
stream based on their sequence number.

11
WAN Design
Step 1:Analyzing customer requirements
Step 2: Characterizing the existing network and sites
Step 3: Designing the network topology and solutions
Application Requirements of WAN Design
Response Time: Response time is the time between a user request (such as the entry
of a command or keystroke) and the host system’s command execution or response
delivery.
Throughput: In data transmission, throughput is the amount of data moved
successfully from one place to another in a given time period.
Packet Loss: In telecommunication transmission, packet loss is expressed as a bit
error rate (BER), which is the percentage of bits that have errors, relative to the total
number of bits received in a transmission.
Reliability: reliability is the measure of a network's ability to consistently and
predictably perform its intended function without failure or interruption over a
specified period. 12
Enterprise Edge WAN and MAN Considerations
When designing the Wide Area Network (WAN) and Metropolitan Area
Network (MAN) for the enterprise edge, there are several considerations to
keep in mind.
These considerations help ensure the network is reliable, secure, scalable, and
able to meet the organization's requirements and consider the following
factors:
Support for network growth
Appropriate availability
Operational expenses
Operational complexity
Voice and video support
Network segmentation support
13
Selecting Enterprise Edge Components
Selecting Enterprise Edge Components: After identifying the remote
connectivity requirements and architecture, you are ready to select the
individual WAN components.
Hardware Selection: When selecting hardware, use the vendor
documentation to evaluate the WAN hardware components.
The selection process typically considers the function and features of the
particular devices, including their port densities, packet throughput,
expandability capabilities, and readiness to provide redundant connections.
Software Selection: The next step is to select the appropriate software
features.

14
Selecting Enterprise Edge Components…
Enterprise Branch Design
Requirements differ with the size of the branch offices. Consider to the following
questions when designing the Enterprise Branch:
How many branch locations need to be supported?
How many existing devices are to be supported at each location?
How much growth is expected at each location, and therefore what level of
scalability is required?
What are the high availability requirements at each location?
What level of security is required in the design?
Are there any requirements for local server farms or networks between the internal
network and the external network (for example, in a demilitarized zone [DMZ])?
What wireless services are needed, and how will they be used by the clients?
What is the approximate budget available? 15
Enterprise Teleworker Design
Organizations are constantly striving to reduce costs, improve employee
productivity, and retain valued employees.
These goals can be furthered by allowing employees to work from home with
quality, function, performance, convenience, and security similar to that
available in the office.

16
17

You might also like