0% found this document useful (0 votes)
4 views62 pages

Chapter 2

Chapter 2 focuses on structuring and modularizing enterprise networks using a hierarchical model consisting of access, distribution, and core layers. It emphasizes the importance of modular design for flexibility, capacity planning, and cost minimization, while detailing the roles and functionalities of each layer. The chapter also introduces the Cisco SONA framework and various enterprise architectures, highlighting guidelines for creating an efficient enterprise network.

Uploaded by

Suvarna Bhoir
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
4 views62 pages

Chapter 2

Chapter 2 focuses on structuring and modularizing enterprise networks using a hierarchical model consisting of access, distribution, and core layers. It emphasizes the importance of modular design for flexibility, capacity planning, and cost minimization, while detailing the roles and functionalities of each layer. The chapter also introduces the Cisco SONA framework and various enterprise architectures, highlighting guidelines for creating an efficient enterprise network.

Uploaded by

Suvarna Bhoir
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Chapter 2

Structuring and Modularising


the Network
Objectives
• To understand network hierarchy.

• To apply modular hierarchical approach for network design.

• To understand modular network services.

• To apply network management protocols and features.


Background
• Enterprise wide network design is equivalent to the development of
software for an enterprise.
• Enterprise network supports the business processes of an enterprise
in similar way as the software developed for an enterprise does.
• Software development methodologies promote the idea of modular
design of software.
• On similar lines, we need to use a modular approach to design the
network for an enterprise.
Network Hierarchy
• Network Hierarchy explains the hierarchical network model, which is
composed of the access, distribution, and core layers.
Hierarchical Network Model
• The hierarchical network model provides a framework that network
designers can use to help ensure that the network is flexible and easy
to implement and troubleshoot.
The hierarchical network design model consists of three layers:
•The access layer provides local and remote workgroup or user
access to the network.
•The distribution layer provides policy-based connectivity.
•The core (or backbone) layer provides high-speed transport to
satisfy the connectivity and transport needs of the distribution
layer devices.
Simple Network using Hierarchical Network Design
• Each hierarchical layer focuses on
specific functions, thereby allowing
the network designer to choose the
right systems and features based
on their function within the model.
• This approach helps provide more
accurate capacity planning and
minimize total costs.
• Figure aside illustrates a sample
network showing the mapping to the
hierarchical model's three layers.
The Role of the Access Layer

• The access layer is the concentration point at which clients access the
network.
• Access layer devices control traffic by localizing service requests to
the access media.
• The purpose of the access layer is to grant user access to network
resources.
The access layer's characteristics
• In the LAN environment, the access layer typically incorporates switched
LAN devices with ports that provide connectivity for workstations and
servers.
• In the WAN environment, the access layer for teleworkers or remote sites
provides access to the corporate network across some wide-area
technology, such as Frame Relay, Multiprotocol Label Switching (MPLS),
Integrated Services Digital Network, leased lines, Digital Subscriber Line
(DSL) over traditional telephone copper lines, or coaxial cable.
• So as not to compromise network integrity, access is granted only to
authenticated users or devices (such as those with physical address or
logical name authentication).
• Access can be provided to end users as part of either a Layer 2 (L2)
switching environment or a multilayer switching environment.
Using Layer 2 Switching in the Access Layer
• Access to local workstations and servers can be provided using shared or
switched media LANs.
• VLANs may be used to segment the switched LANs.
• Each LAN or VLAN is a single broadcast domain.
• The access layer aggregates end-user switched 10/100/1000 ports.
• It provides Fast Ethernet, Fast EtherChannel, and Gigabit Ethernet uplinks to the
distribution layer to satisfy connectivity requirements and reduce the size of the
broadcast domains.
• A recommended best practice is to implement one VLAN—thus supporting one IP
subnet—per access switch and to connect the access switches to the distribution
switches with Layer 3 links rather than with trunks.
• Using the Rapid Spanning Tree Protocol (RSTP) which provides faster spanning-
tree convergence after a topology change.
Using Multilayer Switching in the Access Layer
• The most common design for remote users is to use multilayer
switches or routers.
• A multilayer switch, or router, is the boundary for broadcast domains.
• It is necessary for communicating between broadcast domains
(including VLANs).
• Access routers provide services such as route propagation, packet
filtering, authentication, security, Quality of Service (QoS), and so on.
• These technologies allow the network to be optimized to satisfy a
particular user's needs.
Access Layer Example

• Figure above illustrates a sample network in which the campus access layer aggregates
end users and provides uplinks to the distribution layer.
• The access layer switches are dual-attached to the distribution layer switches for high
availability.
Distribution Layer Functionality
• The distribution layer represents both a separation between the
access and core layers.
• It serves as a connection point between the diverse access sites and
the core layer.
• The distribution layer determines department or workgroup access
and provides policy-based connectivity.
• The distribution layer connects network services to the access layer
and implements policies for QoS, security, traffic loading, and routing.
Policy-Based Connectivity
• Policy-based connectivity means implementing the policies of the
organization.
Methods for implementing policies include the following:
• Filtering by source or destination address
• Filtering based on input or output ports
• Providing specific static routes rather than using routes from a
dynamic routing protocol
• Security (for example, certain packets might not be allowed into a
specific part of the network)
• QoS mechanisms
Distribution Layer Example
Following are the characteristics of the distribution layer in
the routed campus network shown in Figure aside:
•Multilayer switching is used toward the access layer
•Multilayer switching is performed in the distribution layer
and extended toward the core layer.
•The distribution layer performs two-way route
redistribution to exchange the routes between the Routing
Information Protocol version 2 (RIPv2) and Enhanced
Interior Gateway Routing Protocol (EIGRP) routing
processes.
•Route filtering is configured on the interfaces toward the
access layer.
•Route summarization is configured on the interfaces
toward the core layer.
•The distribution layer contains highly redundant
connectivity, both toward the access layer and toward the
core layer.
Core Layer Functionality
• The core layer is a high-speed backbone designed to switch packets as
quickly as possible to optimize communication transport within the
network.
• Provide a high level of availability and reliability.
• The core must be able to accommodate failures by rerouting traffic and
responding quickly to changes in network topology.
• The core layer should not perform any packet manipulation, such as
checking access lists or filtering, which would slow down the switching of
packets.
• The core layer must be manageable.
• The core devices must be able to implement scalable protocols and
technologies, and provide alternative paths and load balancing.
Switching in the Core Layer
In figure aside, a typical packet between access sites
follows these steps:
•Step 1 The packet is Layer 2–switched toward a
distribution switch.
•Step 2 The distribution switch performs multilayer
switching toward a core interface.
•Step 3 The packet is Layer 2–switched across the LAN
core.
•Step 4 The receiving distribution switch performs
multilayer switching toward an access layer LAN.
•Step 5 The packet is Layer 2–switched across the
access layer LAN to the destination host.
CISCO SONA FRAMEWORK
The SONA framework illustrates the concept that
the network is the common element that connects
and enables all components of the IT
infrastructure.
The network infrastructure layer:
• This layer is where all the IT resources are
interconnected across a converged network
foundation.
• The IT resources include servers, storage, and
clients.
• The network infrastructure layer represents how
these resources exist in different places in the
network, including the campus, branch, data
center, WAN, metropolitan-area network (MAN),
and teleworker.
The interactive services layer: This layer enables The application layer:
efficient allocation of resources to applications and • This includes business applications and collaboration
business processes delivered through the networked applications.
infrastructure. • The objective for customers in this layer is to meet business
requirements and achieve efficiencies by leveraging the
interactive services layer.
Benefits of Cisco SONA

• Functionality: Supports the organizational requirements.


• Scalability: Supports growth and expansion of organizational tasks by
separating functions and products into layers. This separation makes it
easier to grow the network.
• Availability: Provides necessary services reliably anywhere, anytime.
• Performance: Provides desired responsiveness, throughput, and utilization
on a per-application basis through the network infrastructure and services.
• Manageability: Provides control, performance monitoring, and fault
detection.
• Efficiency: Through step-by-step network services growth, SONA provides
network services and infrastructure with reasonable operational costs and
appropriate capital investment.
Functional Areas of Cisco Enterprise
Architecture
CISCO Enterprise Campus Architecture
This architecture provides high availability, redundant hardware and software
features, automatic procedures for re-configuring network paths at failures; IP
multicast capabilities like optimized bandwidth consumption, QoS & Integrated security.
The different modules are,
• Enterprise Campus Infrastructure : The enterprise campus module is separated out into
a number of different layers that include the different parts of the network.
• Campus Core: The core focuses on the fast transport of network traffic, intelligent
switching and routing; must be able to adapt to network changes quickly.
• Building Distribution :The building distribution aggregates the traffic from the access
layer and provides routing and packet manipulation. This is also the location within the
network where policies for QoS, security and traffic loading are implemented.
• Building Access : The building access is responsible for the connectivity of end devices on
the network.
CISCO Enterprise Edge Architecture
• The enterprise edge functional area is responsible for the aggregation of several different off-
campus elements as well as the routing of this traffic into the campus core module.
• It offers connectivity to voice, video and data services outside the enterprise; enables enterprise
to use Internet and partner resources; also provides resources for its customers.
The different modules include:
• E-Commerce : It is responsible for the processing of all electronic transactions. All of the network
elements involved with forwarding and processing these transactions are included within this
module, such as web, application and database servers, firewalls, and network intrusion
detection and prevention systems.
• Internet Connectivity : It is responsible for all other public connectivity not covered within the e-
commerce module. The different network elements in this module include web, DNS, and FTP
servers, firewalls, network intrusion detection and prevention systems and edge routers.
• Remote Access and VPN : It is responsible for initiating and terminating remote access
connections. The different network elements here include Cisco ASA security appliances,
firewalls, network intrusion detection and prevention systems and dial-in concentrators.
• WAN and MAN and Site-to-Site VPN : It is responsible for the routing of traffic from remote sites
back into the central campus location. This includes the use of technologies such as leased lines,
frame relay, ATM, SONET and MPLS, as well as site-to-site VPN technologies.
Service Provider
• The service provider functional area is responsible for connectivity into
Service Provider networks. This includes a number of different
connectivity options, from Internet access through Public Switched
Telephone Network (PSTN) access.
The different modules are,
• ISP : It is responsible for connecting the networking to the Internet; this
includes access for Enterprise remote locations.
• Public Switched Telephone Network (PSTN) : It is responsible for
connecting network elements using analog, ISDN, and wireless
technologies (cellular).
• Frame Relay and ATM Module : The Frame Relay and ATM module is used
to connect remote locations using DSL.
CISCO Enterprise Branch Architecture
• Extend head-office applications and services to thousands of remote locations and
users or to a small group of branches.
• Integrates security, switching, network analysis, caching, and converged
voice and video services into a series of integrated services routers (ISR) in the
branch.
• Provides secure access to voice, mission-critical data, and video applications –
anywhere, anytime.
• Advanced routing, VPNs, redundant WAN links, application content
caching, and local IP telephony call processing features are available.
• Reduce traffic and save bandwidth and operational expenses.
• Support branch offices with the capability to centrally configure,
monitor, and manage devices located at remote sites.
CISCO Enterprise Data Centre Architecture
• This module can be located either at the campus as a server farm or
at a remote facility.
• This architecture allows the enterprise to scale without major
changes to the infrastructure.
• The network and devices offer server and application load
balancing to maximize performance.
• Provide backup using synchronous and asynchronous data
and application replication.
• It enables emerging service-oriented architectures, virtualization,
and on-demand computing.
CISCO Enterprise Teleworker Architecture
• It provides highly secure access to central-site applications and network
services for workers.
• It allows enterprises to securely deliver voice and data services over a
standard broadband access service.
• This provides a business-resiliency solution for the enterprise and
a flexible work environment for employees.
• Its centralized management minimizes the IT support costs.
• Implements robust integrated security & identity-based networking.
Guidelines for Creating an Enterprise Network
• When creating an Enterprise network,
1. divide the network into appropriate areas, where the Enterprise
Campus includes all devices and connections within the main
Campus location;
2. the Enterprise Edge covers all communications with remote
locations and the Internet from the perspective of the Enterprise
Campus; and
3. the remote modules include the remote branches, teleworkers, and
the remote data center.
4. Define clear boundaries between each of the areas.
Enterprise Campus Modules
• The Campus Infrastructure design consists of several
buildings connected across a Campus Core.
• The Campus Infrastructure module connects devices
within a campus to the Server Farm and Enterprise Edge
modules.
• A single building in a Campus Infrastructure design
contains a Building Access layer and a Building
Distribution layer.
• When more buildings are added to the Campus
Infrastructure, a backbone or Campus Core layer is added
between buildings.
• The Campus Infrastructure module includes three layers:
■ The Building Access layer
■ The Building Distribution layer
■ The Campus Core layer
Building Access Layer
The Building Access layer, located within a campus building, aggregates end users from different workgroups and
provides uplinks to the Building Distribution layer.
It contains end-user devices such as workstations, Cisco IP phones, and networked printers, connected to Layer 2
access switches.

Building Distribution Layer


The Building Distribution layer aggregates the wiring closets within a building and provides connectivity to the
Campus Core layer.
It provides aggregation of the access layer networks using multilayer switching. The Building Distribution layer
performs routing, QoS, and access control.
Campus Core Layer
The Campus Core layer is the core layer of the Campus Infrastructure module. Within the Enterprise Campus
functional area, it connects the buildings and various parts of the campus.
Specifically, this layer interconnects the Building Distribution layer with the Server Farm and the Enterprise Edge
modules.
Server Farm Module
A high-capacity, centralized server farm module provides users with internal server resources.
In addition, it typically supports network management services for the enterprise, including monitoring, logging,
and troubleshooting, and other common management features from end to end.
The Server Farm module typically contains internal e-mail and other corporate servers that provide internal
users with application, file, print, e-mail, and Domain Name System (DNS) services.
Enterprise Campus Guidelines
Step 1. Select modules within the campus that act as buildings with access and distribution
layers.
Step 2. Determine the locations and the number of access switches and their uplinks to
distribution layer switches.
Step 3. Select the appropriate distribution layer switches, taking into account the number of
access layer switches and end users. Use at least two distribution layer switches for
redundancy.
Step 4. Consider two uplink connections from each access layer switch to the two distribution
layer switches.
Step 5. Determine where servers are or will be located, and design the Server Farm module
with at least two distribution layer switches that connect all servers for full redundancy.
Step 6. Design the Campus Infrastructure module's Campus Core layer using at least two
switches and provide for the expected traffic volume between modules.
Step 7. Interconnect all modules of the Enterprise Campus with the Campus Infrastructure
module's Campus Core layer in a redundant manner.
Enterprise Edge Modules
• The Enterprise Edge infrastructure
modules aggregate the
connectivity from the various
elements outside the campus—
using various services and WAN
technologies as needed, typically
provisioned from service
providers—and route the traffic
into the Campus Core layer.
• The Enterprise Edge modules
perform security functions when
enterprise resources connect
across public networks and the
Internet.
E-commerce Module
• The E-commerce module enables enterprises to successfully deploy e-
commerce applications and take advantage of the opportunities the
Internet provides. To build a successful e-commerce solution, the following
network devices might be included:
• Web servers: Act as the primary user interface for e-commerce navigation
• Application servers: Host the various applications
• Database servers: Contain the application and transaction information that
is the heart of the e-commerce business implementation
• Firewalls or firewall routers: Govern communication and provide security
between the system's various users
• Network Intrusion Detection System/Network Intrusion Protection System
(NIDS/ NIPS) appliances: Monitor key network segments in the module to
detect and respond to attacks against the network
Internet Connectivity Module
• The Internet Connectivity module provides internal users with connectivity to Internet
services, such as HTTP, FTP, Simple Mail Transfer Protocol (SMTP), and DNS.
• Major components used in the Internet Connectivity module include the following:
SMTP mail servers: Act as a relay between the Internet and the intranet mail servers.
DNS servers: Serve as the authoritative external DNS server for the enterprise and relay
internal DNS requests to the Internet.
Public servers (for example, FTP and HTTP): Provide public information about the
organization. Each server on the public services segment contains host-based intrusion
detection systems (HIDS) to monitor against any rogue activity at the operating system
level and in common server applications including HTTP, FTP, and SMTP.
Firewalls or firewall routers: Provide network-level protection of resources, provide stateful
filtering of traffic, and forward VPN traffic from remote sites and users for termination.
Edge routers: Provide basic filtering and multilayer connectivity to the Internet.
Remote Access and VPN Module

• The Remote Access and VPN module terminates remote access traffic and VPN
traffic that the Internet Connectivity Module forwards from remote users and
remote sites.
• Major components used in the Remote Access and VPN module include the
following:
Dial-in access concentrators: Terminate dial-in connections and authenticate
individual users
Cisco Adaptive Security Appliances (ASA): Terminate IPsec tunnels, authenticate
individual remote users, and provide firewall and intrusion prevention services
Firewalls: Provide network-level protection of resources and statefull filtering of
traffic, provide differentiated security for remote access users, authenticate trusted
remote sites, and provide connectivity using IPsec tunnels
NIDS appliances: Provide Layer 4 to Layer 7 monitoring of key network segments in
the module
WAN and MAN and Site-to-Site VPN Module
• The WAN and MAN and Site-to-Site VPN module uses various WAN
technologies like Frame Relay, ATM, DSL.
• This module incorporates all Cisco devices that support these WAN
technologies, and routing, access control, and QoS mechanisms.
Enterprise Edge Guidelines
Step 1 Create the E-commerce module (for business-to-business or
business-to-customer scenarios) that require Internet access. Deploy a
high-security policy that allows customers to access predefined servers
and services.
Step 2 Determine the connections from the corporate network into the
Internet, and assign them to the Internet Connectivity module.
Step 3 Design the Remote Access and VPN module if the enterprise
requires VPN connections or dial-in for accessing the internal network
from the outside world.
Step 4 Determine which part of the edge is used exclusively for
permanent connections to remote locations (such as branch offices),
and assign it to the WAN and MAN and Site-to-Site VPN module. All
WAN devices supporting Frame Relay, ATM, cable, MPLS, leased lines,
SONET/SDH, and so on, are located here.
Service Provider Modules
• They are necessary to enable communication with
other networks, using a variety of WAN technologies,
and with Internet service providers (ISP).
• ISP module represents enterprise IP connectivity to an
ISP network.
• PSTN module represents all nonpermanent WAN
connection.
• Frame Relay / ATM module covers all WAN technologies
for permanent connectivity with remote locations.
Enterprise Branch Module
• Extends an enterprise to a remote location.
• Provides resilient network architecture.
• Provides mobility and security.
• Able to connect to the central site to access company information.
• Uses a simplified version of the Campus Infrastructure module design.
• Benefit from high-speed Internet access, VPN connectivity to
corporate intranets, telecommuting capabilities for work-at-home
employees, videoconferencing.
Enterprise Data Center Module

• Enhances the application, server, and storage solutions.


• Equips organizations to manage increased security, cost, and regulatory
requirements.
• The Enterprise Data Center module may include the following components:
At the networked infrastructure layer: Gigabit Ethernet, 10-Gigabit Ethernet,
with storage switching and optical transport devices
At the interactive services layer: Services include storage fabric services,
computer services, security services, and application optimization services
At the management layer: Tools include Fabric Manager (for element and
network management) and Cisco VFrame (for server and service
provisioning)
Enterprise Teleworker Module

• Teleworker means people working from home, hotels, or any random


place.
• It includes people working on mobile while travelling or otherwise.
• It provides secure access to enterprise network applications and
resources.
Services Within Modular Networks

• Create an enterprise-wide networked infrastructure and interactive


services to serve as a solid foundation for business and collaborative
applications.
• A network service is a supporting and necessary service, but not an
ultimate solution. For example, security and QoS are not ultimate
goals for a network; they are necessary to enable other services and
applications and are therefore classified as network services.
However, IP telephony might be an ultimate goal of a network and is
therefore a network application (or solution), rather than a service.
Interactive Services

• Since the inception of packet-based communications, networks have


always offered a forwarding service. Forwarding is the fundamental
activity within an internetwork.
• With advances in networking software and hardware, the network
can offer an increasingly rich, intelligent set of mechanisms for
forwarding information.
• Interactive services add intelligence to the network infrastructure.
• The SONA interactive services layer includes both application
networking services and infrastructure services.
• Security services: Ensure that all aspects of the network are secure,
from devices connecting to the network to secured transport to data
theft prevention
• Mobility services: Allow users to access network resources regardless
of their physical location
• Storage services: Provide distributed and virtual storage across the
infrastructure
• Voice and collaboration services: Deliver the foundation by which
voice can be carried across the network, such as security and high
availability
• Compute services: Connect and virtualize compute resources based
on the application
• Identity services: Map resources and policies to the user and device
Security Services in a Modular Network Design

• Security is an infrastructure service that increases the network's


integrity by protecting network resources and users from internal and
external threats.
• Security both in the Enterprise Campus (internal security) and at the
Enterprise Edge (from external threats) is important. An enterprise
should include several layers of protection so that a breach at one
layer or in one network module does not mean that other layers or
modules are also compromised.
Internal Security

• If the security established at the Enterprise Edge fails, an unprotected


Enterprise Campus is vulnerable. Deploying several layers of security
increases the protection of the Enterprise Campus, where the most
strategic assets usually reside.
• Relying on physical security is not enough. For example, as a visitor to
the organization, a potential attacker could gain physical access to
devices in the Enterprise Campus.
• Often external access does not stop at the Enterprise Edge; some
applications require at least indirect access to the Enterprise Campus
resources. Strong security must protect access to these resources.
• At the Building Access layer, access is controlled at the port level using the data
link layer information. Some examples are filtering based on media access control
addresses and IEEE 802.1X port authentication.
• The Building Distribution layer performs filtering to keep unnecessary traffic from
the Campus Core. This packet filtering can be considered a security function
because it does prevent some undesired access to other modules.
• The Campus Core layer is a high-speed switching backbone and should be
designed to switch packets as quickly as possible; it should not perform any
security functions, because doing so would slow down the switching of packets.
• The Server Farm module's primary goal is to provide application services to end
users and devices. Enterprises often overlook the Server Farm module from a
security perspective. Given the high degree of access that most employees have
to these servers, they often become the primary goal of internally originated
attacks. Simply relying on effective passwords does not provide a comprehensive
attack mitigation strategy. Using host-based and network-based IPSs and IDSs,
private VLANs, and access control provides a much more comprehensive attack
response. For example, onboard IDS within the Server Farm's multilayer switches
inspects traffic flows.
External Security
• When designing security in an enterprise network, the Enterprise Edge is
the first line of defense at which potential outside attacks can be stopped.
• The Enterprise Edge is like a wall with small doors and strong guards that
efficiently control any access.
• The following four attack methods are commonly used in attempts to
compromise the integrity of the enterprise network from the outside:
1. IP Spoofing
2. Password Attacks
3. DoS Attacks
4. Application Layer Attacks
IP spoofing:
• An IP spoofing attack occurs when a hacker uses a trusted computer to launch an
attack from inside or outside the network.
• The hacker uses either an IP address that is in the range of a network's trusted IP
addresses or a trusted external IP address that provides access to specified
resources on the network.
• IP spoofing attacks often lead to other types of attacks.
• For example, a hacker might launch a denial of service (DoS) attack using spoofed
source addresses to hide his identity.
Password attacks:
• Using a packet sniffer to determine usernames and passwords is a simple
password attack; however, the term password attack usually refers to repeated
brute-force attempts to identify username and password information.
• Trojan horse programs are another method that can be used to determine this
information.
• A hacker might also use IP spoofing as a first step in a system attack by violating a
trust relationship based on source IP addresses.
• First, however, the system would have to be configured to bypass password
authentication so that only a username is required.
• DoS attacks: DoS attacks focus on making a service unavailable for
normal use and are typically accomplished by exhausting some
resource limitation on the network or within an operating system or
application.
• Application layer attacks: Application layer attacks typically exploit
well-known weaknesses in common software programs to gain access
to a computer.
Network Management Protocols and Features
• Proper network management is a critical component of an efficient
network.
• Network administrators need tools to monitor the functionality of the
network devices, the connections between them, and the services
they provide.
• SNMP has become the de facto standard for use in network
management solutions and is tightly connected with remote
monitoring (RMON) and Management Information Bases (MIB).
• Each managed device in the network has several variables that
quantify the state of the device.
• You can monitor managed devices by reading the values of these
variables, and you can control managed devices by writing values into
these variables.
Network Management Architecture
The network management architecture consists of the
following:
•Network management system (NMS): A system that
executes applications that monitor and control managed
devices. NMSs provide the bulk of the processing and
memory resources that are required for network management.
•Network management protocol: A protocol that facilitates
the exchange of management information between the NMS
and managed devices, including SNMP, MIB, and RMON.
•Managed devices: A device (such as a router) managed by
an NMS.
•Management agents: Software, on managed devices, that
collects and stores management information, including SNMP
agents and RMON agents.
•Management information: Data that is of interest to a
device's management, usually stored in MIBs.
Simple Network Management Protocol (SNMP)
• SNMP is the simplest network management protocol. (v1, v2, v3)
• SNMP defines how management information is exchanged between network
management applications and management agents.
Manager: The manager, a network management application in an NMS,
periodically polls the SNMP agents that reside on managed devices for
the data, thereby enabling information to be displayed using a GUI on the
NMS.
Protocol: SNMP is a protocol for message exchange. It uses the User Datagram
Protocol (UDP) transport mechanism to send and retrieve management
information, such as MIB variables.
Managed device: A device (such as a router) managed by the manager.
Management agents: SNMP management agents reside on managed devices to
collect and store a range of information about the device and its operation,
respond to the manager's requests, and generate traps to inform the manager
about certain events.
MIB: The management agent collects data and stores it locally in the MIB, a
database of objects about the device. Community strings, which are similar to
passwords, control access to the MIB. To access or set MIB variables, the user
must specify the appropriate read or write community string; otherwise, access
is denied.
SNMP Messages
•Get Request: Used by the manager to request a specific
MIB variable from the agent.
•Get Next Request: Used after the initial get request to
retrieve the next object instance from a table or list.
•Set Request: Used to set a MIB variable on an agent.
•Get Response: Used by an agent to respond to a
manager's Get Request or Get Next Request message.
•Trap: Used by an agent to transmit an unsolicited alarm
to the manager. A Trap message is sent when specific
conditions occur, such as a change in the state of a
device, a device or component failure, or an agent
initialization or restart.
•GetBulk message type: Used for retrieving large amounts of data, such as
tables. This message reduces repetitive requests and replies, thereby
improving performance.
•InformRequest: Used to alert the SNMP manager of a specific condition.
Unlike unacknowledged trap messages, InformRequest messages are
acknowledged. A managed device sends an InformRequest to the NMS; the
NMS acknowledges the receipt of the message by sending a Response
message back to the managed device.
SNMP Security Levels
• NoAuthNoPriv: Without authentication and without privacy
(encryption).
• AuthNoPriv: With authentication but without privacy. Authentication
is based on Hash-Based Message Authentication Code-Message
Digest 5 or HMAC-Secure Hash Algorithm algorithms.
• AuthPriv: With authentication as described earlier and privacy using
the 56-bit Cipher-Block Chaining-Data Encryption Standard encryption
standard.
Management Information Base (MIB)
• A MIB is a collection of managed objects.
• A MIB stores information, which is collected by the local management
agent, on a managed device for later retrieval by a network
management protocol.
• Each object in a MIB has a unique identifier that network
management applications use to identify and retrieve the value of the
specific object.
• The MIB has a tree-like structure in which similar objects are grouped
under the same branch of the MIB tree.
• As shown in Figure, the MIB structure is logically represented by a tree
hierarchy.
• The root of the tree is unnamed and splits into three main branches:
Consultative Committee for International Telegraph and Telephone
(CCITT), ISO, and joint ISO/CCITT.
• These branches and those that fall below each category are identified with
short text strings and integers.
• Text strings describe object names, whereas integers form object identifiers
that allow software to create compact, encoded representations of the
names.
• The object identifier in the Internet MIB hierarchy is the sequence of
numeric labels on the nodes along a path from the root to the object.
Remote Network Monitoring (RMON)
• The RMON standard allows packet and traffic patterns on LAN segments to be
monitored.
• RMON is a MIB that provides support for proactive management of LAN traffic.
• RMON tracks the following items:
1. Number of packets
2. Packet sizes
3. Broadcasts
4. Network utilization
5. Errors and conditions, such as Ethernet collisions
6. Statistics for hosts, including errors generated by hosts, busiest hosts, and
which hosts communicate with each other.
RMON (contd..)
• RMON agents can reside in routers, switches, hubs, servers, hosts, or
dedicated RMON probes.
• Because RMON can collect a lot of data, dedicated RMON probes are
often used on routers and switches instead of enabling RMON agents
on these devices.
• Performance thresholds can be set and reported on if the threshold is
breached; this helps reduce management traffic.
• RMON provides effective network fault diagnosis, performance
tuning, and planning for network upgrades.
RMON groups
• Statistics: Contains statistics such as packets sent, bytes sent, broadcast packets, multicast
packets, CRC errors, runts, giants, fragments, jabbers, collisions, and so forth, for each monitored
interface on the device.
• History: Used to store periodic statistical samples for later retrieval.
• Alarm: Used to set specific thresholds for managed objects and to trigger an event on crossing
the threshold (this requires an Events group).
• Host: Contains statistics associated with each host discovered on the network.
• Host Top N: Contains statistics for hosts that top a list ordered by one of their observed variables.
• Matrix: Contains statistics for conversations between sets of two addresses, including the number
of packets or bytes exchanged between two hosts.
• Filters: Contains rules for data packet filters; data packets matched by these rules generate events
or are stored locally in a Packet Capture group.
• Packet Capture: Contains data packets that match rules set in the Filters group.
• Events: Controls the generation and notification of events from this device.
• TokenRing: Contains the following Token Ring Extensions:
• — Ring Station—Detailed statistics on individual stations
• — Ring Station Order—Ordered list of stations currently on the ring
• — Ring Station Configuration—Configuration information and insertion/removal data on each station
• — Source Routing—Statistics on source routing, such as hop counts
• Protocol Directory: Provides the list of protocols that the device supports
• Protocol Distribution: Contains traffic statistics for each supported
protocol
• Address Mapping: Contains network layer-to-MAC layer address
mappings
• Network Layer Host: Contains statistics for the network layer traffic to or
from each host
• Network Layer Matrix: Contains network layer traffic statistics for
conversations between pairs of hosts
• Application Layer Host: Contains statistics for the application layer traffic
to or from each host
• Application Layer Matrix: Contains application layer traffic statistics for
conversations between pairs of hosts
• User History Collection: Contains periodic samples of user-specified
variables
• Probe Configuration: Provides a standard way of remotely configuring
probe parameters, such as trap destination and out-of-band
Syslog Accounting
• A system message and error reporting service is an essential
component of any operating system.
• The syslog system message report system state information to a
network manager.
• Cisco devices produce syslog messages as a result of network events.
• Every syslog message contains a time stamp (if enabled), severity
level, and facility.
• Example: 20:14:26: %SYS-5-MOD_OK:Module 1 is online
Syslog messages contain up to 80 characters; a percent sign (%) follows the optional sequence
number or time-stamp information if configured. Syslog messages are structured as follows:

seq no:timestamp: %facility-severity-MNEMONIC:description


•A sequence number appears on the syslog message if the service sequence-numbers global configuration command is configured.
•The time stamp shows the date and time of the message or event if the service timestamps log [datetime | log] global configuration
command is configured. The time stamp can have one of three formats:
• — mm/dd hh:mm:ss
• — hh:mm:ss (for short uptimes)
• — d h (for long uptimes)
•Facility: A code consisting of two or more uppercase letters that indicate the facility to which the message refers. Syslog facilities are service
identifiers used to identify and categorize system state data for error and event message reporting. A facility can be a hardware device, a
protocol, or a module of the system software. The Cisco IOS software has more than 500 different facilities; the following are the most common:
• — IP
• — OSPF (OSPF protocol)
• — SYS (operating system)
• — IPsec (IP Security)
• — RSP (Route Switch Processor)
• — IF (interface)
• — LINK (data link messages)
• Other facilities include CDP, QoS, RADIUS, multicast (MCAST), MLS, TCP, VLAN trunking protocol (VTP), Telnet, and trivial file
transfer protocol (TFTP).
•Severity: A single-digit code (from 0 to 7) that reflects the severity of the condition; the lower the number, the more serious the situation. Syslog
defines the following severity levels:
• — Emergency (Level 0, which is the highest level)
• — Alert (Level 1)
• — Critical (Level 2)
• — Error (Level 3)
• — Warning (Level 4)
• — Notice (Level 5)
• — Informational (Level 6)
• — Debugging (Level 7)
•Mnemonic: A code that uniquely identifies the error message.
•Description: A text string that describes the condition. This portion of the message sometimes contains detailed information about the event,
including port numbers, network addresses, or addresses that correspond to locations in the system memory address space.

You might also like