Showing posts with label Network Diagram. Show all posts
Showing posts with label Network Diagram. Show all posts

Wednesday, 13 November 2019

Cisco Enterprise Network Architecture

Cisco Enterprise Network Architecture

This section explains the various modules in the network design and describes the Cisco enterprise architecture model . The benefits obtained through a systematic design approach are also covered.

MODULAR NETWORK DESIGN

While the hierarchical network design works well within the campus infrastructure, the networks expanded beyond these borders. As shown in Image 1, the networks became more sophisticated and complex, and some require connections to dedicated data centers, which are usually external.
Often, branches require connectivity to campus backbones, and employees need to be able to work from their home offices or other remote locations. Because the complexity of the network to meet these demands increased, it became necessary to modify the design of the network by one that used a more modular approach.
A modular network design separates the network into several functional network modules, and each of these points to a specific place or purpose in the network. The modules represent areas that have a different physical or logical connectivity. They are responsible for designating where the different functions are carried out in the network.
The modular approach has several benefits:

  • Faults that occur within a module can be isolated from the rest of the network, allowing for easier problem detection.
  • Changes, updates or the introduction of new network services can be carried out in a controlled and gradual manner, allowing greater flexibility in the maintenance and operation of the campus network.
  • When a specific module no longer has sufficient capacity or does not have a new function or service, it can be updated or replaced with another module that has the same structural function in the general hierarchical design.
  • Security can be implemented modularly.

MODULES IN BUSINESS ARCHITECTURE

The modular approach applied to the network design further divides the three-layer hierarchical design, since it eliminates specific blocks or modular areas. These basic modules are connected to each other through the core of the network.

The basic network modules include the following:

  • Access and distribution : also called “distribution block”, it is the best known element and the fundamental component of campus design ( orange frame ).
  • Services : This is a generic block that is used to identify services such as the centralized wireless controllers of the Lightweight Access Point Protocol (LWAPP), the unified communications services, the policy gateways, among others ( celestial framework ).
  • Data center : originally, it was called "server farm". This block is responsible for managing and maintaining many data systems that are critical to modern business operations. Employees, partners and customers rely on data and data center resources to create, collaborate and interact effectively ( green framework ).
  • Business perimeter : consists of the perimeter Internet and the WAN perimeter. These blocks offer connectivity to voice, video and data services outside the company ( red frame ).

CISCO ENTERPRISE ARCHITECTURE MODEL

To meet the need for modularity in network design, Cisco developed the Cisco enterprise architecture model . This model provides all the benefits of hierarchical network design in campus infrastructure and facilitates the design of larger and scalable networks.
The Cisco enterprise architecture model separates the business network into functional areas that are known as "modules." The modularity that is incorporated into the architecture allows for flexibility in network design and facilitates its implementation and problem solving.
As shown in Image, the following are the main modules of the Cisco enterprise architecture:


  • Business campus
  • Enterprise Edge
  • Service provider end

There are additional modules connected to the perimeter of the service provider:

  • Company data center
  • Company Branch
  • Remote worker of the company

CISCO BUSINESS CAMPUS

A campus network is a building or group of buildings connected to a business network that consists of many LANs. Generally, a campus is limited to a fixed geographical area, but it can cover several neighboring buildings, for example, an industrial complex or the environment of an industrial park.
The business campus module describes the recommended methods for creating a scalable network, while addressing the needs of commercial operations of the campus type. The architecture is modular and can be easily expanded to include additional buildings or campus floors as the company grows.
The business campus module consists of the following submodules:

  • Building access
  • Building distribution
  • Campus Core
  • Data center

Together, these submodules do the following:

  • They provide high availability through a robust hierarchical network design.
  • They integrate IP communications, mobility and advanced security.
  • They use multicast traffic and QoS to optimize network traffic.
  • They provide greater security and flexibility by managing access, VLANs and VPNs with IPsec.
  • The architecture of the business campus module provides the company with high availability through a robust multilayer design, redundant hardware and software features, and automatic procedures to reconfigure network routes when failures occur.

Integrated security protects against the impact of worms, viruses and other network attacks, in addition to mitigating it, even at the switch port level.
The data center sub-module typically contains internal corporate and email servers that provide application, archiving, printing, email and domain name system (DNS) services to internal users.

CISCO BUSINESS PERIMETER

The business perimeter module provides connectivity for voice, video and data services outside the company. Often, this module works as a link between the business campus module and the other modules.
The business perimeter module consists of the following submodules:

  • E-commerce networks and servers : the e-commerce submodule allows companies to support e-commerce applications through the Internet.

They include web, application and database servers, firewall and firewall routers, and intrusion prevention systems (IPS) in the network.

  • Internet connectivity and perimeter zone (DMZ) : The Internet sub-module of the business perimeter provides internal users with secure connectivity to Internet services, such as public servers, email and DNS. Connectivity is also provided to one or more Internet service providers (ISPs).

They include firewall and firewall routers, Internet perimeter routers, FTP and HTTP servers, SMTP relay servers and DNS servers.

  • Remote access and VPN: The remote access and VPN sub-module of the business perimeter provides remote access termination services, including authentication for remote users and sites.

They include firewalls, dial-up hubs, Cisco Adaptive Security Devices (ASA) and intrusion prevention system (IPS) applications on the network.

WAN : The WAN submodule uses various WAN technologies to route traffic between remote sites and the central site.
They include technologies such as multi-protocol tag switching (MPLS), metropolitan Ethernet, leased lines, synchronous optical network (SONET) and synchronous digital hierarchy (SDH), PPP, Frame Relay, ATM, cable, digital subscriber line (DSL) and wireless technology.

SERVICE PROVIDER END


  • Companies use service providers (SP) to link to other sites. The perimeter module of the SP may include the following:
  • Internet service providers (ISP)
  • WAN services, such as Frame Relay, ATM and MAN
  • Public switched telephone network (PSTN) services
  • The perimeter of the SP provides connectivity between the business campus module and the remote data center, branch and remote worker modules of the company.

The perimeter module of the SP has the following characteristics:

  • It covers large geographic areas in a cost-effective manner.
  • Converge voice, video and data services through a single IP communications network.
  • Supports QoS and service level agreements.
  • It supports VPN security (IPsec and MPLS) through the Layer 2 and Layer 3 WANs.
  • Connection to an ISP

Redundant connections to a single ISP can include the following:

  • Simple connection: a single connection to an ISP
  • Double connection: two or more connections to a single ISP
  • Connection to several ISPs

Redundancy can also be established with several ISPs, as shown in Image 5. The options for connecting to several ISPs include the following:

  • Multiple host connection: connections to two or more ISPs
  • Dual multiple host connection: multiple connections to two or more ISPs

REMOTE FUNCTIONAL AREA

The remote functional area is responsible for the remote connectivity options and includes several modules:

COMPANY BRANCH

The company's branch module includes remote branches that allow employees to work in off-campus locations.

  • In general, these locations provide security, telephony and mobility options to employees, as well as general connectivity to the campus network and the various components located within the business campus.
  • The company's branch module allows companies to extend applications and services from the head office, such as security, Cisco Unified Communications and advanced application performance, to remote branches.
  • The perimeter device that connects the remote site to the central site varies according to the needs and size of the site.
  • Large remote sites can use advanced technology Cisco Catalyst switches, while smaller sites can use an ISR G2 router. These remote sites depend on the perimeter of the SP to provide the services and applications of the main site.
  • In Image, the company's branch module connects to the business campus primarily through a WAN link; however, it also has a backup internet link. The Internet link uses VPN technology with IPsec from site to site to encrypt corporate data.

REMOTE WORKER OF THE COMPANY

The company's remote worker module is responsible for providing connectivity to employees who work from various geographically dispersed locations, including domestic offices, hotels or customer sites.

  • The remote worker module recommends that mobile users connect to the Internet through the services of a local ISP, such as the cable modem or DSL modem.
  • VPN services can be used to protect communications between the mobile worker and the central campus.
  • Integrated security and identity-based network services allow the company to extend campus security policies to the remote worker.
  • Staff can log in to the network securely through the VPN and access authorized applications and services from a single cost-effective platform.

COMPANY DATA CENTER

The company's data center module is a data center with the same functional options as the campus data center, but in a remote location.

  • This provides an additional layer of security, since the external data center can provide the company with disaster recovery and business continuity services.
  • Advanced technology switches, such as Cisco Nexus series switches, use fast WAN services such as Metropolitan Ethernet (MetroE) to connect the business campus to the remote company's data center.
  • Redundant data centers provide support through synchronous and asynchronous replication of data and applications. In addition, the network and devices offer load balancing of servers and applications to maximize performance. This solution allows the company to scale without major changes in infrastructure.

Tuesday, 12 November 2019

Hierarchical Network Design | Cisco Hierarchical Model

Hierarchical Network Design | Cisco hierarchical Model

This post describe the Hierarchical Network Design and principles of structured engineering for network design . You will learn the three layers of Cisco hierarchical Model and how they are used in network design. Network design start from analyzing the network component, it is useful to categorize the networks according to the number of devices served:

  • Small network : provides services for up to 200 devices.
  • Medium network : provides services for 200 to 1000 devices.
  • Large network : provides services for more than 1000 devices.

Network designs vary according to the size and needs of organizations. There are many variables to consider when designing a network. Normally a large business network consisting of a main campus that connects small, medium and large sites. Network design is an expanding area and requires a lot of knowledge and experience. The objective of this section is to present widely accepted network design concepts.

PRINCIPLES OF STRUCTURED ENGINEERING

Regardless of the size or requirements of the network, a fundamental factor for the correct implementation of any network design is to follow good principles of structured engineering:

  • Hierarchy : a hierarchical network model is a useful high-level tool for designing a reliable network infrastructure. Divide the complex problem of network design into smaller and easier to manage areas.
  • Modularity : by separating in modules the various functions that exist in a network, it is easier to design. Cisco identified several modules, including the business campus, the service block, the data center and the Internet perimeter.
  • Resistance : the network must be available so that it can be used both in normal conditions (maintenance periods) and abnormal conditions (hardware or software failures).
  • Flexibility : the ability to modify parts of the network, add new services or increase capacity without the need for major updates (i.e. replace major hardware devices).

To meet these fundamental design objectives, the network must be built on the basis of a hierarchical network architecture that allows flexibility and growth.

Cisco Hierarchical Model

In network technology, a hierarchical design involves dividing the network into independent layers . Each layer (or level) in the hierarchy provides specific functions that define its function within the general network.
This helps the network designer and architect to optimize and select the appropriate network features, hardware and software to perform the specific functions of that network layer. Hierarchical models apply to LAN and WAN design.
A typical design of a corporate campus hierarchical LAN network includes the following three layers:

  • Access layer : provides network access for workgroups and users.
  • Distribution layer : provides policy-based connectivity and controls the boundary between the access and core layers.
  • Core layer : provides fast transport between distribution switches within the business campus.
The benefit of dividing a flat network into smaller and easier to manage blocks is that local traffic remains local. Only traffic destined for other networks is moved to a higher layer.
Layer 2 devices in a flat network provide few opportunities to control broadcasts or filter unwanted traffic. As more devices and applications are added to a flat network, response times degrade until the network becomes unusable.

In Image, another example of a three-layer hierarchical network design is shown. Note that each building uses the same hierarchical network model that includes the access, distribution and core layers.

ACCESS LAYER

In a LAN environment, the access layer grants access to the network for the terminals. In the WAN environment, you can provide access to the business network for remote workers or remote sites through WAN connections.
As shown in Image, the access layer for a small business network usually incorporates Layer 2 switches and access points that provide connectivity between workstations and servers.

The access layer performs several functions, including the following:

  • Layer 2 Switching
  • High availability
  • Port security
  • Classification and marking of QoS, and confidence limits
  • Address Resolution Protocol (ARP) Inspection
  • Virtual access control lists (VACL)
  • Expansion tree
  • Auxiliary Ethernet and VLAN power for VoIP

DISTRIBUTION LAYER

The distribution layer aggregates the data received from the access layer switches before they are transmitted to the core layer for routing to its final destination. In Image 4, the distribution layer is the boundary between the layer 2 domains and the layer 3 routed network.
The distribution layer device is the center in wiring cabinets. To segment workgroups and isolate network problems in a campus environment, a multilayer router or switch is used.
A distribution layer switch can provide upstream services for many access layer switches.
The distribution layer can provide the following:

  • LAN or WAN link aggregation.
  • Policy-based security in the form of access control lists (ACLs) and filtering.
  • Routing services between LAN and VLAN networks, and between routing domains (eg, EIGRP to OSPF).
  • Redundancy and load balancing.
  • A limit for aggregation and summarization of routes that is configured in the interfaces to the core layer.
  • Broadcast domain control, since neither routers nor multilayer switches resend broadcasts. The device works as a demarcation point between broadcast domains.

Cisco CORE LAYER

The core layer is also known as " network backbone ." The core layer consists of high-speed network devices, such as Cisco Catalyst 6500 or 6800 switches. These are designed to switch packets as quickly as possible and interconnect various campus components, such as distribution modules, service modules, the center of data and the perimeter of the WAN.
As shown in above Image, the core layer is essential for interconnectivity between the distribution layer devices; for example, interconnects the distribution block to the perimeter of the WAN and the Internet.
The core must have high availability and must be redundant. The kernel aggregates traffic from all devices in the distribution layer, so it must be able to send large amounts of data quickly.
Some of the considerations regarding the core layer include the following:

  • You must provide high speed switching (i.e. fast transport).
  • It must provide reliability and fault tolerance.
  • You must achieve scalability through faster teams, not more teams.
  • You must avoid packet handling that implies a high demand for the CPU because of security, inspection, quality of service (QoS) classification or other processes.

TWO-LEVEL CONTRACTED CORE DESIGN

There are no absolute rules about how a campus network should be physically assembled. While it is true that many campus networks are built with three physical levels of switches, it is not a strict requirement. On a smaller campus, the network can have two levels of switches in which the core and distribution elements are combined into a physical switch. This is called "contracted core design."
The three-tier hierarchical design maximizes performance, network availability and the ability to scale the network design.
However, there are many small business networks that do not grow much over time. Therefore, a two-level hierarchical design in which the core and distribution layers are combined into a single layer is usually more practical. There is a "contracted core" when the functions of the distribution layer and the core layer are implemented by a single device. The main motivation to choose the contracted core design is the reduction of network costs, while maintaining the majority of the benefits of the three-tier hierarchical model.

Monday, 21 October 2019

What is Network Address Translation & how NAT works?

What is Network Address Translation & how NAT works?

This article cover What is Network Address Translation & how NAT works, it features.

WHAT IS NAT?

NAT has many uses, but the main use of NAT is to translate or map the private IPs to public IP address. This is achieved by allowing networks to use private IPv4 addresses internally and by providing translation to a public address only when necessary. NAT has the additional benefit of providing a certain degree of privacy and additional security to a network, since it hides the internal IPv4 addresses of external networks.
Routers with NAT enabled can be configured with one or more valid public IPv4 addresses. These public addresses are known as " NAT pool". When an internal device sends out-of-network traffic, the router with NAT enabled translates the device's internal IPv4 address to a public address in the NAT set. For external devices, all incoming and outgoing network traffic appears to have a public IPv4 address from the set of addresses provided.

In general, NAT routers work at the border of an internal route network. An internal route network is one that has a single connection to its neighboring network, an entrance to the network and an exit from it. In the example in Image 3, R2 is a border router. Viewed from the ISP, R2 forms a network of internal routes.
When a device within the internal route network wishes to communicate with a device outside its network, the packet is forwarded to the border router. The border router performs the NAT process, that is, it translates the internal private address of the device to a public, external and routable address.

NAT FEATURES

There are not enough public IPv4 addresses to assign a unique address to each device connected to the Internet. Networks are usually implemented through the use of private IPv4 addresses, as defined in RFC 1918. Image 1 shows the range of addresses included in RFC 1918. It is very likely that the computer you use to view this website is assigned a private address

These private addresses are used within an organization or a site to allow devices to communicate locally. However, since these addresses do not identify individual companies or organizations, private IPv4 addresses cannot be routed over the Internet. To allow a device with a private IPv4 address to access resources and devices outside the local network, the private address must first be translated into a public address. NAT provides the translation of private addresses to public addresses. This allows a device with a private IPv4 address to access resources outside its private network, such as those found on the Internet. The combination of NAT with private IPv4 addresses proved to be a useful method to preserve public IPv4 addresses. A single public IPv4 address can be shared among hundreds or even thousands of devices, each configured with an exclusive private IPv4 address.
Without NAT, IPv4 address space depletion would have occurred long before the year 2000 . However, NAT has some limitations, which are discussed below. The solution to IPv4 address space depletion and  Network Address Translation limitations is the final transition to IPv6 .

NAT TERMINOLOGY

According to  Network Address Translation terminology, the internal network is the set of networks subject to translation. The external network refers to all other networks.
When using NAT, IPv4 addresses are designated differently, depending on whether they are on the private network or on the public network (Internet), and whether the traffic is inbound or outbound.

NAT includes four types of addresses:

  • Private Local Address
  • Global IP Address
  • External local address
  • Global external address

When determining what type of address is used, it is important to remember that NAT terminology is always applied from the perspective of the device with the translated address:

  • Private address:  the address of the device that is translated through NAT.
  • External address:  the address of the destination device.

 Network Address Translation also uses the concepts of local or global in relation to addresses:

  • Local address:  any address that appears in the internal portion of the network.
  • Global address:  any address that appears in the outer portion of the network.

HOW DOES NAT WORK?

In this example, PC1 with private address 192.168.10.10 wishes to communicate with an external web server with public address 209.165.201.1.


  • PC1 sends a packet addressed to the web server. R1 forwards the packet to R2.
  • When the packet arrives at R2, the router with NAT enabled for the network, R2 reads the source IPv4 address of the packet to determine if it meets the criteria specified for translation.
  • In this case, the source IPv4 address meets the criteria and translates from 192.168.10.10 (internal local address) to 209.165.200.226 (internal global address). R2 adds this local to global address assignment to the NAT table.
  • R2 sends the packet with the translated source address to the destination.
  • The web server responds with a packet addressed to the internal global address of PC1 (209.165.200.226).
  • The R2 receives the packet with the destination address 209.165.200.226. The R2 reviews the NAT table and finds an entry for this assignment. R2 uses this information and translates the internal global address (209.165.200.226) to the internal local address (192.168.10.10), and the packet is forwarded to PC1.


Wednesday, 7 August 2019

Network Diagram or Network Representations | Topology Diagram

Network Diagram or Network Representations | Topology Diagram


To representing a network we use different symbol and topology icon, and this Topology Diagram known as Network Diagrams. In this section we will see the Logical Topology Diagrams and the Physical Topology Diagrams. The topology diagrams are mandatory for everyone working with networks. This is how a network is represented.

Network Symbols


Network diagrams use symbols / images to represent the different devices and connections that make up a network. A diagram allows you to easily understand the way in which devices are connected in a large network. This type of representation of a network is called a topology diagram . The ability to recognize the logical representations of physical network components is essential to visualize the organization and operation of a network.


In addition to these representations, specialized terminology is used when talking about how these devices and the media connect to each other. Some important terms to remember are:


  • Network interface card: A NIC, or LAN adapter, provides the physical connection to the network on the PC or other terminal. The means that connect the PC to the network device are connected directly to the NIC.
  • Physical port: a connector or connection on a network device where the media is connected to a terminal or other network device.
  • Interface: specialized ports on a network device that connects to individual networks. Since routers are used to interconnect networks, the ports of a router are known as network interfaces.

TYPES OF NETWORK DIAGRAMS

Topology diagrams are mandatory for everyone who works with networks. These diagrams provide a visual map that shows how the network is connected.

There are two types of topology diagrams:

PHYSICAL TOPOLOGY DIAGRAM

Identify the physical location of the intermediary devices and the installation of the cables.


LOGIC TOPOLOGY DIAGRAM

Identify devices, ports and addressing scheme.

In summary, the topologies shown in the physical and logical diagrams are appropriate for your level of understanding at this point in the course.