Designing Remote Connectivity Part 02 — Transcript
Full transcript
- 0:05designing the enterprise
- 0:07one
- 0:10using one technologies numerous one
- 0:13technologies exists
- 0:15today and new technologies are
- 0:17constantly merging
- 0:19the most appropriate one selection
- 0:21usually results in high efficiency and
- 0:23leads to
- 0:24customer satisfaction the network
- 0:26designer
- 0:27must be aware of all the possible one
- 0:30design choices
- 0:31while taking into account customer
- 0:33requirements
- 0:34this section describes the use of
- 0:37various one technologies
- 0:39including remote access vpns
- 0:43one backup and the internet as a backup
- 0:45one
- 0:48let's start with the traditional one
- 0:50technologies
- 0:52so traditional one technologies includes
- 0:54the following
- 0:55you've got the list lines point-to-point
- 0:58connections
- 0:59indefinitely reserved for transmissions
- 1:02rather than used only when transmission
- 1:05is required
- 1:07so you also have the circuit switch
- 1:09networks
- 1:11a type of network that for the duration
- 1:13of the connection
- 1:14obtains and or dedicates a physical path
- 1:19for a single connection between two
- 1:21network endpoints
- 1:23and you've got the packet switched and
- 1:26cell
- 1:27switched networks a carrier creates
- 1:30permanent virtual circuits or pvcs
- 1:33or switched virtual circuits or svcs
- 1:36that delivers packets of data
- 1:39among customer sites
- 1:43now for the one topologies we have this
- 1:46star or also known as the hub and spoke
- 1:49topology
- 1:51so the benefits network simplicity
- 1:54low number of circuits the only drawback
- 1:57is sub-optimal traffic flow
- 1:59there is no redundancy here so if the
- 2:02hub goes down well all the spokes
- 2:06are disconnected the next apology
- 2:09is a full mesh topology so benefits
- 2:14any to any connectivity high level of
- 2:17redundancy
- 2:19drawbacks configuration complexity and
- 2:22of course the number of circuits
- 2:25and you also have the partially mesh
- 2:27topology
- 2:29a compromise between the star and a
- 2:32fully meshed
- 2:36designing the remote access network so
- 2:40the objective is to provide a unified
- 2:43solution for remote access
- 2:45grant the connection seamlessly as if
- 2:48in the company headquarters application
- 2:52requirements includes
- 2:53low to medium volume data file transfer
- 2:56and interactive
- 2:57traffic for teleworkers and traveling
- 3:00workers
- 3:01voice services for teleworkers
- 3:04connectivity options ip access through
- 3:07an on demand
- 3:09or always on connection so technologies
- 3:12includes dial up the old dial up dsl
- 3:16cable wireless broadband and others
- 3:22overview of a virtual private networks
- 3:24or vpn
- 3:26so a vpn is a connectivity deployed on a
- 3:29shared infrastructure
- 3:31with the same policies security and
- 3:34performance as a private network but
- 3:36typically with lower total cost of
- 3:38ownership
- 3:40and we are using the public network like
- 3:42the internet
- 3:44to provide connectivity among sites
- 3:49so connectivity option first is the
- 3:52overlay vpn
- 3:55so vpn connectivity options like the
- 3:58overlay
- 4:00vpdn or the virtual private dial-up
- 4:02networks and peer-to-peer vpns
- 4:04now let's focus on the overlay vpn here
- 4:08with overlay vpns the provider's
- 4:11infrastructure provides
- 4:13virtual point-to-point links between
- 4:16customer sites
- 4:18overlay vpns are implemented with a
- 4:20number of technologies
- 4:22including the traditional layer 1 and
- 4:24layer 2 technologies
- 4:27okay so overlaid with modern layer 3 ip
- 4:31based solutions such as the generic
- 4:34routing encapsulation green
- 4:36and ipsec so you can check the
- 4:39supplementary videos
- 4:40to learn more about vpns 3 and ipsec
- 4:45so from the layer 3 perspective
- 4:48the provider network is invisible
- 4:52the customer routers are linked with
- 4:54emulated point-to-point links
- 4:57so the routing protocol runs directly
- 4:59between routers that establish
- 5:01routing adjacencies in exchange routing
- 5:04information
- 5:06so the provider is not aware of customer
- 5:09routing
- 5:10and does not have any information about
- 5:12customer routes
- 5:14so the provider's only responsibility is
- 5:17the point-to-point data transport
- 5:18between the customer sites
- 5:22so although they are well known and easy
- 5:25to implement
- 5:26overlay vpns are more difficult to
- 5:28operate and have higher maintenance
- 5:30costs
- 5:31for the following reasons first
- 5:35every individual purple circuit must be
- 5:37provisioned
- 5:39optimum routing between customer sites
- 5:41requires a full mesh
- 5:43of vertical circuits between sites
- 5:46bandwidth must be provisioned on a
- 5:49side-to-side
- 5:50basis so this figure here
- 5:53illustrates an overlay vpn the router on
- 5:57the left
- 5:58in the enterprise edge module has one
- 6:01physical connection
- 6:02to the service provider with two virtual
- 6:04circuits provision
- 6:06you've got the virtual circuit one and
- 6:08then the virtual circuit two here
- 6:11now vc1 provides connectivity to the
- 6:13router
- 6:15on the top right okay
- 6:18whereas vc2 or the virtual circuit 2
- 6:21here
- 6:22provides connectivity to the branch
- 6:23office router
- 6:25to the bottom right
- 6:29next would be the virtual private dial
- 6:31up network
- 6:32or the vpdns
- 6:36vpdns enable an enterprise to configure
- 6:38secure
- 6:39networks that rely on an isp for
- 6:42connectivity
- 6:44with vpdns the customers
- 6:48use a provider's dial-in
- 6:51or other type of connectivity
- 6:52infrastructure for their private
- 6:54connections
- 6:56a vpdn can be used with any available
- 6:59access technology
- 7:02ubiqt is important meaning that bpdns
- 7:06should work with any technology
- 7:08including modem
- 7:10isdn xdsl or cable connections
- 7:15so the isp agrees to forward the
- 7:19company's traffic
- 7:20from the isps pop to a company run
- 7:25home gateway so network configuration
- 7:28and security remain in the client's
- 7:30control
- 7:32so the service providers or sp supplies
- 7:34a virtual tunnel
- 7:36between the company's sites using a
- 7:39layer to forwarding
- 7:41or point-to-point tunneling or ietf
- 7:43layer to tunneling protocol l2tp tunnels
- 7:47now this figure here illustrates a vpdn
- 7:52in this figure the isp terminates
- 7:56the dial up connection at the l2tp
- 7:59access concentrator
- 8:01or the lac and forwards
- 8:04traffic through dynamically established
- 8:06tunnels
- 8:07to a remote access server called l2tp
- 8:11network server or the lns
- 8:15all right now a vpdn provides potential
- 8:19operations
- 8:20and infrastructure costs or cost savings
- 8:24because a company can outsource its
- 8:26dial-up equipment
- 8:28thereby avoiding the cost of being in
- 8:31the remote access server
- 8:32business
- 8:36so the next one would be the
- 8:37peer-to-peer vpn
- 8:40in a peer-to-peer vpn the provider
- 8:43actively participates in
- 8:45customer routing traditional
- 8:47peer-to-peer vpns are implemented with
- 8:50packet filters or shared providers edge
- 8:52or pe
- 8:53routers or with dedicated pre-customer
- 8:56pre-routers
- 8:58so in addition to high maintenance cost
- 9:01for the packet filter approach
- 9:03or equipment costs for the dedicated per
- 9:05customer peer router approach
- 9:08both methods require the customer to
- 9:10accept the provider assigned address
- 9:13space
- 9:14or to use public ip addresses in the
- 9:17private
- 9:17customer network so
- 9:20modern mpls vpns
- 9:24provide all the benefits of peer-to-peer
- 9:27vpns and alleviate most of the
- 9:30peer-to-peer vpn drawbacks such as the
- 9:33need for common customer addresses
- 9:36so overlapping addresses which are
- 9:39usually the result of companies using
- 9:41private addressing
- 9:43are one of the major obstacles to
- 9:45successful peer-to-peer
- 9:48vpn implementations so mpls of vpns
- 9:52solved this problem by giving each vpn
- 9:54its own routing and for wiring table in
- 9:56the router
- 9:58thus effectively creating a virtual
- 10:01routers
- 10:02for each of the customers
- 10:06now what are the benefits of the virtual
- 10:08private networks or vpns
- 10:11let's talk about flexibility
- 10:14so vpns offer flexibility because side
- 10:17to side and remote access connections
- 10:19can be
- 10:20set up quickly and over the existing
- 10:23infrastructure to extend the network
- 10:25to remote users so
- 10:30extra net connectivity for business
- 10:31partner is also a possibility
- 10:34okay and a variety of security policies
- 10:37can be provisioned in a vpn thereby
- 10:39enabling flexible interior connection
- 10:42of different security domains so you can
- 10:45set up and restructure networks
- 10:47quickly next would be the network cost
- 10:51so lower network communication cost so
- 10:54lower cost
- 10:55is a primary reason for migrating from
- 10:58the traditional connectivity option
- 11:00to a vpn connection so reduce dial up
- 11:03and dedicated bandwidth infrastructure
- 11:05and service provider costs
- 11:08make vpns attractive
- 11:11so customers can reuse existing links
- 11:14and take advantage of the statistical
- 11:16packet multiplexing features
- 11:19next would be scalability so vpns
- 11:23allow an organization to leverage and
- 11:25extend the classic
- 11:26one to more remote users and external
- 11:29users
- 11:30vpns offer scalability over large
- 11:34areas because iptransport is universally
- 11:37available
- 11:39this arrangement reduces the number of
- 11:41physical connections and simplifies
- 11:43the underlying structure of the
- 11:46customers
- 11:47one
- 11:50one backup technologies so let's take
- 11:54the one backup strategies here
- 11:57so this section describes various backup
- 12:00options
- 12:00for providing alternative path
- 12:04for remote access so one links are
- 12:07relatively unavailable
- 12:09okay or unreliable compared to land
- 12:12links
- 12:13and often are much lower than the lands
- 12:17to which they connect so this
- 12:20combination of uncertain reliability
- 12:22lacks
- 12:22speed and high importance makes
- 12:26one links good candidates for redundancy
- 12:29to achieve high availability
- 12:31so branch offices should experience
- 12:34minimum downtime
- 12:36in case of primary link failure a backup
- 12:39connection
- 12:40can be established either by a dial up
- 12:44or by using permanent connections so the
- 12:47main
- 12:47one backup options are as follows so
- 12:50you've got the
- 12:52dial up backup routing
- 12:56you've got the permanent secondary
- 12:58wireless
- 12:59or the the permanent secondary one
- 13:01length
- 13:02okay the shadow pvc and ipsec tunnel
- 13:06across the internet
- 13:08so for every connectivity of the remote
- 13:11offices
- 13:12to your headquarters so there should be
- 13:15a corresponding backup
- 13:20let's have our first example here
- 13:22permanent secondary one link
- 13:25so deploying an additional permanent one
- 13:28link between
- 13:28each remote office and the central
- 13:32office
- 13:33makes the network more fault tolerant
- 13:36so this solution offers the following
- 13:38two advantages
- 13:39so first you've got to provide a backup
- 13:42link
- 13:44the backup link is used if a primary
- 13:46link that connects
- 13:47any remote office with the central
- 13:49office fields
- 13:52routers automatically route around field
- 13:55one
- 13:56by using the floating static routes and
- 13:59routing protocols such as eigrp
- 14:01and ospf if one of the link fails
- 14:05the router recalculates and sends all
- 14:07traffic to another link
- 14:09allowing applications to proceed if a
- 14:12one link
- 14:13fails so thereby improving application
- 14:16availability
- 14:18so also you've got the increased
- 14:21bandwidth
- 14:22so both the primary and the secondary
- 14:24links can be used simultaneously because
- 14:27they are permanent so the routing
- 14:30protocol automatically performs
- 14:32load balancing between two parallel
- 14:36links with equal costs or an equal cost
- 14:40if eigrp is used
- 14:42the resulting increased bandwidth
- 14:44decreases the
- 14:45response time so
- 14:48in the figure the connections between
- 14:51the enterprise
- 14:52edge and the remote sites here
- 14:55use a permanent primary and secondary
- 14:58one links
- 14:59for redundancy a routing protocol such
- 15:03as eigrp
- 15:04that supports load balancing over an
- 15:06equal pass
- 15:08on either a per packet or per
- 15:10destination basis is used
- 15:12to increase the utilization of the
- 15:15backup link
- 15:18next example is the shadow pvc
- 15:22with a shadow pvcs as long as the
- 15:25maximum load on the shadow pvc does not
- 15:27exist
- 15:28a certain rate such as 1 4 of the
- 15:31primary speed
- 15:32while the primary pvc is available
- 15:35the service providers provides a
- 15:38secondary pvc without any additional
- 15:40charge
- 15:42so if traffic limit on the shadow pvc is
- 15:45exited
- 15:46while the primary pvc is up the service
- 15:49provider charges
- 15:50for the excess load on the shadow pvc
- 15:54now this figure here illustrates a
- 15:56redundant connections between the remote
- 15:58sites
- 15:59and the enterprise edge using a seattle
- 16:01pvc offered by the service provider
- 16:05so because of the potential
- 16:08for additional costs the routers must
- 16:11avoid
- 16:11sending any unnecessary data except
- 16:14for example routing traffic over a
- 16:17shadow
- 16:20pvc
- 16:22the internet as a one backup technology
- 16:25so this section describes the internet
- 16:27as an alternative option
- 16:28for a field one connection this type of
- 16:32connection is considered best
- 16:34effort and does not guarantee any
- 16:35bandwidth
- 16:37so common uh methods for connecting
- 16:40non-continuous private networks
- 16:42over a public ip network includes the
- 16:45following
- 16:47so you've got the use of the ip routing
- 16:49without constraints
- 16:51you have the grid tunnels and the
- 16:53hypersec tunnels
- 16:55so if you want to learn more about vpns
- 16:59you can go ahead and check the
- 17:00supplementary videos on vpns
- 17:05layer 3 tunneling layer 3 tunneling uses
- 17:08a layer 3 protocol to transport
- 17:11over additional or another layer 3
- 17:14network
- 17:15so typically layer 3 tunneling is used
- 17:18either to connect
- 17:20two non-contiguous parts of a non-ip
- 17:23network
- 17:24over an ip network or to connect two ip
- 17:27networks
- 17:27over a backbone ip network possibly
- 17:30hiding the ip addressing details
- 17:33of the two networks from the backbone ip
- 17:36network
- 17:37so following are the two layer three
- 17:40tunneling methods
- 17:41for connecting non-contiguous private
- 17:44networks
- 17:44over a public ip network so first is
- 17:49with the use of glee so gree is a
- 17:51protocol developed by cisco
- 17:53that encapsulates a wide variety of
- 17:56packet types
- 17:57inside ip tunnels so gree is designed
- 18:01for generic tunneling
- 18:02of protocols in the cisco ios
- 18:06grid tunnels ip over ip which can be
- 18:10useful
- 18:11when building a small scale ipvp and
- 18:14network that does not require
- 18:16substantial security so it is simple and
- 18:19flexible for basic ipv vpns
- 18:22packet payload is not encrypted this is
- 18:24an unsecure
- 18:26vpn protocol and provisioning of panels
- 18:28is not very scalable
- 18:31so the next option is the use of ipsec
- 18:34ipsec is both a tunnel encapsulation
- 18:37protocol
- 18:38and a security protocol so ipsec
- 18:41provides security for transmission of
- 18:43sensitive information over
- 18:44unprotected networks such as the
- 18:46internet
- 18:47by encrypting the tunnel's data
- 18:50so ipsec acts as the network layer in
- 18:53tunneling or transport mode and protects
- 18:56and authenticates ip packets between
- 18:58participating ipsec
- 19:00devices so again when we say ipsec
- 19:05packet payload can be encrypted hypersec
- 19:07receiver can authenticate source
- 19:09of packets and it uses the ike and pki
- 19:18enterprise one architecture
- 19:19considerations
- 19:22so support for network growth
- 19:25enterprises that anticipate significant
- 19:28growth
- 19:29should choose a technology that allows
- 19:31the network to grow
- 19:32with their business so one technologist
- 19:36with high support for network growth
- 19:38make it possible to add new branches or
- 19:41remote offices
- 19:42with minimal configurations at existing
- 19:45sites
- 19:46thus minimizing the cost and its staff
- 19:50requirements
- 19:51for such charges so the next one would
- 19:54be
- 19:55appropriate availability so businesses
- 19:59heavily affected by even the smallest
- 20:02disruption in network communications
- 20:05should consider high availability and
- 20:07important characteristics when choosing
- 20:09a connectivity technology
- 20:11highly available technologies provide
- 20:14inherent redundancy where no single
- 20:16point of failure
- 20:18exists in the network
- 20:21next would be operational expenses
- 20:24some one technologies result in a higher
- 20:27cost
- 20:28than others a private line technology
- 20:32such as the old frame relay or atm for
- 20:34example typically results in a higher
- 20:37carrier fees
- 20:38than a technology such as ipsec ipvpn
- 20:42which takes advantage of the public
- 20:44internet to help reduce costs
- 20:48so the next one would be operational
- 20:50complexity
- 20:52so the metropolitan area network
- 20:56and the wide area network technologies
- 20:58have varying levels
- 21:00of inherent technical complexity so the
- 21:03level of technical expertise
- 21:05required within the enterprise also
- 21:08varies
- 21:09so in most cases businesses can upgrade
- 21:12their man or one
- 21:14and take advantage of the expertise
- 21:17of the existing i.t staff requiring
- 21:19minimal training
- 21:21so next would be voice and video support
- 21:26so man and one technology support
- 21:28equality of service which helps
- 21:30enable advanced applications such as
- 21:32voice
- 21:33and video over the network next should
- 21:36be effort and cost
- 21:38to implement okay to migrate from
- 21:41private connectivity
- 21:43so when an enterprise is migrating from
- 21:45private connectivity to another
- 21:47technology
- 21:49it is important to evaluate the short
- 21:52and long term costs
- 21:53and benefits for this migration last
- 21:58would be
- 21:59the network segmentation support
- 22:03okay network segmentation means
- 22:05supporting a single network that is
- 22:07logically segmented one advantage of
- 22:10network segmentation is that
- 22:12it reduces the expenditures associated
- 22:15with equipment and maintenance
- 22:17network administration and network
- 22:20carrier
- 22:21charges as compared to separate physical
- 22:24networks
- 22:27cisco enterprise man and one
- 22:29architecture
- 22:31so what are the technologies here
- 22:34the cisco enterprise management
- 22:35architecture employs a number of
- 22:37man and one technologies engineered and
- 22:40optimized
- 22:41to enter operate as a contiguous system
- 22:46providing the integrated qos
- 22:50network security reliability and
- 22:52manageability required
- 22:54to support a variety of advanced
- 22:56business applications and services
- 22:59so these technologies include a number
- 23:01of secure
- 23:02alternatives to traditional private one
- 23:06connectivity and help increase network
- 23:08scalability
- 23:09and reduce monthly carrier fees
- 23:16now for the comparison the cisco
- 23:18enterprise management architecture
- 23:20includes
- 23:21the following technologies as summarized
- 23:23in this table here
- 23:24so you've got the private one the isp
- 23:27service
- 23:27hypersite and remote access ipsec vpn
- 23:31you've got the sp and pls and ipvpn
- 23:34and you've got this self-deployed mpls
- 23:39now for the private one private
- 23:41connectivity takes advantage of the
- 23:44existing
- 23:45one technologies or other connections
- 23:48to provide an additional level of
- 23:50security when connecting sites
- 23:52strong encryption like this
- 23:563ds aes and others
- 24:00can be added that ensures
- 24:03strong security next would be isp
- 24:06service
- 24:07so cytoside and remote access ipsec vpn
- 24:11these technologies take advantage of the
- 24:13ubiquity of public and private networks
- 24:16the use of strong encryption standards
- 24:18like test 3ds aes and others
- 24:21makes this one option more secure than
- 24:24traditional private connectivity
- 24:26and makes it compliant with many new
- 24:28information security regulations imposed
- 24:31on government and
- 24:32industry groups such as healthcares and
- 24:35finance okay so next would be the sp
- 24:39mpls and
- 24:41ipvpn a network based
- 24:44ipvpn is similar in many ways to private
- 24:47connectivity
- 24:48but with added flexibility scalability
- 24:52and
- 24:52rich now for the self-deployed
- 24:56mpls this is a network segmentation
- 24:59technique
- 25:00that allows enterprises to logically
- 25:02segment the network
- 25:04self-deployed mpls is typically reserved
- 25:07for very large enterprises or an sp
- 25:10willing to make a significant investment
- 25:13in network equipment and training and
- 25:16for those who have an i.t
- 25:17staff that is comfortable with a high
- 25:20degree of technical complexity
- 25:26enterprise can use a combination of
- 25:28these technologies to support their
- 25:30remote connectivity requirements
- 25:32so this figure here shows an example
- 25:37uh implementation of a combination of
- 25:39three technologies in healthcare
- 25:41environment
- 25:47selecting enterprise edge components so
- 25:50after identifying the remote
- 25:52connectivity requirements and
- 25:54architecture
- 25:55you are ready to select the individual
- 25:58one components
- 25:59so of course that includes hardware and
- 26:01software
- 26:03now hardware selection when selecting
- 26:05hardware
- 26:06use the vendor documentation to evaluate
- 26:10the one hardware components the
- 26:13selection process
- 26:14typically considers the function and
- 26:16features
- 26:17of the particular devices including
- 26:20their port densities
- 26:22packet throughput expandability
- 26:24capabilities
- 26:26and readiness to provide redundant
- 26:28connections
- 26:30now for the software selection the next
- 26:32step is to select the appropriate
- 26:34software features
- 26:36now when using cisco equipment the
- 26:39software is the cisco ios
- 26:41now when using enhanced good devices
- 26:45so you have the same considerations
- 26:51now as illustrated in the figure here
- 26:54the cisco ios software has been
- 26:56optimized for different markets
- 26:58network roles and platforms just like
- 27:01any other
- 27:02brands so cisco ios software meets the
- 27:05requirements of various markets
- 27:08this includes the enterprise service
- 27:09provider and commercial
- 27:11and places in the network access score
- 27:14and distribution
- 27:15and the edge
- 27:16[Music]
- 27:18now let us summarize designing the
- 27:20enterprise one
- 27:22traditional one technologies include
- 27:24list lines
- 27:25circuit switched psdn and packet
- 27:28switched
- 27:29networks remote access networks connect
- 27:32teleworkers and traveling employees
- 27:35a vpn provides connectivity over a
- 27:38shared infrastructure
- 27:40with the same policies and performance
- 27:43as a private network one backup
- 27:46strategies are needed to provide
- 27:49high availability between remote sites
- 27:52the cisco enterprise one and man
- 27:54architecture provides integrated qos
- 27:57network security reliability and
- 28:00manageability enterprise one design
- 28:04includes selecting the appropriate
- 28:06components including hardware
- 28:08and software
About this transcript
This page contains the full transcript of Designing Remote Connectivity Part 02 by Santelmo, generated from the public captions YouTube serves with the video. The transcript has 3,105 words across 681 segments, with the original timestamps preserved so you can click any line to jump to that moment in the embedded player.
What you can do with it
Use the transcript to take notes, quote the speaker, build a study guide, generate a summary with ChatGPT or Claude via the YouTube Summary tool, or export it as a timed subtitle file with YouTube to SRT. You can also re-open it in the transcriber to translate the transcript into 100+ languages.
Free YouTube transcript tool
YouTube2Text is a free YouTube transcript generator — no signup, no daily limit. Paste any YouTube link and get the full transcript instantly, with timestamps, click-to-jump, translation to 100+ languages, AI prompts for ChatGPT, Claude, and Gemini, and exports to TXT, SRT, VTT, or Markdown.