Structuring and Modularizing the Network Part 2 — Transcript
Full transcript
- 0:04using a modular approach
- 0:06in network design
- 0:10this section expands on the cisco
- 0:13service oriented network architecture
- 0:16or the sona framework described in
- 0:19applying a methodology to a design
- 0:21video and explores the six modules of
- 0:24the cisco enterprise architecture
- 0:26with an emphasis on the network
- 0:28infrastructure design considerations
- 0:31now the modularity built into the
- 0:33architecture
- 0:34allows flexibility in network design
- 0:37and facilitates implementation and
- 0:39troubleshooting
- 0:43let's start with the cisco oriented
- 0:45network architecture or the sona
- 0:47so as illustrated here in the figure the
- 0:50cisco sona provides an enterprise
- 0:52wide framework that integrates the
- 0:55entire
- 0:56network so that includes the campus
- 0:59data center enterprise edge
- 1:02one branches and teleworkers
- 1:05so that offering staff secure access to
- 1:09the tools
- 1:10processes and service they require
- 1:16now the modules of the cisco enterprise
- 1:18architecture represent
- 1:20focused views on each of the places
- 1:23in the network described in the sona
- 1:25framework
- 1:27so each module has a distinct network
- 1:30infrastructure
- 1:31and distinct services network
- 1:34applications
- 1:35extend between the modules
- 1:39let's talk about the cisco enterprise
- 1:41architecture
- 1:43so the functional areas of the cisco
- 1:45enterprise
- 1:46architecture so at the first layer
- 1:49of the modularity in the cisco
- 1:51enterprise architecture
- 1:53the entire network is divided into
- 1:55functional components
- 1:57so functional areas that contain
- 2:00network modules while still maintaining
- 2:03the hierarchical concept
- 2:05of the core distribution and access
- 2:08layers
- 2:09with the network okay so take note that
- 2:13the access distribution and core layers
- 2:16can appear in any functional area or
- 2:19module
- 2:20of the cisco enterprise architecture so
- 2:23the cisco enterprise architecture
- 2:25comprises of
- 2:26the following six major functional
- 2:29areas also called as modules
- 2:32okay so this includes the enterprise uh
- 2:34campus
- 2:36the enterprise edge the
- 2:40service provider okay so service
- 2:43provider
- 2:44one in internet here you also have the
- 2:47enterprise branch the
- 2:51enterprise data center and the
- 2:54enterprise
- 2:55teleworker so the figure illustrates
- 2:59the modules within the cisco enterprise
- 3:03architecture now the key point here is
- 3:07an enterprise does not implement the
- 3:09modules
- 3:10in the service provider functional area
- 3:14they are necessary for enabling
- 3:15communication
- 3:17with the other networks so the cisco
- 3:20enterprise campus architecture
- 3:22combines a core infrastructure of
- 3:25intelligent switching and routing
- 3:27with tightly integrated productivity
- 3:29enhancing technologies
- 3:31including mobility
- 3:35and advanced security so the
- 3:38architecture provides
- 3:39the enterprise with high availability
- 3:42through a resilient multi-layer design
- 3:45redundant
- 3:46hardware and software features and
- 3:48automatic procedures
- 3:50for a configuring network path when
- 3:53failure occurs
- 3:55so also you've got the ip multicast
- 3:59capabilities
- 4:00provide optimized bandwidth consumption
- 4:03and the quality of service features
- 4:05ensure that real-time traffic
- 4:08such as voice video or critical data
- 4:12is not dropped or delayed
- 4:15so integrated security protects against
- 4:18and mitigates the impact of worms
- 4:22viruses and other attacks on the network
- 4:25including
- 4:26the switchboard level so for example
- 4:30the cisco enterprise-wide architecture
- 4:33extends support
- 4:34for security standards such as the ieee
- 4:38802.1x
- 4:40port based network access control
- 4:43standard
- 4:44and the extensible authentication
- 4:46protocol or eap
- 4:49it also provides the flexibility to add
- 4:52internet protocol security or ipsec
- 4:55and mpls virtual private networks
- 4:58vpn identify and access management
- 5:03and vlans to compartmentalize
- 5:06access these features help improve
- 5:10performance and security
- 5:12while decreasing costs
- 5:15okay now let's talk about the cisco
- 5:18enterprise
- 5:18edge architecture here it offers
- 5:22connectivity to voice
- 5:25okay video and data services outside
- 5:28enterprise
- 5:30now this module enables the enterprise
- 5:33to use
- 5:34the internet and partner resources
- 5:38and provides resources for its customers
- 5:43so quality of service service levels
- 5:46and security are the main issues
- 5:49in the enterprise edge
- 5:52okay so next would be the cisco
- 5:54enterprise
- 5:55one and man and side to side vpn module
- 5:59which is also part of the enterprise
- 6:01edge
- 6:02okay now it offers the convergence of
- 6:06voice
- 6:06video and data services over a single
- 6:10communications or over single network
- 6:12which enables
- 6:14the enterprise to span a large
- 6:16geographic areas
- 6:18in cost effective manner so the quality
- 6:21of service
- 6:22granular service levels and
- 6:25comprehensive encryption options
- 6:28help ensure the secure delivery of high
- 6:30quality corporate
- 6:32voice video and data resources
- 6:35to all the corporate sites enabling
- 6:37staff to work productively
- 6:40and efficiently whenever they are
- 6:42located
- 6:44okay so security is provided
- 6:48with multi-service vpns both ipsec
- 6:51and mpls okay
- 6:55that is over a layer two or alleged
- 6:57three wide area networks
- 6:59have been spoke for full mesh topologies
- 7:04you also have the cisco enterprise data
- 7:07center
- 7:08okay or the enterprise data center
- 7:11architecture
- 7:13this is a cohesive adaptive network
- 7:16architecture
- 7:17that supports requirements for
- 7:19consolidation
- 7:21business continuance and security while
- 7:24enabling emerging service oriented
- 7:25architectures
- 7:27virtualization and on-demand computing
- 7:32now staff suppliers and customers can be
- 7:36provided with secure access to
- 7:38applications and resources
- 7:40simplifying and streamlining management
- 7:42and significantly reducing
- 7:44to overhead so redundant data centers
- 7:48provide backup using synchronous and
- 7:51asynchronous data
- 7:52and application replication which is
- 7:54very important in the design
- 7:57the network and devices offer server and
- 8:00application load balancing to maximize
- 8:02performance so this architecture
- 8:06allows the enterprise to scale without
- 8:09a major changes in the infrastructure or
- 8:12to the infrastructure
- 8:14so this module can be located either at
- 8:17the campus as a server farm
- 8:19or at a remote facility okay
- 8:23so the next one would be the cisco
- 8:25enterprise branch
- 8:27architecture so this allows enterprises
- 8:30to extend the head
- 8:31office applications and services such as
- 8:35security okay communications
- 8:38and advanced application performance to
- 8:41thousands of remote locations and users
- 8:44or to small group of branches
- 8:48so it integrates security switching
- 8:51network analysis
- 8:53caching and converged voice and video
- 8:55services
- 8:57into a series of integrated service
- 8:58routers or isrs
- 9:01that is located in the branch so that
- 9:03the enterprises
- 9:04can deploy new services without buying
- 9:08new routers
- 9:10so the architecture provides secure
- 9:12access to voice
- 9:14mission critical data and video
- 9:18applications
- 9:19anywhere anytime so advanced
- 9:23routing vpns redundant one links
- 9:28application content caching and local ip
- 9:31telephony
- 9:33processing features are available with
- 9:35high levels of resilience
- 9:37for all the branch offices so an
- 9:40optimized
- 9:41network leverages the one and lan
- 9:45to reduce traffic and save bandwidth and
- 9:48operational expenses
- 9:50so the enterprise can easily support
- 9:53branch offices
- 9:54with the capability to centrally
- 9:57configure
- 9:58monitor and manage devices located at
- 10:00the remote sites
- 10:02okay so the next one would be this
- 10:05enterprise teleworker architecture here
- 10:08okay so which allows enterprises to
- 10:10securely deliver
- 10:12voice and data services to remote small
- 10:16or home offices known as a small office
- 10:19home office or soho
- 10:21over a standard broadband access service
- 10:24providing a business resiliency solution
- 10:27for the enterprise and a flexible work
- 10:30environment for employees
- 10:33so centralized management minimizes the
- 10:35id support
- 10:36costs and robust integrated services
- 10:41of security which mitigates the unique
- 10:43security challenges
- 10:45of this environment so integrated
- 10:48security and identity
- 10:50based networking services enable the
- 10:53enterprise to extend
- 10:54campus security policies to the
- 10:56teleworker so teleworker are those
- 10:59working away from the office
- 11:02okay are we working away from
- 11:06the enterprise okay so these are
- 11:09working at home okay a work from home
- 11:13application okay so
- 11:16the staff can securely login to the
- 11:19network
- 11:19over and always on vpn and access or
- 11:23gain access to
- 11:24authorized applications and services
- 11:27from a single
- 11:28cost effective platform so productivity
- 11:31can be further enhanced by adding an
- 11:33iphone
- 11:34okay so thereby providing cost effective
- 11:36access to centralized ip communications
- 11:39with voice and unified messaging
- 11:42services
- 11:44so this architecture allows the network
- 11:46designer
- 11:47to focus on only a selected module
- 11:50and its functions so designers can
- 11:53describe
- 11:54each network application and service on
- 11:57a peer module
- 11:59basis and validate it as
- 12:03part of the complete enterprise network
- 12:05design
- 12:06so modules can be added to achieve
- 12:09scalability
- 12:10if necessary for example an organization
- 12:13can add
- 12:14more enterprise campus okay
- 12:18if it has more than one campus
- 12:26let's have an example here of dividing
- 12:28the network into areas
- 12:30so the figure shows an example of
- 12:32dividing network
- 12:34into an enterprise campus area
- 12:37an enterprise campus edge
- 12:40and some remote areas
- 12:46enterprise campus infrastructure module
- 12:50so the following section provide
- 12:52additional details about each of the
- 12:54functional areas
- 12:56and their modules okay
- 12:59so let's start with the enterprise
- 13:02campus
- 13:03modules so this section introduces
- 13:06the enterprise campus functional area
- 13:10and describes the purpose of each module
- 13:13they're in
- 13:14it also discusses connections with other
- 13:17modules
- 13:18okay so an enterprise campus site
- 13:21is a large site that is often the
- 13:24corporate headquarters
- 13:26or a major office so regional offices
- 13:30soho's and mobile workers
- 13:33might have to connect to the central
- 13:35campus for data in information
- 13:38so as illustrated here the enterprise
- 13:41campus
- 13:42functional area includes the campus
- 13:44infrastructure module
- 13:46and typically a server farm module
- 13:51okay now let's dig in into
- 13:55the campus infrastructure module
- 13:58all right so the campus infrastructure
- 14:00module design consists of
- 14:02several buildings connected across a
- 14:04campus core
- 14:06so the campus infrastructure module
- 14:08connects devices
- 14:09within a campus to the server farm
- 14:13okay across the campus core
- 14:17okay so that is basically a single
- 14:20building
- 14:21in a campus infrastructure design
- 14:22contains a building access layer
- 14:25and a building distribution layer
- 14:28okay so when more buildings are added to
- 14:31the campus infrastructure
- 14:33a backbone or campus core layer is added
- 14:36between buildings
- 14:37so the campus infrastructure module
- 14:40includes three layers okay so basically
- 14:44you've got the building access layer
- 14:46you've got the building distribution
- 14:48layer
- 14:49and you've got the campus core layer
- 14:53so take note that in most general model
- 14:57the building access layer uses layer 2
- 14:59switching
- 15:01and the building distribution layer uses
- 15:04layer 3 switching or the multi-layer
- 15:06switching
- 15:10building access layer so the building
- 15:12access layer
- 15:14located within a campus building
- 15:16aggregates
- 15:17end users from different work groups
- 15:20and provides uplinks to the building
- 15:23distribution layer
- 15:25so it contains end user devices such as
- 15:29workstations iphones
- 15:32you also have network printers connected
- 15:34to layer 2 access switches
- 15:37vlans okay what else
- 15:40uh stp might also be supported
- 15:44so the building access layer provides
- 15:46important services such as
- 15:47broadcast suppression protocol filtering
- 15:50network access ip multicast and the
- 15:53quality of service
- 15:55so for high availability the access
- 15:58switches
- 15:59are dual attached to the distribution
- 16:02layer switches
- 16:04so the building access layer might also
- 16:06provide a poe
- 16:08or the power over internet and auxiliary
- 16:10vlans
- 16:11to support voice services
- 16:16building distribution layer the building
- 16:19distribution layer aggregates
- 16:21the wiring closets within a building and
- 16:24provides connectivity
- 16:26to the campus core so it provides
- 16:29aggregation of the access layer networks
- 16:32using multi-layer switching
- 16:34the building distribution layer performs
- 16:36routing
- 16:38the quality of service and access
- 16:40control
- 16:41so requests for data flow into the
- 16:44multi-layer switches and onward into the
- 16:46campus core layer
- 16:48responses follow the reverse path
- 16:51so redundancy and load balancing with
- 16:54the building access and campus core
- 16:56layer
- 16:57are recommended for example
- 17:01in the figure the building distribution
- 17:03layer has to equal
- 17:04cost paths into the campus core
- 17:08okay so that is providing
- 17:12fast failure recovery because each
- 17:15distribution switch
- 17:16maintains a two equal cost path
- 17:19in each routing table to every
- 17:22destination network
- 17:24so if one of the connection to the
- 17:25campus core layer fails
- 17:28all routes immediately switch over
- 17:31to the remaining path
- 17:36campus core layer so the campus core
- 17:39layer
- 17:40is the core layer of the campus
- 17:41infrastructure module
- 17:44so within the enterprise campus
- 17:45functional area
- 17:47this high performance switch backbone
- 17:50connects the buildings
- 17:52and various parts of the campus so
- 17:55specifically
- 17:56this layer interconnects the building
- 17:58distribution layer
- 17:59with the server form and the enterprise
- 18:02edge modules so the campus core layer
- 18:07of the campus infrastructure module
- 18:09provides redundant and fast converging
- 18:11connectivity
- 18:13between buildings and with the server
- 18:15farm
- 18:16okay and enterprise edge modules
- 18:20so it routes and switches traffic as
- 18:22quickly as possible
- 18:24from one module to another so this
- 18:27modules usually uses a multi-layer
- 18:31switches
- 18:32for high throughput functions with added
- 18:35routing quality of service and
- 18:39security features
- 18:43server farm module so basically the
- 18:45servers are located on this module
- 18:47so this is a high capacity centralized
- 18:50server for module
- 18:51which provides users with internal
- 18:53server resources
- 18:55so in addition it typically supports
- 18:58network management services
- 19:00for the enterprise including monitoring
- 19:03logging and other common management
- 19:07features
- 19:08from an end to end so the server farm
- 19:11module typically contains internal email
- 19:14and other corporate servers that provide
- 19:18internal users with application
- 19:21file print email and domain name systems
- 19:25or dns services
- 19:27so as shown in the figure here because
- 19:30access to these servers is by
- 19:33as a best practice they are typically
- 19:35connected to two different switches
- 19:38to enable full redundancy or load
- 19:41sharing okay so moreover
- 19:45the server for module switches are
- 19:48cross-connected to the campus core
- 19:51okay so thereby enabling high
- 19:53reliability and availability
- 19:56for all servers in the server farm
- 19:58module
- 19:59so the network management system
- 20:00performs system logging
- 20:02network monitoring and general
- 20:05configuration management functions
- 20:08so for management purposes
- 20:11so an out of band network connection
- 20:14so basically that is a network on which
- 20:16no production traffic travels
- 20:19to all network components is recommended
- 20:22so for locations where an out of bound
- 20:25network is impossible so because of
- 20:27geographic
- 20:28or system related issues maybe so the
- 20:31network management system uses
- 20:33the production network so the network
- 20:37management
- 20:37can provide configuration management for
- 20:40nearly
- 20:41all devices in the network so using a
- 20:44combination
- 20:45of two technologies okay
- 20:48so you can use the cisco ios routers
- 20:52that can act as terminal servers to
- 20:55provide a dedicated management network
- 20:57segment to console ports
- 20:59on the cisco devices throughout the
- 21:00enterprise by using a reverse
- 21:02telnet function okay so more
- 21:06extensive management features software
- 21:08changes
- 21:09content updates login alarm aggregation
- 21:13and snmp or the simple network
- 21:16management
- 21:16protocol can be provided through
- 21:19dedicated
- 21:20out of band management network segment
- 21:28enterprise campus guidelines so we need
- 21:32to follow these guidelines for creating
- 21:34the modules
- 21:35within an enterprise campus functional
- 21:37area
- 21:39so first select modules
- 21:42within the campus that act as buildings
- 21:45with access and distribution layers
- 21:48second
- 21:49determine the locations and the number
- 21:51of access switches
- 21:53and their uplinks to distribution layer
- 21:55switches
- 21:57okay so third select the appropriate
- 22:00distribution layer switches
- 22:02taking into account the number of access
- 22:04layer switches and end users
- 22:07so use at least two distribution layer
- 22:10switches
- 22:11for redundancy fourth
- 22:15consider two uplink connections from
- 22:17each access layer switch
- 22:19to the distribution layer switches
- 22:23okay so step 5 determine where servers
- 22:27are or will be located so
- 22:30and you have the design the server form
- 22:32module
- 22:33with at least two distribution layer
- 22:35switches that connect
- 22:37all servers okay so that is to eliminate
- 22:40the possibility of down times
- 22:43sixth design the campus infrastructure
- 22:45module campus core layer using at least
- 22:48two switches and provide for the
- 22:51expected traffic volume between modules
- 22:55and then the last one would be of course
- 22:56you have to interconnect all the modules
- 22:59of the enterprise campus with the campus
- 23:02infrastructure module campus core layer
- 23:05in a redundant manner
- 23:10enterprise edge modules so this section
- 23:14describes the components of the
- 23:16enterprise
- 23:16edge and explains the importance of
- 23:20each module so the enterprise
- 23:23edge infrastructure modules aggregates
- 23:26the connectivity from various elements
- 23:28outside the campus okay so using various
- 23:31services
- 23:32and wide area technologies as needed
- 23:35okay so this typically provision from
- 23:38service providers
- 23:40and route the traffic into a campus core
- 23:42layer
- 23:43so the enterprise edge module perform
- 23:47security functions when enterprise
- 23:49resources connect across
- 23:50public networks and the internet
- 23:53so as shown in the figure okay and in
- 23:56the following list
- 23:58the enterprise edge functional area is
- 24:00composed of four
- 24:02main modules you've got the
- 24:05e-commerce module the
- 24:08internet connectivity module the remote
- 24:12access and vpn module and you've got the
- 24:16one and man and cytoside vpn module
- 24:21now for the e-commerce module
- 24:24okay so what it does is so basically
- 24:28the e-commerce module includes the
- 24:30devices and services
- 24:32necessary for an organization to provide
- 24:36an e-commerce applications
- 24:38so the web server should be there okay
- 24:41so you also have the internet
- 24:42connectivity module
- 24:44so the internet connectivity module
- 24:46provides enterprise
- 24:47users with internet access
- 24:51so that is where your isp
- 24:54you should have at least two isps okay
- 24:57so to connect to your internet
- 24:59connectivity module
- 25:00that is to provide redundancy if one of
- 25:03the isp
- 25:04accidentally goes down so
- 25:07third would be the remote access and vpn
- 25:09module
- 25:10this module terminates vpn traffic and
- 25:13dial in connections
- 25:15from external users okay
- 25:18and the last one would be the one and
- 25:21man
- 25:21and cytoside vpn module which provides
- 25:25connectivity
- 25:26between remote sites and the central
- 25:29side
- 25:30over various one technologies so frame
- 25:33relay
- 25:34is nearly obsolete so we have new
- 25:38technologies coming in
- 25:39and you can use that to connect on this
- 25:42one and man and side to side vpn module
- 25:47now this modules connect to the campus
- 25:50core directly
- 25:51or through an optional edge distribution
- 25:53module
- 25:55the optional distribution
- 26:00or edge distribution module aggregates
- 26:02the connectivity
- 26:03from various elements at the enterprise
- 26:07edge
- 26:08and draws the traffic into the campus
- 26:10board
- 26:11okay now in addition the edge
- 26:15distribution module
- 26:16acts as a boundary between the
- 26:18enterprise campus
- 26:19and enterprise edge and is the last line
- 26:23of defense against external attacks
- 26:26so each structure is similar to that of
- 26:28a building distribution layer
- 26:34e-commerce module so the e-commerce
- 26:36module enables
- 26:38enterprises to successfully deploy an
- 26:40e-commerce applications
- 26:42and take advantage of the opportunities
- 26:44of the internet
- 26:45provides okay so the major
- 26:49or the majority of the traffic is
- 26:50initiated external
- 26:52to the enterprise so all e-commerce
- 26:56transactions
- 26:58pass through a series of intelligent
- 27:00services that provide scalability
- 27:03security and high availability
- 27:06within the overall ecommerce network
- 27:08design
- 27:10so to build a successful e-commerce
- 27:12solution
- 27:13the following network devices might be
- 27:15included
- 27:17okay so basically you've got the web
- 27:19servers okay
- 27:20so act as the primary user interface for
- 27:24an e-commerce navigation
- 27:26so you might have also an application
- 27:29servers
- 27:30okay so which hosts various applications
- 27:33database servers
- 27:35okay should be there also which contains
- 27:38the application and transaction
- 27:39information that is the heart
- 27:41of the e-commerce business
- 27:43implementation and
- 27:44also there should be firewall or
- 27:47firewall routers
- 27:48okay so govern communication and provide
- 27:51security between the systems of various
- 27:54users
- 27:56also there should be a network intrusion
- 27:58detection system
- 27:59for the ips the intrusion prevention
- 28:02system
- 28:03okay so which monitors key network
- 28:06segments
- 28:07in the module to detect and respond to
- 28:10attacks
- 28:11against the network so you could also
- 28:14have the multi-layer switch
- 28:16with ids or ips okay so ids is
- 28:20nearly obsolete okay and
- 28:23mostly nowadays we are using the ips or
- 28:25the intrusion prevention system
- 28:28which provides traffic transport and
- 28:31integrated security monitoring
- 28:34you could also have the host based
- 28:37intrusion
- 28:38prevention systems deployed on
- 28:41sensitive core application servers and
- 28:44on dedicated
- 28:45appliances to provide
- 28:48uh real-time reporting and
- 28:51prevention of attacks as an extra layer
- 28:54of
- 28:55defense also
- 28:59next would be internet connectivity
- 29:01module
- 29:02okay now the internet connectivity
- 29:05module provides internal users
- 29:07with connectivity to internet services
- 29:09such as
- 29:11http https ftp
- 29:15or the simple mail transfer protocol
- 29:17smtp and dns
- 29:19so this module also provides internet
- 29:22users with access to information
- 29:24published
- 29:25on the enterprise public servers such as
- 29:27http
- 29:28and ftp servers
- 29:32so internet session initiation is
- 29:34typically from
- 29:35inside the enterprise towards the
- 29:37internet okay
- 29:38so additionally this module accepts
- 29:42vpn traffic from remote users
- 29:45and remote sites and forwards
- 29:48it to the remote access and vpn module
- 29:52where vpn termination takes place
- 29:56okay so the internet connectivity module
- 29:59is not designed to serve e-commerce
- 30:02applications
- 30:03so major components used in the internet
- 30:06connectivity module includes the
- 30:08following
- 30:09so as what i have mentioned earlier
- 30:11you've got some sort of the smtp mail
- 30:13servers
- 30:14okay this would act as a relay between
- 30:17the internet
- 30:18and the internet mail servers you also
- 30:21have the dns
- 30:23servers so serves as authoritative
- 30:26external dns server
- 30:28for the enterprise and relay internal
- 30:30dns requests
- 30:32to the internet so also
- 30:35you've got public servers for example
- 30:37the ftp
- 30:38and http or https which
- 30:41provide public information about
- 30:44organization
- 30:46each server on the public services
- 30:48segment contains
- 30:50host based intrusion detection system
- 30:53or the hids to
- 30:56monitor against any rogue activity at
- 30:59the operating system level
- 31:00and in common server application
- 31:03including http
- 31:05ftp and smtp
- 31:08also you could implement some firewall
- 31:10here okay firewalls or
- 31:12firewall routers so provide network
- 31:14level protection of
- 31:16resources provide stateful filtering of
- 31:19traffic
- 31:20and forward vpn traffic from remote
- 31:22sites
- 31:23and users for terminations
- 31:26so edge routers provide
- 31:30base basic filtering and multi-layer
- 31:33connectivity to the internet
- 31:35so again security should be considered
- 31:39on all of these modules here
- 31:42remote access and vpn module so the
- 31:46remote access and vpn module terminates
- 31:48remote access traffic
- 31:50and vpn traffic that the internet
- 31:52connectivity module
- 31:53forwards from remote users and remote
- 31:56sites
- 31:57so it also uses the internet
- 31:59connectivity module to initiate
- 32:01vpn connections to remote sites so
- 32:04furthermore
- 32:05this module terminates a dial in
- 32:07connection received
- 32:09from the public switch telephone network
- 32:11or the pstn
- 32:13okay so and after successful
- 32:15authentication
- 32:17grants dial in service or user access
- 32:20to the network so basically
- 32:24the remote access and vpn module
- 32:26consists of major components
- 32:28like the dial in access concentrators
- 32:32you also have the adaptive security
- 32:34appliances or asa
- 32:36firewalls okay and you've got some sort
- 32:40of an
- 32:40ips appliances
- 32:47one and man and side to side vpn module
- 32:51so the man and one and side to side
- 32:54vpn module uses various one technologies
- 32:57including cytoside vpns
- 33:00to route traffic between remote sites
- 33:02and the central side
- 33:04so in addition so we could have
- 33:08the list lines okay so circuit switch
- 33:11data link technologies
- 33:13like the old frame relay and the atm
- 33:16which are already
- 33:17obsolete so this module can use more
- 33:20recent
- 33:21one physical layer technologies okay
- 33:24so something like the synchronous
- 33:27optical network
- 33:28or the synchronous digital hierarchy or
- 33:30sdh
- 33:31cable dsl fiber to home
- 33:35their fiber mpls and metro internet
- 33:38it could also include wireless and
- 33:42service provider vpns
- 33:45so basically this module incorporates
- 33:49all cisco devices
- 33:51and even nancy devices that support
- 33:53these one technologies
- 33:55and routing access control and quality
- 33:58of service mechanisms
- 34:00so although security is not a critical
- 34:02when all links are
- 34:03owned by the enterprise it should be
- 34:06considered
- 34:07in the network design okay so the key
- 34:10point here is
- 34:12the man or the metropolitan area network
- 34:16and the one or the wide area network
- 34:19and the cytoside virtual private network
- 34:21module
- 34:22does not include the one connections or
- 34:26links
- 34:27it provides only interfaces to the one
- 34:33enterprise edge guidelines
- 34:35so you need to follow these guidelines
- 34:37for creating
- 34:39the modules within the enterprise edge
- 34:41of functional areas
- 34:42okay so first create the e-commerce
- 34:46module
- 34:46for business to business or business to
- 34:48customer scenarios
- 34:50when customers or partners require
- 34:52internet access to business applications
- 34:54and database servers
- 34:56so deploy a high security policy
- 34:59that allows customers to access
- 35:02predefined servers
- 35:04and services yet restricts all other
- 35:07operations
- 35:09okay so second you need to determine
- 35:13the connections from the corporate
- 35:15network into the internet
- 35:17and assign them to the internet
- 35:20connectivity module
- 35:22so this module should implement security
- 35:25to prevent
- 35:26any unauthorized access from the
- 35:28internet
- 35:29to the internal network so public web
- 35:33servers
- 35:33reside in this module or the e-commerce
- 35:37module
- 35:39third is design the remote access and
- 35:42vpn module if the enterprise
- 35:44requires vpn connections or
- 35:47dial in or accessing the internal
- 35:50network from
- 35:51the outside world so implement the
- 35:54security policy on this module
- 35:56okay so users should be able to access
- 35:59the internal network directly
- 36:02without authentication and authorization
- 36:05so the vpn sessions use connectivity
- 36:09from the internet connectivity module
- 36:12okay so next would be determine
- 36:15which part of the edge is used
- 36:17exclusively
- 36:19for permanent connections to remote
- 36:21locations
- 36:22such as branch offices and
- 36:26assign it to the one and man and side to
- 36:29side
- 36:29vpn module all one devices supporting
- 36:33frame relay
- 36:35atm cable mpls
- 36:38list lines sony sdh and so on
- 36:41are located here
- 36:46service provider modules
- 36:49so service provider modules as shown
- 36:52here on this figure
- 36:54shows the modules within the service
- 36:56provider functional area
- 36:58the enterprise itself does not implement
- 37:01these
- 37:01modules however they are necessary to
- 37:04enable communication
- 37:06with other networks using a variety of
- 37:09one technologies
- 37:11and with internet service providers or
- 37:14the isp
- 37:16the modules within the service provider
- 37:19functional area
- 37:20are as follows so basically you've got
- 37:23the internet service provider module or
- 37:25the isp module
- 37:27you've got the pstn module okay
- 37:30and you've got the one technology module
- 37:33here so it could be again
- 37:35a newer technology other than frame
- 37:38relay and atm which are already obsolete
- 37:42now the internet service provider
- 37:46module the internet service provider
- 37:49module represents enterprise ip
- 37:51connectivity to an isp network
- 37:53for basic access to the internet or for
- 37:56enabling enterprise ad services such as
- 37:59those in the e-commerce okay remote
- 38:02access
- 38:03and vpn and internet connectivity
- 38:05modules
- 38:07so enterprises can connect to two or
- 38:10more isps
- 38:11to provide redundant connections to the
- 38:14internet
- 38:15so the physical connection between the
- 38:17isp and the enterprise can now use
- 38:19any of the one technologies available on
- 38:23your work area
- 38:25next would be the pstn module so the
- 38:28pstn module represents the dial dial-up
- 38:31infrastructure
- 38:32for accessing the enterprise network
- 38:34using isdn
- 38:35analog and wireless telephony or the
- 38:37cellular technologies
- 38:39so enterprises can also use this
- 38:42infrastructure
- 38:43to back up existing one links one backup
- 38:46connections
- 38:48are generally established on demand
- 38:51and turned down after the idle timeout
- 38:55okay so next would be
- 38:58this frame relay and atm module or shall
- 39:01i call it the one
- 39:03technology module okay so the
- 39:06traditional frame relay and atm are
- 39:08still
- 39:08used by some organization or by some
- 39:11countries however
- 39:12despite the module's name it also
- 39:14represents
- 39:15many modern technologies that's why i
- 39:17call this the one technology
- 39:20module okay so this could include
- 39:23any one technology available on your
- 39:26work area
- 39:30enterprise remote modules so the three
- 39:34modules supporting remote enterprise
- 39:36locations are the enterprise branch
- 39:40the enterprise data center and the
- 39:43enterprise
- 39:47now the enterprise branch module extends
- 39:51the enterprise by providing its location
- 39:55with a resilient network architecture
- 39:58with integrated security
- 40:00communications and wireless mobility
- 40:04so any branch office generally
- 40:06accommodates
- 40:07employees who have a compelling reasons
- 40:11to be located away from the central side
- 40:13such as
- 40:14regional sales office okay now the
- 40:18branch office
- 40:19is sometimes called the remote site or
- 40:22remote office or maybe sales office
- 40:26so branch office users must be able to
- 40:29connect to the central site
- 40:30to access company information therefore
- 40:34they benefit from high-speed internet
- 40:37access
- 40:38vpn connectivity to corporate extranet
- 40:41or
- 40:41internet telecommuting capabilities
- 40:44for work at home employees okay also
- 40:48video conferencing
- 40:50and economical psd and quality voice and
- 40:52fax
- 40:53calls over a managed type networks or
- 40:56you'll have this voip implementation
- 41:00okay so the enterprise branch module is
- 41:03typically
- 41:04or this one typically uses a simplified
- 41:07version
- 41:08of the campus infrastructure module
- 41:11design
- 41:13now let's focus on the enterprise data
- 41:16center module here
- 41:18the enterprise data center module has an
- 41:20architecture that is similar to
- 41:23campus server farm module as discussed
- 41:26earlier
- 41:27okay so the enterprise data center
- 41:30network architecture allows the network
- 41:32to evolve
- 41:33into a platform that enhances the
- 41:36application
- 41:37server and storage solutions
- 41:40and equips organization to manage
- 41:43increased security cost and
- 41:47regulatory requirements while providing
- 41:50the ability to respond quickly
- 41:52to changing business environments
- 41:55so the enterprise data center module may
- 41:57include
- 41:58the following components so maybe you'll
- 42:01have
- 42:02something like at the interactive
- 42:05service layer
- 42:06and at the management layer okay
- 42:10so take note that at the network
- 42:14infrastructure layer
- 42:16the gigabit ethernet okay or 10g
- 42:19or infiniband connections with storage
- 42:21switching and optical transport devices
- 42:24so if you have heard of infiniband that
- 42:27is basically the term used on high
- 42:28high-speed switch
- 42:30fabric mesh technology okay so this is
- 42:33used in
- 42:34the storage area network
- 42:37now on the interactive services layer
- 42:41services include storage fabric services
- 42:44computer services security services
- 42:46and application optimization services
- 42:49okay and at the management layer tools
- 42:52include
- 42:53fabric manager okay so for element and
- 42:55network management
- 42:57or you also have the v frame for server
- 43:00and service
- 43:01provisioning so the remote enterprise
- 43:04data center module
- 43:06includes highly available one
- 43:08connectivity
- 43:09with business continuance capabilities
- 43:12to integrate it
- 43:13with the rest of the enterprise
- 43:15architecture
- 43:16so the server farm module in the campus
- 43:19can leverage
- 43:21the one connectivity of the campus core
- 43:24but the remote enterprise data center
- 43:27must implement
- 43:28its own one connectivity
- 43:33next would be the enterprise teleworker
- 43:37so enterprise teleworker module provides
- 43:40people
- 43:40in geographically dispersed locations
- 43:43such as
- 43:44home offices or hotels with highly
- 43:47secure
- 43:48access to central site applications and
- 43:50network services
- 43:52the enterprise teleworker module
- 43:54supports a small office
- 43:56with one several employees or
- 43:59home office of a telecommuter
- 44:02so telecommuters might also be mobile
- 44:05users
- 44:07people who need to access while
- 44:09traveling
- 44:10or who do not work
- 44:13at a fixed company site
- 44:17okay so depending on the amount of use
- 44:20and the one services available
- 44:22telecommuters working from home tend to
- 44:25use
- 44:25broadband or worst dial-up services
- 44:30if the broadband is not available
- 44:33so mobile users tend to access the
- 44:35company network using
- 44:37broadband internet service and the vpn
- 44:40client software on their laptops
- 44:42or via a synchronous dial up connection
- 44:45through the telephone company so
- 44:49computers
- 44:49working from home might also use a vpn
- 44:53channel gateway router
- 44:55for encrypted data and voice traffic
- 44:58to and from the network
- 45:03so to summarize based on
- 45:06the sauna the cisco enterprise
- 45:08architecture provides
- 45:10a modular enterprise-wide hierarchical
- 45:13approach
- 45:14for providing network infrastructure and
- 45:17services
- 45:18to all the places in the network
- 45:22okay so the enterprise campus
- 45:24infrastructure module includes the
- 45:26campus infrastructure module
- 45:28and the server farm module so the
- 45:31enterprise
- 45:32edge modules includes the
- 45:35e-commerce module the internet
- 45:37connectivity module
- 45:39the remote access and vpn module
- 45:42and the one and man and cyber site
- 45:45modules
- 45:46so the remote enterprise modules
- 45:49includes the remote branches
- 45:51data centers and teleworkers
About this transcript
This page contains the full transcript of Structuring and Modularizing the Network Part 2 by Santelmo, generated from the public captions YouTube serves with the video. The transcript has 4,995 words across 1,109 segments, with the original timestamps preserved so you can click any line to jump to that moment in the embedded player.
What you can do with it
Use the transcript to take notes, quote the speaker, build a study guide, generate a summary with ChatGPT or Claude via the YouTube Summary tool, or export it as a timed subtitle file with YouTube to SRT. You can also re-open it in the transcriber to translate the transcript into 100+ languages.
Free YouTube transcript tool
YouTube2Text is a free YouTube transcript generator — no signup, no daily limit. Paste any YouTube link and get the full transcript instantly, with timestamps, click-to-jump, translation to 100+ languages, AI prompts for ChatGPT, Claude, and Gemini, and exports to TXT, SRT, VTT, or Markdown.