YouTube2Text

Structuring and Modularizing the Network Part 2 — Transcript

by Santelmo · 4,995 words · 1,109 segments · language en · Watch on YouTube

Full transcript

  1. 0:04using a modular approach
  2. 0:06in network design
  3. 0:10this section expands on the cisco
  4. 0:13service oriented network architecture
  5. 0:16or the sona framework described in
  6. 0:19applying a methodology to a design
  7. 0:21video and explores the six modules of
  8. 0:24the cisco enterprise architecture
  9. 0:26with an emphasis on the network
  10. 0:28infrastructure design considerations
  11. 0:31now the modularity built into the
  12. 0:33architecture
  13. 0:34allows flexibility in network design
  14. 0:37and facilitates implementation and
  15. 0:39troubleshooting
  16. 0:43let's start with the cisco oriented
  17. 0:45network architecture or the sona
  18. 0:47so as illustrated here in the figure the
  19. 0:50cisco sona provides an enterprise
  20. 0:52wide framework that integrates the
  21. 0:55entire
  22. 0:56network so that includes the campus
  23. 0:59data center enterprise edge
  24. 1:02one branches and teleworkers
  25. 1:05so that offering staff secure access to
  26. 1:09the tools
  27. 1:10processes and service they require
  28. 1:16now the modules of the cisco enterprise
  29. 1:18architecture represent
  30. 1:20focused views on each of the places
  31. 1:23in the network described in the sona
  32. 1:25framework
  33. 1:27so each module has a distinct network
  34. 1:30infrastructure
  35. 1:31and distinct services network
  36. 1:34applications
  37. 1:35extend between the modules
  38. 1:39let's talk about the cisco enterprise
  39. 1:41architecture
  40. 1:43so the functional areas of the cisco
  41. 1:45enterprise
  42. 1:46architecture so at the first layer
  43. 1:49of the modularity in the cisco
  44. 1:51enterprise architecture
  45. 1:53the entire network is divided into
  46. 1:55functional components
  47. 1:57so functional areas that contain
  48. 2:00network modules while still maintaining
  49. 2:03the hierarchical concept
  50. 2:05of the core distribution and access
  51. 2:08layers
  52. 2:09with the network okay so take note that
  53. 2:13the access distribution and core layers
  54. 2:16can appear in any functional area or
  55. 2:19module
  56. 2:20of the cisco enterprise architecture so
  57. 2:23the cisco enterprise architecture
  58. 2:25comprises of
  59. 2:26the following six major functional
  60. 2:29areas also called as modules
  61. 2:32okay so this includes the enterprise uh
  62. 2:34campus
  63. 2:36the enterprise edge the
  64. 2:40service provider okay so service
  65. 2:43provider
  66. 2:44one in internet here you also have the
  67. 2:47enterprise branch the
  68. 2:51enterprise data center and the
  69. 2:54enterprise
  70. 2:55teleworker so the figure illustrates
  71. 2:59the modules within the cisco enterprise
  72. 3:03architecture now the key point here is
  73. 3:07an enterprise does not implement the
  74. 3:09modules
  75. 3:10in the service provider functional area
  76. 3:14they are necessary for enabling
  77. 3:15communication
  78. 3:17with the other networks so the cisco
  79. 3:20enterprise campus architecture
  80. 3:22combines a core infrastructure of
  81. 3:25intelligent switching and routing
  82. 3:27with tightly integrated productivity
  83. 3:29enhancing technologies
  84. 3:31including mobility
  85. 3:35and advanced security so the
  86. 3:38architecture provides
  87. 3:39the enterprise with high availability
  88. 3:42through a resilient multi-layer design
  89. 3:45redundant
  90. 3:46hardware and software features and
  91. 3:48automatic procedures
  92. 3:50for a configuring network path when
  93. 3:53failure occurs
  94. 3:55so also you've got the ip multicast
  95. 3:59capabilities
  96. 4:00provide optimized bandwidth consumption
  97. 4:03and the quality of service features
  98. 4:05ensure that real-time traffic
  99. 4:08such as voice video or critical data
  100. 4:12is not dropped or delayed
  101. 4:15so integrated security protects against
  102. 4:18and mitigates the impact of worms
  103. 4:22viruses and other attacks on the network
  104. 4:25including
  105. 4:26the switchboard level so for example
  106. 4:30the cisco enterprise-wide architecture
  107. 4:33extends support
  108. 4:34for security standards such as the ieee
  109. 4:38802.1x
  110. 4:40port based network access control
  111. 4:43standard
  112. 4:44and the extensible authentication
  113. 4:46protocol or eap
  114. 4:49it also provides the flexibility to add
  115. 4:52internet protocol security or ipsec
  116. 4:55and mpls virtual private networks
  117. 4:58vpn identify and access management
  118. 5:03and vlans to compartmentalize
  119. 5:06access these features help improve
  120. 5:10performance and security
  121. 5:12while decreasing costs
  122. 5:15okay now let's talk about the cisco
  123. 5:18enterprise
  124. 5:18edge architecture here it offers
  125. 5:22connectivity to voice
  126. 5:25okay video and data services outside
  127. 5:28enterprise
  128. 5:30now this module enables the enterprise
  129. 5:33to use
  130. 5:34the internet and partner resources
  131. 5:38and provides resources for its customers
  132. 5:43so quality of service service levels
  133. 5:46and security are the main issues
  134. 5:49in the enterprise edge
  135. 5:52okay so next would be the cisco
  136. 5:54enterprise
  137. 5:55one and man and side to side vpn module
  138. 5:59which is also part of the enterprise
  139. 6:01edge
  140. 6:02okay now it offers the convergence of
  141. 6:06voice
  142. 6:06video and data services over a single
  143. 6:10communications or over single network
  144. 6:12which enables
  145. 6:14the enterprise to span a large
  146. 6:16geographic areas
  147. 6:18in cost effective manner so the quality
  148. 6:21of service
  149. 6:22granular service levels and
  150. 6:25comprehensive encryption options
  151. 6:28help ensure the secure delivery of high
  152. 6:30quality corporate
  153. 6:32voice video and data resources
  154. 6:35to all the corporate sites enabling
  155. 6:37staff to work productively
  156. 6:40and efficiently whenever they are
  157. 6:42located
  158. 6:44okay so security is provided
  159. 6:48with multi-service vpns both ipsec
  160. 6:51and mpls okay
  161. 6:55that is over a layer two or alleged
  162. 6:57three wide area networks
  163. 6:59have been spoke for full mesh topologies
  164. 7:04you also have the cisco enterprise data
  165. 7:07center
  166. 7:08okay or the enterprise data center
  167. 7:11architecture
  168. 7:13this is a cohesive adaptive network
  169. 7:16architecture
  170. 7:17that supports requirements for
  171. 7:19consolidation
  172. 7:21business continuance and security while
  173. 7:24enabling emerging service oriented
  174. 7:25architectures
  175. 7:27virtualization and on-demand computing
  176. 7:32now staff suppliers and customers can be
  177. 7:36provided with secure access to
  178. 7:38applications and resources
  179. 7:40simplifying and streamlining management
  180. 7:42and significantly reducing
  181. 7:44to overhead so redundant data centers
  182. 7:48provide backup using synchronous and
  183. 7:51asynchronous data
  184. 7:52and application replication which is
  185. 7:54very important in the design
  186. 7:57the network and devices offer server and
  187. 8:00application load balancing to maximize
  188. 8:02performance so this architecture
  189. 8:06allows the enterprise to scale without
  190. 8:09a major changes in the infrastructure or
  191. 8:12to the infrastructure
  192. 8:14so this module can be located either at
  193. 8:17the campus as a server farm
  194. 8:19or at a remote facility okay
  195. 8:23so the next one would be the cisco
  196. 8:25enterprise branch
  197. 8:27architecture so this allows enterprises
  198. 8:30to extend the head
  199. 8:31office applications and services such as
  200. 8:35security okay communications
  201. 8:38and advanced application performance to
  202. 8:41thousands of remote locations and users
  203. 8:44or to small group of branches
  204. 8:48so it integrates security switching
  205. 8:51network analysis
  206. 8:53caching and converged voice and video
  207. 8:55services
  208. 8:57into a series of integrated service
  209. 8:58routers or isrs
  210. 9:01that is located in the branch so that
  211. 9:03the enterprises
  212. 9:04can deploy new services without buying
  213. 9:08new routers
  214. 9:10so the architecture provides secure
  215. 9:12access to voice
  216. 9:14mission critical data and video
  217. 9:18applications
  218. 9:19anywhere anytime so advanced
  219. 9:23routing vpns redundant one links
  220. 9:28application content caching and local ip
  221. 9:31telephony
  222. 9:33processing features are available with
  223. 9:35high levels of resilience
  224. 9:37for all the branch offices so an
  225. 9:40optimized
  226. 9:41network leverages the one and lan
  227. 9:45to reduce traffic and save bandwidth and
  228. 9:48operational expenses
  229. 9:50so the enterprise can easily support
  230. 9:53branch offices
  231. 9:54with the capability to centrally
  232. 9:57configure
  233. 9:58monitor and manage devices located at
  234. 10:00the remote sites
  235. 10:02okay so the next one would be this
  236. 10:05enterprise teleworker architecture here
  237. 10:08okay so which allows enterprises to
  238. 10:10securely deliver
  239. 10:12voice and data services to remote small
  240. 10:16or home offices known as a small office
  241. 10:19home office or soho
  242. 10:21over a standard broadband access service
  243. 10:24providing a business resiliency solution
  244. 10:27for the enterprise and a flexible work
  245. 10:30environment for employees
  246. 10:33so centralized management minimizes the
  247. 10:35id support
  248. 10:36costs and robust integrated services
  249. 10:41of security which mitigates the unique
  250. 10:43security challenges
  251. 10:45of this environment so integrated
  252. 10:48security and identity
  253. 10:50based networking services enable the
  254. 10:53enterprise to extend
  255. 10:54campus security policies to the
  256. 10:56teleworker so teleworker are those
  257. 10:59working away from the office
  258. 11:02okay are we working away from
  259. 11:06the enterprise okay so these are
  260. 11:09working at home okay a work from home
  261. 11:13application okay so
  262. 11:16the staff can securely login to the
  263. 11:19network
  264. 11:19over and always on vpn and access or
  265. 11:23gain access to
  266. 11:24authorized applications and services
  267. 11:27from a single
  268. 11:28cost effective platform so productivity
  269. 11:31can be further enhanced by adding an
  270. 11:33iphone
  271. 11:34okay so thereby providing cost effective
  272. 11:36access to centralized ip communications
  273. 11:39with voice and unified messaging
  274. 11:42services
  275. 11:44so this architecture allows the network
  276. 11:46designer
  277. 11:47to focus on only a selected module
  278. 11:50and its functions so designers can
  279. 11:53describe
  280. 11:54each network application and service on
  281. 11:57a peer module
  282. 11:59basis and validate it as
  283. 12:03part of the complete enterprise network
  284. 12:05design
  285. 12:06so modules can be added to achieve
  286. 12:09scalability
  287. 12:10if necessary for example an organization
  288. 12:13can add
  289. 12:14more enterprise campus okay
  290. 12:18if it has more than one campus
  291. 12:26let's have an example here of dividing
  292. 12:28the network into areas
  293. 12:30so the figure shows an example of
  294. 12:32dividing network
  295. 12:34into an enterprise campus area
  296. 12:37an enterprise campus edge
  297. 12:40and some remote areas
  298. 12:46enterprise campus infrastructure module
  299. 12:50so the following section provide
  300. 12:52additional details about each of the
  301. 12:54functional areas
  302. 12:56and their modules okay
  303. 12:59so let's start with the enterprise
  304. 13:02campus
  305. 13:03modules so this section introduces
  306. 13:06the enterprise campus functional area
  307. 13:10and describes the purpose of each module
  308. 13:13they're in
  309. 13:14it also discusses connections with other
  310. 13:17modules
  311. 13:18okay so an enterprise campus site
  312. 13:21is a large site that is often the
  313. 13:24corporate headquarters
  314. 13:26or a major office so regional offices
  315. 13:30soho's and mobile workers
  316. 13:33might have to connect to the central
  317. 13:35campus for data in information
  318. 13:38so as illustrated here the enterprise
  319. 13:41campus
  320. 13:42functional area includes the campus
  321. 13:44infrastructure module
  322. 13:46and typically a server farm module
  323. 13:51okay now let's dig in into
  324. 13:55the campus infrastructure module
  325. 13:58all right so the campus infrastructure
  326. 14:00module design consists of
  327. 14:02several buildings connected across a
  328. 14:04campus core
  329. 14:06so the campus infrastructure module
  330. 14:08connects devices
  331. 14:09within a campus to the server farm
  332. 14:13okay across the campus core
  333. 14:17okay so that is basically a single
  334. 14:20building
  335. 14:21in a campus infrastructure design
  336. 14:22contains a building access layer
  337. 14:25and a building distribution layer
  338. 14:28okay so when more buildings are added to
  339. 14:31the campus infrastructure
  340. 14:33a backbone or campus core layer is added
  341. 14:36between buildings
  342. 14:37so the campus infrastructure module
  343. 14:40includes three layers okay so basically
  344. 14:44you've got the building access layer
  345. 14:46you've got the building distribution
  346. 14:48layer
  347. 14:49and you've got the campus core layer
  348. 14:53so take note that in most general model
  349. 14:57the building access layer uses layer 2
  350. 14:59switching
  351. 15:01and the building distribution layer uses
  352. 15:04layer 3 switching or the multi-layer
  353. 15:06switching
  354. 15:10building access layer so the building
  355. 15:12access layer
  356. 15:14located within a campus building
  357. 15:16aggregates
  358. 15:17end users from different work groups
  359. 15:20and provides uplinks to the building
  360. 15:23distribution layer
  361. 15:25so it contains end user devices such as
  362. 15:29workstations iphones
  363. 15:32you also have network printers connected
  364. 15:34to layer 2 access switches
  365. 15:37vlans okay what else
  366. 15:40uh stp might also be supported
  367. 15:44so the building access layer provides
  368. 15:46important services such as
  369. 15:47broadcast suppression protocol filtering
  370. 15:50network access ip multicast and the
  371. 15:53quality of service
  372. 15:55so for high availability the access
  373. 15:58switches
  374. 15:59are dual attached to the distribution
  375. 16:02layer switches
  376. 16:04so the building access layer might also
  377. 16:06provide a poe
  378. 16:08or the power over internet and auxiliary
  379. 16:10vlans
  380. 16:11to support voice services
  381. 16:16building distribution layer the building
  382. 16:19distribution layer aggregates
  383. 16:21the wiring closets within a building and
  384. 16:24provides connectivity
  385. 16:26to the campus core so it provides
  386. 16:29aggregation of the access layer networks
  387. 16:32using multi-layer switching
  388. 16:34the building distribution layer performs
  389. 16:36routing
  390. 16:38the quality of service and access
  391. 16:40control
  392. 16:41so requests for data flow into the
  393. 16:44multi-layer switches and onward into the
  394. 16:46campus core layer
  395. 16:48responses follow the reverse path
  396. 16:51so redundancy and load balancing with
  397. 16:54the building access and campus core
  398. 16:56layer
  399. 16:57are recommended for example
  400. 17:01in the figure the building distribution
  401. 17:03layer has to equal
  402. 17:04cost paths into the campus core
  403. 17:08okay so that is providing
  404. 17:12fast failure recovery because each
  405. 17:15distribution switch
  406. 17:16maintains a two equal cost path
  407. 17:19in each routing table to every
  408. 17:22destination network
  409. 17:24so if one of the connection to the
  410. 17:25campus core layer fails
  411. 17:28all routes immediately switch over
  412. 17:31to the remaining path
  413. 17:36campus core layer so the campus core
  414. 17:39layer
  415. 17:40is the core layer of the campus
  416. 17:41infrastructure module
  417. 17:44so within the enterprise campus
  418. 17:45functional area
  419. 17:47this high performance switch backbone
  420. 17:50connects the buildings
  421. 17:52and various parts of the campus so
  422. 17:55specifically
  423. 17:56this layer interconnects the building
  424. 17:58distribution layer
  425. 17:59with the server form and the enterprise
  426. 18:02edge modules so the campus core layer
  427. 18:07of the campus infrastructure module
  428. 18:09provides redundant and fast converging
  429. 18:11connectivity
  430. 18:13between buildings and with the server
  431. 18:15farm
  432. 18:16okay and enterprise edge modules
  433. 18:20so it routes and switches traffic as
  434. 18:22quickly as possible
  435. 18:24from one module to another so this
  436. 18:27modules usually uses a multi-layer
  437. 18:31switches
  438. 18:32for high throughput functions with added
  439. 18:35routing quality of service and
  440. 18:39security features
  441. 18:43server farm module so basically the
  442. 18:45servers are located on this module
  443. 18:47so this is a high capacity centralized
  444. 18:50server for module
  445. 18:51which provides users with internal
  446. 18:53server resources
  447. 18:55so in addition it typically supports
  448. 18:58network management services
  449. 19:00for the enterprise including monitoring
  450. 19:03logging and other common management
  451. 19:07features
  452. 19:08from an end to end so the server farm
  453. 19:11module typically contains internal email
  454. 19:14and other corporate servers that provide
  455. 19:18internal users with application
  456. 19:21file print email and domain name systems
  457. 19:25or dns services
  458. 19:27so as shown in the figure here because
  459. 19:30access to these servers is by
  460. 19:33as a best practice they are typically
  461. 19:35connected to two different switches
  462. 19:38to enable full redundancy or load
  463. 19:41sharing okay so moreover
  464. 19:45the server for module switches are
  465. 19:48cross-connected to the campus core
  466. 19:51okay so thereby enabling high
  467. 19:53reliability and availability
  468. 19:56for all servers in the server farm
  469. 19:58module
  470. 19:59so the network management system
  471. 20:00performs system logging
  472. 20:02network monitoring and general
  473. 20:05configuration management functions
  474. 20:08so for management purposes
  475. 20:11so an out of band network connection
  476. 20:14so basically that is a network on which
  477. 20:16no production traffic travels
  478. 20:19to all network components is recommended
  479. 20:22so for locations where an out of bound
  480. 20:25network is impossible so because of
  481. 20:27geographic
  482. 20:28or system related issues maybe so the
  483. 20:31network management system uses
  484. 20:33the production network so the network
  485. 20:37management
  486. 20:37can provide configuration management for
  487. 20:40nearly
  488. 20:41all devices in the network so using a
  489. 20:44combination
  490. 20:45of two technologies okay
  491. 20:48so you can use the cisco ios routers
  492. 20:52that can act as terminal servers to
  493. 20:55provide a dedicated management network
  494. 20:57segment to console ports
  495. 20:59on the cisco devices throughout the
  496. 21:00enterprise by using a reverse
  497. 21:02telnet function okay so more
  498. 21:06extensive management features software
  499. 21:08changes
  500. 21:09content updates login alarm aggregation
  501. 21:13and snmp or the simple network
  502. 21:16management
  503. 21:16protocol can be provided through
  504. 21:19dedicated
  505. 21:20out of band management network segment
  506. 21:28enterprise campus guidelines so we need
  507. 21:32to follow these guidelines for creating
  508. 21:34the modules
  509. 21:35within an enterprise campus functional
  510. 21:37area
  511. 21:39so first select modules
  512. 21:42within the campus that act as buildings
  513. 21:45with access and distribution layers
  514. 21:48second
  515. 21:49determine the locations and the number
  516. 21:51of access switches
  517. 21:53and their uplinks to distribution layer
  518. 21:55switches
  519. 21:57okay so third select the appropriate
  520. 22:00distribution layer switches
  521. 22:02taking into account the number of access
  522. 22:04layer switches and end users
  523. 22:07so use at least two distribution layer
  524. 22:10switches
  525. 22:11for redundancy fourth
  526. 22:15consider two uplink connections from
  527. 22:17each access layer switch
  528. 22:19to the distribution layer switches
  529. 22:23okay so step 5 determine where servers
  530. 22:27are or will be located so
  531. 22:30and you have the design the server form
  532. 22:32module
  533. 22:33with at least two distribution layer
  534. 22:35switches that connect
  535. 22:37all servers okay so that is to eliminate
  536. 22:40the possibility of down times
  537. 22:43sixth design the campus infrastructure
  538. 22:45module campus core layer using at least
  539. 22:48two switches and provide for the
  540. 22:51expected traffic volume between modules
  541. 22:55and then the last one would be of course
  542. 22:56you have to interconnect all the modules
  543. 22:59of the enterprise campus with the campus
  544. 23:02infrastructure module campus core layer
  545. 23:05in a redundant manner
  546. 23:10enterprise edge modules so this section
  547. 23:14describes the components of the
  548. 23:16enterprise
  549. 23:16edge and explains the importance of
  550. 23:20each module so the enterprise
  551. 23:23edge infrastructure modules aggregates
  552. 23:26the connectivity from various elements
  553. 23:28outside the campus okay so using various
  554. 23:31services
  555. 23:32and wide area technologies as needed
  556. 23:35okay so this typically provision from
  557. 23:38service providers
  558. 23:40and route the traffic into a campus core
  559. 23:42layer
  560. 23:43so the enterprise edge module perform
  561. 23:47security functions when enterprise
  562. 23:49resources connect across
  563. 23:50public networks and the internet
  564. 23:53so as shown in the figure okay and in
  565. 23:56the following list
  566. 23:58the enterprise edge functional area is
  567. 24:00composed of four
  568. 24:02main modules you've got the
  569. 24:05e-commerce module the
  570. 24:08internet connectivity module the remote
  571. 24:12access and vpn module and you've got the
  572. 24:16one and man and cytoside vpn module
  573. 24:21now for the e-commerce module
  574. 24:24okay so what it does is so basically
  575. 24:28the e-commerce module includes the
  576. 24:30devices and services
  577. 24:32necessary for an organization to provide
  578. 24:36an e-commerce applications
  579. 24:38so the web server should be there okay
  580. 24:41so you also have the internet
  581. 24:42connectivity module
  582. 24:44so the internet connectivity module
  583. 24:46provides enterprise
  584. 24:47users with internet access
  585. 24:51so that is where your isp
  586. 24:54you should have at least two isps okay
  587. 24:57so to connect to your internet
  588. 24:59connectivity module
  589. 25:00that is to provide redundancy if one of
  590. 25:03the isp
  591. 25:04accidentally goes down so
  592. 25:07third would be the remote access and vpn
  593. 25:09module
  594. 25:10this module terminates vpn traffic and
  595. 25:13dial in connections
  596. 25:15from external users okay
  597. 25:18and the last one would be the one and
  598. 25:21man
  599. 25:21and cytoside vpn module which provides
  600. 25:25connectivity
  601. 25:26between remote sites and the central
  602. 25:29side
  603. 25:30over various one technologies so frame
  604. 25:33relay
  605. 25:34is nearly obsolete so we have new
  606. 25:38technologies coming in
  607. 25:39and you can use that to connect on this
  608. 25:42one and man and side to side vpn module
  609. 25:47now this modules connect to the campus
  610. 25:50core directly
  611. 25:51or through an optional edge distribution
  612. 25:53module
  613. 25:55the optional distribution
  614. 26:00or edge distribution module aggregates
  615. 26:02the connectivity
  616. 26:03from various elements at the enterprise
  617. 26:07edge
  618. 26:08and draws the traffic into the campus
  619. 26:10board
  620. 26:11okay now in addition the edge
  621. 26:15distribution module
  622. 26:16acts as a boundary between the
  623. 26:18enterprise campus
  624. 26:19and enterprise edge and is the last line
  625. 26:23of defense against external attacks
  626. 26:26so each structure is similar to that of
  627. 26:28a building distribution layer
  628. 26:34e-commerce module so the e-commerce
  629. 26:36module enables
  630. 26:38enterprises to successfully deploy an
  631. 26:40e-commerce applications
  632. 26:42and take advantage of the opportunities
  633. 26:44of the internet
  634. 26:45provides okay so the major
  635. 26:49or the majority of the traffic is
  636. 26:50initiated external
  637. 26:52to the enterprise so all e-commerce
  638. 26:56transactions
  639. 26:58pass through a series of intelligent
  640. 27:00services that provide scalability
  641. 27:03security and high availability
  642. 27:06within the overall ecommerce network
  643. 27:08design
  644. 27:10so to build a successful e-commerce
  645. 27:12solution
  646. 27:13the following network devices might be
  647. 27:15included
  648. 27:17okay so basically you've got the web
  649. 27:19servers okay
  650. 27:20so act as the primary user interface for
  651. 27:24an e-commerce navigation
  652. 27:26so you might have also an application
  653. 27:29servers
  654. 27:30okay so which hosts various applications
  655. 27:33database servers
  656. 27:35okay should be there also which contains
  657. 27:38the application and transaction
  658. 27:39information that is the heart
  659. 27:41of the e-commerce business
  660. 27:43implementation and
  661. 27:44also there should be firewall or
  662. 27:47firewall routers
  663. 27:48okay so govern communication and provide
  664. 27:51security between the systems of various
  665. 27:54users
  666. 27:56also there should be a network intrusion
  667. 27:58detection system
  668. 27:59for the ips the intrusion prevention
  669. 28:02system
  670. 28:03okay so which monitors key network
  671. 28:06segments
  672. 28:07in the module to detect and respond to
  673. 28:10attacks
  674. 28:11against the network so you could also
  675. 28:14have the multi-layer switch
  676. 28:16with ids or ips okay so ids is
  677. 28:20nearly obsolete okay and
  678. 28:23mostly nowadays we are using the ips or
  679. 28:25the intrusion prevention system
  680. 28:28which provides traffic transport and
  681. 28:31integrated security monitoring
  682. 28:34you could also have the host based
  683. 28:37intrusion
  684. 28:38prevention systems deployed on
  685. 28:41sensitive core application servers and
  686. 28:44on dedicated
  687. 28:45appliances to provide
  688. 28:48uh real-time reporting and
  689. 28:51prevention of attacks as an extra layer
  690. 28:54of
  691. 28:55defense also
  692. 28:59next would be internet connectivity
  693. 29:01module
  694. 29:02okay now the internet connectivity
  695. 29:05module provides internal users
  696. 29:07with connectivity to internet services
  697. 29:09such as
  698. 29:11http https ftp
  699. 29:15or the simple mail transfer protocol
  700. 29:17smtp and dns
  701. 29:19so this module also provides internet
  702. 29:22users with access to information
  703. 29:24published
  704. 29:25on the enterprise public servers such as
  705. 29:27http
  706. 29:28and ftp servers
  707. 29:32so internet session initiation is
  708. 29:34typically from
  709. 29:35inside the enterprise towards the
  710. 29:37internet okay
  711. 29:38so additionally this module accepts
  712. 29:42vpn traffic from remote users
  713. 29:45and remote sites and forwards
  714. 29:48it to the remote access and vpn module
  715. 29:52where vpn termination takes place
  716. 29:56okay so the internet connectivity module
  717. 29:59is not designed to serve e-commerce
  718. 30:02applications
  719. 30:03so major components used in the internet
  720. 30:06connectivity module includes the
  721. 30:08following
  722. 30:09so as what i have mentioned earlier
  723. 30:11you've got some sort of the smtp mail
  724. 30:13servers
  725. 30:14okay this would act as a relay between
  726. 30:17the internet
  727. 30:18and the internet mail servers you also
  728. 30:21have the dns
  729. 30:23servers so serves as authoritative
  730. 30:26external dns server
  731. 30:28for the enterprise and relay internal
  732. 30:30dns requests
  733. 30:32to the internet so also
  734. 30:35you've got public servers for example
  735. 30:37the ftp
  736. 30:38and http or https which
  737. 30:41provide public information about
  738. 30:44organization
  739. 30:46each server on the public services
  740. 30:48segment contains
  741. 30:50host based intrusion detection system
  742. 30:53or the hids to
  743. 30:56monitor against any rogue activity at
  744. 30:59the operating system level
  745. 31:00and in common server application
  746. 31:03including http
  747. 31:05ftp and smtp
  748. 31:08also you could implement some firewall
  749. 31:10here okay firewalls or
  750. 31:12firewall routers so provide network
  751. 31:14level protection of
  752. 31:16resources provide stateful filtering of
  753. 31:19traffic
  754. 31:20and forward vpn traffic from remote
  755. 31:22sites
  756. 31:23and users for terminations
  757. 31:26so edge routers provide
  758. 31:30base basic filtering and multi-layer
  759. 31:33connectivity to the internet
  760. 31:35so again security should be considered
  761. 31:39on all of these modules here
  762. 31:42remote access and vpn module so the
  763. 31:46remote access and vpn module terminates
  764. 31:48remote access traffic
  765. 31:50and vpn traffic that the internet
  766. 31:52connectivity module
  767. 31:53forwards from remote users and remote
  768. 31:56sites
  769. 31:57so it also uses the internet
  770. 31:59connectivity module to initiate
  771. 32:01vpn connections to remote sites so
  772. 32:04furthermore
  773. 32:05this module terminates a dial in
  774. 32:07connection received
  775. 32:09from the public switch telephone network
  776. 32:11or the pstn
  777. 32:13okay so and after successful
  778. 32:15authentication
  779. 32:17grants dial in service or user access
  780. 32:20to the network so basically
  781. 32:24the remote access and vpn module
  782. 32:26consists of major components
  783. 32:28like the dial in access concentrators
  784. 32:32you also have the adaptive security
  785. 32:34appliances or asa
  786. 32:36firewalls okay and you've got some sort
  787. 32:40of an
  788. 32:40ips appliances
  789. 32:47one and man and side to side vpn module
  790. 32:51so the man and one and side to side
  791. 32:54vpn module uses various one technologies
  792. 32:57including cytoside vpns
  793. 33:00to route traffic between remote sites
  794. 33:02and the central side
  795. 33:04so in addition so we could have
  796. 33:08the list lines okay so circuit switch
  797. 33:11data link technologies
  798. 33:13like the old frame relay and the atm
  799. 33:16which are already
  800. 33:17obsolete so this module can use more
  801. 33:20recent
  802. 33:21one physical layer technologies okay
  803. 33:24so something like the synchronous
  804. 33:27optical network
  805. 33:28or the synchronous digital hierarchy or
  806. 33:30sdh
  807. 33:31cable dsl fiber to home
  808. 33:35their fiber mpls and metro internet
  809. 33:38it could also include wireless and
  810. 33:42service provider vpns
  811. 33:45so basically this module incorporates
  812. 33:49all cisco devices
  813. 33:51and even nancy devices that support
  814. 33:53these one technologies
  815. 33:55and routing access control and quality
  816. 33:58of service mechanisms
  817. 34:00so although security is not a critical
  818. 34:02when all links are
  819. 34:03owned by the enterprise it should be
  820. 34:06considered
  821. 34:07in the network design okay so the key
  822. 34:10point here is
  823. 34:12the man or the metropolitan area network
  824. 34:16and the one or the wide area network
  825. 34:19and the cytoside virtual private network
  826. 34:21module
  827. 34:22does not include the one connections or
  828. 34:26links
  829. 34:27it provides only interfaces to the one
  830. 34:33enterprise edge guidelines
  831. 34:35so you need to follow these guidelines
  832. 34:37for creating
  833. 34:39the modules within the enterprise edge
  834. 34:41of functional areas
  835. 34:42okay so first create the e-commerce
  836. 34:46module
  837. 34:46for business to business or business to
  838. 34:48customer scenarios
  839. 34:50when customers or partners require
  840. 34:52internet access to business applications
  841. 34:54and database servers
  842. 34:56so deploy a high security policy
  843. 34:59that allows customers to access
  844. 35:02predefined servers
  845. 35:04and services yet restricts all other
  846. 35:07operations
  847. 35:09okay so second you need to determine
  848. 35:13the connections from the corporate
  849. 35:15network into the internet
  850. 35:17and assign them to the internet
  851. 35:20connectivity module
  852. 35:22so this module should implement security
  853. 35:25to prevent
  854. 35:26any unauthorized access from the
  855. 35:28internet
  856. 35:29to the internal network so public web
  857. 35:33servers
  858. 35:33reside in this module or the e-commerce
  859. 35:37module
  860. 35:39third is design the remote access and
  861. 35:42vpn module if the enterprise
  862. 35:44requires vpn connections or
  863. 35:47dial in or accessing the internal
  864. 35:50network from
  865. 35:51the outside world so implement the
  866. 35:54security policy on this module
  867. 35:56okay so users should be able to access
  868. 35:59the internal network directly
  869. 36:02without authentication and authorization
  870. 36:05so the vpn sessions use connectivity
  871. 36:09from the internet connectivity module
  872. 36:12okay so next would be determine
  873. 36:15which part of the edge is used
  874. 36:17exclusively
  875. 36:19for permanent connections to remote
  876. 36:21locations
  877. 36:22such as branch offices and
  878. 36:26assign it to the one and man and side to
  879. 36:29side
  880. 36:29vpn module all one devices supporting
  881. 36:33frame relay
  882. 36:35atm cable mpls
  883. 36:38list lines sony sdh and so on
  884. 36:41are located here
  885. 36:46service provider modules
  886. 36:49so service provider modules as shown
  887. 36:52here on this figure
  888. 36:54shows the modules within the service
  889. 36:56provider functional area
  890. 36:58the enterprise itself does not implement
  891. 37:01these
  892. 37:01modules however they are necessary to
  893. 37:04enable communication
  894. 37:06with other networks using a variety of
  895. 37:09one technologies
  896. 37:11and with internet service providers or
  897. 37:14the isp
  898. 37:16the modules within the service provider
  899. 37:19functional area
  900. 37:20are as follows so basically you've got
  901. 37:23the internet service provider module or
  902. 37:25the isp module
  903. 37:27you've got the pstn module okay
  904. 37:30and you've got the one technology module
  905. 37:33here so it could be again
  906. 37:35a newer technology other than frame
  907. 37:38relay and atm which are already obsolete
  908. 37:42now the internet service provider
  909. 37:46module the internet service provider
  910. 37:49module represents enterprise ip
  911. 37:51connectivity to an isp network
  912. 37:53for basic access to the internet or for
  913. 37:56enabling enterprise ad services such as
  914. 37:59those in the e-commerce okay remote
  915. 38:02access
  916. 38:03and vpn and internet connectivity
  917. 38:05modules
  918. 38:07so enterprises can connect to two or
  919. 38:10more isps
  920. 38:11to provide redundant connections to the
  921. 38:14internet
  922. 38:15so the physical connection between the
  923. 38:17isp and the enterprise can now use
  924. 38:19any of the one technologies available on
  925. 38:23your work area
  926. 38:25next would be the pstn module so the
  927. 38:28pstn module represents the dial dial-up
  928. 38:31infrastructure
  929. 38:32for accessing the enterprise network
  930. 38:34using isdn
  931. 38:35analog and wireless telephony or the
  932. 38:37cellular technologies
  933. 38:39so enterprises can also use this
  934. 38:42infrastructure
  935. 38:43to back up existing one links one backup
  936. 38:46connections
  937. 38:48are generally established on demand
  938. 38:51and turned down after the idle timeout
  939. 38:55okay so next would be
  940. 38:58this frame relay and atm module or shall
  941. 39:01i call it the one
  942. 39:03technology module okay so the
  943. 39:06traditional frame relay and atm are
  944. 39:08still
  945. 39:08used by some organization or by some
  946. 39:11countries however
  947. 39:12despite the module's name it also
  948. 39:14represents
  949. 39:15many modern technologies that's why i
  950. 39:17call this the one technology
  951. 39:20module okay so this could include
  952. 39:23any one technology available on your
  953. 39:26work area
  954. 39:30enterprise remote modules so the three
  955. 39:34modules supporting remote enterprise
  956. 39:36locations are the enterprise branch
  957. 39:40the enterprise data center and the
  958. 39:43enterprise
  959. 39:47now the enterprise branch module extends
  960. 39:51the enterprise by providing its location
  961. 39:55with a resilient network architecture
  962. 39:58with integrated security
  963. 40:00communications and wireless mobility
  964. 40:04so any branch office generally
  965. 40:06accommodates
  966. 40:07employees who have a compelling reasons
  967. 40:11to be located away from the central side
  968. 40:13such as
  969. 40:14regional sales office okay now the
  970. 40:18branch office
  971. 40:19is sometimes called the remote site or
  972. 40:22remote office or maybe sales office
  973. 40:26so branch office users must be able to
  974. 40:29connect to the central site
  975. 40:30to access company information therefore
  976. 40:34they benefit from high-speed internet
  977. 40:37access
  978. 40:38vpn connectivity to corporate extranet
  979. 40:41or
  980. 40:41internet telecommuting capabilities
  981. 40:44for work at home employees okay also
  982. 40:48video conferencing
  983. 40:50and economical psd and quality voice and
  984. 40:52fax
  985. 40:53calls over a managed type networks or
  986. 40:56you'll have this voip implementation
  987. 41:00okay so the enterprise branch module is
  988. 41:03typically
  989. 41:04or this one typically uses a simplified
  990. 41:07version
  991. 41:08of the campus infrastructure module
  992. 41:11design
  993. 41:13now let's focus on the enterprise data
  994. 41:16center module here
  995. 41:18the enterprise data center module has an
  996. 41:20architecture that is similar to
  997. 41:23campus server farm module as discussed
  998. 41:26earlier
  999. 41:27okay so the enterprise data center
  1000. 41:30network architecture allows the network
  1001. 41:32to evolve
  1002. 41:33into a platform that enhances the
  1003. 41:36application
  1004. 41:37server and storage solutions
  1005. 41:40and equips organization to manage
  1006. 41:43increased security cost and
  1007. 41:47regulatory requirements while providing
  1008. 41:50the ability to respond quickly
  1009. 41:52to changing business environments
  1010. 41:55so the enterprise data center module may
  1011. 41:57include
  1012. 41:58the following components so maybe you'll
  1013. 42:01have
  1014. 42:02something like at the interactive
  1015. 42:05service layer
  1016. 42:06and at the management layer okay
  1017. 42:10so take note that at the network
  1018. 42:14infrastructure layer
  1019. 42:16the gigabit ethernet okay or 10g
  1020. 42:19or infiniband connections with storage
  1021. 42:21switching and optical transport devices
  1022. 42:24so if you have heard of infiniband that
  1023. 42:27is basically the term used on high
  1024. 42:28high-speed switch
  1025. 42:30fabric mesh technology okay so this is
  1026. 42:33used in
  1027. 42:34the storage area network
  1028. 42:37now on the interactive services layer
  1029. 42:41services include storage fabric services
  1030. 42:44computer services security services
  1031. 42:46and application optimization services
  1032. 42:49okay and at the management layer tools
  1033. 42:52include
  1034. 42:53fabric manager okay so for element and
  1035. 42:55network management
  1036. 42:57or you also have the v frame for server
  1037. 43:00and service
  1038. 43:01provisioning so the remote enterprise
  1039. 43:04data center module
  1040. 43:06includes highly available one
  1041. 43:08connectivity
  1042. 43:09with business continuance capabilities
  1043. 43:12to integrate it
  1044. 43:13with the rest of the enterprise
  1045. 43:15architecture
  1046. 43:16so the server farm module in the campus
  1047. 43:19can leverage
  1048. 43:21the one connectivity of the campus core
  1049. 43:24but the remote enterprise data center
  1050. 43:27must implement
  1051. 43:28its own one connectivity
  1052. 43:33next would be the enterprise teleworker
  1053. 43:37so enterprise teleworker module provides
  1054. 43:40people
  1055. 43:40in geographically dispersed locations
  1056. 43:43such as
  1057. 43:44home offices or hotels with highly
  1058. 43:47secure
  1059. 43:48access to central site applications and
  1060. 43:50network services
  1061. 43:52the enterprise teleworker module
  1062. 43:54supports a small office
  1063. 43:56with one several employees or
  1064. 43:59home office of a telecommuter
  1065. 44:02so telecommuters might also be mobile
  1066. 44:05users
  1067. 44:07people who need to access while
  1068. 44:09traveling
  1069. 44:10or who do not work
  1070. 44:13at a fixed company site
  1071. 44:17okay so depending on the amount of use
  1072. 44:20and the one services available
  1073. 44:22telecommuters working from home tend to
  1074. 44:25use
  1075. 44:25broadband or worst dial-up services
  1076. 44:30if the broadband is not available
  1077. 44:33so mobile users tend to access the
  1078. 44:35company network using
  1079. 44:37broadband internet service and the vpn
  1080. 44:40client software on their laptops
  1081. 44:42or via a synchronous dial up connection
  1082. 44:45through the telephone company so
  1083. 44:49computers
  1084. 44:49working from home might also use a vpn
  1085. 44:53channel gateway router
  1086. 44:55for encrypted data and voice traffic
  1087. 44:58to and from the network
  1088. 45:03so to summarize based on
  1089. 45:06the sauna the cisco enterprise
  1090. 45:08architecture provides
  1091. 45:10a modular enterprise-wide hierarchical
  1092. 45:13approach
  1093. 45:14for providing network infrastructure and
  1094. 45:17services
  1095. 45:18to all the places in the network
  1096. 45:22okay so the enterprise campus
  1097. 45:24infrastructure module includes the
  1098. 45:26campus infrastructure module
  1099. 45:28and the server farm module so the
  1100. 45:31enterprise
  1101. 45:32edge modules includes the
  1102. 45:35e-commerce module the internet
  1103. 45:37connectivity module
  1104. 45:39the remote access and vpn module
  1105. 45:42and the one and man and cyber site
  1106. 45:45modules
  1107. 45:46so the remote enterprise modules
  1108. 45:49includes the remote branches
  1109. 45:51data centers and teleworkers

About this transcript

This page contains the full transcript of Structuring and Modularizing the Network Part 2 by Santelmo, generated from the public captions YouTube serves with the video. The transcript has 4,995 words across 1,109 segments, with the original timestamps preserved so you can click any line to jump to that moment in the embedded player.

What you can do with it

Use the transcript to take notes, quote the speaker, build a study guide, generate a summary with ChatGPT or Claude via the YouTube Summary tool, or export it as a timed subtitle file with YouTube to SRT. You can also re-open it in the transcriber to translate the transcript into 100+ languages.

Free YouTube transcript tool

YouTube2Text is a free YouTube transcript generator — no signup, no daily limit. Paste any YouTube link and get the full transcript instantly, with timestamps, click-to-jump, translation to 100+ languages, AI prompts for ChatGPT, Claude, and Gemini, and exports to TXT, SRT, VTT, or Markdown.