YouTube2Text

Structuring and Modularizing the Network Part 3 — Transcript

by Santelmo · 6,031 words · 1,337 segments · language en · Watch on YouTube

Full transcript

  1. 0:05services
  2. 0:06within modular networks
  3. 0:11business that operate large enterprise
  4. 0:13networks strive to create
  5. 0:15an enterprise-wide network
  6. 0:17infrastructure and interactive services
  7. 0:20to serve as a solid foundation for
  8. 0:23business
  9. 0:24and collaborative applications this
  10. 0:27section explores
  11. 0:28some of the interactive services with
  12. 0:31respect to
  13. 0:32the modules that form the cisco
  14. 0:35enterprise architecture
  15. 0:37so the key point here is a network
  16. 0:39service is a supporting and necessary
  17. 0:41service
  18. 0:42but not an ultimate solution for example
  19. 0:46security and quality of service are not
  20. 0:48ultimate goals
  21. 0:50for a network they are necessary
  22. 0:53to enable other services and
  23. 0:54applications
  24. 0:56and are therefore classified as network
  25. 0:58services
  26. 1:00however ip telephony might be an
  27. 1:03ultimate goal of a network and is
  28. 1:06therefore
  29. 1:06a network application or solution rather
  30. 1:09than
  31. 1:10a service so interactive services
  32. 1:14since the inception of a packet-based
  33. 1:16communication
  34. 1:18networks have always offered a
  35. 1:20forwarding service
  36. 1:21forwarding is the fundamental activity
  37. 1:24within the internetwork
  38. 1:26in ip this forwarding service was built
  39. 1:29on the assumption
  40. 1:31that end nodes in the network were
  41. 1:33intelligent
  42. 1:35and that the network core did not have
  43. 1:39so with advances in networking software
  44. 1:41and hardware
  45. 1:42the network can offer an increasingly
  46. 1:44rich intelligent set of mechanisms
  47. 1:47for forwarding information interactive
  48. 1:51services
  49. 1:52add intelligence to the network
  50. 1:54infrastructure
  51. 1:55beyond simply moving a datagram between
  52. 1:59two points for example
  53. 2:02through intelligent network
  54. 2:03classification the network distinguishes
  55. 2:06and identifies traffic based on
  56. 2:08application content
  57. 2:10and context advanced network services
  58. 2:14use the traffic classification to
  59. 2:16regulate performance
  60. 2:18ensure security facilitate delivery and
  61. 2:22improve manageability network
  62. 2:25applications such as
  63. 2:26ip telephony support the enter
  64. 2:29enterprise network environment
  65. 2:31from the teleworker to the campus to
  66. 2:34the data center so these applications
  67. 2:37are enabled by critical network services
  68. 2:40and
  69. 2:41provide a common set of capabilities
  70. 2:44to support the application's
  71. 2:46network-wide requirements
  72. 2:48including security high availability
  73. 2:52reliability flexibility responsiveness
  74. 2:57and compliance
  75. 3:05examining the role of the infrastructure
  76. 3:07services
  77. 3:08recall the layers of the cisco sona
  78. 3:10framework illustrated in the future
  79. 3:13so the sona interactive services layer
  80. 3:15includes
  81. 3:16both application networking and
  82. 3:19the infrastructure services so for
  83. 3:22example
  84. 3:23the following infrastructure services
  85. 3:25shown earlier in the figure
  86. 3:26enhance classic network functions to
  87. 3:29support
  88. 3:30today's application environment by
  89. 3:32mapping the application's requirements
  90. 3:35to the resources that they require from
  91. 3:37the network
  92. 3:39so these are security services
  93. 3:42it ensures that all aspects of the
  94. 3:44network are secure
  95. 3:46from devices connecting to the network
  96. 3:49to secure
  97. 3:50transport to data theft prevention
  98. 3:53you also have mobility services
  99. 3:56it allows users to access network
  100. 3:59resources regardless of their physical
  101. 4:01location
  102. 4:03you also have this storage services
  103. 4:06okay so which provide distributed and
  104. 4:09virtual storage
  105. 4:10across the infrastructure you also have
  106. 4:14a voice and collaboration services
  107. 4:17it deliver the foundation by which voice
  108. 4:20can be carried across the network such
  109. 4:24as security and high availability
  110. 4:28you also have this compute services it
  111. 4:31connect and virtualize compute
  112. 4:33resources based on the application
  113. 4:36and you've got the identity services
  114. 4:40which map resources and policies
  115. 4:43to the user and the device
  116. 4:47now what are the reasons for internal
  117. 4:49security
  118. 4:51strongly protecting the internal
  119. 4:53enterprise campus by including security
  120. 4:55functions
  121. 4:56in each individual element is important
  122. 4:59for the following reasons
  123. 5:02so that would be if the security
  124. 5:03established at the
  125. 5:05enterprise edge fails an unprotected
  126. 5:08enterprise campus
  127. 5:10is vulnerable so deploying several
  128. 5:13layers of security increases the
  129. 5:15protection
  130. 5:16of the enterprise campus where the most
  131. 5:19strategic asset usually resides
  132. 5:24so relying on physical security is not
  133. 5:26enough so for example
  134. 5:28as a visitor to the organization a
  135. 5:30potential attacker
  136. 5:32could gain physical access to devices in
  137. 5:35the enterprise campus
  138. 5:37okay often external access does not stop
  139. 5:42at the enterprise edge so some
  140. 5:44applications
  141. 5:45require indirect external access
  142. 5:50to the enterprise campus okay
  143. 5:53so strong security must protect access
  144. 5:57to this resources
  145. 6:00modularizing internal security so
  146. 6:04examples of network services embedded
  147. 6:07in the infrastructure services includes
  148. 6:09the following
  149. 6:10so first you've got the network
  150. 6:13management okay so it includes
  151. 6:16land management for advanced management
  152. 6:19of a multi-layer switches
  153. 6:21routed one management for monitoring
  154. 6:24traffic management and access control
  155. 6:27to administer the routed infrastructure
  156. 6:30of
  157. 6:31a multi-service networks service
  158. 6:34management for managing and monitoring
  159. 6:36service level agreements or slas
  160. 6:38and vpn security management for
  161. 6:41optimizing
  162. 6:42vpn performance and security
  163. 6:44administration
  164. 6:46so high availability ensures
  165. 6:50end-to-end availability for services
  166. 6:54so that includes clients and sessions
  167. 6:57so implementation includes reliable
  168. 7:00fault tolerant
  169. 7:01network devices to automatically
  170. 7:04identify
  171. 7:05and overcome failures and resilient
  172. 7:08network technologies
  173. 7:10so also we need the quality of service
  174. 7:14so manages the delay delay variation or
  175. 7:17also known as the jitter
  176. 7:19bandwidth availability and packet loss
  177. 7:22parameters
  178. 7:23of a network to meet the diverse needs
  179. 7:26of voice
  180. 7:27video and data applications so quality
  181. 7:30of service features
  182. 7:31provide value-added functionality such
  183. 7:34as
  184. 7:34network-based application recognition
  185. 7:37for classifying traffic
  186. 7:39on the application basis so cisco ios
  187. 7:43ipslas or the previously called
  188. 7:46the service assurance agent for an
  189. 7:49end-to-end
  190. 7:50quality of service measurements so
  191. 7:53resource
  192. 7:54reservation protocol signaling for
  193. 7:56admission control and reservation of
  194. 7:57resources
  195. 7:59and a variety of configurable queue
  196. 8:01insertion
  197. 8:02and servicing function
  198. 8:05so you also have multi casting or ip
  199. 8:09multicasting
  200. 8:10so it provides a bandwidth conserving
  201. 8:13technology that reduces network traffic
  202. 8:15by delivering a single stream of
  203. 8:17information intended for many recipients
  204. 8:20throughout the transport network so
  205. 8:22multicasting enables
  206. 8:24distribution of video conferencing
  207. 8:27corporate communications
  208. 8:29distance learning software and other
  209. 8:31applications
  210. 8:33so multicast packets are replicated only
  211. 8:36as necessary
  212. 8:37by routers enabled with protocol
  213. 8:39independent multicast
  214. 8:41and other supporting multicast protocols
  215. 8:44that result
  216. 8:46in the most efficient delivery of data
  217. 8:49to multiple receivers so to support
  218. 8:51network applications efficiently
  219. 8:54so deploy the underlying infrastructure
  220. 8:56services in some
  221. 8:57or all modules of the enterprise network
  222. 9:00as
  223. 9:01required so this design elements can be
  224. 9:04replicated simply to
  225. 9:06other enterprise network modules
  226. 9:09as network changes so as a result
  227. 9:13modularization to small subsets of the
  228. 9:15overall network simplifies the network
  229. 9:17design
  230. 9:18and often reduces the network's cost
  231. 9:22and complexity so the following are some
  232. 9:26of the recommended security practices
  233. 9:28in each of the module so you've got at
  234. 9:30the building
  235. 9:32okay so for building access access is
  236. 9:35controlled
  237. 9:36at the port level using data link layer
  238. 9:39information
  239. 9:41some examples are filtering based on
  240. 9:43media access control addresses
  241. 9:46and the ieee 802.1x
  242. 9:49port authentication okay
  243. 9:53now on the building distribution it
  244. 9:55performs
  245. 9:56filtering to keep unnecessary traffic
  246. 9:59from the campus core
  247. 10:01this packet filtering can be considered
  248. 10:04a security function because it does
  249. 10:06prevent
  250. 10:07some undesired access to other modules
  251. 10:11so given that switches in the building
  252. 10:13distribution layer
  253. 10:15are typically multi-layer switches and
  254. 10:17are there for layer 3 aware
  255. 10:20this is the first place on the data path
  256. 10:22in which
  257. 10:23filtering based on the network layer
  258. 10:25information can be performed
  259. 10:28okay so you also have the campus core
  260. 10:31layer
  261. 10:32so this is a high speed switching
  262. 10:34backbone
  263. 10:35and should be designed to switch packets
  264. 10:38as quickly as possible
  265. 10:40so it should not perform any security
  266. 10:42functions
  267. 10:43because doing so would slow down the
  268. 10:46switching of packets
  269. 10:49so next would be the server for modules
  270. 10:52which primary goal
  271. 10:53is to provide application services to
  272. 10:56end users
  273. 10:57and devices so enterprises
  274. 11:00often overlook the server for module
  275. 11:03from a security perspective
  276. 11:05okay so given the high degree of access
  277. 11:08that most employees
  278. 11:10have to these servers they often become
  279. 11:13the primary
  280. 11:14goal of internally originated attacks
  281. 11:17so simply relying on the effective
  282. 11:20passwords
  283. 11:21does not provide a comprehensive attack
  284. 11:23mitigation strategy
  285. 11:25so using a host based in network based
  286. 11:28ips
  287. 11:29and idss so private vlans
  288. 11:33and access control provides a much
  289. 11:36more comprehensive attack response so
  290. 11:39for example
  291. 11:40onboard ideas or ips within the server
  292. 11:44farm
  293. 11:44multi-layer switches that inspects
  294. 11:48traffic flows okay
  295. 11:51now the server farm module typically
  296. 11:53includes
  297. 11:55network management systems to securely
  298. 11:58manage
  299. 11:58all the devices and hosts within the
  300. 12:01enterprise architecture
  301. 12:03so for example syslog provides an
  302. 12:05important information on security
  303. 12:07violations
  304. 12:08and configuration changes by lagging
  305. 12:10security related
  306. 12:12uh events authentication authorization
  307. 12:16and accounting and so on so on
  308. 12:18authentication authorization and
  309. 12:20accounting or triple
  310. 12:21a that is a security server
  311. 12:24okay so also works on a one-time
  312. 12:26password or otp
  313. 12:28server that is to provide a high level
  314. 12:31of security
  315. 12:33to all local and remote users
  316. 12:36so a and otp authentication reduces the
  317. 12:39likelihood of
  318. 12:41successful password attack let me give
  319. 12:43you some
  320. 12:44information about aaa or the
  321. 12:46authentication
  322. 12:48authorization and accounting
  323. 12:51so aaa is a crucial aspect of network
  324. 12:53security
  325. 12:54that should be considered during the
  326. 12:55network design an
  327. 12:57aaa server handles the following
  328. 13:00so first is authentication with
  329. 13:04authentication that pertains to who
  330. 13:07authentication checks the user's
  331. 13:09identity typically
  332. 13:11through a username and password
  333. 13:13combination
  334. 13:15the next a is authorization
  335. 13:18this pertains to what so after the user
  336. 13:21is authenticated
  337. 13:23the aaa server dictates what activity
  338. 13:26the user is allowed to perform on the
  339. 13:28network
  340. 13:30so the last a is accounting accounting
  341. 13:33pertains to
  342. 13:34when the aaa server can record the
  343. 13:38length of the session
  344. 13:39the services accessed during the session
  345. 13:43and so on so everything will be logged
  346. 13:45in on the accounting
  347. 13:47server
  348. 13:52how about external threats so
  349. 13:55when designing a network security in an
  350. 13:58enterprise network
  351. 13:59the enterprise edge is the first line of
  352. 14:02defense
  353. 14:03at which potential outside attacks
  354. 14:06can be stopped so the enterprise edge is
  355. 14:09like a wall
  356. 14:11with small doors and strong guards that
  357. 14:14efficiently control any access
  358. 14:17so the following for attack methods are
  359. 14:19commonly used in attempts
  360. 14:21to compromise the integrity of the
  361. 14:23enterprise network
  362. 14:24from the outside so first would be
  363. 14:27ip spoofing okay
  364. 14:31so ip spoofing attack occurs
  365. 14:34when a hacker uses a trusted computer to
  366. 14:38launch
  367. 14:38an attack from inside or outside the
  368. 14:40network
  369. 14:42the hacker uses either an ip address
  370. 14:45that is in the range of the network's
  371. 14:48trusted ip addresses or
  372. 14:50trusted external ip addresses that
  373. 14:53provides access to specified
  374. 14:55resources on the network ip spoofing
  375. 14:58attack
  376. 14:59often lead to other types of attacks
  377. 15:03for example a hacker might launch a
  378. 15:06denial of services
  379. 15:07or dos using spoofed
  380. 15:11source address to hide his identity
  381. 15:14okay so you also have password attacks
  382. 15:18so using a packet sniffer to determine
  383. 15:21username and passwords
  384. 15:23is a simple password attack however
  385. 15:26the term password attack usually
  386. 15:29referred to repeated brute force
  387. 15:31attempts
  388. 15:32to identify username and password
  389. 15:34information
  390. 15:35so trojan horse programs are another
  391. 15:38method
  392. 15:39that can be used to determine this
  393. 15:41information
  394. 15:42so a hacker might also use ip spoofing
  395. 15:45as a first step in system attack by
  396. 15:49violating the trust relationship
  397. 15:51based on the source ip addresses
  398. 15:54so first however the system would have
  399. 15:57to be configured to bypass password
  400. 15:59authentication
  401. 16:00so that only username is required
  402. 16:04so you only ha you also have this dos
  403. 16:07attacks
  404. 16:08or the denial of service attacks so dos
  405. 16:11attacks
  406. 16:12focus on making a service unavailable
  407. 16:15for normal use
  408. 16:16and are typically accomplished by
  409. 16:18exhausting some resource limitation
  410. 16:21on the network or within an operating
  411. 16:24system or applications
  412. 16:26okay so also we have this application
  413. 16:29layer tab
  414. 16:31so application layer attacks typically
  415. 16:33exploit
  416. 16:34well-known weaknesses in common software
  417. 16:37programs
  418. 16:38to gain access to a computer
  419. 16:44designing high availability so most
  420. 16:48enterprise networks
  421. 16:49carry mission critical information
  422. 16:52organizations
  423. 16:53that run such networks are usually
  424. 16:56interested in protecting the integrity
  425. 16:58of
  426. 16:59that information along with security
  427. 17:03this organization expects the
  428. 17:05internetworking platform
  429. 17:06to offer sufficient level of resilience
  430. 17:10so this section introduces another
  431. 17:13network infrastructure service
  432. 17:15high availability to ensure adequate
  433. 17:18connectivity for mission critical
  434. 17:20applications
  435. 17:21high availability is an essential
  436. 17:23component
  437. 17:24of an enterprise environment okay
  438. 17:28now designing for high availability in a
  439. 17:30network so redundant network design
  440. 17:34duplicate network links and devices
  441. 17:36eliminating single point of failure
  442. 17:39on the network that is high availability
  443. 17:43so the goal is to duplicate components
  444. 17:46whose
  445. 17:47failure to disable critical applications
  446. 17:51so because redundancy is expensive to
  447. 17:54deploy and maintain
  448. 17:55redundant topologies should be
  449. 17:57implemented with care so redundancy adds
  450. 18:01complexity to the network topology
  451. 18:03and to network addressing and routing so
  452. 18:06the level of redundancy should meet
  453. 18:08organizations availability
  454. 18:10and affordability requirements so what's
  455. 18:14the key point here
  456. 18:15so before selecting redundant design
  457. 18:17solutions
  458. 18:19analyze the business and technical goals
  459. 18:22and constraints
  460. 18:23to establish the required availability
  461. 18:26and affordability
  462. 18:28so critical application systems internet
  463. 18:31working devices
  464. 18:32and link must be identified
  465. 18:35so analyze the risk tolerance and the
  466. 18:38consequences
  467. 18:39of not implementing redundancy and
  468. 18:42ensure
  469. 18:43that you consider the trade-offs of
  470. 18:46redundancy versus cost
  471. 18:47and simplicity versus complexity
  472. 18:51so duplicate any component whose failure
  473. 18:54could disable critical applications
  474. 18:57and redundancy is not provided
  475. 19:01by simply duplicating all links so
  476. 19:04unless
  477. 19:05all devices are completely fault
  478. 19:07tolerant
  479. 19:08so redundant links should terminate at
  480. 19:11different devices
  481. 19:13otherwise devices are not
  482. 19:16fault tolerant becoming a single points
  483. 19:19of
  484. 19:22failure
  485. 19:24how about designing for route redundancy
  486. 19:28so the following types of redundancy may
  487. 19:30be used
  488. 19:31in the modules of an enterprise so
  489. 19:34you've got sort of
  490. 19:35device redundancy including card
  491. 19:38and port redundancy you also have
  492. 19:42redundant physical connections to
  493. 19:44critical workstations and servers
  494. 19:47route redundancy can also be considered
  495. 19:50link redundancy and even power
  496. 19:53redundancy
  497. 19:54including redundant power supplies
  498. 19:56integral to the network devices
  499. 19:59and redundant power to building's
  500. 20:01physical plan
  501. 20:04now designing for redundancy so
  502. 20:06redundant routes have two purposes
  503. 20:09so that is to minimize the effect of
  504. 20:11link failures
  505. 20:13and to minimize the effect of the
  506. 20:15internet working device
  507. 20:17failure so redundant routes might also
  508. 20:20be used
  509. 20:21for load balancing when all routes
  510. 20:24are up okay now possible ways
  511. 20:28to make connection redundant includes
  512. 20:30the following
  513. 20:31so you've got parallel physical links
  514. 20:34between switches and routers
  515. 20:36you could also have back a plan and one
  516. 20:38links
  517. 20:39for example ddr backup for less lines
  518. 20:45now the following are possible ways to
  519. 20:47make the network redundant
  520. 20:50so a full mess to provide complete
  521. 20:53redundancy
  522. 20:54and good performance a partial mesh
  523. 20:58which is less expensive and more
  524. 21:01scalable
  525. 21:02the common approach when designing the
  526. 21:04route redundancy is to implement
  527. 21:06partial redundancy by using a partial
  528. 21:09mesh instead of a full mesh
  529. 21:11and backup links to alternative devices
  530. 21:15so this protects only the most vital
  531. 21:18parts
  532. 21:19of the network such as links
  533. 21:22between the layers and the concentration
  534. 21:24devices
  535. 21:28now example of campus infrastructure
  536. 21:31redundancy
  537. 21:32so a full mesh forms any to any
  538. 21:36connectivity and is ideal for connecting
  539. 21:39a reasonably small number of devices
  540. 21:42however as the network topology grows
  541. 21:45the number of links required to maintain
  542. 21:47a full mesh increases exponentially
  543. 21:50so the number of links in a full mesh
  544. 21:53is uh n okay times n
  545. 21:57minus one divided by two okay so where n
  546. 22:00is the number of routers so as the
  547. 22:03number of router appear increases
  548. 22:05the bandwidth and cpu resources devoted
  549. 22:07to processing routing updates
  550. 22:09and service requests also increases
  551. 22:13now in a partial mesh network that is
  552. 22:16similar to the full mesh network with
  553. 22:18some of its connections
  554. 22:19removed okay now a partial mesh
  555. 22:23backbone might be appropriate for a
  556. 22:25campus network
  557. 22:26in which traffic predominantly goes
  558. 22:29into one centralized server farm module
  559. 22:33now this figure here illustrates an
  560. 22:35example of
  561. 22:36route redundancy in the campus okay
  562. 22:40now in this example the access layer
  563. 22:42switches
  564. 22:44are fully meshed with the distribution
  565. 22:46layer switches
  566. 22:48okay if the link or distribution switch
  567. 22:50fails
  568. 22:51an access layer switch can still
  569. 22:53accommodate and communicate
  570. 22:55with the distribution layer
  571. 22:58now the multi-layer switches select the
  572. 23:00primary and back up path
  573. 23:02between the axis and distribution layers
  574. 23:04based on the links
  575. 23:06metric as computed by the routing
  576. 23:08protocol algorithm in use
  577. 23:10the best path is placed in the
  578. 23:13forwarding table
  579. 23:15and in case of equal cost path
  580. 23:18load sharing takes place
  581. 23:22how about example of edge redundancy
  582. 23:26so designing for link redundancy it is
  583. 23:29often necessary to provision
  584. 23:31redundant media in locations where
  585. 23:33mission critical application traffic
  586. 23:35travels
  587. 23:37so in layer 2 switch networks
  588. 23:40redundant links are permitted as long as
  589. 23:42stp is running
  590. 23:45so stp guarantees one and
  591. 23:48only one active path within the
  592. 23:50broadcast domain
  593. 23:51avoiding problems such as broadcast
  594. 23:54storms
  595. 23:55when a broadcast storms continuously
  596. 23:57loops
  597. 23:58okay now the redundant path
  598. 24:01automatically activates
  599. 24:03when the active path goes down so
  600. 24:06because
  601. 24:06one links are often critical pieces of
  602. 24:09the internetwork
  603. 24:10redundant media are often deployed in
  604. 24:13one environment
  605. 24:15now if you will observe on this figure
  606. 24:17here where
  607. 24:18frame relay circuit is used in parallel
  608. 24:21with
  609. 24:22a backup ipc connection over the
  610. 24:25internet
  611. 24:26so backup links can use different
  612. 24:28technologies
  613. 24:29and so with the frame relay which i said
  614. 24:32from the previous video
  615. 24:33is almost obsolete okay now it is
  616. 24:37important that the backup provides
  617. 24:38sufficient capacity
  618. 24:40to meet the critical requirements if the
  619. 24:42primary route fails
  620. 24:44so backup links can always on or can
  621. 24:47always be on
  622. 24:49or and become active when a primary link
  623. 24:51goes down
  624. 24:52or becomes congested so you have this
  625. 24:56connectivity okay so one is active the
  626. 24:59other one is standby
  627. 25:03now how about high availability in the
  628. 25:05server farm module
  629. 25:07so improving the reliability of critical
  630. 25:10workstations and servers
  631. 25:12usually depends on the hardware and
  632. 25:15operating system software in use
  633. 25:17some common ways of connecting includes
  634. 25:19the following
  635. 25:20so you could have the single attachment
  636. 25:23okay so which is not recommended
  637. 25:26so when a workstation on a server has
  638. 25:29traffic to send to a station that is not
  639. 25:31local
  640. 25:33it must know the address of the router
  641. 25:35on each network segment
  642. 25:38so if that router fails the workstation
  643. 25:40or server needs a mechanism to discover
  644. 25:43an alternative router
  645. 25:45so if the workstation or server has a
  646. 25:47single attachment
  647. 25:49it needs layer 3 mechanism to
  648. 25:52dynamically find an alternative router
  649. 25:54therefore the single attachment method
  650. 25:57is not
  651. 25:58recommended okay so
  652. 26:01the available mechanism includes address
  653. 26:03resolution protocol or the arp
  654. 26:06you've got a router discovery protocol
  655. 26:09or rdp
  656. 26:11routing protocols such as routing
  657. 26:13information protocol
  658. 26:15rep ospf eigrp
  659. 26:18you could also have this hot standby
  660. 26:20router protocol
  661. 26:22okay or the hsrp the gateway
  662. 26:25load balancing product called jlbp and
  663. 26:29the virtual router redundancy protocol
  664. 26:31vrp
  665. 26:34now example attachment through a
  666. 26:36redundant transceiver
  667. 26:38okay so this is an attachment through
  668. 26:41redundant transceiver
  669. 26:42so physical redundancy with redundant
  670. 26:46transceiver
  671. 26:47is suitable in environments where the
  672. 26:49workstation hardware or software
  673. 26:51does not support redundant attachment
  674. 26:54options
  675. 26:55okay
  676. 26:59now in this diagram here it is an
  677. 27:01example of attachment
  678. 27:02through redundant and icd okay
  679. 27:06so attachment through redundant network
  680. 27:08interface cards or nic
  681. 27:10some environments for example most unix
  682. 27:12servers
  683. 27:13support redundant attachment through
  684. 27:15dual analysis
  685. 27:17so primary and backup so the device
  686. 27:20drivers
  687. 27:21represents this attachment as a single
  688. 27:24interface
  689. 27:25to the operating system
  690. 27:28now for fast ethernet or giga ethernet
  691. 27:31port bundles so fast easter channel
  692. 27:35and gigabit ether channel port bundles
  693. 27:38group
  694. 27:38multiple pass or gigabit ethernet ports
  695. 27:42into a single logical transmission path
  696. 27:45between a switch
  697. 27:46and a router so host or another switch
  698. 27:50so stp treats the easter channel as one
  699. 27:53logical length
  700. 27:55so the switch distributes frame across
  701. 27:57the ports in an insert channel
  702. 28:00so this load balancing was originally
  703. 28:02done
  704. 28:03based only on map addresses so however
  705. 28:07newer implementations can also load
  706. 28:09balance
  707. 28:10based on ip addresses or layer 4 port
  708. 28:13numbers
  709. 28:15so source destination or source and
  710. 28:18destination addresses
  711. 28:19or port numbers can be used so if a port
  712. 28:23within an ether channel fails traffic
  713. 28:26previously carried over the field port
  714. 28:28reverts to the remaining ports
  715. 28:31within the insert channel so if you want
  716. 28:33to learn more about insert channel you
  717. 28:35could go ahead and check the
  718. 28:36supplementary videos on easter channel
  719. 28:42voice transport overview so voice
  720. 28:45services
  721. 28:46in a modular network design so to ensure
  722. 28:49successful implementation of voice
  723. 28:51applications
  724. 28:53network designers must consider the
  725. 28:56enterprise
  726. 28:57services in infrastructure in edge
  727. 28:59configuration
  728. 29:00for example to support voip
  729. 29:03the underlying ip infrastructure must be
  730. 29:06functioning
  731. 29:06and robust in other words
  732. 29:10don't even think of adding voice to a
  733. 29:12network experiencing other problems such
  734. 29:14as
  735. 29:14congestion or network failures
  736. 29:18okay now two voice implementations
  737. 29:22voice transport is general term so that
  738. 29:24can be divided
  739. 29:25into the following two implementations
  740. 29:27here okay
  741. 29:29so you've got the voip or the voice over
  742. 29:31ip
  743. 29:32and the ip telephony now voip
  744. 29:37uses voice enabled routers to convert
  745. 29:40analog voice
  746. 29:41into ip packets or packetized
  747. 29:45digital voice channels and route those
  748. 29:48packets between the corresponding
  749. 29:50locations
  750. 29:52users do not often notice that voip is
  751. 29:55implemented in the network
  752. 29:57so they use their traditional phones
  753. 30:00which
  754. 30:01are connected to the pbx however
  755. 30:04the pbx is not connected to pstn or to
  756. 30:07another
  757. 30:08pbx okay so back to a voice enabled
  758. 30:11router that
  759. 30:12is an entry point to voip
  760. 30:16so voice enabled routers can also
  761. 30:18terminate ip
  762. 30:19phones using session initiation protocol
  763. 30:23for call control and signaling so the
  764. 30:26next one would be
  765. 30:27ip telephony so for ip telephony
  766. 30:32traditional phones are replaced with
  767. 30:35iphones
  768. 30:37so a single or a server for call
  769. 30:40control and signaling such as this cisco
  770. 30:43unified communication manager
  771. 30:45okay so the ip phone
  772. 30:49itself performs voice to ip conversion
  773. 30:52and no voice enabled routers are
  774. 30:54required within the enterprise network
  775. 30:57however if a congestion to the pstn is
  776. 31:01required
  777. 31:01a voice enabled router or other gateway
  778. 31:05in the enterprise edge is added
  779. 31:08where calls are forwarded to the pstn
  780. 31:13so both implementation voip and ip
  781. 31:16telephony
  782. 31:17require properly designed networks
  783. 31:21so using a modular approach in voice
  784. 31:24transport design
  785. 31:26that is especially important because of
  786. 31:28the voice sensitivity to delay
  787. 31:30and the complexity of troubleshooting
  788. 31:32voice networks
  789. 31:34so all cisco enterprise architecture
  790. 31:36modules
  791. 31:37are involved in voice transport design
  792. 31:44ip telephony components so ip telephony
  793. 31:48components
  794. 31:49an ip telephony network contains four
  795. 31:52main voice specific components okay
  796. 31:56so this includes an iphone's okay
  797. 31:59an iphone are used to place calls in an
  798. 32:02ip telephony network
  799. 32:04they perform voice to ip and vice versa
  800. 32:08coding and compression
  801. 32:09using special hardware so iphones
  802. 32:13offer services such as directory lookup
  803. 32:17and internet access so the phones
  804. 32:20are active network devices that require
  805. 32:23power to operate
  806. 32:25so power is applied through the lan
  807. 32:26connection using the poe
  808. 32:29or with external power supply okay
  809. 32:32so the next one would be switches with
  810. 32:34inline power so you've got switches
  811. 32:36there
  812. 32:37so switches with inline power are poi
  813. 32:39enabled the modular wiring closet
  814. 32:42to provide centralized power for the
  815. 32:45telephony networks
  816. 32:46so these switches are similar to
  817. 32:49traditional switches
  818. 32:50with an added option to provide power to
  819. 32:54the lan ports
  820. 32:55where iphones are connected
  821. 32:58now the switches also perform some basic
  822. 33:00uos tasks
  823. 33:02such as packet classification which is
  824. 33:05required
  825. 33:06for prioritizing voice through the
  826. 33:09network
  827. 33:10so also you have this
  828. 33:13voice or the call processing manager
  829. 33:17okay or the call processing engine now
  830. 33:20the call processing manager
  831. 33:22such as the cisco unified communication
  832. 33:24manager
  833. 33:25it provides central control and
  834. 33:27configuration management for iphones
  835. 33:30so it provides the core functionality to
  836. 33:33initialize
  837. 33:34ip telephony devices and to perform
  838. 33:38all setup and call routing throughout
  839. 33:40the network
  840. 33:42okay now this cisco unified
  841. 33:44communication manager can be clustered
  842. 33:46to provide distributed scalable and
  843. 33:49highly available ip telephony model
  844. 33:52so adding more servers to plaster of
  845. 33:55servers
  846. 33:56provides more capacity to the system
  847. 34:00okay next would be the voice gateway
  848. 34:05okay so voice gateways also called voice
  849. 34:08enabled routers
  850. 34:10or voice enabled switches provide voice
  851. 34:13services such as
  852. 34:14voice to ip coding and compression so
  853. 34:17pstn access
  854. 34:19ipp packet routing backup call
  855. 34:22processing
  856. 34:23and voice services so backup
  857. 34:27backup call processing allows voice
  858. 34:30gateways
  859. 34:31to take over call processing in case of
  860. 34:34the primary call processing manager
  861. 34:36fails
  862. 34:37so voice gateways typically support
  863. 34:40a subset of a call processing
  864. 34:42functionality supported by
  865. 34:44this unified communication manager
  866. 34:48so other components of ip telephony
  867. 34:50network includes
  868. 34:52a robust ip network of course okay
  869. 34:55so voice messaging and applications
  870. 34:58and a digital signal processor resources
  871. 35:01to process voice functions in hardware
  872. 35:04so which is much faster than doing it in
  873. 35:07software
  874. 35:08so these components are located
  875. 35:10throughout the enterprise network
  876. 35:12as you can see here on this diagram
  877. 35:19modular approach in voice network design
  878. 35:24so implementing voice requires deploying
  879. 35:26delay sensitive services
  880. 35:28such as end-to-end in all enterprise
  881. 35:31network modules
  882. 35:34so use the modular approach to simplify
  883. 35:36design
  884. 35:38implementation and especially
  885. 35:40troubleshooting
  886. 35:42so voice implementation requires some
  887. 35:44modification to the existing enterprise
  888. 35:46network
  889. 35:47okay so that is in terms of performance
  890. 35:50capacity and availability because it is
  891. 35:52an end-to-end solution
  892. 35:54so for example so clients iphones are
  893. 35:58located
  894. 35:59in the building access layer
  895. 36:02okay and then
  896. 36:05the call processing manager is located
  897. 36:07in
  898. 36:08the server farm okay so therefore
  899. 36:11all modules in the enterprise network
  900. 36:14are involved
  901. 36:14in voice processing and must be
  902. 36:17adequately considered
  903. 36:20voice affects various modules of the
  904. 36:23network
  905. 36:24as follows now on the building
  906. 36:27access layer iphones and and user
  907. 36:30computers are attached
  908. 36:32to a layer two switches here so switches
  909. 36:35provides
  910. 36:36power to ip phones and provide
  911. 36:39quality of service packet classification
  912. 36:41and marking
  913. 36:42which is essential for proper voice
  914. 36:45packet manipulation
  915. 36:47through the network okay now
  916. 36:50on the building distribution layer this
  917. 36:53layer performs
  918. 36:54packet reclassification if building
  919. 36:57access
  920. 36:58is unable to classify packets or is not
  921. 37:02within
  922. 37:02trusted boundary so it aggregates
  923. 37:06the building access layer switches or
  924. 37:08the wiring closets
  925. 37:10and provides redundant objects to the
  926. 37:12campus core layer
  927. 37:15okay now on the campus core layer
  928. 37:19this forms the network score so all
  929. 37:22enterprise
  930. 37:23network modules are attached to it
  931. 37:25however
  932. 37:26okay so this could be virtually
  933. 37:29all traffic between application servers
  934. 37:32and clients
  935. 37:32traverses the campus core
  936. 37:36and with the advent of wire speed
  937. 37:38multi-layer gigabit switching devices
  938. 37:41land back bones might migrate it or
  939. 37:44might have migrated
  940. 37:46to switch gigabit architectures that
  941. 37:48combine
  942. 37:49all the benefits of routing with wire
  943. 37:52speed packet forwarding
  944. 37:54okay now on the server farm
  945. 37:58so this module includes multi-layer
  946. 38:00switches with
  947. 38:01redundant connections to redundant cisco
  948. 38:04unified communication managers
  949. 38:06which are essential for providing
  950. 38:09high availability and reliability
  951. 38:12now for the enterprise edge okay
  952. 38:16now the enterprise edge extends ip
  953. 38:19telephony
  954. 38:21from the enterprise campus to remove
  955. 38:23locations of via ones
  956. 38:25okay the pstn or the public switch
  957. 38:28telephone network
  958. 38:29okay and the internet
  959. 38:34example voice network solution so this
  960. 38:37figure here shows the voice network
  961. 38:39solution
  962. 38:40in the cisco enterprise architecture so
  963. 38:43it
  964. 38:44illustrates how a call is initiated
  965. 38:47on the ip phone okay
  966. 38:51so going to the destination
  967. 38:54okay so how the call setup goes through
  968. 38:57the cisco unified communication managers
  969. 38:59and how the end-to-end session between
  970. 39:02the iep phones or the two iphones
  971. 39:04is established so take note that the
  972. 39:07cisco unified communications manager is
  973. 39:09involved
  974. 39:10in only the call setup okay
  975. 39:13now calls this thing for remote
  976. 39:15locations
  977. 39:16traverses the enterprise edge
  978. 39:20that is through the one and man
  979. 39:23and also if possible that could be via
  980. 39:26the side
  981. 39:27side vpn module or through the remote
  982. 39:29access and vpn module
  983. 39:32so calls distinct for public phone
  984. 39:34numbers on the pstn are routed over the
  985. 39:36enterprise
  986. 39:37edge through the remote access and vpn
  987. 39:40module so
  988. 39:42calls between ip phones
  989. 39:45reverses the building access the
  990. 39:47building distribution
  991. 39:49okay and the campus score layers and of
  992. 39:52course
  993. 39:53the server farm module so although call
  994. 39:56setup uses these modules
  995. 39:58speech employs only the building access
  996. 40:03building distribution and in some cases
  997. 40:06the campus core layers
  998. 40:11evaluating the existing data
  999. 40:13infrastructure for voice design
  1000. 40:16so evaluating the existing data when
  1001. 40:19designing ip telephony
  1002. 40:21designers must document and evaluate
  1003. 40:24the existing data infrastructure in each
  1004. 40:27enterprise module
  1005. 40:29to help determine upgrade requirements
  1006. 40:32so
  1007. 40:32items to consider includes the following
  1008. 40:35so first of course we have to talk about
  1009. 40:38performance okay
  1010. 40:41now enhance infrastructure for
  1011. 40:43additional bandwidth
  1012. 40:44consistent performance or higher
  1013. 40:47availability if required
  1014. 40:49might be necessary for the conveying or
  1015. 40:52converging environment
  1016. 40:54okay now performance evaluation includes
  1017. 40:57analyzing the network maps
  1018. 40:59device inventory information and network
  1019. 41:02baseline information
  1020. 41:04so links and devices such as with high
  1021. 41:07picked
  1022. 41:08or busy rs okay so use might have
  1023. 41:13to provide sufficient capacity for the
  1024. 41:15additional voice traffic
  1025. 41:17so devices with high cpu use
  1026. 41:20high backplane use high memory use
  1027. 41:24cubing drops or buffer misses might have
  1028. 41:28to be upgraded
  1029. 41:29okay so the next one would be
  1030. 41:32availability
  1031. 41:34okay so redundancy in all the network
  1032. 41:37modules should be reviewed
  1033. 41:38to ensure that the network can meet the
  1034. 41:41recommended ip telephony availability
  1035. 41:43goals
  1036. 41:44with the current or new network design
  1037. 41:47next would be the feature requirements
  1038. 41:49so examine the router and switch
  1039. 41:51characteristics
  1040. 41:52including the chassis module and
  1041. 41:55software version
  1042. 41:57that is to determine the ip telephony
  1043. 41:59features
  1044. 42:00okay in the existing environment
  1045. 42:04next would be the potential network
  1046. 42:06capacity or impact
  1047. 42:08okay so
  1048. 42:11for the capacity evaluate the overall
  1049. 42:14network capacity and the impact
  1050. 42:16of ip telephony on a module by module
  1051. 42:19basis
  1052. 42:20to ensure that the network meets
  1053. 42:22capacity requirements
  1054. 42:23and that there is no adverse impact
  1055. 42:27on the existing network and application
  1056. 42:29requirements
  1057. 42:30now for power assess the power
  1058. 42:33requirements
  1059. 42:34of the new network infrastructure
  1060. 42:37ensuring
  1061. 42:38that additional devices will not over
  1062. 42:40subscribe
  1063. 42:41existing power consider taking advantage
  1064. 42:44of the poi capabilities in devices
  1065. 42:50how about wireless lan okay so wireless
  1066. 42:54services in a modular network so a
  1067. 42:57wireless lan or wlan supports
  1068. 43:00mobile clients connecting to the
  1069. 43:02enterprise networks
  1070. 43:04the module clients do not have a
  1071. 43:06physical connection to the network
  1072. 43:07because
  1073. 43:07wireless lans replace the layer 1
  1074. 43:10traditional wired network usually cat5
  1075. 43:12or cat5e okay so with
  1076. 43:16the radio frequency or rf transmissions
  1077. 43:18through the air
  1078. 43:20now wireless lans are for local networks
  1079. 43:23either in building line of sight outdoor
  1080. 43:26bridging application
  1081. 43:28or combination of post so in a wireless
  1082. 43:31network
  1083. 43:32many issues can arise to prevent the
  1084. 43:34radio frequency signal from reaching all
  1085. 43:36parts of the facility
  1086. 43:39multi-pass distortion hidden node
  1087. 43:43problems
  1088. 43:44interference from other wireless sources
  1089. 43:47and near far issues
  1090. 43:50now a site survey helps find the regions
  1091. 43:54where these issues occur by defining the
  1092. 43:57contours of
  1093. 43:58radio frequency coverage in a particular
  1094. 44:01facility
  1095. 44:02discovering regions where multi-path
  1096. 44:04distortion can occur
  1097. 44:06areas where radio frequency
  1098. 44:08interferences is high
  1099. 44:10and finding solutions to eliminate such
  1100. 44:13issues so privacy and security issues
  1101. 44:16must also be considered in a wireless
  1102. 44:18network
  1103. 44:19okay because wireless lands are
  1104. 44:21typically connected to the world network
  1105. 44:24so all the modules within the enterprise
  1106. 44:26infrastructure
  1107. 44:28must be considered to ensure the success
  1108. 44:31of a wireless deployment
  1109. 44:35centralized to our less than model
  1110. 44:37components so as
  1111. 44:38illustrated on this figure here the four
  1112. 44:41main components in a centralized
  1113. 44:43wireless lan deployment
  1114. 44:44are as follows so first is basically
  1115. 44:47you need the end users devices
  1116. 44:51so a pc or other end user device in
  1117. 44:54access layer uses wireless nic to
  1118. 44:56connect
  1119. 44:57to an access point okay so that is via
  1120. 45:01radio waves next would be the access
  1121. 45:04points
  1122. 45:04or wireless aps aps or access points
  1123. 45:08typically in the access layer
  1124. 45:10are shared devices that function similar
  1125. 45:13to hub
  1126. 45:14so the cisco aps can either lightweight
  1127. 45:16or autonomous
  1128. 45:18lightweight aps are used in centralized
  1129. 45:21wireless lan deployments
  1130. 45:23a lightweight ap receives control and
  1131. 45:26configuration from the wireless lan
  1132. 45:28controller
  1133. 45:28or the wlc with which it is associated
  1134. 45:33providing a centralized point of
  1135. 45:36management
  1136. 45:37and reducing the security concern of
  1137. 45:39stolen access point
  1138. 45:41so an autonomous ap has a local
  1139. 45:43configuration and requires
  1140. 45:44local management which might make
  1141. 45:48consistent configurations difficult
  1142. 45:50and to the cost of network management
  1143. 45:53of course that would be added okay so
  1144. 45:56next would be
  1145. 45:57the wlc or the wireless lan controller a
  1146. 46:00wlc provides
  1147. 46:02management and support for wireless
  1148. 46:04services such as
  1149. 46:06roaming the wlc is typically in the core
  1150. 46:10layer of an enterprise network
  1151. 46:13and of course you have to consider the
  1152. 46:15existing switched and routed wired
  1153. 46:17networks
  1154. 46:18so the wireless ap is connect to the
  1155. 46:20wired enterprise
  1156. 46:22network so if you want to learn more
  1157. 46:24about this wireless lan concepts and
  1158. 46:26implementation
  1159. 46:28you could go ahead and check the
  1160. 46:29supplementary videos
  1161. 46:34application networking services
  1162. 46:37okay now traditional networks
  1163. 46:40handle static web pages email
  1164. 46:43and routine client server traffic
  1165. 46:46so today enterprise networks must
  1166. 46:50handle more sophisticated types of
  1167. 46:52network applications that
  1168. 46:54include voice and video so examples
  1169. 46:57includes
  1170. 46:58voice transport video conferencing
  1171. 47:01online learning
  1172. 47:02online training and audio and video
  1173. 47:05broadcasts
  1174. 47:06so applications plays increasing demands
  1175. 47:10on id infrastructure
  1176. 47:12as they evolve into highly visible
  1177. 47:14services
  1178. 47:16that represent the face of the business
  1179. 47:19to internal and external audiences
  1180. 47:22now the large amount of variety of data
  1181. 47:25requires
  1182. 47:26that the modern network be application
  1183. 47:28aware
  1184. 47:30okay so in other words
  1185. 47:33be aware of the content carried across
  1186. 47:36it
  1187. 47:37to optimally handle that content
  1188. 47:41now it is no longer enough simply to add
  1189. 47:44more bandwidth
  1190. 47:45as needs grown okay
  1191. 47:48so networks have had to become smarter
  1192. 47:52a new role of emerging for the network
  1193. 47:55as
  1194. 47:55provider of application infrastructure
  1195. 47:57services
  1196. 47:58that extend the value of applications
  1197. 48:02now either by improving delivery of
  1198. 48:04content to users
  1199. 48:06and other applications or by offloading
  1200. 48:09infrastructure functions that today
  1201. 48:11burden development
  1202. 48:13and operation teams so application
  1203. 48:16networking services or
  1204. 48:17ants provides this intelligence
  1205. 48:22okay all right
  1206. 48:25so ants can resolve application issues
  1207. 48:29okay so for example
  1208. 48:32say we have the consolidation of data
  1209. 48:35centers
  1210. 48:36result in remote employees having slower
  1211. 48:39access to centrally managed applications
  1212. 48:43so the sample and solution is basically
  1213. 48:46wide area application services can
  1214. 48:49compress
  1215. 48:50okay cache and optimize content
  1216. 48:54for remote users so that they experience
  1217. 48:58a land-like responsiveness okay
  1218. 49:02so another sample deployment issue would
  1219. 49:05be
  1220. 49:06a new website or a new web-based
  1221. 49:09ordering system
  1222. 49:10experiences a high proportion of
  1223. 49:13abandoned orders
  1224. 49:15because of poor responsiveness
  1225. 49:18during the checkout process so
  1226. 49:21the sample and solution would be
  1227. 49:24optimization of the web streams being
  1228. 49:27sent
  1229. 49:28to an e-commerce portal which reduces
  1230. 49:31latency
  1231. 49:32suppresses unnecessary reloading of web
  1232. 49:36objects
  1233. 49:37and offloads low-level tasks
  1234. 49:40from the web server okay
  1235. 49:44so what else say you have
  1236. 49:47uh a business partners need immediate
  1237. 49:51and secure electronic access to
  1238. 49:53information
  1239. 49:55held in the back office applications
  1240. 49:58such as shipment information
  1241. 50:02so the solution okay might be
  1242. 50:05security and remote connectivity
  1243. 50:07services that automatically validates a
  1244. 50:09partner's
  1245. 50:10request route it to the appropriate back
  1246. 50:13office application
  1247. 50:15and encrypt and prioritize the response
  1248. 50:19okay now last one would be
  1249. 50:23sample deployment issue purchasing
  1250. 50:26application needs
  1251. 50:27to log and track orders over a certain
  1252. 50:31value of
  1253. 50:31compliance purposes so
  1254. 50:34the and solution would be application
  1255. 50:38messaging service that intercepts
  1256. 50:40purchase orders locates the value
  1257. 50:44and logs large orders to a database
  1258. 50:47according to business
  1259. 50:49policy rules okay so that's how
  1260. 50:53ants can resolve application issues
  1261. 50:58now what are the ants components now
  1262. 51:01this
  1263. 51:01figure here illustrates an example of
  1264. 51:04ants
  1265. 51:05deployed in offices connected over a
  1266. 51:07wide area network
  1267. 51:09providing a land-like performance to
  1268. 51:12users
  1269. 51:13in the branch regional and remote
  1270. 51:16offices
  1271. 51:17so ants components are deployed
  1272. 51:20symmetrically in the data center and
  1273. 51:23distant offices
  1274. 51:25the ants components in this example are
  1275. 51:28as follows
  1276. 51:30so basically they've got this wide
  1277. 51:33application services or us
  1278. 51:36okay that is the software so the cisco
  1279. 51:39software
  1280. 51:41gives remote offices land-like
  1281. 51:44access to centrally hosted applications
  1282. 51:48servers storage and multimedia
  1283. 51:52okay so another component would be this
  1284. 51:54a wide area application engine
  1285. 51:57okay or wa appliance
  1286. 52:01now the cisco wa appliance provide a
  1287. 52:04high performance
  1288. 52:06global land like access
  1289. 52:09to enterprise applications and data now
  1290. 52:12the wa
  1291. 52:13is use either was
  1292. 52:16or was or the application and content
  1293. 52:20networking system
  1294. 52:21or the acns software now the waes
  1295. 52:26help consolidate storage servers and so
  1296. 52:29forth
  1297. 52:30in the corporate data center with only
  1298. 52:32low cost
  1299. 52:33easy to maintain network appliances in
  1300. 52:36distant offices
  1301. 52:38okay next would be series content engine
  1302. 52:41module
  1303. 52:43okay now the content engine modules can
  1304. 52:45be deployed
  1305. 52:46in a data center or branch offices
  1306. 52:49to optimize lan and one bandwidth
  1307. 52:54to accelerate deployment of
  1308. 52:56mission-critical web applications
  1309. 52:58add web content security and deliver
  1310. 53:02live and on-demand business videos
  1311. 53:10now to summarize okay
  1312. 53:13so network infrastructure services add
  1313. 53:16intelligence to the network
  1314. 53:17infrastructure
  1315. 53:19supporting application awareness within
  1316. 53:22the network
  1317. 53:23so security is a network infrastructure
  1318. 53:25service that increases the integrity of
  1319. 53:27the network
  1320. 53:29by protecting network resources and
  1321. 53:32users from internal and external threats
  1322. 53:36high availability services protect
  1323. 53:38integrity of mission critical
  1324. 53:40information
  1325. 53:41with networking platforms and topologies
  1326. 53:45that offer sufficient level of
  1327. 53:48resiliency
  1328. 53:50voice infrastructure services throughout
  1329. 53:52the enterprise are needed to support ip
  1330. 53:54telephony
  1331. 53:55so wireless services support mobile
  1332. 53:57clients and integrate it
  1333. 53:59with a wired network and last would be
  1334. 54:03the cisco ins or ans optimizes website
  1335. 54:06performance
  1336. 54:07content delivery and the security and
  1337. 54:10connectivity applications

About this transcript

This page contains the full transcript of Structuring and Modularizing the Network Part 3 by Santelmo, generated from the public captions YouTube serves with the video. The transcript has 6,031 words across 1,337 segments, with the original timestamps preserved so you can click any line to jump to that moment in the embedded player.

What you can do with it

Use the transcript to take notes, quote the speaker, build a study guide, generate a summary with ChatGPT or Claude via the YouTube Summary tool, or export it as a timed subtitle file with YouTube to SRT. You can also re-open it in the transcriber to translate the transcript into 100+ languages.

Free YouTube transcript tool

YouTube2Text is a free YouTube transcript generator — no signup, no daily limit. Paste any YouTube link and get the full transcript instantly, with timestamps, click-to-jump, translation to 100+ languages, AI prompts for ChatGPT, Claude, and Gemini, and exports to TXT, SRT, VTT, or Markdown.