Structuring and Modularizing the Network Part 3 — Transcript
Full transcript
- 0:05services
- 0:06within modular networks
- 0:11business that operate large enterprise
- 0:13networks strive to create
- 0:15an enterprise-wide network
- 0:17infrastructure and interactive services
- 0:20to serve as a solid foundation for
- 0:23business
- 0:24and collaborative applications this
- 0:27section explores
- 0:28some of the interactive services with
- 0:31respect to
- 0:32the modules that form the cisco
- 0:35enterprise architecture
- 0:37so the key point here is a network
- 0:39service is a supporting and necessary
- 0:41service
- 0:42but not an ultimate solution for example
- 0:46security and quality of service are not
- 0:48ultimate goals
- 0:50for a network they are necessary
- 0:53to enable other services and
- 0:54applications
- 0:56and are therefore classified as network
- 0:58services
- 1:00however ip telephony might be an
- 1:03ultimate goal of a network and is
- 1:06therefore
- 1:06a network application or solution rather
- 1:09than
- 1:10a service so interactive services
- 1:14since the inception of a packet-based
- 1:16communication
- 1:18networks have always offered a
- 1:20forwarding service
- 1:21forwarding is the fundamental activity
- 1:24within the internetwork
- 1:26in ip this forwarding service was built
- 1:29on the assumption
- 1:31that end nodes in the network were
- 1:33intelligent
- 1:35and that the network core did not have
- 1:39so with advances in networking software
- 1:41and hardware
- 1:42the network can offer an increasingly
- 1:44rich intelligent set of mechanisms
- 1:47for forwarding information interactive
- 1:51services
- 1:52add intelligence to the network
- 1:54infrastructure
- 1:55beyond simply moving a datagram between
- 1:59two points for example
- 2:02through intelligent network
- 2:03classification the network distinguishes
- 2:06and identifies traffic based on
- 2:08application content
- 2:10and context advanced network services
- 2:14use the traffic classification to
- 2:16regulate performance
- 2:18ensure security facilitate delivery and
- 2:22improve manageability network
- 2:25applications such as
- 2:26ip telephony support the enter
- 2:29enterprise network environment
- 2:31from the teleworker to the campus to
- 2:34the data center so these applications
- 2:37are enabled by critical network services
- 2:40and
- 2:41provide a common set of capabilities
- 2:44to support the application's
- 2:46network-wide requirements
- 2:48including security high availability
- 2:52reliability flexibility responsiveness
- 2:57and compliance
- 3:05examining the role of the infrastructure
- 3:07services
- 3:08recall the layers of the cisco sona
- 3:10framework illustrated in the future
- 3:13so the sona interactive services layer
- 3:15includes
- 3:16both application networking and
- 3:19the infrastructure services so for
- 3:22example
- 3:23the following infrastructure services
- 3:25shown earlier in the figure
- 3:26enhance classic network functions to
- 3:29support
- 3:30today's application environment by
- 3:32mapping the application's requirements
- 3:35to the resources that they require from
- 3:37the network
- 3:39so these are security services
- 3:42it ensures that all aspects of the
- 3:44network are secure
- 3:46from devices connecting to the network
- 3:49to secure
- 3:50transport to data theft prevention
- 3:53you also have mobility services
- 3:56it allows users to access network
- 3:59resources regardless of their physical
- 4:01location
- 4:03you also have this storage services
- 4:06okay so which provide distributed and
- 4:09virtual storage
- 4:10across the infrastructure you also have
- 4:14a voice and collaboration services
- 4:17it deliver the foundation by which voice
- 4:20can be carried across the network such
- 4:24as security and high availability
- 4:28you also have this compute services it
- 4:31connect and virtualize compute
- 4:33resources based on the application
- 4:36and you've got the identity services
- 4:40which map resources and policies
- 4:43to the user and the device
- 4:47now what are the reasons for internal
- 4:49security
- 4:51strongly protecting the internal
- 4:53enterprise campus by including security
- 4:55functions
- 4:56in each individual element is important
- 4:59for the following reasons
- 5:02so that would be if the security
- 5:03established at the
- 5:05enterprise edge fails an unprotected
- 5:08enterprise campus
- 5:10is vulnerable so deploying several
- 5:13layers of security increases the
- 5:15protection
- 5:16of the enterprise campus where the most
- 5:19strategic asset usually resides
- 5:24so relying on physical security is not
- 5:26enough so for example
- 5:28as a visitor to the organization a
- 5:30potential attacker
- 5:32could gain physical access to devices in
- 5:35the enterprise campus
- 5:37okay often external access does not stop
- 5:42at the enterprise edge so some
- 5:44applications
- 5:45require indirect external access
- 5:50to the enterprise campus okay
- 5:53so strong security must protect access
- 5:57to this resources
- 6:00modularizing internal security so
- 6:04examples of network services embedded
- 6:07in the infrastructure services includes
- 6:09the following
- 6:10so first you've got the network
- 6:13management okay so it includes
- 6:16land management for advanced management
- 6:19of a multi-layer switches
- 6:21routed one management for monitoring
- 6:24traffic management and access control
- 6:27to administer the routed infrastructure
- 6:30of
- 6:31a multi-service networks service
- 6:34management for managing and monitoring
- 6:36service level agreements or slas
- 6:38and vpn security management for
- 6:41optimizing
- 6:42vpn performance and security
- 6:44administration
- 6:46so high availability ensures
- 6:50end-to-end availability for services
- 6:54so that includes clients and sessions
- 6:57so implementation includes reliable
- 7:00fault tolerant
- 7:01network devices to automatically
- 7:04identify
- 7:05and overcome failures and resilient
- 7:08network technologies
- 7:10so also we need the quality of service
- 7:14so manages the delay delay variation or
- 7:17also known as the jitter
- 7:19bandwidth availability and packet loss
- 7:22parameters
- 7:23of a network to meet the diverse needs
- 7:26of voice
- 7:27video and data applications so quality
- 7:30of service features
- 7:31provide value-added functionality such
- 7:34as
- 7:34network-based application recognition
- 7:37for classifying traffic
- 7:39on the application basis so cisco ios
- 7:43ipslas or the previously called
- 7:46the service assurance agent for an
- 7:49end-to-end
- 7:50quality of service measurements so
- 7:53resource
- 7:54reservation protocol signaling for
- 7:56admission control and reservation of
- 7:57resources
- 7:59and a variety of configurable queue
- 8:01insertion
- 8:02and servicing function
- 8:05so you also have multi casting or ip
- 8:09multicasting
- 8:10so it provides a bandwidth conserving
- 8:13technology that reduces network traffic
- 8:15by delivering a single stream of
- 8:17information intended for many recipients
- 8:20throughout the transport network so
- 8:22multicasting enables
- 8:24distribution of video conferencing
- 8:27corporate communications
- 8:29distance learning software and other
- 8:31applications
- 8:33so multicast packets are replicated only
- 8:36as necessary
- 8:37by routers enabled with protocol
- 8:39independent multicast
- 8:41and other supporting multicast protocols
- 8:44that result
- 8:46in the most efficient delivery of data
- 8:49to multiple receivers so to support
- 8:51network applications efficiently
- 8:54so deploy the underlying infrastructure
- 8:56services in some
- 8:57or all modules of the enterprise network
- 9:00as
- 9:01required so this design elements can be
- 9:04replicated simply to
- 9:06other enterprise network modules
- 9:09as network changes so as a result
- 9:13modularization to small subsets of the
- 9:15overall network simplifies the network
- 9:17design
- 9:18and often reduces the network's cost
- 9:22and complexity so the following are some
- 9:26of the recommended security practices
- 9:28in each of the module so you've got at
- 9:30the building
- 9:32okay so for building access access is
- 9:35controlled
- 9:36at the port level using data link layer
- 9:39information
- 9:41some examples are filtering based on
- 9:43media access control addresses
- 9:46and the ieee 802.1x
- 9:49port authentication okay
- 9:53now on the building distribution it
- 9:55performs
- 9:56filtering to keep unnecessary traffic
- 9:59from the campus core
- 10:01this packet filtering can be considered
- 10:04a security function because it does
- 10:06prevent
- 10:07some undesired access to other modules
- 10:11so given that switches in the building
- 10:13distribution layer
- 10:15are typically multi-layer switches and
- 10:17are there for layer 3 aware
- 10:20this is the first place on the data path
- 10:22in which
- 10:23filtering based on the network layer
- 10:25information can be performed
- 10:28okay so you also have the campus core
- 10:31layer
- 10:32so this is a high speed switching
- 10:34backbone
- 10:35and should be designed to switch packets
- 10:38as quickly as possible
- 10:40so it should not perform any security
- 10:42functions
- 10:43because doing so would slow down the
- 10:46switching of packets
- 10:49so next would be the server for modules
- 10:52which primary goal
- 10:53is to provide application services to
- 10:56end users
- 10:57and devices so enterprises
- 11:00often overlook the server for module
- 11:03from a security perspective
- 11:05okay so given the high degree of access
- 11:08that most employees
- 11:10have to these servers they often become
- 11:13the primary
- 11:14goal of internally originated attacks
- 11:17so simply relying on the effective
- 11:20passwords
- 11:21does not provide a comprehensive attack
- 11:23mitigation strategy
- 11:25so using a host based in network based
- 11:28ips
- 11:29and idss so private vlans
- 11:33and access control provides a much
- 11:36more comprehensive attack response so
- 11:39for example
- 11:40onboard ideas or ips within the server
- 11:44farm
- 11:44multi-layer switches that inspects
- 11:48traffic flows okay
- 11:51now the server farm module typically
- 11:53includes
- 11:55network management systems to securely
- 11:58manage
- 11:58all the devices and hosts within the
- 12:01enterprise architecture
- 12:03so for example syslog provides an
- 12:05important information on security
- 12:07violations
- 12:08and configuration changes by lagging
- 12:10security related
- 12:12uh events authentication authorization
- 12:16and accounting and so on so on
- 12:18authentication authorization and
- 12:20accounting or triple
- 12:21a that is a security server
- 12:24okay so also works on a one-time
- 12:26password or otp
- 12:28server that is to provide a high level
- 12:31of security
- 12:33to all local and remote users
- 12:36so a and otp authentication reduces the
- 12:39likelihood of
- 12:41successful password attack let me give
- 12:43you some
- 12:44information about aaa or the
- 12:46authentication
- 12:48authorization and accounting
- 12:51so aaa is a crucial aspect of network
- 12:53security
- 12:54that should be considered during the
- 12:55network design an
- 12:57aaa server handles the following
- 13:00so first is authentication with
- 13:04authentication that pertains to who
- 13:07authentication checks the user's
- 13:09identity typically
- 13:11through a username and password
- 13:13combination
- 13:15the next a is authorization
- 13:18this pertains to what so after the user
- 13:21is authenticated
- 13:23the aaa server dictates what activity
- 13:26the user is allowed to perform on the
- 13:28network
- 13:30so the last a is accounting accounting
- 13:33pertains to
- 13:34when the aaa server can record the
- 13:38length of the session
- 13:39the services accessed during the session
- 13:43and so on so everything will be logged
- 13:45in on the accounting
- 13:47server
- 13:52how about external threats so
- 13:55when designing a network security in an
- 13:58enterprise network
- 13:59the enterprise edge is the first line of
- 14:02defense
- 14:03at which potential outside attacks
- 14:06can be stopped so the enterprise edge is
- 14:09like a wall
- 14:11with small doors and strong guards that
- 14:14efficiently control any access
- 14:17so the following for attack methods are
- 14:19commonly used in attempts
- 14:21to compromise the integrity of the
- 14:23enterprise network
- 14:24from the outside so first would be
- 14:27ip spoofing okay
- 14:31so ip spoofing attack occurs
- 14:34when a hacker uses a trusted computer to
- 14:38launch
- 14:38an attack from inside or outside the
- 14:40network
- 14:42the hacker uses either an ip address
- 14:45that is in the range of the network's
- 14:48trusted ip addresses or
- 14:50trusted external ip addresses that
- 14:53provides access to specified
- 14:55resources on the network ip spoofing
- 14:58attack
- 14:59often lead to other types of attacks
- 15:03for example a hacker might launch a
- 15:06denial of services
- 15:07or dos using spoofed
- 15:11source address to hide his identity
- 15:14okay so you also have password attacks
- 15:18so using a packet sniffer to determine
- 15:21username and passwords
- 15:23is a simple password attack however
- 15:26the term password attack usually
- 15:29referred to repeated brute force
- 15:31attempts
- 15:32to identify username and password
- 15:34information
- 15:35so trojan horse programs are another
- 15:38method
- 15:39that can be used to determine this
- 15:41information
- 15:42so a hacker might also use ip spoofing
- 15:45as a first step in system attack by
- 15:49violating the trust relationship
- 15:51based on the source ip addresses
- 15:54so first however the system would have
- 15:57to be configured to bypass password
- 15:59authentication
- 16:00so that only username is required
- 16:04so you only ha you also have this dos
- 16:07attacks
- 16:08or the denial of service attacks so dos
- 16:11attacks
- 16:12focus on making a service unavailable
- 16:15for normal use
- 16:16and are typically accomplished by
- 16:18exhausting some resource limitation
- 16:21on the network or within an operating
- 16:24system or applications
- 16:26okay so also we have this application
- 16:29layer tab
- 16:31so application layer attacks typically
- 16:33exploit
- 16:34well-known weaknesses in common software
- 16:37programs
- 16:38to gain access to a computer
- 16:44designing high availability so most
- 16:48enterprise networks
- 16:49carry mission critical information
- 16:52organizations
- 16:53that run such networks are usually
- 16:56interested in protecting the integrity
- 16:58of
- 16:59that information along with security
- 17:03this organization expects the
- 17:05internetworking platform
- 17:06to offer sufficient level of resilience
- 17:10so this section introduces another
- 17:13network infrastructure service
- 17:15high availability to ensure adequate
- 17:18connectivity for mission critical
- 17:20applications
- 17:21high availability is an essential
- 17:23component
- 17:24of an enterprise environment okay
- 17:28now designing for high availability in a
- 17:30network so redundant network design
- 17:34duplicate network links and devices
- 17:36eliminating single point of failure
- 17:39on the network that is high availability
- 17:43so the goal is to duplicate components
- 17:46whose
- 17:47failure to disable critical applications
- 17:51so because redundancy is expensive to
- 17:54deploy and maintain
- 17:55redundant topologies should be
- 17:57implemented with care so redundancy adds
- 18:01complexity to the network topology
- 18:03and to network addressing and routing so
- 18:06the level of redundancy should meet
- 18:08organizations availability
- 18:10and affordability requirements so what's
- 18:14the key point here
- 18:15so before selecting redundant design
- 18:17solutions
- 18:19analyze the business and technical goals
- 18:22and constraints
- 18:23to establish the required availability
- 18:26and affordability
- 18:28so critical application systems internet
- 18:31working devices
- 18:32and link must be identified
- 18:35so analyze the risk tolerance and the
- 18:38consequences
- 18:39of not implementing redundancy and
- 18:42ensure
- 18:43that you consider the trade-offs of
- 18:46redundancy versus cost
- 18:47and simplicity versus complexity
- 18:51so duplicate any component whose failure
- 18:54could disable critical applications
- 18:57and redundancy is not provided
- 19:01by simply duplicating all links so
- 19:04unless
- 19:05all devices are completely fault
- 19:07tolerant
- 19:08so redundant links should terminate at
- 19:11different devices
- 19:13otherwise devices are not
- 19:16fault tolerant becoming a single points
- 19:19of
- 19:22failure
- 19:24how about designing for route redundancy
- 19:28so the following types of redundancy may
- 19:30be used
- 19:31in the modules of an enterprise so
- 19:34you've got sort of
- 19:35device redundancy including card
- 19:38and port redundancy you also have
- 19:42redundant physical connections to
- 19:44critical workstations and servers
- 19:47route redundancy can also be considered
- 19:50link redundancy and even power
- 19:53redundancy
- 19:54including redundant power supplies
- 19:56integral to the network devices
- 19:59and redundant power to building's
- 20:01physical plan
- 20:04now designing for redundancy so
- 20:06redundant routes have two purposes
- 20:09so that is to minimize the effect of
- 20:11link failures
- 20:13and to minimize the effect of the
- 20:15internet working device
- 20:17failure so redundant routes might also
- 20:20be used
- 20:21for load balancing when all routes
- 20:24are up okay now possible ways
- 20:28to make connection redundant includes
- 20:30the following
- 20:31so you've got parallel physical links
- 20:34between switches and routers
- 20:36you could also have back a plan and one
- 20:38links
- 20:39for example ddr backup for less lines
- 20:45now the following are possible ways to
- 20:47make the network redundant
- 20:50so a full mess to provide complete
- 20:53redundancy
- 20:54and good performance a partial mesh
- 20:58which is less expensive and more
- 21:01scalable
- 21:02the common approach when designing the
- 21:04route redundancy is to implement
- 21:06partial redundancy by using a partial
- 21:09mesh instead of a full mesh
- 21:11and backup links to alternative devices
- 21:15so this protects only the most vital
- 21:18parts
- 21:19of the network such as links
- 21:22between the layers and the concentration
- 21:24devices
- 21:28now example of campus infrastructure
- 21:31redundancy
- 21:32so a full mesh forms any to any
- 21:36connectivity and is ideal for connecting
- 21:39a reasonably small number of devices
- 21:42however as the network topology grows
- 21:45the number of links required to maintain
- 21:47a full mesh increases exponentially
- 21:50so the number of links in a full mesh
- 21:53is uh n okay times n
- 21:57minus one divided by two okay so where n
- 22:00is the number of routers so as the
- 22:03number of router appear increases
- 22:05the bandwidth and cpu resources devoted
- 22:07to processing routing updates
- 22:09and service requests also increases
- 22:13now in a partial mesh network that is
- 22:16similar to the full mesh network with
- 22:18some of its connections
- 22:19removed okay now a partial mesh
- 22:23backbone might be appropriate for a
- 22:25campus network
- 22:26in which traffic predominantly goes
- 22:29into one centralized server farm module
- 22:33now this figure here illustrates an
- 22:35example of
- 22:36route redundancy in the campus okay
- 22:40now in this example the access layer
- 22:42switches
- 22:44are fully meshed with the distribution
- 22:46layer switches
- 22:48okay if the link or distribution switch
- 22:50fails
- 22:51an access layer switch can still
- 22:53accommodate and communicate
- 22:55with the distribution layer
- 22:58now the multi-layer switches select the
- 23:00primary and back up path
- 23:02between the axis and distribution layers
- 23:04based on the links
- 23:06metric as computed by the routing
- 23:08protocol algorithm in use
- 23:10the best path is placed in the
- 23:13forwarding table
- 23:15and in case of equal cost path
- 23:18load sharing takes place
- 23:22how about example of edge redundancy
- 23:26so designing for link redundancy it is
- 23:29often necessary to provision
- 23:31redundant media in locations where
- 23:33mission critical application traffic
- 23:35travels
- 23:37so in layer 2 switch networks
- 23:40redundant links are permitted as long as
- 23:42stp is running
- 23:45so stp guarantees one and
- 23:48only one active path within the
- 23:50broadcast domain
- 23:51avoiding problems such as broadcast
- 23:54storms
- 23:55when a broadcast storms continuously
- 23:57loops
- 23:58okay now the redundant path
- 24:01automatically activates
- 24:03when the active path goes down so
- 24:06because
- 24:06one links are often critical pieces of
- 24:09the internetwork
- 24:10redundant media are often deployed in
- 24:13one environment
- 24:15now if you will observe on this figure
- 24:17here where
- 24:18frame relay circuit is used in parallel
- 24:21with
- 24:22a backup ipc connection over the
- 24:25internet
- 24:26so backup links can use different
- 24:28technologies
- 24:29and so with the frame relay which i said
- 24:32from the previous video
- 24:33is almost obsolete okay now it is
- 24:37important that the backup provides
- 24:38sufficient capacity
- 24:40to meet the critical requirements if the
- 24:42primary route fails
- 24:44so backup links can always on or can
- 24:47always be on
- 24:49or and become active when a primary link
- 24:51goes down
- 24:52or becomes congested so you have this
- 24:56connectivity okay so one is active the
- 24:59other one is standby
- 25:03now how about high availability in the
- 25:05server farm module
- 25:07so improving the reliability of critical
- 25:10workstations and servers
- 25:12usually depends on the hardware and
- 25:15operating system software in use
- 25:17some common ways of connecting includes
- 25:19the following
- 25:20so you could have the single attachment
- 25:23okay so which is not recommended
- 25:26so when a workstation on a server has
- 25:29traffic to send to a station that is not
- 25:31local
- 25:33it must know the address of the router
- 25:35on each network segment
- 25:38so if that router fails the workstation
- 25:40or server needs a mechanism to discover
- 25:43an alternative router
- 25:45so if the workstation or server has a
- 25:47single attachment
- 25:49it needs layer 3 mechanism to
- 25:52dynamically find an alternative router
- 25:54therefore the single attachment method
- 25:57is not
- 25:58recommended okay so
- 26:01the available mechanism includes address
- 26:03resolution protocol or the arp
- 26:06you've got a router discovery protocol
- 26:09or rdp
- 26:11routing protocols such as routing
- 26:13information protocol
- 26:15rep ospf eigrp
- 26:18you could also have this hot standby
- 26:20router protocol
- 26:22okay or the hsrp the gateway
- 26:25load balancing product called jlbp and
- 26:29the virtual router redundancy protocol
- 26:31vrp
- 26:34now example attachment through a
- 26:36redundant transceiver
- 26:38okay so this is an attachment through
- 26:41redundant transceiver
- 26:42so physical redundancy with redundant
- 26:46transceiver
- 26:47is suitable in environments where the
- 26:49workstation hardware or software
- 26:51does not support redundant attachment
- 26:54options
- 26:55okay
- 26:59now in this diagram here it is an
- 27:01example of attachment
- 27:02through redundant and icd okay
- 27:06so attachment through redundant network
- 27:08interface cards or nic
- 27:10some environments for example most unix
- 27:12servers
- 27:13support redundant attachment through
- 27:15dual analysis
- 27:17so primary and backup so the device
- 27:20drivers
- 27:21represents this attachment as a single
- 27:24interface
- 27:25to the operating system
- 27:28now for fast ethernet or giga ethernet
- 27:31port bundles so fast easter channel
- 27:35and gigabit ether channel port bundles
- 27:38group
- 27:38multiple pass or gigabit ethernet ports
- 27:42into a single logical transmission path
- 27:45between a switch
- 27:46and a router so host or another switch
- 27:50so stp treats the easter channel as one
- 27:53logical length
- 27:55so the switch distributes frame across
- 27:57the ports in an insert channel
- 28:00so this load balancing was originally
- 28:02done
- 28:03based only on map addresses so however
- 28:07newer implementations can also load
- 28:09balance
- 28:10based on ip addresses or layer 4 port
- 28:13numbers
- 28:15so source destination or source and
- 28:18destination addresses
- 28:19or port numbers can be used so if a port
- 28:23within an ether channel fails traffic
- 28:26previously carried over the field port
- 28:28reverts to the remaining ports
- 28:31within the insert channel so if you want
- 28:33to learn more about insert channel you
- 28:35could go ahead and check the
- 28:36supplementary videos on easter channel
- 28:42voice transport overview so voice
- 28:45services
- 28:46in a modular network design so to ensure
- 28:49successful implementation of voice
- 28:51applications
- 28:53network designers must consider the
- 28:56enterprise
- 28:57services in infrastructure in edge
- 28:59configuration
- 29:00for example to support voip
- 29:03the underlying ip infrastructure must be
- 29:06functioning
- 29:06and robust in other words
- 29:10don't even think of adding voice to a
- 29:12network experiencing other problems such
- 29:14as
- 29:14congestion or network failures
- 29:18okay now two voice implementations
- 29:22voice transport is general term so that
- 29:24can be divided
- 29:25into the following two implementations
- 29:27here okay
- 29:29so you've got the voip or the voice over
- 29:31ip
- 29:32and the ip telephony now voip
- 29:37uses voice enabled routers to convert
- 29:40analog voice
- 29:41into ip packets or packetized
- 29:45digital voice channels and route those
- 29:48packets between the corresponding
- 29:50locations
- 29:52users do not often notice that voip is
- 29:55implemented in the network
- 29:57so they use their traditional phones
- 30:00which
- 30:01are connected to the pbx however
- 30:04the pbx is not connected to pstn or to
- 30:07another
- 30:08pbx okay so back to a voice enabled
- 30:11router that
- 30:12is an entry point to voip
- 30:16so voice enabled routers can also
- 30:18terminate ip
- 30:19phones using session initiation protocol
- 30:23for call control and signaling so the
- 30:26next one would be
- 30:27ip telephony so for ip telephony
- 30:32traditional phones are replaced with
- 30:35iphones
- 30:37so a single or a server for call
- 30:40control and signaling such as this cisco
- 30:43unified communication manager
- 30:45okay so the ip phone
- 30:49itself performs voice to ip conversion
- 30:52and no voice enabled routers are
- 30:54required within the enterprise network
- 30:57however if a congestion to the pstn is
- 31:01required
- 31:01a voice enabled router or other gateway
- 31:05in the enterprise edge is added
- 31:08where calls are forwarded to the pstn
- 31:13so both implementation voip and ip
- 31:16telephony
- 31:17require properly designed networks
- 31:21so using a modular approach in voice
- 31:24transport design
- 31:26that is especially important because of
- 31:28the voice sensitivity to delay
- 31:30and the complexity of troubleshooting
- 31:32voice networks
- 31:34so all cisco enterprise architecture
- 31:36modules
- 31:37are involved in voice transport design
- 31:44ip telephony components so ip telephony
- 31:48components
- 31:49an ip telephony network contains four
- 31:52main voice specific components okay
- 31:56so this includes an iphone's okay
- 31:59an iphone are used to place calls in an
- 32:02ip telephony network
- 32:04they perform voice to ip and vice versa
- 32:08coding and compression
- 32:09using special hardware so iphones
- 32:13offer services such as directory lookup
- 32:17and internet access so the phones
- 32:20are active network devices that require
- 32:23power to operate
- 32:25so power is applied through the lan
- 32:26connection using the poe
- 32:29or with external power supply okay
- 32:32so the next one would be switches with
- 32:34inline power so you've got switches
- 32:36there
- 32:37so switches with inline power are poi
- 32:39enabled the modular wiring closet
- 32:42to provide centralized power for the
- 32:45telephony networks
- 32:46so these switches are similar to
- 32:49traditional switches
- 32:50with an added option to provide power to
- 32:54the lan ports
- 32:55where iphones are connected
- 32:58now the switches also perform some basic
- 33:00uos tasks
- 33:02such as packet classification which is
- 33:05required
- 33:06for prioritizing voice through the
- 33:09network
- 33:10so also you have this
- 33:13voice or the call processing manager
- 33:17okay or the call processing engine now
- 33:20the call processing manager
- 33:22such as the cisco unified communication
- 33:24manager
- 33:25it provides central control and
- 33:27configuration management for iphones
- 33:30so it provides the core functionality to
- 33:33initialize
- 33:34ip telephony devices and to perform
- 33:38all setup and call routing throughout
- 33:40the network
- 33:42okay now this cisco unified
- 33:44communication manager can be clustered
- 33:46to provide distributed scalable and
- 33:49highly available ip telephony model
- 33:52so adding more servers to plaster of
- 33:55servers
- 33:56provides more capacity to the system
- 34:00okay next would be the voice gateway
- 34:05okay so voice gateways also called voice
- 34:08enabled routers
- 34:10or voice enabled switches provide voice
- 34:13services such as
- 34:14voice to ip coding and compression so
- 34:17pstn access
- 34:19ipp packet routing backup call
- 34:22processing
- 34:23and voice services so backup
- 34:27backup call processing allows voice
- 34:30gateways
- 34:31to take over call processing in case of
- 34:34the primary call processing manager
- 34:36fails
- 34:37so voice gateways typically support
- 34:40a subset of a call processing
- 34:42functionality supported by
- 34:44this unified communication manager
- 34:48so other components of ip telephony
- 34:50network includes
- 34:52a robust ip network of course okay
- 34:55so voice messaging and applications
- 34:58and a digital signal processor resources
- 35:01to process voice functions in hardware
- 35:04so which is much faster than doing it in
- 35:07software
- 35:08so these components are located
- 35:10throughout the enterprise network
- 35:12as you can see here on this diagram
- 35:19modular approach in voice network design
- 35:24so implementing voice requires deploying
- 35:26delay sensitive services
- 35:28such as end-to-end in all enterprise
- 35:31network modules
- 35:34so use the modular approach to simplify
- 35:36design
- 35:38implementation and especially
- 35:40troubleshooting
- 35:42so voice implementation requires some
- 35:44modification to the existing enterprise
- 35:46network
- 35:47okay so that is in terms of performance
- 35:50capacity and availability because it is
- 35:52an end-to-end solution
- 35:54so for example so clients iphones are
- 35:58located
- 35:59in the building access layer
- 36:02okay and then
- 36:05the call processing manager is located
- 36:07in
- 36:08the server farm okay so therefore
- 36:11all modules in the enterprise network
- 36:14are involved
- 36:14in voice processing and must be
- 36:17adequately considered
- 36:20voice affects various modules of the
- 36:23network
- 36:24as follows now on the building
- 36:27access layer iphones and and user
- 36:30computers are attached
- 36:32to a layer two switches here so switches
- 36:35provides
- 36:36power to ip phones and provide
- 36:39quality of service packet classification
- 36:41and marking
- 36:42which is essential for proper voice
- 36:45packet manipulation
- 36:47through the network okay now
- 36:50on the building distribution layer this
- 36:53layer performs
- 36:54packet reclassification if building
- 36:57access
- 36:58is unable to classify packets or is not
- 37:02within
- 37:02trusted boundary so it aggregates
- 37:06the building access layer switches or
- 37:08the wiring closets
- 37:10and provides redundant objects to the
- 37:12campus core layer
- 37:15okay now on the campus core layer
- 37:19this forms the network score so all
- 37:22enterprise
- 37:23network modules are attached to it
- 37:25however
- 37:26okay so this could be virtually
- 37:29all traffic between application servers
- 37:32and clients
- 37:32traverses the campus core
- 37:36and with the advent of wire speed
- 37:38multi-layer gigabit switching devices
- 37:41land back bones might migrate it or
- 37:44might have migrated
- 37:46to switch gigabit architectures that
- 37:48combine
- 37:49all the benefits of routing with wire
- 37:52speed packet forwarding
- 37:54okay now on the server farm
- 37:58so this module includes multi-layer
- 38:00switches with
- 38:01redundant connections to redundant cisco
- 38:04unified communication managers
- 38:06which are essential for providing
- 38:09high availability and reliability
- 38:12now for the enterprise edge okay
- 38:16now the enterprise edge extends ip
- 38:19telephony
- 38:21from the enterprise campus to remove
- 38:23locations of via ones
- 38:25okay the pstn or the public switch
- 38:28telephone network
- 38:29okay and the internet
- 38:34example voice network solution so this
- 38:37figure here shows the voice network
- 38:39solution
- 38:40in the cisco enterprise architecture so
- 38:43it
- 38:44illustrates how a call is initiated
- 38:47on the ip phone okay
- 38:51so going to the destination
- 38:54okay so how the call setup goes through
- 38:57the cisco unified communication managers
- 38:59and how the end-to-end session between
- 39:02the iep phones or the two iphones
- 39:04is established so take note that the
- 39:07cisco unified communications manager is
- 39:09involved
- 39:10in only the call setup okay
- 39:13now calls this thing for remote
- 39:15locations
- 39:16traverses the enterprise edge
- 39:20that is through the one and man
- 39:23and also if possible that could be via
- 39:26the side
- 39:27side vpn module or through the remote
- 39:29access and vpn module
- 39:32so calls distinct for public phone
- 39:34numbers on the pstn are routed over the
- 39:36enterprise
- 39:37edge through the remote access and vpn
- 39:40module so
- 39:42calls between ip phones
- 39:45reverses the building access the
- 39:47building distribution
- 39:49okay and the campus score layers and of
- 39:52course
- 39:53the server farm module so although call
- 39:56setup uses these modules
- 39:58speech employs only the building access
- 40:03building distribution and in some cases
- 40:06the campus core layers
- 40:11evaluating the existing data
- 40:13infrastructure for voice design
- 40:16so evaluating the existing data when
- 40:19designing ip telephony
- 40:21designers must document and evaluate
- 40:24the existing data infrastructure in each
- 40:27enterprise module
- 40:29to help determine upgrade requirements
- 40:32so
- 40:32items to consider includes the following
- 40:35so first of course we have to talk about
- 40:38performance okay
- 40:41now enhance infrastructure for
- 40:43additional bandwidth
- 40:44consistent performance or higher
- 40:47availability if required
- 40:49might be necessary for the conveying or
- 40:52converging environment
- 40:54okay now performance evaluation includes
- 40:57analyzing the network maps
- 40:59device inventory information and network
- 41:02baseline information
- 41:04so links and devices such as with high
- 41:07picked
- 41:08or busy rs okay so use might have
- 41:13to provide sufficient capacity for the
- 41:15additional voice traffic
- 41:17so devices with high cpu use
- 41:20high backplane use high memory use
- 41:24cubing drops or buffer misses might have
- 41:28to be upgraded
- 41:29okay so the next one would be
- 41:32availability
- 41:34okay so redundancy in all the network
- 41:37modules should be reviewed
- 41:38to ensure that the network can meet the
- 41:41recommended ip telephony availability
- 41:43goals
- 41:44with the current or new network design
- 41:47next would be the feature requirements
- 41:49so examine the router and switch
- 41:51characteristics
- 41:52including the chassis module and
- 41:55software version
- 41:57that is to determine the ip telephony
- 41:59features
- 42:00okay in the existing environment
- 42:04next would be the potential network
- 42:06capacity or impact
- 42:08okay so
- 42:11for the capacity evaluate the overall
- 42:14network capacity and the impact
- 42:16of ip telephony on a module by module
- 42:19basis
- 42:20to ensure that the network meets
- 42:22capacity requirements
- 42:23and that there is no adverse impact
- 42:27on the existing network and application
- 42:29requirements
- 42:30now for power assess the power
- 42:33requirements
- 42:34of the new network infrastructure
- 42:37ensuring
- 42:38that additional devices will not over
- 42:40subscribe
- 42:41existing power consider taking advantage
- 42:44of the poi capabilities in devices
- 42:50how about wireless lan okay so wireless
- 42:54services in a modular network so a
- 42:57wireless lan or wlan supports
- 43:00mobile clients connecting to the
- 43:02enterprise networks
- 43:04the module clients do not have a
- 43:06physical connection to the network
- 43:07because
- 43:07wireless lans replace the layer 1
- 43:10traditional wired network usually cat5
- 43:12or cat5e okay so with
- 43:16the radio frequency or rf transmissions
- 43:18through the air
- 43:20now wireless lans are for local networks
- 43:23either in building line of sight outdoor
- 43:26bridging application
- 43:28or combination of post so in a wireless
- 43:31network
- 43:32many issues can arise to prevent the
- 43:34radio frequency signal from reaching all
- 43:36parts of the facility
- 43:39multi-pass distortion hidden node
- 43:43problems
- 43:44interference from other wireless sources
- 43:47and near far issues
- 43:50now a site survey helps find the regions
- 43:54where these issues occur by defining the
- 43:57contours of
- 43:58radio frequency coverage in a particular
- 44:01facility
- 44:02discovering regions where multi-path
- 44:04distortion can occur
- 44:06areas where radio frequency
- 44:08interferences is high
- 44:10and finding solutions to eliminate such
- 44:13issues so privacy and security issues
- 44:16must also be considered in a wireless
- 44:18network
- 44:19okay because wireless lands are
- 44:21typically connected to the world network
- 44:24so all the modules within the enterprise
- 44:26infrastructure
- 44:28must be considered to ensure the success
- 44:31of a wireless deployment
- 44:35centralized to our less than model
- 44:37components so as
- 44:38illustrated on this figure here the four
- 44:41main components in a centralized
- 44:43wireless lan deployment
- 44:44are as follows so first is basically
- 44:47you need the end users devices
- 44:51so a pc or other end user device in
- 44:54access layer uses wireless nic to
- 44:56connect
- 44:57to an access point okay so that is via
- 45:01radio waves next would be the access
- 45:04points
- 45:04or wireless aps aps or access points
- 45:08typically in the access layer
- 45:10are shared devices that function similar
- 45:13to hub
- 45:14so the cisco aps can either lightweight
- 45:16or autonomous
- 45:18lightweight aps are used in centralized
- 45:21wireless lan deployments
- 45:23a lightweight ap receives control and
- 45:26configuration from the wireless lan
- 45:28controller
- 45:28or the wlc with which it is associated
- 45:33providing a centralized point of
- 45:36management
- 45:37and reducing the security concern of
- 45:39stolen access point
- 45:41so an autonomous ap has a local
- 45:43configuration and requires
- 45:44local management which might make
- 45:48consistent configurations difficult
- 45:50and to the cost of network management
- 45:53of course that would be added okay so
- 45:56next would be
- 45:57the wlc or the wireless lan controller a
- 46:00wlc provides
- 46:02management and support for wireless
- 46:04services such as
- 46:06roaming the wlc is typically in the core
- 46:10layer of an enterprise network
- 46:13and of course you have to consider the
- 46:15existing switched and routed wired
- 46:17networks
- 46:18so the wireless ap is connect to the
- 46:20wired enterprise
- 46:22network so if you want to learn more
- 46:24about this wireless lan concepts and
- 46:26implementation
- 46:28you could go ahead and check the
- 46:29supplementary videos
- 46:34application networking services
- 46:37okay now traditional networks
- 46:40handle static web pages email
- 46:43and routine client server traffic
- 46:46so today enterprise networks must
- 46:50handle more sophisticated types of
- 46:52network applications that
- 46:54include voice and video so examples
- 46:57includes
- 46:58voice transport video conferencing
- 47:01online learning
- 47:02online training and audio and video
- 47:05broadcasts
- 47:06so applications plays increasing demands
- 47:10on id infrastructure
- 47:12as they evolve into highly visible
- 47:14services
- 47:16that represent the face of the business
- 47:19to internal and external audiences
- 47:22now the large amount of variety of data
- 47:25requires
- 47:26that the modern network be application
- 47:28aware
- 47:30okay so in other words
- 47:33be aware of the content carried across
- 47:36it
- 47:37to optimally handle that content
- 47:41now it is no longer enough simply to add
- 47:44more bandwidth
- 47:45as needs grown okay
- 47:48so networks have had to become smarter
- 47:52a new role of emerging for the network
- 47:55as
- 47:55provider of application infrastructure
- 47:57services
- 47:58that extend the value of applications
- 48:02now either by improving delivery of
- 48:04content to users
- 48:06and other applications or by offloading
- 48:09infrastructure functions that today
- 48:11burden development
- 48:13and operation teams so application
- 48:16networking services or
- 48:17ants provides this intelligence
- 48:22okay all right
- 48:25so ants can resolve application issues
- 48:29okay so for example
- 48:32say we have the consolidation of data
- 48:35centers
- 48:36result in remote employees having slower
- 48:39access to centrally managed applications
- 48:43so the sample and solution is basically
- 48:46wide area application services can
- 48:49compress
- 48:50okay cache and optimize content
- 48:54for remote users so that they experience
- 48:58a land-like responsiveness okay
- 49:02so another sample deployment issue would
- 49:05be
- 49:06a new website or a new web-based
- 49:09ordering system
- 49:10experiences a high proportion of
- 49:13abandoned orders
- 49:15because of poor responsiveness
- 49:18during the checkout process so
- 49:21the sample and solution would be
- 49:24optimization of the web streams being
- 49:27sent
- 49:28to an e-commerce portal which reduces
- 49:31latency
- 49:32suppresses unnecessary reloading of web
- 49:36objects
- 49:37and offloads low-level tasks
- 49:40from the web server okay
- 49:44so what else say you have
- 49:47uh a business partners need immediate
- 49:51and secure electronic access to
- 49:53information
- 49:55held in the back office applications
- 49:58such as shipment information
- 50:02so the solution okay might be
- 50:05security and remote connectivity
- 50:07services that automatically validates a
- 50:09partner's
- 50:10request route it to the appropriate back
- 50:13office application
- 50:15and encrypt and prioritize the response
- 50:19okay now last one would be
- 50:23sample deployment issue purchasing
- 50:26application needs
- 50:27to log and track orders over a certain
- 50:31value of
- 50:31compliance purposes so
- 50:34the and solution would be application
- 50:38messaging service that intercepts
- 50:40purchase orders locates the value
- 50:44and logs large orders to a database
- 50:47according to business
- 50:49policy rules okay so that's how
- 50:53ants can resolve application issues
- 50:58now what are the ants components now
- 51:01this
- 51:01figure here illustrates an example of
- 51:04ants
- 51:05deployed in offices connected over a
- 51:07wide area network
- 51:09providing a land-like performance to
- 51:12users
- 51:13in the branch regional and remote
- 51:16offices
- 51:17so ants components are deployed
- 51:20symmetrically in the data center and
- 51:23distant offices
- 51:25the ants components in this example are
- 51:28as follows
- 51:30so basically they've got this wide
- 51:33application services or us
- 51:36okay that is the software so the cisco
- 51:39software
- 51:41gives remote offices land-like
- 51:44access to centrally hosted applications
- 51:48servers storage and multimedia
- 51:52okay so another component would be this
- 51:54a wide area application engine
- 51:57okay or wa appliance
- 52:01now the cisco wa appliance provide a
- 52:04high performance
- 52:06global land like access
- 52:09to enterprise applications and data now
- 52:12the wa
- 52:13is use either was
- 52:16or was or the application and content
- 52:20networking system
- 52:21or the acns software now the waes
- 52:26help consolidate storage servers and so
- 52:29forth
- 52:30in the corporate data center with only
- 52:32low cost
- 52:33easy to maintain network appliances in
- 52:36distant offices
- 52:38okay next would be series content engine
- 52:41module
- 52:43okay now the content engine modules can
- 52:45be deployed
- 52:46in a data center or branch offices
- 52:49to optimize lan and one bandwidth
- 52:54to accelerate deployment of
- 52:56mission-critical web applications
- 52:58add web content security and deliver
- 53:02live and on-demand business videos
- 53:10now to summarize okay
- 53:13so network infrastructure services add
- 53:16intelligence to the network
- 53:17infrastructure
- 53:19supporting application awareness within
- 53:22the network
- 53:23so security is a network infrastructure
- 53:25service that increases the integrity of
- 53:27the network
- 53:29by protecting network resources and
- 53:32users from internal and external threats
- 53:36high availability services protect
- 53:38integrity of mission critical
- 53:40information
- 53:41with networking platforms and topologies
- 53:45that offer sufficient level of
- 53:48resiliency
- 53:50voice infrastructure services throughout
- 53:52the enterprise are needed to support ip
- 53:54telephony
- 53:55so wireless services support mobile
- 53:57clients and integrate it
- 53:59with a wired network and last would be
- 54:03the cisco ins or ans optimizes website
- 54:06performance
- 54:07content delivery and the security and
- 54:10connectivity applications
About this transcript
This page contains the full transcript of Structuring and Modularizing the Network Part 3 by Santelmo, generated from the public captions YouTube serves with the video. The transcript has 6,031 words across 1,337 segments, with the original timestamps preserved so you can click any line to jump to that moment in the embedded player.
What you can do with it
Use the transcript to take notes, quote the speaker, build a study guide, generate a summary with ChatGPT or Claude via the YouTube Summary tool, or export it as a timed subtitle file with YouTube to SRT. You can also re-open it in the transcriber to translate the transcript into 100+ languages.
Free YouTube transcript tool
YouTube2Text is a free YouTube transcript generator — no signup, no daily limit. Paste any YouTube link and get the full transcript instantly, with timestamps, click-to-jump, translation to 100+ languages, AI prompts for ChatGPT, Claude, and Gemini, and exports to TXT, SRT, VTT, or Markdown.