Structuring and Modularizing the Network Part 4 — Transcript
Full transcript
- 0:04identifying network management protocols
- 0:06and features
- 0:10proper network management is a critical
- 0:12component
- 0:13of an efficient network network
- 0:16administrators
- 0:17need tools to monitor the functionality
- 0:20of the network devices
- 0:22the connections between them and the
- 0:24services they provide
- 0:26snmp or the simple network management
- 0:28protocol has become the de facto
- 0:30standard for use in network management
- 0:32solutions
- 0:34and is tightly connected with remote
- 0:36monitoring or harmon
- 0:38and management information basis or mib
- 0:42each managed device in the network has
- 0:45several variables that
- 0:47quantify the state of the device you can
- 0:50monitor managed devices
- 0:52by reading the values of these variables
- 0:55and
- 0:56you can control managed devices by
- 0:58writing values into these variables
- 1:01so this section introduces snmp
- 1:04and describes the differences between
- 1:06snmp versions
- 1:07one two and three
- 1:11the role of mibs and snmp and harmon's
- 1:14monitoring is described
- 1:16the cisco network discovery protocol
- 1:19or the cdp is introduced this section
- 1:23concludes with a description of methods
- 1:26for gathering network statistics
- 1:29let's get started
- 1:32network management architecture
- 1:36so this figure illustrates a generic
- 1:38network management
- 1:40architecture so the network management
- 1:43architecture consists
- 1:44of the following so first there should
- 1:47be
- 1:47an nms or the network management system
- 1:52this is a system that executes
- 1:54applications
- 1:55that monitor and control managed devices
- 1:59nmss provide a bulk of processing
- 2:03and memory resources that are required
- 2:06for network management
- 2:08so next would be the network management
- 2:10protocol
- 2:12so a protocol that facilitates the
- 2:14exchange of mib information between
- 2:17the nms and the managed devices so this
- 2:20includes
- 2:22the snmp or the simple network
- 2:24management protocol
- 2:25the mib or the management information
- 2:28base
- 2:28and armon or the remote monitoring
- 2:32also there should be managed devices
- 2:37so a device such as router computers and
- 2:41nodes
- 2:42those are managed devices
- 2:45okay so these are managed by the network
- 2:47management system
- 2:50you also have management agents
- 2:53so these are software on managed devices
- 2:57that collect and store management
- 2:58information
- 3:00including snmp agents and armored agents
- 3:06next would be the management information
- 3:10okay so data that is interest
- 3:13to a device management usually stored in
- 3:16the mips
- 3:18so a variety of network management
- 3:20applications can be used on network
- 3:22management systems
- 3:23the choice depends on the network
- 3:25platform such as hardware and
- 3:28operating systems the management
- 3:30information resides on network
- 3:32devices management agents
- 3:35that resides on the device collect and
- 3:37store data
- 3:38in a standardized data definition known
- 3:41as the mib
- 3:43or the management information base okay
- 3:46now the network management application
- 3:48uses snmp
- 3:50or other network management protocols
- 3:53to retrieve the data that the management
- 3:56agents
- 3:57collect and the retrieved data is
- 4:00typically processed and prepared
- 4:02for display with the gui or graphical
- 4:05user interface
- 4:07which allows the operator to use
- 4:09graphical representation of the network
- 4:12to control manage devices and program
- 4:16the network management application
- 4:22okay so let's have the simple network
- 4:24management protocol or snmp overview
- 4:27okay so snmp has become the de facto
- 4:30standard
- 4:31for network management so snmp is a
- 4:35simple solution
- 4:36that requires a little code to implement
- 4:39which enables
- 4:40vendors to easily build snmp
- 4:43agents for their products so in addition
- 4:48snmp is often the foundation of the
- 4:50network management architecture
- 4:53so snmp defines how management
- 4:55information is exchanged
- 4:57between network management applications
- 4:59and management agents
- 5:02now this figure here shows the terms
- 5:05used in snmp now they are described as
- 5:09follows
- 5:10so let's start with the manager
- 5:13okay so the manager a network management
- 5:16application
- 5:17in an nms periodically pulls
- 5:20the snmp agents that reside on the
- 5:24managed devices
- 5:25for the data thereby enabling
- 5:28information
- 5:29to be displayed using a graphical user
- 5:32interface or gui
- 5:33on the nmss a disadvantage
- 5:36of periodic snmp polling is the possible
- 5:40delay between
- 5:41when an event occurs and when it is
- 5:44collected by the nms
- 5:47so there is a trade-off between
- 5:50falling frequency and bandwidth
- 5:53usage okay so
- 5:56next would be the protocol so the snmp
- 6:00is a protocol for
- 6:01message exchange it uses user datagram
- 6:05protocol or udp
- 6:08so to send and retrieve management
- 6:10information such as
- 6:11the mib variables
- 6:15next would be manage devices okay
- 6:18a managed device router switches
- 6:22computers these are being managed by the
- 6:25manager
- 6:27okay and also you have management agents
- 6:30or agent these are snmp management
- 6:33agents
- 6:34reside on the managed devices to collect
- 6:36and store a range of information
- 6:38about the device and its operation
- 6:41response to manager's request
- 6:44and generate traps to inform the manager
- 6:47about certain events
- 6:49now snmp traps are sent by the
- 6:51management agents
- 6:53to the nms when certain events occur
- 6:57so trap notifications could result
- 7:00in substantial network and agent
- 7:03resource savings
- 7:04by eliminating the need for some snmp
- 7:07polling requests
- 7:09and the other one would be the mib
- 7:13or the management information base so
- 7:15the mib
- 7:16okay or the management agent collects
- 7:19data
- 7:20and store it locally in the mib so mib
- 7:23is basically
- 7:24the storage or the database of objects
- 7:27about the device
- 7:29okay now community strings which are
- 7:32similar to passwords
- 7:34control access to the mib so to access a
- 7:37set of
- 7:38mib variables the user must specify
- 7:42the appropriate read or write community
- 7:44string
- 7:45otherwise access is denied
- 7:51snmp version 1 message types
- 7:55so the initial version of the snmp snmp
- 7:58version 1
- 7:59is defined in the rfc 1157
- 8:02the simple network management protocol
- 8:04or snmp
- 8:06so the protocol simplicity is apparent
- 8:09by the set of operations
- 8:11that are available so this figure here
- 8:14shows the basic snmp messages
- 8:17which the manager uses to transfer data
- 8:20from the agents okay
- 8:24to the manager okay now these messages
- 8:28are described as follows so first you've
- 8:30got
- 8:31get request so used by the manager to
- 8:35request a specific
- 8:36mib variable from the agent
- 8:40next would be get next request
- 8:43these are used after the initial get
- 8:46request to retrieve the next
- 8:47object instance from a table or list
- 8:52next would be set request used to set
- 8:55a mib variable on the agent
- 8:59and then get response used by agent
- 9:02to respond to a manager's get request or
- 9:05get next request message
- 9:08and the last one would be trump used by
- 9:11the
- 9:12agent to transmit an unsolicited alarm
- 9:16to the manager so a trap message is sent
- 9:20when specific conditions occur such as
- 9:23the change in the state of the device a
- 9:26device or component failure
- 9:28and an agent initialization or
- 9:34restart
- 9:36snmp version 2. so snmp version 2
- 9:39is a revised protocol that includes
- 9:42performance
- 9:43and manager to manage your communication
- 9:45improvements on snmp
- 9:48so snmp version 2 was introduced with
- 9:50rfc
- 9:521441 introduction to version 2
- 9:55of the internet standard network
- 9:57management framework
- 9:59but members of the ietf subcommittee
- 10:02could not agree
- 10:03on several sections of snmp version 2
- 10:05specifications
- 10:07so primarily the protocol security and
- 10:10administrative
- 10:11needs so several attempts to achieve
- 10:15acceptance of snmp version 2 have been
- 10:18made
- 10:18by releasing experimental modified
- 10:20versions
- 10:22so commonly known as the snmp v2
- 10:25okay snmp v2
- 10:28u snmp v1 plus
- 10:32and snmpv 1.5 which does not contain
- 10:36the disputed parts so
- 10:40the community based snmp version 2
- 10:43or the snmp version 2c which is defined
- 10:46in the rfc
- 10:471901 introduction to community based
- 10:51snmp version 2 is referred to as
- 10:54snmp version 2 because it is the common
- 10:56implementation
- 10:58okay now the c stands for community
- 11:01based
- 11:02security so because snmp version 2c uses
- 11:06the same community strings as snmp
- 11:08version 1
- 11:10for read and write access so snmp
- 11:13version
- 11:142 changes include the introduction of
- 11:17the following two
- 11:18new message types so basically you've
- 11:21got this
- 11:22get bulk request
- 11:25which is used for retrieving large
- 11:27amounts of data such as tables
- 11:30okay this message reduces repetitive
- 11:33requests and replies so thereby
- 11:36improving
- 11:37performance next one would be
- 11:40the inform request used to alert the
- 11:43snmp manager
- 11:45of the specific condition unlike and
- 11:47acknowledge
- 11:48trapped messages inform request messages
- 11:51are acknowledged
- 11:53a managed device sends an inform request
- 11:56to the nms
- 11:57the nms acknowledges the receipt of the
- 12:00message
- 12:01by sending a response message back to
- 12:04the managed device
- 12:06so another improvement of snmp version 2
- 12:09over snmp version 1 is the addition of
- 12:12new data types with 64-bit counters
- 12:15because 32-bit counters were quickly
- 12:18overflowed
- 12:19by fast network interfaces
- 12:24snmp version 3. so snmp version 3 is the
- 12:28latest
- 12:29snmp version to overcome the
- 12:32person2c okay and
- 12:35it became a full standard so each
- 12:39introduction has moved snmp version 1
- 12:42and snmp version 2 to historic status
- 12:46now we have two types of status for the
- 12:48standards
- 12:49so one mentioned was historic that means
- 12:53the old version was replaced with
- 12:56a new version so something like snmp
- 12:59version one
- 13:00okay it's already historic okay snmp
- 13:03version two
- 13:04is already stored and at the same time
- 13:07they are obsolete because they are
- 13:08obsoleted by a new releases or a new
- 13:11version
- 13:12okay now snmp version 3 which is
- 13:15described in the rfc
- 13:173410 through 3415
- 13:21ads methods to ensure the secure
- 13:24transmission of critical data to and
- 13:27from the managed
- 13:28devices so snmp version 3
- 13:32introduces the following three security
- 13:34levels here
- 13:35so you've got no auth no priv
- 13:39so that means without authentication and
- 13:41without
- 13:42privacy or encryption
- 13:46next would be us not brief
- 13:49okay so there is an authentication
- 13:52but without privacy authentication is
- 13:55based on the hash
- 13:56based message authentication code
- 13:59message digest 5
- 14:01or the hmac secure hash algorithms
- 14:04okay you also have the auth brief
- 14:08so with authentication as described
- 14:09early and privacy using the 56-bit
- 14:12cyber block chaining data encryption
- 14:15standard encryption standard
- 14:17so security levels can be specified per
- 14:20user or per group of users via direct
- 14:24interaction
- 14:25with the managed device or
- 14:28via snmp operations so security levels
- 14:32determine which
- 14:33snmp objects or user
- 14:37can access for reading writing or
- 14:40creating
- 14:41and the list of notifications that users
- 14:43can
- 14:44receive
- 14:49mib definition okay so the internet
- 14:52mib hierarchy now as shown here in the
- 14:56figure
- 14:57the mib structure is logically
- 14:59represented
- 15:01by a binary or a tree okay
- 15:04hierarchy so the root of the tree
- 15:08is unnamed okay and splits into three
- 15:12main branches so basically consultative
- 15:16committee for
- 15:17international telegraph and telephone
- 15:20the ccit okay the iso
- 15:25and the iso cc itt
- 15:28now these branches and those that fall
- 15:31below the category are identified with
- 15:33short text
- 15:34strings and integers
- 15:38now text strings describe object names
- 15:41whereas integers form object identifiers
- 15:46that allow software create compact
- 15:49encoded representation of the names
- 15:52now the object identifier in the
- 15:54internet mib hierarchy is the sequence
- 15:56of numeric labels
- 15:57on the nodes along the path from root
- 16:01to the object the internet standard mib
- 16:04is represented by the object identifier
- 16:07something like
- 16:111.3.6.1.2.1
- 16:13which can also be expressed as
- 16:17iso.org that dod
- 16:20that internet dot mgmt
- 16:24dot mib
- 16:29mib definition so the cisco private
- 16:33section of the mi b3 contains
- 16:35private managed objects which
- 16:39are introduced by cisco such as
- 16:42following objects for routers so small
- 16:45medium large and huge buffers
- 16:48primary and secondary memory and
- 16:50proprietary protocols
- 16:52so private definitions of managed
- 16:54objects
- 16:55must be compiled into the nms
- 16:58before they can be used the result is
- 17:02output that is more descriptive with
- 17:05variables and events
- 17:06that can be referred to by names okay
- 17:10so the private extensions to mi b2
- 17:13something like you have this 1.3.6 that
- 17:15wanted for that 1.9
- 17:17or it is the iso.org
- 17:21that dod that internet that private that
- 17:23enterprise that cisco
- 17:25so that is within the three year
- 17:31mib definition so let's have an example
- 17:34so
- 17:34this figure here depicts the snmp
- 17:38mib variable retrieval in action okay
- 17:42now in this example the network
- 17:45manager okay wants to retrieve the
- 17:47number of errors
- 17:49on the first interface starting with
- 17:53interface
- 17:54number zero okay now the valid range of
- 17:58interface numbers is zero through the
- 18:00maximum number of ports
- 18:02minus one because we've started with
- 18:04zero
- 18:05okay now the manager creates the snmp
- 18:09get request message
- 18:10with reference to the mib variable and
- 18:13that is
- 18:171.3.6.1.2.1
- 18:18that 2 the 2.1.20.0
- 18:23okay so which represents
- 18:26interface outgoing errors on interface
- 18:28zero
- 18:30okay the agent creates the snmp get
- 18:33response message
- 18:34in response to the manager's request
- 18:38the response includes the value of the
- 18:41referenced variable
- 18:42now in this example the agent returned
- 18:46value is 11 okay indicating
- 18:50that there were 11 outgoing errors
- 18:53on that interface
- 18:58arm on one or the remote monitoring
- 19:01so the key point would be armond is an
- 19:04mib
- 19:05that provides support for proactive
- 19:08management of land traffic
- 19:11okay so arm one standard allows pocket
- 19:14and traffic patterns on the local area
- 19:16network segments to be monitored
- 19:19so armond trucks the following items
- 19:22so number of packets okay uh packet
- 19:25sizes
- 19:26broadcasts network utilization
- 19:30errors and conditions such as internet
- 19:32collisions
- 19:34statistics for hosts including errors
- 19:37generated
- 19:38by hosts bcs hosts
- 19:41and which hosts communicate with each
- 19:44other
- 19:45so armand feature include historical
- 19:48views of armand statistics
- 19:50based on user-defined sample intervals
- 19:54alarms that are based on user-defined
- 19:57press holds
- 19:58and packet capture based on user-defined
- 20:01filters
- 20:05now the armand groups okay so harmon
- 20:08agents gather nine groups of statistics
- 20:11okay 10 including the token ring
- 20:14which are forwarded to the manager on
- 20:17request
- 20:18usually via snmp so
- 20:21this includes statistics okay
- 20:25history alarm host
- 20:28host top n matrix
- 20:32filters you've got packet capture
- 20:35events and then of course the token ring
- 20:39okay now the statistics contain
- 20:42statistics such as packet sent
- 20:43okay byte sent broadcast packets
- 20:47multicast packets the crc or the cyclic
- 20:51redundancy check
- 20:52okay plants giants fragments jabbers and
- 20:55so on
- 20:56so the history used to store periodic
- 20:59statistical samples for
- 21:01later retrieval now the alarm is used to
- 21:05set specific thresholds
- 21:07for managed objects and to trigger an
- 21:10event
- 21:11on crossing the threshold okay so the
- 21:14host contains statistics associated with
- 21:16each host discovered on the network
- 21:19the host top end contains statistics for
- 21:22hosts
- 21:22that top a list ordered by one of their
- 21:25observed
- 21:26variables the matrix contains statistics
- 21:29for conversations between
- 21:31sets of two addresses
- 21:35including the number of packets or bytes
- 21:38exchanged
- 21:39between two hosts filters
- 21:43it contains rules for data packet
- 21:45filters data packets
- 21:47matched by these rules generate events
- 21:51or are stored locally in the packet
- 21:53capture group
- 21:55packet capture contains data packets
- 21:58that match rules set in the filters
- 22:01group and events
- 22:04so controls the generation and
- 22:06notification of events
- 22:08from this device so token ring contains
- 22:12the following token ring extensions like
- 22:14um
- 22:15ring station detailed statistics on
- 22:18individual stations
- 22:20ring station order order list
- 22:23configuration information and insertion
- 22:26or removal data on each station
- 22:29and source routing
- 22:34armon 2 so armand1
- 22:37only provides visibility into data link
- 22:40and the physical layers potential
- 22:42problems
- 22:43that occur at the higher layers still
- 22:46require other capture and the code tools
- 22:50so because harmon's limitation or
- 22:52armon's one limitations
- 22:54so armond 2 was developed to extend the
- 22:57functionality to
- 22:58upper layer protocols so basically for
- 23:00armon 1
- 23:02that caters only on the physical layer
- 23:05and data link layer
- 23:07whereas armond 2 that extended the
- 23:11capability of r11
- 23:12up to the application layer okay
- 23:16now with visibility into the upper layer
- 23:18protocols the network manager can
- 23:20monitor
- 23:20any upper layer protocol traffic for any
- 23:23device
- 23:24or subnet in addition to mac layer
- 23:26traffic
- 23:28so armond 2 allows the collection of
- 23:30statistics
- 23:32beyond the specific segments mac layer
- 23:35and provides an end-to-end view of
- 23:37network conversations
- 23:38per protocol okay so the network manager
- 23:42can view conversations
- 23:44at the network and application layer so
- 23:46therefore
- 23:48traffic generated by the specific host
- 23:50or even the specific application for
- 23:52example
- 23:53a telnet okay or a web browser
- 23:58okay so that can be observed okay now
- 24:02the key point
- 24:03for armon 2 armand 2 is not a
- 24:06replacement for armon 1
- 24:08but an extension of it okay
- 24:11so armond 2 extends arm on 1
- 24:15by adding 9 more groups that provide
- 24:18visibility
- 24:18to the upper layers okay
- 24:22so this figure here
- 24:26illustrates the hormone groups that were
- 24:28added
- 24:29when armon 2 was introduced so
- 24:32this includes protocol directory
- 24:35distribution mapping
- 24:39network layer host network layer matrix
- 24:43the application layer hosts the
- 24:44application layer matrix
- 24:46the user history collection and probe
- 24:49configuration
- 24:53netflow infrastructure
- 24:56cisco net flow is a measurement
- 24:58technology that measures
- 25:00flows that pass through cisco devices
- 25:04so netflow answers the questions of what
- 25:08when where and how traffic is flowing
- 25:11in the network so netflow data
- 25:14can be exported to network management
- 25:16applications
- 25:18to further process the information
- 25:21providing tables and graphs for
- 25:24accounting and billing
- 25:25or as to aid for network planning
- 25:29so the key components of net flow are
- 25:32the net flow cache
- 25:33and data source that stores ipflow
- 25:36information
- 25:38and the net flow export or transport
- 25:40mechanism
- 25:41that sends netflow data to a network
- 25:44management collector such as
- 25:46netflow collection engine
- 25:49now the netflow collected data serves as
- 25:51the basis
- 25:52for a set of applications including
- 25:55network traffic
- 25:56accounting usage-based network billing
- 26:00network planning and network monitoring
- 26:03so netflow also provides a measurement
- 26:07base
- 26:07for qos applications it
- 26:10captures the traffic classification or
- 26:13precedence
- 26:15associated with each flow so thereby
- 26:18enabling differentiated charging based
- 26:21on the quality of service
- 26:24[Music]
- 26:26now comparing netflow and armon okay so
- 26:28you've got the netflow versus
- 26:30armon information gathering
- 26:34so netflow can be configured on
- 26:35individual interfaces
- 26:37thereby providing information on traffic
- 26:40that passes through those interfaces and
- 26:42collecting the following types of
- 26:44information
- 26:45so you've got the source and destination
- 26:47interface numbers
- 26:49for addresses input and output interface
- 26:52numbers
- 26:53or addresses tcp udp source
- 26:56port and destination ports the number of
- 26:59bytes and
- 27:00packets in the flow the source and
- 27:02destination autonomous system numbers
- 27:04for bgp
- 27:06time of the day and the iptos or type of
- 27:09service
- 27:10okay now compared to using snmp with arm
- 27:13on mib
- 27:14net flow's information gathering
- 27:16benefits includes
- 27:18greater detail of collected data so
- 27:21data time stamping support for various
- 27:24data per interface
- 27:26and greater scalability to a large
- 27:28number of interfaces
- 27:30so arm1 is also limited by the size of
- 27:34each memory table so netflow's
- 27:37performance
- 27:37impact is much lower than hormones
- 27:41and external probes are not required
- 27:46applications using netflow so netflows
- 27:49enable several key customer applications
- 27:52including the following so you've got
- 27:54accounting and billing
- 27:56so because flow data includes details
- 27:59such as ip addresses
- 28:01packet and byte counts timestamps
- 28:04and application port numbers netflow
- 28:07data provides
- 28:08fine-grained metering for highly
- 28:10flexible and detailed resource
- 28:12utilization accounting
- 28:14for example service providers can use
- 28:17this information to migrate from a
- 28:19single fee
- 28:21flat rate billing to more flexible
- 28:23charging mechanisms
- 28:24based on time of day bandwidth usage
- 28:29application usage the quality of service
- 28:31and so forth
- 28:33so enterprise customers can use
- 28:36information
- 28:37for departmental cost recovery or cost
- 28:40allocation for resource utilization
- 28:44so the next one would be network
- 28:47planning and analysis
- 28:49so the net flow data provides
- 28:51information for sophisticated network
- 28:53architecture tools
- 28:54to optimize both strategic planning
- 28:58okay and tactical network engineering
- 29:02decisions so this has the benefits
- 29:06of minimizing the total cost of network
- 29:09operations
- 29:10while maximizing network performance
- 29:12capacity and reliability
- 29:16so next one would be the network
- 29:17monitoring
- 29:19okay netflow enables extensive near
- 29:22real-time network monitoring
- 29:25so to provide aggregate traffic or
- 29:27application based
- 29:28views flow based analysis techniques can
- 29:32be used
- 29:32to visualize the traffic patterns
- 29:34associated with individual routers and
- 29:36switches
- 29:37on network-wide basis now this analysis
- 29:41provides network managers with proactive
- 29:44problem detection
- 29:45efficient troubleshooting and rapid
- 29:48problem resolution
- 29:50next would be application monitoring and
- 29:53profiling
- 29:55so netflow data enables network managers
- 29:58to gain a detailed time-based view of
- 30:02application usage over the network
- 30:04so content and service providers can
- 30:08use this information to plan and
- 30:10allocate network and application
- 30:12resources
- 30:13such as web server sizing and location
- 30:17okay so that is just to meet the
- 30:19customer demands
- 30:22next would be the user monitoring and
- 30:24profiling
- 30:25okay so netflow data enables network
- 30:28managers to understand
- 30:29customer and user network utilization
- 30:33resource application this information
- 30:36can be used
- 30:37to plan efficiently allocate access
- 30:40backbone and application resources and
- 30:44detect and resolve potential security
- 30:47and
- 30:47policy violations
- 30:50so the last one would be the net flow
- 30:53data warehousing and mining
- 30:54okay in support of proactive marketing
- 30:58and customer service programs
- 31:00net flow data or information derived
- 31:03from
- 31:04it can be warehoused for later retrieval
- 31:08and analysis for example you can
- 31:11determine
- 31:11which applications and services are
- 31:14being used by internal and external
- 31:16users
- 31:16and target them for improved service
- 31:20this is especially useful for service
- 31:23providers
- 31:24so because netflow data enables them to
- 31:26create a wider range of offered services
- 31:30okay so a service provider can easily
- 31:33determine the traffic characteristics of
- 31:35various services
- 31:36and based on this data provide new
- 31:40services to the user
- 31:42so an example of such service is the
- 31:45voice over ip
- 31:47which requires the quality of service
- 31:49adjustment
- 31:50the service provider might charge users
- 31:54for this type of service
- 32:00cisco discovery protocol or the cdp
- 32:03now this has the equivalent on the open
- 32:06standard
- 32:06so we call it lldp okay
- 32:10so this one is cdp okay
- 32:14now let's focus on the cdp or the cisco
- 32:16discovery protocol
- 32:18so basically cdp is a cisco proprietary
- 32:21protocol that operates between cisco
- 32:23devices
- 32:24at the data link layer so cdp
- 32:27information is sent
- 32:29only between directly connected cisco
- 32:31devices
- 32:32a cisco device never forwards a cdp
- 32:35frame okay now cdp
- 32:38enables systems that support different
- 32:42network layer protocols to communicate
- 32:45and enables other cisco devices
- 32:47on the network to be discovered
- 32:50so cdp provides a summary of directly
- 32:53connected switches
- 32:54routers and other cisco devices so
- 32:57cdp is a media and protocol independent
- 33:00protocol
- 33:01that is enabled by default on
- 33:04its supported interface of cisc devices
- 33:08so would it be a router access servers
- 33:10and switches
- 33:13the physical media must support sub
- 33:15network access protocol encapsulation
- 33:18okay now this figure here illustrates
- 33:20the relationship between cdp
- 33:23and other protocols again cdp is a
- 33:27proprietary protocol and can be used
- 33:29only on cisco devices
- 33:31now if you're planning to have the
- 33:33functionality
- 33:35on a nan cisco device then you can use
- 33:37lldp
- 33:41discovering neighbors with the cisco
- 33:44cisco discovery protocol
- 33:46or cdp so how cdp works
- 33:49so as illustrated in this figure cdp
- 33:52information is sent
- 33:54only when directly connected cisco
- 33:56devices
- 33:58in this figure the person connected to
- 34:01switch a c the router
- 34:04and the two switches directly attached
- 34:06to switching other devices are not
- 34:08visible by a cdp
- 34:10so for example the person would have to
- 34:13log
- 34:14to switch b to see router c
- 34:18with cdb okay so cdp
- 34:22is a hello based protocol and all cisco
- 34:25devices that run cdp
- 34:27periodically advertise their attributes
- 34:30to their neighbors using a multicast
- 34:33address
- 34:34so this frames advertise a time to leave
- 34:37or ttl value
- 34:39the whole time in seconds okay so that
- 34:42indicates
- 34:42how long the information must be
- 34:45retained
- 34:46before it can be discarded cdp
- 34:49frames are sent with a time to leave
- 34:52value that is non-zero
- 34:54so after an interface is enabled
- 34:57so a ttl value of zero is sent
- 35:00immediately before the interface is shut
- 35:02down
- 35:03so allowing other devices to quickly
- 35:06discover
- 35:07lost neighbors
- 35:12syslag accounting so a system
- 35:16message or error reporting service is an
- 35:19essential component of
- 35:21any operating system so the syslag
- 35:24system message service provides a means
- 35:27for the system in its running processes
- 35:30to report
- 35:31system okay to a network manager
- 35:34so that includes the state information
- 35:37now cisco devices produce dislike
- 35:39messages as a result
- 35:41of network events syslag message
- 35:44contains a timestamp
- 35:45if enabled severity level and
- 35:49facility now that severity level
- 35:53is denoted by these integers here
- 35:57so emergency level zero
- 36:00so alert is level one critical level two
- 36:04error level three and so on so debugging
- 36:08okay is at level seven
- 36:12so example of syslag message is provided
- 36:14on this figure here
- 36:16so it shows a sample of syslag message
- 36:18produced by
- 36:19the cisco ios software the most common
- 36:23messages
- 36:24are those that a device produces an
- 36:27exiting configuration mode
- 36:29and the link up and down messages
- 36:32if acl logging is configured the device
- 36:36generates syslog messages when packets
- 36:39match
- 36:40the acl condition so
- 36:43acl logging can be useful to detect
- 36:47packets that are denied access based on
- 36:51the security policy
- 36:52that is set by the access list or acl
- 36:57so example of syslag messages so
- 37:00this figure illustrates the syslag
- 37:03distributed architecture
- 37:05syslog messages are sent to the console
- 37:08session by default
- 37:10okay so a device must be configured to
- 37:13send syslag message
- 37:14elsewhere the configuration includes the
- 37:17address of the nms
- 37:19or other device so network devices can
- 37:22be configured to send syslag messages
- 37:24directly to the nms
- 37:26or to the remote network host on which
- 37:28systec analyzer is installed
- 37:32so a syslag analyzer conserves bandwidth
- 37:35on one lens
- 37:36because the analyzer usually applies
- 37:39different filters
- 37:40and sends only at the predefined subset
- 37:43of
- 37:43all the syslog messages it receives the
- 37:46analyzer
- 37:47filters and periodically forwards
- 37:50messages
- 37:51to the central nms for example
- 37:54the analyzer could filter acl logging
- 37:57data
- 37:58from other router or switches like
- 38:00entries
- 38:01to ensure that the acl logging data does
- 38:05not overwhelm
- 38:06the syslog reporting tool
- 38:12so let's have the summary of
- 38:15this subtopic or segment so network
- 38:19management is supported
- 38:20with various devices and servers
- 38:23that use network management protocols
- 38:26and standards
- 38:28so snmp is a simple network management
- 38:30protocol
- 38:32that is the foundation of network
- 38:33management architecture
- 38:36amib stores local management agent
- 38:39information on a managed device
- 38:41so arm1 is an mib
- 38:45that supports proactive management of
- 38:48remote networks
- 38:50so netflow collects network flow data to
- 38:53support
- 38:54network accounting usage based billing
- 38:58planning performance monitoring and
- 39:00quality of service applications
- 39:03the cisco discovery protocol is a cisco
- 39:05proprietary protocol that enables you to
- 39:07discover cisco devices on the network
- 39:10the counterpart is lldp okay
- 39:14so syslag reports system state
- 39:18information
- 39:20based on preset facilities and severity
- 39:23levels
- 39:27and for the module summary
- 39:31okay we've talked about the hierarchical
- 39:33network structure
- 39:35that composes of access
- 39:38distribution and core layers based on
- 39:41the
- 39:42cisco sona the enterprise or the cisco
- 39:44enterprise architecture
- 39:46provides a modular hierarchical approach
- 39:49for providing network infrastructure and
- 39:51services
- 39:52to all places in the network so network
- 39:56infrastructure services
- 39:58add intelligence to the network
- 39:59infrastructure
- 40:01supporting application awareness within
- 40:03the network
- 40:05so network management protocol supports
- 40:07the exchange of management information
- 40:10between the network management system
- 40:13and
- 40:13manage devices
- 40:18so that's the end of the video have a
- 40:21great day
- 40:26you
About this transcript
This page contains the full transcript of Structuring and Modularizing the Network Part 4 by Santelmo, generated from the public captions YouTube serves with the video. The transcript has 4,420 words across 946 segments, with the original timestamps preserved so you can click any line to jump to that moment in the embedded player.
What you can do with it
Use the transcript to take notes, quote the speaker, build a study guide, generate a summary with ChatGPT or Claude via the YouTube Summary tool, or export it as a timed subtitle file with YouTube to SRT. You can also re-open it in the transcriber to translate the transcript into 100+ languages.
Free YouTube transcript tool
YouTube2Text is a free YouTube transcript generator — no signup, no daily limit. Paste any YouTube link and get the full transcript instantly, with timestamps, click-to-jump, translation to 100+ languages, AI prompts for ChatGPT, Claude, and Gemini, and exports to TXT, SRT, VTT, or Markdown.