YouTube2Text

Structuring and Modularizing the Network Part 4 — Transcript

by Santelmo · 4,420 words · 946 segments · language en · Watch on YouTube

Full transcript

  1. 0:04identifying network management protocols
  2. 0:06and features
  3. 0:10proper network management is a critical
  4. 0:12component
  5. 0:13of an efficient network network
  6. 0:16administrators
  7. 0:17need tools to monitor the functionality
  8. 0:20of the network devices
  9. 0:22the connections between them and the
  10. 0:24services they provide
  11. 0:26snmp or the simple network management
  12. 0:28protocol has become the de facto
  13. 0:30standard for use in network management
  14. 0:32solutions
  15. 0:34and is tightly connected with remote
  16. 0:36monitoring or harmon
  17. 0:38and management information basis or mib
  18. 0:42each managed device in the network has
  19. 0:45several variables that
  20. 0:47quantify the state of the device you can
  21. 0:50monitor managed devices
  22. 0:52by reading the values of these variables
  23. 0:55and
  24. 0:56you can control managed devices by
  25. 0:58writing values into these variables
  26. 1:01so this section introduces snmp
  27. 1:04and describes the differences between
  28. 1:06snmp versions
  29. 1:07one two and three
  30. 1:11the role of mibs and snmp and harmon's
  31. 1:14monitoring is described
  32. 1:16the cisco network discovery protocol
  33. 1:19or the cdp is introduced this section
  34. 1:23concludes with a description of methods
  35. 1:26for gathering network statistics
  36. 1:29let's get started
  37. 1:32network management architecture
  38. 1:36so this figure illustrates a generic
  39. 1:38network management
  40. 1:40architecture so the network management
  41. 1:43architecture consists
  42. 1:44of the following so first there should
  43. 1:47be
  44. 1:47an nms or the network management system
  45. 1:52this is a system that executes
  46. 1:54applications
  47. 1:55that monitor and control managed devices
  48. 1:59nmss provide a bulk of processing
  49. 2:03and memory resources that are required
  50. 2:06for network management
  51. 2:08so next would be the network management
  52. 2:10protocol
  53. 2:12so a protocol that facilitates the
  54. 2:14exchange of mib information between
  55. 2:17the nms and the managed devices so this
  56. 2:20includes
  57. 2:22the snmp or the simple network
  58. 2:24management protocol
  59. 2:25the mib or the management information
  60. 2:28base
  61. 2:28and armon or the remote monitoring
  62. 2:32also there should be managed devices
  63. 2:37so a device such as router computers and
  64. 2:41nodes
  65. 2:42those are managed devices
  66. 2:45okay so these are managed by the network
  67. 2:47management system
  68. 2:50you also have management agents
  69. 2:53so these are software on managed devices
  70. 2:57that collect and store management
  71. 2:58information
  72. 3:00including snmp agents and armored agents
  73. 3:06next would be the management information
  74. 3:10okay so data that is interest
  75. 3:13to a device management usually stored in
  76. 3:16the mips
  77. 3:18so a variety of network management
  78. 3:20applications can be used on network
  79. 3:22management systems
  80. 3:23the choice depends on the network
  81. 3:25platform such as hardware and
  82. 3:28operating systems the management
  83. 3:30information resides on network
  84. 3:32devices management agents
  85. 3:35that resides on the device collect and
  86. 3:37store data
  87. 3:38in a standardized data definition known
  88. 3:41as the mib
  89. 3:43or the management information base okay
  90. 3:46now the network management application
  91. 3:48uses snmp
  92. 3:50or other network management protocols
  93. 3:53to retrieve the data that the management
  94. 3:56agents
  95. 3:57collect and the retrieved data is
  96. 4:00typically processed and prepared
  97. 4:02for display with the gui or graphical
  98. 4:05user interface
  99. 4:07which allows the operator to use
  100. 4:09graphical representation of the network
  101. 4:12to control manage devices and program
  102. 4:16the network management application
  103. 4:22okay so let's have the simple network
  104. 4:24management protocol or snmp overview
  105. 4:27okay so snmp has become the de facto
  106. 4:30standard
  107. 4:31for network management so snmp is a
  108. 4:35simple solution
  109. 4:36that requires a little code to implement
  110. 4:39which enables
  111. 4:40vendors to easily build snmp
  112. 4:43agents for their products so in addition
  113. 4:48snmp is often the foundation of the
  114. 4:50network management architecture
  115. 4:53so snmp defines how management
  116. 4:55information is exchanged
  117. 4:57between network management applications
  118. 4:59and management agents
  119. 5:02now this figure here shows the terms
  120. 5:05used in snmp now they are described as
  121. 5:09follows
  122. 5:10so let's start with the manager
  123. 5:13okay so the manager a network management
  124. 5:16application
  125. 5:17in an nms periodically pulls
  126. 5:20the snmp agents that reside on the
  127. 5:24managed devices
  128. 5:25for the data thereby enabling
  129. 5:28information
  130. 5:29to be displayed using a graphical user
  131. 5:32interface or gui
  132. 5:33on the nmss a disadvantage
  133. 5:36of periodic snmp polling is the possible
  134. 5:40delay between
  135. 5:41when an event occurs and when it is
  136. 5:44collected by the nms
  137. 5:47so there is a trade-off between
  138. 5:50falling frequency and bandwidth
  139. 5:53usage okay so
  140. 5:56next would be the protocol so the snmp
  141. 6:00is a protocol for
  142. 6:01message exchange it uses user datagram
  143. 6:05protocol or udp
  144. 6:08so to send and retrieve management
  145. 6:10information such as
  146. 6:11the mib variables
  147. 6:15next would be manage devices okay
  148. 6:18a managed device router switches
  149. 6:22computers these are being managed by the
  150. 6:25manager
  151. 6:27okay and also you have management agents
  152. 6:30or agent these are snmp management
  153. 6:33agents
  154. 6:34reside on the managed devices to collect
  155. 6:36and store a range of information
  156. 6:38about the device and its operation
  157. 6:41response to manager's request
  158. 6:44and generate traps to inform the manager
  159. 6:47about certain events
  160. 6:49now snmp traps are sent by the
  161. 6:51management agents
  162. 6:53to the nms when certain events occur
  163. 6:57so trap notifications could result
  164. 7:00in substantial network and agent
  165. 7:03resource savings
  166. 7:04by eliminating the need for some snmp
  167. 7:07polling requests
  168. 7:09and the other one would be the mib
  169. 7:13or the management information base so
  170. 7:15the mib
  171. 7:16okay or the management agent collects
  172. 7:19data
  173. 7:20and store it locally in the mib so mib
  174. 7:23is basically
  175. 7:24the storage or the database of objects
  176. 7:27about the device
  177. 7:29okay now community strings which are
  178. 7:32similar to passwords
  179. 7:34control access to the mib so to access a
  180. 7:37set of
  181. 7:38mib variables the user must specify
  182. 7:42the appropriate read or write community
  183. 7:44string
  184. 7:45otherwise access is denied
  185. 7:51snmp version 1 message types
  186. 7:55so the initial version of the snmp snmp
  187. 7:58version 1
  188. 7:59is defined in the rfc 1157
  189. 8:02the simple network management protocol
  190. 8:04or snmp
  191. 8:06so the protocol simplicity is apparent
  192. 8:09by the set of operations
  193. 8:11that are available so this figure here
  194. 8:14shows the basic snmp messages
  195. 8:17which the manager uses to transfer data
  196. 8:20from the agents okay
  197. 8:24to the manager okay now these messages
  198. 8:28are described as follows so first you've
  199. 8:30got
  200. 8:31get request so used by the manager to
  201. 8:35request a specific
  202. 8:36mib variable from the agent
  203. 8:40next would be get next request
  204. 8:43these are used after the initial get
  205. 8:46request to retrieve the next
  206. 8:47object instance from a table or list
  207. 8:52next would be set request used to set
  208. 8:55a mib variable on the agent
  209. 8:59and then get response used by agent
  210. 9:02to respond to a manager's get request or
  211. 9:05get next request message
  212. 9:08and the last one would be trump used by
  213. 9:11the
  214. 9:12agent to transmit an unsolicited alarm
  215. 9:16to the manager so a trap message is sent
  216. 9:20when specific conditions occur such as
  217. 9:23the change in the state of the device a
  218. 9:26device or component failure
  219. 9:28and an agent initialization or
  220. 9:34restart
  221. 9:36snmp version 2. so snmp version 2
  222. 9:39is a revised protocol that includes
  223. 9:42performance
  224. 9:43and manager to manage your communication
  225. 9:45improvements on snmp
  226. 9:48so snmp version 2 was introduced with
  227. 9:50rfc
  228. 9:521441 introduction to version 2
  229. 9:55of the internet standard network
  230. 9:57management framework
  231. 9:59but members of the ietf subcommittee
  232. 10:02could not agree
  233. 10:03on several sections of snmp version 2
  234. 10:05specifications
  235. 10:07so primarily the protocol security and
  236. 10:10administrative
  237. 10:11needs so several attempts to achieve
  238. 10:15acceptance of snmp version 2 have been
  239. 10:18made
  240. 10:18by releasing experimental modified
  241. 10:20versions
  242. 10:22so commonly known as the snmp v2
  243. 10:25okay snmp v2
  244. 10:28u snmp v1 plus
  245. 10:32and snmpv 1.5 which does not contain
  246. 10:36the disputed parts so
  247. 10:40the community based snmp version 2
  248. 10:43or the snmp version 2c which is defined
  249. 10:46in the rfc
  250. 10:471901 introduction to community based
  251. 10:51snmp version 2 is referred to as
  252. 10:54snmp version 2 because it is the common
  253. 10:56implementation
  254. 10:58okay now the c stands for community
  255. 11:01based
  256. 11:02security so because snmp version 2c uses
  257. 11:06the same community strings as snmp
  258. 11:08version 1
  259. 11:10for read and write access so snmp
  260. 11:13version
  261. 11:142 changes include the introduction of
  262. 11:17the following two
  263. 11:18new message types so basically you've
  264. 11:21got this
  265. 11:22get bulk request
  266. 11:25which is used for retrieving large
  267. 11:27amounts of data such as tables
  268. 11:30okay this message reduces repetitive
  269. 11:33requests and replies so thereby
  270. 11:36improving
  271. 11:37performance next one would be
  272. 11:40the inform request used to alert the
  273. 11:43snmp manager
  274. 11:45of the specific condition unlike and
  275. 11:47acknowledge
  276. 11:48trapped messages inform request messages
  277. 11:51are acknowledged
  278. 11:53a managed device sends an inform request
  279. 11:56to the nms
  280. 11:57the nms acknowledges the receipt of the
  281. 12:00message
  282. 12:01by sending a response message back to
  283. 12:04the managed device
  284. 12:06so another improvement of snmp version 2
  285. 12:09over snmp version 1 is the addition of
  286. 12:12new data types with 64-bit counters
  287. 12:15because 32-bit counters were quickly
  288. 12:18overflowed
  289. 12:19by fast network interfaces
  290. 12:24snmp version 3. so snmp version 3 is the
  291. 12:28latest
  292. 12:29snmp version to overcome the
  293. 12:32person2c okay and
  294. 12:35it became a full standard so each
  295. 12:39introduction has moved snmp version 1
  296. 12:42and snmp version 2 to historic status
  297. 12:46now we have two types of status for the
  298. 12:48standards
  299. 12:49so one mentioned was historic that means
  300. 12:53the old version was replaced with
  301. 12:56a new version so something like snmp
  302. 12:59version one
  303. 13:00okay it's already historic okay snmp
  304. 13:03version two
  305. 13:04is already stored and at the same time
  306. 13:07they are obsolete because they are
  307. 13:08obsoleted by a new releases or a new
  308. 13:11version
  309. 13:12okay now snmp version 3 which is
  310. 13:15described in the rfc
  311. 13:173410 through 3415
  312. 13:21ads methods to ensure the secure
  313. 13:24transmission of critical data to and
  314. 13:27from the managed
  315. 13:28devices so snmp version 3
  316. 13:32introduces the following three security
  317. 13:34levels here
  318. 13:35so you've got no auth no priv
  319. 13:39so that means without authentication and
  320. 13:41without
  321. 13:42privacy or encryption
  322. 13:46next would be us not brief
  323. 13:49okay so there is an authentication
  324. 13:52but without privacy authentication is
  325. 13:55based on the hash
  326. 13:56based message authentication code
  327. 13:59message digest 5
  328. 14:01or the hmac secure hash algorithms
  329. 14:04okay you also have the auth brief
  330. 14:08so with authentication as described
  331. 14:09early and privacy using the 56-bit
  332. 14:12cyber block chaining data encryption
  333. 14:15standard encryption standard
  334. 14:17so security levels can be specified per
  335. 14:20user or per group of users via direct
  336. 14:24interaction
  337. 14:25with the managed device or
  338. 14:28via snmp operations so security levels
  339. 14:32determine which
  340. 14:33snmp objects or user
  341. 14:37can access for reading writing or
  342. 14:40creating
  343. 14:41and the list of notifications that users
  344. 14:43can
  345. 14:44receive
  346. 14:49mib definition okay so the internet
  347. 14:52mib hierarchy now as shown here in the
  348. 14:56figure
  349. 14:57the mib structure is logically
  350. 14:59represented
  351. 15:01by a binary or a tree okay
  352. 15:04hierarchy so the root of the tree
  353. 15:08is unnamed okay and splits into three
  354. 15:12main branches so basically consultative
  355. 15:16committee for
  356. 15:17international telegraph and telephone
  357. 15:20the ccit okay the iso
  358. 15:25and the iso cc itt
  359. 15:28now these branches and those that fall
  360. 15:31below the category are identified with
  361. 15:33short text
  362. 15:34strings and integers
  363. 15:38now text strings describe object names
  364. 15:41whereas integers form object identifiers
  365. 15:46that allow software create compact
  366. 15:49encoded representation of the names
  367. 15:52now the object identifier in the
  368. 15:54internet mib hierarchy is the sequence
  369. 15:56of numeric labels
  370. 15:57on the nodes along the path from root
  371. 16:01to the object the internet standard mib
  372. 16:04is represented by the object identifier
  373. 16:07something like
  374. 16:111.3.6.1.2.1
  375. 16:13which can also be expressed as
  376. 16:17iso.org that dod
  377. 16:20that internet dot mgmt
  378. 16:24dot mib
  379. 16:29mib definition so the cisco private
  380. 16:33section of the mi b3 contains
  381. 16:35private managed objects which
  382. 16:39are introduced by cisco such as
  383. 16:42following objects for routers so small
  384. 16:45medium large and huge buffers
  385. 16:48primary and secondary memory and
  386. 16:50proprietary protocols
  387. 16:52so private definitions of managed
  388. 16:54objects
  389. 16:55must be compiled into the nms
  390. 16:58before they can be used the result is
  391. 17:02output that is more descriptive with
  392. 17:05variables and events
  393. 17:06that can be referred to by names okay
  394. 17:10so the private extensions to mi b2
  395. 17:13something like you have this 1.3.6 that
  396. 17:15wanted for that 1.9
  397. 17:17or it is the iso.org
  398. 17:21that dod that internet that private that
  399. 17:23enterprise that cisco
  400. 17:25so that is within the three year
  401. 17:31mib definition so let's have an example
  402. 17:34so
  403. 17:34this figure here depicts the snmp
  404. 17:38mib variable retrieval in action okay
  405. 17:42now in this example the network
  406. 17:45manager okay wants to retrieve the
  407. 17:47number of errors
  408. 17:49on the first interface starting with
  409. 17:53interface
  410. 17:54number zero okay now the valid range of
  411. 17:58interface numbers is zero through the
  412. 18:00maximum number of ports
  413. 18:02minus one because we've started with
  414. 18:04zero
  415. 18:05okay now the manager creates the snmp
  416. 18:09get request message
  417. 18:10with reference to the mib variable and
  418. 18:13that is
  419. 18:171.3.6.1.2.1
  420. 18:18that 2 the 2.1.20.0
  421. 18:23okay so which represents
  422. 18:26interface outgoing errors on interface
  423. 18:28zero
  424. 18:30okay the agent creates the snmp get
  425. 18:33response message
  426. 18:34in response to the manager's request
  427. 18:38the response includes the value of the
  428. 18:41referenced variable
  429. 18:42now in this example the agent returned
  430. 18:46value is 11 okay indicating
  431. 18:50that there were 11 outgoing errors
  432. 18:53on that interface
  433. 18:58arm on one or the remote monitoring
  434. 19:01so the key point would be armond is an
  435. 19:04mib
  436. 19:05that provides support for proactive
  437. 19:08management of land traffic
  438. 19:11okay so arm one standard allows pocket
  439. 19:14and traffic patterns on the local area
  440. 19:16network segments to be monitored
  441. 19:19so armond trucks the following items
  442. 19:22so number of packets okay uh packet
  443. 19:25sizes
  444. 19:26broadcasts network utilization
  445. 19:30errors and conditions such as internet
  446. 19:32collisions
  447. 19:34statistics for hosts including errors
  448. 19:37generated
  449. 19:38by hosts bcs hosts
  450. 19:41and which hosts communicate with each
  451. 19:44other
  452. 19:45so armand feature include historical
  453. 19:48views of armand statistics
  454. 19:50based on user-defined sample intervals
  455. 19:54alarms that are based on user-defined
  456. 19:57press holds
  457. 19:58and packet capture based on user-defined
  458. 20:01filters
  459. 20:05now the armand groups okay so harmon
  460. 20:08agents gather nine groups of statistics
  461. 20:11okay 10 including the token ring
  462. 20:14which are forwarded to the manager on
  463. 20:17request
  464. 20:18usually via snmp so
  465. 20:21this includes statistics okay
  466. 20:25history alarm host
  467. 20:28host top n matrix
  468. 20:32filters you've got packet capture
  469. 20:35events and then of course the token ring
  470. 20:39okay now the statistics contain
  471. 20:42statistics such as packet sent
  472. 20:43okay byte sent broadcast packets
  473. 20:47multicast packets the crc or the cyclic
  474. 20:51redundancy check
  475. 20:52okay plants giants fragments jabbers and
  476. 20:55so on
  477. 20:56so the history used to store periodic
  478. 20:59statistical samples for
  479. 21:01later retrieval now the alarm is used to
  480. 21:05set specific thresholds
  481. 21:07for managed objects and to trigger an
  482. 21:10event
  483. 21:11on crossing the threshold okay so the
  484. 21:14host contains statistics associated with
  485. 21:16each host discovered on the network
  486. 21:19the host top end contains statistics for
  487. 21:22hosts
  488. 21:22that top a list ordered by one of their
  489. 21:25observed
  490. 21:26variables the matrix contains statistics
  491. 21:29for conversations between
  492. 21:31sets of two addresses
  493. 21:35including the number of packets or bytes
  494. 21:38exchanged
  495. 21:39between two hosts filters
  496. 21:43it contains rules for data packet
  497. 21:45filters data packets
  498. 21:47matched by these rules generate events
  499. 21:51or are stored locally in the packet
  500. 21:53capture group
  501. 21:55packet capture contains data packets
  502. 21:58that match rules set in the filters
  503. 22:01group and events
  504. 22:04so controls the generation and
  505. 22:06notification of events
  506. 22:08from this device so token ring contains
  507. 22:12the following token ring extensions like
  508. 22:14um
  509. 22:15ring station detailed statistics on
  510. 22:18individual stations
  511. 22:20ring station order order list
  512. 22:23configuration information and insertion
  513. 22:26or removal data on each station
  514. 22:29and source routing
  515. 22:34armon 2 so armand1
  516. 22:37only provides visibility into data link
  517. 22:40and the physical layers potential
  518. 22:42problems
  519. 22:43that occur at the higher layers still
  520. 22:46require other capture and the code tools
  521. 22:50so because harmon's limitation or
  522. 22:52armon's one limitations
  523. 22:54so armond 2 was developed to extend the
  524. 22:57functionality to
  525. 22:58upper layer protocols so basically for
  526. 23:00armon 1
  527. 23:02that caters only on the physical layer
  528. 23:05and data link layer
  529. 23:07whereas armond 2 that extended the
  530. 23:11capability of r11
  531. 23:12up to the application layer okay
  532. 23:16now with visibility into the upper layer
  533. 23:18protocols the network manager can
  534. 23:20monitor
  535. 23:20any upper layer protocol traffic for any
  536. 23:23device
  537. 23:24or subnet in addition to mac layer
  538. 23:26traffic
  539. 23:28so armond 2 allows the collection of
  540. 23:30statistics
  541. 23:32beyond the specific segments mac layer
  542. 23:35and provides an end-to-end view of
  543. 23:37network conversations
  544. 23:38per protocol okay so the network manager
  545. 23:42can view conversations
  546. 23:44at the network and application layer so
  547. 23:46therefore
  548. 23:48traffic generated by the specific host
  549. 23:50or even the specific application for
  550. 23:52example
  551. 23:53a telnet okay or a web browser
  552. 23:58okay so that can be observed okay now
  553. 24:02the key point
  554. 24:03for armon 2 armand 2 is not a
  555. 24:06replacement for armon 1
  556. 24:08but an extension of it okay
  557. 24:11so armond 2 extends arm on 1
  558. 24:15by adding 9 more groups that provide
  559. 24:18visibility
  560. 24:18to the upper layers okay
  561. 24:22so this figure here
  562. 24:26illustrates the hormone groups that were
  563. 24:28added
  564. 24:29when armon 2 was introduced so
  565. 24:32this includes protocol directory
  566. 24:35distribution mapping
  567. 24:39network layer host network layer matrix
  568. 24:43the application layer hosts the
  569. 24:44application layer matrix
  570. 24:46the user history collection and probe
  571. 24:49configuration
  572. 24:53netflow infrastructure
  573. 24:56cisco net flow is a measurement
  574. 24:58technology that measures
  575. 25:00flows that pass through cisco devices
  576. 25:04so netflow answers the questions of what
  577. 25:08when where and how traffic is flowing
  578. 25:11in the network so netflow data
  579. 25:14can be exported to network management
  580. 25:16applications
  581. 25:18to further process the information
  582. 25:21providing tables and graphs for
  583. 25:24accounting and billing
  584. 25:25or as to aid for network planning
  585. 25:29so the key components of net flow are
  586. 25:32the net flow cache
  587. 25:33and data source that stores ipflow
  588. 25:36information
  589. 25:38and the net flow export or transport
  590. 25:40mechanism
  591. 25:41that sends netflow data to a network
  592. 25:44management collector such as
  593. 25:46netflow collection engine
  594. 25:49now the netflow collected data serves as
  595. 25:51the basis
  596. 25:52for a set of applications including
  597. 25:55network traffic
  598. 25:56accounting usage-based network billing
  599. 26:00network planning and network monitoring
  600. 26:03so netflow also provides a measurement
  601. 26:07base
  602. 26:07for qos applications it
  603. 26:10captures the traffic classification or
  604. 26:13precedence
  605. 26:15associated with each flow so thereby
  606. 26:18enabling differentiated charging based
  607. 26:21on the quality of service
  608. 26:24[Music]
  609. 26:26now comparing netflow and armon okay so
  610. 26:28you've got the netflow versus
  611. 26:30armon information gathering
  612. 26:34so netflow can be configured on
  613. 26:35individual interfaces
  614. 26:37thereby providing information on traffic
  615. 26:40that passes through those interfaces and
  616. 26:42collecting the following types of
  617. 26:44information
  618. 26:45so you've got the source and destination
  619. 26:47interface numbers
  620. 26:49for addresses input and output interface
  621. 26:52numbers
  622. 26:53or addresses tcp udp source
  623. 26:56port and destination ports the number of
  624. 26:59bytes and
  625. 27:00packets in the flow the source and
  626. 27:02destination autonomous system numbers
  627. 27:04for bgp
  628. 27:06time of the day and the iptos or type of
  629. 27:09service
  630. 27:10okay now compared to using snmp with arm
  631. 27:13on mib
  632. 27:14net flow's information gathering
  633. 27:16benefits includes
  634. 27:18greater detail of collected data so
  635. 27:21data time stamping support for various
  636. 27:24data per interface
  637. 27:26and greater scalability to a large
  638. 27:28number of interfaces
  639. 27:30so arm1 is also limited by the size of
  640. 27:34each memory table so netflow's
  641. 27:37performance
  642. 27:37impact is much lower than hormones
  643. 27:41and external probes are not required
  644. 27:46applications using netflow so netflows
  645. 27:49enable several key customer applications
  646. 27:52including the following so you've got
  647. 27:54accounting and billing
  648. 27:56so because flow data includes details
  649. 27:59such as ip addresses
  650. 28:01packet and byte counts timestamps
  651. 28:04and application port numbers netflow
  652. 28:07data provides
  653. 28:08fine-grained metering for highly
  654. 28:10flexible and detailed resource
  655. 28:12utilization accounting
  656. 28:14for example service providers can use
  657. 28:17this information to migrate from a
  658. 28:19single fee
  659. 28:21flat rate billing to more flexible
  660. 28:23charging mechanisms
  661. 28:24based on time of day bandwidth usage
  662. 28:29application usage the quality of service
  663. 28:31and so forth
  664. 28:33so enterprise customers can use
  665. 28:36information
  666. 28:37for departmental cost recovery or cost
  667. 28:40allocation for resource utilization
  668. 28:44so the next one would be network
  669. 28:47planning and analysis
  670. 28:49so the net flow data provides
  671. 28:51information for sophisticated network
  672. 28:53architecture tools
  673. 28:54to optimize both strategic planning
  674. 28:58okay and tactical network engineering
  675. 29:02decisions so this has the benefits
  676. 29:06of minimizing the total cost of network
  677. 29:09operations
  678. 29:10while maximizing network performance
  679. 29:12capacity and reliability
  680. 29:16so next one would be the network
  681. 29:17monitoring
  682. 29:19okay netflow enables extensive near
  683. 29:22real-time network monitoring
  684. 29:25so to provide aggregate traffic or
  685. 29:27application based
  686. 29:28views flow based analysis techniques can
  687. 29:32be used
  688. 29:32to visualize the traffic patterns
  689. 29:34associated with individual routers and
  690. 29:36switches
  691. 29:37on network-wide basis now this analysis
  692. 29:41provides network managers with proactive
  693. 29:44problem detection
  694. 29:45efficient troubleshooting and rapid
  695. 29:48problem resolution
  696. 29:50next would be application monitoring and
  697. 29:53profiling
  698. 29:55so netflow data enables network managers
  699. 29:58to gain a detailed time-based view of
  700. 30:02application usage over the network
  701. 30:04so content and service providers can
  702. 30:08use this information to plan and
  703. 30:10allocate network and application
  704. 30:12resources
  705. 30:13such as web server sizing and location
  706. 30:17okay so that is just to meet the
  707. 30:19customer demands
  708. 30:22next would be the user monitoring and
  709. 30:24profiling
  710. 30:25okay so netflow data enables network
  711. 30:28managers to understand
  712. 30:29customer and user network utilization
  713. 30:33resource application this information
  714. 30:36can be used
  715. 30:37to plan efficiently allocate access
  716. 30:40backbone and application resources and
  717. 30:44detect and resolve potential security
  718. 30:47and
  719. 30:47policy violations
  720. 30:50so the last one would be the net flow
  721. 30:53data warehousing and mining
  722. 30:54okay in support of proactive marketing
  723. 30:58and customer service programs
  724. 31:00net flow data or information derived
  725. 31:03from
  726. 31:04it can be warehoused for later retrieval
  727. 31:08and analysis for example you can
  728. 31:11determine
  729. 31:11which applications and services are
  730. 31:14being used by internal and external
  731. 31:16users
  732. 31:16and target them for improved service
  733. 31:20this is especially useful for service
  734. 31:23providers
  735. 31:24so because netflow data enables them to
  736. 31:26create a wider range of offered services
  737. 31:30okay so a service provider can easily
  738. 31:33determine the traffic characteristics of
  739. 31:35various services
  740. 31:36and based on this data provide new
  741. 31:40services to the user
  742. 31:42so an example of such service is the
  743. 31:45voice over ip
  744. 31:47which requires the quality of service
  745. 31:49adjustment
  746. 31:50the service provider might charge users
  747. 31:54for this type of service
  748. 32:00cisco discovery protocol or the cdp
  749. 32:03now this has the equivalent on the open
  750. 32:06standard
  751. 32:06so we call it lldp okay
  752. 32:10so this one is cdp okay
  753. 32:14now let's focus on the cdp or the cisco
  754. 32:16discovery protocol
  755. 32:18so basically cdp is a cisco proprietary
  756. 32:21protocol that operates between cisco
  757. 32:23devices
  758. 32:24at the data link layer so cdp
  759. 32:27information is sent
  760. 32:29only between directly connected cisco
  761. 32:31devices
  762. 32:32a cisco device never forwards a cdp
  763. 32:35frame okay now cdp
  764. 32:38enables systems that support different
  765. 32:42network layer protocols to communicate
  766. 32:45and enables other cisco devices
  767. 32:47on the network to be discovered
  768. 32:50so cdp provides a summary of directly
  769. 32:53connected switches
  770. 32:54routers and other cisco devices so
  771. 32:57cdp is a media and protocol independent
  772. 33:00protocol
  773. 33:01that is enabled by default on
  774. 33:04its supported interface of cisc devices
  775. 33:08so would it be a router access servers
  776. 33:10and switches
  777. 33:13the physical media must support sub
  778. 33:15network access protocol encapsulation
  779. 33:18okay now this figure here illustrates
  780. 33:20the relationship between cdp
  781. 33:23and other protocols again cdp is a
  782. 33:27proprietary protocol and can be used
  783. 33:29only on cisco devices
  784. 33:31now if you're planning to have the
  785. 33:33functionality
  786. 33:35on a nan cisco device then you can use
  787. 33:37lldp
  788. 33:41discovering neighbors with the cisco
  789. 33:44cisco discovery protocol
  790. 33:46or cdp so how cdp works
  791. 33:49so as illustrated in this figure cdp
  792. 33:52information is sent
  793. 33:54only when directly connected cisco
  794. 33:56devices
  795. 33:58in this figure the person connected to
  796. 34:01switch a c the router
  797. 34:04and the two switches directly attached
  798. 34:06to switching other devices are not
  799. 34:08visible by a cdp
  800. 34:10so for example the person would have to
  801. 34:13log
  802. 34:14to switch b to see router c
  803. 34:18with cdb okay so cdp
  804. 34:22is a hello based protocol and all cisco
  805. 34:25devices that run cdp
  806. 34:27periodically advertise their attributes
  807. 34:30to their neighbors using a multicast
  808. 34:33address
  809. 34:34so this frames advertise a time to leave
  810. 34:37or ttl value
  811. 34:39the whole time in seconds okay so that
  812. 34:42indicates
  813. 34:42how long the information must be
  814. 34:45retained
  815. 34:46before it can be discarded cdp
  816. 34:49frames are sent with a time to leave
  817. 34:52value that is non-zero
  818. 34:54so after an interface is enabled
  819. 34:57so a ttl value of zero is sent
  820. 35:00immediately before the interface is shut
  821. 35:02down
  822. 35:03so allowing other devices to quickly
  823. 35:06discover
  824. 35:07lost neighbors
  825. 35:12syslag accounting so a system
  826. 35:16message or error reporting service is an
  827. 35:19essential component of
  828. 35:21any operating system so the syslag
  829. 35:24system message service provides a means
  830. 35:27for the system in its running processes
  831. 35:30to report
  832. 35:31system okay to a network manager
  833. 35:34so that includes the state information
  834. 35:37now cisco devices produce dislike
  835. 35:39messages as a result
  836. 35:41of network events syslag message
  837. 35:44contains a timestamp
  838. 35:45if enabled severity level and
  839. 35:49facility now that severity level
  840. 35:53is denoted by these integers here
  841. 35:57so emergency level zero
  842. 36:00so alert is level one critical level two
  843. 36:04error level three and so on so debugging
  844. 36:08okay is at level seven
  845. 36:12so example of syslag message is provided
  846. 36:14on this figure here
  847. 36:16so it shows a sample of syslag message
  848. 36:18produced by
  849. 36:19the cisco ios software the most common
  850. 36:23messages
  851. 36:24are those that a device produces an
  852. 36:27exiting configuration mode
  853. 36:29and the link up and down messages
  854. 36:32if acl logging is configured the device
  855. 36:36generates syslog messages when packets
  856. 36:39match
  857. 36:40the acl condition so
  858. 36:43acl logging can be useful to detect
  859. 36:47packets that are denied access based on
  860. 36:51the security policy
  861. 36:52that is set by the access list or acl
  862. 36:57so example of syslag messages so
  863. 37:00this figure illustrates the syslag
  864. 37:03distributed architecture
  865. 37:05syslog messages are sent to the console
  866. 37:08session by default
  867. 37:10okay so a device must be configured to
  868. 37:13send syslag message
  869. 37:14elsewhere the configuration includes the
  870. 37:17address of the nms
  871. 37:19or other device so network devices can
  872. 37:22be configured to send syslag messages
  873. 37:24directly to the nms
  874. 37:26or to the remote network host on which
  875. 37:28systec analyzer is installed
  876. 37:32so a syslag analyzer conserves bandwidth
  877. 37:35on one lens
  878. 37:36because the analyzer usually applies
  879. 37:39different filters
  880. 37:40and sends only at the predefined subset
  881. 37:43of
  882. 37:43all the syslog messages it receives the
  883. 37:46analyzer
  884. 37:47filters and periodically forwards
  885. 37:50messages
  886. 37:51to the central nms for example
  887. 37:54the analyzer could filter acl logging
  888. 37:57data
  889. 37:58from other router or switches like
  890. 38:00entries
  891. 38:01to ensure that the acl logging data does
  892. 38:05not overwhelm
  893. 38:06the syslog reporting tool
  894. 38:12so let's have the summary of
  895. 38:15this subtopic or segment so network
  896. 38:19management is supported
  897. 38:20with various devices and servers
  898. 38:23that use network management protocols
  899. 38:26and standards
  900. 38:28so snmp is a simple network management
  901. 38:30protocol
  902. 38:32that is the foundation of network
  903. 38:33management architecture
  904. 38:36amib stores local management agent
  905. 38:39information on a managed device
  906. 38:41so arm1 is an mib
  907. 38:45that supports proactive management of
  908. 38:48remote networks
  909. 38:50so netflow collects network flow data to
  910. 38:53support
  911. 38:54network accounting usage based billing
  912. 38:58planning performance monitoring and
  913. 39:00quality of service applications
  914. 39:03the cisco discovery protocol is a cisco
  915. 39:05proprietary protocol that enables you to
  916. 39:07discover cisco devices on the network
  917. 39:10the counterpart is lldp okay
  918. 39:14so syslag reports system state
  919. 39:18information
  920. 39:20based on preset facilities and severity
  921. 39:23levels
  922. 39:27and for the module summary
  923. 39:31okay we've talked about the hierarchical
  924. 39:33network structure
  925. 39:35that composes of access
  926. 39:38distribution and core layers based on
  927. 39:41the
  928. 39:42cisco sona the enterprise or the cisco
  929. 39:44enterprise architecture
  930. 39:46provides a modular hierarchical approach
  931. 39:49for providing network infrastructure and
  932. 39:51services
  933. 39:52to all places in the network so network
  934. 39:56infrastructure services
  935. 39:58add intelligence to the network
  936. 39:59infrastructure
  937. 40:01supporting application awareness within
  938. 40:03the network
  939. 40:05so network management protocol supports
  940. 40:07the exchange of management information
  941. 40:10between the network management system
  942. 40:13and
  943. 40:13manage devices
  944. 40:18so that's the end of the video have a
  945. 40:21great day
  946. 40:26you

About this transcript

This page contains the full transcript of Structuring and Modularizing the Network Part 4 by Santelmo, generated from the public captions YouTube serves with the video. The transcript has 4,420 words across 946 segments, with the original timestamps preserved so you can click any line to jump to that moment in the embedded player.

What you can do with it

Use the transcript to take notes, quote the speaker, build a study guide, generate a summary with ChatGPT or Claude via the YouTube Summary tool, or export it as a timed subtitle file with YouTube to SRT. You can also re-open it in the transcriber to translate the transcript into 100+ languages.

Free YouTube transcript tool

YouTube2Text is a free YouTube transcript generator — no signup, no daily limit. Paste any YouTube link and get the full transcript instantly, with timestamps, click-to-jump, translation to 100+ languages, AI prompts for ChatGPT, Claude, and Gemini, and exports to TXT, SRT, VTT, or Markdown.