Data Centers

D Sniffing Spoofing

Sniffing refers to the act of intercepting TCP packets. This can be simple eavesdropping or something more sinister. Spoofing is the act of sending an illegitimate packet with an expected ACK, which can be guessed, predicted, or obtained by snooping. In a DOS attack, the web server identifies the suspect source and blocks any more incoming packets from it. The attacker can remotely take control of many other computers and start launching timed attacks. The solution is the same for the DOS...

Dynamically Allocated IP Addresses

A network administrator is responsible for assigning which devices receive which IP addresses in a corporate network. The admin assigns an IP address to a device in one of two ways by configuring the device with a specific address or by letting the device automatically learn its address from the network. Dynamic Host Configuration Protocol (DHCP) is the protocol used for automatic IP address assignment. Dynamic addressing saves considerable administrative effort and conserves IP addressing...

WAN Services

Three types of transport are used with WANs Point-to-point Also known as leased line, a point-to-point connection is a pre-established link from one site, across a service provider's network, to a remote site. The carrier establishes the point-to-point link for the customer's private use. Circuit switching A service provider establishes a dedicated physical circuit into a carrier network for two or more connections. Unlike point-to-point, which has exactly two sites connected to a single...

Where You Encrypt Matters

Encryption can be implemented at one of three OSI layers the application, data link, or network layer. Each layer has advantages and disadvantages. For application layer encryption, each application must be upgraded to support encryption, and all hosts that communicate with the applications must speak the same encryption language. This can often mean replacing all hosts in a network, but it does not necessarily require any network upgrades, because traffic is unaffected. Network layer...

ISDN Device Types and Reference Points

ISDN specifies both the equipment and the connection points between equipment to ensure compatibility with the PSTN and among ISDN vendors. TE1 Terminal endpoint 1. TE1s are devices that have a native ISDN interface. NT2 Network termination 2. An NT2 aggregates and switches all ISDN lines at the customer service site using a customer switching device. NT1 Network termination 1. NT1s convert signals into a form used by the ISDN line. An NT1 plugs into a standard phone jack. TE2 Terminal endpoint...

Network Admission Control

Network Admission Control (NAC) builds on IBNS by providing an additional hurdle that devices must leap before being allowed to access the network. After a laptop passes the identity check (assuming that IBNS is being used), the network provides an additional challenge to the device to assess its health. Health is determined by the corporate security policy. It typically includes auditing the laptop for proper installation and current operation of mandatory security software programs, such as...

Open Versus Proprietary Systems

Although the open-source model is well-known today, when the OSI model was being developed, there was an ongoing struggle to balance technical openness with competitive advantage. At that time, each individual network equipment vendor saw it as an advantage to develop technologies that other companies could not copy or interact with. Proprietary systems let a vendor claim competitive advantage as well as collect fees from other vendors it might choose to share the technology with. However,...

Network Management Protocols

Many tools and protocols help you effectively manage network devices. These tools and protocols help you configure, back up, monitor, and measure network devices. Network-management software makes efficient use of public domain protocols to discover and manage networks. The first protocol is simply the Transmission Control Protocol Internet Protocol (TCP IP) ping tool. Network-management software, in its simplest form, uses ping as a heartbeat monitor. Ping sends a single request to a device,...

Watching Movies Without Flooding the World

IP multicast is a bandwidth-conserving technology based on IP in which data intended for multiple receivers is efficiently transmitted with a single stream. IP multicast best serves streaming audio, video, and data applications such as software distribution or stock-quote broadcasts. Consider this example A corporate officer needs to deliver a live video broadcast to the company's employees. Doing so across an IP network using traditional IP protocols would require that the video feed be...

The OSI Model

At some point, everyone involved with networking comes across a reference to the Open Systems Interconnection (OSI) seven-layer model. Because this model provides the architectural framework for all of network and computing communication, it's a good place to start. Even if you don't ever plan on setting up your own network, being familiar with this model is essential to understanding how it all works. The OSI seven-layer model describes the functions for computers to communicate with each...

Protocol Independent Multicast PIM

PIM is IP routing protocol-independent and can leverage whichever unicast routing protocols are used to populate the unicast routing table. PIM uses this unicast routing information to perform the multicast forwarding function. Although PIM is called a multicast routing protocol, it actually uses the unicast routing table to perform the RPF check function instead of building a completely independent multicast routing table. It includes two different modes of behavior for dense and sparse...

Sometimes the Earth Is Flat

As with most networking technologies, there has sometimes been a pendulum effect in the popularity of Layer 2 bridged (flat) networks versus Layer 3 routed networks. Cisco's initial business convinced customers to insert routing devices to break up their predominantly flat, bridged networks to more efficiently transmit traffic and reduce the number of users affected when broadcast storms and loops occurred. However, in the mid-1990s, LAN switches became wildly popular for replacing bridges and...

ARP Poisoning Spoofing

Address Resolution Protocol (ARP) is a tool that allows devices to communicate when they do not have all the information they need about the device that they are trying to communicate with. Attackers can use ARP to learn the MAC and IP addresses of legitimate users on the network using a technique called gratuitous ARP. As soon as the hacker has obtained address information, he can use it to conduct man-in-the-middle attacks, sniff passwords, or siphon off data. Attacker 10.1.1.25 Victim...

When Good Networks Go Bad

One of the most basic and critical functions of the network is to provide a way for network administrators to provision and maintain the network devices themselves. Functions that need to be performed include establishing new connections, updating the network topology, monitoring network throughput and performance, and enforcing security and service policies. All this (and more) is performed by the control plane in a network device. The control plane is responsible for providing an interface to...

History of Ethernet

Robert Metcalfe developed Ethernet at the famous Xerox Palo Alto Research Center (PARC) in 1972. The folks at Xerox PARC had developed a personal workstation with a graphical user interface. They needed a technology to network these workstations with their newly developed laser printers. (Remember, the first PC, the MITS altair, was not introduced to the public until 1975.) Metcalfe originally called this network the Alto Aloha Network. He changed the name to Ethernet in 1973 to make it clear...

Ata Glance Asynchronous Transfer Mode ATM

ATM delivers information in fixed-size units called cells. Every ATM cell, regardless of the type of information (voice, video, data), is exactly 53 bytes with 48 bytes of information and 5 bytes of header (overhead) information. This is different from other protocols that can increase the cell size and actually increase the header or overhead traffic on a network. There are two distinct advantages in using fixed cell sizes that outweigh the cost of the additional overhead. Header 48 Bytes of...

Storage Networking Technologies

This section briefly summarizes some common storage technologies. Small Computer Systems Interface (SCSI) SCSI (pronounced scuzzy) is a parallel bus interface port used to connect peripheral devices such as RAID, tape devices, and servers. SCSI is a low-cost method of directly connecting devices but is limited with regard to scalability and distance. System with SCSI Disk Tower Disk Tower Host Adapter SCSI Index 1 SCSI Index 2 System with SCSI Disk Tower Disk Tower Host Adapter SCSI Index 1...

Deep Packet Inspection

Deep Packet Inspection (DPI) is a technique that allows network security devices such as firewalls to look deeper into the IP packet to try to learn its true intent. Instead of relying on fairly standard packet header information (essentially Layers 2 and 3), which again is starting to look the same for every application on the network, DPI can look much further up the OSI stack, into Layers 4 through 7. With the increased visibility that DPI provides, it is possible for network security...

Combating Access Based Attacks

A common entry point for network threats are the wired (and wireless) access ports where devices connect, such as laptops, printers, IP phones, and others. Without appropriate measures, hackers attempting to cause mischief in networks can plug into a port and use it as a launching location to work their way into the rest of the network. Such intrusions may require physical access to the corporate location. Physical security measures such as locked doors, badge readers, video surveillance, and...

Virtual Circuits

Frame Relay connections are established using logical connections called virtual circuits. Virtual circuits can pass through several DCE devices throughout the Frame Relay Packet-Switched Network (PSN). Several virtual circuits can be multiplexed into a single physical circuit for transmission across the network. The two types of virtual circuits are switched virtual circuits (SVC) and permanent virtual circuits (PVC). An SVC is a temporary connection used for sporadic data transfer between DTE...

Fiber Channel and IP

The two access methods available for SANs are fiber channel (the official name is Fibre Channel) and Internet Protocol (IP). Dedicated fiber-channel networks attach servers to storage devices. The fiber-channel network passes around data blocks (blocks are used by disk access), which the servers access through host-bus adapters. The servers then attach to LANs to provide the information to the rest of the network. SAN components include host-bus adapters, storage systems (RAID, JBOD, tape, and...

Explaining Toll Bypass

Provider Toll Network

Toll bypass is the ability of IP telephony users to avoid (or bypass) long-distance (toll) charges. The following figure illustrates where the fees are levied. Traditional telephony Charges accrue for access to local phone carriers. In addition, a longdistance provider also collects a fee for transport over its system. If this company maintains a data network, it must also pay a different local provider for access to the data (IP) network. Unified Communications With this method, a local...

Rogue Access Points

Rogue or unauthorized wireless access points provide a serious security threat to a network. Locating and shutting down such unauthorized APs can be difficult without automated detection and location systems. The Cisco Unified Wireless solution uses authorized wireless access points to scan the environment for rogue access points. Detection information is provided to the WLCs, which can then assist in correlation and isolation and provide the information to the WCS. Wireless topology...

Throwing Away the Ties That Bind

The evolution of the telephone reveals one consistent evolving design principle People do not want to be tied to a particular location when using the phone. The first phones were attached to the wall, and people leaned down or stood on their toes to speak into the horn and listen to the response. Then the mouthpiece and listening device were combined into a single handset and connected to the phone by a cord. The phone still hung on the wall, but you could rest the handset against your head and...

Dynamic Multipoint VPNs DMVPN

Site-to-site VPNs that use IPsec for encryption typically were set up in advance and in a point-to-point topology. Each tunnel must be configured between a branch office and a headquarters site. A WAN headend aggregating many thousands of branch office connections could literally have tens of thousands of configuration commands required to deploy a WAN service. DMVPNs simplify the deployment. There are two types of DMVPN topologies Hub-and-spoke DMVPN connects many branch offices (spokes) to a...

Sonet Dwdm and DPT

Three primary optical technologies are employed today Synchronous Optical NET (SONET) Dense wavelength division multiplexing (DWDM) Dynamic packet transport (DPT) All three convert electrical signals into light and vice versa. Fiber-Optic Transmission Systems (FOTS) do the conversion. Fiber-optic signals are not susceptible to electrical interference. The signals can transmit over long distances and send more information than traditional electrical transports. The combination of these benefits...

Frame Transmission Modes

Switches typically are Layer 2 devices (some switches now perform Layer 3 and higher functions). According to the OSI model, the data unit processed by a switch is called a frame. Switches must balance speed and accuracy (no errors) when processing frames, because typically they are measured on both attributes. The three primary frame switching modes are as follows Cut-through Also known as fast-forward. The switch checks only the destination address and immediately begins forwarding the frame....

What Is QoS

QoS is a collection of features designed to ensure reliable, timely delivery of voice and other real-time packets across an IP network. Unlike data files, which can be broken up, sent in random order, and reassembled at the receiving end, it is critical for voice packets to arrive in order with minimal delay. QoS does just that. Think of it as VIP treatment for packets. QoS allows different types of applications to contend for network resources. Voice, video, and critical data applications may...

Types of Data Centers

Data centers are defined by what type of network they support. The three basic classes are Internet, intranet, and extranet. Each type of data center has specific infrastructure, security, and management requirements for its supporting server farms Internet server farms are accessed from the Internet and typically are available to a large community. Web interfaces and web browsers are widely available, which makes them pervasive. Intranet server farms should have the same ease of access as...

Using Black White Lists

If a company chooses to manage its own URL filtering, all the URLs considered out of policy must URL Filtering Eliminating Unwanted Web Page Access 201 be configured in a black white list in the network device responsible for intercepting HTTP requests. The pros and cons of this approach are as follows It provides a basic solution if a few specific URLs need to be exempted. It allows the company to directly manage the URLs it considers to be out of policy. Existing network equipment can be...

Cisco Networking Simplified Second Edition

Jim Doherty, Neil Anderson, Paul Delia Maggiora Copyright 2008 Cisco Systems, Inc. Published by Cisco Press 800 East 96th Street Indianapolis, IN 46240 USA All rights reserved. No part of this book may be reproduced or transmitted in any form or by any means, electronic or mechanical, including photocopying, recording, or by any information storage and retrieval system, without written permission from the publisher, except for the inclusion of brief quotations in a review. Printed in the United...

Network Availability

One of the most important aspects of networking is keeping the network running at all times, under any circumstances, even during times of excessive use or stress. Actually, especially during times of excessive use or stress. Why Because a downed network can mean millions of dollars per minute in lost revenue. Consider a large retailer with 3000 stores that processes hundreds of credit card transactions per minute. If it cannot accept credit card purchases, it delays or loses sales. The first...

Networking Fundamentals

Before we begin talking about specific networking technologies and applications, it's worth taking a few How Computers Communicate 5 pages to go over some networking fundamentals. Networks exist for the sole purpose of sharing informait 5 5 5 TCP IP and IP Addressing 13 tion between people or machines. However, to share information, rules must be followed to ensure that the myriad combinations of devices, transports, hardware, and software can communicate smoothly. Internet Applications 27 In...

How Does It Work

The Cisco Unified MeetingPlace solution provides easy collaboration for employees. This solution is highly integrated with other Cisco Unified Communications systems, including Unified VoIP Communications, Unified Video Conferencing, Presence, and others. This solution also supports scheduled or ad hoc conferencing and allows sharing of presentation slides and documents and easy transfer of sharing control among participants. Unified Communications is most useful when it integrates with the...

QoS for Wireless VoIP

Just like wired networks, for wireless networks to carry voice calls with good voice quality, quality of service (QoS) techniques are required. Network administrators must consider both upstream Wireless multimedia (WMM) is a form of wireless (client-to-network) and downstream (network-to- QoS being standardized within the Wi-Fi Alliance client) traffic flows. QoS service policies should be based on 802.11e and 802.1p standards. mapped between wired network and radio interface. Wireless VoIP...

Pv6 Addresses

The 128-bit address used in IPv6 allows for a greater number of addresses and subnets (enough space for 1015 endpoints 340,282,366,920,938, 463,463,374,607,431,768,211,456 total ). IPv6 was designed to give every user on Earth multiple global addresses that can be used for a wide variety of devices, including cell phones, PDAs, IP-enabled vehicles, consumer electronics, and many more. In addition to providing more address space, IPv6 has the following advantages over IPv4 Easier address...

Data Center Layers

Data centers can be logically divided into six logical layers. These layers do not correlate to the OSI layers. This list represents one of a number of ways to look at data centers. These layers are based on logical functions Aggregation Consists of network infrastructure components that connect all data center service devices, such as firewalls, content switches, Call Managers, and Content Distribution Managers. Front-end Contains FTP, Telnet, e-mail, web servers, and other business...

What Is Storage Networking

To overcome the drawbacks of server-centric storage, a network-centric model called storage networking has been developed. Storage networking is the software and hardware that enable storage to be consolidated, shared, accessed, replicated, and managed over a shared network infrastructure. To understand how storage networking works, you must understand the different storage methods and technologies.

Extra Layers

Discussions among technical purists can often lead to philosophical or budgetary debates that can quickly derail otherwise-productive meetings. These discussions are often referred to as Layer 8 (political) and Layer 9 (financial) debates. Although these layers are not really part of the OSI model, they are usually the underlying cause of heated technology arguments. Another common joke among networking professionals is the type of networking problem referred to as a Layer 8 issue. Because the...

Distribution nTier Model

As the importance and size of server farms have increased, the limitations of a traditional client server model of data storage and retrieval have become more evident. The -tier model separates the server farm functions into distinct tiers, which improves both efficiency and ease of management. The model typically has three tiers. The first tier typically runs the user-facing applications, the second tier maps user requests to the data, and the third tier is where the data is actually stored....

Scavenger QoS

Scavenger QoS operates on the principle that if we know a typical application's behavior on a device and on the network, we can build safeguards into the network to recognize and stop an application if it is not behaving normally. For example, if we know that a particular port on the network has an IP-enabled telephone connected to it, and we know that device normally transmits less than, say, 150 kbps of RTP traffic packets, and suddenly we see more than 4 Mbps of RTP traffic from that port,...

ATM Features

ATM implements two features that make it both useful and interesting (well, interesting in a network geek kind of way). The two concepts are asynchronous transmission and fixed cell size. The Asynchronous part of ATM refers to the protocol's ability to use a more efficient version of time-division multiplexing (TDM). Multiplexing is a method of combining multiple data streams onto a single physical or logical connection. Time division means that each data stream has an assigned slot in a...

WLAN Roaming

Because wireless APs are relatively inexpensive, and the desire for bandwidth is high, most companies choose to deploy multiple APs with a reduced transmission radius and increased throughput. This solution, however, introduces the need to implement a WLAN roaming scheme. Roaming is a term used to describe switching from the control of one AP to another. APs should be positioned so that there are no dead spots. As a user moves away from one AP, the power and signal quality decrease. A good...

Infrastructure Layer

From the perspective of delivering the reliable voice services people expect on the PSTN, the infrastructure layer is the most critical. It is the job of the infrastructure to ensure that a call (in the form of VoIP packets) is carried from source to destination in a reliable and timely manner. Traditional data networks tolerate delay or some degree of packet loss because of the nature of the applications that they were designed for, such as access to relatively low-speed mainframe...

Comfort Noise

The digital signals used in VoIP are usually much cleaner than the analog signals used in circuit-switched telephony. This is because in analog systems, any amplification of the signal also amplifies noise, resulting in the static heard in the background during calls. With digital signals, noise can be cleaned out, and a much more pure sound can be achieved. This may seem like a good thing, but it actually causes problems. It turns out that on analog calls the slight background noise indicates...

How URL Filtering Works

After the list of restricted sites is created, all HTTP requests for content are intercepted by the network and are checked against the policy list. Requests deemed appropriate are allowed, and the web session works without interruption. GET www.cisco.com GET www.xxxpics.com GET www.gambling.com Requests for content that are against company policies are blocked and are often redirected to a page stating that the site that was requested was blocked because of inappropriate content. In some cases...

Problems with Loops

Although redundancy can prevent a single point of failure from causing the entire switched network to fail, it can also cause problems such as broadcast storms, multiple copies of frames, and MAC address table instability. A broadcast storm refers to the infinite flooding of frames. Broadcast storms can quickly shut down a network. An example of a broadcast storm is shown here. 1. A broadcast frame is sent by another segment and is received by the top ports of switches A and B. 2. Both switches...

Cisco Unified Personal Communicator CUPC

The Cisco Unified Personal Communicator (CUPC) refers to an integrated Unified Communications client that runs on a laptop or handheld computer, bringing together many forms of communications on a single device. Types of communications include voice, video, instant messaging, voice mail, e-mail, application sharing, and web conferencing and collaboration. The CUPC endpoint is integrated into the business Unified Communications system. Therefore, it has a phone number in the corporate dial plan...

Data Link Connection Identifier

Frame Relay virtual circuits are identified by datalink connection identifiers (DLCI). DLCI values typically are assigned by the Frame Relay service provider. Frame Relay DLCIs are of local significance only. In other words, the DLCI values are unique only at the endpoints, not over WANs. Therefore, two DTE devices connected by a virtual circuit might use a different DLCI value to refer to the same connection. In addition, two DTEs can be connected on the same virtual circuit but still have...

Guest Access Step by Step

The following sequence provides a step-by-step flow of how a guest is given Internet access over the corporate wireless network 1. A guest login is created (usually by an administrative assistant or other employee). 2. Credentials can be e-mailed or printed for guests or visitors. 3. When the guest arrives, he or she connects to open SSID. 4. After the guest is connected, a web-authentication portal intercepts traffic and prompts the guest for his or her login information. 5. Guest traffic...

Deencapsulation

De-encapsulation, the opposite of encapsulation, is the process of passing information up the stack. When a layer receives a PDU from the layer below, it does the following 1. It reads the control information provided by the peer source device. 2. The layer strips the control information (header) from the frame. 3. It processes the data (usually passing it up the stack). Each subsequent layer performs this same de-encapsulation process. To continue the preceding example, when the plane arrives,...

Acknowledgments

Jim and Neil would like to thank the following people Our families, whom we lied to after the last book, when we said we would not do this again, and who put up with our working late nights and weekends. This time, we mean it. Our publisher and the fine team at Cisco Press and Pearson Education. We would especially like to thank our editor, Sheri Cain, who bravely agreed to join us on another project our production manager, Patrick Kanouse Chris Cleveland Karen Gettman Tonya Simpson Jennifer...

Device Isolation

The Cisco network virtualization framework can be used to isolate specialized devices, such as ATMs and manufacturing robots, as well as to provide hosted network services for in-store kiosks Access control uses MAC Auth Bypass (MAB) and static port assignment to map specialized devices (ATMs, IP video surveillance cameras, building HVAC systems, manufacturing robots, hosted entity kiosks, and so on) to private virtual network partitions. Path isolation securely isolates specialized device...

Passive Monitoring

An IDS passively monitors packets on the network and logs events. The figure shows the steps involved 1. Traffic on the network is copied and routed to the IDS Sensor for analysis. 2. If traffic matches an intrusion signature, the signature fires. 3. IDS Sensor sends an alarm to the management