Network Design
Designing a Campus Network Design Topology
Campus network design topologies should meet a customer's goals for availability and performance by featuring small bandwidth domains, small broadcast domains, redundancy, mirrored servers, and multi ways for a workstation to reach a router for off-net communications. Campus networks should be desig using a hierarchical, modular approach so that the network offers good performance, maintainability, ai scalability. Most campus networks feature a high-performance, switched backbone, called the...
Project Scope
The Project Scope section provides information on the extent of the project, including a summary of the departments and networks that will be affected by the project. The Project Scope section specifies whether the project is for a new network or modifications to an existing network. It indicates whether the design is for a single network segment, a set of LANs, a building or campus network, a set of WAN or remote-access networks, or possibly the whole enterprise network. An example of a...
Guidelines for Hierarchical Network Design
This section briefly describes some guidelines for hierarchical network design. Following these simple guidelines will help you design networks that take advantage of the benefits of hierarchical design. The first guideline is that you should control the diameter of a hierarchical enterprise network topology. In most cases, three major layers are sufficient (as shown in Figure 5-4) Controlling the network diameter provides low and predictable latency. It also helps you predict routing paths,...
Securing Dialup Access
Security is critical for dialup access and should consist of firewall technologies, physical security, authentication and authorization mechanisms, auditing, and possibly encryption. Authentication and authorization are the most important features for dialup access security. One-time passwords with security cards make a lot of sense in this arena. Remote users and remote routers that use the Point-to-Point Protocol (PPP) should be authenticated with the Challenge Handshake Authentication...
Implementation Plan
The Implementation Plan includes your recommendations for deploying the network design. The level of detail in this section varies from project to project, and depends on your relationship to your customer. If you are a member of an Information Systems (IS) department that is responsible for the design and implementation of the new network, then this section should be quite detailed. If you are a sales engineer for a vendor of networking products, on the other hand, your role is probably to...
Integrated Services Digital Network
PPP is often used with Integrated Services Digital Network (ISDN), which is a digital data-transport service offered by regional telephone carriers. ISDN supports the transmission of text, graphics, video, music, voice, and other source material over telephone lines. PPP provides data encapsulation, link integrity, and authentication for ISDN. ISDN offers a cost-effective, remote-access solution for telecommuters and remote offices that require higher transmission speeds and quicker connection...
Circuit Diversity
When provisioning backup WAN links, you should learn as much as possible about the actual physical circuit routing. Different carriers sometimes use the same facilities, meaning that your backup path is susceptible to the same failures as your primary path. You should do some investigative work to ensure that your backup really is a backup. Network engineers use the term circuit diversity to refer to the optimum situation of circuits using different paths. Because carriers lease capacity to...
Selecting Technologies and Devices for Enterprise Networks
This chapter presents technologies for the remote-access and wide-area network (WAN) components of an enterprise network design. The chapter discusses physical and data link layer protocols and enterprise network devices, such as remote-access servers, routers, and virtual private network (VPN) concentrators. The chapter begins with a discussion of the following remote-access technologies The Point-to-Point Protocol (PPP) Integrated Services Digital Network (ISDN) Digital Subscriber Line (DSL)...
Controlled Load Service
Controlled-load service is defined in RFC 2211 and provides a client data flow with a QoS closely approximating the QoS that same flow would receive on an unloaded network. Admission control is applied to requests to ensure that the requested service is received even when the network is overloaded. The controlled-load service is intended for applications that are highly sensitive to overloaded conditions, such as real-time applications. These applications work well on unloaded networks, but...
Optimizing Network Performance to Meet Quality of Service Requirements
In addition to optimizing bandwidth usage by adding IP multicast, LFI, and compression features to a network design, you may determine that optimization is also needed to meet QoS requirements. The Characterizing Quality of Service Requirements section in Chapter 4 talked about specifying the QoS that an application requires. This section covers some techniques for meeting those requirements. The focus of this section is meeting QoS requirements in a TCP IP internetwork. For more information on...
Analyzing Errors on Switched Ethernet Networks
Switches are replacing hubs in many campus networks. A switch port that is in half-duplex mode follows the normal rules of CSMA CD. The port senses carrier, defers if necessary, detects collisions, backs off, and retransmits. Whether a collision can occur depends on what is connected to the switched port. If a shared medium is connected to the switch, collisions may occur. A good rule of thumb is that less than 0.1 percent of frames should encounter collisions. There should be no late...
InBand Versus Outof Band Monitoring
With in-band monitoring, network management data travels across an internetwork using the same paths as user traffic. This makes the network management architecture easy to develop, but results in the dilemma that network management data is impacted by problems on the internetwork, making it harder to troubleshoot the problems. It is beneficial to be able to use management tools even when the internetwork is congested, failing, or under a security attack. With out-of-band monitoring, network...
Meeting Security Goals with Firewall Topologies
A firewall is a system or combination of systems that enforces a boundary between two or more networks. A firewall can be a router with access control lists (ACLs), a dedicated hardware box, or software running on a PC or UNIX system. A firewall should be placed in the network topology so that all traffic from outside the protected network must pass through the firewall. A security policy specifies which traffic is authorized to pass through the firewall. Firewalls are especially important at...
Dynamic Inter Switch Link Protocol
With early versions of ISL, you had to manually enable ISL at both ends of a trunk. In more recent versions of Cisco switching software, the Cisco proprietary Dynamic Inter-Switch Link (DISL) protocol supports a switch negotiating with the remote side to enable or disable ISL. DISL should be recommended to your design customers, but be careful with its configuration. ISL on a trunk interface can be set to on, off, desirable, auto, and nonegotiate. Nonegotiate enables ISL but does not send any...
Redundancy and Load Sharing in Wired LANs
In wired campus networks, it is common practice to design redundant links between LAN switches. Mos LAN switches implement the IEEE 802.1D spanning-tree algorithm to avoid network loops. The 802.1D standard is a good solution for redundancy, but not for load sharing, because only one path is active. S' switch vendors, including Cisco, let you have one spanning tree per VLAN, which can be used to implem redundancy. A switch can act as the root bridge for one VLAN and as a backup for the root...
Uplink Fast and Backbone Fast
UplinkFast is a Cisco feature that can be configured on access layer switches. UplinkFast improves the convergence time of STP in the event of a failure of a redundant uplink from an access layer switch. An uplink is a connection from an access layer switch to a higher-end switch in the distribution layer of a hierarchical network design. Figure 7-1 illustrates a typical redundant, hierarchical network design. Users are connected to Switch A in the access layer. The access layer switch is...
Responding to a Customers Request for Proposal
An RFP lists a customer's design requirements and the types of solutions a network design must include. Organizations send RFPs to vendors and design consultants and use the responses they receive to weed out suppliers that cannot meet requirements. RFP responses help organizations compare competing designs, product capabilities, pricing, and service and support alternatives. Every RFP is different, but typically an RFP includes some or all of the following topics Business goals for the project...
Identifying the Scope of a Network Design Project
One of the first steps in starting a network design project is to determine its scope. Some of the most common network design projects these days are small in scope for example, projects to allow a few people in a sales office to access the enterprise network via a VPN. On the other hand, some design projects are large in scope. Ask your customer to help you understand if the design is for a single network segment, a set of LANs, a set of WAN or remote-access networks, or the entire enterprise...
Selecting a WAN Service Provider
In addition to selecting technologies and devices for a WAN network design, you must also select service providers or carriers. One obvious criterion for selecting a service provider is the cost of services. Using cost as the main selection criterion, however, can make the choice difficult because providers offer distinct services and define terms and conditions differently. Also, for many network designs, cost is not the main criterion. The following criteria are often more important than cost...
Design Document Appendix
Most design documents include one or more appendixes that present supplemental information about the design and implementation. Supplemental information can include detailed topology maps, device configurations, network addressing and naming details, and comprehensive results from the testing of the network design. You can also include business information such as a list of contacts at the customer's site and in your organization, including e-mail addresses, phone numbers, beeper numbers, and...
Securing Server Farms
Server farms host file, print, database, and application servers inside campus networks and branch offices. These servers often contain an enterprise's most sensitive information, so they must be protected. Because servers are accessed by a large number of users, network performance is usually a critical issue, which can limit the choice of protection mechanisms. Nonetheless, methods should be deployed to protect against the compromise of exposed applications and unauthorized access to data....
Why Use a Hierarchical Network Design Model
Networks that grow unheeded without any plan in place tend to develop in an unstructured format. Dr. Peter Welcher, the author of network design and technology articles for Cisco World and other publications, refers to unplanned networks as fur-ball networks. Welcher explains the disadvantages of a fur-ball topology by pointing out the problems that too many CPU adjacencies cause. When network devices communicate with many other devices, the workload required of the CPUs on the devices can be...
Mbps Ethernet
Although 100-Mbps Ethernet is beginning to replace 10-Mbps Ethernet, 10-Mbps Ethernet can still play a role in your network design, particularly at the access layer. For some customers 10-Mbps capacity is sufficient. For customers who have low bandwidth needs and a small budget, 10-Mbps Ethernet is an appropriate solution if the network does not need to scale to 100-Mbps in the near future. Many business applications do not benefit from an upgrade to 100-Mbps shared Ethernet. Inefficient...
Aggregatable Global Addresses
Aggregatable global unicast addresses are equivalent to public registered addresses in IPv4. These addresses are designed to support the type of provider-based aggregation currently used on the Internet and a new, geographic type of aggregation based on exchange points. (The latter is experimental, and provider-based aggregation may remain the norm.) The structure of aggregatable global unicast addresses enables aggregation of routing prefixes so that the number of routing table entries in the...
Synchronous Optical Network
The next WAN technology this chapter covers is Synchronous Optical Network (SONET), which is a physical layer specification for high-speed synchronous transmission of packets or cells over fiber-optic cabling. SONET was proposed by Bellcore in the mid-1980s and is now an international standard. SONET uses the SDH system with STS-1 as its basic building block. Service providers and carriers are making wide use of SONET in their internal networks. SONET is also gaining popularity within private...
Making Network Design Tradeoffs
Despite what politicians tell us about state and federal budgets during an election year, in the real world meeting goals requires making tradeoffs. This section describes some typical network design tradeoffs. To meet high expectations for availability, redundant components are often necessary, which raises the cost of a network implementation. To meet rigorous performance requirements, high-cost circuits and equipment are required. To enforce strict security policies, expensive monitoring...
Cisco Express Forwarding
CEF is a Cisco-patented technique for switching packets very quickly across large backbone networks and the Internet. Rather than relying on the caching techniques used by classic switching methods, CEF depends on a forwarding information base (FIB). The FIB allows CEF to be much less processor-intensive than other Layer 3 switching methods because the FIB tables contain forwarding information for all routes in the routing tables (whereas a cache contains only a subset of routing information)....
The Spanning Tree Protocol
The topology of each module and submodule of a campus network design is partially determined by the Spanning Tree Protocol (STP). STP is a protocol and algorithm, documented in IEEE 802.1D, for dynamically pruning an arbitrary topology of connected Layer 2 switches into a spanning tree. The topology that results spans the entire switched domain and is shaped like a mathematical tree, with branches that spread out from a stem without forming loops or polygons. The network designer physica...
Gigabit Ethernet
Gigabit Ethernet was originally defined in the IEEE 802.3z standard and is now merged into the 2002 edition of IEEE 802.3. It operates essentially like 100-Mbps Ethernet, except that it is 10 times faster. It uses CSMA CD with support for one repeater per collision domain, and handles both half- and full-duplex operations. It uses a standard 802.3 frame format and frame size. To avoid the need to reduce the size of a half-duplex Gigabit Ethernet network to 1 10th the size of a 100-Mbps Ethernet...
Gbps Ethernet
One of the reasons that Ethernet is such a good choice for campus network designs is that it continues to grow with increasing bandwidth demands. In 2002, the IEEE standardized 10-Gbps Ethernet in the 802.3ae specification. 10-Gbps Ethernet differs in some important ways from the other Ethernet implementations, but it is also remarkable how similar it is to the other implementations. The frame format and other Layer 2 specifications remain the same which means that applications that use...
The Interoperability Lab at the University of New Hampshire IOL
Refer to www.iol.unh.edu for more information. ICSA Labs. Refer to www.icsalabs.com for more information. Miercom Labs. Refer to www.miercom.com for more information. KeyLabs. Refer to www.keylabs.com for more information. The Tolly Group. Refer to www.tollygroup.com for more information. Sometimes, for simple network designs, you can rely on test results from vendors, independent labs, or trade journals to prove to your customer that your design will perform as intended. For example, if you...
Analyzing Network Efficiency
Chapter 2 talked about the importance of using maximum frame sizes to increase network efficiency. Bandwidth utilization is optimized for efficiency when applications and protocols are configured to send large amounts of data per frame, thus minimizing the number of frames and round-trip delays required for a transaction. The number of frames per transaction can also be minimized if the receiver is configured with a large receive window allowing it to accept multiple frames before it must send...
Authentication in Wireless Networks
In a wired Ethernet LAN, a device must physically plug into the network to communicate. This fundamental feature of a wired Ethernet is not present in the realm of wireless networking, however. There is nothing to plug in. The IEEE 802.11 standard provides a method for devices to authenticate to a wireless access point, thus emulating the basic security provided by a wired network where a user must have physical access to a port to communicate. Authentication takes place after a wireless client...
Securing Network Services and Network Management
To protect internal network services, it is important to protect internal internetworking devices, such as routers and switches. You should treat each network device as a high-value host and harden (strength) it against possible intrusions. This involves common practices such as running only the minimal necessary services and establishing trust only with authentic partners. For example, a router should not accept routing updates from a router that has not been authenticated. Routing protocols...
The Internet Group Management Protocol
The Internet Group Management Protocol (IGMP) allows a host to join a group and inform routers of the need to receive a particular data stream. IP hosts use IGMP to report their multicast group memberships to immediately neighboring multicast routers. When a user (or system process) starts an application that requires a host to join a multicast group, the host transmits a membership-report message to inform routers on the segment that traffic for the group should be multicast to the host's...
Checking the Status of Major Routers Switches and Firewalls
The final step in characterizing the existing internetwork is to check the behavior of the internetworking devices in the internetwork. This includes routers and switches that connect layers of a hierarchical topology, backbone routers and switches, and routers, switches, and firewalls that will have the most significant roles in your new network design. It's not necessary to check every LAN switch, just the major switches, routers, and firewalls. Checking the behavior and health of an...
Characterizing Wiring and Media
To help you meet scalability and availability goals for your new network design, it is important to understand the cabling design and wiring of the existing network. Documenting the existing cabling design can help you plan for enhancements and identify any potential problems. If possible, you should document the types of cabling in use as well as cable distances. Distance information is useful when selecting data link layer technologies based on distance restrictions. While exploring the...
Figure 106 The Building Network Design for WVCC
The switches run the IEEE 802.1D Spanning Tree Protocol. The switches support SNMP and RMON. A Windows-based network management software package monitors the switches. The software runs on a server in the server farm module of the network design. All devices are part of the same broadcast domain. All devices (except two public servers) are part of the 192.168.1.0 subnet using a subnet mask of 255.255.255.0. Addressing for end-user PCs and Macintoshes is accomplished with DHCP. A Windows server...
Modularizing Security Design
Security experts promote the security defense in depth principle. This principle states that network security should be multilayered with many different techniques used to protect the network. No security mechanism can be guaranteed to withstand every attack. Therefore, each mechanism should have a backup mechanism. This is sometimes called the belt-and-suspenders approach. Both a belt and suspenders are used to ensure that trousers stay up. A networking example is to use a dedicated firewall...
Optimizing Your Network Design
Optimization is a critical design step for organizations that use high-bandwidth and delay-sensitive applications. To achieve business goals, these organizations expect their networks to use bandwidth efficiently, to control delay and jitter, and to support preferential service for essential applications. Internetworking vendors, such as Cisco Systems, and standards bodies, such as the Institute of Electrical and Electronics Engineers (IEEE) and the Internet Engineering Task Force (IETF), offer...
Variable Length Subnet Masking
Using a classless routing protocol means that you can have different sizes of subnets within a single network. Varying the size of subnets is also known as variable-length subnet masking, or VLSM. VLSM relies on providing prefix length information explicitly with each use of an address. The length of the prefix is evaluated independently at each place it is used. The capability to have a different prefix length at different points supports efficiency and flexibility in the use of the IP address...
Routing Protocol Convergence
Convergence is the time it takes for routers to arrive at a consistent understanding of the internetwork place. A change can be a network segment or router failing, or a new segment or router joining the inte importance of quick convergence for your particular customer, you should develop an understanding of on the customer's network. Are there links that tend to fail often Is the customer's network always u enhancements or because of reliability problems Because packets may not be reliably...
IP Workstationto Router Communication
IP implementations vary in how they implement workstation-to-router communication. Some IP workstations send an Address Resolution Protocol (ARP) frame to find a remote station. A router runnin proxy ARP can respond to the ARP request with the router's data link layer address. Cisco routers run p ARP by default. The advantage of depending on proxy ARP to reach remote stations is that a workstation doesn't have 1 configured with the address of a router. However, because proxy ARP has never been...
Load Sharing
The primary purpose of redundancy is to meet availability requirements. A secondary goal is to improve performance by supporting load sharing across parallel links. Load sharing, sometimes called load balancing, allows two or more interfaces or paths to share traffic load. Purists have taken to using the term load sharing instead of load balancing because the load is usually not precisely balanced across multiple links. Because routers can cache the interface that they use for a destination...
Selecting Technologies and Devices for Campus Networks
Physical network design involves the selection of LAN and WAN technologies for campus and enterprise network designs. During this phase of the top-down network design process, choices are made regarding cabling, physical and data link layer protocols, and internetworking devices (such as hubs, switches, routers, and wireless access points). A logical design, which Part II, Logical Network Design, covered, forms the foundation for a physical design. In addition, business goals, technical...
Broadcast Multicast Behavior
A broadcast frame is a frame that goes to all network stations on a LAN. At the data link layer, the destination address of a broadcast frame is FF FF FF FF FF FF (all 1s in binary). A multicast frame is a frame that goes to a subset of stations. For example, a frame destined to 01 00 0C CC CC CC goes to Cisco routers and switches that are running the Cisco Discovery Protocol (CDP) on a LAN. Layer 2 internetworking devices, such as switches and bridges, forward broadcast and multicast frames...
The Dynamic Host Configuration Protocol
BOOTP hosts can interoperate with DHCP hosts, although DHCP adds many enhancements to BOOTP, including a larger vendor-specific information field (called the options field in DHCP) and the automatic allocation of reusable network layer addresses. DHCP has bypassed BOOTP in popularity, probably because it is easier to configure. Unlike BOOTP, DHCP does not require a network administrator to maintain a MAC-to-IP address table. DHCP uses a client server model. Servers...
Mesh Versus Hierarchical Mesh Topologies
Network designers often recommend a mesh topology to meet availability requirements. In a full-mesh topology, every router or switch is connected to every other router or switch. A full-mesh network provides complete redundancy, and offers good performance because there is just a single-link delay between any two sites. A partial-mesh network has fewer connections. To reach another router or switch in a partial-mesh network might require traversing intermediate links, as shown in Figure 5-3....
Characterizing Routing Protocols
All routing protocols have the same general goal to share network reachability information among rout goal in a variety of ways. Some routing protocols send a complete routing table to other routers. Other information on the status of directly connected links. Some routing protocols send periodic hello packet routers. Some routing protocols include advanced information such as a subnet mask or prefix length w protocols share dynamic (learned) information, but in some cases, static configuration...
Digital Subscriber Line Remote Access
Another technology for remote access is Digital Subscriber Line (DSL). Telephone companies offer DSL for high-speed data traffic over ordinary telephone wires. With DSL, a home office or small office can connect a DSL modem (or DSL router with a built-in modem) to a phone line and use this connection to reach a central-site intranet and or the Internet. DSL is similar to ISDN in that it is a technology that operates over existing telephone lines between a telephone switching station and a home...
Compressed Real Time Protocol
The Real Time Protocol (RTP), which is defined in RFC 1889, provides end-to-end network transport functions suitable for transmitting real-time data over multicast or unicast network services. Applications typically run RTP on top of the User Datagram Protocol (UDP) to make use of UDP's multiplexing and checksum services. Working together with UDP, RTP implements Layer 4 (transport) functionality. (UDP is not required. RTP can be used with other suitable underlying network or transport...
Windowing and Flow Control
To really understand network traffic, you need to understand windowing and flow control. A TCP IP device, for example, sends segments (packets) of data in quick sequence, without waiting for an acknowledgment, until its send window has been exhausted. A station's send window is based on the recipient's receive window. The recipient states in every TCP packet how much data it is ready to receive. This total can vary from a few bytes up to 65,535 bytes. The recipient's receive window is based on...
Technical Goals Checklist
You can use the following checklist to determine if you have addressed all your client's technical objectives and concerns I- I have documented the customer's plans for expanding the number of sites, users, and servers for the next 1 year and the next 2 years. I. The customer has told me about any plans to migrate departmental servers to server farms or intranets. I- The customer has told me about any plans to integrate SNA or other mainframes into the multiprotocol internetwork. The customer...
Routing Table Maintenance Protocol
RTMP is the main routing protocol for the AppleTalk protocol suite. Contrary to many pictures that you RTMP is not a transport layer protocol. It is a typical distance-vector routing protocol. RTMP packets res AppleTalk's network layer protocol, the Datagram Delivery Protocol (DDP). An RTMP router sends its routing table every 10 seconds, using split horizon. Apple Computer chose sui convergence time on large internetworks and to support end systems learning about a router on their n large...
Other DSL Implementations
DSL is sometimes called xDSL because of the many types of DSL technologies. In addition to ADSL and SDSL, providers in your area may support the following services ISDN DSL (IDSL) is a cross between ISDN and DSL. As with ISDN, IDSL uses a single wire pair to transmit data at 128 Kbps in both directions and at distances of up to 15,000 to 18,000 feet (about 4600 to 5500 meters). Unlike ISDN, IDSL does not use a signaling channel (a D channel). High-Bit-Rate DSL (HDSL) is a mature technology that...
Site Local Addresses
Site-local addresses are IPv6 unicast addresses that use the FEC0 10 (1111 1110 11) prefix, followed by a subnet identifier and the interface identifier. Their purpose is the same as that of the RFC 1918 private addresses in IPv4. Routers must not forward any packets with site-local source or destination addresses outside of a site. Site-local addresses start with a 10-bit format prefix, giving you 128 minus 10 (118) bits to work with inside your routing domain, so they can be used to number an...
Interior Gateway Routing Protocol
Cisco developed the distance-vector Interior Gateway Routing Protocol (IGRP) in the mid-1980s to mee a robust and scalable interior routing protocol. Many customers migrated their RIP networks to IGRP to and reliance on just one metric (hop count). IGRP's 90-second update timer for sending route updates ' 30-second update timer for customers concerned about bandwidth utilization. IGRP uses a composite metric based on the following factors Bandwidth. The bandwidth of the lowest-bandwidth segment...
Using an Unpublished Service Set Identifier
Every WLAN has an SSID that identifies it. To gain access to a wireless LAN, a client must know the correct SSID. Some network administrators rely on this as a method for security even though it doesn't truly authenticate the client and doesn't provide any data privacy. Also, an eavesdropper can easily determine the SSID with the use of a wireless protocol analyzer, such as WildPackets's AiroPeek product. The SSID is advertised in plain text in beacon messages that the access point sends. Some...
DHCP Relay Agents
As mentioned, a router can act as a DHCP relay agent. This means that the router passes DHCP broadcast messages from clients to DHCP servers that are not on the same subnet as the clients. This avoids a requirement for a DHCP server to reside on each subnet with clients. With Cisco routers, you can use the ip helper-address command on each router interface where clients reside to cause the router to become a DHCP relay agent. An address parameter for the command should point to the IP address...
Documenting Application Usage Patterns
The first step in documenting application-usage patterns is to identify user communities, the number of users in the communities, and the applications the users employ. This step, which was already covered earlier in this chapter, can help you identify the total number of users for each application. In addition to identifying the total number of users for each application, you should also document the following information The frequency of application sessions (number of sessions per day, week,...
Routing Information Protocol
The IP Routing Information Protocol (RIP) was the first standard routing protocol developed for TCP IP originally for the Xerox Network System (XNS) protocols and was adopted by the IP community in the e common interior routing protocol for many years, probably because it is easy to configure and runs on i still in use on older networks and networks where simplicity and ease of troubleshooting are important. documented in RFC 1058. RIP version 2 (RIPv2) is documented in RFC 2453. RIP broadcasts...
Error Recovery Mechanisms
Poorly designed error-recovery mechanisms can waste bandwidth. For example, if a protocol retransmits data very quickly without waiting a long enough time to receive an acknowledgment, this can cause performance degradation for the rest of the network due to the bandwidth used. Acknowledgments at Layer 2 waste bandwidth as seen earlier in the Protocol Interaction section. Connectionless protocols usually do not implement error recovery. Most data link layer and network layer protocols are...
Specifying Availability Requirements
You should encourage your customers to specify availability requirements with precision. Consider the difference between an uptime of 99.70 percent and an uptime of 99.95 percent. An uptime of 99.70 percent means the network is down 30 minutes per week, which is not acceptable to many customers. An uptime of 99.95 percent means the network is down 5 minutes per week, which may be acceptable, depending on the type of business. Availability requirements should be specified with at least two...
Thin Client Traffic Flow
A special case of the client server architecture is a thin client, which is software or hardware that is designed to be particularly simple and to work in an environment where the bulk of data processing occurs on a server. With thin client technology, (also known as server-based computing), user applications originate on a central server. In some cases, the application runs on the central server, and, in other cases, the software is installed on the server and is downloaded into the client...
VPN Concentrators
Both routers and firewalls at the central site can act as the termination point for VPN tunnels. A generic router or firewall can become overwhelmed if a network supports many tunnels, however. If you expect the peak number of simultaneous users to reach 100, or the estimated amount of user traffic to exceed 4 Mbps, a VPN concentrator should be deployed. A VPN concentrator is a dedicated hardware platform that aggregates a large volume of simultaneous VPN connections. Generally, enterprises...
Causes of Delay
Any goals regarding delay must take into account fundamental physics. Despite science fiction stories that say differently, any signal experiences a propagation delay resulting from the finite speed of light, which is about 300,000 kilometers per second (or 186,000 miles per second for metric-challenged readers in the United States). Network designers can also remember 1 nanosecond per foot. These values are for light traveling in a vacuum. A signal in a cable or optical fiber travels...
Redundant Wireless Access Points
In both wired and wireless campus LAN architectures, redundancy is usually desirable to ensure high availability. For campus networks with WLANs that are mission critical, Cisco has a feature called access point hot standby that supports two access points being configured to use the same channel in a single coverage area. Only one of the access points is active. The standby access point passively monitors the network and the primary access point. If the primary access point fails, the secondary...
WiFi Protected Access and Robust Security Network
Two other developments that are related to 802.11i and wireless security are Wi-Fi Protected Access (WPA) and Robust Security Network (RSN). WPA is a subset of the 802.11i standard that has been adopted by the Wi-Fi Alliance. The Wi-Fi Alliance is a nonprofit international association formed in 1999 to certify interoperability of wireless products based on IEEE 802.11 specifications. The Wi-Fi Alliance introduced WPA because 802.11i was not ratified yet and also because 802.11i includes...
Optimized IP Addressing and Routing for the Campus Backbone
The network administrators and student assistants decided to keep the hierarchical, mesh logical topology that their predecessors so wisely chose. However, to fix the IP addressing problems, a routing module was added to each of the building high-end switches, essentially turning the switches into fast routers. With this new approach, the administrators were able to subdivide the network logically into multiple subnets. The administrators decided to stay with private addresses. They assigned...
Server Redundancy
This section covers guidelines for server redundancy in a campus network design. File, web, Dynamic H Configuration Protocol (DHCP), name, and database servers are all candidates for redundancy in a cam design, depending on a customer's requirements. In a network that supports Voice over IP (VoIP), the servers that provide the mapping between a phone number and an IP address and handle call processir should be provisioned in a redundant fashion. Cisco CallManager software, for example, supports...
Classless Routing Versus Classful Routing
As shown in Figure 6-1, an IP address contains a prefix part and a host part. Routers use the prefix to determine the path for a destination address that is not local. Routers use the host part to reach local hosts. Figure 6-1. The Two Parts of an IP Address Figure 6-1. The Two Parts of an IP Address A prefix identifies a block of host numbers and is used for routing to that block. Traditional routing, also known as classful routing, does not transmit any information about the prefix length....
The Common Open Policy Service Protocol
As mentioned in the previous section, RSVP simply transports QoS requests and provides techniques for routers to maintain information about the state of resource reservations. For RSVP to be effective, it needs support from additional protocols that understand actual services and policies regarding the services. One such protocol is the Common Open Policy Service (COPS) protocol, which is specified in RFC 2748. COPS defines a simple client server model for supporting policy control with QoS...
Remote Monitoring RMON
The RMON MIB was developed by the IETF in the early 1990s to address shortcomings in the standard MIBs, which lacked the ability to provide statistics on data link and physical layer parameters. The IETF originally developed the RMON MIB to provide Ethernet traffic statistics and fault diagnosis. In 1994, Token Ring statistics were added. RMON agents gather statistics on cyclic redundancy check (CRC) errors, Ethernet collisions, Token Ring soft errors, packet-size distribution, the number of...
Types of Cables
Three major types of cables are used in campus network implementations Shielded copper, including shielded twisted-pair (STP), coaxial (coax), and twin-axial (twinax) cables Unshielded copper (typically UTP) cables STP cabling was widely used in Token Ring networks in the 1980s and 1990s. Most Token Ring networks have been replaced by Ethernet networks these days. Ethernet generally uses UTP and fiber-optic cabling, although it is possible to make Ethernet work on STP cabling. (The fact that...
The IP Typeof Service Field
The purpose of the type-of-service field is to help a router select a route from a set of routes with different characteristics. Routing protocols attempt to determine the best route to a destination, but there are several definitions of best cheapest, fastest, most reliable, and so on. In theory, a routing protocol should be able to select a route based on the type of service that an application specifies. The type-of-service field within the type-of-service byte in an IP header has four bits...
Making Decisions as Part of the Top Down Network Design Process
The next few chapters provide guidelines for selecting network design solutions for a customer. The decisions you make regarding protocols and technologies should be based on the information you have gathered on your customer's business and technical goals. Researchers studying decision models say that one of the most important aspects of making a sound decision is having a good list of goals. In her book The Can-Do Manager, published by the American Management Association, Tess Kirby says that...
Summary for Part III
Chapter 11 concludes Part III, Physical Network Design. Physical design involves the selection of media, technologies, and devices for campus and enterprise networks. A physical design consists of cabling, Layer 1 and Layer 2 protocol implementations, and network devices. The physical design depends on business objectives, technical requirements, traffic characteristics, and traffic flows, which Part I of this book discussed. The physical design builds on the logical design, which Part II...
Documenting Traffic Flow on the Existing Network
Documenting traffic flow involves identifying and characterizing individual traffic flows between traffic sources and stores. Traffic flows have recently become a hot topic for discussion in the Internet community. A lot of progress is being made on defining flows, measuring flow behavior, and allowing an end station to specify performance requirements for flows. To understand traffic flow behavior better, you can read Request For Comments (RFC) 2722, Traffic Flow Measurement Architecture. RFC...
Characterizing Quality of Service Requirements
Analyzing network traffic requirements isn't quite as simple as identifying flows, measuring the load for flows, and characterizing traffic behavior such as broadcast and error-recovery behavior. You need to also characterize the QoS requirements for applications. Just knowing the load (bandwidth) requirement for an application is not sufficient. You also need to know if the requirement is flexible or inflexible. Some applications continue to work (although slowly) when bandwidth is not...
Redistribution Between Routing Protocols
Redistribution allows routers to run more than one routing protocol and share routes among routing pro redistribution can be challenging because every routing protocol behaves differently and routing protoco information about routes, prefixes, metrics, link states, and so on. Redistribution can lead to routing loc can complicate planning and troubleshooting. Despite the challenges, redistribution may be desirable when connecting different layers of the hierarch new routing protocol, when...
Cisco Net Flow Accounting
As mentioned in Chapter 3, Cisco IOS NetFlow technology is an integral part of Cisco IOS Software that collects and measures data as it enters router or switch interfaces. The information gathered enables a network manager to characterize utilization of network and application resources. It can also be used to design quality of service (QoS) support. A network flow is defined as a unidirectional sequence of packets between a source and destination endpoint. A flow endpoint is identified both by...
Frame Relay Traffic Control
When you subscribe to a Frame Relay service with a provider, you establish an access rate and order the appropriate line service and interface for the router to support this access rate. The access rate is the maximum number of bits per second that a DTE, such as a router, can transmit into the Frame Relay network. In addition, many service providers let you specify other parameters related to bandwidth usage, including a committed information rate (CIR), a committed burst size (Bc), and an...
Disaster Recovery
Most large institutions have recognized the need for a plan to sustain business and technical operations after natural disasters, such as floods, fires, hurricanes, and earthquakes. Also, some large enterprises (especially service providers) must plan how to recover from satellite outages. Satellite outages can be caused by meteorite storms, collisions with space debris, solar flares, or system failures. Unfortunately, institutions have also found the need to specify a recovery plan for...
Virtual LANs
A campus network should be designed using small bandwidth and small broadcast domains. A bandwidt domain is a set of devices that share bandwidth and compete for access to the bandwidth. A traditional topology or hub-based Ethernet, for example, is a single bandwidth domain. A switch divides up bandw domains and is often used to connect each device so that the network consists of many, extremely sma bandwidth domains. With switches, as opposed to hubs, the bandwidth domain consists of the...
Adaptability
When designing a network, you should try to avoid incorporating any elements that would make it hard to implement new technologies in the future. A good network design can adapt to new technologies and changes. Changes can come in the form of new protocols, new business practices, new fiscal goals, new legislation, and a myriad of other possibilities. For example, some states have enacted environmental laws that require a reduction in the number of employees driving to work. To meet the legal...
Testing Your Network Design
Part IV, Testing, Optimizing, and Documenting Your Network Design, of Top-Down Network Design covers the final steps in network design testing, optimizing, and documenting your design. This chapter discusses testing your design, which is a critical step in a systems-analysis approach to network design. Testing will help you prove to yourself and your network design customer that your solution meets business and technical goals. This chapter covers using industry tests to predict the performance...
Tcpip Dhcp Packets
Table A-4 shows the packets that a TCP IP station running DHCP sends and receives when it boots. Although a DHCP client sends more packets than a traditional TCP IP station when initializing, DHCP is still recommended. The benefits of dynamic configuration outweigh the disadvantages of extra traffic and extra broadcast packets. Table A-4. Packets for TCP IP DHCP Client Initialization Once every few seconds until client hears from a DHCP server ARP to make sure its own address is unique...
Half Duplex and Full Duplex Ethernet
Ethernet was originally defined for a shared medium with stations using the carrier sense multiple access collision detection (CSMA CD) algorithm to regulate the sending of frames and the detection of collisions when two stations send at the same time. With shared Ethernet, a station listens before it sends data. If the medium is already in use, the station defers its transmission until the medium is free. Shared Ethernet is half duplex, meaning that a station is either transmitting or...
Challenges Associated with Cable Modem Systems
A challenge with implementing a remote-access solution based on cable modems is that the CATV infrastructure was designed for broadcasting TV signals in just one direction from the cable TV company to a person's home. Data transmission, however, is bidirectional. Data travels from the provider to the home (or small office) and from the home to the provider. Because of the design of CATV networks, most cable-network services offer much more bandwidth for downstream traffic (from the service...
Changes in Enterprise Networks
Enterprise networks at many corporations have been undergoing major changes. The value of making vast amounts of data available to employees, customers, and business partners has been recognized. Corporate employees, field employees, contract employees, and telecommuters need access to sales, marketing, engineering, and financial data, regardless of whether the data is stored on centralized or distributed servers or mainframes. Suppliers, vendors, and customers also need access to many types of...
Flat WAN Topologies
A wide-area network (WAN) for a small company can consist of a few sites connected in a loop. Each site has a WAN router that connects to two other adjacent sites via point-to-point links, as shown at the top of Figure 5-2. As long as the WAN is small (a few sites), routing protocols can converge quickly, and communication with any other site can recover when a link fails. (As long as only one link fails, communication recovers. When more than one link fails, some sites are isolated from...
Estimating Traffic Overhead for Various Protocols
The previous section talked about characterizing application traffic load by looking at the size of data objects that applications transfer across networks. To completely characterize application behavior, you should investigate which protocols an application uses. Once you know the protocols, you can calculate traffic load more precisely by adding the size of protocol headers to the size of data objects. Table 4-6 shows some typical protocol header sizes. Table 4-6. Traffic Overhead for...
Cable Modem Remote Access
Another option for remote access is a cable modem. A cable modem operates over the coax cable that is used by cable TV (CATV) providers. Coax cable supports higher speeds than telephone lines, so cable-modem solutions are much faster than analogmodem solutions, and usually faster than ISDN solutions (depending on how many users share the cable). Another benefit of cable modems is that no dialup is required. This is an advantage over analog modems that take a long time to dial and connect to a...
Doing a Wireless Site Survey
A site survey confirms signal propagation, strength, and accuracy in different locations. Many wireless network interface cards (NICs) ship with utilities that enable you to measure signal strength. Cisco 802.11 NICs ship with the Cisco Aironet Client Utility (ACU), which is a graphical tool for configuring, monitoring, and managing the NIC and its wireless environment. A site survey can be as simple as walking around with a wireless notebook computer and using the utility to measure signal...
Application Layer Throughput
Most end users are concerned about the throughput for applications. Marketing materials from some networking vendors refer to application layer throughput as goodput. Calling it goodput sheds light on the fact that it is a measurement of good and relevant application layer data transmitted per unit of time. It is possible to improve throughput such that more data per second is transmitted, but not increase goodput, because the extra data transmitted is overhead or retransmissions. It is also...
Switching Techniques
In addition to running routing protocols to develop a routing topology, the major job of a router is to switch packets from incoming interfaces to outgoing interfaces. Switching involves receiving a packet, determining how to forward the packet based on the routing topology and QoS and policy requirements, and switching the packet to the right outgoing interface or interfaces. The speed at which a router can perform this task is a major factor in determining network performance in a routed...
Writing Test Scripts
For each test, write a test script that lists the steps to be taken to fulfill the test objective. The script should identify which tool is used for each step, how the tool is used to make relevant measurements, and what information should be logged during testing. The script should define initial values for parameters and how to vary those parameters during testing. For example, the test script might include an initial traffic-load value and incremental increases for the load. The following is...
Using a Structured Network Design Process
Top-down network design is a discipline that grew out of the success of structured software programming and structured systems analysis. The main goal of structured systems analysis is to more accurately represent users' needs, which are unfortunately often ignored or misrepresented. Another goal is to make the project manageable by dividing it into modules that can be more easily maintained and changed. Structured systems analysis has the following characteristics The system is designed in a...
Designing a Network Topology
In this chapter, you will learn techniques for developing a network topology. A topology is a map of an internetwork that indicates network segments, interconnection points, and user communities. Although geographical sites can appear on the map, the purpose of the map is to show the geometry of the network, not the physical geography or technical implementation. The map is a high-level blueprint of the network, analogous to an architectural drawing that shows the location and size of rooms for...
Selecting Routers for an Enterprise WAN Design
An enterprise WAN connects high-performance routers. Chapter 10 covered typical criteria for the selection of internetworking devices in general. The criteria in Chapter 10 (such as the number of ports, processing speed, media and technologies supported, mean time to repair MTTR , mean time between failure MTBF , and so on) apply to enterprise as well as campus devices. In addition, enterprise routers should offer high throughput, high availability, and advanced features to optimize the...
Split Horizon Hold Down and Poison Reverse Features of Distance Vector Protocols
A router running a distance-vector protocol sends its routing table out each of its ports on a periodic ba split-horizon technique, the router sends only routes that are reachable via other ports. This reduces th importantly, improves the accuracy of routing information. With split horizon, a router does not tell ano better learned locally. Most distance-vector protocols also implement a hold-down timer so that new information about a rout< believed right away, in case the information is...
See [BRI beacon
Frame from a Token Ring or FDDI device indicating a serious problem with the ring, such as a broken cable. 2. Frame sent by a wireless access point during normal operation. Wireless clients listen to beacon frames to locate access points. backward explicit congestion notification. Bit set by a Frame Relay network in frames traveling in the opposite direction of frames encountering a congested path. Compare with FECN. bit error rate. Ratio of received bits that contain errors to the total number...
Open Shortest Path First
In the late 1980s, the IETF recognized the need to develop an interior link-state routing protocol to mei networks that were constrained by the limitations of RIP. The Open Shortest Path First (OSPF) routing work. OSPF is defined in RFC 2328. The advantages of OSPF are as follows OSPF is an open standard supported by many vendors. OSPF authenticates protocol exchanges to meet security goals. OSPF supports discontiguous subnets and VLSM. OSPF sends multicast frames, rather than broadcast frames,...
Systems Development Life Cycles
Systems analysis students are familiar with the concept that typical systems are developed and continue to exist over a period of time, often called a systems development life cycle. Many systems analysis books use the acronym SDLC to refer to the life cycle, which may sound strange to networking students who know SDLC as Synchronous Data Link Control, a bit-oriented, full-duplex protocol used on synchronous serial links, often found in a legacy Systems Network Architecture (SNA) environment....
The Plan Design Implement Operate Optimize Pdioo Network Life Cycle
Cisco Systems teaches the Plan Design Implement Operate Optimize (PDIOO) set of phases for the life cycle of a network. It doesn't matter exactly which life cycle you use, as long as you realize that network design should be accomplished in a structured, planned, modular fashion, and that feedback from the users of the operational network should be fed back into new network projects to enhance or redesign the network. Learning the Cisco steps is important if you are studying for a Cisco design...
Proactive Network Management
When helping your customer design network management strategies, you should encourage the practice of proactive network management. As more companies recognize the strategic importance of their internetworks, they are putting more emphasis on proactive management. Proactive management means checking the health of the network during normal operation to recognize potential problems, optimize performance, and plan upgrades. Companies that practice proactive management collect statistics and...
Classic Methods for Layer 3 Packet Switching
Process switching is the slowest of the switching methods. With process switching, when an interface processor receives an incoming packet, it transfers the packet to input output memory on the router. The interface processor also generates a receive interrupt of the central processor. The central processor determines the type of packet and places it in the appropriate input queue. For example, if it is an IP packet, the central processor places the packet in the ip_input queue. The next time...
Appendix B References and Recommended Reading
DNS and BIND, 4th ed. Sebastopol, California O'Reilly & Associates, Inc. 2001. Berkowitz, H. WAN Survival Guide. New York, New York John Wiley & Sons, Inc. 2001. Buchanan, R. The Art of Testing Network Systems. New York, New York John Wiley & Sons, Inc. 1996. Clark, K. and K. Hamilton. Cisco LAN Switching. Indianapolis, Indiana Cisco Press, Comer, D.E. Internetworking with TCP IP Principles, Protocols, and Architecture, Volume I, 4th ed. Englewood Cliffs, New...
The Service Provider Edge
Although the focus of this chapter is designing a logical topology for an enterprise network, a quick discussion of service providers is warranted at this point. The Enterprise Composite Network Model includes the service provider edge module, and, although you aren't expected to design this module as an enterprise network designer, you need to have some understanding of it and be able to select the appropriate provider (or providers) for your design customers. The selection of a service...
Discontiguous Subnets
As mentioned earlier, classful routing protocols automatically summarize subnets. One side-effect of this is that discontiguous subnets are not supported. Subnets must be next to each other that is, contiguous. Figure 6-3 shows an enterprise network with discontiguous subnets. Figure 6-3. A Network with Discontiguous Subnets With a classful routing protocol such as RIP version 1 or IGRP, Router A in Figure 6-3 advertises that it can get to network 10.0.0.0. Router B ignores this advertisement,...
The Core Layer
The core layer of a three-layer hierarchical topology is the high-speed backbone of the internetwork. Because the core layer is critical for interconnectivity, you should design the core layer with redundant components. The core layer should be highly reliable and should adapt to changes quickly. When configuring routers in the core layer, you should use routing features that optimize packet throughput. You should avoid using packet filters or other features that slow down the manipulation of...
Determining the Scope of a Prototype System
Based on a clear understanding of your customer's goals, you should determine how much of the network system you must implement to convince your customer that the design will meet requirements. Because it is generally not practical to implement a complete, full-scale system, you should isolate which aspects of a network design are most important to your customer. Your prototype should verify important capabilities and functions that might not perform adequately. Risky functions can include...
Simple Network Management Protocol
SNMP is supported by most commercial NMSs as well as many networking devices including switches, routers, servers, and workstations. SNMP has gained widespread popularity because of its simplicity and because it is easy to implement, install, and use. Also, when used sensibly, SNMP does not place undue burden on the network. Interoperability between SNMP implementations from different vendors can be achieved with minimal effort because SNMP is so simple. SNMPv3 should gradually supplant...
Flat LAN Topologies
In the early and mid-1990s, a typical design for a LAN was PCs and servers attached to one or more hubs in a flat topology. The PCs and servers implemented a media- access control process, such as token passing or carrier sense multiple access with collision detection (CSMA CD) to control access to the shared bandwidth. The devices were all part of the same bandwidth domain and had the ability to negatively affect delay and throughput for other devices. These days, network designers usually...
Selecting Switching and Routing Protocols
The goal of this chapter is to help you select the right switching and routing protocols for your network design customer. The selections you make will depend on your customer's business and technical goals. To help you select the right protocols for your customer, the chapter covers the following attributes of switching and routing protocols Network traffic characteristics Bandwidth, memory, and CPU usage The approximate number of peer routers or switches supported The capability to quickly...
Multicast Open Shortest Path First
MOSPF, which is defined in RFC 1584, is a multicast routing protocol for OSPF environments. MOSPF complements OSPF's capability to develop a link-state database that describes a network topology. MOSPF supplements the database with an additional type of link-state record for group memberships. A router running MOSPF computes a shortest-path tree to all destinations within its area, and then uses advertised group-membership information to prune the branches of the tree that do not lead to any...
IETF Differentiated Services Working Group Quality of Service Specifications
The IETF also has a Differentiated Services working group that works on QoS-related specifications. RFC 2475, An Architecture for Differentiated Services, defines an architecture for implementing scalable service differentiation in an internetwork or the Internet. As Chapter 13, Optimizing Your Network Design, covers in more detail, IP packets can be marked with a differentiated services codepoint (DSCP) to influence queuing and packet-dropping decisions for IP datagrams on an output interface...
Developing a Modular Block Diagram
In addition to developing a set of detailed maps, it is often helpful to draw a simplified block diagram of the network, or parts of the network. The diagram can depict the major functions of the network, in a modular fashion. Figure 3-2 shows a block, modularized network topology map that is based on the Cisco Enterprise Composite Network Model. The model is part of Cisco's Secure Architecture for Enterprises (SAFE). Figure 3-2. Modularized Network Topology Example Figure 3-2. Modularized...
Positioning an Access Point for Maximum Coverage
Most access points use an isotropic antenna, which means that the signal strength is theoretically the s. when measured along axes in all directions. If you suspend an access point in space, the coverage shoi resemble that of a three-dimensional sphere with the access point at its center. In reality, the limitation antenna design usually result in less-uniform coverage, however. The most common type of access poii antenna is omnidirectional, which isn't really omni or iso. Instead of a sphere,...
Using Dynamic Addressing for End Systems
Dynamic addressing reduces the configuration tasks required to connect end systems to an internetwork. Dynamic addressing also supports users who change offices frequently, travel, or work at home occasionally. With dynamic addressing, a station can automatically learn which network segment it is currently attached to, and adjust its network layer address accordingly. Dynamic addressing is built in to desktop protocols such as AppleTalk and Novell NetWare. The designers of these protocols...
Terminal equipment type 2 TE2 NonISDN terminals that predate the
There are also two types of NT devices NT1 devices. Implement ISDN physical layer functions and connect user devices to the ISDN facility. NT2 devices. Perform concentration services and implement Layer 2 and Layer 3 protocol functions. Equipment that provides NT2 functionality includes controllers and Private Branch Exchanges (PBXs). In the United States and Canada, ISDN enters the small office or home on a two-wire circuit at the U reference point, as shown in Figure 11-4. An NT1 interface...
Zero Configuration Networking
The Zero Configuration Networking (Zeroconf) working group of the Internet Engineering Task Force (IETF) has carried the concept of dynamic addressing one step further than DHCP. Like AppleTalk and IPv6, Zeroconf can allocate IP addresses without a server. It can also translate between names and IP addresses without a DNS server. To handle naming, Zeroconf supports multicast DNS (mDNS), which uses multicast addressing for name resolution. So far, the Zeroconf work has been limited to small...
Network Monitoring and Management Tools
There are many network-monitoring and management tools that can help you characterize the existing network. This section lists just a few The Multi Router Traffic Grapher (MRTG) is a tool for monitoring network traffic load and other performance characteristics on routed and switched internetworks. MRTG generates HTML pages containing images that provide a live (real-time) graphical representation of network traffic. MRTG is based on the Perl scripting language and C programming language and...
Performance Characteristics of the Current Network
From the analysis conducted by the student assistants and from switch, router, and server logs, the IT department determined that bandwidth on the Ethernet campus network is lightly used. However, three major problems are likely the cause of the difficulties that users are experiencing The IP addressing scheme supports just one IP subnet with a subnet mask of 255.255.255.0. In other words, only 254 addresses are allowed. A few years ago, the IT department assumed that only a small subset of...
Backup Paths
To maintain interconnectivity even when one or more links are down, redundant network designs include a backup path for packets to travel when there are problems on the primary path. A backup path consists of routers and switches and individual backup links between routers and switches, which duplicate devices and links on the primary path. When estimating network performance for a redundant network design, you should take into consideration two aspects of the backup path How much capacity does...
Developing Network Security Strategies
Developing security strategies that can protect all parts of a complicated network while having a limited effect on ease of use and performance is one of the most important and difficult tasks related to network design. Security design is challenged by the complexity and porous nature of modern networks that include public servers for electronic commerce, extranet connections for business partners, and remoteaccess services for users reaching the network from home, customer sites, hotel rooms,...
Network Health Checklist
You can use the following Network Health checklist to assist you in verifying the health of an existing internetwork. The Network Health checklist is generic in nature and documents a best-case scenario. The thresholds might not apply to all networks. I. The network topology and physical infrastructure are well documented. I- Network addresses and names are assigned in a structured manner and are well documented. I. Network wiring is installed in a structured manner and is well labeled. I-...
Load on the DS1 Circuits
As shown in Figure 12-5, traffic through the DS-1 lines was generally light, except for the nightly file synchronization that started around midnight and lasted about 4 hours. Figure 12-5. Load in Bytes per Minute in Building 1 Near the Router that Connects to Building 4 Figure 12-5. Load in Bytes per Minute in Building 1 Near the Router that Connects to Building 4 During normal work hours, the two DS-1 links appear to be used at under 10 percent of capacity 90 percent of the time. Figure 12-5...
Fundamental VLAN Designs
To understand VLANs, it helps to think about real (nonvirtual) LANs first. Imagine two switches that are connected to each other in any way. Switch A connects stations in Network A and Switch B connects stations in Network B, as shown in Figure 5-8. Figure 5-8. Two Switches with Stations Attached Figure 5-8. Two Switches with Stations Attached When Station A1 in Figure 5-8 sends a broadcast, Station A2 and Station A3 receive the broadcast, but none of the stations in Network B receive the...
Strategies for Moving from IPv4 to IPv6
Three primary mechanisms that help with the transition from IPv4 to IPv6 are as follows Dual stack. Both IPv4 and IPv6 stacks run on the system. The system is able to communicate with both IPv6 and IPv4 devices. The choice of IP version is based on name lookup and application preference. This is the most appropriate for campus and access layer networks during the transition period and is the preferred technique for transition to IPv6. Operating systems that support a dual stack include FreeBSD,...
Link State Routing Protocols
Link-state routing protocols do not exchange routing tables. Instead, routers running a link-state routin about the links to which a router is connected. Each router learns enough information about links in the build its own routing table. The following protocols are link-state routing protocols IP Open Shortest Path First (OSPF) IP Intermediate System-to-Intermediate System (IS-IS) NetWare Link Services Protocol (NLSP) A link-state routing protocol uses a shortest-path first algorithm, such as...
Writing a Test Plan for the Prototype System
After you have decided on the scope of your prototype, write a plan that describes how you will test the prototype. The test plan should include each of the following topics, which the next few sections of this chapter describe in more detail Test objectives and acceptance criteria The types of tests that will be run Network equipment and other resources required The timeline and milestones for the testing project Developing Test Objectives and Acceptance Criteria The first and most important...
Measuring Bandwidth Utilization by Protocol
Network Utilization in Hour Intervals Developing a baseline of network performance should also include measuring utilization from broadcast traffic versus unicast traffic, and by each major protocol. As discussed in Chapter 4, some protocols send excessive broadcast traffic, which can seriously degrade performance, especially on switched networks. To measure bandwidth utilization by protocol, place a protocol analyzer or remote monitoring (RMON) probe on each major network segment...
First In First Out Queuing
FIFO queuing provides basic store-and-forward functionality. It involves storing packets when the network is congested and forwarding them in the order they arrived when the network is no longer congested. FIFO has the advantage that it is the default queuing algorithm in some instances, so requires no configuration. FIFO has the disadvantage that it makes no decision about packet priority. The order of arrival determines the order a packet is processed and output. With FIFO queuing, if there...
Analyzing Network Utilization
Network utilization is a measurement of how much bandwidth is in use during a specific time interval. Utilization is commonly specified as a percentage of capacity. If a network-monitoring tool says that network utilization on a Fast Ethernet segment is 70 percent, for example, this means that 70 percent of the 100-Mbps capacity is in use, averaged over a specified timeframe or window. Different tools use different averaging windows for computing network utilization. Some tools let the user...
Password Authentication Protocol and Challenge Handshake Authentication Protocol
PPP supports two types of authentication Password Authentication Protocol (PAP) Challenge Handshake Authentication Protocol (CHAP) CHAP is more secure than PAP and is recommended. (In fact, the RFC that discusses CHAP and PAP, RFC 1334, has been obsoleted by RFC 1994, which no longer mentions PAP.) With PAP, a user's password is sent as clear text. An intruder can use a protocol analyzer to capture the password and later use the password to break into the network. CHAP provides protection...
Multilink PPP and Multichassis Multilink PPP
Multilink PPP (MPPP) adds support for channel aggregation to PPP. As mentioned in Chapter 5, Designing a Network Topology, channel aggregation can be used for load sharing and providing extra bandwidth. With channel aggregation, a device can automatically bring up additional channels as bandwidth requirements increase. Channel aggregation usually is used in an ISDN environment, but it can be used on other types of serial interfaces also. (A PC connected to two analog modems can use channel...
Business Goals Checklist
You can use the following checklist to determine if you have addressed your client's business-oriented objectives and concerns. If you can't gather every piece of data mentioned in the checklist, make sure you document what is missing in case it becomes critical, but don't stall the project to gather every last detail. This book teaches an ideal network design methodology that you should try to follow, but if real-world constraints, such as uncooperative network design customers, budget cuts,...
Physical Security
Physical security refers to limiting access to key network resources by keeping the resources behind a locked door. Physical security can protect a network from inadvertent misuses of network equipment by untrained employees and contractors. It can also protect the network from hackers, competitors, and terrorists walking in off the street and changing equipment configurations. Depending on the level of protection, physical security may protect a network from terrorist and biohazard events,...
Estimating Traffic Load Caused by Routing Protocols
At this point in the network design process, you might not have selected routing protocols for the new network design, but you should have identified routing protocols running on the existing network. To help you characterize network traffic caused by routing protocols, Table 4-7 shows the amount of bandwidth used by legacy distance-vector routing protocols. Table 4-7. Bandwidth Used by Legacy Routing Protocols Table 4-7. Bandwidth Used by Legacy Routing Protocols Estimating traffic load caused...
Checking the Health of the Existing Internetwork
Studying the performance of the existing internetwork gives you a baseline measurement from which to measure new network performance. Armed with measurements of the present internetwork, you can demonstrate to your customer how much better the new internetwork performs once your design is implemented. Many of the network-performance goals discussed in Chapter 2, Analyzing Technical Goals and Tradeoffs, are overall goals for an internetwork. Because the performance of existing network segments...
Identifying Major Traffic Sources and Stores
To understand network traffic flow, you should first identify user communities and data stores for existing and new applications. Chapter 3, Characterizing the Existing Internetwork, talked about locating major hosts, interconnect devices, and network segments on a customer's network. The tasks discussed in Chapter 3 facilitate the tasks discussed in this chapter of identifying major user communities and data stores. A user community is a set of workers who use a particular application or set...
Business and Technical Goals
Klamath's main business goals for the WAN design project are as follows Increase profits by implementing a WAN that will support the goals of the Conservation Initiative Task Force, in particular the new distance-learning Improve the performance of the existing WAN to support more efficient operations. Contain the rising costs associated with operating the existing WAN. Provide a network that will let employees more easily share ideas for further improving efficiency and increasing the use of...
Distributed Computing Traffic Flow
Distributed computing refers to applications that require multiple computing nodes working together to complete a job. Some complex modeling and rendering tasks cannot be accomplished in a reasonable timeframe unless multiple computers process data and run algorithms simultaneously. The visual effects for movies are often developed in a distributed-computing environment. Distributed computing is also used in the semiconductor industry to serve the extreme computing needs of microchip design and...























