Network Design

Metrics Used by Routing Protocols

Different routing protocols calculate their routing metrics from different parameters and with different formulas. Some use simple metrics (such as RIPv1 and RIPv2), and some use complex metrics (such as EIGRP). RIPv1 and RIPv2 use only the hop count to determine the best path (the path with the smallest hop count is preferred). Because they do not consider bandwidth, RIPv1 and RIPv2 are not suitable for networks that have significantly different transmission speeds on redundant paths. For...

Identifying Customer Requirements

As the organization's network grows, so does the organization's dependency on the network and the applications that use it. Network-accessible organizational data and mission-critical applications that are essential to the organization's operations depend on network availability. To design a network that meets customers' needs, the organizational goals, organizational constraints, technical goals, and technical constraints must be identified.

Route Summarization

Cisco Passive Interface Vlan

Chapter 6 explains route summarization (which is also called route aggregation or supernetting). In route summarization, a single summary address in the routing table represents a set of routes. Summarization reduces the routing update traffic, the number of routes in the routing table, and the overall router overhead in the router receiving the routes. A large flat network is not scalable because routing traffic consumes considerable network resources. When a network change occurs, it is...

Distribution Layer Functionality

Design Sample Distribution Network

This section describes distribution layer functions and the interaction of the distribution layer with the core and access layers. The distribution layer represents both a separation between the access and core layers and a connection point between the diverse access sites and the core layer. The distribution layer determines department or workgroup access and provides policy-based connectivity. Following are the characteristics of the distribution layer Distribution layer devices control...

Name Resolution

Names are used to identify different hosts and resources on the network and to provide user-friendly interaction with computers a name is much easier to remember than an IP address. This section covers the purpose of name resolution, provides information about different available name resolution strategies, and discusses Domain Name System (DNS) name resolution. Hosts (computers, servers, printers, and so forth) identify themselves to each other using various naming schemes. Each computer on...

Physical Addresses

MAC addresses were discussed earlier recall that these are at the data link layer and are considered physical addresses. When a network interface card is manufactured, it is assigned an address called a burned-in address (BIA) that doesn't change when the network card is installed in a device and is moved from one network to another. Typically, this BIA is copied to interface memory and is used as the interface's MAC address. MAC addresses are analogous to Social Insurance numbers or Social...

Network Application Characteristics and Considerations

Infrastructure Clan Vlan Segment

The network application's characteristics and requirements influence the design in many ways. The applications that are critical to the organization, and the network demands of these applications, determine enterprise traffic patterns inside the Enterprise Campus network, which influences bandwidth usage, response times, and the selection of the transmission medium. Different types of application communication result in varying network demands. The following sections review four types of...

Lightweight APs

The available Cisco lightweight APs and their features are detailed in Table 9-6. Table 9-6 Cisco Lightweight AP Features Table 9-6 Cisco Lightweight AP Features (Continued) 1 Remote edge AP (REAP) and hybrid REAP (H-REAP) are described in the Design Considerations for Branch Office Wireless Networks section later in this chapter. AP models with the most memory support the most feature flexibility. NOTE The AP features supported might change as products are updated, products are replaced, and...

Tools for Analyzing Traffic

Tools used for traffic analysis range from manual identification of applications using Cisco IOS software commands to those in which dedicated software- or hardware-based analyzers capture live packets or use the Simple Network Management Protocol (SNMP) to gather interface information. Analysis tools include the following Cisco IOS Network-Based Application Recognition (NBAR) NBAR can be used to identify the presence of well-known applications and protocols in the network. Cisco IOS NetFlow...

QoS for Voice

Voice Network

IP telephony places strict requirements on IP packet loss, packet delay, and delay variation (jitter). Therefore, QoS mechanisms on Cisco switches and routers are important throughout the network if voice traffic is sharing network resources with data traffic. Redundant devices and network links that provide quick convergence after network failures or topology changes are also important to ensure a highly available infrastructure. The following summarizes the process to determine whether to...

Building Distribution Layer Design Considerations

Layers Cases Distribution Center

The Building Distribution layer aggregates the Building Access layer, segments workgroups, and isolates segments from failures and broadcast storms. This layer implements many policies based on access lists and QoS settings. The Building Distribution layer can protect the Campus Core network from any impact of Building Access layer problems by implementing all the organization's policies. When implementing the Building Distribution layer, consider the following questions How many devices will...

Server Placement

Web Server Placement Network

Within a campus network, servers may be placed locally in the Building Access or Building Distribution layer, or attached directly to the Campus Core. Centralized servers are typically grouped into a server farm located in the Enterprise Campus or in a separate data center. Servers Directly Attached to Building Access or Building Distribution Layer Switches If a server is local to a certain workgroup that corresponds to one VLAN, and all workgroup members and the server are attached to a...

Case Study Answers Cxf

Cisco Core Distribution Access Wan

The following figure illustrates the recommended Campus design this figure includes the Campus Core, Building Distribution, and Building Access layers, and the Server Farm. 12 Smaller Buildings 1 or 2 Wiring Closets per Building 12 Smaller Buildings 1 or 2 Wiring Closets per Building For the Campus Core, two switches are used for high availability. Putting the Campus Core switches in Main Building 1 with the servers is ideal because a lot of network traffic generally flows to the Server Farm....

Interactive Services

Since the inception of packet-based communications, networks have always offered a forwarding service. Forwarding is the fundamental activity within an internetwork. In IP, this forwarding service was built on the assumption that end nodes in the network were intelligent, and that the network core did not have intelligence. With advances in networking software and hardware, the network can offer an increasingly rich, intelligent set of mechanisms for forwarding information. Interactive services...

Case Study 101 Answers

Acmc Network Core

As mentioned in Chapter 2, a key business security requirement is that the hospital must comply with the U.S. Health Insurance Portability and Accountability Act (HIPAA). HIPAA is about patient confidentiality and the costs of failing to provide adequate security and confidentiality. Threats to network security include the following Reconnaissance, usually the prelude to a more focused attack Gaining unauthorized system access DoS, including from worms, viruses, and patch management issues...

Acronyms and Abbreviations

This element lists abbreviations, acronyms, and initialisms used in this book and in the internetworking industry. Many of these acronyms and other terms are also described in the Cisco Internetworking Terms and Acronyms resource, available at http www.cisco.com univercd cc td doc cisintwk ita . Authentication, authorization, and accounting Algebraic code-excited linear prediction Application and Content Networking System Adaptive Differential Pulse Code Modulation American National Standards...

Threat Reconnaissance Attacks

Reconnaissance attacks aim to discover information about a network, including the following Network services that are running A common technique to find active targets such as networking devices and user endpoints is port scanning, in which data is sent to various TCP and User Datagram Protocol (UDP) ports on a device and the response from the device is evaluated. To avoid reconnaissance attacks, a network should be tested to see how much it would reveal if attacked. The following are some...

Building a Prototype or Pilot Network

Network Design Bulding

It is often desirable to verify a design before implementation. A design can be tested in an existing, or live, network this is called a pilot or, preferably, in a prototype network that does not affect the existing network. A successful design implementation in either a pilot or prototype network can be used as a proof of concept in preparation for full implementation and can be used as input to the implementation steps. A pilot network tests and verifies the design before the network is...

Core Layer Functionality

Core Layer

This section describes core layer functions and the interaction of the core layer with the distribution layer. The function of the core layer is to provide fast and efficient data transport. Characteristics of the The core layer is a high-speed backbone that should be designed to switch packets as quickly as possible to optimize communication transport within the network. Because the core is critical for connectivity, core layer devices are expected to provide a high level of availability and...

Enterprise Campus Modules

Enterprise Campus Network Design

This section introduces the Enterprise Campus functional area and describes the purpose of each module therein. It also discusses connections with other modules. An enterprise campus site is a large site that is often the corporate headquarters or a major office. Regional offices, SOHOs, and mobile workers might have to connect to the central campus for data and information. As illustrated in Figure 3-11, the Enterprise Campus functional area includes the Campus Infrastructure module and,...

Environmental Characteristics and Considerations

The campus environment, including the location of the network nodes, the distance between the nodes, and the transmission media used, influences the network topology. This section examines these considerations. The location of Enterprise Campus nodes and the distances between them determine the network's geography. Nodes, including end-user workstations and servers, can be located in one or multiple buildings. Based on the location of nodes and the distance between them, the network designer...

Telephony Signaling

In a telephony system, a signaling mechanism is required for establishing and disconnecting The following forms of signaling are used when a telephone call is placed via a PBX Between the telephone and PBX Between the PBX and PSTN switch At a high level, there are two signaling realms, as shown in Figure 8-7 Local-loop signaling Between a PSTN or PBX switch and a subscriber (telephone) Trunk signaling Between PSTN switches, between a PSTN switch and a PBX, or between PBX switches Figure 8-7...

Answers to Review Questions Dbw

Both private and public IPv4 addresses might be required in a network that requires Internet connectivity but that does not require all its end systems to be publicly accessible. The mask is 255.255.255.240. The address is a Class B address. The host part is binary 0101 (decimal 5). The network part is 172.17.7.binary 1111xxxx (decimal 172.17.7.240). 24 - 2 14 hosts can reside on this subnet. 4. Information that must be collected to determine the size of the network includes the number and type...

Designing Link Redundancy

It is often necessary to provision redundant media in locations where mission-critical application traffic travels. In Layer 2-switched networks, redundant links are permitted as long as STP is running. STP guarantees one, and only one, active path within a broadcast domain, avoiding problems such as broadcast storms (when a broadcast continuously loops). The redundant path automatically activates when the active path goes down. Because WAN links are often critical pieces of the internetwork,...

Case Study Questions Psd

Step 1 Develop a list of relevant information that should be provided in the ACMC WAN Request for Proposal (RFP). Step 2 ACMC put out an RFP specifying that it requires at least T1 bandwidth at the remote clinics. The responses to the RFP, indicating the technologies currently available to ACMC, are shown in Table 5-8. Calculate the monthly cost of using each of the technologies shown in Table 5-8 by completing the Monthly Cost column in this table. Table 5-8 ACMC RFP Results Leased line T1 at...

Case Study ACMC Hospital IP Addressing Design

Cisco Hospital Network Design

This case study is a continuation of the ACMC Hospital case study introduced in Chapter 2, Applying a Methodology to Network Design. Use the scenarios, information, and parameters provided at each task of the ongoing case study. If you encounter ambiguities, make reasonable assumptions and proceed. For all tasks, use the initial customer scenario and build on the solutions provided thus far. You can use any and all documentation, books, white papers, and so on. In each step, you act as a...

Guidelines for Creating an Enterprise Network

Enterprise Network Design

When creating an Enterprise network, divide the network into appropriate areas, where the Enterprise Campus includes all devices and connections within the main Campus location the Enterprise Edge covers all communications with remote locations and the Internet from the perspective of the Enterprise Campus and the remote modules include the remote branches, teleworkers, and the remote data center. Define clear boundaries between each of the areas. NOTE Depending on the network, an enterprise...

Answers to Review Questions

Access layer Devices A, B, E, and F Distribution layer Devices A, B, D, and F Core layer Device C 2. The role of each layer in the hierarchical network model is as follows The access layer provides local and remote workgroup or user access to the network. The distribution layer provides policy-based connectivity. The core (or backbone) layer provides high-speed transport. 3. False. The layers do not need to be implemented as distinct physical entities. The layers are defined to aid successful...

Infrastructure Device Characteristics and Considerations

Network end-user devices are commonly connected using switched technology rather than using a shared media segment. Switched technology provides dedicated network bandwidth for each device on the network. Switched networks can support network infrastructure services, such as QoS, security, and management a shared media segment cannot support these features. In the past, LAN switches were Layer 2-only devices. Data link layer (Layer 2) switching supports multiple simultaneous frame flows....

Building Access Layer Design Considerations

Distribution Layer Router

When implementing the campus infrastructure's Building Access layer, consider the following questions How many users or host ports are currently required in the wiring closet, and how many will it require in the future Should the switches be fixed or modular configuration How many ports are available for end-user connectivity at the walls of the buildings How many access switches are not located in wiring closets What cabling is currently available in the wiring closet, and what cabling options...

Access Layer Functionality

This section describes the access layer functions and the interaction of the access layer with the distribution layer and local or remote users. The access layer is the concentration point at which clients access the network. Access layer devices control traffic by localizing service requests to the access media. The purpose of the access layer is to grant user access to network resources. Following are the access layer's characteristics In the campus environment, the access layer typically...

Optimizing Bandwidth in a WAN

It is expensive to transmit data over a WAN. Therefore, one of many different techniques such as data compression, bandwidth combination, tuning window size, congestion management (queuing and scheduling), congestion avoidance, and traffic shaping and policing can be used to optimize bandwidth usage and improve overall performance. The following sections describe these techniques. Compression is the reduction of data size to save transmission time. Compression enables more efficient use of the...

LWAPP Fundamentals

Lwapp Header

LWAPP is an IETF draft protocol that defines the control messaging for setup and path authentication and runtime operations between APs and WLCs. LWAPP also defines the tunneling mechanism for data traffic. The LWAPP tunnel uses Layer 2 or Layer 3 transport. LWAPP defines how the lightweight APs communicate with the WLC. LWAPP data messages encapsulate and forward data frames from and to wireless clients. LWAPP control messages are management messages exchanged between a WLC and the APs. LWAPP...

WLAN Controllers

Wlan Controller Network Diagram Logo

Despite being called a wireless LAN controller, a WLC is connected to the wired LAN and to the lightweight APs by wires. The WLC does not have any wireless connections. The following are three important WLC terms Ports A WLC port is a physical connection on the WLC that connects to its neighboring switch in the wired campus infrastructure. Each WLC port is by default an 802.1Q VLAN trunk port the WLC forwards information received from the WLANs, via the APs, over a trunk port to the campus...

Mobility in a Cisco Unified Wireless Network

This section covers how mobility is supported in a Cisco UWN deployment. One significant benefit of wireless networks and a key reason they are deployed is mobility. This is the capability of end devices to move to new locations and remain networked without reassociation and DHCP delays. Roaming occurs when a wireless client moves its association from one AP and reassociates to another AP, within the same SSID. In a low-quality roaming experience, mobility involves a new association with a new...

Case Study Answers Epq

Clinic Network Design

NOTE Because WLC redundancy requirements were not addressed in the case study, the customer should be asked whether redundancy is required. There are many possibilities for selection and placement of the WLCs. One option is to use 4404 WLCs with LAG, supporting up to 100 APs on each WLC. This solution allows a distributed approach, with one controller in each Main Building and in the Children's Place. These three controllers would provide enough capacity such that any two could support all 165...

WAN Transport Technologies

Dual Sonet Rings Atm Switching

Table 5-1 compares various WAN technologies, based on the main factors that influence technology selection. This table provides typical baseline characteristics to help you compare the performance and features offered by different technologies. Often, the offerings of the service provider limit your technology decisions. NOTE Some WAN technology characteristics differ between service providers Table 5-1 is meant to illustrate typical characteristics. Table 5-1 WAN Transport Technology...

The Internet as a WAN Backup Technology

List Wan Backup Technology

This section describes the Internet as an alternative option for a failed WAN connection. This type of connection is considered best-effort and does not guarantee any bandwidth. Common methods for connecting noncontiguous private networks over a public IP network include the following IP routing without constraints The following sections describe these methods. When relying on the Internet to provide a backup for branch offices, a company must fully cooperate with the ISP and announce its...

Global Aggregatable Unicast Addresses

IPv6 global aggregatable unicast addresses are equivalent to IPv4 unicast addresses. The structure of global aggregatable unicast addresses enables summarization (aggregation) of routing prefixes so that the number of routing table entries in the global routing table can be reduced. Global unicast addresses used on links are aggregated upward, through organizations, and then to intermediate-level ISPs, and eventually to top-level ISPs. A global unicast address typically consists of a 48-bit...

OSPF Hierarchical Design

Ospf Design Sample Networks

Although OSPF was developed for large networks, its implementation requires proper design and planning this is especially important for networks with 50 or more routers. The concept of multiple separate areas inside one domain (or AS) was implemented in OSPF to reduce the amount of routing traffic and make networks more scalable. In OSPF, there must always be one backbone area area 0 to which all other nonbackbone areas must be directly attached. A router is a member of an OSPF area when at...

OSPF Characteristics

OSPF is a link-state protocol that has the following characteristics for deployment in enterprise networks Fast convergence OSPF achieves fast convergence times using triggered link-state updates that include one or more link-state advertisements (LSA). LSAs describe the state of links on specific routers and are propagated unchanged within an area. Therefore, all routers in the same area have identical topology tables each router has a complete view of all links and devices in the area....

Configuring NAT for Basic Local IP Address Translation

The following procedure enables basic local IP address translation Step 1 At a minimum, IP routing and appropriate IP addresses must be configured on the router. Step 2 To perform static address translations for inside local addresses, define the addresses using the following command Routen(config) ip nat inside source static local-ip global-ip Step 3 To perform dynamic translations, do the following a. Configure a standard IP access list to identify the inside network addresses that will be...

Configuring Inside Global Address Overloading or PAT

The following procedure configures inside global address overloading Step 1 At a minimum, IP routing and appropriate IP addresses must be configured on the router. Step 2 Configure dynamic address translation, as described in the Configuring NAT for Basic Local IP Address Translation section earlier in this appendix. When you define the mapping between the access list and the IP NAT pool, add the overload keyword to the command Router(config) ip nat inside source list access-list-number pool...

Call Control and Transport Protocols

Microwave Transmission Node

Voice communication over IP is a mix of call control signals and voice conversations coded and possibly compressed into IP packets. Both reliable (connection-oriented) and so-called unreliable (connectionless) transmissions are required for voice communication. Reliable transmission guarantees sequenced, error-free, flow-controlled transmission of packets. However, because reliable transport is connection-oriented, it can delay transmission and reduce throughput. TCP provides reliable transport...

Bandwidth Considerations

Bandwidth availability is a key issue to consider when designing voice on IP networks. The amount of bandwidth per call varies greatly, depending on which codec is used and how many voice samples are required per packet. However, the best coding mechanism does not necessarily result in the best voice quality for example, the better the compression, the worse the voice quality. The designer must decide which is more important better voice quality or more efficient bandwidth consumption. Reducing...

Designing Route Redundancy

To minimize the effect of link failures To minimize the effect of an internetworking device failure Redundant routes might also be used for load balancing when all routes are up. By default, the Cisco IOS balances between a maximum of four equal-cost paths for IP. Using the maximum-paths maximum-path router configuration command, you can request that up to 16 equally good routes be kept in the routing table (set maximum-path to 1 to disable load balancing). When a packet is process-switched,...

Campus Core Design Considerations

Building Core Design

Low price per port and high port density can govern switch choice for wiring closet environments, but high-performance wire-rate multilayer switching drives the Campus Core design. Using Campus Core switches reduces the number of connections between the Building Distribution layer switches and simplifies the integration of the Server Farm module and Enterprise Edge modules. Campus Core switches are primarily focused on wire-speed forwarding on all interfaces and are differentiated by the level...

Case Study Questions Kkl

Prototype Network Design For Hospitals

Step 1 Hospital Omega is a nearby hospital that has been having financial difficulties. It is facing large licensing and application development costs to bring its financial and other applications up to date. To cut costs and stabilize finances, Hospital Omega will merge with ACMC. All data services will move to the ACMC data center and gradually migrate to the modern applications that ACMC already has in place. The Hospital Omega network was deployed between seven and ten years ago, and in...

PBXs and the PSTN

Pstn Network

This section introduces PBX and PSTN switches and networks. Differences Between a PBX and a PSTN Switch As shown in Table 8-1, PBXs and PSTN switches share many similarities, but they also have many differences. Table 8-1 PBX and PSTN Switch Comparison Table 8-1 PBX and PSTN Switch Comparison Scales to hundreds of thousands of phones Uses proprietary protocols to control telephones Uses open-standard protocols between switches and telephones Interconnects remote branch subsystems and telephones...

Converting IP Addresses Between Decimal and Binary

An IP address is a 32-bit, two-level hierarchical number. It is hierarchical because the first portion of the address represents the network, and the second portion of the address represents the node (or host). The 32 bits are grouped into four octets, with 8 bits per octet. The value of each octet ranges from 0 to 255 decimal, or 00000000 to 11111111 binary. IP addresses are usually written in dotted-decimal notation, which means that each octet is written in decimal notation and dots are...

Enterprise Data Center Infrastructure

Cisco Multilayer Infrastructure

Figure 4-22 shows a typical large Enterprise Data Center infrastructure design. The design follows the Cisco multilayer infrastructure architecture, including core, aggregation, and access layers. NOTE In the Enterprise Data Center, the distribution layer is known as the aggregation layer. Figure 4-22 Sample Data Center Infrastructure Figure 4-22 Sample Data Center Infrastructure Layer 2 Clustering Blade Chassis Blade Chassis Mainframe Layer 3 and NIC Teaming with Pass-Through with Integrated...

Centralized WLAN Components

Architecture Wifi Centralise

As illustrated in Figure 3-23, the four main components in a centralized WLAN deployment are as follows End-user devices A PC or other end-user device in the access layer uses a wireless NIC to connect to an access point (AP) using radio waves. Wireless APs APs, typically in the access layer, are shared devices that function similar to a hub. Cisco APs can be either lightweight or autonomous. Lightweight APs are used in centralized WLAN deployments. A lightweight AP receives control and...

Enterprise Edge Modules

Internet Vpn Ecommerce

This section describes the components of the Enterprise Edge and explains the importance of each module. The Enterprise Edge infrastructure modules aggregate the connectivity from the various elements outside the campus using various services and WAN technologies as needed, typically provisioned from service providers and route the traffic into the Campus Core layer. The Enterprise Edge modules perform security functions when enterprise resources connect across public networks and the Internet....

Syslog Accounting

A system message and error reporting service is an essential component of any operating system. The syslog system message service provides a means for the system and its running processes to report system state information to a network manager. Cisco devices produce syslog messages as a result of network events. Every syslog message contains a time stamp (if enabled), severity level, and facility. Example 3-1 shows samples of syslog messages produced by the Cisco IOS software. The most common...

The Cisco UWN Architecture

Wpa Wpa2 Wpa3 Architecture

In a traditional WLAN, each AP operates as a separate autonomous node configured with SSID, RF channel, RF power settings, and so forth. Scaling to large contiguous, coordinated WLANs and adding higher-level applications is challenging with these autonomous APs. For example, if an autonomous AP hears a nearby AP operating on the same channel, the autonomous AP has no way of determining whether the adjacent AP is part of the same network or a neighboring network. Some form of centralized...

Determining the Size of the Network

Tables Ethernet Topology

The first step in designing an IP addressing plan is determining the size of the network to establish how many IP subnets and how many IP addresses are needed on each subnet. To gather this information, answer the following questions How many locations does the network consist of The designer must determine the number and type of locations. How many devices in each location need addresses The network designer must determine the number of devices that need to be addressed, including end systems,...

Voice Quality Issues

Overall voice quality is a function of many factors, including delay, jitter, packet loss, and echo. This section discusses these factors and ways to minimize them. Packet delay can cause voice quality degradation. When designing networks that transport voice, you must understand and account for the network's delay components. Correctly accounting for all potential delays ensures that overall network performance is acceptable. The generally accepted limit for good quality voice connection delay...

Radio Resource Management and RF Groups

This section provides a brief overview of Cisco RRM and RF groups. Real-time RF management is a foundation of the Cisco UWN solution. Key RF challenges in managing a wireless environment include the following Limited nonoverlapping channels The physical characteristics of RF propagation The transient nature of RF environments AP capacity is affected by the applications being run over the wireless network. For example, a recommended practice is to support approximately seven to eight voice calls...

Answers to Review Questions Ljn

Some examples of laws and directives influencing network security include the following The U.S. Gramm-Leach-Bliley Act of 1999 (GLBA) Provides limited privacy protections against the sale of private financial information. The U.S. Health Insurance Portability and Accountability Act (HIPAA) Aims to enable better access to health insurance, reduce fraud and abuse, and lower the overall cost of health care in the United States. European Union Data Protection Directive 95 46 EC Aims to protect...

Pv6 Address Scope Types

Similar to IPv4, a single source can address datagrams to either one or many destinations at the same time in IPv6. NOTE RFC 4291, IPv6 Addressing Architecture, defines the IPv6 addressing architecture. Following are the types of IPv6 addresses Unicast (one-to-one) Similar to an IPv4 unicast address, an IPv6 unicast address is for a single source to send data to a single destination. A packet sent to a unicast IPv6 address goes to the interface identified by that address. The IPv6 unicast...

Enterprise Teleworker Module

The Enterprise Teleworker module provides people in geographically dispersed locations, such as home offices or hotels, with highly secure access to central-site applications and network services. The Enterprise Teleworker module supports a small office with one to several employees or the home office of a telecommuter. Telecommuters might also be mobile users people who need access while traveling or who do not work at a fixed company site. Depending on the amount of use and the WAN services...

IEEE 8021x and IBNS

Recall from Chapter 9 that IEEE 802.1X is an open standards-based protocol for authenticating network clients (or ports) based on a user ID or on the device. 802.1X runs between end devices or users (called supplicants) trying to connect to ports, and an Ethernet device, such as a Cisco Catalyst switch or Cisco wireless access point (AP) (called the authenticator). Authentication and authorization are achieved with back-end communication to an authentication server such as Cisco Secure Access...

Distance Vector Versus Link State Versus Hybrid Protocols

There are two main types of routing protocols Distance vector protocol In a distance vector protocol, routing decisions are made on a hop-by-hop basis. Each router relies on its neighbor routers to make the correct routing decisions. The router passes only the results of this decision (its routing table) to its neighbors. Distance vector protocols are typically slower to converge and do not scale well however, they are easy to implement and maintain. Examples of distance vector protocols...

Introduction to IP Telephony

Seal Gas Tubing For Compressor

IP telephony refers to cost-effective communication services, including voice, fax, and voice-messaging applications, transported via the packet-switched IP network rather than the circuit-switched PSTN. VoIP uses voice-enabled routers to convert voice into IP packets and route those packets between corresponding locations. Users do not often notice the implementation of VoIP in the network they use their traditional phones, connected to a PBX. However, the PBX is not connected to the PSTN or...

Analog and Digital Signaling

The human voice generates sound waves a telephone converts the sound waves into analog signals. However, analog transmission is not particularly efficient. Analog signals must be amplified when they become weak from transmission loss as they travel. However, amplification of analog signals also amplifies noise. The PSTN is a collection of interconnected voice-oriented public telephone networks, both commercial and government-owned. The PSTN today consists almost entirely of digital technology,...

Private and Public IPv4 Addresses

Public Addresses

Recall from Chapter 1 that the IP address space is divided into public and private spaces. Private addresses are reserved IP addresses that are to be used only internally within a company's network, not on the Internet. Private addresses must therefore be mapped to a company's external registered address when sending anything on the Internet. Public IP addresses are provided for external communication. Figure 6-1 illustrates the use of private and public addresses in a network. Figure 6-1...

LANs and WANs

LANs were first used between PCs when users needed to connect with other PCs in the same building to share resources. A LAN is a high-speed, yet relatively inexpensive, network that allows connected computers to communicate. LANs have limited reach (hence the term local-area network), typically less than a few hundred meters, so they can connect only devices in the same room or building, or possibly within the same campus. A LAN is an always-on connection in other words, you don't have to dial...

WAN Backup Strategies

Wan Connections

This section describes various backup options for providing alternative paths for remote access. WAN links are relatively unreliable compared to LAN links and often are much slower than the LANs to which they connect. This combination of uncertain reliability, lack of speed, and high importance makes WAN links good candidates for redundancy to achieve high availability. Branch offices should experience minimum downtime in case of primary link failure. A backup connection can be established,...

WLAN Security

WLAN security includes the following Authentication Ensures that only legitimate clients access the network via trusted APs. Encryption Ensures the confidentiality of transmitted data. Intrusion detection and intrusion protection Monitors, detects, and mitigates unauthorized access and attacks against the network. Initially, basic 802.11 WLAN security was provided via Wired Equivalent Privacy (WEP) authentication and encryption, using static keys. With static WEP, the encryption keys must match...

Design Considerations for Outdoor Wireless Networks

Outdoor Mesh Network

Traditional outdoor wireless deployment options include point-to-point or point-to-multipoint bridging between buildings. Outdoor wireless mesh is a relatively new option in which the APs are connected in a mesh with many redundant connections between nodes. Figure 9-33 illustrates these options. Figure 9-33 Outdoor Wireless Options Figure 9-33 Outdoor Wireless Options Mesh APs discover each other automatically and select the best path through the mesh for maximizing system capacity and...

Traditional WAN Technologies

Design Network Using Wan Technology

Traditional WAN technologies include the following Leased lines Point-to-point connections indefinitely reserved for transmissions, rather than used only when transmission is required. The carrier establishes the connection either by dedicating a physical wire or by delegating a channel using frequency division multiplexing or time-division multiplexing (TDM). Leased-line connections usually use synchronous transmission. Circuit-switched networks A type of network that, for the duration of the...

Integrated ISIS

IS-IS was developed by Digital Equipment Corporation (DEC) as the dynamic link-state routing protocol for the Open Systems Interconnection (OSI) protocol suite. The OSI suite uses Connectionless Network Service (CLNS) to provide connectionless delivery of data, and the actual Layer 3 protocol is Connectionless Network Protocol (CLNP). CLNP is the OSI suite solution for connectionless delivery of data, similar to IP in the TCP IP suite. IS-IS uses CLNS addresses to identify the routers and build...

Pv6 Address Format

Rather than using dotted-decimal format, IPv6 addresses are written as hexadecimal numbers with colons between each set of four hexadecimal digits (which is 16 bits) we like to call this the coloned hex format. The format is x x x x x x x x, where x is a 16-bit hexadecimal field. A sample address is as follows Fortunately, you can shorten the written form of IPv6 addresses. Leading 0s within each set of four hexadecimal digits can be omitted, and a pair of colons ( ) can be used, once within an...

IP Extended Access Lists

Plastic Snap Design

Standard access lists offer quick configuration and low overhead in limiting traffic based on source addresses in a network. Extended access lists provide a higher degree of control by enabling filtering based on the source and destination addresses, transport layer protocol, and application port number. These features make it possible to limit traffic based on the uses of the network. As shown in Figure B-14, every condition tested in a line of an extended access list must match for the line...

Cisco IOS Software Packaging

Cisco is migrating to using Cisco IOS Packaging to simplify the image-selection process by consolidating the total number of packages and using consistent package names across all hardware products. Figure 5-22 illustrates the various packages available with Cisco IOS packaging. Figure 5-21 Cisco IOS Software in the Network Figure 5-21 Cisco IOS Software in the Network Broadband access Mobility and wireless Data center Security Broadband access Mobility and wireless Data center Security Cisco...

SWitCh PSTN

PSTN switches interconnect business PBXs and public and private telephones. Large PSTN switches are located at COs, which provide circuits throughout the telephony network. PSTN switches are deployed in hierarchies to provide resiliency and redundancy to the PSTN network and avoid a single point of failure. PSTN signaling traditionally supported only basic features such as caller ID and direct inward dialing. Modern PSTN switches now support, on a fee basis, many traditional PBX services,...

The Cisco Enterprise Data Center Architecture Framework

Network Enterprise Center

The consolidation and virtualization of data center resources requires a highly scalable, resilient, secure data center network foundation. As described in Chapter 2, Applying a Methodology to Network Design, the Cisco Service-Oriented Network Architecture (SONA) framework defines how enterprises can evolve toward intelligence in the network that optimizes applications, business processes, and resources. The Cisco Enterprise Data Center Architecture, based on SONA, provides organizations with a...

Virtual LANs

As noted earlier, a broadcast domain includes all devices that receive each others' broadcasts (and multicasts). All the devices connected to one router port are in the same broadcast domain. Routers block broadcasts (destined for all networks) and multicasts by default routers forward only unicast packets (destined for a specific device) and packets of a special type called directed broadcasts. Typically, you think of a broadcast domain as being a physical wire, a LAN. But a broadcast domain...

Enterprise Branch Design

Insinkerator Hot Water Dispenser Parts

Requirements differ with the size of the branch offices. Consider to the following questions when How many branch locations need to be supported How many existing devices (including end users, hosts, and network infrastructure) are to be supported at each location The number of devices supported is limited by the physical number of ports available. How much growth is expected at each location, and therefore what level of scalability is required What are the high availability requirements at...

Design Considerations for Branch Office Wireless Networks

Network Design Any Branch

This section reviews design considerations for branch wireless network design, including REAP and H-REAP. The following are several key design considerations for branch office wireless networks How many APs are needed, and what are their requirements Recall that, generally, an AP can support 7 to 8 wireless phones or 20 or more data-only devices. Ports must be available on the local switch to connect the APs to the wired network. Power to the APs, either through PoE or traditional power...

Introduction

Modern networks are both extremely complex and critical to business success. As organizational processes continue to increase the requirements for bandwidth, reliability, and functionality from their networks, network designers are challenged to rapidly develop and evolve networks that use new protocols and technologies. Network designers are also challenged to stay current with the internetworking industry's constant and rapid changes. Designing robust, reliable, scalable networks is a...

Local Loops Trunks and Interswitch Communications

Local Loop Explained Pstn

Figure 8-5 illustrates a typical telephone infrastructure and connections between telephony devices. Figure 8-5 Local Loops, Trunks, and Interswitch Communication Figure 8-5 Local Loops, Trunks, and Interswitch Communication The telephone infrastructure starts with a simple pair of copper wires running to the end user's home or business. This physical cabling is known as a local loop or telephone line the local loop physically connects the home telephone to the CO PSTN switch. Similarly, the...

Case Study Scenario

Case Study Networks Used Epanet

This case study analyzes the network infrastructure of ACMC Hospital, a fictitious small county hospital. The hospital has provided you with a short description of the current situation and its plans. As a network designer, it is your job to identify all the organization's requirements and data that will allow you to provide an effective solution. ACMC Hospital is a medium-sized regional hospital located in Acme County, with approximately 500 staff members supporting up to 1000 patients. The...

Interior Versus Exterior Routing Protocols

An autonomous system (AS), also known as a domain, is a collection of routers that are under a common administration, such as a company's internal network or an Internet service provider's (ISP's) network. Because the Internet is based on the AS concept, two types of routing protocols are required Interior gateway protocols (IGP) are intra-AS (inside an AS) routing protocols. Examples of IGPs include Routing Information Protocol (RIP) version 1 (RIPv1), RIP version 2 (RIPv2), Open Shortest Path...

IEEE 80211 Operational Standards

In September 1999 the IEEE ratified the IEEE 802.11a standard (5 GHz at 54 Mbps) and the IEEE 802.11b standard (2.4 GHz at 11 Mbps). In June 2003, the IEEE ratified the 802.11g standard (2.4 GHz at 54 Mbps) this standard is backward-compatible with 802.11b systems, because both use the same 2.4-GHz bandwidth. The following are the existing IEEE 802.11 standards for wireless communication 802.11a 54 Mbps at 5 GHz, ratified in 1999 802.11b 11 Mbps 2.4 GHz, ratified in 1999 802.11d World mode,...

The OSI Layers

The following sections briefly describe each of the seven layers of the OSI model, starting at the lowest layer. Appendix C, Open System Interconnection (OSI) Reference Model, delves deeper into the details of the OSI model. The OSI physical layer defines specifications such as the electrical and mechanical conditions necessary for activating, maintaining, and deactivating the physical link between devices. Specifications include voltage levels, maximum cable lengths, connector types, and...

Determining an IP Address Class

To accommodate large and small networks, the 32-bit IP addresses are segregated into Classes A through E. The first few bits of the first octet determine the class of an address this then determines how many network bits and host bits are in the address. Figure B-4 illustrates the bits for Class A, B, and C addresses. Each address class allows for a certain number of network addresses and a certain number of host addresses within a network. Table B-2 shows the address format, the address range,...

Border Gateway Protocol

BGP is an EGP that is primarily used to interconnect autonomous systems. BGP is a successor to EGP, the Exterior Gateway Protocol (note the dual use of the EGP acronym). Because EGP is obsolete, BGP is currently the only EGP in use. BGP-4 is the latest version of BGP. It is defined in RFC 4271, A Border Gateway Protocol (BGP-4). As noted in this RFC, the classic definition of an AS is a set of routers under a single technical administration, using an Interior Gateway Protocol (IGP) and common...

Tunneling Transition Mechanism

The purpose of tunneling is to encapsulate packets of one type in packets of another type. When transitioning to IPv6, tunneling encapsulates IPv6 packets in IPv4 packets, as shown in Figure 6-25. Figure 6-25 Tunneling IPv6 Packets Within IPv4 Packets Figure 6-25 Tunneling IPv6 Packets Within IPv4 Packets By using overlay tunnels, isolated IPv6 networks can communicate without having to upgrade the IPv4 infrastructure between them. Both routers and hosts can use tunneling. The following...

TCPIP Transport Layer Protocols

The TCP IP transport layer includes the following two protocols Transmission Control Protocol (TCP) Provides connection-oriented, end-to-end reliable transmission. Before sending any data, TCP on the source device establishes a connection with TCP on the destination device, ensuring that both sides are synchronized. Data is acknowledged any data not received properly is retransmitted. FTP is an example of an application that uses TCP to guarantee that the data sent from one device to another is...

IP Telephony Components

An IP telephony network contains four main voice-specific components IP phones IP phones are used to place calls in an IP telephony network. They perform voice-to-IP (and vice versa) coding and compression using special hardware. IP phones offer services such as user directory lookups and Internet access. The phones are active network devices that require power to operate power is supplied through the LAN connection using PoE or with an external power supply. Switches with inline power Switches...

Pv4 Addresses and Subnetting Job Aid

Figure B-1 is a job aid to help you with various aspects of IP addressing, including how to distinguish address classes, the number of subnets and hosts available with various subnet masks, and how to interpret IP addresses. Net First Standard Mask Class Host Octet Binary A N.H.H.H 1-126 1111 1111 0000 0000 0000 0000 0000 0000 B N.N.H.H 128-191 1111 1111 1111 1111 0000000000000000 C N.N.N.H 192-223 1111 1111 1111 1111 1111 1111 00000000 Address 172.16.5.72 1010 1100 0001 0000 0000 0101 0100...

Cisco Security Management Technologies

The Cisco Security Management Suite is a framework of products and technologies designed for scalable policy administration and enforcement for the Cisco Self-Defending Network. This integrated solution can simplify and automate the tasks associated with security management operations, including configuration, monitoring, analysis, and response. The key components of this suite include the following Cisco Security Manager Cisco Security Manager is a powerful but easy-to-use solution for...

WLAN Components

Client devices use wireless NICs or adapters to connect to a wireless network in either ad hoc (peer-to-peer) mode or infrastructure mode using APs. Cisco APs can be either autonomous or lightweight. NOTE Autonomous APs used to be called thick, fat, or decentralized APs, whereas lightweight APs were called thin or centralized APs. These components are described in the following sections. The Cisco Compatible Extensions (CCX) program for WLAN client devices allows vendors of WLAN client devices...

PSTN Numbering Plans

Itu Recommendation 164

PSTN numbering plans are the foundation for routing voice calls through the PSTN network. For any telephone network to function, a unique address must identify each telephone. Voice addressing relies on a combination of international and national standards, local telephone company practices, and internal customer-specific codes. The International Telecommunications Union Telecommunication Standardization Sector (ITU-T) recommendation E.164 defines the international numbering plan. Each...

Cisco Enterprise MAN and WAN Architecture Technologies

The Cisco Enterprise MAN and WAN architecture employs a number of MAN and WAN technologies engineered and optimized to interoperate as a contiguous system, providing the integrated QoS, network security, reliability, and manageability required to support a variety of advanced business applications and services. These technologies include a number of secure alternatives to traditional private WAN connectivity and help increase network scalability and reduce monthly carrier fees. The Cisco...

Review Questions Ten

Answer the following questions, and then refer to Appendix A for the answers 1. List some laws that might influence network security. 2. What is the difference between a virus and a worm 3. Why might a hacker launch a reconnaissance attack 4. What is a denial-of-service (DoS) attack 5. How do Dynamic ARP Inspection (DAI) and DHCP snooping interact 6. Match the terms with the definitions Terms Availability threat Definitions The result of a network's incapability to handle an enormous quantity...

TCPIP Internet Layer Protocols

The TCP IP Internet layer corresponds to the OSI network layer and includes the IP-routed protocol, as well as a protocol for message and error reporting. The protocols at this layer include the following IP Provides connectionless, best-effort delivery of datagrams through the network. A unique IP address a logical address is assigned to each interface of each device in the network. IP and IP addresses are introduced later in this chapter and are described in more detail in Appendix B, IPv4...

Link State Example

Both OSPF and Integrated IS-IS use the Hello protocol for establishing neighbor relationships. Those relationships are stored in a neighbor table (also called an adjacencies database). Each router learns a complete network topology from information shared through these neighbor relationships. That topology is stored in the router's link-state database (LSDB), also called the topology table or topology database. Each router uses this topology and the SPF algorithm to create a shortest-path tree...

Case Study ACMC Hospital UWN Considerations

This case study is a continuation of the ACMC Hospital case study introduced in Chapter 2, Applying a Methodology to Network Design. Use the scenarios, information, and parameters provided at each task of the ongoing case study. If you encounter ambiguities, make reasonable assumptions and proceed. For all tasks, use the initial customer scenario and build on the solutions provided thus far. You can use all documentation, books, white papers, and so on. In each step, you act as a network design...

Risk Integrity Violations and Confidentiality Breaches

Network Breach Risk Factors

Key security risks are integrity violations and confidentiality breaches. Integrity violations can occur when an attacker attempts to change sensitive data without proper authorization. An example of an integrity violation is when an attacker obtains permission to write to sensitive data and then changes or deletes it. The owner of the data might not detect such a change until it is too late, perhaps when the change has already resulted in tangible loss. Because of the difficulty of detecting...

Secure Connectivity

This section discusses the secure connectivity element of the Cisco Self-Defending Network. Secure connectivity relies on privacy and data integrity. Ensuring the privacy and integrity of all information is vital to today's businesses. Increased network connectivity results in increased exposure. As organizations adopt the use of the Internet for intranet, extranet, and teleworker connectivity such as broadband always-on connections maintaining security, data integrity, and privacy across these...

Hierarchical Routing Protocols

To solve the problems associated with flat routing protocols, additional features are implemented in hierarchical routing protocols to support large networks for example, some support an area-based design. Hierarchical routing protocols are typically classless link-state protocols. Recall from Chapter 6 that classless means that routing updates include subnet masks in their routing updates therefore, the routing protocol supports VLSM. Hierarchy is part of the implementation of link-state...

NAC Framework and Cisco NAC Appliance

NAC allows network access only to compliant and trusted wired or wireless endpoint devices, such as PCs, laptops, servers, and personal digital assistants (PDA), and it can restrict the access of noncompliant devices. Two NAC options are available the NAC framework and the NAC appliance. The NAC framework is an industrywide initiative led by Cisco that uses the network infrastructure and third-party software to enforce security policy compliance on all endpoints. The NAC framework is sold...

Network Management Architecture

Network System Design And Management

Figure 3-25 illustrates a generic network management architecture. Figure 3-25 Network Management Architecture Figure 3-25 Network Management Architecture The network management architecture consists of the following Network management system (NMS) A system that executes applications that monitor and control managed devices. NMSs provide the bulk of the processing and memory resources that are required for network management. Network management protocol A protocol that facilitates the exchange...

Characterizing the Existing Network and Sites

High Level Network Diagram

The second step of the design methodology is characterizing the existing network and sites. Information collected and documented in this step is important, because the design might depend on the existing network's hardware, software, and link capacity. In many cases, a network already exists and the new design relies on restructuring and upgrading the existing network and sites. Even when a network does not exist, the sites that will be networked still should be examined. The following sections...

What Is a Routing Metric

A metric is a value (such as path length) that routing protocols use to measure paths to a destination. Different routing protocols base their metric on different measurements, including hop count, interface speed, or more-complex metrics. Most routing protocols maintain databases containing all the networks that the routing protocol recognizes and all the paths to each network. If a routing protocol recognizes more than one way to reach a network, it compares the metric for each different path...

Route Redistribution Direction

Route Redistribution Example

Redistribution is often applied between the Campus Core and Enterprise Edge protocols. As shown in Figure 7-16, redistribution is possible in two ways One-way route redistribution Routing information is redistributed from one routing protocol or domain to another, but not vice versa. Static or default routes are required in the opposite direction to provide connectivity. Two-way route redistribution Routing information is redistributed from one routing protocol or domain to another, and vice...

Case Study 102 Answers

The flat Layer 2 network is one issue. Some stability could be added to the network with Layer 3 switching. The hospital does not use DHCP adding it could be a time-consuming but worthwhile process. Another issue is the hospital's older equipment, which should be modernized. The old cabling is another issue that needs to be addressed. Random testing of 10 to 20 percent of the cabling should be conducted to get a feel for its condition. If the cabling is substandard, the hospital will need to be...

Interface Identifiers in IPv6 Addresses

In IPv6, a link is a network medium over which network nodes communicate using the link layer. Interface IDs in IPv6 addresses are used to identify a unique interface on a link. They can also be thought of as the host portion of an IPv6 address. Interface IDs are required to be unique on a link and can also be unique over a broader scope. When the interface identifier is derived directly from the data link layer address of the interface, the scope of that identifier is assumed to be universal...

Review Questions Imn

Answer the following questions, and then see Appendix A for the answers. 1. In what situations could static routing be preferred over dynamic routing 2. What do dynamic routing protocols do 3. Which type of routing protocol is used for interconnecting autonomous systems 4. Do IGPs or EGPs typically converge faster 6. How do distance vector and link-state routing protocols differ 8. What parameters do the following routing protocols use in their metric calculation by default 10. How does the...

Overloading Inside Global Addresses

Figure D-3 illustrates NAT operation when a single inside global address simultaneously represents multiple inside local addresses overloading addresses is also known as PAT. Figure D-3 PAT Overloading Inside Global Addresses Figure D-3 PAT Overloading Inside Global Addresses The following describes the process of overloading inside global addresses, as depicted in Step 1 The user at Host 10.1.1.1 opens a connection to Host B. Step 2 The first packet the router receives from Host 10.1.1.1...

WAN Transport Technology Pricing and Contract Considerations

This section discusses pricing and contract considerations for WAN technologies. NOTE The pricing, time frame, and contract details provided here are examples from the United States market. Organizations in other countries might have different experiences. However, the items in this section should be considered when implementing a WAN. Service and pricing options between carriers should be compared and negotiated, depending on competition in the area. Historically, WAN transport costs include...

Review Questions Mjw

Answer the following questions, and then refer to Appendix A for the answers. 1. What steps are involved in converting analog signals to digital signals 2. What is pulse amplitude modulation 3. What is pulse code modulation 4. Match the following terms with their definitions Terms Converting an analog sample to a digital code word Compression increases as the sample signal increases Removing nonspeech components Compressing and expanding signals 6. What are some differences between a PBX and a...

Case Study Answers Nas

The RFP should include the following items The number of sites and the minimum bandwidth required to each site The service level that should be guaranteed (that the provider will deliver) under the SLA The mean time to repair (MTTR) that is acceptable under the SLA The level of packet loss, latency, and jitter that is acceptable under the SLA How the SLA parameters will be measured Any penalties for SLA noncompliance 2. The monthly cost calculations are shown in the last column of the following...

Case Study ACMC Hospital Network Upgrade

This case study analyzes the network infrastructure of Acme County Medical Center (ACMC) Hospital, a fictitious small county hospital in the United States. This same case study is used throughout the remainder of the book so that you can continue to evaluate your understanding of the concepts presented. Use the scenarios, information, and parameters provided at each task of the ongoing case study. If you encounter ambiguities, make reasonable assumptions and proceed. For all tasks, use the...

Case Study Additional Information

Remote Acmc

Figure 5-30 shows the existing WAN links and the planned campus infrastructure. Figure 5-30 Case Study ACMC Hospital WAN Links and Planned Campus Infrastructure Figure 5-30 Case Study ACMC Hospital WAN Links and Planned Campus Infrastructure The ACMC Hospital CIO realizes that WAN performance to the remote clinics is poor and that some new applications will require more bandwidth. These applications include programs that allow doctors at the central site to access medical images, such as...

Case Study ACMC Hospital Routing Protocol Design

This case study is a continuation of the ACMC Hospital case study introduced in Chapter 2. Use the scenarios, information, and parameters provided at each task of the ongoing case study. If you encounter ambiguities, make reasonable assumptions and proceed. For all tasks, use the initial customer scenario and build on the solutions provided thus far. You can use any and all documentation, books, white papers, and so on. In each step, you act as a network design consultant. Make creative...

Case Study 102 ACMC Hospital Network Connecting More Hospitals

This case study is a continuation of ACMC Hospital Case Study 10-1. Use the scenarios, information, and parameters provided at each task of the ongoing case study. If you encounter ambiguities, make reasonable assumptions and proceed. For all tasks, use the initial customer scenario and build on the solutions provided thus far. You can use any and all documentation, books, white papers, and so on. In each step, you act as a network design consultant. Make creative proposals to accomplish the...

Analyzing Network Traffic and Applications

Traffic analysis is the third step in characterizing a network. Traffic analysis verifies the set of applications and protocols used in the network and determines the applications' traffic patterns. It might reveal any additional applications or protocols running on the network. Each discovered application and protocol should be described in the following terms Security-related requirements Scope (in other words, the network modules in which the application or protocol is used) Use the...

IP Standard Access Lists

Icmp Packet Explained

Standard access lists permit or deny packets based only on the packet's source IP address, as shown in Figure B-9. The access list number range for standard IP access lists is 1 to 99 or from 1300 to 1999. Standard access lists are easier to configure than their more robust counterparts, extended access lists. Figure B-9 Standard IP Access Lists Filter Based Only on the Source Address A standard access list is a sequential collection of permit and deny conditions that apply to source IP...

IGP and EGP Example

Egp Network

Figure 7-2 shows three interconnected autonomous systems (domains). Each AS uses an IGP for intra-AS (intra-domain) routing. Figure 7-2 Interior Protocols Are Used Inside and Exterior Protocols Are Used Between Autonomous Systems Figure 7-2 Interior Protocols Are Used Inside and Exterior Protocols Are Used Between Autonomous Systems The autonomous systems require some form of interdomain routing to communicate with each other. Static routes are used in simple cases typically, an EGP is used....

Maintaining Data Integrity

Network Data Intergrity

Cryptography also provides data integrity mechanisms to protect data in transit over untrusted networks. Cryptographic protocols, such as secure fingerprints and digital signatures, can detect any integrity violation of sensitive data. Secure fingerprints attach a cryptographically strong checksum to data. This checksum is generated and verified using a secret key that only authorized subjects know. By verifying the checksum of received data, an authorized subject can verify data integrity. For...

Extending an IP Classful Address Using Subnet Masks

RFC 950, Internet Standard Subnetting Procedure, was written to address the IP address shortage. It proposed a procedure, called subnet masking, for dividing Class A, B, and C addresses into smaller pieces, thereby increasing the number of possible networks. A subnet mask is a 32-bit value that identifies which address bits represent network bits and which represent host bits. In other words, the router does not determine the network portion of the address by looking at the value of the first...

RF Site Survey

This section reviews the reasons that an RF site survey is used in wireless network design, and the process to conduct such a survey. An RF site survey is the first step in the design and deployment of a wireless network, and the most important step to ensure desired operation. A site survey is a process by which the surveyor studies the facility to understand the RF characteristics in the environment, plans and reviews RF coverage areas, checks for RF interference, and determines the...

Controller Redundancy Design

Spavinaw Lake Map

Recall that the AP discovery and join decision process first looks for a defined primary, secondary, or tertiary WLC (as specified by the controller's sysName). An AP's second choice is to join a WLC configured as a master controller. This is typically used only on initial AP deployment to find an initial controller, at which time the AP should be configured with its deterministic controllers. The last choice in the AP join decision algorithm is to try to dynamically choose a WLC based on the...

Top Down Design Example

Consider an example that uses the basics of the top-down approach when designing an IP telephony network solution. In this example, the customer requires a network that can support IP telephony. IP telephony permits the use of the same network resources for both data and voice transport, thus reducing the costs of having two separate networks. To achieve this, the network must support Voice over IP (VoIP) technology this first step in the design process is illustrated in Figure 2-19. Figure...

Network Design Tools

Several types of tools can be used to ease the task of designing a complex modern network, Network modeling tools Network modeling tools are helpful when a lot of input design information (such as customer requirements, network audit and analysis results, and so on) exists. Network modeling tools enable modeling of both simple and complex networks. The tools process the information provided and return a proposed configuration, which can be modified and reprocessed to add redundant links,...

Voice Coding and Compression

Voice communication over IP relies on voice that is coded and encapsulated into IP packets. This section provides an overview of the various codecs used in voice networks. NOTE The term codec can have the following two meanings A coder-decoder An integrated circuit device that typically uses PCM to transform analog signals into a digital bit stream and digital signals back into analog signals. A software algorithm Used to compress and decompress speech or audio signals in VoIP, Frame Relay, and...

Clearing NAT Translation Entries

To clear a dynamic translation entry, use the commands shown in Table D-3. Table D-3 Commands to Clear NAT Translation Entries Clears all dynamic translation entries. clear ip nat translation inside global-ip local-ip outside local-ip global-ip Clears a simple dynamic translation entry that contains an inside translation or both an inside and outside translation. clear ip nat translation outside local-ip global-ip Clears a simple dynamic translation entry that contains an outside translation....

RIPv2 Convergence Example

Routing Table Convergence

RIPv2 is a distance vector protocol that periodically propagates its routing information. Distance vector protocols use the principle of hold-down to prevent routing loops. Putting a route in hold-down after the route has failed (perhaps due to a link failure) means that if a routing update arrives with the same or a worse metric, the new route is not installed until the hold-down timer expires. Even though the destination might no longer be reachable, a route in hold-down is still used to...

Design Considerations for Campus Wireless Networks

Example Design Network

This section reviews design considerations for enterprise campus wireless networks. To develop an enterprise campus wireless network design, the following questions need to be answered How many APs are needed Sufficient APs to provide RF coverage, with the required features to support the wireless clients, are needed. Different APs have different features, including internal or external antenna, single or dual radios, and number of devices supported. Optimally, deploy more APs than indicated by...

Documenting the Design

A design document lists the design requirements, documents the existing network and the network design, identifies the proof-of-concept strategy and results, and details the implementation plan. The final design document structure should be similar to the one in Figure 2-26, which includes Introduction Every design document should include an introduction to present the main reasons leading to the network design or redesign. Design requirements Also a mandatory part of any design document, this...

Introduction to WANs

This section defines a WAN and describes its primary design objectives. A WAN is a data communications network that covers a relatively broad geographic area. A WAN typically uses the transmission facilities provided by service providers (SP) (also called carriers), such as telephone companies. Switches, or concentrators, connect the WAN links, relay information through the WAN, and enable the services it provides. A network provider often charges users a fee, called a tariff, for the services...

RMON1 and RMON2

RMON1 only provides visibility into the data link and the physical layers potential problems that occur at the higher layers still require other capture and decode tools. Because of RMONl's limitations, RMON2 was developed to extend functionality to upper-layer protocols. As illustrated in Figure 3-31, RMON2 provides full network visibility from the network layer through to the application layer. Figure 3-31 RMON2 Is an Extension of RMON1 Application Presentation Session Transport Network RMON2...

Internal Security

Internal Security Network For Bank

Strongly protecting the internal Enterprise Campus by including security functions in each individual element is important for the following reasons If the security established at the Enterprise Edge fails, an unprotected Enterprise Campus is vulnerable. Deploying several layers of security increases the protection of the Enterprise Campus, where the most strategic assets usually reside. Relying on physical security is not enough. For example, as a visitor to the organization, a potential...

Restricting Virtual Terminal Access

Vty Protocol

This section discusses how you can use standard access lists to limit virtual terminal access. Standard and extended access lists block packets from going through the router. They are not designed to block packets that originate within the router. An outbound Telnet extended access list does not prevent router-initiated Telnet sessions by default. For security purposes, users can be denied virtual terminal (vty) access to the router, or they can be permitted vty access to the router but denied...

Remote Access Network Design

When you're designing remote-access networks for teleworkers and traveling employees, the type of connection drives the technology selection, such as whether to choose a data link or a network layer connection. By analyzing the application requirements and service provider offerings, you can choose the most suitable of a wide range of remote-access technologies. Typical remoteaccess requirements include the following Data link layer WAN technologies from remote sites to the Enterprise Edge...

Enterprise Edge WAN and MAN Considerations

When selecting Enterprise Edge technologies, consider the following factors Support for network growth Enterprises that anticipate significant growth should choose a technology that allows the network to grow with their business. WAN technologies with high support for network growth make it possible to add new branches or remote offices with minimal configuration at existing sites, thus minimizing the costs and IT staff requirements for such changes. WAN technologies with lower support for...

Physical Security Guidelines

The traditional method of managing the risk of physical compromise is to deploy physical access controls using techniques such as locks or alarms. It is also important to identify how a physical security breach might interact with network security mechanisms. For example, there could be a significant risk if an attacker physically accesses a switch port located in a corporate building and from there has unrestricted access to the corporate network. If, during the development of the security...

Communication Among OSI Layers

This section describes how communication among the seven OSI layers is accomplished. When you send an e-mail from Toronto to your friend in San Francisco, you can think of your e-mail application sending a message to the e-mail application on your friend's computer. In OSI model terms, information is exchanged between peer OSI layers the application layer on your computer is communicating with the application layer on your friend's computer. However, to accomplish this, the e-mail must go...

Erlang Tables

Off Net Open Net

Erlang tables show the amount of traffic potential (the BHT) for specified numbers of circuits for given probabilities of receiving a busy signal (the GoS). The BHT calculation results are stated in CCSs or Erlangs. Erlang tables combine offered traffic (the BHT), number of circuits, and GoS in the following traffic models Erlang B This is the most common traffic model, which is used to calculate how many lines are required if the traffic (in Erlangs) during the busiest hour is known. The model...

Routing in the Campus Core

The Campus Core provides high-speed data transmission between Building Distribution devices. The Campus Core is critical for connectivity and, therefore, incorporates a high level of redundancy using redundant links and load sharing between equal-cost paths. In the event of a link failure, it must immediately converge, adapting quickly to change to provide a seamless transport service. EIGRP and OSPF both adapt quickly to changes and have short convergence times. Therefore, they are suitable...

WAN Interconnections

Figure 5-1 illustrates the three ways that WAN technologies connect the Enterprise Edge modules with the outside world, represented by the service provider network. Typically, the intent is to provide the following connections Connectivity between the Enterprise Edge modules and the Internet Service Provider (ISP) Edge module Connectivity between Enterprise sites across the ISP network Connectivity between Enterprise sites across the SP or public switched telephone network (PSTN) carrier...

Hierarchical Network Model

The hierarchical network model provides a framework that network designers can use to help ensure that the network is flexible and easy to implement and troubleshoot. As shown in Figure 3-1, the hierarchical network design model consists of three layers The access layer provides local and remote workgroup or user access to the network. The distribution layer provides policy-based connectivity. The core (or backbone) layer provides high-speed transport to satisfy the connectivity and transport...

Decision Tables in Network Design

Decision tables are used for making systematic decisions when there are multiple solutions or options to a network issue or problem. Decision tables facilitate the selection of the most appropriate option from many possibilities and can be helpful for justifying why a certain solution was chosen. Options are usually selected based on the highest level of compliance with given requirements. Basic guidelines for creating a network design decision table include the following Step 1 Determine the...

Routing Protocol Convergence

Whenever a change occurs in a network's topology, all the routers in that network must learn the new topology. This process is both collaborative and independent the routers share information with each other, but they must calculate the impact of the topology change independently. Because they must mutually develop an independent agreement on the new topology, they are said to converge on this consensus. Convergence properties include the speed of propagation of routing information and the...

Evaluating the Cost Effectiveness of WAN Ownership

In the WAN environment, the following usually represent fixed costs Equipment purchases, such as modems, channel service unit data service units, and router interfaces Circuit and service provisioning Network-management tools and platforms Recurring costs include the monthly circuit fees from the SP and the WAN's support and maintenance, including any network management center personnel. From an ownership perspective, WAN links can be thought of in the following three categories Private A...

Time Estimates for Performing Network Characterization

This section provides some guidelines to estimate how long it may take to characterize the network. The time required to characterize a network varies significantly, depending on factors such as the following The experience of the network engineer The quality of documentation provided by the customer and the quality of the communication with the customer The size and complexity of network The efficiency of network management and discovery tools Whether or not the network devices are carefully...

Routing Tables

To determine the best path on which to send a packet, a router must know where the packet's destination network is. Routers learn about networks by being physically connected to them or by learning about them either from other routers or from a network administrator. Routes configured by network administrators are known as static routes because they are hard-coded in the router and remain there static until the administrator removes them. Routes to which a router is physically connected are...

ANS Components

Figure 3-24 illustrates an example of ANS deployed in offices connected over a WAN, providing LAN-like performance to users in the branch, regional, and remote offices. ANS components are deployed symmetrically in the data center and the distant offices. The ANS components in this example are as follows Cisco Wide Area Application Services (WAAS) software Cisco WAAS software gives remote offices LAN-like access to centrally hosted applications, servers, storage, and multimedia. Cisco Wide Area...

OSI Models Presentation Layer

The presentation layer provides a variety of coding and conversion functions that are applied to application layer data. These functions ensure that information sent from one system's application layer is readable by another system's application layer. Some examples of presentation layer coding and conversion schemes include common data representation formats, conversion of character representation formats, common data compression schemes, and common data encryption schemes. Common data...

Calculating Trunk Capacity or Bandwidth

The trunk capacity for voice calls can be calculated by the following formula Trunk capacity (number of simultaneous calls to be supported) * (bandwidth required per call) The first component of this formula, the number of simultaneous calls to be supported, is the number of circuits required for the known amount of traffic, as calculated from the Erlang tables. NOTE If 100 percent of calls must go through, Erlang tables are not required instead, the maximum number of simultaneous calls...