Networking for Management
One way in which network elements can be connected to a management system is through the network element's management port.
For most routers, this is a serial interface. It is possible to connect a terminal, such as a notebook computer, directly to that serial interface using a serial cable, as illustrated in Figure 3-10. The terminal thus connected to a network device is typically referred to as a craft terminal, in reference to the craft technician who typically uses it. The craft terminal then functions as a console through which a user (a craft technician) can interact with the device. For example, the craft technician can enter CLI commands to configure and troubleshoot the network device.
Figure 3-10 Connecting a Craft Terminal to a Managed Device
Router
Router
Serial Cable
Serial Cable
Craft Terminal
Craft Terminal
Of course, if you are a craft technician, in most cases, it soon becomes impractical to go from device to device, connecting and disconnecting the craft terminal as you go along. You need to continuously fumble around with the plugs and the cables, and, worse, you need physical access to the network elements and must work in spaces that can be quite confined. For these reasons, a terminal server can be introduced, as illustrated in Figure 3-11.
Figure 3-11 Connecting to Multiple Devices Through a Terminal Server
The terminal server takes the place of an intermediate "switch" between the actual craft terminal and the network element. The terminal server has a whole set of serial interface ports through which it can connect with many network elements simultaneously, one through each port. In addition, it has a port for the craft terminal to connect to. You can connect your craft terminal to the terminal server to connect to every device that is hooked up to the terminal server. When connecting, your console initially opens a session with the terminal server. You can then specify which port you want to be switched to. From that point on, the terminal server relays all communication between your craft terminal and network element connected to that port. Thus, you can communicate with the network element behind the terminal server's port, just as if you were directly connected through its console port. When you are finished with that network element and want to switch to a different device that is connected to a different port, you typically enter a
Craft Terminal
Figure 3-11 Connecting to Multiple Devices Through a Terminal Server
Craft Terminal
special command that is prefixed with a special escape parameter. This allows the terminal server to recognize that it itself is the intended recipient for the command and can switch you to another port.
To make matters even better, the terminal server also has an IP address and an Ethernet interface. This enables you to connect to the terminal servers through a network, such as a local-area network (LAN). This way, your craft terminal no longer needs to be directly connected to the terminal server, as long as it connects to the same network. Accessing the network element works exactly the same as when you access the terminal server through its local port: You specify which port you want to be connected to and are dropped into a terminal session with the device that is connected to that port. Because it is, of course, possible to address different terminal servers over the network by merely using their respective IP address, it is no longer required to physically connect and disconnect between different terminal servers just to be connected to network elements that are connected to different terminal servers. After all, terminal servers have only a finite number of ports, usually no more than a few dozens. Instead, the craft terminal can reach any terminal server on the network and, with it, any network element connected to a port of the terminal server. In fact, the craft terminal can be a management application, for all practical purposes; it does not need to be a human craft technician interacting with the device.
Of course, what you have just introduced and barely noticed is an actual management network— a network to interconnect managing application (your craft terminal) and managed devices.
Of course, the management network that we have just built has one big drawback: Although we can connect to any network element, it is necessary to keep track of which network element is connected to which terminal server, and through which port. It is easy to lose track of this information, especially as the number of network elements, terminal servers, and, thus, complexity of the management network grows. Wouldn't it be easier if you could just address the network elements directly, instead of through a port of a terminal server? This leads us to another way in which to connect to the network elements directly.
The second method of connecting to an NE is through its Ethernet port. Most NEs offer such a port through which they can be addressed directly from the network. The NE does not use the port to route traffic; the NE uses it to attach to a network like any other host. Now the NE no longer needs to be addressed in terms of a serial port of a terminal server through which it connects. Instead, it has its own IP address—used for management purposes—that allows the NE to be treated and addressed like any host on a network. In addition, this Ethernet port, not the console port, is the interface of choice to interact with the device using methods other than the CLI, such as a management protocol like SNMP. The console port, after all, is intended mainly as an easy means for craft technicians and, thus, human users who need to interact with the device, not for management systems over a network.
The third method of connecting to an NE is to simply use a port that is shared with other traffic— traffic that does not terminate at the NE, but that is routed or switched. In this case, management traffic is carried "in band" instead of "out of band," as with the other options.
Post a comment