R O M A N I A N E D U C A T I O N N E T W O R K Ro work Management Framework: A Distributed Virtual NOC Architecture DVNOC Model Octavian RUSU octavian@iasi.roedu.net Florin B. MANOLACHE florin@andrew.cmu.edu Ro Conference 2003, June 5-6, 2003
work Management work management the mechanism used for all managed objects within the Physical and Data Link Layer to do: monitoring controlling coordination Strategies: Centralized Distributed Hierarchical Ro Conference, Iasi, June 5-6, 2003
work Management Components work management components: Configuration management - detects and controls the state of the network Performance management - controls and analyses throughput and error rate Fault management is responsible for detecting, isolating and controlling abnormal behavior Accounting management collects and processes data about resource consumption in the network Security management deals with access control Service management components: Monitoring - involves gathering data about the network Control - manipulation of devices Reporting - abnormal events are reported Ro Conference, Iasi, June 5-6, 2003
Distributed Virtual work Operation Centers (DVNOC) NMCU work Management Coordinating Unit NMEU work Management Executive Unit SSU Special Solutions Units NOC work Operation Center APM Access Port Managers ESP External Service Providers NMCU NMEU ESP # SSU # Help Desk APMs NOCs Ro Conference, Iasi, June 5-6, 2003
NMCU - work Management Coordinating Unit sets up the main network policies, including the network evolution and upgrades of the equipments and services; establishes relations and appoints services with External Service Providers (ESPs); performs the high level design of all services; decides about special solutions and services by appropriate Special Solutions Units (SSU); coordinates the work Management Executive Unit (NMEU) activities Ro Conference, Iasi, June 5-6, 2003
NMEU - work Management Executive Unit The technical core of the management team for the entire network responsible for the technical integrity of the services provided on the network; implements new services using configuration solutions provided by SSUs; technically defines and modifies network policies; plans network development; operates a Help Desk which interacts with APMs; ESP, to provide fault isolation and management of the lines and/or services supervised by a different authority; SSUs during testing period for new services operates the Trouble Ticket System Ro Conference, Iasi, June 5-6, 2003
SSU - Special Solutions Units specialized task teams distributed in the service dimension provide studies for proposed services by NMCU, specifying issues of interest for the network objectives and policies; provide configuration files for network equipment to implement the proposed services; interact with NMEU during service activation; report through the Help Desk problems related to a service; monitor service operation using network management tools during the implementation period. Ro Conference, Iasi, June 5-6, 2003
APM - Access Port Managers geographically distributed teams (one for each NOC) responsible for the local NOC activities monitor the network operation in their area of authority; configure the local communication equipment; monitor the implementation of the services within their NOCs; interact with NMEU to maintain the centralized management system; interact with the users at the NOC level. Ro Conference, Iasi, June 5-6, 2003
DVNOC - Advantages centralized character for network operation all information flows through the NMEU. distributed character achieved through APMs provide network management and user support within a geographical area of authority SSUs responsible for particular services implementation on the entire network. interaction between SSUs and APMs is handled by NMCU providing consistency of all operations. Ro Conference, Iasi, June 5-6, 2003
DVNOC Implementation Configuration Management Looking Glass user level access authorization; configuration file viewer; interfaces status and parameter viewer; IP routing table and/or single IP route viewer; routing protocols status viewer; simple debugging tools (ping and traceroute); router command line interface. Ro Conference, Iasi, June 5-6, 2003
DVNOC Implementation Performance Management The performance management component must be implemented hierarchical (SNMP) Transaction security for this component can be achieved using SNMPv3, a new SNMP protocol framework which is already available. The security component for SNMPv3 was proposed in RFC 2274 OpenSource tools Cricket and MRTG/RRD (http://cricket.sourceforge.net, http://people.ee.ethz.ch/~oetike r/webtools/) Weathermap (http://www.indiana.edu/). Ro Conference, Iasi, June 5-6, 2003
DVNOC Implementation Fault Management can be centralized is monitoring essential for fast fault isolation Specialized tools for monitoring host, routers, resources, network services (HTTP, SMTP, FTP). Features: contact notifications - email, pager, phone.; ability to define event handlers for service and host events; capability to scheduled downtime for suppressing host and service; web interface for viewing current network status, notification and problem history, log file, etc.; support for user defined plug-ins to perform service checks; hierarchical user authorization for access to the web interface; Ro Conference, Iasi, June 5-6, 2003
DVNOC Implementation Fault Management (Tools) good quality Open Source package that was tested and offers the above and more features is Nagios (http://www.nagios.org). Ro Conference, Iasi, June 5-6, 2003
DVNOC Implementation Accounting and Security Management Accounting Management There are few options for accounting management solutions using Open Source software: IPaccounting, is available from Istituto Nazionale di Fisica Nucleare, Italy Other approaches based on traffic flow Security Management A very good tool for network security management is Snort, an Open Source network intrusion detection system, capable of real-time traffic analysis packet logging on IP networks under development by Ro Iasi team (http://zazu.iasi.roedu.net). Ro Conference, Iasi, June 5-6, 2003
Trouble Ticket System Features: Web-based interface with user level authentication; Multiple queues support (administrative, technical, etc.); Interface for ticket submitting and operation via e-mail; Granular user access control (requestor, watcher, admin, owner, etc.); SQL database storage system; Hierarchical tickets linking system (parent-child relationships); Customizable templates for system messages Request Tracker (http://www.bestpractical.com/rt/) Ro Conference, Iasi, June 5-6, 2003
Conclusion DVNOC framework establishes the responsibilities of each unit involved in the management of a network structure with branches spread over a large geographical area: NMCU - work Management Coordinating Unit NMEU - work Management Executive Unit SSU - Special Solutions Units APM - Access Port Managers at each NOC Distributed and centralized strategies and opportunities for outsourcing Ro Conference, Iasi, June 5-6, 2003
Questions and Thanks Questions Thanks Ro Conference, Iasi, June 5-6, 2003