EMC PERSPECTIVE Comparing Network Change and Configuration Management Solutions When information comes together, your world moves ahead.
Network change and configuration management is central to next-generation infrastructure management. Next-generation network devices increasingly look and behave more like servers every day. Equipment vendors are continuing to decouple their software from their hardware so that they can eventually virtualize network services and applications that currently are tied to hardwarespecific modules. As a result, networking equipment increasingly will operate like a virtualized server running multiple operating systems, as well as multiple applications (such as VoIP services or security). That increasing complexity makes the role of effective and efficient network change and configuration management more critical than ever. The following tables provide a framework for comparing the major products in this market offered by HP/Opsware and with EMC s network change and configuration management solution, EMC VoyenceControl. Excellent Very Good Good Fair Poor Architecture 2 Web services/flexible API VoyenceControl offers a powerful web services and J2EE API that supports virtually all functions of the application and is designed to be future proof reducing upgrade and maintenance costs for customers. CMDB-ready architecture VoyenceControl s API and event framework make it ideal for plugging into CMDB projects and is why Voyence was the vendor of choice for the BMC pilot Atrium product. Device coverage (more than 1,300) VoyenceControl supports more than 35 different vendors covering more than 1,300 different device models. VoyenceControl s powerful and open device-driver system makes management of new devices easy. Scalable, distributed architecture VoyenceControl offers a truly distributed architecture that segments device communication and application services for optimal network management. Role-based access control VoyenceControl offers granular security controls down to specific devices, as well as the ability to restrict user access to sensitive information located on those devices. Complete web-deployed interface All products in the EMC Voyence family are either web-based or webdeployed, requiring no separate client installations to be managed. Additionally, the client is far more flexible than web-based applets. Event framework VoyenceControl offers a powerful event framework that tracks events from the network and generated by the system. These events are categorized and published via a variety of means, including e-mail, SNMP traps, and JMS.
Integration/Partnerships EMC VoyenceControl has extensive integration with EMC Smarts, linking problem and change management and providing a comprehensive management solution that delivers closed-loop service orchestration. HP Network Node Manager (NNM) VoyenceControl has an integration module with HP NNM. BMC Voyence was selected as the initial network partner for BMC s Atrium CMDB and VoyenceControl is tightly integrated with many other BMC products. Cisco RME VoyenceControl has a strong integration with Cisco RME, which has been deployed by customers worldwide. IBM Voyence has a tight integration with the NetCool product line that IBM acquired from Micromuse. Voyence has an integration with the NSM system. CA Baseline Network auto-discovery VoyenceControl offers the ability to either discover the network with ping sweeps, SNMP sweeps, or multi-hop discovery. Additionally, VoyenceControl can take a data feed from another system to populate the device repository. Configuration history VoyenceControl stores and manages the complete configuration history of the device, including who changed the device, who authorized the change, and if the change was in compliance with policy. True multi-configuration file support VoyenceControl stores and manages each configuration unit (files, hardware, diagnostics, etc.) separately, giving the customer complete information about the state of the device, its history, and who changed what. Hardware history VoyenceControl stores and manages the complete hardware history of the device. Topology information VoyenceControl determines the connections among devices and automatically generates a diagram view of the network. Abstracted device configurations VoyenceControl's attributed model abstracts device configurations into a vendor-neutral model, allowing for cross-vendor compliance tests and reporting. VoyenceControl has the only model designed to be extended without product releases. Operational data management Using its extensible attributed model, VoyenceControl can in addition to the configuration gather operational data, such as ARP and CAM tables, and Access List Match counts. Granular searching/data mining VoyenceControl has a powerful search engine to find devices based on names, hardware information, configuration settings, and other options. 3
Compliance Management Standards VoyenceControl offers a powerful system for defining your network standards, with the tools to remediate the issues found all without requiring scripting. Policies VoyenceControl offers a policy-based system that will detect standards violations in real time and give you the immediate option to correct the errors. Automated policy enforcement VoyenceControl offers a policy-based system that will detect standards violations in real time and give you the immediate option to correct the errors. Change auditing VoyenceControl stores and manages the complete configuration history of the device, including who changed the device, who authorized the change, and if the change was in compliance with policy. Compliance auditing VoyenceControl offers a powerful system for defining your network standards with the tools to remediate the issues found, all without requiring scripting. Query-based compliance Utilizing the Voyence attributed model, a user can create powerful cross-vendor queries and run compliance rules against them. Compliance reporting VoyenceControl provides detailed compliance reporting, including summary and detail information in a readily digestible graphical format. Automated resolution of devices with multiple interfaces VoyenceControl's compliance engine will continue checking a device until it finds all violations and can generate remediations to completely bring a device back into compliance. Policy assurance with autoremediation VoyenceControl's compliance policies monitor the devices in real time and can automatically schedule remediation jobs to bring wayward devices back into compliance as soon as they are modified. Keystroke logging VoyenceControl logs all keystrokes during direct device interactions (cut-through), and can mask "sensitive" data from those logs. 4
Change Management Design workspaces VoyenceControl is the only application that provides a virtual sandbox for designing new network roll-outs or changes. Job scheduling VoyenceControl offers a powerful schedule management system. Approval workflow VoyenceControl ensures that all changes taking place on the network go through proper approvals and can enforce it in the application or via integration with an external change tool. Configuration editors VoyenceControl offers four different editors to allow specific control over the type of change you are making and to make more complex changes easier. IP address management VoyenceControl offers an IP address management and allocation tool for network deployments. Mass updates VoyenceControl has many tools for making mass changes from password manager, template merge, and configlet editors. Rollback VoyenceControl provides the capability to roll a device back to any previous configuration. Password management VoyenceControl can automatically roll the credential sets on devices (including SNMPv3 keys) in a vendor-neutral method. Robust interface editor VoyenceControl can allow for the provisioning of multiple interfaces and global configurations in a powerful interface editor. This can allow for the saving/loading of "groups" for management of access lists and QoS setting as an example. Includes IP address management capabilities VoyenceControl offers IP address management tools that can automatically assign the next-available addresses to configurations. Duplicate IP address awareness VoyenceControl will alert users to the possible introduction of duplicate IP addresses. Additionally, VoyenceControl provides events to external systems when a duplicate address is detected. Templates VoyenceControl has a powerful template system that includes variable validations, bulk merges with csv files, reference variables, and integration with an IP address management system. Script import VoyenceControl has tools that allow you to use your existing Velocity, Perl or TCL/Expect scripts within the product. However, VoyenceControl's unique interface means such scripts are not required. Maintenance windows VoyenceControl has a comprehensive set of maintenance-window tools to allow for granular control of what type of activity can take place on the network at a given time. Job-conflict awareness VoyenceControl will notify engineers when they are scheduling potentially conflicting change jobs. Device drivers abstract all device communications so the user does not have to script this into each change made. VoyenceControl's device drivers abstract all the communication with the networking device so the engineer needs to only type the configuration changes he wants (as opposed to writing complicated change scripts). Automated (command) scripts VoyenceControl can automatically generate a change and/or command script based on user sessions with devices. Patch/OS management VoyenceControl has a powerful OS management capability that allows a user to deploy multiple OS changes and manage the detailed memory allocations on the device. Telnet/SSH proxy VoyenceControl offers proxy (cut-through) tools to allow engineers direct access to device command-lines when needed. 5
Security Planning stored centrally Sensitive information masking Secure device communications (SSHv2, SNMPv3, SCP, etc.) Using VoyenceControl's unique design workspaces, all change planning and design work can be stored and accessed in a secured, central environment. VoyenceControl offers the ability for customers to define their own sensitive information, which can be masked from devices configurations for unauthorized users. VoyenceControl supports many different device protocols, including SSH, SCP, SNMPv3 as well as Telnet, TFTP, FTP, and SNMPv1&2. EMC Corporation Hopkinton Massachusetts 01748-9103 1-508-435-1000 In North America 1-866-464-7381 www.emc.com EMC 2, EMC, Smarts, and where information lives are registered trademarks and Voyence and VoyenceControl are trademarks of EMC Corporation. All other trademarks used herein are the property of their respective owners. Copyright 2008 EMC Corporation. All rights reserved. Published in the USA. 03/08 EMC Perspective H4315