D.R. Network Design. The Small College Version



Similar documents
Disaster Recovery Design Ehab Ashary University of Colorado at Colorado Springs

Data Center Networking Designing Today s Data Center

IP Telephony Management

Troubleshooting and Maintaining Cisco IP Networks Volume 1

Next-Gen Securitized Network Virtualization

Virtual PortChannels: Building Networks without Spanning Tree Protocol

REFERENCE ARCHITECTURES FOR MANUFACTURING

TechBrief Introduction

CCNP SWITCH: Implementing High Availability and Redundancy in a Campus Network

Load balancing and traffic control in BGP

Recommended IP Telephony Architecture

Top-Down Network Design

Industrial Network Security for SCADA, Automation, Process Control and PLC Systems. Contents. 1 An Introduction to Industrial Network Security 1

全 新 企 業 網 路 儲 存 應 用 THE STORAGE NETWORK MATTERS FOR EMC IP STORAGE PLATFORMS

Flexible SDN Transport Networks With Optical Circuit Switching

Load balancing and traffic control in BGP

Voice Over IP. MultiFlow IP Phone # 3071 Subnet # Subnet Mask IP address Telephone.

Expert Reference Series of White Papers. Planning for the Redeployment of Technical Personnel in the Modern Data Center

White paper. Business Applications of Wide Area Ethernet

State of Texas. TEX-AN Next Generation. NNI Plan

DATA CENTER. Best Practices for High Availability Deployment for the Brocade ADX Switch

Data Center Fabric Convergence for Cloud Computing (the Debate of Ethernet vs. Fibre Channel is Over)

Network System Design Lesson Objectives

The OpenDNS Global Network Delivers a Secure Connection Every Time. Everywhere.

MS 20413A: Designing and Implementing a Server Infrastructure

CONTROL LEVEL NETWORK RESILIENCY USING RING TOPOLOGIES. Joseph C. Lee, Product Manager Jessica Forguites, Product Specialist

Ethernet Fabrics: An Architecture for Cloud Networking

Industrial Ethernet How to Keep Your Network Up and Running A Beginner s Guide to Redundancy Standards

Network Topology. White Paper

How To Load Balance On A Cisco Cisco Cs3.X With A Csono Css 3.X And Csonos 3.5.X (Cisco Css) On A Powerline With A Powerpack (C

Data Center Convergence. Ahmad Zamer, Brocade

IT-AD08: ADD ON DIPLOMA IN COMPUTER NETWORK DESIGN AND INSTALLATION

Cisco Certified Network Associate Exam. Operation of IP Data Networks. LAN Switching Technologies. IP addressing (IPv4 / IPv6)

Broadband Bonding Network Appliance TRUFFLE BBNA6401

Juniper / Cisco Interoperability Tests. August 2014

Designing and Implementing a Server Infrastructure MOC 20413

IP SAN Best Practices

VPN Solution Guide Peplink Balance Series. Peplink Balance. VPN Solution Guide Copyright 2015 Peplink

TRILL Large Layer 2 Network Solution

Deliver Fabric-Based Infrastructure for Virtualization and Cloud Computing

RESILIENT NETWORK DESIGN

PR03. High Availability

Interconnecting Cisco Networking Devices: Accelerated (CCNAX) 2.0(80 Hs) 1-Interconnecting Cisco Networking Devices Part 1 (40 Hs)

Networking 4 Voice and Video over IP (VVoIP)

SSVVP SIP School VVoIP Professional Certification

The Keys for Campus Networking: Integration, Integration, and Integration

DEDICATED NETWORKS FOR IP STORAGE

What is VLAN Routing?

IMPLEMENTING CISCO SWITCHED NETWORKS V2.0 (SWITCH)

SDN and Data Center Networks

"Charting the Course...

Jive Core: Platform, Infrastructure, and Installation

Installation of the On Site Server (OSS)

Brocade Solution for EMC VSPEX Server Virtualization

ExamPDF. Higher Quality,Better service!

How To Understand and Configure Your Network for IntraVUE

SDN and FTTH Software defined networking for fiber networks

Brocade One Data Center Cloud-Optimized Networks

HARTING Ha-VIS Management Software

DATA CENTER INTERCONNECT SICHERER UND FLEXIBLER DATENAUSTAUSCH ZWISCHEN RECHENZENTREN COPYRIGHT 2014 ALCATEL-LUCENT. ALL RIGHTS RESERVED.

Introduction about cisco company and its products (network devices) Tell about cisco offered courses and its salary benefits (ccna ccnp ccie )

13 Courses Quick Guide

Juniper Networks QFabric: Scaling for the Modern Data Center

Deployment Topologies

Migrate from Cisco Catalyst 6500 Series Switches to Cisco Nexus 9000 Series Switches

Designing and Implementing a Server Infrastructure

Network Virtualization Network Admission Control Deployment Guide

OmniCube. SimpliVity OmniCube and Multi Federation ROBO Reference Architecture. White Paper. Authors: Bob Gropman

Enabling Multiple Wireless Networks on RV320 VPN Router, WAP321 Wireless-N Access Point, and Sx300 Series Switches

Cisco Advanced Services for Network Security

Demonstrating the high performance and feature richness of the compact MX Series

Configuring the Transparent or Routed Firewall

Contents. Foreword. Acknowledgments

Networking. Sixth Edition. A Beginner's Guide BRUCE HALLBERG

MPLS provides multi-site solution

ITL BULLETIN FOR JANUARY 2011

Disaster-Resilient Backbone and Access Networks

Cisco Networking Academy CCNP Multilayer Switching

Adapting MPLS Fast Reroute to Create Resilient Rings

Broadband Bonding Network Appliance TRUFFLE BBNA6401

Address Scheme Planning for an ISP backbone Network

How Proactive Business Continuity Can Protect and Grow Your Business. A CenturyLink White Paper

ITKwebcollege.ADMIN-Basics Fundamentals of Microsoft Windows Server

High Availability Failover Optimization Tuning HA Timers PAN-OS 6.0.0

Configuring Dual VPNs with Dual ISP Links Using ECMP Tech Note PAN-OS 7.0

Feature Comparison. Windows Server 2008 R2 Hyper-V and Windows Server 2012 Hyper-V

Using Virtual Switches in PowerVM to Drive Maximum Value of 10 Gb Ethernet

Vocia MS-1 Network Considerations for VoIP. Vocia MS-1 and Network Port Configuration. VoIP Network Switch. Control Network Switch

Isilon IQ Network Configuration Guide

Connect Converge / Converged Infrastructure

Building a small Data Centre

TRILL for Service Provider Data Center and IXP. Francois Tallet, Cisco Systems

Intel Ethernet Switch Load Balancing System Design Using Advanced Features in Intel Ethernet Switch Family

Network Virtualization and Data Center Networks Data Center Virtualization - Basics. Qin Yin Fall Semester 2013

Radware ADC-VX Solution. The Agility of Virtual; The Predictability of Physical

Networking Topology For Your System

Transcription:

D.R. Network Design The Small College Version

Disaster Recovery Complex, far-reaching I.T. topic Our focus Improve network design to: Enhance ability to recover following a disaster Eliminate or limit effects of some disasters Accomplish improvements Without LOTS of money/people/rocket science By maximizing our inherently distributed, but very useful geography! 2

Common Roots Distributed geography Expensive network build-out A financial enemy A typical history Star topology network Collapsed core Evolutionary development Limit large 1-time expenses Maintain simplicity 3

Potential Pitfalls 4 Centralized resources Single point of failure Arduous recovery Risk = T x V x I Threat Vulnerability Impact (time+money+reputation) Impact increasing dramatically Greater complexity More mission-critical services

What did we do? Over a period of three years: Built consensus around the importance of BC/DR resulting in the development of a strategy Deployed a backup data center to house test/recovery services Distributed network core to four building, using a partial mesh design with OSPF routing Replication of mission critical data between primary and backup data centers 5

Building consensus Involve senior management. Educate! Knowledge is power. Ask for help You do not know all the answers! Enables collaboration and encourages broader ownership 6

Backup Data Center 7 Build-out location for disaster recovery Enables faster operational setup Location Collectively identify a site Physically separate from primary data center Well-connected Devise a fiscal plan Ours was a two-year plan: total cost ~$50k Devise a construction plan Distributed geography is now your friend!

Containing Data Center Costs Use internal resources when possible Install used components when reasonable Raised floor Cabinets UPS, but buy new batteries Start small, but with room to grow quickly! 8

Distributed Network Core Advantages: More is better -- eliminate the SPoF! Increased resiliency A layer 2 or 3 protocol can bypass failures Disadvantages: Increased complexity Geography is now your BEST friend! 9

How to distribute a network core Identify 3+ locations Should facilitate aggregation of fiber links. Available pathways to interconnect all locations. Adequate power and environmental controls. Choose a multi-path network design/protocol Ring Mesh Install links/equipment/protection protocol 10

Ring or mesh? Ring Fewer interconnections / lower cost Possibly increased hop count (L2/3) Mesh Full mesh requires r!/n!(r-n)! links, where r = number of locations, and n = 2. Full mesh = direct link between any two nodes Higher cost 11

L2 or L3 Protection Scheme? 12 Layer 2 Resilient Packet Ring (RPR), IEEE 802.17 SONET-like protection/recovery times Designed for metro networks Expensive; YMMV Proprietary Ethernet ring protection schemes E.g. Ethernet Automatic Protection Switching, RFC 3619 SONET-like protection/recovery times No standardized implementations with interoperability tests; YMMV HSRP, Spanning Tree Protocol

L2 or L3 Protection Scheme? Layer 3 Routing protocols Well understood Reliable and mature implementations Converge in seconds Faster is not always better Interoperability tested for many kinds of equipment(*) Requires IP address space provisioned by location rather than function! 13

We chose OSPF! Standard, non-proprietary Converges slower than fastest L2 options! May be less prone to flapping when faced with transient events. Allows injection of addresses into L3 cloud Default gateway IP AnyCast addresses for query/response protocols, e.g. DNS, RADIUS 14

Gotcha! Re-numbering was required Our IP address spaces were coalesced by function and not by geographic location. Addresses MUST be unique by geography, but CAN be coalesced by: Geography first, then by function (small routing table) Function first, then by geography (shorter ACLs) Done over a weekend after weeks of planning Perl-generated automated scripts for network gear and services (DNS,DHCP) DHCP helped for many devices SneakerNet for other devices, plus testing 15

Address Space by Geography 3 10.0.128.0/18 Acad, Stu, Admin, Labs 4 10.0.192.0/18 Acad, Stu, Admin, Labs 2 10.0.64.0/18 Acad, Stu, Admin, Labs 1 10.0.0.0/18 Acad, Stu, Admin, Labs 16

Address Space by Function 3 Acad 10.0.32.0/20 Stu 10.0.96.0/20 Admin 10.0.160.0/20 Labs 10.0.224.0/20 2 Acad 10.0.16.0/20 Stu 10.0.80.0/20 Admin 10.0.144.0/20 Labs 10.0.208.0/20 4 Acad 10.0.48.0/20 Stu 10.0.112.0/20 Admin 10.0.176.0/20 Labs 10.0.240.0/20 1 Acad 10.0.0.0/20 Stu 10.0.64.0/20 Admin 10.0.128.0/20 Labs 10.0.192.0/20 17

Why was re-numbering good? Eliminate network policy implementation inaccuracies reflected in real configurations. Completely re-worked network security policies, e.g. firewall rules, core ACLs, etc. Cleaned up DHCP and DNS Improve VLAN tag numbering scheme Numbered each network core location. Used these as prefix for VLANs at those nodes. Router/L3 switch interface address schemes 18

The results 19 OSPF area 0 used for core with a single /24, but /29 s per link Separate OSPF area for each core node F/W runs OSPF and injects default route Hosts -> upstream core node as def. g/w

Benefits 20 Increased flexibility Route around link failures Easily reconfigured in disaster recovery mode Shorten recovery time Increased reliability Windows DCs, DNS, and some ERP supporting hardware distributed between data centers IP AnyCast can provide diverse routes Replicate key data from iscsi SAN to backup data center

Next steps [Re-]terminate more fiber in new core sites Better load-balancing of traffic Reduced impact of failure at any single core node 21

Points to remember Improving disaster preparedness does not necessarily have to involve huge investments Evolutionary vs. revolutionary A staged approach is More easily assimilated into I.T. culture Fiscally achievable 22

Points to remember D.R. network design does not need to be complex Can be done without big investments in: Infrastructure Human resources Professional development (no rocket science) Take advantage of your geography!!! 23

Thank you! Questions? Discussion?