ccdp arch

168
CCDP Arch

Upload: hendra-mulyanto

Post on 08-Jun-2015

832 views

Category:

Design


2 download

TRANSCRIPT

Page 1: Ccdp arch

CCDP Arch

Page 2: Ccdp arch

Modular Network Design

Page 3: Ccdp arch

Distribution Layer

Page 4: Ccdp arch

Core Layer

Page 5: Ccdp arch

Is Core Layer Needed ?

Page 6: Ccdp arch

Optimal Redundancy

Page 7: Ccdp arch

Provide Alternate Paths

Page 8: Ccdp arch

Avoid Single Points of Failure

Page 9: Ccdp arch

Deterministic Design

Page 10: Ccdp arch

Layer 2 Hardening

Page 11: Ccdp arch

Topology for UDLD

Page 12: Ccdp arch

Etherchannels

Page 13: Ccdp arch

VSS Logical vs Physical Topology

Page 14: Ccdp arch

Access Distribution Block Design

Page 15: Ccdp arch

VSS and MEC

Page 16: Ccdp arch

VSS Logical Topology

Page 17: Ccdp arch

Build Redundant Triangle

Page 18: Ccdp arch

Use Passive Interfaces at the Access Layer Triangles

Page 19: Ccdp arch

Summarize at the Distribution Layer Triangles

Page 20: Ccdp arch

Gateway Load Balancing Protocol Triangles

Page 21: Ccdp arch

GLBP VLAN Spanning Triangles

Page 22: Ccdp arch

GLBP and STP Tuning Triangles

Page 23: Ccdp arch

Layer 2 Distribution Switch Interconnection

Page 24: Ccdp arch

Layer 3 Distribution Switch Interconnection Triangles

Page 25: Ccdp arch

Layer 3 Distribution Switch Interconnection with GLBP

Page 26: Ccdp arch

VSS Layer 3 Interconnect

Page 27: Ccdp arch

Layer 3 Access to Distribution Interconnection

Page 28: Ccdp arch

Daisy Chaining Layer Access Switches

Page 29: Ccdp arch

StackWise Technology

Page 30: Ccdp arch

Too Little Redundancy

Page 31: Ccdp arch

Impact of an Uplink Failure

Page 32: Ccdp arch

Impact on Return-Path Traffic

Page 33: Ccdp arch

Asymmetric Routing

Page 34: Ccdp arch

IP Telephony Extends the Network Edge

Page 35: Ccdp arch

Campus QoS Design Consideration

Page 36: Ccdp arch

Route Summarization

Page 37: Ccdp arch

Originating Default Routes

Page 38: Ccdp arch

Avoid Inappropiate Transit Traffic

Page 39: Ccdp arch

Defensive Filtering

Page 40: Ccdp arch

Scaling EIGRP with Multiple Autonomous System

Page 41: Ccdp arch

Example: External Route Redistribution Issue

Page 42: Ccdp arch

Filtering EIGRP Redistribution with Route Tags

Page 43: Ccdp arch

Filtering EIGRP Routing Updates with Inbound Route Tags

Page 44: Ccdp arch

Example: Queries with multiple EIGRP Autonomous System

Page 45: Ccdp arch

OSPF Hierarchy

Page 46: Ccdp arch

Area and Domain Summarization

Page 47: Ccdp arch

Number of Areas in Hub and Spoke Design

Page 48: Ccdp arch

Issues with Hub and Spoke Design

Page 49: Ccdp arch

OSPF Area Border Connection Behaviour

Page 50: Ccdp arch

IBGP Full Mesh Requirement

Page 51: Ccdp arch

BGP Route Reflectors

Page 52: Ccdp arch

BGP Route Reflector Definitions

Page 53: Ccdp arch

Route Reflector Basics

Page 54: Ccdp arch

Confederation Definitions

Page 55: Ccdp arch

IBGP Full Mesh Peering

Page 56: Ccdp arch

Confederations Reduce the Number of IBGP Peers

Page 57: Ccdp arch

Deploying Confederations

Page 58: Ccdp arch

CWDM Technical Overview

Page 59: Ccdp arch

DWDM Technical Overview

Page 60: Ccdp arch

RPR Customer View

Page 61: Ccdp arch

Metro Ethernet Architechture

Page 62: Ccdp arch

End to End QoS

Page 63: Ccdp arch

Hierarchical VPLS Overview

Page 64: Ccdp arch

Managed Router combined with Internal Routing

Page 65: Ccdp arch

Managed Router from two Service Provider

Page 66: Ccdp arch

Example of PfR in the Enterprise

Page 67: Ccdp arch

SAN Overview

Page 68: Ccdp arch

Direct-Attached Storage

Page 69: Ccdp arch

Network Attached Storage

Page 70: Ccdp arch

FICON

Page 71: Ccdp arch

SANTap

Page 72: Ccdp arch

Major SAN Design Factors

Page 73: Ccdp arch

Single-Switch Collapse-Core Design

Page 74: Ccdp arch

Small Scale Dual Fabric: Collapsed Core Design

Page 75: Ccdp arch

Medium Scale, Dual Fabric Collapse-Core Design

Page 76: Ccdp arch

Large Scale, Dual Fabric Core-Edge Design

Page 77: Ccdp arch

SAN Extension

Page 78: Ccdp arch

FCIP

Page 79: Ccdp arch

iSCSI

Page 80: Ccdp arch

SAN Extension Development

Page 81: Ccdp arch

High-Availability SAN Extension

Page 82: Ccdp arch

Before I/O Consolidation

Page 83: Ccdp arch

After I/O Consolidation

Page 84: Ccdp arch

Nexus in the Access Layer

Page 85: Ccdp arch

FCoE VLAN to VSAN Mapping and VLAN Trunking

Page 86: Ccdp arch

Typical Ecommerce Module Topology

Page 87: Ccdp arch

Logical Representation using a Server as an Application Gateway

Page 88: Ccdp arch

Implementing Virtualization with Firewall Context

Page 89: Ccdp arch

A Firewall runs in Either Transparent or Route Mode

Page 90: Ccdp arch

Example use of a Firewall in Transparent Mode

Page 91: Ccdp arch

A Server Load Balancer represents Multiple Servers

Page 92: Ccdp arch

A SLB in Route Mode Routes between Outside and Inside Subnets

Page 93: Ccdp arch

A SLB in Inline Bridge Mode Bridges Between VLAN in a Single Subnet

Page 94: Ccdp arch

A SLB in one armed mode isn’t inline with the Traffic

Page 95: Ccdp arch

Traffic Flow with Misconfiguration

Page 96: Ccdp arch

Traffic Flows Correctly when the One-Arm SLB is configured with Client NAT

Page 97: Ccdp arch

Using one Firewall per ISP

Page 98: Ccdp arch

Using Statefull Failover with a Common External Prefix

Page 99: Ccdp arch

Using Distributed Data Centers

Page 100: Ccdp arch

Data Center Services includes Statefull Firewall, SSL Offload, SLB, WAFs, IPS

Page 101: Ccdp arch

Base E-Commerce Module Design

Page 102: Ccdp arch

Base E-Commerce Module Design Routing Logic

Page 103: Ccdp arch

E-Commerce Module Design with Two Firewall Layers

Page 104: Ccdp arch

E-Commerce Module One Armed SLB Design with Two Firewall Layers

Page 105: Ccdp arch

E-Commerce module One-Armed SLB Design with Firewall Contexts

Page 106: Ccdp arch

E-Commerce Module one Armed Design with ACE

Page 107: Ccdp arch

Simple Zone Based Firewall with Three Zones

Page 108: Ccdp arch

Virtual Firewall Overview

Page 109: Ccdp arch

MSFC Placement

Page 110: Ccdp arch

Active/Active Firewall Topology

Page 111: Ccdp arch

Asymmetric Routing with ASR Group on a Single FWSM

Page 112: Ccdp arch

Asymmetric Routing with Active/Active Topology

Page 113: Ccdp arch

Load Balancing FWSM using PBR

Page 114: Ccdp arch

Load Balancing FWSM using ECMP Routing

Page 115: Ccdp arch

Isolated Ports on FWSM in Routed Mode

Page 116: Ccdp arch

Community Ports on FWSM in Routed Mode

Page 117: Ccdp arch

NAC Comparison

Page 118: Ccdp arch

Process Flow with the NAC Appliance

Page 119: Ccdp arch

Cisco NAS Gateway Modes

Page 120: Ccdp arch

Cisco NAC Appliance Redundancy Design

Page 121: Ccdp arch

Layer-2 in Band Design

Page 122: Ccdp arch

Layer 2 In-Band Virtual Gateway

Page 123: Ccdp arch

Layer 2 In-Band Real IP Gateway

Page 124: Ccdp arch

Layer 2 Out of Band Virtual Gateway

Page 125: Ccdp arch

Layer 3 In-Band Virtual Gateway

Page 126: Ccdp arch

Layer 3 In-Band with Multiple Remotes

Page 127: Ccdp arch

Layer 3 OOB with Addressing

Page 128: Ccdp arch

NAC Framework

Page 129: Ccdp arch

IDS and IPS Overview

Page 130: Ccdp arch

IPS Appliance Deployment Options

Page 131: Ccdp arch

Scaling Cisco Security MARS with Global Controller Deployment

Page 132: Ccdp arch

Remote Access VPN

Page 133: Ccdp arch

VPN Architechture

Page 134: Ccdp arch

WAN Replacement with VPN

Page 135: Ccdp arch

WAN Backup via VPN

Page 136: Ccdp arch

VPN Device Placement: Pararel with Firewall

Page 137: Ccdp arch

VPN Device on a Firewall DMZ

Page 138: Ccdp arch

Integrated VPN and Firewall

Page 139: Ccdp arch

IPSec VPN

Page 140: Ccdp arch

GRE over IPSec

Page 141: Ccdp arch

DMVPN Topology

Page 142: Ccdp arch

GET VPN Topology

Page 143: Ccdp arch

Unicast versus Multicast

Page 144: Ccdp arch

IP Multicast Groups Define who receives Multicast data

Page 145: Ccdp arch

Cisco Multicast Architechture

Page 146: Ccdp arch

IGMPv3: Joining a Group

Page 147: Ccdp arch

IGMP and CGMP inform Network Devices about Which host want which Multicast data

Page 148: Ccdp arch

Multicast Distribution Tree are created by Routers

Page 149: Ccdp arch

Source Distribution Tree for Source 1

Page 150: Ccdp arch

Separate Source Tree is build for Source 2 sending to the Group

Page 151: Ccdp arch

Sources send toward the RP and the RP Sends to the Receivers

Page 152: Ccdp arch

PIM-SM Shared Tree Join

Page 153: Ccdp arch

PIM-SM Sender Registration Process

Page 154: Ccdp arch

PIM-SM Source Tree Switchover

Page 155: Ccdp arch

Bidir-PIM is Efficient for Many to many Communication

Page 156: Ccdp arch

SSM Join Process

Page 157: Ccdp arch

SSM Source Path Tree Creation

Page 158: Ccdp arch

With Anycast RP, the RP Load Share and act as a Hot Backup for each other

Page 159: Ccdp arch

Auto-RP Announcement Go to 224.0.1.39

Page 160: Ccdp arch

Auto-RP Discovery Messages Go to 224.0.1.40

Page 161: Ccdp arch

To Elect an Active BSR, C-BSR send BSR Messages on All Interfaces

Page 162: Ccdp arch

The Active BSR sends the Entire List of C-RP in Periodic BSR Messages

Page 163: Ccdp arch

Multicast Replication Impacts where Access Control should be Applied

Page 164: Ccdp arch

Network for Packet Filter-Based Access Control

Page 165: Ccdp arch

Network for Host Receiver-Based Access Control

Page 166: Ccdp arch

Network for PIM-SM Source Control

Page 167: Ccdp arch

Application Optimization Technologies

Page 168: Ccdp arch

Apply Netflow Monitoring