Showing posts with label Network. Show all posts
Showing posts with label Network. Show all posts

Friday, 17 December 2010

Information Technology Training CCNA Certification Network Design Concepts (640-863 DESGN)

A CCNA Exam seminar allows a basic foundation of network design of Cisco integrated networks based on the Cisco Service-Oriented Network Architecture and is intended as an additional study book for the 640-863 DESGN certification exam.

Certified professionals design routed and switched network infrastructures and services including LAN, WAN, and broadband access.

The related CCNA Exam: Designing for Cisco Internet work Solutions Exam (640-863 DESGN)

In order to get pass this exam you will need to learn to:

* Apply best practices according to Cisco's Service oriented Network Architecture model

* Design scalable and secure routed and switched enterprise LAN, WAN, broadband as well as wireless networks

* Select the appropriate Cisco devices according the pre-settings of the design

Prerequisites: CCNA-level experience is required to successfully understand the concepts presented in this workshop and prepare for the exam.

A list of some of the subjects you will learn:

Cisco Intelligent Information Network. Getting Started with Cisco Service-Oriented Network Architecture, Cisco As networks and applications built using its Intelligent Information Network. Prepare, plan, design, implement, manage, and optimize (PPDIOO)

The top-down system and network analysis. Ensure that the organizational and technical problems and constraints with a "top down".Tasks and guides to collect customer input and current network infrastructure. Utilities and procedures for assessing, testing and analyzing the current network

Documentation and Testing. The Design Document Cisco and 3rd party Network Management utilities and protocols

Network Hierarchy and Organization Architecture. The Three-layer Hierarchical Network System (Access, Distribution and Core). The six sections of Enterprise Architecture. Methods to set redundancy in the Network

Here is a short clip that the material in this way a course for CCNA Exam Reviews

CCNA Exam

Thursday, 9 December 2010

Computer Network Routers, Hubs, and Switches

When computer networks are working well, which we hope is most of the time, the inner workings of the system modules are transparent to the average user. The most common components on a computer network, not counting cables, are "routers", "hubs", and "switches". Many of these modules can be similar cosmetically. Each assembly typically has Ethernet connectors (RJ45, which looks like an oversized telephone plug) and LED indicators. However, these modules function differently, and it is important to understand the differences.

Modern network hardware operates on the "Open System Interconnection" (OSI) standard. This standard defines how communications on a network should be implemented. By conforming to this standard, modules from different manufacturers can coexist on the same network. Wireless networks (WiFi) and the 802.11X standard are an additional subset of network systems.

When a message is sent between computers, it is broken into parts. At the base level, the message is reduced to "1" and "0" bits. The next level is a group of bits called a "frame". A frame contains its control information, including target address and error detection. The next level is a group of frames called a "packet". The terms frame and packet are sometimes used interchangeably. If a message is sent on a complex network like the Internet, some of the packets may take a otherwise, and met at the destination.

Tracking error with two frames and packages used. The most common procedure is called "cyclic redundancy check (CRC). Sums CRC of all" 1 "in the frame or packet. This number in hex at the end of frame / packet is stored. On the receiving side, the process is repeated . If I have the two hexadecimal values, is the proof. Otherwise, the receiver requests that the sending deviceresend. Most of this functionality is performed by integrated circuits (chips) inside the network modules.

The Hub

The network hub operates on the first layer of the OSI standard, called the "physical layer". The hub is the most simple of the three modules. A hub is not aware of the contents of the message that is processed; it handles the message as bits. It simply records the signal, and rebroadcast it to all, including back to the port that sent the message. An "active" hub will clean the electrical signal of noise and amplify the signal before rebroadcast. A "passive" hub does not amplify the received signal; it merely receives a signal, and rebroadcast the signal as received to each port. Hubs are sometimes used to link multiple computers with a printer.

The Network Switch

The network switch operates on the second layer of the OSI standard, called the "data link layer". The network switch, as indicated by its name, switches signal paths, so that a message frame goes to a specific destination. A switch will improve a networks performance, especially on networks with many computers. A switch has enough on-board intelligence to remember the path to each destination. The network switch handles a message in frames. 

When you connect a computer to a network switch, the switch will record the Media Access Control or "MAC" address of the computer's network interface card (NIC). This is called address protocol, or "ARP". When a frame is received intended for a specific computer, the switch sends the frame only to that computer. By preventing paths of the network from being utilized by every frame, network resources are conserved. Computer A can send a frame to computer B, while simultaneously, computer C is sending a frame to computer D.

The Network Router

The network router operates on the third layer of the OSI standard, called the "network layer". A router's name is also indicative of its role. Routers have some of the same capabilities as switches, but routers are most often used to connect two or more networks. For example, a router could be used to connect a wireless network with a conventional local area network (LAN). Another common use is to connect a LAN with the Internet (a "wide-area network", or "WAN"). In this role, the router uses "Network Address Translation" (NAT) so that all of the computers attached to the LAN can share a single IP address. A network router handles the message in packets. A router uses the IP addresses in the packets to route them between multiple networks.

A personal computer can be configured to handle the function of a router if it is equipped with router software and two or more network interface cards (NIC). A separate NIC is needed for each network.

A router is capable of advanced functions, including serving as DHCP (domain host control protocol) server and Firewall. A Firewall protects computers from potential hazards from the other computers outside the network. Linking multiple networks often requires the conversion of protocols. 

A router is an extremely diverse classification. Routers may provide connectivity inside offices, between different locations, and between businesses and the Internet. The largest routers connect Internet service providers, are used in very large business networks, or connect a business with a satellite link to a distant corporate locale. Advanced routers are powerful computers, complete with microprocessors. Very sophisticated routers are used by the Internet to manage the network traffic most efficiently. 

A router maintains a table called "routing information base" (RIB) that tracks information about the available routes. The RIB can be static (manually determined by a network administrator) or dynamic (continually updated based on changing conditions). A RIB is simple on a small LAN, but can be extremely complex in the very large routers used on the Internet.

Summary

There are more types of network modules than the three discussed here, and there can be significant overlap in roles. For example, an "intelligent hub" can have many of the characteristics of a network switch. Wireless networks (WAN) have much in common with their conventional LAN cousins, but additional protocol is added for the special security and interference concerns specific to wireless networks. Multiple roles may be combined into a single assembly. Network routers sometimes have subassemblies that function as network switches.  

Sunday, 14 November 2010

Network Security Across the Enterprise - Stop Gap Measures to Help You Protect Your Network

Today's business networks consist of numerous remote access connections from employees and outsourcing firms. Too often, the inherent security risks arising from these connections outside the network are overlooked. Continuous improvements have been made that can enhance security in today's network infrastructure; taking particular focus on the users accessing the network externally and monitoring access end- points are critical for businesses to protect their digital assets.

Installing the correct software for the specific needs of your IT infrastructure is essential to having the best security protection possible. Many companies install "off the shelf" security software and assume they are protected. Unfortunately, that is not the case due to the nature of today's network threats. Threats are diverse in nature, including the usual spam, spyware, viruses, trojans, worms, and the occasional possibility that a hacker has targeted your servers.

The to neutralize an appropriate security solution for your business almost all of these threats to the network. Too often installed with a software package, network administrators spend much of their time to defend the integrity of its network perimeter to prevent attacks by the hand and then manually patch the security hole.

Pay for network administrators to protect the integrity of the network is an expensive affair - much more than installing the rightsecurity solution that your network requires. Network administrators have many other responsibilities that need their attention. Part of their job is to make your business operate more efficiently - they can't focus on this if they have to manually defend the network infrastructure all the time.

Another threat that must be considered is the threat occurring from within the perimeter, in other words, an employee. Sensitive proprietary information is most often stolen by someone on the payroll. A proper network security solution must guard against these kinds of attacks also. Network administrators definitely have their role in this area by creating security policies and strictly enforcing them.

A smart strategy to give your network the protection it needs against the various security threats is a layered security approach. Layered security is a customized approach to your network's specific requirements utilizing both hardware and software solutions. Once the hardware and software is working simultaneously to protect your company, both are able to instantaneously update their capabilities to handle the latest in security threats.

Security software can be configured to update multiple times a day if the need be; hardware updates usually consist of firmware upgrades and an update wizard much like that present within the software application.

All-in-one Security Suites A multi-pronged strategy should be implemented to combat the multiple Sources of threats to enterprise networks today. Too often the sources of those threats arrive in spam with Trojans or spyware installation inside a hidden software overlap. Combating these threats requires the use of firewalls, anti-spyware, malware and spam protection.

Recently, the trend in the software industry has been to combine these previously separate security applications into a complete security suite. security applications in accordance withEnterprise networks are security suites that integrate to focus on a common goal. These security suites include antivirus, anti-spyware, anti-spam and firewall, all gathered in one application. Find the best stand-alone applications in each category of security risk is still an option, but not a necessity.

The all-in-one security suite, a software company money to purchase reduced cost and save time with the ease of integrated management ofvarious threat sources.

Trusted Platform Module (TPM) A TPM is a standard developed by the Trusted Computing Group defining hardware specifications that generate encryption keys. TPM chips not only guard against intrusion attempts and software attacks but also physical theft of the device containing the chip. TPM chips work as a compliment to user authentication to enhance the authentication process.

Authentication describes all processes involved in determining whether a user granted access to the corporate network is, in fact, who that user claims to be. Authentication is most often granted through use of a password, but other techniques involve biometrics that uniquely identify a user by identifying a unique trait no other person has such as a fingerprint or characteristics of the eye cornea.

Today, TPM chips are often integrated into standard desktop and laptop motherboards. Intel began integrating TPM chips into its motherboards in 2003, as are other motherboard manufacturers. If a motherboard, this chip features within the specifications of the motherboard to be present.

These chips can encrypt data at the local level and greater security in a remote place such as WiFi hotspots full of computer users that seems harmless, malicious hackers to get bored. Enterprise and Ultimate versions of Microsoft Windows Vista operating system using this technology within the BitLocker Drive Encryptionfeature.

While Vista does provide support for TPM technology, the chips are not dependent upon any platform to function.

TPM has the same functionality on Linux as it does within the Windows operating system. There are even specifications from Trusted Computing Group for mobile devices such as PDAs and cell phones.

To use TPM enhanced security, network users only need to download the security policy to their desktop machine and run a setup wizard that will create a set of encryption keys for that computer. Following these simple steps significantly improves security for the remote computer user.

Admission Based on User Identity Establishing a user's identity depends upon successfully passing the authentication processes. As previously mentioned user authentication can involve much more than a user name and password. Besides the emerging biometrics technology for user authentication, smart cards and security tokens are another method that enhances the user name/password authentication process.

The use of smart cards or security tokens adds a hardware layer requirement to the authentication process. This creates a two-tier security requirement, one a secret password and the other a hardware requirement that the secure system must recognize before granting access.

Tokens and smart cards operate in essentially the same fashion but have a different appearance. Tokens take on the appearance of a flash drive and connection through a USB port while smart cards require special hardware, a smart card reader, that connects to the desktop or laptop computer. Smart cards often take on the appearance of an identification badge and may contain a photo of the employee.

However authentication is verified, once this happens a user should be granted access through a secure virtual network (VLAN) connection. A VLAN establishes connections to the remote user as if that person was a part of the internal network and allows for all VLAN users to be grouped together within distinct security policies.

Remote users connecting through a VLAN should only have access to essential network resources and how those resources can be copied or modified should be carefully monitored.

Specifications established by the Institute of Electrical and Electronics Engineers (IEEE) have resulted in what is known as the secure VLAN (S-VLAN) architecture. Also commonly referred to as tag-based VLAN, the standard is known as 802.1q. It enhances VLAN security by adding an extra tag within media access control (MAC) addresses that identify network adapter hardware within a network. This method will prevent unidentified MAC addresses from accessing the network.

Network Segmentation This concept, working hand-in-hand with VLAN connections, determines what resources a user can access remotely using policy enforcement points (PEPs) to enforce the security policy throughout the network segments. Furthermore, the VLAN, or S-VLAN, can be treated as a separate segment with its own PEP requirements.

PEP works with a user's authentication to enforce the network security policy. All users connecting to the network must be guaranteed by the PEP that they meet the security policy requirements contained within the PEP. The PEP determines what network resources a user can access, and how these resources can be modified.

The PEP for VLAN connections should be enhanced from what the same user can do with the resources internally. This can be accomplished through network segmentation simply be defining the VLAN connections as a separate segment and enforcing a uniform security policy across that segment. Defining a policy in this manner can also define what internal network segments the client can access from a remote location.

Keeping VLAN connections as a separate segment also isolates security breaches to that segment if one were to occur. This keeps the security breach from spreading throughout the corporate network. Enhancing network security even further, a VLAN segment could be handled by it's own virtualized environment, thus isolating all remote connections within the corporate network.

Centralized Security Policy Management Technology hardware and software targeting the different facets of security threats create multiple software platforms that all must be separately managed. If done incorrectly, this can create a daunting task for network administration and can increase staffing costs due to the increased time requirements to manage the technologies (whether they be hardware and/or software).

Integrated security software suites centralize the security policy by combining all security threat attacks into one application, thus requiring only one management console for administration purposes.

Depending on the type of business you're in a security policy should be used corporate-wide that is all-encompassing for the entire network. Administrators and management can define the security policy separately, but one overriding definition of the policy needs to be maintained so that it is uniform across the corporate network. This ensures there are no other security procedures working against the centralized policy and limiting what the policy was defined to implement.

Not only does a centralized security policy become easier to manage, but it also reduces strain on network resources. Multiple security policies defined by different applications focusing on one security threat can aggregately hog much more bandwidth than a centralized security policy contained within an all-encompassing security suite. With all the threats coming from the Web, ease of management and application is essential to maintaining any corporate security policy.

Frequently asked Questions:

1. I trust my employees. Why should I enhance network security?

Even the most trusted employees can pose a risk of a network security breach. It is important that employees follow established company security standards. Enhancing security will guard against lapsing employees and the occasional disgruntled employee seeking to cause damage to the network.

2. Do these innovations really create a secure environment for remote access?

Yes they do. These enhancements not only greatly enhance a secure VLAN connection but they also use widely accepted standards that are often integrated into common hardware and software. It's there, your company only needs to start using the technology.

3. My company is happy with using separate software, that way each application can focus on a separate security threat. Why should I consider an all-in-one security suite?

Many of the popular software applications commonly used by businesses have expanded their focus to identify all security threats. This includes solutions from both software and hardware appliance technology manufacturers. Many of these firms saw the need to consolidate security early on and purchased smaller software firms to gain that knowledge their firm was lacking. A security suite at the application level, will make management much easier and your IT staff will thank you for it.

4. Do I need to add a hardware requirement to the authentication process?

Requiring the use of security tokens or smart cards should be considered for employees accessing the company network from a remote site. Particularly if that employee needs to access sensitive company information while on the road, a simple flash drive secure token prevents a thief from accessing that sensitive data on a stolen laptop.

5. With all this concern about WiFi hotspots should employees be required not to use these locations to connect to the company network?

WiFi hotspots have sprung up nationwide and present the easiest method for your remote employees to access the Internet. Unfortunately, hotspots can also be full of bored, unemployed hackers who have nothing better to do than find a way to intercept a busy employee's transmissions at the next table. That's not to say employees on the road should avoid hotspots. That would severely limit them from accessing the network at all. With technologies like S-VLAN and secure authentication in place, a business can implement technologies to reduce threats both now and in the future.

Implementing the latest network security technologies is a high priority for IT Management. In today's network environment with many users accessing your digital assets remotely, it's critical to get your network security correct during the planning phase of the integration process.

Obviously, it should be noted that most large companies have multiple operating systems running (Windows, Mac O/S, etc) and that for many of these companies all-in-one security suites face certain challenges in a mixed operating system environment.

That is why I stress that you consider having layered security (both hardware and software) and don't simply rely on software applications to protect your digital assets. As technology changes so do the opportunities for security breaches.

As these security threats become more sophisticated, hardware and software developers will continue to innovate and it's essential businesses keep up with, and implement these technologies.

Tuesday, 2 November 2010

Juniper AX411 Premium Wireless Access Point is an ideal solution for branch network

One of the difficulties for the company, its subsidiaries with less IT support is the extension of secure system for its branches. After employees technical skills (especially security) in each of the branches lead to structural costs. In modern societies with multiple offices, the integration of the communication system between headquarters and branch offices is a must for business productivity. However, connects the settlements, the have a low-security will only security holes and vulnerabilities to the headquarters and the corporate network as a whole.

One of the shortcomings, the holes on the safety of the branches, the use of the wireless network that is not properly designed with safety. wireless access to corporate data without limiting guests to access the network can provide the security that affect the system. Provide any data encryption for> Wireless communication is very dangerous for the system, the unauthorized users can easily access.

Many network administrators find it difficult to extend the protection of security are well protected from fixed to wireless networks. This is sometimes caused by the difficulty of integration of various networking products from different manufacturers. In addition, the last thing in security operations of the radioNetworks for many network administrators. And 'so the choice of premium wireless access points in wireless networking for remote offices is very important to reduce a compromise safety. The access points available to secure your wired network can be integrated.

Juniper AX411 Wireless LAN Access Point, SRX series is combined with the Juniper would be an ideal solution for branch offices and helps network administratorsManagement and design for both wired and wireless security. AX411 is designed for branch offices of enterprise-class companies. If your home or office SOHO build, you can consider the points cheaper, such as DAP-1522 Wireless-N Access Point from D-Link duo.

Which product is

Juniper AX411 Wireless LAN Access Point is built with the latest technology wireless 802.11n 2x3 MIMO dual-band and providesSpeed up to 300Mbps. With support for dual-band, AX411, the host species of 2.4 GHz and 5 GHz wireless devices based on both.

AX411 is designed to be easily integrated with the award-winning Juniper Branch. This provision allows for centralized management and security levels of the wired network to wireless networks easy. The combination of the AX411 and SRX-series Gateway you can extend the security and Quality of Service (QoS) requirementswireless networks easily.

Juniper AX411 Wireless LAN Access Point supports multiple SSIDs that you separate the security requirements for different user groups, which provide different levels of security access to corporate information, customers without access to the internal network. You can match any offer unique SSID and security with the specific requirements for QoS policies for your enterprise security.

AX411 is designed to support future cluster cloning technologyPoints to networks to facilitate the deployment of multiple access for wireless large. The good thing with the integration of the SRX-series is that the SRX wireless controller provides expertise in the management of up to 2 AX411 Access Point. But, you should run more than two AX411 devices require, you must purchase additional software licenses.

Juniper AX411 Wireless LAN Access Point supports 802.3af Power over Ethernet (PoE) to help install the equipmentin the region where power outlets are like the installations covered. Simply connect the AX411 Gigabit Ethernet LAN with UTP cable to PoE-enabled switch port or a connection with the SRX-Series PoE. AX411 includes the assembly of simple use of the devices in the wall or ceiling desk.

The construction of a wireless network for branch offices, companies must meet strict set of security policy. Low-security projectThe branches are used only to promote security flaws and vulnerabilities of the corporate network. The combination of Juniper AX411 wireless access points and gateways, the SRX-Series is the ideal solution for branch office network.

With Grinsing Ki

Friday, 22 October 2010

Network security across the enterprise - to help stop gap measures, your networks

The current enterprise networks consisting of multiple remote access connections by employees and outsourcing companies. Too often, the inherent security risks, see from these connections outside the network. Continuous improvements have been made, to improve security in today's network infrastructure, with particular attention to users accessing the network from outside intrusion and endpoint monitoring is critical for companies to protect their digitalGoods.

Install the right software for the specific needs of your IT infrastructure is important, with the best security precautions. Many companies install "off the shelf" software security, assuming that they are protected. Unfortunately, this is not the case because of the nature of today's threats from the network. The threats are numerous, including the usual spam, spyware, viruses, trojans, worms, and the occasional possibility that a hacker has targeted the server.

L 'to neutralize an appropriate security solution for your business almost all of these threats to the network. Too often installed with a software package, network administrators spend much of their time to defend the integrity of its network perimeter to prevent attacks by the hand and then manually patch the security hole.

Pay for network administrators to protect the integrity of the network is an expensive affair - much more than installing the rightsecurity solution that requires your network. Network administrators have many other tasks that require attention. Part of their job is to work more efficiently your business - can not focus on them when they defend the network infrastructure has manually all the time.

Another hazard to consider is the likelihood that occur within the site, in other words, an employee. Sensitive information of the owner is usually stolen from someone on thePayroll. A real solution for network security must be protected against this attack and guard. Network administrators certainly have their role in this area through the creation of security policies and recommended their implementation.

An intelligent strategy for your network needs and to protect against various security threats, multi-layered approach to security. multi-layered security is a concept tailored to your specific network requirements with both hardware and software solutions. After the hardwareand software are working together to protect your business, be able to immediately upgrade their skills to meet the latest security threats.

security software can be configured to update multiple times a day, when demand, hardware upgrades in the control of firmware updates and the update wizard, very similar to that within the application software.

All in a multi-strategy fronts should be implemented on-one security suite for manySources of threats to enterprise networks today. Too often the sources of those threats arrive in spam with Trojans or spyware installation inside a hidden software overlap. Combating these threats requires the use of firewalls, anti-spyware, malware and spam protection.

Recently, the trend in the software industry has been to combine these previously separate security applications into a complete security suite. security applications in accordance withEnterprise networks are security suites that integrate to focus on a common goal. These security suites include antivirus, anti-spyware, anti-spam and firewall, all gathered in one application. Find the best stand-alone applications in each category of security risk is still an option, but not a necessity.

The all-in-one security suite, a software company money in reduced purchasing costs and save time with the ease of integrated management ofvarious sources of threat.

Trusted Platform Module (TPM) TPM is a standard keyboard developed by the Trusted Computing Group defines the hardware specifications to generate the encryption. TPM to protect not only against intrusions and attacks, but also the theft of the device with the chip. TPM chip to operate as a compliment to authenticate users to improve the authentication.

Authentication describes all the processes involved in determiningif a user is granted access to the corporate network is, in fact, claims to be the user. Authentication is granted more often with the use of a password, but also include other techniques for biometric data that uniquely identify a user, identifying a unique property has no other person like a fingerprint, or the characteristics of the cornea.

Today TPM chips are often integrated into standard desktop motherboards and laptops. Intel has begun integrating TPM chip in its motherboards in 2003, whenare other motherboard manufacturers. If a motherboard, this chip features within the specifications of the motherboard to be present.

These chips can encrypt data at the local level and greater security in a remote place such as WiFi hotspots full of computer users that seems harmless, malicious hackers to get bored. Enterprise and Ultimate versions of Microsoft Windows Vista operating system using this technology within the BitLocker Drive EncryptionFeature.

Although support Windows Vista for the TPM, the chips are not dependent on the work platform.

TPM has the same functionality on Linux, since it is not within the Windows operating system. There is also evidence by the Trusted Computing Group for mobile devices such as PDAs and cell phones.

To use the enhanced security the TPM, users need only download the network security policy to your desktop computer and run a setup wizard to create a series ofKey to that computer. By following these simple steps significantly improved the safety for the user's computer remotely.

Admission based on user identity construction of a user depends on passing the authentication process. As already mentioned, user authentication, is much more than a user name and password. In addition to an emerging biometric technology for user authentication, smart cards and security tokens other method, which amplifiesAuthentication username / password.

The use of smart cards or security tokens adds a level of hardware requirements for authentication. This creates a safety requirement at two levels to get a secret password and the other a hardware requirement that a secure system must identify before granting access.

Tokens and Smart Cards work essentially the same but look different. Coins look like a flash drive and connect up to takea USB port, and smart cards require special hardware, a smart card reader that connects to your computer desktop or laptop. Smart cards often take on the appearance of an identity document and may contain a photo of the employee.

However, the authentication is verified will be granted as soon as this happens, user access through a secure virtual network (VLAN) connection. A VLAN provides links to the remote user, as if this person was a part of the internal network and allows allVLAN members together, as part of distinct security policies are grouped together.

remote users to connect through a VLAN only needs to access network resources and how these essential resources can be copied or modified, must be carefully monitored.

have established figures of the Institute of Electrical and Electronics Engineers (IEEE), has conducted what is known as a secure VLAN (S-VLAN) architecture. commonly referred to as tag-based VLAN is the standard known as 802.1q.VLANs increase security by adding an extra day at the Media Access Control (MAC), the hardware on the network to identify a network. This method is not identified MAC addresses to prevent access to the network.

This concept of network segmentation work hand in hand with the VLAN links, determine the resources that a user can remotely using Policy Enforcement Point (PEP) for segments of the application of security policies across the network. L 'VLAN or S-VLANs can be treated as a separate segment with distinct needs PEP.

PEP uses a user authentication to the network to enforce security policies. All users connect to the network must be guaranteed by the PEP, to meet the safety requirements laid down in the PEP. The PEP determines which network resources a user can access and how these resources can be changed.

The PEP for the VLAN links must be made of what we can do the same thing to improvewith internal resources, this can be done through network segmentation, are just establishing links VLAN as a separate sector and enforce a uniform security policy in this segment. Definition of a policy in this way can also choose which segments of the internal network can access the client from a remote location.

Liaising VLAN as a separate segment and isolate security breaches in this segment, if it occurs. This has in itself the vulnerabilitySpread across the network. Improved network security even more, could be a VLAN segment dealt with their environment virtualized, remote and isolated all the connections inside the corporate network.

Centralized management of security policies, hardware and software technology, particularly the various aspects of security threats, provide different software platforms, each of which must be handled separately. If done incorrectly, this can be a daunting task for the networkincrease administrative costs and personnel to manage due to the exigencies of time greater than the technology (both hardware and / or software).

Integrated security suite of software centralization of security policy from a combination of all the attacks on the security threat in an application, requiring only a management console for administrative purposes.

Depending on the type of business you are in a security policy should be used at the enterprise level, which is inclusive forentire network. Administrators can define and manage security policy in isolation, but an imperative of policy must therefore be kept constant throughout the corporate network. This ensures no other security measures against the policy and the centralized control of what has been called the policy to be implemented.

Not only a security policy for central, easy to manage, but also reduces the load on network resources. Several securitypolicies by different applications are centered on a security threat defined include pork total bandwidth much more than a centralized security policy within a complete security suite. With all the threats from the Web to facilitate the management and use is essential to maintaining a corporate security policy.

Frequently Asked Questions:

1. I trust my staff. Why should I improve network security?

Even the employees are a familyRisk of breaching the security of the network. It 'important that employees follow safety standards established companies. Strengthening security is trying to end the employees and the occasional disgruntled employee who guard cause harm to the network.

2. These changes create a truly secure environment for remote access?

We do. These improvements not only improve significantly on a secure server VLANs, but also the widely accepted standard that are often integrated intocommon hardware and software. And 'there, the company must start with the technology.

3. My company is satisfied with the use of separate software, so any application can focus on a threat to the security separate. Why would an all-in-one security suite?

have extended many of the top software applications commonly used to identify companies to focus on all threats. These solutions include software, hardware and applianceProducers. Many of these companies saw the need for consolidation of security in early and bought smaller software companies to acquire the missing knowledge of their society. A suite of security at the application level, it is much easier and manage the IT staff will thank you.

4. I need to add a requirement for hardware authentication?

The use of security tokens or smart cards should be considered for employee access to the corporate network from remoteSite. In particular, when the employee needs to access sensitive company information while on the road, a simple thief flash drive Secure token prevents access to sensitive data on a laptop stolen.

5. With all these concerns WiFi hotspots use no employee should be required to connect these locations to the corporate network?

WiFi hotspots have sprung up at national level and are the easiest way for your remote workers to access the Internet. Unfortunately Hotspotcan also completely bored, unemployed hackers who do nothing better than finding a way to take a transfer of employees at the next table. This does not mean that people in the street hotspot should be avoided. Which would restrict access to the network. Thanks to technologies like S-VLAN and secure authentication in place, a company can implement technology to reduce the threats of today and tomorrow.

The application of the latest technology in network security is apriorities for IT management. Located in today's network environment with many users access to digital resources, it is important to correct network security during the planning phase of the integration process to get.

Of course it should be noted that the larger companies with multiple operating systems must be running (Windows, Mac O / S, etc.) and that many of these companies all-in-one security suite of some of the challenges in a mixed environment of face operating system environment.

Therefore Istress that we need to consider multi-level security solutions (hardware and software) and not only on software applications to protect your digital assets. As technology changes so the chances of security breaches.

Because these threats are increasingly sophisticated hardware and software developers continue to innovate and is essential for businesses, and implement these technologies.

Wednesday, 13 October 2010

what kind of wireless network adapter for your best?

In the past, if we all do not plug it in, connect the Internet or the cable is connected to a greater effort than the rest of the wires to the computer. Laptop computers are created and the hills of the strings has been fixed, had to do something to the Internet. With all the other laptops, the cable was only prevents the complete freedom and mobility.

It seems a near-miracle now be able to surf the Internet completely hollow. It was not possiblewithout the design of modern wireless network adapter. Rather than shut up in an office, Internet users now have the freedom to do their work or leisure in nature, or where they want.

Who cares? Built-in radio transmitter and receiver adapter included in each wireless network. Your computer is now able to connect to a wireless LAN and connect to the Internet.

What kind should I buy? When it comes to Purchase a wireless network adapter, you have two options: USB or PCI. The choice depends on the type of computer system in use.

If the computer is a traditional desktop, wireless PCI adapter is the best for you. Add this in committees specifically for your computer and fits in the rest of the hardware. The desktop will have a place to go for the adapter, called the PCI bus.

For a notebook, on the other hand, you need a USB> Wi-Fi adapter. This is to develop, rather than outside inside, and can be easily inserted in the same place you could put the USB flash drive or other development. Do not worry - most notebooks have more USB ports for all your needs.

Another option is to install a wireless network - a feature that many notebooks today. Small chips are already stored in the computer and serve as a network adapter. No additional installation is required.

To check whether your computerexisting wireless networks, click the Start menu and then check the network connections. Another way might seem from the network for everyone is clicking on the group of computers that are located next to the volume and time on the toolbar. A mysterious external switch (turning the wireless on and off) is also a good indicator.

Monday, 11 October 2010

Computer network routers, hubs and switches

If computer networks are working well and we can only hope that most of the time, the inner workings of the system modules are transparent to the average user. The most common components in a computer network, not including the cable, "are" router "hub" and "switch". Many of these modules can be aesthetically similar. Each module is typically Ethernet ports (RJ45, which seems to connect a phone large) and LED display. However, theseForms> work differently, and it is important to understand the differences.

modern network hardware work on the "Open System Interconnection (OSI) standard. This standard defines how communication should be implemented in a network. By this standard, the modules from different vendors can coexist on the same network. Wireless Networks (WLAN) and 802.11x standard is an additional element of network systems.

If aMessage is sent from one computer to another, will be subdivided into parts. A basic level, the message of "1" and "0" bit is reduced. The next step is a group of bits as a "framework". A frame contains control information including the destination address, and error detection. The next step is a set of frames as a "package". The terms frame and packet are sometimes used interchangeably. If a message is sent through a complex network like the Internet, some packetsotherwise, and met at the destination.

Tracking error with two frames and packages used. The most common procedure is called "cyclic redundancy check (CRC). Sums CRC of all" 1 "in the frame or packet. This number in hex at the end of frame / packet is stored. On the receiving side, the process is repeated . If I have the two hexadecimal values, is the proof. Otherwise, the receiver requests that the sending device. Send Most of these functions are performed by modules integrated circuits (chips) on the network.

The Hub

The hub network is working on the first layer of the OSI, the process known as "physically." The hub is the simplest of the three;. Module A hub is not aware of the contents of the message that it processes the message as a bit '. It 'simply records the message and distribute it to everyone, even back in portthat your message hub "active", the electrical signal from the noise and amplify the clean signal before repeating hub "person" does not amplify the signals received, .. it only receives a signal and get the signal as a repeat for each port. The hubs are sometimes used to connect multiple computers to a printer.

The network switch

The power switch works on the second layer of the OSI standard, the so-called "Data Link Layer." The network ofSwitch, as the name suggests on, signaling pathways, so that a wire leading to a particular destination. A switch is to improve network performance, especially in networks with large numbers of computers. A switch has enough intelligence on board to mark the path to each destination. The switch operates a network of message frames.

When you connect a computer to a network switch, the switch records or Media Access Control address "MAC" ComputerNetwork Interface Card (NIC). This is called "ARP", such as address or protocol. If a frame is received for a specific computer, the switch sends the frame on this machine only. Preventing the streets of the network used by all frameworks, network resources are conserved. A computer can have a frame to send computer B, while at the same time, computer C computer sends a frame to D.

The network router

The network router is working on the thirdLayer of the OSI standard, called "Network Layer". A router is the name of a reference to his role. Routers are some of the same functions as switches, routers, but most often used two or more networks. For example, a router could) be used to connect a network with a conventional wireless LAN (Local Area Network. Another common use ") is a LAN connection to the Internet (a" Wide Area Network "or" WAN. In this role, theRouter uses Network Address Translation (NAT) so that all computers connected to LAN address can be a shared IP. A network router message packets. A router uses IP addresses to route packets between multiple networks.

A PC can be configured to handle the function of a router when you use the router software and two or more network interface cards (NIC) is. A separate network card for every needNetwork

A router is capable of advanced features, including a (Domain Host Control Protocol), DHCP server and firewall. A firewall protects your computer from potential threats from other computers on the network. The connection of multiple networks often requires the conversion of protocols.

A router is a versatile classification. Router can provide connectivity within agencies, between different locations, including businesses and the Internet.The largest routers combine Internet Service Providers are used in corporate networks of large size, or close a deal with satellite remote to a local company. Advanced routers are powerful computer, complete with microprocessors. Very sophisticated routers are used by the Internet to manage network traffic more efficiently.

A router maintains a table called "Routing Information Base (RIB), which tracks information on courses available. May be at the RIB (To be updated continually as conditions change) dynamic static (manually determined by a network administrator) o. A RIB is easily on a small LAN, but can be very complex and very large routers used on the Internet.

Summary

There are different types of network modules compared to the three discussed here, and may be significant overlap of roles. For example, an "intelligent hub" change many of the characteristics of a network.> Wireless Networks (WAN) have much in common with their cousins traditional LAN, but new security protocol networks and concerns specifically related to wireless interference. A single meeting roles may be combined in many network routers sometimes have components as the function of network switches.

Wednesday, 29 September 2010

Considerations for creating an extension of mobility to the enterprise network

Mobile Strategy

This paper your organization has an established market and accepted the business case for mobility and you are ready to proceed. When you implement a mobility solution, the effects are not limited to the actual consumers, but also the subtle and long-term effect on your IT strategy and execution. Over the past ten years we have seen the level of IT infrastructure from a private internal to increase information to the outside public access publishingon the Internet. It 's time to deal with the provision of external access to internal information systems and have to deal with a new set of questions about how to support a wide range of mobile devices? How to manage access to information on internal systems of these devices? We provide a safe and reliable?

The opening of business systems to mobile users requires careful planning to avoid the effects of changes in order to reduce the principal stakeholders, end users and IT management. A strategyMobility must watch include the following areas:


Mobile devices and device management



Communications (wireless and wireline), protocols and costs



Mobile applications individually and Usability



back-office data such as data requirements and integration points



central platform for mobile access, how the data in the mobile Internet



Security for authentication and encryption



Solution delivery and pricing models

The desired result of the analysis of these points represent the functional requirements, ease of use and structural engineering, as the architecture of mobile system for your business. The considerations of these issues are discussed in this paper.

Devices and equipment

The pace of technology for drivers coming onto the market continues to climb, sales of notebook and laptop now surpassed sales of desktop PCs and the billions of mobile phonesare sold more and more data applications can. There is also a full range of equipment in the cross-over between these two extremes, consisting of smart phones, PDAs, handheld bivalve, tablets, and more. This is a seemingly unlimited number of less form factors, different screen sizes, some rotating input methods (keyboard, keypad, stylus, finger, scanner for bar codes and RFID, voice, and more), type of and processor performance, memory size of kilobytes per gigabyteruggerdised construction and not the least of operating systems and application environments.

From the point of view of the device selection is the only safe rule to expect a mixed environment of today's standard equipment is likely to be available in 24 months. However, minimizing IT costs and resources is the adoption and application of the rules, so what's the solution? For mobility, is the answer to that device that fits the needs of end users select and use aDevice mobility management platform, leading to all units of the fleet. The platform abstracts the management of mobility devices, hidden individual differences.

A mobility platform must enable device management for enterprise applications, including the configuration of communication devices and updating applications on a single user or user group.

Communications

In many respects, mobile applicationsreplace the current manual paper-based systems can obviously only need a limited method of communication for exchange of data from back-office systems. However, a simple request because this option may cause too, could be given a user connects the device to a modem to dial telephone, intranet or even a PC sync connected, or if a wireless network or used as a mobile WiFi hotspot ? Each method has its cost, performance and latency, availability,Investments in infrastructure and security ramifications.

advanced mobile applications that require more immediate and require the collaboration of solutions push function, back-office notifications in real time to return the product.

Create or purchase of mobile applications that run efficiently on a network of communication selected as a wired LAN can perform badly when you switch to a wireless network. Conversely, if low-bandwidth optimizedlatency high-up or wireless mobile network to settle the same question you can not use his generation, wireless networks, high bandwidth, or third parties.

The best approach is to select the most appropriate communication network (s) for the purposes of the application and use a mobility platform that removes details of the communication by the application. A Wireless Application Gateway (WAG) to handle communications between the device and back-office will beOptimization of communication. It also provides a function of added value, such as support for push notification and independent compression of the selected network.

How to access client

cable networks that have been around for decades, a relatively high speed and reliable communication channel to the back-office systems with different models of large existing enterprise applications such as Thin Client Terminal (Citrix, Web) and multi-tier (client, server and database logic levels)Thick clients. The separation between the presentation of the request and the user is essentially a choice of IT management and a key driver for the model. Both models tend to take more than one communication link is to manage the integrity of transactions (record locking) and the sharing of resources in real time.

For mobility, with its unreliable nature of communication, it is time to reassess the models of appropriate access. The networks are in power, however, increases the inherentType of wireless range means that it will never be omnipresent and disturbances are still clearly the terms of latency of wired networks, applications running on the wired network for the good does not work, probably well over W-LAN in all.

To choose the two most common methods between a thin or thick client model. Thin clients are typically a Web browser or a specially built as a Citrix client, where the network must be available forthe required function. This thin client solutions have been a number of enterprise mobility solutions because of the limited capacity of the Web browser for mobile devices and frustrating usability problems for the ultimate success. thick client offering quick response and improved user interface, but they suffer the burden of administration and distribution of the update.

This in turn provides a platform for mobility solutions as the best of two models, the model called "intelligent" client. This allows the optimsiedThe thick client experience with the dynamic performance of thin clients. Applications and forms, mobile devices can be used to dynamically provide the latest features to install, without the administrative burden of updating each device or find the 'software that is.

Mobile Applications

Most organizations have invested in their employees' data collection processes and back-office systems is difficult to find a ready-made mobileThe request will be an exact match. The most common is an existing application and retrain staff to meet, or a custom solution that is tailored to create and grow as demand for organizational needs.

The choice of a platform that is rich, but simply can deploy toolkit for creating mobile applications, which is essential for success. The application can then mirror the current forms and processes that help reduce the impact of changes to end users. The toolkit includes must approachnot only the user but the data structures and communication to back-office, as well as having a one-stop location for the construction of a complete solution.

Many IT projects fail or higher, as were its development budget software races, underestimated the complexity or the original requirements are unclear. A platform, mobility for non-programmers, such as the objectives of Business Process Engineers, keeps the focus on solving business. In addition to a coupled device managementPlatform is the ability to easily implement new versions of the scope for rapid testing and user acceptance.

Systems Integration

Often referred to standards is that there are many to choose from and that's not true that with Enterprise Application Integration (EAI), in which each system or group of systems in particular, are protocols for exchanging data, usually from the file simple text import / export of complex informationMessage Broker bus. New rules will continue to log on as the data requirements and change management to take new opportunities.

Designing mobile applications to communicate with a specific back-office system appears to be the easiest and fastest way to move forward, but to create these blocks in a particular protocol is a server problem when the system is changed or newly updated. Instead, the construction of mobile systems, on the loose on the back-office system is connectedessential for success.

A mobility platform is a set of integration capabilities that are independent of mobile applications and change through the IT administration. The integration options should, because the data are presented and insisted (as raw text files and XML) and protocol for the common use (such as the actions of network drives, FTP, HTTP, and Enterprise Message Broker). full audit logs are needed to determine a history of dataIntegration.

Security

Computer security system the highest priority and the security information about the company faces. The growth of Internet technologies for access to content with the development of encryption, authentication and identification associated. Enterprise Firewall, Virtual Private Networks (VPN), intrusion detection, centralized authentication server, the standard to keep out intruders.

Mobility can affect a numberThis system of safety standards and therefore undermine the protection of corporate networks that allows users to obtain unauthorized access vulnerabilities, or to obtain business information from a mobile device is lost of stolen. Security options must be applied on the mobile device and in communication with the company.

A mobility platform should provide data synchronization and access over secure channels, such as HTTPS or VPN. multi-factor authentication of the user and the deviceas the use of unique identification ID of the device or network built SIM (Subscriber Identification Module) cards or network functions such as caller.

From a planning application data should only be stored on the mobile device and other data can be entered.

Server

Mobile applications require an application gateway for communicating, which will provide back-office application services are always available. This in turn requires that theGateway runs on an operating system stable and scalable application server. This is also integrated into the corporate network to authenticate users and access to data in back-office. You should be able to grow with increasing demand for transactional mobile access to data and back-office. The application should be based platforms in a scalable architecture and industry standards are used, such as J2EE o. NET architecture. These architectures can provideCompany or carrier performance and reliability.

The administration should be the mobility platform is a server and user management roles for delegated tasks in the IT team to do. Remote access to the server via the Web, offers easy access to the system without installing client.

Solution Delivery Options

With the growth of the Internet, e-mail there was growing acceptance of the benefits of outsourcing data processing systems for high availabilityand remote access to systems without depending on other infrastructure. This is also the case of wireless application gateways, and operational requirements and costs of care for the following licenses:


Application Service Provider (ASP) - capital expenditure limits, system maintenance, etc. (great for non-IT company). Do not grow the business and is not an investment decision, but the operating costs.



Managed Service - RelatedASP, but requires investment in hardware, the company, but the source management and control.



Software - The most common model of software licenses today, the investment in hardware, software licenses and ongoing operations are managed in-house needs. Both ASP and managed services, an inexpensive and quick to market capacity. The mobility platform and service provider, offering a flexible solution that can be startedfast business benefits can be assessed.

Conclusion

This work has demonstrated a number of technical areas that are pulled before the addition of a mobile extension to the corporate network into account. This information can be used to comprehensively assess the capabilities of the gateway applications available on the mobile market. The gateway will be selected for the company, have a history of proven solutions and practical with a change in course that is coupledContinuous investment in the future progress of cellular technologies.

For more information: www.retriever.com.au

Saturday, 28 August 2010

Network security across the enterprise - helping to stop gap measures, your network

Today, enterprise networks consist of numerous remote access connections by employees and outsourcing companies. Too often, the security risks inherent in these compounds are facing outside the network. continuous improvement have been made that the security could in network infrastructure is now increasing, are essential, with particular attention to users outside the network access and monitoring of access parameters for the company to protect their digitalActivities.

Install the right software for the specific needs of your IT infrastructure is essential to have the best security measures possible. Many companies set up "off the shelf" software security and assume they are protected. Unfortunately, this is not the case because of the nature of today's threats from the network. The threats are numerous, including the usual spam, spyware, viruses, trojans, worms, and occasionally the possibility that a hacker has your server in line.

Theto neutralize the right security solution for organizing almost all of these threats to the network. Too often installed with a software package, network administrators spend much of their time to defending the network perimeter of the entire ward off attacks by hand and then manually patch the security breach.

Pay for network administrators to defend the integrity of the network is a costly affair - much more than installing the properSecurity solution that requires your network. Network administrators have many other tasks that require your attention. Part of their job is to make your business operate more efficiently - can not concentrate on them when they defend yourself, network infrastructure, all the time.

Another threat that must be taken into account, the risk that occur within the premises, in other words, an employee. Sensitive information of the owner is usually stolen by someone onPayroll. A real solution for network security to guard against this attack as well. Network administrators certainly have their role in this area through the creation of security policies and recommended their implementation.

A clever strategy for the network needs to protect against security threats is a different approach to layered security. layered security approach is a customized network to use the specific requirements of hardware and software solutions. After the hardwareand the software will work together to protect your business, be able to immediately upgrade their ability to consider the most recent security threats.

security software can be configured to update multiple times daily, if necessary, be, hardware upgrades, as a rule of firmware updates, and an upgrade wizard much like the application inside the software.

All sides in a multi-strategy should be implemented on-one security suite for manySources of threats to enterprise networks today. Too often the sources of these threats, with spam or spyware, trojan arrives overlay are hidden inside a software installation. Combating these threats requires the use of firewalls, anti-spyware, malware and spam protection.

Recently, the evolution of the software sector has been to combine these previously separate security applications in an all-inclusive security suite. Security applications on standardCorporate networks are security suites that integrate to focus on a common goal. These security suites include antivirus, anti-spyware, anti-spam and firewall, all packaged together in an application. Find the best stand-alone applications in each category of security risk is still an option but not a necessity.

The All-in-one security suite to save money on software companies reduce time and cost with ease of integrated management ofThreat of different sources.

Trusted Platform Module (TPM) The TPM is a standard developed by the Trusted Computing Group to define the specific hardware to generate the encryption key. TPM is not only against intrusions and software, but also physical attacks to guard stolen devices with the chip. TPM chip works as a compliment for user authentication to improve the authentication.

Authentication describes the processes involved in identifyingif a user is allowed access to the corporate network, in fact, must be supplied by the user. Authentication is usually granted through the use of a password, but other biometrics that uniquely identify a user, identifying a unique property has no other person, such as a fingerprint or characteristics of the cornea of the eye.

Today, TPM is often integrated into standard desktop motherboards and laptops. Intel began the integration of the TPM chip in its motherboards in 2003, whenare other motherboard manufacturers. If a motherboard, this chip will be included in the specifications of the motherboard.

These chips can encrypt data locally and provides greater safety in a remote site, such as Wi-Fi hot spot full of innocent-looking computer users, hackers with malicious intent to get bored. Microsoft Ultimate and Enterprise editions of Windows Vista operating system with this technology by BitLocker Drive EncryptionFeature.

While Vista provides support for TPM technology, the chips are not dependent on work from any platform.

TPM has the same functionality on Linux, because they are not in the Windows operating system. There are also some Trusted Computing Group's specifications for mobile devices such as PDAs and cell phones.

For TPM security, advanced network security policy, users simply download to your desktop computer and run a setup wizard to create a series ofKey to the computer. Following these simple steps significantly improves the safety of users of remote computer.

The admission by the user's identity construction of a user depends on passing the authentication process. As mentioned user authentication can be much more than a username and password. Apart from the growth in biometric technology for user authentication, smart cards and security tokens are another way that strengthensusername / password authentication process.

The smart card or request a security token created layer hardware authentication. This creates a safety requirement that one of two classes a secret password, and other hardware requirements for a secure system must identify before granting access.

Tokens and Smart Cards work essentially the same way, but they look different. Chips take on the appearance of a flash drive and connect upa USB port, and smart cards require special hardware, a smart card reader on your computer desktop or laptop connect. Smart cards are often the appearance of an identification badge and may include a photo of the employee.

However, authentication is to be inspected as soon as this happens a user to grant access via a secure virtual network (VLAN) connection. A VLAN provides connection to the remote user as if this person was a part of the internal network and allows allVLAN users are grouped into different security policies.

Remote users connect via a VLAN should only have access to network resources and essential to how these resources can be copied or modified, must be carefully monitored.

Details of the Institute of Electrical and Electronics Engineers (IEEE) have a safe VLAN (S-VLANs known lead based) architecture. Often referred to as tag-based VLAN is the standard known as 802.1q.Increases security by identifying an additional VLAN tag within the Media Access Control (MAC), hardware network adapter in a network. This method is not identified MAC addresses to prevent access to the network.

The concept of network segmentation work hand in hand with VLAN connections, determines which users can access resources remotely via a policy enforcement points (PEP) on the areas of application of security policies across the network. TheVLAN or S-VLANs can be treated as a separate segment to its own standards PEP.

PEP works with a user authentication to the network to enforce security policies. All users connect to the network must be guaranteed by the PEP, that they meet the requirements of security policy contained in the PEP. The PEP determines which network resources a user can access and how these resources can be changed.

The PEP VLAN connections should be improved, which can be done by the same userThis can intern with the resources through the network segmentation achieved simply defining VLAN connections as a separate sector and implement a uniform policy of safety in this segment. The definition of a policy in this way can also choose which segments of the internal reviews can be accessed from a remote location.

Liaising VLAN as a separate segment and isolate security breaches if they occur in this segment. This will keep out the security holeSpread across the network. further improve the network security still a VLAN segment could be treated by him isolated virtual environment, so all remote connections inside the corporate network.

Centralized security of hardware and software in particular the various aspects of security threats, creating different software platforms, each of which must be handled separately. If done correctly, this can create an enormous task for the networkAdministrative and staff may increase due to increased time requirements for managing technology (both hardware and / or software).

Integrated security software suite to centralize security policy through a combination of attacks on security threats in an application that requires only one management console for management purposes.

Depending on the type of business you are in a security policy should be used company wide, which is to include all-entire network. Administrators can define and manage security policy separately, but an absolute definition of the policy must be maintained, so that uniform throughout the network. This ensures that there is no security procedures, the key to implement the policy and limiting what the policy was adopted.

Not just a centralized security policy has become easier to manage, but also reduces the pressure on network resources. Multiple securityPolicies for different applications with an emphasis on a possible security threat total hog more bandwidth than a centralized security policy within a security suite complete content defined. With all the threats from the Web, ease of use and application is essential for maintaining corporate security policies.

FAQ:

Before I trust my staff. Why would I want to improve network security?

Even employees are a familyRisk of a breach of network security. It 'important that employees follow the safety standards established in society. Increased security is seeking the termination of employees and the occasional disgruntled employee call cause harm to the network.

According to these changes really create a secure environment for remote access?

We do. These improvements not only improve substantially secure VLAN connection, but is widely accepted that the rules are often involved incommon hardware and software. And 'there, the company must start with technology.

My company is using third party software can be separated, the way each application to focus on a separate threat to the security happy. Why should I be an all-in-one Security Suite?

Many of the most popular software applications are often used by companies expanded their focus to identify all security risks. These solutions include software and hardware appliancesProducers. Many of these companies saw the need to win to consolidate security in the initial phase and has acquired smaller software companies, knowledge of their company was missing. A suite of security at the application level, it is much easier and manage the IT staff will thank you.

I must add a fourth hardware requirements for authentication?

The use of security tokens or smart cards are to be considered for workers' access to the corporate network from a remoteWebsite. Especially when these workers require access to sensitive company information while on the road to avoid a simple flash drive secure token that a thief to access sensitive data on a laptop stolen.

Fifth With all this concern for Wi-Fi hotspots, employees should be required to use these sites to connect to the corporate network?

Wi-Fi hotspots have emerged at national level and are the easiest way to remote employees access to the Internet. Unfortunately Hotspotscan completely bored, unemployed hackers to do nothing better than to find a way, a transfer of employees at the table next to intercept. This is not to tell people on the street to avoid hotspots. Which limits access to the network. With technologies such as S-VLAN and secure authentication in place, a company can deploy technologies to reduce threats now and in the future.

The implementation of the latest technologies is a safety netpriorities for IT management. In today's network environment with many users to access your digital assets at a distance, it is extremely important to correct network security during the planning phase of the integration process.

Obviously noticed that most of the larger companies have run multiple operating systems (Windows, Mac will be O / S, etc.) and that many of these firms all-in-one security suites face particular challenges in a mixed system environment operational.

I thenemphasize that you are considering multi-layer security architecture (both hardware and software), and not only need software to protect your digital assets. As technology changes, so the chances of security breaches.

Because these threats are increasingly sophisticated hardware and software developers continue to innovate and that is essential to keep businesses and application of these technologies.

Tuesday, 24 August 2010

Network Switches - Basics

The network switch plays a key role in society and people home networks, but too many confuse what is the purpose of the system and how it differs from a router. I decided to write this blog post to explain the basics of passage - from different species, suppliers to buy from them.

A brief overview of network switches

A network switch is a type of computer network products, network bridge segments. Change sometimes referred to as a packageor simply a switch. The switch is an important component in the most networks (LANs), including medium and large corporate networks that use managed switches connected to each other more.

A switch is much less demanding than a router. While routers and switches are very similar in appearance, they differ significantly in their router internal components.

Types of network switches

Unmanaged Switch: This is usually the least expensive type ofSwitch, most commonly in homes or small offices. They are very easy, takes the plug and play, no specific configuration options

Managed Switches: Managed Switches offer optional configuration options, enabling a wide variety of features. There are several ways to make these options, the use of an instrument at a distance, such as Simple Network Management Protocol (SNMP) access to the switch to a command line interface such as telnet.


IntelligentSwitch: Smart Switches are different from fully managed switches, because they allow only a certain number of changes and functionality. Because users can configure the basic settings, they are often cheaper than the fully-managed breeding. Some basic functions often turn to a switch port Smart are some details on or off, connection speed and duplex settings and the settings for port priority

Enterprise Managed Switches: Enterprise Switches are more configurable andexpensive version of managed switches. They are more common in business networks in a number of other switches. They are more efficient for large enterprises, where the module can access a central administration to save time and money. Some advanced features for business settings switches VLAN, link aggregation and port mirroring.

Switches purchases

There are several switches manufacturer brands that offer differentiated and competitive products, including Cisco,3Com, Alcatel e. While switches are purchased out of the box from online retailers, can a way to save money is to use a switch from a retailer online to find. A business buyer can often save thousands of dollars to buy used Cisco or other networking hardware brand.

If you decide to go the way of an online retailer, you must consider several factors to ensure that skills are a good fit. One factor is a good guarantee as it is always a risk to buy usedEquipment. Another reason is significant discounts (50%) the price of retail. The third aspect which I recommend an online manufacturer of network hardware is a good score. The ability to help people is to talk with your purchase undervalued.

I hope this post "support base switch 'helps those who are confused or looking for a way to buy a switch.

Thursday, 12 August 2010

LAN Design and the Hierarchical Network Model

CCNA focuses on networks for SMEs (small and medium enterprises).
A hierarchical design model is recommended.
Easy to manage and expand.
Problems are resolved quickly.

hierarchical network design divided into three layers.
Core, (CL).
Distribrution (DL).
Access (AL).

Each layer provides specific functions.
This "modularity" facilitates the scalability and performance.

Access Layer (AL): the lowest

Interfaces with the terminal(User).
Includes routers, switches, bridges, hubs and wireless access points.
Provides a means of connecting devices to the network and control who can communicate over the network.

Distribution Layer (DL):

Aggregates data received from TO before the transfer of CL for routing.
Controls the flow of traffic with the policy and outlines broadcast domains with VLANs defined in the AL.
Allow VLAN traffic segmentation (separate subnets).
DL-switchestypically high-performance devices, high availability and redundancy to ensure reliability.

Core Layer (CL):

The high-speed backbone or internetwork.
Key to the cohesion between the devices at the distribution level? must be highly available and redundant.
Often combined with Internet resources.
Fm TFC aggregates all devices, so it must be able to quickly transfer large amounts of data.
Note: the smaller networks often combine the distribution andCore layers.

Three Laye3rs logic is divided into a clearly defined hierarchy.
It 'much more difficult to see these layers physically.

Advantages of a hierarchical network:

Scalability:

Hierarchy of networks very well.
The modular design allows you to replicate design elements.
Expansion is easy to program and implement.

Redundancy:

As a network grows, the availability is increasingly important.
Availability increases dramatically with hierarchicalNetworks.
For example, Al-connect switches to switches 2 DL. When DL switch fails, the AT-switch, switch to another.
Redundancy is limited to the level of access. Normally, the devices do not connect to multiple switches.

Performance:

Properly designed networks can achieve near wire speed btw all devices.

Safety:

AL-switch can be configured to control devices can connect to the net to give.
More advanced security policyAvailable from the DL.
AL Some switches support L3 capability, but usually it is the task of DL-switch, because it can process more efficient.

Manageability:

Changes can be repeated for all devices in a layer, probably because they perform the same functions.
Distribution of new switches will be simplified as configurations can be adopted with few changes.
Consistency within each layer simplifies debugging.

Maintainability:

Because ofits modularity and scalability are accustomed to hierarchical networks easily.
This also means that networks are less expensive.
In other designs will be the network management is growing increasingly complicated.

Principles of Hierarchical Network Design:

hierarchical design is no guarantee of good design.
simple guidelines to help distinguish BTWN well-designed and poorly thought through hierarchical networks.

Network diameter:

In general, the first thingassayed.
Reaching the number of devices through a package to its destination.
Small diameter ensures low latency and predictable.

Bandwidth aggregation (added):

combined to give the links btw switch to throughput.
Cisco has a proprietary technology called Link Aggregation EtherChannel.
aggregated links are provided by different dashed lines with an oval or a single dashed line with an oval.
May be at any level (less frequently used @AL).

Redundancy:

The redundancy can be provided in a number of options.
For example, 2x or 2x connections BTWN equipment devices.
redundant links can be expensive.
Redundancy design starts in the AL. Ensure that accommodate all network devices? 3 LR switches.
This helps determine the DL-3 switch? CL-switch.

What is a converged network?

SMEs are increasingly running voice, video and data.
The convergence process is the combination of these.
ARecently this possibility was limited to large companies.
Legacy (older) devices hindered convergence.
Since analog phones has not been replaced, you can see and legacy PBX systems and IP-based PBX.
Convergence is now easier and cheaper.
With a convergence is to manage a single network.
It costs less to deploy and manage.
IT cabling to be simplified.
Convergence also creates new opportunities.
You can wire the voice and videodirectly into the PC of an employee.
You do not need a phone or expensive video equipment.
Soft phones (Cisco IP | Communicator) offer a high degree of flexibility.
With the software, companies can quickly convert to converged networks with low cost of capital.
With cheap webcams for video conferencing can be added.

Separate voice, video and data networks:

voice networks include telephone lines run to a PBX (Private BDXT Exchange) isolation switch in a wiring closet Telco PSTN(Public Switch Telephony Network).
fm Cabinet Telco often separate the data and video cabinets.
New phone? a new line for the telephone system.
With a network of properly designed hierarchical voice lines with little or no impact will be.
Now the sense that networks can accommodate BW, converges.

Exploring the hierarchical network switches:

Tk-flow analysis:
The process of measurement and analysis of BW use to optimize performance, planning and HWImprovement.
To select the appropriate gear in a hierarchical network, you must spec flows by TFC, users and servers.
The networks should be designed with an eye toward growth.
Powered by the TFC-flow analysis software.
If port density and price check sufficient transmission capacity to ensure growth.

Analysis Tools:

Many TFC-flow analysis tools are available.
SolarWinds Orion NetFlow 8.1 CE analysis.

User Community Analysis:

Identifies users grpingsand its impact on net return.
Influenced port density and flow of TFC, influences the selection of network switches.
Typically, users are grped the work function.
For example, human resources and finance a plan to another.
Each department. have different users and needs, and requires access to various network resources.
Select Options, connections enough to meet the needs and enough to satisfy the department pwrful TFC.
Good network design also factors inGrowing.
Examine the TFC generated by end-user applications.
Some communities of users create a lot of others do not.
The position of the user community, which influences the data is stored and server farms.
Users agree to close their servers, you can reduce the diameter of the network, reducing the impact on other users.
However, the use is not always bound by their physical location or office.

The stored data and data analysis server:

Data can be servers, SAN,NAS units bu tape or disc or other component.
Contains both client-server and server / server TFC.
TFC Client-server typically passes through several switches.
forward prices BW-aggregation and-switch can help eliminate the bottlenecks for this type of TFC.
Some server applications to generate a high volume server btw.
These servers are shoule neighbors (ie, secure data centers shown).
TFC entire switch data center is usually very high.
Requires higherImplementation switches.

Topology diagram:

A graphic representation of a network infrastructure.
Shows how all the switches are connected together, including those designed to connect ports.
It shows where and how many switches are in use.
They can also contain information about the density and GPRS device.
Helps to visually identify potential bottlenecks.
Very difficult to create after the fact.

Switch Features:

Switch form factors:

fixed configuration or modularstackable or non-stackable.
Thickness is measured in rack units. (This is 1U, 3U).
Fixed Config switch - hardware can not be added.
Modular Switches - Chassis allows line cards containing multiple ports.
The larger frame, more modules can be supported.

stackable switches:

Can be linked together via a special cable that provides high-bandwidth backplane throughput btw switches.
Cisco StackWise technology allows you to interconnectnine switches with fully redundant backplane connections.
Stacked switches operate effectively as a single large switch.
Desirable, where fault tolerance and availability are critical BW and a modular switch is too expensive.

Performance:

Port density:

port density per switch is three doors available.
roots are typically fixed ports 1000!

large corporate networks do require high-density modular switches to the optimum use of space and PWR.
AlsoAvoid bottlenecks uplink.
A series of solid swtches consume a lot of additional ports for switch aggregation BW btw.
Compete in a modular switch aggregation is less problematic because the chassis backplane, the BW.

Forwarding Rates:

The processing capacity of a switch in bps.
Switch product lines are labeled for shipping rates.
If this is too low, can not take his wire-speed on all ports.
= Wire speed that each port is capable of(10Mbps etc.).
For example, switch to 48 GbE ports at wire speed = 48 Gb / s of the TFC.
If the switch only supports 32 Gbps (internal), can not operate at full wire speed on all posrts simultaneously.
Access switches normally not required full wire speed, because they are limited by their physical and uplink to the DL.

Link Aggregation:

Determine whether to aggregate ports enough to support the required BW.
switch port 24-GbE EC was up to 24 Gbps.
If youconnected to the network through a single cable, you can only forward 1 Gbps for the rest of the network.
The wire speed is 01:24 for each of the 24 devices.
Links to support the aggregation of these bottlenecks up to 8 ports to reduce grped where up to 8 Gbps.
can be constructed with 10-GbE uplink rates of return high.
Cisco uses the term EtherChannel ports = aggregates.

Power over Ethernet (PoE):

PoE can provide a power switch onExisting Ethernet.
Wireless AP can be used by IP phones and some of them.
Allows greater flexibility for equipment installations.
Adds significant costs to the switch.
PoE switch labeled with "V" for volts.

Layer 3 functions:

Typically, the switches operate at L2, and, above all, deal with MAC addresses.
L3 switches provide advanced features.
L3 switch = Multi Layer Switch.

switch functions in a hierarchical network:

Access Layer SwitchFeatures:

Port Security - the first line of defense for a network.
How many and which devices are allowed to connect.
All Cisco switches support port Layer Security.
VLAN component - of converged networks.
Voice TFC is usually given in a separate VLAN.
Port Speed:
Fast Ethernet is sufficient for most voice and data TFC.
PoE - much more expensive, so use only when necessary.
Link Aggregation - on all 3 lvls supported.
QoS - VoIP needs.

DistributionLayer Switch offers:

Collect all data-switch-switch and forwards them to the CL.
Provides inter-VLAN routing.
DL-switches have a capacity to manufacture than AL.
Need Help L3 inter-VLAN routing.

Security Policy:

Need L3 so advanced security policies can be applied.
ACL control the flow through a network of TFC.
ACL filter switches allow TFC.
ACLs are CPU-intensive because each packet inspection and must match ACLRules.
Placing on the ACL DL also reduces the 3 options that require additional configuration mgmt.
Policy-based connectivity and access to departmentaléworkgroup base coat.

Quality of service:

DL-switches must be implemented priorities for the next fm TFC maintenance AL Switches, QoS.
If not all devices support QoS, reduced benefits, -. poor performance and quality.
DL-switches are under high demand.
Need redundancyadequate availability.
DL-switches are typically used in pairs.
Recommend that they support multiple, hot-swappable power supply PWR.
Finally, they must link aggregation and aggregate broadband connection back to basic support.

Core Layer Switch Features:

CL is the backbone for high speed.
The transmission rate depends on the number of networked devices.
If you choose to inadequate controls on nuclear, you are faced with potentialBottleneck slowing down all the questions TFC.
CL should be aggregated to support 10 GbE switch.
L3 redundancy has a faster convergence of L2, so sure, CL-L3 switches support functions.
CL switches should support provides full redundancy.
QoS is the center for high-speed WAN access is often more important prohibitivel expensive.

Switches for SMEs:

Identify uses Cisco SMB applications.

The features of Cisco Catalyst switches:

You can not just choose oneTurn on the size of a company.
Companies are often integrated cross with other institutions.
In 6500 makes sense as an AL-switch, where there are hundreds of users in an area such as the stock market.
Cat Express 500 - forward prices = 8.8 to 24 Gbps.
Cat 2960 - L3, QoS, PoE is 16 to 32 Gbps.
Cat 3560 - enterprise-class, PoE, QoS, 32-128 Gbps.
Cat 3750 - piled high performance.
Cat 4500 - DL midrange modular - up to 136 Gbps.
Cat 4900 - Data Center.
Cat6500 - DL & CL - up to 720 Gbps.

Miscellaneous:

MDF - main distribution function.
Gi 0E1 - short for Gigabit Ethernet.
Spanning Tree - Protocol allows redundant paths, but stopped to avoid some links, switching loops.