10.07.2015 Views

Designing Cisco Network Service Architectures - Free Books

Designing Cisco Network Service Architectures - Free Books

Designing Cisco Network Service Architectures - Free Books

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Step 3 (E-Commerce Redesign Statement of Work) The hardware in the CollocationFacility is coming off lease, and the E-Commerce manager has the budget to “do itwell”. You have been asked to come up with a proposed design, meeting thefollowing requirements:— Firewall support is desired between web and application, application and databaselayers. That way, a server compromise in one layer might be contained before itaffects the other layers.— If there is a good way to protect servers within a VLAN from each other, CP Hotelswould like to know about it.— The CIO emphasized that the new design should take advantage of technology andspeed improvements, while complying with shifts in what are consideredrecommended practices.— Simplicity and low device count matter – collocation space is costly, and tight.— The web site is doubling in traffic volume every year. The design needs to scale tocover growth over the next 4-5 years.— There is talk of the collocation provider managing the devices within its site, soappropriate security is needed inside the data centers in case there is a lapse in thesecurity they provide.— Do not forget to put in IPS capability.— After losing millions of dollars due to a single extended outage, management haspurchased the <strong>Network</strong> General Infinistream product, which does packet capture andreporting based on terabytes of disk space. The intent is to use it as a “network flightrecord” to help analyze the next outage. Your design will need to provide SPANports and “plumbing” so that the Infinistream can capture every packet every devicein the collocation facility transmits on the inside of the firewall.Step 4 SAN Business Case and High-Level Design for Collocation Facilities— All web pages and application and database files are static, used to generateresponses to web queries. Some of the databases are refreshed nightly, others changemonthly, reflecting new hotel locations, etc. Actual guest reservations, frequenttraveler benefits, and so on are stored in databases within the data center, not thecollocation facility.— At a very high level, what might be some business or technical reasons for usingSAN in the collocation facilities? If you think a SAN is not needed or inappropriate,prepare to justify this.— How would you describe your SAN design at a high level, taking the above securityrequirements into account?Page 25 Lab Guide © 2007 <strong>Cisco</strong> Systems, Inc.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!