| 0 comments ]

Enterprise Edge WAN and MAN Architecture

Add a note hereRecall from Chapter 3, “Structuring and Modularizing the Network,” that the Cisco Service-Oriented Network Architecture (SONA) Enterprise Edge and the WAN and MAN modules are represented as the Enterprise Edge functional area of the Cisco Enterprise Architectures. This section describes the Enterprise Edge WAN and MAN architectures and technologies.

Add a note here Enterprise Edge WAN and MAN Considerations

Add a note here When selecting Enterprise Edge technologies, consider the following factors:

  • Add a note here Support for network growth: Enterprises that anticipate significant growth should choose a technology that allows the network to grow with their business. WAN technologies with high support for network growth make it possible to add new branches or remote offices with minimal configuration at existing sites, thus minimizing the costs and IT staff requirements for such changes. WAN technologies with lower support for network growth require significantly more time, effort, and cost to expand the network.

  • Add a note here Appropriate availability: Businesses heavily affected by even the smallest disruption in network communications should consider high availability an important characteristic when choosing a connectivity technology. Highly available technologies provide inherent redundancy where no single point of failure exists in the network. Lower-availability technologies can still dynamically recover from a network disruption in a short time period, but this minor disruption might be too costly for some businesses. Technologies that do not inherently provide high availability can be made more available through redundancy in design, by using products with redundant characteristics such as multiple WAN connections, and by using backup power supplies.

  • Add a note here Operational expenses: Some WAN technologies result in higher costs than others. A private-line technology such as Frame Relay or ATM, for example, typically results in higher carrier fees than a technology such as an IPsec-based IP VPN, which takes advantage of the public Internet to help reduce costs. It is important to note, however, that migrating to a particular technology for the sole purpose of reducing carrier fees, without considering network performance and QoS, can limit support for some advanced technologies such as voice and video.

  • Add a note here Operational complexity: Cisco MAN and WAN technologies have varying levels of inherent technical complexity, so the level of technical expertise required within the enterprise also varies. In most cases, businesses can upgrade their MAN or WAN and take advantage of the expertise of the existing IT staff, requiring minimal training. When an enterprise wants to maintain greater control over its network by taking on responsibilities usually borne by an SP, extensive IT training could be required to successfully deploy and manage a particular WAN technology.

  • Add a note here Voice and video support: Most Cisco MAN and WAN technologies support QoS, which helps enable advanced applications such as voice and video over the network. In cases where a WAN technology uses an SP with a Cisco QoS-certified multiservice IP VPN, an adequate level of QoS is assured to support voice and video traffic. In cases where the public Internet is used as the WAN connection, however, QoS cannot always be guaranteed, and a high-bandwidth broadband connection might be required for small offices, teleworkers, and remote contact center agents using voice and video communications.

  • Add a note here Effort and equipment cost to migrate from private connectivity: When an enterprise is migrating from private connectivity to another technology, it is important to evaluate the short- and long-term costs and benefits of this migration. In many cases, this is accomplished with minimal investment in equipment, time, and IT staffing. In some instances, however, this migration requires a significant short-term investment, not only in new equipment, but also in IT training. Such an investment might also provide long-term increased cost savings, lower operational expenditures, and increased productivity.

  • Add a note here Network segmentation support: Network segmentation means supporting a single network that is logically segmented. One advantage of network segmentation is that it reduces expenditures associated with equipment and maintenance, network administration, and network carrier charges as compared to separate physical networks. Another advantage is increased security; segmentation can help isolate departments or limit partners’ access to the corporate network.

Add a note here Cisco Enterprise MAN and WAN Architecture Technologies

Add a note hereThe Cisco Enterprise MAN and WAN architecture employs a number of MAN and WAN technologies engineered and optimized to interoperate as a contiguous system, providing the integrated QoS, network security, reliability, and manageability required to support a variety of advanced business applications and services. These technologies include a number of secure alternatives to traditional private WAN connectivity and help increase network scalability and reduce monthly carrier fees. The Cisco Enterprise MAN and WAN architecture includes the following technologies, as summarized in Table 5-4:

  • Add a note here Private WAN: Private connectivity takes advantage of existing Frame Relay, ATM, or other connections. To provide an additional level of security when connecting sites, strong encryption (using Digital Encryption Standard [DES], Triple DES [3DES], and Advanced Encryption Standard [AES]) can be added. A private WAN is ideally suited for an enterprise with moderate growth expectations, where relatively few new branches or remote offices will be deployed over the coming years. Businesses that require secure, dedicated, and reliable connectivity for compliance with information privacy standards, and that also require support for advanced applications such as voice and video, benefit from encrypted private connectivity. However, this technology can result in relatively high recurring monthly carrier fees and is not the preferred technology for extending connectivity to teleworkers and remote call agents. An enterprise might choose encrypted private connectivity to network its larger branch offices, but opt for other technologies, such as a VPN, to connect remote users and smaller sites.

  • Add a note here ISP service (site-to-site and remote-access IPsec VPN): These technologies take advantage of the ubiquity of public and private IP networks. The use of strong encryption standards (DES, 3DES, and AES) makes this WAN option more secure than traditional private connectivity and makes it compliant with the many new information security regulations imposed on government and industry groups (such as healthcare and finance). When implemented over the public Internet, IPsec VPNs are best suited for businesses that require basic data connectivity. However, if support for delay-sensitive, advanced applications such as voice and video is required, an IPsec VPN should be implemented over an SP’s private network where an adequate level of QoS is assured to support voice and video traffic. Relatively low monthly carrier fees make this technology appropriate for businesses seeking to connect a high number of teleworkers, remote contact center agents, or small remote offices over a geographically dispersed area.

  • Add a note here SP MPLS and IP VPN: A network-based IP VPN is similar in many ways to private connectivity, but with added flexibility, scalability, and reach. The any-to-any nature of an MPLS-enabled IP VPN (any branch can be networked to any branch), combined with its comprehensive QoS for voice and video traffic, suits the needs of many enterprises, especially those with high growth expectations, where many new branches and remote offices will be added over the next few years. The secure, reliable connectivity and relatively lower carrier fees that are inherent in this technology make a network-based IP VPN a good choice for businesses looking to use a managed service solution to connect branches, remote offices, teleworkers, and remote call agents.

  • Add a note here Self-deployed MPLS: Self-deployed MPLS is a network segmentation technique that allows enterprises to logically segment the network. Self-deployed MPLS is typically reserved for very large enterprises or an SP willing to make a significant investment in network equipment and training, and for those that have an IT staff that is comfortable with a high degree of technical complexity.

Add a note here Table 5-4: Cisco Enterprise WAN and MAN Architecture Comparison
Open table as spreadsheet

Add a note herePrivate WAN

Add a note hereISP Service (Site-to-Site and Remote-Access IPsec VPN)

Add a note hereSP MPLS and IP VPN

Add a note hereSelf-Deployed MPLS

Add a note hereSecure transport

Add a note hereIPsec (optional)

Add a note hereIPsec (mandatory)

Add a note hereIPsec (mandatory)

Add a note hereIPsec (mandatory)

Add a note hereHigh availability

Add a note hereExcellent

Add a note hereGood

Add a note hereExcellent

Add a note hereExcellent

Add a note hereMulticast

Add a note hereGood

Add a note hereGood

Add a note hereGood

Add a note hereExcellent

Add a note hereVoice and video support

Add a note hereExcellent

Add a note hereLow

Add a note hereExcellent

Add a note hereExcellent

Add a note hereScalable network growth

Add a note hereModerate

Add a note hereGood

Add a note hereExcellent

Add a note hereExcellent

Add a note hereEasily shared WAN links

Add a note hereModerate

Add a note hereModerate

Add a note hereModerate

Add a note hereExcellent

Add a note here Operational costs

Add a note hereHigh

Add a note hereLow

Add a note hereModerate; depends on transport

Add a note hereModerate to high

Add a note hereNetwork control

Add a note hereHigh

Add a note hereModerate

Add a note hereModerate

Add a note hereHigh

Add a note hereEffort to migrate from private WAN

Add a note hereLow

Add a note hereModerate

Add a note hereModerate

Add a note hereHigh

Add a note hereEnterprises can use a combination of these technologies to support their remote connectivity requirements. Figure 5-20 shows a sample implementation of a combination of three technologies in a healthcare environment.

Image from book
Add a note hereFigure 5-20: Sample Cisco WAN Architectures in a Healthcare Environment

Selecting Enterprise Edge Components

Add a note here After identifying the remote connectivity requirements and architecture, you are ready to select the individual WAN components.

Add a note here Hardware Selection

Add a note hereWhen selecting hardware, use the vendor documentation to evaluate the WAN hardware components. The selection process typically considers the function and features of the particular devices, including their port densities, packet throughput, expandability capabilities, and readiness to provide redundant connections.

Add a note here Software Selection

Add a note hereThe next step is to select the appropriate software features; when using Cisco equipment, the software is the Cisco IOS. As illustrated in Figure 5-21, the Cisco IOS Software has been optimized for different markets, network roles, and platforms. Cisco IOS Software meets the requirements of various markets (enterprise, service provider, and commercial) and places in the network (access, core and distribution, and edge).

Click to collapse
Add a note hereFigure 5-21: Cisco IOS Software in the Network

Add a note hereCisco IOS software product lines share a common base of technologies. Most of the features available in the T releases for a given technology are also available in the S and XR releases.

Add a note here Cisco IOS Software Packaging

Add a note hereCisco is migrating to using Cisco IOS Packaging to simplify the image-selection process by consolidating the total number of packages and using consistent package names across all hardware products. Figure 5-22 illustrates the various packages available with Cisco IOS packaging.

Click to collapse
Add a note hereFigure 5-22: Cisco IOS Packaging

Add a note here Four packages have been designed to satisfy the requirements in base service categories; they are as follows:

  • Add a note here IP Base: Supports IP data

  • Add a note here IP Voice: Supports converged voice and data

  • Add a note here Advanced Security: Provides security and VPN

  • Add a note here Enterprise Base: Provides enterprise Layer 3 protocols and IBM support


Note

Add a note hereThe features of the lower-tier packages are included in the higher-tier packages.

Add a note hereThree additional premium packages offer new Cisco IOS Software feature combinations that address more complex network requirements:

  • Add a note here SP Services: Adds SP features, including MPLS, ATM, Secure Shell (SSH) and NetFlow, to the IP Voice package

  • Add a note here Advanced IP Services: Adds advanced SP services to the Advanced Security package

  • Add a note here Enterprise Services: Adds advanced SP services to the Enterprise Base package

Add a note hereAdvanced Enterprise Services, which integrates support for all routing protocols with voice, security, and VPN capabilities, includes all the features of the other packages.


Note

Add a note hereCisco IOS Packaging is available for Cisco IOS Release 12.3 on some Cisco Integrated Services Routers (ISR). Most Cisco access, distribution or aggregation, and core routers, and other hardware that runs Cisco IOS software, will support Cisco IOS Packaging in the future.

Add a note hereAfter a feature is introduced, it is also included in the more comprehensive packages. Cisco calls this the feature inheritance principle of Cisco IOS Packaging; it provides clear migration, clarifying the feature content of the various packages and how they relate to one another.

Cisco IOS Packaging Technology Segmentation

Add a note here Table 5-5 illustrates some of the technologies supported in the various Cisco IOS packages.

Add a note here Table 5-5: Cisco IOS Packaging Technology Segmentation
Open table as spreadsheet

Add a note hereData Connectivity

Add a note hereVoIP and VoFR[1]

Add a note hereATM, VoATM[2], MPLS

Add a note hereAppleTalk, IPX[3], IBM Protocols

Add a note hereFirewall, IDS[4], VPN

Add a note hereIP Base

Add a note hereX

Add a note hereIP Voice

Add a note hereX

Add a note hereX

Add a note hereAdvanced Security

Add a note hereX

Add a note hereX

Add a note hereEnterprise Base

Add a note hereX

Add a note hereX

Add a note hereSP Services

Add a note hereX

Add a note hereX

Add a note hereX

Add a note hereAdvanced IP Services

Add a note hereX

Add a note hereX

Add a note hereX

Add a note hereX

Add a note hereEnterprise Services

Add a note hereX

Add a note hereX

Add a note hereX

Add a note hereX

Add a note hereAdvanced Enterprise Services

Add a note hereX

Add a note hereX

Add a note hereX

Add a note hereX

Add a note hereX

Add a note here [1]VoFR = Voice over Frame Relay

Add a note here [2]VoATM = Voice over ATM

Add a note here [3]IPX = Internetwork Packet Exchange

Add a note here [4]IDS = Intrusion Detection System

Comparing the Functions of Cisco Router Platforms and Software Families

Add a note here Table 5-6 compares the functions of the Cisco router platforms and the software families that support them.


Note

Add a note hereThe specific router platforms and software releases available will change over time; refer to http://www.cisco.com/ for the latest information.

Add a note here Table 5-6: Comparing Cisco Router Platforms and Software Features
Open table as spreadsheet

Add a note here Hardware

Add a note hereSoftware

Add a note hereFunction

Add a note here3560, 3750

Add a note hereCisco IOS T Releases 12.3, 12.4, 12.3T, 12.4T

Add a note hereSupports access routing platforms, providing fast, scalable delivery of mission-critical enterprise applications

Add a note here7200, 7301, 7304, 7500, 10000

Add a note hereCisco IOS S Release 12.2SB

Add a note hereDelivers midrange broadband and leased-line aggregation for Enterprise and SP Edge networks

Add a note here7600

Add a note hereCisco IOS S Release 12.2SR

Add a note hereDelivers high-end Ethernet LAN switching for Enterprise access, distribution, core, and data center deployments, and high-end Metro Ethernet for the SP Edge

Add a note here12000, CRS-1

Add a note hereCisco IOS XR

Add a note hereProvides massive scale, continuous system availability, and service flexibility for SP core and edge (takes advantage of the massively distributed processing capabilities of the Cisco CRS-1 and the Cisco 12000)

Comparing the Functions of Multilayer Switch Platforms and Software Families

Add a note here Table 5-7 compares the functions of the Cisco multilayer switch platforms and the software families that support them.

Add a note here Table 5-7: Comparing Cisco Multilayer Switch Platforms and Software Features
Open table as spreadsheet

Add a note hereHardware

Add a note hereSoftware

Add a note hereFunction

Add a note here800, 1800, 2800, 3800, 7200

Add a note hereCisco IOS S Release 12.2SE

Add a note hereProvides low-end to midrange Ethernet LAN switching for Enterprise access and distribution deployments

Add a note here4500, 4900

Add a note hereCisco IOS S Release 12.2SG

Add a note hereProvides midrange Ethernet LAN switching for Enterprise access and distribution deployments in the campus, and supports Metro Ethernet

Add a note here6500

Add a note hereCisco IOS S Release 12.2SX

Add a note hereDelivers high-end Ethernet LAN switching for Enterprise access, distribution, core, and data center deployments, and high-end Metro Ethernet for the SP Edge


Note

Add a note hereThe specific multilayer switch platforms and software releases available will change over time; refer to http://www.cisco.com/ for the latest information.



0 comments

Post a Comment