Documenti di Didattica
Documenti di Professioni
Documenti di Cultura
Core Values
1 2
3 4
Continuous Improvement
Continuous Improvement Discipline through Lean and Six Sigma Methods Business Transformation
Technology Overview
Major Benefits
On-demand full mesh connectivity with simple hub-and-spoke configuration Automatic IP Security (IPsec) triggering for building an IPsec tunnel Near Zero-touch deployment for adding remote sites Reduced latency and bandwidth savings Fully supports enterprise dynamic routing protocols Supports dynamically addressed spokes (remote sites)
Applications
Cost-driven use of Internet to replace or backup MPLS-based WAN topologies while providing platform for distributed applications such as voice (in context of proper engineering design considerations).
Network Design Design, Redundancy and Scaling Routing Dynamic routing protocols Encrypting peers Finding, mapping and authenticating
WE HELP BUILD THE WORLD 2
1 tunnel interface configured per remote site Individual access-lists, crypto map polices and isakmp shared-keys.
Hardware Requirements
Model
Switch Ports
License
20 20 50 50 50 50 100
Need to purchase Advanced IP Services License Need to purchase Advanced IP Services License Comes with Advanced IP Services License Comes with Advanced IP Services License Need to purchase Advanced IP Services License Need to purchase Security Feature License Need to purchase Advanced IP Services License
Hardware Requirements
Model Part Number Description US List Price UK List Price
End of Sale: July 15, 2010 Cisco 881 Ethernet Sec Router Cisco 881 Ethernet Sec Router 802.11n FCC Comp Cisco 881 Ethernet Sec Router 802.11n ETSI Comp $649 $999 $999 446 686 686
CISCO891-K9
CISCO891W-AGN-A-K9
$1,295
$1,845 $1,295 $1,845
890
1,268 890 1,268
892 1800
CISCO892-K9 CISCO892W-AGN-E-K9
Cisco1921/K9 with 2GE, SEC License PAK, 512MB DRAM, 256MB Fl Cisco 1941 Security Bundle w/SEC license PAK Cisco 1941Security Router, 802.11 a/b/g/n AP ETSI Compliant Cisco 1941 Router w/ 802.11 a/b/g/n FCC Compliant WLAN ISM End of Sale: Nov 1, 2011
880 1900
SL-880-AIS L-SL-19-SEC-K9=
Cisco 880 Advanced IP Services License Security E-Delivery PAK for Cisco 1900
$150 $1,000
103 687
SmartNet Requirements
The following support package for the router should be purchased which provides a warrantee and technical support from Cisco systems.
SmartNet can be purchased and managed though LaSalle in the near future
Analog
Modem
EMEA - USR015630D USRobotics 56K External Data/Fax Modem V92 Americas - USR5686E USRobotics 56K External Data/Fax Modem V92
3G
If an analog line is not available at a location, a 3G connection might be able to be used to provide out of band access. GIS is researching the equipment that will be needed for this type of access and the price.
To preserve the bandwidth on the HADC Internet connections, the DMVPN routers will have a rate limit on HADC Tunnel interfaces only. There will not be a rate limit on traffic between DMVPN locations.
ISP Questions
Is this circuit ADSL, SDSL or a dedicated internet circuit? What are the upsteam and downstream bandwidth speeds? Is the circuit provisioned without NAT?
Are there any proxies/firewalls or other devices that may negatively impact the functioning of IPSec traffic on the ISP network?
Is/are the IP address(es) assigned static (non-changing)? Is the default gateway for this assigned static (non-changing)? If using DSL, will the IP addressing be assigned dynamically?
If using DSL, will the ISP router/modem be required to run in bridge mode to avoid the use of NAT?
If using DSL, will ppp authentcation be required on the Harsco router? What type of physical presentation is provided to the Harsco router (i.e. Ethernet, RJ-11 etc)?
Agenda
Pre-test checklist
ISP link validation Router licensing and IOS Site-specific configuration details (site name, DHCP scopes, Sites and Services, etc.)
Post-check checklist
Pre-test checklist
DSL Link with Ethernet handoff and share the bandwidth details to GIS team. Need an Public IP address without NATing . If the Static IP is provided then default gateway should also be provided. If the DSL link terminated as PPPoE then the modem should be configured in a Bridge mode. Connect a Notebook to the ISP link and do the below check Check for Internet connectivity If it is a PPPoE and then setup a dial-up profile and validate the DSL account credentials. MTU test - Ping to Camphill Headend router with below values Ping 72.20.207.59 - l 1500 should be working and take down the latency values. OOB Modem with PSTN connection is required to access the router remotely during migrations/outages. If OOB access is not available then need a 3G data card connected to a Laptop.
Pre-test Check-list
Below are the currently identified Router models for L2L sites. For all these below models to support DMVPN we need to upgrade for permanent license with below IOS versions forIOS File name models respectively. FLASH those each Sl.No Router Model IOS version IOS file size DRA
M 1 2 3 4 5
For 1841 routers we have currently running Advance security license which will not support DMVPN, so we need to upgrade it to Advance IP services license and appropriate IOS image as mentioned in the table. To upgrade we need router and one server/Desktop in the network, so that we can copy the IOS locally and do the up gradation and at the same time we need console access as well.
WE HELP BUILD THE WORLD 16
Pre-test Check-list
Site-specific configuration details (site name, DHCP scopes, Sites and Services, etc.)
TSM need to provide Site Code details GIS will provide the DHCP scope details and raise GDM to create the DHCP scopes and verify these subnets are added in the sites and Services.
Post-check checklist
Already covered in pre-test checklist, but need to ensure that all Intranet applications are working from the site, which can be done during UAT Ping test to both the Data Center servers from PC. Internet /Intranet applications performance. Tracert to both the Data Center servers to verify it is selecting the correct path. User acceptance test Login to Harsco Network from cold boot and note response times Response Time:_______________________________________ Obtain details of the Local Ip Addressing Scheme. Use the ipconfig / all Ping the local Default Gateway Ping the DHCP Server 10.10.0.1 / 10.14.0.1 / 10.10.0.2 Tracert 10.10.0.1/10.14.0.1/10.10.0.2 Tracert/ping to 10.42.4.254 (DMVPN) Login to Harsco Network from cold boot and note response times Test All Divisional Applications which is specific to your regional operation. Test Any Local WAN / LAN Printing Test All Shared Servies From Tier 1 Data Centre Email Portal http://portal.harsco.com Hyperion ASEP Test internet browsing tracert www.bbc.co.uk WE HELP BUILD THE WORLD 18
CiscoWorks
GIS Network team will ensure to update those newly added Router inventory details into it and further fine tune the other parameters to ensure configuration archives happens on regular basis GIS Network team will further also add this new device into tool as eell for further monitoring and other interface BW reports This tool is helpful for capacity planning to find out top-talker in the network, so Network team will configured required parameter on the router LAN interfaces. This is monitoring tool to capture device generated logs to store in a database which further help to look into during any incident cases related to the devices. Network team will ensure to configure on the device for the same. Network team have inventory database maintained for all site devices globally and will update the list accordingly once site is successfully completed with migration.
Whats Up Gold
Netflow
Syslog