1 directories and policy-based networking - strassner directories & policy-based networking...
TRANSCRIPT
1Directories and Policy-Based Networking - Strassner
Directories & Policy-Based Networking
0827_02F8_c1
John StrassnerCisco Systems
2Directories and Policy-Based Networking - Strassner
UsersApplications
Computers...
ConfigurationConfigurationComplexityComplexity
Need for Policy
Application/Application/NetworkNetwork
IntegrationIntegration
Network DevicesNetwork ServicesNetwork Resources
IntelligentNetwork
InconsistentInconsistentPoliciesPolicies
3Directories and Policy-Based Networking - Strassner
Policy-Based Networking
Directory
EnabledDirectory
Enabled
User
Requirements
User
Requirements
Net
wo
rkS
ervi
ces
Net
wo
rkS
ervi
ces
4Directories and Policy-Based Networking - Strassner
What is a Network Policy?
Linkage Between User, Applications, and Network Services
Enterprise Policy
Mobility
FirewallsCampus
• What are my policies?
• Where are my users?
• What are their privileges?
UNIVERSALUNIVERSALPASSPORTPASSPORT
KjkjkjdgdkkjdkjfdkI kdfjkdjIkejkejKkdkdfdKKjkdjdKjkdjfkdKjkdKjdkfjkdj Kjdk
USA
************************
************************
Kdkfldkaloeekjfkjajjakjkjkjkajkjfiejijgkd
kdjfkdkdkdkddfkdjfkdjkdkdkfjdkkdjkfd
kfjdkfjdkjkdjkdjkajkjfdkjfkdjkfjkjajjajdjfla
kjdfkjeiieiefkeieooei
5Directories and Policy-Based Networking - Strassner
Prioritize Applications
QoSPolicyServerQoS
PolicyServer Net Manager
CampusBackbone
TrainingServers
PublicFrame Relay
Order Entry, Order Entry, Finance, Finance,
ManufacturingManufacturing
RemoteCampus
• Create QoS policy» Mission-critical—high
• Distribute policy bindings» QoS Policy Servers
» Network enforcement nodes
6Directories and Policy-Based Networking - Strassner
Restrict Multimedia ApplicationsQoSPolicyServerQoS
PolicyServer Net Manager
CampusBackbone
TrainingServers
PublicFrame Relay
Order Entry, Order Entry, Finance, Finance,
ManufacturingManufacturing
RemoteCampus
• Create QoS policy» Multimedia bandwidth
less than 100 kbps
• RSVP Proxy
• Policy enforcement
7Directories and Policy-Based Networking - Strassner
PSTNISDN
Campus Backbone
AS 5300
Remote Access Policy
Mobile Users
EncryptedEncryptedID/PasswordID/PasswordID/PasswordID/Password
ID/PasswordID/PasswordID/PasswordID/Password
ID/PasswordID/PasswordID/PasswordID/PasswordID/PasswordID/Password
CiscoSecure
Telecommuters
• Authentication, Authorization, Accounting (AAA)
• Centralized administration
8Directories and Policy-Based Networking - Strassner
New Management Paradigm
• New Model for Integrationthe Management Intranet
»WEB Link integration»WEB Data Integration»WEB Task Integration
• Knowledge-Based Operationsfor Assured Network Services
»Local network knowledge»Vendor-augmented knowledge»Change notification
9Directories and Policy-Based Networking - Strassner
</XML>HTTP,
LDAP, etc.
Data Description
TransportEncoding
Access
WBEM Environment
10Directories and Policy-Based Networking - Strassner
The Management Intranet
Heterogeneous Management Servers
Cisco MicrosoftIntel CompaqBMC
CIM/XML CIM/XML
CIMDENXMLMOF
Directory
Device ID
DigitalCertificate
11Directories and Policy-Based Networking - Strassner
OtherVendor
Intelligent Network Management
Device Device Device DeviceService Service Device DeviceService
Helpdesk, Trouble-ticket, Event-Based Middleware
DatabaseAppSystem
ManagementServer DesktopNetwork
OtherVendor
Service
12Directories and Policy-Based Networking - Strassner
Role of Directories
• Common information model
• User profiles, applications, and network services
• Single-user identity
• Integrated policies
Desktop
Application
User
Network
Integration
Directory Directory ServicesServices
13Directories and Policy-Based Networking - Strassner
Multi-Service Profiles
cisco.com Password = cisco vpdn:tunnel-id=cisco-gw vpdn:ip-addresses=1.1.1.2 vpdn:nas-password=12000 vpdn:gw-password=GSR
VoIP Password = cisco vpdn:tunnel-id=voip-gw vpdn:ip-addresses=3.3.2.1 vpdn:nas-password=pin vpdn:gw-password=drop
Games Password = cisco vpdn:tunnel-id=games-gw vpdn:ip-addresses=3.1.3.1 vpdn:nas-password=Space vpdn:gw-password=Invader
Service ProfilesUser Profiles
jdoe Password = letmein Service = Internet Service = cisco.com Service = Games
GroupA Service = Internet Service = coke.com Service = Games
Dashboard
Guest Password=No Password Service = Internet Service = VoIP Service = Games
jdoe
********
Go
Services
Internet
username
password
GamesCisco
14Directories and Policy-Based Networking - Strassner
Scalable Policy Infrastructure
Server
Cache
LDAPLDAP
PolicyEngine
PolicyEngine
Security
Addresses
RADIUS
DNS/DHCPLDAPLDAP
LDAPLDAP
DistributedPolicy Enforcement Intelligent
InfrastructureCentral Policy
Repository
Services and SLAs
User and Devices
Profiles and PoliciesPolicyEngine
QoS
LDAPLDAP
15Directories and Policy-Based Networking - Strassner