DC LAN infrastructure - Mirror network for monitoring

Hi experts,
Does anyone have implementations examples of a "mirror" network in large datacenters designs for monitoring purpouses using TAPs (ex. netoptics or gigamon)? I'm evaluating some monitoring solutions but it's mandatory to configure mirroring on the switches to capture the traffic on the network. As the DC is large and there are another devices that need mirroring (IDSs, IPS, Probes) I'm thinking in implement a "mirror network" in all datacenter using TAPs. I'd like to see some implementations examples of a "mirror network" to evaluate if this strategy is viable.
Thanks in advance
Wesley

- OM3 multimode fiber
- Distribution network Gigabit SFP 1000Base T and FTP
There are so many combination of how to implement this project and it all boils down to your budget.   
The two items I've highlighted are "old school".  
- Poe for access switches
What kind of PoE?  PoE, PoE+ or uPoE.  
- Wardrobe 1 (150 Data and VoIP)
- Wardrobe 2 (60 Data and VoIP)
- Wardrobe 3 (200 data and VoIP)
Breakdown of how many PoE devices (and their respective power draw) per switch.  

Similar Messages

  • Migrating from SonicWALL to RRAS - questions on functionality for business network setup & monitoring

    At my organization we are planning to move away from using SonicWALL and using Microsoft Server 2012 RRAS to handle IPv4 NAT routing and VPN connections for remote employees.  I am trying to plan for all the functionality I currently have in our
    SonicWALL router, and I'm not familiar with the Windows equivalent for some features and/or if the available features will have all the  functionality our organization needs.  Additionally wondering if there is something better that you would recommend
    in terms of ease-of-use / management from an IT standpoint. 
    Feature:  Firewall
    I assume that Windows Advanced Firewall can handle all the firewall settings that I would normally find in an enterprise router.  Is this a correct assumption?
    Feature:  Content blocking
    What Microsoft technology would I use for blocking certain content and websites from being viewed in the workplace network?  Can Windows Firewall handle these two types of content blocking?:
    Blocking websites by general content - i.e. block porn sites. 
    Blocking websites by specific URL
    Feature:  Network activity monitoring
    In cases where the network is slow, what would I use to inspect what IP/MAC is hogging bandwidth?  Currently on SonicWALL we are able to see which computer is hogging bandwidth, see what website is, how much bandwidth it is consuming.  Can RRAS
    handle this level of detail, or is SCOM / some other technology more well-suited?  Should we use a non-Microsoft application (something like Wireshark) instead?
    Feature: Network prioritization (QoS / bandwidth management)
    Can we set certain network groups to have priority over others?  For example, if we split our incoming network into two networks using RRAS, 192.168.50.x for data and 10.0.50.x for VOIP, I want the VOIP network to get priority in order to
    ensure quality audio on all phone calls.  I assume this is available in RRAS.
    Basically I'm just looking to see what systems I need set up to satisfy these business needs.  If anyone has any real-world experience let me know what your setup is like -- I'm curious to know! 

    "I assume that Windows Advanced Firewall can handle all the firewall settings that I would normally find in an enterprise router.  Is this a correct assumption?"
    Your statement as it stands is correct.  In fact, Windows firewall will handle more firewall settings than those found in a
    router.  However, SonicWall is not just a router - it's a firewall.  There is a big difference. Given that you are comparing Windows Firewall to a robust firewall, I agree with Dennis that you should either stay with SonicWall or
    look at Microsoft's product.  But, given that on the link Dennis provided, you will find that Microsoft is discontinuing UAG, you might want to stick with what you know - SonicWall.  Or, you need to evaluate your needs more.  Yes, Microsoft
    provides a number of built-in capabilities that may address your particular needs.  We can't answer that.  But, if there are features you need that are not available via Windows Server, then it is best to get a product that addresses those needs.
    .:|:.:|:. tim

  • I'm looking for some help connecting linksys IP Cameras to my home network to monitor my property when I'm travelling. I used to do this with linksys WAPS, but since I've discarded all my old linksys networking and standardized on airport, I can't get the

    I'm looking for some help connecting linksys IP Cameras to my home network to monitor my property when I'm travelling.  I used to do this with linksys WAPS, but since I've discarded all my old linksys networking and standardized on airport, I can't get these things working.  I know that I have to identify my camera through the DHCP table and set up port forwarding and there is the problem. 
    My network consists of 4  base stations set up in a roaming network - same network name and passwords.  I need to do it this way so I don't have to switch network when I move from one side of the house to the other, go to the cabana, or my shop in the barn.  The network works pretty well since I went to a roaming set up.  Good performance, yata, yata, yata.
    However, the roaming network requires the AEBS's to be set up in bridge mode, rather than sharing an ip address.  When the AEBS is set to  bridge mode, you don't see a DCHP table or have the ability to identify your IP Cam through the AEBS - and hence, no port forwarding. 
    I am able to identify and set up my Linksys IP Cam by locating the ip address on my FIOS router, even though, it's plugged into an AEBS.  I set it up, see the video, remove the ethernet cable from the IP Cam, restart - and I can't get to it from an AEBS.  In researching this, it appears, I should be setting up the AEBS to "share an IP Address", going to the DHCP table and identifying the camera's IP address and setting up port forwarding.  However, you don't see any of the DHCP or port forwarding options in Airport Network Utility when configuring in bridge mode. 
    I'm hoping I'm missing something here and that the solution isn't to set it up at the FIOS router level, but I'm beginning to think that's my only hope.  What concerns me there is that I should be able to see the IP cam on the network without port forwarding since I'm not coming from outside, and I can't even do this unless it's connected hard wire.
    I'd appreciate any insight into this that anyone might have.  I've hit the wall with what I know.
    Thanks.

    In a roaming network, your "main" router is the device that would require port mapping/forwarding to be configured in order to access the IP camera from the Internet. This router is also the one that would be provide the private IP address for the camera which you will want to be a static one.
    So as you described your network, the IP cameras should be getting an IP address or you assigned it a static one and this is the address that you would enter in the Private IP address (or equivalent depending on the router used) field when setting up port mapping.
    If you are not able to access this camera from the local network, then this should be troubleshot first.

  • Scanning the network for devices with Network Monitor

    At the moment there are no way to scan your network for devices. And I think there is a good reason for not doing so. If your users shut down their PC when their day is done - do you need an alert for that? 
    They way this is designed is for you to decide which devices is the most important, so much that it demands live monitoring.

    Are they going to add the ability to scan the network for devices instead of having to manually add them? I've seen it in the inventory management but can't find a way to do it in the Network Monitor. I apologise if you can already do this but I haven't figured it out myself.
    This topic first appeared in the Spiceworks Community

  • How to mirror to tv monitor using macbook pro 2012

    how to mirror to tv monitor using macbook pro 2012.  The airplay is not displayed anywhere except I Tunes which only plays what is on I Tunes.

    Howdy there nell a-7,
    It sounds like you are not seeing the Airplay icon in the menu bar on your Mac but you do see it in iTunes. I would use these steps from the following article to help troubleshoot the issue:
    iOS: Troubleshooting AirPlay and AirPlay Mirroring
    http://support.apple.com/kb/TS4215
    Try these steps first
    Verify that your iOS device's software is up to date.
    Verify your Apple TV's software is up to date.
    Verify that your iOS device has Wi-Fi turned on. Enable Wi-Fi on your iOS device by going to Settings > Wi-Fi.
    All AirPlay-enabled devices must be connected to the same Wi-Fi network.
    Some Wi-Fi network configurations offer a Guest Network. On your Apple TV, go to Settings > General >Network and ensure that you're connecting to the same Wi-Fi network on your iOS device. On your iOS device, tap Setting > Wi-Fi and confirm that this matches your Apple TV.
    If the AirPlay icon doesn't appear
    Ensure that you have followed the steps in using AirPlay and AirPlay Mirroring.If you are still unable to see the AirPlay icon  , try one of the following steps:
    If trying to AirPlay, or AirPlay mirror, to your Apple TV, ensure that AirPlay is enabled on your Apple TV as well. You can enable or disable AirPlay on Apple TV in the AirPlay menu: Settings > AirPlay.
    Check Internet or network connectivity on all affected devices.
    Some content requires an Internet connection to authorize content playback. AirPlay capabilities may be limited if your network is not connected to the Internet.
    If attempting to use AirPlay from a third-party app or a website from your Safari app on your iOS device, confirm that the app or website is AirPlay compatible (refer to the developers of the app or website for additional information).
    Here is some additional information about Airplay for Mac:
    About AirPlay Mirroring in OS X
    http://support.apple.com/kb/HT5404
    Thank you for using Apple Support Communities.
    All the best,
    Sterling

  • Should I create a separate network for iOS devices?

    My family and I are leaving the Windows platform and going Mac/Apple.  Here's what we have:
    3 iPhones, 2 iPads, new iMac (coming from Santa for the kids), new MacBook Pro 15.4 with retina, Roku 3, and possibly thinking of trying Apple TV (to compare to the Roku).
    I have wireless internet through ATT U-verse and their 2Wire router.  I am getting the Airport Time Capsule 2TB today.  My question is...should I setup the airport time capsule as a separate wifi network for all my iOS devices, or should I just extend the current 2WIRE ATT U-verse wireless network?  I think the easiest thing to do would be setup the Airport TC in bridge mode to extend the network.  But I recall reading a blog post where someone set up a separate network on the Airport TC for all his apple products.  This sounded like a great idea because from what I understand, the iOS devices can take advantage of the Airport TC offering a better speed.  Of course, I can't find the article anywhere (Murphy's Law).  My thought is to keep my work laptop (windows) and the Roku 3 on the 2Wire network and the iOS devices on a separate network.
    I'm new to apple products (except the phone haha) so what does the community recommend?
    Thanks in advance,
    AC

    Would the best solution be to extend my current by network running a cable from the LAN port of the uverse router to the WAN port of the airport time capsule?  This would create another wireless AP, correct?  I simply do what you said...use the same wireless name (SSID), security protocol, and password of the uverse router on the airport time capsule and I'm all set.  But I think the airport utility has an option to "Add to an existing network."  Is this the setup I should choose?  I believe you have reference this kb article in another discussion post.  Thanks again for your help.
    This is the way I would do it.. but there is no right and wrong here.. just options with different uses..
    The cable backbone is ideal.
    You are creating another AP.. yes.. and that is why it works.. extend by wireless is slow. You are using wireless in one hop connections.
    Everything else is running over fast ethernet or gigabit hopefully.
    I am not sure if the add to existing network will work correctly.. if you have the TC plugged in by ethernet it should.. but manual setup of this is trivial.
    Bridge the TC as per my previous post.. setup wireless exactly as normal but use same ssid and security setup.. simple to the point of trivial.
    Roaming I must add is perfect in theory.. in practice stuff doesn't always swap "towers" the way you idealize.. it stays stuck to the poorer signal when a better one is right next to it.
    That is the nature of wifi. A voodoo technology.. 80% black arts. and 50% science.. (in voodoo it has poor maths).

  • Main network for backups, Guest for iTunes

    I have a 2T TC (4th gen) up and running with both a main network (192...) and a guest network (172...) connected to DSL modem for high-speed internet access.
    I want to dedicate the main network for use by family members - computers (4 Macs, 2 PCs), printers, etc. I wish to use the guest network for the kids and their friends to access the internet with their iPods/Pads/Phones, etc. So far so good.
    I currently have the kids controlling iTunes/AirPlay into my whole house audio system. I configured an old PC configured as a music server connecting wirelessly to the main (192) net of the TC. It runs iTunes and sends its Apple Lossless CD files to an AirPort Express (wireless OFF, hardwired to Ethernet backbone) which converts them to optical and sends them to an audio receiver for D/A conversion and amplificaiton. The kids have the "Remote" app on their handhelds which allows them to either operate iTunes on the music server (with Dad's old crummy music) or to play their own iTunes music (term used loosely) via the same route (TC main net-> backbone -> AirPort -> receiver). OK, so far so good.
    The question is how do I put the music server, AirPort Express and kids' handhelds on the guest network so I don't have to give out access to my main network to "friends of friends of friends"? It seems the Guest Network is only available wirelessly from the TC (on second floor). If i need to add wireless capability where the TC can't provide it (walkout level pool and patio), how can I extend the guest network? I have an older Netgear Wireless Routher that could be used. Also, I have ready acess to the ethernet backbone. Any ideas? Any help would be greatly appreciated.

    This is a fairly complex setup so let me toss in a hint.. and you will need to see if you can pursue it. Your ethernet backbone, so called, can run multiple IP address ranges or subnets. It is not obvious but the setup will require you to set addresses manually in the computer.
    In OSX Just click the + in the network box and a dialogue box will pop up allowing you to set a secondary connection to either airport or ethernet. Select the one to use and then give the connection an obvious name.. eg secondaryeth1
    In Windows PC you can setup secondary IP, but the first connection needs to be manually set as well. ie you cannot do dhcp and then add a secondary IP.
    Then select that connection and give it a new IP in the secondary network using manual IP.. only give ip and subnet.. do not use a gateway (router) or dns address.. that will confuse the main gateway of the computer. You can then lose internet connection, and is not required for local LAN connection.
    .. end of hint.
    Pure speculation.. you might be able to setup a secondary IP on the airport and connect to the guest network. But you will need to be careful that the server pc doesn't simply become a bridge between the two networks.
    Or the connection to secondary IP via ethernet might allow it connect to the wireless connection on the TC if it isn't isolated.
    The other method is to use your "I have an older Netgear Wireless Routher that could be used."
    The trick here would be to use this as a WAP connected directly to the music server, via ethernet, on a secondary IP address. Don't use the guest network on the TC at all.
    Whether this would then work to control music to the airport express.. that is where I get lost. And your setup is outside of my experience..

  • HT201335 Will AirPlay mirroring work for watching TV episodes from the Internet?

    Will AirPlay mirroring work for watching TV episodes from a television network's website that we have up on the iPad/iPhone/computer or is it just for iTunes?
    We're contemplating canceling our cable and using Apple TV solely.  if it will do that, it sounds like a good option for us.

    If your Mac is 2011 or newer and you install OS X Mountain Lion on it, you will be able to mirror your screen to the AppleTV. DVD playback won´t work.
    Airplay Mirroring compatible Macs:
    iMac (Mid 2011 or newer)
    Mac mini (Mid 2011 or newer)
    MacBook Air (Mid 2011 or newer)
    MacBook Pro (Early 2011 or newer)
    More info: http://www.apple.com/osx/specs/
    As for your iOS devices it depends on the player app being used to play the video. Some players will let you stream the video to your AppleTV others won't. For example, the YouTube player will allow it, but the Netflix player won`t.

  • Do we need both management Pack and ADP  for monitoring SOA suite 11g

    Hi,
    Do we need to Both management pack and ADP (OCAMM) Application Dependancy and Performance for monitoring SOA Suite 11g.
    I was creating a monitoring template for SOA Composite and SOA Infrastructure and wanted to know if I need to install additional ( management packs, ADP and Middleware Plugins ) packs to get an effective template.

    A management pack generally refers to the set of pages in EM Grid/Cloud Control which provide functionality for a given set of target types. Since EM Grid Control 11g, the ADP functionality has been part of the Grid Control release and the pages licensed via the Management Pack Plus for SOA or the SOA Management Pack EE.
    To populate the ADP pages with data, additional steps must be performed in order to deploy an ADP manager and ADP agents. Doing this is optional, depending on whether or not you require the additional capability that those pages provide.
    ADP data, however, are collected and stored separately from the core GC/CC metrics and are not related to the monitoring template functionality.

  • Dedicated network for AlwaysON replication traffic when a replica is a Failover Cluster Instance

    Hi,
        We are planning to setup dedicated network for our Availability Group replication traffic. We have a Failover Cluster Instance as the primary replica and a standalone SQL server instance as the secondary. 
        I understand that we will need to manually configure the database mirroring endpoints on both the replicas to listen on the specific IP. 
       But how do I configure the database mirroring endpoint on the Failover Cluster Instance ?
    Please help.
    Thanks and Regards,
    Jisha

    If you have a dedicated network for your Availability Group replication traffic between the FCI and the standalone instance, you need to identify if there will be other network services included in the mix. For example, your public network is already using
    it's own DNS server by virtue of Active Directory integration. Your dedicated network for replication traffic may or may not have its own DNS server so configuring the endpoints would involve using either IP addresses like the one highlighted in the
    blog post or using hosts file with fully qualified domain names so you can use them when creating the endpoints
    Edwin Sarmiento SQL Server MVP | Microsoft Certified Master
    Blog |
    Twitter | LinkedIn
    SQL Server High Availability and Disaster Recover Deep Dive Course

  • Using second wireless network for client Hyper-V VMs

    Hello all,
    I have a question concerning client Hyper-V on Win8.1 Pro Preview and wirelessly connecting only the VMs. I'm a student at a university and the university wired Ethernet network only allows 2 devices to be registered per student. So for me, those 2 would
    be the host OS and my Xbox, which leaves no room for any of my VMs. I need a way to connect my VMs to the wireless network (which has no such limitations) mostly for programming assignments using Linux.
    I'm thinking of buying a wireless NIC for my desktop and using that as a second external switch that the VMs will use for connectivity. The host will use the first external switch that currently exists. However, I'm not sure how I can keep the host on the
    wired LAN while also installing a wireless NIC only for the VMs. Do I install the NIC, make it an external switch without host access, then join the network? Or do I join the network first then set it up as a virtual switch? Can client versions of Windows
    handle multiple simultaneous NICs?
    Also, would the host even need an external switch in this case? I have one since I set up the VMs at home where all machines can use the wired NIC.

    Ahh, that's right. check out this post.  This should explain the problem and offer a workable solution.
    Hi,
    I remember some articles mentioned Windows Hyper-V does not allow you to bind a wireless network adapter to a virtual machine.
    Since the virtual switch in Hyper-V is a “layer-2 switch,” which means that it switches (i.e. determines the route a certain Ethernet packet takes) using the MAC addresses that uniquely identify each (physical and virtual) network adapter card. The MAC address
    of the source and destination machines are sent in each Ethernet packet and a layer-2 switch uses this to determine where it should send the incoming packet. An external virtual switch is connected to the external world through the physical NIC. Ethernet packets
    from a VM destined for a machine in the external world are sent out through this physical NIC. This means that the physical NIC must be able to carry the traffic from all the VMs connected to this virtual switch, thus implying that the packets flowing through
    the physical NIC will contain multiple MAC addresses (one for each VM’s virtual NIC). This is supported on wired physical NICs (by putting the NIC in promiscuous mode), but not supported on wireless NICs since the wireless channel established by the WiFi NIC
    and its access point only allows Ethernet packets with the WiFi NIC’s MAC address and nothing else. In other words, Hyper-V couldn’t use WiFi NICs for an external switch if we continued to use the current virtual switch architecture.
    To work around this limitation, you can use Microsoft Bridging solution. Create an Internal network, name it “External”, system will create a Virtual Network adapter for it. Create Network Bridge between your WiFi NIC and the Virtual External Network adapter.
    Assign External network for your VMs, so they have internet connection.
    For more information please refer to following MS articles:
    Bringing Hyper-V to “Windows 8”
    http://blogs.msdn.com/b/b8/archive/2011/09/07/bringing-hyper-v-to-windows-8.aspx
    Hyper-V: How to Run Hyper-V on a Laptop
    http://social.technet.microsoft.com/wiki/contents/articles/185.hyper-v-how-to-run-hyper-v-on-a-laptop-en-us.aspx
    Configuring Virtual Networks
    http://technet.microsoft.com/en-us/library/cc816585(v=WS.10).aspx
    Hope this helps!
    TechNet Subscriber Support
    If you are
    TechNet Subscription user and have any feedback on our support quality, please send your feedback
    here.
    Lawrence
    TechNet Community Support
    source: 
    http://social.technet.microsoft.com/Forums/windowsserver/en-US/d9fb7866-0fbc-4c06-b8ea-df3c35c75c74/windows-8-hyperv-bridged-wifi-issues-when-creating-virtual-machines
    Remember to select 'Mark as Answer' for any reply that provided a solution

  • [Request] NTM - Network Traffic Monitor

    Hi to everyone:
    Could anyone package this?: NTM - Network Traffic Monitor
    NTM is a monitor of the network and internet traffic for GNU/Linux. Some characteristics:
        * Choice of the interface to monitoring.
        * Period to monitoring: Day, Week, Month, Year or Custom Days. With autoupdate.
        * Threshold: Autodisconnection if a limit is reached (by NetworkManager).
        * Traffic Monitoring: Inbound, outbount and total traffic; Show the traffic speed.
        * Time Monitoring: Total time of connections in the period.
        * Time Slot Monitoring: Number of sessions used.
        * Reports: Show of average values and daily traffic of a configurable period.
        * Online checking with NetworkManager or by "Ping Mode".
        * The traffic is attributed to the day when the session began.
        * Not need root privilege.
        * Not invasive, use a system try icon.
    NTM is useful for the people that have a internet plan with a limit, and moreover the exceed traffic is expensive.
    NTM is write in python and is a open source software, the license is the GNU GPL v2.
    A lot of thanks.

    #Maintairner: Brieuc Roblin <brieuc.roblin at gmail dot com>
    pkgname='ntm'
    pkgver='1.2.2'
    pkgrel='1'
    pkgdesc="Monitor of the network and internet traffic"
    arch=('i686' 'x86_64')
    license=('GPL')
    depends=('pywebkitgtk' 'lsb-release' 'networkmanager')
    makedepends=('dpkg')
    url=('http://netramon.sourceforge.net/eng/index.html')
    source=('http://freefr.dl.sourceforge.net/project/netramon/NTM/ntm-1.x/ntm-1.2.2.deb')
    md5sums=('ec438b8c952ac866ffdaa57538d189b7')
    build() {
    cd "$srcdir"
    # Extracting deb
    msg2 "Extracting .deb ..."
    dpkg-deb -x ntm-*.deb deb
    cd "deb"
    # Installing
    msg2 "Installing..."
    cp -r . "$pkgdir"/
    I can't really test the program as I'm not using NetworkManager.
    Last edited by PyrO_70 (2010-08-20 19:18:24)

  • Is there an app for monitoring CELLPHONE usage? (Not data, calls, SMS, etc.)

    Hey! Is there an app for monitoring CELLPHONE usage? (Not data, calls, SMS, etc.). I know there's for data, but I wanna know if there's one that keeps track of calls, SMS, etc.
    Thanks!

    Unless O2 has an app available via the iTunes app store that provides for this as AT&T does for the iPhone sold in the U.S., I don't believe so.
    The iPhone includes a usage indicator for Call Time and Cellular Network Data usage, which can be reset on a monthly basis based on your billing cycle, but there is no usage indicator for the number of messages sent or received.

  • Why no mirroring button for AirPlay in ios 8.1

    There is no mirroring button for AirPlay in ios 8.1' I've read another forum that says you just need to scroll up, I have done that and it is simply not there up or down scroll. Please help, can no longer multitask.
    Jay

    Really guys, there has always been a mirroring switch it mirrors your screen to your Apple TV, and of course you have to be on the same wifi network I'd have to be an idiot not to know that. The control center is there the AirPlay is there, the option for Apple TV is there, it streams but no mirroring on off switch is present. Please don't answer questions with this type of stuff.

  • IPS-ME - Remote Monitoring - Running server on workstation for monitoring..

    Hi,
    Is there any way to use IPS-ME on a remote windows workstation for monitoring.
    I have 5 sensors that I want to configure with IPS-ME on a windows 2k3 server. The server will be in the Data Center and it will be use to config and monitor the sensor alerts.
    I am wondering how the users will be monitoring events since IPS-ME is not running on their workstation...
    Is windows Remote Desktop to my IPS-ME server the only option?
    Thanks,
    JP

    Remote Desktop, VNC etc. seems to be the only option. Unless you want to run multiple instances of IME, but this will be very resource intensive for your Sensors, Network, End-Systems and might severely degrade performance.
    The best option is to get a Cisco MARS box and correlate all meaningful alerts in a single web browser, where all Security Admins can login and take relevant actions.
    Regards
    Farrukh

Maybe you are looking for