DMZ layer design review

Hello,
I would appreciate if some can share their experience/problems with below design between Core-Firewall-DMZ-Aggregation setup.
1. There is a Layer-3 connectivity between core and firewall segments with L3 point-to-point links running OSPF. The active firewall(FW-A) forms ospf neighborship with Core-A and similarly FW-B forms ospf neighborship with Core-B and Core-A / Core-B form ospf neighborship.
2. Aggregation switch and Firewall are connected over L2 trunks and OSPF is running over SVIs (VLAN 13 / bcast segment), Aggregation switch-A is elected as DR and Aggregation switch-B is BDR, both firewalls have configured ospf priority to zero. FW-A(active) forms ospf adjacency with Aggregation-A and Aggregation-B, and each Aggregation switch forms ospf neighborship with the active firewall only.
Is there any chance that the broadcast network b/w Aggregation switch and Firewall can cause any problem when any of the aggregation switch reloads.
I have attached a rough sketch for better understanding.
Regards,
Akhtar

Hello,
I would appreciate if some can share their experience/problems with below design between Core-Firewall-DMZ-Aggregation setup.
1. There is a Layer-3 connectivity between core and firewall segments with L3 point-to-point links running OSPF. The active firewall(FW-A) forms ospf neighborship with Core-A and similarly FW-B forms ospf neighborship with Core-B and Core-A / Core-B form ospf neighborship.
2. Aggregation switch and Firewall are connected over L2 trunks and OSPF is running over SVIs (VLAN 13 / bcast segment), Aggregation switch-A is elected as DR and Aggregation switch-B is BDR, both firewalls have configured ospf priority to zero. FW-A(active) forms ospf adjacency with Aggregation-A and Aggregation-B, and each Aggregation switch forms ospf neighborship with the active firewall only.
Is there any chance that the broadcast network b/w Aggregation switch and Firewall can cause any problem when any of the aggregation switch reloads.
I have attached a rough sketch for better understanding.
Regards,
Akhtar

Similar Messages

  • VSphere 5.5 Design Review Checklist

    In my new assignment,  I am doing Design Review of a vSphere 5.5 Environment.
    Is there a brief Checklist that mentions All the Best Practices; To get me started.
    Thank You !

    Hi,
    Usually companies like IBM, VMware, HP, etc. have their own Reference Architectures.
    A lot of Reference Architectures are  posted publically by VMware. Try to search, if you can find the one which suits your needs.
    If you work in one of the BIG companies, try to check your internal documentations.
    Good Luck

  • BI Technical Design Review Criteria/Best Practice Assessments

    Dear Experts,
    I am currently involved in conducting a pre-build BITechnical Design Review i.e. Data Model structure/Extractor/Transformation Logic/Data Flow Diagrams.
    Are there any tangible criteria/review template/methods out there to ensure all components are included in a BI design and that they conform to the SAP Best Practices?
    Thanks,
    Jony

    Hi jonathan,
    The BW Project guidelines can be as follows ,
    Stages in BW project
    1 Project Preparation / Requirement Gathering
    2 Business Blueprint
    3 Realization
    4 Final Preparation
    5 GO Live & Support
    Project Preparation / Requirement Gathering
    Collect requirement thru interviews with Business teams /Core users / Information Leaders .
    Study & analyze KPI 's (key figures) of Business process .
    Identify the measurement criteria's (Characteristics).
    Understand the Drill down requirements if any.
    Understand the Business process data flow if any .
    Identify the needs for data staging layers in BW – (i.e need for ODS if any)
    Understand the system landscape .
    Prepare Final Requirements Documents in the form of Functional Specifications containing :
    Report Owners,
    Data flow ,
    KPI’s ,
    measurement criteria’s,
    Report format along with drilldown requirements .
    2 Business Blueprint
    Check Business content against the requirements
    Check for appropriate
    Info Objects - Key figures & Characters
    Check for Info cubes / ODS
    Check for data sources & identify fields in source system
    Identify Master data
    document all the information in a file – follow standard templates
    Prepare final solution
    Identify differences (Gaps) between Business Content & Functional
    specification. propose new solutions/Developments & changes if required at different levels such as Info Objects ,Info cube , Data source etc . Document the gaps & respective solutions proposed– follow standard templates
    Design & Documentation
    Design the ERD & MDM diagrams for each cube & related objects
    Design the primary keys/data fields for intermediate Storage in ODS
    Design the Data flow charts right from data source up to Cube .
    Consider the performance parameters while designing data models
    Prepare High level / Low level design documents for each data model.--- follow standard templates
    Identify the Roles & Authorizations required and Document it – follow standard templates
    final review of design with core BW users .
    Sign off the BBP documents
    3 Realization
    Check & Apply Latest Patches/Packages ...in BW & R/3 systems.
    Activate/Build & enhance the cubes/ODS as per data model designs...maintain the version documents .
    Identify & activate Info objects / Master data info sources / attributes ,prepare update rules
    Assign data sources .prepare transfer rules , prepare multi providers . prepare Info packages .
    perform the unit testing for data loads….both for master data & transaction data .
    develop & test the end user queries .
    Design the process chains ,schedule & test
    create authorizations / Roles …assign to users ..and test
    Apply necessary patches & Notes if any .
    freeze & release the final objects to quality systems
    perform quality tests .
    Re design if required . (document changes, maintain versions)
    4 Final Preparation
    Prepare the final check list of objects to be released .identify the dependencies & sequence of release
    perform Go Live checks as recommended by SAP in production system
    keep up to date Patch Levels in Production system
    Test for production scenarios in a pre-production system which is a replica of production system .
    Do not Encourage the changes at this stage .
    freeze the objects .
    5 GO Live & Support
    keep up to date Patch Levels
    Release the objects to production system
    Run the set ups in R/3 source system & Initialize Loads in BW
    Schedule Batch jobs in R/3 system (Delta loads)
    schedule the process chains in BW .
    Performance tuning – on going activity
    Enhancements - if any
    You can get some detailed information in the following link.
    http://sap.ittoolbox.com/documents/document.asp?i=3581
    Try to go to ASAP implementation roadmap.
    https://websmp103.sap-ag.de/~form/sapnet?_SHORTKEY=01100035870000420636&_SCENARIO=01100035870000000202
    Check the links below that gives you brief overview of the above steps .
    https://websmp201.sap-ag.de/asap
    http://www.geocities.com/santosh_karkhanis/ASAP/
    ASAP
    https://websmp201.sap-ag.de/asap
    http://www.geocities.com/santosh_karkhanis/ASAP/
    https://service.sap.com/roadmaps
    https://websmp104.sap-ag.de/bi
    ***Please reward if useful.**
    Blue Print:
    http://www.sap.com/services/servsuptech/bestpractices/index.epx --- look for blueprint
    http://iris.tennessee.edu/Blueprint/BW/BW-Blue%20Print-Final.doc
    http://help.sap.com/bp_biv335/BI_EN/html/Business_Blueprint.htm
    You can get some detailed information in the following link.
    http://sap.ittoolbox.com/documents/document.asp?i=3581
    also please chck out
    https://www.sdn.sap.com/irj/servlet/prt/portal/prtroot/docs/library/uuid/2e8e5288-0b01-0010-2ea8-bcd4df5084a7
    a hwo to on BI7.0 upgrade .. also as suggested check out the BW upgrade roadmap on the support portal..
    Hope it helps..
    CSM Reddy
    Assign points if helpful
    Message was edited by:
            CSM REDDY

  • Do I make more then one diagram in Multi layer design Diagrams?

    Do you make more then one Diagrams for Multi layer diagrams?
    develop the multi layer design. ?
    So I had to make a SSD or sequence Diagram now we have to make a multi design diagram?
    for the multi design. will we just be creating one big diagram of the assignment for this part?
    or is it going to be a collection of a bunch of separate diagrams. as books shows a few of them? regarding layers?
    For example create a diagram to cover all different layers/steps
    So should be a collection of 3 or more diagrams for Part 3 of TMA3
    do I have this correct?

    Just click on "Buy" one at a time. If you do them all in one sitting, they will be grouped as a single charge on your credit card.
    Some online music download stores have the ability to combine multiple miscellaneous tracks into a single zip file for purchase and download, but the iTunes Store does not work that way.

  • EJB Exception Layer Design Feedback

    I am in the process of creating a EJB layer talking to EIS Tier via JCA adapter. The EJBs are all stateless. The EJBs would be used by servlets, ejbs, or jsps. The EJBs are stateless in nature. I would like to make sure the exception hierarchy I have is considered good design practice and if there are suggestions on how I may improve it. I decided to go for unchecked exception all through my design (this I don't want to change -- pretty sure about this).
    So, here is how I designed my exception class. One of my goals was to keep the exception handling very simple at the client-side and not inundate customers with too many types of exceptions. I decided to go for a has-A type relationship to model much of the exceptions because I couldn’t really classify some of them to be a is-A. All exceptions thrown by my EJB layer would be contained within MyApplicationException. A getCause() will give insight into the cause at a very fine level. A getMessage() would suffice for most situations. Whereever exceptions are being thrown, the cause is being stored.
    java.lang.Exception
    --java.lang.RuntimeException
    ___ --MyBaseException
    _______+----MyApplicationException (this is the container for all my exceptions)
    _______+----MyConfigException
    I created a exceptionhelper class that handles most of the exceptions and throws the right exception depending on the cause. For brevity sake, I am not including all code details in the sample below.
    At the EIS Tier level, we have AutomationExceptions or Windows exception being thrown. These exceptions get thrown by the Windows code that is running in the EIS Tier (server). These exceptions are caught by the EJB code, then we do some processing like looking up the windows error code and producing the right message. The exception is then thrown back to the client with more information (MyApplicationException->getCause() would return AutomationException)
    In the EJB code I have something like this….
    try {
    serverConn.connectToEISTier()
    } catch (AutomatedException e) {
    throw new MyApplicationException(“Custom Message.”, ExceptionHelper.handleAutomatedException(e)); }
    At the EJB level
    •we have create, and naming exceptions thrown either on failed lookup or something failing when creating the ejbs or there might be programming errors or there might be missing resources when EJB is trying to connect and possibly encounters data retrieval failures or Some sort of configuration error might be there in the deployment descriptor (user did soemthing wrong - wrong value for environment entry). All these are caught, and converted into runtime exception namely MyApplicationException. Where classification is deemed necessary we for e.g convert then contained exception to say configexception.
    try {  
         lookup the context()
    } catch(NamingException ex){
    Cause = new myConfigException(“lookup failed because ….”);
    Throw new MyApplicationException(cause);
    At the transport level: some communication exception happened.
    At the client level:
    Client might be calling the apis wrongly and breaching the contract, or possibly supplied wrong credentials.
    Please share feedback / thoughts.

    There is an interesting article that discusses EJB Exception Layering:
    http://www-128.ibm.com/developerworks/java/library/j-ejbexcept.html
    As a rule of thumb: in every layer, create two types of exceptions that extend from the appropriate class (application exceptions and system exceptions). The next layer catches these and handles them appropriately. This way, you hide the implementation of the layers. An example where this is implemented is Spring.
    To summarize, I like your idea, but I define exceptions for every layer and not put them in one hiearchy.
    Regards,
    Lonneke

  • 802.1x Guest Vlan and Routed access layer design

    Hi!
    For many reasons, I have to re-design my campus network in a more ISP like way. The plan is to move to a routed access layer in the next two years. I have 802.1x with guest vlan on my access ports(3750). I was reading on the subject and I found that the guest vlan feature was not availeble with internal vlan(routed port).
    Is this limitation realy there, is there a way I can get around it without complicating my design even more. Do cisco have plan to lift this???

    You cannot use/configure 802.1X on a routed port today. Typically, 802.1X is to be used for LAN edge ports.
    The Guest-VLAN should work with a routed access design though. If your Guest-VLAN is chosen to be separate from say otherwise statically configured access VLANs, you would need to configure it via separate SVI with corresponding IP info (in a routed access model).
    Hope this helps,

  • Distribution layer design

    What's todays look on Medium to Small branch office design? Do you stack multiple switches or buy lets say a 4500? I'm looking for Pros and Cons. And if you stack how do you tie in SX,SC fiber to the Access layer?

    Choice depends of features and performance (and often cost).
    For smaller LANs, I've found the stackable switches, often, a viable choice.
    As to using fiber, stackable switches often offer some SFP (or other modular) ports to which you can attach fiber. However, at least in Cisco's current product offerings, high density fiber isn't really available. For instance, there's the stackable Catalyst 3750G-12S, but it only provides 12 ports. (It does, though, provide internal resources and SDM templates for non-edge usage.)
    [edit]
    PS:
    BTW, in a small LAN, depending on distances, you might be able to user copper uplinks and/or run most of the LAN on one stack (which avoids the needs for uplinks/downlinks). Or, if you use stackable switches on the access edge, might find number of uplinks necessary is decreased.

  • Question about service layer design

    I have a question about the design/architecture of service model layers, specifically the task service layer.
    Could a task service be a small "action", ie an operation that doesn't require composition? So if I have a requirement to allow customers to update their personal info, like address, would I have a task service named ChangeCustomerMailingAddress, that in turn calls the update operation on the Customer entity? Or would it be better to call the entity service directly? Another example would be retrieving data, like RetrieveCustomerBillingHistory, would that be a separate task service, or just a get/read operation on the Customer entity service?
    Any insight is appreciated.
    Thanks

    You seem to be confused what all the different parts of Java do.
    JRE - runtime environment, the minimum needed to run standard java applications
    Java Standard Edition - the standard set of API's that form the base of most java applications. You need the J2SE SDK to compile these applications and the JRE to run them.
    Now talking about "application design", I'm not sure what you mean. Are you talking about graphical user interfaces? In that case you would want to look into Swing, and that is indeed part of the standard edition API set.

  • IPS design review

    Hello ,
    Could you review my IPS design (the topology picture is in the attachment) ? Can I have one IPS with three or four ports attached to the same switch in an etherchannel? I am talking about one IPS with multiple interfaces. For example two IPS with four interfaces in the switch's etherchannel group with eigth ports. ( IPS's interfaces are in VLAN pair mode )
    Kind Regards.

    Sorry, i have forgotten to attach the topology picture.

  • Logical and semantic layer design in four facts structure

    Hi
    My physical layer contains four fact table and several mutual dimensions.
    The fact tables are not connected together.
    My preference is to build four star schemes on one business model in the logical layer
    and to provide one semantic layer with all four facts and mutual dimension.
    Am I going throw a loops and data duplication adventure?
    Is there any problem with this structure?
    What is the best practice in this case?
    The users should have the option to drag columns in all possible combination.
    moshe

    Hello, the feature of a connecting Crystal Enterprise via a Universe  top of ERP/ECC comes with BI 4 Feature Pack 3 which is not available yet
    Ingo's book includes information on that release BI 4.0 FP 3
    Please see Figure 3 on this blog /people/tammy.powlas3/blog/2011/12/04/sap-integration-with-businessobjects-bi-40-feature-pack-3-asug-webcast-summary
    Regards,
    Tammy
    Edited by: Tammy Powlas on Dec 17, 2011 2:22 PM

  • Physical layer design in obiee 11g

    Hi,
    I need a clarification regarding physical layer degin in obiee 11g,I imported Oracle Apps reports ,but could not find any keys there at table level.So should i create keys on the imported table level or at the alias level of the imported tables.
    Thanks-Bhaskar

    If you import a transaction table you may have keys imported in physical layer but when you going with warehouse table you may not have keys at database level, you define them using join in physical layer.
    We have surrogate keys in dwh.
    Hope this clear your doubt, if helps pls mark

  • Identification of Core and Distribution Layer Design

    Hi 
    I am a CCNA certified and I am doing a job as an IT technician here in UAE. I'm the only IT person in my company. Having no prior experience in networking field, I find myself in a pickle. With the help of CDP, I have figured out the network diagram. I am told that there is a COLLAPSED CORE network running in my company. I cannot identify the Core switches here. My question is how to identify the the core switches? We have two internet connections in two separate buildings. Can somebody please help me out. Please..

    Generally speaking with a L2 access layer to L3 distribution switches the default gateways of the vlans are on the distribution switches.
    The core switches are used when you need to interconnect multiple distribution switches eg. a campus LAN type environment.
    In many sites if you only have one building the core and distribution switches are the same pair of switches but to be precise the default gateways are not on the core but the distribution switches.
    If you have a separate pair of core switches you usually connect your distribution switches using L3 links so again the STP root for the vlans would actually be the distribution switches for the vlans they route for and not the core switches.
    Separate core switches are basically just a high speed interconnect between your distribution pairs and should be left to do that so the routing between vlans, acls etc. are done locally on the distribution switches and only traffic for remote vlans/IP subnets ie. those on other distribution switches would go via the core switches.
    If the same pair of switches is used for both functions then all routing between vlans and routing to remote networks is done by that pair.
    Jon

  • Technical Design Review Question: mySAP Execution Architecture.

    I got my hands on technical design documentation for a project on COPA budget. I came up with a few questions but I will post them separately for fast closing and awards:
    1. In the Requirements discussion, I came across something
    “Job naming conventions apply… and completion of Autosys Job Schedule request form is required….Forward this form to the mySAP Execution Architecture team for processing”
    Is this a an internal team or it refers to some group at SAP company?
    Is the Autosys Job Schedule request form a standard for or you think the environment had just come up a form for their internal processes? What may this include?
    Thanks.

    Hi,
    If I understood correctly, The organization wants to maintain a document on jobs to be maintained regularly in production system. It will be used as a  reference in the support of BW production activities.
    I hope, the mySAP Execution Architecture team for processing is the internal team from your client.
    With rgds,
    Anil Kumar Sharma .P
    Message was edited by: Anil Kumar Sharma

  • Multiple WAN site redundancy design review (dark fiber, p2p, DMVPN)

    I'm re-designing a couple of wan sites.  I'm using EIGRP over both some leased dark fiber and p2p provider connections.  The attached (pdf) physical topology says it all, I'm thinking of using ip sla to track and inject routes over prefered connections, but really just looking for feed back if someone is interested in taking a look. 
    I've bought 2 2951's with es3g-16-p modules so I can build svi's and do hsrp between the paths, building redundancy between the 3 available paths back to our enterprise core (1Gbps, 40Mbps, 50Mbps).
    multiple vlans at both sites...
    e.g.: (wan site1 (vlan 10-15), want site2 (vlan 16-20))
    Thoughts and thanks?

    hi there
    not sure why you need to use DMVPN if it all internal same internal network unless you need to have all the traffic between sites to be encrypted
    anyway in general i would say of use the direct link to reach the directly connected networks per site
    example using site one 100M link to reach DC and WAN
    and use site2 50M local link to reach WAN as primary path and use the site1-site2 fibre to reach DC as primary path for site2 this could archive a good load sharing and reduce the load on the link between site1 and site2
    IP SLA in a topology like your for sure can very helpful to improve failover time and make the routing more topology aware
    hope this helps

  • Flash Design Review

    Hi
    I have designed hanging flash menu for my web design web site
    Hope this is compatible with all web browers
    Please give your comment on this unique flash design
    kushan

    It's cute but Flash for navigation is pure poison because many browsers don't support it.  Most notably Apple iPad, iPhone & iTouch do not support Flash.  How will those users navigate your site?
    For all practical purposes, Flash is dead as a web technology except for gaming sites and special device apps.
    I think a better choice is CSS styled menus to support the majority of users.  If you want to add some animation  to your site, look at HTML5, CSS3 transitions and JavaScript
    See Adobe Edge
    http://labs.adobe.com/technologies/edge/
    Nancy O.
    Alt-Web Design & Publishing
    Web | Graphics | Print | Media  Specialists 
    http://alt-web.com/

Maybe you are looking for