DMZ VLANs in the Data Centre - Physical or Logical Seperation

I am building a new DMZ in my Data Centre and I'm looking at the merits of Logical Seperation rather than Physical Seperation.
Instead of putting in some new DMZ Switches and then physically cabling all the DMZ devices and Servers to these switches so that these are physically seperate from the rest of the DC, I'm thinking of connecting them up to the existing DC Switches and just use a different set of VLANs with the routed interface for these on Physical Firewalls.
Can people please appraise me of the concerns or issues with this? Are there any articles or design papers on this?
Thanks

Come on guys I expected someone to at least make some form of comment!
It looks like either the community doesn't know or doesn't care!

Similar Messages

  • How to decrease the data in physical layer

    Hi to all,
    physical layer have some data. but i want to decrease the data in the physical layer with out delete. how u can do. how many ways are there to do this process?
    Thanks.........
    Prasad

    He posted the same question decrease the data in physical layer , but didn't reply anymore.
    Maybe we can get to know what he actually wants in this thread...
    Cheers,
    C.

  • Error occurred when view the data from physical layer

    Hi ,
    I have created system  DSN like "demo1" for excel file. After that i import the excel file into administration tool.
    after that i want to view the data from physical layer. At that time ,I am getting following error .
    Please resolve this issue.
    Thanks in advance,

    hi ashok,
    u can push data from  psa to ods, for this goto the psa in rsa1>psa>goto that request>rightclick>select " schedule update Immediately ", then data will moved from psa to ods.
                                                 or
    In ods > delete the failed request>goto the processing tab-->select 3rd option   " psa and then subsequentially to data targets ", --> schedule the infopackage.
    bye
    sunil

  • Oracle 10gR2 Data guard physical or logical standby server?

    Hi
    We are planing to implement an Oracle 10gR2 data guard standby server for DR purposes, I found out that there are two type of standby server which is logical and physical standby server. I want to know which one is preferable? in term of complexity of setup and maintenance?
    regards

    Well it depends on what you mean by maintenance. I found the physical standby to be very little trouble at all ; however the logical standby has restrictions on it that the physical standby does not. In essence the physical standby merely digest archive logs; where as the logical standby uses logminer like functionality to process sql statements much like Oracle streams.
    Hope that helps,
    -JR jr.

  • Oracle Data Guard: Physical and Logical

    I have a Primary database and have created a Physical Standby on another node. The physical standby is kept in synch via REDO Aply - online redo logs.
    QUESTION: is it possible to create a Logical Standby off of the Physical Standby? I dont think so since the logical is kept in synch from a primary via SQL- Aply. CAN SOMEONE PLEASE CONFIRM.
    I thought that a logical standby MUST be created from a Primary and not a Physical.
    Thanks!!

    Documentation is your friend,Orace does not not hide the information,how to create a logical standby:
    http://download.oracle.com/docs/cd/E11882_01/server.112/e10700/create_ls.htm#g105412
    Werner

  • Data centre connectivity options

    Hello
    I am currently investigating a dual data centre design running
    in active/active mode. The data centres will each have connectivity to
    our WAN (MPLS) and to the Internet. They will have also have dedicated
    links to each other for site replication etc.
    Having read a few of the Cisco SRND's what i am still a little unclear
    about is whether it is better to connect the two data centres over the
    dedicated link using layer 2 or layer 3 and what the pros and cons are of
    each. I would appreciate any experiences (good and bad) that people have had
    in this area.
    My instinct is to go layer 3 eliminating a potential spanning tree issue
    that could affect both data centres but i am sure there are more issues
    than this to take into account.
    Many thanks

    i have redundant data centers and they have been setup as follows for specific reasons:
    (these data centers are not separated by a WAN, if they were, a T3 or better would be required in my case but i'd opt for a metro fiber type of solution to provide GB+)
    using the 3 hierarchial network design: core, distribution, access
    1) the CORE is L3/routed; we do not want a L2/switched core for a few reasons. one is to allieviate STP and its inherent problems.
    (the core should be moving packets as fast and predictable as possible; stp can interrupt this and cause complete packet forwarding delay or worse; with todays routers, they can route packets just as fast as switching them, or faster in some cases)
    2) the distribution layer is switched with fully meshed GB or greater trunks to both the cores. also provides redundant intra VLAN routing for all the VLANs controlled in their specific 'distribution blocks'; i have 5 fully redundant distribution blocks with VLAN routing and VLAN load balancing via HSRP.
    (i channel upto 6 GB trunks in a given link)
    3) the access layer is switched with fully meshed GB or greater trunks to at least two distribution switches per access switch; one trunk to each core, at least.
    (there is no routing performed at the access layer)
    other reasons such as the routing operation, location and number of distribution switches, administration and speed affect the design.

  • How to relocate a Data Centre

    Dear Netpro gurus,
    I have been tasked with relocation of the Data Centre at work.  does anyone out there who has any good tips / articles on how to do a successful Data Centre re-location?
    Cheers,
    Hunt                  

    Questions thay i would ask if i get something similar...
    - how much is the bearable downtime
    - Does the network topology gives flexibility to use new ip subnets so that i may prepare some functionality at destination site before relocation.
    - do i have the complete design document of existing DC physical connectivity
    - Have i already been provided with the internet/intranet links at new site
    - do i have planned for the power, space and cooling requirements for my infra and have i done the dite survey to know if that has been provisioned
    - have the resources from each stakeholder been identified, engaged and scheduled
    - do i have the checklist for all the network and service readiness tests to be done after thr relocation...
    Sent from Cisco Technical Support Android App

  • WAAS Mobile HA between 2 Data Centres

    We have to deploy WAAS Mobile between 2 Data Centres, with remote user connecting to either DC across VPN & then connecting to a local WAAS Mobile server. We are trying to understand the best way to configure this from the available documentation on CCO.
    We are a bit confused re the role of the WAAS Mobile Manager Server.
    Is this similar to the role of Central Manager on normal WAAS, i.e configuration/management etc, or does it have any function in the selection of the server a client will connect to.
    Regarding HA & Load balancing of the connections between the Data Centres, this is how we think we should deploy it!
    Deploy a Server Farm at each DC & use the Latency based method of farm selection. This way the client should connect to the local server farm, based on which DC the VPN connects to?
    Is this correct, has anyone deployed WAAS mobile in this way or have any advice?
    Thanks
    Colin

    Fabricpath is L2; not related to the L3 technology you want to use; if VRF are in use you can just use VLANs which is described in your first scenario : "use 2 routers with VRF lite configuration in each DC, then dot1q on the trunk through the Fabric Path"

  • SQL 2012 AlwaysOn Dual Data Centre (an instance in each data centre with a secondary in each other respectively)

    Hi, hopefully someone will be able to find my scenario interesting enough to comment on!
    We have two instances of SQL, for this example I will call them 'L' and 'J'. We also have two data-centres, for this example I will call them 'D1' and 'D2'. We are attempting to create a new solution and our hardware budget is rather large. The directive
    from the company is that they want to be able to run either instance from either data centre. Preferably the primary for each will be seperated, so for example:
    Instance 'L' will sit in data centre 'D1' with the ability to move to 'D2', and...
    Instance 'J' will sit in data centre 'D2' with the ability to move to 'D1' on request.
    My initial idea was to create a 6-node cluster - 3-nodes in each data centre. Let's name these D1-1, D1-2, D1-3 and D2-1, D2-2, D2-3 to signify which data centre they sit in.
    'L' could then sit on (for example) D1-1, with the option to move to D1-2 (synchronously), D2-1,D2-2 (a-synchronously)
    'J' could sit on D2-3, with D2-2 as a synchronous secondary and D1-3,D1-2 as the asynchronous secondaries.
    Our asynchronous secondaries in this solution are our full DR options, our synchronous secondaries are our DR option without moving to another data centre site. The synchronous secondaries will be set up as automatic fail-over partners.
    In theory, that may seen like a good approach. But when I took it to the proof of concept stage, we had issues with quorum...
    Because there are three nodes at each side of the fence (3 in each data centre), then neither side has the 'majority' (the number of votes required to take control of the cluster). To get around this, we used WSFC with Node and File Share majority - with
    the file share sitting in the D1 data centre. Now the D1 data centre has 4 votes in total, and D2 only has 3.
    This is a great setup if one of our data centres was defined as the 'primary', but the business requirement is to have two primary data centres, with the ability to fail over to one another.
    In the proof of concept, i tested the theory by building the example solution and dropping the connection which divides the two data centres. It caused the data centre with the file share to stay online (as it had the majority), but the other data centre
    lost it's availability group listeners. SQL Server stayed online, just not via the AG listener's name - i.e. we could connect to them via their hostnames, rather than the shared 'virtual' name.
    So I guess really I'm wondering, did anyone else have any experience of this type of setup? or any adjustments that can be made to the example solution, or the quorum settings in order to provide a nice outcome?

    So if all nodes lost connectivity to the fileshare it means that there are a total number of 6 votes visible to each node now. Think of people holding up their hands and each one can see the hand. If the second link between the two sites went down then each
    node on each side would only see 3 hands being held up. Since Quorum maximum votes =7, the majority needed to be seen by a node would be 4. So in that scenario, every node would realize it had lost majority and would offline from the cluster.
    Remember that quorum maximum (and therefore majority), never changes *unless* YOU change node weight. Failures just mean then is one less vote that can be cast, but the required majority remains the same.
    Thanks for the complement btw -very kind! I am presuming by your tag that you might be based in the UK. If so and you are ever nearby, make sure you drop by and say hello! I'll be talking at the
    London SQL UG two weeks from today if you are around.
    Regards,
    Mark Broadbent.
    Contact me through (twitter|blog|SQLCloud)
    Please click "Propose As Answer" if a post solves your problem
    or "Vote As Helpful" if a post has been useful to you
    Come and see me at the
    PASS Summit 2012

  • How to print the data  if we take different fields from diffrent tables

    Hi ABAPers,
    I take diff fields from 3 tables. Those are
    these fields from EKBE
           EBELN
           EBELP
           BELNR
           BUZEI
           BWART
           BUDAT
           AREWR
           REEWR
           WERKS
           MWSKZ
    these fields from EKKO
           BUKRS
           BSART
           WAERS
    these field from EKPO
           TXZ01
           MATNR
           MTART
    I want to print the data all fields.What logic can i write?
    Please help me for this question and i am waiting for your response.
    Regards,
    Raja Sekhar.

    Hi,
    First you have to fetch data from all the three tables and then consolidate into final table.
    In Declaration:
    1.Declare Internal Table for EKKO holding:
    EBELN
    BUKRS
    BSART
    WAERS
    2.Declare Internal Table for EKPO holding:
    EBELN
    EBELP
    TXZ01
    MATNR
    MTART
    3.Declare Internal Table for EKBe holding:
    EBELN
    EBELP
    BELNR
    BUZEI
    BWART
    BUDAT
    AREWR
    REEWR
    WERKS
    MWSKZ
    *==> This table has
    MANDT
    EBELN
    EBELP
    ZEKKN
    VGABE
    GJAHR
    BELNR
    BUZEI
    as Primary keys field,you should have values for all the PK aotherwise you will get multiple entries*
    4.Declare a Final Internal Table i_final with all the fields you want
    EBELN
    EBELP
    BUKRS
    BSART
    WAERS
    TXZ01
    MATNR
    MTART
    BELNR
    BUZEI
    BWART
    BUDAT
    AREWR
    REEWR
    WERKS
    MWSKZ
    Data Fetching
    select EBELN
    BUKRS
    BSART
    WAERS
    from EKKO
    into table i_ekko
    where .........<selection criteria>.
    if not i_ekko is initial.
    select EBELN
    EBELP
    TXZ01
    MATNR
    MTART
    from EKPO
    into table i_ekpo
    for all entries in i_ekko
    where EBELN = I_EKKO-EBELN
    AND ......<If any other selection criteria>.
    if not i_ekpo is initial.
    select EBELN
    EBELP
    BELNR
    BUZEI
    BWART
    BUDAT
    AREWR
    REEWR
    WERKS
    MWSKZ
    from EKBE
    into table i_ekbe
    for all entries in i_ekpo
    where ebeln = i_ekpo-ebeln
    and ebelp = i_ekpo-ebelp
    and ..........<If any othet selection criteria>
    endif.
    endif.
    Consolidate
    sort i_ekko by ebeln.
    sort i_ekpo by ebeln ebelp.
    sort i_ekbe by ebeln ebelp.
    LOOP AT i_ekbe into wa_ekbe.
    read table i_ekko into wa_ekko with key ebeln = wa_ekbe-vbeln binary search.
    if sy-subrc = 0.
    ====>Move all the required firlds from I_EKKO to i_final  , like
    wa_final-BUKRS = wa_ekko-BUKRS.
    endif.
    read table i_ekpo into wa_ekpo with key ebeln = wa_ekbe-vbeln
    ebelp = wa_ekbe-ebelp binary search.
    if sy-subrc = 0.
    ====>Move all the required firlds from I_EKPO to i_final  , like
    wa_final-EBELP = wa_ekko-EBELP.
    wa_final-TXZ01 = wa_ekko-TXZ01.
    endif.
    ==>Also all the required fields from EKBE to final table, like
    wa_final-BELNR = wa_ekbe-BELNR.
    endloop.

  • Difference between physical and logical standby database

    What is the difference between physical and logical standby database?

    Hi,
    Physical Standy where its a read only DB.
    Logs are applied.
    Logical Standy where it can be Read / Write DB and the logs are applied in terms of SQL Statements.
    Thanks & Regards,
    Pavan Kumar N

  • Is there anyway to restore lost game data and achievement from the Game Centre after doing a full restore without backup?

    I recently restored my iPad to fix issues with the Facebook account attached to my iPad clearing all saved data and I didn't backup with iCloud because I wanted to get rid of the Facebook account that I could no longer access and remove or attach with games. Game achievements are shown in the Game Centre but when I play the app it starts at the very beginning of the app with no progress is there anyway to retrieve my progress?

    No. Not without a backup.

  • My games data on game centre is there but i don't have the data on the apps, why is this?

    I had my ipod 4g replaced as it had a few bugs on it a while ago. I signed into game centre on my new ipod and all the data of the apps I had before were there. But I cant understand why the data on game centre isn't transfering the the apps on the Ipod.

    can it not transfer them as it is a different ipod?

  • Is there any documentation on the BC Data Centre's?

    Hi,
    I have been a premium reseller of BC for over two years but I am struggling to find any documentation about the BC Data Centre's. I have not been asked before but I am launching a delegate Registration Microsite for Symantec and as with all larger companies their procurement process requires evidetiary documentation to be supplied.
    Specifically they are asking for specification or documentation on:
    ISO 27001 certificate and Network Penetration test information.
    Any help or guidance to this information would be greatly appreciated.
    Cheers
    Rob

    Hi Sidney,
    Thanks for the helpful responses. I have had some progress with my queries and have now recieved PCI compliance documentation that BC sent through after your suggested ticket. Moving forward, I think that the shift to AWS will resolve all certification and compliance issues - I imagine this doesn’t come up too often with a product that is aimed firmly at SME’s.
    My issue arose as I work for SME’s who in turn work for Blue Chips. Companies like Symantec, Sony & Canon all have extremely stringent procurement procedures even though they are budget conscious and the inference of documentation falls down the chain to us the technical supplier – the National Account Managers and Product managers just set up the deals and promotions and the legal/financial teams then throttle everyone with paperwork. They have simply been told that any websites which contain staff information must reach a very high standard of security and auditory compliance which is understandable but cannot be answered with ‘well its Adobe… of course they are secure!’.
    I will follow up to the community when I have finished my research and have a result!
    Thanks
    Rob

  • When I try to publish my Muse site I get "Query failed" appear in the "Publish to" and "Data Centre"

    What can I do to solve that? It's stopping me from publishing updates.

    Yes, I am publishing it to BC. It happened the other day too but had
    never happened in the previous 9 months that I have been using Muse (and
    BC). Have I really hit two maintenance periods in such a short time?
    Seems quite unlikely but let's hope so.
    Jonathan Phillips
    Head of Marketing
    PACT Educational Trust
    m: 07517 610209
    e: [email protected]
    visit www.pactschools.org.uk
    Open Days ***
    OLIVER HOUSE SCHOOL: THURSDAY 20TH MARCH 10AM-12PM
    oliverhouse.org.uk
    visit the websites for more details ***
    On 03-04-2014 17:18, Brad Lawryk wrote:
    RE: WHEN I TRY TO PUBLISH MY MUSE SITE I GET "QUERY FAILED" APPEAR IN THE "PUBLISH TO" AND "DATA CENTRE"
    created by Brad Lawryk in Help with using Adobe Muse CC - View the full discussion

Maybe you are looking for

  • IPhoto movie share not working...something is missing...

    I have a client with ML/iLife/iMac-all the latest updates for all. He has an iPhone 4 and took several movies. Via cable he has them in his library along with several still photos of the same location (Grand Canyon). On his iMac/iPhoto/Event his pict

  • List versions causing performance problems

    We have a List - not Library - List - with about 100 columns (Yes. We know that's a lot and have verified that one Item wraps to two DB rows), none of which is indexed.  An InfoPath form is used to enter and view the List Items. Versioning is on for

  • Is there a way to find out what other devices are using my apple ID?

    I have recently discovered that someone is purchasing apps on using my apple id account i have managed to view a statement through the Mac computer but that only tells me what the purchase is, how many there are and how much it totals to. I wanted to

  • Image losing resolution?

    I'm wondering if there is a way to set my image to not lose to much quality when it is is scaled. Let me give you an example. I have a banner that is 1000 x 400. My screen resolution is 2048 x 1152. My monitor is a 24" monitor. I singed up for a goog

  • HelpX is failing. Time to reconsider...

    We (I'm sure others will follow) were send here to express our concert about the current helpx-concept. I'm a ACI for After Effects and Premiere, and will be for SpeedGrade as soon as such is availeble. My concers regard these applications: - I miss