Internet Data center

What are the firewall auditing software needed for IDC setup..Monitoring s/w in Cisco..

You might find this software helpful. See post http://forums.cisco.com/eforum/servlet/NetProf?page=netprof&CommCmd=MB%3Fcmd%3Dpass_through%26location%3Doutline%40%5E1%40%40.ee78b1b

Similar Messages

  • Can i access internet, if I am connected to MPLS Network in my Data Center

    I am planning a connectivity to MPLS network of a Service Provider. Do I need a separate internet connectivity or the MPLS connection it self will provide me the access to internet.
    The main idea is to provide access to applications hosted in Data center to all the remote users who are working using their laptops and wireless broadband.
    Kindl suggest.
    Thanks for the support, in advance. 

    I am planning a connectivity to
    MPLS network of a Service Provider. Do I need a separate internet
    connectivity or the MPLS connection it self will provide me the access
    to internet.
    The
    main idea is to provide access to applications hosted in Data center to
    all the remote users who are working using their laptops and wireless
    broadband.
    Kindl suggest.
    Thanks for the support, in advance. 
    Hi,
    MPLS service provider can do the same check out the below link for more information
    https://www.cisco.com/en/US/tech/tk436/tk428/technologies_white_paper09186a00801281f1.shtml
    Hope to Help !!
    Ganesh.H
    If helpful do rate the post

  • Replication between 130 nodes and 1 Data Center

    Hi everyone.
    I have 130 database nodes (Oracle Standard Edition One) with a big distance of separation, and 1 Data Center with 3 nodes (Oracle Real Application Cluster 10g R2). The connection between nodes and datacenter is through various ISP ( WAN).
    I have exactly the same model design of database in nodes and datacenter.
    DataCenter is a repository of data for reporting to directors and dictate the business rules to guide all nodes.
    Each node have approximately 15 machines connected with desktop application.
    In other words Desktop Application with a Backend Database (node).
    My idea of replication is not instantly, when a transaction commit in a node then replicate to datacenter. Also over nigth replicate images because is heavy, approximately 1 mg per image. Each image correspond to one transaction.
    On the orher hand i have to replicate some data from datacenter to nodes, business rule, for example: new company names, new persons, new prohibitions, etc.
    My problem is to determine th best way to replicate data through nodes to datacenter.
    Please somebody could suggest me the best solution.
    Thanks in advanced.

    Last I checked, Streams and multi-master replication require enterprise edition databases at both ends, which rules them out for the sort of deployment you're envisioning.
    If a given table will only ever be modified on nodes or on the master site, never both, you can build everything as read-only materialized views. This would probably require, though, that the server at the data center have 130 copies of each table, 1 per node. For schemas of any size, this obviously gets complicated very quickly. For asynchronous replcation to work, you'd need to schedule periodic refreshes, which assumes that you have relatively stable internet connections between the nodes and the data center.
    I guess I would tend to question the utility of having so many nodes. Is it really necessary to have so many? Or could you just beef up the master and have everyone connect directly?
    Justin
    Distributed Database Consulting, Inc.
    http://www.ddbcinc.com/askDDBC

  • Collapsed Data Center Tier - Best Practice

    Hey guys,
    I'm working with a company who's doing a Data Center build-out. This is not a huge build out and I don't believe I really need a 2 tier design (access, core/aggregation). I'm looking for a 1 tier design. I say this because they only really have one rack of hosts - and we are not connected to a WAN or campus network - we are a dev shop (albeit a pretty damn big dev shop) who hosts internet sites and web applications to the public. 
    My network design relies heavily on VRF's. I treat every web application published to the internet as it's town "tenant" with one leaked route which is my managment network so I have any management servers ( continues deployment, monitoring, etc...) sitting in this subnet that is leaked. Each VRF has their own route to a virtual firewall context of their own and out to the internet. 
    Right now we are in a managed datacenter. I'm going to be building out their own switching environment utilizing the above design and moving away from the managed data center. That being said I need to pick the correct switches for this 1 tier design. I need a good amount of 10gbe port density (124 ports minimum). I was thinking about going with 4 5672UP or 4 C3064TQ-10GT - these will work as both my access and core (about 61 servers, one fiber uplink to my corporate network, and one fiber uplink to a firewall running multiple device contexts via multiple vlans) 
    That being said - With the use of VRFs, VLAN, and MP-BGP (used to leak my routes) what is the best redundancy topology for this design. If I was using catalyst 6500's I would do VSS and be done with it - but I don't believe vPC on the nexus switches traffic and is really more for a two tier model (vPC on two cores, aggregation/access switch connects up to both cores but it looks like one.) What I need to accomplish sounds to me that I'm going to be doing this the old fashion way , running a port channel between each switch, and hopefully using a non STP method to avoid loops. 
    Am I left with any other options? 

    ISP comes into the collapsed core after a router. A specific firewall interface (firewall is in multi context mode) sits on the "outside" vlan specific to each VRF. 

  • Layer 2 connect - data center web hosting

    hi, i need your help!!
    i have data center with the nexus 7000 , i have servers connecting to the cisco 7000 with web servers. my company do hosting for customers.
    the poing that we have shared resources like vmwares on blades and so on.. mean that the ports of the blade are connecting physically to the nexus 7000 with trunk and vlans for every customers.
    my nexus connecting to FW than to WAN stiches than to Routers connecting to the internet so if i asked to to hosting from the internet its easy.
    the problem is now i have cusomer that wants to connect his switch over the wan directly to his area at my datacenter....  we make for him servers that are the same like his servers with the same subnet and he makes replications...
    he dont have router, he connect his switch over wan provider at layer 2 to me..
    should i connect him direcly to my nexus??? with his vlan?? should i need other solution like eompls??? what is the safest way to connect him with layer 2.. and i repeat the problem that our servers are shared between many customers - the same nexus ports, please help!!

    Hello,
    1.PIX is the precursor to the ASA so at this point the ASA is probably a better choice since it'll be around longer plus I'm sure they have beefed up the base hardware compared to the pix.
    2.Your external router is dependant on how much traffic your going to be dropping into your hosting site. A 7200 series router is a fairly beefy router and should be able to handle what you need if your looking.
    3.One of the nice things about the 6500 is you can put a FWSM and segment all your different hosting servers to provide a more granular network control.
    I don't have any case studys but will look around and post them if I find some.
    Patrick

  • Single CAS NameSpace in Multi-Data Center Model With Exchange 2013

    Hi
    We are in process of transitioning from Exchange 2007 to Exchange 2013. Our Exchange 2007 infrastructure is as follows:
    2 Data centers (DC 1 and DC 2). Both with active user population. Both have their own direct Internet Connectivity
    Standalone Exchange 2007 mailbox servers in each data center
    Load Balanced CAS (HT co-located) servers using Hardware Load Balancers in each data center. Load balancers are configured with VIP and FQDNs (LoadBalancer1.Com and LoadBalancer2.com)
    Currently No access allowed from Internet except ActiveSync (No OWA or OA)
    Outlook anywhere is disabled in Exchange 2007 organization but once mailboxes will be moved to Exchange 2013, OA will definitely be used – we will provide OA on Intranet as well as Internet
    All the internal URLs including Autodiscover point to VIP (Load Balancer IP)
    Autodiscover is not currently published on Internet, but we have a plan to publish it now once Exchange 2013 is introduced
    We want to keep a single CAS NameSpace BYOD.ABC.Com for our ActiveSync and OA (and not going to allow OWA) access from Internet. We want to have Split-DNS for our new Exchange 2013 infrastructure due to
    the simplicity it brings. So we are going to use one name BYOD.ABC.Com from the Internet. We have GSLB that provide Fault Tolerance and Geo-Load Balance to external requests coming from Exchange clients, between two data centers. When we will
    install new Exchange 2013 servers, they’ll be part of new VIP so:
    In a 2 data center model, can we name our internal VIPs same in both data centers (i:e BYOD.ABC.Com) as we have decided to go with Split-DNS? Do you see any caveats to this strategy
    If the above strategy will not work, what are the alternate approach(es).
    If we configure same names for the VIPs in both data centers, it will mean that the Autodiscover SCPs for all the Exchange 2013 CAS objects (and Exchange 2007 CAS objects during co-existence) will point to BYOD.ABC.Com. This should not be a problem for
    AD joined systems as they’ll find and contact Autodiscover endpoints in their own sites (based on Keywords attribute that tells which AD site SCP belongs to) –
    Please correct me if this is wrong.
    If we configure same names for the VIIPs in both data centers, this also means that we have to configure BYOD.ABC.Com on External as well as Internal URLs on all the Exchange 2013 servers across both the data centers – Wouldn’t that be a problem – in terms
    of loops during CAS-CAS Proxy/Redirection?
    If we configure different names of the VIPs (say BYOD1.ABC.Com and BYOD2.ABC.Com), how will the Outlook Anywhere requests be handled in both data centers. The OA requests from DC1 will expect the Certificate Principle Name to be BYOD1.ABC.Com and requests
    from DC2 will expect the Certificate Principle Name to be BYOD2.ABC.Com. How to get this stuff working. As far as I know, OA expects CPN to match with it’s name.
    Thanks
    Taranjeet Singh
    zamn

    Any comments/suggestions from community......
    Thanks
    Taranjeet Singh
    zamn

  • Data Center Redundancy

    Hi, dear experts!
    I) My  Input data is (read please, or see attach):
    - I have one active data center (main office), one backup data center (backup office), and several branch offices and many corporate internet users
    - Each of the offices has redundant internet connection: Main office via ISP1 and ISP2, backup office via ISP3 and ISP4.
    - Standby data center duplicates corporates services (such as Exchange, Sharepoint, FileStorage).
    - Main office and backup office are long-distanced from each other (about 800 km), and interconnected via 1Gb fiberoptic.
    II) My tasks are:
    1. Provide redundant network  connection for local ofiice users to corporate services.
    2. Provide redundant network connection for branch offices and internet users to corporate services.
    III) My ideas are:
    1. Accordingly to the 1-st task. Here I suppose to use load balancers in redundant configuration.
    2. Accordingly to the 2-nd task. To my mind there are two scenarios.
    2.1 First scenario. To built a DMVPN topology using main and backup offices as a hubs, and branch offices as a spokes.
    2.2 Second scenario. To by provider independet IPv4-adress block and ASN, to advertise main and backup office networks in internet.
    IV) My questions are:
    -What scenario according to the 2-nd task is better: using a DMVPN-topology or using an ASN-redundancy?
    -Is it possible to avoid assymetric routing problems in case of using a an ASN-redundancy?
    Thank you!

    I think Global loadblancer device will solve your both issue or there is an other solution for 2nd question,
    to use BGP confedration, that means use two private ASN internaly one in each DC, and put them both DC in one confedration, use one public ASN with all your  ISP's.
    Regards,

  • Ip addressing for data center

    can you suggest me which pool we use for data center public or private,which is best one

    You will encounter conflicts ONLY if you are connecting to a network that is using your same address space. See more below.
    The private IP addresses that you assign for a private network (inter-office LAN, Internet Service Provider customer bases, campus networks, etc) should fall within the following three blocks of the IP address space:
    10.0.0.1 to 10.255.255.255, which provides a single Class A network of addresses, which would use subnet mask 255.0.0.0.
    (theoretically up to 16,777,215 addresses, good for VERY large enterprises like internet service providers or other global deployment)
    172.16.0.1 to 172.31.255.254, which provides 16 contiguous Class B network addresses, which would use subnet mask 255.255.0.0.
    (theoretically up to 1,048,576 addresses, good for large enterprises like colleges and governmental organizations)
    192.168.0.1 to 192.168.255.254, which provides up to 2^16 Class C network addresses, which would use subnet mask 255.255.255.0.
    (theoretically up to 65,536 addresses, widely used by default in consumer/retail networking equipment)
    Explanation of Subnet masks, Network classes, and other technical info is readily available on the internet.

  • Migrate Standby ASA to Backup Data Center

    Hello Experts,
    We have backup data center where I am now  planning to provide backup internet service ( in the case where there is internet down or power outage at main server room) .
    I have a pair of Cisco ASA's 5540, one of which I need to move to backup data center ( BDC), Presently I have ADSL router at disaster serve room with static public IP from ISP.
    Currently, I am publishing all my internal resources through ASA. Now my questions, if I move Standby ASA to Disaster Server Room. How I can publish the same internal resources through standby ASA and make it standby as active during the down time of main server room
    Please can anyone suggestion how to achieve this setup. Is is this scenario possible
    Thanking in advance.
    Samir

    Hello,
    I knew it.
    I'll just tell you from the beginning hope it might help you to understand. I appreciate your help.
    Presently at my main data center I'm having a  leased line router and then 2 ASA 5540 (with failover active/standby).
    I was thinking to move 1 ASA to backup disaster server room. In this regard,  I asked earlier how I can still achieve the active/standby after migrating to backup room. But you had anwered my query
    Query 2
    I have got new ADSL service and router  with public static IP at backup server room. Now I moved one of my ASA.
    How can I keep publishing the internal resources ( like access to internal webserver, rdp connection) by using this ADSL service if the main server room is completely down .
    Hope it is clear.
    Thanks

  • Need helip for data center designing

    Sir ,
    I am going to design a data center where the following equipments are the
    1. one router 7609
    2. two core switch (WS-C6509-E)
    3. two firewall (WS-C6506-E, with Firewall blade)
    4. one VOICE ROUTER (CISCO2821with PVDM2-64, VWIC2-2MFT-T1/E1, PVDM2-32)
    5. one Remote Access Server (AS5400XM, AS5000XM 60 Dial Port Feature Card, AS5400 Octal E1/PRI DFC card)
    6. two CALLMANAGER-5.1
    7. multiple no of Cisco IP Phone 7940G with Video Advantage with VT Camera II
    8. one Gatekeeper (2811)
    9. one Internet Router (3845)
    10. one Authentication, Authorization and Accounting (AAA) System
    11. one ISDN RAS 2811 with2-Port Channelized E1/T1/ISDN-PRI Network Module with video conferencing (polycom)
    12. one Network Intrusion Detection/ Prevention System (NIDS)
    13. one NMS
    14. one Content Switch for Server Load Balancing
    15. multiple Video Phone
    16. lots of sever ( mail. Web, storage, etc )
    17. polycom MGC 100
    18. polycom 7000
    also 20 no of 7206 VXR will be connect with 7609 router through lease line
    so.. if u send me some link or some sample design and share some advice where I can gather some idea to design this data center in a proper way
    thanks
    tirtha

    IMO opinion the best place to start is by reading the SRNDs. They can be found here-
    http://www.cisco.com/en/US/netsol/ns656/networking_solutions_design_guidances_list.html
    Hope that helps.

  • How to know the balance and validity of internet data in iPad

    How to know the balance and validity of internet data in iPad?

    Sir I m using internet in ipad4 with airtel network
    They provide me 2gb data with the amount of 255 rupees
    And now I inserted the sim in my ipad4
    And start the surfing on safari n all
    And now I wanted to know how much data is balance.

  • Welcome to the Solutions and Architectures Data Center & Virtualization Community

    Welcome to the Solutions and Architectures Data Center & Virtualization Community. We encourage everyone to share their knowledge  and start conversations related to Data Center and Virtualization  Solutions and architectures.All topics are welcome, including  Servers – Unified Computing, Data Center Security, Data Center  Switching, Data Center Management and Automation, Storage Networking,  Application Networking Services and solutions to solve business  problems.
    Remember,  just like in the workplace,  be courteous to your fellow forum  participants. Please refrain from  using disparaging or obscene language  or posting advertisements.
    Cheers,
    Dan Bruhn 

    Hi,
    I have a question...
    I going to install two Nexus 7009 with three N7K-F248XP-25  modules on each one, I am planning to create 3 VDC, but at the initial configuration the system does not show the ethernets ports of these modules, even with the show inventory and show module I can see tah the modules are recognized and its status is OK. There is something that I have to do before start to configure these modules...? enable some feature or license in order to see the ports with show running CLI...?

  • Welcome to the Enterprise Data Center Networking Discussion

    Welcome to the Cisco Networking Professionals Connection Network Infrastructure Forum. This conversation will provide you the opportunity to discuss general issues surrounding Enterprise Data Center Networking. We encourage everyone to share their knowledge and start conversations on issues such as Mainframe connectivity, SNA Switching Services, DLSw+, managing SNA/IP and any other topic concerning Enterprise Data Center Networking.
    Remember, just like in the workplace, be courteous to your fellow forum participants. Please refrain from using disparaging or obscene language or posting advertisements.
    We encourage you to tell your fellow networking professionals about the site!
    If you would like us to send them a personal invitation simply send their names and e-mail addresses along with your name to us at [email protected]

    Hi together,
    Since the release of SAP NetWeaver 2004s to 'Unrestricted Shipment' as of 6th of June 2006, we have renamed the forum 'SAP NetWeaver2004s Ramp-Up' to 'BI in SAP NetWeaver2004s'.
    The forum should continue to adress BI issues particular to the release SAP NetWeaver 2004s. Please post general BI, project, etc. question to the other existing BI forums.
    The SAP NetWeaver BI organisation will also use this forum to communicate / roll-out information particular to the release of SAP NetWeaver 2004s (in addtion to the FAQs and other material on the SAP Service Marketplace and information in other areas of the SDN).
      Cheers
         SAP NetWeaver BI Organisation

  • Internet data sim in saudi how to use in iphone 4

    im kevin from the philipines, im here in saudi arabia, i bought a internet data sim from one of the telecom here and unfortunately its not
    working on my iphone 4 which i bought from the philippines, does anyone know what should be done for the settings i guess?
    thanks

    if it is locked to at&t you could possibly contact them for unlocking and cant use that iphone worldwide.

  • Deploying Cisco Overlay Transport Virtualization (OTV) in Data Center Networks

    Welcome to the Cisco Support Community Ask the Expert conversation. This is an opportunity to learn and ask questions about how to plan, design, and implement Cisco Overlay Transport Virtualization (OTV) in your Data Center Network with Cisco experts Anees Mohamed Abdulla and Pranav Doshi.
    Anees Mohamed Abdulla is a network consulting engineer for Cisco Advanced Services, where he has been delivering plan, design, and implementation services for enterprise-class data center networks with leading technologies such as vPC, FabricPath, and OTV. He has 10 years of experience in the enterprise data center networking area and has carried various roles within Cisco such as LAN switching content engineer and LAN switching TAC engineer. He holds a bachelor's degree in electronics and communications and has a CCIE certification 18764 in routing and switching. 
    Pranav Doshi is a network consulting engineer for Cisco Advanced Services, where he has been delivering plan, design, and implementation services for enterprise-class data center networks with leading technologies such as vPC, FabricPath, and OTV. Pranav has experience in the enterprise data center networking area and has carried various roles within Cisco such as LAN switching TAC engineer and now network consulting engineer. He holds a bachelor's degree in electronics and communications and a master's degree in electrical engineering from the University of Southern California.
    Remember to use the rating system to let Anees and Pranav know if you have received an adequate response.  
    Because of the volume expected during this event, Anees and Pranav might not be able to answer each question. Remember that you can continue the conversation on the Data Center, sub-community forum shortly after the event. This event lasts through August 23, 2013. Visit this forum often to view responses to your questions and the questions of other Cisco Support Community members.

    Hi Dennis,
        All those Layer 2 extension technologies require STP to be extended between Data Centers if you need to have multiple paths between Data Centers. OTV does not extend STP rather it has its own mechanism (AED election) to avoid loop when multiple paths are enabled. It means any STP control plane issue, we don't carry to the other Data Center.
        OTV natively suppresses Unknown Unicast Flooding across the OTV overlay. Unknown unicast flooding is a painful problem in layer 2 network and difficult to troubleshoot to identify the root cause if you don't have proper network monitoring tool.
       It has ARP optimization which eliminates flooding ARP packets across Data Center by responding locally with cached ARP messages. One of the common issues I have seen in Data Center is some server or device in the network sends continuous ARP packets which hits Control plane in the Aggregation layer which in turn causes network connectivity issue.
    The above three points proves the Layer 2 domain isolation between data centers. If you have redundant Data Centers with Layer 2 extended without OTV, the above explained layer 2 issue which happens in one Data Center carries the same failure to the second data center which creates the question of what is the point of having two different Data Centers if we can not isolate the failure domain.
      OTV natively supports HSRP localization with few command lines. This is a very important requirement in building Active/Active Data Center.
    Even though your question is related to L2TP, OTV deserves the comparison with VPLS and those comparison will also be applicable for L2TP. The below link explains in detail...
    http://www.cisco.com/en/US/prod/collateral/switches/ps9441/ps9402/white_paper_c11-574984.html
    Thanks,
    Anees.

Maybe you are looking for