Network Topology/Configuration Validation

Hi,
We are implementing a Two-tier firewall architecture using Fortigate and cisco ASA-5500 series firewall for our internal network.
All the tiers will be redundant mode firewall (Active/Active)
First tier firewall (Fortigate) will host the WEB servers (Front end servers)
Second tier firewall (ASA-5520) will host the database (Back end servers) storage servers
Pls refer the attached security-setup-final PPT for actual topology.
Kindly Guide on the configuration in terms of :-
1) Routing protocol to be used (OSPF/RIP)
2) PRI dialup config (DDR) design for branches
3) Firewall design validation
4) IP Scheme validation (Attached)
5) Wan setup termination point
Pls suggest if the proposed setup and related IP scheme will work seamlessly
Regards

Hi,
How many OSPF areas should be created.
For Primary and DR site.
Should both the site be configured in area 0 or different area.
Also should we use single subnet for dialup (ISDN-BRI) for backup or should we use point to point subnet for each dialup location.
Primary link will be channelized E1.

Similar Messages

  • Creating a network topology with Darwin

    Hello,
    here are some questions concerning the neural net module at Darwin. I would be grateful if anyone can answer some of my questions:
    1. sensitivity analysis: How is importance/sensitivity of each independent variable to the model measured ? (E.g. by measuring the %-increase of the train error if specific variable is taken out of the model ? )
    2. Darwin provides the user with three types of activation functions: linear, sigmoid and hypertangent. In a paper with the title "Darwin: A scalable integrated System for Data Mining" , May 14 1997, accessible throug the ORACLE web-sites, some more activation functions have been mentioned : Heaviside, sinusoidal etc. The (most recent) release Darwin 3.7, has only three different activation functions. How can different activation functions be added. I would like to know that, because many application examples from the financial sector used the Gaussian or Radial basis (RBF) function to develop models in financial analysis (portfolio management, prediction of financial crisis etc.)
    MOST IMPORTANT QUESTIONS CONCERNING DEVELOPMENT OF NETWORK ARCHITECTURE AND NETWORK TRAINING:
    -> Please refer again to "Darwin: A Scalable Integrated System for Data Mining
    Overview of Darwin's philosophy, architecture, and functionality for 2.x and 3.x releases, 1997" , May 14 1997, accessible throug the ORACLE web-sites on http://datamining.us.oracle.com/
    3. p. 7 : The train and cross-validation mode includes an efficient implementation of the cross validation method for choosing the optimale size of network. It takes advantage of the properties of the error surface, and trains multiple networks with only a marginal increase in time needed for training a single network.
    As the notion "Cross-Validation" and especially algorithms using "cross-validation"-techniques to develop a network topology have throughout literature completely different definitions and underlying ideas, may you please explain your understanding of cross-validation by clarifying the algorithm for selection of single-hidden-layer neural net as described above.
    4. Learning curve analysis: Does exist a bootstrap loop for the evaluation of a learning curve ? How was the learning curve, as it is presented in the paper above, developed with the aid of a bootstrap-loop explained on p. 11
    5. Most recent results in research on generalization performance and its relation to the development of an architecture of a neural net, assume/stress again that overtraining is only an effect of a misspecified, too high machine complexity. Therefore, in this case, conventional training&test-mode is not appropriate for traing a learning machine of optimal complexity.
    Consequently, the idea of stopped-training is ambiguous. Only a learning machine with a too high complexity, is capable of approximating the intrinsic noise in the data.
    The generalization performance of a learning machine of optimal complexity (i.e.no under-, no overfitting) increases asymptotically without turning point. (in this case: test error decreases asymptotically with the number of training iterations)
    Own experiences, results, comments ?
    Please note : Following article could answer this question from a more theoretical viewpoint, but hasn't been available to me yet:
    Wang, C., Venkatesh, S. S. and Judd, J. S. 1994. Optimal Stopping and Effective Machine Complexity in Learning.
    Advances in Neural Networks Processing Systems, G. Tesauro, D. S. Touretzky and T. K. Leen Eds. MIT Press.
    Vol. 7, p239.
    6. Does Darwin provide the user with a visualization tool in order to illustrate the process of learning by showing network weights? If not, how can this be implemented with the help of Darwin.
    This has often been defined as "monitoring" in order to show development of network weights and to make some conclusions.
    7. Genetic Algorithms: Can you specify the exact values of the parameters used in the genetic algorithm for network training? E.g. the defined value of the probability of mutation. Please note, that different parameter values (e.g. probability of mutation) used in the genetic algorithm have an effect on the performance of the search for a global optimum .
    8. Genetic Algorithm : Why does the g
    genetic algorithm has a learning rate ? Normally Genetic Algorithm do not have learning rates, please explain this parameter.
    Learning rate are only know for gradient descemt algorithms.
    9. Key-field wizzard: How is the importance of an independent variable towards the dependent variable measured ? Which is the underlying correlation coefficient ? The Darwin Help explains the two options to calculate the importance: Gini and cost.
    10. E.g. why not use IBM intelligent miner for data preparation instead ORACLE Darwin, because Intelligent miner has two very important processes for data preparation in order to clean data from multi-collinearity:
    - factor analysis
    - principal component analysis (delivers same results)
    null

    I have a very similar setup and I'd be happy just to be able to get my MacBook to print to the HP6213!
    Are there any guidelines out there for setting up to print to a printer connected to a Windoze infected PC?
    btw
    I suspect you'd need a printer with a LAN card onboard to be able to print to it without using the Windows machine as a print server.
    rgds,
    Dave

  • How to Identify the Network Topology being used for a running ForeFront TMG Stand Alone array?

    Hello Experts,
    My client has decided to move their datacenter  from one location to other including the ForeFront TMG servers which are being used as Reverse Proxy and TMG Gateway  in DMZ environment.
    I need to know the network topology used for this configuration so that I could chose the same topology when creating new TMG environment at new datacenter. Here are some details : 
    1. There are 2 TMG servers configured in a DMZ Workgroup in Stand Alone array.
    2. Both servers have 3 NIC attached to them. (one has all public IPs configured, another one has internal IP address and the third one has Management IP which is used to connect the server via RDP).
    3. There are more than 50 websites published via this standalone array.
    I am very new to Forefront TMG technology and need to know the Topology used to create such environment.
    Thanks 
    Lalit

    Hi,
    According to your description, you can use the 3-leg perimeter network template and choose which network adapter connects to the LAN, which network adapter connects to the external  network and which network adapter connects to the DMZ.
    Did you set up TCP/IP settings for the three NICs? If not, please refer to the link below:
    Recommended Network Adapter Configuration for Forefront TMG Enterprise Edition Servers
    More information:
    Microsoft Forefront TMG – How to use TMG network templates (Note:
    Microsoft is providing this information as a convenience to you. The sites are not controlled by Microsoft. Please make sure that you completely understand the risk before retrieving any suggestions from the above link.)
    Best regards,
    Susie

  • Cisco Prime Infrastructure 2.2 - Network Topology error

    He dears,
    My Customer has installed over UCS Cisco Prime Infrastructure 2.2.
    The network is composed with Switches nexus 93962-px and 2960x. All devices were discovered and inventoried successfully.
    The problems is that Network Topology is not showing the connections between devices. Some devices connections are showed (partially) and another not.
    We've already checked that CDP is run and working fine on all of switches.
    I appreciate your help!
    Tks,
    Regis

    I'm sorry to say that but Prime Infrastructure does not support IP SLA functionality similar to Cisco Prime LMS:
    http://www.cisco.com/en/US/prod/collateral/netmgtsw/ps6504/ps6528/ps12239/guide_c07-729089.html
    It's in the developer's plans but there's no schedule yet for this feature.
    It's possible to manually configure IP SLA on the device and then define Custom SNMP templates in Prime Infrastructure and poll whatever information you might consider relevant.
    This isn't user friendly (exact OID needs to be typed manually) and is a bit quite complicated, though.
    -Thanks
    Vinod
    **Rating Encourages contributors, and its really free. **

  • Drawing network topology in Cisco Prime LMS 4.2

    Hi all:
    I installed the Cisco Prime LMS 4.2 and managed to discover the Cisco devices and user devices like my PC stations.
    Then I tried to draw the network topology from this LMS 4.2 and I found the topology under the Configuration and Monitor tab. By clicking to these two tabs, it appears a page of something like below:
    Topology Services
    You can use Topology Services to:
    - View detailed xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
    - Display the physical and logical services in your network
    - xxxxx xxxxxxxxxxxxxxxxxxxxxxxxxxxx
    - xxxxx xxxxxxxxxxxxxxxxxxxxxxxxxxxx
    - xxxxx xxxxxxxxxxxxxxxxxxxxxxxxxxxx
    - xxxxx xxxxxxxxxxxxxxxxxxxxxxxxxxxx
    - xxxxx xxxxxxxxxxxxxxxxxxxxxxxxxxxx
    There is no action click on this page and it looks like an explanation page and cannot do anything.
    May I know how to draw the networl topology by this Cisco Prime LMS 4.2?
    Hope to hear the answer from anyone know about this soon. Many thanks!
    Warmest regards,
    tangsuan

    Hi Mantej:
    Thanks to your link and I have downloaded the Prime LMS 4.2 document.
    I then read and installed the JRE first in 64 bits because my Windows OS is 64bits but it still prompts out the Java installation screen. I then installed the JRE in 32 bits.
    After that, it has no more Java installation screen. It then request for downloading file at the Windows top bar. I follow the request to riight click to allow the downloading. The Java running and downlaod the file.
    After that, I cannot see any difference. Meaning I still cannot access anything for Toplology Services to draw my network topology diagram.
    May I know what should be happen and what is the next step to do the topology drawing?
    Many thanks!
    Regards,
    tangsuan

  • Realtime - network topology viewer

    Hello guys,
    is it possible to see realtime network topology viewer without collecting data manually. because everytime my device down , i have to click "perform data collection button " to see realtime network topology. without pressing it, looks like our device still up. 

    You should not set data collection to less than 5 minutes. It will likely be continually be consuming resources on your server and adversely affect performance (usability).
    Here is the relevant section from the above reference (the same documentation should be available with your server):
    Scheduling Data Collection
    Data Collection runs automatically when you add, or delete devices in the Unified Device Manager (UDM).
    You can also schedule the day and time of data collection using this feature.
    You can start data collection immediately for all or failed devices and schedule data collection for all devices. All devices is a default option. You can select the Failed devices option to run data collection for failed devices.
    To schedule data collection:
    Step 1 Select Admin > Collection Settings > Data Collection > Data Collection Schedule.
    The Data Collection Schedule dialog box appears.
    Step 2 Modify the data collection settings as described in Table 6-2.
    Table 6-2     Data Collection Schedule Settings
    Field
    Description
    Usage Notes
    Schedule
    Days, Hour, Min
    Days on which and the time at which data collection is scheduled.
    The optimum data collection schedule depends on the size of the network and the frequency of network changes.
    The default data collection schedule is every 4 hours, on the 4-hour mark, daily: 04.00, 08.00, 12.00, 16.00, 20.00, 24.00 Note that time is in the 24-hour format.
    •Select a schedule and click Edit to edit the schedule.
    •Select a schedule and click Delete to delete the schedule.
    •Click Add to add a new schedule.
    Step 3 Click OK to save the changes or click Cancel to exit.
    Best Practices
    Be cautious while scheduling Data Collection:
    •Data Collection consumes significant resources on the network management system.
    •Use the Polling option to see the device and link status without running data collection. For more details on polling see, Data Collection Critical Device Poller
    Data Collection Critical Device Poller
    LMS polls the entire network for device and link status periodically.This feature allows you to:
    •Configure the time interval at which the network is polled.
    •Poll only a critical set of devices.
    Use this option to see the device and link status without running Data Collection.
    Since Data Collection consumes significant system resources, you can simply poll the network and view the device and link status in Topology maps.
    Adding Critical Devices to the Device Poller
    To add a device to the Critical Devices list from Topology Map:
    Step 1 Launch a Topology map.
    Step 2 Right click a device and select Add device to Critical Poller.

  • LMS 4.1 Network Topology Layer 2 view - Re layout map not working

    I've finally got Topology Data Collection working on Prime LMS 4.1.
    However, when I run Network Topology Layer 2 view and try and re-layout the view to any of the options, Circular, Hierarchical, Symmetrical or Orthogonal, the map never re-draws to that type of layout.It always stays as a mess.
    I think it must be a 'feature'.
    Any ideas ?
    Cheers
    Barry

    I searched again and didn't find any errors in the same line as the IP or Hostname of the unconnected switches. But I did notice that these switches and all of the devices upstream have "Discovery ani TopoSMFGenerateAbstractTopology" lines where the rest have "Discovery ani TopoSMFGenerateCdpTopology". Do I need to delete everything upstream to the seed device and then rerun a Data Collection? I've included the log. One of the unconnected switches is: 192.168.40.11 Display name: TC160_C. Thanks again.

  • Find network printer configuration remotely

    Hi,
    Is there a way to know all my network printers specific configuration,
    (we have many print servers,  and many network printers configured with different configurations,  one such is "keep printed documents")
    I would to know in my network how many print queues are enabled this configuration option,  if this is possible via script or GUI console.

    Thanks for the reply,
    I gone through those PS commands,  those cmds only apply for W2K12 servers,  I am looking for cmd or scripting options for win2k3 and above servers,  Its a mixed environment.    
    check out this:
    Syntax
    cscript prncnfg.vbs -t [-s RemoteComputer] -p PrinterName [-u UserName -w Password]
    [-r PortName] [-l Location] [-m Comment] [-h ShareName] [-f SeparatorText] [-y DataType]
    [-st StartTime] [-ut EndTime] [-o Priority] [-i DefaultPriority] [{+ | -}shared]
    [{+ | -}direct] [{+ | -}published] [{+ | -}hidden] [{+ | -}rawonly]
    [{+ | -}queued] [{+ | -}keepprintedjobs]
    [{+ | -}workoffline] [{+ | -}enabledevq] [{+ | -}docompletefirst][{+ | -}enablebidi]
    from this link: http://technet.microsoft.com/en-us/library/bb490971.aspx
    Every second counts..make use of it. Disclaimer: This posting is provided AS IS with no warranties or guarantees and confers no rights.
    IT Stuff Quick Bytes

  • Prime Infrastructure 2.2 - Network Topology View - Spanning Tree View

    Hello Team,
    Is it possible on PI 2.2 (latest version) under Maps/Network Topology View to be able to "monitor" the spanning-tree performance?
    thanks in advance,
    George

    Sorry but that's not a currently offered feature.
    It would be nice - the Netsys product that Cisco acquired 18-1/2 years ago (and subsequently abandoned) used to do this quite nicely.

  • Configuration validation resulted in error(s)

    Hi,
    I am facing a problem in configurator,we are using deferred booking workflow.When we are creating new orders with ATO/PTO items the standard BOOK Node in the workflow is getting completed with result Incomplete.
    The error message on sales order, which we can see from View all open messages, is saying as"Configurator validation resulted in error(s)".
    When we copy the above sales order which is failing with above error and create a new order, the new order is getting booked successfully.We are not changing anything in the copied order.
    Also the deferred workflow is not giving any issues when creating a sales order using the Standard item.The OM debug is also not suggesting anything related to this.
    Please let me know if anyone have come across this issue.
    Thanks!

    Thanks Sandeep for ur reply on this..
    I followed the process u mentioned but it didnt work.Actually as I mentioned in my first question, this issue is coming up only when we are creating new sales order.If we copy the sales order which is not getting booked then the new one(copied) sales order's gets booked correctly.Though the copied sales order also have same configuration.
    I also tried to validate the Configuration for the sales order having issue using the api CZ_CONFIG_API_PUB.verify_configuration and this resulting as SUCCESS.
    Is there any thing in the deferred booking process which may cause this issue?
    Also the error message Configuration Validation resulted in errors is coming through a exception, and the exception is being used in CZ_BATCH_VALIDATE.The batch validate is being called from Send_Input_xml procedure.It seems if we copy the order this procedure for batch validate is not being called.
    but i m not getting any clue in Send_Input_xml procedure abt why exception is being raised.
    Thanks!

  • Is a one server with two system IDs configuration valid when using MSCS

    As the last step in my upgrade from BW30b to BI70 I need to introduce Java.
    My newly upgraded ABAP BI70 system is running on a Microsoft Cluster and it was my intention to add Java as a separate system(SID).  When doing this it appeared I would be able to add the two systems to the same cluster group by selecting "Support of multiple SAP systems in one MSCS cluster" but this resulted in errors and I have found note 967123 which tells me not to chose this option when using MSCS.
    It appears my options are a separate server all together or an ABAP+Java install which limits our upgrade options on each stack.
    If anyone has found a work around for this I would be very interested.
    Thank you

    Hi Helmut,
    Not sure how the D-Link works, but it looks like it has Wireless 802 also from the specs, so the Ethernet & Wireless would each have an IP & different MAC addies.
    I always thought one Mac address can have only one IP address.
    Nope, you can prove this to yourself on your Mac, In Network>Show:>Network Port Configurations, highlight say Ethernet, Copy, give that another IP Manually if you wish...

  • Network Topology for Performance/Redundancy

    Hello there,
    I am projecting my first Oracle VM Pool for the test the virtualization the many Single Oracle Databases 11Gr2 Standard Edition One, but I have difficult about the network topology best practices.
    I have imagined this:
    bond0(2x 1gb) - Manament Network and Heartbeat.
    bond1(2x 1gb) - Live Migration. ( I want use DRS )
    bond2(2x 1gb) - VM Public Network.
    bond3(2x 1gb) - VM Manament Network ( Manamgement and Backup for VMs ).
    bond4(2x 10GBE) - Storage. ( with Jumbo Frame )
    All bonds in active-backup (mode=1)
    All ports to be connected to two distinct switchs for redundancy.
    Is that correct ?
    Any suggestion ?
    Best Regards,
    Rodrigo.

    This blog post will provide the networking design details your looking for: Oracle Cloud Reference Design

  • Configuration Validation error when booking an Sales Order.

    Hi,
    Getting an error when booking an sales order ie; "Configuration Validation error".
    We are upgrading from 11.5.8 to 12.1.1 and this issue is critical. Please provide your valuable suggestion and advice.
    Thanks in advance,
    Asif

    It seems you use configurator. Is this happening in production or in some test instance?
    If it is a test instance, when was it cloned from prod? Did you clone the configurator instance at the same time?
    1) You should publish the configurator model from the configurator developer to this new instance.
    2) Also, it is possible that the selections made during order entry earlier are not valid anymore due to ECO/BOM changes or due to configurator rule changes. Open the configuration, make any selections if necessary and then click ok.
    This will repopulate the order lines then you should be able to book the order.
    Hope this helps
    Sandeep Gandhi
    Independent Techno-functional Consultant

  • Preferences advanced network connection configure button missing

    Checking preferences > advanced > network > connection > configure how Firefox connects to the internet, found that the "settings" button did not appear. Also, the "encryption" tab on the far right was gone.
    Most recent changes were to install addons Certificate Patrol and Perspectives. I reverted to a profile saved before they were installed but that made no difference. The troubleshooting data below is without the two addons.

    Thanks for the quick response. To answer the first question, the window can't be resized, at least on 10.5. Macs are cranky about such things.
    I had been working on isolating the problem since posting the question. It is in my userChrome CSS running under Stylish; so the problem is either the CSS or Stylish or Stylish Custom. In any event not some external thing, which was my main concern. I'm sure that this did not occur with previous combinations of Firefox, userChrome, and the two extensions. The problem may never be fixed, but can be circumvented by just disabling the CSS when needed.
    Sorry to have stirred up things, but it was a troubling phenomenon.

  • Network Interface Configuration

    For Solaris 9,
    <<Q1>> What is the following interfaces name means? le, hme? Which is the Ethernet port?
    <<Q2>> Where is the networking configuration file stored in the Solaris 9?
    <<Q3>>How to configure the network interfaces in Solaris 9?
    <<Q4>> Did we need to restart the network after we have edit the network configuration? If, how to restart the network? (e.g. in Debian /etc/init.d/networking restart).
    Please assist.

    You also posted this same question at another forum web site.
    It appears your answer is going to be over there.
    There's now no sense in duplicating it here.
    ['Network Interface Configuration' at www.LinuxQuestions.Org|http://www.linuxquestions.org/questions/solaris-opensolaris-20/network-interface-configuration-652192/]

Maybe you are looking for