Вы находитесь на странице: 1из 52

Design Workshop

IP Routing Service 1
Existing Solutions
• LAN Design #1
• Internet Edge Design #1
• Firewall Design #1
• WAN Design #1
• VPN Design #1
Network Design Diagram
Design Notes for LAN
General Design Notes: Services/Solutions

• Data Center Facilities • General Best Practices


• Reliability: Hardware, Power, Connections • Security Best Practices
• Network Management: NMS, Diagrams, • Routing
Docs • Virtual LAN (VLAN)
• Naming Std: <cmp>-<dev-id>-<rm>-<loc>-<st/co> • Trunking (802.1Q)
• VLAN Std: Data, Voice, Server, Mgmt, Other • Spanning Tree Protocol (STP)
• IP Address Std: 10.X.Y.H • Reliability: UDLD, LG, NSF, SSO
• Subnets: Users (4), Guests (4), Mgmt • Security: BPDU, DAI, SG, Trunk Sec, DHCP Snooping
• NM: SNMP, Log, NTP, VTY ACL, HW
• Multicast
• IPv6
• Power over Ethernet (PoE)
Design Notes for Internet Edge
General Design Notes: Services/Solutions

• Data Center Facilities • General Best Practices


• Reliability: Hardware, Power, Connections • Security Best Practices
• Network Management: NMS, Diagrams, • Routing, BGP
Docs • FHRP, Multicast, IPv6
• Naming Std: <cmp>-<dev-id>-<rm>-<loc>-<st/co> • Solutions: Firewall
• VLAN Std: Data, Voice, Server, Mgmt, Other • NM: SNMP, Log, NTP, VTY ACL, Netflow
• IP Address Std: 10.X.Y.H
• Subnets: Users (4), Guests (4), Mgmt,
Public, Transit (IE_LAN)
Design Notes for Firewall
General Design Notes: Services/Solutions/Features

• Data Center Facilities • General Best Practices


• Reliability: Hardware, Power, Connections • Security Best Practices
• Network Management: NMS, Diagrams, • IP Routing
Docs • NAT
• Naming Std: <cmp>-<dev-id>-<rm>-<loc>-<st/co> • Feature: SSL/TLS Decryption
• VLAN Std: Data, Voice, Server, Mgmt, Other • Feature: NGFW Security Features
• IP Address Std: 10.X.Y.H • Solution: VPN & Remote Access, DMZ
• Subnets: Users (4), Guests (4), Mgmt • NM: SNMP, NTP, Netflow, Syslog
• Policies: Access, RFC1918/2827, SMTP, Whitelist/Blacklist
• FW Traffic Considerations: H.323, SIP
Design Notes for WAN
General Design Notes: Services/Solutions

• Data Center Facilities • General Best Practices


• Reliability: Hardware, Power, Connections • Security Best Practices
• Network Management: NMS, Diagrams, • IP Routing
Docs • NM: SNMP, Log, NTP, VTY ACL, Netflow
• Naming Std: <cmp>-<dev-id>-<rm>-<loc>-<st/co> • Solution: VPN & Remote Access
• VLAN Std: Data, Voice, Server, Mgmt, Other • Multicast, IPv6, QoS, ACL
• IP Address Std: 10.X.Y.H
• Subnets: Users (4), Guests (4), Mgmt,
Public, Transit (IE_LAN, WAN_LAN), WAN
Network Design Diagram
Design Notes for Routing
Routing Notes Services/Configuration

• -- • --
Routing, IP
4 – Services
IP Routing Service
Step 1: Gather all subnets that will be used
• LAN/Campus
• WAN
• Data Center
• Internet Edge
• Voice (Unified Communications)
• Wireless
• DMZ & Extranet
Step 1: Gather all subnets that will be used
Step 1: Gather all subnets that will be used
• User Subnets (x4)
• Guest Subnets (x4)
• Management Subnet
• Public Subnet(s)
• Transit Subnet (Internet Edge_LAN)
• Transit Subnet (WAN_LAN)
• WAN Subnet(s)
• Server Subnet
Step 2: Where will each subnet be routed?
• Router
• Layer 3 Switch
• Firewall
• None
Network Design Diagram
Design Notes for Routing
Routing Notes Services/Configuration

• Public subnet(s) (routed on Edge routers) • --


Network Design Diagram
Design Notes for Routing
Routing Notes Services/Configuration

• Public subnet(s) (routed on ERs, FWs) • --


Network Design Diagram
Design Notes for Routing
Routing Notes Services/Configuration

• Public subnet(s) (routed on ERs, FWs) • --


• WAN subnets (routed on WAN routers)
Network Design Diagram
Design Notes for Routing
Routing Notes Services/Configuration

• Public subnet(s) (routed on ERs, FWs) • --


• WAN subnets (routed on WAN routers)
• User subnets (routed on L3 Core switch)
• Guest subnets (routed on L3 Core switch)
• Server subnets (routed on L3 Core switch)
• Transit subnets (routed on L3 Core switch)
• MGMT subnet (routed on L3 Core switch)
Step 3: Routing Protocols
Step 3: Routing Protocols
Step 3: Routing Protocols
Network Design Diagram
Step 3: Routing Protocols
Network Design Diagram
Design Notes for Routing
Routing Notes Services/Configuration

• Public subnet(s) (routed on ERs, FWs) • OSPF


• WAN subnets (routed on WAN routers)
• User subnets (routed on L3 Core switch)
• Guest subnets (routed on L3 Core switch)
• Server subnets (routed on L3 Core switch)
• Transit subnets (routed on L3 Core switch)
• MGMT subnet (routed on L3 Core switch)
• Routing Protocol (Internal): OSPF
Step 3: Routing Protocols
Internet Edge Design
Design Notes for Internet Edge
General Design Notes: Services/Solutions

• Data Center Facilities • General Best Practices


• Reliability: Hardware, Power, Connections • Security Best Practices
• Network Management: NMS, Diagrams, • Routing, BGP
Docs • FHRP, Multicast, IPv6
• Naming Std: <cmp>-<dev-id>-<rm>-<loc>-<st/co> • Solutions: Firewall
• VLAN Std: Data, Voice, Server, Mgmt, Other • NM: SNMP, Log, NTP, VTY ACL, Netflow
• IP Address Std: 10.X.Y.H
• Subnets: Users (4), Guests (4), Mgmt,
Public, Transit (IE_LAN)
Network Design Diagram
Design Notes for Routing
Routing Notes Services/Configuration

• Public subnet(s) (routed on ERs, FWs) • OSPF


• WAN subnets (routed on WAN routers) • BGP
• User subnets (routed on L3 Core switch)
• Guest subnets (routed on L3 Core switch)
• Server subnets (routed on L3 Core switch)
• Transit subnets (routed on L3 Core switch)
• MGMT subnet (routed on L3 Core switch)
• Routing Protocol (Internal): OSPF
• Routing Protocol (External): BGP
Step 4: Default Gateway
• Routing Types:
• Static routes
• IGP routing (OSPF, EIGRP)
• EGP routing (BGP)

• Default Gateway Root:


• Core switch
• Edge router
• Firewall appliance
Network Design Diagram
Design Notes for Routing
Routing Notes Services/Configuration

• Public subnet(s) (routed on ERs, FWs) • OSPF


• WAN subnets (routed on WAN routers) • BGP
• User subnets (routed on L3 Core switch)
• Guest subnets (routed on L3 Core switch)
• Server subnets (routed on L3 Core switch)
• Transit subnets (routed on L3 Core switch)
• MGMT subnet (routed on L3 Core switch)
• Routing Protocol (Internal): OSPF
• Routing Protocol (External): BGP
• Default Gateway via IGP (OSPF)
• Default Gateway Root via Edge router
Step 5: Route Filtering
• Using Access Control Lists
• Using a Firewall
• Virtualization (VLAN, VRF)
• None
• Isolated
Step 5: Route Filtering
• Using Access Control Lists
Step 5: Route Filtering
• Using a Firewall
Step 5: Route Filtering
• Using Virtualization (VLAN, VRF)
Step 5: Route Filtering
• Using Access Control Lists
Step 5: Route Filtering
• Using ACLs
• User Subnets
• Guest Subnets
• Server Subnet

• None
• Management Subnet
• WAN Subnet
• Transit Subnet (Internet Edge_LAN)
• Transit Subnet (WAN_LAN)

• Using Firewall
• Public Subnet(s)
Step 5: Route Filtering
Design Notes for Routing
Routing Notes Services/Configuration

• Public subnet(s) (routed on ERs, FWs) • OSPF


• WAN subnets (routed on WAN routers) • BGP
• User subnets (routed on L3 Core switch)
• Guest subnets (routed on L3 Core switch)
• Server subnets (routed on L3 Core switch)
• Transit subnets (routed on L3 Core switch)
• MGMT subnet (routed on L3 Core switch)
• Routing Protocol (Internal): OSPF
• Routing Protocol (External): BGP
• Default Gateway via IGP (OSPF)
• Default Gateway Root via Edge router
• ACL: User, Guest, Server subnets
• FW: Public subnets
Step 6: Additional routing related services
• Cisco Express Forwarding (CEF) ; recommended

• Policy Based Routing (PBR)


Design Notes for Routing
Routing Notes Services/Configuration

• Public subnet(s) (routed on ERs, FWs) • OSPF


• WAN subnets (routed on WAN routers) • BGP
• User subnets (routed on L3 Core switch) • IP CEF
• Guest subnets (routed on L3 Core switch)
• Server subnets (routed on L3 Core switch)
• Transit subnets (routed on L3 Core switch)
• MGMT subnet (routed on L3 Core switch)
• Routing Protocol (Internal): OSPF
• Routing Protocol (External): BGP
• Default Gateway via IGP (OSPF)
• Default Gateway Root via Edge router
• ACL: User, Guest, Server subnets
• FW: Public subnets
Step 7: Security Services for IP Routing
• NULL (Black Hole) Routing
Design Notes for Routing
Routing Notes Services/Configuration

• Subnets Routed: • OSPF


• Public subnet(s) (routed on ERs, FWs)
• BGP
• WAN subnets (routed on WAN routers)
• User subnets (routed on L3 Core switch) • IP CEF
• Guest subnets (routed on L3 Core switch)
• Server subnets (routed on L3 Core switch)
• Transit subnets (routed on L3 Core switch)
• MGMT subnet (routed on L3 Core switch)
• Protocols:
• Routing Protocol (Internal): OSPF
• Routing Protocol (External): BGP
• Default Gateway:
• Default Gateway via IGP (OSPF)
• Default Gateway Root via Edge router
• Route/Subnet Security:
• ACL: User, Guest, Server subnets
• FW: Public subnets
• Considerations:
• NULL (Black Hole) Routing, PBR
Network Design Diagram
Routing Service 1
Completed

Вам также может понравиться