RuggedPOD O/S Deployment strategy. Disclaimers The content of this presentation is released under GPL v2 license en Creative Common Attribution-ShareAlike.

Slides:



Advertisements
Similar presentations
Windows Deployment Services WDS for Large Scale Enterprises and Small IT Shops Presented By: Ryan Drown Systems Administrator for Krannert.
Advertisements

Campus LAN Overview. Objectives Identify the technical considerations in campus LAN design Identify the business considerations in campus LAN design Describe.
Saving Money by Recycling Existing Computers with LTSP Peter Billson Linux Terminal Server Project (LTSP.org) Linux User Group in Princeton LUG/IP July.
Ch. 6 – Switch Configuration CCNA 3 version Overview Identify the major components of a Catalyst switch Monitor switch activity and status using.
Content Overview Update Process Additional Tools.
Threaded Case Study - RE Miller (Nick Effler, Brian Ford, Cindy Coultas & Teresa Duchardt) April-May, 2000 b Project Goals Implement WAN Access to connect.
Hotspot Express $ One of the Pioneers of complete WiFi solutions in India $ Hardware to create HOTSPOTs  Software to secure HOTSPOTs & Manage the users.
Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D.
1 Version 3.0 Module 8 Virtual LANs. 2 Version 3.0.
© 2003, Cisco Systems, Inc. All rights reserved. FWL 1.0— © 2003, Cisco Systems, Inc. All rights reserved.
Vulnerability In Wi-Fi By Angus U CS 265 Section 2 Instructor: Mark Stamp.
Hardware Firewall Feature © N. Ganesan, Ph.D.. Chapter Objectives Show the configuration of a hardware firewall such as Dlink DI 604 Illustrate the sharing.
Topics 1.Security options and settings 2.Layer 2 vs. Layer 3 connection types 3.Advanced network and routing options 4.Local connections 5.Offline mode.
Introduction to XTMv WatchGuard Training.
Networking with Windows Vista.. Vista’s New Tools and Features The Network and Sharing Center Network Discovery Network Map Network Diagnostics.
Supermicro © 2009 GPU Solutions Universal I/O Double-Sided Datacenter Optimized Twin Architecture SuperBlade ® Storage Embedded IPMI.
Topics 1.Taking the Lock into use – physical serialization 2.Detailed setup options 3.Using mobile broadband 4.Taking the Key into use.
Computer Networks IGCSE ICT Section 4.
(part 3).  Switches, also known as switching hubs, have become an increasingly important part of our networking today, because when working with hubs,
1 © 2001, Cisco Systems, Inc. All rights reserved. Session Number Presentation_ID Cisco Easy VPN Solutions Applications and Implementation with Cisco IOS.
Treaded Case Study Computer Networks 2002 Daire Sheriden Ronan Monaghan Mark Gilmore.
Mesh Networking Broadband HamNet Advanced Configurations.
Untangle and OpenVPN. ‏ What is OpenVPN? Allows secure remote connection Based on SSL Uses UDP 1194 Supports – Site to Site (hardware to hardware) – Site.
© 2012 Cisco and/or its affiliates. All rights reserved. 1 CCNA Security 1.1 Instructional Resource Chapter 10 – Implementing the Cisco Adaptive Security.
TOSIBOX LOCK security options 1 1.
© 2007 Cisco Systems, Inc. All rights reserved.Cisco Public 1 Version 4.1 Configuring Network Devices Working at a Small-to-Medium Business or ISP – Chapter.
© 2007 NeoAccel, Inc. NeoAccel SGX Installation Guide Dear Customer: We are pleased to provide you with our training presentation for our SSL VPN-Plus.
Linux Operations and Administration
Fundamentals of Networking Discovery 1, Chapter 2 Operating Systems.
IGEL UMS Product Marketing Manager October 2011 Florian Spatz Universal Management Suite.
26/4/2001VMware - HEPix - LAL 2001 Windows/Linux Coexistence : VMware Approach HEPix – LAL Apr Michel Jouvin
IT:NETWORK:MICROSOFT SERVER 2 DHCP AND WINDOWS DEPLOYMENT SERVICES.
Module 6 – Switch Configuration CCNA 3 Cabrillo College.
1 © 2003, Cisco Systems, Inc. All rights reserved. CCNA 3 v3.0 Module 6 Switch Configuration.
1 © 2003, Cisco Systems, Inc. All rights reserved. CCNA 3 v3.0 Module 6 Switch Configuration Cisco Networking Academy.
1 © 2003, Cisco Systems, Inc. All rights reserved. CCNA 3 v3.0 Module 6 Switch Configuration.
INSTALLING MICROSOFT EXCHANGE SERVER 2003 CLUSTERS AND FRONT-END AND BACK ‑ END SERVERS Chapter 4.
Weekly Report By: Devin Trejo Week of May 30, > June 5, 2015.
RSG (Remote Service Gateway). 1. Overview  Overview The LDK-RSG (LDK-Remote Services Gateway) is a remote gateway that provides a fully transparent connection.
CCNA 3 Week 6 Switch Configuration. Copyright © 2005 University of Bolton Physical Details Available in variety of sizes –12 port, 16 port, up to 48 port.
Functional Area 3: ProPortable Module 3.4 ProPortable Router GUI.
HUB Connects multiple workstations, servers, and other devices to a network. Can be used to connect two or more computers to one network port. Handles.
© 2007 Cisco Systems, Inc. All rights reserved.Cisco Public ITE PC v4.0 Chapter 1 1 Configuring Network Devices Working at a Small-to-Medium Business or.
1/28/2010 Network Plus Unit 4 WAP Configuration WAP Configuration In this section we will discuss basic Wireless Access configuration using a Linksys.
Smart Switches FS526T / FS750T / GS748T / GS724T
Company LOGO Networking Components Hysen Tmava LTEC 4550.
Cisco ASA 5505 Joseph Cicero Northeast Wisconsin Technical College.
1 Cisco Switch (Ref. CCNA5 Introduction to Networks 2.1)
OBJECTIVE: o Describe various network topologies o Discuss the role of network devices o Understand Network Configuration Factors to deploy a new network.
1 © 2005 Cisco Systems, Inc. All rights reserved. 111 © 2004, Cisco Systems, Inc. All rights reserved. CNIT 221 Security 2 ver.2 Module 8 City College.
Setup and Management for the CacheRaQ. Confidential, Page 2 Cache Installation Outline – Setup & Wizard – Cache Configurations –ICP.
Installing a Network Printer. Network printers work much like any other printer except the data flow is through a network. This means the printer must.
The Washington School District Mike, Mark, Joy, Armando, & Mona.
Wireless ISP Infrastructure
Laptop Support in PPD Chris Brew Rutherford Appleton Laboratory.
NETGEAR CONFIDENTIAL FVX538 ProSafe VPN Firewall 200.
1 Version 3.0 Module 8 Virtual LANs. 2 Version 3.0.
System Center 2012 Configuration Manager Service Pack 1 Overview.
© ExplorNet’s Centers for Quality Teaching and Learning 1 Install, configure, and deploy a SOHO wireless/wired router using appropriate settings. Objective.
SMOOTHWALL FIREWALL By Nitheish Kumarr. INTRODUCTION  Smooth wall Express is a Linux based firewall produced by the Smooth wall Open Source Project Team.
Cisco Exam Questions IMPLEMENTING CISCO IOS NETWORK SECURITY (IINS V2.0) VERSION: Presents: 1.
OSCAR Symposium – Quebec City, Canada – June 2008 Proposal for Modifications to the OSCAR Architecture to Address Challenges in Distributed System Management.
Configuring Network Devices
Mobile equipment for vacuum control
Obtain Your Dream Certification
pfSense Presented at the MUUG General Meeting on 2012-Apr-10
Wireless Modes.
Embedded IPMI.
Configuring Network Devices
HC Hyper-V Module GUI Portal VPS Templates Web Console
Presentation transcript:

RuggedPOD O/S Deployment strategy

Disclaimers The content of this presentation is released under GPL v2 license en Creative Common Attribution-ShareAlike 4.0 International Attribution-ShareAlike 4.0 International Feel free to contact us if you have any question – RuggedPOD is an Open Hardware project released under OCP HL R license.

Context RuggedPOD can be operated from LAN to WAN (aka the distance between the POD might be really long with limited bandwidth and high latency in the case of a Telco CDN usage, or could be ultra short in the case of an Outdoor Datacenter Approach)

Software constraints RuggedPOD has a local firmware running on a RaspberryPI 2 board. This firmware is Linux based and has to be upgradable Local boards needs to be remotely bootable and installable.

Long distance use case  600 kms  10Mbps  100 kms  100Mbps RuggedPOD 1RuggedPOD n Blade 1Blade 2 Blade 3Blade 4 Raspberry Interna l switch Optional switch Remote management site End user backbone and offices 1Gb/s 10Gb/s or 1Gb/s copper

Short distance use case Can we assume that if long distance strategy works short distance might be relevant too ?

VLAN strategy We assume that the boards used doesn’t have a mandatory IPMI interface and that Administration tasks are “special” tasks performed into a distinct operating mode than production. 2 VLAN – 1 Admin Address allocated through DHCP request or static mode – Initial configuration performed through DHCP – If remote technician deployment, setup can be performed locally with a pre-configured laptop running a DHCP server and associated cable Remote management board port as well as Blade boards ports are in the same admin VLAN at initial setup Remote management board moves Blades boards from Admin VLAN to Production VLAN through ReST call PXE is available only on the Admin network and from the Remote Management card – => everything to deploy O/S must be distributed through this network – Remote management board discover Mac Address and provide PXE only to the local Mac Address

VLAN strategy (2) Production – Production is a routable network with public access and no firewall – Production is accessible only through the node when they have reached the “INSTALL” status Switch ports – At a time a switch port can be configured into a single VLAN. No port trunking is allowed

VLAN strategy constraints Internal switch has to be reconfigurable through the management board as to switch ports from Administration VLAN to Production VLAN Switch firmware has to be “rock-solid” as if it is hacked, access to the admin network could be performed except if MAC address filtering is performed at the backbone side. A CLI or ReSTful API is needed on the switch side

Remote console and Management GUI Blade boards can be accessed through a local Webserver running on the admin board The GUI provides full access to remote console through serial connection to each board or through IPMI remote console (need to be configured board per board through the GUI)

Case of boards with integrated IPMI We do not use the feature and it has to be disabled at firmware level if the remote console is still accessible after that operation Remote console has to be available through serial connection