Building Corporate Data Networks – A Case Study Delivered at Institution of Engineers, Sri Lanka - Saparagamuwa Provincial Center 31st March 2005
Objectives At the end of this case study you will be able to Transfer a business communication requirements into a data network requirement Describe the primary components that constitutes a data network Identify the basic elements of LAN, WAN and Security sub systems Prescribe a high level network structure for a generic corporate data network
Acme Corporation Acme Corporation is a multinational organization who has two of their manufacturing plants in Sri Lanka. They produce automobile tires for export and local market. The main factory and head office is located at Kelaniya and another factory at BOI zone, Katunayake. They have a warehouse at Peliyagoda and a raw material store at Thalawakale. Acme Corp need to build a data network to deploy their new ERP (Enterprise Resource Planning) application. The Katunayake factory and Peliyagoda warehouse are to be connected online to the head office and the raw material store is to be connected for batch processing via a dial up facility. In addition they need to have Internet connectivity, a local web site and E-mail service for their staff. Staff from corporate head quarters (abroad) and telecommuters in Sri Lanka need to gain access to Acme Corp network for various activities. Data and network security are concerns of the network administrator.
Acme Corporation (Cont’d) Raw Material Stores (Thalawakale) Branch Factory (BOI Zone - Katunayake) Warehouse (Peliyagoda) Internet Head Office / Main Factory (Kelaniya) Telecommuters Mobile Users
Network Elements User and server local connectivity at head office, branch, warehouse and store Network switches and devices Cabling infrastructure (copper/fiber) Wide area interconnectivity Routers Links from a network service provider Internet connectivity Router Internet connection from as Internet Service Provider (ISP) Security Firewall Virtual Private Network (VPN) device Telecommuting Remote access server Modems Telephone lines Wireless connectivity at head office Wireless access point Network address planning
Branch LAN Branch, Warehouse & Stores LAN Devices Branch Factory 10/100 Base-TX Warehouse 10/100 Base-TX Stores 10/100 Base-TX Branch, Warehouse & Stores LAN Devices 10/100 Base-TX Autosense Ethernet Switch - 03 nos. Copper (UTP) Cable plant at all 03 locations
Head Office LAN Floor 3 ERP Server and other shared Resources Wireless Access Point Mobile Users ERP Server and other shared Resources Network Printer Floor 3 10/100 Base-TX Optical Fibre Uplinks 100 Base-FX Floor 2 10/100 Base-TX Floor 1
Head Office LAN (cont’d) Head Office LAN Components 10/100 Base-TX Autosense Ethernet Switch – 03 nos. Optical fiber transceivers – 4 nos. Wireless Access Point – 1 no. Copper (UTP) / Fiber Cable plant
Wide Area Network Branch Factory Router Head Office Ethernet Modem DSU/CSU Modem Leased Line Ethernet Router Ethernet DSU/CSU Router Warehouse Ethernet Modem Router PSTN Modem Ethernet Stores
Wide Area Network (cont’d) WAN Components Routers – 4 nos. DSU/CSUs – 4 nos. (Digital Service Units/Channel Service Units) Modems (synchronous) – 5 nos. Leased Lines – 2 nos. Head Office ↔ Branch Factory Head Office ↔ Warehouse PSTN Links (Telephone lines) – 5 nos. Head Office – 2 nos. Branch Factory – 1 no. Warehouse – 1 no. Stores - 1 no.
WAN Connectivity Options Leased Links / Clear Channel Circuits Dead copper loops Active copper loops Microwave point-to-point links Microwave point-to-multi point access system PDH/SDH* transmission networks Satellite links Dark fiber loop Free space optics (laser) Public Switched Data Networks Frame Relay ATM Public IP Backbone Multi Protocol Label Switching (MPLS) IP backbone VPN over Internet Packet over SONET/SDH * PDH – Pleisiochronous Digital Hierarchy SDH – Synchronous Digital Hierarchy
WAN Data rates Link speeds DS0 - 64 kbps 128 / 256 / 512 / 1024 kbps E1 – 2 Mbps E3 – 34 Mbps OC-3c / STM-1 – 155 Mbps OC-12 / STM-4 – 622 Mbps OC-48 / STM-16 – 2.488 Gbps Gigabit Ethernet – 1,000 Mbps 10 Gigabit Ethernet - 10 Gbps Fiber Channel – 2 Gbps Uses OSI Layer 2 Framing Protocols
Dial-up Services Dial Backup Dial on Demand Bandwidth on Demand to recover from failed links Dial on Demand to provide on demand access and disconnect while idling Bandwidth on Demand to provide increased bandwidth during congestion Options PSTN – Public Switched Telephone Network ISDN – Integrated Service Digital Network
Internet Connectivity Unprotected Network De-militarized Zone Secure Network Web Server and Mail Server Internet VPN Gateway ISP ERP Server and other shared Resources DSU/CSU Firewall Router Downlinks to 2nd and 1st Floors To Router 10/100 Base-TX
Firewall Security Policy Web Server and Mail Server Internet VPN Gateway ISP Web, Mail server connections Outgoing Mail Incoming Web, Mail VPN connections ERP Server and other shared Resources DSU/CSU Router Firewall Downlinks to 2nd and 1st Floors To Router Corporate users’ Internet Access No access
Secure Access to ERP Server IPSec ‘Tunnel’ for secure communication Client at Headquarters Encrypted Authenticated Authorized Accounted …. access only. Internet Web Server and Mail Server ISP VPN Gateway ERP Server and other shared Resources DSU/CSU Router Firewall To Router Downlinks to 2nd and 1st Floors
Internet and Security Internet connetivity Security Router – 1 no. DSU/CSU – 1 no. ISP connection – 1 no. Security Firewall – 1 no. VPN Gateway device – 1 no.
Remote Access Service RAS Components Remote Access Server – 1 no. PSTN Ethernet (DMZ) Remote Access Server Modem Pool Home User Notebook Computer RAS Components Remote Access Server – 1 no. Modems (Asynchronous) – 4 nos. PSTN (telephone) lines – 4 nos.
Complete Head Office Network Leased Line DSU/CSU Modem Router PSTN Internet Router Firewall ISP DSU/CSU Remote Access Server Modem Pool Web Server and Mail Server ERP Server and other shared Resources VPN Gateway Wireless Access Point Mobile Users
Bill of Material Head Office Branch Warehouse Store Total Ethernet Switch 3 1 6 Optical Transceivers 4 Router 2 5 DSU/CSU Modem (Sync.) Remote Access Server Modem (Async.) Firewall VPN Gateway Wireless AP 1 1 Cable Plant ü
Summary Business requirement Network requirement Local area network Wide area network Internet connectivity Firewall and VPN
Thank you