Download presentation
Presentation is loading. Please wait.
Published byNorma Harrington Modified over 9 years ago
1
The Computing Infrastructure Division of Computing and Information Technology CLEMSON U N I V E R S I T Y July 30, 1997
2
Agenda n Background n Network Backbone Design & Connectivity n Network Resource Access n DCIT and Departmental Public Lab Access n User Support and Training n Summary
3
Background on Clemson IS n Large Systems Background n Strong Development Shop n Mainframe and Open Systems Expertise n Departmental LANs ruled 90’s until Novell Directory Services (NDS) n NDS populated in Summer 1995 (36,000 users) n Departmental LANs gone. More centralized management of the network. n NDS is centerpiece of security and authentication.
4
Mission n Provide computing infrastructure. n Empower Users and Departments. n Provide guidance in selecting solutions based on industry standards. n Deploy solutions to meet the needs of institutional computing. n Provide user support and training.
5
Network Backbone Design and Connectivity
6
Networking @ Clemson n Core Backbone n Distribution n Access n Dorm Access n Off Campus Access n Extension Offices n Internet Access
7
Core Backbone n FDDI 100Mbps ring n Connecting 8 Fiber Distribution Centers n FDDI connected routers
8
FDDI Core Backbone Brackett ITC
9
Distribution n Distribute backbone connections to buildings. n Most buildings have two 10Mbps connections. n Implementing switched 100Mbps connections to buildings. n Labs within buildings are on a dedicated 10Mbps connection.
10
Distribution Example
11
Access n Category 5 cabling within buildings. n Switches are used to provide traffic segmentation. n Most buildings have 48 to 78 users per segment.
12
Access n In the last year we have been connecting 24 port shared hubs to switched 10M segments for general use. n High bandwidth areas will get switched 10 or 100Mbps connections.
13
Access Example 1
14
Access Example 2
15
Dorm Access n 2500+ dorm rooms have a 10BaseT Ethernet connection per bed. n We use DHCP to assign IP addresses. n This Fall there will be a WEB page for Dorm residents to signup for service. n Automation of the port activation.
16
Off Campus Access n Partnered with MCI for dial up access. n Limited PPP connectivity free. n Any Internet Service Provider.
17
CampusMCI n MCI Provides ALL equipment and lines. n Adds additional equipment when needed. n Direct connection to the Clemson Network. n Internet traffic uses MCI’s Internet connection.
18
CampusMCI Cost to User n $14.95/month for 70 hours of connect time. n $0.95/ hour for additional connect time. n The hours 1am - 6am are FREE. n 800 service available at an additional $0.10/minute
19
Free Dial Up Access n 52 lines for Dial Up network access. n Support Point to Point Protocol (PPP). n Session time limit 30 minutes. n Limited to the Clemson domain, no Internet access.
20
Any Internet Service Provider n Faculty, Staff and Students can use their choice of Internet Service Providers to access Clemson Network resources.
21
Extension Offices n All 46 County Extension Offices of South Carolina are connected to the Clemson Network via Bell South Frame Relay service. n Each office has at least 24 ethernet ports.
22
Internet Access n BBN Planet provides a 3Mbps connection to Clemson from their Austell, Ga T-3 point of presence. n Will be converting to Info Avenue in Fall 1997.
23
What’s Next? n Add the Calhoun Courts and Lightsey Bridge dorms to the network. n Additional buildings with 100Mbps connections to backbone. n Deploy additional switches with the buildings. n ATM network testing.
24
Network Resource Access
25
Goals n Promote collaborative computing – Intra-workgroup – Inter-workgroup – Faculty/Student n Individual/Group presence on the network. n Central management of computing n Distributed management of data n Single authentication of distributed systems. n Keep heterogeneous systems “homogeneous”
26
Server Strategy & Management n Novell, NT, Unix, and OS/390 servers maintained by DCIT n DCIT provides hardware and Network Operating System (NOS). n DCIT administers backups. n DCIT performs user administration. n Group maintains data and security with help of a Tech Support Provider (TSP). n Virus Protection and Software Metering
27
Automatic Userid System (AUS) AUS Personnel Admissions MVS Unix NDS Other
28
Distribute Resource Management
29
Personal Storage (User Data Servers) StudentD EmployeD Any Faculty or Staff Member Any Student Office, Lab, or DialUp Dorm, Lab, or DialUp
30
Collaborative Storage - “Group Servers” (Faculty & Staff) Group Server2 EmployeD Group Server1
31
Collaborative Storage - “App Servers” (Students) StudentD Applications Server(N)
32
Collaborative Storage (Faculty and Students) App Server EmployeD Group Server1 StudentD
33
Printing Strategy OS/390 Unix ??? Print Gateway PC Mac Q Q Q Q Q
34
NDS Design for Printing
35
Electronic Mail Server: n Based on Sun Solaris. n No user accounts required on Solaris. n Server software developed at Clemson. n Multiple recipients / one copy of message. n Server based on POP/MIME Internet standard protocols. IMAP4 coming? n Eudora site license purchased by DCIT. n Listserver gaining wide spread acceptance and use. Class/section list automated.
36
Mail Server DOS POPc mainframe POPc Windows POPc Mac POPc UNIX POPc OS/2 POPc ? ? popD ListD Mail Server Mail Server
37
Mail Server: Statistics 199519961997*Category 14k 46k85kDaily Average POP Connections 13k36k62kDaily Average Msgs Retrieved from Server 27k48k92kAverage Msgs Sent using Server per day *based on partial year statistics through May 26, 1997.
38
Automated Email Distribution List & NDS Group Membership MVS OS/390 ListMGR popD ListD Mail Server Mail Server TCP/IP Class Roles Departments NDS GroupMGR NLM TCP/IP
39
WEB Serving n Institutional Servers n Department or Group Servers n Organizational Page Servers n Personal Page Servers n Administrative and Student Application Page Servers
40
NDS web Security via NT/Unix/?
41
Authentication Server n Too many userid/password combinations for each user to remember. n Need central set of secure servers that all systems use for authentication. n Clemson University Personal ID (CUPID). n Based on Automatic Userid System (AUS). n Idea born in interdepartmental task force. n Production on July 1, 1996.
42
Authentication Server MAIL authC WEB authC mainframe authC Unix authC Netware authC Sun authC NT authC Oracle authC
43
NDSNDS IntranetWare Server BIntranetWare Server A AUTHSERV.NLM IntranetWare Server C Mainframe(MVS) VTAM RACF AuthClient Onlines MAIL(solaris) AuthClient POPd NTServer(4.0) AuthClient Website Application User Workstation (‘95/Mac/NT Workstation) Eudora TN3270NetscapeLogin.exe Linux AuthClient Apache Application AUTHSERV.NLM
44
Authentication Server n NLM is multithreaded. n Clients use common code base. n Clients have built-in failover capability. n Communication based on TCP/IP sockets. n >90% successful password checks complete in less than 0.1 seconds. n >2 million requests serviced by primary server over a 6 week period. 50,000/day
45
NDS Authentication through NT/Unix/other To the WEB? Application: Employee Info System (EIS) Type: WEB Server OS: Windows NT 4.0 Server Enabling App: Website/Visual Basic
46
Using NDS Security Across the Intranet Authenticated Client Server Auth Client Authentication Server NDS Netscape IIS 32bit DLL AUTHSERV NLM NDS Page request CheckEquiv Check Security Equivalence Locate user object and run equivalence list. NT 4.0
47
AUTHSERV Client Functions n Password Check n Password Change n Resolve to Fully Distinguished Name n Check Security Equivalence n Check 3rd Party Access Rights n Return Group Membership n Misc Administrative Functions
48
Caldera OpenLinux and Apache Caldera OpenLinux File Server File Server File Server AuthC Browser AuthServer File Server File Server n WEB gateway to Netware File System.
49
Web Interface to Home Directories via Authserv NDS Gateway Application: Personal Pages Type: WEB Server OS: Linux Server Enabling App: Apache/Caldera http://www.clemson.edu/~acollin
50
Web Interface to Department Pages Application: Departmental Pages Type: WEB Server OS: Linux Server Enabling App: Apache/Caldera http://dcitnds.clemson.edu/CSO/depts/maint
51
Using NDS to Secure Web Pages NovellAuth on AuthName Novell Tree AuthType Basic require user gmcochr require user kellen require group.resadmin.groups.employee.clemsonu
52
WebAuth: Web Single Signon Workstation 3rd Party WebServer WebAuth Client AuthServ NLM NDS WebAuth NLM Auth Client Web Browser 1 Web Browser 2 DCIT Authentication WebServer WebAuth Trusted Client CHECK STORE Only trusted web servers prompt for userid password and set cookie in browser. Other web servers must use the cookie to determine the user. Redirect
53
Goals - Review n Promote collaborative computing – Intra-workgroup – Inter-workgroup – Faculty/Student n Individual/Group presence on the network n Central management of computing n Distributed management of data n Single authentication of distributed systems n Keep heterogeneous systems “homogeneous”
54
DCIT & Departmental Lab Access
55
DCIT Public Access Labs n For Everyone (not just Students). n Consist of Mac and PC workstations. n Every user has virtual “personal PC”. n All labs are identical to the user. n Each lab has an “application server”. n General purpose apps supplied by DCIT. n DCIT installs and administers applications for departments.
56
Departmental Labs n Marry DCIT’s public lab framework with the specialized needs of a department lab. n Space and workstations provided by the department. n Maintained by the department and SIG. n Allow the user access to the “lab” from anywhere.
57
Supported Operating Systems in Public Labs n Windows 3.11 n Windows 95 n Macintosh (System 7.6)
58
Windows 3.11 Lab Workstation Key Features n “Isitcool” is used to provide application server failover support. n Workstation runs “The Conformist” to ensure consistency among machines. n Custom contextless login is used to avoid context “problem.” n Each user gets a “Virtual PC” which follows them from computer to computer.
59
Isitcool - Fail-over Applications Server Attachment Applications Server(2) ISITCOOL NLM Applications Server(n) ISITCOOL NLM Applications Server(1) Work- station Lab 1 ISITCOOL NLM Workstation Disk Image Applications Isitcool? NO! YES!
60
The Conformist Applications Server(1) Work- station Lab 1 ISITCOOL NLM Workstation Disk Image Applications n Written by Clemson to provide a solution to the problem of corrupted workstations. n All application servers contain a image of a “perfect” workstation drive. nThe conformist performs comparison of the local drive to this “perfect” image and makes the appropriate changes. nThe conformist can also allow for slight variations between workstations.
61
Contextless login program n The user only has to enter their userid and password and we search for their userid in the three user containers and log the user in if found. n This means the user types “joeuser” and does not have to remember “.joeuser.j.students.clemsonu”
62
Virtual PC n All user settings are stored in their Novell home directory n This means as you move from PC to PC your settings follow, giving you the feel of your own PC each time you use a lab machine regardless of location.
63
Windows 95 Lab Workstation Key Features n SFLogin is used as contextless login solution. n Isitcool is used for workstation failover. n Roaming profiles are supported to provide virtual PC. Profiles are implemented in a way to reduce network traffic n PCRDist is run to ensure machine consistency.
64
Macintosh Lab Workstation Key Features n “Assimilator” is used to ensure consistency among machines. n Custom contextless login program is used to eliminate the context “problem”. n Eudora Launcher and Netscape Launcher are used to bring some of the features of the Virtual PC to the Macintosh.
65
The Assimilator AppleShare FileServer Work- station Lab 1 Macintosh Workstation Disk Image Applications n Appleshare File Servers contain a image of a “perfect” workstation drive. n Assimilator is not currently NDS aware so, images are currently stored on Macintosh Appleshare fileservers. nThe Assimilator performs comparison of the local drive to this “perfect” image and makes the appropriate changes.
66
Macintosh Contextless Login n The Macintosh login provides not only a contextless login solution, but finds and maps the users home directory as well.
67
User Support & Training
68
Support Structure Questions/Problems Answers/Resources Client Support Systems Integration LAN Systems Network Services TSPs HelpDesk Faculty Staff Students Level 1 College Consultant Computer Resources Enterprise Systems University Systems Support Level 2 Level 3
69
Training n Employee Training n Student Training
70
Employee Training n University Support Systems n Customized Training n Desktop Applications n Office Applications Specialist Certification Program n Technology Support Program
71
Student Training n In-class training n Computer Literacy Program n Short courses
72
Advanced Technology Center (ATC) n Focus on University multimedia activities n Provides funding for faculty multimedia projects n Maintains multimedia labs for training faculty and testing software n Offers multimedia training classes
73
Summary
74
n Clearly defined infrastructure support model n National leader in supporting collaborative computing n Efficient cooperative user support model n Weak points in support structure accurately identified
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.