Presentation is loading. Please wait.

Presentation is loading. Please wait.

Brookhaven Science Associates U.S. Department of Energy 1 Network Services BNL USATLAS Tier 1 / Tier 2 Meeting John Bigrow December 14, 2005.

Similar presentations


Presentation on theme: "Brookhaven Science Associates U.S. Department of Energy 1 Network Services BNL USATLAS Tier 1 / Tier 2 Meeting John Bigrow December 14, 2005."— Presentation transcript:

1 Brookhaven Science Associates U.S. Department of Energy 1 Network Services BNL USATLAS Tier 1 / Tier 2 Meeting John Bigrow December 14, 2005

2 Brookhaven Science Associates U.S. Department of Energy 2 Network Services n BNL LHC Overview Preliminary Network and Security Architecture IP Address space allocations Performance Monitoring

3 Brookhaven Science Associates U.S. Department of Energy 3 n Network Security Limitations Current firewall Architecture –6 virtual 1 Gb/Sec EtherChannel to backplane –Rated total throughput of 5 Gb/Sec -EtherChannel Overhead Loss –Single 1 Gb/Sec flow / interface Network Services

4 Brookhaven Science Associates U.S. Department of Energy 4 n Network Security Limitations (Continued) Current Router Architecture –Single Access Control List (ACL) / interface -1 inbound and 1 outbound -Default behavior Implicit deny –A single ACL can become unwieldy in a complex WAN environment Network Services

5 Brookhaven Science Associates U.S. Department of Energy 5 n Network Security Limitations (Continued) Network Services …………. access-list 109 deny ip host 81.12.96.78 any access-list 109 remark Block IPs per ticket 160,729 1 Month 12/8 access-list 109 deny ip host 219.105.44.115 any access-list 109 deny ip host 217.199.177.208 any access-list 109 deny ip host 202.108.13.91 any access-list 109 deny ip host 210.219.231.2 any access-list 109 remark ********************* Allow ************************* access-list 109 remark permit all before implicit deny access-list 109 permit ip any any

6 Brookhaven Science Associates U.S. Department of Energy 6 Network Services

7 Brookhaven Science Associates U.S. Department of Energy 7 n IP Address Allocation Tier 0 to Tier 1 (BNL - CERN) Requires routable IP Address space Direct BGP peering with CERN to / from BNL Limited route advertisements between T0 and T1 –For the LHC OPN Circuit BNL will use 192.12.15.0/24 Network Services

8 Brookhaven Science Associates U.S. Department of Energy 8 n IP Address Allocation Tier 1 to Tier X (BNL - Internet) Requires routable IP Address space Direct BGP peering with ES Net from BNL Full Internet route advertisements –ES Net CIDR IP Address Space –For the Internet circuit BNL will use 198.124.220.0/24 –3 additional class C networks available Network Services

9 Brookhaven Science Associates U.S. Department of Energy 9 n IP Address Allocation Tier 1 to Tier X (Continued) DNS Fully Qualified Domain Hostname Accessible ONLY from ES Net –No other path to get to BNL for LHC / Atlas Network Services

10 Brookhaven Science Associates U.S. Department of Energy 10 Network Services

11 Brookhaven Science Associates U.S. Department of Energy 11 n Future BNL LHC OPN Enhancements Dedicated Cisco Firewall Service Modules when available –Eliminate router ACL Functionality / Maintenance –Connection Logging –Each FWSM circuit will not impede the 10 Gb/Sec. –Stateful FWSM redundancy IDS / IPS when available Network Services

12 Brookhaven Science Associates U.S. Department of Energy 12 Network Services

13 Brookhaven Science Associates U.S. Department of Energy 13 Network Services n Mon browser-based IP service monitor n Internet-centric WAN based monitor application n Interrogates essential BNL network services

14 Brookhaven Science Associates U.S. Department of Energy 14

15 Brookhaven Science Associates U.S. Department of Energy 15 Network Services n MonaLisa Java based SNMP monitoring tool n External WAN based monitor n Tracks BNL EtherChannel OC-48 n Firewall Service Module n 10 Gb/Sec. Uplink to the BNL core

16 Brookhaven Science Associates U.S. Department of Energy 16 Network Services

17 Brookhaven Science Associates U.S. Department of Energy 17 Network Services

18 Brookhaven Science Associates U.S. Department of Energy 18 n Summary Tier 2 traffic dependant on Internet connectivity –Path to BNL via ES Net only –Initial router ACL based access to BNL –BNL provides DNS hostname for Internet resolution Network Services

19 Brookhaven Science Associates U.S. Department of Energy 19 Questions/Comments ??? Network Services

20 Brookhaven Science Associates U.S. Department of Energy 20 BNL Points of Contact n Scott Bradley, Manager of Network Services 631.344.5745, bradley@bnl.gov n John Bigrow, Senior Network Architect 631.344.2648, big@bnl.gov Network Services


Download ppt "Brookhaven Science Associates U.S. Department of Energy 1 Network Services BNL USATLAS Tier 1 / Tier 2 Meeting John Bigrow December 14, 2005."

Similar presentations


Ads by Google