![]() |
|
| F E A T U R E | |
Policy-Based Network Management November 29, 1999 By Joel Conover If you're like many network managers, you have an expensive PC or Unix workstation attached to your infrastructure that is meant to collect vital network-health statistics from your enterprise, but mostly collects dust. But that's about to change. Vendors are reinventing network management, transforming its role from passive network monitoring to active QoS (Quality of Service) and network service-level-agreement provisioning. If you think your mission-critical applications are not performing as well as they should be, this new generation of network-management tools promises to help you squeeze every last ounce of bandwidth from your overworked network. During the past year, a number of new features should have made their way onto your routed network. Have you been keeping up with all the new QoS capabilities on Cisco Systems routers? Cisco's IOS 11 (Internetwork Operating System version 11) introduced new ways to manage the traffic on LAN and WAN links. Likewise, Nortel Networks' BayRS 13.2 offers many new QoS-specific commands. But it's a nightmare to understand, implement and track the configuration modifi- cations required to affect specific traffic flows on your network, and in many cases it's simply impossible. Policy-based network management (PBNM) software is vendors' answer for managing QoS and security on distributed networks. We polled 13 vendors with an interest in policy-based networking and were pleasantly surprised to find that all had products in the works. Nine volunteered to bring their solutions to our Real-World Labs® at the University of Wisconsin-Madison for the first-ever roundup of policy-based network management products. We included both device vendors and independent management-system vendors that are trying to carve out a niche in the market. The device vendors included Allot Communications, Cisco, Extreme Networks, Lucent Technologies, Nortel and Spectrum Management (a wholly owned subsidiary of Cabletron Systems). Hewlett-Packard Co. is in the middle, with separate network-management and network-equipment divisions, and a product that is tailored to both halves. And two startups, IPHighway and Orchestream, are touting device-independent solutions. Until recently, most of the hype around PBNM had more bluster than luster. But vendors have been quick to turn pipe dreams into product. The nine contenders we tested implemented the features we felt were necessary for a 1.0 policy management product (see our features chart). We tested each vendor's work-in-progress--generally unreleased beta software--and made an assessment of each overall product strategy. In the process, we saw that various vendors define "policy networking" differently. That's why we chose not to grade these products. Instead, we give two Editor's Choice awards: one to Orchestream for having the most mature PBNM solution to date, and one to Cisco, for having the most comprehensive long-term strategy. Orchestream has been a trailblazer in policy-based management, and its 2.0 software, which was being prepared for shipment during our tests, reflects this. The software supports the widest range of devices and the most options of the products we tested. We based our decision regarding the best bet for long-term strategy on factors such as how vendors planned to integrate with legacy tools for network management, what standards-based protocols the vendors claimed to embrace (see "PBNM: A Matter of Protocol,"), their multivendor story and our best guess at the vendor's chance of delivering on the strategy. We chose Cisco, despite its rather checkered past in network management. Cisco's solution, based on the COPS (Common Open Policy Server) protocol, builds a foundation that will let the vendor integrate not only its own products, but also most other products on the network. Active network monitoring, network service-level-agreement management, and integration with multiple network operating systems for user-based policies are all part of its picture. Bringing all these components together is no easy task, but we think Cisco has the best chance to do it first.
Caveat Emptor Worse, this area still suffers from a lack of standards. There are two key issues that remain to be addressed: First, how the vendor will access and control the hardware, and second, how these systems glean information about an organization's users and resources. Device configuration can be accomplished only by employing a combination of CLI (command-level interface), SNMP, COPS and LDAP. We'd feel much better if we had a single standardized access transport and nomenclature.
| |
|
PAGE: 1 I 2 I 3 I 4 I 5 I 6 I 7 I 8 I 9 I 10 I 11 I 12 I 13 I 14 I NEXT PAGE |
|
Best of the Web
Data deduplication: Declawing the clones
Data deduplication is emerging as a critically important new arrow in the storage administrator's quiver to answer hard questions about the increasing problem in storage growth costs.
Compression, Encryption, Deduplication, and Replication: Strange Bedfellows
One of the great ironies of storage technology is the inverse relationship between efficiency and security: Adding performance or reducing storage requirements almost always results in reducing the confidentiality, integrity, or availability of a system.
WAN Optimization Whitelists and Blacklists
Optimization is a fantastic way of saving money and creating really happy customers at the same time, but it doesn't work flawlessly for all applications.
WAN Optimization as a Managed Service: It's Not About the Cost
This insight examines how organizations outsourcing their WAN optimization initiatives to a third-party go about achieving their goals for application performance, reducing operational costs, and streamlining enterprise infrastructure.





