![]() |
|
| F E A T U R E | |
|
|
|
November 29, 1999 |
||
|
|
PBNM: It's a Matter of Protocol Policy-based network management depends on many different protocols--some new, some old. Each PBNM vendor must decide how to implement communication between multiple policy servers, directories and the devices that are being managed. Although the vendors and their products share some common ground, there is little consensus as to which protocols will dominate the PBNM space in the long run. Here is a summary of those methods and protocols, as well as our assessment about which protocols will be most relevant in the future.
RSVP Additionally, the RSVP specification provides a mechanism for applications to signal their QoS (Quality of Service) requirements. Enterprise routers then allocate bandwidth, but only within policies dictated by the policy-management system. Such detailed application accounting is problematic. As flows move from the edge of the network toward the core, each router must track more of them exponentially. Therefore, it is neither practical nor cost-effective to provide per-flow accountability at every router. Microsoft Corp. has embraced a new form of RSVP, called RSVP+, in its forthcoming Windows 2000. Using RSVP+, an application can signal for network-bandwidth parameters and a DiffServ code point to be used for the application flow. RSVP+ lets network administrators provision application flows into classes of service, rather than doing per-flow accounting, making it more reasonable for core routers to implement tracking of the protocol.
COPS vs. SNMP COPS also benefits from active participation by the devices under management (as compared to SNMP's polling) and a sophisticated abstraction model. The protocol was designed to specify conditions, actions and roles that the device vendor can implement. Because COPS has a well-defined parameter set, implementing multivendor support is much easier. Regardless of which switch or router a policy server is speaking to, it should be able to send one set of common commands that provision QoS. COPS for dynamic QoS signaling is a standard. COPS-PR for provisioning--a superset of COPS--has not yet been ratified. For the next year, vendors will have to depend on proprietary solutions or prestandard COPS-PR implementations. Spectrum Management and other vendors have committed to using SNMP for configuring their network devices. However, Spectrum says it will implement a COPS-enabled PBNM server. And though both COPS and SNMP are capable (given the right SNMP MIB objects), we think COPS and COPS-PR will dominate the market in the long term.
Telnet Telnet output is also difficult to deal with. Vendors that implement policies on a Cisco router, for example, must parse the "show running-config" command to determine router version, access-control lists, interfaces and other parameters of interest to the PBNM platform. Because it is almost impossible to reverse-engineer existing policies without access to the original policy networking configuration, vendors can provide only "add-on" functionality. They cannot read existing access-control list entries to build a more complete PBNM picture. SNMP and COPS can alleviate these difficulties because they provide a more defined schema. Cisco has been dedicated to the COPS protocol, and has implemented it on some of its router platforms starting with IOS 12.0.5(T).
LDAP Version 3 Other vendors plan to use the LDAP directory as a distribution and/or interoperability mechanism. Most notably, Extreme Networks says it feels that if a common directory format can be realized, then sharing policies between multiple products (policy managers and other network management tools) would be simplified. But developing such a common directory format will take time. Lucent has taken the concept of the directory-enabled policy solution a step further. Rather than rely on COPS or SNMP for device configuration, it has embedded LDAP agents on its Cajun line of switches and plans to extend that agent to WAN equipment and voice switching hardware. Other vendors are quick to point out LDAP's flaws, such as slow writes to the directory. But Lucent argues that LDAP's scalability and fault tolerance make it the best protocol for directory-enabled policy-based networks. And then there is Microsoft, whose LDAP-enabled Active Directory has inspired much speculation. Most vendors say they plan to take advantage of the user and account information the Active Directory tree is expected to store. However, none could provide a sampling of an Active Directory-enabled PBNM application.
IEEE 802.1X
When a new user logs into a workstation, the workstation sends out a special multicast packet to the switch to identify the user, IP address, MAC (Media Access Control) address and other vital statistics. The switch forwards the packet to the policy manager, which can then make an intelligent decision about that user. The policy manager then replies to enable or deny access for that user on that port. 802.1X adds security to a network by preventing users from attempting denial-of-service attacks or other malicious actions while the network is trying to determine whether a DHCP lease should be given to the user.
|
|
|
|
PAGE: 1 I 2 I 3 I 4 I 5 I 6 I 7 I 8 I 9 I 10 I 11 I 12 I 13 I 14 I NEXT PAGE |
||
Best of the Web
Data deduplication: Declawing the clones
Data deduplication is emerging as a critically important new arrow in the storage administrator's quiver to answer hard questions about the increasing problem in storage growth costs.
Compression, Encryption, Deduplication, and Replication: Strange Bedfellows
One of the great ironies of storage technology is the inverse relationship between efficiency and security: Adding performance or reducing storage requirements almost always results in reducing the confidentiality, integrity, or availability of a system.
WAN Optimization Whitelists and Blacklists
Optimization is a fantastic way of saving money and creating really happy customers at the same time, but it doesn't work flawlessly for all applications.
WAN Optimization as a Managed Service: It's Not About the Cost
This insight examines how organizations outsourcing their WAN optimization initiatives to a third-party go about achieving their goals for application performance, reducing operational costs, and streamlining enterprise infrastructure.






