Upcoming Events

Executive conference

Cloud Connect March 16-18

Comprehensive thought leadership for executives, IT professionals and developers. Topics include: the ROI, cost and economics of on-demand computing; Migration strategies to move from on-premise to cloud-based IT; Vertical cloud specialization, tailoring features and architectures to specific applications, industries, and customer ecosystems

More Events »

Subscribe to Newsletter

  • Keep up with all of the latest news and analysis on the fast-moving IT industry with Network Computing newsletters.
Sign Up



  F E A T U R E
Policy-Based Network Management

November 29, 1999


Policy Strategies
A good policy-management strategy comprises four phases. The first, and most difficult, phase is identifying the network traffic that needs to be classified, using traditional tools such as RMON, SNMP and packet-capture tools. This involves measuring the typical amount of bandwidth used, peak load times, typical traffic burst sizes and overall packet-size distribution. It is also critical to evaluate the latency that applications will tolerate. None of the products we tested offer this sort of functionality. The resourceful network administrator must hack his way through these issues and come up with a fair game plan.

In phase two, the network administrator must construct and deploy a set of policies to help shape or eliminate different types of traffic and carve up available bandwidth. Your WAN connections will require the most attention in this department. Many of the policy management solutions have scheduling features that let you create dynamic policies that shape traffic to fit your users' and customers' varying needs. The most dynamic solutions by far were products from Cisco Systems and Orchestream. Hewlett-Packard and IPHighway also were able to demonstrate multivendor policies based on a wide range of differentiators. Other vendors had pieces of the equation in place, but their solutions were far from complete.

Phase three involves deploying mechanisms to measure the policies' effects. Simple user feedback is a first-generation mechanism that is particularly effective when something goes wrong. But in the long term, the network devices must be able to report service level statistics back to the policy management tool. Most of the products we tested had little or no functionality in this area. One notable exception was Allot Communications, whose in-line hardware provided extensive feedback as to the effects of policies on your network. However, in most cases we used brute-force mechanisms, such as measuring end-to-end throughput using Chariot or "telneting" to the router and verifying access-control-list match counters, to determine whether a policy was being used and enforced.

Finally, once you've developed a feedback mechanism, the potential exists for the network to become self-tuning. No products had anything close to that today. Reporting based on device statistics will be the first step towards a self-tuning network. Spectrum Management was able to demonstrate a working reporting mechanism, but it lacked the necessary statistics to help us gauge whether the policies were actually working. In the long run, empowering your network with the power to adjust itself dynamically is a dangerous proposition: If a solution is too granular, it could lead to a feedback loop that could shut out your most mission-critical traffic. Fortunately, most vendors feel this level of sophistication is still several years away. First, the network must be able to inform the administrator of any type of statistics, a feature that was sorely lacking in the products we reviewed.

PAGE: 1 I 2 I 3 I 4 I 5 I 6 I 7 I 8 I 9 I 10 I 11 I 12 I 13 I 14 I FIRST PAGE
 

Best of the Web

Data deduplication: Declawing the clones

Data deduplication is emerging as a critically important new arrow in the storage administrator's quiver to answer hard questions about the increasing problem in storage growth costs.

Quick Read

Compression, Encryption, Deduplication, and Replication: Strange Bedfellows

One of the great ironies of storage technology is the inverse relationship between efficiency and security: Adding performance or reducing storage requirements almost always results in reducing the confidentiality, integrity, or availability of a system.

Quick Read

WAN Optimization Whitelists and Blacklists

Optimization is a fantastic way of saving money and creating really happy customers at the same time, but it doesn't work flawlessly for all applications.

Quick Read

WAN Optimization as a Managed Service: It's Not About the Cost

This insight examines how organizations outsourcing their WAN optimization initiatives to a third-party go about achieving their goals for application performance, reducing operational costs, and streamlining enterprise infrastructure.

Quick Read

  Sponsored Links

Premium Content

Next Generation Data Center, Delivered, November 17th
NWC


Salary

Video