Bezpieczne i wysoce skalowalne Data Center.pdf

(1921 KB) Pobierz
<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
Bezpieczne i wysoce skalowalne
Data Center
Piotr Szolkowski
Pre-sales Support Engineer
pszolkowski@extremenetworks.com
© 2011 Extreme Networks, Inc. All rights reserved.
840749551.042.png
 
840749551.058.png 840749551.065.png 840749551.001.png 840749551.002.png 840749551.003.png 840749551.004.png
ExtremeXOS: Modular Operating System
Modularity = Business Continuity
Dynamic software uploads
Self-healing process restart
Restart capable processes:
Telnet/SSH/SCP (11.0)
SNMP (11.0)
TFTP (11.0)
HTTPD (11.3)
XML/SOAP (12.0)
CNA Agent (11.2)
Network Login (11.3)
LLDP (11.4)
EAPS (11.0)
VRRP (11.0)
OSPF (Graceful Restart extensions, 11.3)
BGP (Graceful Restart extensions, 11.4)
IS-IS (Graceful Restart extensions, 12.1)
2
End-to-end, from desktop to data
center core, means consistent,
© 2011 Extreme Networks, Inc. All rights reserved.
2
840749551.005.png
 
840749551.006.png 840749551.007.png 840749551.008.png 840749551.009.png 840749551.010.png 840749551.011.png
CLEAR-Flow
CLEAR-Flow is a statistical measurement capability in
ExtremeXOS® that:
Collects data from ACL matches (in the form of counters)
Uses a switch-based language to evaluate these counters
Can modify switch behavior based on these evaluations
There are five CLEAR-Flow expressions:
Count Rules: Measure the count of a variable
Delta Rules: Measure the change in the count of a variable in a
specific period of time
Ratio Rules: Measure the ratio between two variables
Delta-Ratio Rules : Measure the change in the ratio between two
variables
Rule-True-Count Rules: Measures the number of times a CLEAR-Flow
rule has been true (fired)
3
© 2011 Extreme Networks, Inc. All rights reserved.
3
840749551.012.png
 
840749551.013.png 840749551.014.png 840749551.015.png 840749551.016.png 840749551.017.png
 
840749551.018.png
CLEAR-Flow
Analyze
& Measure
1
Attack Launched
2
3
Take Action
Permit
CLEAR-Flow
Security
Rules Engine
Deny
1
QoS Profile
Mirror
2
SNMP Trap
3
SYSLOG
Dynamic CLI
Command
BlackDiamond®
8800 c-series Modules
C ontinuou s L earning E xamination A ction & R eporting
4
© 2011 Extreme Networks, Inc. All rights reserved.
4
840749551.019.png
 
840749551.020.png 840749551.021.png 840749551.022.png 840749551.023.png 840749551.024.png
 
840749551.025.png 840749551.026.png
 
840749551.027.png
 
840749551.028.png
 
840749551.029.png 840749551.030.png 840749551.031.png 840749551.032.png 840749551.033.png 840749551.034.png 840749551.035.png 840749551.036.png 840749551.037.png 840749551.038.png 840749551.039.png 840749551.040.png 840749551.041.png
 
840749551.043.png
 
840749551.044.png 840749551.045.png
 
840749551.046.png
 
840749551.047.png
 
840749551.048.png 840749551.049.png
Direct Attach™
Eliminate the vSwitch “Virtually” Reducing Network Tiers
Data Center
Core
Minimal traffic
provisioning (if any) is
done at the vSwitch.
vSwitch
VM2
VM1
Today’s Inter-VM Switching
5
© 2011 Extreme Networks, Inc. All rights reserved.
840749551.050.png
 
840749551.051.png 840749551.052.png 840749551.053.png 840749551.054.png 840749551.055.png 840749551.056.png 840749551.057.png 840749551.059.png 840749551.060.png 840749551.061.png 840749551.062.png
 
840749551.063.png 840749551.064.png
Zgłoś jeśli naruszono regulamin