Posts

Showing posts with the label Network Design

Why study for a Cloud networking certification?

So, why study for a Cloud Networking certification? So, that was a wake-up call! Just taken my first attempt at the AWS Networking Specialty exam and it was an experience! I've been saying to my team for some time that in order to really understand the networking within cloud environments, and to get the optimum experience for customers in those environments, you need to really appreciate how applications are deployed, and the elements in AWS and Azure you need to make those applications reliable and scalable, And if ever I needed confirmation of that, I got it this morning.  The exam has 60 questions for which you're given 3 hours to complete them.  You shouldn't need that, but my goodness, it's tough and just illustrates how the paradigm shift to Cloud highlights what we have known for years - DC (and thus Cloud) networking is all about enabling application flows. If you're planning on looking into this (and as a networker you should - whether you believe ...

Five Design Principles for the Network Architect - The Sixth Principle!

(#7 of 7) Throughout this series , I have tried to set out a set of simple design principles I believe all network architects should adhere to in order to ensure the success of their projects.  These have covered properties of the network and their operation which, given the appropriate level of attention, can make the difference between a successful and useful foundation for a customer's IT and one that fails to provide the right kind of underpinning for the services and systems that the customer needs to be successful. An availabl e network ensures that clients can access the applications and services they need to when they need to; a scalable network can grow or shrink to meet demands placed on it by the customer; a secure network ensures that a customer can support their customers with integrity and privacy; a supportable network infrastructure is one which is measurable and transparent, and has the right tooling around it to ease operations; a simple network is ...

Five Design Principles for the Network Architect - Simplicity

(#6 of 7) So, across the articles in  this series , we have covered most of the basic tenets of network design to ensure we have an available, supportable, secure network to implement for our customer.  Inevitably though, in any network there is a need to implement a wide range of capabilities - in order to interoperate between different vendors' kit perhaps; or maybe with a specific network operator for WAN connectivity; and of course we are highly unlikely to have an entirely green field operation, so the chances are we need to interact with an existing environment. Simplicity vs Complexity All of these bring a degree of complexity to  the network design, but also to the implementation and ongoing support of the network.  But when we say "complexity", what do we really mean?  Well, better minds than mine have considered this at length, and while there is no absolute consensus, a widely accepted definition might be where the network has a large number o...

5 Ways Network Engineers Can Learn From Leonardo

I’ve just had a week away from the hustle and bustle of work, spending seven days with the family in the peace and tranquility of Meia Praia near Lagos in Portugal.  (Incidentally, I thoroughly recommend visiting the area if you’ve never been) While we were away, I resolved to plough through Walter Isaacson’s biography of Leonardo da Vinci , having thoroughly enjoyed the insights from his book about Steve Jobs. After starting it on the flight out, I turned the last page on the homeward bound Ryanair 737-800 about an hour out of Faro and felt compelled to write down my takeaways from it. First things first, I’d strongly recommend reading the book. Isaacson doesn’t take a strictly linear path through Leonardo’s life but instead covers a series of main themes that gradually build to give a picture of a complex intellect. He can be a little repetitive at times as the threads cross over but they do all come together towards the end of his life to show how all the elements of his perso...

Five Design Principles for the Network Architect - Supportability

(#5 of 7) As this series has developed, we have addressed a number of areas that affect the detail of the technical solution to be deployed. Supportability is more concerned with the legacy that the deployment project leaves behind. As we have already seen, the purpose of the network is to provide a level of connectivity availability for an application or service to a consumer of that service. The concept of supportability complements that, ensuring that appropriate monitoring of the environment is in place; that the correct tooling is available to maintain and change the infrastructure if required; and the processes are available to ensure that service levels are maintained. This is the area that dovetails with the end customer's operational model and so is driven by their 'day 2' requirements. Let's address these areas one by one. Visibility When we discussed availability, I made mention of the fact that we can't have a 'one size fits all' ap...

Five Design Principles for the Network Architect - Security

(#4 of 7) To continue the  series , this post talks at a high level about principles you should consider when you're looking at the security aspects of your network design.  Be aware I am not a cyber security guy.  But I do know what security elements you should consider when you build a network design, so this is what I'm discussing herein.  If you want more on cyber security, you could find a lot worse starting point than fellow #CiscoChampion Zoë Rose's blog  https://www.zoërose.com  or follow her on Twitter  @5683Monkey . [Disclosure: Zoë proof read this post for me to help keep me honest - thank you!] As every security course ever taught points out, there are three fundamental goals of any security design: Confidentiality - ensuring that data is not accessible by parties from whom it should be hidden.  Most network security mechanisms are concerned with this in some way - including access control; network segmentation; policy ...

Five Design Principles for the Network Architect Series Index

●  Introduction  ●  ●  Availability  ●  Scalability  ● Security ● ●  Supportability ● Simplicity ●  ● Pragmatism ●    

Five Design Principles for the Network Architect - Scalability

(#3 of 7) Continuing our series on design principles , the next area of consideration is scalability.  Every design guide you ever read extols the virtues of making networks scalable, but in reality what does this mean? The usual definition of the term relates to ensuring a network has sufficient capacity for the current usage patterns and for projected future growth.  This works at two levels - at a micro level, this is ensuring that we provide sufficient ports of the appropriate speed, that we use network devices with sufficient aggregate throughput, that the circuits we specify have sufficient bandwidth for the use cases identified during the collection of user requirements. We monitor those elements and carry out trend analysis to ensure the environment stays within the bounds within which we built the network, and we can add more capacity simply and with minimal disruption when it is required. At a macro level, we ensure our overall network archit...

Five Design Principles for the Network Architect - Availability

(#2 of 7) In the first post in this series , I shared a summary of my fundamental design principles which I try to apply to every network design I am involved in.  The follow-ups to that summary post will discuss these at greater length - this one addresses Network Availability. The network exists to provide the transport for endpoints to be able to consume services in a "remote" location.    Whether the endpoints are application servers in racks in a DC trying to consume database entries, wireless clients accessing an application in the data centre, sensors collecting data and dropping that data into storage, and regardless of location of the services themselves - public cloud, private cloud, co-lo DC - the fundamental measure of success of the network is availability of the service to the endpoint and thus the user. Clearly then availability can't be considered a simple measure of the network as a whole - it takes a number of capabilities and properties ...

Five Design Principles for the Network Architect - Intro

(#1 of 7) Whilst studying for the CCDE , you stumble across new design methodologies all the time, each of which set out some fundamental principles by which you should look to adhere when building your network solutions - the one that springs to mind is Chapter 1 of Russ White's book "Optimal Routing Design" .   The idea is that you bear those simple ideas in mind as you go through the design process, checking back in with them to make sure that the design you produce will lead to a network which is robust and manageable, but still meets customer requirements. Through an iterative process of my own, I have arrived at five principles I try and embody in my work, and over coming blog posts, I'll go into more detail on how I look to apply each of them.   They are: Availability … is the fundamental desirable property of a network, its raison d'être.   The network exists as the transport to deliver apps to users, make data available to apps, and coll...