Saturday, April 9, 2011

Speedy VLANs


IT managers are always looking for ways to do their jobs more efficiently, while still providing the quality of service that their clients expect. Virtual LAN technology (VLAN) can help them on both fronts, by easing administrative chores and improving enterprise network performance. VLANs allow IT managers to group users and resources in any way they like, regardless of the physical LAN segment to which those resources are attached. An organization may want to group all users in the marketing department on the same
VLAN with the servers that host the applications and data they use most often, for example. The users who belong to that marketing group may be spread throughout a building, or even the country, but they can still belong to the same VLAN.
This type of flexibility in grouping users and resources stands in stark contrast to the days when IT managers were restricted to grouping resources solely by the port to which they were connected. Any changes to the network configuration required a visit to one or more wiring closets to physically move the user or resource from one port to another.With VLANs, such changes can be performed in software, from a central administrative console, thus greatly improving efficiency. At the same time, VLANs can be used to improve network
performance in a number of ways – by grouping users that communicate often with one another on the same VLAN, for example, or by creating a VLAN for use by “power users” that tend to consume a lot of network bandwidth.
VLANs are most suitable for mid- to large size companies, but even smaller companies with highly demanding users may benefit. Essentially, any organization with a network large enough that it needs to be segmented in some fashion can benefit.



When they first came on the scene in the mid 1990s, there were three basic ways to build a VLAN on any given switch or router. The port-based model called for assigning each router or switch port to a specific VLAN. Ports 1-5, for example, might be the engineering VLAN, while ports 6-10 belong to the marketing
VLAN. Some ports may be assigned to more than one VLAN, such as a port that connects a server used by multiple groups. Administrators could make changes to port and VLAN assignments from a central console, rather than physically pulling and rearranging wires. If a repeater was attached to any port, however, all the devices connected to that repeater must belong to the same VLAN. Another approach was to assign resources to VLANs based on their unique media access control (MAC) address. The switch or router supporting the VLAN maintained a list detailing which MAC addresses belong to which VLAN, and routed
traffic accordingly based on the source or destination MAC address. The drawbacks to this method included the time required to assign each MAC address to a given VLAN. Assigning the same MAC address to multiple VLANs could also wreak havoc with bridges and routers, making it difficult to share server resources among separate VLANs. Layer 3-based VLANs group resources according to the protocol and Layer 3 address they employ. In this fashion, all IP or IPX traffic can be assigned to its own VLAN, or perhaps all wireless LAN and Voice over IP (VoIP) traffic. The Layer 3 approach also enables all non-routable protocols to share a VLAN, thus limiting the effect of broadcasts on the rest of the network, improving performance for all users.

Labels: , ,

Monday, December 13, 2010

Management, and Control of IT Infrastructures


Networks are wonderful things. They connect servers, resources, applications, and
users together, all to drive your business forward. But as application complexity goes
up, as the need for more and more servers goes up, as more and more virtual servers
are deployed, and as the need for more and more bandwidth increases, networking
complexity increases as well.
There are routers and switches, NICs and more NICs, and cables and cables, and more
cables. Oh, the cables! Hundreds, even thousands of wires are running all over your
data center. And if you want to change a server or reconfigure an application, the time
and effort involved in juggling cables is almost ridiculous.
Cables and networks should help your business flow. Instead, as your business grows,
they become complex and challenging bottlenecks to productivity.
Fortunately, all that is about to change.
 
The Network Nightmare
The modern data center is a networked data center. Virtual servers live in physical
servers and blades. Blades live in racks. And all those virtual servers, all those physical
servers and blades, and all those racks need to talk to each other:

NICs, Switches, and Cables
When data leaves a server, it does so through a network interface card 
(NIC), then travels across a cable to a switch, which acts like a 
switchboard, then travels to and across other switches, and eventually 
travels through another NIC back into another server. Each server uses 
one or more NICs. As more servers are added, more NICs are added. As 
more NICs are added, more switches are needed. Connecting them all are 
cables. 
Virtualization Magnifies the Problem 
Virtualization reduced the number of physical boxes required for certain 
applications, but it didn’t reduce the network load. In fact, virtual servers 
have substantially increased the network load. It’s now almost absurdly 
easy to add a new server, but terribly difficult to add the network and cable 
infrastructure to support the new server. 
LANs vs. SANs 
Data center data and storage traffic  both travel across cables. Ethernet 
(and most IP-based applications) can  survive having some packets lost 
and then re-sent during  operation. But storage networking must be 
lossless, and must maintain throughput.

These separate levels of required performance have given rise to two completely divergent 
network infrastructures, one based mostly on Ethernet, and the other based mostly 
on Fiber Channel.  
The result is once again more cables, more connections, less flexibility, 
and increased complexity. 
Cable Aggregation  
Racks often contain many more servers today than they did even a few 
years ago. Virtualization has made  that possible. Unfortunately, the 
virtualization trend didn’t reduce the need for more wires. Instead it made 
it worse. 
Wiring and provisioning racks require many complex connections be made 
at top-of-rack, and then all of those connections are often bundled 
together at another set of switches at end-of-row. Always, the complexity 
increases.

It’s reached the point where the task of adding a completely new server application can
take far less time than simply wiring up the connections.  Gartner's Cameron Haight
reports that setting up a virtual machine is relatively fast (a matter of hours), but
provisioning all the networking changes required to support that  virtual machine can
take as long as six weeks.
Networking, a technology designed to help businesses grow, is instead getting in the
way of growth. IT organizations are change-adverse because a simple change, like
adding one new application, could have a complex ripple effect throughout the entire
data center.
The number of connections, switches, and cables keeps going up.  IT staff is spending
more and more time on maintenance and wires. The technical wizards who should be
driving innovation across the organization are, instead, being driven to distraction simply
attempting to keep up.
The Network as a Service 
The solution is turning the network into  a service, creating a virtualized network
infrastructure. What makes all this work  is a network topology known as a switched
fabric. Rather than using a lot of point-to-point connections, a fabric-based network
allows many nodes to connect to each other like threads in a tapestry, often dynamically
changing to compensate for changing load requirements.
Once you’re able to dynamically reallocate your network resources, you’re able to begin
serving network resources on-demand, both when and where they’re needed.

Here’s how:
Virtualize Connections 
Typically, one NIC supports one connection. Each new connection 
requires more NICs. It’s now possible, however, to virtualize your network 
connections, so each NIC can support multiple connections. You can 
dynamically add more connections and change the purpose of those 
connections on-the-fly.
Wire Once 
Once you virtualize your connections, you can build out your physical 
wiring infrastructure once. When applications and server requirements 
change, you can make changes in your virtualized connections through 
management software, eliminating the need to pull wires for each change 
in application or server requirements.
Repurpose Without Tears 
Once you embrace the concept of wiring once, you can repurpose 
network, storage, and compute resources on the fly. Your IT department is 
no longer subject to waiting days or weeks for a re-provisioned network. 
Instead, the network can be modified  to meet line-of-business needs 
quickly, and without drastic and complex changes to the physical data 
center facilities.
Increase Performance 
Complexity breeds bottlenecks. The more connections, wires, and 
switches you have, the more overhead you have running across your 
network, and the slower everything gets. 
Once you can virtualize your network infrastructure, you can cut 90% or 
more of your physical wiring, which will substantially drop the network 
housekeeping overhead. The result is increased performance, often by as 
much as 50%.

It’s astonishing how much IT time and effort is bottled up in cabling bottlenecks. By
virtualizing the network and turning your network into a service, most of that time can be
freed up and put to far better use.

Organizational Benefits 
When you transition to the network as a service, you’ll be taking complexity out of your
network. This will make it easier for you to manage not just basic networking elements,
but your entire IT infrastructure.
You’ll be able to turn your IT operation into an agile, responsive, innovative contributor
to your organization’s mission. You’ll also able to do more, even while spending less on
expensive networking gear. You can allocate what spending you do to support line-ofbusiness
objectives rather than for basic, repetitive, and inefficient operations.
You’ll be able to maximize your data center space, reduce your overall power costs, and
even free up strategic IT personnel for more bottom-line oriented tasks.
Future Innovations 
Today, network fabrics still have one substantial limitation: LAN vs. SAN. Local Area
Networks are usually Ethernet-based, while Storage Area Networks run on Fiber
Channel. Even though virtualized networks remove most of the cabling overhead,
there’s still the need for these two types of cables.
That’s changing. Standards bodies are working on encapsulating Fiber Channel frames
into Ethernet frames, so that all of the SAN traffic can run across Ethernet. This
technology is called Fiber Channel over Ethernet, or FCoE.
But encapsulating frames won’t solve the bigger issue, the need for a lossless Ethernet
mechanism, especially across a congested data center network. The Data Center
Bridging (DCB) Task Group of the IEEE 802.1 Working Group is working on adding
performance capabilities to Ethernet called Converged, Enhanced Ethernet.
Some venders are currently offering solutions they claim will be compliant with these
future standards. If you decide to implement these solutions now, make sure your
performance agreements include upgrades for  pre-standard revisions and eventually,
final standards compliance.
In the very near future, you’ll be able to  transition your network to a policy-based
approach for managing your infrastructure. You’ll be able to control it as a resource,
reallocating workloads dynamically depending on your needs at the time, whether
across the data center or even between data centers.






Labels: , , ,

Wednesday, September 22, 2010

What is Power over Ethernet (PoE)?


Power over Ethernet or PoE as it is more commonly known; is progressively establishing its name as ‘The universal power socket’. The term didn’t quite actually moved me until a couple of weeks back, when I bought a wireless broadband connection, for which the operating company handed me over an outdoor CPE (CPEo) and dispatched a field engineering team to install it.
Apparently, the roof mounted device is fed only by one single Ethernet cable but no power cord. Reason? Yes ! the device features an active PoE solution. And today not only a broadband CPE, but any device connected to the network through an Ethernet cable can eliminate the need of a separate AC/DC power adapter, and the cord feeding the power.
The concept might not be appealing for a single terminal network like mine, but when the numbers increase the payback is impressive.
So lets get an insight of the technology before conferring over its advantages and shortcoming. But before even that, lets take a look at a any conventional Ethernet based network . . . Hmm . . . How about a wireless network in a medium sized office.
PoE 001 What is Power over Ethernet (PoE)?
The figure shows how several Wi-Fi access points are set up across an office environment to provide wireless LAN and internet facility. In such a scenario, positioning these many adapters i.e. one for each Access Point would never continue to seem feasible once their count increases from four to many. Moreover, AC/DC adapters hold wide disrepute as power dissipaters. Some may even waste up to 40% of the power for nothing.
A scheme to tackle the power loss problem may possibly be to install a centralized DC supply unit as shown in the figure below:
PoE 002 What is Power over Ethernet (PoE)?
The solution is still not good to cut the expense out. The amount saved by reducing the number of adapters is worn in paying for the electrical wiring and the power therefore being dissipated in the long run of wires.
PoE steps in here; a technology that eliminates a separate power cable running all along the network cable. PoE eradicates the need of dedicated power cable by effectively delivering the power over the same Ethernet cable used for carrying the data. A PoE arrangement has two basic modules. A Power Sourcing Equipment (PSE) and Power-Data Splitter (PDS). Leaving the technical details spaced out, a PSE ramps up the DC power onto the Ethernet cable. A PDS, as predictable, separates the power from data and feeds the two to appropriate terminals of the device. Refer to figure below:
PoE 003 What is Power over Ethernet (PoE)?
Overall, a PoE enabled network may typically have a single PSE and many PDSs. The number of PSEs in a network can be greater than 1, but still the ratio remains quite biased towards the PDSs side. However the minimum number of PSD and PDS is 1 each for the most simplest network even.
PoE 004 What is Power over Ethernet (PoE)?
Although separate PSDs and PDSs are available for converting any ordinary Ethernet based network into a PoE network, devices are now being designed for a PoE network with built-in PDSs; known as Powered Device (PD). Some of the most common PDs available in the market are: Wi-Fi Access Points, Wi-Fi Routers, Ethernet switches, IP Phones, IP cameras and Electronic Notice Boards to name a few.
In the end, it must also be referred that power-line network is another such sister technology that can eliminate the need of separate power cable. But the difference is that PoE uses data line to carry data and power, whereas power-line network uses the installed power lines to carry the power and data. Moreover, PoE transmits DC power over data line, but power-line transmits data over AC power lines.

Labels: ,

Thursday, August 19, 2010

Selecting new IT leaders

One of the great privileges and responsibilities of leadership is identifying and training the next generation of managers and leaders. Somewhere in between crisis management, contract negotiations, internal politics, status monitoring and your myriad other tasks, you should spend a few moments considering the future leadership of your organization. Figuring out who has the potential to become a great leader or middle manager of IT is difficult. Given that leadership is one of those things that most of us can identify when it's put before us but find difficult to describe, it often seems impossible to predict an individual's prospects.

There are traits that can be predictors of success. But before we dive into what to look for, let's put to rest a few of the commonly used criteria that haven't yielded stellar results.

Education. Lots of great business leaders have put in time in MBA programs, but even a degree from Harvard or the Kellogg School (my alma mater) doesn't guarantee the right stuff. While important, understanding the mechanics and subtleties of business doesn't necessarily translate into leadership success.

Tech smarts. As believers in meritocracy, we're drawn to the idea that the person who best understands what's going on technically is best qualified to be in charge. Unfortunately, the skills needed in a leadership role are different from technical savvy -- and often don't reside in one person.

Bossiness. The natural desire to be in charge doesn't necessarily predict whether someone will be a good leader in a technical environment. The hierarchical top-down approach tends to be fragile when it comes to creative work. Those with the built-in desire to command frequently run smack into the brick wall of technical staff intelligence and intransigence.

So, which traits are better predictors of who will make great leaders?

Emotional flexibility. We talk a lot about being a good leader, but what about becoming one?

Great leaders start out somewhere else and have to move into leadership roles. Becoming a leader poses transitional challenges that can be met only with emotional flexibility. One of the great challenges for a new manager is to transform his view of himself, to change how he measures himself and his success. Early life and career work is judged by personal productivity. In school, we're judged by the quality and quantity of our papers, tests and quizzes. Young workers are judged by the quality, quantity and speed of task completion. Our self-images become tied to our personal productivity.

Moving into management requires a fundamental shift in how we view ourselves, a shift in the emotions about self and work. Leaders are judged not by their personal productivity but by their effect on the productivity, morale and effectiveness of others. Managers must be able to derive their personal satisfaction from helping others be productive rather than being productive themselves. This is a difficult transformation that's poorly understood and rarely discussed.

The ability to adopt a new self-image is critical to the transition into a successful leadership role.

Comfort with ambiguity. Beyond mastering their emotions, leaders must be able to cope with the chaos and confusion of reality. The world is a complex place filled with facts, provisional facts, lies, opinions and emotions. A large part of the leader's role is to help interpret the turmoil and bring order, sense and meaning to daily work. Successful leaders must transform ambiguity into clarity and create compelling narratives out of complexity.

They also bring a high tolerance for the continuing existence of confusion. They're able to hold contradictory ideas in their heads simultaneously without experiencing undue stress. Strong leaders aren't impervious to new facts and information but are comfortable revising their interpretations to meet changing times.

Ability to communicate. The ability to cope with ambiguity means nothing without the ability to communicate. If leaders and managers deliver value through their effect on others, communication is their primary tool. Whether leaders communicate verbally, in writing or through their actions, their ability to connect with those they lead is of prime importance.

Considering these "softer" skills can help you to ensure a successful future for your organization.

Labels: ,

Few Important things you should know about privacy protection and IT

These days, IT bears a tremendous responsibility for safeguarding corporate data and protecting personal privacy information. This overview shows just how entrenched privacy concerns have become in the regular operations of the IT organization.

Personal privacy has become a major public concern. Highly visible data breaches, identity theft, and frauds such as phishing scams have created a huge corporate and consumer burden and threaten trust in Internet and e-commerce services.



Studies have shown that almost half of U.S. residents have "little or no confidence" that adequate steps have been taken to secure their personal data. Compounding this lack of confidence is the increasing sophistication of online crime schemes. It's hard to tell who is legitimate, and a growing number of users are becoming victims of the Internet. Let's look at some privacy concerns and how they affect IT. 




#1: Reporting compromised data: It's the law 

Several states require that state entities, persons, or businesses disclose to a resident when his or her private information is reasonably believed to have been acquired by someone without authorization. An organization must publicly disclose when personal information in its possession appears to have been compromised. In 2003, California passed a law that requires organizations to notify residents if the organization experienced a data security breach that caused risk to personal information. Currently, 28 states have passed similar laws, and security breach notification bills are pending in more than 15 other states. Notification of a breach is costly, as there is usually a per-person fine.

#2: Customer loyalty is directly dependent on privacy 

Consumers rely on the Internet for shopping, banking, government, healthcare, and other services, while trusting that their personal and financial information is protected and inaccessible to unauthorized use. When this trust is broken, customer loyalty can evaporate--overnight. The costs of identity theft and other fraud are too great to risk doing business with organizations known for mistrust of private information.

Between 2001and 2004, more than 196 privacy-related legal actions were raised against 255 corporate defendants, including financial services, health care, pharmaceutical, information services, e-commerce, manufacturing, media, and retail. More than 33 class action suits have also been filed. Here are some interesting figures on how Web consumers view privacy:
86% are concerned about privacy of personal data.
45% never provide real names to sites.
5% use software to hide computer identities.
86% favor "opt-in" that requires permission before using data.
94% want privacy violators to be punished.

#3: IT pros bear most of the burden for privacy 

Here are a few things to consider when developing systems:
Know the types of data you are working with that include PII (personally identifiable information.) This includes the user's name and e-mail address, health care, and credit card or social security numbers. Don't collect more data than necessary.
Know how to implement mechanisms for notifying users that their personal data may be collected and offer them ways to opt out or consent to the collection of their data. A record of opt-out acknowledgement may also be required.
Determine where the system vulnerabilities lie: in the application, database, wireless network, Web access, or other interfaces.
Understand the steps to secure PII from misuse or unauthorized access, including access controls, encryption, physical security, and auditing. Encryption is probably the best defense. When an encrypted laptop is stolen, at least the data is protected.


#4: A data classification policy is essential 

Today, data managers are expected to become steward of their organization's information. They're asked to view the data under their care as a valuable asset and manage it based on what or who it represents. An organization should have a policy definition of classified, confidential, and public information and clearly define data that's the most valuable and/or secret.

A key component of this policy is a data security plan that addresses the foreseeable risks to the integrity of the information maintained in an organization's systems. Control of and access to PII data is the subject of recent privacy regulations in the United States. The European Union also has specific requirements to protect its residents.

#5: Identifying critical systems helps risk analysis 

Once you have a clear picture of how the data is classified and have identified potential data risks, target the systems that manage the data for a more detailed analysis of risks to data integrity.

A benefit of this exercise is to have better risk-ranking of major IT processes and systems, allowing you to focus on higher potential privacy risk areas. Auditing controls that are expected by law for critical systems that contain "regulated" data is a best practice.


#6: Organizations carry the burden of proof 

Did you get hacked? Was it successful? What data was affected? How many customers? What states? Even unsuccessful attacks may have to be disclosed, unless an organization can prove that no personal information was made available to or accessed by an unauthorized party. As a result, an organization's intrusion detection and prevention systems must be effective and create reliable records of their effectiveness.

If a company concludes that a security incident didn't result in unauthorized access to personal data, but a customer suffers identity theft as a result of the attack, the organization will probably be found liable. Disclosing and reporting a breach is almost sure to damage the organization with financial consequences. Notification alone costs about $100 per customer per incident. So if 10,000 customers are affected, the incident will cost at least $1,000,000.


#7: CPOs oversee privacy issues 

The primary role of the chief privacy officer (CPO) is to establish privacy policies for both customers and employees and to review and rule on related issues. A CPO usually chairs a privacy committee in larger organizations to provide guidance on managing incidents, privacy policies, security awareness, and many other privacy issues. The buck stops here when there's a decision to be made on technology or business that can affect compliance.

The CPO is becoming very busy these days, fielding questions on legal issues that usually have an impact on IT. IT is often responsible for finding solutions to privacy issues, such as intelligent encryption.


#8: Privacy incident management can prevent future risks 

Who gets notified and when? Privacy incident management is not unlike other incident response functions, except when it comes to notification. Notification requirements are usually spelled out in the law, but notification can still be an arduous process. The CPO will likely oversee the incident response team that determines the cause and severity of the incident and issues report findings. An important outcome of investigating an incident and finding the root cause is remedying systems against similar risks in the future.


#9: Boundaries are blurring 

Who is responsible when data is shared between organizations in the course of business? What if a breach is caused by one of your organization's outsourcers? If your employees' 401K data is on an insecure laptop owned by the 401K provider and the laptop is stolen, who bears the burden?

IT outsourcing is popular, but whose responsibility is it to protect you when an employee or a vendor happens to leave a USB stick on the counter at Starbucks when paying for a latte? If this device contains insecure private information, the mishap could constitute a data breach.

It's most critical to have privacy and security language in all IT contracts with third parties. Incidents can't always be prevented, but you can buy some indemnity if you draft a proper contract. Data security in contracts is becoming more common; use your legal team if necessary.

#10: White collar crime threatens privacy

A huge market exists for selling personal information, especially credit card numbers. The average rate for an ID is about $50. The infrastructure for online crime is more sophisticated than you can imagine. Marc Gaffan, a marketer at RSA Security Inc., offered this description of the problem in the article "The Net's not-so-secret economy of crime": "There's an organized crime industry out there with defined roles and specialties. There are communications, rules of engagement, and even ethics. It's a whole value chain of facilitating fraud, and only the last steps are actually dedicated to translating activity into money."

A Web site called TalkCash.net was a fraud marketplace for its members. To become a member, an applicant was asked to submit a few credit card numbers to show that he or she was really a "crook." This site is no longer open for business.



Labels: , ,