Top Banner
Campus Network Design for NREN Engineers Dale Smith Network Startup Resource Center [email protected] This document is a result of work by the Network Startup Resource Center (NSRC at http://www.nsrc.org ). This document may be freely copied, modified, and otherwise re-used on the condition that any re-use acknowledge the NSRC as the original source.
48

Campus Network Design for NREN Engineers

Mar 17, 2022

Download

Documents

dariahiddleston
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Campus Network Design for NREN Engineers

Campus Network Design for NREN Engineers

Dale Smith Network Startup Resource Center

[email protected] This document is a result of work by the Network Startup Resource Center (NSRC at http://www.nsrc.org). This document may be

freely copied, modified, and otherwise re-used on the condition that any re-use acknowledge the NSRC as the original source.

Page 2: Campus Network Design for NREN Engineers

Research and Education Networks •  Some Terminology

– Research and Education = R&E – Research and Education Networks = REN – National REN = NREN

•  Globally, the REN connectivity is very complex and very difficult to understand

Page 3: Campus Network Design for NREN Engineers

Research and Education Networking

•  A layered model – Global Connectivity – Regional RENs – National Research and Education Networks – All users are connected at the campus

network level •  No scientist is connected directly to a National

Network. They are all connected to campus or enterprise networks

Page 4: Campus Network Design for NREN Engineers

Global REN Connections

•  Connect Regional or National networks together

•  Tend to be longer, more expensive circuits •  Not always well coordinated •  Routing policies often inconsistent •  Always are peering networks

Page 5: Campus Network Design for NREN Engineers
Page 6: Campus Network Design for NREN Engineers
Page 7: Campus Network Design for NREN Engineers
Page 8: Campus Network Design for NREN Engineers

Regional REN Connections

•  Connects RENs of individual countries within a geographic region – EUMedConnect (North Africa/Middle East) – TEIN4 (Asia) – CAREN (Central Asia) – GEANT (Europe) – RedCLARA (South & Central America) – AfricaConnect/Ubuntunet (West & Central Africa) – And others

Page 9: Campus Network Design for NREN Engineers

RedCLARA March 2011

Porto Alegre

ALICE2  

CLARA  

RNP  

AmLight  

Page 10: Campus Network Design for NREN Engineers
Page 11: Campus Network Design for NREN Engineers
Page 12: Campus Network Design for NREN Engineers

Campus versus NREN •  As an NREN engineer, why do you care

about campus networks? •  How about when they call with

– The Internet is slow – You aren’t giving me the bandwidth you are

selling me •  Often these problems are campus

problems, not a problem with the NREN •  What is your role to help campuses?

Page 13: Campus Network Design for NREN Engineers

Campus Network Challenges •  Many are not structured properly and can’t

effectively utilize high bandwidth connections

•  Many make heavy use of NAT and firewalls that limit performance

•  Many are built with unmanaged network equipment that provide no ability for monitoring or tuning the network

•  Many don’t run any network monitoring

Page 14: Campus Network Design for NREN Engineers

Campus Network Rules •  Minimize number of network devices in any path •  Use standard solutions for common situations •  Build Separate Core and Edge Networks •  Provide services near the core •  Separate border routers from core •  Provide opportunities to firewall and shape

network traffic

Page 15: Campus Network Design for NREN Engineers

Core versus Edge •  Core network is the “core” of your network

– Needs to have reliable power and air conditioning

– May have multiple cores – Always route in the core

•  Edge is toward the edges of your network – Provide service inside of individual buildings

to individual computers – Always switch at the edge

Page 16: Campus Network Design for NREN Engineers

Minimize Number of Network Devices in the Path

•  Build star networks

•  Not daisy chained networks

Page 17: Campus Network Design for NREN Engineers

Edge Networks (Layer 2 LANs) •  Provides Service to end users •  Each of these networks will be an IP

subnet •  Plan for no more than 250 Computers at

maximum •  Should be one of these for every

reasonable sized building •  This network should only be switched •  Always buy switches that are managed –

no unmanaged switches!

Page 18: Campus Network Design for NREN Engineers

Edge Networks

•  Make every network look like this:

Fiber link to core router

Page 19: Campus Network Design for NREN Engineers

Edge Networks Continued •  Build Edge network incrementally as you

have demand and money •  Start Small:

Fiber link to core router

Page 20: Campus Network Design for NREN Engineers

Edge Networks Continued •  Then as you need to add machines to the

network, add a switch to get this: Fiber link to core router

Page 21: Campus Network Design for NREN Engineers

Edge Networks Continued •  And keep adding switches to get to the

final configuration Fiber link to core router

Page 22: Campus Network Design for NREN Engineers

Edge Networks Continued •  And keep adding switches to get to the

final configuration Fiber link to core router

Page 23: Campus Network Design for NREN Engineers

Edge Networks Continued •  Resist the urge to save money by breaking this

model and daisy chaining networks or buildings together

•  Try hard not to do this: Fiber link to core router

Link to adjacent building

Link to another building

Page 24: Campus Network Design for NREN Engineers

Edge Networks Continued •  There are cases where you can serve multiple

small buildings with one subnet. •  Do it carefully.

Cat5e or fiber

Fiber link to core router

Cat5e or fiber

Page 25: Campus Network Design for NREN Engineers

Core Network

Page 26: Campus Network Design for NREN Engineers

Routing versus Switching Layer 2 versus Layer 3

•  Routers provide more isolation between devices (they stop broadcasts)

•  Routing is more complicated, but also more sophisticated and can make more efficient use of the network, particularly if there are redundancy elements such as loops

Page 27: Campus Network Design for NREN Engineers

Layer 3 Switches •  Many vendors use the term “Layer 3

Switch”. •  These are contradictory terms

– Layer 3 = Routing – Switch = Layer 2

•  What vendors mean is that it is a device that can be configured as a router or a switch or possibly both at the same time.

Page 28: Campus Network Design for NREN Engineers

Switching versus Routing These links must be routed, not switched

Page 29: Campus Network Design for NREN Engineers

Core Network •  Reliability is the key

–  remember many users and possibly your whole network relies on the core

•  May have one or more network core locations •  Core location must have reliable power

– UPS battery backup (redundant UPS as your network evolves)

– Generator – Grounding and bonding

•  Core location must have reliable air conditioning

Page 30: Campus Network Design for NREN Engineers

Core Network •  At the core of your network should be routers – you must

route, not switch. •  Routers give isolation between subnets •  A simple core:

Border Router Core Router All router interfaces on a separate subnet

Central Servers for campus

Fiber optic links to remote buildings

ISP

Page 31: Campus Network Design for NREN Engineers

Where to put Firewalls •  Security devices are usually placed “in line” •  This means that the speed of the firewall affects access to

the outside world •  This is a typical design:

Border Router Firewall/ Traffic Shaper

Core Router All router interfaces on a separate subnet

Fiber optic links to remote buildings

ISP

Page 32: Campus Network Design for NREN Engineers

Where to put Firewalls •  As Campus Networks have gotten better bandwidth, the

firewall becomes a bottleneck. •  Consider moving high bandwidth devices from behind

firewall (this is sometimes called the Science DMZ) •  Recommended Configuration:

Border Router Firewall/ Traffic Shaper

Core Router All router interfaces on a separate subnet

Fiber optic links to remote buildings

ISP

Science DMZ Router or switch Science DMZ

Hosts and Monitoring

Page 33: Campus Network Design for NREN Engineers

Where to put Servers? •  Servers should never be on the same subnet as users •  Should be on a separate subnet off of the core router •  Servers should be at your core location where there is

good power and air conditioning Border Router Firewall/

Traffic Shaper Core Router All router interfaces on a separate subnet

Fiber optic links to remote buildings

Servers in core

Internet Service Provider

Page 34: Campus Network Design for NREN Engineers

Where to put Servers? •  Sometimes you need servers that have public IP addresses •  Can put directly off of a firewall with no NAT •  Can have some servers with an interface on both the

external network and an internal network Border Router Firewall Core Router All router

interfaces on a separate subnet

Fiber optic links to remote buildings

Internal Servers

Internet Service Provider

Public Servers

Page 35: Campus Network Design for NREN Engineers

Border Router •  Connects to outside world •  RENs and Peering are the reason you need them

–  Science DMZ might be another reason •  Must get Provider Independent IP address space to

really make this work right

Campus Network

Internet Service Provider

Your REN

Page 36: Campus Network Design for NREN Engineers

Putting it all Together Border Router

Core Router

Fiber Optic Links

Firewall/

Traffic Shaper

Fiber Optic Links

Internal Servers

ISP

Your REN

Public Servers

Science DMZ Servers and Monitoring

Page 37: Campus Network Design for NREN Engineers

Wireless Links instead of Fiber

Wireless Links

Border Router

Core Router

Fiber Optic Links

Firewall/

Traffic Shaper

Internal Servers

ISP

Your REN

Public Servers

Science DMZ Servers and Monitoring

Page 38: Campus Network Design for NREN Engineers

Layer 2 and 3 Summary •  Route in the core •  Switch at the edge •  Build star networks – don’t daisy chain •  Buy only managed switches – re-purpose

your old unmanaged switches for labs

Page 39: Campus Network Design for NREN Engineers

Campus Fiber Optic Cabling •  Two basic types of fiber

– Multi Mode

– Single Mode

Page 40: Campus Network Design for NREN Engineers

Multi Mode Fiber •  Two basic types:

– 62.5 micron core. Legacy, older style – 50 micron core. Newer

•  A number of standards to be aware – G.651 – 50 micron – OSI/IEC 11801 OM1 – 62.5 – OSI/IEC 11801 OM2 – 50 micron – OSI/IEC 11801 OM3 – 50 micron laser optimized – OSI/IEC 11801 OM4 – 50 micron higher bw

Page 41: Campus Network Design for NREN Engineers

Single Mode Fiber •  All have core between 8 and 10 micron •  Standard types:

– OS1 and OS2 (OSI/IEC 11801 types) –  ITU G.652 (A, B, C, D) –  ITU G.653 – 1310/1550 with EDFA amps –  ITU G.654 – 1550 only –  ITU G.655 – 1550/1625 for long haul DWDM –  ITU G.656 – 1460/1625 for long haul DWDM

•  You want G.652.D or OS2 single mode

Page 42: Campus Network Design for NREN Engineers

Types of Optical Interfaces

Standard Speed Fiber Type

100baseFX 100Mbs MM

1000baseSX 1Gbs MM

1000baseLX/LH 1Gbs MM or SM

10GbaseSR 10Gbs MM

10GbaseLRM 10Gbs MM

10GbaseLR 10Gbs SM

10GbaseER 10Gbs SM

Page 43: Campus Network Design for NREN Engineers

Optical Interfaces: Cost & Distance Standard Cost* OM1 OM2 OM3 OM4 G.652.D

100baseFX $125 2km 2km 2km 2km No

1000baseSX $100 275m 550m 1km 1.1km No

1000baseLX/LH $169 500m 500m 500m 500m 10km

10GbaseSR $475 33m 82m 300m 550m No

10GbaseLRM $785 220m 220m 300m 400m No

10GbaseLR $495 No No No No 10km

10GbaseER $6050 No No No No 40km

*pricing for genuine Cisco products from networkhardwareoutlet.com. In the USA, these products can be purchased cheaper than shown.

Page 44: Campus Network Design for NREN Engineers

Simple Campus Network

•  What kind of fiber will work for Gigabit? •  How about for 10Gig?

Border Router

Core Router

Central Servers for campus

Fiber optic links to remote buildings

200m 300m 500m 600m

Copper cable

Page 45: Campus Network Design for NREN Engineers

Fiber Price Comparison

Fiber Type Cost per km* OM1 (62.5 legacy) $4,270

OM2 (50 legacy) $2,854

OM3 (50 laser optimized) $7,248

OM4 (new std) $7,990

G.652.D (single mode) $938

•  Single mode fiber cabling is cheaper •  Multi mode optical interfaces are cheaper •  What makes sense for your campus?

*Pricing based on 12-fiber outdoor cable, Corning 012TU4-T41xxD20, quote obtained in April, 2013

Page 46: Campus Network Design for NREN Engineers

Fiber Recommendations - Campus •  Campus networks should only install

single mode G.652.D or OS2 fiber •  They should not install any type of multi

mode fiber •  Contractors will recommend OM3 or OM4

– Don’t do that, use single mode

Page 47: Campus Network Design for NREN Engineers

Questions?

This document is a result of work by the Network Startup Resource Center (NSRC at http://www.nsrc.org). This document may be freely copied, modified, and otherwise re-used on the condition that any re-use acknowledge the

NSRC as the original source.

Page 48: Campus Network Design for NREN Engineers

Symbols to use for diagrams