Title: Directories
1Directories Policy-Based Networking
John Strassner Cisco Systems
0827_02F8_c1
2Need for Policy
IntelligentNetwork
3Policy-Based Networking
4What is a Network Policy?
Linkage Between User, Applications, and Network
Services
Campus
Firewalls
Enterprise Policy
- What are my policies?
- Where are my users?
- What are their privileges?
Mobility
5Prioritize Applications
QoS Policy Server
QoS Policy Server
Net Manager
CampusBackbone
Public Frame Relay
Remote Campus
- Create QoS policy
- Mission-criticalhigh
- Distribute policy bindings
- QoS Policy Servers
- Network enforcement nodes
Order Entry, Finance, Manufacturing
Training Servers
6Restrict Multimedia Applications
QoS Policy Server
QoS Policy Server
Net Manager
CampusBackbone
Public Frame Relay
Remote Campus
- Create QoS policy
- Multimedia bandwidth less than 100 kbps
- RSVP Proxy
- Policy enforcement
Order Entry, Finance, Manufacturing
Training Servers
7Remote Access Policy
CiscoSecure
Encrypted ID/Password
ID/Password ID/Password ID/Password
Telecommuters
PSTN ISDN
Campus Backbone
AS 5300
Mobile Users
- Authentication, Authorization, Accounting (AAA)
- Centralized administration
8New Management Paradigm
- New Model for Integrationthe Management Intranet
- WEB Link integration
- WEB Data Integration
- WEB Task Integration
- Knowledge-Based Operationsfor Assured Network
Services - Local network knowledge
- Vendor-augmented knowledge
- Change notification
9WBEM Environment
Data Description
HTTP, LDAP, etc.
lt/XMLgt
Access
TransportEncoding
10The Management Intranet
CIM DEN XMLMOF
Heterogeneous Management Servers
11Intelligent Network Management
Helpdesk, Trouble-ticket, Event-Based Middleware
System Management
Server
Desktop
OtherVendor
OtherVendor
Device
Device
Device
Service
Device
Device
Service
Device
Service
Service
12Role of Directories
Integration
User
- Common information model
- User profiles, applications, and network services
- Single-user identity
- Integrated policies
Directory Services
Application
Desktop
Network
13Multi-Service Profiles
User Profiles
Service Profiles
Dashboard
cisco.com Password cisco
vpdntunnel-idcisco-gw
vpdnip-addresses1.1.1.2
vpdnnas-password12000
vpdngw-passwordGSR
jdoe Password letmein Service
Internet Service cisco.com
Service Games
Games Password cisco
vpdntunnel-idgames-gw
vpdnip-addresses3.1.3.1
vpdnnas-passwordSpace
vpdngw-passwordInvader
GroupA Service Internet
Service coke.com Service
Games
VoIP Password cisco
vpdntunnel-idvoip-gw
vpdnip-addresses3.3.2.1
vpdnnas-passwordpin
vpdngw-passworddrop
Guest PasswordNo Password Service
Internet Service VoIP Service
Games
14Scalable Policy Infrastructure
Distributed Policy Enforcement
IntelligentInfrastructure
Central Policy Repository
Security
RADIUS
PolicyEngine
User and Devices
LDAP
Profiles and Policies
QoS
Server
PolicyEngine
Cache
Services and SLAs
LDAP
LDAP
Addresses
PolicyEngine
DNS/DHCP
LDAP
15(No Transcript)