CRS STANDARD
NETWORK PLATFORM
July 6th, 2017
Presented by: Victor Konana
Standard Network Platform overview
2
• Part of System Management Program
– Standard Network Platform
– End User Computing
– Database Migration to Commercial Hosting
• Aimed toward decrease of ICT footprint in CPs
– Technology change
– Services becoming more important than servers
– CP realizes IT infrastructure cost saving over time
– Lower cost of maintenance of equipment
• Standardization of ICT systems Agency-wide
– Technology standardization
– Configuration standardization
Where we started?
3
4
5
Overview of SNPdesign
5
Physical equipment
• Enterprise level of networking equipment based on Cisco brand
– Router
• Integrated Services Router - 2921/2951
• Multiple services/technologies implemented within
– http://www.cisco.com/c/en/us/products/routers/2951-integrated-services-router-
isr/index.html
– http://www.cisco.com/c/en/us/products/routers/2921-integrated-services-router-
isr/index.html
– Switches
• Cisco Catalyst 2960-24LC-S
– PoE enabled/24 ports
– Wireless access points
• Cisco Aironet AIR-CAP2702E-x-K9
– Dual band controller based 802.11 a/g/n/ac with external antennas
6
7
Services
• Content filtering, malware scanning, intrusion prevention
• Hypervisor virtualization platform containing MS Windows Server
• Optimization & acceleration of CRS Global internet traffic
• Central management and monitoring system
• Network services
– Firewall
– DHCP/DNS
– Virtual Private Network/VPN – for SNP devices management
• Network segmentation
– Multiple networks within CP
– Guest wireless (isolated from internal network)
8
Content filtering & malware scanning
• Based on Cisco Cloud Web Security (CWS) aka Scansafe
• Cloud based system
• Traffic is proxied through Cisco CWS cloud
• Inspects all traffic and blocks unwanted content/sites
• Same, standard blocking set for the entire Agency
• Prevents malware and viruses infecting CRS computers
• Provides zero-day threat protection as well (in real time)
• Strong reporting capability on utilization of internet traffic within CP
• Failover capability enabled
• Enables identification of rogue (bandwidth consuming) devices
9
Hypervisor virtualization platform with
Windows Server 2012
• Windows 2012 R2 Standard Operating System
• Runs as Virtual Machine on VMWare environment hosted on UCSE
module integrated within router
• 1 TB of HDD space (fault tolerant), 16 GB of RAM, Intel Xeon E3 CPU
• Managed by CP IT staff - full management rights
• Replaces existing legacy server(s)
– Additional backup domain controller will be shipped by end of May for increased
fault tolerance
• Designed for
– AD/DC/DNS
– File services
– CP applications (transfer in accordance with Change Control Board processes)
10
Global management and monitoring systems
• Cisco Prime (Collocated at Rackspace)
– Central management system for routers and switches
– Management and monitoring of Cisco devices
– Also used as backup system for configuration of Cisco devices
• Cisco Wireless Controller (Collocated at Rackspace)
– Central management system for wireless devices
– Provisioning, management and monitoring of wireless devices
• PRTG (Collocated at Rackspace)
– Real-time monitoring tool for availability of network devices
– Also used as troubleshooting system for internet connectivity issues in CPs
– To be utilized as alerting system for connectivity issues
• CWS aka Scansafe (Cisco Cloud)
– Web security setup, application traffic control, management and reporting
11
Optimization of CRS Global internet traffic
• Based on Cisco WAAS (Wide Area Application Service) technology
• Improves bandwidth utilization between CP and CRS Global systems
(SharePoint and accompanying services)
• Technology integrated into each router
• Centrally managed
• http://www.cisco.com/c/en/us/products/routers/wide-area-application-services-
waas-software/index.html
12
Network services
• Firewall
– Zone based firewall
– Integrated in router configuration
– Granular firewall rules allow network segmentation (and guest wireless network)
– http://www.cisco.com/c/en/us/products/security/ios-firewall/index.html
• DHCP/DNS
– Router IOS base services
– Replaces MS Windows DHCP systems
– Internal AD DNS namespace is forwarded to internal Windows AD DNS server(s)
• Virtual Private Network/VPN
– Connects SNP setup in CP office with central management systems in Rackspace
– Used for managing SNP devices only. SNP setup fully functional if VPN is down
– Uses site-to-site IPSec VPN
13
Where are we now?
• Standard Network Platform operational on 88 locations (Min 15
Users)
• Content filtering/malware scanning system is operational (450k
malware filtered weekly)
• Fully on Microsoft hosted Email Office 365 and Onedrive
• Microsoft SharePoint
• Microsoft intune Desktop and Mobile device Management
• Global ERP Solution
• Testing of Cisco Web Security Client for End Users
• Pre-positioning of equipment for New Offices, Emergencies and
Support
14
• ICT4D is gaining momentum in the Agency
• Decrease of infrastructure cost and maintenance – increased
resources availability for ICT4D
• Sharing of information and practices, using common configuration
approach
• Central monitoring tools and reporting systems
• Improved Documentation
15
Challenges
• Logistics
• Connectivity
– ISP/VSAT related issues
– Bandwidth consumption
– Optimization of internet routes for Cisco Web Security
• Communication
– Identification of issue
– Improve our troubleshooting techniques in order to identify the core cause of the
problems and properly escalate
• Hardware equipment failure
16
Standard Network Platform support
• Integrated support approach (coordination between GKIM, RISA and
CP IT Managers)
• Round the clock support provided (support provided in 22 time zones
on 3 languages)
• Due to standardization of Standard Network Platform, network layer is
maintained by GKIM
• Windows Server virtual machine is managed by CP IT Managers
• Vendor support – CISCO TAC
17
18
Cisco Web Security
aka
ScanSafe
19
What is CWS?
20
ScanSafe Data Flow
21
Features
22
• Web filtering
• Malware scanning
• Web reputation
• Application visibility and control
• Centralized management and reporting
Why ScanSafe?
• Talos Security and Research Group: analyzes anomalies, uncovers
new threats, and monitors traffic trends. Talos generates new rules
and updates every 3 to 5 minutes.
• World-class support
– Software updates and major upgrades to keep applications performing optimally
with the most current feature set
– Access to Cisco Technical Assistance Center (TAC) for fast, specialized support
– Online tools that build and expand in-house expertise and boost business agility
• Industry-leading uptime
– Delivers an SLA of 99.999 percent uptime.
– Cloud Web Security stays current with the latest threat information.
– Security is always on and available, freeing your staff to focus on other priorities
23
ScanSafeWarning!
24
ScanSafe Blocked Content
25
ScanSafe Portal
26
Scan Center Web Filtering Reporting Output
27
Application and Composite Reporting
28
PRTG Network Monitor
(PaesslerRouterTrafficGrapher)
29
Overview
30
Objectives
• Proactive performance monitoring for all Internet links
• Monitor Availability of Network Active Equipment
• Network Traffic Protocol Analysis
31
Default Home Page
32
Device Groups and Sensors
33
Sensor States
Sensor COLOR STATUS NAME
Red Down
Bright-Red Down (Acknowledged)
Yellow Warning
Orange Unusual
Green Up
Blue Paused
34
35
DashBoard
36
Live Data
36
37
Historic Data
37
38
EmailAlerts

More Related Content

PPTX
MMS2012-HP VirtualSystem-The Ideal Foundation for a Microsoft Private Cloud
PPT
Information Security Lesson 4 - Baselines - Eric Vanderburg
PPT
Chapter09
PDF
Faster and more efficient system management with Lenovo XClarity Administrator
PPT
Chapter08
PDF
Lenovo XClarity March 2016 Updates
PPTX
PPTX
DGI Compliance Webinar
MMS2012-HP VirtualSystem-The Ideal Foundation for a Microsoft Private Cloud
Information Security Lesson 4 - Baselines - Eric Vanderburg
Chapter09
Faster and more efficient system management with Lenovo XClarity Administrator
Chapter08
Lenovo XClarity March 2016 Updates
DGI Compliance Webinar

What's hot (20)

PPSX
VMware: my jsme “software defined”
PPTX
07. datacenters
PDF
NephOS Product Datasheet
PDF
Site Manager Platform as a service:TERMINALFOUR t44u 2013:
PDF
10 disaster recovery
PPTX
New Tampa Data Center - Peak 10
PPT
IBM Impact session CICS V52 overview
PPT
Data center
PDF
9 postproduction
PPTX
Site24x7 Server Monitoring from the Cloud
PDF
Simplify WAN Deployment with the Cisco IWAN Application
PDF
SFScon19 - Marco Bizzantino - GitOps and Immutable Infrastructure
PDF
CICS TS V5 Technical Overview
PPT
Private cloud with vmware
PPTX
01. 03.-introduction-to-infrastructure
PDF
bwd_company_flier
PPTX
Network Management
PDF
[WSO2Con EU 2017] WSO2 Unleashed: Full Stack Automation, Pitfalls and Solutions
PPTX
SHARE 2015 SeattleShare cics ts 52 technical overview
ODP
SHARE 2014, Pittsburgh CICS scalability
VMware: my jsme “software defined”
07. datacenters
NephOS Product Datasheet
Site Manager Platform as a service:TERMINALFOUR t44u 2013:
10 disaster recovery
New Tampa Data Center - Peak 10
IBM Impact session CICS V52 overview
Data center
9 postproduction
Site24x7 Server Monitoring from the Cloud
Simplify WAN Deployment with the Cisco IWAN Application
SFScon19 - Marco Bizzantino - GitOps and Immutable Infrastructure
CICS TS V5 Technical Overview
Private cloud with vmware
01. 03.-introduction-to-infrastructure
bwd_company_flier
Network Management
[WSO2Con EU 2017] WSO2 Unleashed: Full Stack Automation, Pitfalls and Solutions
SHARE 2015 SeattleShare cics ts 52 technical overview
SHARE 2014, Pittsburgh CICS scalability
Ad

Similar to Cisco Standard Network Platform (SNP) - Catholic Relief Services Case Study (20)

PPT
01 route routing services
PPTX
CCNP v6 Route: Implementing IP Routing Chapter1
PPT
Dcna technology update
PDF
Innovations in Switching
PPT
Cisco Strategic Profile
PDF
Qos For Ipmpls Networks Gallo Mark Zhang Raymond Alvarez Santiago
PDF
The Network Enabled EOC
PPTX
Apresentação ccna en_SWITCH_v6_Ch01.pptx
PPTX
Cisco prime-nms-overview-hi-techdays deep dive
PPTX
Cisco prime-nms-overview-hi-techdays deep dive
PDF
Unified industrial wireless networks (cisco)
PDF
Enterprise Architecture, Deployment and Positioning
PPT
Jvvnl 071108
PDF
How Cisco Provides World-Class Technology Conference Experiences Using Automa...
PPT
E s switch_v6_ch01
PPTX
Cisco ucs overview ibm team 2014 v.2 - handout
DOCX
GREAT MINDS
PDF
Sled local gov pov october 2016 v2
PDF
Next Generation Campus Switching: Are You Ready
01 route routing services
CCNP v6 Route: Implementing IP Routing Chapter1
Dcna technology update
Innovations in Switching
Cisco Strategic Profile
Qos For Ipmpls Networks Gallo Mark Zhang Raymond Alvarez Santiago
The Network Enabled EOC
Apresentação ccna en_SWITCH_v6_Ch01.pptx
Cisco prime-nms-overview-hi-techdays deep dive
Cisco prime-nms-overview-hi-techdays deep dive
Unified industrial wireless networks (cisco)
Enterprise Architecture, Deployment and Positioning
Jvvnl 071108
How Cisco Provides World-Class Technology Conference Experiences Using Automa...
E s switch_v6_ch01
Cisco ucs overview ibm team 2014 v.2 - handout
GREAT MINDS
Sled local gov pov october 2016 v2
Next Generation Campus Switching: Are You Ready
Ad

More from nicholas njoroge (15)

PPTX
Sustainable Connectivity after the Emergency Response Phase
PPTX
Humanitarian ICT Road-Map and Standardisation
PPTX
Business Relationship Management in IRC
PPTX
Best practices for data centers
PPTX
Best practices in networks and infrastructure
PPTX
Women and ICT - UNOCHA (ROSEA)
PPTX
Meraki - Case Study, PATH International - Part 2
PPTX
Meraki - Case Study, PATH International
PPTX
ICT for Development (ICT4D) in Plan International
PPTX
ICT4D in Catholic Relief Services (CRS)
PPTX
Fortinet Network Security Appliance - Case Study, CARE USA
PDF
ICT in Emergencies - Nethope
PPTX
Cloud adoption strategies for non profits - DAI
PPTX
Business Relations and Engage - Save the Children
PPTX
IT Strategy and Governance - SOS Children's Villages
Sustainable Connectivity after the Emergency Response Phase
Humanitarian ICT Road-Map and Standardisation
Business Relationship Management in IRC
Best practices for data centers
Best practices in networks and infrastructure
Women and ICT - UNOCHA (ROSEA)
Meraki - Case Study, PATH International - Part 2
Meraki - Case Study, PATH International
ICT for Development (ICT4D) in Plan International
ICT4D in Catholic Relief Services (CRS)
Fortinet Network Security Appliance - Case Study, CARE USA
ICT in Emergencies - Nethope
Cloud adoption strategies for non profits - DAI
Business Relations and Engage - Save the Children
IT Strategy and Governance - SOS Children's Villages

Recently uploaded (20)

PPTX
Build automations faster and more reliably with UiPath ScreenPlay
PDF
LMS bot: enhanced learning management systems for improved student learning e...
PDF
Human Computer Interaction Miterm Lesson
PDF
MENA-ECEONOMIC-CONTEXT-VC MENA-ECEONOMIC
PDF
Dell Pro Micro: Speed customer interactions, patient processing, and learning...
PPTX
Presentation - Principles of Instructional Design.pptx
PDF
Lung cancer patients survival prediction using outlier detection and optimize...
PDF
Transform-Your-Factory-with-AI-Driven-Quality-Engineering.pdf
PDF
Examining Bias in AI Generated News Content.pdf
PPTX
SGT Report The Beast Plan and Cyberphysical Systems of Control
PDF
Planning-an-Audit-A-How-To-Guide-Checklist-WP.pdf
PDF
Co-training pseudo-labeling for text classification with support vector machi...
PDF
Ensemble model-based arrhythmia classification with local interpretable model...
PDF
SaaS reusability assessment using machine learning techniques
PDF
“The Future of Visual AI: Efficient Multimodal Intelligence,” a Keynote Prese...
PDF
Rapid Prototyping: A lecture on prototyping techniques for interface design
PDF
Decision Optimization - From Theory to Practice
PDF
CXOs-Are-you-still-doing-manual-DevOps-in-the-age-of-AI.pdf
PDF
4 layer Arch & Reference Arch of IoT.pdf
PDF
5-Ways-AI-is-Revolutionizing-Telecom-Quality-Engineering.pdf
Build automations faster and more reliably with UiPath ScreenPlay
LMS bot: enhanced learning management systems for improved student learning e...
Human Computer Interaction Miterm Lesson
MENA-ECEONOMIC-CONTEXT-VC MENA-ECEONOMIC
Dell Pro Micro: Speed customer interactions, patient processing, and learning...
Presentation - Principles of Instructional Design.pptx
Lung cancer patients survival prediction using outlier detection and optimize...
Transform-Your-Factory-with-AI-Driven-Quality-Engineering.pdf
Examining Bias in AI Generated News Content.pdf
SGT Report The Beast Plan and Cyberphysical Systems of Control
Planning-an-Audit-A-How-To-Guide-Checklist-WP.pdf
Co-training pseudo-labeling for text classification with support vector machi...
Ensemble model-based arrhythmia classification with local interpretable model...
SaaS reusability assessment using machine learning techniques
“The Future of Visual AI: Efficient Multimodal Intelligence,” a Keynote Prese...
Rapid Prototyping: A lecture on prototyping techniques for interface design
Decision Optimization - From Theory to Practice
CXOs-Are-you-still-doing-manual-DevOps-in-the-age-of-AI.pdf
4 layer Arch & Reference Arch of IoT.pdf
5-Ways-AI-is-Revolutionizing-Telecom-Quality-Engineering.pdf

Cisco Standard Network Platform (SNP) - Catholic Relief Services Case Study

  • 1. CRS STANDARD NETWORK PLATFORM July 6th, 2017 Presented by: Victor Konana
  • 2. Standard Network Platform overview 2 • Part of System Management Program – Standard Network Platform – End User Computing – Database Migration to Commercial Hosting • Aimed toward decrease of ICT footprint in CPs – Technology change – Services becoming more important than servers – CP realizes IT infrastructure cost saving over time – Lower cost of maintenance of equipment • Standardization of ICT systems Agency-wide – Technology standardization – Configuration standardization
  • 4. 4
  • 6. Physical equipment • Enterprise level of networking equipment based on Cisco brand – Router • Integrated Services Router - 2921/2951 • Multiple services/technologies implemented within – http://www.cisco.com/c/en/us/products/routers/2951-integrated-services-router- isr/index.html – http://www.cisco.com/c/en/us/products/routers/2921-integrated-services-router- isr/index.html – Switches • Cisco Catalyst 2960-24LC-S – PoE enabled/24 ports – Wireless access points • Cisco Aironet AIR-CAP2702E-x-K9 – Dual band controller based 802.11 a/g/n/ac with external antennas 6
  • 7. 7
  • 8. Services • Content filtering, malware scanning, intrusion prevention • Hypervisor virtualization platform containing MS Windows Server • Optimization & acceleration of CRS Global internet traffic • Central management and monitoring system • Network services – Firewall – DHCP/DNS – Virtual Private Network/VPN – for SNP devices management • Network segmentation – Multiple networks within CP – Guest wireless (isolated from internal network) 8
  • 9. Content filtering & malware scanning • Based on Cisco Cloud Web Security (CWS) aka Scansafe • Cloud based system • Traffic is proxied through Cisco CWS cloud • Inspects all traffic and blocks unwanted content/sites • Same, standard blocking set for the entire Agency • Prevents malware and viruses infecting CRS computers • Provides zero-day threat protection as well (in real time) • Strong reporting capability on utilization of internet traffic within CP • Failover capability enabled • Enables identification of rogue (bandwidth consuming) devices 9
  • 10. Hypervisor virtualization platform with Windows Server 2012 • Windows 2012 R2 Standard Operating System • Runs as Virtual Machine on VMWare environment hosted on UCSE module integrated within router • 1 TB of HDD space (fault tolerant), 16 GB of RAM, Intel Xeon E3 CPU • Managed by CP IT staff - full management rights • Replaces existing legacy server(s) – Additional backup domain controller will be shipped by end of May for increased fault tolerance • Designed for – AD/DC/DNS – File services – CP applications (transfer in accordance with Change Control Board processes) 10
  • 11. Global management and monitoring systems • Cisco Prime (Collocated at Rackspace) – Central management system for routers and switches – Management and monitoring of Cisco devices – Also used as backup system for configuration of Cisco devices • Cisco Wireless Controller (Collocated at Rackspace) – Central management system for wireless devices – Provisioning, management and monitoring of wireless devices • PRTG (Collocated at Rackspace) – Real-time monitoring tool for availability of network devices – Also used as troubleshooting system for internet connectivity issues in CPs – To be utilized as alerting system for connectivity issues • CWS aka Scansafe (Cisco Cloud) – Web security setup, application traffic control, management and reporting 11
  • 12. Optimization of CRS Global internet traffic • Based on Cisco WAAS (Wide Area Application Service) technology • Improves bandwidth utilization between CP and CRS Global systems (SharePoint and accompanying services) • Technology integrated into each router • Centrally managed • http://www.cisco.com/c/en/us/products/routers/wide-area-application-services- waas-software/index.html 12
  • 13. Network services • Firewall – Zone based firewall – Integrated in router configuration – Granular firewall rules allow network segmentation (and guest wireless network) – http://www.cisco.com/c/en/us/products/security/ios-firewall/index.html • DHCP/DNS – Router IOS base services – Replaces MS Windows DHCP systems – Internal AD DNS namespace is forwarded to internal Windows AD DNS server(s) • Virtual Private Network/VPN – Connects SNP setup in CP office with central management systems in Rackspace – Used for managing SNP devices only. SNP setup fully functional if VPN is down – Uses site-to-site IPSec VPN 13
  • 14. Where are we now? • Standard Network Platform operational on 88 locations (Min 15 Users) • Content filtering/malware scanning system is operational (450k malware filtered weekly) • Fully on Microsoft hosted Email Office 365 and Onedrive • Microsoft SharePoint • Microsoft intune Desktop and Mobile device Management • Global ERP Solution • Testing of Cisco Web Security Client for End Users • Pre-positioning of equipment for New Offices, Emergencies and Support 14
  • 15. • ICT4D is gaining momentum in the Agency • Decrease of infrastructure cost and maintenance – increased resources availability for ICT4D • Sharing of information and practices, using common configuration approach • Central monitoring tools and reporting systems • Improved Documentation 15
  • 16. Challenges • Logistics • Connectivity – ISP/VSAT related issues – Bandwidth consumption – Optimization of internet routes for Cisco Web Security • Communication – Identification of issue – Improve our troubleshooting techniques in order to identify the core cause of the problems and properly escalate • Hardware equipment failure 16
  • 17. Standard Network Platform support • Integrated support approach (coordination between GKIM, RISA and CP IT Managers) • Round the clock support provided (support provided in 22 time zones on 3 languages) • Due to standardization of Standard Network Platform, network layer is maintained by GKIM • Windows Server virtual machine is managed by CP IT Managers • Vendor support – CISCO TAC 17
  • 18. 18
  • 22. Features 22 • Web filtering • Malware scanning • Web reputation • Application visibility and control • Centralized management and reporting
  • 23. Why ScanSafe? • Talos Security and Research Group: analyzes anomalies, uncovers new threats, and monitors traffic trends. Talos generates new rules and updates every 3 to 5 minutes. • World-class support – Software updates and major upgrades to keep applications performing optimally with the most current feature set – Access to Cisco Technical Assistance Center (TAC) for fast, specialized support – Online tools that build and expand in-house expertise and boost business agility • Industry-leading uptime – Delivers an SLA of 99.999 percent uptime. – Cloud Web Security stays current with the latest threat information. – Security is always on and available, freeing your staff to focus on other priorities 23
  • 27. Scan Center Web Filtering Reporting Output 27
  • 31. Objectives • Proactive performance monitoring for all Internet links • Monitor Availability of Network Active Equipment • Network Traffic Protocol Analysis 31
  • 33. Device Groups and Sensors 33
  • 34. Sensor States Sensor COLOR STATUS NAME Red Down Bright-Red Down (Acknowledged) Yellow Warning Orange Unusual Green Up Blue Paused 34