+ All Categories

ppt

Date post: 29-Jun-2015
Category:
Upload: networksguy
View: 240 times
Download: 0 times
Share this document with a friend
Popular Tags:
51
AANTS: Web-Based Tools for Cooperative Campus Network Administration Charles Thomas Dave Plonka AANTS Administration Team Division of Info. Tech. (DoIT) Network Services University of Wisconsin - Madison
Transcript
Page 1: ppt

AANTS:Web-Based Tools for Cooperative Campus Network Administration

Charles Thomas

Dave PlonkaAANTS Administration Team

Division of Info. Tech. (DoIT)

Network Services

University of Wisconsin - Madison

Page 2: ppt

Past Campus Network:

• ATM LANE environment with 5 or 6 routers.

• Multiple switch brands, many models.• Centrally-managed configurations for

50-75 devices.

Page 3: ppt

Past Campus Network:

• Campus departments administered their own LANs and had their own IT staff.

• Gear purchase, configuration, deployment, and maintenance was handled on a department-by-department basis.

• This led to a hodgepodge of operating procedures and network designs, some incompatible with each other.

Page 4: ppt

Campus XXI Century Network Upgrade

• Use Cisco equipment as a standard to minimize cross-vendor incompatibilities.

• Increase the backbone speed to 10 Gb/s.• Offer 1 Gb/s departmental connections. • Move to a centrally-purchased and

centrally-managed network model.

Page 5: ppt

Present Campus Network

• Nearly 900 Cisco network devices, many models.

• A few Juniper and NetScreen devices.• 41,000+ managed ports.• The number of managed buildings,

devices, and ports is growing every day.

Page 6: ppt
Page 7: ppt

The Challenge

• Campus LAN admins (Authorized Agents) need to administer the switches and ports which carry their LANs.

• The gear is centrally owned/managed, therefore we cannot allow them direct access (e.g. ssh or telnet) to the switches themselves.

• Need to maintain good relations with AAs and not deprive them of their sense of autonomy (political/practical).

Page 8: ppt
Page 9: ppt

The Goal

• Give our Authorized Agents comparable (and in many cases improved) network management capabilities.

• Maintain appropriate levels of security, authorization and access control.– Protect centrally-managed gear.– Protect AAs from each other.

Page 10: ppt

AANTS: Authorized Agent Network Tool Suite

• Loosely-coupled set of web-based utilities for network administration.

• Tools are team-developed in-house, optimized toward local networking practices, driven by user need.

• Allow users (campus LAN administrators and network engineers) to manage network devices, change device configurations, troubleshoot, inspect traffic data, coordinate with users, and perform other network management tasks.

Page 11: ppt

Foundation Technologies:

• NetCMS - Network Device Configuration Management System for tracking router/switch configurations.

• WiscNIC - RIPE whois database of network information.

• Oracle/MySQL - Device config database.• Cisconf - Cisco tftp config tool.• GNU Make - Project management.• FlowScan and MRTG (Multi-Router Traffic

Grapher).

Page 12: ppt
Page 13: ppt
Page 14: ppt
Page 15: ppt
Page 16: ppt
Page 17: ppt
Page 18: ppt
Page 19: ppt
Page 20: ppt
Page 21: ppt
Page 22: ppt

LookingGlass

• Run command-line operations on devices and view results.

• View ethernet switch logs.

Page 23: ppt
Page 24: ppt
Page 25: ppt

NetStats

• Graph router interface and switch port statistics.

• Several summary graphs displaying different types of traffic statistics at the campus network border.

• Searchable interface to traffic statistics.

Page 26: ppt
Page 27: ppt
Page 28: ppt

NetWatch

• Locate a host given a MAC or IP address.

• Discover which devices are connected to a specific switch.

Page 29: ppt
Page 30: ppt

EdgeConf• Configure device ports.• Perform multiple port changes as one

transaction.• Label ports with user information• Work with port subsets.• Examine switch port configurations and

other switch information.• Users can only change devices/ports for

which they are authorized.

Page 31: ppt
Page 32: ppt
Page 33: ppt
Page 34: ppt
Page 35: ppt
Page 36: ppt

VlanFinder• Discovers all currently active VLANs.• User selects one or more VLANs.• Display devices and ports on which the VLANs are

active.• Display VLAN attributes:

– Configuration of routed VLAN interfaces

– Any trunk allowed VLANs

– VLAN Spanning Tree Protocol priorities

• Device names and ports will be hot-linked (where applicable) to EdgeConf.

Page 37: ppt

VlanFinder• Used to identify devices/ports which could

potentially be affected by work on a specific VLAN.

• Used to map the current configuration of a VLAN prior to reconfiguration.

• Used to verify the real-world result of network configuration changes (“Did my change do what I wanted?”).

Page 38: ppt
Page 39: ppt
Page 40: ppt
Page 41: ppt

MailByDevice• Select one or more network devices.• Find all VLANs on each device.• Get all technical and administrative contacts

for each VLAN from the WiscNIC database.• User can compose an email message.• Message will be mailed to all users.• Used to alert users when certain devices are

going to be affected by NS actions.

Page 42: ppt
Page 43: ppt
Page 44: ppt

CodePusher• Push commands, operating code, or configuration

code to selected network devices.– Run command-line directives (e.g. ‘show int’).– Upgrade system software.– Modify device configurations.– Manage ACLs.

• Parallelized for maximum efficiency.• Can specify a delayed device restart date/time.• Parses results into log files which can be viewed

from the web browser .• Performs error-checking.• Reports results via email.

Page 45: ppt
Page 46: ppt

Live Demos

Page 47: ppt

Summary

• AANTS tools allow our customers to manage their network over the web, regardless of the user’s platform of choice.

• AANTS tool development is driven by user input and real-world needs.

• AANTS is built on a foundation of freely-available software.

• Local networking practices guide AANTS’ growth as a customized system.

Page 48: ppt

Summary (cont.)• Day-to-day management tasks are handled more

quickly and easily for network services staff.• Improved Security Management

– Maintain common Access-Control-Lists across network gear.

– Locate and isolate compromised and abusive machines.

– Visually identify bouts of abusive traffic.

– Block traffic involving abusive intra- or extra-campus hosts

Page 49: ppt

Summary (cont.)• These tools help us maintain good relations with

campus LAN admins by empowering them rather than moving responsibility away from them.

• This cooperative policy makes use of available campus IT talent to help network services staff manage the network.

Page 50: ppt

Contact the AANTS Admin Team

[email protected]

Page 51: ppt

Q&A


Recommended