Showing posts with label connect. Show all posts
Showing posts with label connect. Show all posts

Wednesday, March 26, 2008

From Bridges to Routers continue...

Using a Router to Segment the Network

Like bridges, routers can be used to isolate traffic between network segments. Unlike bridges, routers further reduce network bandwidth use because they do not pass broadcast messages from one segment to another unless programmed to do so. A router also does not have to take time to learn which nodes are connected to each segment. The information it needs is configured in advance—the administrator assigns protocols and addresses to each port. Routing protocols also use various methods to update each other about network topology as it changes.

One very important reason why routers are used to help organize a network into segments is that routers enable you to connect many network segments. Whereas bridges are limited to a few thousand nodes, depending on the topology used, routers can enable the LAN to be connected to an infinitely larger WAN, such as the Internet.

The internal processing that routers must perform make them slower than bridges (although that might not be the case with most high-end routers being manufactured today), which need to examine only a small amount of data in the packet header. Although this performance difference will not be noticed on network segments with only moderate traffic use, you might find that you need to place routers at only strategic locations throughout the network, retaining switches for connecting other computers or network segments. Remember that you can connect individual computers to a switch port or use the port to connect to other switches.

Internet 2010

The method you use will depend on the usage patterns that can be monitored for each segment and the cost of the links used to connect different segments. Another thing to consider is that many of the high-end routers available today operate at what is called "wire speed." That means they can route packets at virtually the same speed as the network medium, with just the very slightest delay for processing time.

Connecting to a Larger WAN or the Internet

When connecting the LAN to a WAN, a router is required. When connecting to the Internet, for example, you cannot use a bridge or a repeater. The Internet is composed of a hierarchical IP address space and a router is needed to participate in this hierarchy. Or you might plan to use a dedicated line of some sort to connect to a larger corporate network. In that case, placing a router between your LAN and the WAN hardware, such as an ATM switch connection, will help reduce the traffic that crosses the expensive dedicated connection by keeping local traffic confined to the local network segments.

Note

There are two situations in which a router is not needed to make an Internet connection. The first is if you have a modem- based dial-up connection. Although it's possible to set up routing tables in operating systems such as Windows and Unix/Linux, this isn't really a practical method for connecting a small office IAN to the Internet due to the very limited speed.

The other situation is when you use a broadband connection, such as a cable or DSL modem. In this case, you can connect the high-bandwidth modem to a single computer and then set up routing tables so that other computers can send and receive traffic through the computer, which operates as a router. However, there's a better idea in a Small Office/Home Office (SOHO) or Remote Office Branch Office (ROBO) environment or a home environment where everyone from the parents to the kids have their own computers: Purchase an inexpensive 4-6 port router (for less than $100 in mast cases) that you can connect to the cable/DSL modem. These types of routers require very little knowledge about computers and can usually be set up in less than a half-hour.

Although you'll certainly have to configure the ports that connect the local LAN and the WAN interface, you might have to reconfigure addressing information on clients. For example, if you're already using a valid TCP/IP network address, possibly a subnet of the corporate network address space, you'll need to configure only routers.

If your business has just been acquired by a larger concern, however, you might find that your LAN has been assigned a new subnet by the larger corporation. In such a case, you'll probably have to plan on downtime for end users in order to make changes to important servers, such as Domain Name System (DNS) servers. DHCP servers (which workstations can find themselves) are used to translate between user-friendly names and IP addresses. Although DHCP can dynamically assign configuration information to workstations, important servers, such as DNS servers or gateways to other networks (usually routers), must have a static (unchanging) address. This is because part of the configuration information that DHCP supplies to clients is those addresses! If the address of a DNS server changed with every reboot of the server, you would have to reconfigure the information on each workstation client—a tedious effort even in a small network!

By using DHCP, you can overcome client configuration headaches such as this. Just reconfigure the DHCP server with the address range for the new subnet, add in the DNS servers and default gateway, and reboot your client computers. This is a simple explanation of the information supplied by DHCP servers. Indeed, you can use DHCP to provide configuration information for many other network parameters.

From Bridges to Routers

Routers are inherently slower than bridges when it comes to forwarding network packets. This is because a router must read further into each network frame to get Network layer addressing information, whereas a bridge merely looks at a fixed location for the MAC address. Hubs, bridges, and switches can be set up in a short amount of time and usually require little or no configuration.

Routers require that the network administrator configure networking information for each port that's used. The command set available to configure a router is quite large because it's a very flexible device and can be confusing for a novice. The kinds of information you need to configure a new router are

  1. A list of the network protocols for which you'll be using the router. For example, TCP/IP or IPX/SPX.
  2. The routing protocol that you'll use for each network protocol. For example, RIP.
  3. Whether or not you'll need to set filters to block certain addresses or IP or UDP ports—a tech• nique used to create a simple firewall.
  4. Information about the address space used on each segment the router will connect.

Network Protocol Issues

Internet 2010

In many networks, more than one network protocol is used on the same medium. To do their job, routers need configuration information about each protocol for each port. For example, because each port on the router connects to a different network segment, each port must have a unique network address that it can use to communicate on the segment. If you plan to restrict some segments for security or other reasons, you'll need to create a set of access control lists (ACLs) for each port, which indicate which frames are allowed through, in both directions.

When using a router to connect to a larger WAN, you'll probably be faced with having to configure a port on the router that uses a WAN protocol, such as Frame Relay, in addition to protocols you're already familiar with on your network. With a WAN connection, you'll have to coordinate your activities with other system administrators to ensure that the router is configured with the correct information for the larger network.

Network Addressing Issues

Because the router makes decisions based on a higher-level networking protocol, such as IP, you'll have to take into consideration your current address space when you decide to introduce a router into the network. If you're adding new segments to the LAN and have the freedom to choose a new network address, this can be an easy task. If you're going to take an existing LAN and use a router to separate it into more manageable segments, you have two possible choices. You can use your original network address for one segment and create new networks on the remaining segments or you can use subnetting.

Regardless, you'll have to then reconfigure each client with new addressing information. If you're using DHCP, the process is made simpler because you can make the changes at a central location and have clients request the new information after the changes have been made. DHCP is the most prevalent method used today to configure workstations and other non-server devices on a network.

If you're going to use a router to connect your LAN to a larger corporate network, you might not have to make any addressing changes on your network, depending on the company's overall network plan. You'll still have to configure the ports, however. If you're going to connect the LAN to the Internet, using a router configured as a firewall might be something to consider.

Other Router Management Issues

Routers are very much like smart PCs that have been customized to perform the routing function efficiently. They have CPUs, memory, and I/O ports just like an ordinary PC. They also have an operating system, which is subject to periodic updates by the manufacturer. So, in addition to learning how to configure the router, you'll also need to become familiar with the commands used for such functions as saving a copy of the system image to a server for backup purposes and performing troubleshooting and testing.

Managing a network that uses routers can seem a difficult task at first. However, by enabling you to organize your network according to the hierarchical network address spaces used by upper-level network protocols, the initial configuration problems will be worth the effort.

Tuesday, March 25, 2008

Growing Beyond a Small LAN continue...

Segmenting the Network Can Improve Performance

You might need to segment devices on the network for many different reasons. These include the following:

1. Topology limitations—You need to add more nodes to the network but the expansion will break distance limitations or maximum nodes-per-segment rules. This is usually the case only in older Ethernet LANs where the broadcast domain was constrained by the round-trip time.

2. Networking protocol limitationsAddress space is fragmented and you need to connect segments that have different network addresses. This can happen when two companies merge and both already have an address space in place for their respective networks. It's much easier to simply place one or more routers between the two networks than it is to reassign network addresses to the many devices on the network. When using DHCP to configure workstations, this might not be a limitation, provided that you have an address space that can accommodate all the devices that will be placed on the larger network.

Internet 2010

3. Network bandwidth limitations—When a few high-performance servers or workstations consume too much of the segment's available bandwidth, it's time to segment the LAN (create additional subnets) and thus limit network traffic to smaller segments that contain fewer devices.

4. Security reasons—An Ethernet adapter set to promiscuous mode can intercept all packets that are sent out on a particular segment, for example. You need to place a few high security workstations on their own segment, yet allow some kind of connection to the rest of the network. Keep in mind that in an Ethernet network that uses hubs as a wiring concentrator, every device on the hub (or hubs) can see every network frame that's broadcast on the LAN. It isn't difficult to download a program from an Internet source to read every packet that passes through the network.

Geographically distant connections—It's best to segment each geographic location to ensure that unnecessary traffic isn't being sent across the remote connection and wasting valuable bandwidth. Some routers provide a dial-up function so that a dedicated link isn't necessary, providing an inexpensive way to use routers to connect branch offices.

Depending on which combination of these reasons applies to your situation, a router or switch might be the solution you need to segment the network.

Connecting Remote Locations

When a business expands geographically, you'll find that using bridges to connect remote locations isn't a feasible solution. There are many different technologies from which you can choose today— from simple dedicated lines to ATM and Frame Relay—to connect geographically distant locations.

For these connections, you'll find it necessary to incorporate routers or switches. You'll also find these methods of transport expensive. Today, it isn't unreasonable to consider connecting the local network to the Internet with a router that provides virtual private network (VPN) capabilities. Thus, by using an inexpensive connection to the Internet (far cheaper than using leased dedicated lines), you can still provide a secure channel to remote branch locations.

When to Use a Router

Routers are similar to bridges only in the fact that they can both be used to connect multiple network segments. Whereas bridges make all their decisions based on the MAC address of a particular network packet, routers access the addressing information provided by a higher-level protocol to decide how to best forward a packet. Using the OSI reference model (see Appendix A, "Overview of the OSI Seven-

Layer Networking Reference Model"), you can see that the bridge operates at layer 2, the Data Link layer, whereas routers operate at layer 3, the Network layer. With bridges, the address space is flat: It's simply the MAC addresses associated with nodes on each segment, each one unique. For protocols operating at the Network layer, the address space becomes more complicated because there must be a mechanism for identifying the network as well as the individual node.

When to Use a Switch

Switches are one of the fastest growing categories of network equipment. They can act as a wiring concentrator for a LAN just as a hub does, but they also can make available a much larger bandwidth to clients because they selectively forward traffic from one port to another based on the destination address of each packet. When you use a switch with only one node attached to each port, you are in effect creating a collection of broadcast domains that consist of only two network nodes: the switch and the client node connected to the port. For network adapters and switches that support full-duplex operation, the effective bandwidth is doubled for each client and there is no broadcast domain between the two.

Internet Blogosphere