Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x

Network Architecture

11K

Solutions

11K

Contributors

Network design and methodology, also known as network architecture, is the design of a communication network. It is a framework for the specification of a network's physical components and their functional organization and configuration, its operational principles and procedures, as well as data formats used in its operation. In telecommunication, the specification of a network architecture may also include a detailed description of products and services delivered via a communications network, as well as detailed rate and billing structures under which services are compensated.

Share tech news, updates, or what's on your mind.

Sign up to Post

We have a couple of servers that requires "outgoing" access to PlayStore & Appstore
from our Development as well as Production environmt.

As Appstore is a Class A subnet while Playstore is rather large as well (I don't know yet
what are its subnet ranges), what are the best ways to secure this?  Are the following
reasonable ways ?

I heard permitting too wide a range is risky.  Why?  Can appstore/playstore's IP addrs
range get spoofed or those 2 stores can get compromised or what's the reason?


1. Production has to go thru our proxy as our proxy resolves the URLs of appstore &
   playstore?

2. As our Development does not have its own proxy & has no connectivity to our
   Production proxy, permit only about ten Class C ranges for Development/testing
   purpose.  Ten Class C means 2540 IP addrs

3. Any other best practices to secure this?

4. Would placing these app servers behind WAF help?
0
Survive A High-Traffic Event with Percona
LVL 3
Survive A High-Traffic Event with Percona

Your application or website rely on your database to deliver information about products and services to your customers. You can’t afford to have your database lose performance, lose availability or become unresponsive – even for just a few minutes.

Hi

2x 2920 Core switches with 2x HP Edge switches connecting

If you have a stacked pair of switches (so 2x HP Procurve 2920 connected in a ring configuration with stacking cables) - then how should trunks be configured (etherchannels for the non HP switch aware) to access switches?

If I go to the Menu CLI and it lists the ports of both switches, I assume that if I setup a trunk on ports 23 and 24 on switch 1 then I need to setup the same on switch 2.  

- Do I set these up as two trunks with 2 ports from each switch contributing?  (ie - Trunk 1 with ports from Switch 1 ports 21,22 and Switch 2 ports 21,22, Trunk 2 with ports from Switch 1 ports 23,24 and Trunk 2 with ports from Switch 2 ports 23,24
- Or do I set them up as four trunks? (Ie Trunk 1 with ports from Switch 1 ports 21,22, Trunk 2 with ports from Switch 1 ports 23,24, Trunk 3 with ports from Switch 2 ports 21,22, Trunk 4 with ports from Switch 2 ports 23,24)

Hopefully makes sense  - I have tested it with option 1 above and fails over without issue but just wanted to confirm the best practice

Thanks
0
So, here is my scenario

Currently with 192.168.60.0/24 network set as VLAN200 on a switch, my router is 192.168.60.2.

Got a cisco 2960 switch as 192.168.60.1, and set with default GW 192.168.60.2

However, I need to set a new vlan for a vpn (mikrotik)

Mikrotik ip is 8.20.15.251/24

Ive created a VLAN400, as 8.20.15.0/24 and indicated the ip helper as the mikrotik. After assigning ports to that VLAN, it doesnt acquire IP, neither reach the GW (if I assign static IP to the computer). From the switch, if I try to ping the mikrotik ip, it does not respond (if I connect a computer directly on the mikrotik, I do get an IP, I can access it and even access the VPN services without problems)

Am I missing something?

thank you
0
Hi

Citrix not able to load applications. We are login but application not able to load?

When I click the application it run for 3 Sec and it disappears.
0
does anyone have a configuration template for Nexus 7K multicast over MPLS?
0
I am subcontracting some fiber work to a friend that does this for a living.

Specifications
~1000ft
Underground through Conduit
6 Strand

What type of high-quality fiber should I buy and from where? Plenum or non?
0
We have a Meraki MX400 firewall, and 11 SG500-52P Switches we are using for Access.  I'd like to get something for Core or Aggregation, what kind of product do you recommend?  Would we benefit from having a 3850 or something along the those lines to serve as the distribution or L3 switch?  Should we create stacks for the 11 SG500-52Ps?

Thank you in advance.

Nico
0
All experts, I have remote site with multiple vlans connected by site to site VPN.  there ip address range start 10.0.8.0 / 255.255.252.0 and some of department has 10.0.28.0, 10.0.29.0, 10.0.30.0 / 255.255.255.0.   How do i combine these networks and route them by simple route statement use on vpn?  I currently set to all vlan networks mapped and working but I would like to have simple statement such as following

10.0.0.0 255.255.0.0 to  10.0.28.0, 10.0.29.0, 10.0.30.0 / 255.255.255.0 and 10.0.8.0 / 255.255.252.0

I hope it makes sense. I believe supernet was how it configured it. I open to your advise Thank you!
0
Devices:
Google Home,
Aruba IAP-305 (RW)
NordVPN


I am trying to set up a VPN for my Google Home so it will register as being in the US. I am currently in Ireland and have purchased a subscription to NordVPN.  From what I understand, a VPN cannot be put on the actual Google Home device.

I currently make a lot of calls to the US. Google Home offers free calls in the US but is not available here in Ireland. This is one of the main things I want to get from my Google Home.

If the net result of the VPN makes Google Home look like its in the US, I do not want the rest of my tech devices to think they are in that location, i.e all of my other tech devices have locations in Ireland.

Regards,
Robbie
0
Can Azure AD can be used for replication between AD sites/DCs?  Say one DC in US and another one in China.  
Install AAD Connect on both Domain Controllers.  Can they be synced through AAD?  Or, has to be a direct connectivity?
0
[Webinar] Lessons on Recovering from Petya
LVL 10
[Webinar] Lessons on Recovering from Petya

Skyport is working hard to help customers recover from recent attacks, like the Petya worm. This work has brought to light some important lessons. New malware attacks like this can take down your entire environment. Learn from others mistakes on how to prevent Petya like worms.

i have developed small application in oracle 10g forms 6i .it's working rightly but i want to acess that application from another client pc which reside on different network how it can be done .
plz help me.
0
I am trying to see what the best way to assign vlans to my subnets. The below is what I was planning for with the 3rd octet as the vlan#:
- vlan 8 - 10.10.8.0/22 (10.10.8.1 - 10.10.11.254)
- vlan 18 - 10.10.12.0/22 (10.10.12.1 - 10.10.15.254)

But now we are breaking 10.10.8.0/22 to the below. Any tips on assigning the vlan #?
vlan8 - 10.10.8.0/28
vlan? - 10.10.8.16/28
vlan? - 10.10.8.32/27
vlan? - 10.10.8.64/26
0
for example check the nodes about flapping,down , restarting reasons etc
thanks
Nader Al-Kahtani
0
Hi There,

I have a requirement to forward all inbound and outbound for SMTP 25 (TLS)  email to Symantec message lab. This question is mixture of architecture and applying the right solution on F5.The requirement is to setup a VIP on F5.  My understanding is that the Traffic will be forwarded to our location, through our edge firewall (and NAT'd - public IP to private) to a private F5 VIP IP (with backend Exchange mail edge servers in a pool).  Additionally, we need to have our egress mail traffic (that is sourced from the edge pool members) reverse-proxy back through the same VIP IP address (currently used for ingress traffic).

We have internal and external F5s. Would the above scenario be best done on the LTM that's facing external? Also, do I need any iRules on F5?  Do you need specific natting on the F5s or just leave it as default.

Regards
Sam
0
Hi

I have a watchguard T30. Need to configure one of the Eth ports as a vlan port. The  need to connect the Eth port to a Huawei Layer 2 switch.

How do I configure the switch to allow for vlans?

Thank
0
Hi

I'm setting up a Huawei layer 2 switch Monday morning. Haven't done one of these before. I'm familiar with HP and Cisco. Could some one assist with some cli commands.

I need a few vlans configured and a trunk port from the firewall.

Thanks
0
Need some advice.  Upgrading my 10/100 network with about 50 device connections, to Gigabit and running new Cat6 Cabling.  It is a 2 story building, with all the connected devices on the 1st floor and the server room in the basement.  I was thinking of installing a switch and patch panel, centrally on the first floor and running a fiber trunk to the basement switch.  Does this sound reasonable?  Suggestions on switches and design?
0
I am looking for some good quality unmanaged network switch for my small business.

They will be running everything from Pcs to cameras.

I would like something of very good quality and reliability/

Best POE Silent 10/100 and Gigabit UnManaged Network Switch

Thank you.
robbie
0
Hello

I have a couple of WAN connections and used by few users to access company services like : Mail,Web Applications...etc.
Both Lines have "A" Records with our ISP. if one line is down,  is it possible to redirect the users to access services through the back up line ? or can you suggest best scenario ?

Best Regards
Mahmoud
0
Free Tool: Site Down Detector
LVL 10
Free Tool: Site Down Detector

Helpful to verify reports of your own downtime, or to double check a downed website you are trying to access.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Hi there, I need to create wifi network with official lan.
I need to now know to do it and things to keep in mind.

Also, It would be better if a person has to provide his official credentials to join the wifi group.

Regards
Anil Chauhan
0
Looking for better ideas than I already am working with:

What are the industry's best methods practiced to integrate 2 or more companies into a single cohesive infrastructure?
0
Debug info attached

I have configured a HP Procurve 3500 YL with the following Spanning Tree config:

spanning-tree
spanning-tree instance 2 vlan 109-285
spanning-tree instance 2 priority 0
spanning-tree priority 0

This config works well on other switches on our WAN. However, in this instance (only this switch), the topology count changes several times a minute. I believe it has something to do with ports 19 and 23. Each is configured with a single vlan and are directly connected to a Cisco 2960 switch. All others ports are connected to HP Aruba switches.

Ideas?
spanning-tree-debug
0
hi guys

I've installed a trial version of the network performance monitor from Solarwinds. However, it only discovered printers and switches/routers.

Can it discover PC's? Or do you need agents installed on them for it to discover those?

Thanks for helping
Yashy
0
I'm at a client which has an Internet feed from their Israel office which egresses in NYC. Nobody seems to know why it was put in that way. Might any experts on here with middle east experience know why you might want to egress on the other side of the Atlantic rather than just using a local ISP? Or at least Europe? Security issue? Tax issue? Something else??
0
Hi All,

We got Linksys LGS552p switch, and TZ400 Firewall.
behind a "AT&T Modem"  , but we have external IP for the TZ 400.

I need to setup VLANS, 90 for workstations, 20 or servers and 50 for voice.

am I missing any hardware to route between the VLANS?
where should I start with first?


thanks
Jason
0

Network Architecture

11K

Solutions

11K

Contributors

Network design and methodology, also known as network architecture, is the design of a communication network. It is a framework for the specification of a network's physical components and their functional organization and configuration, its operational principles and procedures, as well as data formats used in its operation. In telecommunication, the specification of a network architecture may also include a detailed description of products and services delivered via a communications network, as well as detailed rate and billing structures under which services are compensated.