Showing posts with label Networks. Show all posts
Showing posts with label Networks. Show all posts

0 TCP-IP architecture model

1. Network interface(Data link) layer
2. Network layer
3. Transport layer
4. Application layer


Network interface layer
The lowest layer of the TCP/IP model. Its task is to provide access to the transmission physical medium and it differs according to the implementation of the medium.

Network layer
The network layer provides network addressing, routing and datagram transmission. Used protocols that will be of interest further regarding DHCP are IP and ARP.

IP protocol
It is the basic protocol of the network layer and in general the internet as a whole. It sends datagrams, which are independent units that contain information about the destination, source and the sequence number of the datagram. The sequence number is used for message reconstruction, since the delivery order of the datagrams might not be the same as their order in the message and delivery reliability isn't guaranteed at all.
IP protocol versions:
" IP v4 - 32 bit addresses. Provides approximately 4 billion unique addresses which aren't sufficient at present times.
" IP v6 - 128 bit addresses. The transition to v6 will bring (is bringing) higher security, QoS, packet segmentation and many more IP addresses. (the transition from IP v4 to IP v6 must be supported by the system provider)


ARP protocol
The ARP abbreviation stands for Address Resolution Protocol. This protocol is used to find the physical address (MAC) based on a known IP address. If required ARP sends information concerning the wanted address to all the stations in the network - Broadcast. The stations consequently answer with a message containing their MAC. If the wanted device/station is outside the node/segment, the appropriate router will answer instead of it.

Transport layer
The transport layer is implemented only in terminal devices and it adjusts the behavior of the network according to the requirements of the device/application.



Application layer
The application layer is composed of programs that use net services to fulfill the needs of users. Examples of specific protocols are for instance FTP, DNS and DHCP.
Application protocols use TCP, UDP or both services at the same time. So called ports are used to differentiate between application protocols, they represent a type of label of the application. It is possible to change the ports in the settings of the service, but each service has a default port that isn't changed for most services and is used as an unwritten standard.

" FTP = 21
" DNS = 53
" DHCP = 67 + 68


Read more

0 Windows Server 2003 Active Directory and Network Infrastructure

It is a hierarchical representation of all the objects and their attributes available on the network. It enables administrators to manage the network resources, i.e., computers, users, printers, shared folders, etc., in an easy way. The logical structure represented by Active Directory consists of forests, trees, domains, organizational units, and individual objects. This structure is completely independent from the physical structure of the network, and allows administrators to manage domains according to the organizational needs without bothering about the physical network structure.

Following is the description of all logical components of the Active Directory structure:

Forest: A forest is the outermost boundary of an Active Directory structure. It is a group of multiple domain trees that share a common schema but do not form a contiguous namespace. It is created when the first Active Directory-based computer is installed on a network. There is at least one forest on a network. The first domain in a forest is called a root domain. It controls the schema and domain naming for the entire forest. It can be separately removed from the forest. Administrators can create multiple forests and then create trust relationships between specific domains in those forests, depending upon the organizational needs.

Trees: A hierarchical structure of multiple domains organized in the Active Directory forest is referred to as a tree. It consists of a root domain and several child domains. The first domain created in a tree becomes the root domain. Any domain added to the root domain becomes its child, and the root domain becomes its parent. The parent-child hierarchy continues until the terminal node is reached. All domains in a tree share a common schema, which is defined at the forest level. Depending upon the organizational needs, multiple domain trees can be included in a forest.


Domains: A domain is the basic organizational structure of a Windows Server 2003 networking model. It logically organizes the resources on a network and defines a security boundary in Active Directory. The directory may contain more than one domain, and each domain follows its own security policy and trust relationships with other domains. Almost all the organizations having a large network use domain type of networking model to enhance network security and enable administrators to efficiently manage the entire network.


Objects: Active Directory stores all network resources in the form of objects in a hierarchical structure of containers and subcontainers, thereby making them easily accessible and manageable. Each object class consists of several attributes. Whenever a new object is created for a particular class, it automatically inherits all attributes from its member class. Although the Windows Server 2003 Active Directory defines its default set of objects, administrators can modify it according to the organizational needs.


Organizational Unit (OU): It is the least abstract component of the Windows Server 2003 Active Directory. It works as a container into which resources of a domain can be placed. Its logical structure is similar to an organization's functional structure. It allows creating administrative boundaries in a domain by delegating separate administrative tasks to the administrators on the domain. Administrators can create multiple Organizational Units in the network. They can also create nesting of OUs, which means that other OUs can be created within an OU.
In a large complex network, the Active Directory service provides a single point of management for the administrators by placing all the network resources at a single place. It allows administrators to effectively delegate administrative tasks as well as facilitate fast searching of network resources. It is easily scalable, i.e., administrators can add a large number of resources to it without having additional administrative burden. It is accomplished by partitioning the directory database, distributing it across other domains, and establishing trust relationships, thereby providing users with benefits of decentralization, and at the same time, maintaining the centralized administration.

The physical network infrastructure of Active Directory is far too simple as compared to its logical structure. The physical components are domain controllers and sites.


Domain Controller: A Windows 2003 server on which Active Directory services are installed and run is called a domain controller. A domain controller locally resolves queries for information about objects in its domain. A domain can have multiple domain controllers. Each domain controller in a domain follows the multimaster model by having a complete replica of the domain's directory partition. In this model, every domain controller holds a master copy of its directory partition. Administrators can use any of the domain controllers to modify the Active Directory database. The changes performed by the administrators are automatically replicated to other domain controllers in the domain.

However, there are some operations that do not follow the multimaster model. Active Directory handles these operations and assigns them to a single domain controller to be accomplished. Such a domain controller is referred to as operations master. The operations master performs several roles, which can be forest-wide as well as domain-wide.

Forest-wide roles: There are two types of forest-wide roles:

Schema Master and Domain Naming Master. The Schema Master is responsible for maintaining the schema and distributing it to the entire forest. The Domain Naming Master is responsible for maintaining the integrity of the forest by recording additions of
Read more

0 IT Networks: How to Argue for a Bigger Budget

IT network managers have to fight the "if it ain't broke don't fix it" mindset to win resources. With computer networks, that mindset is dangerously complacent. IT networks will keep pumping data until they die or let in hackers. Here are some winning arguments against "if it ain't broke…"


IT Network Maintenance: Better Analogies
Don't let your IT network's budget get lumped with IT in general--or worse, operations in general. "If it ain't broke, don't fix it" sometimes makes sense in IT or operations. Upgrading workstations or desks can cost productivity, making it self-defeating.

You have to stress that IT networks are different from workstations or desks.
• IT networks are harder to repair.
• IT networks cannot be done without until fixed. You depend on them for email, web, file transfers, and in some organizations, printing, fax and telephone. If your network breaks you may be forced to rely on hand-written letters.
• IT network improvements rarely lower productivity on the front line. Instead, a faster, more reliable network can improve front-line productivity.
Here are the analogies you should stress to counter "if it ain't broke":
• Plumbing: IT networks will appear to function until they burst. The damage will be more expensive than maintenance ever could have been. In the meantime, you are losing productivity to all the little "leaks."
• Dams: If a poorly maintained IT network bursts, the eventual flood will harm overall productivity.
• War: There is no such thing as "good enough" when you are in competition. With an IT network, you're in a quiet arms race with hackers. You are also competing with your business competitors in terms of productivity.
• Health: Your IT network has to be in top physical condition. You can't make up for bad habits with a week or two of "rejuvenation." Meanwhile, your day-to-day performance will suffer.
• Cars: Don't wait for your IT network to conk out. Get a regular tune-up of up-to-date equipment.


IT Network Maintenance: What Can Go Wrong
Now, let's drive the point home. Here are some concrete, easy-to-explain reasons to keep your network up-to-date:
• Power supplies. Without redundant backups, your network is vulnerable to a shutdown. The lost productivity will make extra equipment seem inexpensive in comparison.
• Integrity. Faulty or contradictory data can break older networks. Newer equipment has solved these problems. Again, the potential cost of lost productivity makes newer equipment a good value.
• Firewalls. Hackers can leak trade secrets stolen from unprotected networks. Firewall software upgrades are relatively inexpensive.
• VOIP. Organizations worldwide are switching to VOIP--not just outside-line telephones but also switchboard and teleconferencing. If your network is out-of-date, it may fail when you eventually try this new technology.
• Speed. Older platforms such as 10BASET will throttle your bandwidth. You can now upgrade to a Terabit or more. Just think of the seconds, minutes, hours, and days lost as staff wait for email to arrive and web pages to load.
Final tip: show how cost-effective IT network maintenance really is. Get a firm cost estimate from a vendor. Just make sure your cost estimate is as competitive as it can be. You can often get new equipment at half the cost of retail by buying refurbished equipment.
Close your case for a better network with this wisdom: no matter what you pay, keeping your network up-to-date is cheaper than the consequences of letting it fall into disrepair.

Read more

0 How To Secure Your Wireless Network

People have more flexible time due to wireless network. Thanks to the invention of wireless. People can now work from home while taking care of their kids or doing house works. No more stress from traffic jam anymore. Is this great?

Well, there is something you should realize. Working from home while using a wireless local area network (WLAN) may lead to theft of sensitive information and hacker or virus infiltration unless proper measures are taken. As WLANs send information over radio waves, someone with a receiver in your area could be picking up the transmission, thus gaining access to your computer. They could load viruses on to your laptop which could be transferred to the company's network when you go back to work.

Believe it or not! Up to 75 per cent of WLAN users do not have standard security features installed, while 20 per cent are left completely open as default configurations are not secured, but made for the users to have their network up and running ASAP. It is recommended that wireless router/access point setup be always done though a wired client.

You can setup your security by follow these steps:

1. Change default administrative password on wireless router/access point to a secured password.

2. Enable at least 128-bit WEP encryption on both card and access point. Change your WEP keys periodically. If equipment does not support at least 128-bit WEP encryption, consider replacing it. Although there are security issues with WEP, it represents minimum level of security, and it should be enabled.

3. Change the default SSID on your router/access point to a hard to guess name. Setup your computer device to connect to this SSID by default.

4. Setup router/access point not to broadcast the SSID. The same SSID needs to be setup on the client side manually. This feature may not be available on all equipment.

5. Block anonymous Internet requests or pings. On each computer having wireless network card, network connection properties should be configured to allow connection to Access Point Networks Only. Computer to Computer (peer to peer) Connection should not be allowed.

Enable MAC filtering. Deny association to wireless network for unspecified MAC addresses. Mac or Physical addresses are available through your computer device network connection setup and they are physically written on network cards. When adding new wireless cards / computer to the network, their MAC addresses should be registered with the router /access point. Network router should have firewall features enabled and demilitarized zone (DMZ) feature disabled.

All computers should have a properly configured personal firewall in addition to a hardware firewall. You should also update router/access point firmware when new versions become available. Locating router/access point away from strangers is also helpful so they cannot reset the router/access point to default settings. You can even try to locate router/access point in the middle of the building rather than near windows to limit signal coverage outside the building.

There is no guarantee of a full protection of your wireless network, but following these suggested tips can definitely lessen your risk of exposing to attackers aiming at insecure networks.

Read more

0 Intranet Implementation: The Advantages Of A Web-Based Solution

The traditional approach to implementing an intranet is to purchase a software package, modify it for your needs, and install it on your system.

Over the past few years, another option has grown in popularity – the implementation of a web-based solution.

As you consider the choice between installed software and a web-based intranet, here are some considerations:


1.The most important requirement of any intranet is that everyone uses it.

To assure broad-based participation, the intranet must be easy to implement, simple to use, cost-effective to maintain, and offer each individual user the power to post, access and use content in a way that serves their specific needs. In short, the intranet must have value to everyone.

Web-based intranets are designed around this concept. The interface and navigation are consistent with their use of the web – an environment in which they feel in control, using familiar tools.

In contrast, the business world is littered with countless elegant and feature-rich soft-ware based intranets that have failed. Why? Because they represented an alien environment into which the user was expected to venture. Few employees had the time or the interest (or courage) to enter, rendering the intranet impotent, with the powerful tools unused.

This is the plight of traditional, out-of-the-box software solutions. Unlike web-based intranets, they force users into a constrained environment requiring in-depth training, built around rules designed for the group, rather than the individual.


2. Software intranets have unpredictable costs: in time, attention and money.

Software based solutions require extensive internal support. The ongoing expense in both staff time and money takes the focus of your IT group away from mission-critical tasks.

System integration, Implementation, maintenance, technology upgrades, training and user support are all on-going tasks that represent a significant, recurring investment. The cost can be substantial, far exceeding your initial license cost and monthly fee.


3. Web-based intranets offer a predictable cost and cutting-edge technology.

Most web-based solutions offer a fixed monthly fee that covers all maintenance, technology upgrades, training and user support. The costs are predictable, the technology evolutionary, and it's all done with minimal involvement of your IT staff.

It's for these reasons that companies needing broad-based participation in a changing environment are choosing web-based intranets over traditional software solutions.

Read more

Delete this element to display blogger navbar

 
© TECHNO FILES | Design by Blog template in collaboration with Concert Tickets, and Menopause symptoms
Powered by Blogger