Gigamon U - WAN, LAN, and now the DAN

17
LAN, WAN, SAN, and now DAN D ata A ccess N etwork

description

The DAN or Data Access Network is a newly emerging "best practice" for passive monitoring of mission critical networks that solves real access problems, improves network performance and uptime, and saves capital, operation and maintenance costs. A DAN is a combination of out-of-band data access switching plus passive monitoring instrumentation to enable required security, compliance, forensics review, application performance, VoIP QoS, uptime and other network management tasks. Data is acquired from multiple SPAN ports or taps and multicast to multiple tools, aggregated to a few consolidated tools, and filtered or divided across many instances of the same tools. The DAN may be thought of as a Òdata socketÓ providing immediate access for ad hoc tool deployment without impact to the production network and outside of the scope of configuration management policies.

Transcript of Gigamon U - WAN, LAN, and now the DAN

Page 1: Gigamon U - WAN, LAN, and now the DAN

LAN, WAN, SAN,and now

DANData Access Network

Page 2: Gigamon U - WAN, LAN, and now the DAN

What’s a DAN?out-of-band passive monitoring network

Includes passive tools like: Security IDS Sensors,

Application Performance Monitors,

Troubleshooting Protocol Analyzers,

VoIP QoS Probes,

Forensic Recorders,

and Data Access Switching

Prop

rieta

ry &

Con

fiden

tial

Page 3: Gigamon U - WAN, LAN, and now the DAN

Prop

rieta

ry &

Con

fiden

tial

3

DAN provides “Data Sockets”Part of a Flexible Network Infrastructure

• Plug-in multiple out-of-band tools – ANY data to ANY tool• Unobtrusive 24x7 tool connections – never touch the network• Aggregate, Replicate, Filter and load balance data streams• Use legacy 1Gig tools to monitor new 10Gig networks

Page 4: Gigamon U - WAN, LAN, and now the DAN

Why are DANs Needed Now?Things Have Changed

Enron and 9/11 spawned SOX auditing, increased security

and lawful intercept requirement

PLUS technology and business developments:Web site e-commerce and internet applications demand support

VoIP and media convergence make the network more strategic

Green networking demands smaller Data Center footprint

Network is how business gets done. Downtime is unacceptable

Prop

rieta

ry &

Con

fiden

tial

Page 5: Gigamon U - WAN, LAN, and now the DAN

New SOX compliance transaction monitors Keep your boss out of jail!

IDS Sensors detect external attacksFrom hackers

NAC appliance protects networks from insideFrom your own people!

CALEA lawful intercept and Forensic Recorders

Configuration monitoring tools watch over network resources

Application and Network troubleshooting

Prop

rieta

ry &

Con

fiden

tial

Proliferation of Tools

Page 6: Gigamon U - WAN, LAN, and now the DAN

Prop

rieta

ry &

Con

fiden

tial

Proliferation Causes Contention for Span Ports

Security and IT Engineers seen

here “Negotiating” Over

a SPAN Port

Page 7: Gigamon U - WAN, LAN, and now the DAN

Prop

rieta

ry &

Con

fiden

tial

An Analogy:

Using a DAN is like using a power strip.

Page 8: Gigamon U - WAN, LAN, and now the DAN

Prop

rieta

ry &

Con

fiden

tial

Too Many Power Tools? Not Enough Sockets?

?

??

?

Page 9: Gigamon U - WAN, LAN, and now the DAN

Prop

rieta

ry &

Con

fiden

tial

For Power Tools, use a Power Strip

Page 10: Gigamon U - WAN, LAN, and now the DAN

Prop

rieta

ry &

Con

fiden

tial

Too Many Monitoring Tools? Not Enough Span Ports?

?

?

?

?

Page 11: Gigamon U - WAN, LAN, and now the DAN

Prop

rieta

ry &

Con

fiden

tial

For Sensors/Monitors/Analyzers,Use a DAN Switch

One Span port serves Many tools

Page 12: Gigamon U - WAN, LAN, and now the DAN

What Other Problems do DANssolve?

Distributed Monitoring burning the budget?Consolidate tools; $ave money on capital and operational budgets

Unsecure monitor or tap ports risk data leakage?DAN can secure all access point to prevent snooping

Too much traffic for one tool? Reduce and balance load over multiple units to match tool capacity

Restrictive Configuration Management Policies?Deploy tools and make changes on your own schedule

Prop

rieta

ry &

Con

fiden

tial

Page 13: Gigamon U - WAN, LAN, and now the DAN

Prop

rieta

ry &

Con

fiden

tial

Monitoring a Mesh Network?

Page 14: Gigamon U - WAN, LAN, and now the DAN

Prop

rieta

ry &

Con

fiden

tial

Old Solution: Lots of Distributed Tools,Deploy one tool per span port/switch

Lots of hardware…very expensive!

Page 15: Gigamon U - WAN, LAN, and now the DAN

Prop

rieta

ry &

Con

fiden

tial

Better: Distribute Connections with a DANConsolidate Tools; Save CapEx $$$

Aggregate and balance flows to Consolidated Tools

Page 16: Gigamon U - WAN, LAN, and now the DAN

DAN is “Best Practice” for Network Infrastructure Design

Totally flexible solution to many problems

Facilitates unobtrusive instrumentation of a network

Solves requirement for multiple tool access

Gives tools the view of the total network

Secures monitor and tap ports

Improves monitor coverage, saves time and money.

Prop

rieta

ry &

Con

fiden

tial

Page 17: Gigamon U - WAN, LAN, and now the DAN

DAN Solves Access Problems By

• Aggregating many links to any tool

• Multicasting any link to many tools

• Filtering data to map packets to tools

• Saving $$ Cap Ex and Op Ex budget$

Any to Any Any to ManyMany to Any Bit-Mask Filtering

Prop

rieta

ry &

Con

fiden

tial