Your SlideShare is downloading. ×
0
Download It
Download It
Download It
Download It
Download It
Download It
Download It
Download It
Download It
Download It
Download It
Download It
Download It
Download It
Download It
Upcoming SlideShare
Loading in...5
×

Thanks for flagging this SlideShare!

Oops! An error has occurred.

×
Saving this for later? Get the SlideShare app to save on your phone or tablet. Read anywhere, anytime – even offline.
Text the download link to your phone
Standard text messaging rates apply

Download It

166

Published on

0 Comments
0 Likes
Statistics
Notes
  • Be the first to comment

  • Be the first to like this

No Downloads
Views
Total Views
166
On Slideshare
0
From Embeds
0
Number of Embeds
0
Actions
Shares
0
Downloads
1
Comments
0
Likes
0
Embeds 0
No embeds

Report content
Flagged as inappropriate Flag as inappropriate
Flag as inappropriate

Select your reason for flagging this presentation as inappropriate.

Cancel
No notes for slide

Transcript

  • 1. Management Solution for Cisco NG Advanced Security Services IPSec & virtual Firewall Management solution October 2007
  • 2. Dorado Software: Redcell Management SW <ul><li>A certified Cisco Technology development Partner </li></ul><ul><li>Develop specialized product packages that address Cisco-specific IT infrastructure features as part of the Redcell Security Services Management Solution </li></ul>
  • 3. Redcell Security Services Management Overview - Cisco Edition - <ul><li>Enhance Cisco’s network based security and managed security solutions by providing a scalable and easy to use GUI based provisioning and monitoring system. </li></ul><ul><ul><li>Provide an easy to use, graphical based, heterogeneous network and service management system </li></ul></ul><ul><ul><li>Perform centralized configuration management </li></ul></ul><ul><ul><li>Flow-through automated provisioning, decrease service activation time and decrease errors associated with manual tasks </li></ul></ul>Cisco XR 12000 SPA-IPSEC 12x06 12x16 12x10 12x04
  • 4. Redcell Security Services Management – Cisco Edition - <ul><li>Manage XR-12K based vFW services on MSB and IPsec services on VPN SPA </li></ul><ul><li>Provides scalable and easy to use GUI based provisioning and monitoring system </li></ul><ul><ul><li>Overall management of the MSB </li></ul></ul><ul><ul><li>Overall management of the VPN SPA </li></ul></ul><ul><ul><li>Management of VRF-Aware Service Interface (VASI) </li></ul></ul><ul><ul><li>Management of vFW </li></ul></ul><ul><ul><li>Management of IPsec and GRE </li></ul></ul><ul><ul><li>Management of Service Policies </li></ul></ul>
  • 5. vFW Services Management Solution - Detailed <ul><li>Detailed Discovery and Asset Management of Cisco XR 12000 device </li></ul><ul><ul><li>Topology (logical & geographical) of all discovered devices </li></ul></ul><ul><ul><li>Device level configuration (FW, VASI, Blade HA) </li></ul></ul><ul><ul><li>Fault Management </li></ul></ul><ul><ul><li>Performance Management (vFW MIB support) </li></ul></ul><ul><li>Advanced configuration of Cisco XR-12K Multi-Service Blade (MSB) </li></ul><ul><ul><li>Discovery of the MSB (Context, Resource classes, Interfaces, ACLs, HA) </li></ul></ul><ul><ul><li>Inventory (Physical & Logical) of the MSB </li></ul></ul><ul><li>Centralized Service Allocation and Provisioning for Service / Security policies </li></ul><ul><ul><li>ACLs </li></ul></ul><ul><ul><li>NAT / PAT </li></ul></ul><ul><ul><li>Inspections </li></ul></ul><ul><li>Upgrade & Patch </li></ul><ul><ul><li>Firmware / Software </li></ul></ul><ul><ul><li>Security Patches </li></ul></ul><ul><li>Change Management </li></ul><ul><ul><li>Firewall context and ACL changes </li></ul></ul>12x06 12x16 12x10 12x04
  • 6. vFW Services Management Solution - Workflow <ul><ul><li>Discovery – Bring all the target devices under management by Redcell </li></ul></ul><ul><ul><li>(Optional) – Create network objects for use in Redcell Service Policies </li></ul></ul><ul><ul><li>(Optional) – Create VASI for use within the vFW </li></ul></ul><ul><ul><li>Create the vFW service, which creates the context. This includes fault tolerance configuration, FMI assignment, Resource Class configuration, and interface configuration </li></ul></ul><ul><ul><li>Create (multiple) Service Policies for use with the context. This includes ACLs, NAT/PAT (via multimatch), management policies, and inspection (FTP/HTTP) policies </li></ul></ul>
  • 7. Typical Deployment at the PoP P CRS-12000 CRS-1 PE PE PE PE I P P P SP CORE PE XR-12000 <ul><li>FW Services are provided at the customer facing interface </li></ul><ul><li>Stateful FW Intra-chassis HA support </li></ul><ul><li>Service Configuration & Network Management by Dorado Software – Redcell solution </li></ul>CE vFW NAT Dorado Software Access network Transit / Distribution Core Peering PoP XB XB XB XB
  • 8. IPSec Services Management Solution - Detailed <ul><li>Detailed Discovery and Asset Management of Cisco XR 12000 device </li></ul><ul><ul><li>Topology (logical & geographical) of all discovered devices </li></ul></ul><ul><ul><li>Device level configuration </li></ul></ul><ul><ul><li>Fault Management </li></ul></ul><ul><ul><li>Performance Management (IPSec MIB support) </li></ul></ul><ul><li>Advanced configuration of Cisco XR 12000 IPSec VPN SPA </li></ul><ul><ul><li>Discovery of the IPSec VPN SPA (ISAKMP, IPSec, PKI, Failover, ACL, Service Tunnel) </li></ul></ul><ul><ul><li>Inventory (Physical & Logical) of the IPSec VPN SPA </li></ul></ul><ul><li>Service Allocation and Provisioning for IPSec / ISAKMP VPNs </li></ul><ul><ul><li>Including IPSec + GRE tunnels </li></ul></ul><ul><ul><li>Remote Access / EZ-VPN </li></ul></ul><ul><li>Upgrade & Patch </li></ul><ul><ul><li>Firmware / Software </li></ul></ul><ul><ul><li>Security Patches </li></ul></ul><ul><li>Change Management </li></ul><ul><ul><li>IPSec + GRE service interfaces </li></ul></ul><ul><ul><li>ISAKMP configuration </li></ul></ul>Cisco XR 12000 SPA-IPSEC 12x06 12x16 12x10 12x04
  • 9. IPSec Services Management Solution - Workflow <ul><ul><li>Discovery – Bring all the target devices under management by Redcell </li></ul></ul><ul><ul><li>(Optional) Create Service templates for use in the service </li></ul></ul><ul><ul><li>Configure (multiple) IPSec customer sites as the service endpoints </li></ul></ul><ul><ul><li>Provision the IPSec (or IPSec / GRE) service </li></ul></ul>Cisco XR 12000 SPA-IPSEC
  • 10. Redcell Lifecycle Management Features – Cisco Edition - <ul><li>Visibility; </li></ul><ul><li>Configuration file back-up and restoration; </li></ul><ul><li>Software (OS) release management; </li></ul><ul><li>Comprehensive logging & auditing; </li></ul><ul><li>Service & device health monitoring; </li></ul><ul><li>Change detection & remediation; </li></ul><ul><li>Event management & automation; </li></ul><ul><li>Graphical service, network, and device topology; </li></ul><ul><li>Service provisioning; and </li></ul><ul><li>Comprehensive reporting on everything! </li></ul>Redcell offers complete lifecycle management
  • 11. Redcell Lifecycle Management Features – Cisco Edition - Deep Discovery and Resynchronization Discover entire environment many different ways including via subnet, IP range, IP address or host name. Deep discovery all H/W, S/W, physical, and logical subcomponents. Inventory View Single database and Graphical User Interface (GUI) of complete device assets for consistent IPsec and Firewall service configuration and activation Equipment Group Management Create static, dynamic, nested, and mixed groups for applying one-to-many changes to disparate network devices and group reporting Discrete Configuration Real-time discrete configuration of devices via GUI Active Configuration Graphical scripting / command-based configuration Configuration File Management Device configuration file backup, restore, view, edit, delete and compare. Template-based creation and management of full or partial, configlet, configuration files.
  • 12. Redcell Lifecycle Management Features – Cisco Edition - Device Asset Topology Hierarchical visual mapping with alarm propagation. Visualize interrelationships of managed systems and underlying infrastructure down to the interconnect level. Task/ Job Scheduler Perform functions and tasks at scheduled times and intervals Audit Trail Record all actions – system, user, device Monitoring Performance monitoring (SNMP data collection & graphing, primarily used for thresholding), event/alarm monitoring (syslog/SNMP traps), and service monitoring (correlates SNP and Syslog events to defined services for service monitoring , as service-affecting alarms) Reporting Flexible template-based inventory reporting by device, subcomponent, and service. Exportable to .csv, html, .pdf formats User Security Management Multi-level security for individual user and group administration OSS interface <ul><ul><li>Web services/SOAP (XML) and SNMP trap forwarding </li></ul></ul>
  • 13. <ul><li>Application Server </li></ul><ul><ul><li>Solaris SunFire V240 with Dual 1.34 GHz CPU </li></ul></ul><ul><ul><li>Windows Pentium 4, 3.2 GHz CPU </li></ul></ul><ul><ul><li>2 GB RAM / 20 GB available disk space </li></ul></ul><ul><li>Mediation Server </li></ul><ul><ul><li>Solaris SunFire V240 with Dual 1.34 GHz CPU </li></ul></ul><ul><ul><li>Windows Pentium 4, 3.2 GHz CPU </li></ul></ul><ul><ul><li>2 GB RAM / 10 GB available disk space </li></ul></ul><ul><li>Database Server (Oracle) </li></ul><ul><ul><li>Solaris SunFire V440 with Quad 1.593 GHz CPU </li></ul></ul><ul><ul><li>4 GB RAM / 20 GB available disk space </li></ul></ul>Hardware Requirements – Cisco Edition -
  • 14. Clustered Server High Availability Deployment Options – Cisco Edition -
  • 15. Contacts <ul><li>Redcell Security Services Management – Cisco Edition - link </li></ul><ul><ul><li>www.doradosoftware.com/ciscoSecurity </li></ul></ul><ul><li>For additional information please contact </li></ul><ul><ul><li>[email_address] </li></ul></ul>

×