SlideShare a Scribd company logo
S#$% My Network Says
Jim Gogan - ITS Communication Technologies
CTC Retreat - October 21, 2010
“Nervous? In 5 billion years the sun will burn out
and nothing you did will matter. Feel better?”
its.unc.edu 2
 Overall performance ultimately depends on the
weakest components
“A parent’s only as good as their dumbest kid. If one wins a Nobel
Prize but the other gets robbed by a hooker, you failed”
 Chosing specific network equipment keeps
getting more challenging
“ You don’t have to be good to succeed. You just gotta be the least
crappy option. Example: We’re eating at The Olive Garden.”
Network Architecture
its.unc.edu 3
Network Architecture
 BIG …… really big …..
its.unc.edu 4
Changes to Intrusion Prevention
Systems (Tipping Points)
 New 10 Gbps inline systems installed at the two campus
border points – first time we’ve had complete IPS
coverage at the border (where approx. 98% of the
attacks are seen)
 Allows us to do a phased removal of the majority of
internal IPS/TP units, primarily at the distribution
layer; to date, Phillips, Franklin and Kenan Labs Tier 1s
are gone
 Removals will generally produce noticeable
performance improvements on inter-subnet traffic
“Sometimes it’s nice having you around. But now ain’t one of those times.”
its.unc.edu 5
Wi-Fi Networking
 Continues to be an “a la carte” service at
$1200 per access point
 Continues to be based on really, really
moronic technologies and vendor
implementations
“No one cares about all the things your smartphone does. You didn’t invent
it, you just bought it. Anybody can do that. Oh, and there’s a 50/50 chance it
won’t work with WEP”
its.unc.edu 6
TAR-WAP
 Teaching and Research Wireless
Activation Project
• Proposals from faculty requesting AP installation in designated
rooms specifically for teaching and/or research activities
• Search http://help.unc.edu for TAR-WAP for details
• Include in proposal:
 Specific academic course/research activity requesting
connectivity
 Summary of how Wi-Fi would be used
 Approx. number of concurrent students
 Commitment to provide feedback to ITS
its.unc.edu 7
TAR-WAP Installations since
Sept 2009
• Morehead Planetarium -- Remedy ticket 1563220
• Peabody 306
• Coker 201 -- Remedy ticket 1611676
• Fordham Hall Conference Rooms -- Remedy ticket 1618907
• Swain Hall -- Remedy ticket 1611710
• Med School Wing Classrooms -- Remedy ticket 1618892
• Baity Laboratory Building - SPH -- Remedy ticket 1626497
• Michael Hooker Research Center - Nutrition-SPH -- Remedy ticket 1626497
• Mitchell Hall - Geological Sciences -- Remedy ticket 1680602
• Alumni Building - Archaeology and Anthropology -- Remedy ticket 1678032
• Coker Hall - UNC Herbarium -- Remedy ticket 1698584
• Carolina Center for Educational Excellence - School of Education -- Remedy ticket 1701652
• Wilson Library 318 - CFE Training Facility -- Remedy ticket 1745944
• School of Medicine - Bondurant and MBRB Auditoriums -- Remedy ticket 1720461
• Burnett-Womack - Division of Radiologic Science -- Remedy ticket 1519846
• Peabody Hall Rm 02 - School of Education -- Remedy ticket 1749683
• Peabody Hall 206 and 211 - School of Education -- Remedy ticket 1764506
• Phillips Hall - Physics-SCALE-UP -- Remedy ticket 1719892
• Coker Hall - Biology -- Remedy ticket 1839960
• Coates Building - Geography Research Labs -- Remedy ticket 1839941
its.unc.edu 8
Network Management
 Growing use of “NetFlow” collectors
its.unc.edu 9
Network Management – More
(Can’t Have Too Much)
 Continued
evolution and
testing of NAC
(Network Access
Control)
 Continued
evolution of NIT
(Network
Information
Tool)
its.unc.edu 10
Neutral Hosting Project
 Installation of advanced campus-wide DAS (Distributed Antenna
System) to provide uniform outdoor and in-building wireless
mobile coverage (voice, data and beyond)
 Project has been underway for the past 3+ years
 Final construction design plans (for all sites except Kenan Stadium
and the Smith Center) now under final internal review process—
expect submission to State Construction Office for approval the
first week in November.
 Remaining sites (Kenan and Smith Center) will be finalized in
November.
 Construction start targeted for first quarter 2011.
 AT&T, T-Mobile and Verizon participating—Sprint currently dealing
with budgetary issues—will probably join sometime in 2011.
 100% funded by the carriers
its.unc.edu 11
Campus Voice Services
 New AVST voice messaging platform installed in April 2010
• Will provide unified messaging, virtual fax and other
advanced features
• Links campus voicemail once again with UNC Healthcare
 Current AT&T Centrex contract expires in March 2011
 Comprehensive voice services RFP released in May 2010
 Interdepartmental RFP response evaluation team now
reviewing vendor proposals—final recommendation due in
November
 IT governance committee working on new rate model
proposal—separates funding sources for core campus services
(networking) from optional services (telephony services)
its.unc.edu 12
Working with Network Vendors
 Really? REALLY????
• You want a complete network diagram of all nodes on the
campus network? Really??
• You design a product that sends ARP requests for hosts not on
the local network? Really??
• You build a switch with 10Gb ports, but the ASIC is designed
only to multiplex 1Gb flows? Really?!?
• You say that a core router module is having problems because
of “vibrations”? REALLY?!?!?!
• You add two new promised features, but introduce three new
bugs? REALLY?????????
“ There’s a word for people like that … No, I’m saying, there’s a word and I
don’t know what it is. I’m not being poetic”
“Sometimes life leaves a hundred dollar bill on your dresser, and you
don’t realize until later that it’s because it screwed you”
its.unc.edu 13
Working with You
 Great user support COMMUNITY!!!
• Knowledgeable, responsive and inquisitive
 We love seeing NIT results in tickets
 PLEASE send tickets (with IP/MAC address info)
instead of phone calls
“Why would I want to check a voicemail on my phone? People want
to talk to me, call again. If I want to talk to you, I’ll answer.”
its.unc.edu
Thank you!

More Related Content

Similar to S#$% My Network Says (CTC Retreat 2010)

Building a Regional 100G Collaboration Infrastructure
Building a Regional 100G Collaboration InfrastructureBuilding a Regional 100G Collaboration Infrastructure
Building a Regional 100G Collaboration Infrastructure
Larry Smarr
 
Science DMZ as a Service: Creating Science Super- Facilities with GENI
Science DMZ as a Service: Creating Science Super- Facilities with GENIScience DMZ as a Service: Creating Science Super- Facilities with GENI
Science DMZ as a Service: Creating Science Super- Facilities with GENI
US-Ignite
 
First time principals
First time principalsFirst time principals
First time principals
Douglas Harré
 
The Pacific Research Platform: a Science-Driven Big-Data Freeway System
The Pacific Research Platform: a Science-Driven Big-Data Freeway SystemThe Pacific Research Platform: a Science-Driven Big-Data Freeway System
The Pacific Research Platform: a Science-Driven Big-Data Freeway System
Larry Smarr
 
GAMMON at GAETC
GAMMON at GAETCGAMMON at GAETC
GAMMON at GAETC
warrenalecmatthews
 
DISTRIBUTED NETWORKING - By Hansa Edirisinghe
DISTRIBUTED NETWORKING - By Hansa EdirisingheDISTRIBUTED NETWORKING - By Hansa Edirisinghe
DISTRIBUTED NETWORKING - By Hansa Edirisinghe
Hansa Edirisinghe
 
Topic 1 introduction
Topic 1 introductionTopic 1 introduction
Topic 1 introduction
SangeethaBg
 
AAP Part I DeliverableHere is the assignment to be comple.docx
AAP Part I DeliverableHere is the assignment to be comple.docxAAP Part I DeliverableHere is the assignment to be comple.docx
AAP Part I DeliverableHere is the assignment to be comple.docx
annetnash8266
 
Science Engagement: A Non-Technical Approach to the Technical Divide
Science Engagement: A Non-Technical Approach to the Technical DivideScience Engagement: A Non-Technical Approach to the Technical Divide
Science Engagement: A Non-Technical Approach to the Technical Divide
Cybera Inc.
 
Datacom module 1: Introduction to Data Communications
Datacom module 1:  Introduction to Data CommunicationsDatacom module 1:  Introduction to Data Communications
Datacom module 1: Introduction to Data Communications
Jeffrey Des Binwag
 
Challenges and Opportunities in Deploying IPv6, DNSSEC, and Other Key Technol...
Challenges and Opportunities in Deploying IPv6, DNSSEC, and Other Key Technol...Challenges and Opportunities in Deploying IPv6, DNSSEC, and Other Key Technol...
Challenges and Opportunities in Deploying IPv6, DNSSEC, and Other Key Technol...
Internet Society
 
Challenges and Opportunities in Deploying IPv6, DNSSEC, and Other Key Technol...
Challenges and Opportunities in Deploying IPv6, DNSSEC, and Other Key Technol...Challenges and Opportunities in Deploying IPv6, DNSSEC, and Other Key Technol...
Challenges and Opportunities in Deploying IPv6, DNSSEC, and Other Key Technol...
Deploy360 Programme (Internet Society)
 
Challenges and Opportunities in Deploying IPv6, DNSSEC, and Other Key Technol...
Challenges and Opportunities in Deploying IPv6, DNSSEC, and Other Key Technol...Challenges and Opportunities in Deploying IPv6, DNSSEC, and Other Key Technol...
Challenges and Opportunities in Deploying IPv6, DNSSEC, and Other Key Technol...
Deploy360 Programme (Internet Society)
 
Vehicular Content Centric Network (VCCN): A Survey and Research Challenges
Vehicular Content Centric Network (VCCN): A Survey and Research ChallengesVehicular Content Centric Network (VCCN): A Survey and Research Challenges
Vehicular Content Centric Network (VCCN): A Survey and Research Challenges
Syed Hassan Ahmed
 
The Pacific Research Platform: A Science-Driven Big-Data Freeway System
The Pacific Research Platform: A Science-Driven Big-Data Freeway SystemThe Pacific Research Platform: A Science-Driven Big-Data Freeway System
The Pacific Research Platform: A Science-Driven Big-Data Freeway System
Larry Smarr
 
The Pacific Research Platform:a Science-Driven Big-Data Freeway System
The Pacific Research Platform:a Science-Driven Big-Data Freeway SystemThe Pacific Research Platform:a Science-Driven Big-Data Freeway System
The Pacific Research Platform:a Science-Driven Big-Data Freeway System
Larry Smarr
 
Challenges in end-to-end performance
Challenges in end-to-end performanceChallenges in end-to-end performance
Challenges in end-to-end performance
Jisc
 
An Integrated West Coast Science DMZ for Data-Intensive Research
An Integrated West Coast Science DMZ for Data-Intensive ResearchAn Integrated West Coast Science DMZ for Data-Intensive Research
An Integrated West Coast Science DMZ for Data-Intensive Research
Larry Smarr
 

Similar to S#$% My Network Says (CTC Retreat 2010) (20)

Building a Regional 100G Collaboration Infrastructure
Building a Regional 100G Collaboration InfrastructureBuilding a Regional 100G Collaboration Infrastructure
Building a Regional 100G Collaboration Infrastructure
 
Science DMZ as a Service: Creating Science Super- Facilities with GENI
Science DMZ as a Service: Creating Science Super- Facilities with GENIScience DMZ as a Service: Creating Science Super- Facilities with GENI
Science DMZ as a Service: Creating Science Super- Facilities with GENI
 
First time principals
First time principalsFirst time principals
First time principals
 
The Pacific Research Platform: a Science-Driven Big-Data Freeway System
The Pacific Research Platform: a Science-Driven Big-Data Freeway SystemThe Pacific Research Platform: a Science-Driven Big-Data Freeway System
The Pacific Research Platform: a Science-Driven Big-Data Freeway System
 
GAMMON at GAETC
GAMMON at GAETCGAMMON at GAETC
GAMMON at GAETC
 
DISTRIBUTED NETWORKING - By Hansa Edirisinghe
DISTRIBUTED NETWORKING - By Hansa EdirisingheDISTRIBUTED NETWORKING - By Hansa Edirisinghe
DISTRIBUTED NETWORKING - By Hansa Edirisinghe
 
Topic 1 introduction
Topic 1 introductionTopic 1 introduction
Topic 1 introduction
 
AAP Part I DeliverableHere is the assignment to be comple.docx
AAP Part I DeliverableHere is the assignment to be comple.docxAAP Part I DeliverableHere is the assignment to be comple.docx
AAP Part I DeliverableHere is the assignment to be comple.docx
 
[.ppt]
[.ppt][.ppt]
[.ppt]
 
Naveen Resume
Naveen ResumeNaveen Resume
Naveen Resume
 
Science Engagement: A Non-Technical Approach to the Technical Divide
Science Engagement: A Non-Technical Approach to the Technical DivideScience Engagement: A Non-Technical Approach to the Technical Divide
Science Engagement: A Non-Technical Approach to the Technical Divide
 
Datacom module 1: Introduction to Data Communications
Datacom module 1:  Introduction to Data CommunicationsDatacom module 1:  Introduction to Data Communications
Datacom module 1: Introduction to Data Communications
 
Challenges and Opportunities in Deploying IPv6, DNSSEC, and Other Key Technol...
Challenges and Opportunities in Deploying IPv6, DNSSEC, and Other Key Technol...Challenges and Opportunities in Deploying IPv6, DNSSEC, and Other Key Technol...
Challenges and Opportunities in Deploying IPv6, DNSSEC, and Other Key Technol...
 
Challenges and Opportunities in Deploying IPv6, DNSSEC, and Other Key Technol...
Challenges and Opportunities in Deploying IPv6, DNSSEC, and Other Key Technol...Challenges and Opportunities in Deploying IPv6, DNSSEC, and Other Key Technol...
Challenges and Opportunities in Deploying IPv6, DNSSEC, and Other Key Technol...
 
Challenges and Opportunities in Deploying IPv6, DNSSEC, and Other Key Technol...
Challenges and Opportunities in Deploying IPv6, DNSSEC, and Other Key Technol...Challenges and Opportunities in Deploying IPv6, DNSSEC, and Other Key Technol...
Challenges and Opportunities in Deploying IPv6, DNSSEC, and Other Key Technol...
 
Vehicular Content Centric Network (VCCN): A Survey and Research Challenges
Vehicular Content Centric Network (VCCN): A Survey and Research ChallengesVehicular Content Centric Network (VCCN): A Survey and Research Challenges
Vehicular Content Centric Network (VCCN): A Survey and Research Challenges
 
The Pacific Research Platform: A Science-Driven Big-Data Freeway System
The Pacific Research Platform: A Science-Driven Big-Data Freeway SystemThe Pacific Research Platform: A Science-Driven Big-Data Freeway System
The Pacific Research Platform: A Science-Driven Big-Data Freeway System
 
The Pacific Research Platform:a Science-Driven Big-Data Freeway System
The Pacific Research Platform:a Science-Driven Big-Data Freeway SystemThe Pacific Research Platform:a Science-Driven Big-Data Freeway System
The Pacific Research Platform:a Science-Driven Big-Data Freeway System
 
Challenges in end-to-end performance
Challenges in end-to-end performanceChallenges in end-to-end performance
Challenges in end-to-end performance
 
An Integrated West Coast Science DMZ for Data-Intensive Research
An Integrated West Coast Science DMZ for Data-Intensive ResearchAn Integrated West Coast Science DMZ for Data-Intensive Research
An Integrated West Coast Science DMZ for Data-Intensive Research
 

More from Gary Wilhelm

Transitions and Extensions – What Schools Have Learned from Sakai Migrations
Transitions and Extensions – What Schools Have Learned from Sakai Migrations Transitions and Extensions – What Schools Have Learned from Sakai Migrations
Transitions and Extensions – What Schools Have Learned from Sakai Migrations Gary Wilhelm
 
Go go gadgets! Implementing a technology collection for staff use
Go go gadgets! Implementing a technology collection for staff useGo go gadgets! Implementing a technology collection for staff use
Go go gadgets! Implementing a technology collection for staff use
Gary Wilhelm
 
Using Dataverse Virtual Archive Technology for Research Data Management
Using Dataverse Virtual Archive Technology for Research Data ManagementUsing Dataverse Virtual Archive Technology for Research Data Management
Using Dataverse Virtual Archive Technology for Research Data Management
Gary Wilhelm
 
Network Attached Storage (NAS) Initiative
Network Attached Storage (NAS) Initiative Network Attached Storage (NAS) Initiative
Network Attached Storage (NAS) Initiative
Gary Wilhelm
 
Supporting your remote clients with bomgar
Supporting your remote clients with bomgarSupporting your remote clients with bomgar
Supporting your remote clients with bomgar
Gary Wilhelm
 
After the Breach
After the BreachAfter the Breach
After the Breach
Gary Wilhelm
 
Virtualization and you: where are we?
Virtualization and you: where are we?Virtualization and you: where are we?
Virtualization and you: where are we?
Gary Wilhelm
 
Online Copyright Education
Online Copyright EducationOnline Copyright Education
Online Copyright Education
Gary Wilhelm
 
Leveraging Centralized IT Support Services as a First Point of Contact
Leveraging Centralized IT Support Services as a First Point of ContactLeveraging Centralized IT Support Services as a First Point of Contact
Leveraging Centralized IT Support Services as a First Point of Contact
Gary Wilhelm
 
Building Cyber-infrastructure at UNC-CH
Building Cyber-infrastructure at UNC-CHBuilding Cyber-infrastructure at UNC-CH
Building Cyber-infrastructure at UNC-CH
Gary Wilhelm
 
Network Attached Storage Initiative
Network Attached Storage InitiativeNetwork Attached Storage Initiative
Network Attached Storage Initiative
Gary Wilhelm
 

More from Gary Wilhelm (11)

Transitions and Extensions – What Schools Have Learned from Sakai Migrations
Transitions and Extensions – What Schools Have Learned from Sakai Migrations Transitions and Extensions – What Schools Have Learned from Sakai Migrations
Transitions and Extensions – What Schools Have Learned from Sakai Migrations
 
Go go gadgets! Implementing a technology collection for staff use
Go go gadgets! Implementing a technology collection for staff useGo go gadgets! Implementing a technology collection for staff use
Go go gadgets! Implementing a technology collection for staff use
 
Using Dataverse Virtual Archive Technology for Research Data Management
Using Dataverse Virtual Archive Technology for Research Data ManagementUsing Dataverse Virtual Archive Technology for Research Data Management
Using Dataverse Virtual Archive Technology for Research Data Management
 
Network Attached Storage (NAS) Initiative
Network Attached Storage (NAS) Initiative Network Attached Storage (NAS) Initiative
Network Attached Storage (NAS) Initiative
 
Supporting your remote clients with bomgar
Supporting your remote clients with bomgarSupporting your remote clients with bomgar
Supporting your remote clients with bomgar
 
After the Breach
After the BreachAfter the Breach
After the Breach
 
Virtualization and you: where are we?
Virtualization and you: where are we?Virtualization and you: where are we?
Virtualization and you: where are we?
 
Online Copyright Education
Online Copyright EducationOnline Copyright Education
Online Copyright Education
 
Leveraging Centralized IT Support Services as a First Point of Contact
Leveraging Centralized IT Support Services as a First Point of ContactLeveraging Centralized IT Support Services as a First Point of Contact
Leveraging Centralized IT Support Services as a First Point of Contact
 
Building Cyber-infrastructure at UNC-CH
Building Cyber-infrastructure at UNC-CHBuilding Cyber-infrastructure at UNC-CH
Building Cyber-infrastructure at UNC-CH
 
Network Attached Storage Initiative
Network Attached Storage InitiativeNetwork Attached Storage Initiative
Network Attached Storage Initiative
 

Recently uploaded

SAP Sapphire 2024 - ASUG301 building better apps with SAP Fiori.pdf
SAP Sapphire 2024 - ASUG301 building better apps with SAP Fiori.pdfSAP Sapphire 2024 - ASUG301 building better apps with SAP Fiori.pdf
SAP Sapphire 2024 - ASUG301 building better apps with SAP Fiori.pdf
Peter Spielvogel
 
Transcript: Selling digital books in 2024: Insights from industry leaders - T...
Transcript: Selling digital books in 2024: Insights from industry leaders - T...Transcript: Selling digital books in 2024: Insights from industry leaders - T...
Transcript: Selling digital books in 2024: Insights from industry leaders - T...
BookNet Canada
 
Observability Concepts EVERY Developer Should Know -- DeveloperWeek Europe.pdf
Observability Concepts EVERY Developer Should Know -- DeveloperWeek Europe.pdfObservability Concepts EVERY Developer Should Know -- DeveloperWeek Europe.pdf
Observability Concepts EVERY Developer Should Know -- DeveloperWeek Europe.pdf
Paige Cruz
 
FIDO Alliance Osaka Seminar: Passkeys at Amazon.pdf
FIDO Alliance Osaka Seminar: Passkeys at Amazon.pdfFIDO Alliance Osaka Seminar: Passkeys at Amazon.pdf
FIDO Alliance Osaka Seminar: Passkeys at Amazon.pdf
FIDO Alliance
 
Why You Should Replace Windows 11 with Nitrux Linux 3.5.0 for enhanced perfor...
Why You Should Replace Windows 11 with Nitrux Linux 3.5.0 for enhanced perfor...Why You Should Replace Windows 11 with Nitrux Linux 3.5.0 for enhanced perfor...
Why You Should Replace Windows 11 with Nitrux Linux 3.5.0 for enhanced perfor...
SOFTTECHHUB
 
Communications Mining Series - Zero to Hero - Session 1
Communications Mining Series - Zero to Hero - Session 1Communications Mining Series - Zero to Hero - Session 1
Communications Mining Series - Zero to Hero - Session 1
DianaGray10
 
Video Streaming: Then, Now, and in the Future
Video Streaming: Then, Now, and in the FutureVideo Streaming: Then, Now, and in the Future
Video Streaming: Then, Now, and in the Future
Alpen-Adria-Universität
 
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
DanBrown980551
 
Monitoring Java Application Security with JDK Tools and JFR Events
Monitoring Java Application Security with JDK Tools and JFR EventsMonitoring Java Application Security with JDK Tools and JFR Events
Monitoring Java Application Security with JDK Tools and JFR Events
Ana-Maria Mihalceanu
 
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdfFIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
FIDO Alliance
 
20240607 QFM018 Elixir Reading List May 2024
20240607 QFM018 Elixir Reading List May 202420240607 QFM018 Elixir Reading List May 2024
20240607 QFM018 Elixir Reading List May 2024
Matthew Sinclair
 
Pushing the limits of ePRTC: 100ns holdover for 100 days
Pushing the limits of ePRTC: 100ns holdover for 100 daysPushing the limits of ePRTC: 100ns holdover for 100 days
Pushing the limits of ePRTC: 100ns holdover for 100 days
Adtran
 
Alt. GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using ...
Alt. GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using ...Alt. GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using ...
Alt. GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using ...
James Anderson
 
State of ICS and IoT Cyber Threat Landscape Report 2024 preview
State of ICS and IoT Cyber Threat Landscape Report 2024 previewState of ICS and IoT Cyber Threat Landscape Report 2024 preview
State of ICS and IoT Cyber Threat Landscape Report 2024 preview
Prayukth K V
 
20240605 QFM017 Machine Intelligence Reading List May 2024
20240605 QFM017 Machine Intelligence Reading List May 202420240605 QFM017 Machine Intelligence Reading List May 2024
20240605 QFM017 Machine Intelligence Reading List May 2024
Matthew Sinclair
 
PHP Frameworks: I want to break free (IPC Berlin 2024)
PHP Frameworks: I want to break free (IPC Berlin 2024)PHP Frameworks: I want to break free (IPC Berlin 2024)
PHP Frameworks: I want to break free (IPC Berlin 2024)
Ralf Eggert
 
GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deplo...
GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deplo...GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deplo...
GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deplo...
James Anderson
 
Encryption in Microsoft 365 - ExpertsLive Netherlands 2024
Encryption in Microsoft 365 - ExpertsLive Netherlands 2024Encryption in Microsoft 365 - ExpertsLive Netherlands 2024
Encryption in Microsoft 365 - ExpertsLive Netherlands 2024
Albert Hoitingh
 
GraphSummit Singapore | Enhancing Changi Airport Group's Passenger Experience...
GraphSummit Singapore | Enhancing Changi Airport Group's Passenger Experience...GraphSummit Singapore | Enhancing Changi Airport Group's Passenger Experience...
GraphSummit Singapore | Enhancing Changi Airport Group's Passenger Experience...
Neo4j
 
GridMate - End to end testing is a critical piece to ensure quality and avoid...
GridMate - End to end testing is a critical piece to ensure quality and avoid...GridMate - End to end testing is a critical piece to ensure quality and avoid...
GridMate - End to end testing is a critical piece to ensure quality and avoid...
ThomasParaiso2
 

Recently uploaded (20)

SAP Sapphire 2024 - ASUG301 building better apps with SAP Fiori.pdf
SAP Sapphire 2024 - ASUG301 building better apps with SAP Fiori.pdfSAP Sapphire 2024 - ASUG301 building better apps with SAP Fiori.pdf
SAP Sapphire 2024 - ASUG301 building better apps with SAP Fiori.pdf
 
Transcript: Selling digital books in 2024: Insights from industry leaders - T...
Transcript: Selling digital books in 2024: Insights from industry leaders - T...Transcript: Selling digital books in 2024: Insights from industry leaders - T...
Transcript: Selling digital books in 2024: Insights from industry leaders - T...
 
Observability Concepts EVERY Developer Should Know -- DeveloperWeek Europe.pdf
Observability Concepts EVERY Developer Should Know -- DeveloperWeek Europe.pdfObservability Concepts EVERY Developer Should Know -- DeveloperWeek Europe.pdf
Observability Concepts EVERY Developer Should Know -- DeveloperWeek Europe.pdf
 
FIDO Alliance Osaka Seminar: Passkeys at Amazon.pdf
FIDO Alliance Osaka Seminar: Passkeys at Amazon.pdfFIDO Alliance Osaka Seminar: Passkeys at Amazon.pdf
FIDO Alliance Osaka Seminar: Passkeys at Amazon.pdf
 
Why You Should Replace Windows 11 with Nitrux Linux 3.5.0 for enhanced perfor...
Why You Should Replace Windows 11 with Nitrux Linux 3.5.0 for enhanced perfor...Why You Should Replace Windows 11 with Nitrux Linux 3.5.0 for enhanced perfor...
Why You Should Replace Windows 11 with Nitrux Linux 3.5.0 for enhanced perfor...
 
Communications Mining Series - Zero to Hero - Session 1
Communications Mining Series - Zero to Hero - Session 1Communications Mining Series - Zero to Hero - Session 1
Communications Mining Series - Zero to Hero - Session 1
 
Video Streaming: Then, Now, and in the Future
Video Streaming: Then, Now, and in the FutureVideo Streaming: Then, Now, and in the Future
Video Streaming: Then, Now, and in the Future
 
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
 
Monitoring Java Application Security with JDK Tools and JFR Events
Monitoring Java Application Security with JDK Tools and JFR EventsMonitoring Java Application Security with JDK Tools and JFR Events
Monitoring Java Application Security with JDK Tools and JFR Events
 
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdfFIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
 
20240607 QFM018 Elixir Reading List May 2024
20240607 QFM018 Elixir Reading List May 202420240607 QFM018 Elixir Reading List May 2024
20240607 QFM018 Elixir Reading List May 2024
 
Pushing the limits of ePRTC: 100ns holdover for 100 days
Pushing the limits of ePRTC: 100ns holdover for 100 daysPushing the limits of ePRTC: 100ns holdover for 100 days
Pushing the limits of ePRTC: 100ns holdover for 100 days
 
Alt. GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using ...
Alt. GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using ...Alt. GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using ...
Alt. GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using ...
 
State of ICS and IoT Cyber Threat Landscape Report 2024 preview
State of ICS and IoT Cyber Threat Landscape Report 2024 previewState of ICS and IoT Cyber Threat Landscape Report 2024 preview
State of ICS and IoT Cyber Threat Landscape Report 2024 preview
 
20240605 QFM017 Machine Intelligence Reading List May 2024
20240605 QFM017 Machine Intelligence Reading List May 202420240605 QFM017 Machine Intelligence Reading List May 2024
20240605 QFM017 Machine Intelligence Reading List May 2024
 
PHP Frameworks: I want to break free (IPC Berlin 2024)
PHP Frameworks: I want to break free (IPC Berlin 2024)PHP Frameworks: I want to break free (IPC Berlin 2024)
PHP Frameworks: I want to break free (IPC Berlin 2024)
 
GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deplo...
GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deplo...GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deplo...
GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deplo...
 
Encryption in Microsoft 365 - ExpertsLive Netherlands 2024
Encryption in Microsoft 365 - ExpertsLive Netherlands 2024Encryption in Microsoft 365 - ExpertsLive Netherlands 2024
Encryption in Microsoft 365 - ExpertsLive Netherlands 2024
 
GraphSummit Singapore | Enhancing Changi Airport Group's Passenger Experience...
GraphSummit Singapore | Enhancing Changi Airport Group's Passenger Experience...GraphSummit Singapore | Enhancing Changi Airport Group's Passenger Experience...
GraphSummit Singapore | Enhancing Changi Airport Group's Passenger Experience...
 
GridMate - End to end testing is a critical piece to ensure quality and avoid...
GridMate - End to end testing is a critical piece to ensure quality and avoid...GridMate - End to end testing is a critical piece to ensure quality and avoid...
GridMate - End to end testing is a critical piece to ensure quality and avoid...
 

S#$% My Network Says (CTC Retreat 2010)

  • 1. S#$% My Network Says Jim Gogan - ITS Communication Technologies CTC Retreat - October 21, 2010 “Nervous? In 5 billion years the sun will burn out and nothing you did will matter. Feel better?”
  • 2. its.unc.edu 2  Overall performance ultimately depends on the weakest components “A parent’s only as good as their dumbest kid. If one wins a Nobel Prize but the other gets robbed by a hooker, you failed”  Chosing specific network equipment keeps getting more challenging “ You don’t have to be good to succeed. You just gotta be the least crappy option. Example: We’re eating at The Olive Garden.” Network Architecture
  • 3. its.unc.edu 3 Network Architecture  BIG …… really big …..
  • 4. its.unc.edu 4 Changes to Intrusion Prevention Systems (Tipping Points)  New 10 Gbps inline systems installed at the two campus border points – first time we’ve had complete IPS coverage at the border (where approx. 98% of the attacks are seen)  Allows us to do a phased removal of the majority of internal IPS/TP units, primarily at the distribution layer; to date, Phillips, Franklin and Kenan Labs Tier 1s are gone  Removals will generally produce noticeable performance improvements on inter-subnet traffic “Sometimes it’s nice having you around. But now ain’t one of those times.”
  • 5. its.unc.edu 5 Wi-Fi Networking  Continues to be an “a la carte” service at $1200 per access point  Continues to be based on really, really moronic technologies and vendor implementations “No one cares about all the things your smartphone does. You didn’t invent it, you just bought it. Anybody can do that. Oh, and there’s a 50/50 chance it won’t work with WEP”
  • 6. its.unc.edu 6 TAR-WAP  Teaching and Research Wireless Activation Project • Proposals from faculty requesting AP installation in designated rooms specifically for teaching and/or research activities • Search http://help.unc.edu for TAR-WAP for details • Include in proposal:  Specific academic course/research activity requesting connectivity  Summary of how Wi-Fi would be used  Approx. number of concurrent students  Commitment to provide feedback to ITS
  • 7. its.unc.edu 7 TAR-WAP Installations since Sept 2009 • Morehead Planetarium -- Remedy ticket 1563220 • Peabody 306 • Coker 201 -- Remedy ticket 1611676 • Fordham Hall Conference Rooms -- Remedy ticket 1618907 • Swain Hall -- Remedy ticket 1611710 • Med School Wing Classrooms -- Remedy ticket 1618892 • Baity Laboratory Building - SPH -- Remedy ticket 1626497 • Michael Hooker Research Center - Nutrition-SPH -- Remedy ticket 1626497 • Mitchell Hall - Geological Sciences -- Remedy ticket 1680602 • Alumni Building - Archaeology and Anthropology -- Remedy ticket 1678032 • Coker Hall - UNC Herbarium -- Remedy ticket 1698584 • Carolina Center for Educational Excellence - School of Education -- Remedy ticket 1701652 • Wilson Library 318 - CFE Training Facility -- Remedy ticket 1745944 • School of Medicine - Bondurant and MBRB Auditoriums -- Remedy ticket 1720461 • Burnett-Womack - Division of Radiologic Science -- Remedy ticket 1519846 • Peabody Hall Rm 02 - School of Education -- Remedy ticket 1749683 • Peabody Hall 206 and 211 - School of Education -- Remedy ticket 1764506 • Phillips Hall - Physics-SCALE-UP -- Remedy ticket 1719892 • Coker Hall - Biology -- Remedy ticket 1839960 • Coates Building - Geography Research Labs -- Remedy ticket 1839941
  • 8. its.unc.edu 8 Network Management  Growing use of “NetFlow” collectors
  • 9. its.unc.edu 9 Network Management – More (Can’t Have Too Much)  Continued evolution and testing of NAC (Network Access Control)  Continued evolution of NIT (Network Information Tool)
  • 10. its.unc.edu 10 Neutral Hosting Project  Installation of advanced campus-wide DAS (Distributed Antenna System) to provide uniform outdoor and in-building wireless mobile coverage (voice, data and beyond)  Project has been underway for the past 3+ years  Final construction design plans (for all sites except Kenan Stadium and the Smith Center) now under final internal review process— expect submission to State Construction Office for approval the first week in November.  Remaining sites (Kenan and Smith Center) will be finalized in November.  Construction start targeted for first quarter 2011.  AT&T, T-Mobile and Verizon participating—Sprint currently dealing with budgetary issues—will probably join sometime in 2011.  100% funded by the carriers
  • 11. its.unc.edu 11 Campus Voice Services  New AVST voice messaging platform installed in April 2010 • Will provide unified messaging, virtual fax and other advanced features • Links campus voicemail once again with UNC Healthcare  Current AT&T Centrex contract expires in March 2011  Comprehensive voice services RFP released in May 2010  Interdepartmental RFP response evaluation team now reviewing vendor proposals—final recommendation due in November  IT governance committee working on new rate model proposal—separates funding sources for core campus services (networking) from optional services (telephony services)
  • 12. its.unc.edu 12 Working with Network Vendors  Really? REALLY???? • You want a complete network diagram of all nodes on the campus network? Really?? • You design a product that sends ARP requests for hosts not on the local network? Really?? • You build a switch with 10Gb ports, but the ASIC is designed only to multiplex 1Gb flows? Really?!? • You say that a core router module is having problems because of “vibrations”? REALLY?!?!?! • You add two new promised features, but introduce three new bugs? REALLY????????? “ There’s a word for people like that … No, I’m saying, there’s a word and I don’t know what it is. I’m not being poetic” “Sometimes life leaves a hundred dollar bill on your dresser, and you don’t realize until later that it’s because it screwed you”
  • 13. its.unc.edu 13 Working with You  Great user support COMMUNITY!!! • Knowledgeable, responsive and inquisitive  We love seeing NIT results in tickets  PLEASE send tickets (with IP/MAC address info) instead of phone calls “Why would I want to check a voicemail on my phone? People want to talk to me, call again. If I want to talk to you, I’ll answer.”

Editor's Notes

  1. The Title Slide: Add the name of the presentation, the appropriate division or presenter and date of the presentation.
  2. Basic content slide: Add slide title and slide text in the appropriate places. To create a new slide, go to “Insert > New Slide” from the main menu.
  3. In order for create a section divider slide, add a new slide, select the “Title Only” Slide Layout and apply the “Section Divider” master from the Slide Design menu. For more information regarding slide layouts and slide designs, please visit http://office.microsoft.com/training