JHOP Boston Podcast: Recent Episodes

Michael "Zig" Zsiga

Providing real world context around technology

View Details

Hey Nerds, Geeks, and Ziglets out there.  Today we start our Mini Series on Segment Routing with our Guest Expert Suraj Soni.  We have a lot planned for this Mini Series but today’s focus is “Why Segment Routing?” so lets get to it!  

Guest Expert: Suraj Soni

Soni has been working in our industry for 10 years in multiple verticals to include Enterprise and Service Provider Networks.  He is a triple CCIE in R&S, Sec, and Service Provider.  He has numerous other Vendor Certifications such as F5 and Nokia.  He has been in a number of different roles in his career such as Solution Architect and Network Consultant.  He currently is a Senior Network Manager for a company in Singapore.  Please Welcome my friend Soni to our show today!!  Welcome Soni!

Soni joins the Zigbits Network Design Podcast today to start a Mini Series on Segment Routing!  We are going to have about 5 podcast episodes and a number of blog posts to help reenforce the topics we are covering.   Today’s topic is “Why Segment Routing”?

Why Segment Routing? Segment Routing is a control plan protocol for MPLS.  Segment Routing came into picture because of the evolution of Software Defined Network Solutions (SDN) and the desire to expand said SDN solutions and concepts into the Service Provider arena.

Why is LDP and RSVP out, why do we need SR? One reason is because with LDP and RSVP we are statically mapping our policy to an IP address.  In addition with LDP and RSVP we have no visibility of the applications running over the Service Provider Core without implementing some other technology or solution.

Sample Use Cases:

Voice and Video – Needs low latency

Higher bandwidth needed for file download

In both of these use cases, with LDP and RSVP we have static uni-directional configurations of MPLS TE Tunnels which in most cases are never removed even when they are no longer needed.  Lets simplify this to say unnecessary TE Tunnels and complexity.

How Segment Routing different: For Segment Routing there is no signally like there is with LDP, RSVP, and MPLS TE.  Segment Routing is a signal free protocol because it instead uses your IGP for signaling.  The IGP floods the Segment Routing information as well when it sends out other information updates. Currently only OSPF and IS-IS are supported.   

Segment Routing is not going to resolve these Use Case issues by itself.  Segment Routing is a part of a solution.

A Solution can resolve issues, a technology cannot resolve an issue.

Open Controller (SDN) Within this entire solution we need a brain or an intelligence center to give us some of the SDN pieces we desire in the Service Provider Core.  This is where we bring in a controller of some sort.   This controller is going to have both the visibility of the customer locations (Data Center, WAN, Campus, etc..) and also the Service Provider Core network.  This allows the controller to have a full End to End visibility of the network.  With the full End to End visibility, the controller is seeing the use cases happen in real time.

The controller and application will have a form of integration which we will show in a later segment of this mini series.  This integration will give the controller the ability to fetch the details for the applications in question. Then the controller will find the path throughout the End to End network dynamically keeping measurement of all of the necessary health controls of the different paths and the application requirements (think latency and jitter for voice here as an example).  Once the path is identified the controller tells the application what the path is by giving the application packets the Segment ID list.

With this solution, nothing is configured on the routers like MPLS TE or RSVP.  The only requirement on the routers is to properly configure Segment Routing.

What if I don’t have a controller, you can still use Segment Routing, but you will rely on label forwarding, more to come in future 

Segment Routing Summary With Segment Routing we are no longer routing based on destination but are routing based on source. No hardware refresh is required to support Segment Routing only software upgrade if the hardware supports it.  There is no need for any configuration on the routers minus the enabling of Segment Routing.  Some of the configurations we would normally talk about is MPLS TE and RSVP.

We decouple the need to configure policy elements based on specific IP Addresses.  Think static MPLS TE Tunnels with node and link protection here.  Because we no longer have dependencies on the IP or Port, we are free to have a dynamic solution moving forward.

Because this solution utilizes an intelligent controller we now have full application visibility which we didn’t have before.

Here Soni and I highlight an Entire Solution that is defined as a SDN SP Core Network.  This solution enables network for application readiness and for forwarding application traffic on more information than just IPs.

How to stay engaged with Soni:

Twitter: https://twitter.com/SurajSo12629850

LinkedIn: https://www.linkedin.com/in/suraj-soni-cciex3-a3459062/

Youtube: https://www.youtube.com/channel/UC_yESR7l4B-zJU9McxiAEyw

Work with me: Through your participation in a healthy mentoring and coaching relationship, you will benefit greatly from the education, the experiences, the influences, leadership and even the resources provided. Learn how you can accomplish more, in one year, than you could accomplish in your career…in your business…and in your life.

Accomplish More Now!!

Provide Feedback

You can leave a comment on the blog!

You can leave a voicemail at (617) 913-4103

You can email us at Feedback@zigbits.tech

Transparency: This post may contain affiliate links to products or services were I may receive a level of compensation from your actions by following those links. This is seamless to you and does not add any additional cost to the products or services in question. In addition, I do not let any affiliate relationship cloud my judgement or my recommendation of a product or service. My recommendations will always be above reproach.  This is my commitment to you Ziglets!

The post ZNDP 41 – Why Segment Routing? appeared first on Zigbits - Where Zigabytes are faster than Gigabytes.

View Details

I am back!!  Sorry it’s been so long.  I went MIA for a bit, but I am back today with a new episode of the Zigbits Network Design Podcast!  Today I will be highlighting the Benefits of SD-WAN, vendor agnostically!!   Enough jabbering, lets get on with the show!

What is SD-WAN? 

We are keeping this Vendor Agnostic, but we will do some blog posts in the future that highlight specific vendor solutions.

Underlay and Overlay

This is a Fabric Architecture for the Transport / WAN Place in the network

Abstracting Policy control decisions from the underlay and placing them in the Overlay with a software controller

Network Design Benefits of SD-WAN Connectivity Agnostic and Ubiquitous

With an SD-WAN architecture, we now have an underlay and an overlay.  The overlay is what we spent most of our time on, with policy and routing controllers that are specific to our environments.  We have in-fact decoupled the ties legacy networks had on the underlay network. 

With Connectivity Agnosticity and Ubiquity, we no longer need to use a specific MPLS Provider, or that specific Metro Ethernet circuit.  

We have the capability of keeping all of our customer specific policy elements, quality of experience, segmentation, application aware routing, dynamic traffic paths, and so much more within the SD-WAN Overlay and Software Controller.

Now when we need to migrate from one underlay to another, it doesn’t break the business.  The network isn’t going to go down when we do this migration, just a VPN, or Virtual Network, or Path, whatever vendor specific word you want to use in this place, the intent here is that our jobs as network engineers, and network architects are made easier because of SD-WAN.  

Business Benefits of SD-WAN SD-WAN is a business enabler, it allows businesses to be agile and it allows a business to realize cost savings.  These cost savings can be both OPEX and CAPEX.  In addition to the monetary savings, there is a Manpower savings…Now companies will no longer need as many full time staff roles to manage the environment.

With the advent of SD-WAN, businesses now can play the provider market when it comes to MPLS circuits. Let’s call this Provider Market Comparison, though I am probably wrong with this wording.  Now we can make the different Provider’s compete with one another as businesses are no longer locked into a Provider.

Businesses can now custom tailor the overlay to fit their specific business needs, the business priorities, and the business outcomes.  Before the creation of SD-WAN, businesses had to pick the best provider but that best provider never had all of the answers.

We have compliance, audit, and regulatory standards.  We have the necessary report requirements and capabilities that traditionally were a manual processes.  We have dynamic security vulnerability detection and we can predict our server and user data flows.

User Benefits of SD-WAN Finally, we now have an end to end provisioning of Quality of Experience, not to be confused with Quality of Service, though Quality of Experience includes Quality of Service.  Quality of Experience is everything to the end user.  Users are getting the access they need (not what they want), independent of where and how they are connecting to the SD-WAN fabric, with all aspects of user experience taken into account.  

Work with me: Through your participation in a healthy mentoring and coaching relationship, you will benefit greatly from the education, the experiences, the influences, leadership and even the resources provided. Learn how you can accomplish more, in one year, than you could accomplish in your career…in your business…and in your life.

Accomplish More Now!!

Provide Feedback

You can leave a comment on the blog!

You can leave a voicemail at (617) 913-4103

You can email us at Feedback@zigbits.tech

Transparency: This post may contain affiliate links to products or services were I may receive a level of compensation from your actions by following those links. This is seamless to you and does not add any additional cost to the products or services in question. In addition, I do not let any affiliate relationship cloud my judgement or my recommendation of a product or service. My recommendations will always be above reproach.  This is my commitment to you Ziglets!

The post ZNDP 40 – Benefits of SD-WAN appeared first on Zigbits - Where Zigabytes are faster than Gigabytes.

View Details

In Today’s episode, we are going to cover Design Documents.  I recently had a number of coaching sessions where design documents were discussed.  I then attempted to remember how I learned about all of the Design Documents that I have seen, written, and peer reviewed over my career, but I couldn’t find a good answer other than experience.  Well today we are going to shed some light on what I would call the most common Design Documents our there.  Lets get started.

Design Documents – Agenda

Customer Requirements Document (CRD)

Reference Architecture (RA)

High Level Design (HLD)

Low Level Design (LLD)

Design Documents – CRD

Customer Requirements Documents

Undervalued and skipped

Built together with the customer and the Designer

Illicit information from customer, thats our role as a Designer

Design Documents – RA

Reference Architectures

Abstraction of an Architecture in a perfect world situation

Sometimes you will see a HLD, a LLD, and a mix of these together.  Its not always end to end though and fully inclusive.  Its more like here is the 85% solution in a perfect world.  Now you as a Design need to apply this reference architecture within the environment you are working on with the associated requirements.

Design Documents – HLD

High Level Design

Specific to an environment

Apply information from CRD and associated Reference architectures to build out the HLD

Example??

You need a router here, a Firewall there, and some sort of transport connecting everything together.  

Things like Single points of failure, dual points of failure, and , shared fate would be discussed and ruled out 

Design specific decisions are highlighted and discussed.  For example, this document would discuss decisions around MPLS BGP Route Reflect Design.  Cold potato and hot potato routing.  If there should be dedicated RRs for IP address-families versus VPN address-families, or should they be mingled on the same set of BGP RRs.  More importantly, it would discuss the pros and cons to each of these design decisions.

You could also see an As-Built version of this as well, where someone documented in an HLD formation what the current environment is.

What you will not find here, is the actually configuration of features and devices. This aligns perfectly with the next design document, the LLD

Design Documents – LLD

Low Level Design

The Low Level Design Document, or LLD is where all of the technical configurations of features, devices, and all of those nerd knobs you want to use is going to be. 

Some times called Detail Design Documents. There are also As-Built versions of these as well depending on who is creating the documents.

Work with me: Through your participation in a healthy mentoring and coaching relationship, you will benefit greatly from the education, the experiences, the influences, leadership and even the resources provided. Learn how you can accomplish more, in one year, than you could accomplish in your career…in your business…and in your life.

Accomplish More Now!!

Provide Feedback

You can leave a comment on the blog!

You can leave a voicemail at (617) 913-4103

You can email us at Feedback@zigbits.tech

Transparency: This post may contain affiliate links to products or services were I may receive a level of compensation from your actions by following those links. This is seamless to you and does not add any additional cost to the products or services in question. In addition, I do not let any affiliate relationship cloud my judgement or my recommendation of a product or service. My recommendations will always be above reproach.  This is my commitment to you Ziglets!

The post ZNDP 039 – Design Documents appeared first on Zigbits - Where Zigabytes are faster than Gigabytes.

View Details

In today’s installment we have an Ask Zig episode.  Roy from Virginia sent in the following question: “My job isn’t challenging or providing me needed experience, what should I do?”  Hear the answer in today’s episode!!

Roy from Virginia sent in this question:

Roy has recently transitioned into a new role as a Network Engineer but he is running into a similar issue that he has been in before. It seems like a lot of the jobs aren’t as challenging and don’t offer the needed experience.  For example, most of the time i’m left with no work or doing very easy tasks like changing VLANs on a switchport. Do you have any recommendations on how to position myself in a spot where i’m able to learn and develop my networking skills?

What you mention here is a very common situation in the industry.  The reality of the situation is that you will never truly know a position or role until you are actually in it. I’m not saying all Network Engineer Roles are the same here, what I am saying though is that you will not know until you are in the specific role.

The 4 Important Items: I like to break it down into 4 important items:

  1. Rewarding work

  2. Having purpose

  3. Continuous Learning

  4. Studying

How to position yourself! Now as to what recommendations on how to position yourself to be in a specific role or position, I think you first need to identify what your end goal and end destination is?  What are you passionate about and how can you embrace that passion into your career?

If you are simply just looking to be challenged and to help improve your networking skills, then thats easy to position yourself into a role that includes those items. 

From a challenge perspective:

I would highly recommend taking a role with an integrator, a Vendor Partner, or a Value Added Reseller. 

This will be a challenge because its very fast pace, you will be jumping from one technology to another every week. 

You will need to learn new technology very quickly and be able to explain it to customers and make it relatable .

The downside of positions like these are that they usually require a lot of nighttime / weekend work and / or travel.

Outside of a position like this:

I think finding what you are looking for will be highly dependent on the company, the vertical, and the culture. 

A lot of this you can find out during the interview process.

Keep in mind, the interview is for both parties, its not a one-sided interview.

You are interviewing the company

right core values

right company

right position

In the case that you are in now: I would focus on you challenging yourself and developing your networking skills.  If you have a desire to make yourself better at something, thats the hardest part.  Now all you need to do is dedicate the time and learn.

Hopefully that answered your question Roy.  Thank you for sending it in!

Work with me: Through your participation in a healthy mentoring and coaching relationship, you will benefit greatly from the education, the experiences, the influences, leadership and even the resources provided. Learn how you can accomplish more, in one year, than you could accomplish in your career…in your business…and in your life.

Accomplish More Now!!

Provide Feedback

You can leave a comment on the blog!

You can leave a voicemail at (617) 913-4103

You can email us at Feedback@zigbits.tech

Transparency: This post may contain affiliate links to products or services were I may receive a level of compensation from your actions by following those links. This is seamless to you and does not add any additional cost to the products or services in question. In addition, I do not let any affiliate relationship cloud my judgement or my recommendation of a product or service. My recommendations will always be above reproach.  This is my commitment to you Ziglets!

The post ZNDP 038 – Ask Zig – My job isn’t challenging or providing me needed experience, what should I do? appeared first on Zigbits - Where Zigabytes are faster than Gigabytes.

View Details

A little under the weather today and I apologize for this episode publishing a few days late.  Today we have an Ask Zig Episode. Rob from Tampa Florida asked this question on LinkedIn. “Do you think that pursuing CCIE data center makes as much sense as it used to?”  Hear the Answer in today’s episode!

First off is their still value in the CCIE DC?

The journey

How much you can learn about yourself

How much technology you can learn

The Testing process / experience itself (Full Scale Labing, Stress management, Time management)

Becoming an expert

If you already have 2 or 3 CCIEs, there probably isn’t a good ROI

I think it depends on your end goal and your end destination There are so many new initiatives that a DC Expert can and should focus on

Automation, Programming, Orchestration

Cloud (On-Prem, Pubic Cloud, Hybrid Cloud, Multi-Cloud, Micro-Clouds, etc)

Cloud Providers – AWS, Azure, Google

Hardware Vendors (Cisco, Juniper, etc…)

Vendor Certifications

What type of career path are you working towards?

Are you going to end up architecting and designing Cisco Data Center Solutions with Nexus 9Ks, UCS, ACI, Storage Area Networks, etc…

Are you going to be connecting on Prem DC environments to Cloud offerings such as AWS VPCs?  You still will need to understand the technology of both CCIE R&S and CCIE DC tracks, probably not to the level of the CCIE Exams but you will still need to know the concepts and the theory of the technology

Are you just going to be spending 90% of your time in the cloud space?

Are you going to be hands on keyboard, typing away at the CLI or are you going to be in a Web GUI selecting dropdown’s to configure something?

Its not as clear cut as it once was, but answering these questions will definitely help you determine what you should focus on.

Today’s DC Expert Today, though this could and very well might change, I think a DC Expert needs to have a good mixture of the following Skillsets:

CCIE DC

Not saying that a DC Expert needs the certification here, but needs to understand and know the technology.  The theory, the concepts, and be able to troubleshoot it if necessary.

Cloud Experience

Definitely a must in today’s industry. These are things that are paramount today.

How do you connect into a Cloud environment

How do you design for redundancy between your on-prem and cloud environments.

How do you troubleshoot cloud.

How do you determine proper bandwidth levels between on-prem and cloud.

Do you use a VPN type connection model into the cloud or do you use direct links from a provider?

Automation / Orchestration / Programming

These three industry disruptors have changed and will continue to change this industry.

They have positive effect on the bottom line for businesses.

Understanding the difference between Automation and Orchestration, and where to use them.

Programming concepts and experience is a must. Not saying every Network Engineer or Network Architect needs to run out right now to get a Degree in Programming.  What I am saying is that you will need to understand programming concepts, frameworks, and terminology.  You will need to have some perspective, so some basic programming courses would be highly value-able.

Summary Personally, I still have plans, though they might dwindle over the coming years, of going after the CCIE in DC and the CCIE in Security.  For me there isn’t a direct ROI, but I do believe these are very relevant in today’s industry.  Rob, for you this will depend on what you are looking to be doing in the next 5 and 10 years.  Will you still be in the same role you are in today?  Do you thrive on DC technology, Cloud technology, and / or Security?  What gets you out of bed in the morning?

Work with me: Through your participation in a healthy mentoring and coaching relationship, you will benefit greatly from the education, the experiences, the influences, leadership and even the resources provided. Learn how you can accomplish more, in one year, than you could accomplish in your career…in your business…and in your life.

Accomplish More Now!!

Provide Feedback

You can leave a comment on the blog!

You can leave a voicemail at (617) 913-4103

You can email us at Feedback@zigbits.tech

Transparency: This post may contain affiliate links to products or services were I may receive a level of compensation from your actions by following those links. This is seamless to you and does not add any additional cost to the products or services in question. In addition, I do not let any affiliate relationship cloud my judgement or my recommendation of a product or service. My recommendations will always be above reproach.  This is my commitment to you Ziglets!

The post ZNDP 037 – Ask Zig – Do You Think The CCIE DC Makes Sense? appeared first on Zigbits - Where Zigabytes are faster than Gigabytes.

View Details

For today’s Zigbits Network Design Podcast we start a Design Case Study Series with my friend Daren Fulwell.  In this first installment we set the stage for this Design Case Study Series, highlighting the constraints, requirements, and over arching architecture model used to solve the business priorities and business outcomes the customer was looking to achieve. Lets dive into it now!

Guest Expert: Daren Fulwell

Daren is a network architect with 20+ years’ experience of supporting, building and designing networks: covering everything from wireless infrastructure and traditional LANs, across all kinds of WAN and into the software-defined DC and Cloud. Daren currently holds the CCIE R&S and the CCDE certifications.  Daren is actively involved in the networking community, including through the Cisco Champions program and the CCIE Advisory Council. Please welcome Daren Fulwell to the show!

Design Case Study – Part 1 – The Overview The customer in question is a financial company based in London. Founded in 2001, it was recently acquired by a North American parent company and as such had a number of mandated requirements for their foundational infrastructure. As well as the head office, the customer had satellite offices across Europe and the US with existing connectivity using a mixture of MPLS L3VPN and IPSec VPN into their central firewall. We were approached in 2014 to assist in assessing those requirements for:

New office LAN environment kit going end-of-life;

Mandated purpose-built DCs for Prod and DR (existing Prod servers were located in the office building, DR in a co-lo facility);

As a result, an upgrade to the existing co-lo network and a new co-lo facility for DR;

Introduction of resilient MPLS and Internet access across the two DCs.

Design Case Study – The Constraints!! Project constraints were pretty standard – the three that had a material impact on the design were:

Legacy circuits were required to be ceased and had contractual dates to do so;

IP addressing for the servers had to be maintained due to custom applications in use, and the third party support arrangements for them;

The internal support team was only small and multi-disciplined and so minimizing change in fundamental technologies was considered a benefit to prevent any re-training requirement.

Design Case Study – The Requirements As we were looking at dealing with wide-ranging network changes, we took the opportunity to advise on building an architectural model for the network and set some fundamental design principles. Fundamentally, we agreed that we would define a program of works with a work stream for each element, but all within an over-arching design for the whole network.

As the customer is multi-national, they have a requirement for maintaining service 24×7. The fundamental tenet was then to maximize availability in all ways.

Minimize the time to detect failures (including grey failures)

Minimize the time to restore service at failure

Modularize the network to limit impact of failure (blast radius)

Use redundancy in the network where it can be beneficial (equipment or links)

Full High Availability to be used where appropriate

Where HA not possible/sensible, look at how loss of a device impacts others and consider where fate sharing can be used to our benefit. 

Design Case Study – The Architectural Model The over-arching network design can be described thus:

Three separate UK sites with triangulated Layer 3 point-to-point links. A second link to be installed between the Data Centers for additional resilience and to allow (under normal conditions) for replication traffic;

BFD to be used for fast failure detection on the point-to-point links;

EIGRP to be used as the routing protocol of choice – each route would have at least two candidate paths and so the feasible successor feature of EIGRP allowing a fast replacement route should the preferred path fail was beneficial;

Minimize the use of STP using LACP;

OTV used to stretch Layer 2 between office and DC sites for tactical migrations and for DR;

MPLS L3VPN and Internet access presented at each DC site and routed into the UK network;

Firewalls injecting routes into EIGRP for public and private WAN, weighted based on primary links being at the Prod DC and backup being at DR;

Use of IP SLA to track availability of Internet service in the DC and facilitate failover based on grey failure;

Use of route summaries to reduce time to fail over Internet connections. 

Storyboarding In a program of activity such as this, I always take care to storyboard the work streams to a sufficient level of detail as to help illustrate the interdependencies between them and understand the view of the network at any given stage in the program.

Design Case Study – Low-Level Design The bulk of the low-level design was pretty standard fare:

The new campus LAN was built out from a Cat 6807 VSS pair using LACP to access switch stacks, wireless provision was upgraded to a pair of WLC5508 controllers. Multicast configuration was required to allow use of trading handsets;

The new DC LANs were built identically consisting of a pair of Nexus 9K switches running NX-OS (ACI was not considered an option due to operational complexity). 10G was a requirement with support for 40G should it be required. New ASA firewalls were installed for the new Internet provision;

UCS server infrastructure was installed at both Data Centers to provide the capacity for the VMs with an amount of loan swing kit made available during the movement of VMs between sites to effect transition.

Additional Areas for the Design Case Study There were a number of key design areas that warrant further discussion though including:

Use of OTV across all three sites for L2 extension;

Internet routing and failover.

Security

Multicast

Routing / redistribution

Migration process

Business outcomes / business priorities

How to stay engaged with Daren:

Website: https://networkshokunin.blogspot.com/

Twitter: https://twitter.com/DarenFulwell

LinkedIn: https://www.linkedin.com/in/daren-fulwell/

Work with me: Through your participation in a healthy mentoring and coaching relationship, you will benefit greatly from the education, the experiences, the influences, leadership and even the resources provided. Learn how you can accomplish more, in one year, than you could accomplish in your career…in your business…and in your life.

Accomplish More Now!!

Provide Feedback

You can leave a comment on the blog!

You can leave a voicemail at (617) 913-4103

You can email us at Feedback@zigbits.tech

Transparency: This post may contain affiliate links to products or services were I may receive a level of compensation from your actions by following those links. This is seamless to you and does not add any additional cost to the products or services in question. In addition, I do not let any affiliate relationship cloud my judgement or my recommendation of a product or service. My recommendations will always be above reproach.  This is my commitment to you Ziglets!

The post ZNDP 036 – Design Case Study with Daren Fulwell – Part 1 The Overview appeared first on Zigbits - Where Zigabytes are faster than Gigabytes.

View Details

The Iconic Mr. Nick Russo joins us once again for today’s topic of Wireless QoS Design! Today Nick and I talk about QoS, RFC 4594, Wireless QoS, RFC 8325, WMM, UP values, DCF, TXOP, Wireless High Density, Wireless High Demand, and much more!  We also highlight an issue around vendor endpoints not marking Wireless Voice traffic the way you would expect!  Hold on to your seats folks, we are live in 3…2…1!!!

Guest Expert: Nicholas (Nick) Russo

Today’s guest Expert has become an icon within this industry. He holds Cisco Certified Design Expert (CCDE), and two Cisco Certified Internetwork Expert (CCIE), one in Routing & Switching and the second in Service Provider.  He is a great friend and Marine Brother!  This is now Nick’s fourth podcast episode with Zigbits so he should be well known by now! The other ZNDP episodes that Nick has been involved in are listed below:

ZNDP 005 – Carrier Supporting Carrier (CSC) with Nick Russo

ZNDP 030 – Designing for DevOps with Nick Russo

ZNDP 033 – CI/CD … See Why?

Before Wireless QoS, there was QoS! The purpose of QoS in general is to provide the proper treatment required by an application that results in a positive user experience and business outcome. This typically involves flow classification/marking, SLA compliance, traffic conditioning, and more.

With QoS you can think outside of the box.  Don’t be hampered by a Legacy thought process that Video / Voice traffic always has to be in the Priority Queue or Low Latency Queue. Business requirements and outcomes will always dictate what application is the most important within the organization and it might not be Video or Voice.

RFC 4594 Summary Sections 3 and 4: It’s an easy read and very important for network designers of any stripe.

  1. Network Control: Routing protocols and other traffic holding the network together

  2. Signaling: Interactive voice/video signaling (call setup, forwarding, etc)

  3. OAM: Network operations: SNMP, SSH, RADIUS, TACACS, Netflow

  4. Voice: Very sensitive to latency, jitter, and loss

  5. Broadcast Video: Typically has application level buffering. Includes live video feeds, IPTV, CCTV

  6. Real-time interactive: Telepresence; similar SLA as VOIP with a little bit more latency but less loss

  7. Multimedia Conf: Bidirectional software media, like webex

  8. Multimedia Stream: Video on demand, Youtube/Netflix videos, unidirectional video viewing

  9. Transaction Data (LL): Interactive foreground applications; users are expecting a response (ERP, CRM)

  10. Bulk Data (HT): Non-interactive background applications; database sync, backup jobs

  11. Best Effort: Most applications fit here, anything unclassified

  12. Scavenger: Explicit low priority, video games, peer to peer traffic

Wireless Multi Media (WMM) IEEE 802.11e adopted by the Wifi alliance as Wireless Multi Media (WMM). There are four access categories listed below:

Background

Best effort

Video

Voice.

Each AC has two specific user priority (UP) values associated with it. These are similar to Ethernet class of service (CoS) in wired networks.

802.11e UP

UP 1 – Background (AC BK)

UP 2 – Spare (AC BK)

UP 0 – Best effort (AC BE)

UP 3 – Excellent effort (AC BE)

UP 4 – Controlled Load (AC VI)

UP 5 – Video (AC VI)

UP 6 – Voice (AC VO)

UP 7 – Network control (AC VO)

Wireless QoS operation is focused on reducing the likelihood of collisions for high priority traffic. This leads to fewer retransmissions, less wasted time, and improved application performance.

Wireless Traffic is still Half Duplex, and so its a limiting factor on bandwidth / performance. This is why its imperative to have Wireless QoS Implemented on your most critical traffic / Application

Distributed Coordination Function (DCF) at a high level 1. Wait some fixed amount of time (DCF interframe spacing, DIFS)

  1. Select a random backoff timer between 0 and the minimum contention window (CWMIN), and wait that time

  2. When timer reaches zero, transmit

  3. If ack is not received, double the contention window time (expontential backoff approaching CWMAX) and try again

Wireless QoS proposes a variable arbitrated IFS (AIFS) strategy. Higher priority access categories (there are 4) will have shorter AIFS. Additionally, higher priority classes will have smaller CWMIN and CWMAX, allowing them to almost always beat lower priority traffic for wireless media access.

Think of a conference call where everyone but your manager has to wait 2 seconds to talk. Your manager only has to wait 1 second to talk, thus ensuring that if your manager has something to say he/she will say it first and foremost.

TX Opportunity (TXOP) Last, TX opportunity (TXOP) allows a station to send multiple frames without DCF cycles in between each one. Background and BE TXOP are 0, meaning they only send 1 frame at a time. Video is highest, primarily because voice is benign and predictable, video is greedy and bursty. VOIP sampling is typically 20 ms or so and doesn’t need a large period of time to transit.

Wireless High Density and High Demand From a Wireless Video design perspective it is paramount to make sure you have enough bandwidth available to support it. This then gets into Wireless High Density and Wireless High Demand design considerations.

For Wireless High Density think of a Theme Park or a Sports Stadium where the number of Wireless clients is high but the bandwidth demands are low (Social media, web browsing, etc…)

For Wireless High Demand think of a K-12 or Higher Education where the instructing methodology is streaming Unicast Video at a very high resolution 4K or higher.

A great use case for both a High Demand and a High Density Wireless Design would be a Higher Education starting to incorporate Virtual Reality and Augmented Reality solutions over Wireless. The density and demand implications start to get exponentially high.

Four things to consider:

The DSCP of the original packet entering the WLC and being encapsulated in CAPWAP impacts the CAPWAP DSCP header (downstream wired transport to  AP).

The UP imposed by the AP after removing the CAPWAP encapsulation and translating the Ethernet header to 802.11. The UP value is derived from the CAPWAP DSCP value (downstream wireless transport from AP to client).

The UP imposed by the client (locally originated) and sent over the air to the AP. This value is often determined by the DSCP of the original packet being sent, similar to how Ethernet CoS is derived from DSCP in wired networks.

The CAPWAP DSCP imposed by the AP after translating 802.11 to Ethernet and encapsulating it in CAPWAP towards the WLC. This is determined by the UP value, typically NOT the inner DSCP (this can be adjusted on some vendor equipment).

An example: A wired user places a VOIP call to a wireless client using an Apply iPhone 6. The wired phone sets DSCP EF (46) which is commonly used.

Downstream Flow: 1. Wired phone traffic enters the WLC with DSCP EF (decimal 46) and is encapsulated in CAPWAP.

  1. The CAPWAP DSCP is copied from inner DSCP, resulting in DSCP EF being transported down to the AP. So far, so good.

  2. The AP translates CAPWAP DSCP EF to UP 6 which is used for voice across wireless networks. Again, good.

Upstream Flow: 4. The iPhone 6 sends traffic up to the AP using UP 5 which is used for video traffic. Why? Because Apple has a business driver to promote Facetime, its interactive video/video application, which uses UP 6.

  1. The AP thinks this is video traffic since it’s marked UP 5. AP maps this to a CAPWAP DSCP of AF41 (34) which is an appropriate video marking. Inner is DSCP EF, set by the phone, but the transport between AP and WLC will see only CAPWAP DSCP 34.

  2. The WLC decapsulates CAPWAP and sends the inner IP packet with DSCP EF into the wired network.

Trusting DSCP is the newer and more effective method. That at least protects the wired network.

If you’re stuck trusting UP: 1. Statically mutate DSCP at the ingress switchport where the AP connects. Might work where you know there is a lot of BYOD voice but little/no video, so you can map AF41 to EF with high certainty that its actually voice. Coupled with rate limiting/ACLs to block video, this could work.

  1. Try to match based on packet sizes. This might work OK for voice most of the time since packet sizes are fixed, but will have false positives.

  2. Run your APs in FlexConnect with local switching, or whatever non-Cisco vendors call it. This eliminates CAPWAP data plane entirely, but comes with many other challenges in a high-scale environment (mobility, IPAM, etc)

  3. If CAPWAP data plane is not encrypted, DPI could be used on the switch, if supported, to copy the inner DSCP to CAPWAP DSCP. I’ve never seen this before in production.

Note that trusting DSCP (versus UP) at the AP does not help the WLAN in these cases. The client could use worse AIFS and CWMIN/CWMAX timers.

Takeaways:

Expect asymmetric and inconsistent QoS within your network, especially when BYOD is deployed (large variation of devices)! Fortunately, RFC 8325 addresses this by proposing a DSCP/UP mapping standard. Section 4.3 provides a good summary. Released in February 2018, so its fresh, and likely not build into many products today.

One phone manufacturer’s business driver could affect your entire campus QoS strategy. A single voice flow could have inconsistent QoS inside and outside of the CAPWAP tunnel, and also upstream and downstream from the AP. Be aware!

Nick has tested this on many mobile devices across all RFC 4594 recommended DSCP values and recorded the results, including plain English conclusions. The direct links to these resources are in the below reference material section. Nick has provided all of this 100% free!

Reference material:

Download tons of WLAN PCAPs, a test results matrix, and a QoS summary per RFC 4594. Save yourself the hassle! http://njrusmc.net/jobaid/jobaid.html

Wireshark filter used in this the discussion:

ip.id == 0x2e6d || ip.id == 0xcd77

Use the filter above on the following files:

  1. qos/marking/qos_marking_appleiphone6_alloy_wired.pcapng

  2. qos/marking/qos_marking_appleiphone6_alloy_wlan.pcapng

RFC 4594 – Config Guidelines for Diffserv

RFC 8325 – Mapping Diffserv to IEEE 802.11

Cisco Live Presentation: QoS Design and Deployment for Wireless LANs – BRKRST-2515

Presenter – Robert Barton, Principal Systems Engineer @ Cisco

How to stay engaged with Nick:

Website: http://www.njrusmc.net/

Twitter: https://twitter.com/nickrusso42518

LinkedIn: linkedin.com/in/nicholas-russo-63297541

Nick’s Github Repository: https://github.com/nickrusso42518/

Publications:

CCIE Service Provider Version 4 – Written and Lab Exam Comprehensive Guide By Nicholas (Nick) Russo

CCIE and CCDE Written Exam – Evolving Technologies Study Guide By Nicholas (Nick) Russo

BGP Traffic Engineering Server for Leaf-Spine Data Center Fabrics By Nicholas (Nick) Russo

Work with me: Through your participation in a healthy mentoring and coaching relationship, you will benefit greatly from the education, the experiences, the influences, leadership and even the resources provided. Learn how you can accomplish more, in one year, than you could accomplish in your career…in your business…and in your life.

Accomplish More Now!!

Provide Feedback

You can leave a comment on the blog!

You can leave a voicemail at (617) 913-4103

You can email us at Feedback@zigbits.tech

Transparency: This post may contain affiliate links to products or services were I may receive a level of compensation from your actions by following those links. This is seamless to you and does not add any additional cost to the products or services in question. In addition, I do not let any affiliate relationship cloud my judgement or my recommendation of a product or service. My recommendations will always be above reproach.  This is my commitment to you Ziglets!

The post ZNDP 035 – Wireless QoS Design appeared first on Zigbits - Where Zigabytes are faster than Gigabytes.

View Details

We are joined today with my good friend Tim McConnaughy and he brings us our design case study for today’s show! This show is all about Data Center Interconnect Design, its a design use case with BGP.  There is BGP, eBGP, and iBGP. This is a real customer solution deployed today in the wild so lets get into it!!

Guest Expert: Tim McConnaughy

Today’s expert is Tim McConnaughy.  Tim holds a CCIE in Routing and Switching, has 8 years of experience in network operations, design and architecture. Tim has travelled the world doing data center colocation builds/refreshes/migrations, remote office network redesigns/implementations, and as a Cisco Advanced Services NCE has worked with very large enterprise customers to deliver network designs to solve business needs.

  1. High level summary of Data Center Interconnect solution From a technology solution perspective, we deal mainly with eBGP and iBGP to facilitate the Data Center Interconnect from both the Service Provider side and our own.

Business Drivers, Requirements, & Constraints for Data Center Interconnect

Network in transition. The main campus was closing and the Data Center assets were needing to be moved to a new colocation. The staff was relocating to other various campuses.

The customer already had one data center which was connected to a MAN on which the old campus and some other old sites were connected. There were new fiber purchased to connect the old and new data centers as well as to allow those remote sites on the MAN to migrate. The plan was to decommission the old campus, data center and MAN and stand up the new data center with new connectivity in phases.

The major constraints were that the old Campus/Data Center/MAN had to keep operational while the new data center and new fiber runs were completed or purchased. A transition network was also set up to move the old data center data to the new data center servers

  1. Full list of technical solutions that were compared.

Customer came with a preliminary design which included eBGP between the 2 Data Centers and EIGRP as well as a full redistribution between the two planned for every hop-on / hop-off point.

In working with the customer we defined some areas of improvement, such as opportunities to keep the BGP path attributes intact for better path selection and limit points of redistribution.

After further exploration including an all-day whiteboard session, we identified that the proposed topology closely mimicked a CLOS spine/leaf topology which lent itself well to a full eBGP design.

This actually greatly simplified bringing in the MPLS L3 VPN provider into the WAN and setting up path preference and path redundancy between the two data centers.

3. Discuss the technical solution chosen and why The more we investigated good redistribution points and how it impacted traffic flow and complexity of path preference, the more we kept landing on BGP. There were a few prior constraints, for example, the firewalls use OSPF in the services towers, and the campus/local data center runs EIGRP and need to communicate directly, so there is some redistribution, but for the most part the vision of a CLOS topology was realized.

  1. What other technical solutions were there beside the Data Center Interconnect solution? If the services towers were designed differently and had not been self-contained islands we would likely not have ended up with the same topology, because eBGP is not as good at convergence as a traditional IGP, and if the lines were much less sharp between services, there would not have been as much of a drive to segment them from a traffic flow perspective. This would have clearly indicated a simple approach with a single IGP domain. 

How to stay engaged with Tim:

Website: http://carpe-dmvpn.com

Twitter:   https://twitter.com/juangolbez

LinkedIn: https://www.linkedin.com/in/tmcconnaughy/

Related Resources:

RFC-7938 Use of BGP for Routing in Large-Scale Data Centers

Mentoring and Coaching with Zig: Through your participation in a healthy mentoring and coaching relationship, you will benefit greatly from the education, the experiences, the influences, leadership and even the resources provided. Learn how you can accomplish more, in one year, than you could accomplish in your career…in your business…and in your life.

Accomplish More Now!!

Ask Zig: Ask Zig episodes feature answers to the questions that you provide. Yes You! The questions can be technical, business, certification, or personal related.  I can help out in all of these areas and much more.  If you would like your question spotlighted and answered on the next #AskZig episode submit them now!

Submit Your #AskZig Question Now!!

Provide Feedback

You can leave a comment on the blog!

You can leave a voicemail at (617) 913-4103

You can email us at Feedback@zigbits.tech

Engage with Zigbits further:

Subscribe to the podcast on an iPhone or on an Android

Follow Zigbits on Twitter!

Follow Zigbits on LinkedIn!

Follow Zigbits on Facebook!

Engage with me further:

Follow me on Twitter!

Follow me on LinkedIn!

Transparency: This post may contain affiliate links to products or services were I may receive a level of compensation from your actions by following those links. This is seamless to you and does not add any additional cost to the products or services in question. In addition, I do not let any affiliate relationship cloud my judgement or my recommendation of a product or service. My recommendations will always be above reproach.  This is my commitment to you Ziglets!

The post ZNDP 034 – Data Center Interconnect Design Use Case with BGP appeared first on Zigbits - Where Zigabytes are faster than Gigabytes.

View Details

The Iconic Mr. Nick Russo joins us once again for today’s topic of CI / CD … See Why?! Today we are picking up where Nick and I stopped in ZNDP Episode 30 – Designing for DevOps, if you didn’t get a chance to listen to that episode yet you can find it at zigbits.tech/30, If you need some context around DevOps you should definitely listen to Episode 30. For today’s topic we are discussing CI/CD which is Continuous Integration / Continuous Delivery/Deployment. And we are live in 3…2…1!!!

Continuous Integration in CI/CD Traditionally, developers would work in their own feature/topic branches for months, then deal with what is called “merge hell” towards the end of the project when entering the “integration testing” phrase. This is typically weeks or months as combining many silos of work is fraught with problems. This goes way past software development; the “divide and conquer” approach for any complex project is best accomplished by continuous lateral communication. CI means merging code together regularly (daily) which kicks off a comprehensive set of tests to ensure code functionality and quality. CI provides immediate feedback as to any problems that arise.

Commonly associated with software development, but can be applied more generically. In this use case, to a complex Ansible library used at a large customer.

Continuing from last time (ZNDP Episode 30), we discussed our specific purpose, along with the processes and tools to support it. How do we ensure quality? How do we know the machine built the right product? We checked the inputs, what about the fabrication steps?

Consider an automotive assembly operation (way overly simplified). First build the frame, then put the wheels on, then the body, then the glass. If the frame is defective, why put the wheels on? Let’s try to achieve “Quality at the source” through all the integration steps. This runs whenever code is committed or merged.

The CI Process in CI/CD:

  1. Lint all the code. Look for syntax/styling issues, and static code analysis to detect security threats. This takes seconds. Fail fast!

  2. Unit (filter) tests. Execute the individual units locally to ensure they function.

  3. Role tests. Roles typically rely on filters, so run those against some virtual devices.

  4. Playbook tests. Playbooks typically rely on roles, so run those against some virtual devices. For cost/runtime savings, you can stub out the virtual devices and provide mock data to the rest of the playbook, but this is less effective. This takes tens of minutes.

It usually doesn’t make sense to continue to the next step if a previous one fails. For example, if static code analysis reveals a security flaw, executing the code may pose a security risk.

Bonus feature: CI integrates with chat programs (chatops) to notify developers on-the-fly about activities. New comment/issue, code committed, pipeline pass/fail, etc. Common chat tools like Slack, Ryver, and Mattermost are used for this.

Consider even more creative examples, such as Nick’s OSPF Cisco Live discussion. Configs and markdown READMEs are up on github. Here is Nick’s Github Repository link. There is no real code here, just text documents and a diagram. 

Nick’s Troubleshooting OSPF – BRKRST-3010 Cisco Live Session:  – Session Presentation

– Video Recording

What’s the value of CI in CI/CD? First, linting the markdown documents ensures they look fresh and high quality. Second, maybe we can do some basic quality checking of the device configurations. There are 19 devices in the lab, and there are two folders (final and initial configs) each with 19 configs, for a total of 38. We can ensure that there are exactly 38 config files. We can also search the files for critical information, such as the author’s name and email (for assistance/questions). Last, we can search the files to ensure the hostname of the device (R1) is the same as the file filename (R1.txt) once the file extension is removed. It’s frustrating to log into a device with mixed up hostnames.

Is this a killer example of CI? Certainly not. But it’s better than nothing and helps prove the value of CI goes far beyond the software development world. A little bit of quality checking sets the basis for expansion later and provides you a degree of confidence.

Continuous Delivery and Continuous Deployment in CI/CD After code has been integrated, code can be delivered or deployed. These steps always occur after CI, which has integrated/tested the code extensively. Which one does CD stand for, “delivery” or “deployment”? Both actually.

Delivery Fully tested/integrated code is ready for delivery into production, but is manually deployed. After deployment, testing/monitoring still occurs automatically. Think of a big “easy button”, all the previous steps were automated but a human makes the final push.

Deployment The next logical step after continuous delivery, continuous deployment deploys code into production automatically after CI tests pass.

In Nick’s work environment with Gitlab CI, we only do continuous delivery. Remember, baby steps. We do not have an infrastructure-as-code solution, so continuous deployment doesn’t make sense. Many in the DevOps community feel that continuous delivery is a must-have, and I agree. Continuous deployment may not be appropriate for every business, but should remain a target/goal for many. It carries high risk for network devices that are typically deployed in lower density than servers (in terms of availability).

Nick’s best example of CD is how his website (http://www.njrusmc.net/) is deployed. 

AWS today doesn’t have S3 as a build target for CodePipeline, so instead, I use the AWS CLI from a CodeBuild step to copy files from CodeCommit to the S3 bucket hosting my static website. Both before and after this copy, I run linters for HTML and Python, then a detailed health check on the website’s HTML code, ensuring good-looking HTML and no dead hyperlinks. I am notified via email when pipelines begin, and when they complete with a PASS or FAIL status.

Initially, I was doing continuous delivery for my website. Once my code passed all tests and was staged for production, I manually copied the files into the S3 bucket. Then I started the post-install automated validation tests. I decided to upgrade to continuous deployment both to show a public example of how it works on a simple project, and to simplify my code updates.

In a network-based infrastructure-as-code environment, commiting an updated YAML file containing a list of firewalls ports/protocols kicks off the CI process to validate the changes. The continuous deployment process would idempotently (changing only what needs to be changed) update the firewall configurations based on the changes. The manner of this update could be anything, from SSH commands to REST, NETCONF, or gRPC API calls.

How to get started with CI/CD: Nick has used 3 different products for 3 purposes:

  1. Travis CI: Easy to use and free for open-source projects. Integrates seamlessly with Github, and I use this for all of my production-ready Github projects. It’s probably the best place to start! Travis.ci.org

  2. AWS CodeBuild/CodePipeline: More complex to use since these tools are wholly integrated with the AWS ecosystem of services. A pipeline contains many stages, one of which could be a build. The build has sub-stages as well. I use this to deploy my personal website and the source CI/CD code is publicly available to help you get started. It isn’t free, but is very affordable for small projects. Integration with CodeCommit (private Git repo) is very good, and works well for private code.

  3. Gitlab CI: Supported online (gitlab.com) or on-premises with a private installation. I use the private option at work. The initial setup is more complex as you have to create “runners” and register them to Gitlab. Runners can have a variety of executor types, like “shell” (what I use), “docker” (for spinning up docker containers within one runner), and more. Once the runner is registered, it’s just as easy as the others. The omnibus installation even comes with Mattermost built-in for simplified ChatOps!

There are endless others, but many have a similar configuration mechanism. Define a YAML file that determines the build/test sequence, usually something like install, pre build, build, post build …. or install, before script, script, after script. Minor language differences for similar concepts.

Nick’s examples with CI/CD:

Ansible playbooks (Travis CI)

Cisco Live Sessions (Travis CI)

Website (AWS CodeBuild/CodeDeploy)

Pete Lumbis example with CI/CD:

Cumulus Networking (Gitlab)

Call to Action:

What topics would you like us to spotlight on our next Design episode?

Guest Expert: Nicholas (Nick) Russo

Today’s guest Expert has become an icon within this industry. He holds Cisco Certified Design Expert (CCDE), and two Cisco Certified Internetwork Expert (CCIE), one in Routing & Switching and the second in Service Provider.  He is just coming off an amazing week at Cisco Live US 2018 in Orlando, Florida where he shattered the Cisco Live presentation bar with his Troubleshoot OSPF session! 

How to stay engaged with Nick:

Website: http://www.njrusmc.net/

Twitter: https://twitter.com/nickrusso42518

LinkedIn: linkedin.com/in/nicholas-russo-63297541

Nick’s Github Repository: https://github.com/nickrusso42518/

Publications:

CCIE Service Provider Version 4 – Written and Lab Exam Comprehensive Guide By Nicholas (Nick) Russo

CCIE and CCDE Written Exam – Evolving Technologies Study Guide By Nicholas (Nick) Russo

BGP Traffic Engineering Server for Leaf-Spine Data Center Fabrics By Nicholas (Nick) Russo

Related Resources:

ZNDP 030 – Designing for DevOps with Nick Russo

Making Work Visible: Exposing Time Theft to Optimize Work & Flow

Mentoring and Coaching with Zig: Through your participation in a healthy mentoring and coaching relationship, you will benefit greatly from the education, the experiences, the influences, leadership and even the resources provided. Learn how you can accomplish more, in one year, than you could accomplish in your career…in your business…and in your life.

Accomplish More Now!!

Ask Zig: Ask Zig episodes feature answers to the questions that you provide. Yes You! The questions can be technical, business, certification, or personal related.  I can help out in all of these areas and much more.  If you would like your question spotlighted and answered on the next #AskZig episode submit them now!

Submit Your #AskZig Question Now!!

Provide Feedback

You can leave a comment on the blog!

You can leave a voicemail at (617) 913-4103

You can email us at Feedback@zigbits.tech

Engage with Zigbits further:

Subscribe to the podcast on an iPhone or on an Android

Follow Zigbits on Twitter!

Follow Zigbits on LinkedIn!

Follow Zigbits on Facebook!

Engage with me further:

Follow me on Twitter!

Follow me on LinkedIn!

Transparency: This post may contain affiliate links to products or services were I may receive a level of compensation from your actions by following those links. This is seamless to you and does not add any additional cost to the products or services in question. In addition, I do not let any affiliate relationship cloud my judgement or my recommendation of a product or service. My recommendations will always be above reproach.  This is my commitment to you Ziglets!

The post ZNDP 033 – CI/CD … See Why? appeared first on Zigbits - Where Zigabytes are faster than Gigabytes.

View Details

Today’s show is all about Cisco ISE Client Authentication Design with Guest Expert Andy Richter, who is a Security Practice Manager and Distinguished Engineer at Presidio. This episode is a follow up episode from ZNDP # 29 – Cisco ISE Authentication Design!  In this episode we are focusing on the Client Authentication piece of the puzzle.  Andy and I talk about Supplicants, PEAP, EAP-TLS, EAP-Chaining, AnyConnect NAM, and much more! So much Tech in this episode so lets get to it!

Cisco ISE Client Authentication – Methodologies Overview

Discussion of general supplicant capabilities and limitations

Password vs certificate inner methods

Go over TLS tunnel for outer security – Preventing rogue WLANs

Server certificate trust design – Wildcard Certs and SAN Certs

User vs Machine

Cisco ISE Client Authentication – Supplicants Windows Native 

GPO

PEAP

EAP-TTLS

EAP-TLS

Prevent Guest access

Anyconnect NAM

MIX methods

EAP-Chaining – EAP-fast overview

Corp SSID

Wired Switching

Mac OSX

MDM/JAMF provisioned 

PEAP

TLS

Term of the Show:

What is a Supplicant?

Guest Expert: Andy Richter

Today we welcome back my good friend Andy Richter as our guest Expert! Andy is a Full-on Cisco ISE Expert, he has written one of the best Cisco ISE Books that I still personally use as a reference today.  He is actually the reason I learned ISE in the first place and he personally taught me some of the basics of ISE day one. He currently is a Distinguished Engineer and Security Practice Manager at Presidio!

How to engage with Andy further:

Twitter: https://twitter.com/quasinerd

LinkedIn: https://www.linkedin.com/in/andy-richter-b55a771/

Publications:

Practical Deployment of Cisco Identity Services Engine (ISE)

Call to Action:

What topics would you like us to spotlight on our next Design episode?

Mentoring and Coaching with Zig: Through your participation in a healthy mentoring and coaching relationship, you will benefit greatly from the education, the experiences, the influences, leadership and even the resources provided. Learn how you can accomplish more, in one year, than you could accomplish in your career…in your business…and in your life.

Accomplish More Now!!

Ask Zig: Ask Zig episodes feature answers to the questions that you provide. Yes You! The questions can be technical, business, certification, or personal related.  I can help out in all of these areas and much more.  If you would like your question spotlighted and answered on the next #AskZig episode submit them now!

Submit Your #AskZig Question Now!!

Provide Feedback

You can leave a comment on the blog!

You can leave a voicemail at (617) 913-4103

You can email us at Feedback@zigbits.tech

Engage with Zigbits further:

Subscribe to the podcast on an iPhone or on an Android

Follow Zigbits on Twitter!

Follow Zigbits on LinkedIn!

Follow Zigbits on Facebook!

Engage with me further:

Follow me on Twitter!

Follow me on LinkedIn!

Transparency: This post may contain affiliate links to products or services were I may receive a level of compensation from your actions by following those links. This is seamless to you and does not add any additional cost to the products or services in question. In addition, I do not let any affiliate relationship cloud my judgement or my recommendation of a product or service. My recommendations will always be above reproach.  This is my commitment to you Ziglets!

The post ZNDP 032 – Cisco ISE Client Authentication Design with Andy Richter appeared first on Zigbits - Where Zigabytes are faster than Gigabytes.

View Details

Hey Friends, Nerds, Geeks, and Ziglets out there, today’s Zigbits Network Design Podcast show number 31 is a recap of Cisco Live US 2018 which was held in Orlando, Florida.  We had The Force, Rides, Food, Drinks, Concerts, Technical Sessions, Keynotes, traditional Networking discussions, and a who lot more!!  Sit back and get readying for a great summary of Cisco Live US 2018!!!  Its Recap time, starting now!

Cisco Live US 2018 – Take Off!! Started off the day on the plane that I didn’t think was ever going to take off, but it did!! Not the best picture of me with my double chins!! . This is actually one of only a few pictures I took with my phone the entire week.  I also took a picture of my badge, never feel complete at Cisco Live without my Ribbons!!  

I got in late Sunday night but was able to get dinner with some of my CCIE R&S Study Group friends (more like brothers at this point).  We talk every day still even years after studying together and each year we do a couple of dinners at CLUS. A lot of us actually work at Cisco now so it’s really amazing to reflect on where we all started out years ago. All of our wives know each other now as well as they come to CLUS every year and hang out too.  I can’t emphasis how such a bond is formed when you are going through the same journey together.  We had some “midnight” pizza which we actually ordered from Dominos and had it delivered to the restaurant we were at. Everyone was staring at us!

Sadly, no pictures were taken of the midnight pizza but there are some with my original CCIE R&S Study Group. We called ourselves the CCIE Kool Kats. There have been a lot of jokes over the years from that name. If you are on social media you can follow our hashtag #CCIEKoolKats.  For the record, my friend Steven and I did not plan to wear the same shirt in the below picture.  Such is the life of nerds at #SummerCampForNerds.

Cisco Live US 2018 – WWT Party!! Every year at CLUS, one of the most sought-after parties, other than the CCIE party and CAE, is the WWT party.  The WWT party has been literally epic every year, last year in Vegas being the best!  I went this year with a number of people and it was a great party even though it rained, which will be a common theme throughout the week! They had carnival type games and a live Band that was very good playing 90’s music all night.  The food was hotdogs and pretzel bites (love them), and of course Beer, Wine, and Soda to drink.  Being the natural introvert, I am, my day had been overall taxing with the sessions I had gone too and the number of people I was catching up with, I had to recharge a little bit at the beginning of the WWT party (picture me in a corner eating pretzel bites and drinking water by myself for 30 minutes). I think WWT expected a lot more people to be at the party this year but because of the rain and having to move the band inside, it wasn’t as spectacular as years before, still a great party and I had a blast with my friends and co-workers throwing darts at balloons and other carnival type games.

Cisco Live US 2018 – CCIE Party…Is the Force Strong with you?  Tuesday Night was the CCIE Party!!  Star Wars Themed Party!! Literally awesome, though I think marketing did a bad job as it was very misleading to most people where the CCIE Party was going to be this year.  Most of us thought it was going to be at the World Showcase in Epcot but it was actually at the Epcot World Showplace. Once we understood the mistake, we were taken to this massive Star Wars themed building.  It was one huge room, where surprisingly we all fit.  Half the room was decorated for the Light Side and the other half was decorated for the Dark Side.  The theme didn’t stop at the decoration, the food was even matching the Light side and Dark side.  They also had most of the primary Star Wars characters in the building so you could take pictures with them.  Throughout the 3-hour party they had different Star War’s themed events, almost like a live play.  They had Star Wars trivia and a few other Star Wars games going on.  The food was really good, probably the best the entire week outside of a dinner at a couple of restaurants.  Near the end a few of us decided to get some pictures with the Stormtroopers but for whatever reason they didn’t get put on our card, so we never actually got them.  My wife got a picture with Chewbacca and Darth Vader, I was too busy running into people I knew, meeting people I only knew virtually, and talking a whole bunch to get any pictures with the characters!

Below is a picture of Dmitry Figol and I, with Silva Spiva photobombing us at the CCIE Party! I actually think the intent was for us all to have a photo together but it definitely looks like she is photobombing the picture. 

A couple of notes here:

Dmitry runs a Network automation / orchestration live stream on Twitch.tv.  Normally this site is used for stream video games, but he is using it to stream him doing automation / orchestration which I think is a great idea.  This past weekend he did a stream on Cisco NSO!  Here is his link:  https://www.twitch.tv/dmfigol

Silvia is also someone you should know of and given a chance should meet.  She is the Cisco DevNet Community Manager and has her hands in a lot of different public / social things.  She is also just an all around great person!

More Pictures of the CCIE Party!! Let the Force be with you!

Cisco Live US 2018 – The Customer Appreciation Event (CAE) Wednesday Night was The Customer Appreciation Event (CAE).  They rented out Universal Studios, not part of it, not half of it….The Entire Theme Park was rented out for the night.  For us it opened at 7pm and we were off.  I think the limiting factor with the Theme Park is that there is just so much to do, you really have to choose what’s most important to you.  Are you a thrill seeker and want to go on all of the Roller Coasters??  You could if you wanted too.  If you were more into music and concerts, you could have just found a good spot to stand / sit at a number of the different bands and performances playing (Sam Hunt, Blue Man Group, Cake, etc…).  Then of course there was food, and everything was open and free.  The downfall for the night was that it rained…wait it didn’t just rained it poured for over an hour.  The group I was hanging out with wanted to go to Hogwarts so we were literally running from one side of the park to the other when the downpour started.  For most of us, we weren’t going to let the rain ruin our fun.  The Harry Potter themed area was really cool, I had never seen it before.  We also did a number of other rides but one of my favorites was the Simpson’s ride.  For dinner, I had a chicken and waffle sandwich…Yum!! After dinner we decided to check out Sam Hunt’s concert before heading to the buses and calling it a night!  Below is a picture of me at the CAE before it started to rain with the Cisco Live HAT!!

Cisco Live US 2018 – The Final Day  My friend Steven and I decided to make a trip to Chuy’s for lunch, which is Brad Edgeworth’s favorite place to eat! We always like to give Brad a hard time.  We’ve been known to make BGP questions each year in an attempt to stump each other.  Two years ago, at the ICE Bar in Vegas, we were writing on the napkins trying to solve some weird BGP corner case Brad saw in TAC one day for hours.  So, we took a picture to send to him. He then gave us a verbal lashing on Social media and then decided to also go to Chuy’s a few hours later with Vinit Jain.  See both pictures below.  I couldn’t find the picture of our food though, so you get the picture of our pretty faces. What Nerds do when at #SummerCampForNerds

Outside of Customer Meetings, Sessions, Keynotes, and “Night Life” at Cisco Live US 2018!! When I wasn’t running, and I literally mean running at times, between the Customer Meetings, Technical Sessions, Keynotes, and the night life activities, there was the World of Solutions, The Social Hub, The Social Impact Area, and The Certification Lounge.  I also did three podcast episodes for my podcast, and another podcast episode for another podcasting brand.

World of Solutions (WoS) Pretty cool this year, not as big as the last two years in Vegas but still a lot of booths.  It took me all week to make it through all of the booths, I try to read / watch / take in each one to understand what the problem is they are solving.  I spent a lot of time at the Live Action booth with the LiveNX demo.

The Social Hub The social hub is usually a place where you can find a seat and chill for a few minutes, check email, do some work. The other thing that happens here is the traditional networking talks; meeting people for the first time, discussing things, etc… Last year I had done a Cisco Live Commercial here for the Social Team.  They added a number of things this year that I thought was neat.  You could play battleships, connect four, table tennis, and a number of other cool games, but they were rather life size.  If I can find a picture I will share it.

A picture of the social hub screen at CLUS, but it doesn’t do it justice or the World of Solutions justice but its what I could find.

The Certification Lounge I spent most of my “free” time here.  This is a lounge within the World of Solutions were anyone that holds a Cisco Certification can hang out.  And a lot of us hang out here.  I would plan to be here for 1 hour and before I knew it I was there for 3 or 4 hours.  A lot of the key players like to discuss new initiatives within the industry here as well.  I couldn’t find all of the pictures that others took but I was able to find some below.

Me, Tom Whaley, Jason Gooley, and Daniel Dib

Tom is one of 10 Cisco Certified Architects in the world and is a Cisco TSA!

Jason is a dual CCIE (R&S, SP), a Cisco Live Presenter, a CHINOG Organizer, and a Cisco TSA on the World Wide Team.

Daniel is a CCIE and CCDE (We studied together!) and currently works at Conscia Netsafe in Sweden as a Network Architect

The last day of the conference, Daniel Dib asked a group of us to take a picture for his Daughter’s Birthday so we did!!

Me and David Penaloza

David is a Social media beast!  He is on it all of the time.  He is also working on the CCDE which he took the practical in the last attempt!   We are hoping he will join the CCDE ranks soon!!

Me and Tim McConnaughy

I met Tim through a CCIE study group called Routergods.  Great guy and come to find out he actually works at Cisco as a NCE.  We will be doing a podcast episode in the near future

Scott Morris, Katherine McNamara, and I

A lot can be said about Scott.  He really has been around the industry for a long time, as you can see from the ribbons on his badge.  He holds 4 CCIEs, yes I said 4!!  He also is a CCDE, JNCIE-SP, and a JNCIE-ENT.  He is a Consultant for Cisco in the form of a contractor and also runs his own business called Alchemy Global Networks, LLC.

Katherine, or Kat as I call her (right or wrong is what has stuck). She is also known as the ISEQueen. She has two CCIEs, DC and Security (she just passed this one last month or so).  She is a Cisco Security CSE. She loves Cats!

Just Me and Silva in DevNet having fun!  Good times!!

Someone very motivated!!  Not sure who this actually was!

The Engineering Death Match Event this year! 

CCNP R&S Speed Question Challenge!

Some of the questions were mine!!!!!!

So, I always support the Engineering Death Match event.  It can get really crazy at times with people cheering on different competitors.  Last year’s event was multiple Design focused events and I was one of the EngDM Judge, with my CCDE Buddy Danial Dib!!!  So much fun!  This year was focused on the CCNP R&S and I submitted about 20 questions for the contestants to answer!

Cisco Live US 2018 – Studying for your CCIE R&S:

Troubleshooting OSPF – BRKRST-3310

Presenter – Nicholas Russo – Consulting Engineer, Cisco Systems

Can you draw a network diagram from having access to one router in an OSPF configured network?  If not then this session is totally for you!! Hands down the best technical presentation of OSPF I have ever seen.  This is how everyone should learn how to walk through the OSPF Database. 

Troubleshooting IS-IS – BRKRST-3302

Presenter – Brad Edgeworth – Systems Engineer, Cisco Systems

Multicast Troubleshooting – BRKIPM-2264

Presenter – Denise Fishburne – Solutions Architect, Cisco Systems

VRF, MPLS and MPBGP Fundaments – BRKCRT-2601

Presenter – Jason Gooley – Technical Solutions Architect, Cisco Systems

Cisco Live US 2018 – Key Technology Sessions for the future My personal Technology focus for Cisco Live was around the End to End solution / architecture picture so the below presentations fit that theme.

Securing your network from the desktop to the cloud with end-to-end segmentation – BSOGEN-2000

Presenter – Victor Moreno

Building the Vision: Design and Benefits of the End-to-end Cisco Policy Based Network Architecture – BRKARC-2015

Presenters

John Bartin – Systems Engineering Manager, Cisco Systems

Jerel Howell – CSE, Cisco Systems

Building an End-End Policy Driven Secure Hybrid Cloud DC Architecture – BRKSEC-2980

Presenter – David Jansen – Distinguished Systems Engineer, Cisco Systems

Cisco Live US 2018 – Keynotes The keynotes were ok this year, not the best but not the worst.  Last year’s keynote at CLUS17 in Las Vegas really set the bar high and I just don’t think the Keynotes met that same level this year.  I’ve received similar feedback from others, both customers and Cisco employees.  

Cisco Live has put all of the Keynotes from this year into a playlist at the following link.  It’s the first playlist at the top of the page.https://www.ciscolive.com/us/attend/about/daily-highlights/

Cisco Live US 2018 – Summary There is always more stuff to do than you can actually fit in the time you have at Cisco Live but I think I summarized it all as best as possible.  I met with a lot of customers.  We did a few Cisco Live NOC tours with said customers which was pretty sweet!  As always if you have any questions please let me know.

Call to Action:

What topics would you like us to spotlight on our next Design episode?

Mentoring and Coaching with Zig: Through your participation in a healthy mentoring and coaching relationship, you will benefit greatly from the education, the experiences, the influences, leadership and even the resources provided. Learn how you can accomplish more, in one year, than you could accomplish in your career…in your business…and in your life.

Accomplish More Now!!

Ask Zig: Ask Zig episodes feature answers to the questions that you provide. Yes You! The questions can be technical, business, certification, or personal related.  I can help out in all of these areas and much more.  If you would like your question spotlighted and answered on the next #AskZig episode submit them now!

Submit Your #AskZig Question Now!!

Provide Feedback

You can leave a comment on the blog!

You can leave a voicemail at (617) 913-4103

You can email us at Feedback@zigbits.tech

Engage with Zigbits further:

Subscribe to the podcast on an iPhone or on an Android

Follow Zigbits on Twitter!

Follow Zigbits on LinkedIn!

Follow Zigbits on Facebook!

Engage with me further:

Follow me on Twitter!

Follow me on LinkedIn!

Transparency: This post may contain affiliate links to products or services were I may receive a level of compensation from your actions by following those links. This is seamless to you and does not add any additional cost to the products or services in question. In addition, I do not let any affiliate relationship cloud my judgement or my recommendation of a product or service. My recommendations will always be above reproach.  This is my commitment to you Ziglets!

The post ZNDP 031 – Cisco Live US 2018 Recap appeared first on Zigbits - Where Zigabytes are faster than Gigabytes.

View Details

In Today’s Zigbits Network Design Podcast (ZNDP) episode we invite back an up an comming icon within this industry, my good friend Mr. Nick Russo to have a conversation around Designing for DevOps. If you’ve heard of DevOps in any form and even if you haven’t, you will want to tune in to this episode.  Nick and I get into a lot of real world examples of utilizing DevOps to meet business outcomes and requirements.  We also define a number of concepts and techniques that can help you when Designing for DevOps. Strap in for a great 90 minute show!

Designing for DevOps – Purpose, Process, People, Tools Purpose, Process, People, and Tools should be considered in sequence and its very important when we are discussing designing for DevOps.

Purpose: What are we trying to solve? Why does our organization even exist? What is the goal? Jim Womack: ”What do your customers want that you are not currently able to supply?” From the customer’s perspective, how do we add value?

Process: Set of dependent events to achieve the goal. Waste is any action taken that doesn’t add value (and for which customers would not be willing to pay)

People: People must understand the purpose and design/improve processes to achieve it

Tools: Tools are the mechanisms by which we implement steps in a process to add value. We in IT focus far too much on this. Automation solutions are just tools in our toolbox, just like OSPF, EIGRP, Inter-AS options, and CSC.

Designing for DevOps – Analogies

A race car with me driving

A Kia Optima with a professional driver

A race car with a professional driver but only allowed to drive up to second gear

None of these combinations are likely to win the race.

Holistic look at process improvement through an entire system.

Designing for DevOps – Types Purposes vs Business Drivers:

Growth:

Take risks and show a decisive competitive edge without cost concerns. think Amazon, very few profitably quarters, almost 500B market cap.

Profitability:

Focus on new revenue streams (external) and cost reduction (internal). external like generating reports from web servers to marketing faster (lower lead time). internal like faster resolution of tickets with better quality, less rework (lower operating expense).

Stability:

Typically not true for companies, but definitely for govt. start small and be conservative

Enterprise vs Service Provider:

Enterprise:

Internal IT service team would be focused on bug fixes, request fulfillment, WAN expansion/migration, etc. IT as a service provider for the business

External: Ecommerce websites, marketing analytics, etc. IT as a business partner

Similar for military. one group of people focuses on providing access to users, the other designs the comms plan for military operations

Service Provider: been automated for a long time

Service provisioning: edge services to deliver customer connectivity. short lead time and customer flexibility, sometimes even customer control

Core routing: TE optimization, HA/FRR, cost reduction to avoid expensive DWDM equipment upgrades (capex) or new fiber runs

Brownfield vs Greenfield:

Brownfield:

Less tolerance for risk, slower migration, backwards compatibility with older stuff (unusable via SSH, not some API-based mechanism). start small and focus on business value. processes tend to be crystalized

Greenfield:

With proper planning, easier to do right the first time, which is generally less expensive over the long term. example: NETCONF serializing XML over SSH based on YANG models. if the network is new, more than likely the processes used to manage the network are also new. be sure to map out the procedural steps in advance and target your automation towards the bottleneck pieces

Designing for DevOps with Scalability in mind: With automation, scale often means scaling up/out the automation system to manage the large device count. once you define the golden config and have it in version control, ensuring it is applied to all devices (IAC model) doesn’t take much more logical effort. of course this is product specific. its similar to code. copy/pasting code and lack of abstractions (like functions) is less acceptable as the code grows. example: Ansible static inventory gets less attractive as system grows. but the playbooks don’t really change. also consider the load on your process steps (bottleneck)

Designing for DevOps – Our Story  Background: Government is bureaucratic. Its the race car with professional drivers but constrained to second gear example above. Broken processes drive the craze over panacea tools to solve all problems.

Our purpose: improve product quality without increasing cost or lead time

Challenges:

Customers regularly change their orders just hours before they are due to be shipped

When the product is delivered, the customer may procrastinate performing a quality check

Our Process: Side note: most of our processes are configure to order, so our bottleneck is our first processing step. Our fabrication activities that feed assembly are fast!

  1. Time the release of materials to some fixed time before they are due for shipment. eg, customer places order 30 days in advance, but production only takes 30 minutes. release materials 2 days prior to delivery a few days early. ideally, materials should be released as close to 30 minutes prior as possible. The longer the gap between material release and shipment, the more likely rework is needed.

  2. Before fabrication begins, a series of integrated checks on operator input is conducted.  This allows for “fail fast” to minimize NVA time.

  3. Track the product as WIP until it is delivered to the customer. Use the Kanban methodology to enforce WIP limits per product type (level by mix).

  4. Fabrication activities (configs, documents, checksums, etc) and the assembly of these files into a winzip bundle is fully automated. There is no need to maintain finished goods inventory as products are shipped immediately (we keep a copy, but comes at insignificant carrying cost)

Quality Testing: How do we know the machine built the right product? We checked the inputs, what about the fabrication steps?

Continuous integration: Quality at the source and throughout an ansible CI pipeline. This runs whenever code is committed or merged.

  1. Lint all the code. look for syntax/styling issues, and static code analysis to detect security threats

  2. Unit (filter) tests. execute the individual units locally to ensure they function

  3. Role tests. roles typically rely on filters, so run those against some virtual devices

  4. Playbook tests. playbooks typically rely on roles, so run those against some virtual devices

It doesn’t make sense to continue to the next step if a previous one fails. For example, if static code analysis reveals a security flaw, executing the code in the unit tests is unwise.

CI integrates with chat programs (chatops) to notify developers on-the-fly about activities. New comment/issue, code committed, pipeline pass/fail, etc

Tool Itself The main purpose is to create files (take from readme).  Suppose you have a branch site with a router, switch, and firewall. you have 8 branches. You will end up with 8 folders with 3 configs each. You’d make 3 templates (r, s, f) and specify 8 entities with their unique inputs, like IP ranges, etc

Some extra features:

  1. Infra: supporting infrastructure for the sites. update the SNMP map, AAA server, BGP route-reflectors, or DMVPN headend

  2. Checksum: SHA256 computed for each file to ensure integrity when delivering to customer

  3. Docs: each entity can have an auto-generated document, like a site diagram, to accompany it. Jinja2+LaTeX

On the surface, doesn’t seem impressive. no device logins and still a lot of manual application. That’s just how it is right now. Removing waste never happens in one pass. New waste is revealed each time old waste is removed. This is progress!!

Tips for Starting out with Designing for DevOps Start with: what is your purpose?

Risk-averse managers are not going to fall for “infra as code” on day 1. Most will be afraid to even let automated tools make changes. Start small, with baby steps that lead to an end goal and an end destination.

– Instead of doing configs manually, auto generate files. We are here!!.

– Then, write them direct to devices (as if copy/pasted)

– Then, make it idempotent, adding in only the things that change

– Then, stop using CLI, and migrate to structured data serialization through APIs

We already know automation can:

  1. Improve quality by reducing variation (more consistent results)

  2. Reduce lead time by increasing throughput for the same WIP (less time spent in fab)

  3. Reduce cost by decreasing rework (corollary of increased quality) via direct labor

Kind of flies in the face of quality, speed, cost (QSC) but I know for a fact it works!

The code is here on Github, and the specific tool we discussed is called “mkfd”

Term of the Show:

What is the definition of DevOps?

Call to Action:

What topics would you like us to spotlight on our next Design episode?

Guest Expert: Nicholas (Nick) Russo

Today’s guest Expert has become an icon within this industry, he has been featured on the community show, The Network Collective, he has been on our show episode 5 (ZNDP 005 – Carrier Supporting Carrier (CSC) with Nick Russo) where we talked about CSC for 90 minutes. He holds Cisco Certified Design Expert (CCDE), and two Cisco Certified Internetwork Expert (CCIE), one in Routing & Switching and the second in Service Provider.  He is just coming off an amazing week at Cisco Live US 2018 in Orlando, Florida where he shattered the Cisco Live presentation bar with his Troubleshoot OSPF session! 

How to stay engaged with Nick:

Website: http://www.njrusmc.net/

Twitter: https://twitter.com/nickrusso42518

LinkedIn: linkedin.com/in/nicholas-russo-63297541

Nick’s Github Repository: https://github.com/nickrusso42518/

Publications:

CCIE Service Provider Version 4 – Written and Lab Exam Comprehensive Guide By Nicholas (Nick) Russo

CCIE and CCDE Written Exam – Evolving Technologies Study Guide By Nicholas (Nick) Russo

BGP Traffic Engineering Server for Leaf-Spine Data Center Fabrics By Nicholas (Nick) Russo

Related Resources:

Making Work Visible: Exposing Time Theft to Optimize Work & Flow

Mentoring and Coaching with Zig: Through your participation in a healthy mentoring and coaching relationship, you will benefit greatly from the education, the experiences, the influences, leadership and even the resources provided. Learn how you can accomplish more, in one year, than you could accomplish in your career…in your business…and in your life.

Accomplish More Now!!

Ask Zig: Ask Zig episodes feature answers to the questions that you provide. Yes You! The questions can be technical, business, certification, or personal related.  I can help out in all of these areas and much more.  If you would like your question spotlighted and answered on the next #AskZig episode submit them now!

Submit Your #AskZig Question Now!!

Provide Feedback

You can leave a comment on the blog!

You can leave a voicemail at (617) 913-4103

You can email us at Feedback@zigbits.tech

Engage with Zigbits further:

Subscribe to the podcast on an iPhone or on an Android

Follow Zigbits on Twitter!

Follow Zigbits on LinkedIn!

Follow Zigbits on Facebook!

Engage with me further:

Follow me on Twitter!

Follow me on LinkedIn!

Transparency: This post may contain affiliate links to products or services were I may receive a level of compensation from your actions by following those links. This is seamless to you and does not add any additional cost to the products or services in question. In addition, I do not let any affiliate relationship cloud my judgement or my recommendation of a product or service. My recommendations will always be above reproach.  This is my commitment to you Ziglets!

The post ZNDP 030 – Designing for DevOps with Nick Russo appeared first on Zigbits - Where Zigabytes are faster than Gigabytes.

View Details

Today’s Zigbits Network Design Podcast (ZNDP) is being recorded at Cisco Live US 2018! Today’s show is all about Cisco ISE Authentication Design with Guest Expert Andy Richter, who is a Security Practice Manager and Distinguished Engineer at Presidio. There is a whole bunch of technology in this episode, so get out your pens and notepads, turn up your volume and lets get started!

Cisco ISE Authentication Design Overview

Cisco ISE intro

Authentication methods

Deployment options

Cisco ISE Authentication Design Enforcement Methodologies

Wired

VLAN override

dACL

Wireless

VLAN override

Airspace ACL

QoS and other cool shit

Cisco ISE Authentication Design Corporate vs BYOD Auth

Corporate

EAP-TLS

EAP-Chaining/AC

PEAP – Machine Only

BYOD

PEAP – User

Web auth

NSP

Cisco ISE Authentication Design Misc

Trustsec

SGT

SGACL

SXP

MACSEC

Manual PSK

ISE

Call to Action:

What else would you like to know about Cisco ISE?

Hosted By: Michael “Zig” Zsiga

Guest Expert: Andy Richter 

How to engage with Andy further:

LinkedIn Profile

Twitter Profile

Publication – Practical Deployment of Cisco Identity Services Engine (ISE)

Related Resources: Cisco ISE Community

Mentoring and Coaching with Zig: Through your participation in a healthy mentoring and coaching relationship, you will benefit greatly from the education, the experiences, the influences, leadership and even the resources provided. Learn how you can accomplish more, in one year, than you could accomplish in your career…in your business…and in your life.

Accomplish More Now!!

Ask Zig: Ask Zig episodes feature answers to the questions that you provide. Yes You! The questions can be technical, business, certification, or personal related.  I can help out in all of these areas and much more.  If you would like your question spotlighted and answered on the next #AskZig episode submit them now!

Submit Your #AskZig Question Now!!

Provide Feedback

You can leave a comment on the blog!

You can leave a voicemail at (617) 913-4103

You can email us at Feedback@zigbits.tech

Engage with Zigbits further:

Subscribe to the podcast on an iPhone or on an Android

Follow Zigbits on Twitter!

Follow Zigbits on LinkedIn!

Follow Zigbits on Facebook!

Engage with me further:

Follow me on Twitter!

Follow me on LinkedIn!

Transparency: This post may contain affiliate links to products or services were I may receive a level of compensation from your actions by following those links. This is seamless to you and does not add any additional cost to the products or services in question. In addition, I do not let any affiliate relationship cloud my judgement or my recommendation of a product or service. My recommendations will always be above reproach.  This is my commitment to you Ziglets!

The post ZNDP 029 – Cisco ISE Authentication Design with Andy Richter appeared first on Zigbits - Where Zigabytes are faster than Gigabytes.

View Details

Today’s Zigbits Network Design Podcast (ZNDP) covers Cisco Live US 2018! Today we discuss what Cisco Live means to me and what it should mean to you, How to get the most out of Cisco Live each year, and some of my recommendations for this week! Turn up your volume, start the podcast, and lets do it! 

Zig’s Cisco Live US 2018 Message I cover the following topics:

What does Cisco Live mean to me?

How you can Get the most out of Cisco Live!!

My Cisco Live Recommendations

Call to Action:

If this was your brand and your content, what would you like to see happen here?

Hosted By: Michael “Zig” Zsiga

Guest Expert: None

Related Resources: Cisco ISE Community

Mentoring and Coaching with Zig: Through your participation in a healthy mentoring and coaching relationship, you will benefit greatly from the education, the experiences, the influences, leadership and even the resources provided. Learn how you can accomplish more, in one year, than you could accomplish in your career…in your business…and in your life.

Accomplish More Now!!

Ask Zig: Ask Zig episodes feature answers to the questions that you provide. Yes You! The questions can be technical, business, certification, or personal related.  I can help out in all of these areas and much more.  If you would like your question spotlighted and answered on the next #AskZig episode submit them now!

Submit Your #AskZig Question Now!!

Provide Feedback

You can leave a comment on the blog!

You can leave a voicemail at (617) 913-4103

You can email us at Feedback@zigbits.tech

Engage with Zigbits further:

Subscribe to the podcast on an iPhone or on an Android

Follow Zigbits on Twitter!

Follow Zigbits on LinkedIn!

Follow Zigbits on Facebook!

Engage with me further:

Follow me on Twitter!

Follow me on LinkedIn!

Transparency: This post may contain affiliate links to products or services were I may receive a level of compensation from your actions by following those links. This is seamless to you and does not add any additional cost to the products or services in question. In addition, I do not let any affiliate relationship cloud my judgement or my recommendation of a product or service. My recommendations will always be above reproach.  This is my commitment to you Ziglets!

The post ZNDP 028 – Zig’s Cisco Live US 2018 Message appeared first on Zigbits - Where Zigabytes are faster than Gigabytes.

View Details

ZNDP 027 – The Year of Identity Today’s Zigbits Network Design Podcast (ZNDP) is all about what we did in the last year…Its The year of Identity Episode.  Today we discuss the current Identity Crisis / Process we are going through behind the scenes.  Lets Jump right in!!  Turn up your volume, start the podcast, and lets do it!

One year Identity…Introspection Time! As we round out the first year of the Zigbits brand, its time for some introspection. We have come a long way in a year.  When I started all of this a year ago, I had no idea what I was doing, I had no end goal or destination in mind, and I had no overall purpose or direction.

Identity Crisis and Current Process Reaching out to Peers, Mentors, Friends, and Followers for guidance. The comments and feedback I’ve received has been very humbling, very amazing! My initial reaction was “I had no idea people felt this way”.  Below is a quick list of some of the comments I received from you.

You feel like an introvert, but its not what someone would think communicating with you

Extreme Ownership

Hard-working-to-a-ridiculous-level

Insatiable hunger for knowledge

Catalyst Aurora

Approachable – Some smart people are completely unapproachable out of fear of coming off stupid

Inherent Team Leader & Mentor

Wide range of knowledge

Ability to translate business speak into design

Strong communication skills

Ability to paint the big picture

Trusted Advisor

Be both an Architect and a SME

Ambitious

Strong technical Skills

Business Acumen

Understanding of technical debt

Reliable professional opinion

Self-disipline

Dogged persistence

Genuine

Generous with time

Humble

Competence

Customer Satisfaction

Military background

Like to get stuff done

Integrity

High level of energy but don’t feel rushed

Friendly and inviting narrative

Generous

Can tackle any subject and make it look easy

Friendly

Outgoing

Modest

Technically professional

Down to Earth

Not overpowering or overdone

Passion

Positivity

Dogged determination

Drive to find new ways to help

Commitment to helping others

A combination of expertise and the ability to transfer it in an un-intimidating way

Current Identity Crisis Process Outcome I started to go through this process of determining my Identity, more specifically what is the Zigbits brand Identity and what do I actually want to do with it.  This has been the hardest part honestly above anything else.  Actually putting words together to state a purpose for all of this. I want this to be more than just providing real world context around technology. I’m not diminishing it, but its not the single purpose that I feel called to do.  Its a pillar and part of the overall foundation, but its not everything. With all of that, here is my current draft of Value Proposition Statement:

I am a natural born leader, mentor, and coach with 20 years of experience ranging from the Military / Government world to the commercial and retail industries. I’m a United States Marine! I’m an Influencer, Thought Leader, and a Trusted Advisor. I maintain a level of Integrity, Motivation, Determination, Dedication and Commitment that I naturally instill in others around me: AKA My Catalyst Aurora!

My goal is to build a long lasting relationship with each professional I come in contact with be it directly or indirectly which will allow me to provide them value by leading, mentoring, and coaching them indefinitely.  This is something that I feel in my heart that I am called to do.

I provide a friendly and collaborative environment for Network Engineers, Network Architects, and C Level Executives with relevant Content, Products, and Services that solve the ever growing list of Business and Technology problems we have today. Together, we are bridging the gap between the Business and Technology sides of the industry!

Call to Action:

If this was your brand and your content, what would you like to see happen here?

Hosted By: Michael “Zig” Zsiga

Guest Expert: None

Thank you for the podcast reviews! Thank you for the iTunes reviews as they sincerely motivate me to continue to give back to this community that I love.  If you enjoy the podcast and the information I share, please feel free to write your own personalized review on iTunes!

Ask questions and give feedback

You can leave a comment on the blog!

You can leave a voicemail at (617) 913-4103

You can email us at Feedback@zigbits.tech

Engage with Zigbits further:

Subscribe to the podcast on an iPhone or on an Android

Follow Zigbits on Twitter!

Follow Zigbits on LinkedIn!

Follow Zigbits on Facebook!

Engage with me further:

Follow me on Twitter!

Follow me on LinkedIn!

Transparency: This post may contain affiliate links to products or services were I may receive a level of compensation from your actions by following those links. This is seamless to you and does not add any additional cost to the products or services in question. In addition, I do not let any affiliate relationship cloud my judgement or my recommendation of a product or service. My recommendations will always be above reproach.  This is my commitment to you Ziglets!

The post ZNDP 027 – The Year of Identity appeared first on Zigbits - Where Zigabytes are faster than Gigabytes.

View Details

Cisco Live US 2018 Its that time of the year!  Cisco Live US 2018!!!! Its only a few more weeks away! As we started last year, today’s episode is all about maximizing your time while at Cisco Live US 2018 towards Network Design and the Cisco Certified Design Expert Certification!

Related Posts:

ZNDP 023 – CCDE Practical Exam Recommendations and Tips

ZNDP 020 – Ask Zig – What is Your CCxE Methodology?

ZNDP 010 – An Overview of the Cisco Certified Design Expert (CCDE) Certification with Jeremy Filliben

ZNDP 008 – Ask Zig – What CCxE Should You Pursue?

ZNDP 004 – Cisco Live US 2017 – Preview

CCDE / Network Design Specific Sessions This year there are well over 1000 Cisco Live Sessions and I’ve looked through them all, a time consuming task, and have narrowed the Zigbits CCDE / Network Design Session list down to a little more than 50 sessions to choose from.  These are sessions that fit the Design bucket but are also not just a beginner session on a technology.  The idea here is to get the best use of your time while you are at Cisco Live.  Each session in this list has been given a priority level of importance that is either High, Medium, or Low.

High

TECCCDE-3005: CCDE: The Cisco Certified Design Expert $$ *

LTRCCDE-3006: Advanced – CCDE Lab $$ *

BRKMPL-2118: Evolving Network Application Use-Cases Using Segment Routing In the Enterprise

BRKDCN-2035: VXLAN BGP EVPN based Multi-Site 

BRKSPG-2202: Deploying Carrier Ethernet services using Cisco Metro Fabric and Ethernet VPN (EVPN) 

BRKCRS-2501: Campus QoS Design-Simplified

BRKSPG-2509: BGP-EVPN and SR Fabric – Addressing the evolving Data Center requirements 

BRKMPL-2110: Enterprise MPLS – Customer Case Studies 

BRKMPL-2116: Design & Customer Use Cases: MPLS, Segment Routing and SD-WAN in Enterprise Networks *

BRKRST-2301: Intermediate – Enterprise IPv6 Deployment 

BRKRST-2501: Enterprise QoS Design 5 *

BRKIPM-3017: mVPN Deployment Models *

BRKRST-3122: Segment Routing: Technology deep-dive and advanced use cases 

BRKMPL-2102: Designing MPLS-based IP VPNs 

BRKRST-2337: OSPF Deployment in Modern Networks *

BRKMPL-2100: Deploying Traffic Engineering in MPLS and Segment Routing Backbones *

FLPDCN-3378: Building DataCenter networks with VXLAN BGP EVPN *

BRKMPL-2115: MPLS Architectural approaches for Data Center and Cloud 

BRKIPM-2249: Multicast and Segment Routing *

Medium

TECCRS-2500: Advanced Enterprise WAN Design and Deployment $$

TECCRS-2001: Intermediate – Enterprise High Availability Design and Architecture $$

LTRMPL-3843: Design, Deployment and Troubleshooting Scalable MPLS Architecture (Platform : IOS-XR, IOS-XE) $$ 

BRKOPT-2000: Deploying Data Center Interconnect with Wavelength Division Multiplexing 

BRKCRS-1500: Introduction to Campus Wired LAN Deployment Using Cisco Validated Designs 

INSSPG-1500: Intelligent, Mass-Scale Networking for Secure, Critical Infrastructure 

BRKSPG-2777: What DC Fabrics Can Teach Us About SP Core Design…or Not! 

PSOOPT-2100: Data Center Interconnect (DCI) Architectures Leveraging Dark Fiber & Dense Wave Division Multiplexing (DWDM)

BRKRST-2352: OSPF and IS-IS: A Comparative Anatomy

BRKDCN-3378: Building DataCenter Networks with VXLAN BGP EVPN 

BRKMPL-2114: Integrating Campus/DC fabrics with MPLS 

BRKMPL-3333: EVPN: Network Virtualization Solution for Next Generation Enterprise DCs, DC Interconnections, and SPDCs 

TNKIOT-1003: The Modern Factory Design 

BRKDCN-2300: Modern Infrastructure Designs of Business Continuity Architectures * 

BRKRST-2041: WAN Architectures and Design Principles 

BRKMPL-2112: MPLS WAN Backbone Solutions and Design for Enterprise and SP 

PNLGEN-1001: Cisco Live Network and NOC Panel 

BRKOPT-1001: Transport Network Modernization and TDM to IP Migration 

BRKSEC-2881: Designing Remote-Access and Site-to-Site IPSec networks with FlexVPN 

Low

BRKCCIE-3004: A CCIE’s Introduction to MPLS Networks 

BRKRST-2616: Beyond Dual-Stack: Using IPv6 like you’ve never imagined 

BRKRST-2042: Highly Available Wide Area Network Design 

BRKDCN-2218: Data Center Design for the Midsize Enterprise 

BRKOPT-2106: DWDM 101 and Technology Advances *

BRKSEC-3052: Demystifying DMVPN 

LTRMPL-2108: MPLS and Its Applications $$ – Lab

BRKSAN-2883: Advanced Storage Area Network Design 

BRKCCIE-3000: BGP is your Friend – BGP for the CCIE Candidates 

BRKRST-2515: QoS Design and Deployment for Wireless LANs 

BRKSPM-2034: 5G Mobile Transport Design and Deployments 

BRKRST-2309: Introduction to WAN MACsec – Aligning Encryption Technologies with WAN Transport 

FLPSPG-2602: IPv4 Exhaustion: NAT and Transition to IPv6 for Service Providers 

FLPSDN-2410: Carrier Grade NFVI for Service Providers *

BRKEWN-2013: High Density Wi-Fi Design, Deployment, and Optimization

BRKRST-2124: Introduction to Segment Routing

BRKEWN-2027: Design and Deployment of Outdoor Wireless Networks 

BRKCRT-2601: VRF, MPLS and MPBGP Fundamentals

$$ – Addition Cost Sessions

  • – Sessions included in schedule

A Zigbits “Network Design” Session Schedule The goal of the Zigbits “Network Design” Session Schedule is to give you the most amount of time in Design and Business related sessions that you can be in at Cisco Live US 2018.  There are no limits and the only constraint is to make time for the Keynote sessions throughout the week.  If your goal for Cisco Live is to dedicate all of your time towards Network Design or Studying for the CCDE Certification than this schedule is for you!!

Zigbits Cisco Live US Network Design / CCDE Session Schedule Cisco Live US Day 1 – Sunday June 10th, 2018 I would do a paid session on Sunday. There are three great sessions to select from. These are all day sessions – 8 hours.

TECCCDE-3005: CCDE: The Cisco Certified Design Expert $$

TECCRS-2500: Advanced Enterprise WAN Design and Deployment $$

TECCRS-2001: Intermediate – Enterprise High Availability Design and Architecture $$

Cisco Live US Day 2 – Monday June 11th, 2018

8:30am – 10:00am

BRKCRS-1500: Introduction to Campus Wired LAN Deployment Using Cisco Validated Designs 

BRKRST-2616: Beyond Dual-Stack: Using IPv6 like you’ve never imagined 

I would probably go with BRKCRS-1500 over BRKRST-2616 but it will really depend on your areas of expertise and weaknesses.

10:30am – 11:30am

Opening Keynote

1:00pm – 5:00pm

LTRCCDE-3006: Advanced – CCDE Lab $$

I would highly recommend the CCDE Lab Session on Monday afternoon but this does require an extra fee.If you have the money available I would definitely sign up for LTRCCDE-3006, but if not here is a second set of sessions for Monday Afternoon.

1:00pm – 1:30pm

INSSPG-1500: Intelligent, Mass-Scale Networking for Secure, Critical Infrastructure

1:30pm – 3:30pm

BRKMPL-2118: Evolving Network Application Use-Cases Using Segment Routing In the Enterprise

4:00pm – 5:30pm

BRKMPL-2110: Enterprise MPLS – Customer Case Studies 

Cisco Live US Day 3 – Tuesday June 12th, 2018

8:00am – 10:00am

BRKMPL-2116: Design & Customer Use Cases: MPLS, Segment Routing and SD-WAN in Enterprise Networks 

10:30am – 11:30am

Technology Keynote

1:30pm – 3:30pm

BRKRST-2501: Enterprise QoS Design 5 

4:00pm – 5:30pm

BRKOPT-2106: DWDM 101 and Technology Advances 

Cisco Live US Day 4 – Wednesday June 13th, 2018

8:00am – 10:00am

BRKIPM-3017: mVPN Deployment Models 

10:30am – 12:00pm

BRKRST-2337: OSPF Deployment in Modern Networks

1:30pm – 3:30pm

BRKDCN-2300: Modern Infrastructure Designs of Business Continuity Architectures 

Or

1:30pm – 3:00pm

BRKRST-2515: QoS Design and Deployment for Wireless LANs 

3:00pm – 4:00pm

FLPSPG-2602: IPv4 Exhaustion: NAT and Transition to IPv6 for Service Providers 

Then

4:30pm – 5:30pm

FLPSDN-2410: Carrier Grade NFVI for Service Providers 

With either option you decide to go with here between 1:30pm – 4:00pm, you will still be able to make the FLPSDN-2410 session at 4:30pm.

Cisco Live US Day 5 – Thursday June 14th, 2018

8:00am – 10:00am

BRKMPL-2100: Deploying Traffic Engineering in MPLS and Segment Routing Backbones 

10:00am – 11:00am

FLPDCN-3378: Building DataCenter networks with VXLAN BGP EVPN 

1:00pm – 2:30pm

BRKIPM-2249: Multicast and Segment Routing 

3:00pm – 4:00pm

Closing Keynote

Recommendations for Cisco Live US 1. Wear some nice comfortable shoes

  1. Stay hydrated

  2. Take breaks

  3. Get some sleep

  4. Don’t over book yourself

  5. Make time for the unexpected… Make time for “Network Nirvana” discussions!

The Term of the Show

Mean Time Between Failures (MTBF)

Call to Action:

Share this content with someone you believe would benefit from it as much as you have!

Hosted By: Michael “Zig” Zsiga

Guest Expert: None

Thank you for the podcast reviews! Thank you for the iTunes reviews as they sincerely motivate me to continue to give back to this community that I love.  If you enjoy the podcast and the information I share, please feel free to write your own personalized review on iTunes!

Related Resources:

Paid for sessions cost break down:

Lab Instructor lead 2 hours – 295.00

Lab Instructor lead 4 hours – 695.00

Lab Instructor lead 8 hours – 1095.00

Technical Seminar 4 hours – 595.00

Technical Seminar 8 hours – 895.00

Ask questions and give feedback

You can leave a comment on the blog!

You can leave a voicemail at (617) 913-4103

You can email us at Feedback@zigbits.tech

Engage with Zigbits further:

Subscribe to the podcast on an iPhone or on an Android

Follow Zigbits on Twitter!

Follow Zigbits on LinkedIn!

Follow Zigbits on Facebook!

Engage with me further:

Follow me on Twitter!

Follow me on LinkedIn!

Transparency: This post may contain affiliate links to products or services were I may receive a level of compensation from your actions by following those links. This is seamless to you and does not add any additional cost to the products or services in question. In addition, I do not let any affiliate relationship cloud my judgement or my recommendation of a product or service. My recommendations will always be above reproach.  This is my commitment to you Ziglets!

The post ZNDP 026 – Cisco Live US 2018 Network Design & CCDE Focused Sessions appeared first on Zigbits - Where Zigabytes are faster than Gigabytes.

View Details

Data Center Migration

Hey Friends, Nerds, and Geeks, we are back today with our Audio podcast show # 25 and its a Guest Expert show! My good friend Malcolm Booden from the UK Joined me in Jan for a discussion around Designing for Data Center Migration and Application Mobility.  We talk about a lot of different concepts, perspectives, and items to keep in mind in when you are going through an event like this.  Today is the first part of the discussion. So sit back, turn up the volume and enjoy the show!

Data Center Migrations We are going to talk about data center design and more specifically design when migration of Data Center services either to a private or public cloud are considerations. What should you think about when performing a Data Center migration of any magnitude, and what is the thought process that has to come with such an initiative?

What is really involved in planning a Data Center migration. No matter what specific type of Data Center migration you’re performing, the main things to understand before you start the design are:

The Five Main items to Consider

Business drivers and constraints

Applications in scope

WAN topology

Traffic Flows (users and apps)

What is in place now?

Data Center Migrations vary in size and complexity Data Center migrations can vary in size and complexity and be very different depending on what the objective is, but we can touch on a few different Data Center migration types and what may drive each of them:

First of all there’s different scope and scale of a Data Center migration depending on what is happening. Large scale migration of tens to hundreds or thousands of apps, or is an application being moved to a new location i.e. SAAS cloud, hosted etc.  For now, we are going to concentrate on “full” Data Center migrations where multiple apps need to be migrated.

New applications or services being deployed in a new Data Center for specific purpose i.e.

Cloud app, private cloud app

Micro-Clouds

Micro-Services

More of an application migration

Data Center migration could be replacing critical infrastructure such as the Data Center core switching architecture, like for like or to a different platform i.e. to new vendor or introducing an overlay to deliver Software Defined Data Center (SDDC) where applications are remaining unchanged.

Moving applications from one Data Center to another for one of the following reasons:

Relocation of office

Moving services offsite / colocation (space, power)

Managed service award to outsourcing company

Key Requirements and Drivers

Stand up applications or services in a new location

Acquisition and mergers, managed service outsources – Enterprise

End of existing managed service and moving to a new provider – Enterprise

New services being offered by a provider – MSP / ISP

Constraints and Challenges

Cost

Time to deploy / market

Skill sets available

In house staff

Outsourced

VAR availability

Other Items to consider

IP Addresses (PI and PA)

DNS

Switching

Firewalls

Remote Access

2FA

Load Balancers / Local DNS Global (Anycast, DNS TTLs etc)

WAN connectivity (Overlay vs Native L3VPN etc)

WAN Performance / Optimization

Voice / Video and performance especially in global networks

New or Lift and shift applications – or both

Impact this migration has on addressing (Re-IP applications usually not feasible)

Normally IP addresses within code

Re-IP exercise may be completed to tidy up noncontiguous DC ranges and migration time may be best time to consider

Legacy applications which are sensitive to TCP drops require

Consider firewall clustering

Knock on effects of L2 stretched between sites

Ecommerce requirements, persistence etc for 24/7 services

Availability / downtime available

Layer 2 (or 3) DCI – whole show in itself!…….why we should or shouldn’t do L2 DCI, but how it can be achieved!

Software Defined Data Center (SDDC) We are now beginning to enter the SDDC territory so the question is raised how and when do we migrate to software defined architecture and is it feasible for everyone?

Different Technology Options Example: LISP + OTV – where OTV was the main requirement How to route LISP using tunnels or redistribute into existing WAN routing protocol LISP Multihop with tunnels over WAN, Firewall in path between XTR and EID / FHRP router. Service Provider core had routing limit on number of routes in VRF where injecting large number of LISP host routes would have broken the network (potentially).  This is often the challenge – seeing what may happen if something is designed a certain way in advance.

Example: DNS load balancing such as F5 if the budget was available Budget is most commonly the factor which plays into “being creative” – that said with something like a Data Center migration there is normally a decent budget for the purposes of that organization but requirements always come out of the woodwork within the project and it is when unexpected factors which cost money appear that is when you sometimes need to be creative.

It is about finding a balance between something that will deliver the solution required, but is also supportable.

The Term of the Show

Data Center Interconnect (DCI)

Call to Action:

Share this content with someone you believe would benefit from it as much as you have!

Hosted By: Michael “Zig” Zsiga

Guest Expert: Malcolm Booden

Round Trip Technology – Blogs, Vlogs, and Audio Content

Twitter!!

Thank you for the podcast reviews! Thank you for the iTunes reviews as they sincerely motivate me to continue to give back to this community that I love.  If you enjoy the podcast and the information I share, please feel free to write your own personalized review on iTunes!

Ask questions and give feedback

You can leave a comment in the show notes

You can leave a voicemail at (617) 913-4103

You can email us at Feedback@zigbits.tech

Engage with Zigbits further:

Subscribe to the podcast on an iPhone or on an Android

Follow Zigbits on Twitter!

Follow Zigbits on LinkedIn!

Follow Zigbits on Facebook!

Engage with me further:

Follow me on Twitter!

Follow me on LinkedIn!

Transparency: This post may contain affiliate links to products or services were I may receive a level of compensation from your actions by following those links. This is seamless to you and does not add any additional cost to the products or services in question. In addition, I do not let any affiliate relationship cloud my judgement or my recommendation of a product or service. My recommendations will always be above reproach.  This is my commitment to each and everyone!

The post ZNDP 025 – Designing for Data Center Migration and Application Mobility with Malcolm Booden – Part 1 appeared first on Zigbits - Where Zigabytes are faster than Gigabytes.

View Details

Hey Friends, Nerds, and Geeks out there, we have an Ask Zig episode.  Shahzad on twitter asked “In regards to CCIE what is your take on expert of a given topic. In other words how much depth should be covered?”.  This is a great question that we are going to answer it in this episode!  Find your favorite spot to listen, get some note taking material if you need, and lets get this show started!

Thanks Shahzad for taking the time to ask this question.  I appreciate you!

What is an Expert and how is one measured as an Expert

Some say it takes 10,000 hours to become an expert at something

It Depends on you, your personality and how quickly you can learn something new and apply it.

Can you teach someone it?

Three Facets for being an expert on a specific technology

Theory

Implementation

A Vision of the Big Picture

Summary Each exam has a blueprint that you should Walk through, grading yourself honestly.  Don’t overly focus on technology not on the blueprint.  Know what you know and what you don’t know, and where to find it! Finally, surround yourself with other experts that will continue to challenge you daily!

The Term of the Show

Mean Time to Repair (MTTR)

Call to Action:

Share this content with someone you believe would benefit from it as much as you have!

Hosted By: Michael “Zig” Zsiga

Guest Expert: None

Thank you for the podcast reviews! Thank you for the iTunes reviews as they sincerely motivate me to continue to give back to this community that I love.  If you enjoy the podcast and the information I share, please feel free to write your own personalized review on iTunes!

Ask questions and give feedback

You can leave a comment in the show notes

You can leave a voicemail at (617) 913-4103

You can email us at Feedback@zigbits.tech

Engage with Zigbits further:

Subscribe to the podcast on an iPhone or on an Android

Follow Zigbits on Twitter!

Follow Zigbits on LinkedIn!

Follow Zigbits on Facebook!

Engage with me further:

Follow me on Twitter!

Follow me on LinkedIn!

Transparency: This post may contain affiliate links to products or services were I may receive a level of compensation from your actions by following those links. This is seamless to you and does not add any additional cost to the products or services in question. In addition, I do not let any affiliate relationship cloud my judgement or my recommendation of a product or service. My recommendations will always be above reproach.  This is my commitment to you Ziglets!

The post ZNDP 024 – Ask Zig – How much depth should be covered to be an expert? appeared first on Zigbits - Where Zigabytes are faster than Gigabytes.

View Details

Hey Friends, Nerds, and Geeks out there, in this episode we are going to highlight some CCDE Practical Exam Recommendations and Tips that will help you on your journey to pursue the CCDE Certification. And we are starting right now!!

Related Posts: If you haven’t seen these posts yet, you should check them out:

My Unleashing the CCDE Blog Post Titled: The A-Ha Moment

ZNDP 002 – Honor, Courage, and Commitment…For the CCDE!!

ZNDP 008 – Ask Zig – What CCxE Should you Pursue?

ZNDP 010 – An Overview of the CCDE Certification with Jeremy Filliben

ZNDP 020 – Ask Zig – What is Your CCxE Methodology?

Your Role During Your CCDE Practical Exam:

Determine what your role is for the scenario, at the beginning of each scenario

Reflect on your role throughout the scenario

Your role will determine what you have access too

For Example, Enterprise vs Service Provider

For each Scenario in Your CCDE Practical Exam: Determine what the Business vertical is

Retail

Bank

School

Online

Determine what the Design Use Case is

Add / Replace Technology or Service

Merge Divest

Scaling

Greenfield

Design Failure

“You” During Your CCDE Practical Exam: Don’t make assumptions

Don’t assume complexity is bad if the scenario does not mention it.

The scenario will give you enough information to make a decision, you just need to find it.

Bring your technical knowledge and experience but Leave your Preconceived Notions and Assumptions at the door of the testing center

Read and Read again!

Carefully read each question at least 2 times

Also, read each answer a couple of times to make sure you fully understand what is being asked

If you are not following or understanding the question, re-read the scenario, you are probably missing some relevant information

Lastly, try to determine what the test creator is trying to test you on

Do not dwell on questions

If you do not know an answer to a question, you probably missed key information in the scenario, go find it!

Do not focus on the level set choices

Through out the scenarios, they will level set on design decisions.  They might choose MPLS L2VPN over MPLS L3VPN, even though MPLS L3VPN was the better answer.

Do not focus on this, as the scenario is testing on something else now.

Be confident in your answer and move on!

It’s a chart, I must fill it in…don’t!

When seeing a chart, check only the items that actually make sense in the current scenario

Do not fall into the mental trap of needing to fill in the entire chart.

Connecting with the Scenario

You need to connect with the scenario but you also need to be reading the scenario fast.  There is a happy middle ground here that you will have to determine for yourself.

I found skim reading and Sparsely highlighting worked for me.

Do not over connect with the scenario

Questions will have multiple answers

This is intended so do not stress.  Stick with the answer you can properly defend the “Why did I choose it?” question, because you will most likely be asked!

Your CCDE Practical Exam Strategy: Divide your notes into different sections

Business

Network

Application

Security

QoS

Multicast

Draw a diagram per Scenario

A physical diagram

A quick logical diagram

Highlighting

I was an overzealous highlighter in the first 2 attempts, this makes it hard to find important information when everything is highlighted

Skim reading while sparsely highlighting is what worked for me in the end

I used 1 color but others have used multiple colors

Practice and do what works for you

Lunch Break, Do I study more????

During your lunch break, use the time to relax your mind.

Do not attempt to study or do work

Eat some good food, drink some water, have some coffee

This exam is a marathon and you need every minute to de-stress and relax

Summary

You can’t be successful with the CCDE Practical Exam with out a Strategy

Each person’s strategy will be different, but you need to come up with one that will work for you.

What worked for me most likely will not work for everyone else.  Take the bits and pieces that does work for you, and build your own strategy off of it.

The Term of the Show

Mean time to Failure (MTTR)

Call to Action:

Share this content with someone you believe would benefit from it as much as you have!

Hosted By: Michael “Zig” Zsiga

Guest Expert: None

Thank you for the podcast reviews! Thank you for the iTunes reviews as they sincerely motivate me to continue to give back to this community that I love.  If you enjoy the podcast and the information I share, please feel free to write your own personalized review on iTunes!

Ask questions and give feedback

You can leave a comment in the show notes

You can leave a voicemail at (617) 913-4103

You can email us at Feedback@zigbits.tech

Engage with Zigbits further:

Subscribe to the podcast on an iPhone or on an Android

Follow Zigbits on Twitter!

Follow Zigbits on LinkedIn!

Follow Zigbits on Facebook!

Engage with me further:

Follow me on Twitter!

Follow me on LinkedIn!

Transparency: This post may contain affiliate links to products or services were I may receive a level of compensation from your actions by following those links. This is seamless to you and does not add any additional cost to the products or services in question. In addition, I do not let any affiliate relationship cloud my judgement or my recommendation of a product or service. My recommendations will always be above reproach.  This is my commitment to you Ziglets!

The post ZNDP 023 – CCDE Practical Exam Recommendation and Tips appeared first on Zigbits - Where Zigabytes are faster than Gigabytes.

View Details

Hey Friends, Nerds, and Geeks out there, today you are going to find out what a Ziglet is.  Launch your favorite podcatcher app, turn up the volume, queue the DJ…lets get this show on the road!! 

Unintentional Disservice with Ziglet

Serving this community

I’m here to serve you and serve this community, I’m here to help this community

Problem

Not explaining what a Ziglet is from my personal perspective

Then Forcing the Ziglet identification on you

In Summary

Not only did I not explain what a Ziglet is and my vision for it, I forced it on you all.

Its not going away, I’m just going to change how I go about using it

Not how I wanted Ziglet to come across,

This show is all about what a Ziglet means to me

What are my goals, views, and expectations of the Ziglet branding.

Then each of you can determine for yourselves if you would like to self identify as a Ziglet or not.  You have the choice!

What is a Ziglet? Goals / Views / Expectations:

Words of Endearment

Nerd and Geek are words of endearment from my perspective

I Wanted something more for you to use, for all of us to use

Never wanted to impose it on you

The Community

We are making a community here, with the different podcasts, with the different Blog Series and I wanted an identification of some sort for those that choice to use it.

Maybe a Label and an Icon that meant something more.

A Badge of Honor!!

Long Term Plan for Zigbits & Ziglet:

We are Building a Brand and a Vision: Zigbits is the brand, with Ziglets being a part of that brand!

A Badge of Honor

A proud identification

Merchandise

Learning as I go

The Term of the Show

PIN – Places in the Network

Datacenter

Transport (WAN)

Edge / Access / LAN

Border / Internet Edge

DMZ

Call to Action:

Share this content with someone you believe would benefit from it as much as you have!

Hosted By: Michael “Zig” Zsiga

Guest Expert: None

Thank you for the podcast reviews! Thank you for the iTunes reviews as they sincerely motivate me to continue to give back to this community that I love.  If you enjoy the podcast and the information I share, please feel free to write your own personalized review on iTunes!

Ask questions and give feedback

You can leave a comment in the show notes

You can leave a voicemail at (617) 913-4103

You can email us at Feedback@zigbits.tech

Engage with Zigbits further:

Subscribe to the podcast on an iPhone or on an Android

Follow Zigbits on Twitter!

Follow Zigbits on LinkedIn!

Follow Zigbits on Facebook!

Engage with me further:

Follow me on Twitter!

Follow me on LinkedIn!

Transparency: This post may contain affiliate links to products or services were I may receive a level of compensation from your actions by following those links. This is seamless to you and does not add any additional cost to the products or services in question. In addition, I do not let any affiliate relationship cloud my judgement or my recommendation of a product or service. My recommendations will always be above reproach.  This is my commitment to you Ziglets!

The post ZNDP 022 – What is a Ziglet? appeared first on Zigbits - Where Zigabytes are faster than Gigabytes.