NETWORK_aa ARCHITECTURE_aa SNHUENERGY_ INC 1
N _aa Archi _aa SNHUE _a Inc,
Southern_aa New_aa Hampshire_aa University_
IT_aa 640-Q5156_aa Telecommunication/_aa Networking_aa
Executive_aa Summary
NETWORK_aa ARCHITECTURE_aa SNHUENERGY_ INC 2
SNHUEnegry_aa Inc,_aa is_aa a_aa medium_ sized_aa oil_aa and_aa gas_aa company_aa that_a is_aa
focused_aa on_aa the_a discovery_aa and_aa drilling_ of_aa oil-base_ products._aa aa_aa The_aa
company_aa wants_aa to_ grow_aa focused_ on_aa exploration_aa into_ a_aa company_aa that_aa also_aa
provides_aa the_aa transportation_aa and_aa refinement_aa of_aa its_aa discoveries._aa _aa This_aa is_a a_aa
big_aa step_aa for_ the_aa company,_aa and_aa it_aa wants_aa to_aa make_aa sure_aa the_aa
communication_aa infrastructure_aa is_ ready_aa to_ delivery_aa in_aa the_aa next_ 12_aa to_aa 18 _a
months._aa The_aa current_aa network_aa now_aa give_aa us_aa some_aa concern_aa about_aa impact_aa
of_aa losing_aa connectivity_aa between_aa Dallas_aa router_aa and_ the_aa Memphis_aa router_
affect_aa to_aa business,_ communication_aa between_aa the_a users._aa aa_aa The_ network_aa loses_aa
connectivity_aa means_aa lost_aa dollars_aa and_aa lost_aa business_aa opportunities._aa The_a
application_aa may_ be_aa impact_aa should_a be:_aa email,_aa Video_aa Conferencing,_aa Payroll,_aa
Accounting_aa and_aa HR._ When_aa the_aa router_aa losing_aa connectives_aa the_aa users_aa must_aa
waiting_aa on_aa their_aa network_aa to_a catch_aa up_aa to_aa the_aa speed_aa at_aa which_aa they_a are_aa
working._aa They_aa have_ to_aa sit_aa and_aa wait_aa for_aa file_aa transfers,_aa applications_aa to_aa
open,_aa attachments_aa to_aa download,_aa and_a web_aa pages_aa to_aa open._aa Slow_aa internet_aa
causes_aa costly_aa delays_aa in_aa the_aa company_aa operations_aa and_aa work_aa flow_aa
management._aa The_aa risk_ of_aa just_aa having_aa a_aa single_ router_aa or_a switch_aa within_aa
Memphis_aa office_aa it_a could_aa shut_ down_aa the _a Memphis_aa site_aa if_aa the_aa router_aa in_aa
Memphis_aa down,_aa or_aa switch_aa down._aa aa_aa The_aa route_aa traffic_aa takes_aa among_aa different_aa
network_aa providers_aa also_aa affects_aa performance._aa
In_aa the_aa future,_aa the_aa company_aa will_aa extend_aa these_aa services_aa across_aa the_aa
WAN_aa by_aa using_aa TCP/IP_aa communication_aa processes,_aa because_aa Wide_aa Area_
Network_aa (WAN)_aa to_a connect_aa the_aa two_a locations._aa WAN_aa connections_aa vary_aa in_aa
NETWORK_aa ARCHITECTURE_aa SNHUENERGY_ INC 3
bandwidth_aa depending_aa on_ your_aa needs,_aa and_aa may_aa be_ set_aa up_ as_aa a_aa direct_aa
connection_aa or_aa a_ virtual_aa private_aa network_aa (VPN)_aa via_ the_aa Internet._aa Either_aa
way,_aa connecting_aa your_aa locations_aa will_ enable_aa better_aa and_aa more_ secure_aa
communication_aa within_aa your_aa business._ aa_aa For_a Memphis_aa site_aa we_aa will_aa get_aa
extra_aa switch_aa and_aa router_aa for_aa back_aa up,_aa in_ case_aa the_a single_aa switch,_a and_aa
router_aa down._aa aa_a I_aa would_aa consider_aa security_aa when_aa making_aa any_aa change_aa to_aa
company_aa network_aa infrastructure,_aa especially_a when_aa connecting_aa two_aa sites._aa I_aa
would_aa consider_aa higher_aa level_aa protection_a network_aa security_aa when_aa expend_aa the_aa
network.
Current_aa Network_aa Architecture:_aa Network_aa Applications
The_aa company_aa currently_aa uses_a these_aa applications:_aa Email,_ Payroll,_aa
Accounting,_aa and_aa Human_aa Resource._aa aa_aa The_aa network_aa plays_aa a_a huge_aa role_aa in_
application_aa performance_aa management_aa in_ the _aa company._aa aa_aa Per_aa Robbie_aa Harrel_
in_aa journal_aa article:_ “Understanding_aa the_aa network_aa application_aa environment”_aa states_aa
depending_aa upon_aa server_aa locations_ and_aa network_aa geography,_aa the_aa traffic_aa patterns_a
can_aa be_aa significantly_aa different_aa for_aa different_aa areas_aa of_ the_aa network._aa This_a
requires_aa a_aa wide_a view_aa of_aa the_ network_aa in_aa terms_aa of_aa capturing_aa application_aa
flows._aa Therefore_aa we_aa need_aa to_aa understanding_aa and_aa controlling_aa that_aa traffic_aa is_
critical,_aa and_aa centralizing_aa computing_aa facilities_aa for_aa servers_aa can_aa provide_aa greater_aa
visibility_aa without_aa the_aa need_aa to_a decentralize_aa application_ traffic_aa capturing_aa
capabilities_aa (Harrell,_aa N.D).
Current_aa Network_aa Architecture:_aa OSI_aa Model
NETWORK_aa ARCHITECTURE_aa SNHUENERGY_ INC 4
The_a component_aa of_aa the_aa network_ with_aa the_aa OSI_aa transport_aa layer:_aa
switch,_aa router,_aa firewall,_aa PC_ work_aa stations,_aa servers,_aa application._aa aa_a The_aa device_aa
use_aa for_aa network_ layer_aa is_aa router._aa aa_aa Layer_aa 3,_aa the_ network_aa layer_aa of_aa the_aa
OSI_aa model,_aa provides_aa an_aa end-to-end_aa logical_aa addressing_aa system_aa so _ that_ a_aa
packet_aa of_aa data_aa can_ be_aa routed_aa across_a several_aa layer_aa 2_a networks_aa (Ethernet,_aa
Token_aa Ring,_aa Frame_aa Relay,_aa etc.)._aa aa_ Note_aa that_aa network_ layer_aa addresses_aa can_aa
also_aa be_aa referred_aa to_aa as_aa logical_aa addresses._aa To_aa make_aa it_aa easier_aa to_aa manage_aa
the_aa network_aa and_aa control_aa the_aa flow_aa of_aa packets,_aa many_aa organizations_aa separate_aa
their_aa network_aa layer_aa addressing_aa into_aa smaller_aa parts_aa known_aa as_aa subnets._
Routers_aa use_aa the_ network_aa or_aa subnet_aa portion_aa of_ the_aa IP_aa addressing_aa to_aa route_
traffic_aa between_aa different_aa networks._ Each_aa router_aa must_aa be_aa configured_aa
specifically_aa for_aa the_ networks _aa or _aa subnets _aa that _aa will _aa be _aa connected _aa to _aa its _aa
interfaces_aa (Simoneau,_aa N.D)._
The_aa Firewall_aa device_ is_aa use_a in_aa Transport_aa layer_aa of_aa the_aa OSI_ model,_aa
offers_aa end-to-end_aa communication_aa between_aa end_aa devices_aa through_aa a_a network._aa
Depending_aa on_aa the_a application,_aa the_aa transport_aa layer_aa either_ offers_aa reliable,_
connection-oriented_aa or_aa connectionless,_aa best-effort_aa communications_aa (Simoneau,_aa N.D).
Base_aa on_aa the_ current_aa network_aa architecture_aa the_aa company_a use_aa the_aa
Internet_aa Layer_aa to_aa uses_aa the_aa source_ and_aa destination_a addresses_aa in_aa order_aa to_aa
facilitate_aa the_aa movement_aa of_aa data_a between_aa the_aa Network_a Access_aa layer_aa and_a
the_aa Transport_aa layer;_aa the_aa data_ flows_aa from_ one_aa node_aa on_aa the_aa network_a to_aa
the_aa next_aa node_aa in_aa a_aa path_aa moving_aa toward_aa the_aa final_a destination_aa by_aa
Achetson_aa defines_aa in_ the_aa article:_aa “The_a seven_aa Layers_aa of_a Networking”._aa Per_aa
NETWORK_aa ARCHITECTURE_aa SNHUENERGY_ INC 5
Achetson_aa the_aa two_a other_aa common_aa protocols_ that_aa operate_aa at_aa the _a TCP/IP_aa
Internet_aa layer_aa are_aa derivatives_aa of_aa IP:_aa IP_aa version_aa 4_aa (IPv4)_aa and_aa IPv6._a The_aa
devices_aa that_aa typically_aa operate_aa at_aa the_aa Internet_aa layer_aa are_aa routers._aa The_aa
Internet_aa layer_aa of_a the_aa TCP/IP_aa model_aa corresponds_aa to_aa the_a Network_aa layer_aa
(Layer_aa 3)_aa of_aa the_aa OSI_ model_aa (Achetson, _ 2014).
Current_aa network:_aa Physical_aa network_aa devices
Per_aa article:_aa “Exploring_aa the_aa Modern_aa Computer_aa Network:_aa Types,_aa Functions,_aa
and_aa Hardware”_aa the_aa network_aa infrastructure_aa contains_aa three_ categories_aa of_aa
network_aa components:
• End_aa devices
• Intermediary_aa devices
• Network_aa media
Hardware_aa comprises_aa the_ components_aa of_aa the_aa network_aa platform_aa that_aa typically_
are_aa visible,_aa such_a as_aa a_aa laptop,_aa PC,_aa switch,_aa router,_ wireless_a access_aa point,_aa
or_aa the_aa cabling_a used_aa to_a connect_aa the_ devices._aa Occasionally,_aa some_aa network_aa
components_aa may_aa not_aa be_aa visible._aa In_aa the_aa case_ of_aa wireless_aa media,_aa for_aa
example,_aa messages_aa are_aa transmitted_aa through_ the_aa air_aa using_ invisible_aa radio_aa
frequency_aa or_aa infrared_aa waves._aa aa_aa The_ physical_aa Computers_a (work_aa stations,_aa
laptops,_aa file_aa servers,_aa web_aa servers)
• Network_aa printers
• VoIP_aa phones
• TelePresence_aa endpoints
• Security_aa cameras
NETWORK_aa ARCHITECTURE_aa SNHUENERGY_ INC 6
• Mobile_aa handheld_aa devices_aa (such_aa as_aa smartphones,_aa tablets,_aa PDAs,_aa and_a
wireless_aa debit/credit_aa card_aa readers_aa and_aa barcode_aa scanners)_aa (Exploring_aa the_aa
Modern_aa Computer_aa Network:_aa Types,_aa Functions,_aa and_aa Hardware,_aa 2013).
The_aa physical_aa of_a the _ network_ with_aa the_aa OSI_ transport_aa layer:_aa switch,_a router,_aa
firewall,_aa PC_a work_aa stations,_a servers,_aa application._aa aa_aa The_aa device_a use_aa for_aa
network_aa layer_aa is_ router._aa aa_aa Layer_aa 3,_ the_aa network_aa layer_aa of_aa the_a OSI_aa
model,_aa provides_aa an_aa end-to-end_aa logical_aa addressing_aa system_a so_aa that_aa a_aa packet_aa
of_aa data_aa can_aa be_aa routed_aa across_aa several_aa layer_aa 2_aa networks_aa (Ethernet,_aa Token_aa
Ring,_aa Frame_aa Relay,_aa etc.)._aa Note_aa that_aa network_aa layer_aa addresses_aa can_aa also_aa be_aa
referred_aa to_aa as_aa logical_aa addresses._aa aa_aa To_aa make_aa it_aa easier_aa to_aa manage_aa the_aa
network_aa and_aa control_aa the_aa flow _a of_aa packets,_aa many_ organizations_aa separate_aa their_aa
network_aa layer_aa addressing_aa into_ smaller_aa parts_aa known_aa as_aa subnets._aa Routers_aa use_aa
the_aa network_aa or_a subnet_aa portion_aa of_aa the_aa IP_ addressing_aa to_aa route_ traffic_
between_aa different_aa networks._aa Each_aa router_aa must_aa be_aa configured_ specifically_aa for_a
the_aa networks_aa or_a subnets _ that_aa will_aa be_aa connected_aa to_aa its_a interfaces_aa
(Simoneau,_aa N.D)._aa
The_aa Firewall_aa device_ is_aa use_a in_aa Transport_aa layer_aa of_aa the_aa OSI_ model,_aa
offers_aa end-to-end_aa communication_aa between_aa end_aa devices_aa through_aa a_a network._aa
Depending_aa on_aa the_a application,_aa the_aa transport_aa layer_aa either_ offers_aa reliable,_aa
connection-oriented_aa or_aa connectionless,_aa best-effort_aa communications_aa (Simoneau,_aa N.D).
Current_aa network:_aa Critical_aa Traffic_aa Patterns
According_aa article:_aa “7_a factors_aa that_aa an_aa impact_aa your_aa network_aa
performance”_aa Annese_aa Team_aa states_aa a_aa network’s_aa limitations_aa are_aa critical_aa areas_aa
NETWORK_aa ARCHITECTURE_aa SNHUENERGY_ INC 7
of_aa concern_aa when_aa performing_aa capacity_aa and_aa performance_aa management._aa These_aa
limitations_aa primarily_aa include_aa the_aa following:
Errors:_aa Network_aa errors_a can_ generally_aa be_aa categorized_aa into_aa problems_aa with_aa
queuing,_aa latency,_aa and_aa jitter._aa The_aa data_aa queue_aa can_aa affect_aa network_aa
performance_aa in_aa several_aa ways._aa For_aa example,_aa larger_aa queues_aa increase_aa the_aa wait_aa
time,_aa while_aa smaller_a queues_aa increase_aa the_aa probability_aa of_aa dropped_aa data.
Speed:_aa Pipe_aa size_a is_aa the_aa amount _ of_a data_aa the_a network_aa can_aa send_aa
simultaneously_aa on_aa a_ single_aa connection._aa It's_aa often_aa confused_aa with_aa connection_aa
speed,_aa although_aa pipe_ size_aa doesn't_aa actually_aa affect_aa the_aa speed_aa at_aa which_aa data_aa
travels_aa between_aa nodes._aa While_aa hardware_aa capabilities_aa determine_aa the_a maximum_aa
bandwidth_aa that_aa is_aa theoretically_aa available,_aa software_aa mechanisms_aa typically_aa
allocate_aa a_aa lower_aa bandwidth_aa for_a each_aa network_aa service.
Memory:_aa Memory_aa is_a a_aa computing_aa resource_aa that_aa has_a requirements_aa in_aa both_aa
the_aa data_aa and_a control_aa planes._aa The_aa performance_aa of_aa the_aa entire_aa network_aa can_aa
degrade_aa when_ control_aa plane_a processes_aa fail,_aa as_aa is_aa the_aa case _ when _aa routing _
convergence_aa requires_ additional_aa memory.
Distance:_aa Distance_aa can_aa have_aa a_ dramatic_aa impact_aa on_ network_aa performance,_aa
especially_aa when_aa the_ applications_aa haven't_aa been_aa optimized._aa The_aa maximum_a
speed_aa at_aa which_aa data_aa can_aa be_aa forward_aa is_ the_aa speed_ of_aa light,_ which_aa is_aa
186,000_aa miles_aa per_aa second_aa or _ 186_aa miles_aa per_aa millisecond._aa This_aa packet_aa
forwarding_aa delay_aa becomes_ significant_aa when_ an_aa enterprise_aa is_aa running_aa an_aa
international_aa client/server_aa application.
NETWORK_aa ARCHITECTURE_aa SNHUENERGY_ INC 8
Central_aa Processing_aa Unit_aa (CPU):_aa A_aa node's_aa central_aa processing_aa unit_aa (CPU)_aa is_aa
typically_aa used_aa by_aa both_aa the_aa control_ and_aa data_aa planes._aa Capacity_aa and_aa
performance_aa management_aa requires_aa a_aa network_aa and_ its_aa nodes_a to_aa have_aa
insufficient_aa processing_aa capability_aa at_aa all_aa times._aa A_aa single_aa node_aa with_aa an_aa
inadequate_aa CPU_aa can_aa impact_aa the_ entire_aa network_aa due_aa to_aa the_aa high_aa degree_aa
of_aa interdependence_aa between_aa the_aa nodes_aa in_aa the_aa modern_aa network._aa Insufficient_aa
processing_aa can_a also_aa increase_aa latency_aa if_aa a_aa node's_ CPU_aa is_a unable_aa to_aa keep_
up_aa with_aa network_ traffic.
Applications:_aa Applications_aa can_aa also_aa affect_aa a_aa network's_aa capacity_aa and_aa
performance,_aa with_aa issues_aa such_aa as_aa the_aa amount_aa of_aa data_aa the_aa application_ is_aa
able_aa to_aa transmit_ compared_aa to_aa what_aa it_aa needs_ to_aa transmit._aa This_aa factor_aa is_
especially_aa critical_aa for_a the_aa performance_aa of_ Wide_aa Area_aa Networks_ (WANs)._aa
Additional_aa application_aa characteristics_aa that_aa affect_a capacity_aa and_ performance_aa
include_aa application_aa keep-alive_aa and_ window_aa sizes_aa (Team,_aa 2017).
Management_aa of_aa a_aa network's_aa availability,_aa capacity,_aa and_aa performance_aa is_aa
therefore_aa crucial_aa for_ achieving_aa an_aa organization's_aa business_aa objectives._aa It_aa really_aa
impact_aa of_aa losing_a connectivity_aa between_aa Dallas_aa router_aa and_aa the_aa Memphis_aa
router_aa affect_aa to_aa business,_aa communication_aa between_aa the_aa users._a aa_aa The_aa network_a
loses_aa connectivity_aa means_aa lost_aa dollars_aa and_aa lost_aa business_aa opportunities._aa The_aa
application_aa may_aa be_a impact_aa should _a be:_aa email,_aa Video_aa Conferencing,_aa Payroll,_aa
Accounting_aa and_aa HR._ When_aa the_aa router_aa losing_aa connectives_aa the_aa users_aa must_aa
waiting_aa on_aa their_aa network_aa to_a catch_aa up_aa to_aa the_aa speed_aa at_aa which_aa they_a are_aa
working._aa They_aa have_ to_aa sit_aa and_aa wait_aa for_aa file_aa transfers,_aa applications_aa to_aa
NETWORK_aa ARCHITECTURE_aa SNHUENERGY_ INC 9
open,_ attachments_aa to_aa download,_a and_aa web_aa pages_aa to_aa open._ Slow_aa internet_aa
causes_aa costly_aa delays_aa in_aa the_aa company_aa operations_aa and_aa work_aa flow_aa
management._aa According_aa to_ Pangiotis_aa Vouzis_aa in_aa the_aa article:_aa “Impact_aa of_aa
Packet_aa Loss,_aa Jitter,_aa and_aa Latency_aa on_aa VoIP”_aa the_aa poor_aa VoIP_aa quality_aa because_aa
latency,_aa jilter,_aa and_aa packet_aa loss_aa can_aa never_aa be_a completely_aa eliminated_ from_aa
real_aa world_aa networks._ (Vouzis,_aa 2016)._aa Telephony_aa is_ all_aa UDP_aa based,_aa and_aa
packets_aa may_aa not_a arrive_aa at_aa the_aa destination,_ or_aa get_ discarded_aa if_aa they_aa
arrive_aa delayed_aa or_ contain_aa errors._aa This_aa results_aa in_aa missing_a audio_aa information_aa
at_aa the_aa destination._aa
_aa SQL _aa Server,_aa similar_aa to_aa other_aa enterprise_aa database_aa systems,_aa can_aa place_aa an_aa
extremely_aa large_aa load_aa on_aa an_aa I/O_aa subsystem._aa In_aa most_aa large_aa database_aa
applications,_aa physical_aa I/O_aa configuration_aa and_aa tuning_ play_aa a_aa significant_aa role_aa
in_aa overall_aa system_ performance. _aa aa_aa There _aa are_aa three_aa major_aa I/O_aa performance_aa
factors_aa to_aa consider:
• I/O_aa bandwidth:_aa The_aa aggregate_aa bandwidth,_aa typically_a measured_aa in_aa
megabytes_aa per_aa second_aa that_a can_aa be_aa sustained_aa to_a a_aa database_aa device
• I/O_aa latency:_aa The_aa latency,_aa typically_aa measured_aa in_aa milliseconds,_aa between_
a_aa request_aa for_aa I/O_aa by_aa the _ database_aa system_ and_aa the_aa point_aa where_aa
the_aa I/O_aa request_aa is_aa completed
• CPU_aa cost:_aa The_a host_aa CPU_aa cost,_aa typically_aa measured_aa in_aa CPU_aa
microseconds,_aa for_aa the_aa database_ system_aa to_aa complete_aa a_a single_aa I/O_aa
(Description_aa of_aa support_aa for_ network_aa database_aa files_aa in_a SQL_aa Server,_aa
2016).
NETWORK_aa ARCHITECTURE_aa SNHUENERGY_ INC 10
According_aa from_aa Rene_aa Millman_aa in_ the_aa article:_aa “What’s_aa slowing_aa down_aa your_aa
network_aa and_aa how_aa to_aa fix_aa it”_aa Network_a management_aa to_aa watch_aa when_
network_aa slow_aa is_ to_aa see_ bandwidth_aa as_aa the_ problem,_aa but_aa with_a investigation,_aa
it_aa is_a often_aa not_aa within_aa a_aa LAN_aa environment,_aa where_aa a_ high _a amount_aa of_aa
bandwidth_aa is_aa available._aa More_aa likely,_aa the_ problem_aa lies_aa within_aa the_aa WAN,_aa
where_aa capacity_aa is_a more_aa finite_aa and_a expensive_aa (Millman,_aa N.D).
Current_aa network_aa Architecture:_aa Pattern_aa across_aa the_aa Infrastructure
According_aa Michelle_aa in_aa article:”_aa The_aa Layers_aa of_aa the_a OSI_aa Model_aa
Illustrated”_aa The_aa organizations_aa have_aa a_aa systems_ (servers,_ desktops,_aa laptops,_aa
mobile_aa devices,_aa etc.)_aa available_aa worldwide_aa and_a connected_aa through_aa LAN_aa and_aa
WAN_aa connections_aa in_aa multiple_aa locations_aa such_aa as_aa the_aa internet,_aa internal_aa
networks,_aa perimeter_aa networks,_aa as_aa well_aa as_aa across_aa firewalls_aa and_aa other_aa
security_aa equipment_aa that_aa need_aa to_aa be_aa managed_aa and_aa supported_aa centrally,_aa using_aa
a_aa systems_aa management_aa tool_aa or_aa solution_ that_aa has_aa to_aa be_aa designed,_aa adapted_aa
and_aa configured_aa in_ order_aa to_ address_aa business_aa and_aa technical_aa concerns._aa aa_aa
First_aa we_aa need_aa identify_aa network_aa requirement_aa on_aa 2_a factors:
Business_aa goals:_aa Focus_aa on_aa how_aa the_ network_aa can_aa make_aa the_a business _a more _aa
successful._aa
Technical_aa requirements:_aa Focus_aa on_aa how_aa the_aa technology_aa is_aa implemented_aa
within_aa the_aa network
The_aa next_aa one_a we_aa need_aa characterizing_aa the_aa existing_aa network:_aa Information_aa
about_aa the_aa current_ network_aa and_aa services_aa is_ gathered_aa and_aa analyzed._aa It_ is_aa
necessary_aa to_aa compare_aa the_aa functionality_a of_aa the _ existing_aa network_aa with_aa the_aa
NETWORK_aa ARCHITECTURE_aa SNHUENERGY_ INC 11
defined_aa goals_aa of_aa the_aa new_aa project._aa The_aa designer_aa determines_aa whether_aa any_aa
existing_aa equipment,_aa infrastructure,_aa and_aa protocols_aa can_aa be_a reused,_aa and_aa what_aa
new_aa equipment_aa and_a protocols_aa are_aa needed_ to_aa complete_aa the_aa design._aa aa_aa Then_aa
design_aa network_aa topology:_aa the_aa network_aa applications_aa and_aa service_aa requirements_aa
are_aa identified,_aa and_ then_aa the_aa network_ is_aa designed_aa to_aa support_ them._aa When_aa
the_aa design_aa is_aa complete,_aa a_aa prototype_aa or_aa proof-of-concept_aa test_aa is_aa performed._aa
This_aa approach_aa ensures_aa that_aa the_aa new_a design_aa functions_aa as_aa expected_aa before_aa
it_aa is_a implemented._aa Routers_aa are _a small_aa electronic_aa devices_aa that_aa join_aa multiple_aa
computer_aa networks_aa together_aa via_a either_aa wired_aa or_aa wireless_aa connections._aa aa_aa
Routers_aa contain_aa a_aa processor_aa (CPU),_aa several_aa kinds_a of_aa digital_aa memory,_aa and_a
input-output_aa (I/O)_aa interfaces._aa They_aa function_ as_aa when_aa a_aa network_aa packet_aa
leaves_aa the_aa computer,_aa or_aa other_aa networking_ device, _aa in _aa route _aa to _aa a _aa destination _aa
outside_aa its’_aa own_aa LAN,_aa some_aa additional_aa information_aa must_a be_aa attached_aa to_aa
the_aa packet._aa aa_a This_aa information_aa would_a be_aa in_aa the_aa form_aa of_ a_aa default_aa
gateway._aa aa_aa This_aa default_aa gateway_aa would_aa typically_ be_aa a_aa router._aa aa_aa If_aa the_aa
router_aa does_aa not_a have_aa specific_aa knowledge_aa of_aa where_aa the_aa packet_aa should_aa be_aa
delivered,_aa it_aa forwards_aa the_aa packet_aa upstream_aa to_aa another_aa special-purpose_aa
computers,_aa one_aa that_a does_aa not_aa require_aa a_aa keyboard_aa or_aa display_aa (Michell,_a
2017)._aa aa_aa
Network_aa switches_aa are_aa the_aa glue_aa that_aa binds_aa computer _a communications._aa aa_aa Your_aa
computer_aa at_aa work_aa typically_aa connects_aa to_ a_aa network_aa switch._ A_aa switch’s_aa job_aa
is_aa to_aa receive_aa packets_aa from_a a_aa computer,_ or_aa other_aa networking_aa device,_aa and_aa
send_aa them_aa to_a the_aa proper_aa place._aa aa_aa The_ switch_aa keeps_aa a_aa list_aa of_aa all_ the_aa
NETWORK_aa ARCHITECTURE_aa SNHUENERGY_ INC 12
devices_ connected_aa to_aa it_aa (Aubrett’s_aa non-technical_aa IT_ dictionary)._aa aa_a _aa In_aa
addition,_aa switches_aa share_aa this_aa information_aa with_aa other_aa switches_aa to_ which_aa they_aa
are_aa linked._aa aa_a aa_aa This_a way,_aa if_aa computer_ A_aa needs_aa to_ communicate_aa with_aa
computer_aa B,_a the_aa switches_aa know_ exactly_aa where_aa computer_a A_aa and_aa computer_aa
B_aa are_aa connected_aa as_aa long_aa as_aa they_aa exist_ on_aa the_aa same_aa LAN._aa aa_a If_aa
computer_aa A_aa and_aa computer_aa B_aa do_aa not_aa exist_aa on_aa the_aa same_a LAN,_aa the_aa
computer_aa must_aa provide_aa the_ information_aa of_aa a_aa router,_aa called_aa a_aa default_aa
gateway,_aa which_a can_aa handle_aa the_ traffic_ when_aa it_aa sends_aa the_aa packet.
Firewall:_aa aa_aa A_aa firewall_aa is_aa the_aa gatekeeper_aa between_aa a_aa private_ network_aa and_aa
the_aa rest_aa of_a the_aa world._aa The_aa firewall_aa determines_aa what,_aa if_aa anything,_aa inside_aa
the_aa private_aa network_ should_aa be_aa accessible_aa from_aa the_ outside._aa Firewalls_aa exist_
in_aa many_aa forms._aa Some_aa are_aa hardware_aa appliances_aa which_aa are_ dedicated_aa solely_
to_aa performing_aa the_aa firewall_aa functions._aa Some_aa firewalls_aa are_a software _aa
components_aa which_aa run_aa on_aa routers_aa designed_aa to_aa sit_ at_aa the_aa network_aa edge._aa
Some_aa firewalls_aa are_aa software _aa packages_aa which_aa run_aa on_aa a_aa server._aa Most_aa PC_
operating_aa systems_aa such_aa as_aa Microsoft_ have_aa a_ built-in_aa firewall_aa to_aa protect_aa
local_aa resources_aa (Aubrett’s_aa non-technical_aa IT,_aa dictionary)._aa _aa The_aa firewall’s_aa job_aa
is_aa to_aa examine_aa network_aa packets_aa which_aa are_aa sent_aa to_aa destinations_aa within_aa the_
private_aa network_aa to_ see_aa if_ they_aa should_aa be _a allowed _aa to _aa pass.
Current_aa network_aa Architecture:_aa Performance_aa Issues
It_ really_aa impact_aa of_ losing_aa connectivity_aa between_aa Dallas_aa router_aa and_
the_aa Memphis_aa router_ affect_a to_aa business,_a communication_aa between_aa the_aa users._aa aa_a
The_aa network_aa lose_aa connectivity_aa means_a lost_aa dollars_aa and_aa lost_aa business_aa
NETWORK_aa ARCHITECTURE_aa SNHUENERGY_ INC 13
opportunities._aa The_aa application_aa may_aa be_aa impact _ should_aa be:_aa email,_aa Video_aa
Conferencing,_aa Payroll,_aa Accounting_aa and_ HR._aa When_aa the_aa router_aa losing_aa
connectives_aa the_aa users_ must_aa waiting_aa on_aa their_aa network_aa to_aa catch_aa up_aa to_a the_aa
speed_aa at_aa which_aa they_ are_aa working._aa They_ have_aa to_ sit_aa and_aa wait_aa for_aa file_
transfers,_aa applications_aa to_aa open,_ attachments_aa to_ download,_aa and_aa web_aa pages_aa to_aa
open._aa Slow_aa internet_ causes_aa costly_aa delays_aa in_aa the_aa company_aa operations_aa and_aa
work_aa flow_aa management._
The_aa risk_aa of_aa just_aa having_aa a_ single_aa router_aa or_aa switch_aa within_a Memphis_aa
office_aa it_ could_aa shut_aa down_aa the_aa Memphis_aa site _a if_aa the_ router_aa in_ Memphis_aa
down,_aa or_aa switch_ down._aa aa_aa The_aa route_aa traffic_aa takes_aa among_aa different_aa network_aa
providers_aa also_aa affects_aa performance.
Current_aa network_aa Architecture:_aa Security_aa issues
A_aa high_aa security_aa communication_aa flow_aa path_aa is_aa not_aa useful_aa when_aa the_aa
network_aa path_aa cannot_aa support_aa capacity_aa and_aa reachability_aa requirements._ The _aa
deployment_aa phase_aa in_a communication_aa network_a can_aa facilitate_aa an_aa optimal_aa
network_aa path_aa by_a focusing_aa on_aa both_a the_aa network_aa performance_aa and_aa the_
network_aa security_aa at_aa the_aa same_aa time._aa aa_a The_aa networking_aa and_ security_aa
industries_aa reflect_aa this_aa dichotomy_aa with_aa strong_aa security_aa companies_aa and_ strong_aa
networking_aa companies._aa A_a firewall_aa is_a a_aa network_aa security_aa device_aa that_aa grants_aa
or_aa rejects_aa network_a access_aa to_aa traffic_aa flows_aa between_aa an_aa untrusted_aa zone_aa
(e.g.,_aa the_aa Internet)_aa and_aa a_aa trusted_a zone_aa (e.g.,_ a_aa private_aa or_ corporate_aa
network)._aa The_aa firewall_aa acts_aa as_aa the_aa demarcation_aa point_aa or _a “traffic_aa cop”_aa in_
the_aa network,_aa as_aa all_aa communication_aa should_aa flow_aa through_aa it_ and_aa it_a is_aa
NETWORK_aa ARCHITECTURE_aa SNHUENERGY_ INC 14
where_aa traffic_a is_aa granted_aa or_aa rejected_aa access_aa (Singh,N.D)._aa aa_aa A_aa firewall_aa is_aa a_aa
network_aa security_aa device_aa that_aa monitors_aa incoming_aa and_aa outgoing_ network_aa
traffic_aa and_aa decides_aa whether_ to_aa allow_ or _aa block _aa specific _ traffic_aa based_aa on_aa a_aa
defined_aa set_aa of_aa security_aa rules._aa Therefore_aa if_aa network_aa down_aa is_ affect_a to_aa
firewall._aa aa_aa A_a firewall_aa is_aa every_aa bit_aa as_aa critical_aa to_aa security_aa as_aa an_aa anti-virus_aa
program._aa Firewalls_aa stop_ malware_aa from_aa spreading_aa to_aa a_aa network_aa and_ defend_aa
against_aa hackers_aa attempting_aa to_aa infiltrate_aa a_aa targeted_aa system._aa Disabling_aa a_aa
firewall_aa can_aa therefore_aa leave_aa a_aa business_aa vulnerable_ to_aa abuse,_aa allowing_aa
viruses_aa to_aa infect_aa interconnected_aa devices,_aa and_aa giving_aa cybercriminals_aa the_aa
opportunity_aa to_aa execute_aa malicious_aa code_aa remotely._aa End-to-end_aa latency_aa (the_aa
delay_aa that_aa happens_a to_aa a_aa packet_aa end_a to_aa end_aa from_aa the_a PC_ to_ the_aa
server)_aa and_aa any_aa errors_aa causing_aa re-transmission_aa on_aa the_aa network_aa will_aa also_aa
degrade_aa application_aa performance_aa and_aa slow_aa the_aa network_aa (Millman,_aa N.D).
Future_aa Network:_aa Future_aa Communication_aa Needs
Today_aa network’s_aa components_aa work_aa together_aa is_ changing_aa and_ fast. _ aa_
According_aa to_aa article:_aa “A_aa new_aa model_aa for_aa the_aa future_aa network_aa architecture”_aa
our_aa latest_aa infrastructure_aa model_aa harnesses_aa the_a future_aa architecture_aa evolution_aa to_a
enable_aa fast_aa problem_ solving_aa in_aa a_aa more_aa manageable_aa and_aa effective_aa way_aa
(NA,_aa 2017)._aa aa_a The_aa future_aa communication_aa is_aa designed_aa for_ the_aa needs_aa of_aa
operators_aa and_aa their_aa customers,_aa with_aa the_aa option_aa to_ change_aa and_aa evolve_aa
individual_aa sections_aa rather_aa than_aa changing_aa the_aa entire_aa system._aa Some_aa of_aa
commend_aa for_aa new_ future_aa communication_aa network_aa first_aa would_aa be_aa application_aa
clouds._aa aa_aa According_a to_aa article:_aa “Uncovering_aa the_aa application_aa cloud” _a The_
NETWORK_aa ARCHITECTURE_aa SNHUENERGY_ INC 15
application_aa cloud_aa model_aa directs_aa resources_aa when_aa and_aa where_aa they_aa are_aa
needed._aa It_aa becomes_aa even_aa more_aa effective_aa when_aa combined_aa with_aa the_a
connectivity_aa infrastructure_aa evolution,_aa ready_aa to_aa roll_aa out_aa new_a innovations_aa
across_aa different_aa industries._aa aa_a The_aa application_aa cloud_a resides_aa on_aa top_aa of_aa the_aa
distributed_ cloud_aa infrastructure. _aa This_aa distributed_aa cloud_aa infrastructure_aa exposes_aa
network_aa assets_aa from_aa one_aa or_aa several_aa operators._aa aa_aa The_ hardware_aa management_aa
system_aa becomes_aa more_aa important_aa than_aa ever,_aa as_aa there_aa are_aa several_aa types_aa of_aa
physical_aa sites_aa playing_aa different_aa roles_aa and_aa with_a different_aa requirements_aa (2017).
The_aa next_aa step_aa considers_aa should_aa be_aa management_aa and_aa monetization._aa aa_aa
According_aa to_aa article:_aa “Architecture_aa evolution_aa for_aa automation_aa and_aa network_aa
programmability”_aa recommend_aa full_aa network_aa programmability_aa for_ a_aa network_aa and_aa
its_aa services_aa needs_aa to_aa consider_aa all_aa the_a building_aa blocks:_aa how_aa each_aa piece_aa
of_aa the_aa network_a will_aa evolve;_aa how _a they _a will _aa interface;_aa and_aa how_aa they_a
support_aa the_aa structure_aa and_aa business_aa processes_aa of_aa an_aa operator._aa But_aa to_aa
achieve_aa such_aa levels_aa of_aa flexibility_aa requires_aa the_aa inter-domain_aa interfaces_aa as_aa
well_aa as_aa the_aa domains_aa to_aa evolve._ aa_aa Network_aa functions_ will_aa no_aa longer_aa be_aa
located_aa according_aa to_ traditional_a vertical_aa groupings_aa in_ single_aa network_aa nodes,_aa
but_aa will_aa instead_ be_aa distributed_aa to_ provide_aa connectivity_ where_aa it_a is_aa needed_aa
(2017)._aa aa_aa As_aa applications_aa like_aa self-driving_aa vehicles_aa and_aa remotely_aa operated_aa
machinery_aa evolve,_aa become_aa more_aa innovative,_aa and_aa more_aa widespread,_aa the_aa level_aa
of_aa performance_aa that_ 5G_aa networks_aa need_a to_aa deliver_a will_aa inevitably_aa rise._a aa_aa
Per_aa article:_aa “Flexibility_aa in_aa 5G_aa transport_aa networks:_aa the_aa key_aa to_aa meeting_aa the_aa
demand_aa for_aa connectivity”_aa the_aa new_aa 5G_aa transport_aa network_aa are_aa high_aa –_aa
NETWORK_aa ARCHITECTURE_aa SNHUENERGY_ INC 16
providing_aa support_aa for_ a_aa massive_aa range_aa of_aa services._aa Industry_ transformation,_aa
digitalization,_a the_ global_aa dependence_aa on_a mobile_aa broadband,_aa MTC,_aa the_aa IoT,_aa
and_aa the_aa rise_a of_aa innovative_aa industrial_aa applications_aa all_aa require_aa new_aa services,_aa
which_aa has_aa a_a considerable_aa impact_aa on_ the_aa transport_aa network._aa For_aa example,_aa
a_aa new_aa radio-access_aa model_aa that_aa supports_ highly_aa scalable_aa video_ distribution_aa
or_aa massive_ MTC_aa data_aa uploading_aa might_aa require_aa additional_aa transport_aa facilities_
–_aa such_aa as_aa a_aa scalable_aa way_aa to_ provide_aa multicasting._ aa_aa
Per_aa Ryan_aa Rouse_aa it’s_aa important_ that_aa teams_aa across_ every_aa step_aa of_a oil_aa
and_aa gas_aa production,_a including_aa upstream_aa (hydraulic_aa fracturing,_aa oil_aa field_
monitoring_aa and_aa offshore_aa rigs),_aa midstream_aa (pipeline_aa monitoring_ and_aa pumping_aa
stations)_aa and_aa downstream_aa (refineries_aa and_aa gas_aa stations)_aa applications,_aa use_
dependable_aa network_ components_aa that_aa can_aa withstand_aa harsh_aa industrial_aa conditions_aa
for_aa the_aa highest_ network_aa reliability_aa and_ availability._aa aa_aa Cyber_aa security,_aa for_
example,_aa is_aa quickly_aa becoming_aa a_ big_aa concern_aa for _ industries _aa everywhere, _aa
especially_aa oil_aa and_aa gas_aa (Rouse,_aa 2017)._a aa_aa According_aa to_aa Rouse_ in_aa his_
article:_aa “Future-Proofing_aa Oil_aa and_ Gas_aa Networks:_aa 4_aa Things_aa to_ Look_aa For”_
The_aa biggest_aa step_ teams_aa can_aa take_aa to_aa ensure_aa they_aa have_aa a_aa solid_aa
communications_aa network_aa is_aa to_aa invest_aa in_ high-quality,_aa rugged_aa Ethernet_a
infrastructure_aa designed_aa specifically_aa for_a use_aa in_aa harsh_aa environments._ In_aa
addition,_aa it’s_aa essential_aa to_aa understand_ when_aa and_ where_aa to_a use_aa industrial-
grade_aa components_aa versus_ those_aa designed_aa for_aa commercial_aa settings_aa (Rouse,_aa
2017)._aa The_aa plan_a for_aa SNHUEnergy,_aa Inc_aa will_a grow,_aa but_aa we_a need_aa to_aa
ensure_aa their_aa control_ rooms_aa and_aa overall_aa communications_aa infrastructure_aa are_aa well-
NETWORK_aa ARCHITECTURE_aa SNHUENERGY_ INC 17
equipped_aa to_aa support_ expansion,_aa harsh_aa environments_aa and_aa modern_aa technologies._aa
Success_aa requires_aa the_ right_aa combination_aa of_aa switches,_aa cabling,_aa firewalls_aa and_aa
wireless_aa components_aa that_aa deliver_aa on_ the_aa team’s_aa unique_aa needs,_aa protect_aa
against_aa evolving_aa threats_aa and_a add_aa to_aa the_ bottom-line.
Future_aa Network_aa Architecture:_aa Network_aa Architecture
According_aa to_aa Rouse_ comment_aa when_aa considering_aa how_aa to_ design_aa the_aa
network,_aa we_aa should_aa look_aa for_aa components_aa that_aa meet_aa the_aa following_aa four_aa
requirements:
Safety_aa and_aa reliability:_aa Remote_aa monitoring_aa solutions_ offering_aa high_aa network_aa
visibility_aa and_aa control_aa are_aa helpful,_aa in_ addition _aa to _aa leading_aa industrial_aa security_aa
and_aa firewall_aa products_ for_aa Layer_aa 2_aa and_aa Layer_aa 3_aa networks._aa _aa We_aa look_aa
for_aa components_aa that_ can_aa withstand_aa the_aa harshest_aa environmental_aa conditions_aa
and_aa are_aa compliant_ to_aa oil_aa and_aa gas_aa standards,_ meeting_aa all_aa possible_aa
classified_aa types_aa for_aa each_aa facility_aa site_aa to_aa ensure_aa compliance_aa with_aa UL_aa Class_aa
I_aa Division_aa 2_aa and_aa ATEX_aa certifications._aa Solutions_aa that_aa can_aa transmit_aa up_aa to_aa
170km_aa without_aa using_aa active_ repeaters_aa in_a between_aa are_aa ideal_ for_aa oil_aa and_aa
gas_aa applications.
Reduced_aa operational_aa costs:_aa Constant_aa maintenance-related_aa updates,_aa
especially_aa in_aa difficult_aa to_a reach_aa areas_aa such_aa as_aa deep_aa water_aa shelters_aa below_
200-400m_aa of_aa the_ surface,_aa are_aa extremely_aa costly._aa This_aa is_aa not_aa only_a because_aa
of_aa maintenance_aa fees,_ but_aa also_aa because_aa of_aa unnecessary_aa downtime._aa aa_aa
Maintenance-free_aa networking_aa solutions_aa that_ allow_aa you_aa to_aa remotely_ and_aa
automatically_aa monitor_aa wells_a and _ fields_aa and_aa take_aa preventable_aa measures_aa to_
NETWORK_aa ARCHITECTURE_aa SNHUENERGY_ INC 18
help_aa avoid_aa production_ downtime._aa Using_aa multi-Gigabit_aa solutions_aa that_a offer_aa
extended_aa bandwidth_aa and_aa expandability_ are_aa flexible_a and_aa cost-effective_aa tools_aa
that_aa can_aa support_aa this_aa initiative.
Minimized_aa installation_aa efforts:_aa Installation_aa can_aa be_aa costly_aa in_aa most_aa
industrial_aa settings_aa –_a but_aa even_aa more_a costly_aa in_a extreme_aa oil_a and_aa gas_aa
settings,_aa which_aa are_aa often_aa underwater._aa aa_aa Wide_aa local_aa area_aa network_aa (WLAN)_aa
solutions_aa that_aa meet_ the_aa ATEX_aa Zone_aa 2_aa standard_aa for_ oil_aa and_aa gas_aa
applications_aa can_aa help_aa reduce_aa wire_aa line_aa installation_aa costs_ and_aa enable_aa teams_aa
to_aa get_a closer_aa to_a the_aa field_ level,_aa contributing_aa to_aa seamless_aa installation._a
Withstand_aa harsh_aa environments:_aa The_a biggest_aa step_aa teams_a can_aa take_aa to_aa ensure_
they_aa have_aa a_aa solid_aa communications_aa network_aa is_aa to_aa invest_aa in_ high-quality,_aa
rugged_aa Ethernet_aa infrastructure_aa designed_aa specifically_aa for_aa use_aa in_ harsh_aa
environments._aa In_ addition,_ it’s_aa essential_aa to_aa understand_aa when_aa and_aa where_aa to_aa
use_aa industrial-grade_aa components_aa versus_aa those_aa designed_ for_aa commercial_aa settings.
Identify_aa solutions_aa that_ withstand_aa the_aa corrosive_ and_aa extreme_aa elements_aa
oil_aa and_aa gas_aa applications_aa face_aa every_aa day,_aa including_aa water_aa immersion,_aa
crushing,_aa abrasion,_aa UV_aa exposure,_aa oils_aa and_aa solvents,_aa sunlight,_aa extreme_aa
temperatures,_aa chemical_aa exposure,_aa and_aa prolonged_aa vibration_aa and_aa noise._aa This_a is_aa
foundational_aa to_aa the_aa success_aa of_aa upstream,_aa midstream_aa and_aa downstream_aa
processes_aa (Rouse,_aa 2017)._aa
We_aa will_aa focus_aa on_aa switching_aa and_aa routing,_ access,_aa signaling_aa and_a
control,_aa performance_aa and_aa reliability,_aa security,_aa physical_aa design_ and_aa transport, _a
NETWORK_aa ARCHITECTURE_aa SNHUENERGY_ INC 19
we_aa incorporate_aa all_aa important_aa elements_aa of_aa design_aa to_a plan_aa for_aa future_aa
communication_aa network_aa needs.
We_aa will_aa extend_aa these_aa services_aa across_aa the_aa WAN_aa by_aa using_ TCP/IP_aa
communication_aa processes,_aa because_aa Wide_aa Area_ Network _aa (WAN)_aa to_aa connect_aa
the_aa two_aa locations._aa WAN_a connections_aa vary_aa in_aa bandwidth_aa depending_aa on _ your_aa
needs,_aa and_aa may_aa be_aa set_aa up_ as_aa a_aa direct_aa connection_aa or_aa a_aa virtual_aa private_aa
network_aa (VPN)_aa via_aa the_aa Internet._aa Either_a way,_aa connecting_aa your_aa locations_aa will_aa
enable_aa better_aa and_a more_aa secure_aa communication_aa within_aa your_a business._aa aa_aa For_
Memphis_aa site_aa we_aa will_aa get_aa extra_ switch_aa and_a router_aa for_aa back_aa up,_aa in_aa case_
the_aa single_aa switch,_a and_aa router_aa down._aa aa_aa I_aa would _aa consider _aa security _aa when _
making_aa any_aa change_ to_aa company_a network_aa infrastructure,_aa especially_aa when_a
connecting_aa two_aa sites._aa I_ would_aa consider_aa higher_aa level_aa protection_aa network_aa
security_aa when_aa expend_a the_aa network._aa I_aa will_aa consider_aa building_ network_aa and_aa
implement_aa user_aa application_aa network_aa management_aa policies_a to_aa overcome_aa
congestion_aa and_aa performance_aa issues._aa aa_aa When_aa building_aa new_ network_aa the_aa
system_aa can_aa monitor_aa and_aa respond_ to_aa network_aa security_aa threats_aa in_a real_aa time_aa
to_aa thwart_aa increasingly_aa sophisticated_aa attacks_ and_aa intrusions._aa aa_aa
Planning_aa and_aa Security:_aa Performances_aa and_aa
Security_aa Issues
Today’s_aa networks_aa are_aa congested._aa In_aa addition_aa to_aa carrying_aa traditional_aa
business_aa application_aa data_aa (e.g.,_aa email_aa and_aa file_aa transfer),_aa internal_aa networks_aa
are_aa now_aa also_aa carrying_aa voice_aa traffic_aa and_aa on_aa demand_aa video_aa conferencing._aa
NETWORK_aa ARCHITECTURE_aa SNHUENERGY_ INC 20
Per_aa Dave_aa Shackleford_aa in_aa his_aa article:_aa “Monitoring_aa Security_aa and_aa Performance_aa
on_aa Converged_ Traffic_aa works”_aa states_aa performance_aa and_aa security_aa monitoring_aa are_aa
growing_aa closer_aa together_aa than_ ever_aa as_aa these_aa new_aa and_aa traditional_aa forms_aa of_
traffic_aa clog_aa our_aa networks._aa Although_aa the_aa presence_aa of_aa a_aa performance_aa or_aa
security_aa issue_aa does_a not_aa necessarily_aa indicate_aa the_aa existence_a of_aa the_aa other,_aa
many_aa analysts_aa are_ realizing_aa the_ benefits_aa of_aa behavioral_ baselines_aa and_aa how_aa
a_aa more_aa holistic_aa approach_aa can_ alleviate_aa the_aa problems_a of_aa both_aa congestion_aa
and_aa security._aa For_aa example,_aa large_aa data_aa transfers_aa that_aa are_aa causing_aa congestion_aa
issues_aa could_ potentially_aa indicate_aa an_aa attacker_aa retrieving_aa database_aa records._
Therefore_aa security_aa is_aa major_aa concern_aa on_aa the_ network_aa therefore_aa I_ must_aa seek_aa
a_aa unified_aa way_aa to_aa correlate_aa different_aa alerts_aa from_a performance_aa and_aa security_aa
monitoring_aa systems._aa For_aa security_ keep_aa pace_aa with_aa new_aa attacks_aa on_aa protocols,_aa
such_aa as_aa SIP,_aa which_aa include_aa registration_aa hijacking_a and_aa eavesdropping?_aa
Increased_aa visibility_aa into_aa network_aa traffic_aa and_aa behavioral_aa baselines_aa is_aa critical_aa
to_aa detect_aa and_aa prevent_aa such_aa attacks_aa (Shackeford,_aa 2008)._aa For_aa many_a of_aa
today’s_aa more_aa complex_aa attacks,_aa as_aa well_ as_aa the_aa majority_aa of_ sophisticated_aa
malware,_aa the_aa network_a architecture_aa will_aa need_aa to_aa inspect_aa the_a full_aa content_aa of_
packets_aa on_aa the_a network_aa for_aa application_ like_aa VoIP,_aa email_aa will_aa need_aa to_
decode_aa content_aa within_aa RTP_aa packets_aa with_aa additional_aa tools_aa or_aa inspect_aa
specific_aa SIP_aa packets.
Planning_aa and_aa Security:_aa Network_aa Management_aa tool
Per_aa Fed_aa Tech_a Staff_aa in_ article:_aa “6_aa Network_aa Security_ Tools_aa Every_aa
Agency_aa Needs”_aa states_ Network_aa management_aa systems,_aa with_aa their_aa monitoring_aa
NETWORK_aa ARCHITECTURE_aa SNHUENERGY_ INC 21
capabilities_aa and_aa unified_aa views_aa into_aa infrastructure_aa dynamics,_aa give_aa IT_aa
organizations_aa a_aa powerful_aa weapon_aa for_aa fighting_a cyber_aa threats._a To_aa secure_aa
today’s_aa distributed_aa networks,_aa IT_a teams_aa also_aa must_aa develop_aa defense-in-depth_aa
strategies_aa that_aa combine_a network-enforced _ security _aa technologies _aa with _aa best _aa
practices_aa (Staff,_ 2013)._aa aa_aa According_ to_aa these_aa authors_aa these_aa tools_aa recommend_aa
to_aa use_aa are:
Instruction_aa detection_aa and_aa prevention_aa systems:_aa These_a tools_aa help_aa IT_aa staff_aa
identify_aa and_aa protect_a their_aa wired_aa and_ wireless_aa networks_aa against_aa several_aa
security_a threat_a types._aa These_aa technologies,_aa like_aa several_aa other_aa categories_aa of_aa
network_aa security_aa tools,_aa are_aa being_a deployed_aa with_aa greater_aa frequency_aa as_aa
networks_aa grow_aa in_aa size_aa and_aa complexity_a (Staff,_ 2013)._aa aa_ Both_aa tools_aa
solutions_aa detect_aa threat_aa activity_aa in_ the_aa form_aa of_aa malware,_aa spyware,_aa viruses,_aa
worms_aa and_ other_ attack_aa types,_ as_aa well_aa as_aa threats_aa posed_ by_aa policy_aa
violations._aa Instruction_aa detection_aa tools_aa passively_aa monitor_ and_aa detect_aa suspicious_aa
activity;_aa prevention_aa system_aa tools_ perform_aa active,_ in-line_aa monitoring_ and_aa can_aa
prevent_aa attacks_aa by_ known_aa and_aa unknown_aa sources._aa Both_aa tool_aa types_aa can_aa
identify_aa and_aa classify_ attack_aa types_aa (Staff,_aa 2013).
Anti-Malware:_aa this_aa tools_aa help_ administrators_aa identify,_aa block_a and_aa remove_aa
malware._aa They_aa enable_aa the_ IT_aa department_aa to_aa tailor_aa its_aa anti-malware_aa policies_aa
to_aa identify_aa known_aa and_aa unknown_a malware_aa sources,_aa for_aa example,_ or_aa surveil_
specific_aa users_aa and_aa groups._aa I_aa would_aa use_aa this _a tool_aa for_aa security_aa defenses,_aa
operating_aa systems,_aa browsers,_aa applications_aa and_aa popular_aa targets_aa such_aa as_aa Adobe_aa
NETWORK_aa ARCHITECTURE_aa SNHUENERGY_ INC 22
Flash,_aa Acrobat_aa and_a Reader_aa —_aa that_aa they_ can_aa exploit_aa to_aa fully_a access_aa a_aa
victim’s_aa network.
Network_aa Access_aa control:_aa this_aa tool_aa we_a use_aa for_ compliant_aa devices_aa access_aa to_aa
network_aa assets._aa They_ handle_aa access_aa authentication_aa and_aa authorization_aa functions_aa
and_aa can_aa even_aa control_aa the_a data_aa that_a specific_aa user’s_aa access,_aa based_aa on_a their_aa
ability_aa to_aa recognize_aa users,_aa their_aa devices_aa and_aa their_aa network_a roles._aa aa_ Another_aa
tools_aa I_aa would_aa consider_aa and_aa use_aa is_aa Next-Generation_aa Firewall,_aa this_aa tools_aa
improve_aa on_aa standard_aa firewall_aa capabilities_aa through_aa application-awareness_aa features_aa
(Staff,_aa 2013)._aa aa_aa The_aa last_aa tool_ I_aa will_aa use_aa is_aa authentication_aa and_aa
authorization,_aa per_aa FedTech_aa Staff_aa the_aa traditional_aa directory-based_aa services,_aa such_aa
as_aa Active_aa Directory,_aa authenticates_aa users_aa and_aa grant_aa access_aa based_aa on_a
authorization_aa rules._aa Newer_aa identity-based_a security_a technologies_aa manage_aa
authentication_aa and_aa authorization_aa through_aa such_aa methods_aa as_aa digital_aa certificates_aa
and_aa public_aa key_a infrastructure _ solutions _aa (Staff,_aa 2013).
Planning_aa and_aa Security:_aa Security_aa Devices
From_aa a_aa security_aa standpoint,_aa the_aa pieces_aa of_aa hardware_aa that_aa will_a help_aa
provide_aa security_aa are_ firewalls_aa and_aa routers._ Firewall_aa is_a the_aa first _ security_aa
device_aa I_aa am_aa concern._aa aa_aa aa_aa As_aa the_a first_aa line_aa of_aa network_aa defense, _aa firewalls_aa
provide_aa protection_aa from_aa outside_aa attacks,_a but_aa they_aa have_ no_aa control_aa over_
attacks_aa from_aa within_ the_aa corporate_aa network._aa Some_aa firewalls_aa also_aa block_aa
traffic_aa and_aa services_aa that_a are_aa actually_aa legitimate._aa aa_aa A_a firewall_aa is_a designed_aa
to_aa protect_aa one_aa network_aa from_aa another_aa network._aa _aa In_aa the_aa lesson_aa
“Understanding_aa the_aa Basic_aa Security_aa Concepts_aa of_a Network_aa and_ System_aa
NETWORK_aa ARCHITECTURE_aa SNHUENERGY_ INC 23
Devices”_aa by_aa Bittlingmeier,_ and_aa King_a states_aa network_aa security_ is_aa concentrated_aa
on_aa configuring_aa the_aa firewall,_aa or_aa at_aa least _a is_aa built_aa around_aa it,_aa a_a
compromised_aa firewall_aa can_aa mean_aa a_aa disaster_aa for_a a_aa network._aa _aa Three_aa basic_
types_aa of_aa firewalls_aa are_aa available,_aa in_aa addition_aa to_aa one—the_a stateful_aa inspection_aa
firewall—that_aa combines_aa the_aa features_aa of_aa the_aa three_aa basic_aa types._aa Firewall_aa
architectures_aa include_aa the_aa following:
• Packet-filtering_aa firewall
• Circuit-level_ gateway
• Application-level_aa gateway
• Stateful_aa inspection_aa firewall
Firewalls_aa act_aa like_aa filters._aa They_aa help_aa company_aa monitor_ data_aa traffic_aa between_aa
company’s_aa network_aa and_aa the_aa Internet._aa aa_
For_aa a_aa router,_aa I_aa should_aa make_aa sure_aa it_aa set_aa a_aa password_aa and_aa enable_aa
encryption._aa Unprotected_aa wireless_ networks_aa are_aa a_ bad_aa idea._aa Most_a routers_aa
have_aa either_aa Wireless_aa Encryption_aa (WEP)_aa or_aa Wi-Fi_aa Protected_aa Access_aa (WPA)_
encryption_aa options._aa aa_ Some_aa have_aa both._aa WPA_aa is_aa more_aa secure_aa than_aa WEP._aa
Enabling_aa encryption_aa and_aa choosing_aa a_aa strong_ router_aa administrator_aa password_a
are_aa two_aa steps_a that_aa will_aa help_aa keep_aa company’s_aa network_aa secure.
Planning_aa and_a Security:_aa Changes_aa to_aa Existing_aa devices
The_aa existing_aa devices_ the_aa SNHUEnergy_aa Inc,_aa is_aa Firewall._aa aa_aa I_aa just_aa
may_aa update_aa to_ use_aa Barracuda_aa Next_aa Generation_aa Firewall._aa _aa According_aa to_
the_aa website_aa of_a Barracuda_aa Firewall,_aa this_aa modern_aa network_aa includes_aa a_aa
combination_aa of_aa local_aa servers,_aa remote_aa devices_aa and_aa cloud-hosted_aa applications._ aa_aa
NETWORK_aa ARCHITECTURE_aa SNHUENERGY_ INC 24
Barracuda_aa NextGen_aa Firewalls_aa are_aa purpose-built_aa for_aa the_aa modern,_ distributed_aa
network_aa in_aa which_aa network_aa performance_aa and_aa availability_aa is_aa as_ important_aa as_aa
security._aa Unlike_aa traditional_aa port-based_ firewalls,_aa our_aa firewalls_aa are_aa application-
aware,_aa enabling_aa you_aa to_ regulate_aa application_aa usage_aa and_aa intelligently_aa prioritize_a
network_aa traffic._ aa_aa Barracuda_aa NextGen_aa Firewalls_aa feature_aa advanced_aa security_a
capabilities,_aa including_aa integrated_aa Intrusion_aa Prevention_aa (IPS),_aa URL_aa filtering_aa and_
antivirus_aa to_aa identify_aa and_aa block_aa evasion_aa attempts_aa that_ would_aa trick_a traditional_aa
systems._aa Barracuda’s_aa security_aa extends_aa beyond_aa your_aa network_a to_aa Barracuda’s_aa
Advanced_aa Threat_aa Protection_aa (ATP)_aa cloud_ for_aa both_aa statistical_a and_aa sandboxing_aa
analysis_aa of_aa zero-day_aa and_aa targeted_aa threats_aa that_aa routinely_aa bypass_ signature-
based_aa IPS_aa and_ antivirus_aa engines_aa (Barracuda.com)._aa aa_aa
Planning_aa and_aa Security:_aa Challenges
Barracuda_ next-generation_aa firewalls_aa are_aa fully_aa application_aa and_ user_aa
aware_aa and,_aa thus,_aa can_ specifically_aa allow_aa or_aa disallow_aa access_aa to_aa certain_aa
applications_aa by_aa users._ aa_aa How_aa we_aa address_aa information_aa security_aa and_aa risk_aa
management._aa The_aa challenge_aa is_aa that_ cloud_aa security_aa processes_aa and_aa solutions_a
are_aa still_aa being_aa developed._aa aa_aa Managing_ configuration_aa changes_aa on_aa switches,_aa
routers,_aa firewalls,_aa controllers,_aa and_aa other_a network_aa devices,_aa at_aa locations_aa across_aa
the_a network,_aa is_aa an_aa obvious_aa challenge._aa For_aa example,_aa deploying_aa a_aa new_aa
service,_aa which_aa involves_aa wide-scale_aa configuration_aa changes,_aa could_aa take_aa days_aa
or_aa weeks_aa to_aa reliably_aa complete._aa According_aa to_ article:_aa “The_aa Best_aa Free_aa
Network_aa Configuration_aa and_a Change_aa Management_aa Tools”_aa make_aa me_aa consider_aa
must_aa have_aa a_ reliable _ way_aa for_aa knowing_aa when,_aa who,_aa what,_aa and_aa how_aa your_aa
NETWORK_aa ARCHITECTURE_aa SNHUENERGY_ INC 25
device_aa configurations_aa have_aa changed._aa This_aa will_aa help_aa you_a detect_aa out-of-process_aa
and_aa rogue_aa changes,_a reconcile_aa changes_aa to_aa valid_aa change_aa requests,_aa and_aa ensure_aa
that_aa actual_aa changes_aa were_aa properly_aa made._aa aa_aa Another_a challenge_aa we_aa must_a
think_aa by_aa Ranbe_a in_aa article:_aa “What_aa happen_aa if_aa Firewall_aa disable”_aa that_aa will_aa
affect_aa all_aa data_a packets_aa to_aa entering_aa and_aa exiting_aa the_aa network_aa unrestricted._aa
This_aa includes_aa not_a just_aa expected_aa traffic,_aa but_aa also_aa malicious_ data_aa --_aa thereby_aa
putting_aa the_aa network_a at_aa risk._aa If_aa a_aa software _aa firewall_a is_aa disabled,_aa it's_aa not_aa
just_aa the_aa associated_ computer_aa that's_aa in_aa harm's_aa way;_ worms_aa --_aa a_ type_aa of_aa
malware_aa --_aa for_aa example,_aa can_aa spread_aa across_aa a_ network_aa connection,_aa infecting_aa
all_aa of_aa the_ PCs_aa attached_aa to_aa the_aa LAN._aa Disabling_aa a_ hardware_aa firewall_aa also_aa
impacts_aa all_ of_aa the_aa devices_aa that_aa connect_aa to_aa the_ network_aa (Ranbe,_aa N.D)._aa
Planning_aa and_aa Security:_aa Overall_aa Risk
According_aa to_aa article:_aa “The_aa Increasing_aa Threat_aa to_aa Network_aa Infrastructure_aa
Devices_aa and_aa Recommended_aa Mitigations”_aa the_aa author_aa gives_a the_aa risk_aa when_aa
update_aa network_aa device._aa aa_aa According_aa to_aa the_aa author_ perimeter_aa devices,_aa such_a
as_aa firewalls_aa and_aa intrusion_aa detection_aa systems,_aa have_aa been_aa the_aa traditional_aa
technologies_aa used_aa to_ secure_aa the_aa network,_aa but_aa as_aa threats_a change,_aa so_aa must_aa
security_aa strategies._aa Organizations_aa can_aa no_aa longer_aa rely_ on_aa perimeter_aa devices_aa
to_aa protect_aa the_ network_aa from_aa cyber_aa intrusions;_aa organizations_a must _a also_aa be_aa
able_aa to_aa contain_ the_aa impact/losses_aa within_aa the_aa internal_aa network_aa and_aa
infrastructure_aa (N.A,_aa 2016)._aa The_ risk_aa is_a when_aa the_aa network_aa administrator_aa
change_aa the_aa network_a device_aa or_aa upgrade_aa the_aa software_aa attackers_aa either_aa use_a
the_aa default_aa credentials_aa to_aa log_aa into_ the_aa device_aa or_a obtain _ weak_aa credentials_aa
NETWORK_aa ARCHITECTURE_aa SNHUENERGY_ INC 26
from_aa other_aa insecure_aa devices_aa or_aa communications._aa The_aa implant_aa resides_aa within_aa
a_aa modified_aa IOS_ image_aa and,_aa when_a loaded,_aa maintains_aa its_aa persistence_aa in_aa the_aa
environment,_aa even_aa after_aa a_aa system_ reboot._aa Any_aa further_aa modules_aa loaded_aa by_
the_aa attacker_aa will_a only_aa exist_aa in_aa the_aa router’s_aa volatile_aa memory_ and_aa will_aa not_aa
be_aa available_aa for_a use_aa after_aa the_ device_aa reboots._aa However,_aa these_aa
devices_aa are_aa rarely_aa or_ never_aa rebooted_aa (N.A,_aa 2016)._aa _aa If_aa the_aa network_aa
infrastructure_aa is_aa compromised,_aa malicious_aa hackers_aa or_aa adversaries_aa can_aa gain_aa full_aa
control_aa of_aa the_aa network_aa infrastructure _a enabling_aa further_aa compromise_aa of_aa other_aa
types_aa of_aa devices_aa and_aa data_aa and_aa allowing_aa traffic_aa to_aa be_ redirected,_aa changed,_aa
or_aa denied._aa Possibilities_aa of_aa manipulation_aa include_aa denial-of-service,_aa data_aa theft,_
or_aa unauthorized_aa changes_aa to_aa the_aa data_a (N.A,_aa 2016).
I’ve_aa learned_aa all_aa the_aa challenge_aa and_a the_aa risk_aa when_aa network _ device_aa upgrade_aa
I_aa will_aa consider_aa when_aa I_aa perform_aa the_aa change._aa aa_ I_aa learn_a from_aa the_aa article_aa
opening_aa the_aa firewall_aa does_aa potentially_aa allow_aa malicious_aa traffic_aa to_aa enter_aa
through_aa the_aa applicable_aa port,_aa but_aa businesses_aa can_aa use_aa nonstandard_aa ports,_aa
when_aa possible,_aa to_aa reduce_aa the_aa risk_aa of_aa attack_aa (N.A,_aa 2016)._aa Therefore,_aa when_aa
I_aa applying_aa software_a updates_aa or_aa installing_a new_aa programs_aa --_aa the_aa software_aa
firewall_aa must_aa be_aa disabled._aa When_aa possible,_ I_aa should_aa disconnect_aa a_aa computer_aa
from_aa the_aa Internet_aa before_ disabling _aa the _ firewall_aa to_aa eliminate_aa the_a risk_aa of_aa
attack._aa
Conclusions
With_aa the_a network_aa becoming_aa more_aa important_aa than_aa ever,_ the_aa three_aa
top_aa reasons_aa for_aa network_aa upgrades_aa are_aa performance,_aa reliability_aa and_aa security_a
NETWORK_aa ARCHITECTURE_aa SNHUENERGY_ INC 27
that_aa SNHUEnergy,_aa Inc_aa consider._aa When_aa we_aa upgrade_ the_aa network,_aa the_
clients_aa and_aa users_a use_aa multimedia_aa and_aa unified_aa communications_aa over_a IP_aa such_aa
as_aa telephones,_aa IM_aa and_ video,_aa it's_ important_aa that_aa they_aa have_aa a_a reliable_aa
Internet_aa connection_aa and_aa a_a high-functioning_aa router._aa The_ quality_aa of_aa service_aa
on_aa network,_aa video_a conferencing,_aa voice_aa are_aa become_aa important_a too._aa aa_aa The_aa
main_aa thing_aa is_ security,_aa when_aa we_a upgrade_aa network_aa with_aa high_ security,_aa
with_aa the_aa new_ firewall_aa generation_aa keeps_aa track_aa of_ all_aa the_aa operations_aa
performed_aa in_aa the_aa network_aa device_aa -_a who_aa invoked_aa what_ operation,_aa on_aa what_aa
device_aa at_aa what_aa time_aa and_aa the_ result_aa of_a the_aa operation._aa
Reference
Achetson,_aa K._aa (2014,_aa April_aa 2)._aa The_aa Seven_aa Layers_aa of_aa Networking._aa
Retrieved_aa August_a 19,_aa 2017,_aa from_aa http://blog.boson.com/bid/102913/The-Seven-
Layers-of-Networking-Part-III
Architecture_aa evolution_aa for_aa automation_ and_aa network_aa programmability._aa
(2014,_aa November_aa 28)._aa Retrieved_aa August_aa 6,_aa 2017,_aa from_aa
https://www.ericsson.com/en/publications/ericsson-technology-review/archive/2014/architecture-
evolution-for-automation-and-network-programmability?fromDate=2014-01-
01&categoryFilter=ericsson_review_1270673222_c&toDate=2014-12-31
Aubrett's_aa Non-Technical_aa IT_aa Dictionary_aa -_aa Switch._aa (n.d.)._a Retrieved_aa July_aa
9,_aa 2017,_aa from_aa https://www.aubrett.com/non-technical/network/switch/non-technical-switch
NETWORK_aa ARCHITECTURE_aa SNHUENERGY_ INC 28
Balancing_aa network_aa performance_aa and_aa network_aa security_aa in_ a_aa smart_aa grid_aa
application._aa (n.d.)._aa Retrieved_ July_aa 23,_a 2017,_aa from_a
http://ieeexplore.ieee.org/document/7819235/
Bittlingmeier,_aa D.,_aa &_aa King,_aa T._aa (2003,_aa April_ 25)._aa CompTIA_aa Security_aa
Exam:_aa Devices,_aa Media,_ and_aa Topology_aa Security._aa Retrieved_aa August_aa 19,_aa 2017,_aa
from_aa http://www.pearsonitcertification.com/articles/article.aspx?p=31562&seqNum=2
Description_aa of_aa support_ for_aa network_aa database_aa files_aa in_ SQL_aa Server._aa
(2016,_aa April_aa 12)._aa Retrieved_aa July_aa 23,_a 2017,_aa from_a
https://support.microsoft.com/en-us/help/304261/description-of-support-for-network-database-
files-in-sql-server
Exploring_aa the_aa Modern_ Computer_aa Network:_aa Types,_aa Functions,_aa and_aa
Hardware._aa (2013,_aa December_aa 13)._aa Retrieved_aa July_aa 23,_a 2017,_aa from_
http://www.ciscopress.com/articles/article.asp?p=2158215
Flexibility_aa in_aa 5G_a transport_aa networks:_aa the_aa key_aa to_ meeting_aa the_aa
demand_aa for_aa connectivity._aa (n.d.)._aa Retrieved_aa August_ 6,_aa 2017,_aa from_aa
https://www.ericsson.com/en/publications/ericsson-technology-review/archive/2015/flexibility-
in-5g-transport-networks-the-key-to-meeting-the-demand-for-connectivity
Henderson,_aa R._aa (2013,_aa October_aa 1)._aa Network _a Architecture_aa Of_ The_aa
Future:_aa It’s_aa Now._aa Retrieved_aa August_aa 6,_a 2017,_aa from_aa
http://blog.mavtechglobal.com/blog/2013/10/01/network-architecture-of-the-future-its-now
Harrel,_aa R._aa (n.d.)._a Understanding_aa the_aa network_aa application_aa environment._aa
Retrieved_aa August_aa 19,_ 2017,_aa from_aa
NETWORK_aa ARCHITECTURE_aa SNHUENERGY_ INC 29
http://searchenterprisewan.techtarget.com/tip/Understanding-the-network-application-
environment
Michell,_aa B._aa (2017,_aa February_aa 8)._aa What_aa Is_aa a_aa Router_aa for_aa Computer_aa
Networks?_aa Retrieved_aa July_aa 9,_aa 2017,_aa from_a https://www.lifewire.com/how-routers-
work-816456
Mitchell,_aa B._ (2017, _aa April _a 07). _aa The _aa Layers_aa of_aa the_a OSI_aa Model_aa
Illustrated._aa Retrieved_aa July_aa 9,_aa 2017,_aa from_a https://www.lifewire.com/layers-of-the-osi-
model-illustrated-818017
Millman,_aa R._aa (n.d.)._a What’s_aa slowing_aa down_aa your_aa network_aa and_aa how_a to_aa
fix_aa it._aa Retrieved_aa July_aa 23,_aa 2017,_aa from_aa
http://www.computerweekly.com/feature/Whats-slowing-down-your-network-and-how-to-fix-it
Ranbe,_aa R._aa (n.d.)._a What_aa Happens_aa if_aa a_aa Firewall_aa Is_ Disabled?_aa
Retrieved_aa July_aa 9,_ 2017,_aa from_aa http://smallbusiness.chron.com/happens-firewall-
disabled-62134.html
Rouse,_aa R._aa (2017,_aa May_aa 17)._aa Future-Proofing_aa Oil_aa and_ Gas_aa Networks:_aa
4_aa Things_aa to_ Look_aa For._aa Retrieved_aa August_aa 6,_aa 2017,_aa from_aa
http://www.belden.com/blog/industrialethernet/future-proofing-oil-and-gas-networks-4-things-
to-look-for.cfm
Shackleford,_aa D._aa (2008,_aa April_a 30)._aa Monitoring_aa Security_a and_aa
Performance_aa on_aa Converged_aa Traffic_a works._aa Retrieved_aa August_aa 19,_aa 2017,_a from_aa
https://www.sans.org/reading-room/whitepapers/analyst/monitoring-security-performance-
converged-traffic-networks-34720
NETWORK_aa ARCHITECTURE_aa SNHUENERGY_ INC 30
Staff,_aa F._aa T._aa (2013,_a September_aa 23)._aa 6_a Network_aa Security_aa Tools_aa Every_aa
Agency_aa Needs._aa Retrieved_aa August_aa 19,_aa 2017,_aa from_aa
https://fedtechmagazine.com/article/2013/09/6-network-security-tools-every-agency-needs
Simoneau,_aa P._ (n.d.)._aa The_aa OSI_aa Model:_aa Understanding_aa the_aa Seven_aa
Layers_aa of_aa Computer_aa Networks._aa Retrieved_aa July_ 9,_aa 2017,_aa from_aa
http://ru6.cti.gr/bouras-old/WP_Simoneau_OSIModel.pdf
Singh,_aa N._aa (n.d.)._aa WHAT_aa IS_aa A_ FIREWALL?_aa Firewalls_aa and_aa Their_aa
Evolution._aa Retrieved_aa July_aa 9,_ 2017,_aa from_aa
https://www.paloaltonetworks.com/cyberpedia/what-is-a-firewall
Simoneau,_aa P._ (n.d.)._aa The_aa OSI_aa Model:_aa Understanding_aa the_aa Seven_aa
Layers_aa of_aa Computer_aa Networks._aa Retrieved_aa July_ 9,_aa 2017,_aa from_aa
http://ru6.cti.gr/bouras-old/WP_Simoneau_OSIModel.pdf
Singh,_aa N._aa (n.d.).What_aa is_aa the_aa Firewalls?_aa Firewalls_aa and_aa Their_aa
Evolution._aa Retrieved_aa July_aa 9,_ 2017,_aa from_aa
https://www.paloaltonetworks.com/cyberpedia/what-is-a-firewall
Team,_aa A._aa (2017,_aa April_ 18)._aa 7_a Factors_aa that_aa can_aa impact_aa your_aa
network_aa performance._aa Retrieved_aa July_aa 23,_aa 2017,_aa from_aa
http://www.annese.com/blog/7-factors-that-can-impact-your-network-performance
The_aa Best_aa Free_aa Network_aa Configuration_aa and_aa Change_aa Management_ Tools._aa
(2016,_aa March_aa 16)._ Retrieved_aa August_aa 20,_aa 2017,_aa from_
http://www.dnsstuff.com/free-network-configuration-management-tools
NETWORK_aa ARCHITECTURE_aa SNHUENERGY_ INC 31
The_aa Increasing_aa Threat_aa to_aa Network_aa Infrastructure_aa Devices_a and_aa
Recommended_aa Mitigations._aa (2016,_aa September_a 6)._aa Retrieved_aa August_aa 20,_aa 2017,_aa
from_aa https://www.us-cert.gov/ncas/alerts/TA16-250A
The_aa OSI_aa Model:_aa applications,_aa devices,_aa and_aa protocols_a related_aa to_aa the_aa
OSI_aa model_aa Layers._a (n.d.)._aa Retrieved_ July_aa 9,_aa 2017,_a from_aa
https://www.examcollection.com/certification-training/network-plus-osi-model-application-
devices-and-protocols.html
Vouzis,_aa P._aa (2016,_aa August_aa 18)._aa Impact_ of_aa Packet_aa Loss,_aa Jitter,_ and_aa
Latency_aa on_ VoIP._aa Retrieved_aa July_aa 23,_aa 2017,_aa from_aa
https://netbeez.net/2016/08/18/impact-of-packet-loss-jitter-and-latency-on-voip/
https://www.barracuda.com/products/ngfirewall
NETWORK_aa ARCHITECTURE_aa SNHUENERGY_ INC 32