1 / 31100%
NETWORK aa ARCHITECTURE aa SNHUENERGY aa INC 1
N aa Arch aa SNHUE aa In ,
Southern aa New aa Hampshire aa University aa
IT 640-Q5156 aa Telecommunication/ aa Networking a
NETWORK aa ARCHITECTURE aa SNHUENERGY aa INC 2
Executive aa Summary
SNHUEnergy Inc, aa is aa a aa medium aa sized aa oil aa and aa gas aa company aa that aa is aa
focused aa on aa the aa discovery aa and aa drilling aa of aa oil-base aa products. aa a aa The aa company aa
wants aa to aa grow aa focused aa on aa exploration aa into aa a aa company aa that also aa provides aa
the aa transportation aa and aa refinement of aa its aa discoveries. aa aa aa This aa is aa a aa big aa step aa for
the aa company, aa and a it aa wants aa to aa make aa sure aa the aa communication aa infrastructure aa is
ready aa to a delivery aa in aa the aa next aa 12 aa to aa 18 aa months. The aa current aa network aa
now aa give aa us aa some aa concern aa about aa impact aa of aa losing aa connectivity aa between aa
Dallas aa router aa and aa the aa Memphis aa router aa affect aa to aa business, aa communication aa
between aa the aa users. aa aa The aa network aa loses aa connectivity aa means aa lost a dollars aa and aa
lost aa business aa opportunities. aa The aa application aa may aa be aa impact aa should aa be: a email, aa
Video aa Conferencing, aa Payroll, aa Accounting aa and aa HR. aa When aa the aa router aa losing aa
connectives aa the aa users aa must aa waiting aa on aa their aa network aa to aa catch aa up aa to the aa
speed aa at aa which aa they aa are aa working. aa They aa have to aa sit aa and aa wait aa for aa file aa
transfers, aa applications aa to open, aa attachments aa to download, aa and aa web aa pages aa to aa
open. aa Slow aa internet aa causes aa costly aa delays aa in the aa company aa operations aa and aa work
flow aa management. aa The aa risk aa of aa just a having aa a aa single aa router aa or aa switch aa within
Memphis aa office aa it a could aa shut aa down aa the a Memphis aa site aa if aa the aa router aa in aa
Memphis aa down, aa or aa switch aa down. aa aa aa The a route aa traffic aa takes aa among aa different aa
network aa providers aa also a affects aa performance. aa
In the aa future, aa the a company aa will aa extend a these aa services aa across aa the aa WAN
by aa using aa TCP/IP aa communication aa processes, aa because aa Wide aa Area aa Network aa
(WAN) aa to aa connect aa the aa two aa locations. aa WAN aa connections aa vary aa in aa bandwidth aa
NETWORK aa ARCHITECTURE aa SNHUENERGY aa INC 3
depending aa on aa your aa needs, aa and aa may aa be aa set aa up aa as aa a direct aa connection aa or a
virtual aa private aa network aa (VPN) aa via aa the a Internet. aa Either aa way, aa connecting aa your aa
locations aa will aa enable aa better aa and aa more aa secure aa communication aa within aa your aa
business. aa aa aa For aa Memphis aa site aa we aa will aa get aa extra aa switch a and aa router aa for a back aa
up, aa in aa case aa the aa single aa switch, a and aa router aa down. aa aa I aa would aa consider aa security
when aa making aa any change aa to aa company aa network aa infrastructure, aa especially aa when aa
connecting aa two aa sites. a I aa would aa consider aa higher aa level aa protection aa network aa security
when aa expend aa the a network.
Current aa Network aa Architecture: aa Network aa Applications
The aa company aa currently aa uses these aa applications: aa Email, aa Payroll, aa
Accounting, aa and aa Human aa Resource. aa aa aa The aa network plays aa a aa huge aa role aa in aa
application aa performance aa management aa in aa the aa company. aa aa aa Per aa Robbie aa Harrel aa in aa
journal aa article: aa “Understanding aa the aa network aa application aa environment” aa states aa
depending aa upon aa server aa locations aa and aa network aa geography, aa the aa traffic aa patterns aa
can aa be aa significantly aa different aa for aa different aa areas aa of aa the aa network. aa This a requires
a aa wide aa view aa of aa the aa network aa in aa terms a of aa capturing aa application aa flows.
Therefore aa we aa need aa to aa understanding aa and aa controlling aa that traffic aa is critical, aa
and aa centralizing aa computing facilities aa for aa servers aa can aa provide aa greater aa visibility aa
without aa the aa need aa to aa decentralize aa application a traffic aa capturing aa capabilities aa
(Harrell, aa N.D).
Current aa Network aa Architecture: aa OSI aa Model
The aa component aa of aa the aa network aa with aa the aa OSI aa transport aa layer: aa switch,
router, firewall, aa PC work aa stations, aa servers, aa application. aa aa The aa device aa use aa for aa
NETWORK aa ARCHITECTURE aa SNHUENERGY aa INC 4
network aa layer aa is router. aa aa aa Layer aa 3, aa the aa network aa layer aa of the aa OSI aa model, aa
provides aa an aa end-to-end aa logical aa addressing aa system aa so aa that aa a aa packet aa of aa data aa
can aa be aa routed aa across aa several layer aa 2 aa networks aa (Ethernet, aa Token aa Ring, aa Frame aa
Relay, aa etc.). aa aa aa Note aa that aa network aa layer addresses aa can aa also aa be aa referred aa to aa as aa
logical aa addresses. aa To aa make aa it aa easier aa to aa manage aa the aa network aa and aa control aa the
flow aa of aa packets, many aa organizations aa separate aa their aa network aa layer aa addressing aa
into aa smaller aa parts a known aa as aa subnets. aa Routers aa use aa the network aa or aa subnet aa
portion aa of aa the aa IP aa addressing aa to aa route traffic aa between aa different aa networks. aa Each
router aa must aa be a configured aa specifically aa for aa the networks aa or aa subnets aa that will aa
be aa connected aa to aa its aa interfaces aa (Simoneau, aa N.D). aa
The aa Firewall aa device a is aa use aa in aa Transport aa layer aa of aa the OSI aa model, aa
offers aa end-to-end aa communication aa between aa end devices aa through aa a aa network. aa
Depending aa on aa the aa application, aa the aa transport aa layer either aa offers aa reliable, aa
connection-oriented aa or aa connectionless, aa best-effort aa communications aa (Simoneau, aa N.D).
Base aa on aa the aa current aa network aa architecture aa the aa company aa use aa the aa Internet aa
Layer aa to aa uses the aa source aa and aa destination aa addresses aa in aa order aa to aa facilitate aa the aa
movement aa of aa data aa between aa the aa Network Access aa layer aa and aa the aa Transport aa
layer; aa the aa data a flows aa from aa one aa node on aa the a network aa to aa the aa next aa node aa in aa
a aa path aa moving aa toward aa the aa final aa destination aa by aa Achetson aa defines aa in aa the aa
article: aa “The aa seven aa Layers aa of aa Networking”. aa Per aa Achetson aa the aa two aa other aa
common aa protocols aa that aa operate aa at aa the aa TCP/IP aa Internet aa layer aa are aa derivatives of
IP: aa IP aa version aa 4 aa (IPv4) aa and aa IPv6. aa The devices aa that aa typically aa operate aa at aa
the aa Internet aa layer aa are aa routers. aa The aa Internet aa layer aa of aa the TCP/IP aa model aa
NETWORK aa ARCHITECTURE aa SNHUENERGY aa INC 5
corresponds aa to aa the Network aa layer aa (Layer aa 3) aa of aa the aa OSI aa model aa (Achetson, aa
2014).
Current aa network: aa Physical aa network aa devices
Per aa article: aa “Exploring aa the aa Modern aa Computer aa Network: a Types, aa Functions, aa
and aa Hardware” aa the aa network aa infrastructure aa contains aa three aa categories aa of aa network aa
components:
• End aa devices
• Intermediary aa devices
• Network aa media
Hardware aa comprises aa the aa components aa of aa the aa network aa platform aa that aa typically aa are
visible, aa such aa as aa a laptop, aa PC, aa switch, aa router, wireless aa access aa point, aa or aa the aa
cabling aa used aa to a connect aa the aa devices. aa Occasionally, aa some aa network aa components aa
may aa not aa be a visible. aa In the aa case aa of aa wireless aa media, aa for aa example, aa messages aa
are aa transmitted aa through aa the air aa using aa invisible aa radio aa frequency aa or aa infrared aa
waves. aa aa aa The aa physical aa Computers aa (work aa stations, aa laptops, aa file aa servers, aa web aa
servers)
• Network aa printers
• VoIP aa phones
• TelePresence aa endpoints
• Security aa cameras
• Mobile aa handheld aa devices aa (such aa as aa smartphones, aa tablets, aa PDAs, aa and aa
wireless aa debit/credit aa card aa readers aa and aa barcode aa scanners) aa (Exploring aa the aa
Modern aa Computer aa Network: aa Types, aa Functions, aa and aa Hardware, aa 2013).
NETWORK aa ARCHITECTURE aa SNHUENERGY aa INC 6
The aa physical aa of aa the aa network aa with aa the aa OSI aa transport aa layer: aa switch, aa router,
firewall, aa PC aa work aa stations, aa servers, aa application. aa aa aa The aa device use aa for aa network aa
layer aa is aa router. aa aa aa Layer aa 3, aa the aa network layer aa of aa the aa OSI aa model, aa provides aa
an aa end-to-end aa logical aa addressing a system aa so aa that aa a aa packet aa of aa data aa can aa be aa
routed aa across aa several layer aa 2 aa networks aa (Ethernet, aa Token aa Ring, aa Frame aa Relay, aa
etc.). aa Note aa that aa network aa layer aa addresses aa can aa also aa be aa referred aa to aa as aa logical aa
addresses. aa aa aa To aa make aa it aa easier aa to aa manage aa the aa network aa and aa control aa the flow
of aa packets, aa many organizations aa separate aa their aa network layer aa addressing aa into aa
smaller aa parts aa known aa as aa subnets. aa Routers aa use aa the aa network aa or aa subnet aa portion aa
of aa the aa IP aa addressing aa to aa route aa traffic aa between aa different aa networks. aa Each a router aa
must aa be aa configured aa specifically aa for aa the aa networks aa or aa subnets aa that will aa be aa
connected aa to aa its interfaces aa (Simoneau, aa N.D). aa
The aa Firewall aa device a is aa use aa in aa Transport aa layer aa of aa the OSI aa model, aa
offers aa end-to-end aa communication aa between aa end devices aa through aa a aa network. aa
Depending aa on aa the aa application, aa the aa transport aa layer either aa offers aa reliable, aa
connection-oriented aa or aa connectionless, aa best-effort aa communications aa (Simoneau, aa N.D).
Current aa network: aa Critical aa Traffic aa Patterns
According aa article: aa “7 aa factors that aa an aa impact aa your aa network aa performance” aa
Annese aa Team aa states a aa network’s aa limitations aa are aa critical aa areas aa of aa concern aa
when aa performing aa capacity aa and aa performance aa management. aa These limitations aa
primarily aa include aa the following:
Errors: aa Network aa errors aa can aa generally aa be aa categorized aa into aa problems aa with aa
queuing, aa latency, aa and aa jitter. aa The aa data aa queue aa can aa affect aa network aa performance aa
NETWORK aa ARCHITECTURE aa SNHUENERGY aa INC 7
in aa several aa ways. aa For aa example, aa larger aa queues aa increase aa the aa wait aa time, while aa
smaller aa queues aa increase aa the aa probability aa of aa dropped data.
Speed: aa Pipe aa size aa is aa the aa amount aa of aa data the aa network aa can aa send aa
simultaneously aa on aa a a single aa connection. aa It's aa often aa confused aa with aa connection aa
speed, aa although aa pipe aa size aa doesn't aa actually aa affect aa the aa speed aa at aa which aa data aa
travels aa between aa nodes. aa While aa hardware aa capabilities aa determine aa the aa maximum aa
bandwidth aa that aa is aa theoretically aa available, aa software aa mechanisms aa typically aa allocate a
a aa lower aa bandwidth aa for aa each aa network aa service.
Memory: aa Memory aa is a aa computing aa resource aa that aa has aa requirements in aa both aa the
data aa and aa control planes. aa The aa performance aa of the aa entire aa network aa can aa degrade
when aa control aa plane aa processes aa fail, aa as aa is aa the aa case aa when aa routing aa convergence aa
requires aa additional aa memory.
Distance: aa Distance aa can have aa a aa dramatic impact aa on aa network performance, aa
especially aa when aa the aa applications aa haven't aa been aa optimized. aa The aa maximum aa speed aa
at aa which aa data aa can aa be aa forward aa is aa the aa speed aa of aa light, aa which aa is aa 186,000 aa
miles aa per aa second aa or aa 186 aa miles aa per aa millisecond. aa This aa packet aa forwarding aa delay
becomes aa significant aa when aa an aa enterprise aa is aa running aa an aa international aa client/server
application.
Central aa Processing aa Unit aa (CPU): aa A aa node's aa central aa processing aa unit aa (CPU) aa is
typically aa used aa by aa both aa the aa control aa and data aa planes. aa Capacity aa and aa performance
management aa requires aa a aa network aa and aa its nodes aa to aa have insufficient aa processing
capability aa at aa all aa times. a A aa single aa node with aa an aa inadequate a CPU aa can aa impact aa
the aa entire aa network aa due aa to aa the high aa degree aa of aa interdependence aa between aa the aa
NETWORK aa ARCHITECTURE aa SNHUENERGY aa INC 8
nodes aa in aa the modern aa network. aa Insufficient aa processing aa can aa also aa increase aa latency
if aa a aa node's aa CPU aa is aa unable aa to aa keep up aa with aa network aa traffic.
Applications: aa Applications aa can aa also aa affect aa a aa network's aa capacity aa and aa
performance, aa with aa issues aa such aa as aa the aa amount aa of a data aa the aa application aa is aa able
to aa transmit aa compared aa to aa what aa it aa needs aa to a transmit. aa This aa factor aa is aa especially
critical aa for aa the aa performance aa of aa Wide aa Area aa Networks aa (WANs). aa Additional aa
application aa characteristics that aa affect aa capacity aa and aa performance aa include aa
application aa keep-alive aa and window aa sizes aa (Team, 2017).
Management aa of aa a aa network's aa availability, aa capacity, aa and a performance aa is aa therefore aa
crucial aa for aa achieving an aa organization's aa business aa objectives. aa It aa really aa impact aa of aa
losing aa connectivity aa between aa Dallas aa router aa and aa the aa Memphis router aa affect aa to aa
business, aa communication aa between aa the users. aa aa aa The network aa loses aa connectivity aa
means aa lost aa dollars aa and aa lost aa business aa opportunities. aa The aa application aa may be aa
impact aa should aa be: aa email, aa Video aa Conferencing, aa Payroll, aa Accounting and aa HR. aa
When aa the aa router aa losing aa connectives aa the aa users aa must aa waiting aa on aa their aa network aa
to aa catch aa up to aa the speed aa at aa which aa they are aa working. aa They aa have aa to aa sit aa
and aa wait aa for aa file aa transfers, aa applications aa to aa open, aa attachments aa to aa download, aa
and aa web aa pages aa to aa open. aa Slow aa internet aa causes aa costly aa delays in aa the aa company
operations aa and aa work a flow aa management. aa According aa to aa Pangiotis aa Vouzis aa in the aa
article: aa “Impact aa of Packet aa Loss, aa Jitter, aa and aa Latency aa on aa VoIP” aa the aa poor aa VoIP
quality aa because aa latency, aa jilter, aa and aa packet aa loss aa can aa never aa be aa completely aa
eliminated aa from aa real a world aa networks. aa (Vouzis, aa 2016). aa Telephony aa is aa all aa UDP aa
based, aa and aa packets aa may aa not aa arrive aa at aa the aa destination, aa or aa get aa discarded aa if aa
NETWORK aa ARCHITECTURE aa SNHUENERGY aa INC 9
they aa arrive aa delayed a or aa contain aa errors. aa This aa results aa in aa missing aa audio aa
information aa at aa the aa destination. aa
aa SQL aa Server, aa similar aa to aa other aa enterprise aa database aa systems, aa can aa place aa an aa
extremely aa large aa load aa on aa an aa I/O aa subsystem. aa In aa most aa large aa database aa
applications, aa physical aa I/O aa configuration aa and aa tuning aa play aa a a significant aa role aa in aa
overall aa system aa performance. aa aa aa There aa are aa three aa major aa I/O aa performance aa factors aa
to aa consider:
• I/O aa bandwidth: aa The aa aggregate aa bandwidth, aa typically aa measured aa in aa
megabytes aa per aa second aa that a can aa be aa sustained aa to a aa database aa device
• I/O aa latency: aa The aa latency, aa typically aa measured aa in aa milliseconds, aa between aa a aa
request aa for aa I/O aa by aa the aa database aa system a and aa the aa point where aa the aa I/O aa
request aa is aa completed
• CPU aa cost: aa The host aa CPU aa cost, aa typically aa measured aa in aa CPU
microseconds, aa for aa the aa database aa system aa to aa complete aa a aa single aa I/O
(Description aa of aa support aa for network aa database aa files a in aa SQL aa Server, a 2016).
According aa from aa Rene aa Millman aa in aa the aa article: aa “What’s aa slowing aa down aa your aa
network aa and aa how aa to aa fix aa it” aa Network aa management aa to aa watch aa when aa network aa
slow aa is aa to aa see aa bandwidth aa as aa the aa problem, aa but aa with investigation, aa it aa is aa often
not aa within aa a LAN aa environment, aa where aa a aa high aa amount aa of aa bandwidth aa is aa
available. aa More aa likely, aa the aa problem aa lies within aa the aa WAN, aa where aa capacity aa is
more aa finite aa and aa expensive aa (Millman, aa N.D).
Current aa network aa Architecture: aa Pattern aa across aa the aa Infrastructure
NETWORK aa ARCHITECTURE aa SNHUENERGY aa INC 10
According aa Michelle aa in aa article:” aa The aa Layers aa of aa the aa OSI aa Model aa
Illustrated” aa The aa organizations aa have aa a aa systems aa (servers, aa desktops, aa laptops, aa mobile
devices, aa etc.) aa available aa worldwide and aa connected aa through aa LAN aa and aa WAN aa
connections aa in aa multiple aa locations aa such aa as aa the aa internet, aa internal aa networks, aa
perimeter aa networks, aa as aa well aa as aa across a firewalls aa and aa other a security aa equipment aa
that aa need aa to aa be aa managed aa and aa supported aa centrally, aa using aa a aa systems aa
management aa tool aa or a solution aa that aa has aa to aa be aa designed, adapted aa and aa configured
in aa order a to aa address aa business aa and aa technical aa concerns. aa aa First aa we aa need aa
identify aa network aa requirement aa on aa 2 aa factors:
Business aa goals: aa Focus a on aa how aa the aa network aa can aa make aa the aa business aa more
successful. aa
Technical aa requirements: aa Focus on aa how aa the aa technology aa is aa implemented aa within aa
the aa network
The aa next aa one aa we aa need aa characterizing aa the a existing aa network: aa Information aa about
the aa current aa network aa and aa services aa is aa gathered aa and aa analyzed. aa It aa is aa necessary aa
to aa compare aa the functionality aa of aa the aa existing aa network aa with the aa defined aa goals aa
of aa the aa new aa project. aa The aa designer aa determines a whether aa any aa existing equipment, aa
infrastructure, aa and aa protocols aa can aa be aa reused, and aa what aa new a equipment aa and aa
protocols aa are aa needed to aa complete aa the aa design. aa aa aa Then a design aa network aa topology:
the aa network aa applications aa and aa service aa requirements aa are aa identified, aa and aa then aa the
network aa is aa designed aa to aa support them. aa When aa the aa design is aa complete, aa a aa
prototype aa or aa proof-of-concept aa test aa is aa performed. aa This a approach aa ensures aa that aa the
new aa design aa functions aa as aa expected aa before aa it aa is aa implemented. aa Routers aa are aa
NETWORK aa ARCHITECTURE aa SNHUENERGY aa INC 11
small aa electronic aa devices aa that aa join aa multiple aa computer networks aa together aa via
either aa wired aa or aa wireless aa connections. aa aa aa Routers aa contain aa a aa processor aa (CPU), aa
several aa kinds aa of aa digital aa memory, aa and aa input-output aa (I/O) aa interfaces. aa They aa
function aa as aa when aa a network aa packet aa leaves aa the aa computer, aa or other aa networking
device, aa in a route aa to aa a aa destination aa outside aa its’ aa own aa LAN, aa some aa additional aa
information aa must aa be aa attached aa to aa the aa packet. aa aa aa This aa information aa would aa be aa in a
the aa form aa of aa a aa default aa gateway. aa aa a This aa default aa gateway aa would aa typically aa be a
router. aa aa aa If aa the aa router aa does aa not aa have a specific aa knowledge aa of aa where aa the
packet aa should aa be aa delivered, aa it aa forwards aa the aa packet aa upstream aa to aa another aa
special-purpose aa computers, aa one aa that aa does aa not aa require a a aa keyboard aa or a display aa
(Michell, aa 2017). aa aa aa
Network aa switches aa are a the aa glue aa that aa binds aa computer aa communications. aa aa aa Your aa
computer aa at aa work aa typically aa connects a to aa a aa network aa switch. aa A aa switch’s aa job aa is
to aa receive aa packets aa from aa a aa computer, a or aa other aa networking aa device, aa and aa send aa
them aa to aa the proper aa place. aa aa The aa switch aa keeps aa a aa list aa of all aa the aa devices aa
connected aa to aa it aa (Aubrett’s aa non-technical aa IT aa dictionary). aa aa aa aa aa In aa addition, aa
switches aa share aa this aa information aa with aa other switches aa to aa which they aa are aa linked.
aa aa aa aa This way, aa if aa computer aa A aa needs aa to aa communicate aa with aa computer aa B, aa the aa
switches aa know aa exactly a where aa computer aa A aa and aa computer aa B are aa connected aa as aa
long aa as aa they aa exist aa on aa the aa same aa LAN. aa aa aa If aa computer aa A aa and aa computer aa B aa
do aa not aa exist aa on aa the aa same aa LAN, the aa computer aa must provide aa the aa information aa
of aa a aa router, aa called aa a aa default aa gateway, aa which aa can aa handle aa the aa traffic aa when aa it
sends aa the aa packet.
NETWORK aa ARCHITECTURE aa SNHUENERGY aa INC 12
Firewall: aa aa aa A aa firewall aa is aa the aa gatekeeper aa between aa a aa private aa network aa and aa the a
rest aa of aa the aa world. aa The aa firewall aa determines aa what, aa if aa anything, aa inside aa the aa
private aa network aa should aa be aa accessible aa from aa the aa outside. aa Firewalls aa exist aa in aa
many aa forms. aa Some aa are aa hardware aa appliances aa which aa are aa dedicated aa solely a to aa
performing aa the aa firewall aa functions. aa Some aa firewalls aa are aa software aa components aa
which aa run aa on aa routers aa designed aa to aa sit aa at aa the aa network aa edge. aa Some aa firewalls aa
are aa software aa packages aa which aa run aa on aa a aa server. aa Most aa PC aa operating aa systems aa
such aa as aa Microsoft aa have aa a aa built-in aa firewall aa to aa protect local aa resources aa
(Aubrett’s aa non-technical aa IT, aa dictionary). aa aa The aa firewall’s aa job aa is aa to aa examine aa
network aa packets aa which aa are a sent aa to aa destinations aa within aa the aa private aa network aa to aa
see aa if aa they should aa be aa allowed aa to aa pass.
Current aa network aa Architecture: aa Performance aa Issues
It really aa impact aa of aa losing aa connectivity aa between aa Dallas aa router aa and aa the
Memphis aa router aa affect aa to aa business, aa communication aa between aa the aa users. aa aa aa The aa
network aa lose aa connectivity aa means aa lost aa dollars aa and aa lost aa business aa opportunities. aa
The aa application aa may be aa impact aa should aa be: aa email, aa Video aa Conferencing, aa Payroll,
Accounting aa and aa HR. When aa the aa router aa losing aa connectives aa the aa users a must aa
waiting aa on aa their aa network aa to aa catch aa up aa to aa the aa speed aa at aa which aa they aa are aa
working. aa They aa have a to aa sit aa and aa wait aa for aa file aa transfers, aa applications aa to aa open,
attachments aa to aa download, aa and aa web aa pages to aa open. aa Slow internet aa causes aa
costly aa delays aa in the aa company aa operations aa and aa work aa flow aa management. aa
The aa risk aa of aa just aa having aa a aa single a router aa or aa switch within aa Memphis aa
office aa it aa could aa shut aa down aa the aa Memphis aa site aa if aa the aa router in aa Memphis aa
NETWORK aa ARCHITECTURE aa SNHUENERGY aa INC 13
down, aa or aa switch aa down. aa aa aa The aa route a traffic aa takes aa among aa different aa network aa
providers aa also aa affects aa performance.
Current aa network aa Architecture: aa Security aa issues
A aa high aa security aa communication aa flow aa path aa is not aa useful aa when the aa
network aa path aa cannot a support aa capacity aa and aa reachability aa requirements. aa The aa
deployment aa phase aa in communication aa network aa can aa facilitate aa an aa optimal aa network a
path aa by aa focusing aa on both aa the aa network aa performance aa and aa the network aa security aa
at aa the aa same aa time. a aa aa The aa networking aa and aa security aa industries aa reflect aa this aa
dichotomy aa with aa strong security aa companies aa and aa strong networking aa companies. aa A
firewall aa is aa a aa network aa security aa device aa that aa grants aa or aa rejects aa network aa access aa
to aa traffic aa flows aa between aa an aa untrusted aa zone aa (e.g., aa the aa Internet) aa and aa a aa trusted aa
zone aa (e.g., aa a aa private aa or aa corporate aa network). aa The aa firewall aa acts a as aa the aa
demarcation aa point aa or “traffic aa cop” aa in aa the aa network, aa as aa all aa communication aa
should aa flow aa through aa it aa and aa it is aa where aa traffic aa is aa granted aa or aa rejected aa access
(Singh,N.D). aa aa aa A a firewall aa is aa a network aa security aa device aa that monitors aa
incoming aa and aa outgoing network aa traffic aa and aa decides aa whether aa to aa allow aa or aa block
specific aa traffic aa based a on aa a aa defined aa set a of aa security aa rules. Therefore aa if aa
network aa down aa is aa affect aa to aa firewall. aa aa aa A aa firewall aa is aa every aa bit aa as aa critical aa to aa
security aa as aa an aa anti-virus aa program. aa Firewalls aa stop aa malware aa from aa spreading aa to aa
a aa network aa and aa defend aa against aa hackers aa attempting aa to aa infiltrate a aa targeted aa
system. aa Disabling aa a aa firewall aa can aa therefore aa leave aa a aa business aa vulnerable aa to aa
abuse, aa allowing aa viruses aa to aa infect aa interconnected aa devices, aa and aa giving aa
cybercriminals aa the aa opportunity aa to aa execute a malicious aa code aa remotely. aa End-to-end aa
NETWORK aa ARCHITECTURE aa SNHUENERGY aa INC 14
latency aa (the aa delay aa that aa happens aa to aa a aa packet aa end aa to aa end aa from aa the aa PC aa to aa
the aa server) aa and aa any errors aa causing a re-transmission aa on aa the aa network aa will aa also aa
degrade aa application aa performance aa and aa slow aa the network aa (Millman, aa N.D).
Future aa Network: aa Future aa Communication aa Needs
Today aa network’s aa components aa work aa together aa is aa changing aa and aa fast. aa aa aa
According aa to aa article: aa “A aa new aa model aa for aa the aa future network aa architecture” aa our aa
latest aa infrastructure aa model aa harnesses aa the aa future aa architecture aa evolution aa to aa enable aa
fast aa problem aa solving in aa a aa more a manageable aa and aa effective aa way aa (NA, aa 2017). aa aa
The aa future aa communication aa is aa designed aa for aa the aa needs aa of aa operators aa and aa their aa
customers, aa with aa the aa option aa to aa change aa and aa evolve aa individual a sections aa rather aa
than aa changing aa the aa entire aa system. aa Some aa of aa commend aa for aa new aa future aa
communication aa network aa first aa would aa be aa application aa clouds. a aa aa According aa to aa
article: aa “Uncovering aa the aa application cloud” aa The aa application cloud aa model aa directs
resources aa when aa and where aa they aa are aa needed. aa It aa becomes aa even aa more aa effective
when aa combined aa with the aa connectivity aa infrastructure aa evolution, aa ready aa to roll aa
out aa new aa innovations aa across aa different aa industries. aa aa aa The aa application aa cloud aa resides aa
on aa top aa of aa the aa distributed aa cloud aa infrastructure. aa This aa distributed aa cloud aa
infrastructure aa exposes aa network aa assets aa from aa one aa or aa several aa operators. aa aa aa The aa
hardware aa management aa system aa becomes aa more aa important aa than aa ever, aa as aa there aa are
several aa types aa of a physical aa sites aa playing different aa roles aa and with aa different aa
requirements aa (2017).
The aa next aa step aa considers aa should aa be aa management aa and aa monetization. aa aa aa According aa
to aa article: aa “Architecture aa evolution aa for aa automation a and aa network aa programmability” aa
NETWORK aa ARCHITECTURE aa SNHUENERGY aa INC 15
recommend aa full aa network aa programmability aa for aa a aa network and aa its aa services aa needs
to aa consider aa all the aa building aa blocks: aa how aa each aa piece aa of aa the aa network aa will aa
evolve; aa how aa they aa will aa interface; aa and aa how aa they aa support aa the structure aa and aa
business aa processes aa of aa an aa operator. aa But aa to aa achieve aa such levels aa of a flexibility aa
requires aa the aa inter-domain aa interfaces aa as aa well aa as aa the aa domains aa to aa evolve. aa a aa
Network aa functions aa will aa no longer aa be aa located aa according aa to aa traditional aa vertical aa
groupings aa in aa single network aa nodes, aa but will aa instead aa be distributed aa to aa provide
connectivity aa where aa it aa is aa needed aa (2017). aa aa aa As aa applications aa like aa self-driving aa
vehicles aa and aa remotely operated aa machinery aa evolve, aa become aa more aa innovative, aa and
more aa widespread, aa the aa level aa of aa performance aa that aa 5G aa networks aa need aa to aa
deliver aa will aa inevitably aa rise. aa aa Per aa article: “Flexibility aa in aa 5G aa transport aa
networks: aa the aa key aa to aa meeting aa the demand aa for aa connectivity” aa the aa new aa 5G aa
transport aa network aa are aa high aa – aa providing aa support aa for aa a aa massive aa range aa of
services. aa Industry aa transformation, aa digitalization, aa the aa global aa dependence aa on aa mobile
broadband, aa MTC, aa the aa IoT, aa and aa the aa rise aa of aa innovative industrial aa applications aa
all aa require aa new aa services, aa which aa has aa a considerable aa impact aa on aa the aa transport aa
network. aa For aa example, a a aa new aa radio-access aa model aa that aa supports aa highly aa scalable
video aa distribution aa or aa massive aa MTC aa data uploading aa might aa require aa additional aa
transport aa facilities aa – a such aa as aa a aa scalable aa way aa to aa provide aa multicasting. aa aa aa
Per aa Ryan aa Rouse aa it’s aa important aa that aa teams aa across aa every aa step aa of aa oil aa
and aa gas aa production, aa including aa upstream aa (hydraulic aa fracturing, aa oil aa field
monitoring aa and aa offshore aa rigs), aa midstream aa (pipeline aa monitoring aa and aa pumping aa
stations) aa and aa downstream aa (refineries aa and aa gas aa stations) aa applications, aa use aa
NETWORK aa ARCHITECTURE aa SNHUENERGY aa INC 16
dependable aa network aa components aa that can aa withstand aa harsh aa industrial a conditions aa
for aa the aa highest aa network aa reliability aa and aa availability. aa aa aa Cyber aa security, aa for aa
example, aa is aa quickly becoming aa a aa big aa concern aa for aa industries aa everywhere, aa
especially aa oil aa and aa gas aa (Rouse, aa 2017). aa aa According aa to aa Rouse in aa his aa article:
“Future-Proofing aa Oil aa and aa Gas aa Networks: aa 4 aa Things a to aa Look aa For” aa The aa biggest
step aa teams aa can aa take aa to aa ensure aa they a have aa a aa solid aa communications aa network aa
is aa to aa invest aa in aa high-quality, aa rugged aa Ethernet aa infrastructure aa designed aa specifically aa
for aa use aa in harsh aa environments. aa In aa addition, aa it’s aa essential aa to aa understand aa when
and aa where aa to aa use aa industrial-grade aa components aa versus aa those aa designed aa for
commercial aa settings aa (Rouse, aa 2017). aa The aa plan aa for aa SNHUEnergy, aa Inc aa will aa grow,
but aa we aa need aa to aa ensure aa their aa control aa rooms aa and aa overall aa communications aa
infrastructure aa are aa well-equipped aa to aa support aa expansion, aa harsh aa environments aa and aa
modern aa technologies. aa Success aa requires aa the aa right aa combination aa of aa switches, aa
cabling, aa firewalls aa and aa wireless aa components aa that aa deliver aa on aa the aa team’s aa unique aa
needs, aa protect aa against aa evolving aa threats aa and aa add aa to aa the aa bottom-line.
Future aa Network aa Architecture: aa Network aa Architecture
According aa to aa Rouse a comment aa when aa considering aa how aa to aa design aa the aa
network, aa we aa should aa look aa for aa components aa that aa meet aa the aa following four aa
requirements:
Safety aa and aa reliability: aa Remote monitoring aa solutions aa offering aa high network aa
visibility aa and aa control are aa helpful, aa in addition aa to aa leading aa industrial aa security aa
and aa firewall aa products aa for aa Layer aa 2 aa and Layer aa 3 aa networks. aa aa We aa look aa for aa
components aa that aa can aa withstand aa the aa harshest aa environmental aa conditions aa and aa are aa
NETWORK aa ARCHITECTURE aa SNHUENERGY aa INC 17
compliant aa to aa oil and aa gas aa standards, aa meeting aa all aa possible aa classified aa types aa for
each aa facility aa site aa to aa ensure aa compliance aa with aa UL aa Class I aa Division aa 2 aa and
ATEX aa certifications. aa Solutions aa that aa can aa transmit aa up aa to aa 170km aa without aa using aa
active aa repeaters aa in between aa are aa ideal aa for aa oil aa and aa gas aa applications.
Reduced aa operational aa costs: aa Constant aa maintenance-related aa updates, aa especially aa
in aa difficult aa to reach aa areas aa such aa as aa deep aa water aa shelters aa below aa 200-400m aa of aa
the aa surface, aa are aa extremely aa costly. aa This aa is aa not aa only aa because aa of aa maintenance aa
fees, aa but aa also aa because aa of aa unnecessary aa downtime. aa aa Maintenance-free aa networking aa
solutions aa that aa allow a you aa to aa remotely aa and aa automatically aa monitor aa wells aa and aa
fields aa and aa take aa preventable aa measures aa to help aa avoid aa production aa downtime. aa
Using aa multi-Gigabit aa solutions aa that offer aa extended aa bandwidth aa and aa expandability aa
are aa flexible aa and aa cost-effective aa tools aa that aa can aa support aa this aa initiative.
Minimized aa installation aa efforts: aa Installation aa can aa be aa costly aa in aa most aa
industrial aa settings aa – a but aa even aa more aa costly aa in aa extreme aa oil aa and aa gas aa settings,
which aa are aa often aa underwater. aa aa aa Wide aa local aa area aa network a (WLAN) aa solutions aa that
meet aa the aa ATEX aa Zone aa 2 aa standard a for aa oil aa and aa gas aa applications aa can aa help aa
reduce aa wire aa line aa installation aa costs aa and aa enable aa teams aa to aa get aa closer aa to aa the aa
field aa level, aa contributing aa to aa seamless aa installation. aa Withstand aa harsh environments: aa
The aa biggest aa step a teams aa can aa take aa to aa ensure aa they aa have a aa solid aa
communications aa network aa is to aa invest aa in aa high-quality, aa rugged aa Ethernet aa
infrastructure aa designed aa specifically aa for aa use aa in a harsh aa environments. aa In aa addition, aa
it’s aa essential aa to aa understand aa when aa and aa where aa to aa use aa industrial-grade aa
components aa versus aa those aa designed aa for aa commercial aa settings.
NETWORK aa ARCHITECTURE aa SNHUENERGY aa INC 18
Identify aa solutions aa that a withstand aa the aa corrosive aa and aa extreme aa elements aa oil aa
and aa gas aa applications a face aa every aa day, including aa water aa immersion, a crushing, aa
abrasion, aa UV aa exposure, aa oils and aa solvents, aa sunlight, aa extreme aa temperatures, aa
chemical aa exposure, aa and aa prolonged aa vibration aa and aa noise. This aa is aa foundational aa to a
the aa success aa of aa upstream, aa midstream aa and aa downstream aa processes aa (Rouse, aa 2017). a
We aa will aa focus aa on aa switching aa and aa routing, access, aa signaling aa and aa control, aa
performance aa and aa reliability, aa security, aa physical aa design a and aa transport, aa we aa
incorporate aa all aa important aa elements of aa design aa to aa plan aa for future aa communication
network aa needs.
We aa will aa extend aa these aa services aa across aa the WAN aa by aa using TCP/IP aa
communication aa processes, aa because aa Wide aa Area aa Network aa (WAN) aa to aa connect aa the aa
two aa locations. aa WAN aa connections aa vary aa in bandwidth aa depending aa on aa your needs,
and aa may aa be set aa up aa as aa a aa direct aa connection aa or a aa virtual aa private aa network aa
(VPN) aa via aa the aa Internet. aa Either aa way, aa connecting aa your aa locations aa will aa enable aa
better aa and aa more aa secure aa communication aa within aa your aa business. aa aa For aa Memphis aa
site aa we aa will aa get a extra aa switch aa and aa router aa for aa back aa up, in aa case aa the aa single aa
switch, aa and aa router aa down. aa aa aa I aa would a consider aa security aa when aa making aa any aa
change aa to aa company aa network aa infrastructure, aa especially aa when aa connecting aa two aa
sites. aa I aa would aa consider aa higher aa level aa protection aa network aa security aa when aa expend aa
the aa network. aa I aa will aa consider aa building aa network aa and aa implement aa user a application aa
network aa management aa policies aa to aa overcome aa congestion aa and aa performance aa issues. aa
When aa building aa new network aa the aa system can aa monitor aa and aa respond aa to aa
NETWORK aa ARCHITECTURE aa SNHUENERGY aa INC 19
network aa security aa threats aa in aa real aa time aa to thwart aa increasingly aa sophisticated aa
attacks aa and aa intrusions. aa aa
Planning aa and aa Security: aa Performances aa and aa
Security aa Issues
Today’s aa networks aa are aa congested. aa In aa addition aa to aa carrying aa traditional aa
business aa application aa data aa (e.g., aa email aa and aa file aa transfer), aa internal aa networks aa are aa
now aa also aa carrying aa voice aa traffic aa and aa on aa demand aa video aa conferencing. aa Per aa Dave
Shackleford aa in aa his aa article: aa “Monitoring aa Security aa and aa Performance aa on aa
Converged aa Traffic aa works” aa states aa performance aa and aa security monitoring aa are aa
growing aa closer aa together aa than aa ever aa as aa these aa new aa and traditional aa forms aa of aa
traffic aa clog aa our aa networks. aa Although the aa presence aa of aa a aa performance aa or aa
security aa issue aa does aa not aa necessarily aa indicate aa the aa existence aa of aa the other, a many aa
analysts aa are aa realizing aa the benefits aa of aa behavioral aa baselines aa and aa how aa a aa more aa
holistic aa approach aa can aa alleviate aa the a problems aa of aa both congestion aa and aa security. aa
For aa example, aa large aa data aa transfers aa that aa are aa causing aa congestion aa issues aa could aa
potentially aa indicate aa an aa attacker aa retrieving aa database aa records. aa Therefore aa security aa is
major aa concern aa on aa the aa network aa therefore aa I aa must aa seek a aa unified aa way aa to aa
correlate aa different aa alerts aa from performance aa and aa security aa monitoring aa systems. aa For
security aa keep aa pace aa with aa new aa attacks on aa protocols, aa such aa as a SIP, aa which aa
include aa registration aa hijacking aa and aa eavesdropping? aa Increased aa visibility aa into aa
network aa traffic aa and aa behavioral aa baselines aa is aa critical aa to aa detect aa and aa prevent aa such
attacks aa (Shackeford, aa 2008). aa For aa many aa of today’s aa more aa complex aa attacks, aa as aa
NETWORK aa ARCHITECTURE aa SNHUENERGY aa INC 20
well aa as aa the aa majority aa of aa sophisticated aa malware, aa the aa network aa architecture aa will aa
need aa to aa inspect aa the aa full aa content aa of aa packets aa on aa the aa network aa for application aa
like aa VoIP, aa email aa will aa need to aa decode aa content aa within aa RTP aa packets aa with aa
additional aa tools aa or aa inspect aa specific aa SIP aa packets.
Planning aa and aa Security: aa Network aa Management aa tool
Per aa Fed aa Tech Staff aa in aa article: aa “6 aa Network aa Security aa Tools aa Every aa
Agency aa Needs” aa states a Network aa management aa systems, aa with a their aa monitoring aa
capabilities aa and aa unified aa views aa into aa infrastructure aa dynamics, give aa IT aa
organizations aa a aa powerful aa weapon aa for aa fighting aa cyber aa threats. aa To aa secure aa today’s aa
distributed aa networks, aa IT aa teams aa also aa must aa develop aa defense-in-depth aa strategies aa
that aa combine aa network-enforced aa security aa technologies aa with aa best aa practices aa (Staff, aa
2013). aa aa aa According a to aa these aa authors aa these aa tools aa recommend to aa use aa are:
Instruction aa detection aa and aa prevention aa systems: aa These aa tools aa help aa IT aa staff aa identify
and aa protect aa their wired aa and aa wireless networks aa against aa several aa security aa threat aa
types. aa These aa technologies, aa like several aa other aa categories aa of aa network aa security aa
tools, aa are aa being aa deployed aa with aa greater aa frequency aa as aa networks aa grow aa in size aa
and aa complexity aa (Staff, aa 2013). aa aa Both aa tools aa solutions aa detect aa threat aa activity aa in aa
the aa form aa of aa malware, aa spyware, aa viruses, aa worms aa and aa other aa attack aa types, aa as aa
well aa as aa threats aa posed aa by policy aa violations. aa Instruction aa detection aa tools aa passively
monitor aa and aa detect aa suspicious aa activity; aa prevention aa system aa tools aa perform a active,
in-line aa monitoring aa and aa can aa prevent aa attacks aa by aa known and aa unknown aa sources. a
Both aa tool aa types aa can aa identify and aa classify a attack aa types aa (Staff, aa 2013).
NETWORK aa ARCHITECTURE aa SNHUENERGY aa INC 21
Anti-Malware: aa this aa tools aa help administrators aa identify, aa block aa and aa remove aa
malware. aa They aa enable aa the aa IT aa department aa to aa tailor aa its aa anti-malware aa policies aa to
identify aa known aa and unknown aa malware aa sources, aa for aa example, aa or aa surveil aa
specific aa users aa and aa groups. aa I aa would aa use aa this aa tool aa for aa security aa defenses, aa
operating aa systems, aa browsers, aa applications aa and aa popular aa targets a such aa as aa Adobe aa
Flash, aa Acrobat aa and aa Reader aa — aa that aa they aa can aa exploit aa to aa fully access aa a aa
victim’s aa network.
Network aa Access aa control: aa this tool aa we aa use aa for compliant aa devices aa access aa to aa
network aa assets. aa They a handle aa access aa authentication aa and authorization aa functions aa
and aa can aa even aa control aa the aa data aa that aa specific aa user’s aa access, aa based aa on aa their aa
ability aa to aa recognize aa users, aa their aa devices aa and aa their aa network aa roles. aa aa aa Another
tools aa I aa would aa consider aa and aa use aa is aa Next-Generation aa Firewall, aa this aa tools aa
improve aa on aa standard firewall aa capabilities aa through aa application-awareness aa features aa
(Staff, aa 2013). aa aa aa The a last aa tool aa I aa will aa use aa is authentication aa and authorization, aa
per aa FedTech aa Staff aa the aa traditional aa directory-based aa services, aa such aa as aa Active aa
Directory, aa authenticates aa users aa and aa grant aa access aa based aa on aa authorization aa rules. aa
Newer aa identity-based aa security aa technologies manage aa authentication aa and aa
authorization aa through aa such aa methods aa as aa digital aa certificates aa and aa public aa key a
infrastructure aa solutions aa (Staff, aa 2013).
Planning aa and aa Security: aa Security aa Devices
From aa a aa security aa standpoint, aa the aa pieces aa of aa hardware aa that will aa help aa
provide aa security aa are aa firewalls aa and aa routers. aa Firewall aa is aa the aa first aa security aa device
I aa am aa concern. aa aa aa aa As aa the aa first aa line aa of a network aa defense, aa firewalls aa provide aa
NETWORK aa ARCHITECTURE aa SNHUENERGY aa INC 22
protection aa from aa outside aa attacks, aa but aa they have aa no aa control aa over aa attacks aa from aa
within aa the aa corporate aa network. aa Some aa firewalls aa also a block aa traffic aa and aa services aa
that aa are aa actually aa legitimate. aa aa aa A aa firewall aa is aa designed aa to aa protect aa one aa network aa
from aa another aa network. aa aa In aa the aa lesson aa “Understanding aa the aa Basic aa Security aa
Concepts aa of aa Network aa and aa System Devices” aa by aa Bittlingmeier, aa and aa King aa states aa
network aa security aa is a concentrated aa on aa configuring aa the aa firewall, aa or aa at aa least aa is aa
built aa around aa it, aa a aa compromised aa firewall aa can aa mean aa a aa disaster aa for aa a network. aa
aa Three aa basic aa types aa of aa firewalls aa are aa available, aa in aa addition to aa one—the aa
stateful aa inspection aa firewall—that aa combines aa the aa features aa of aa the aa three aa basic
types. aa Firewall aa architectures aa include aa the aa following:
• Packet-filtering aa firewall
• Circuit-level aa gateway
• Application-level aa gateway
• Stateful aa inspection aa firewall
Firewalls aa act aa like aa filters. aa They aa help aa company aa monitor aa data aa traffic aa between aa
company’s aa network aa and aa the aa Internet. aa aa aa
For aa a aa router, aa I aa should aa make aa sure aa it aa set aa a aa password and aa enable aa
encryption. aa Unprotected aa wireless aa networks are aa a aa bad idea. aa Most aa routers aa have aa
either aa Wireless aa Encryption aa (WEP) aa or aa Wi-Fi aa Protected aa Access a (WPA) aa encryption
options. aa aa aa Some have aa both. aa WPA aa is aa more aa secure aa than aa WEP. aa Enabling aa
encryption aa and aa choosing aa a aa strong aa router aa administrator aa password aa are aa two steps aa
that aa will aa help aa keep aa company’s aa network aa secure.
Planning aa and aa Security: aa Changes aa to aa Existing aa devices
NETWORK aa ARCHITECTURE aa SNHUENERGY aa INC 23
The aa existing aa devices aa the aa SNHUEnergy aa Inc, aa is aa Firewall. aa aa aa I aa just may aa
update aa to aa use Barracuda aa Next aa Generation aa Firewall. aa aa aa According a to aa the aa website
of aa Barracuda aa Firewall, aa this aa modern aa network aa includes aa a aa combination aa of local aa
servers, aa remote aa devices aa and aa cloud-hosted aa applications. aa aa Barracuda aa NextGen aa
Firewalls aa are aa purpose-built aa for a the aa modern, aa distributed network aa in aa which aa
network aa performance aa and aa availability a is aa as aa important aa as aa security. aa Unlike
traditional aa port-based aa firewalls, aa our aa firewalls aa are aa application-aware, aa enabling you aa
to aa regulate aa application aa usage aa and aa intelligently aa prioritize aa network aa traffic. aa aa aa
Barracuda aa NextGen aa Firewalls aa feature aa advanced aa security aa capabilities, aa including aa
integrated aa Intrusion aa Prevention aa (IPS), aa URL aa filtering aa and antivirus aa to aa identify aa
and aa block aa evasion aa attempts aa that aa would aa trick aa traditional aa systems. aa Barracuda’s aa
security aa extends aa beyond aa your network aa to aa Barracuda’s aa Advanced aa Threat aa
Protection aa (ATP) aa cloud aa for aa both aa statistical a and aa sandboxing aa analysis aa of aa zero-day
and aa targeted aa threats aa that aa routinely aa bypass aa signature-based aa IPS aa and aa antivirus aa
engines aa (Barracuda.com). aa aa aa
Planning aa and aa Security: aa Challenges
Barracuda aa next-generation aa firewalls are aa fully aa application aa and aa user aa aware aa
and, aa thus, aa can aa specifically aa allow aa or aa disallow aa access aa to aa certain aa applications aa by
users. aa aa aa How we aa address aa information aa security aa and risk aa management. aa The aa
challenge aa is aa that aa cloud aa security aa processes aa and aa solutions aa are aa still aa being aa
developed. aa aa aa Managing a configuration aa changes aa on aa switches, aa routers, aa firewalls, aa
controllers, aa and aa other aa network devices, aa at aa locations aa across aa the aa network, aa is aa an
obvious aa challenge. aa For aa example, deploying aa a aa new aa service, aa which aa involves aa
NETWORK aa ARCHITECTURE aa SNHUENERGY aa INC 24
wide-scale aa configuration aa changes, aa could aa take aa days aa or a weeks aa to aa reliably aa
complete. aa According aa to article: aa “The aa Best a Free aa Network aa Configuration aa and
Change aa Management aa Tools” aa make me aa consider aa must aa have aa a a reliable aa way aa for
knowing aa when, aa who, what, aa and aa how aa your aa device aa configurations aa have
changed. aa This aa will aa help aa you aa detect aa out-of-process aa and aa rogue changes, aa
reconcile aa changes aa to valid aa change aa requests, aa and aa ensure aa that a actual aa changes aa
were aa properly aa made. aa aa Another aa challenge aa we aa must a think aa by aa Ranbe aa in aa article:
“What aa happen aa if aa Firewall aa disable” aa that aa will aa affect aa all aa data aa packets aa to aa
entering aa and aa exiting a the aa network aa unrestricted. aa This aa includes aa not aa just a expected aa
traffic, aa but aa also aa malicious aa data aa -- aa thereby aa putting the aa network aa at aa risk. aa If aa a aa
software aa firewall aa is a disabled, aa it's aa not aa just aa the aa associated computer aa that's aa in aa
harm's aa way; aa worms aa -- aa a aa type aa of aa malware aa -- aa for aa example, aa can aa spread aa
across aa a aa network aa connection, aa infecting aa all a of aa the aa PCs aa attached aa to aa the LAN. aa
Disabling aa a aa hardware aa firewall aa also aa impacts all aa of aa the aa devices aa that aa connect aa
to aa the aa network (Ranbe, aa N.D). aa
Planning aa and aa Security: aa Overall aa Risk
According aa to aa article: aa “The aa Increasing aa Threat aa to Network aa Infrastructure aa
Devices aa and aa Recommended aa Mitigations” aa the aa author aa gives aa the aa risk aa when aa
update aa network aa device. aa aa aa According aa to the aa author aa perimeter devices, aa such aa as aa
firewalls aa and aa intrusion aa detection aa systems, aa have aa been aa the aa traditional a technologies
used aa to aa secure aa the aa network, aa but a as aa threats aa change, aa so aa must aa security aa
strategies. aa Organizations aa can aa no aa longer aa rely aa on aa perimeter aa devices aa to aa protect aa
the aa network aa from aa cyber aa intrusions; aa organizations aa must aa also aa be aa able aa to aa contain
NETWORK aa ARCHITECTURE aa SNHUENERGY aa INC 25
the aa impact/losses aa within aa the aa internal aa network aa and aa infrastructure aa (N.A, aa 2016). aa
The aa risk aa is when aa the aa network aa administrator aa change aa the network aa device aa or aa
upgrade aa the aa software attackers aa either aa use the aa default aa credentials a to aa log aa into
the aa device aa or a obtain aa weak aa credentials aa from aa other aa insecure aa devices aa or aa
communications. aa The aa implant aa resides aa within aa a aa modified a IOS aa image aa and, aa when
loaded, aa maintains aa its aa persistence aa in a the aa environment, aa even after aa a aa system aa
reboot. aa Any aa further aa modules aa loaded aa by aa the aa attacker aa will aa only aa exist in aa the aa
router’s aa volatile aa memory aa and will aa not aa be aa available aa for aa use aa after aa the aa device aa
reboots. aa However, aa these aa devices aa are aa rarely aa or aa never aa rebooted aa (N.A, aa 2016).
aa aa If aa the aa network aa infrastructure aa is aa compromised, aa malicious aa hackers aa or aa
adversaries aa can aa gain aa full aa control of aa the aa network aa infrastructure aa enabling aa further
compromise aa of aa other aa types aa of aa devices a and aa data aa and aa allowing aa traffic aa to be aa
redirected, aa changed, aa or aa denied. aa Possibilities aa of aa manipulation aa include aa denial-of-
service, aa data aa theft, aa or aa unauthorized aa changes aa to aa the aa data aa (N.A, aa 2016).
I’ve aa learned aa all aa the aa challenge aa and aa the aa risk aa when aa network device aa upgrade aa I aa
will aa consider aa when aa I aa perform aa the aa change. aa aa aa I aa learn aa from aa the aa article opening
the aa firewall aa does aa potentially aa allow aa malicious aa traffic aa to aa enter aa through aa the aa
applicable aa port, aa but aa businesses aa can aa use aa nonstandard aa ports, aa when aa possible, aa to aa
reduce aa the aa risk aa of aa attack aa (N.A, aa 2016). aa Therefore, aa when aa I aa applying aa software aa
updates aa or aa installing aa new programs aa -- aa the aa software aa firewall aa must aa be aa disabled.
When aa possible, aa I should aa disconnect aa a aa computer aa from aa the aa Internet aa before aa
disabling aa the aa firewall aa to aa eliminate aa the risk aa of aa attack. aa
Conclusions
NETWORK aa ARCHITECTURE aa SNHUENERGY aa INC 26
With aa the aa network aa becoming aa more aa important aa than aa ever, aa the a three aa top aa
reasons aa for aa network aa upgrades aa are aa performance, aa reliability aa and aa security aa that aa
SNHUEnergy, aa Inc aa consider. aa When we aa upgrade aa the aa network, the aa clients aa and aa
users aa use aa multimedia a and aa unified aa communications aa over aa IP aa such aa as aa telephones,
IM and aa video, aa it's aa important aa that aa they a have aa a aa reliable aa Internet aa connection aa
and aa a aa high-functioning aa router. aa The aa quality aa of aa service aa on aa network, aa video aa
conferencing, aa voice aa are aa become important aa too. aa aa aa The main aa thing aa is aa security, aa
when aa we aa upgrade aa network aa with aa high aa security, aa with the aa new aa firewall aa
generation aa keeps aa track of aa all aa the aa operations aa performed aa in the aa network aa device
- aa who aa invoked a what aa operation, aa on aa what aa device aa at aa what aa time aa and aa the aa
result aa of aa the aa operation. aa
Reference
Achetson, aa K. aa (2014, aa April aa 2). The aa Seven aa Layers aa of Networking. aa
Retrieved aa August aa 19, aa 2017, aa from aa http://blog.boson.com/bid/102913/The-Seven-Layers-
of-Networking-Part-III
Architecture aa evolution aa for aa automation a and aa network aa programmability. aa (2014,
November aa 28). aa Retrieved aa August aa 6, aa 2017, aa from aa
https://www.ericsson.com/en/publications/ericsson-technology-review/archive/2014/architecture-
evolution-for-automation-and-network-programmability?fromDate=2014-01-
01&categoryFilter=ericsson_review_1270673222_c&toDate=2014-12-31
Aubrett's aa Non-Technical aa IT aa Dictionary aa - aa Switch. aa (n.d.). Retrieved aa July aa 9,
2017, aa from aa https://www.aubrett.com/non-technical/network/switch/non-technical-switch
NETWORK aa ARCHITECTURE aa SNHUENERGY aa INC 27
Balancing aa network aa performance aa and aa network aa security aa in aa a aa smart aa grid aa
application. aa (n.d.). aa Retrieved aa July aa 23, aa 2017, aa from aa
http://ieeexplore.ieee.org/document/7819235/
Bittlingmeier, aa D., aa & aa King, a T. aa (2003, aa April aa 25). aa CompTIA aa Security aa
Exam: aa Devices, aa Media, aa and a Topology aa Security. aa Retrieved aa August aa 19, aa 2017, aa
from aa http://www.pearsonitcertification.com/articles/article.aspx?p=31562&seqNum=2
Description aa of aa support aa for aa network aa database aa files aa in aa SQL aa Server. aa
(2016, aa April aa 12). aa Retrieved aa July aa 23, aa 2017, aa from aa https://support.microsoft.com/en-
us/help/304261/description-of-support-for-network-database-files-in-sql-server
Exploring aa the aa Modern a Computer aa Network: aa Types, aa Functions, aa and aa
Hardware. aa (2013, aa December aa 13). aa Retrieved aa July aa 23, aa 2017, aa from aa
http://www.ciscopress.com/articles/article.asp?p=2158215
Flexibility aa in aa 5G aa transport aa networks: aa the aa key to aa meeting a the aa demand aa
for aa connectivity. aa (n.d.). aa Retrieved aa August aa 6, 2017, aa from aa
https://www.ericsson.com/en/publications/ericsson-technology-review/archive/2015/flexibility-
in-5g-transport-networks-the-key-to-meeting-the-demand-for-connectivity
Henderson, aa R. aa (2013, aa October aa 1). aa Network aa Architecture aa Of aa The aa Future: aa
It’s aa Now. aa Retrieved aa August aa 6, aa 2017, from aa
http://blog.mavtechglobal.com/blog/2013/10/01/network-architecture-of-the-future-its-now
Harrel, aa R. aa (n.d.). aa Understanding aa the aa network aa application aa environment. aa
Retrieved aa August aa 19, aa 2017, aa from aa
http://searchenterprisewan.techtarget.com/tip/Understanding-the-network-application-
environment
NETWORK aa ARCHITECTURE aa SNHUENERGY aa INC 28
Michell, aa B. aa (2017, aa February aa 8). aa What aa Is aa a aa Router aa for aa Computer aa
Networks? aa Retrieved aa July aa 9, 2017, aa from aa https://www.lifewire.com/how-routers-work-
816456
Mitchell, aa B. aa (2017, April aa 07). aa The Layers aa of aa the aa OSI aa Model aa
Illustrated. aa Retrieved aa July aa 9, 2017, aa from a https://www.lifewire.com/layers-of-the-osi-
model-illustrated-818017
Millman, aa R. aa (n.d.). What’s aa slowing aa down aa your aa network and aa how aa to
fix aa it. aa Retrieved a July aa 23, aa 2017, aa from aa
http://www.computerweekly.com/feature/Whats-slowing-down-your-network-and-how-to-fix-it
Ranbe, aa R. aa (n.d.). What aa Happens aa if a a aa Firewall aa Is aa Disabled? aa Retrieved aa
July aa 9, aa 2017, aa from aa http://smallbusiness.chron.com/happens-firewall-disabled-62134.html
Rouse, aa R. aa (2017, aa May aa 17). aa Future-Proofing aa Oil aa and aa Gas aa Networks: aa 4 aa
Things aa to aa Look For. aa Retrieved aa August aa 6, aa 2017, aa from aa
http://www.belden.com/blog/industrialethernet/future-proofing-oil-and-gas-networks-4-things-
to-look-for.cfm
Shackleford, aa D. aa (2008, aa April 30). aa Monitoring aa Security and aa Performance aa
on aa Converged aa Traffic aa works. aa Retrieved aa August aa 19, aa 2017, aa from aa
https://www.sans.org/reading-room/whitepapers/analyst/monitoring-security-performance-
converged-traffic-networks-34720
Staff, aa F. aa T. aa (2013, aa September aa 23). aa 6 Network aa Security aa Tools aa Every aa
Agency aa Needs. aa Retrieved aa August aa 19, aa 2017, aa from aa
https://fedtechmagazine.com/article/2013/09/6-network-security-tools-every-agency-needs
NETWORK aa ARCHITECTURE aa SNHUENERGY aa INC 29
Simoneau, aa P. aa (n.d.). aa The aa OSI aa Model: aa Understanding aa the aa Seven aa Layers a
of aa Computer aa Networks. aa Retrieved aa July aa 9, aa 2017, aa from http://ru6.cti.gr/bouras-
old/WP_Simoneau_OSIModel.pdf
Singh, aa N. aa (n.d.). aa WHAT aa IS aa A aa FIREWALL? aa Firewalls aa and aa Their aa
Evolution. aa Retrieved aa July aa 9, 2017, aa from a
https://www.paloaltonetworks.com/cyberpedia/what-is-a-firewall
Simoneau, aa P. aa (n.d.). aa The aa OSI aa Model: aa Understanding aa the aa Seven aa Layers a
of aa Computer aa Networks. aa Retrieved aa July aa 9, aa 2017, aa from http://ru6.cti.gr/bouras-
old/WP_Simoneau_OSIModel.pdf
Singh, aa N. aa (n.d.).What aa is the aa Firewalls? aa Firewalls aa and aa Their aa Evolution. aa
Retrieved aa July aa 9, a 2017, aa from aa https://www.paloaltonetworks.com/cyberpedia/what-is-a-
firewall
Team, aa A. aa (2017, aa April 18). aa 7 aa Factors that aa can aa impact aa your aa network
performance. aa Retrieved aa July aa 23, 2017, aa from aa http://www.annese.com/blog/7-factors-
that-can-impact-your-network-performance
The aa Best aa Free aa Network aa Configuration aa and aa Change aa Management aa Tools. aa
(2016, aa March aa 16). aa Retrieved aa August aa 20, aa 2017, aa from aa http://www.dnsstuff.com/free-
network-configuration-management-tools
The aa Increasing aa Threat aa to a Network aa Infrastructure aa Devices aa and aa
Recommended aa Mitigations. aa (2016, aa September aa 6). aa Retrieved aa August aa 20, aa 2017, aa
from aa https://www.us-cert.gov/ncas/alerts/TA16-250A
The aa OSI aa Model: aa applications, aa devices, aa and aa protocols related aa to aa the aa OSI
model aa Layers. aa (n.d.). a Retrieved aa July aa 9, aa 2017, from aa
NETWORK aa ARCHITECTURE aa SNHUENERGY aa INC 30
https://www.examcollection.com/certification-training/network-plus-osi-model-application-
devices-and-protocols.html
Vouzis, aa P. aa (2016, aa August a 18). aa Impact aa of aa Packet aa Loss, aa Jitter, aa and aa
Latency aa on aa VoIP. aa Retrieved aa July aa 23, aa 2017, aa from aa
https://netbeez.net/2016/08/18/impact-of-packet-loss-jitter-and-latency-on-voip/
https://www.barracuda.com/products/ngfirewall
NETWORK aa ARCHITECTURE aa SNHUENERGY aa INC 31
Students also viewed