250 likes | 375 Views
Module 2: Next Generation Networking. Module Overview. Networking with Windows Server 2008 New Networking Features DNS with Windows Server 2008. Lesson 1: Networking with Windows Server 2008. Review of Windows Server Network Architecture New Networking Features The New TCP/IP Architecture
E N D
Module Overview • Networking with Windows Server 2008 • New Networking Features • DNS with Windows Server 2008
Lesson 1: Networking with Windows Server 2008 • Review of Windows Server Network Architecture • New Networking Features • The New TCP/IP Architecture • Routing Compartments • IPv6 • Demonstration: Introducing IPv6 Addresses
Review of Windows Server Network Architecture Win32 Wnet/Wininet Application Windows Sockets Application NetBIOS Application RPC Application Applications and User Mode Services Application Interfaces RPC WNet Wininet Windows Sockets NetBIOS Support User Kernel Named Pipes Redirector/Server NetBT AFD TCP Packet Classifier IP ICMP IP Forwarder IP Filtering IGMP ARP Traffic Control Packet Scheduler Packet Queue Packet Queue Packet Queue Packet Queue Driver Interfaces NDIS Wrapper
New Networking Features Next Generation TCP/IP Stack IPv6 Enhancements Policy-Based Quality of Service
The New TCP/IP Architecture Winsock User Mode Kernel Mode AFD TDI Clients WSK Clients TDI WSK TDX Next Generation TCP/IP stack (tcpip.sys) RAW TCP UDP Windows Filtering Platform API IPv6 IPv4 802.3 WLAN Loop-back IPv4 Tunnel IPv6 Tunnel NDIS • Dual-IP layer architecture for native IPv4 and IPv6 support • Better security through expanded IPsec integration • Improved performance via hardware accelerationQ • Network auto-tuning and optimization algorithms • Greater extensibility and reliability through rich APIs
Routing Compartments IP routing table IP routing table Corporate Intranet
IPv6 New header format Large address space Efficient and hierarchical addressing and routing infrastructure Stateless and stateful address configuration Built-in security Better support for prioritized delivery New protocol for neighboring node interaction Extensibility
Demonstration: Introducing IPv6 Addresses • Show the Link-Local Address • Identify the Interface ID
Lesson 2: New Networking Features • Security Features • Performance • Receive Window Auto-Tuning • Policy Based Quality of Service • Scalability • Server and Domain Isolation • Server and Domain Isolation in Action
Security Features Reduce the risk of network security threats An additional layer of defense-in-depth Reduced attack surface area to known computers Increased manageability and more healthy clients • Safeguard sensitive data and intellectual property • Authenticated, end-to-end network communications • Scalable, tiered access to trusted networked resources • Protect the confidentiality and integrity of data • Full featured, enterprise functionality • Support for computer and user authentication with IPsec • Network Access Protection over VPNs and IPsec • Secure routing compartments extends isolation to VPN
Performance Automatically adjusts for maximum efficiency Faster network transfers, especially across WAN links Optimized use of available network bandwidth Reduced packet loss, resulting in fewer retransmits • Optimized performance without loss • Intelligent, automated tuning of TCP receive window size • Better packet loss resiliency • Advanced congestion control for better throughput
Receive Window Auto Tuning Replicating data between Tukwila, Bay Area Default configurations On Windows Server 2003 SP1 100Mbps NICs, 10Mbps throughput On Windows Server 2008 100Mbps NICs, 80Mbps throughput 1000Mbps NICs, 400Mbps throughput
Policy-Based Quality of Service • Source IPv4/IPv6 addresses • Destination IPv4/IPv6 addresses • Protocol • Source or destination ports
Scalability Cost-effectively scale networking up and out Specialized hardware frees CPU(s) for applications Ease consolidation with support for multiple Gbps More efficient use of large server resources • Adopt hardware acceleration and offloading • Receive-side scaling optimizes multi-processor systems • Architected to support latest TCP offload hardware • Offload hardware less expensive than new high-end PCs
Server and Domain Isolation Active Directory Domain Controller Corporate Network Trusted Resource Server X Servers with Sensitive Data HR Workstation Unmanaged Computer X Server Isolation Managed Computer Managed Computer Untrusted Domain Isolation
Server and Domain Isolation in Action Data Application Host Server and Domain Isolation Internal Network Perimeter Physical Security Policies, Procedures & Awareness
Lesson 3: DNS with Windows Server 2008 • DNS Overview • DNS Functionality • New DNS Features in Windows Server 2008 • DNS Client Changes
DNS Overview DNS
DNS Functionality • Support for Active Directory Domain Services • Stub Zones • Integration with other Microsoft networking services • Improved ease of administration • RFC-compliant dynamic update protocol support • Support for incremental zone transfer between servers • Conditional forwarders
New DNS Features in Windows Server 2008 Background Zone Loading Support for IPv6 Addresses DNS GlobalNames Zone RODC Support
DNS Client Changes LLMNR Changes to the way DNS Clients Locate DCs DNS Server Link-Local Multicast Name Resolution LLMNR DNS Server
Review • Networking with Windows Server 2008 • New Networking Features • DNS with Windows Server 2008
Lab 1: Reviewing Networking Defaults and Settings • Exercise 1: Review the Network Center • Exercise 2: Creating Domain Isolation Policies • Exercise 3: Create a Centralized QoS Policy • Exercise 4: Communicate with Link-Local Addresses
Lab 2: DNS Management Settings • Exercise 1: Creating Zones in Windows Server 2008 • Exercise 2: Create Resource Records • Exercise 3: Configure Zone Transfers