260 likes | 353 Views
Network Registration & Bandwidth Management. Gary Holeman Ken Johnson Tim Medin. LeTourneau Internet Bandwidth History. 1998 – 1.5 Megabit/sec shared with 5 institutions, very unreliable 2000 – 1.5 Megabit/sec dedicated, commercial provider
E N D
Network Registration & Bandwidth Management Gary Holeman Ken Johnson Tim Medin
LeTourneau Internet Bandwidth History • 1998 – 1.5 Megabit/sec shared with 5 institutions, very unreliable • 2000 – 1.5 Megabit/sec dedicated, commercial provider • 2002 – 3.0 Megabit/sec dedicated, commercial provider • August 2004 – 6.0 Megabit/sec dedicated, two commercial providers, Autonomous System Number (ASN) belongs to LeTourneau, Border Gateway Protocol (BGP) Routing to balance load between providers and provide fault tolerance • March 2005 – 9.0 Megabit/sec dedicated, two commercial providers • June 2005 – 21 Megabit/sec on a full SONET fiber ring both to the campus and on the campus, providing protection from fiber cuts, both on the campus and within Longview. 3 Megabit/sec with secondary provider for fault tolerance. • July 2006 – Expanding to 45 Megabit/sec on the SONET ring, with two different sources
LETU Internet Bandwidth 50 45 40 35 30 Mbit/sec 25 20 15 10 5 0 1998 1999 2000 2001 2002 2003 2004 2005 2006 Year
Assumption • It will not be possible to control the growth in bandwidth use without individual responsibility and accountability.
Background • Background • Problems • Virus Containment • Outbreak in Fall 2004 • Difficult to Quarantine • No Direct Policy Notification
Requirements • Quarantine • Trust Registered Computers • Track Usage • Force DNS Naming • Security Levels
Registration Solutions • NetReg • Tested & Stable • Moderate Support • Security Only at Boot • No VLAN Support Decision: Not Secure Enough
Registration Solutions • Commercial Software • Dedicated Support • Stable • Very Expensive Decision: Too Expensive
Bandwidth Management Solutions • Commercial Software • Stable • Ramping • Expensive • Support Decision: Implementation Failed
Registration Solutions • Custom Solution • Monetarily “Cheap” • Customizable • Development Time Citadel is Born
Citadel Registration Process Validate Username, MAC, and Hostname Redirect to Registration Page Agree to Policies & Submit Connect to Network Move VLAN Wait for New IP
Citadel Query Switch Query Switch Lookup MAC Lookup MAC SNMP Link Up Trap SNMP Link Up Trap Link Up Link Up Move VLAN Move VLAN Link Life Cycle Link Down Link Down Move VLAN SNMP Link Down Trap SNMP Link Down Trap
Citadel Bandwidth Logging Query PacketShaper Move VLAN (Over Limit) Translate IP to MAC Wait next interval Lookup User Log Data
Components Citadel Keep Emissary Herald Watchtower Garrison SNMP Trap Handling Move VLANs Management (Web) Bandwidth Management Messaging
Security Levels & VLANs Untrusted Student Faculty/Staff Voice Admin Special
Results • No Virus Outbreaks • Faster & Better Tracking • Easier Network Troubleshooting • Better Communication
Implementation Steps • Fall 2005 – Announced future bandwidth allocation to student • January 2006 – FAQ with limits and costs provided to students • January 2006 – bandwidth detail pages available to students • Student newspaper articles, student IT committee meetings • May 2006 – Limits and costs in place