Search

Showing posts with label internet. Show all posts
Showing posts with label internet. Show all posts

Menuai $ lewat FLIXYA

Posted by Sinichi on Wednesday, May 27, 2009 , under | komentar (0)



Buat rekan neters yang hobi sama fotografi, dan videografi ada tempat buat memamerkan hasil karya kamu. Klik Saja Flixya disini, atau langsung dari websitenya www.flixya.com buat mengunduh gambar atau video yang sudah dibuat .
langsung saja sign up gratis malah anda bisa mendapatkan dolar lewat iklan adsense dari mbah google caranya setelah mendaftar jadi member flixya juga mendaftar di gogle adsense yang ada di member area keanggotaan flixya anda. Nah sekarang tinggal mengunduh-unduh sepuasnya koleksi gambar atau video andalan tapi ingat jangan yang berbau-bau parno ntar keanggotaan langsung dicabut. Penghasilan ful dari adsense dan kita juga bisa menambah banyak teman di flixya.
Mendingan sekarang coba deh meluncur kesana, semakin banyak teman semakin baik dan semakin besar anda bisa mendapatkan $. Alamat keanggotaan atau link anda bisa ditaro di blog kesayangan anda saya juga baru jadi kita jalan sama-sama insya Allah saya akan membuat video tutorial video editing gratis buat rekan-rekan neters tercinta.



Network Security and Backup Systems

Posted by Sinichi on Thursday, March 6, 2008 , under | komentar (0)



Security

Prevention is the key when it comes to network security. Identifying and stopping intrusion—in all its forms—is what security is all about. But identifying a potential intrusion is not always obvious, or likely. The usual security suspects—Soviet spies, CIA agents, and industrial espionage—make great headlines, but they don't pose real risks to the average company. However, just because you're not building the next secret weapon doesn't mean that you're not at risk from security breaches. Far more often, security risks come from acts committed out of human error, greed, malcontent, or machine error.

Physical theft, electronic tampering, and unauthorized access are just three of the more obvious threats to network equipment and data. Physical theft includes people stealing computers, taking floppies with data, and tapping into the cable to siphon off information. Electronic tampering covers computer viruses and other malicious reprogramming. Unauthorized access, the most common threat to security, usually occurs when people see information they shouldn't.

There are literally hundreds of approaches that can be taken to deal with these threats. Just as there are many forms of home security—from a lock on the door to a 24-hour guard—there are many forms of network security. And as the type of home security you use depends on your neighborhood, valuables, insurance, and the amount of money you have, the type and amount of prevention your network needs depends upon the importance of the company's data, the expense of computer equipment, the likelihood of intrusion, and the amount of money you can afford to spend.

Networking Is A Risky Business

Networks seriously increase access to your information, and with access comes the responsibility of restriction and control. In addition to the usual sources of security breaches—people taping passwords to their monitors and using scanners to electronically eavesdrop—networks invite a whole host of other vulnerabilities. It's easy enough to drop another workstation or server on the network or add another application. Add the ability to dial into the network system, and you pose an even greater risk.

There is no simple formula for calculating your security needs. The amount of security depends upon the threat you perceive. In some cases, the need for security is clear: banks, airlines, credit card companies, the Department of Defense, and insurance companies. In other cases, the risks may be less obvious. Allowing any worker to examine the payroll file makes for disgruntled employees. Your personal calendar indicates when you are out of town. The following are some of the more common risks to network security.

  • Your network can be a danger to itself. Being made of mechanical components, a network can do itself damage when disk heads crash, servers fail, and power supplies blow. Tape and disk platters get old and go bad. Bugs, such as in an out-of-control operating system process or one with a faulty memory mapping, destroy data. Monitor mechanical equipment for wear. For critical components, keep spares onsite or, if warranted, online.

  • Your network is physically vulnerable. Thieves and other intruders can physically break into your building, wiring closet, or server room and steal or vandalize equipment and data. When a file is erased, very often it physically remains on disk or tape—only the entry to the directory structure is removed. Sensitive documents may be printed out and left lying around the office, waiting for prying eyes or thieving hands.

Your first line of defense is the simplest: Use locks, guards, and alarms to protect against these physical vulnerabilities. Lock servers in a room and lock wiring closets, permitting access to only those with a key. Sensitive data must be completely wiped off the media when deleted. Shred all sensitive printouts. Bolt expensive equipment to the floor or to a desk. A slew of products exist to prevent intruders from physically taking equipment. Most involve locking equipment with metal bars, in steel cabinets, or with large chains. Others sound loud alarms to deter the thief. These products can help to keep your equipment from being physically stolen (it also makes them difficult to move from one station to another). If your security needs are extreme, you might employ biometric devices. Biometric devices use a physical aspect of people, such as their fingerprints, to verify their identity.

The next step is to secure the cable. Copper cable gives off electromagnetic radiation, which can be picked up with listening devices, with or without tapping into the cable. One solution is to switch to fiber-optic cable, which does not emit electromagnetic signals and is more difficult to tap without detection.

Diskless PCs are a popular security measure. A diskless PC lacks floppy and fixed drives. Users must boot the computers off the file server. With no drives, no way to remove data physically exists. However, be aware that diskless PCs with serial and parallel ports and expansion slots are insecure. A user can insert a removable disk into an expansion slot and remove data. Or the user can attach a printer.

Another step is to physically limit access to data sources. Use the keyboard lock on PCs and file servers. Lock file servers in closets or computer rooms, thus preventing direct access and forcing intruders to circumvent network security. Rooms with doors and locks are good places for printers and other output devices since printed data may be as sensitive as electronic data.

  • Viruses are potentially one of the most dangerous and costly types of intrusion. Although they are relatively rare to a well-kept network, the penalties inflicted by a virus can be severe. Your network is vulnerable at any point it contacts the outside world, from floppy drives to bridges to modem servers. At these external contacts, your network's messages can be intercepted or misrouted. Workers take notebooks on the road and may come into contact with a virus-infected computer. Users may take work home, where their home computers are infected. Demonstration programs, bulletin boards, and even shrink-wrapped software may have viruses.

    Protecting your network against a computer virus is much the same as protecting it from unauthorized access. If intruders can't access the network, they can't unleash a virus. However, many viruses are introduced by unwitting authorized users. Any new software should be suspected of having viruses. Although programs from bulletin boards may sometimes be infected, several software companies have shipped shrink-wrapped software that was infected with a virus. While specialized programs can look out for viruses and limit the havoc they wreak, no program can prevent a virus. It can only deal with the symptoms.

  • Intentional threats are also potentially damaging. Employees and outsiders pose intentional threats. Outsiders—terrorists, criminals, industrial spies, and crackers—pose the more newsworthy threats, but insiders have the decided advantage of being familiar with the network. Disgruntled employees may try to steal information, but they may also seek revenge by discrediting an employee or sabotaging a project. Employees may sell proprietary information or illegally transfer funds. Employees and outsiders may team up to penetrate the system's security and gain access to sensitive information.

  • Workstation file systems present a threat to the network. DOS is easy to circumvent. Intruders can use the many available programs to get at a hard disk and remove data, even if security programs are at work. For this reason, high security installations may want to use a different operating system, one with a different file system. Unix has sophisticated file security, and additional programs are available for even more protection.

  • Your network radiates electromagnetic signals. With an inexpensive scanner, experienced electronic eavesdroppers can listen in on your network traffic and decode it. Shielded cable, such as coax and shielded twisted pair, radiates less energy than unshielded cable, such as telephone wire. Fiber-optic cable radiates no electromagnetic energy at all—since it uses light instead of electrical signals to transmit—and it's relatively easy to detect taps into a fiber cable, since these decrease the light level of the cable. If your installation demands maximum security, Tempest-certified equipment shields electromagnetic emissions.

  • By far the most common network intrusion is unauthorized access to data, which can take many forms. The first line of defense against unauthorized access should be the workstation interface. Login passwords are a must. Nearly all network operating systems will not give workstation users access to network resources without the correct password. To make passwords more effective, the administrator should assign them and change them at random intervals. Don't let users post their passwords on their monitors or desk blotters. Use mnemonic passwords to help users remember.

Software is available to blank a user's screen or lock the keyboard after a certain definable period of inactivity. Other software will automatically log a user out of the network. In either case, a password is required to renew activity. This prevents the casual snooper, but not a determined one.

A more secure method to stop unauthorized access is an add-in card for each workstation. This card forces the workstation to boot up from a particular drive every time. It can also enforce some kind of user validation, like a password. If the card is removed, the workstation is automatically disabled.

  • Your network administrators present yet another risk. If you give them free rein over the applications and data, you're exposing your network to unnecessary risks. Your network administrators manage the network, not the data on it. Administrators should not have access to payroll information, for example. Similarly, don't fall victim to the fallacy that the department heads should have complete access to the network and its information just because they are in charge.

  • Finally, your network is subject to the whims of nature. Earthquakes, fires, floods, lightning, and power outages can wreak havoc on your servers and other network devices. While the effects of lightning and power outages can be minimized by using uninterruptible power supplies, you'll need to store backups of important data (and perhaps even equipment) offsite to deal with large-scale disasters.

Three Forms Of Data Security

Information security entails making sure the right people have access to the right information, that the information is correct, and that the system is available. These aspects are referred to as confidentiality, integrity, and availability.

Information stored on a network often needs to be confidential, and a secure network does not allow anyone access to confidential information unless they are authorized. The network should require users to prove their identities by providing something they know, such as a password, or by providing something they possess, such as a card key. Most network operating systems and many applications packages use passwords.

In government circles, this aspect of security hinges on secrecy; access to information is granted according to security clearance. In commercial circles, this aspect of security comes more from confidentiality, where only users who need to know the private information have access.

Guarding access to information is one aspect of security; the security system must also guarantee the information itself is accurate, referred to as data integrity. In providing data integrity, for example, a network ensures that a $14,000 bank account balance isn't really supposed to be $14 million. The system must verify the origin of data and when it was sent and received. Network operating systems grant users access to files and directories on a read, write, create, open, and delete basis. Word processors lock files so more than one user cannot modify the same file at the same time. Databases use record locking to provide a finer granularity of access control.

The third aspect of security is network availability. Although not commonly thought of as part of security, a secure network must also ensure that users can access its information. The network must continue to work, and when a failure occurs, the network devices must recover quickly.

Solving Security Problems

Whatever type of security you implement, diligent watchfulness is important to its success. To help, network operating systems include audit trails that track all network activity, including which workstation has tried to log in to a file server three times unsuccessfully or which files have been changed when they should not have been altered.

Some audit trails can sound alarms when certain events take place. For example, the system manager may want to know when certain files are open, or when unusual traffic takes place. Audit trails will also keep a running log of all that takes place, so the network manager may be able to detect a pattern of intrusion.

Protecting against internal threats requires you to control access to files and applications on a need-to-know basis. Only grant access if users present valid reasons to access the application or data. Use the network operating system's security features to restrict access. Keep audit trails of who accesses what files and when. Enforce the use of passwords.

Such access privileges may be assigned by file, by user or a combination of both. For example, users with a certain security level may read and write to certain files. Those with lower security levels might be restricted to reading these files.

The network manager should create a profile of access privileges for each user. This profile, which is executed when the user logs on, restricts the user to authorized data and devices. Profiles may also be set up for data and devices, limiting their access to only authorized users. Profiles make managing security easier since they provide a consistent method of assigning and maintaining network privileges.

Once a user has workstation and network access, other security barriers can be put in place. Most network operating systems have many levels of access control that limit what resources are available, which data can be accessed, and what operations can be performed. These include restricting who can read and write to certain files, directories, applications, servers, and printers.

To reduce the risk, limit connections to the outside world. When you must make connections, use call-back modems, encryption, and virus-detection software. With call-back modems, users must dial into the system, verify their identity, then the modem calls the user back at a predetermined telephone number to establish the connection. Encryption scrambles data into an unreadable format so even if the packets are intercepted, the message remains nonsensical. Upon receipt of the message, only the people who know the private code, or key, can unscramble the data. Virus-detection software will identify many viruses and disable them if possible.

Biometric devices are a rather drastic security measure. Biometric devices use a person's physical characteristics to verify an identity. The verifying physical characteristic varies. Some use fingerprints, others use voice recognition, others scan a person's retina. Biometric devices are quite costly and are for highly secure environments.

Encryption

Passwords, locks, access privileges, and even biometric devices do not always deter the determined intruder. A common tool like a protocol analyzer can be hooked up to the network and the intruder can watch all data, including passwords, pass by. Data encryption is the answer.

With encryption, data is scrambled before transmission, making it unreadable as it passes over the wire, even if it is intercepted. To scramble or encrypt this data, its bits must be transformed according to an algorithm. The data is transmitted, and at the receiving end, a system of keys is used to decode the bits into intelligible information. Keys are necessary for encoding and decoding.

Encryption usually requires extra hardware because of the processing power required. Hardware-based encryption schemes are more difficult to crack than software-based methods.

A common data encryption standard specified by the U.S. government is Data Encryption Standard (DES).

DES defines how the data should be encrypted and the specifications for an electronic key. It uses one 64-bit key for encryption and decryption. This can cause problems because the key must be in the hands of the sender and receiver. The only way to get it from place to place is to transmit it. Transmitting the key introduces a security threat. The Public Key System, with matched public and private keys, is a solution.

Encryption may be done before data is stored or transmitted. Some networks only encrypt data when it is sent, which makes wire tapping more difficult but does not keep intruders from taking data from a disk. Other networks also encrypt data on the hard disk. Data is encrypted as it is written and decrypted as it is read from the disk. Having encryption working in both places keeps network data much more secure. Encrypting passwords, as NetWare 386 does, is sometimes sufficient to deter the casual data thief.

To further enhance encryption's effectiveness, keys should be changed at random intervals. This prevents intruders from discovering either the key or the time the key is changed. Alternative keys should be available, too, in case the original set is compromised.

The best network encryption schemes hide much of the encryption hassle from end users by taking care of key management and encryption automatically.

Develop A Security Plan

Make a planned attack to secure your network. Once your network has been hit by a virus or a data thief, it's too late to start thinking—you should already be acting. Start the planning process by naming a security administrator, who may or may not be the same person as the network administrator. The security administrator works with the network administrators and department heads to develop a security plan.

You must evaluate the dangers to your network. You need to examine its vulnerabilities, the points at which it is susceptible to attack. Then you must identify the threats, or possible dangers to the system, such as a person, an object, or a natural disaster. Vulnerabilities take several forms, including physical, natural, mechanical, communications, and human.

Unintentional, intentional, and natural threats exist in your network, but the majority are unintentional. Users and system administrators commit errors—they delete the wrong file, they disable access to a directory, they corrupt a data file, they never change their passwords, or they write them on their desk blotters. To counter unintentional errors, train your users and administrators about the network and its applications. Keep regular backups of the applications and data, for after a virus infection or data loss, restoring the damaged or lost files may be your only choice.

Reinforce the need to not write their passwords next to their computer or give them to anyone else. They should use passwords that are fairly difficult to guess. For example, users' passwords should not be their first names or spouses' names. Passwords that include numbers are much more difficult to guess. Users shouldn't type their passwords while someone is watching. Users and administrators should change their passwords frequently. Administrators shouldn't use supervisor logons as their "usual" logons.

Don't over-secure the network. Security procedures generally limit freedom to access the network, so implement them carefully. If you restrict access to certain directories, users may not be able to cut and paste freely from one document to another. Users will balk at elaborate security procedures that interfere with their jobs. They will find ways to circumvent the network security procedures, such as storing data on their local hard drives, not on the server, where it would be protected and backed up. Carefully balance the need for security with the security procedure.

For any security plan to work, the employees must take it seriously. The most effective action you can take is to educate your users and administrators on why your security plan is important. When people understand why controls are necessary, they are more likely to cooperate. Make it clear to prospective and current employees that everyone is expected to cooperate. Establish clear consequences for failure to cooperate. Be specific about policies and procedures. Write them down and give everyone a copy. Make sure each individual knows what to do. Don't overdo it. Insofar as possible, make it easy to cooperate. Enlisting the support of employees is probably the single most cost-effective security precaution a company can take.

Finally, natural threats, such as power failures, earthquakes, and other such disasters are a rare but real part of life. Develop a disaster recovery plan to deal with natural disasters and follow it. Archive important data and emergency backup hardware offsite in a secure facility. Keep enough in the archive for you to get your business up and running (and relatively current) should your primary facility get flattened—it could happen!




Network and Systems Management

Posted by Sinichi on , under | komentar (0)



Network Management

Although the physical location of the personal computers on a local area network seldom changes, networks are still dynamic entities. That is, the logical makeup of any network fluctuates from moment to moment.

For example, the number of data and application files in use or stored away, the amount of available disk storage space, the number of users logged in to the network, and the volume of traffic passing through the network cabling all change continually. Moreover, a network offers users a distributed-processing environment, with some processing performed by a centrally located server, some done at users' workstations, adding even more activity to the network.

Keeping this conglomeration of network hardware, software, cables, and the people using them working efficiently comes under the ambiguous term of network management. It's ambiguous in that managing a network can range from the simple to the complex, from a moment's quick fix of plugging in a misplaced network cable to a day-long search for an obscure disk problem.

Network management can be as simple as creating a boot diskette for a new user and making sure that user has proper access to network resources. (Although in truth these jobs may not be all that simple in some widely distributed networks.)

Or managing a network can include daily disk-maintenance duties—backing up network files or defragmenting disk directories. Or it may mean troubleshooting the network, trying to discover why some users are experiencing slow network response. Or it may include reconfiguring a remote internetwork device to improve overall system performance.

In short, network management incorporates an almost unlimited list of duties—basically, doing whatever it takes to keep the network running smoothing and efficiently, with minimal or no downtime.

This job has grown even more difficult as networks have become larger and more complex. The evolution from small workgroups of often identical PCs to large internetworks made up of dissimilar machines—IBM PS/2s, Macintoshes, PC clones, printers, communications gateways, and bridges and routers—has brought more power to the desktop while adding immense complexity to the network manager's job.

Fortunately, vendors are developing more and better tools—some software-based, others complete systems that provide onscreen maps of network resources—to help in the endless task of managing a network.

From Simple To Complex

Network management tools, whether they are as application-specific as a performance monitor or as comprehensive as IBM's mainframe-based NetView, help bring some order to the potentially chaotic network management environment. They give network managers information and capabilities they can use in the battle to keep their networks running trouble-free.

Whether they are intended to merely find cable breaks or to pinpoint the cause of a network slowdown, network management tools are vital to the network manager's day-to-day life. They can help ensure uptime and network reliability, maintain predetermined performance levels, manage network resources optimally, plan for expansion, maintain company security, track network use, and provide a basis for charging customers for network time.

For example, knowing how many network users regularly access a laser printer—and how long they have to wait for their printed material to appear— can help a company decide when it's time to add a second printer. Knowing which workstations generate the heaviest traffic lets a network administrator predict possible bottlenecks—bottlenecks that can be avoided by adding internetwork devices such as bridges or routers.

Five Functional Areas

At a basic level, network management requirements generally fall into five functional areas: configuration management, fault management, security management, performance management, and accounting management.

Configuration management applications deal with installing, initializing, booting, modifying, and tracking the configuration parameters or options of network hardware and software.

Fault management tools provide an audit trail, or historical overview, of a network's error and alarm characteristics. These types of tools show a network manager the number, types, times, and locations of network errors. These errors might be dropped packets and retransmissions (on an Ethernet) or lost tokens (on a Token Ring).

Security management tools allow the network manager to restrict access to various resources, from the applications and files to the entire network itself; these generally offer password-protection schemes that give users different levels of access to different resources. For instance, a user in marketing could be allowed to view, or read a data file in accounting but not be permitted to change or write to it.

Security management is also important in managing the network itself—for instance, only certain individuals (such as network administrators) should be permitted to change configuration settings on a server or other key network devices.

Performance management tools produce real-time and historical statistical information about the network's operation: how many packets are being transmitted at any given moment, the number of users logged into a specific server, and utilization of internetwork lines. As already noted, this type of information can help network administrators pinpoint areas or network segments that pose potential problems.

Performance management tools generally allow polling individual network devices for component-specific information. A communications server might provide information on throughput for each serial port, while a file server might report the number of users logged in, what applications they are using, and the number of active files. This information can then be studied to determine which gateways, servers, or routers are being used heavily and may need added capabilities in the future.

Accounting management applications help their users allocate the costs of various network resources—a public data network gateway, access to a mainframe session, or printer time—to those using them. These applications provide information about session start up/stop, user logins and resource use, and audit trail data. Companies can then use this information to bill departments internally or customers for computer and/or network time.

Built-In NOS Management

Most network operating systems (NOSs) provide some level of network management capabilities; in particular, almost all the leading NOSs offer password-protection schemes that limit users' access to network resources. Novell, for instance, implements its NetWare management scheme through user profiles, which define not only the user's access rights, but the users' classifications (supervisor, workgroup manager, console operator, or user), which also determine the resources they can access.

In this scheme, a supervisor has access rights that allow reconfiguring and upgrading the entire system. The workgroup manager, available with NetWare 3.X, controls only the resources of a single user or user group. This concept allows a supervisor to distribute some of the responsibility for maintaining the network to others around a large network.

A user with console operator access rights can run NetWare's FCONSOLE utility, which allows monitoring and controlling a variety of network performance criteria, such as print queues. The user can access only those resources allowed by the supervisor (or workgroup manager with NetWare 3.X). Although users can access the NetWare management utilities, their rights to actually perform management functions are severely limited.

Although other NOSs' access schemes may differ in specific features from NetWare's, they all offer similar resource-restriction capabilities that give the network managers control over their networks.

Programmable Managers

Many other network product vendors also offer specific network management products that address more-detailed needs. These include Sun Microsystems's SunNet Manager [now known as Solstice], Hewlett-Packard's OpenView, IBM's NetView for AIX, and Cabletron's Spectrum.

Both Sun and Hewlett-Packard designed their network management applications to work with other vendors' "agent" applications that add specific functionality to a system. For example, various agents can perform monitoring and controlling capabilities on gateways and routers.

Other products, however, deliver only partial solutions. These devices include protocol analyzers, which provide configuration and performance data but no accounting management capabilities.

Management Standards

As networks have grown larger and become increasingly heterogeneous in nature, so has the need for industry-standard network management protocols (and products) that operate across a wide range of vendor offerings. The first of these protocols, the Simple Network Management Protocol (SNMP), was developed by the Internet Activities Board in 1988. SNMP generally relies on the User Datagram Protocol/Internet Protocol (UDP/IP) as the underlying mechanism for transferring data between different types of systems and networks, though IPX and AppleTalk have been employed successfully by some products.

Briefly, SNMP is a protocol that defines the communication between a network management station and a device or process to be managed. SNMP's three-layer architecture (network management stations, agents, and a common set of protocols that binds them together) operates with a management information base (MIB) and a structure of management information (SMI). The MIB and SMI are network management concepts that allow defining each network element so these elements can be monitored and controlled by the management stations.

Though widely accepted, SNMP has several limitations. For one, it is considered by some to be too simplistic for managing the large, global-style networks evolving today, and its manager-to-agent architecture leaves it incapable of managing true enterprise-wide networks, which can require manager-to-manager systems as well. Because products based on it are widely available—hundreds of vendors make compatible products—SNMP remains the network management protocol of choice for most PC-based network managers.

Host-Based Systems

Two mainframe-based network management systems with wide industry support are IBM's NetView and AT&T's Unified Network Management Architecture (UNMA.)

Although proprietary in nature, these products enjoy broad end-user support because of their associated vendors' large installed bases of computers. With the protocols already available, many users incorporate their primary vendor's network management products into their networks as a matter of course. IBM's NetView permits nonIBM networks to access the NetView host via its NetView/PC and LAN Network Manager gateway products. IBM also supports SNMP in many of its products.


Internetworking

Posted by Sinichi on , under | komentar (0)



Internetworking

As local area networks become more and more prevalent and increasingly vital to the daily operation of an organization, the need to connect multiple LANs together has become as crucial as it once was to link individual PCs into a workgroup. More and more, it's likely that a worker linked into a firm's marketing department workgroup requires access to resources located on another LAN within the company—a database in the engineering network, for example.

This need has spawned one of the fastest growing areas of the LAN industry: The internetworking marketplace, composed principally of repeaters, bridges, routers, gateways, and, most recently, hybrid products called brouters and routing bridges. Internetworking products bring interconnectivity to workers linked into large, spread-out groups of LANs. They also play a major role in network management by allowing network administrators to segment, or divide, a single network into an assembly of multiple subnetworks. This subdivision can improve network performance—limiting the number of nodes on a network can reduce traffic over the workgroup wiring. It also facilitates security—internetworking allows restricting individuals to specified resources—and increases system reliability—when one workgroup goes down, it doesn't affect the entire network.

There are four primary types of internetworking products: repeaters, bridges, routers, and gateways (see Figures 1–4). (Beginning in 1994 or so, multiport bridges began to be marketed as switches, but switches usually provide the same fundamental functions as the devices traditionally known as bridges. In some cases, switches actually perform local routing functions as well.) Each internetwork product permits various levels of communication between individual networks; each also functions at a separate level within the OSI model.


Figure 1: Repeaters operate at the lowest OSI layer. They regenerate electrical signals.

Figure 2: Bridges operate at the MAC sublayer and are capable of modest traffic control and network partitioning.

Figure 3: Routers operate at the network layer and are capable of stringent traffic control and network partitioning.

Figure 4: Gateways provide translations between two dissimilar computer systems, such as a PC_LAN and an SNA network.

Repeating The Obvious

Repeaters offer the simplest form of interconnectivity. They merely regenerate, or repeat data streams (in reality, electrical signals) between cable segments. In their purest form, repeaters physically extend a network; repeaters operate at the Physical layer of the OSI model. Repeaters, for example, allow extending Ethernet network cable segments from 1,000 feet to more than 5,000 feet. In addition, they provide a level of fault tolerance by isolating networks electrically, so a problem on one cable segment does not affect other segments.

Repeaters do not allow a network manager to isolate traffic; they regenerate every data frame or jam signal over all the networks they link. They do nothing to relieve the load on a network's bandwidth.

Bridges, on the other hand, isolate traffic to specific workgroups while still offering the ability to connect multiple LAN cable segments into a large logical network. Bridges operate one layer higher than repeaters in the OSI model; they operate at the MAC sublayer of the Data-link layer.

Filtering Traffic

Most bridges operate only between similar LAN technologies—between two Ethernets or two Token Rings, for example— but some do offer cross-technology capabilities. They regulate traffic by filtering data frames based on the destination address. When a frame's destination address is local, it is not forwarded by the bridge. When the destination address is remote—i.e., to a node on another workgroup—the bridge forwards it. Bridges automatically "learn" the addresses of the devices attached to their subnetwork.

More sophisticated bridges allow filtering traffic on a variety of factors, including frame size, source address, and type of protocol. Because filtering reduces network traffic, it can substantially increase overall network performance. Bridges operate independently of the upper-layer protocols which allows them to handle any transport protocol, such as the TCP/IP, IBM's SNA, and NetBIOS.

Bridges use custom filters to selectively reject or forward frames that match administrator-specified conditions, such as frame size, specific transport protocol (XNS, TCP/IP), or destination address. Custom filters can work on frames whether they're flowing into or out of a network; a filter can also forward only those frames that match user-defined criteria.

System administrators can use custom filters to help set up and manage administrative domains within a network; for example, a network manager could develop custom filters that isolate electronic mail domains. Custom filters can also restrict protocol-specific frames to certain preset domains. Similarly, filters could forward only specified types of frames.

Source-explicit forwarding (SEF) gives administrator-defined workstations exclusive frame-forwarding privileges on the internetwork. Designated stations can forward frames through a particular port on a routing bridge, while the frames of stations without SEF rights will be rejected. SEF thus permits a system administrator to limit access to normally secure or isolated network segments or resources.

These types of controls let network administrators manage their LANs better, permitting them to create secure domains and increase inter-workgroup efficiency.

Traditional bridges have offered transmission capabilities from only a single workgroup to another workgroup, but the move to centralized LAN management centers has prompted LAN manufacturers to market multiport bridges, now commonly called switches. Multiport bridges give network administrators the advantages of modular expansion and/or reconfiguration. By replacing one interface card with another—for example, adding an FDDI link to a modular multiport bridge—the administrator can keep up with an organization's changing network environment without completely rebuilding the network infrastructure.

The Router Route

Routers operate at still another layer up—at the network layer in the OSI reference model. Routers connect logically separate networks operating under the same transport protocol (i.e., TCP/IP or SNA). Routers are thus protocol-dependent and must support the individual protocols being routed. A router allows multiple paths to exist in an enterprise-wide network, and is "intelligent" enough to determine the most efficient path to send a particular data frame through those multiple paths.

In a typical enterprise-wide network divided by routers, the separate networks are assigned unique numbers, and each independent network is managed separately. Routers automatically learn changes in a network's configuration, just as bridges do, within the limitation of the network protocol's ability to pass routing information between routing nodes. Routers are more complex than bridges, however, because the scope and scale of the internetwork are typically much greater than those of bridged environments.

Routers are particularly useful in organizations with multiple large networks connected to a single backbone. Because they have an inherently more difficult task, routers are generally slower than bridges. Newer routers, capable of routing packets at a LAN protocol's maximum bandwidth (with 10Mbit/sec Ethernet, about 15,000 frames per second), are erasing this limitation, however.

The Spanning Tree Algorithm

The spanning-tree algorithm allows physical loops to exist in a bridged Ethernet network. Loops, which are formed when there are multiple data paths between two segments of an Ethernet network, are particularly useful in mission-critical networks because they provide fault-tolerant redundancy and permit internetwork devices to find and use the most efficient routes between the other internetwork devices on that enterprise-wide LAN.

In a large multi-loop Ethernet, the spanning tree algorithm determines the most desirable path between segments and disables all other paths to eliminate redundant loops. (This path selection process is governed by options that can be selected by the system administrator.) Then, when the active path is unusable for any reason, spanning tree automatically reconfigures the network, activating the most desirable alternative path, until the original active loop is brought back online. Spanning tree permits connecting a corporate network to subsidiary networks via high-speed "active" lines; should either active line fail, a backup loop would be brought online automatically, thus ensuring continued communications.

Spanning Tree's ability to automatically sense trouble areas allows organizations to build large, reliable networks that are still easily managed from a central site; managing similar topologies created with routers alone requires a staff of competent network management personnel.

The Gateway

Gateways act as translators between networks using incompatible transport protocols, such as between TCP/IP and SNA or between SNA and X.25. Gateways operate at the application layer of the OSI model.

One of the more common gateways is a communications gateway between a local area network and a mainframe or minicomputer; such a gateway generally places a special-purpose adapter card in a PC along with a standard network interface card. The resultant system serves as a shared gateway to the host for all the other PCs on the LAN. Such a gateway allows you to use a mainframe or mini as a network server, if desired.

The new internetworking products and features available combined with the old permit creating faster, more secure, and more cost-effective enterprise-wide networks—the kind now being demanded by multinational corporations


Network Software

Posted by Sinichi on , under | komentar (0)



Network Applications

In its most generic sense, the term application applies to a task. For example, a widget maker needs to take orders and transmit these orders to a warehouse where the widgets are shipped to customers. The widget factory and warehouse must exchange inventory information. This whole procedure might be called an order entry and inventory control application. In this sense, other applications include list management, accounting, design, marketing, and sales—the tasks of any enterprise.

More specifically, the term application refers to the computer software used to get a job done. Thus, database management packages such as dBase IV, Paradox, and Oracle are called application software, as are other types of software such as WordPerfect, Co/Session, and 1-2-3. In this sense, application software is distinguished from system software, which is the software that makes computers and networks operate. Think of the application software running on top and taking advantage of the system software and hardware.

Finally, application refers to programs written to perform a specific task. For example, many users have written applications in the dBase language. These customized applications are written by and for end users, not by software vendors. This can get tricky, because some value-added resellers and system integrators write such customized programs to sell. The difference is they are not selling generic applications software as Microsoft, Borland and Lotus do. They, like the end-users themselves, are creating customized programs using the software of developers such as Borland and Microsoft.

Network operating system software, such as NetWare, LAN Manager, and VINES, provide some applications. This presents some complications and indicates some changing directions for the PC network industry.

Networks exist for applications. That is, users install networks to get a job done. Users can have computers, cable, interface cards, file servers, and protocols, but without applications software users can't do much but copy files from disk to disk. Network application software is what people use. The network is just the substrate upon which they use it.

Application Types

There are three types of applications—network-ignorant, network-aware, and network-intrinsic.

Network-ignorant applications are written for use on one computer by one person. These programs can run on a network in the sense that they may be stored on a file server and network users may run them at their workstations. Most of the time there are severe limitations on what these applications can do. Moreover, if two people try to use the program at the same time, data can be lost or corrupted.

For example, if two people try to work on the same 1-2-3 spreadsheet, the person making the last change to the spreadsheet will write over all the changes made by the user who first saved his work. The program has no way of keeping the users from destroying each other's work. It lacks concurrency control. On the other hand, 1-2-3 can be used safely by several people at the same time, as long as they are using different spreadsheets (and if they have a license to do so). But the standalone version of 1-2-3 does not provide functions to take advantage of the network.

Network-aware applications are a step above network-ignorant applications. Usually, they are network-ignorant programs modified to run on a network. These programs recognize they will be used by several users at a time. They have concurrency control features such as file and record locking to coordinate usage by multiple users. For example, when a Paradox user begins to modify an address in a mailing list database, other users who are also looking at the same database table are prevented from changing that particular address record. This is called record locking. When the change is complete, the change is displayed on the screen of every other user looking at the table.

Another network-aware feature is file locking. This is a less sophisticated and less used form of concurrency control. Instead of keeping users out of a particular record, they are kept out of the entire file altogether while another user has it open. Word processing programs are the primary users of this type of concurrency control.

Communications software and electronic mail are also network-aware applications. They use the network to extend the abilities of a PC and share network resources.

At the same time, even these network-aware applications use the network as little more than a peripheral sharing device. The file server holds the data and the program but does not do any processing. Users access the program as if it were local, but all the work is being done by their PC, including all concurrency control. This is changing.

Network-aware programs make up the vast majority of programs written for networks. They are a big improvement over network-ignorant applications and have gone a long way to spur the growth of networking. As they become more sophisticated, the distinction between network-aware and network-intrinsic is blurring.

Network-Intrinsic Applications

Network-intrinsic applications actually share the processing power of several computers. Usually, although not always, this is done by dividing the application program into pieces. One piece is the server, which does data processing; the other piece is the client, which talks to the user. A database server is a good example of this application type. Its principles can be generalized for other network-intrinsic applications.

A database server is composed of front and back ends. The front end is responsible for formulating requests and displaying formatted data to the user. At the front end, users make queries, write reports, create new databases—all the tasks they do with any other database management program. The back end is responsible for managing and searching for data, concurrency control, and security. When a user asks for all the employees in the company database that make more than $50,000, this request is transmitted to the database server or back end. The database server then looks for all the employees making over $50,000 and sends these records to the front end.

In the network-aware method, one program, not two, runs in the user's machine. When the request for middle-income employees is made, the server downloads the entire file over the network to the user program. The user's PC then searches through the file to find the employees with the requested salaries. This takes up much more network bandwidth because the whole file is transferred, instead of just a few records. Other traffic includes concurrency control commands to lock various files and records as needed.

With a database server, concurrency control traffic is eliminated because the server takes care of it. Even more important, only the requested records are sent over the network. The result is a more efficient, safer, and better performing program and network. The two programs are working together to create one application—a true network-intrinsic application.

By implication, network-intrinsic applications have the ability to distribute data over the entire network. They can also distribute processes. This makes for distributed databases, compile servers, compute servers, multitasking communications servers, and many other applications in which programs cooperate across the network to get a job done.

Only a few network-intrinsic applications are available now. New network environments created by operating systems like OS/2 and network operating systems like LAN Manager will help their development by providing multitasking, more memory, faster processors, and programming interfaces that make writing network-intrinsic programs easier. It will take time.

Utilities And Applications

A category of applications we have not discussed is network utilities. Usually, utilities are programs written for network administration and management. One example is NetWare's SYSCON. Others include printer and disk management utilities.

Increasingly, utilities are included in network operating systems. For example, NetWare comes with numerous programs to administer and manage the network. But, even more striking than this development, is the way in which application software and system software are coming together.


Application Layer Protocols

Posted by Sinichi on , under | komentar (0)



Getting connected isn't as difficult as you might think.

The growth of the Internet has been an interesting reflection of the growth of networking in general. The first networks to be deployed in most companies were workgroup networks—islands of connectivity. They were of various types, and they weren't connected to each other.

As networking technologies matured, and networking took on greater importance in many organizations, the workgroup networks grew and often became interconnected. The next step was enterprise-wide networking, and it wasn't long before companies began to deploy e-mail across those enterprise networks.

Today, many companies have full internal networks in place, and the growth of the Internet signals a continuance of the networking trend. Companies are now connecting via the Internet to their trading partners and prospective customers, much as the early workgroup networks interconnected to form a larger corporate network where different departments could collaborate on projects.

The Internet is also mirroring another trend: Just as we've seen microcomputers and workstations move from text-oriented, command-driven operating systems to graphical user interfaces, so too have services on the Internet shifted from the terse command-line types to the graphical World Wide Web.

A consequence of this shift toward the Internet is that network managers are often being asked to set up Internet connections and World Wide Web sites. This Tutorial is the first in a series designed to introduce network managers to the Internet and Web technologies.

Internet Services

The World Wide Web steals the lion's share of attention lately, but there is actually a wide variety of services available on the Internet. "Internet Services," gives a brief description of some of the key services available on the Internet.

In the early years, the Internet was mostly used for electronic mail and for exchanging files between computer systems. These applications tended to be textual and command-line oriented, which means that the Internet was, at that time, mostly used by the "initiates." The Internet didn't really open up to the masses until just a few years ago, when the World Wide Web—an application with a graphical interface—was deployed.

The World Wide Web

What is the Web? It has many aspects, which makes it difficult to describe in just a sentence or two. I'll give you a sentence, but then I'll need several paragraphs to elaborate: The World Wide Web is a client-server system for delivering information in hypermedia form.

The medium of the Web is the Hypertext Markup Language (HTML). HTML is essentially a page description language, similar to Adobe Systems' Postscript or Hewlett-Packard's PCL (Printer Control Language). HTML tells the Web browser on the user's PC how to display the text and graphics that represent the content of a particular Web site. A Web browser is an HTML interpreter that requests and receives HTML-coded documents from a Web server and displays the information according to HTML commands embedded in the code.

The server component of this client-server system is a computer running software that operates according to the hypertext transport protocol (http). The Web server responds to users' Web browsers by sending the files the browsers request.

In most cases, a Web server delivers a document one page at a time. (Of course, that page can be much longer than the height of your display screen—you may have to scroll through several screens to see the entire page). These documents are hypertext, much like the Windows Help system. Certain key words are hyperlinks. Usually, the browser will indicate hyperlink text by underlining it and displaying it in a different color than the rest of the text. (Images can also be hyperlinks.) When you click on a hyperlink, it causes the browser to issue a request for the HTML document associated with that link. The Web server will then service that request. In Web lingo, each request for a file (text document or graphic image) is called a hit.

One difference between hyperlinks in HTML and those in other hypertext systems, such as Windows Help, is that HTML hyperlinks can take you to an entirely different server. These hyperlinks, in effect, make the Web one giant document management system, which explains how the World Wide Web got its name. Published on a Web server, other Web sites or Web documents referenced within this article could be made into hyperlinks; a reader could jump to each reference with just a click of the mouse.

Web servers are attractive electronic publishing systems. In the past, the only way to publish something on the Internet—and ensure that everyone could read it—was to present it in plain ASCII text. Richer formats, such as text displayed in a particular font, size, or style (italics, for example) were word processor-specific. Graphics, too, require specific viewer programs, which the reader may or may not have had. These factors hindered the presentation and effectiveness of electronic publishing. Enter the World Wide Web.

The Web has given us a level of platform independence. It's somewhat similar to having a videocassette that can be played on a wide variety of videocassette recorders, regardless of the vendor. Standardization in http and HTML means that any Web browser can read any Web document (at least, in theory). As HTML develops, vendors tend to add extensions that add new features to HTML or make life easier for its coders. Not every Web browser can read every proprietary extension, so certain features might not work with all browsers. It's still true, though, that if you stick with base-level HTML and avoid proprietary extensions, almost any browser will be able to read and display your documents. Of course, you need a Web browser running on your computer, and it's safe to say that there are now browsers for almost every type of computer.

Web servers were developed to reside on the Internet, but there's no reason you can't use one on any other TCP/IP network, large or small. This has given rise to the idea of corporate intranets—networks that are completely contained within the organizations they serve. Figure 1 shows an example of an intranet, as well as a connection to the Internet. Everything behind the firewall (that is, everything within the dashed lines) is the corporate intranet.

Click To expand
Figure 1: A typical corporate Internet connection. Everything behind the firewall is part of the corporate intranet which is the organization's private network. The dashed line encompasses this particular intranet.

The concept of the Web as a platform-independent, client-server system is tantalizing to developers. Not only is platform independence a nice feature to have on the Internet, it's effective for the intranet as well. Companies such as IBM's Lotus Development are bringing out Internet interfaces for their client-server systems (Lotus Notes, in this case).

Typically, whenever you revise (rev) a client-server system, you have to develop both a new client piece and a new server piece. The amount of work needed on the client side is multiplied several times if you're trying to provide clients for several different operating systems. However, if you use a Web browser as the client, there's no work to be done on the client side whatsoever—you can simply let companies such as Netscape Communications (Mountain View, CA) or Spyglass (Naperville, IL) provide the browsers.

WAN links—at least those that most companies can afford—are typically very restrictive in terms of data throughput when compared with LAN links. Most people consider a T1 line (1.544Mbps) a high-speed link, but it crawls in comparison to 10Mbps Ethernet. For this reason, you must carefully plan the graphic design of your Web pages. Keep graphics small, and never put more than a few on each page, or else your readers will be staring at the Windows hourglass icon for minutes at a time.

As bad as this problem can be in the wide area, it disappears for intranets due to the tremendous throughput of local area networks. If you're going to strictly dedicate a Web site as an intranet server, you can afford to go hog wild with graphics. Ironically, Web servers, which were born on the Internet, seem to be realizing their full potential on the intranet.

If there's a fly in this soup, it's HTML, which is essentially a document publishing system. HTML is read-only and as such, it is not interactive, although you can request new pages by clicking on hyperlinks. There are ways around this, as we'll explore later in the series, but Web designers must really bend over backward to compensate for the one-way nature of HTML.


Network and Transport Layer Protocols

Posted by Sinichi on , under | komentar (0)



The TCP/IP Protocol Suite

Just about everyone in the networking industry talks about interoperability; the U.S. Department of Defense (DOD), in the guise of the ARPANET (Advanced Research Projects Agency Network) project, actually did something about it when it created the Transmission Control Protocol/Internet Protocol (TCP/IP) family of networking protocols.

TCP/IP is the DOD's answer to connecting its rapidly proliferating—and widely dissimilar—computers and networks into a loosely associated wide area network (now called the Internet). TCP/IP is the DOD's vehicle for providing distributed computing capabilities across a large area.

TCP/IP might also be called the less talented but still much in demand ugly stepsister to the International Standards Organization's (ISO) Open System Interconnection (OSI) protocols. Though the OSI protocols were designed to dominate the computer environment, TCP/IP remains the central piece in the complex interoperability puzzle.

A Plenitude Of Protocols

As its two-part name implies, TCP/IP encompasses more than one protocol. It includes a range of protocols that provide distinct services and capabilities necessary for communication between and control of otherwise incompatible computers and networks. In addition to the Transmission Control Protocol (TCP) and Internet Protocol (IP), these include the File Transfer Protocol (FTP), the Simple Mail Transfer Protocol (SMTP), the Internet Control Message Protocol (ICMP), and the Simple Network Management Protocol (SNMP).

Other protocols within the TCP/IP family are the Address Resolution Protocol (ARP), the Reverse Address Resolution Protocol (RARP), the Exterior Gateway Protocol (EGP), and the User Datagram Protocol (UDP). IP, TCP, FTP, SMTP, and Telnet were part of the original DOD military standard, TCP/IP protocol suite promulgated in the late 1970s. Although TCP/IP was the brainchild of and for the military, it has become the de facto protocol for general-purpose intersystem communication.

The TCP/IP Framework

The body of standards making up the TCP/IP suite fit within a four-layer (network access, internet, host-to-host, and process layers) communications framework, shown in Figure 1. Before examining these layers individually, however, it's important to first understand several other concepts.


Figure 1: The TCP/IP body fits within a four-layer framework.

The DOD based its model of data communication on three agents, called processes, hosts, and networks, with processes as the fundamental communications entities. Processes are executed on hosts, which are internetworked computers that can generally support multiple processes. Hosts in turn communicate with each other via a network. Successful completion of an operation on the internet requires action by all three agents.

The transfer of data from one process to another requires first getting the data to the host in which the process resides, then to the process within the host. In this model, a communications facility must be concerned only with routing data between hosts, with the hosts concerned with directing data to processes.

The network-access layer handles the exchange of data among a host, the network that host is attached to, and a host within the same network. The sending host provides the network with the network address of the receiving host to ensure that the network routes the data properly. The TCP/IP network-access layer services correspond to those provided by the physical, data-link, and parts of the network layers in the OSI reference model (see Figure 2).

Click To expand
Figure 2: The TCP/IP network-access layer services correspond to those provided by the physical, data-link, and parts of the network layers in the OSI reference model.

The specific physical, or media-access, protocol used to put TCP/IP data on the wire is independent of TCP/IP's top three layers. This means that TCP/IP can operate over virtually any media-access protocol, including Ethernet, Token Ring, or FDDI.

The separation of the physical-layer functions from the higher layers also means that the services provided by the internet, host-to-host, and process layers are not affected by the specifics of the underlying network protocol used. The same high-level software can function properly regardless of the network type a host is connected to.

The internet layer provides services that permit data to traverse hosts residing on multiple networks. The internet routing protocol runs not only on "local" hosts, but also on gateways that connect two networks. A gateway's primary responsibility is to relay data from one network to the other, making sure it gets to the appropriate destination host.

The host-to-host layer ensures the reliability of the data and between two TCP/IP hosts. And the process layer provides protocols needed to support various end-user applications, such as file transfer or electronic mail.

The TCP/IP Protocols

Each TCP/IP protocol provides a specific service or set of services to move data from one computer to network to computer. The services some of these provide—the File Transfer Protocol (FTP), for instance—are self-explanatory. Others aren't so obvious.

In the lexicon of the TCP/IP world, an interconnected set of networks is called an internet; the Internet Protocol (IP) is responsible for accepting segmented data (in the form of a Protocol Data Unit, or PDU) from a host computer and sending it across the Internet through the required gateways until the data reaches its destination.

The IP delivery process provides what is known as an unreliable connectionless service; proper delivery is not guaranteed by IP. Even PDUs that are delivered may arrive at the destinations out of sequence. TCP must ensure reliable delivery of PDUs. TCP provides the transport mechanism that ensure that data is delivered error-free, in the order it was sent, and without loss or duplication.

TCP's basic role is providing reliable end-to-end data transfer between two processes, called transport users (these include FTP and SMTP). In specific terms, the TCP standard describes five levels of service: multiplexing (the ability to support multiple processes), connection management, data transport, error reporting, and a variety of special capabilities.

In the basic data-transfer process, a transport user such as FTP passes data to TCP, which encapsulates the data into a segment that contains user data and control information (e.g., the destination address). TCP ensures reliable data delivery by numbering outgoing segments sequentially and then having the destination TCP module acknowledge arrival by number. If segments arrive out of order, they can be reordered via sequence numbers, and if a segment fails to arrive, the destination TCP module will not acknowledge its receipt, and the sending TCP module resends it.

TCP allows the transport user to specify the quality of transmission service it requires, permits special urgent data transmissions, and provides security classifications that can be used in routing segments to data-encryption devices. In trying to provide high-quality transmission services, TCP attempts to optimize the underlying IP and network resources. Parameters available include timeout delays and message-delivery precedence. Interrupt-driven urgent transmissions include terminal-generated break characters and alarm conditions.

The services provided by TCP and IP are defined by primitives and parameters. A primitive is a mechanism for specifying the function to be performed, while parameters are used to pass data and control information.

Only two primitives—SEND and DELIVER—are used to define the IP services. Parameters available with these primitives include source and destination host addresses, the recipient protocol (usually TCP), an identifier that distinguishes one user's data from another's, and user data.

TCP offers two primitives and associated parameters: service request and service response primitives. A TCP client sends service request primitives to TCP; TCP issues the service response primitives to the client. Many of these primitives set off an exchange of TCP segments between host processes or computers, and TCP passes the segments to IP in a SEND primitive and receives them from IP in a DELIVER primitive.

Files And Terminals

FTP exists to transfer a file or a portion of a file from one system to another under orders from an FTP user. Typically, a user executes FTP interactively through an operating system interface, which provides the input/output facilities that allow exchanging files between systems.

FTP options allow transferring ASCII and EBCDIC character sets and using transparent bit streams that permit exchanging any sort of data or text file. FTP also provides data-compression options and has password/identifier mechanisms for controlling user access.

SMTP provides the underlying capabilities for a network electronic mail facility. It does not, however, provide the user interface. Primarily, it provides mechanisms for transferring messages between separate systems. SMTP accepts e-mail messages prepared by a native mail facility (such as cc:Mail) and—making use of TCP to send and receive messages across the network— delivers them.

With SMTP, users can send mail to users anywhere in the local network as well as to those on the Internet.

TELNET outlines a network terminal-emulation standard. It allows terminals to connect to and control applications running in a remote host just as if it were a local user of the host.

In implementation, TELNET takes two forms: user and server modules. The user module interacts with the terminal I/O module, providing translation of terminal characteristics into the network-specific codes and vice versa. The server module interacts with processes and applications, serving as a terminal handler to make remote terminals look as if they are local.

SNMP And Other Protocols

Among the other TCP/IP protocols, one of the most widely applied is SNMP, the Simple Network Management Protocol. SNMP supports the exchange of network management messages among hosts, including a central host that is often called a network management console.

SNMP was designed to operate over UDP, the User Datagram Protocol. UDP operates at the same level as TCP, providing a connectionless service for the exchange of messages while avoiding the overhead of TCP's reliability facilities.

ARP and RARP provide mechanisms for hosts to learn MAC and Internet addresses. The former allows a host to discover another host's MAC address, and the latter permits a host to find out its own Internet address, an important capability for diskless PCs without permanent ways to store their Internet addresses.

The Exterior Gateway Protocol allows neighboring gateways in different autonomous systems to exchange information about which networks are accessible via a particular gateway. Industry observers once predicted that most TCP/IP users would eventually migrate to OSI. The question is, when? Few commercially available products offer complete OSI functionality. Most OSI protocols remain in the standards-setting phase, and users continue to be satisfied with the level of service provided by TCP/IP.


Data-Link Protocols

Posted by Sinichi on , under | komentar (0)



Topologies

Understanding the topology of LAN technologies can tell you a lot about your alternatives when installing or expanding a LAN. At its basic level, the topology of a network refers to the way in which all of its pieces have been connected. That is, it refers to the layout of the computers, printers, and other equipment hooked to the network in your building.

Because cable connects these scattered computing resources together into a network, your network's topology is also a function of the way in which the cabling is organized, whether it is arrayed in a bus, ring, or star, which are the three basic physical topologies available to LAN designers (see Figure 1). Although recent technological advances have blurred the distinctions between the physical and logical arrangements, the topology you select (or are forced to select) may also dictate the media-access control method (that is, Ethernet or Token Ring) under which your network will operate.

Click To expand
Figure 1: The three basic physical ntework topologies are the star, ring, and bus. The star is most often used in minicomputer networks. The ring was popularized by Token Ring, and the bus is used in Ethernet.

A network's logical layout may differ from its physical layout. The logical topology defines the electrical path; the physical path defines how the cables, concentrators, and nodes are arranged. For example, Ethernet must be a logical bus network; however, it can be physically configured as a bus or star. Token Ring is a logical ring, but is physically configured as a star. FDDI, a logical ring, is physically configured either as a ring or a star.

The Star Route

Until recently, the star topology has been found mostly in minicomputer and mainframe environments. These typically consist of a system of terminals or PCs, each wired to a central processor. It is also used by AT&T in both its StarLAN network and its Private Branch Exchange (PBX) based network. The star topology is ideal for wide area network (WAN) applications in which outlying offices must communicate with a central office.

A principle advantage of the star topology is that it not only allows centralizing key networking resources-concentrators or line conditioning equipment-but also gives the network administrator a focal point for network management. When something goes wrong with the network, the administrator can troubleshoot it from one place, usually a wiring closet, but possibly from a remote management console.

The star-based network requires a substantial investment in cable, however. Each workstation is connected to the central concentrator by its own dedicated line. In some star-based network technologies (ARCnet, for example) this line is coax cable that runs from an active hub to a workstation. (ARCnet can also operate as a bus.)

The 10Base-T Ethernet standard permits operating traditionally bus-based Ethernet in a star-wired configuration using unshielded twisted-pair (or high grade telephone) wiring.

Cascaded Stars

The use of a modular multiport repeater (also known as a hub or concentrator) with Ethernet allows creating large networks made of what can be called cascaded stars. In this arrangement, one centralized multiport repeater serves as the focal point for many other multiport repeaters, in effect creating a series of star-based Ethernets (see Figure 2).

Click To expand
Figure 2: Twisted-pair Ethernets are often composed of cascaded stars, in which multiport repeaters (represented by boxes) are connected to one another and to a central repeater.

Using modular multiport repeaters also permits mixing star- and bus-based Ethernet workgroups into a single large network. In this instance, the modular repeater must only be able to accept modules that support the many Ethernet-compatible cable types.

The Ring

IBM popularized the ring topology with its Token Ring technology. Like the bus, a Token Ring network uses a single cable. Unlike the bus, the cable's ends are looped to form a complete logical circle or ring. Physically, Token Ring is a star-wired network. Each workstation is connected directly to a central device called a Media Access Unit (MAU). Logically (or electronically), however, the Token Ring remains a true ring (see Figure 3).

Click To expand
Figure 3: Although a physical star, IBM's Token Ring Implementation is logically or electronically a ring. The arrows represent a data packet as it moves from one station to another around the ring.

Unlike the bus, Token Ring uses a deterministic, rather than a contention-based, access method. In the Token Ring access method, an electronic signal called a token is passed from station to station on the ring, with each station regenerating the token as it passes by.

When a station wishes to transmit data over the network, it must wait until the token is passed to it by its neighboring station. It takes control of the station and then places a data packet on the network. Only after the data packet has made a full circuit of the ring, returning to its originator, does the station release the token for the next workstation.

Token Ring can also be expanded by linking multiple rings together, just like Ethernet. In these arrangements, one Token Ring, usually a 16Mbits/sec ring, is dedicated as an internetwork loop, with work group or departmental rings connecting to the company-wide ring via a PC running bridging software.

Taking The Bus

In a bus topology, all workstations on the network are attached to a single cable. Ethernet, AppleTalk, and IBM's PC Network are examples of bus-based networks. This sharing of the transmission media (or cable) has several important ramifications. Most importantly, it means that the cable can carry only one message at a time, and each workstation on the network must be capable of knowing when it can and cannot transmit using this shared medium.

Ethernet employs what is called a Carrier Sense Multiple Access/Collision Detection (CSMA/CD) access method to arbitrate use of the cable and to maximize its throughput. In this method, each station on the bus is always listening on the cable for transmission for other stations. It only transmits when the cable is not busy with another transmission. It is able to sense the collision that occurs when it and another station on the bus transmit at the same moment. Having sensed that a collision has occurred-and that the transmission has miscarried-each workstation waits a random time period (usually several microseconds) before retransmitting.

Naturally, frequent retransmission can slow down an Ethernet LAN; this limits the number of workstations that can be placed on any network segment. Fortunately, network managers have access to numerous devices, such as switches, bridges, and routers, that divide Ethernets in small segments to mitigate this problem.

One common arrangement is to run numerous secondary segments off a backbone bus. In a typical installation, Fast or Gigabit Ethernet segments running between a building's floors would serve as the backbone. PCs on each floor would be connected to each other and the backbone via twisted-pair cable.

These secondary or horizontal segments can be linked to the primary bus via a repeater, a bridge, or a router. Each of these devices has its own benefits and disadvantages, principally in the amount of traffic control they provide and the amount of administration they require.

Two major shortcomings of the traditional coaxial cable bus topology are that it requires lots of cable and troubleshooting the length of several thousand feet of cable can be time-consuming and frustrating. The bus topology is, however, highly expandable.

Reality Injection

Unfortunately, reality often dictates the choice of network topology and access method. For example, organizations with a large installed base of IBM equipment once generally opted for an IBM Token Ring network because IBM heavily endorsed Token Ring. Or it may be physically or financially impossible to install a particular cable type. For example, cable raceways may be jammed full with cable, dictating that you use a cable with a narrow diameter, such as fiber, or even a wireless, radio-based transmission method.


Physical Layer Protocols

Posted by Sinichi on , under | komentar (0)



Encoding, Modulation, and the Physical Layer

The Physical layer doesn't get any respect. This negligence results partly from the fact that there are few end-user interventions once a network's cabling or wireless infrastructure is successfully put into place. The actual behavior of electromagnetic signals and raw digital sequences is generally built into hardware interfaces and is beyond any ordinary fiddling or tuning. Nevertheless, a bit of education about the Physical layer can help prepare you for a deeper understanding of new wireless, optical, and local-loop technologies that will have important future roles in every network.

The Physical layer is responsible for turning some medium into a bit pipe. Copper cabling is the most common data-networking medium of LANs and in the local loop, while fiber optic cabling is prevalent in most wide area networks—and is perhaps the local-loop and the LAN medium of the future. Radio frequency bands also play a role in some data networks, including signals that are relayed via satellites. Some local networks and point-to-point links employ infrared signals propagated through space, and visible light lasers are sometimes used to transmit data without the aid of a fiber optic cable.

Each medium has its strengths, vulnerabilities, and quirks. Cost is obviously an important factor, which explains the prevalence of copper cable in today's infrastructures. Performance, in the form of reliable throughput, is closely related to cost. The rapidly increasing price/performance of fiber optic cabling accounts for the growing hegemony of that medium as it migrates from interstate backbones to metropolitan areas, neighborhoods, and campuses. Although wireless systems have the powerful cost advantages of no cables, trenches, or poles, their relatively low reliability, low privacy, and low throughput offset these advantages.

The main task of the Physical layer is to make the best use of the medium at hand. The laws of physics constrain a medium's potential for reliable bit throughput, but so do regulations devised by the people who need to share limited resources. For example, T1 lines interfere with analog voice, ISDN, and Asymmetric Digital Subscriber Lines (ADSLs) so much that aggregated cables or binder groups can't include T1s.

Analog And Digital Data

Data that needs to be communicated may be in analog or digital form. Analog data is continuous, taking on innumerable values within a range. Voices, images, and temperature readings from a sensor are all examples of analog data. Digital data takes on a limited number of discrete values. In the limiting, and most common case, digital data takes one of two values: zero or one. Logical values such as true or false, integers, and text are commonly encountered examples of digital data.

In order to manipulate or communicate data, it must be encoded as some kind of signal, usually an electrical or electromagnetic signal. Analog data can be encoded as an analog signal. Perhaps the most common example is a plain old telephone in the local loop, though a cassette tape player, the video and audio components of a TV program, and many other household media use analog signals to represent analog data.

Analog data is also commonly encoded with digital signals. If a phone call travels beyond the local exchange carrier's central office into the long distance network, it will be digitized. If you scan an image or capture a sound on the computer, you're converting analog data to digital signals. This analog-to-digital conversion is usually accomplished with a special device or process referred to as a codec, which is short for coder-decoder.

Digital data is routinely converted to analog signals. The most common example is when you make use of the omnipresent voice infrastructure for computer connectivity and employ a modem to represent your bits in the form of audible tones. (Modem is short for modulator-demodulator, which performs the inverse of what a codec does—though in most cases, of course, both a codec and a modem perform both analog-to-digital and digital-to-analog conversions.) Modulation can be considered to be a special case of encoding, though the terms tend to overlap in ordinary usage. Technically speaking, modulation involves combining two signals, either of which can be analog or digital, to produce a resultant signal, which can be analog or digital. Encoding, then, is the representation of data by a signal using any method.

Finally, digital data is also regularly represented by digital signals. Any time you send e-mail, load a file, or download Web pages, you're encoding digital data with digital signals.

Signal Obstacles

The enemies of both analog and digital signals include attenuation, noise, and crosstalk. Attenuation is the tendency of a signal to get weaker with distance. Analog signals must be amplified before they become too diminished to be detectable. Unfortunately, analog signals accumulate noise with repeated amplification. Digital signals, while they are degraded by attenuation, can be detected and repeated indefinitely with no loss of data. This property is one of the principal reasons digital communication became increasingly important in the last years of the 20th century.

Noise is the backdrop of the universe. Atoms and molecules in motion create random electromagnetic signals that prevent any communication channel from being perfectly clear. Of course, all sorts of events, from elevator motors and electric mixers to lightning and solar flares, also contribute noise to our communications environment. Some encoding techniques are less susceptible to particular kinds of noise than others. Crosstalk is a special form of noise that is induced by other signals on a common medium.

Digital signal transmission is used in LANs, where cable lengths are relatively short and thus not subject to severe attenuation. (Attenuation increases with increasing frequency, and digital transmissions have high frequency components, which means that channels with constrained bandwidth aren't suitable for high throughput digital transmissions.) The best known examples of digital transmission on telephone facilities are T1 lines and ISDN.

The simplest representation of digital signals is a line code known as Non Return to Zero Level, or NRZ-L (see Figure 1a). This code is the archetype of what a digital signal looks like, although there are innumerable variations in how best to transmit a digital signal across various media. NRZ-L has severe limitations in practice, but it has real-life applications in RS-232 links and in data storage on hard disk drives.

Click To expand
Figure 1: A large number of digital encoding techniques are available to design Physical-Layer implementations. Five of the most common are illustrated here.

Two of the biggest shortcomings of NRZ-L are its DC component and its inability to carry synchronization information along with the data. If an NRZ-L signal has a sequence of ones, the signal can't pass through such electrical components as transformers and capacitors, which only conduct when the signal is changing. As for synchronization, correct timing is essential for a receiver to identify the discrete states of the digital signal. If a series of ones appears in an NRZ-L transmission, the receiver will require an additional synchronization signal to be aware of how many there are.

T1 lines often use a line code called Bipolar with 8 Zero Substitution (B8ZS, see Figure 1b). B8ZS is a variant of Bipolar Alternate Mark Inversions (AMI, see Figure 1c). (Marks and spaces are just a terminological variation on zeros and ones.) Bipolar AMI solves the DC component problem by alternating the polarity of ones—zeros are represented by no signal, the first one is a positive signal, the second one is a negative signal, and the signal values of subsequent ones alternate. However, with a long string of zeros, Bipolar AMI signals can lose self-synchronization. The 8 Zero Substitution trick takes care of the problem by breaking the alternation rule when it comes across a sequence of eight consecutive zeros. By sticking ones in the places of the fourth and fifth zeros, and in the places of the seventh and eighth zeros, with the first substitute one incorrectly having the polarity of the previous one, and the third substitute one incorrectly having the polarity of the second substitute one, the receiver recognizes an intentional violation and concludes that there is in fact a sequence of eight zeros. This coded violation ensures that there will never be a sequence of more than seven successive no-signal bit times. The rules of mark inversion also add a degree of Physical-layer error detection to this encoding method; noncoded violations will indicate spoiled bits.

Ethernet uses a type of digital signal known as Manchester encoding (see Figure 1d). A one is indicated by a high/low transition in the middle of a bit, while a zero is indicated by a low/high transition in the middle of a bit. Based on the previous discussion, you can see that Manchester encoding has no DC component and is fully self-synchronizing. If there is no transition in a bit time, you have a Physical-layer error indication. The drawback to applying this line code more widely is that its bandwidth requirement is twice the baud rate; in other words, there are significant spectral components as high as 20MHz, which are no problem on coaxial cable or on short distances of twisted-pair cabling, but not suitable for long distances.

ISDN lines make use of a line code known as 2 Binary 1 Quaternary (2B1Q). Symmetric Digital Subscriber Line (SDSL) and High-Bit Rate Digital Subscriber Line (HDSL) also employ this encoding method. A line with 2B1Q encoding uses four distinct signaling levels, with data represented in 2-bit units (see Figure 1e). By encoding two bits with each signal transition, 2B1Q represents the distinction between bits per second and baud rate. The baud rate of a signal is the number of signal transitions per second, and it can't be higher than the bandwidth of the channel. The number of bits per signal element, represented by L, is given by log2L. Thus a code with eight signal elements could encode 3 bits per baud, a code with 16 signal elements could encode 4 bits per baud, and a code with 256 signal elements could encode 8 bits per baud. In the case of ISDN, the bandwidth the signal occupies is 80KHz, the baud rate is 80Kbaud, and the raw data rate is 160Kbits/sec.

Digital Signals, Analog Transmission

A vast infrastructure exists for analog signaling, and much of it can readily transport digital signals as well. The telephony local loop, the cable TV infrastructure, and practically every form of wireless communication are inherently analog transmission media that have been adapted for digital signals.

The earliest modems used a technique known as Frequency-Shift Keying (FSK, see Figure 2a) to represent digital data. FSK devices, such as the Bell 103 modem, used one tone (1070Hz) for zeros and another tone (1270Hz) for 1s. Amplitude-Shift Keying (ASK, see Figure 2b), is one way of describing the modulation of digital data over fiber optic cable. In this case, no light represents a zero while the presence of light above a threshold level represents a one. The third attribute of a sinusoidal signal is its phase, and Phase-Shift Keying (PSK, see Figure 2c) is widely used in modems. Nowadays, modems commonly use a combination of phase and amplitude modulation to encode multiple bits in a single signaling event or symbol.

Cable modems and ADSL make use of a signaling technique called Quadrature Amplitude Modulation (QAM). With QAM, the carrier signal is split into two signals, shifted in phase by 90 degrees. Each component is modulated with ASK, using as many as 16 amplitude levels to represent as many as 256 different states. One ADSL modulation technique, Discrete Multitone (DMT), divides the available twisted-pair spectrum above 25KHz into 256 downstream subchannels of 4KHz each. QAM is then applied to each subchannel according to its individual performance. At best, a single subchannel may be able to carry as many as 60Kbits/sec. Theoretically then, ADSL could provide throughput rates as high as 15.36 Mbits/sec.