- 1
- 2
- < previous
Understand the application and its network requirements
Today's LANs are not the "Wild West" they were many years ago, where all that was needed for network connectivity was an IP address and an activated network port. Network access and admission controls, firewalls and quality of service are a few of the new issues that must be dealt with.
In the previous example, the application required access across the network infrastructure on a specific IP port. If the switch that provided connectivity between the main server and the card access controllers had access control lists or other similar firewall-type rules that prevented such communication, these rules would need modification to allow access.
Note if Layer 7-aware switches (such as traffic shapers) are installed between clients and servers, determining that there is no impediment to network access requires careful examination of policies on such devices. Not long ago I encountered a situation where just such a policy pushed my network troubleshooting skills to the limit before I discovered a flaw in the policy.
Understanding the application and its network requirements can go beyond asking the on-site technician. Often they are trained to install their products in a clean environment and may not know what ports the application needs. Looking at ports open on the server (netstat -an) and performing a trace of attempted connections will usually reveal enough to configure network devices accordingly.
Keep security at the forefront
A vendor's application should not dictate your LAN's security policy. If it's acceptable from a security policy standpoint to open a port in your LAN infrastructure, that's fine. However, if a vendor requests a "nonstandard" port to be opened and it violates your company's security policy, it's reasonable to request an alternative solution.
A few years back I recommended that a client block TCP Port 81 inbound and outbound, as a variant of the Bagle worm was using that port to replicate. The problem was that Port 81 was sometimes used as an alternative Web server port. Not long after, an outside vendor requested that Port 81 be opened globally to provide for connectivity to a Web management application. Instead of reversing the security policy, I suggested the vendor use an alternative port for access. They readily complied and the problem was solved without compromising the local security policy.
I have found that vendors recognize that every LAN that they utilize has a distinct personality, so to speak, and have provisioned flexibility for such. It can be frustrating for a vendor at times because no real-world installation over a multiuse network mirrors a vanilla installation in a test lab.
Remember, the vendor's ultimate goal is to sell its product. In order to do so, the product needs to communicate on your network. While that usually requires some negotiation with the vendor's engineering staff, since it's in both their and your company's interests to ensure workability, this negotiation process is usually relatively painless.
Get involved early in the project
The last thing that you, as a network administrator, need to do is make network decisions under the gun. This will happen if the above issues show themselves close to project completion. The key to avoiding this is to get involved early.
In one case, a client of mine consulted with a vendor to provide credit card readers in several concession areas. The vendor and client performed a walk-through prior to installation and saw that there were network jacks installed at each location. The vendor provided a quote for the readers and had a technician arrive on-site to install.
The problem though was that while the cabling was installed, there was no network infrastructure to support the connections. Not only did that mean no Ethernet switches to make the network connections "hot," but no fiber optics to connect the communication rooms where the cables terminated to the company's backbone. Adding fiber-optics and network electronics to the installation drastically increased the project costs.
Since there were already significant sunk costs incurred, adding the infrastructure was approved. Involving the network team early in the project would have eliminated the surprise costs. This can be accomplished by implementing a corporate policy that any systems that require network access must have input from the corporate network team prior to purchase.
Finally
Remember, while you know your network like the back of your hand, vendors do not.
The variety of applications using your network may continue to grow. Being able to successfully work with vendors whose primary roots are not in data networking can be difficult, but following these few guidelines can ease the implementation process.
Greg Schaffer is a freelance writer based in Tennessee. He has over 15 years of experience in networking, primarily in higher education. He can be reached at newtnoise@comcast.net.
- 1
- 2
- < previous
Read up on the latest ideas and technologies from companies that sell hardware, software and services. Business Intelligence and Enterprise Performance Management: Trends for Emerging Businesses
Email Archiving 101—Customer Case Study
Email Archiving Implementation: Five Costly Mistakes to Avoid
Refresh your AUP: Top tips to ensure your acceptable use policy is fit for purpose
Controlling storage costs with Oracle database 11g
Best Practice in Building an Integrated Information Management Strategy
Discover the advantages of an open architecture multi-vendor network solution
IT Service Management Needs and Adoption Trends: An Analysis of a Global Survey of IT Executives
Zones provide focussed content from Computerworld and leading technology partners.Discover how SOA can create smarter outcomes for your business.
Attend and learn:
- How SOA is helping leading companies to become more agile
- Where you should be applying SOA processes in your company
- The top SOA implementation mistakes to avoid
Click here for more information.
- +
Computerworld Live Podcast #98: The Future of Datacentre IP 18/12/2008 10:33:00
CW Live speaks withLin Nease, Director of Emerging Business for HP ProCurve, to discuss the future of networks, including the effect of IP-based storage on datacentres, new capacity requirements generated by the use of 10Gb Ethernet, and how an efficient network design can slash energy and cooling costs, and help enterprises build a "green" image. - +
Computerworld Live Podcast #97: The Future of Enterprise Networking 25/07/2008 09:45:36
This week CW Live chats with Mark Thompson, global sales and marketing manager for HP ProCurve, on the future of the enterprise networking. Mark discusses the trends we can expect to see in the near future and how the right infrastructure can ensure your enterprise network is secure. - +
Computerworld Live Podcast #96: Security at the Edge 11/06/2008 09:22:22
CW Live speaks with Amol Mitra, HP ProCurve Director of Marketing for Asia Pacific and Japan. Today's topic: how enterprises are starting to shift away from simply controlling security via server logins, firewalls and moving to more adaptive security frameworks. - +
Data Management Edition #10: Multi-Petascale Systems 02/05/2008 09:12:33
This week we look at sustainability and the development of multicore technologies to build multi-petascale systems. - +
IT Security Edition #11: How to poison the Storm botnet 01/05/2008 08:51:55
This week CW Live presents a case study on how to poison the notorious Storm botnet . Plus we take a look at Cisco's plans for Ironport.
IT industry veteran advises caution on outsourcing selection in light of Satyam problems 2009-01-09 21:45:00+11
F-Secure Warns About a Worm Affecting Corporate Networks 2009-01-08 16:42:00+11
Research software developer appoints Susan Dart to new Business Development Director role 2009-01-08 09:08:00+11
Research software developer appoints Susan Dart to new Business Development Director role 2009-01-08 09:08:00+11
Anyware Introduce Two Powerful PCI TV Tuner Cards with S5 Power Up and Windows Media Center Remote 2009-01-07 17:30:00+11
Data grids and service-oriented architecture
When choosing an SOA strategy, corporations must ensure data availability, reliability, performance and scalability. A data grid infrastructure, built with clustered caching provides a framework for improved data access that can create a competitive edge and sustain customer loyalty. Read on to discover how this can be created within your organisation.





