Professional Documents
Culture Documents
SMBEN v2.04-1
Lesson Overview
Upon completing this lesson, you will be able to identify SNF architecture designs to meet customer needs. This ability includes being able to meet these objectives:
Discuss components of SNF design
SMBEN v2.04-2
Main Office
SMBEN v2.04-3
Services offered
Smart Design Architecture: architecture models and components Choosing between hybrid and integrated models
SMBEN v2.04-5
Integrated router
DMZ
Aggregation switch
Access switches
SMBEN v2.04-6
800 ISR
Linksys
DSL/ cable
Linksys
Teleworker Internet
Linksys
ISR
Main office
Mobile worker
SMBEN v2.04-7
SMBEN v2.04-8
Infrastructure protection
Monitoring WAN router health and notification via e-mail/Syslog
SMBEN v2.04-9
QoS
Voice ready Video ready Multicast Firewall IPS Infrastructure security GUI-based configuration
2008 Cisco Systems, Inc. All rights reserved. SMBEN v2.04-10
SMBEN v2.04-11
Hybrid Model
WAN/Internet WAN router
DMZ Servers
DMZ servers
Separate firewall
Local Servers Local servers
Aggregation switch
Call Processing, DHCP, etc. Call processing, DHCP, etc.
Access switches
SMBEN v2.04-12
Catalyst Express 500 24PC Catalyst Express 500G 12TC 2800 ISR
800 ISR
Teleworker Internet
Main Office
Mobile Worker
SMBEN v2.04-13
Yes
Yes
Yes
Low
Yes
Low
Yes
High
No
SMBEN v2.04-14
Hardware Components
Number of Users 0-24 25-36 37-48 49-96 Router Cisco 2801 Cisco 2811 Cisco 2821 Cisco 2851 Aggregation Switch No Catalyst Express 500G-12TC Catalyst Express 500G-12TC Catalyst Express 500G-12TC Access Switch Catalyst Express 500-24PC (1) Catalyst Express 500-24PC (2) Catalyst Express 500-24PC (2) Catalyst Express 500-24PC (3-4)
SMBEN v2.04-15
10/100/1000 Mbps V
10/100/1000 Mbps
802.1Q trunk
WAN router
Layer 2 LAN
VLANs
VLAN Name Cisco-Data Cisco-Voice Local-Services VLAN Number VLAN Description at the Main Office 31 41 4 Carries traffic from/to PCs Voice traffic Optional; used to connect a server such as an AAA server to authenticate users, or other servers, providing local services not accessible from the Internet
SMBEN v2.04-17
STP
10/100/1000 Mbps V 10/100/1000 Mbps
802.1Q trunk
Aggregation switch
802.1Q trunk
WAN router
Layer 2 LAN
SMBEN v2.04-18
SmartPorts Roles
Switch Model Port Type and Number Fast Ethernet ports 1 to 24 (connected to PCs, phones) Gigabit Ethernet or SFP module ports 1 and 2 (connected to aggregation switch) Gigabit Ethernet ports 1 to 8 (connected to any server) Recommended SmartPort Ports Role phone+desktop switch Recommended SmartPort Parameters Data VLAN = 31 Voice VLAN = 41 Note: all VLANs are trunked
servers
Gigabit Ethernet or switch or router Note: all VLANs are SFP module ports 9 to depending on where trunked 12 it is connected
CUCM = Cisco Unified Communications Manager
SMBEN v2.04-19
WAN Design
800 ISR
DSL/ cable
Linksys
Teleworker Internet
Linksys
2800 ISR
Main office
Mobile worker
SMBEN v2.04-20
Layer 3 Design
Layer 3 Services
IP routing IP routing protocols IP addressing and DHCP DNS Network Address Translation NTP
Internet
QoS
SMBEN v2.04-21
IP Addressing Considerations
Voice and data VLANS
NAT Inside
Internet
SMBEN v2.04-23
SMBEN v2.04-24
SMBEN v2.04-25
Policy Enforcement
Anti-spoofing services Virus prevention Unauthorized access prevention
Intrusion Prevention
Worm mitigation
Secure Connectivity
Virtual private network
SMBEN v2.04-26
Q&A
SMBEN v2.04-27
Lesson Summary
SMBEN v2.04-28
Lesson Summary
The SMB Smart Design addresses the secure infrastructure needs of a typical small business and provides many benefits. Three variations of the Smart Design architecture framework are available: the Integrated model, the Hybrid model, and the Simplified Design with Layer 2 LAN. LAN designs, which can consist of core, distribution, and access layers, are typically deployed in one of three ways using either Layer 2 or Layer 3 LAN considerations.
SMBEN v2.04-29
SMBEN v2.04-30