VitalQIP 7.3 and AM 1.7 Update Steve Wiggins July, 2011

VitalQIP 7.3 and AM 1.7 Update
Steve Wiggins
July, 2011
COPYRIGHT © 2011 ALCATEL-LUCENT. ALL RIGHTS RESERVED.
ALCATEL-LUCENT — INTERNAL PROPRIETARY — USE PURSUANT TO COMPANY INSTRUCTION
Explosion of new Devices and Protocols on the Network
Smart Phones
IP Phones
IP soft Phones
IP based switches
Network Appliances
IPAD
Manufacturing Robots
VOIP
Cellular
ENUM (Service Providers)
WIMAX
Unified Communalization (Enterprise)
IMS
IPV6
IPTV
RFID Readers
Bar code readers
Intelligent multiple docking
stations such as Symbol 6 dock
DSL
Docsis
LTE
VitalQIP Architecture
WEB, CLI and API
X
500, 1000, 1200, 5000
Alcatel-Lucent DHCP and DNS
Supported Operating systems
Solaris
RedHat Linux
Windows
Microsoft DNS
Bind compliant DNS
VitalQIP Solution offers end to end functions that suit specific needs.
Soap/XML API’s
Who?
Where?
When?
ARIN/APNIC/AFNIC/
RIPE/AfriNIC
Internet Registries
Robust CLI’s
Integrate
SNMP
IMS LTE WIMAX
Manage/
Communicate
Monitor
Nagios
DNS DHCP
Audit
VitalQIP
DNS/DHCP Probes
SNMP
Allocate
IPAM DNS DHCP
Vital Suite
Secure
Assess
Discover
IPTV
Appliances
VOIP ENUM
SNMP
Report
NAC
Quarantine
Remediate
All Rights Reserved © Alcatel-Lucent 2009
•VitalQIP® Is the most Flexible IP Management Tool available today
Traditional Off the
shelf Software
1200 Platform
HARDWARE
APPLIANCE
SOFTWARE
APPLIANCE
Powered by an Intel Xeon X3430
Quad‐Core 64‐bit 2.4 GHz on a
1U form factor with iLO and 2 hot
swappable PSU
AMS
ESM
AMM
VIRTUAL
ENVIRONMENT
All Rights Reserved © Alcatel-Lucent 2009
ISO versions of ESM, AMS
and AMM software to be
installed on any Red Hat
Linux compliant hardware
VitalQIP supports Multi-Vendor solutions
All Rights Reserved © Alcatel-Lucent 2011
Web Based GUI
Search Engine
Release 7.3
Client ID
Visual-IP space
New VitalQIP web GUI
• Created from real QIP customers representing the world wide customers
base and VitalQIP Customer Advisory board.
• Utilizing Web 2.0 technology
• additional user collaboration
• Modeled after the proven VitalQIP thick Client
• More information in one spot.
• Less mouse clicks
• fewer screens to maneuver
• Enhanced performance
• All new VitalQIP search engine – fast and precise
• Fully complimented by a robust set of CLI commands
ENUM manager in 7.3 GUI
All Rights Reserved © Alcatel-Lucent 2009
WHAT’S NEW IN VITALQIP 7.3
DHCP GENERATION PERFORMANCE TEST RESULTS
• This is based upon customer export which was exhibiting DHCP generation
performance using different versions of VitalQIP
• This is a live export from a VitalQIP solution which is used in production at
the moment, it is not simulated lab data
VITALQIP 7.2 PR2
4 min
OK
VITALQIP 7.2 PR3
VITALQIP 7.3
2.3 min
17 sec
FASTER
FASTER
50%
12
COPYRIGHT © 2011 ALCATEL-LUCENT. ALL RIGHTS RESERVED.
ALCATEL-LUCENT — INTERNAL PROPRIETARY — USE PURSUANT TO COMPANY INSTRUCTION
1400%
Structured Drop-down Menus
 Multi-level drop-down menus allow users to
quickly access data/operations by using fewer
mouse clicks
 Icons improve clarity and give the GUI a more
finished appearance
New features
Tabs offer optimized database
query and navigation
Sort by any
column
Contextual specific actions
Previous/Next buttons allow
moving between objects
without having to go back to
Manage Objects screen
Rearrange
column’s by
dragging
Clear
Clear
Error
error
Messages
messages
Visual IP Space
New search Engine save Templete
Nessus Security Scanner
Starting with 7.3 and AMM 1.6 all VitalQIP and Appliance
releases are checked with the Nessus scanner.
Nessus is a tool designed to automate the testing and discovery of known security
problems. Typically someone, a hacker group, a security company, or a researcher
discovers a specific way to violate the security of a software product. The discovery may
be accidental or through directed research; the vulnerability, in various levels of detail, is
then released to the security community. Nessus is designed to help identify and solve
these known problems, before a hacker takes advantage of them.
All Rights Reserved © Alcatel-Lucent 2011
All Rights Reserved © Alcatel-Lucent 2009
All Rights Reserved © Alcatel-Lucent 2009
All Rights Reserved © Alcatel-Lucent 2009
Appliance Architecture
All Rights Reserved © Alcatel-Lucent 2009
Appliance Roles
All Rights Reserved © Alcatel-Lucent 2009
Introducing the VitalQIP Model 1200 next generation
Appliance
•1U Form Factor
•Dual Power & Quad NICs
•Lights-Out Mgmt
•High Performance
•On-Site Repair
•DNS
•DHCP
•100K+ qps
•12K+ lps
•Additionally available
 3-year next biz day
 4 hour same day on-site repair
 included in price
 via Certified Engineers
 Advance Replacement
•Low list price $8,999
All Rights Reserved © Alcatel-Lucent 2011
VitalQIP Appliance Hardware Platforms
Model 5000 Platform
Carrier Grade. Powered by dual 64-bit Multi-Core Intel® Xeon® Processors in a NEBS-3
compliant 1U platform, mirrored RAID 1 disks, dual AC/DC power supplies, 8GB RAM.
Model 1200 Platform
Enterprise Grade. Powered by a high performance Intel Xeon X3430 Quad Core CPU,
1U platform, 4GB of Memory, 250GB SATA HD, 4 GigE NICs, dual dower supplies and
remote lights-out card.
Model 1000 Platform
Enterprise Grade. Powered by a high performance 64-bit Architecture Intel Xeon Core
2 Duo Processor on a 1U form factor platform. 4 GB memory.
Model 500 Platform
Ideal for Retail and/or Small Office applications. Powered by the 64-bit Intel Atom 230
Processor on a compact, quiet Desktop platform. 1GB memory.
All Rights Reserved © Alcatel-Lucent 2011
New Appliance models coming 2011/2012
QIP 700 (New October 2011) Low end AMM or AMS appliance --1U rack mount,
one 250GB disk drive, Dual Core Intel Pentium processor, single Power supply,
lights out card
QIP 1200-RAID (New December 2011) Same as 1200 with additional raid 5 and
more disk installed
QIP 6000 (New January/ February 2012) Large Enterprise appliance--- 16GB
Memory ,Dual quad core Intel Xeon 2.4Ghz CPU’s, 5 Terra byte raid 5 disk,
dual power supply, 4 GigE lights out card.
All Rights Reserved © Alcatel-Lucent 2011
Performance Numbers
DNS qps:
DHCP lps:
AMM 5000
AMM 1200
AMM 1000
AMM 500
93,000+
6,400+
100,000+
12,000+
43,000+
3,200+
9,000+
1,000+
Using a GigE switch
DNS qps:
280,000
DNS Performance: measured in queries per second (qps)
DHCP Performance: measured in leases per second (lps)
All Rights Reserved © Alcatel-Lucent 2011
SNMP on the
AMS
PKG Scheduler
AM 1.7
Multiple Syslog
servers
DB import/export
from the AMS
Package Deployment Scheduling
Package Deployment Scheduling - enables the user to schedule the package
deployment either directly on the appliance or through appliance group from
the AMS GUI. This helps the AMS GUI administrator to plan in advance and
schedule the package deployment during off peak hours.
All Rights Reserved © Alcatel-Lucent 2011
SNMP on the AMS
The Redhat SNMP server will be started on the AMS and all the advantages of
SNMP monitoring and statistics can be utilized on the AMS.
All Rights Reserved © Alcatel-Lucent 2011
VitalQIP DB Import/Export VIA AMS
allows authorized users to perform VitalQIP database export/import
operations from the AMS web interface. Multiple exports can be stored on the
AMS based on disk availability.
All Rights Reserved © Alcatel-Lucent 2011
Multiple Syslog Servers
This enables AMS GUI users to define up to a maximum of 10 remote logging
servers for each individual appliance to send syslog data to from AM 1.7
onwards.
All Rights Reserved © Alcatel-Lucent 2011
Software Appliance
Software Appliance
S-AMS
Software
Appliance
S-AMM
Software Appliance
S-ESM
 Allow the use of corporate standard
Hardware.
 One time purchase
 Lower Total Cost Of Ownership
(TCO)
 No customs clearance

Leverage corporate volume HW
purchasing.
 No new IT HW training.
 Reuse of existing HW investment.
 Mix and match VitalQIP appliances
with VitalQIP Software appliances.
 Zero lead time for delivery
 No import companies
 Take advantage of Green
initiatives with Blade Server
technology.
Reduce Overall Total Cost of Ownership with Integrated Appliances
•Manage All Remote
DNS/DHCP from a
single point
•Quick Indicators for
Status and Updates
•Reboot, Restart,
Rollback on any
appliance when
required.
•Deploy and Track
Services remotely
with a single click.
All Rights Reserved © Alcatel-Lucent 2009
Quick Indicators for
Status and Updates
All Rights Reserved © Alcatel-Lucent 2009
VitalQIP Software appliance on Riverbed Steel Head
Appliance
VitalQIP DNS and DHCP
Running in a virtual environment
No Restrictions from ALU - Unlimited resource allocation
VitalQIP DNS High Availability (DNS-HA)
Enterprise Server (ESM)
Clients
DNS Queries/
Responses
DNS Push
192.168.5.2
192.168.5.3
192.168.5.4
192.168.5.6
DNS Notify
& Zone Transfer
192.168.5.5
VIP
Heartbeat
Stealth Master
DNS Server
Communication:
DNS Server Sync
DNS Queries
Secondary DNS
Server (Active)
Secondary DNS
Server (Standby)
DNS-HA Pair
All Rights Reserved © Alcatel-Lucent 2009
Notes:
1. Major advantages of DNS-HA:
Improved uptime, single Virtual
IP (VIP) address for clients, etc.
2. Only 1 server in DNS-HA Pair is
active at any given time
3. VIP points to active server
4. Heartbeat used to monitor status
of active server and DNS service
5. Automatic failover to Standby
server occurs in event of failure
6. Stealth Master configuration is
best practice (not mandatory)
for updating DNS zones
7. Stealth Master could also be
resident on ESM appliance
8. VIP must be on same subnet
as Active/Standby servers
9. Standby server is hot/active
10. AMM1000 appliances are shown,
but DNS-HA also runs on AMM500
and AMM5000 appliances (both
appliances in pair should be of
same model)
11. DNS-HA feature is only available
on VitalQIP appliances
12. Crossover cable required for
Heartbeat
VitalQIP DHCP High Availability (DHCP-HA)
Active
Leases
Active
Leases
Active
Leases
Heartbeat
…
Primary DHCP
Server
Primary DHCP
Server
DHCP-HA N:1 Failover
Failover DHCP
Server
DHCP Discover
Messages
Clients
All Rights Reserved © Alcatel-Lucent 2009
Notes:
1. Major advantages of DHCP-HA:
Increased DHCP uptime, no
“split” scopes, minimal hardware
requirements, etc.
2. DHCP-HA available on appliances
(AMM500, AMM1000, AMM5000) as
well as non-appliance servers
3. Recommended maximum is 5:1 (5
Primary servers can be supported
by a single Failover DHCP server)
4. Failover server is “hot” and tracks
DHCP “DORA” messages and
leases
5. If heartbeat determines that
Primary server/service is down,
Failover takes over (client does
not notice the change)
6. When Primary service is restored,
Primary and Failover servers sync
active lease databases and
Primary takes over
7. Router “Helpers” point to both
Primary and Failover server
8. Primary and Failover servers do not
need to be on the same Subnet
9. No crossover cable needed for
Heartbeat
Nagios Map shows appliances status by color
Double click and expand the information
www.alcatel-lucent.com
43 | Presentation Title |
Month 2006