Duties of a System Administrator


Linux involves much more than merely sitting down and turning on the machine. Linux is quite different from the most popular commercial operating systems in a number of ways, but it is no more difficult to learn.

Make no mistake: Every computer in the world has a system administrator. It may be — and probably is — that the majority of system administrators are probably those who decided what software and peripherals were bundled with the machine when it was shipped. By its very nature as a modern, multiuser operating system, Linux requires a degree of administration greater than that of less robust home market systems. By definition, the Linux system administrator is the person who has “root” access, which is to say the one who is the system’s “super user” (or root user). A standard Linux user is limited as to the things he or she can do with the underlying engine of the system.



Installing and Configuring Servers
In the Linux world, the word “server” has a meaning that is broader than you might be used to. For instance, the standard Red Hat Linux graphical user interface (GUI) requires a graphical layer called XFree86. This is a server. It runs even on a standalonemachine with one user account. It must be configured. (Fortunately, Red HatLinux has made this a simple and painless part of installation on all but the mostobscure combinations of video card and monitor; gone are the days of anguishconfiguring a graphical desktop.). Likewise, printing in Linux takes place only after you have configured a print server. Again, this has become so easy as to be nearly trivial. And Whenever a server is connected to machines outside your physical control, security issues arise. You want users to have easy access to the things they need, but you don’t want to open up the system you’re administering to the whole wide world.


Installing and Configuring Application Software
Since Linux is multiuser operating system. Each user has (or shares) an account on the system, be it on a separate machine or on a single machine with multiple accounts. While it is possible for individual users to install some applications in their home directories — drive space set aside for their own files and customizations — these applications are not available to other users without the intervention of the system administrator.

Creating and Maintaining User Accounts
An account must be created for each user and — you guessed it — no one but the system administrator may do this. That’s simple enough. But there’s more, and it involves decisions that either you or your company must make. To what may specific users have access? It might be that there are aspects of your business that make World Wide Web access desirable, but you don’t want everyone spending their working hours surfing the Web. What to do about old accounts? Perhaps someone has left the company. What happens to his or her account? You probably don’t want him or her to continue to have access to the company network. On the other hand, you don’t want to simply delete the account, perhaps to discover later that essential data resided nowhere else.



Backing Up and Restoring Files
There is a need to back up important files so that in the event of a failure of hardware, security, or administration, the system can be up and running again with minimal disruption. Only the system administrator may do this. Once you’ve decided what to back up, you need to decide how frequently you want to perform backups and whether you wish to maintain a series of incremental backups — adding only the files that have changed since the last backup — or multiple full backups, and when these backups are to be performed — do you trust an automated, unattended process?



Monitoring and Tuning Performance
System tuning is an ongoing process aided by a variety of diagnostic and monitoring tools. Some performance decisions are made at installation time, while others are added or tweaked later. A good example is the use of the hdparm utility, which can increase throughput in IDE drives considerably — but for some highspeed modes a check of system logs will show that faulty or inexpensive cables can, in combination with hdparm, produce an enormity of nondestructive but systemslowing errors.

Configuring a Secure System
For any machine that is connected to any other machine, security means hardening against attack and making certain that no one is using your machine as a platform for launching attacks against others. If you are running Web, ftp, or mail servers, it means giving access to those who are entitled to it while locking out everyone else. It means making sure that passwords are not easily guessed and not made available to unauthorized persons, that disgruntled former employees no longer have access to the system, and that no unauthorized person may copy files from your machine or machines.




Read more...

URL Filtering

The internet has been a unified place to access almost any information needed. But, some internet contents are not appropriate to be seen at work, it's just at the wrong time and at the wrong place. Gambling and adult sites are examples of this. But there are some sites that fall into "gray area". Sports leagues, auction, and social networking sites can reduce employees productivity. The first step of URL Filtering is to make a policy of which sites are allowed and which are denied. The policy must also put a decision to the "gray area" site.




How URL Filtering works?





URL Filtering works by making a list of restricted sites. After it is created, all HTTP request will be checked against the list. If the URL is in the list, the request is blocked and typically the employee will be given a warning screen that he/she is trying to access a restricted site. Maintaining the list can be done manually by the network administrator (this way is called black/white list), but the job can be given to a third party server. The company may subscript for the service and the list of restricted sites is maintain in a database on a third-party filtering server.


The advantages of the black/white list are:



  • It provides a basic solution if a few specific URLs need to be exempted.

  • It allows the company to directly manage the URLs it considers to be out of policy.

  • Existing network equipment can be leveraged.


While the advantages of using the third-parti filtering server are:



  • It provides a comprehensive, scalable solution.

  • Companies that specialize in appropriate web content manage the URL lists and provide updates.

  • Existing network equipment can be leveraged.

  • It covers millions of URLs (for the high-end services).


With Cisco, you can use subscription-based Cisco IOS content filtering. This feature is first integrated in IOS 12.2(15)T and offered through third-party companies, Websense, SmartFilter (N2H2), and also Trend Micro (since IOS 12.4(15)XZ and 12.4(20)T). To configure Cisco URL Filtering, first you have to register at one of those companies.The summary steps of configuring URL Filtering with Trend Micro are:



  • Configure Class Maps for Local URL Filtering

  • Configure Class Maps for Trend Micro URL Filtering

  • Configure Parameter Maps for Trend Micro URL Filtering

  • Configure URL Filtering Policies

  • Attach a URL Filtering Policy


You can see Cisco documentation to get examples.



Read more...

The Control Plane (Basic)

The network is said to have two planes: a control plane and a data plane. The data plane simply refers to the information that is being transported. Beside the main function of a network to route and forward data, there's another critical function that should be provided by the network for the network administrators. The network should provide a way for network administrators to provision and maintain the network devices themselves. The functions include monitoring network throughput and performance, updating the network topology, establishing new connections, and enforcing security and service policies. These functions is performed by the control plane in a network device. The control plane is responsible to provide a clean way to the network administrator to access the device, give command, and providing response. When a network goes wrong, the control plane is critical. If somehow the control plane is compromised, the network device could be "locked up". In this state, no network changes are possible, no monitoring is available, and there is no visibility into the operational state.




Control Plane Protection


Control Plane Protection (sometimes called Control Plane Policing or CoPP) should be taken to ensure bandwidth availability for the network administrator. The actions taken involves:



  • Preserving CPU “bandwidth” as a high priority for control plane services

  • Safeguards on the data plane to prevent CPU overruns

  • Separate CPU processors for the data plane and control plane


Denial of service (DoS) and distributed denial of service (DDoS) attacks typically try to overwhelm a device with traffic to the point of instability. Control Plane Policing (CoPP) uses QoS traffic policies to restrict the amount of traffic destined for network devices. The CoPP treats the Control Plane as an independent entity, it has its own ingress and egress port, therefore a set of rules can be attached to the ingress and/or egress of the port. The rules applied to a packet after it has been determined to have the Control Plane as its destination and when a packet goes out from the Control Plane.





An example command of attaching a QoS to the control Plane is:




Router(config)# control-plane


Router(config)#service-policy {input | output} policy-map-name





The first line will enter the control plane configuration mode, while the second line will attach the QoS to the ingress or egress of the control plane port.



Read more...

MultiProtocol Label Switching (MPLS) is Originally developed by Cisco in the form of tag switching, MPLS was adopted as an Internet standard by the Internet Engineering Task Force (IETF). Service providers are the primary implementers of the technology. With MPLS networks, service providers can offer services similar to traditional WAN technologies at lower costs and provide additional IP-based services previously not available.



MPLS provides an encapsulation scheme that serves as an alternative to traditional routing. When a packet comes into the service provider edge, a router assigns a tag to the packet based on the destination IP network. The tag is a type of shorthand for a traditional IP-based route. After the tag is applied, the router forwards the packet into the MPLS core. The core routers read the label, apply the appropriate services, and forward the packet based on the label. As soon as the packet reaches the destination edge of the service provider network, the MPLS label is removed, and the IP packet is forwarded onto the IP network. One of the MPLS services that service providers offer is virtual private networks. Using MPLS labels, service providers can deliver IP-based services to many customers without the complexity of traditional Frame Relay or ATM circuit management. Customers can use private or public IP addressing without concern about overlapping other customer addressing. another opportunity of MPLS is because MPLS provides any-to-any connectivity. MPLS is divided into two layers or planes, each having a specific function in the network. The layers are the Control plane and the Data plane. The Data plane handles forwarding operations. The Control plane is responsible for the exchange of routing information (including labels) between adjacent devices.



Equipment and Stuff



Three primary equipment in MPLS are:


  1. CPE: This is equipment on the customer site. All traffic leaving the local site is routed through this point. This is often called customer equipment (CE).

  2. PE: Located at the ingress point of the SP network, this is the equipment that assigns (and removes) labels. The PE can either be routers or high-end switches. This is also referred to as the Edge Label Switch Router (ELSR).

  3. P: Located in the core of the SP network, provider (P) routers forward packets based on their labels. This is also called a Label Switch Router (LSR).



MPLS Labels


MPLS uses a label to decide where and how to send packets through the network. The label is applied at the ingress to the SP network and is removed at the network egress point. The only router responsible for adding the label is the network router that needs to process the entire packet header. The information contained in the header, along with the preconfigured instructions, is used to generate the label. Labels can be based on IP destinations (this is what traditional routing uses) and other parameters, such as IP sources, QoS, VPN membership, or specific routes for traffic engineering purposes. MPLS is also designed to support forwarding mechanisms from other protocols. Label information is distributed throughout the network using the Label Distribution Protocol (LDP). The

label assigned essentially keeps that packet separated from all other customers’ packets/cells. Because there is no place where one customer can view another customer’s packet/cells, there is no danger of having someone outside the SP network snoop for packets. Obviously this would not stop someone bent on illegally accessing a company’s information, but it does remove the possibility of someone claiming that he “accidentally” received the information.


MPLS router forward packets by using the label, but the router must know the relationship between a label and path through the network. This relationship is established and communicate throughout the network using Forwarding Equivalence Classes (FEC). A FEC is a specific path through the network of LSRs and is equal to the destination network, stored in an IP routing table. The LSRs simply look at the label and forward the packet based on the contents of the FEC. This is much simpler, faster, and more flexible than traditional IP routing.




Read more...

Campus Network Herarchical Design

Over time, the hierarchical approach in designing a network has proven as the most effective. The goal in designing a Campus network is to divide buildings, floors, workgroups, and server farms into different layer 3 groups to prevent network faults from effecting a large scale of the network. The layers in a hierarchical design are:



  • Core: The core is the central thoroughfare for corporate traffic. All other parts of the network eventually feed into the core. You should design the core to switch packets as quickly as possible. This level should not include operations that might slow the switching of the packet: The distribution layer should handle any packet manipulation or filtering that needs to occur.


  • Distribution: The distribution layer should provide policy-based connectivity between the access layers and the core layer. It is at this layer that packets should be filtered or manipulated. Therefore as the packets are routed to the core, the core just simply needs to switch them quickly to the destination distribution location.


  • Access: The access layer provides user access to the network. It is at this point that users are permitted (or denied) access into the corporate network. Typically, each person sitting at a desk has a cable that runs to a wiring closet and connects to a switch; hence, this level is where the user accesses the network.






When correctly designed, a campus network can enhance business efficiency and lower operational cost. Additionally, a properly designed network can position a business for future growth. A modular or hierarchal network is made from building blocks that are easier to replicate, redesign, and grow. Each time a module is added or removed, there shouldn’t be a need to redesign the whole network. Distinct blocks can be put into and out of service without impacting other blocks

or the network core. This greatly enhances troubleshooting, isolating problems, and network management.




Campus Design Best Practices




  • Redundancy, redundancy is a key of a highly available network. However, too much redundancy can actually be a bad network. It causes the network to hard to reach convergence, and also it is hard to troubleshoot and manage the network.



  • High availability, this refer to the ability of the network to recover from failures. High availibility should be design at many layers.

    • Layer 1: Redundant links and hardware providealternative physical paths through the network.

    • Layers 2 and 3: Protocols such as spanning tree,HSRP, and others provide alternative path awareness and fast convergence.

    • Application availability: The application server and client processes must support failover for maximum availability.





  • Oversubscription, Oversubscription occurs when there are more trafficgenerating endpoints than the network can accommodate at a single time. QoS

    should be used to ensure that real-time traffic such as voice and video, or critical data such as SAP traffic, is not dropped or delayed.





Read more...
top