. , , ,

,,,

- — ,

1.

( 100 ) IT . . , , , . , ( , ..).

CorpKAM.

 


2.

 

2.1

 

2.1.1


.1 CorpKAM

( ) :

-  Manufacture (M) B;

-  Research (R) C;

:

1 . :

-  Human Resource (HR);

-  Sales (S);

-  Information Technologies (IT).

2 . :

-  Executive (E);

-  Accounting (Acc);

-  Business (Bus).

3, 4, 5 , :

3 . Project 1 (P1);

4 . Project 2 (P2);

5 . Project 3 (P3).

2- .

B:

- , , 1, - 2. , Production (P). Manufacture (M) ( ) , , 1.

:

Internet , ADSL. Research , 1 Research 1 (R1), 2 Research 2 (R2).

, ISDN. SOHO, PSTN Dial-up 56 /.



2. CorpKAM

2.1.2

, N=5.

(1, ISDN, ASDL) .

.

- Ethernet 100/1000BASE-T ( cat5 ) FDDI.

, .

IP_ (Public_IP) 131.107..0/24, =50*G+N G={1, 2, 3} , N- . , x=50*1+5=55 131.107.55.0/24.

(Private_IP) ICANN 10.55.0.0/16

K = 5, L = 1, N = 5, G = 1.

1

Project 1 Project 2 Project 3
() , . . . . . . . .
1 20 10
4 13 16
5 9 17

3 Manufacture.

2 Manufacture

Manufacture
() . ,
M1 25 10
M2 16 22
P 10 37

4 Research

Res 1 Res 2
() , . . .
1 9 20
2 6 10

5

Human Resource, IT gr., Sales Manag. Accounting Business
() , . . . . . . . . . . .
5 5 8 4 13 3 7

VPN-L2TP/IPSec, 3Com.

:

-  Active Directory;

-  Web FTP CorpKAM , (intranet) ;

-  , Web FTP-;

-  ;

-  , Research;

-  ;

-  IPSec;

-  VPN;

-  (ASDL/ISDN);

-  WLAN;

-  (*);

-  , (*);

-  , (*);

-  .

* - ( ) .


 

3.

, , , .

 

3.1

, . , , :

- ;

- , ;

- (4 /);

- , 7 22 , , 50% 1,5*22*4=132 . , , 4 , , 30 .

- , .

, .

 

3.1.1 ()

( ), . , , ( ). , . , . , , ( ).

, , . .

, , . , , . , , , ( 1).

1. 1

1 2 X Y , N*M , W L , . W L . 3.1.2 .

:

(1)

, 0 ( ) (N+M) ( ).

( 2). . (N+M)/2, :

(2)

, , , (N+M) 1.5*(N+M) .


2. 2 .

, , 1.

(1) (2) ,

, , N+M 2Z, Z.

. , , Z 11-12 . , Z 15-17 ( 25-30 % , , , . .).

X, Y Z , , .

, , UTP cat5. X+Y<=90. UTP cat5 100, IEEE 90 . ( , ) X+Y=90. , ,

(3)

(3) , , , , . ,


(4)

1) , (1). Z=(N+M)/2. Z<15, Z=15.

2) , , (4).

 

3.1.2 ()

, (1-2 ), . , , , . , , .

, . .

, , , . , , , , , , . , . , .

, , , ( , ). 3 .

3.

1 2. 2W*2L. , .

1) , . , Z=(N+M)/2, UTP cat5 (. 3.1.1), (. 3.1.1). , Z=15 (. 3.1), ,

(5)

(5) , W+L=120, . . , UTP cat5, W 105 (120-105=15 ). UTP cat5 90 . , W, .

, . , . , , 15 . 20, B 25, 9. , , (. 3.1). , A 20*225=4500 2, 25*225=5625 2, 9*225=2025 2.

2) , . . , . . , .

3.1.3

. , (5), , W,L<=90 W+L<=120. 4WL. , .

: S=4500 2, , 50*90. , W=90/2=45 L=50/2=25. W+L=70<=120 , , .

, . , 20*180, W=20/2=10, L=180/2=90. W+L=100<=120 , .

B: S==5625 2, , 45*125. , W=125/2=62,5 L=45/2=22,5. W+L=85<=120 , , .

, . , 90*62,5, W=90/2=45, L=62,5/2=31,25. W+L=96,25<=120 , .

: S=2025 2. , .

, UTPcat5 . , , .

, . 3.1.1-3.1.2, :

- 50*90 2, 5;

- 45*125 2, 3;

- 27*752, 2.

 

3.2

 

3.2.1

Ethernet 100/1000Base TX FDDI. FDDI , , , , .

Ethernet 100Base TX. , .

, , , + 50% , Ethernet 100Base-TX, Ethernet 1000Base-TX. , . , (, ), , UTP cat5, ( 10-15 ) .

, . , , 120 550 ( 50%). , 3- , . 1000 /, , , . , , , . , , ( PortTrunking ). , .

, , 1000 /. , .

. 3- , , . 1000 / .

WiFi.


 

3.2.2

3Com, Internet www.levovosd.ru www.apitcom.ru. , . (, , , , ..) , () . ( ADSL,T1,Dial-Up .), .

3COM Switch 4210 26-Port. 24 Ethernet 100 / 2 1000 /. ( Web-), QoS. 2- 1000 /, , . PortTrunking, . VLAN.

Baseline Switch 2916-SFP Plus. 2- , 256 VLAN , Port Trunking 8- 8 . , 14. , , .

, , 3Com Switch 8800 48-Port 10/100/1000BASE-T IPv6. 3-, VLAN, . RIP, OSPF, IGMP, PIM(SM,DM), VRRP, BGP4, IS-IS. .

( ) 2U HP ProLiant DL380 G5. , .

APC SUA3000RMI2U. 3000 . . , , , . .

IBM PC, . 1000-1500$.

 

3.3

2 : , , .

, , GNU- . , . , .

, , 98, NT Prof, XP Prof, 2000 Prof. , XP Prof, . OpenOffice.org 3.0, GNU MS Office. OpenWebMail (http://openwebmail.org/). , , .

Windows 2003 Server. : Web, Datacenter, Enterprice, Standart. Web Datacenter , . Enterprice Statndart :

- Itanium;

- ;

- ;

- ;

- ;

- .

, , , Windows 2003 Server Standart Edition. , .


 

4.

, (DNS, AD, DHCP).

 

3.1 IP

IP ( DHCP)

 

3.1.1 IP

5 . 2 , 3, 4 5- . IP , 1,2 5.

, , , 1- . , 10.55.0.0/16.

6 IP

( 50%) IP IP
1 (Human Resource) 40(60) 64(10.55.0.192/26) 256
1 Sales (S) 40(60) 64(10.55.0.128/26)
1 IT 40(60) 64(10.55.0.64/26)
1 30(45) 64(10.55.0.0/26)
2 Executive (E) 15(23) 32(10.55.1.0/27) 192
2 Accounting (Acc) 52(78) 128(10.55.1.128/25)
2 Business (Bus) 21(32) 32(10.55.1.32/27)
3 Project 1 (P1) 200(300) 512(10.55.2.0/23) 512
4 Project 2 (P2) 208(312) 512(10.55.4.0/23) 512
5 Project 3 (P3) 153(230) 256(10.55.6.0/24) 256

10.55.1.96/26 (64 ) 10.55.7.0/24 (256 ). B C.

. , , , , . , .

C , DNS, FTP, RAS/VPN, Mail, Web IP ( MAC IP , DHCP). DHCP (, ) IP , . , .

FireWall- 131.107.55.0/24(256 ). firewall- , Internet ADSL , ISDN, , ( WireWall-, internet NAT), .

 

3.1.2 IP B

B 1 1,544 /, , .

7 IP

( 50%) IP IP
3 M1 250(375) 512(10.55.8.0/23) 1568
2 M2 352(528) 512(10.55.10.0/23)
1 P 370(555) 512(10.55.12.0/23)
1 15(45) 32(10.55.14.0/27)

10.55.14.0.0/23 (512 ), 10.55.14.0/27 (32 ) B.

, DNS, DHCP, , .

 

3.1.3 IP

B ADSL, 6,1 / , , .

7 IP C

( 50%) IP IP
1 R1 180(240) 256(10.55.16.0/24) 256
2 R2 60(90) 256(10.55.17.0/24) 288
2 15(45) 32(10.55.18.0/27)

10.55.18.0/24 (256 ), 10.55.18.0/27 (32 ) C.

C , DNS, DHCP, , .

 

3.2 DNS

AD, DNS DHCP , AD DNS, . , DNS AD, .

Active Directory, DNS. , . . DNS (split-brain DNS). DNS , . , .

DNS , 2 DNS, . , ( ) Internet.

DNS, , DNS, IP-, . DNS-; , IP-, .

DNS Intranet (firewall), DNS (DMZ) Internet. DNS, . Internet- DNS-. , Internet Intranet, . DNS- Internet, , DNS-. DNS , .

DNS AD . -, AD DNS . -, . , AD . DNS .

CorpKAM . , corpkam.ru. WAN, corpkam.ru. : manuf. corpkam.ru. res.corpkam.ru B C.

, DNS- AD Windows 2003 Enterprice Server. (Secondary), . , , .

, DNS- . , DNS- , , . ( DMZ) , . DNS , DNS- , , .

DNS- forwarder DNS-, DNS- DNS , DNS-, (root-hints). , , .

DNS 3 DNS-: , . main. corpkam.ru ( ), proj.corpkam.ru ( Active Directory). forwarding- , , . DNS-, , DNS- .

DNS- B DNS- A.

C , B DNS- , DNS- C - (stub-zone). , , DNS-, . DNS-, , .

, DNS- C stub-zone A B. forwarder-DNS DNS- .

DNS- Dynamic DNS Updates, , . ADIZ, (secure updates). AD , DNS.

 

3.3 WINS

, Windows 98, NetBIOS. DNS NetBIOS. WINS.

WINS 10-15 . NetBIOS 16- , . 15 16- , , , , . WINS NetBIOS IP-. NT 4, , WINS, NetBIOS IP-. 2 WINS-, WINS-.

WINS DNS NetBIOS. DNS WINS. DNS WINS ( WINS), DNS WINS , .

WINS . , AD , , , .

 

3.4 DHCP

, TCP/IP, IP-. DHCP (Dynamic Host Configuration Protocol, ) IP-. DHCP , TCP/IP. TCP/IP ( , DNS-).

DHCP : DHCP- DHCP-. DHCP DHCP- TCP/IP. DHCP , IP- . . , . DHCP . IP- . IP- DHCP- TCP/IP, , DNS WINS.

Windows Server 2003 DHCP- ( ), DHCP- ( ).

DHCP , , . , DHCP , IP , , ( , 3 ), , DHCP, RFC 1542. DHCP (DHCP Relay Agent) DHCP. DHCP , DHCP/BOOTP DHCP-. DHCP . DHCP DHCP-, DHCP- .

Baseline Switch 2916-SFP Plus RFC 1542, ( ). IP , .

2 DHCP- .

DHCP- , (. . scopes). DHCP , IP- DHCP . , DHCP, , DHCP . , DHCP DHCP TCP/IP.

9 . HR, Sales, IT, Exec, Bus, Acc, Project 1, Project 2 DHCP-, Project 3 . 80/20 , Microsoft.

DHCP :

- (start IP address);

- (End IP address);

- (Subnet mask length);

- (Exclusions)

- (Reservation).

DHCP- HR ( 10.55.0.192/26): 10.55.0.192, - 10.55.0.255. 26 ( , 255.255.255.192), : 10.55.4.1 10.55.4.10.

B DHCP- M1 M2, P. 80/20, .

C (scopes) R1 R2.

DHCP . - , DHCP. , DHCP- Active Directory. DHCP Active Directory, IP DHCP. , DHCP .


3.5 Active Directory(AD)

Active Directory Windows 2003 Server. Active Directory , , . , , , , , , , , , , , (object). Active Directory Windows 2003 Server :

- ;

- ;

- ;

- .

Active Directory . Windows 2003.

Active Directory , , OU ( , ). . Active Directory DNS.

10 . , . , Active Directory.

. , .

. , .

. , .

, ( ; ; ; , ), Active Directory CorpKAM . .

, , . , , . . ( , ), Domain Admins, Schema Admins, Enterprise Admins. , . , , . .

. 2 ( B C), .

. . , . .

, , . , .

, 2 . , .

corpKAM.ru. (main.corpkam.ru), B (manuf.corpkam.ru) C (res.corpkam.ru). (, ). . , , proj.corpkam.ru.

Active Directory, (), :

- ;

- ;

- ;

- ;

- .

. , A 9 , B 3 , C 2 . (proj.corpiso.ru) .

Active Directory. . Active Directory, IP-, . .

3 LAN ( ), WAN, . , . . Active Directory . A 3 : , A . B C .

, , , WAN. . , .

, . . . . . . .

AD , .

(Schema Master) , . Schema Admins. , . . , . . .

(Domain Naming Master) . , , / - . Enterprise Admins, , , . , . , . . , , , . . .

PDC (PDC Emulator) ( Windows 2000), , , . , master browser , NetBIOS. AD, . , , .

, PDC PDC , PDC .

(Relative Identifier Master) , RID , : DN SID, ID . , , , , .

(Infrastructure Master) AD. , GUID DN SID. , .

, , . , , , , , . , , . , , .

, : - , . . PDC .

, AD. Windows 2003 multi-master ( ), , Active Directory. , Windows 2003 Active Directory, , , site links ( ) . Active Directory . , , . connection objects (-). , , Knowledge Consistence Checker (KCC - : ). 15 -, (, - ).

:

1)  RPC over IP Remote Presage Call over IP , , .

2)  SMTP- , ,

Active Directory , , .

Active Directory . , .

. Active Directory , .

 

3.6 (WLAN)

WLAN.

WLAN (Wireless Local Area Network). Wi-Fi. IEEE 802.11, , , , a, b, g n. , , IEEE 802.11g, 54 /. WiFi .

Windows Server 2003 MS-CHAP v2, , MPPE (Microsoft Point-to-Point Encryption) . , MS-CHAP. MS-CHAP v2 , MS-CHAP, ( ), MS-CHAP. MS-CHAP v2 , Windows XP, Windows 2000, Windows 98, Windows Millennium Edition Windows NT 4.0. , Windows 95, MS-CHAP v2 VPN, .

- EAP-MS CHAP V2, , .

WiFi 3CRWE454G75. IEEE 802.11g WPA, EAP, , MS CHAP V2.

 

3.7 DMZ

DMZ , , , . DMZ . , , , .

DMZ :

- DMZ: Mail, Web, ftp, DNS RAS;

- ( );

- DMZ ( , ).

Mail, Web ftp , GNU( ). , FreeBSD, . , . , Web Apach PHP MySQL PostgreSQL. . .

DMZ , , . Mail ftp, Web .

RAS Windows Server 2003, . FreeBSD . , DNS AD, OC Windows 2003 Server.

. . . ( ) . , , . , .

1) 2 firewall- DMZ , - DMZ

2) : . , DMZ .

:

- . , DMZ, ;

- , , ;

- .

, . 1 2, . . , , WAN DMZ, .

firewall. firewall FreeBSD, firewall Smoothwall. . NAT(. 3.7.1), FireWall-a.

, DMZ, :

- 5 ;

- 1 ;

- 5680 OfficeConnect ADSL Wireless.

 

3.7.1 IP , NAT

NAT . WAN, DMZ.

DMZ IP . Dial-Up (. 3.7.3) NAT firewall. IP firewall, .

 

3.8

, CorpKAM , , A.

 

3.8.1 1

, . T1. DNS, , . B 5680, T1. .

T1 - PDH - , , ISDN. T1 OSI: , . T1, T1.

( 64 / ) T1, T1, .. , T1 , . . T1 . T1.

: HDB3 (), AMI.

, , /
(Tx) (DSx)Jx (Ex)
1 () T1 1544 (24 ) 1544 (24 ) 2048 (30 64kbps)
2 () T2 6312 (96 ) 6312 (96 ) 8448 (120 64kbps)
3 () T3 44736 (672 ) 32064 (480 ) 34368 (480 64kbps)
4 () - T4 274176 (4032 ) 97728 (1440 ) 139264 (1920 64kbps)
5 () * * 397200 564992

, , . , VPN .

 

3.8.2 ADSL

Research ( C) Internet , ADSL. OfficeConnect ADSL Wireless , FreeBSD PPPD. , , Smoothwall. VPN- WPA/WPA2 128- bit TKIP/AES wireless encryption, 40/64-bit 128-bit WEP . , A C, VPN-.

ADSL (Asymmetric Digital Subscriber Line - ) , DSL (Digital Subscriber Line - ) xDSL.


4. ADSL

ADSL - "" (.. , ) , "" ( ).

ADSL ( ). . (Echo Cancellation), "" "" ( 5) .

5.

VPN, .3.8.4.

3.8.3 ISDN

ISDN (Integrated Services Digital Network). ISDN 64 / ( B-) (D-).

"B" (Bearer) - , , c 64 /. "", .. , , D-.

"D" (Delta) - 16 (BRI) 64 (PRI) /. "D" 2 30 () - , , .

BRI (Basic Rate Interface) - 144 / (EuroISDN); "B" "D". BRI ISDN-. (multiple subscriber numbers). ISDN , BRI- - .

BRI, ISDN, , , - U-.

PRI (Primary Rate Interface) - B- (, - 30 - 2,048 /). BRI, . , , c ISDN, PRI BRI-. PRI- (SDSL) (HDSL) .

, ISDN :

-  ( 1 10 );

-  , , ;

-  8 (, , , .), , ;

-  , ;

-  - 128 / , 51200 / ( );

-  ( (CLIP), (MSN), -, , 3- ..).

64 /c ( , ), :

-  ;

-  ISDN- 64 /c;

-  ISDN- 128 /c ( ).

:

-  ISDN , , , , - ;

-  ISDN , ( ), ( , - DDR) ( "") 64 128 /c;

-  ISDN- , ;

-  .

VPN, .3.8.4.

 

3.8.4 Dial-Up

SOHO, Dial-up. VPN RAS Windows 2003 Server, . ( ), VPN- ( ).

VPN (Point-to-Point Protocol), (Point-to-Point Tunneling Protocol) L2TP (Layer 2 Tunneling Protocol). IPSec L2TP, , PPTP.

VPN- :

-  VPN- - , VPN- VPN.

-  VPN- - , VPN- VPN. VPN- .

-  - , . . VPN-, , .

-  VPN- - , .

-  - , . WS2003 PPTP L2TP.

-  - , -.

-  - , . WS2003 IP. IP-.


6. VPN-

:

L2TP , IP-, IP- IP- . , , .

IPSec (IPSec ) IP- IP-, IP- IP- .

IPSec TM VPN- , , IP- . IPSec TM VPN- WS2003.

PPTP (Point-to-Point Tunneling Protocol) PPP , . PPTP MPPE (Microsoft Point-to-Point Encryption) . PPP MPPE , MS-CHAP, MS-CHAP v2 EAP-TLS.

PPP, IP - GRE (Generic Routing Encapsulation) IP. IP- VPN- VPN-.

7. PPP

L2TP (Layer Two Tunneling Protocol) RFC, . L2TP , IPSec. L2TP IPSec L2TP/IPSec. L2TP/IPSec VPN, .

8. L2TP

L2TP/IPSec .

1. L2TP - PPP (IP- IPX-) L2TP UDP.

2. L2TP- IPSec ESP (Encapsulating Security Payload), IPSec, , IP. IP- VPN- VPN-.

L2TP DES 3DES , IKE (Internet Key Exchange).

L2TP/lPSec

1)  IPSec ESP , , (). , .

2)  L2TP/IPSec , , .

3)  L2TP/IPSec , , , - IPSec. - - ;

4)  L2TP\IPSec . , . , . (Connection Manager).

L2TP/IPSec

1)  . L2TP/IPSec VPN- VPN-. .

2)  (NAT), NAT -. VPN-, L2TP/IPSec, NAT-, VPN .

, VPN- :

- ;

- ;

- .

, , , . : , . :

- , VPN- ;

- Active Directory, .

Active Directory. , . .

CorpKAM VPN L2TP\IPSec c , , , VPN.

 

3.9

QoS. , , QoS .

 


5.

CorpKAM. . 3Com, /. , .

.

, Active Directory. , , . , .

DNS Active Directory. DNS-. DNS WAN.

. VPN L2TP\IPSec.

1. ( 100 ) IT .

 

 

 

! , , , .
. , :