1
1

00:00:00,068  -->  00:00:01,970
<v ->Recovery sites.</v>
2

2

00:00:01,970  -->  00:00:04,320
In this lesson, we're going to discuss the concept
3

3

00:00:04,320  -->  00:00:05,870
of recovery sites.
4

4

00:00:05,870  -->  00:00:08,270
After all things are going to break and your networks
5

5

00:00:08,270  -->  00:00:09,440
are going to go down.
6

6

00:00:09,440  -->  00:00:11,260
This is just a fact of life.
7

7

00:00:11,260  -->  00:00:13,490
So what are you going to do when it comes time
8

8

00:00:13,490  -->  00:00:15,570
to recover your enterprise network?
9

9

00:00:15,570  -->  00:00:18,280
Well, that's what we're going to discuss in this lesson.
10

10

00:00:18,280  -->  00:00:20,240
When it comes to designing redundant operations
11

11

00:00:20,240  -->  00:00:21,080
for your company,
12

12

00:00:21,080  -->  00:00:23,250
you really should consider a recovery site.
13

13

00:00:23,250  -->  00:00:26,010
And with recovery sites, you have four options.
14

14

00:00:26,010  -->  00:00:28,000
You see, you can have all the software and hardware
15

15

00:00:28,000  -->  00:00:29,100
redundancy you want.
16

16

00:00:29,100  -->  00:00:30,140
But at the end of the day,
17

17

00:00:30,140  -->  00:00:33,370
sometimes you need to actually recover your site too.
18

18

00:00:33,370  -->  00:00:35,320
Now this could be because there's a fire that breaks out
19

19

00:00:35,320  -->  00:00:37,650
in your building or a hurricane or earthquake.
20

20

00:00:37,650  -->  00:00:40,050
All of these things might require you to relocate
21

21

00:00:40,050  -->  00:00:42,240
and if you do, you're going to have to choose
22

22

00:00:42,240  -->  00:00:43,510
one of four options.
23

23

00:00:43,510  -->  00:00:46,550
This could be a cold site, a warm site, a hot site
24

24

00:00:46,550  -->  00:00:47,900
or a cloud site.
25

25

00:00:47,900  -->  00:00:49,560
Now when we deal with cold sites,
26

26

00:00:49,560  -->  00:00:51,220
this means that you have a building that's available
27

27

00:00:51,220  -->  00:00:52,053
for you to use,
28

28

00:00:52,053  -->  00:00:54,690
but you don't have any hardware or software in place.
29

29

00:00:54,690  -->  00:00:57,260
And if you do, those things aren't even configured.
30

30

00:00:57,260  -->  00:00:59,750
So you may have to go out to the store and buy routers
31

31

00:00:59,750  -->  00:01:01,450
and switches and laptops and servers
32

32

00:01:01,450  -->  00:01:02,750
and all that kind of stuff.
33

33

00:01:02,750  -->  00:01:04,950
You're going to bring it to a new building, configure it
34

34

00:01:04,950  -->  00:01:06,500
and then restore your network.
35

35

00:01:06,500  -->  00:01:08,650
This means that while recovery is possible,
36

36

00:01:08,650  -->  00:01:11,370
it's going to be slow and it's going to be time consuming.
37

37

00:01:11,370  -->  00:01:13,840
If I have to build you out a new network and a cold site,
38

38

00:01:13,840  -->  00:01:15,790
that means I'm going to need you to bring everything in
39

39

00:01:15,790  -->  00:01:17,650
after the bad thing has already happened,
40

40

00:01:17,650  -->  00:01:19,240
such as your building catching fire.
41

41

00:01:19,240  -->  00:01:21,290
And this can take me weeks or even months
42

42

00:01:21,290  -->  00:01:23,430
to get you fully backing up and running.
43

43

00:01:23,430  -->  00:01:25,620
Now, the biggest benefit of using a cold site
44

44

00:01:25,620  -->  00:01:27,170
is that it is the cheapest option
45

45

00:01:27,170  -->  00:01:28,530
that we're going to talk about.
46

46

00:01:28,530  -->  00:01:31,350
The drawbacks are that it is slow and essentially
47

47

00:01:31,350  -->  00:01:33,070
this is just going to be an empty building
48

48

00:01:33,070  -->  00:01:35,920
that's waiting for you to move in and start rebuilding.
49

49

00:01:35,920  -->  00:01:37,960
Now next, we have a warm site.
50

50

00:01:37,960  -->  00:01:40,390
A warm site means you have the building available
51

51

00:01:40,390  -->  00:01:43,000
and it already contains a lot of the equipment.
52

52

00:01:43,000  -->  00:01:44,650
You might not have all your software installed
53

53

00:01:44,650  -->  00:01:46,860
on these servers or maybe you don't have the latest security
54

54

00:01:46,860  -->  00:01:49,440
patches or even the data backups from your other site
55

55

00:01:49,440  -->  00:01:51,050
haven't been recovered here yet.
56

56

00:01:51,050  -->  00:01:52,990
But you do already have the hardware
57

57

00:01:52,990  -->  00:01:54,640
and the cabling in place.
58

58

00:01:54,640  -->  00:01:55,640
With a warm site,
59

59

00:01:55,640  -->  00:01:57,590
we already have a network that's running the facility.
60

60

00:01:57,590  -->  00:01:59,740
We have switches and routers and firewalls.
61

61

00:01:59,740  -->  00:02:01,570
But we may not maintain it fully
62

62

00:02:01,570  -->  00:02:03,170
each and every day of the year.
63

63

00:02:03,170  -->  00:02:05,220
So, when a bad event happens
64

64

00:02:05,220  -->  00:02:07,080
and you need to move into the warm site,
65

65

00:02:07,080  -->  00:02:09,010
we can load up our configurations on our routers
66

66

00:02:09,010  -->  00:02:11,750
and switches, install the operating systems on the servers,
67

67

00:02:11,750  -->  00:02:13,160
restore the files from backup
68

68

00:02:13,160  -->  00:02:14,880
and usually within a couple of days,
69

69

00:02:14,880  -->  00:02:16,720
we can get you back up and running.
70

70

00:02:16,720  -->  00:02:18,030
Normally with a warm site,
71

71

00:02:18,030  -->  00:02:20,650
we're looking to restore the time between 24 hours
72

72

00:02:20,650  -->  00:02:21,940
and seven days.
73

73

00:02:21,940  -->  00:02:23,480
Basically, under a week.
74

74

00:02:23,480  -->  00:02:25,320
Recovery here is going to be fairly quick,
75

75

00:02:25,320  -->  00:02:27,280
but not everything from the original site
76

76

00:02:27,280  -->  00:02:29,610
is going to be there and ready for all employees
77

77

00:02:29,610  -->  00:02:31,060
at all times.
78

78

00:02:31,060  -->  00:02:33,570
Now, if speed of recovery is really important to you,
79

79

00:02:33,570  -->  00:02:36,340
the next type of site is your best choice.
80

80

00:02:36,340  -->  00:02:38,050
It's known as a hot site.
81

81

00:02:38,050  -->  00:02:40,280
Now hot site is my personal favorite.
82

82

00:02:40,280  -->  00:02:43,050
But it's also the most expensive to operate.
83

83

00:02:43,050  -->  00:02:46,010
With a hot site, you have a building, you have the equipment
84

84

00:02:46,010  -->  00:02:48,560
and you have the data already on site.
85

85

00:02:48,560  -->  00:02:51,120
That means everything in the hot site is up and running
86

86

00:02:51,120  -->  00:02:52,240
all the time.
87

87

00:02:52,240  -->  00:02:54,340
Ready for you to instantly switch over your operations
88

88

00:02:54,340  -->  00:02:56,350
from your primary site to your hot site
89

89

00:02:56,350  -->  00:02:57,960
at the flip of a switch.
90

90

00:02:57,960  -->  00:03:00,020
This means you need to have the system and network
91

91

00:03:00,020  -->  00:03:02,300
administrators working at that hut site every day
92

92

00:03:02,300  -->  00:03:04,870
of the year, keeping it up and running, secured
93

93

00:03:04,870  -->  00:03:07,250
and patched and ready for us to take over operations
94

94

00:03:07,250  -->  00:03:08,670
whenever we're told to.
95

95

00:03:08,670  -->  00:03:11,480
Basically, your people are going to walk out of the old site,
96

96

00:03:11,480  -->  00:03:14,440
get in their car, drive to the new site, login
97

97

00:03:14,440  -->  00:03:17,160
and they're back to work as if nothing ever happened.
98

98

00:03:17,160  -->  00:03:19,560
This is great because there's very minimal downtime.
99

99

00:03:19,560  -->  00:03:21,880
And you're going to have nearly identical levels of servers
100

100

00:03:21,880  -->  00:03:23,950
at the main site in the hut site.
101

101

00:03:23,950  -->  00:03:27,130
But as you can imagine, this costs a lot of money.
102

102

00:03:27,130  -->  00:03:28,580
Because I have to pay for the building,
103

103

00:03:28,580  -->  00:03:31,090
two sets of equipment, two sets of software licenses
104

104

00:03:31,090  -->  00:03:33,090
and all the people to run all this stuff.
105

105

00:03:33,090  -->  00:03:35,710
You're basically running two sites at all times.
106

106

00:03:35,710  -->  00:03:38,500
Therefore, a hot site gets really expensive.
107

107

00:03:38,500  -->  00:03:40,350
Now a hot site is very critical
108

108

00:03:40,350  -->  00:03:42,940
if you're in a high availability type of situation.
109

109

00:03:42,940  -->  00:03:45,280
Let's say you work for a credit card processing company.
110

110

00:03:45,280  -->  00:03:48,210
And every minute they're down cost them millions of dollars.
111

111

00:03:48,210  -->  00:03:49,560
They would want to have a hot site, right.
112

112

00:03:49,560  -->  00:03:51,430
They don't want to be down for three or four weeks.
113

113

00:03:51,430  -->  00:03:53,160
So they have to make sure they have their network up
114

114

00:03:53,160  -->  00:03:54,700
and available at all times.
115

115

00:03:54,700  -->  00:03:56,110
Same thing if you're working for the government
116

116

00:03:56,110  -->  00:03:56,970
or the military,
117

117

00:03:56,970  -->  00:03:58,830
they always need to make sure they're operating
118

118

00:03:58,830  -->  00:04:00,450
cause otherwise people could die.
119

119

00:04:00,450  -->  00:04:02,240
And so they want to make sure that is always up and running.
120

120

00:04:02,240  -->  00:04:03,930
That's where hot sites are used.
121

121

00:04:03,930  -->  00:04:06,180
Now if you can get away from those type of criticality
122

122

00:04:06,180  -->  00:04:08,850
requirements though, which most organizations can.
123

123

00:04:08,850  -->  00:04:11,220
You're going to end up settling on something like a warm site,
124

124

00:04:11,220  -->  00:04:13,070
because it's going to save you on the cost of running
125

125

00:04:13,070  -->  00:04:15,110
that full recovery hot site.
126

126

00:04:15,110  -->  00:04:16,650
Now the fourth type of site we have
127

127

00:04:16,650  -->  00:04:18,320
is known as a cloud site.
128

128

00:04:18,320  -->  00:04:21,160
Now a cloud site isn't exactly a full recovery site,
129

129

00:04:21,160  -->  00:04:23,470
like a cold warm or hot site is.
130

130

00:04:23,470  -->  00:04:25,510
In fact, there may be no building for you to move
131

131

00:04:25,510  -->  00:04:26,810
your operations into.
132

132

00:04:26,810  -->  00:04:29,690
Instead, a cloud site is a virtual recovery site
133

133

00:04:29,690  -->  00:04:31,350
that allows you to create a recovery version
134

134

00:04:31,350  -->  00:04:33,970
of your organization's network in the cloud.
135

135

00:04:33,970  -->  00:04:36,740
Then if disaster strikes, you can shift all your employees
136

136

00:04:36,740  -->  00:04:39,550
to telework operations by accessing that cloud site.
137

137

00:04:39,550  -->  00:04:43,160
Or you can combine that cloud site with a cold or warm site.
138

138

00:04:43,160  -->  00:04:44,920
This allows you to have a single set of system
139

139

00:04:44,920  -->  00:04:46,580
administrators and network administrators
140

140

00:04:46,580  -->  00:04:48,480
that run your day to day operational networks
141

141

00:04:48,480  -->  00:04:51,010
and they can also run your backup cloud site.
142

142

00:04:51,010  -->  00:04:52,190
Because they can operate at all
143

143

00:04:52,190  -->  00:04:54,120
from wherever they're sitting in the world.
144

144

00:04:54,120  -->  00:04:56,240
Now cloud sites are a good option to use,
145

145

00:04:56,240  -->  00:04:58,740
but you are going to be paying a cloud service provider
146

146

00:04:58,740  -->  00:05:00,950
for all the compute time, the storage
147

147

00:05:00,950  -->  00:05:03,910
and the network access required to use that cloud site
148

148

00:05:03,910  -->  00:05:06,970
before, during and after the disastrous event.
149

149

00:05:06,970  -->  00:05:09,920
So, which of these four options should you consider?
150

150

00:05:09,920  -->  00:05:12,880
Well, that really depends on your organization.
151

151

00:05:12,880  -->  00:05:15,360
It's recovery time objectives, the RTO
152

152

00:05:15,360  -->  00:05:18,000
and its recovery point objectives, RPO.
153

153

00:05:18,000  -->  00:05:20,620
Now the recovery time objective or RTO
154

154

00:05:20,620  -->  00:05:22,750
is the duration of time and service level
155

155

00:05:22,750  -->  00:05:25,520
within which a business process has to be restored
156

156

00:05:25,520  -->  00:05:28,690
after disaster happens in order to avoid unacceptable
157

157

00:05:28,690  -->  00:05:31,870
consequences associated with a breaking continuity.
158

158

00:05:31,870  -->  00:05:35,020
In other words, our RTO is going to answer our question,
159

159

00:05:35,020  -->  00:05:37,590
how much time did it take for the recovery to happen
160

160

00:05:37,590  -->  00:05:40,850
after the notification of a business process disruption?
161

161

00:05:40,850  -->  00:05:43,250
So, if you have a very low RTO,
162

162

00:05:43,250  -->  00:05:45,400
then you're going to have to use either a hot site
163

163

00:05:45,400  -->  00:05:47,670
or a cloud site because you need to get up and running
164

164

00:05:47,670  -->  00:05:48,510
quickly.
165

165

00:05:48,510  -->  00:05:50,940
That is the idea of a low RTO.
166

166

00:05:50,940  -->  00:05:53,640
Now on the other hand, we have to think about our RPO.
167

167

00:05:53,640  -->  00:05:55,640
Which is our recovery point objective.
168

168

00:05:55,640  -->  00:05:59,040
Now RPO is going to be the interval of time that might pass
169

169

00:05:59,040  -->  00:06:02,210
during the disruption before the quantity of data loss
170

170

00:06:02,210  -->  00:06:05,240
during that period exceeds the business continuity plans
171

171

00:06:05,240  -->  00:06:08,320
maximum allowable threshold or tolerance.
172

172

00:06:08,320  -->  00:06:10,610
Now RPO is going to determine the amount of data
173

173

00:06:10,610  -->  00:06:13,380
that will be lost or will have to be re-entered
174

174

00:06:13,380  -->  00:06:15,690
during network operations in downtime.
175

175

00:06:15,690  -->  00:06:18,470
It symbolizes the amount of data that can be acceptably lost
176

176

00:06:18,470  -->  00:06:20,110
by the organization.
177

177

00:06:20,110  -->  00:06:24,600
For example, in my company we have an RPO of 24 hours.
178

178

00:06:24,600  -->  00:06:27,470
That means if all of our servers crashed right now,
179

179

00:06:27,470  -->  00:06:30,870
I as the CEO have accepted the fact that I can lose no more
180

180

00:06:30,870  -->  00:06:34,430
than the last 24 hours worth of data and that would be okay.
181

181

00:06:34,430  -->  00:06:35,910
To achieve this RPO,
182

182

00:06:35,910  -->  00:06:38,980
I have daily backups that are conducted every 24 hours.
183

183

00:06:38,980  -->  00:06:41,370
So, we can ensure we always have our data backed up
184

184

00:06:41,370  -->  00:06:43,480
and ready for restoral at any time.
185

185

00:06:43,480  -->  00:06:47,750
And that means we will lose at most 24 hours worth of data.
186

186

00:06:47,750  -->  00:06:51,500
The RTO that recovery time objective is going to be focused
187

187

00:06:51,500  -->  00:06:53,870
on the real time that passes during a disruption.
188

188

00:06:53,870  -->  00:06:56,260
Like if you took out a stopwatch and started counting.
189

189

00:06:56,260  -->  00:06:58,280
For example, can my business survive
190

190

00:06:58,280  -->  00:07:00,010
if we're down for 24 hours?
191

191

00:07:00,010  -->  00:07:00,843
Sure.
192

192

00:07:00,843  -->  00:07:03,300
It would hurt, we would lose some money, but we can do it.
193

193

00:07:03,300  -->  00:07:04,560
How about seven days?
194

194

00:07:04,560  -->  00:07:06,310
Yeah, again, we would lose some money,
195

195

00:07:06,310  -->  00:07:07,840
we'd have some really angry students,
196

196

00:07:07,840  -->  00:07:09,320
but we could still survive.
197

197

00:07:09,320  -->  00:07:10,890
Now, what about 30 days?
198

198

00:07:10,890  -->  00:07:11,723
No way.
199

199

00:07:11,723  -->  00:07:13,990
Within 30 days all of my customers and students,
200

200

00:07:13,990  -->  00:07:14,970
they would have left me.
201

201

00:07:14,970  -->  00:07:16,090
They would take their certifications
202

202

00:07:16,090  -->  00:07:17,510
through some other provider out there
203

203

00:07:17,510  -->  00:07:18,950
and I would be out of business.
204

204

00:07:18,950  -->  00:07:22,540
So I had to figure out what my RTO someplace between one
205

205

00:07:22,540  -->  00:07:25,030
and seven days to make me happy.
206

206

00:07:25,030  -->  00:07:27,500
So that's the idea of operational risk tolerance,
207

207

00:07:27,500  -->  00:07:29,960
we start thinking about this from an organizational level.
208

208

00:07:29,960  -->  00:07:32,400
How much downtime are you willing to accept?
209

209

00:07:32,400  -->  00:07:34,900
Based on my ability to accept seven days,
210

210

00:07:34,900  -->  00:07:37,590
I could use a warm site instead of a hot site.
211

211

00:07:37,590  -->  00:07:40,180
But if I currently accept 24 hours of downtime
212

212

00:07:40,180  -->  00:07:41,730
or five minutes of downtime,
213

213

00:07:41,730  -->  00:07:44,160
then I would have to use a hot site instead.
214

214

00:07:44,160  -->  00:07:46,690
RTO is used to designate that amount of real time
215

215

00:07:46,690  -->  00:07:49,410
that passes on the clock before that disruption
216

216

00:07:49,410  -->  00:07:52,100
begins to have serious and unacceptable impedances
217

217

00:07:52,100  -->  00:07:54,560
to the flow of our normal business operations.
218

218

00:07:54,560  -->  00:07:56,980
That is the whole concept here with RTO.
219

219

00:07:56,980  -->  00:07:59,880
Now when we start talking about RPO and RTO,
220

220

00:07:59,880  -->  00:08:01,950
you're going to see this talked about a lot in backups
221

221

00:08:01,950  -->  00:08:03,360
and recovery as well.
222

222

00:08:03,360  -->  00:08:05,040
When you deal with backups and recovery,
223

223

00:08:05,040  -->  00:08:07,090
you a few different types of backups.
224

224

00:08:07,090  -->  00:08:09,860
We have things like full backups, incremental backups,
225

225

00:08:09,860  -->  00:08:12,120
differential backups and snapshots.
226

226

00:08:12,120  -->  00:08:14,360
Now a full backup is just what it sounds like.
227

227

00:08:14,360  -->  00:08:17,570
It's a complete backup of every single file on a machine.
228

228

00:08:17,570  -->  00:08:20,420
It is the safest and most comprehensive backup method,
229

229

00:08:20,420  -->  00:08:23,340
but it's also the most time consuming and costly.
230

230

00:08:23,340  -->  00:08:25,040
It's going to take up the most disk space
231

231

00:08:25,040  -->  00:08:26,490
and the most time to run.
232

232

00:08:26,490  -->  00:08:28,970
This is normally going to be run on your servers.
233

233

00:08:28,970  -->  00:08:30,420
Now another type of backup we have
234

234

00:08:30,420  -->  00:08:32,310
is known as an incremental backup.
235

235

00:08:32,310  -->  00:08:34,650
With an incremental backup, I'm going to back up the data
236

236

00:08:34,650  -->  00:08:36,590
that changed since the last backup.
237

237

00:08:36,590  -->  00:08:38,870
So, if I did a full backup on Sunday
238

238

00:08:38,870  -->  00:08:41,270
and I go to do an incremental backup on Monday,
239

239

00:08:41,270  -->  00:08:43,480
I'm only going to back up the things that have changed
240

240

00:08:43,480  -->  00:08:46,170
since doing that full backup on Sunday.
241

241

00:08:46,170  -->  00:08:48,930
Now another type we have is known as a differential backup.
242

242

00:08:48,930  -->  00:08:51,260
A differential backup is only going to back up the data
243

243

00:08:51,260  -->  00:08:53,320
since the last full backup.
244

244

00:08:53,320  -->  00:08:54,890
So, let's go back to my example
245

245

00:08:54,890  -->  00:08:56,530
of Sunday being a full backup
246

246

00:08:56,530  -->  00:08:59,130
and then I did an incremental backup on Monday.
247

247

00:08:59,130  -->  00:09:02,120
Then that backup is going to copy everything since Sunday.
248

248

00:09:02,120  -->  00:09:05,380
But if I do an incremental on Tuesday, it's only going to do
249

249

00:09:05,380  -->  00:09:07,590
the difference between Monday and Tuesday.
250

250

00:09:07,590  -->  00:09:10,460
Cause Monday was the last backup on the incremental backup.
251

251

00:09:10,460  -->  00:09:11,330
When I do it Wednesday,
252

252

00:09:11,330  -->  00:09:13,110
I'm going to get from Tuesday to Wednesday.
253

253

00:09:13,110  -->  00:09:15,460
And so when I do these incrementals,
254

254

00:09:15,460  -->  00:09:17,430
I now have a bunch of smaller pieces
255

255

00:09:17,430  -->  00:09:20,170
that to put back together when I want to restore my servers.
256

256

00:09:20,170  -->  00:09:22,380
Now at differential on the other hand is going to be
257

257

00:09:22,380  -->  00:09:25,140
the entire difference since the last full backup.
258

258

00:09:25,140  -->  00:09:28,020
So if on Wednesday I did a differential backup,
259

259

00:09:28,020  -->  00:09:30,580
I'm going to have all the data that's different from Sunday,
260

260

00:09:30,580  -->  00:09:33,780
the last full backup all the way up through Wednesday.
261

261

00:09:33,780  -->  00:09:35,560
This is the difference between the differential
262

262

00:09:35,560  -->  00:09:36,880
and an incremental.
263

263

00:09:36,880  -->  00:09:39,250
So if I do a full backup on Sunday
264

264

00:09:39,250  -->  00:09:41,060
and then I do a differential on Monday.
265

265

00:09:41,060  -->  00:09:43,260
Monday I did an incremental and the differential,
266

266

00:09:43,260  -->  00:09:44,530
they're going to look the exact same.
267

267

00:09:44,530  -->  00:09:47,010
But on Tuesday the incremental is only going to include
268

268

00:09:47,010  -->  00:09:48,440
the stuff since Monday.
269

269

00:09:48,440  -->  00:09:51,730
But the differential will include everything since Sunday.
270

270

00:09:51,730  -->  00:09:54,270
This includes all of Monday and Tuesdays changes.
271

271

00:09:54,270  -->  00:09:56,140
And so you can see how this differential is going to grow
272

272

00:09:56,140  -->  00:09:58,630
throughout the week until I do another full backup
273

273

00:09:58,630  -->  00:10:00,090
on the next Sunday.
274

274

00:10:00,090  -->  00:10:03,600
Now I do an incremental, it's only that last 24 hour period.
275

275

00:10:03,600  -->  00:10:07,030
Now the last type of backup we have is known as a snapshot.
276

276

00:10:07,030  -->  00:10:08,550
Now if you're using virtualization
277

277

00:10:08,550  -->  00:10:10,140
and you're using virtual machines,
278

278

00:10:10,140  -->  00:10:13,700
this becomes a read only copy of your data frozen in time.
279

279

00:10:13,700  -->  00:10:16,510
For example, I use snapshots a lot when I'm using virtual
280

280

00:10:16,510  -->  00:10:18,960
machines or I'm doing malware analysis.
281

281

00:10:18,960  -->  00:10:20,510
I can take a snapshot on my machine,
282

282

00:10:20,510  -->  00:10:22,350
which is a frozen instant time.
283

283

00:10:22,350  -->  00:10:24,960
And then I can load the malware and all the bad things
284

284

00:10:24,960  -->  00:10:25,793
I need to do.
285

285

00:10:25,793  -->  00:10:27,410
And then once I'm done doing that,
286

286

00:10:27,410  -->  00:10:29,990
I can restore back to that snapshot which was clean
287

287

00:10:29,990  -->  00:10:31,570
before I installed all the malware.
288

288

00:10:31,570  -->  00:10:34,000
This allows me to do dynamic analysis of it.
289

289

00:10:34,000  -->  00:10:36,460
Now if you have a very large Sand array or storage area
290

290

00:10:36,460  -->  00:10:37,450
or network array,
291

291

00:10:37,450  -->  00:10:39,110
you can take snapshots of your servers
292

292

00:10:39,110  -->  00:10:42,160
and your virtual machines in a very quick and easy way
293

293

00:10:42,160  -->  00:10:43,615
and then you'll be able to restore them exactly back
294

294

00:10:43,615  -->  00:10:46,530
to the way they were at any given moment in time.
295

295

00:10:46,530  -->  00:10:49,170
Now when we use full, incremental and differential,
296

296

00:10:49,170  -->  00:10:51,730
most of the time those are going to be used with tape backups
297

297

00:10:51,730  -->  00:10:53,090
and offsite storage.
298

298

00:10:53,090  -->  00:10:55,010
But if you're going to be doing snapshots,
299

299

00:10:55,010  -->  00:10:57,909
that's usually done to a disc like a storage area array.
300

300

00:10:57,909  -->  00:11:01,010
Now, in addition to conducting your backups of your servers,
301

301

00:11:01,010  -->  00:11:02,930
it's also important to conduct backups
302

302

00:11:02,930  -->  00:11:04,440
of your network devices.
303

303

00:11:04,440  -->  00:11:07,430
This includes their state and their configurations.
304

304

00:11:07,430  -->  00:11:10,060
The state of a network device contains all the configuration
305

305

00:11:10,060  -->  00:11:12,350
and dynamic information from a network device
306

306

00:11:12,350  -->  00:11:13,830
at any given time.
307

307

00:11:13,830  -->  00:11:15,850
If you export the state of a network device,
308

308

00:11:15,850  -->  00:11:18,430
it can later be restored to the exact same device
309

309

00:11:18,430  -->  00:11:20,850
or another device of the same model.
310

310

00:11:20,850  -->  00:11:23,830
Similarly, you can backup just the configuration information
311

311

00:11:23,830  -->  00:11:26,930
by conducting a backup of the network device configuration.
312

312

00:11:26,930  -->  00:11:28,900
This can be done using the command line interface
313

313

00:11:28,900  -->  00:11:31,650
on the device or using third-party tools.
314

314

00:11:31,650  -->  00:11:33,830
For example, one organization I worked for
315

315

00:11:33,830  -->  00:11:35,670
had thousands of network devices.
316

316

00:11:35,670  -->  00:11:38,180
So we didn't want to go around and do a weekly configuration
317

317

00:11:38,180  -->  00:11:40,860
backup for all those devices individually.
318

318

00:11:40,860  -->  00:11:43,410
Instead, we configure them to do that using the tool
319

319

00:11:43,410  -->  00:11:44,800
known as SolarWinds.
320

320

00:11:44,800  -->  00:11:47,530
Now once a week, the SolarWinds tool would back up
321

321

00:11:47,530  -->  00:11:49,170
all the configurations and store them
322

322

00:11:49,170  -->  00:11:50,700
on a centralized server.
323

323

00:11:50,700  -->  00:11:53,330
This way, if we ever had a network device that failed,
324

324

00:11:53,330  -->  00:11:55,630
we could quickly install a spare from our inventory,
325

325

00:11:55,630  -->  00:11:57,880
restore the configurations from SolarWinds
326

326

00:11:57,880  -->  00:12:00,320
back to that device and we will be back online
327

327

00:12:00,320  -->  00:12:01,793
in just a couple of minutes.
