1
1

00:00:00,500  -->  00:00:02,270
<v ->Common documentation.</v>
2

2

00:00:02,270  -->  00:00:05,120
In this lesson, we're going to cover the common documentation
3

3

00:00:05,120  -->  00:00:07,660
that you're going to use in your enterprise networks.
4

4

00:00:07,660  -->  00:00:09,640
This includes physical network diagrams,
5

5

00:00:09,640  -->  00:00:12,270
logical network diagrams, wiring diagrams,
6

6

00:00:12,270  -->  00:00:15,020
site survey reports, audit and assessment reports,
7

7

00:00:15,020  -->  00:00:16,506
and baseline configurations.
8

8

00:00:16,506  -->  00:00:19,115
First, we have physical network diagrams.
9

9

00:00:19,115  -->  00:00:21,400
A physical network diagram is used to show
10

10

00:00:21,400  -->  00:00:23,870
the actual physical arrangement of the components
11

11

00:00:23,870  -->  00:00:25,140
that make up your network
12

12

00:00:25,140  -->  00:00:27,036
including the cabling and the hardware.
13

13

00:00:27,036  -->  00:00:29,830
Typically, these diagrams give you a bird's eye view
14

14

00:00:29,830  -->  00:00:31,630
of the network in its physical space,
15

15

00:00:31,630  -->  00:00:33,008
and it looks a lot like a floor plan,
16

16

00:00:33,008  -->  00:00:35,550
but you may also see physical network diagrams
17

17

00:00:35,550  -->  00:00:37,410
that show how things are going to be cabled
18

18

00:00:37,410  -->  00:00:40,120
within an individual rack of a data center as well.
19

19

00:00:40,120  -->  00:00:42,450
For example, if I have a physical network diagram
20

20

00:00:42,450  -->  00:00:44,380
showing the floor plan of a small office,
21

21

00:00:44,380  -->  00:00:46,220
I can notate on that floor plan
22

22

00:00:46,220  -->  00:00:50,540
exactly where each IP-based CCTV is going to be installed.
23

23

00:00:50,540  -->  00:00:51,540
Now, in this example,
24

24

00:00:51,540  -->  00:00:54,080
you can see I have nine IP-based cameras
25

25

00:00:54,080  -->  00:00:56,660
and how the cable is going to run back to a central point,
26

26

00:00:56,660  -->  00:00:58,100
such as this network video recorder
27

27

00:00:58,100  -->  00:01:00,720
that contains nine power over Ethernet ports
28

28

00:01:00,720  -->  00:01:02,500
to run this camera system.
29

29

00:01:02,500  -->  00:01:04,990
I could just as easily have another flow plan like this
30

30

00:01:04,990  -->  00:01:06,870
showing where all my network jacks are going to be located
31

31

00:01:06,870  -->  00:01:09,010
in an office and how the cables are being run back
32

32

00:01:09,010  -->  00:01:10,846
to a patch panel, and from that patch panel
33

33

00:01:10,846  -->  00:01:13,950
back to an edge switch that connects to all these devices.
34

34

00:01:13,950  -->  00:01:16,639
Inside my data center, though, I'm usually more concerned
35

35

00:01:16,639  -->  00:01:18,680
with how things are physically located
36

36

00:01:18,680  -->  00:01:20,340
within one single rack.
37

37

00:01:20,340  -->  00:01:22,582
And so I can create a rack diagram.
38

38

00:01:22,582  -->  00:01:24,716
For example, here's a diagram showing a rack,
39

39

00:01:24,716  -->  00:01:27,350
containing two storage area network controllers,
40

40

00:01:27,350  -->  00:01:29,270
two firewalls, two switches,
41

41

00:01:29,270  -->  00:01:32,140
three virtual machine host servers running ESXi,
42

42

00:01:32,140  -->  00:01:34,228
a backup server, a modular smart array,
43

43

00:01:34,228  -->  00:01:36,560
and a tape backup library.
44

44

00:01:36,560  -->  00:01:39,440
From this diagram, you can clearly see where in this rack
45

45

00:01:39,440  -->  00:01:41,150
each of those units is going to be located
46

46

00:01:41,150  -->  00:01:43,780
and which network cables will connect to which ports
47

47

00:01:43,780  -->  00:01:45,320
on which devices.
48

48

00:01:45,320  -->  00:01:47,080
Another version of this type of diagram
49

49

00:01:47,080  -->  00:01:48,400
may include a front view,
50

50

00:01:48,400  -->  00:01:50,840
which also shows the location inside the cabinet.
51

51

00:01:50,840  -->  00:01:53,010
And it can have the different device names
52

52

00:01:53,010  -->  00:01:55,350
and the IP addresses for each of those devices,
53

53

00:01:55,350  -->  00:01:57,210
but it won't show the actual network cables
54

54

00:01:57,210  -->  00:01:58,190
and where they connect
55

55

00:01:58,190  -->  00:02:00,730
because you're looking at the front of those devices.
56

56

00:02:00,730  -->  00:02:03,240
Now, another type of physical network diagram we have
57

57

00:02:03,240  -->  00:02:04,730
is used to provide documentation
58

58

00:02:04,730  -->  00:02:07,360
for how our main distribution frame or MDF
59

59

00:02:07,360  -->  00:02:09,910
and our intermediate distribution frame or IDF
60

60

00:02:09,910  -->  00:02:11,750
are connected and cabled.
61

61

00:02:11,750  -->  00:02:14,470
In this example, you could see a very generic MDF
62

62

00:02:14,470  -->  00:02:17,780
and IDF layout for a typical three-story office building.
63

63

00:02:17,780  -->  00:02:20,140
Here, we have the MDF on the bottom right corner
64

64

00:02:20,140  -->  00:02:20,973
of the first floor,
65

65

00:02:20,973  -->  00:02:23,070
and then a smaller IDF on the right corner
66

66

00:02:23,070  -->  00:02:24,700
of each of the remaining floors.
67

67

00:02:24,700  -->  00:02:27,660
There's an interconnection between each IDF and the MDF,
68

68

00:02:27,660  -->  00:02:29,553
and each floor has a single network cable
69

69

00:02:29,553  -->  00:02:32,070
running to a jack into an office.
70

70

00:02:32,070  -->  00:02:35,040
Now, this of course is a very oversimplified diagram
71

71

00:02:35,040  -->  00:02:36,720
or an overview diagram,
72

72

00:02:36,720  -->  00:02:38,870
but we can also have additionally detailed diagrams
73

73

00:02:38,870  -->  00:02:40,245
depending on how much work we want.
74

74

00:02:40,245  -->  00:02:43,670
That could show each rack inside the MDF or the IDF
75

75

00:02:43,670  -->  00:02:44,800
and what they would look like,
76

76

00:02:44,800  -->  00:02:46,910
how they're cabled, including their edge switches,
77

77

00:02:46,910  -->  00:02:49,430
patch panels, and other networking equipment.
78

78

00:02:49,430  -->  00:02:51,590
The second type of documentation we need to cover
79

79

00:02:51,590  -->  00:02:53,520
is logical network diagrams.
80

80

00:02:53,520  -->  00:02:55,100
Unlike the physical network diagrams
81

81

00:02:55,100  -->  00:02:56,730
that show exactly which port or cable
82

82

00:02:56,730  -->  00:02:58,530
is going to connect it to and how it's ran
83

83

00:02:58,530  -->  00:03:01,110
on the physical floor plan or the rack layout,
84

84

00:03:01,110  -->  00:03:02,770
we use a logical diagram.
85

85

00:03:02,770  -->  00:03:04,860
We're going to use this to illustrate the flow of data
86

86

00:03:04,860  -->  00:03:06,900
across a network and it's going to be used to show
87

87

00:03:06,900  -->  00:03:09,290
how devices are communicating with each other.
88

88

00:03:09,290  -->  00:03:12,180
These logical diagrams will include things like the subnets,
89

89

00:03:12,180  -->  00:03:13,880
the network objects and devices,
90

90

00:03:13,880  -->  00:03:16,610
the routing protocols and domains, voice gateways,
91

91

00:03:16,610  -->  00:03:19,840
traffic flow, and network segments within a given network.
92

92

00:03:19,840  -->  00:03:22,300
Traditionally, network diagrams were drawn by hand
93

93

00:03:22,300  -->  00:03:25,010
and using symbols to represent the different network devices
94

94

00:03:25,010  -->  00:03:27,290
like routers, switches, firewalls,
95

95

00:03:27,290  -->  00:03:29,510
intrusion detection systems, and clients.
96

96

00:03:29,510  -->  00:03:32,390
In this example, I'm using the standard Cisco notation
97

97

00:03:32,390  -->  00:03:34,440
to demonstrate how the various switches and routers
98

98

00:03:34,440  -->  00:03:36,650
are being connected to form this network.
99

99

00:03:36,650  -->  00:03:39,610
On the logical diagram, we also include the IP addresses
100

100

00:03:39,610  -->  00:03:43,070
and the interface identifiers such as G0/1
101

101

00:03:43,070  -->  00:03:46,440
or gigabit Ethernet 0/1 or ATM1/0,
102

102

00:03:46,440  -->  00:03:49,810
which is for an ATM interface for our routers and switches.
103

103

00:03:49,810  -->  00:03:51,940
Notice the routers are being represented by a circle
104

104

00:03:51,940  -->  00:03:53,870
with four arrows, two pointing inward,
105

105

00:03:53,870  -->  00:03:55,260
and two pointing outward.
106

106

00:03:55,260  -->  00:03:57,120
Switches are going to be represented by a square
107

107

00:03:57,120  -->  00:03:59,620
with four arrows, all pointing outward.
108

108

00:03:59,620  -->  00:04:03,260
Servers like a DHCP, DNS, or TFTP server
109

109

00:04:03,260  -->  00:04:05,730
are represented by a large rectangle server icon.
110

110

00:04:05,730  -->  00:04:07,340
And the computers are going to be shown
111

111

00:04:07,340  -->  00:04:09,030
using a computer icon.
112

112

00:04:09,030  -->  00:04:10,620
Another symbol you may see included
113

113

00:04:10,620  -->  00:04:12,230
is an intrusion detection system
114

114

00:04:12,230  -->  00:04:13,820
or intrusion prevention system,
115

115

00:04:13,820  -->  00:04:15,140
which is going to be a rectangle
116

116

00:04:15,140  -->  00:04:16,920
that contains a circle inside of it
117

117

00:04:16,920  -->  00:04:19,350
with two arrows crossing over the circle.
118

118

00:04:19,350  -->  00:04:21,840
A firewall is usually represented by a brick wall
119

119

00:04:21,840  -->  00:04:23,610
and an access point is going to be represented
120

120

00:04:23,610  -->  00:04:26,470
by a rectangle with a series of radio waves going out of it
121

121

00:04:26,470  -->  00:04:28,280
from the left to the right.
122

122

00:04:28,280  -->  00:04:29,787
Now, as you look at various network diagrams
123

123

00:04:29,787  -->  00:04:32,090
on the internet, you may come across some more
124

124

00:04:32,090  -->  00:04:34,480
modern network diagrams that remove the symbols
125

125

00:04:34,480  -->  00:04:36,700
and instead use pictures of networking equipment
126

126

00:04:36,700  -->  00:04:38,960
that's going to be used in the diagrams instead.
127

127

00:04:38,960  -->  00:04:40,880
In this example, you can see the router
128

128

00:04:40,880  -->  00:04:42,885
connected to the switches and those switches are connected
129

129

00:04:42,885  -->  00:04:44,920
to the client PCs.
130

130

00:04:44,920  -->  00:04:46,700
Next, we have a wiring diagram
131

131

00:04:46,700  -->  00:04:48,560
and this is something we already looked at briefly
132

132

00:04:48,560  -->  00:04:50,880
as part of our physical network diagrams.
133

133

00:04:50,880  -->  00:04:53,250
Wiring diagrams can occur with both physical
134

134

00:04:53,250  -->  00:04:54,850
and logical network diagrams,
135

135

00:04:54,850  -->  00:04:56,220
as long as they are clearly labeled,
136

136

00:04:56,220  -->  00:04:58,550
which cable is connected to which port.
137

137

00:04:58,550  -->  00:04:59,960
The more in-depth wiring diagrams
138

138

00:04:59,960  -->  00:05:02,200
are going to include a floor plan or a rack diagram,
139

139

00:05:02,200  -->  00:05:04,220
so you can see exactly where the cables are being run
140

140

00:05:04,220  -->  00:05:05,860
in the physical environment.
141

141

00:05:05,860  -->  00:05:08,130
Next, we have site survey reports.
142

142

00:05:08,130  -->  00:05:10,390
These are often conducted as part of a wireless survey
143

143

00:05:10,390  -->  00:05:11,560
or an assessment.
144

144

00:05:11,560  -->  00:05:13,550
Now, a wireless site survey sometimes
145

145

00:05:13,550  -->  00:05:16,050
called an RF or radio frequency site survey,
146

146

00:05:16,050  -->  00:05:17,620
or a wireless survey
147

147

00:05:17,620  -->  00:05:20,410
is the process of planning and designing a wireless network
148

148

00:05:20,410  -->  00:05:21,900
to provide a wireless solution
149

149

00:05:21,900  -->  00:05:24,140
that will deliver the required wireless coverage,
150

150

00:05:24,140  -->  00:05:26,910
data rates, network capacity, roaming capability,
151

151

00:05:26,910  -->  00:05:29,670
and quality of service or QoS.
152

152

00:05:29,670  -->  00:05:31,827
In this example, you could see a floor plan that includes
153

153

00:05:31,827  -->  00:05:34,900
the locations of each wireless access point being shown.
154

154

00:05:34,900  -->  00:05:37,400
Then rating out from each access point,
155

155

00:05:37,400  -->  00:05:40,280
you see bands of color, going from green to yellow
156

156

00:05:40,280  -->  00:05:41,580
to orange to red.
157

157

00:05:41,580  -->  00:05:43,904
And this indicates the strength of the wireless signal.
158

158

00:05:43,904  -->  00:05:46,550
Now, when you see green, that's a strong signal.
159

159

00:05:46,550  -->  00:05:49,050
When you see red, that's a weaker signal.
160

160

00:05:49,050  -->  00:05:51,550
Wired site surveys are also conducted sometimes,
161

161

00:05:51,550  -->  00:05:53,040
but in these cases
162

162

00:05:53,040  -->  00:05:54,660
it's usually done as part of a preparation
163

163

00:05:54,660  -->  00:05:56,584
for a major upgrade or installation.
164

164

00:05:56,584  -->  00:05:58,340
With a wired site survey,
165

165

00:05:58,340  -->  00:05:59,438
the installation team is going to come out
166

166

00:05:59,438  -->  00:06:02,750
and look at your MDFs, your IDFs, and your data centers
167

167

00:06:02,750  -->  00:06:05,220
to determine if you have the right power, space, and cooling
168

168

00:06:05,220  -->  00:06:06,490
to support whatever new equipment
169

169

00:06:06,490  -->  00:06:09,060
you're going to be installing as part of that upgrade.
170

170

00:06:09,060  -->  00:06:11,030
For example, if I was going to install three new racks
171

171

00:06:11,030  -->  00:06:12,910
of equipment in your data center,
172

172

00:06:12,910  -->  00:06:14,330
I need to go out there and look at it
173

173

00:06:14,330  -->  00:06:16,220
and make sure you have the physical space required
174

174

00:06:16,220  -->  00:06:17,730
to hold those three racks.
175

175

00:06:17,730  -->  00:06:19,460
In addition to that, I need to make sure
176

176

00:06:19,460  -->  00:06:21,640
you have a powerful enough HVAC system
177

177

00:06:21,640  -->  00:06:24,200
to remove all the extra heat that my new equipment
178

178

00:06:24,200  -->  00:06:26,260
in these three racks is going to produce.
179

179

00:06:26,260  -->  00:06:28,210
I also want to make sure your site has the right power
180

180

00:06:28,210  -->  00:06:30,460
and backup generators and battery backups
181

181

00:06:30,460  -->  00:06:32,210
that you can handle all the extra power
182

182

00:06:32,210  -->  00:06:34,650
that's going to be drawn by all this new equipment.
183

183

00:06:34,650  -->  00:06:37,140
Next, we have audit and assessment reports.
184

184

00:06:37,140  -->  00:06:38,330
Audit and assessment reports
185

185

00:06:38,330  -->  00:06:39,770
are delivered to your organization
186

186

00:06:39,770  -->  00:06:42,180
after a formal assessment has been conducted.
187

187

00:06:42,180  -->  00:06:44,570
These reports will contain an executive summary,
188

188

00:06:44,570  -->  00:06:46,980
an overview of the assessment scope and objectives,
189

189

00:06:46,980  -->  00:06:49,250
the assumptions and limitations of the assessment,
190

190

00:06:49,250  -->  00:06:51,420
the methods and tools used during the assessment,
191

191

00:06:51,420  -->  00:06:53,870
a diagram showing the current environment and systems,
192

192

00:06:53,870  -->  00:06:55,120
the security requirements,
193

193

00:06:55,120  -->  00:06:56,830
a summary of findings and recommendations,
194

194

00:06:56,830  -->  00:06:58,860
and the results of the audit.
195

195

00:06:58,860  -->  00:07:00,770
Essentially, this report is going to contain
196

196

00:07:00,770  -->  00:07:03,620
all the issues the audit team found with your organization,
197

197

00:07:03,620  -->  00:07:05,000
as well as anything your organization
198

198

00:07:05,000  -->  00:07:06,200
is already doing right,
199

199

00:07:06,200  -->  00:07:08,380
and things they should continue to keep doing.
200

200

00:07:08,380  -->  00:07:10,680
Finally, we have baseline configurations.
201

201

00:07:10,680  -->  00:07:12,450
The documented baseline configurations
202

202

00:07:12,450  -->  00:07:15,217
are the most stable versions of a devices configurations.
203

203

00:07:15,217  -->  00:07:16,940
These baseline configurations
204

204

00:07:16,940  -->  00:07:18,870
are documented set of specifications
205

205

00:07:18,870  -->  00:07:21,630
for information system or a configuration item
206

206

00:07:21,630  -->  00:07:24,100
within that system, that has been formally reviewed
207

207

00:07:24,100  -->  00:07:26,240
and agreed on at a given point in time,
208

208

00:07:26,240  -->  00:07:28,000
and which can now only be changed
209

209

00:07:28,000  -->  00:07:29,880
through change control procedures.
210

210

00:07:29,880  -->  00:07:31,440
So, if you want to change the baseline
211

211

00:07:31,440  -->  00:07:33,430
due to an operational need, you need to follow
212

212

00:07:33,430  -->  00:07:35,430
the proper configuration management procedures
213

213

00:07:35,430  -->  00:07:37,200
to request those changes.
214

214

00:07:37,200  -->  00:07:39,630
Those changes will then be properly tested and approved,
215

215

00:07:39,630  -->  00:07:41,750
and they become part of the new baseline
216

216

00:07:41,750  -->  00:07:43,820
for those devices moving forward.
217

217

00:07:43,820  -->  00:07:45,778
As you can see, there is a bunch of documentation
218

218

00:07:45,778  -->  00:07:48,660
that you're going to use in your enterprise networks,
219

219

00:07:48,660  -->  00:07:50,520
including your physical network diagrams,
220

220

00:07:50,520  -->  00:07:53,160
logical network diagrams, wiring diagrams,
221

221

00:07:53,160  -->  00:07:55,770
site survey reports, audit and assessment reports,
222

222

00:07:55,770  -->  00:07:57,453
and baseline configurations.
223

223

00:07:58,435  -->  00:08:00,729
(logo whirring)
