1
00:00:00,000 --> 00:00:00,990
In this lesson,

2
00:00:00,990 --> 00:00:03,180
we're going to cover network appliances.

3
00:00:03,180 --> 00:00:05,730
Now, a network appliance is a dedicated hardware device

4
00:00:05,730 --> 00:00:07,770
with pre-installed software that's designed

5
00:00:07,770 --> 00:00:10,830
to provide specific networking services like security,

6
00:00:10,830 --> 00:00:12,900
data storage, or server functions

7
00:00:12,900 --> 00:00:14,970
inside of a network infrastructure.

8
00:00:14,970 --> 00:00:16,020
There are many different types

9
00:00:16,020 --> 00:00:17,610
of network appliances out there,

10
00:00:17,610 --> 00:00:19,320
but in this lesson we're going to focus

11
00:00:19,320 --> 00:00:21,990
on four different kinds, load balancers,

12
00:00:21,990 --> 00:00:25,110
proxy servers, sensors, and jump servers.

13
00:00:25,110 --> 00:00:27,090
Now, first we have load balancers.

14
00:00:27,090 --> 00:00:28,860
Load balancers are crucial components

15
00:00:28,860 --> 00:00:31,170
in any high availability network or system

16
00:00:31,170 --> 00:00:33,000
because they're designed to distribute the network

17
00:00:33,000 --> 00:00:36,000
or application traffic across multiple servers.

18
00:00:36,000 --> 00:00:38,910
This distribution enhances the efficiency of server use

19
00:00:38,910 --> 00:00:40,680
and it helps to prevent any single device

20
00:00:40,680 --> 00:00:43,170
from being overwhelmed by your user's demands.

21
00:00:43,170 --> 00:00:45,000
This ensures that we can maintain redundancy

22
00:00:45,000 --> 00:00:47,550
and reliability by mitigating risks associated

23
00:00:47,550 --> 00:00:49,050
with relying on a single server

24
00:00:49,050 --> 00:00:51,060
to handle all of your users' traffic.

25
00:00:51,060 --> 00:00:54,240
Instead, by dispersing the traffic, a load balancer can help

26
00:00:54,240 --> 00:00:56,340
to optimize our services response time

27
00:00:56,340 --> 00:00:58,200
and to maximize its throughput to ensure

28
00:00:58,200 --> 00:01:00,630
that no single server becomes a bottleneck,

29
00:01:00,630 --> 00:01:03,570
and this affects the overall performance of your systems.

30
00:01:03,570 --> 00:01:05,129
Now, this particularly is critical

31
00:01:05,129 --> 00:01:07,320
in high demand environments where reliability

32
00:01:07,320 --> 00:01:08,910
and smooth operations of your network

33
00:01:08,910 --> 00:01:11,040
or systems must be maintained.

34
00:01:11,040 --> 00:01:12,510
Our network load balancers

35
00:01:12,510 --> 00:01:14,160
are going to perform continuous health checks

36
00:01:14,160 --> 00:01:16,350
on our servers to ensure they remain responsive

37
00:01:16,350 --> 00:01:18,000
and can take on any additional requests

38
00:01:18,000 --> 00:01:19,380
that are being made of them.

39
00:01:19,380 --> 00:01:21,690
If a server fails, that load balancer

40
00:01:21,690 --> 00:01:23,550
will then simply redirect its traffic

41
00:01:23,550 --> 00:01:25,080
to the remaining operational servers

42
00:01:25,080 --> 00:01:26,520
within that environment.

43
00:01:26,520 --> 00:01:28,020
This allows our load balancers

44
00:01:28,020 --> 00:01:30,480
to help minimize any server downtime being experienced

45
00:01:30,480 --> 00:01:33,510
by our end users, whether that downtime was expected,

46
00:01:33,510 --> 00:01:34,950
such as during a maintenance window,

47
00:01:34,950 --> 00:01:38,040
or unexpected, such as during a system failure.

48
00:01:38,040 --> 00:01:40,470
This kind of dynamic and transparent redirection

49
00:01:40,470 --> 00:01:42,720
will ensure that our services remain uninterrupted

50
00:01:42,720 --> 00:01:44,490
and that our users are experiencing minimal

51
00:01:44,490 --> 00:01:46,290
to no impact at all times

52
00:01:46,290 --> 00:01:49,650
by continuously maintaining our services as operational.

53
00:01:49,650 --> 00:01:52,140
Now, there's also a more advanced version of a load balancer

54
00:01:52,140 --> 00:01:55,170
that you may hear, and this is referred to as an ADC

55
00:01:55,170 --> 00:01:57,570
or application delivery controller.

56
00:01:57,570 --> 00:01:59,310
Now, an application delivery controller

57
00:01:59,310 --> 00:02:01,110
will provide us with a range of functionality

58
00:02:01,110 --> 00:02:02,910
beyond simple load distribution

59
00:02:02,910 --> 00:02:05,790
because it includes functions like SSL termination,

60
00:02:05,790 --> 00:02:08,580
HTTP compression and content caching.

61
00:02:08,580 --> 00:02:11,130
These functions can be used to enhance the efficiency

62
00:02:11,130 --> 00:02:14,100
and performance of our high availability networks as well.

63
00:02:14,100 --> 00:02:15,660
In our modern cloud environments,

64
00:02:15,660 --> 00:02:17,970
load balancers can also leverage the flexibility

65
00:02:17,970 --> 00:02:20,460
and scalability that cloud services offer us

66
00:02:20,460 --> 00:02:22,620
by allowing the network to handle traffic surges

67
00:02:22,620 --> 00:02:25,500
more efficiently by distributing loads across instances,

68
00:02:25,500 --> 00:02:28,290
or even across different data centers as needed.

69
00:02:28,290 --> 00:02:29,610
For all of these reasons,

70
00:02:29,610 --> 00:02:31,950
load balancers have become an indispensable tool

71
00:02:31,950 --> 00:02:33,840
in ensuring the resilience and reliability

72
00:02:33,840 --> 00:02:36,611
of our high traffic websites, critical application systems,

73
00:02:36,611 --> 00:02:38,490
and extensive digital platforms

74
00:02:38,490 --> 00:02:40,920
across various industries and sectors.

75
00:02:40,920 --> 00:02:43,140
Now, second, we have proxy servers.

76
00:02:43,140 --> 00:02:46,080
A proxy server acts as an intermediary between a client

77
00:02:46,080 --> 00:02:48,060
and a server to provide various functions

78
00:02:48,060 --> 00:02:50,010
like content caching, request filtering,

79
00:02:50,010 --> 00:02:52,320
and login management to improve the efficiency

80
00:02:52,320 --> 00:02:55,980
and control access to our resources within a given network.

81
00:02:55,980 --> 00:02:58,890
Proxy servers can store a copy of the data being accessed

82
00:02:58,890 --> 00:03:01,050
by your clients to allow for local retrieval

83
00:03:01,050 --> 00:03:03,120
of that data the next time any other client

84
00:03:03,120 --> 00:03:05,130
on the network asks that same thing

85
00:03:05,130 --> 00:03:06,810
or makes the same request.

86
00:03:06,810 --> 00:03:09,240
This helps to enhance the speed of fulfilling the request,

87
00:03:09,240 --> 00:03:11,730
while also reducing the bandwidth utilization required

88
00:03:11,730 --> 00:03:13,500
to fulfill that specific request

89
00:03:13,500 --> 00:03:15,600
because you now have it cached locally.

90
00:03:15,600 --> 00:03:17,700
By managing logins and requests filtering,

91
00:03:17,700 --> 00:03:19,170
proxy servers can also help us

92
00:03:19,170 --> 00:03:21,030
to enforce our organization's policies

93
00:03:21,030 --> 00:03:23,340
for network utilization by adding additional layers

94
00:03:23,340 --> 00:03:25,770
of security and ensuring the specific network protocols

95
00:03:25,770 --> 00:03:27,210
are going to be followed.

96
00:03:27,210 --> 00:03:29,400
Proxy servers do contribute significantly

97
00:03:29,400 --> 00:03:32,310
to the stability and reliability of our network systems

98
00:03:32,310 --> 00:03:33,780
by providing another layer of defense

99
00:03:33,780 --> 00:03:35,070
against external threats,

100
00:03:35,070 --> 00:03:37,170
including those like distributed denial of service

101
00:03:37,170 --> 00:03:39,870
or DDoS attacks by masking the true endpoints

102
00:03:39,870 --> 00:03:42,060
that are located inside of that network.

103
00:03:42,060 --> 00:03:44,400
This layer of obscurity is also important

104
00:03:44,400 --> 00:03:46,530
and it helps to prevent any kind of direct attacks

105
00:03:46,530 --> 00:03:49,320
on the exposed servers because the attack would be pointed

106
00:03:49,320 --> 00:03:51,330
at the proxy server instead of directly

107
00:03:51,330 --> 00:03:53,760
against our web server or endpoint.

108
00:03:53,760 --> 00:03:55,830
Now, proxy servers are also integral

109
00:03:55,830 --> 00:03:57,510
in the load balancing process,

110
00:03:57,510 --> 00:03:59,070
especially in handling requests

111
00:03:59,070 --> 00:04:01,650
and distributing them across a bunch of servers.

112
00:04:01,650 --> 00:04:04,740
This ensures that no single server endures too much load

113
00:04:04,740 --> 00:04:07,650
and potentially leads to a network or system failure.

114
00:04:07,650 --> 00:04:10,440
Proxy servers also facilitate the smooth operation

115
00:04:10,440 --> 00:04:13,320
of a high availability network by performing essential tasks

116
00:04:13,320 --> 00:04:14,820
to ensure uninterrupted service

117
00:04:14,820 --> 00:04:16,680
across your enterprise networks.

118
00:04:16,680 --> 00:04:18,720
For instance, proxy servers can implement

119
00:04:18,720 --> 00:04:20,339
user authentication protocols

120
00:04:20,339 --> 00:04:22,380
to help direct traffic more safely.

121
00:04:22,380 --> 00:04:25,500
Some advanced proxy servers can also handle data encryption

122
00:04:25,500 --> 00:04:27,600
by providing secure tunnels for the transportation

123
00:04:27,600 --> 00:04:29,430
of any sensitive information.

124
00:04:29,430 --> 00:04:31,410
In circumstances where network architecture

125
00:04:31,410 --> 00:04:33,450
is going to be subject to regulatory compliance,

126
00:04:33,450 --> 00:04:35,670
such as adhering to data sovereignty laws,

127
00:04:35,670 --> 00:04:38,160
your proxy servers can also be used to assist us

128
00:04:38,160 --> 00:04:40,170
by routing that traffic to ensure data

129
00:04:40,170 --> 00:04:42,090
does not cross a geographical boundary

130
00:04:42,090 --> 00:04:43,680
that you don't want it to.

131
00:04:43,680 --> 00:04:45,990
This way, proxy servers are not only augmenting

132
00:04:45,990 --> 00:04:48,480
the security and management of our high traffic networks,

133
00:04:48,480 --> 00:04:50,850
but they also help us to adhere to legal frameworks

134
00:04:50,850 --> 00:04:53,160
and operational protocols that are going to be essential

135
00:04:53,160 --> 00:04:54,900
for the resilience and reliability

136
00:04:54,900 --> 00:04:56,820
of our network infrastructure.

137
00:04:56,820 --> 00:04:58,590
Third, we have sensors.

138
00:04:58,590 --> 00:05:01,140
Now, network sensors are designed to monitor, detect,

139
00:05:01,140 --> 00:05:04,080
and analyze traffic and data flow across the network

140
00:05:04,080 --> 00:05:06,420
in order to identify any unusual activities,

141
00:05:06,420 --> 00:05:08,730
potential security breaches, performance issues,

142
00:05:08,730 --> 00:05:11,370
or other types of operational inefficiencies.

143
00:05:11,370 --> 00:05:13,230
By continuously scanning our networks,

144
00:05:13,230 --> 00:05:15,450
these sensors can provide real-time insights

145
00:05:15,450 --> 00:05:17,130
that enable our network administrators

146
00:05:17,130 --> 00:05:18,720
to understand the ongoing activities

147
00:05:18,720 --> 00:05:20,370
and respond to them proactively

148
00:05:20,370 --> 00:05:23,610
to ensure the network's robustness and reliability.

149
00:05:23,610 --> 00:05:25,590
these network sensors will also contribute

150
00:05:25,590 --> 00:05:27,480
to the system stability and security

151
00:05:27,480 --> 00:05:29,160
in several different ways.

152
00:05:29,160 --> 00:05:30,480
Network sensors can aid

153
00:05:30,480 --> 00:05:32,190
in the performance monitoring processes

154
00:05:32,190 --> 00:05:33,540
by tracking the responsiveness

155
00:05:33,540 --> 00:05:35,760
and availability of our network services,

156
00:05:35,760 --> 00:05:37,500
which is critical for any of our environments

157
00:05:37,500 --> 00:05:40,290
where downtime is considered highly detrimental.

158
00:05:40,290 --> 00:05:41,820
With these sensors, we're going to be able

159
00:05:41,820 --> 00:05:43,440
to detect performance anomalies

160
00:05:43,440 --> 00:05:45,150
such as unexpected traffic spikes

161
00:05:45,150 --> 00:05:47,010
that could lead to service degradation,

162
00:05:47,010 --> 00:05:49,950
and they can trigger alerts for our network operations team

163
00:05:49,950 --> 00:05:51,060
to be able to go and investigate

164
00:05:51,060 --> 00:05:53,970
and overcome any given issues that were identified.

165
00:05:53,970 --> 00:05:56,190
This kind of immediate feedback and awareness

166
00:05:56,190 --> 00:05:57,990
does allow our network operations team

167
00:05:57,990 --> 00:06:00,240
to take quicker actions to aid in the response

168
00:06:00,240 --> 00:06:02,370
and resolution of the potential issues

169
00:06:02,370 --> 00:06:03,330
to be able to help minimize

170
00:06:03,330 --> 00:06:05,730
potential service interruptions or downtime.

171
00:06:05,730 --> 00:06:07,230
From a security perspective,

172
00:06:07,230 --> 00:06:10,050
network sensors can also act as the first line of defense

173
00:06:10,050 --> 00:06:12,060
against different kinds of cyber threats.

174
00:06:12,060 --> 00:06:13,440
These sensors are integral

175
00:06:13,440 --> 00:06:14,970
for our intrusion detection systems

176
00:06:14,970 --> 00:06:16,530
and intrusion prevention systems

177
00:06:16,530 --> 00:06:18,030
because they're focused on identifying

178
00:06:18,030 --> 00:06:19,770
any possible security breaches

179
00:06:19,770 --> 00:06:22,110
that are based on established patterns or behaviors

180
00:06:22,110 --> 00:06:23,670
that indicate that malicious activities

181
00:06:23,670 --> 00:06:25,050
may have been occurring.

182
00:06:25,050 --> 00:06:27,420
For example, a sudden and significant increase

183
00:06:27,420 --> 00:06:30,240
in data request from an unknown IP address might suggest

184
00:06:30,240 --> 00:06:33,270
that a DDoS attack is being attempted against your network.

185
00:06:33,270 --> 00:06:35,970
In this situation, a network sensor could promptly alert

186
00:06:35,970 --> 00:06:37,740
your network administrators to this threat

187
00:06:37,740 --> 00:06:40,170
and enable them to implement immediate countermeasures

188
00:06:40,170 --> 00:06:42,180
to thwart the attack or to mitigate

189
00:06:42,180 --> 00:06:43,920
its potential negative effects.

190
00:06:43,920 --> 00:06:45,600
This level of vigilance is crucial

191
00:06:45,600 --> 00:06:47,280
in maintaining the operational integrity

192
00:06:47,280 --> 00:06:48,990
for our high availability networks

193
00:06:48,990 --> 00:06:50,880
in order to ensure they remain uncompromised

194
00:06:50,880 --> 00:06:52,770
and available for critical processes

195
00:06:52,770 --> 00:06:55,590
and systems that rely on them for stability.

196
00:06:55,590 --> 00:06:57,570
Fourth, we have jump servers.

197
00:06:57,570 --> 00:07:00,000
Now, a jump server, also known as a jump box,

198
00:07:00,000 --> 00:07:02,730
is a dedicated gateway used by system administrators

199
00:07:02,730 --> 00:07:04,740
to securely access devices located

200
00:07:04,740 --> 00:07:07,170
in different security zones within your network.

201
00:07:07,170 --> 00:07:09,870
A jump box is a critical part of a high security

202
00:07:09,870 --> 00:07:11,880
and highly available network architecture

203
00:07:11,880 --> 00:07:14,010
because it acts as an intermediary station

204
00:07:14,010 --> 00:07:15,240
for accessing those servers

205
00:07:15,240 --> 00:07:18,120
and network devices inside of your trusted network.

206
00:07:18,120 --> 00:07:20,400
Using jump boxes, this can help us to ensure

207
00:07:20,400 --> 00:07:22,410
that any direct access to these protected devices

208
00:07:22,410 --> 00:07:24,600
or servers is limited to only connections

209
00:07:24,600 --> 00:07:26,850
from specific workstations or servers

210
00:07:26,850 --> 00:07:28,830
that'll provide a more controlled entry point

211
00:07:28,830 --> 00:07:31,260
that helps to reduce the attack surface of the network

212
00:07:31,260 --> 00:07:32,580
and to prevent potential threats

213
00:07:32,580 --> 00:07:35,040
from reaching sensitive areas of our networks.

214
00:07:35,040 --> 00:07:37,650
These jump servers offer a robust layer of protection

215
00:07:37,650 --> 00:07:39,990
for systems that cannot afford to have any downtime

216
00:07:39,990 --> 00:07:42,210
or data breaches associated with them.

217
00:07:42,210 --> 00:07:44,130
By routing all of our administrative tasks

218
00:07:44,130 --> 00:07:46,830
through a single highly secured and monitored system,

219
00:07:46,830 --> 00:07:49,530
our networks can ensure that only authenticated users

220
00:07:49,530 --> 00:07:52,830
are able to execute changes or access your sensitive data.

221
00:07:52,830 --> 00:07:54,810
By using this centralized point of access,

222
00:07:54,810 --> 00:07:56,580
you're also going to be able to simplify the logging

223
00:07:56,580 --> 00:07:58,590
of your activities to make it easier to audit

224
00:07:58,590 --> 00:08:01,920
and track who has been accessing what information and when.

225
00:08:01,920 --> 00:08:03,900
In the unfortunate event of a cyber attack

226
00:08:03,900 --> 00:08:05,190
or system malfunction,

227
00:08:05,190 --> 00:08:07,170
these jump servers will have a detailed log

228
00:08:07,170 --> 00:08:09,180
of any actions or connections that were made,

229
00:08:09,180 --> 00:08:11,460
so we can significantly speed up the recovery process

230
00:08:11,460 --> 00:08:12,960
during an incident response.

231
00:08:12,960 --> 00:08:15,180
This helps to minimize the downtime of your network,

232
00:08:15,180 --> 00:08:17,160
while maintaining the high availability required

233
00:08:17,160 --> 00:08:19,710
by the overall network and its devices.

234
00:08:19,710 --> 00:08:21,660
Additionally, these jump servers are used

235
00:08:21,660 --> 00:08:23,220
to help facilitate a streamlined approach

236
00:08:23,220 --> 00:08:24,930
to system management and maintenance

237
00:08:24,930 --> 00:08:26,640
to ensure that the operational integrity

238
00:08:26,640 --> 00:08:29,280
of your high availability networks remains intact.

239
00:08:29,280 --> 00:08:31,350
Most commonly, you'll see that a jump server

240
00:08:31,350 --> 00:08:33,419
will host a wide range of tools and scripts

241
00:08:33,419 --> 00:08:35,340
that your system administrators need to use

242
00:08:35,340 --> 00:08:37,650
in order to conduct their necessary functions

243
00:08:37,650 --> 00:08:39,210
such as performing routine checks

244
00:08:39,210 --> 00:08:40,799
and carrying out troubleshooting tasks

245
00:08:40,799 --> 00:08:42,390
in a more efficient manner.

246
00:08:42,390 --> 00:08:44,490
These jump servers are also heavily secured

247
00:08:44,490 --> 00:08:46,080
with advanced monitoring software

248
00:08:46,080 --> 00:08:47,730
to oversee their system's health

249
00:08:47,730 --> 00:08:50,370
so that any performance issues or security vulnerabilities

250
00:08:50,370 --> 00:08:52,920
can be quickly identified and remediated.

251
00:08:52,920 --> 00:08:55,470
By serving as a bridge between various security zones

252
00:08:55,470 --> 00:08:58,110
and providing a platform for critical management functions,

253
00:08:58,110 --> 00:09:00,300
our jump servers do play an important role

254
00:09:00,300 --> 00:09:02,850
in maintaining the uninterrupted and secure operation

255
00:09:02,850 --> 00:09:04,890
of our high availability networks.

256
00:09:04,890 --> 00:09:06,870
So remember, network appliances

257
00:09:06,870 --> 00:09:09,930
are dedicated hardware devices with pre-installed software

258
00:09:09,930 --> 00:09:12,600
that's designed to provide specific networking services.

259
00:09:12,600 --> 00:09:14,460
Load balancers will distribute network

260
00:09:14,460 --> 00:09:16,800
or application traffic across multiple servers

261
00:09:16,800 --> 00:09:18,180
to optimize their performance

262
00:09:18,180 --> 00:09:20,970
and prevent any single server from being overloaded.

263
00:09:20,970 --> 00:09:23,700
Proxy servers will also act as an intermediary

264
00:09:23,700 --> 00:09:25,290
between your clients and your servers

265
00:09:25,290 --> 00:09:27,540
to manage the data flow and offer enhanced levels

266
00:09:27,540 --> 00:09:29,700
of security and content control.

267
00:09:29,700 --> 00:09:32,730
Sensors are tools or devices that monitor various physical

268
00:09:32,730 --> 00:09:34,980
or network conditions to provide real-time data

269
00:09:34,980 --> 00:09:37,350
for system optimization and security.

270
00:09:37,350 --> 00:09:41,490
Jump servers or jump boxes are secure intermediary platforms

271
00:09:41,490 --> 00:09:43,770
that administrators can use for accessing devices

272
00:09:43,770 --> 00:09:46,740
across different security zones within a given network.

273
00:09:46,740 --> 00:09:49,410
Together, these four types of network appliances

274
00:09:49,410 --> 00:09:51,000
will help us to ensure the efficient,

275
00:09:51,000 --> 00:09:53,130
secure and high performance capabilities

276
00:09:53,130 --> 00:09:55,280
of our enterprise network's infrastructure.

