<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Colin McNamara - CCIE 18233 , VCP, EMCIE, NCDA, GEEK &#187; network infrastructure</title>
	<atom:link href="http://www.colinmcnamara.com/technology-tags/network-infrastructure/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.colinmcnamara.com</link>
	<description>Technical reviews and articles from a CCIE with extensive experience in designing and implementing converged enterprise networks.</description>
	<lastBuildDate>Fri, 13 Jan 2012 19:00:08 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>Measuring and mitigating risk involved with sharing virtual infrastructure between DMZ and Internal environments</title>
		<link>http://www.colinmcnamara.com/measuring-and-mitigating-risk-involved-with-sharing-virtual-infrastructure-between-dmz-and-internal-environments/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=measuring-and-mitigating-risk-involved-with-sharing-virtual-infrastructure-between-dmz-and-internal-environments</link>
		<comments>http://www.colinmcnamara.com/measuring-and-mitigating-risk-involved-with-sharing-virtual-infrastructure-between-dmz-and-internal-environments/#comments</comments>
		<pubDate>Tue, 09 Sep 2008 20:36:57 +0000</pubDate>
		<dc:creator>colinmcnamara</dc:creator>
				<category><![CDATA[hyper-v]]></category>
		<category><![CDATA[virtualization]]></category>
		<category><![CDATA[vmware]]></category>
		<category><![CDATA[blog]]></category>
		<category><![CDATA[breach]]></category>
		<category><![CDATA[business context]]></category>
		<category><![CDATA[C]]></category>
		<category><![CDATA[CISCO]]></category>
		<category><![CDATA[Colin]]></category>
		<category><![CDATA[compromise]]></category>
		<category><![CDATA[Data Center]]></category>
		<category><![CDATA[DESIGN]]></category>
		<category><![CDATA[device contexts]]></category>
		<category><![CDATA[enhancements]]></category>
		<category><![CDATA[FCOE]]></category>
		<category><![CDATA[HP]]></category>
		<category><![CDATA[Instances]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[NDA]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[network infrastructure]]></category>
		<category><![CDATA[Nexus 5020]]></category>
		<category><![CDATA[passed]]></category>
		<category><![CDATA[Pic]]></category>
		<category><![CDATA[risk risk]]></category>
		<category><![CDATA[san]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[storage]]></category>
		<category><![CDATA[switch]]></category>
		<category><![CDATA[threat]]></category>
		<category><![CDATA[TrustSec]]></category>
		<category><![CDATA[virtual device]]></category>
		<category><![CDATA[vlan]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://www.colinmcnamara.com/?p=177</guid>
		<description><![CDATA[Ivan Pepelnjak over at IOS Hints and Tricks wrote a post about DMZ VLAN leaking that got me thinking. He writes about &#8220;the VLAN leaking myth&#8221; and how it encourages clients to utilize physically separate network infrastructure in the DMZ&#8217;s. Now first things first, I wouldn&#8217;t call VLAN leaking a myth. At one time it [...]<p>--Colin McNamara
<br/><br/><a href="http://www.colinmcnamara.com/measuring-and-mitigating-risk-involved-with-sharing-virtual-infrastructure-between-dmz-and-internal-environments/">Measuring and mitigating risk involved with sharing virtual infrastructure between DMZ and Internal environments</a></p>
]]></description>
			<content:encoded><![CDATA[<p>Ivan Pepelnjak over at <a href="http://blog.ioshints.info/2008/09/are-vlans-safe-in-dmz-environment.html" target="_blank">IOS Hints and Tricks </a>wrote a post about DMZ VLAN leaking that got me thinking.</p>
<p>He writes about &#8220;the VLAN leaking myth&#8221; and how it encourages clients to utilize physically separate network infrastructure in the DMZ&#8217;s. Now first things first, I wouldn&#8217;t call VLAN leaking a myth. At one time it was a very real and serious vulnerability that was exploited by overflowing the capacity of the switch you were attacking, and causing it to &#8220;downgrade&#8221; from switch to a hub. Once this happened you now had access to previously protected devices, as well as having the ability to sniff data as it passed through the shared hub backplane.</p>
<p>As he mentions though, this is 8 years ago. Most switches have evolved to the point where backplanes far exceed the traffic that could ever be injected into their switchports. Even beyond backplane enhancements there are many ways to further firm up your security stance &#8211; Virtual Device Contexts, not using Layer 3 SVI&#8217;s on a DMZ VLAN, utilizing PVLANs, using port security, virtual routing instances, and many more. Of course, there are still many other attack vectors that still remain, but can be mitigated by utilizing features built into the majority of enterprise switches available today.</p>
<p>I think the real question is not &#8220;are VLANs safe in a DMZ&#8221;. The important question is have you mitigated the probability of compromise (the actual threat) to levels that are acceptable to your business. This question remains whether you have a standalone switch or not. So many times we hear about risk risk and more risk. But risk alone is meaningless in a business context. What is important is combining risk with likelihood. For that I like to use a simple table to come up with the true threat.</p>
<p><a class="thickbox" href="http://www.colinmcnamara.com/wp-content/gallery/breach/risk_grid.gif"><img class="ngg-singlepic ngg-center" src="http://www.colinmcnamara.com/wp-content/gallery/breach/thumbs/thumbs_risk_grid.gif" alt="risk_grid.gif" /></a></p>
<p>For example, as I drive to Fry&#8217;s there is the risk of me dying due to a car crash. The impact of me dying is very high (risk) however the likelihood of an accident is low, and furthermore I reduce (mitigate) the latent risk (threat) by wearing my seat belt. So all in all the threat of me dying on my way to Fry&#8217;s is pretty darn low.</p>
<p>In a business context this may be that I have public facing web servers and network devices in my DMZ. The impact of them being compromised is that my public image may be tarnished for a short time, and my end users may lose productivity if they are not able to VPN into work, or access the Internet while on premise. I mitigate this risk by using firewalls and both host and network based Intrusion Prevention Systems as well as implementing best security practices on my network and systems devices. The latent risk (threat) remaining is at a level that is acceptable to the business leaders, so the system is allowed.</p>
<p>One question that I have seen coming up more often as we move towards fully virtualized data centers is centered around commingling of virtual infrastructure. There are some hard questions which challenge some practices that we have held true over the years.</p>
<ul>
<li>Should you allow sharing of physical memory on a host virtual machine between an internal and DMZ server?</li>
<li>Should you allow virtual infrastructure from multiple security zones to share a storage array or cluster of arrays?</li>
<li>Should you allow multiple virtual switches in different security zones commingling on the same ESX or Hyper-V cluster?</li>
<li>Should you allow virtual firewall and load balancing instances protecting internal and external zones to reside on the same hardware?</li>
<li>Should you allow virtual routing instances from multiple zones to share a physical infrastructure?</li>
</ul>
<p>In the past world of standalone systems, the additional cost of providing a wholly separate infrastructure for DMZ environments was relatively low. Each system generally had internal disk, or at most direct attached storage. Network devices themselves were scaled down to support one chassis one function. This fit quite neatly into the Enterprise Composite Network model that was quite common from 1999-2003.</p>
<p>Now, many data centers have moved to the Service Oriented Network Architecture (SONA). In this model the cost of a virtualized data center is primarily focused on foundation elements such as the virtual storage and virtual fabrics, virtualized network, and virtual systems elements. The cost of providing additional virtualized services off these elements is low, however the cost of duplicating the physical infrastructure is quite high on both the capital and operational levels. This is forcing the technical and executive leadership at many companies to take a long hard look at the true threats they are facing in previously physically separate security zones such as DMZ&#8217;s, Financial and other secure zones. In the end, they are having to decide whether the threat remaining after their security controls is worth duplicating hundreds of thousands of dollars worth of infrastructure or not.</p>
<p>These are hard questions, with really no single good answer. My gut feel is that over the next few years we will continue the move towards the fully virtualized data center where components such as memory, PCI-X buses, storage and network devices are even further decentralized. This will make the cost of duplicating the infrastructure more and more significant, causing consolidated data center (or compute) fabrics to be the norm. At this point the discussion will move away from securing zones by creating separate infrastructure, to providing end to end security, starting integrated application level security, maybe with TrustSec or a dirivative, all the way down to securing the data at rest on disk. For the time being however, the best we can do is sit down and do an honest appraisel of our security stances, mitigate what we can, and do our best to design data center architectures that provide the flexibility of implementing whatever choice the technical and business leaders agree on.<strong>Similar Posts:</strong>
<ul class="similar-posts">
<li><a href="http://www.colinmcnamara.com/moving-towards-a-green-data-center-truth-behind-the-hype/" rel="bookmark" title="February 22, 2008">Moving towards a Green Data Center &#8211; Truth behind the hype</a></li>
<li><a href="http://www.colinmcnamara.com/ciscos-cloud-computing-offering/" rel="bookmark" title="April 7, 2009">Cisco&#8217;s Cloud Computing Offering</a></li>
<li><a href="http://www.colinmcnamara.com/about/" rel="bookmark" title="January 5, 2008">About Colin McNamara</a></li>
<li><a href="http://www.colinmcnamara.com/vote-for-my-vmworld-presentation-shameless-pandering/" rel="bookmark" title="May 12, 2011">Vote for my VMworld presentation &#8211; #3221 Built to fail (shameless pandering)</a></li>
<li><a href="http://www.colinmcnamara.com/remote-site-security-cisco-analog-video-gateway-video-management-storage-system-network-modules-on-the-integrated-services-router-isr/" rel="bookmark" title="June 10, 2008">Simplifying remote site security with Cisco&#8217;s new video surveillance modules on the ISR</a></li>
<li><a href="http://www.colinmcnamara.com/interesting-techwise-tv-episode-on-virtualization/" rel="bookmark" title="October 23, 2008">Interesting TechWise TV episode on  virtualization</a></li>
</ul>
<p><!-- Similar Posts took 54.308 ms --></p>
<p>--Colin McNamara
<br/><br/><a href="http://www.colinmcnamara.com/measuring-and-mitigating-risk-involved-with-sharing-virtual-infrastructure-between-dmz-and-internal-environments/">Measuring and mitigating risk involved with sharing virtual infrastructure between DMZ and Internal environments</a></p>

	Tags: <a href="http://www.colinmcnamara.com/technology-tags/blog/" title="blog" rel="tag">blog</a>, <a href="http://www.colinmcnamara.com/technology-tags/breach/" title="breach" rel="tag">breach</a>, <a href="http://www.colinmcnamara.com/technology-tags/business-context/" title="business context" rel="tag">business context</a>, <a href="http://www.colinmcnamara.com/technology-tags/c/" title="C" rel="tag">C</a>, <a href="http://www.colinmcnamara.com/technology-tags/cisco/" title="CISCO" rel="tag">CISCO</a>, <a href="http://www.colinmcnamara.com/technology-tags/colin/" title="Colin" rel="tag">Colin</a>, <a href="http://www.colinmcnamara.com/technology-tags/compromise/" title="compromise" rel="tag">compromise</a>, <a href="http://www.colinmcnamara.com/technology-tags/data-center/" title="Data Center" rel="tag">Data Center</a>, <a href="http://www.colinmcnamara.com/technology-tags/design/" title="DESIGN" rel="tag">DESIGN</a>, <a href="http://www.colinmcnamara.com/technology-tags/device-contexts/" title="device contexts" rel="tag">device contexts</a>, <a href="http://www.colinmcnamara.com/technology-tags/enhancements/" title="enhancements" rel="tag">enhancements</a>, <a href="http://www.colinmcnamara.com/technology-tags/fcoe/" title="FCOE" rel="tag">FCOE</a>, <a href="http://www.colinmcnamara.com/technology-tags/hp/" title="HP" rel="tag">HP</a>, <a href="http://www.colinmcnamara.com/technology-tags/hyper-v/" title="hyper-v" rel="tag">hyper-v</a>, <a href="http://www.colinmcnamara.com/technology-tags/instances/" title="Instances" rel="tag">Instances</a>, <a href="http://www.colinmcnamara.com/technology-tags/linux/" title="linux" rel="tag">linux</a>, <a href="http://www.colinmcnamara.com/technology-tags/nda/" title="NDA" rel="tag">NDA</a>, <a href="http://www.colinmcnamara.com/technology-tags/network/" title="Network" rel="tag">Network</a>, <a href="http://www.colinmcnamara.com/technology-tags/network-infrastructure/" title="network infrastructure" rel="tag">network infrastructure</a>, <a href="http://www.colinmcnamara.com/technology-tags/nexus-5020/" title="Nexus 5020" rel="tag">Nexus 5020</a>, <a href="http://www.colinmcnamara.com/technology-tags/passed/" title="passed" rel="tag">passed</a>, <a href="http://www.colinmcnamara.com/technology-tags/pic/" title="Pic" rel="tag">Pic</a>, <a href="http://www.colinmcnamara.com/technology-tags/risk-risk/" title="risk risk" rel="tag">risk risk</a>, <a href="http://www.colinmcnamara.com/technology-tags/san/" title="san" rel="tag">san</a>, <a href="http://www.colinmcnamara.com/technology-tags/security/" title="security" rel="tag">security</a>, <a href="http://www.colinmcnamara.com/technology-tags/storage/" title="storage" rel="tag">storage</a>, <a href="http://www.colinmcnamara.com/technology-tags/switch/" title="switch" rel="tag">switch</a>, <a href="http://www.colinmcnamara.com/technology-tags/threat/" title="threat" rel="tag">threat</a>, <a href="http://www.colinmcnamara.com/technology-tags/trustsec/" title="TrustSec" rel="tag">TrustSec</a>, <a href="http://www.colinmcnamara.com/technology-tags/virtual-device/" title="virtual device" rel="tag">virtual device</a>, <a href="http://www.colinmcnamara.com/technology-tags/virtualization/" title="virtualization" rel="tag">virtualization</a>, <a href="http://www.colinmcnamara.com/technology-tags/vlan/" title="vlan" rel="tag">vlan</a>, <a href="http://www.colinmcnamara.com/technology-tags/vmware/" title="vmware" rel="tag">vmware</a>, <a href="http://www.colinmcnamara.com/technology-tags/vulnerability/" title="vulnerability" rel="tag">vulnerability</a><br />
]]></content:encoded>
			<wfw:commentRss>http://www.colinmcnamara.com/measuring-and-mitigating-risk-involved-with-sharing-virtual-infrastructure-between-dmz-and-internal-environments/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Identity aware networking using Cisco TrustSec</title>
		<link>http://www.colinmcnamara.com/identity-aware-networking-using-cisco-trustsec/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=identity-aware-networking-using-cisco-trustsec</link>
		<comments>http://www.colinmcnamara.com/identity-aware-networking-using-cisco-trustsec/#comments</comments>
		<pubDate>Sun, 24 Feb 2008 07:13:07 +0000</pubDate>
		<dc:creator>colinmcnamara</dc:creator>
				<category><![CDATA[CISCO]]></category>
		<category><![CDATA[DC3.0]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[C]]></category>
		<category><![CDATA[Data Center]]></category>
		<category><![CDATA[DESIGN]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[GLBA]]></category>
		<category><![CDATA[HIPPA]]></category>
		<category><![CDATA[HP]]></category>
		<category><![CDATA[MPLS]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[network infrastructure]]></category>
		<category><![CDATA[Nexus]]></category>
		<category><![CDATA[Nexus 7000]]></category>
		<category><![CDATA[Sarbanes Oxley]]></category>
		<category><![CDATA[SOX]]></category>
		<category><![CDATA[switch]]></category>
		<category><![CDATA[TrustSec]]></category>
		<category><![CDATA[vlan]]></category>

		<guid isPermaLink="false">http://www.colinmcnamara.com/2008/02/23/identity-aware-networking-using-cisco-trustsec</guid>
		<description><![CDATA[With all the fanfare surrounding the recent Nexus 7000 release I think many people have missed a significant new development in Cisco&#8217;s security portfolio. That new development is Cisco TrustSec. TrustSec takes the classic notion of access control based source and destination ip:ports and replaces it with a role and resource based methodology that fits [...]<p>--Colin McNamara
<br/><br/><a href="http://www.colinmcnamara.com/identity-aware-networking-using-cisco-trustsec/">Identity aware networking using Cisco TrustSec</a></p>
]]></description>
			<content:encoded><![CDATA[<p>With all the fanfare surrounding the recent Nexus 7000 release I think many people have missed a significant new development in Cisco&#8217;s security portfolio. That new development is Cisco TrustSec. TrustSec takes the classic notion of access control based source and destination ip:ports and replaces it with a role and resource based methodology that fits quite nicely with security requirements driven by information assurance groups. It also brings link security on certain platforms using the 802.1ae protocol that encrypts high speed links at line rate without taking a performance hit.</p>
<p>Cisco TrustSec starts at the edge by negotiating a secure link if both hosts support it (802.1ae). This is similar to wireless encryption schemes, where a secure handshake is established and the L2 path become impervious to sniffing. This is user configurable, and to my knowledge the asics available to support line rate encryption are currently only on the Nexus 7000 blades.</p>
<p>The next step is to start 802.1x negotiations. For the people not familiar with 802.1x, it is a way of passing username / password information from your computer up into the network infrastructure. Once this is completed, the switch can not only utilise tools like NAC to place you into the appropriate quarantine, or access vlans, but it also know knows your identity.</p>
<p>Now the &#8220;network&#8221; is aware of your identity, a new level of granular security control can be deployed across your infrastructure. These security policies can map into &#8220;user x can connect to webserver y&#8221; instead of being restricted by ip and port. This allows you to utilize true roles based administration similar to what you use in your Windows and Unix file systems, but now you can do this across the network.</p>
<p>How is this done ? I like to think of this as a mix between dscp and mpls tags. Which in a nutshell means that when traffic enters the network it is tagged with a small amount of additional &#8220;identity: information which is retained as it traverses the network. This information can be used to augment or completely replace your current ACL based security controls in a way that enables you to more effectively comply with complex regulatory environments such as PCI, SOX, GLBA and HPPA.</p>
<p>Over the past few years we have learned how to leverage intelligence in the the network by utilizing tools like QOS, MPLS VPN&#8217;s, and many others. Expect to add Cisco TrustSec to your quiver of tricks to address the ever growing compliance needs faced by today&#8217;s network designers.</p>
<p><a href="http://www.cisco.com/en/US/netsol/ns774/networking_solutions_package.html" title="http://www.cisco.com/en/US/netsol/ns774/networking_solutions_package.html" target="_blank">Learn more about Cisco TrustSec</a><strong>Similar Posts:</strong>
<ul class="similar-posts">
<li><a href="http://www.colinmcnamara.com/cisco-nexus-7000-datacenter-switch-released-welcome-to-datacenter-30/" rel="bookmark" title="January 28, 2008">Cisco Nexus 7000 DataCenter switch released &#8211; Welcome to DataCenter 3.0</a></li>
<li><a href="http://www.colinmcnamara.com/encrypting-your-backup-tapes-with-cisco-storage-media-encryption-sme/" rel="bookmark" title="May 3, 2008">Encrypting your backup tapes with Cisco Storage Media Encryption (SME)</a></li>
<li><a href="http://www.colinmcnamara.com/altor-virtual-network-security-analyzer-vnsa-integrated-with-ciscos-nexus-1000v-for-vmware/" rel="bookmark" title="September 17, 2008">Altor Virtual Network Security Analyzer (VNSA) integrated with Cisco&#8217;s Nexus 1000v for VMware</a></li>
<li><a href="http://www.colinmcnamara.com/cisco-releases-nexus-1000v-virtual-switch-for-vmware/" rel="bookmark" title="September 16, 2008">Cisco releases Nexus 1000V virtual switch for VMware</a></li>
<li><a href="http://www.colinmcnamara.com/zone-based-ios-firewalls/" rel="bookmark" title="October 15, 2007">Zone based IOS firewalls</a></li>
<li><a href="http://www.colinmcnamara.com/cisco-nexus-4000-blade-switch/" rel="bookmark" title="September 29, 2009">Cisco Nexus 4000 Blade Switch</a></li>
</ul>
<p><!-- Similar Posts took 35.197 ms --></p>
<p>--Colin McNamara
<br/><br/><a href="http://www.colinmcnamara.com/identity-aware-networking-using-cisco-trustsec/">Identity aware networking using Cisco TrustSec</a></p>

	Tags: <a href="http://www.colinmcnamara.com/technology-tags/c/" title="C" rel="tag">C</a>, <a href="http://www.colinmcnamara.com/technology-tags/cisco/" title="CISCO" rel="tag">CISCO</a>, <a href="http://www.colinmcnamara.com/technology-tags/data-center/" title="Data Center" rel="tag">Data Center</a>, <a href="http://www.colinmcnamara.com/technology-tags/dc30/" title="DC3.0" rel="tag">DC3.0</a>, <a href="http://www.colinmcnamara.com/technology-tags/design/" title="DESIGN" rel="tag">DESIGN</a>, <a href="http://www.colinmcnamara.com/technology-tags/encryption/" title="encryption" rel="tag">encryption</a>, <a href="http://www.colinmcnamara.com/technology-tags/glba/" title="GLBA" rel="tag">GLBA</a>, <a href="http://www.colinmcnamara.com/technology-tags/hippa/" title="HIPPA" rel="tag">HIPPA</a>, <a href="http://www.colinmcnamara.com/technology-tags/hp/" title="HP" rel="tag">HP</a>, <a href="http://www.colinmcnamara.com/technology-tags/mpls/" title="MPLS" rel="tag">MPLS</a>, <a href="http://www.colinmcnamara.com/technology-tags/network/" title="Network" rel="tag">Network</a>, <a href="http://www.colinmcnamara.com/technology-tags/network-infrastructure/" title="network infrastructure" rel="tag">network infrastructure</a>, <a href="http://www.colinmcnamara.com/technology-tags/nexus/" title="Nexus" rel="tag">Nexus</a>, <a href="http://www.colinmcnamara.com/technology-tags/nexus-7000/" title="Nexus 7000" rel="tag">Nexus 7000</a>, <a href="http://www.colinmcnamara.com/technology-tags/sarbanes-oxley/" title="Sarbanes Oxley" rel="tag">Sarbanes Oxley</a>, <a href="http://www.colinmcnamara.com/technology-tags/security/" title="security" rel="tag">security</a>, <a href="http://www.colinmcnamara.com/technology-tags/sox/" title="SOX" rel="tag">SOX</a>, <a href="http://www.colinmcnamara.com/technology-tags/switch/" title="switch" rel="tag">switch</a>, <a href="http://www.colinmcnamara.com/technology-tags/trustsec/" title="TrustSec" rel="tag">TrustSec</a>, <a href="http://www.colinmcnamara.com/technology-tags/vlan/" title="vlan" rel="tag">vlan</a><br />
]]></content:encoded>
			<wfw:commentRss>http://www.colinmcnamara.com/identity-aware-networking-using-cisco-trustsec/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Moving towards a Green Data Center &#8211; Truth behind the hype</title>
		<link>http://www.colinmcnamara.com/moving-towards-a-green-data-center-truth-behind-the-hype/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=moving-towards-a-green-data-center-truth-behind-the-hype</link>
		<comments>http://www.colinmcnamara.com/moving-towards-a-green-data-center-truth-behind-the-hype/#comments</comments>
		<pubDate>Fri, 22 Feb 2008 21:53:56 +0000</pubDate>
		<dc:creator>colinmcnamara</dc:creator>
				<category><![CDATA[CISCO]]></category>
		<category><![CDATA[DC3.0]]></category>
		<category><![CDATA[efficiency]]></category>
		<category><![CDATA[Green Data Center]]></category>
		<category><![CDATA[]]></category>
		<category><![CDATA[C]]></category>
		<category><![CDATA[Data Center]]></category>
		<category><![CDATA[eplus]]></category>
		<category><![CDATA[HP]]></category>
		<category><![CDATA[MPLS]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[network infrastructure]]></category>
		<category><![CDATA[PG&E]]></category>
		<category><![CDATA[Power]]></category>
		<category><![CDATA[Provider]]></category>
		<category><![CDATA[service provider]]></category>
		<category><![CDATA[switch]]></category>
		<category><![CDATA[virtualization]]></category>
		<category><![CDATA[vmware]]></category>

		<guid isPermaLink="false">http://www.colinmcnamara.com/2008/02/22/moving-towards-a-green-data-center-truth-behind-the-hype</guid>
		<description><![CDATA[Eplus, Cisco, Hewlett Packard and PG&#38;E held a luncheon this last Friday focused on Green Data Center. I&#8217;ll be the first to admit that at first I thought &#8220;green&#8221; Data Center initiatives were just political and corporate marketing initiatives. I thought they saw Al Gore give some rocking presentation and decided it would be great [...]<p>--Colin McNamara
<br/><br/><a href="http://www.colinmcnamara.com/moving-towards-a-green-data-center-truth-behind-the-hype/">Moving towards a Green Data Center &#8211; Truth behind the hype</a></p>
]]></description>
			<content:encoded><![CDATA[<p>Eplus, Cisco, Hewlett Packard and PG&amp;E held a luncheon this last Friday focused on Green Data Center. I&#8217;ll be the first to admit that at first I thought &#8220;green&#8221; Data Center initiatives were just political and corporate marketing initiatives. I thought they saw Al Gore give some rocking presentation and decided it would be great to market their products as &#8220;green&#8221; while continuing to spew toxins and club baby seals in their manufacturing plants.</p>
<p>I was wrong, the Green Data Center is not about saving baby seals, it is about saving cold hard cash. Saving the world is just a nice side benefit.</p>
<p>That being said, saving cold hard cash is a very important discussion item in any IT Operations group as they are normally seen as a cost center. For them, a penny saved is literally a penny earned. Not only can you save money by not paying for power, but PG&amp;E will actually has a budget to pay you NOT to use their power. Most people here this and get a puzzled look on their face. &#8220;why would the power company, who makes money on power, not want me to buy it from them?&#8221; The answer is that Californians use more power then PG&amp;E can produce at peak times. When they have to buy it from another state it can cost them 10 times or more then they charge us. This is the reason why PG&amp;E will pay you to use less. Each penny they give to the consumer for saving a watt, saves them 4 pennies (80% return on investment).</p>
<p><strong>Great, PG&amp;E saves money by giving it to me. How do I get this cash? Well there are a couple ways to get this.</strong></p>
<ol>
<li>Incentives for new buying new energy efficient servers</li>
<li>Rebates for moving to virtualized servers</li>
<li>Rebates and incentives for moving to thin client desktop systems</li>
<li>Audit teams for cooling and power if your Data Center is 10,000 square feet or more</li>
<li>Incentives for airflow control systems</li>
<li>Incentives for high efficiency UPS and power distribution systems</li>
<li>Technical services for cooling system evaluation (PG&amp;E funded)</li>
</ol>
<p>That is a pretty comprehensive list of how to get money from the power company, but you can save even more money buy not using the power in the first place. Not unsurprisingly this starts with the server.</p>
<p>First thing you can do, is virtualize, virtualize, and virtualize some more. For most people this means VMware. For others this may mean Xen, or Microsofts virtualization product. Whatever flavor you chose, the key message is to consolidate from many servers to few. A server sitting &#8220;idle&#8221; still pulls 50% of its max current. Now, howe many servers do you have that are just sitting there? My guess is a large amount. By virtualizing these servers, you allow them to be stacked onto high performance server that can be run at a higher utilization. This lowers the over all power utilization for your DataCenter. Another side benefit is that ever watt that you remove from a server, you get another watt removed from your cooling.</p>
<p>These same virtualization techniques can also be applied to your network devices, which account for 6 to 12 percent of your datacenters power draw.</p>
<p>Ask yourself a few questions</p>
<ul>
<li> &#8221; Do I need 4 different firewall clusters?&#8221;. It is likely that these are leftovers from organic growth, and that you could consolidate them into virtual firewalls on a more efficient chassis (ASA comes to mind).</li>
<li>&#8221; Do I need to maintain physically separate infrastructure?&#8221;. There are technologies like MPLS, VFR-Lite, Virtual Switching and more that allow you to consolidate onto a shared network infrastructure, taking a service provider approach to providing transport in your network.</li>
<li>&#8221; Am I running old inefficient gear?&#8221;. Power supplies have increased in efficiency over the last few years. There may be a good return on investment for you to upgrade.</li>
<li>&#8221; Can I consolidate into larger chassis?&#8221;. Ask the question, which is more efficient &#8211; a closet full of 3560&#8242;s or a 4507? There is efficiency in scaling out.</li>
</ul>
<p>I hope that reading this has caused you to ask some questions, and maybe look at the larger impact of your network operations on both the ecosystem and your operational expenses. With these questions in hand, you might want to talk to PG&amp;E and your Cisco / HP parter about going &#8220;Green&#8221; in the data center.<strong>Similar Posts:</strong>
<ul class="similar-posts">
<li><a href="http://www.colinmcnamara.com/is-your-network-ready-for-cloud-computing-with-virtual-infrastructure-4/" rel="bookmark" title="November 3, 2008">Is your network ready for Cloud Computing with Virtual Infrastructure 4?</a></li>
<li><a href="http://www.colinmcnamara.com/ciscos-cloud-computing-offering/" rel="bookmark" title="April 7, 2009">Cisco&#8217;s Cloud Computing Offering</a></li>
<li><a href="http://www.colinmcnamara.com/usability-features-in-ciscos-nexus-7000/" rel="bookmark" title="February 7, 2008">Usability features in Cisco&#8217;s Nexus 7000</a></li>
<li><a href="http://www.colinmcnamara.com/cisco-introduces-the-c-series-rack-servers/" rel="bookmark" title="June 4, 2009">Cisco introduces the C-Series Rack Servers</a></li>
<li><a href="http://www.colinmcnamara.com/42/" rel="bookmark" title="August 12, 2007">New features in VMware 3.1</a></li>
<li><a href="http://www.colinmcnamara.com/remote-site-security-cisco-analog-video-gateway-video-management-storage-system-network-modules-on-the-integrated-services-router-isr/" rel="bookmark" title="June 10, 2008">Simplifying remote site security with Cisco&#8217;s new video surveillance modules on the ISR</a></li>
</ul>
<p><!-- Similar Posts took 33.195 ms --></p>
<p>--Colin McNamara
<br/><br/><a href="http://www.colinmcnamara.com/moving-towards-a-green-data-center-truth-behind-the-hype/">Moving towards a Green Data Center &#8211; Truth behind the hype</a></p>

	Tags: <a href="http://www.colinmcnamara.com/technology-tags/145/" title="" rel="tag"></a>, <a href="http://www.colinmcnamara.com/technology-tags/c/" title="C" rel="tag">C</a>, <a href="http://www.colinmcnamara.com/technology-tags/cisco/" title="CISCO" rel="tag">CISCO</a>, <a href="http://www.colinmcnamara.com/technology-tags/data-center/" title="Data Center" rel="tag">Data Center</a>, <a href="http://www.colinmcnamara.com/technology-tags/eplus/" title="eplus" rel="tag">eplus</a>, <a href="http://www.colinmcnamara.com/technology-tags/green-data-center/" title="Green Data Center" rel="tag">Green Data Center</a>, <a href="http://www.colinmcnamara.com/technology-tags/hp/" title="HP" rel="tag">HP</a>, <a href="http://www.colinmcnamara.com/technology-tags/mpls/" title="MPLS" rel="tag">MPLS</a>, <a href="http://www.colinmcnamara.com/technology-tags/network/" title="Network" rel="tag">Network</a>, <a href="http://www.colinmcnamara.com/technology-tags/network-infrastructure/" title="network infrastructure" rel="tag">network infrastructure</a>, <a href="http://www.colinmcnamara.com/technology-tags/pge/" title="PG&amp;E" rel="tag">PG&amp;E</a>, <a href="http://www.colinmcnamara.com/technology-tags/power/" title="Power" rel="tag">Power</a>, <a href="http://www.colinmcnamara.com/technology-tags/provider/" title="Provider" rel="tag">Provider</a>, <a href="http://www.colinmcnamara.com/technology-tags/service-provider/" title="service provider" rel="tag">service provider</a>, <a href="http://www.colinmcnamara.com/technology-tags/switch/" title="switch" rel="tag">switch</a>, <a href="http://www.colinmcnamara.com/technology-tags/virtualization/" title="virtualization" rel="tag">virtualization</a>, <a href="http://www.colinmcnamara.com/technology-tags/vmware/" title="vmware" rel="tag">vmware</a><br />
]]></content:encoded>
			<wfw:commentRss>http://www.colinmcnamara.com/moving-towards-a-green-data-center-truth-behind-the-hype/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Cisco Certified Design Expert &#8211; CCDE &#8211; officially released by Cisco</title>
		<link>http://www.colinmcnamara.com/cisco-certified-design-expert-ccde-officially-released-by-cisco/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=cisco-certified-design-expert-ccde-officially-released-by-cisco</link>
		<comments>http://www.colinmcnamara.com/cisco-certified-design-expert-ccde-officially-released-by-cisco/#comments</comments>
		<pubDate>Tue, 22 Jan 2008 20:24:56 +0000</pubDate>
		<dc:creator>colinmcnamara</dc:creator>
				<category><![CDATA[CCDE]]></category>
		<category><![CDATA[CCIE]]></category>
		<category><![CDATA[certification]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[C]]></category>
		<category><![CDATA[CISCO]]></category>
		<category><![CDATA[DESIGN]]></category>
		<category><![CDATA[eplus]]></category>
		<category><![CDATA[funny]]></category>
		<category><![CDATA[NDA]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[network infrastructure]]></category>
		<category><![CDATA[Provider]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[service provider]]></category>
		<category><![CDATA[storage]]></category>

		<guid isPermaLink="false">http://www.colinmcnamara.com/2008/01/22/cisco-certified-design-expert-ccde-officially-released-by-cisco</guid>
		<description><![CDATA[ Today was the official release date for the CCDE exam. To quote Cisco - &#8220;CCDE Assesses advanced Network Infrastructure Design Principles and Fundamentals for large networks. A CCDE can demonstrate an ability to develop solutions which address planning, design, integration, optimization, operations, security and ongoing support focused at the infrastructure level for customer networks&#8221; For [...]<p>--Colin McNamara
<br/><br/><a href="http://www.colinmcnamara.com/cisco-certified-design-expert-ccde-officially-released-by-cisco/">Cisco Certified Design Expert &#8211; CCDE &#8211; officially released by Cisco</a></p>
]]></description>
			<content:encoded><![CDATA[<p> Today was the official release date for the CCDE exam. To quote Cisco -<br />
&#8220;CCDE Assesses advanced Network Infrastructure Design Principles and Fundamentals for large networks. A CCDE can demonstrate an ability to develop solutions which address planning, design, integration, optimization, operations, security and ongoing support focused at the infrastructure level for customer networks&#8221;</p>
<p>For the engineering perspective on this, the CCDE is equivalent  to the CCIE. However, the CCDE is focused on design and architecture rather then implementation. Where the CCIE (R&amp;S, Voice, Security, Service Provider, Storage) is focused on implementation, the CCDE is focused more on the pre-sales design and architecture efforts. I am personally looking forward to the lab being released, as it provides a certification to validate the skill set needed to be an sales engineer on Enterprise accounts, or to be a network architect at an Enterprise corporation.</p>
<p>It is funny how small a world it is. Eplus (the company I work for) CEO &#8211; Phil Norton was quoted on Cisco&#8217;s press release -</p>
<p>&#8220;Certifications provide a stamp of approval that validates the quality of our organization&#8217;s employees,&#8221; said Phil Norton, chairman, CEO and president of ePlus. &#8220;The CCDE isn&#8217;t about operations; it&#8217;s about recognizing the value of network designers and honoring their core skills that provide a real value to our business and our customers.&#8221;</p>
<p>My gut feel when I first got invited to the CCDE beta program was that this will become a requirement for the Channel. I think Phil&#8217;s statement cements that gut feel into a reality. Obtaining a CCDE will become similar to the CCIE &#8211; a check box that you must attain to work with the top VAR&#8217;s out there. This makes me extremely grateful that I was lucky enough to be invited into the beta group to be allowed first crack at this gem of a certification.<strong>Similar Posts:</strong>
<ul class="similar-posts">
<li><a href="http://www.colinmcnamara.com/its-on-like-donkey-kong-ccde-practical-registration-is-open/" rel="bookmark" title="July 10, 2008">It&#8217;s on like Donkey Kong &#8211; CCDE practical registration is open</a></li>
<li><a href="http://www.colinmcnamara.com/ccde-practical-beta-candidate-deadline-august-1-2008/" rel="bookmark" title="July 21, 2008">CCDE Practical &#8211; Beta candidate deadline August 1 2008</a></li>
<li><a href="http://www.colinmcnamara.com/cisco-certified-architect-board-examination-above-the-ccie-and-ccde/" rel="bookmark" title="June 29, 2009">Cisco Certified Architect &#8211; Board examination above the CCIE and CCDE</a></li>
<li><a href="http://www.colinmcnamara.com/are-you-a-kick-ass-engineer-looking-to-grow/" rel="bookmark" title="March 1, 2011">Are you a kick ass engineer looking to grow?</a></li>
<li><a href="http://www.colinmcnamara.com/challenges-integrating-vmware-into-cisco-networks/" rel="bookmark" title="March 15, 2008">Challenges integrating VMware into Cisco networks</a></li>
<li><a href="http://www.colinmcnamara.com/about/" rel="bookmark" title="January 5, 2008">About Colin McNamara</a></li>
</ul>
<p><!-- Similar Posts took 42.444 ms --></p>
<p>--Colin McNamara
<br/><br/><a href="http://www.colinmcnamara.com/cisco-certified-design-expert-ccde-officially-released-by-cisco/">Cisco Certified Design Expert &#8211; CCDE &#8211; officially released by Cisco</a></p>

	Tags: <a href="http://www.colinmcnamara.com/technology-tags/c/" title="C" rel="tag">C</a>, <a href="http://www.colinmcnamara.com/technology-tags/ccde/" title="CCDE" rel="tag">CCDE</a>, <a href="http://www.colinmcnamara.com/technology-tags/ccie/" title="CCIE" rel="tag">CCIE</a>, <a href="http://www.colinmcnamara.com/technology-tags/certification/" title="certification" rel="tag">certification</a>, <a href="http://www.colinmcnamara.com/technology-tags/cisco/" title="CISCO" rel="tag">CISCO</a>, <a href="http://www.colinmcnamara.com/technology-tags/design/" title="DESIGN" rel="tag">DESIGN</a>, <a href="http://www.colinmcnamara.com/technology-tags/eplus/" title="eplus" rel="tag">eplus</a>, <a href="http://www.colinmcnamara.com/technology-tags/funny/" title="funny" rel="tag">funny</a>, <a href="http://www.colinmcnamara.com/technology-tags/nda/" title="NDA" rel="tag">NDA</a>, <a href="http://www.colinmcnamara.com/technology-tags/network/" title="Network" rel="tag">Network</a>, <a href="http://www.colinmcnamara.com/technology-tags/network-infrastructure/" title="network infrastructure" rel="tag">network infrastructure</a>, <a href="http://www.colinmcnamara.com/technology-tags/provider/" title="Provider" rel="tag">Provider</a>, <a href="http://www.colinmcnamara.com/technology-tags/security/" title="security" rel="tag">security</a>, <a href="http://www.colinmcnamara.com/technology-tags/service-provider/" title="service provider" rel="tag">service provider</a>, <a href="http://www.colinmcnamara.com/technology-tags/storage/" title="storage" rel="tag">storage</a>, <a href="http://www.colinmcnamara.com/technology-tags/technology/" title="Technology" rel="tag">Technology</a><br />
]]></content:encoded>
			<wfw:commentRss>http://www.colinmcnamara.com/cisco-certified-design-expert-ccde-officially-released-by-cisco/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>About Colin McNamara</title>
		<link>http://www.colinmcnamara.com/about/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=about</link>
		<comments>http://www.colinmcnamara.com/about/#comments</comments>
		<pubDate>Sun, 06 Jan 2008 04:35:55 +0000</pubDate>
		<dc:creator>colinmcnamara</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[CCIE]]></category>
		<category><![CDATA[ccie certifications]]></category>
		<category><![CDATA[certification]]></category>
		<category><![CDATA[Colin]]></category>
		<category><![CDATA[Data Center]]></category>
		<category><![CDATA[DESIGN]]></category>
		<category><![CDATA[eplus]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[network infrastructure]]></category>
		<category><![CDATA[photography]]></category>
		<category><![CDATA[Provider]]></category>
		<category><![CDATA[san]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[service provider]]></category>
		<category><![CDATA[storage]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[virtualization]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Colin McNamara is a seasoned professional with over 10 years experience with network technologies. Holding many certifications, including CCIE, VCP and RHCE, he specializes in enterprise network design, with a focus on converged data center technologies. Colin is best known for providing designs that incorporate disparate technologies under a shared virtualized infrastructure. He is a [...]<p>--Colin McNamara
<br/><br/><a href="http://www.colinmcnamara.com/about/">About Colin McNamara</a></p>
]]></description>
			<content:encoded><![CDATA[<p>Colin McNamara is a seasoned professional with over 10 years experience with network technologies. Holding many certifications, including CCIE, VCP and RHCE, he specializes in enterprise network design, with a focus on converged data center technologies.</p>
<p>Colin is best known for providing designs that incorporate disparate technologies under a shared virtualized infrastructure. He is a proponent of both network virtualization and the utilization of service provider technologies inside enterprise networks to support the security delivery of Voice, Video, Storage and Real Time Application traffic over shared network infrastructure.</p>
<p>He resides in the San Ramon (San Francisco Bay Area) , California with his <a title="http://www.ashleymcnamara.com" href="http://www.ashleymcnamara.com" target="_blank">Wife</a> and <a title="http://www.flickr.com/photos/ashleymcnamaraphotography/sets/72157602266182074/" href="http://www.flickr.com/photos/ashleymcnamaraphotography/sets/72157602266182074/" target="_blank">two kids</a>. And is active in multiple boards and organizations, including -</p>
<ul>
<li>Cisco Partner Technology Advisory Board</li>
<li>Consortium of Internet Technology Experts</li>
</ul>
<p>He can be contacted via information found on his <a title="http://www.colinmcnamara.com/resume-colin-mcnamara-ccie-18233" href="http://www.colinmcnamara.com/resume-colin-mcnamara-ccie-18233" target="_blank">CCIE Resume page</a> . by contacting him via <a title="http://www.linkedin.com/in/colinmcnamara" href="http://www.linkedin.com/in/colinmcnamara">Linkedin</a> or at colin@2cups.com</p>
<p style="margin-bottom: 0in;">
<p><strong>Similar Posts:</strong>
<ul class="similar-posts">
<li><a href="http://www.colinmcnamara.com/colin-has-left-eplus-technology/" rel="bookmark" title="June 9, 2011">Colin has left ePlus Technology</a></li>
<li><a href="http://www.colinmcnamara.com/41/" rel="bookmark" title="August 10, 2007">Cool new features in 12.4(15)T</a></li>
<li><a href="http://www.colinmcnamara.com/are-you-a-kick-ass-engineer-looking-to-grow/" rel="bookmark" title="March 1, 2011">Are you a kick ass engineer looking to grow?</a></li>
<li><a href="http://www.colinmcnamara.com/resume-colin-mcnamara-ccie-18233/" rel="bookmark" title="January 6, 2008">Resume &#8211; Colin McNamara, CCIE #18233</a></li>
<li><a href="http://www.colinmcnamara.com/ill-be-at-cisco-live-2008-networkers-in-orlando-all-week/" rel="bookmark" title="June 23, 2008">I&#8217;ll be at Cisco Live 2008 (networkers) in Orlando all week</a></li>
<li><a href="http://www.colinmcnamara.com/cisco-nx-os-40-next-generation-internet-operating-system/" rel="bookmark" title="January 29, 2008">Cisco NX-OS 4.0 | Next Generation Internet Operating System</a></li>
</ul>
<p><!-- Similar Posts took 30.721 ms --></p>
<p>--Colin McNamara
<br/><br/><a href="http://www.colinmcnamara.com/about/">About Colin McNamara</a></p>

	Tags: <a href="http://www.colinmcnamara.com/technology-tags/ccie/" title="CCIE" rel="tag">CCIE</a>, <a href="http://www.colinmcnamara.com/technology-tags/ccie-certifications/" title="ccie certifications" rel="tag">ccie certifications</a>, <a href="http://www.colinmcnamara.com/technology-tags/certification/" title="certification" rel="tag">certification</a>, <a href="http://www.colinmcnamara.com/technology-tags/colin/" title="Colin" rel="tag">Colin</a>, <a href="http://www.colinmcnamara.com/technology-tags/data-center/" title="Data Center" rel="tag">Data Center</a>, <a href="http://www.colinmcnamara.com/technology-tags/design/" title="DESIGN" rel="tag">DESIGN</a>, <a href="http://www.colinmcnamara.com/technology-tags/eplus/" title="eplus" rel="tag">eplus</a>, <a href="http://www.colinmcnamara.com/technology-tags/network/" title="Network" rel="tag">Network</a>, <a href="http://www.colinmcnamara.com/technology-tags/network-infrastructure/" title="network infrastructure" rel="tag">network infrastructure</a>, <a href="http://www.colinmcnamara.com/technology-tags/photography/" title="photography" rel="tag">photography</a>, <a href="http://www.colinmcnamara.com/technology-tags/provider/" title="Provider" rel="tag">Provider</a>, <a href="http://www.colinmcnamara.com/technology-tags/san/" title="san" rel="tag">san</a>, <a href="http://www.colinmcnamara.com/technology-tags/security/" title="security" rel="tag">security</a>, <a href="http://www.colinmcnamara.com/technology-tags/service-provider/" title="service provider" rel="tag">service provider</a>, <a href="http://www.colinmcnamara.com/technology-tags/storage/" title="storage" rel="tag">storage</a>, <a href="http://www.colinmcnamara.com/technology-tags/technology/" title="Technology" rel="tag">Technology</a>, <a href="http://www.colinmcnamara.com/technology-tags/virtualization/" title="virtualization" rel="tag">virtualization</a><br />
]]></content:encoded>
			<wfw:commentRss>http://www.colinmcnamara.com/about/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

