<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Colin McNamara - CCIE 18233 , VCP, RHCE, GCIH, GEEK &#187; TrustSec</title>
	<atom:link href="http://www.colinmcnamara.com/technology-tags/trustsec/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.colinmcnamara.com</link>
	<description>Technical reviews and articles from a CCIE with extensive experience in designing and implementing converged enterprise networks.</description>
	<lastBuildDate>Wed, 28 Jul 2010 18:40:09 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>Cisco&#8217;s Cloud Computing Offering</title>
		<link>http://www.colinmcnamara.com/ciscos-cloud-computing-offering/</link>
		<comments>http://www.colinmcnamara.com/ciscos-cloud-computing-offering/#comments</comments>
		<pubDate>Tue, 07 Apr 2009 16:00:52 +0000</pubDate>
		<dc:creator>colinmcnamara</dc:creator>
				<category><![CDATA[CISCO]]></category>
		<category><![CDATA[Cisco Unified Computing System]]></category>
		<category><![CDATA[Cisco Unified Computing System Managerm UCSM]]></category>
		<category><![CDATA[DC3.0]]></category>
		<category><![CDATA[FCOE]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[cloud computing]]></category>
		<category><![CDATA[vSphere]]></category>
		<category><![CDATA[virtualization]]></category>
		<category><![CDATA[vmware]]></category>
		<category><![CDATA[CCIE]]></category>
		<category><![CDATA[Data Center]]></category>
		<category><![CDATA[paravirtualization]]></category>
		<category><![CDATA[TrustSec]]></category>
		<category><![CDATA[Unified Computing System]]></category>

		<guid isPermaLink="false">http://www.colinmcnamara.com/?p=548</guid>
		<description><![CDATA[Right now Cloud Computing is either the biggest threat that Cisco Systems has ever faced, or the biggest opportunity that Cisco has ever been presented with. How will Cisco react? <p>--Colin McNamara
<br/><br/><a href="http://www.colinmcnamara.com/ciscos-cloud-computing-offering/">Cisco&#8217;s Cloud Computing Offering</a></p>
]]></description>
			<content:encoded><![CDATA[<p>Right now Cloud Computing is either the biggest threat that Cisco Systems has ever faced, or the biggest opportunity that Cisco has ever been presented with.</p>
<p>Why do I say that? It is simple, every server that moves from a corporate data center into a cloud provider is a switchport and fibre channel port (and now server) that is not purchased from Cisco. More so, each system that is moved into the cloud hurts secondary sales of security and content switching products.</p>
<p><span style="font-size: medium;"><strong>The promise of enterprise cloud computing<br />
</strong></span></p>
<p><span style="font-size: medium;"><strong></strong></span>The ability to dynamically scale enterprise compute workloads while only running a &#8220;right sized&#8221; private infrastructure is top of every CIO&#8217;s mind. This is the promise of cloud computing in the enterprise space. However, right now most cloud offerings are too new, and lack the critical integrations with VMware or XenSource (the two most common enterprise virtualization platforms) to make a serious dent in Cisco&#8217;s revenue stream. But fast forward 12 to 16 months and the kinks will be worked out. Projects that would previously have required new capital infrastructure will be restructured to use cloud providers as an operational expense. This will present a real threat to Cisco&#8217;s revenue moving forward.</p>
<p>John Chambers and his team of technologist are not new to this game, this is not the first threat to Cisco&#8217;s sales model. And I am sure that it won&#8217;t be the last. So if I was in their shoes, what would I do? (and more specifically, what do I think <em>they</em> are doing)</p>
<p><span style="font-size: medium;"><strong>Create a compute platform that can power the cloud at a much lower cost that my competitors</strong></span></p>
<p>Cisco publicly announced their computing offering, the Unified Computing System in March of this year. The promise of the UCS is to minimize power, cooling, capital costs and management overhead of data center compute. Looking at this new product line from an enterprise sales perspective it makes sence. For Cisco to continue with their growth plans they had to choose to enter the Compute or Storage markets, with the compute (server) market being the logical step.</p>
<p>While the Unified Computing System is well placed as an enterprise computing platform, I think there is a larger goal in mind. The large goal is to make a platform that can be shared by Cisco&#8217;s largest enterprise clients in their emerging private clouds, as well as by Cisco itself for it&#8217;s own cloud offering. By producing their own servers, with technology that Cisco alone has access too (memory expansion / hypervisor bypass) Cisco sets themselves up to have both lower hardware costs in their own cloud, as well as lower operational costs (power/cooling). This will provide Cisco with higher margin at the same price point as their competitors.</p>
<p><span style="font-size: medium;"><strong>Distribute application aware network devices at customer locations</strong></span></p>
<p>Cisco already has a significant edge over any competitive cloud offering. A vast majority of enterprise customers already run Cisco routers, switches and firewalls. If Cisco decided to say, port the TCP optimization code from their WAN acceleration platform into IOS, and configure it to work with their own cloud offerings this would give them an immediate leg up on the competition. Combine this with the existing WAAS auto discovery and Cisco could conceivably automatically integrate a cloud based caching offering with a customer&#8217;s onsite devices.</p>
<p><span style="font-size: medium;"><strong>Create an application centric cloud security model that can be integrated with virtualization platforms</strong></span></p>
<p>Last year Cisco announced a new approach to security called Cisco TrustSec. This technology includes a change from layer 4 based acl&#8217;s to an application focused role based implementation. This is applicable in the cloud environment because it provides a standard integration for controlling the access to and mobility of applications as they travel between public and private clouds.</p>
<p>An interesting side bar, is the fact that when integrating public and private clouds, there will always be applications that you want to keep on your internal cloud. The easiest way to do this is to put some sort of meta information on the virtual server containing a flag that this server should only run on the private cloud. With VMware there are fields that are used for DRS that can house just such data. I would not be surprised that with all the work that Cisco and VMware have been doing together if this was not implemented with vSphere (Virtual Infrastructure 4).</p>
<p><span style="font-size: medium;"><strong>Learn as an organization how to profit from a SaaS model</strong></span></p>
<p>I think this last piece of the puzzle has been overlooked by many people. Cisco already has in house experience dealing with a massive Software as a Service (SaaS) offering &#8211; Cisco WebEx. In acquiring WebEx Cisco also acquired the talent and technology behind the worlds largest collaboration platform. Cisco should be able to take the lessons learned from running and improving this platform, and apply them to their upcoming cloud offering.</p>
<p><span style="font-size: medium;"><strong>Summary</strong></span></p>
<p>Cisco has to go to market with a Cloud offering to maintain long term viability as a company. When they do they will have the benefit of lower cost of building and operating the grids that their cloud offering will run on. They will be able to leverage millions of Cisco network devices in their current install base as well as provide application centric security integrated with these same devices. And most importantly they will be able to use the lessons learned from running WebEx to ensure flawless delivery of an upcoming cloud computing offering.<strong>Similar Posts:</strong>
<ul class="similar-posts">
<li><a href="http://www.colinmcnamara.com/cisco-emc-and-vmware-partneship-vce-vblocks-acadia-and-the-partner-ecosystem/"  rel="bookmark" title="November 3, 2009">Cisco EMC and VMware partneship VCE VBlocks Acadia and the Partner Ecosystem</a></li>
<li><a href="http://www.colinmcnamara.com/vmworld-2009-schedule/"  rel="bookmark" title="August 31, 2009">VMworld 2009 Schedule</a></li>
<li><a href="http://www.colinmcnamara.com/is-your-network-ready-for-cloud-computing-with-virtual-infrastructure-4/"  rel="bookmark" title="November 3, 2008">Is your network ready for Cloud Computing with Virtual Infrastructure 4?</a></li>
<li><a href="http://www.colinmcnamara.com/where-is-colin-passing-the-vcp-vmware-certified-professional-exam/"  rel="bookmark" title="October 21, 2008">Where is Colin ? Passing the VCP exam (VMware Certified Professional)</a></li>
<li><a href="http://www.colinmcnamara.com/unified-computing-podcast-with-cisco-interactive-network/"  rel="bookmark" title="April 6, 2009">Unified Computing Podcast with Cisco Interactive Network</a></li>
<li><a href="http://www.colinmcnamara.com/cisco-releases-nexus-1000v-virtual-switch-for-vmware/"  rel="bookmark" title="September 16, 2008">Cisco releases Nexus 1000V virtual switch for VMware</a></li>
</ul>
<p><!-- Similar Posts took 11.107 ms --></p>
<p>--Colin McNamara
<br/><br/><a href="http://www.colinmcnamara.com/ciscos-cloud-computing-offering/">Cisco&#8217;s Cloud Computing Offering</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.colinmcnamara.com/ciscos-cloud-computing-offering/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cisco releases Nexus 1000V virtual switch for VMware</title>
		<link>http://www.colinmcnamara.com/cisco-releases-nexus-1000v-virtual-switch-for-vmware/</link>
		<comments>http://www.colinmcnamara.com/cisco-releases-nexus-1000v-virtual-switch-for-vmware/#comments</comments>
		<pubDate>Tue, 16 Sep 2008 20:30:21 +0000</pubDate>
		<dc:creator>colinmcnamara</dc:creator>
				<category><![CDATA[CISCO]]></category>
		<category><![CDATA[DC3.0]]></category>
		<category><![CDATA[Nexus 7000]]></category>
		<category><![CDATA[cloud computing]]></category>
		<category><![CDATA[vmware]]></category>
		<category><![CDATA[blog]]></category>
		<category><![CDATA[C]]></category>
		<category><![CDATA[Colin]]></category>
		<category><![CDATA[Data Center]]></category>
		<category><![CDATA[DESIGN]]></category>
		<category><![CDATA[HP]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[NDA]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[Nexus]]></category>
		<category><![CDATA[nexus 1000v]]></category>
		<category><![CDATA[NX-OS]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[storage]]></category>
		<category><![CDATA[switch]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[TrustSec]]></category>
		<category><![CDATA[virtualization]]></category>
		<category><![CDATA[vlan]]></category>
		<category><![CDATA[vn-link]]></category>

		<guid isPermaLink="false">http://www.colinmcnamara.com/?p=190</guid>
		<description><![CDATA[This afternoon Cisco released a new member of the Nexus family of switches, the Nexus 1000V. This is the first switch to take advantage of VMware opening up their ESX and ESXi platforms to for third party network device manufacturers. This switch directly address some pretty big pain points surrounding current virtualization implementations.
The boundary between [...]<p>--Colin McNamara
<br/><br/><a href="http://www.colinmcnamara.com/cisco-releases-nexus-1000v-virtual-switch-for-vmware/">Cisco releases Nexus 1000V virtual switch for VMware</a></p>
]]></description>
			<content:encoded><![CDATA[<p>This afternoon Cisco released a new member of the Nexus family of switches, the Nexus 1000V. This is the first switch to take advantage of VMware opening up their ESX and ESXi platforms to for third party network device manufacturers. This switch directly address some pretty big pain points surrounding current virtualization implementations.</p>
<p><strong>The boundary between server team and network team responsibilities has become &#8220;fuzzy&#8221;</strong></p>
<p>Cisco address&#8217;s this issue by putting a switch that can be managed via the same methods common to other network devices inside the ESX cluster. This switch runs the same code that has become standard on Cisco&#8217;s Nexus series of Data Center switches &#8211; NX-OS.</p>
<p>Prior to adoption of virtualization, when there was a connectivity problem with a host it was quite common for the network team to verify functionality down to the switch port. The server team would do the same. This allowed for each team to focus on areas that met their core competancy. Once we moved from a real switch port, to a dumb bridge inside ESX, lots of finger pointing resulted.</p>
<p>Now, with a Nexus 1000V sitting virtually inside the ESX clusters, the boundary between network and systems teams has been re-estabilished. Now when there is a problem with a host inside an ESX cluster, the network team can use the same day to day troubleshooting tools available to them in other portions of the network to resolve issues faster, and with less finger pointing.</p>
<p><strong>Security controls have been moved further away from the hosts then we would like</strong></p>
<p>A best practice for applying security policy is to apply controls as close to the source as possible. Think of this analogy &#8211; Your kids are blasting Radio Disney from their computer. Which of the following do you do?</p>
<p>A. Turn down the speakers at the source</p>
<p>B. Distribute earplugs to all members or the household</p>
<p>Of course, the obvious action is to go to the source, and apply a control (turn down the volume, and tell the kids to clean their rooms). The same principle is valid on the networking side. The best practice is to apply security policies such as VLAN ACL&#8217;s and TrustSec policies directly to the switchports that host your switches. Before the Nexus 1000V this was impossible to do in ESX, and forced many environments to move security controls further up into the distribution layer. The side effect of this was that now the security stance from host to host inside ESX clusters was diminished.</p>
<p>The Nexus 1000V brings something called port policies to the table to address this. What these are is pre-configured application security descriptions that are available to you systems administrators to apply in a point and click fashion. Once these policies are applied to the virtualized host, they follow the host where ever it is moved in your virtual cluster.</p>
<p><strong>Provisioning and integrating the networks of VMware ESX clusters with classic networks for most is challenging at best<br />
</strong></p>
<p>I wrote an article in march about this specific issue in my post &#8211; <a href="http://www.colinmcnamara.com/2008/03/15/challenges-integrating-vmware-into-cisco-networks"  target="_blank">Challenges integrating VMware into Cisco networks</a> . The core of this issue is that in general that the network integration portions of VMware ESX clusters is not really designed to address server teams , or network teams. In fact, you need to be pretty savy with both portions to successfully integrate VMware clusters into your network. In the real world, you generally find people that are good at one or the other, not both.</p>
<p>By putting a Nexus 1000V in your VMware clusters, you know give the networking teams something they can understand without having to learn Linux, and how it handles bridges (key to understanding ESX networking). With a Cisco switch running virtually inside your clusters, network teams can follow standard core / distribution / access models with the access layer now residing inside the ESX clusters. The network teams can also leverage their existing LAN switching skills for integrating the virtual switches in the clusters with the existing Data Center switching fabrics.</p>
<p><strong>With these roadblocks addressed, Cisco is moving to further the DC 3.0 vision</strong></p>
<p>To realize the DC 3.0 vision, the network inside of VMware clusters had to be under control, and follow the same architectural guidelines that the rest of our network is subject to. With the Nexus 1000V this is now a reality. The next steps withing the DC 3.0 vision to are to extend virtualization and mobility throughout our storage fabrics, and to continue to extend virtualization to the network as a whole, as well as focusing on application virtualization and acceleration to truly realize the vision of cloud computing in the data center.</p>
<p>On the storage virtualization side, Cisco will be using a technology called FlexAttach to enable virtual and physical hosts to change locations in the datacenter without storage team intervention (more on this in a near future post). And on the application virtulization and acceleration side, expect Cisco to continue to enhance it&#8217;s existing Application Control Engine (ACE) and Wide Area Application Services (WAAS), and further integrate these into their virtualization offerings.</p>
<p><strong>Want to learn more ?</strong></p>
<p><a href="http://www.cisco.com/en/US/prod/collateral/switches/ps9441/ps9902/solution_overview_c22-494040.html"  target="_blank">Introduction to VN-Link network services &#8211; Cisco.com</a></p>
<p><a href="http://www.cisco.com/en/US/prod/collateral/switches/ps9441/ps9902/data_sheet_c78-492971.html"  target="_blank">Nexus 1000V overview &#8211; Cisco.com</a></p>
<p><a href="http://download3.vmware.com/vdcos/demos/DVS_Demo_800x600.html"  target="_blank">VMware distributed vNetwork switch demo &#8211; VMware.com</a></p>
<p><a href="http://www.colinmcnamara.com/2008/03/15/challenges-integrating-vmware-into-cisco-networks"  target="_blank">Challenges integrating VMware into Cisco networks &#8211; colinmcnamara.com</a></p>
<p><a href="http://blogs.cisco.com/datacenter/comments/video_blog_about_our_vmworld_announcements_today/"  target="_blank">Douglas Gourley speaking about how Cisco and VMware will drive Cloud Computing in the Data Center</a><strong>Similar Posts:</strong>
<ul class="similar-posts">
<li><a href="http://www.colinmcnamara.com/altor-virtual-network-security-analyzer-vnsa-integrated-with-ciscos-nexus-1000v-for-vmware/"  rel="bookmark" title="September 17, 2008">Altor Virtual Network Security Analyzer (VNSA) integrated with Cisco&#8217;s Nexus 1000v for VMware</a></li>
<li><a href="http://www.colinmcnamara.com/cisco-nexus-4000-blade-switch/"  rel="bookmark" title="September 29, 2009">Cisco Nexus 4000 Blade Switch</a></li>
<li><a href="http://www.colinmcnamara.com/nexus-5020-consolidated-10-gig-ethernet-and-4-gig-fibre-channel/"  rel="bookmark" title="April 9, 2008">Nexus 5020 &#8211; Consolidated 10 Gig Ethernet and 4 Gig Fibre Channel</a></li>
<li><a href="http://www.colinmcnamara.com/where-is-colin-passing-the-vcp-vmware-certified-professional-exam/"  rel="bookmark" title="October 21, 2008">Where is Colin ? Passing the VCP exam (VMware Certified Professional)</a></li>
<li><a href="http://www.colinmcnamara.com/simplifying-your-data-center-with-ciscos-nexus-2000-fabric-extender-fex/"  rel="bookmark" title="January 27, 2009">Simplifying your Data Center with Cisco&#8217;s Nexus 2000 Fabric Extender (FEX)</a></li>
<li><a href="http://www.colinmcnamara.com/is-your-network-ready-for-cloud-computing-with-virtual-infrastructure-4/"  rel="bookmark" title="November 3, 2008">Is your network ready for Cloud Computing with Virtual Infrastructure 4?</a></li>
</ul>
<p><!-- Similar Posts took 7.901 ms --></p>
<p>--Colin McNamara
<br/><br/><a href="http://www.colinmcnamara.com/cisco-releases-nexus-1000v-virtual-switch-for-vmware/">Cisco releases Nexus 1000V virtual switch for VMware</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.colinmcnamara.com/cisco-releases-nexus-1000v-virtual-switch-for-vmware/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
		<item>
		<title>Measuring and mitigating risk involved with sharing virtual infrastructure between DMZ and Internal environments</title>
		<link>http://www.colinmcnamara.com/measuring-and-mitigating-risk-involved-with-sharing-virtual-infrastructure-between-dmz-and-internal-environments/</link>
		<comments>http://www.colinmcnamara.com/measuring-and-mitigating-risk-involved-with-sharing-virtual-infrastructure-between-dmz-and-internal-environments/#comments</comments>
		<pubDate>Tue, 09 Sep 2008 20:36:57 +0000</pubDate>
		<dc:creator>colinmcnamara</dc:creator>
				<category><![CDATA[hyper-v]]></category>
		<category><![CDATA[virtualization]]></category>
		<category><![CDATA[vmware]]></category>
		<category><![CDATA[blog]]></category>
		<category><![CDATA[breach]]></category>
		<category><![CDATA[business context]]></category>
		<category><![CDATA[C]]></category>
		<category><![CDATA[CISCO]]></category>
		<category><![CDATA[Colin]]></category>
		<category><![CDATA[compromise]]></category>
		<category><![CDATA[Data Center]]></category>
		<category><![CDATA[DESIGN]]></category>
		<category><![CDATA[device contexts]]></category>
		<category><![CDATA[enhancements]]></category>
		<category><![CDATA[FCOE]]></category>
		<category><![CDATA[HP]]></category>
		<category><![CDATA[Instances]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[NDA]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[network infrastructure]]></category>
		<category><![CDATA[Nexus 5020]]></category>
		<category><![CDATA[passed]]></category>
		<category><![CDATA[Pic]]></category>
		<category><![CDATA[risk risk]]></category>
		<category><![CDATA[san]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[storage]]></category>
		<category><![CDATA[switch]]></category>
		<category><![CDATA[threat]]></category>
		<category><![CDATA[TrustSec]]></category>
		<category><![CDATA[virtual device]]></category>
		<category><![CDATA[vlan]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://www.colinmcnamara.com/?p=177</guid>
		<description><![CDATA[Ivan Pepelnjak over at IOS Hints and Tricks wrote a post about DMZ VLAN leaking that got me thinking.
He writes about &#8220;the VLAN leaking myth&#8221; and how it encourages clients to utilize physically separate network infrastructure in the DMZ&#8217;s. Now first things first, I wouldn&#8217;t call VLAN leaking a myth. At one time it was [...]<p>--Colin McNamara
<br/><br/><a href="http://www.colinmcnamara.com/measuring-and-mitigating-risk-involved-with-sharing-virtual-infrastructure-between-dmz-and-internal-environments/">Measuring and mitigating risk involved with sharing virtual infrastructure between DMZ and Internal environments</a></p>
]]></description>
			<content:encoded><![CDATA[<p>Ivan Pepelnjak over at <a href="http://blog.ioshints.info/2008/09/are-vlans-safe-in-dmz-environment.html"  target="_blank">IOS Hints and Tricks </a>wrote a post about DMZ VLAN leaking that got me thinking.</p>
<p>He writes about &#8220;the VLAN leaking myth&#8221; and how it encourages clients to utilize physically separate network infrastructure in the DMZ&#8217;s. Now first things first, I wouldn&#8217;t call VLAN leaking a myth. At one time it was a very real and serious vulnerability that was exploited by overflowing the capacity of the switch you were attacking, and causing it to &#8220;downgrade&#8221; from switch to a hub. Once this happened you now had access to previously protected devices, as well as having the ability to sniff data as it passed through the shared hub backplane.</p>
<p>As he mentions though, this is 8 years ago. Most switches have evolved to the point where backplanes far exceed the traffic that could ever be injected into their switchports. Even beyond backplane enhancements there are many ways to further firm up your security stance &#8211; Virtual Device Contexts, not using Layer 3 SVI&#8217;s on a DMZ VLAN, utilizing PVLANs, using port security, virtual routing instances, and many more. Of course, there are still many other attack vectors that still remain, but can be mitigated by utilizing features built into the majority of enterprise switches available today.</p>
<p>I think the real question is not &#8220;are VLANs safe in a DMZ&#8221;. The important question is have you mitigated the probability of compromise (the actual threat) to levels that are acceptable to your business. This question remains whether you have a standalone switch or not. So many times we hear about risk risk and more risk. But risk alone is meaningless in a business context. What is important is combining risk with likelihood. For that I like to use a simple table to come up with the true threat.</p>
<p><a href="http://www.colinmcnamara.com/wp-content/gallery/breach/risk_grid.gif" class="thickbox" ><img class="ngg-singlepic ngg-center" src="http://www.colinmcnamara.com/wp-content/gallery/breach/thumbs/thumbs_risk_grid.gif" alt="risk_grid.gif" /></a></p>
<p>For example, as I drive to Fry&#8217;s there is the risk of me dying due to a car crash. The impact of me dying is very high (risk) however the likelihood of an accident is low, and furthermore I reduce (mitigate) the latent risk (threat) by wearing my seat belt. So all in all the threat of me dying on my way to Fry&#8217;s is pretty darn low.</p>
<p>In a business context this may be that I have public facing web servers and network devices in my DMZ. The impact of them being compromised is that my public image may be tarnished for a short time, and my end users may lose productivity if they are not able to VPN into work, or access the Internet while on premise. I mitigate this risk by using firewalls and both host and network based Intrusion Prevention Systems as well as implementing best security practices on my network and systems devices. The latent risk (threat) remaining is at a level that is acceptable to the business leaders, so the system is allowed.</p>
<p>One question that I have seen coming up more often as we move towards fully virtualized data centers is centered around commingling of virtual infrastructure. There are some hard questions which challenge some practices that we have held true over the years.</p>
<ul>
<li>Should you allow sharing of physical memory on a host virtual machine between an internal and DMZ server?</li>
<li>Should you allow virtual infrastructure from multiple security zones to share a storage array or cluster of arrays?</li>
<li>Should you allow multiple virtual switches in different security zones commingling on the same ESX or Hyper-V cluster?</li>
<li>Should you allow virtual firewall and load balancing instances protecting internal and external zones to reside on the same hardware?</li>
<li>Should you allow virtual routing instances from multiple zones to share a physical infrastructure?</li>
</ul>
<p>In the past world of standalone systems, the additional cost of providing a wholly separate infrastructure for DMZ environments was relatively low. Each system generally had internal disk, or at most direct attached storage. Network devices themselves were scaled down to support one chassis one function. This fit quite neatly into the Enterprise Composite Network model that was quite common from 1999-2003.</p>
<p>Now, many data centers have moved to the Service Oriented Network Architecture (SONA). In this model the cost of a virtualized data center is primarily focused on foundation elements such as the virtual storage and virtual fabrics, virtualized network, and virtual systems elements. The cost of providing additional virtualized services off these elements is low, however the cost of duplicating the physical infrastructure is quite high on both the capital and operational levels. This is forcing the technical and executive leadership at many companies to take a long hard look at the true threats they are facing in previously physically separate security zones such as DMZ&#8217;s, Financial and other secure zones. In the end, they are having to decide whether the threat remaining after their security controls is worth duplicating hundreds of thousands of dollars worth of infrastructure or not.</p>
<p>These are hard questions, with really no single good answer. My gut feel is that over the next few years we will continue the move towards the fully virtualized data center where components such as memory, PCI-X buses, storage and network devices are even further decentralized. This will make the cost of duplicating the infrastructure more and more significant, causing consolidated data center (or compute) fabrics to be the norm. At this point the discussion will move away from securing zones by creating separate infrastructure, to providing end to end security, starting integrated application level security, maybe with TrustSec or a dirivative, all the way down to securing the data at rest on disk. For the time being however, the best we can do is sit down and do an honest appraisel of our security stances, mitigate what we can, and do our best to design data center architectures that provide the flexibility of implementing whatever choice the technical and business leaders agree on.<strong>Similar Posts:</strong>
<ul class="similar-posts">
<li><a href="http://www.colinmcnamara.com/moving-towards-a-green-data-center-truth-behind-the-hype/"  rel="bookmark" title="February 22, 2008">Moving towards a Green Data Center &#8211; Truth behind the hype</a></li>
<li><a href="http://www.colinmcnamara.com/ciscos-cloud-computing-offering/"  rel="bookmark" title="April 7, 2009">Cisco&#8217;s Cloud Computing Offering</a></li>
<li><a href="http://www.colinmcnamara.com/about/"  rel="bookmark" title="January 5, 2008">About Colin McNamara</a></li>
<li><a href="http://www.colinmcnamara.com/remote-site-security-cisco-analog-video-gateway-video-management-storage-system-network-modules-on-the-integrated-services-router-isr/"  rel="bookmark" title="June 10, 2008">Simplifying remote site security with Cisco&#8217;s new video surveillance modules on the ISR</a></li>
<li><a href="http://www.colinmcnamara.com/interesting-techwise-tv-episode-on-virtualization/"  rel="bookmark" title="October 23, 2008">Interesting TechWise TV episode on  virtualization</a></li>
<li><a href="http://www.colinmcnamara.com/cisco-releases-nexus-1000v-virtual-switch-for-vmware/"  rel="bookmark" title="September 16, 2008">Cisco releases Nexus 1000V virtual switch for VMware</a></li>
</ul>
<p><!-- Similar Posts took 7.286 ms --></p>
<p>--Colin McNamara
<br/><br/><a href="http://www.colinmcnamara.com/measuring-and-mitigating-risk-involved-with-sharing-virtual-infrastructure-between-dmz-and-internal-environments/">Measuring and mitigating risk involved with sharing virtual infrastructure between DMZ and Internal environments</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.colinmcnamara.com/measuring-and-mitigating-risk-involved-with-sharing-virtual-infrastructure-between-dmz-and-internal-environments/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Identity aware networking using Cisco TrustSec</title>
		<link>http://www.colinmcnamara.com/identity-aware-networking-using-cisco-trustsec/</link>
		<comments>http://www.colinmcnamara.com/identity-aware-networking-using-cisco-trustsec/#comments</comments>
		<pubDate>Sun, 24 Feb 2008 07:13:07 +0000</pubDate>
		<dc:creator>colinmcnamara</dc:creator>
				<category><![CDATA[CISCO]]></category>
		<category><![CDATA[DC3.0]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[C]]></category>
		<category><![CDATA[Data Center]]></category>
		<category><![CDATA[DESIGN]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[GLBA]]></category>
		<category><![CDATA[HIPPA]]></category>
		<category><![CDATA[HP]]></category>
		<category><![CDATA[MPLS]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[network infrastructure]]></category>
		<category><![CDATA[Nexus]]></category>
		<category><![CDATA[Nexus 7000]]></category>
		<category><![CDATA[Sarbanes Oxley]]></category>
		<category><![CDATA[SOX]]></category>
		<category><![CDATA[switch]]></category>
		<category><![CDATA[TrustSec]]></category>
		<category><![CDATA[vlan]]></category>

		<guid isPermaLink="false">http://www.colinmcnamara.com/2008/02/23/identity-aware-networking-using-cisco-trustsec</guid>
		<description><![CDATA[With all the fanfare surrounding the recent Nexus 7000 release I think many people have missed a significant new development in Cisco&#8217;s security portfolio. That new development is Cisco TrustSec. TrustSec takes the classic notion of access control based source and destination ip:ports and replaces it with a role and resource based methodology that fits [...]<p>--Colin McNamara
<br/><br/><a href="http://www.colinmcnamara.com/identity-aware-networking-using-cisco-trustsec/">Identity aware networking using Cisco TrustSec</a></p>
]]></description>
			<content:encoded><![CDATA[<p>With all the fanfare surrounding the recent Nexus 7000 release I think many people have missed a significant new development in Cisco&#8217;s security portfolio. That new development is Cisco TrustSec. TrustSec takes the classic notion of access control based source and destination ip:ports and replaces it with a role and resource based methodology that fits quite nicely with security requirements driven by information assurance groups. It also brings link security on certain platforms using the 802.1ae protocol that encrypts high speed links at line rate without taking a performance hit.</p>
<p>Cisco TrustSec starts at the edge by negotiating a secure link if both hosts support it (802.1ae). This is similar to wireless encryption schemes, where a secure handshake is established and the L2 path become impervious to sniffing. This is user configurable, and to my knowledge the asics available to support line rate encryption are currently only on the Nexus 7000 blades.</p>
<p>The next step is to start 802.1x negotiations. For the people not familiar with 802.1x, it is a way of passing username / password information from your computer up into the network infrastructure. Once this is completed, the switch can not only utilise tools like NAC to place you into the appropriate quarantine, or access vlans, but it also know knows your identity.</p>
<p>Now the &#8220;network&#8221; is aware of your identity, a new level of granular security control can be deployed across your infrastructure. These security policies can map into &#8220;user x can connect to webserver y&#8221; instead of being restricted by ip and port. This allows you to utilize true roles based administration similar to what you use in your Windows and Unix file systems, but now you can do this across the network.</p>
<p>How is this done ? I like to think of this as a mix between dscp and mpls tags. Which in a nutshell means that when traffic enters the network it is tagged with a small amount of additional &#8220;identity: information which is retained as it traverses the network. This information can be used to augment or completely replace your current ACL based security controls in a way that enables you to more effectively comply with complex regulatory environments such as PCI, SOX, GLBA and HPPA.</p>
<p>Over the past few years we have learned how to leverage intelligence in the the network by utilizing tools like QOS, MPLS VPN&#8217;s, and many others. Expect to add Cisco TrustSec to your quiver of tricks to address the ever growing compliance needs faced by today&#8217;s network designers.</p>
<p><a href="http://www.cisco.com/en/US/netsol/ns774/networking_solutions_package.html"  title="http://www.cisco.com/en/US/netsol/ns774/networking_solutions_package.html" target="_blank">Learn more about Cisco TrustSec</a><strong>Similar Posts:</strong>
<ul class="similar-posts">
<li><a href="http://www.colinmcnamara.com/encrypting-your-backup-tapes-with-cisco-storage-media-encryption-sme/"  rel="bookmark" title="May 3, 2008">Encrypting your backup tapes with Cisco Storage Media Encryption (SME)</a></li>
<li><a href="http://www.colinmcnamara.com/cisco-nexus-7000-datacenter-switch-released-welcome-to-datacenter-30/"  rel="bookmark" title="January 28, 2008">Cisco Nexus 7000 DataCenter switch released &#8211; Welcome to DataCenter 3.0</a></li>
<li><a href="http://www.colinmcnamara.com/altor-virtual-network-security-analyzer-vnsa-integrated-with-ciscos-nexus-1000v-for-vmware/"  rel="bookmark" title="September 17, 2008">Altor Virtual Network Security Analyzer (VNSA) integrated with Cisco&#8217;s Nexus 1000v for VMware</a></li>
<li><a href="http://www.colinmcnamara.com/cisco-releases-nexus-1000v-virtual-switch-for-vmware/"  rel="bookmark" title="September 16, 2008">Cisco releases Nexus 1000V virtual switch for VMware</a></li>
<li><a href="http://www.colinmcnamara.com/zone-based-ios-firewalls/"  rel="bookmark" title="October 15, 2007">Zone based IOS firewalls</a></li>
<li><a href="http://www.colinmcnamara.com/cisco-nexus-4000-blade-switch/"  rel="bookmark" title="September 29, 2009">Cisco Nexus 4000 Blade Switch</a></li>
</ul>
<p><!-- Similar Posts took 8.056 ms --></p>
<p>--Colin McNamara
<br/><br/><a href="http://www.colinmcnamara.com/identity-aware-networking-using-cisco-trustsec/">Identity aware networking using Cisco TrustSec</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.colinmcnamara.com/identity-aware-networking-using-cisco-trustsec/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Resume &#8211; Colin McNamara, CCIE #18233</title>
		<link>http://www.colinmcnamara.com/resume-colin-mcnamara-ccie-18233/</link>
		<comments>http://www.colinmcnamara.com/resume-colin-mcnamara-ccie-18233/#comments</comments>
		<pubDate>Sun, 06 Jan 2008 17:24:24 +0000</pubDate>
		<dc:creator>colinmcnamara</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[adaptive security]]></category>
		<category><![CDATA[ASR1000]]></category>
		<category><![CDATA[BGP]]></category>
		<category><![CDATA[brocade silkworm]]></category>
		<category><![CDATA[C]]></category>
		<category><![CDATA[callware]]></category>
		<category><![CDATA[CCDE]]></category>
		<category><![CDATA[CCIE]]></category>
		<category><![CDATA[CCNA]]></category>
		<category><![CDATA[certification]]></category>
		<category><![CDATA[CISCO]]></category>
		<category><![CDATA[cisco secure]]></category>
		<category><![CDATA[cisco systems]]></category>
		<category><![CDATA[Colin]]></category>
		<category><![CDATA[connecting]]></category>
		<category><![CDATA[Data Center]]></category>
		<category><![CDATA[Data Center Network Manager]]></category>
		<category><![CDATA[DC3.0]]></category>
		<category><![CDATA[DESIGN]]></category>
		<category><![CDATA[design specialist]]></category>
		<category><![CDATA[directory integration]]></category>
		<category><![CDATA[DNA Lab]]></category>
		<category><![CDATA[EMC]]></category>
		<category><![CDATA[EMCPA]]></category>
		<category><![CDATA[EMCTA]]></category>
		<category><![CDATA[eplus]]></category>
		<category><![CDATA[FCOE]]></category>
		<category><![CDATA[Fibre Channel]]></category>
		<category><![CDATA[Gadget]]></category>
		<category><![CDATA[GLBA]]></category>
		<category><![CDATA[Green Data Center]]></category>
		<category><![CDATA[HIPPA]]></category>
		<category><![CDATA[hosting]]></category>
		<category><![CDATA[HP]]></category>
		<category><![CDATA[IOS-EX]]></category>
		<category><![CDATA[isr]]></category>
		<category><![CDATA[lan support]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[load balancers]]></category>
		<category><![CDATA[mds]]></category>
		<category><![CDATA[MPLS]]></category>
		<category><![CDATA[NDA]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[network solutions]]></category>
		<category><![CDATA[network storage]]></category>
		<category><![CDATA[Nexus]]></category>
		<category><![CDATA[nexus 1000v]]></category>
		<category><![CDATA[Nexus 5020]]></category>
		<category><![CDATA[Nexus 7000]]></category>
		<category><![CDATA[NX-0S]]></category>
		<category><![CDATA[NX-OS]]></category>
		<category><![CDATA[NX-OS 4.0]]></category>
		<category><![CDATA[pix firewalls]]></category>
		<category><![CDATA[Provider]]></category>
		<category><![CDATA[rapid spanning tree]]></category>
		<category><![CDATA[Rbridge]]></category>
		<category><![CDATA[Router]]></category>
		<category><![CDATA[san]]></category>
		<category><![CDATA[Sarbanes Oxley]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[security environments]]></category>
		<category><![CDATA[security infrastructure]]></category>
		<category><![CDATA[service provider]]></category>
		<category><![CDATA[SOX]]></category>
		<category><![CDATA[ssl accelerators]]></category>
		<category><![CDATA[storage]]></category>
		<category><![CDATA[storage area network]]></category>
		<category><![CDATA[storage networking solutions]]></category>
		<category><![CDATA[storage system]]></category>
		<category><![CDATA[support cisco]]></category>
		<category><![CDATA[surveillance systems]]></category>
		<category><![CDATA[switch]]></category>
		<category><![CDATA[technical proficiency]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Trill]]></category>
		<category><![CDATA[TrustSec]]></category>
		<category><![CDATA[VCP]]></category>
		<category><![CDATA[video encoding]]></category>
		<category><![CDATA[virtualization]]></category>
		<category><![CDATA[vmware]]></category>
		<category><![CDATA[wireless lan design]]></category>

		<guid isPermaLink="false">http://www.colinmcnamara.com/resume-colin-mcnamara-ccie-18233/</guid>
		<description><![CDATA[ Colin McNamara, CCIE #18233 – (858) 927-4515 &#8211; colin@2cups.com
CERTIFICATIONS / ACCREDITATIONS HELD
CCIE  &#8211; Cisco Systems Internetwork Expert #18233
VCP &#8211; VMware Certified Professional
CDCUCSS &#8211; Cisco Data Center Unified Computing Support Specialist
VSP &#8211; VMware Sales Professional
VTSP &#8211; VMware Technical Sales Professional
TSS &#8211; Cisco Technical Solutions Specialist, Data Center
GCIH – GIAC Certified Incident Handler
CCVP &#8211; Cisco [...]<p>--Colin McNamara
<br/><br/><a href="http://www.colinmcnamara.com/resume-colin-mcnamara-ccie-18233/">Resume &#8211; Colin McNamara, CCIE #18233</a></p>
]]></description>
			<content:encoded><![CDATA[<p><strong><a href="http://www.colinmcnamara.com" title="Colin McNamara - Home Page"  target="_blank"> Colin McNamara</a>, CCIE #18233 – (858) 927-4515 &#8211; colin@2cups.com</strong></p>
<p style="padding: 0in 0in 0.01in; margin-bottom: 0in; border: medium medium 1px none none solid -moz-use-text-color -moz-use-text-color #000000;"><span style="font-family: Arial,sans-serif;"><strong>CERTIFICATIONS / ACCREDITATIONS HELD</strong></span></p>
<p style="margin-bottom: 0in;">CCIE  &#8211; Cisco Systems Internetwork Expert #18233</p>
<p style="margin-bottom: 0in;">VCP &#8211; VMware Certified Professional</p>
<p style="margin-bottom: 0in;">CDCUCSS &#8211; Cisco Data Center Unified Computing Support Specialist</p>
<p style="margin-bottom: 0in;">VSP &#8211; VMware Sales Professional</p>
<p style="margin-bottom: 0in;">VTSP &#8211; VMware Technical Sales Professional</p>
<p style="margin-bottom: 0in;">TSS &#8211; Cisco Technical Solutions Specialist, Data Center</p>
<p style="margin-bottom: 0in;">GCIH – GIAC Certified Incident Handler</p>
<p style="margin-bottom: 0in;">CCVP &#8211; Cisco Certified Voice Professional</p>
<p style="margin-bottom: 0in;">CSNSSS &#8211; Cisco Storage Networking Solutions Support Specialist</p>
<p style="margin-bottom: 0in;">CSNSDS &#8211; Cisco Storage Network Solutions Design Specialist</p>
<p style="margin-bottom: 0in;">CADCNSS &#8211; Cisco Advanced Data Center Networking Infrastructure Support Specialist</p>
<p style="margin-bottom: 0in;">CCIE Storage Networking</p>
<p style="margin-bottom: 0in;">RHCE &#8211; Redhat Certified Engineer #804006368822511</p>
<p style="margin-bottom: 0in;">RHCT &#8211; Redhat Certified Technician #804006368822511</p>
<p style="margin-bottom: 0in;">EMCPA &#8211; EMC Proven Professional Associate &#8211; Information Storage and Management</p>
<p style="margin-bottom: 0in;">NSCA &#8211; Netscaler Certified Administrator #2005072</p>
<p style="margin-bottom: 0in;">NACE &#8211; Network Appliance Certified Expert #12912</p>
<p style="margin-bottom: 0in;">NACP &#8211; Network Appliance Certified Professional #12017 – Data Protection</p>
<p style="margin-bottom: 0in;">NACP &#8211; Network Appliance Certified Professional #11985 – Storage Area Network</p>
<p style="margin-bottom: 0in;">NACP &#8211; Network Appliance Certified Professional #12911 – High Availability</p>
<p style="margin-bottom: 0in;">Retired Certifications -</p>
<p style="margin-bottom: 0in;">Cisco Qualified Specialist &#8211; IP Telephony Support</p>
<p style="margin-bottom: 0in;">Cisco Qualified Specialist &#8211; IP Telephony Design</p>
<p style="margin-bottom: 0in;">Cisco Qualified Specialist &#8211; IP Telephony Operations</p>
<p style="margin-bottom: 0in;">Cisco Wireless LAN Design Specialist</p>
<p style="margin-bottom: 0in;">Cisco Wireless LAN Support Specialist</p>
<p style="margin-bottom: 0in;">
<p style="padding: 0in 0in 0.01in; margin-bottom: 0in; border: medium medium 1px none none solid -moz-use-text-color -moz-use-text-color #000000;"><span style="font-family: Arial,sans-serif;"><strong>TECHNICAL PROFICIENCY</strong></span></p>
<p style="margin-bottom: 0in;">
<p style="margin-bottom: 0in;"><strong>PROTOCOL PROFICIENCY </strong></p>
<p style="margin-bottom: 0in;">EIGRP, OSPF, RIP, BGP, MPLS,  Spanning Tree, Rapid Spanning Tree, ATM, RTP, SIP, H.323, LWAPP, RADIUS, TACACS+, Ethernet, Fibre Channel, ISCSI, FCIP, FCP, FSPF, NDMP 802.11a, 802.11b, 802.11g, RBE, ISDN, SNMP</p>
<p style="margin-left: 2in; text-indent: -2in; margin-bottom: 0in;">
<p style="margin-bottom: 0in;"><strong>Virtualization Platforms</strong></p>
<p style="margin-bottom: 0in;">VMware ESX, Kernel Virtual Machine, Xen</p>
<p style="margin-left: 2in; text-indent: -2in; margin-bottom: 0in;"><strong>VOICE and VOICE OVER IP</strong></p>
<p style="margin-left: 2in; text-indent: -2in; margin-bottom: 0in;"><strong> </strong>CallManager, Unity, ICS7750, PBX Trunking, SRST, Active Directory Integration, Extended Services, Call Detail Recording, Automated Attendant, Extension, Mobility, Asterisk, Callware and VSR VM.</p>
<p style="margin-left: 2in; text-indent: -2in; margin-bottom: 0in;">
<p style="margin-left: 2in; text-indent: -2in; margin-bottom: 0in;"><strong>HARDWARE</strong></p>
<p style="margin-left: 2in; text-indent: -2in; margin-bottom: 0in;"><strong> </strong>Cisco Unified Computing System (UCS) 6100, 2100, 5100, Nexus 7000, Nexus 5000, Nexus 2000 and Nexus 1000v switches, Catalyst 1900-6509 switches, 1600-7500 series routers, Cisco PIX firewalls, Cisco Load Balancers, Cisco MDS , F5 Load Balancers, Netscreen / Juniper Firewalls, Cisco VPN3000 VPN concentrators, Cisco ASA Adaptive Security Appliances, Nortel Contivity VPN Concentrators, Aironet Access Points and Bridges, Airespace LWAPP concentrators. 3com TotalConnect racks, Ascend dial concentrators, Netscaler Load balancers, SSL accelerators, SSL VPN concentrators. Brocade Silkworm, HP Eva Storage</p>
<p style="margin-left: 2in; text-indent: -2in; margin-bottom: 0in;">
<p style="margin-left: 2in; text-indent: -2in; margin-bottom: 0in;"><strong>NETWORK MANAGEMENT </strong></p>
<p style="margin-left: 2in; text-indent: -2in; margin-bottom: 0in;">Nagios, Cacti, NTOP, IPswitch What’s Up Gold, BIG Brother, Spectrum Network Management, Kiwi Syslog,, MRTG , HP OpenView, Cisco Secure Intrusion Detection system, Cisco Network Based Application Recognition, Snort IDS, Netscreen Firewall Manager, Unified Compute System Manager</p>
<p style="margin-bottom: 0in;">
<p style="margin-bottom: 0in;"><strong>OPERATING SYSTEMS </strong></p>
<p style="margin-bottom: 0in;">Redhat, Suse and Ubuntu Linux, Windows 2000, Windows 2003, Windows 2008, Windows XP, NT4.0, BSD, Solaris, OSX</p>
<p style="margin-bottom: 0in;">
<p style="padding: 0in 0in 0.01in; margin-bottom: 0in; border: medium medium 1px none none solid -moz-use-text-color -moz-use-text-color #000000;"><span style="font-family: Arial,sans-serif;"><strong>BUSINESS ENVIRONMENTS</strong></span></p>
<p style="margin-bottom: 0in;">Consulting, Valued Added Reseller, Large Enterprise, Startup, Banking, Service Provider, Software Development, Manufacturing, Military</p>
<p style="padding: 0in 0in 0.01in; margin-bottom: 0in; border: medium medium 1px none none solid -moz-use-text-color -moz-use-text-color #000000;">
<p style="padding: 0in 0in 0.01in; margin-bottom: 0in; border: medium medium 1px none none solid -moz-use-text-color -moz-use-text-color #000000;"><span style="font-family: Arial,sans-serif;"><strong>EMPLOYMENT</strong></span></p>
<p style="margin-bottom: 0in;">
<p style="margin-bottom: 0in;">1/07 – Present,  ePlus Technology</p>
<p style="margin-bottom: 0in;"><strong>Consulting Systems Engineer &#8211; Data Center<br />
</strong></p>
<p style="margin-bottom: 0in;">Accelerate Data Center sales, design and implement network, storage, and systems solutions for ePlus west coast customers.</p>
<p style="margin-bottom: 0in;"><strong>Accomplishments</strong></p>
<ul>
<li>Developed and deployed go to market strategy for Cisco&#8217;s Unified Computing System resulting in significant competitive advantage in the western united states.</li>
</ul>
<ul>
<li>Increased Data Center revenues year over year in a the worst economy in a century.</li>
</ul>
<ul>
<li>Changed regional sales focus from technology silo&#8217;s to solutions based selling covering network, systems, storage and applications under one umbrella.</li>
<li>
<p style="margin-bottom: 0in;">Established a trend of Advanced 	Technology account wins.</p>
</li>
<li>
<p style="margin-bottom: 0in;">Accelerated ePlus’s southern 	California sales by providing high end engineering support.</p>
</li>
<li>
<p style="margin-bottom: 0in;">Increased sales for ePlus’s 	northern California office by overlaying and training field sales.</p>
</li>
<li>
<p style="margin-bottom: 0in;">Integrated MPLS service provider 	designs into cutting edge Enterprise Solutions.</p>
</li>
<li>
<p style="margin-bottom: 0in;">Filled PM and lead network 	engineer roles for large publicly traded company data center migrations.</p>
</li>
<li>
<p style="margin-bottom: 0in;">Created modular Cisco design / 	quote format and menu based hardware and services options to address rapidly changing customer needs.</p>
</li>
</ul>
<p style="margin-bottom: 0in;">
<p style="margin-bottom: 0in;">9/05 – 1/07 ID Analytics</p>
<p style="margin-bottom: 0in;"><strong>Lead Network Engineer</strong></p>
<p style="margin-bottom: 0in;">Lead team of four engineers, Define network and application integration architecture for large SaaS analytics deployment, Leverage networking technology to increase security and availability, and decrease development and product deployment timelines</p>
<p style="margin-bottom: 0in;"><strong>Accomplishments</strong></p>
<ul>
<li>
<p style="margin-bottom: 0in;">Led team of engineers responsible 	for all Production and Back Office systems in 2 offices and  3 	datacenters</p>
</li>
<li>
<p style="margin-bottom: 0in;">Designed and Implemented ID 	Analytics Phase2 datacenter, processing 1.2-1.8 million financial 	transactions daily.</p>
</li>
<li>
<p style="margin-bottom: 0in;">Designed and Implemented Contents 	Switching and SSL offloading solution, enabled non-disruptive 	scaling of core products</p>
</li>
<li>
<p style="margin-bottom: 0in;">Integrated ID Analytics product 	with the largest card processors in the world – Equifax, Visa, 	TransUnion, etc.</p>
</li>
<li>
<p style="margin-bottom: 0in;">Designed and integrated centralized Fiber Channel and ISCSI SAN solution, increasing application speed and decreasing production database refresh times from 4 weeks to 1 week.</p>
</li>
<li>
<p style="margin-bottom: 0in;">Managed and maintained over 130 	terabytes of storage</p>
</li>
<li>
<p style="margin-bottom: 0in;">Created lights out server imaging 	and deployment solution for remote datacenters</p>
</li>
<li>
<p style="margin-bottom: 0in;">Deployed and integrated monitoring 	solutions utilizing open source technology</p>
</li>
<li>
<p style="margin-bottom: 0in;">Created user emulation probes for 	real time application monitoring and trending of production systems</p>
</li>
<li>
<p style="margin-bottom: 0in;">Worked with development and 	Analytics to create structured Development and QA environments</p>
</li>
<li>
<p style="margin-bottom: 0in;">Spearheaded project to change Analytics / Informatics environment from “unix for workgroups” to high performance computing environment (HPC)</p>
</li>
<li>
<p style="margin-bottom: 0in;">Provide structured documentation 	to US Government and Corporate auditors</p>
</li>
<li>
<p style="margin-bottom: 0in;">Utilized project management skills 	for international rollouts</p>
</li>
</ul>
<p style="margin-left: 0.25in; margin-bottom: 0in;">
<p style="margin-bottom: 0in;">2/04 – 8/2005 Openwave Systems<br />
<strong>Senior Network Engineer, Strategic Design and Integration Group<br />
</strong>Provide technical leadership, Define network architecture, Establish standards and technical vision. Responsible for researching, developing, and architecting technical solutions to business needs.</p>
<p style="margin-bottom: 0in;"><strong>Accomplishments</strong></p>
<ul>
<li>
<p style="margin-bottom: 0in;">Designed Openwave’s new Pacific 	Datacenter Networks, with 900 production, and 2000 development 	servers.</p>
</li>
<li>
<p style="margin-bottom: 0in;">Designed Openwave’s Pacific 	Shores Campus Networks, and Showcase Datacenter.</p>
</li>
<li>
<p style="margin-bottom: 0in;">Responsible for hardware 	acquisition budget of 1.7 million dollars</p>
</li>
<li>
<p style="margin-bottom: 0in;">Established ISCSI  IP based SAN 	infrastructure with DR components in 4 major datacenters worldwide</p>
</li>
<li>
<p style="margin-bottom: 0in;">Promoted from the ranks, moving from running our VOIP phone systems, to Network team lead, to Senior Network Engineer in the Strategic Design and Integration team.</p>
</li>
<li>
<p style="margin-bottom: 0in;">Active and engaged member of 	multiple boards covering design review, change control, and security</p>
</li>
<li>
<p style="margin-bottom: 0in;">Negotiated with Cisco and SBC 	regarding datacenter purchases saving $906,000 off list price.</p>
</li>
<li>
<p style="margin-bottom: 0in;">Renegotiated  Cisco support saving 	Openwave nearly $600,000 over our three year term</p>
</li>
<li>
<p style="margin-bottom: 0in;">Established improved data center 	controls, allowing Openwave to pass Sarbanes Oxley (SOX) audits</p>
</li>
<li>
<p style="margin-bottom: 0in;">Wrote and ran multiple RFP, RFQ, 	and RFI’s</p>
</li>
<li>
<p style="margin-bottom: 0in;">Utilized project management skills 	for international rollouts</p>
</li>
<li>
<p style="margin-bottom: 0in;">Managed, Piloted, and Installed 	new wireless systems for our Customer Briefing Center</p>
</li>
<li>
<p style="margin-bottom: 0in;">Responsible for 6 VOIP clusters 	around the world</p>
</li>
<li>
<p style="margin-bottom: 0in;">Recipient of multiple awards 	recognizing dedication and quality work.</p>
</li>
<li>
<p style="margin-bottom: 0in;">Attended continuing training for 	security management (CISSP)</p>
</li>
</ul>
<p style="margin-bottom: 0in;">
<p style="margin-bottom: 0in;">2/03 – 1/04 USMC Reservist activated in support of Operation Enduring Freedom<br />
<strong>Information Services Coordinator<br />
</strong>Implement and maintain Tactical Data Networks, Provide consulting services to hosting units. Maintain Microsoft Exchange servers in both tactical and garrison environments. Perform security audits and remediation. Train support personnel.</p>
<p style="margin-bottom: 0in;"><strong>Accomplishments</strong></p>
<ul>
<li>
<p style="margin-bottom: 0in;">Performed Disaster recovery of routed ATM LANE environment for Marine Corps Air Station Yuma enabling over 3000 users to resume work (awarded the Navy and Marine Corps Achievement Medal for that event)</p>
</li>
<li>
<p style="margin-bottom: 0in;">Performed security audit and 	created a security and performance remediation plan for MCAS Yuma</p>
</li>
<li>
<p style="margin-bottom: 0in;">Provided project management and 	security audit skills to 3<sup>rd</sup> Marine Air Wing Yuma server 	support teams, managed server security audit, security remediation, 	and SMS rollout.</p>
</li>
<li>
<p style="margin-bottom: 0in;">Designed and implemented Nagios 	network monitoring system at Marine Corps Air Station Yuma.</p>
</li>
<li>
<p style="margin-bottom: 0in;">Implemented Norton Antivirus 	server for MWSS 473</p>
</li>
<li>
<p style="margin-bottom: 0in;">Provided training on to data teams 	from MWSS 473, MCAS Yuma Station IT, and 3<sup>rd</sup> Marine Air 	Wing Yuma server teams.</p>
</li>
</ul>
<p style="margin-bottom: 0in;">
<p style="margin-bottom: 0in;">12/02 – 2/04 <span style="color: #0000ff;"><span style="text-decoration: underline;"><a href="http://www.2cups.com/" >2 Cups Solutions</a></span></span>, Pleasanton , Ca<br />
<strong>Principal Consultant<br />
</strong>Founded 2 Cups Solutions to provide cutting edge Voice, Data, Wireless and Security services to clients in the San Francisco bay and Fresno areas.</p>
<p style="margin-bottom: 0in;"><strong>Accomplishments</strong></p>
<ul>
<li>
<p style="margin-bottom: 0in;">Implemented WAN failover solution 	at two City of Hayward fire stations.</p>
</li>
<li>
<p style="margin-bottom: 0in;">Implemented email and web solution 	for Express Mobile Notary.</p>
</li>
<li>
<p style="margin-bottom: 0in;">Developed and implemented business 	plan focusing on State and Local Government contracts.</p>
</li>
</ul>
<p style="margin-left: 0.25in; margin-bottom: 0in;">
<p style="margin-bottom: 0in;">2/02 – 12/02 ExtraTeam, Pleasanton , Ca<br />
<strong>Senior Systems Engineer<br />
</strong>Design, Installation, Configuration and Maintenance of network systems consisting of Cisco CallManager, Unity, Cisco Secure ACS, LEAP secured wireless, Aironet, Cisco routers and switches, PIX firewalls, and VPN3000 concentrators. Integrating all systems with Active Directory. Performed VOIP feasibility studies. Managed the entire business cycle including sales, design, installation, training and maintenance.</p>
<p style="margin-bottom: 0in;"><strong>Accomplishments</strong></p>
<ul>
<li>
<p style="margin-bottom: 0in;">Integrated CallManager voice 	system with Active Directory</p>
</li>
<li>
<p style="margin-bottom: 0in;">Recovered a failed CallManager 	implementation at Phase 2 Strategies (PR firm for Logitech). Implemented CallManager with up to date hardware and software, upgraded Unity up to reasonably current levels. Brought up remote office in Phoenix utilizing SRST.</p>
</li>
<li>
<p style="margin-bottom: 0in;">Implemented City wide wireless 	network integrated with active directory for the City of Hayward</p>
</li>
<li>
<p style="margin-bottom: 0in;">Implemented VPN Concentrators in conjunction with multiple levels of firewalls for City of Hayward and Hayward PD to meet CLETS requirements.</p>
</li>
<li>
<p style="margin-bottom: 0in;">Implemented network configuration 	management system responsible for the city of Hayward.</p>
</li>
<li>
<p style="margin-bottom: 0in;">Implemented new wan for Livermore Pleasanton Fire department moving fire stations from isdn to T1 and Gigabit fiber lines in conjunction with moving the location for the network core.</p>
</li>
<li>
<p style="margin-bottom: 0in;">Designed and implemented IPSEC based wan for Universal life resources, allowing nationwide secure remote office connectivity while minimizing wan connection costs.</p>
</li>
<li>
<p style="margin-bottom: 0in;">Designed CallManager based VOIP 	system for a 27 site school district</p>
</li>
<li>
<p style="margin-bottom: 0in;">Provided emergency support to Fire 	and Police agencies across the bay area</p>
</li>
<li>
<p style="margin-bottom: 0in;">Performed security remediation for 	a large bay area company</p>
</li>
<li>
<p style="margin-bottom: 0in;">Participated in large switched 	network cutover from 7500 to a 6509 with flex-wan modules for 	Stanislaus County.</p>
</li>
<li>
<p style="margin-bottom: 0in;">Achieved technical certifications for ExtraTeam to become certified under both the Wireless and IP Telephony revised specifications.</p>
</li>
</ul>
<p style="margin-bottom: 0in;">
<p style="margin-bottom: 0in;">7/01 – 2/02 Infobond Inc. Burlingame , Ca<br />
<strong>Network Engineer</strong></p>
<p style="margin-bottom: 0in;">Responsible for engineering duties in a leadership role. Integrated legacy PBX’s using VOIP technology. Used Quality of service to ensure VOIP service levels. Support legacy voice over IP and voice over Frame Relay technologies. Upgrade from legacy voice integrations to state of the art VOIP integrations. Create project plans and act on them.</p>
<p style="margin-bottom: 0in;"><strong>Accomplishments</strong></p>
<ul>
<li>
<p style="margin-bottom: 0in;">Cut over evergreen lines shipping terminal from legacy 3com equipment to VOIP enabled Cisco routers and switches. Accomplished all work during Union stand downs.</p>
</li>
<li>
<p style="margin-bottom: 0in;">Contracted to Openwave, Inc. to run Remote Access while the engineer was on leave. Ran Remote Access for 5 weeks, resolving DSL RLAN issues and IPSec issues, while reducing trouble ticket backload to manageable levels. Assisted other engineers when needed.</p>
</li>
<li>
<p style="margin-bottom: 0in;">Implemented Cisco 6509’s to 	replace aging core network of a Benchmark Capital (bay area 	investment firm).</p>
</li>
<li>
<p style="margin-bottom: 0in;">Diagnosed and resolved VOIP issues that were stopping call center rollouts for Embarcadero Systems (a large bay area shipping company).</p>
</li>
</ul>
<p style="margin-bottom: 0in;">
<p style="margin-bottom: 0in;">03/00 &#8211; 7/01 Knapp Publishing Corporation, San Ramon, Ca<br />
<strong>Network Systems Administrator</strong></p>
<p style="margin-bottom: 0in;">Responsible for day-to-day operations of e-commerce data center, and wide area networks Performed DNS changes for both internal and external networks. Designed, piloted, and implemented network changes. Installation configuration and maintenance of NT, and Windows 2k file, print, and web servers</p>
<p style="margin-bottom: 0in;"><strong>Accomplishments</strong></p>
<ul>
<li>
<p style="margin-bottom: 0in;">Improved service levels from 90% to 99.99%, enhanced security and increased bandwidth were benefits derived from implementing a state-of-the-art web hosting data center</p>
</li>
<li>
<p style="margin-bottom: 0in;">Implemented a network monitoring 	system to document, report, and notify of network status.</p>
</li>
<li>
<p style="margin-bottom: 0in;">Designed and implemented ISDN 	failover of Frame-Relay Network.</p>
</li>
<li>
<p style="margin-bottom: 0in;">Designed, piloted, and implemented 	network changes.</p>
</li>
<li>
<p style="margin-bottom: 0in;">Replaced NT servers with Linux 	based servers, integrated with the Windows network</p>
</li>
</ul>
<p style="margin-bottom: 0in;">
<p style="margin-bottom: 0in;">01/98 &#8211; 03/00 DKA Computers Inc. Clovis, Ca<br />
<strong>Manager Information Services (01/99 &#8211; 03/00 )</strong></p>
<p style="margin-bottom: 0in;">Ran day to day operations of a central valley ISP. Worked with systems manufacturing to bundle client software with all new PC’s. Partnered with local ISP’s to provide access numbers across the valley.</p>
<p style="margin-bottom: 0in;"><strong>Accomplishments</strong></p>
<ul>
<li>
<p style="margin-bottom: 0in;">Managed web development, and 	professional services</p>
</li>
<li>
<p style="margin-bottom: 0in;">Moved web hosting from IIS to 	APACHE based servers, drastically increasing site availability</p>
</li>
<li>
<p style="margin-bottom: 0in;">Produced a forms based web 	application to configure custom systems online.</p>
</li>
<li>
<p style="margin-bottom: 0in;">Designed and implemented an IPSec 	based WAN connecting 3 stores point of sales systems.</p>
</li>
<li>
<p style="margin-bottom: 0in;">Managed corporate office and data 	center relocation project.</p>
</li>
</ul>
<p style="margin-bottom: 0in;"><strong>Senior PC Service Technician (01/98 &#8211; 01/99)</strong></p>
<p style="margin-bottom: 0in;">Provide on call service. Staff PC help desk. Provide direct customer systems support while maximizing company revenues. Configured all servers ordered from manufacturing.</p>
<p style="margin-bottom: 0in;"><strong>Accomplishments</strong></p>
<ul>
<li>
<p style="margin-bottom: 0in;">Responsible for all day to day service activities for a 13 million dollar company. Management of 4 team members. Directly responsible for customer satisfaction</p>
</li>
</ul>
<ul>
<li>
<p style="margin-bottom: 0in;">Implemented hard drive imaging 	system, decreasing both warranty costs and turnaround time</p>
</li>
<li>
<p style="margin-bottom: 0in;">Installed and configured SCO Unix 	reservation system for National Park service, Kings Canyon</p>
</li>
<li>
<p style="margin-bottom: 0in;">Designed, implemented inventory 	tracking database, reducing required stock on hand by $40,000</p>
</li>
</ul>
<p style="padding: 0in 0in 0.01in; margin-bottom: 0in; border: medium medium 1px none none solid -moz-use-text-color -moz-use-text-color #000000;">
<p style="padding: 0in 0in 0.01in; margin-bottom: 0in; border: medium medium 1px none none solid -moz-use-text-color -moz-use-text-color #000000;"><span style="font-family: Arial,sans-serif;"><strong>MILITARY</strong></span></p>
<p style="margin-bottom: 0in;">1996 &#8211; 2004 UNITED STATES MARINE CORPS RESERVE<br />
Have held U.S. Government security clearance &#8211; Secret</p>
<p style="padding: 0in 0in 0.01in; margin-bottom: 0in; border: medium medium 1px none none solid -moz-use-text-color -moz-use-text-color #000000;">
<p style="padding: 0in 0in 0.01in; margin-bottom: 0in; border: medium medium 1px none none solid -moz-use-text-color -moz-use-text-color #000000;"><span style="font-family: Arial,sans-serif;"><strong>EDUCATION</strong></span></p>
<p style="margin-bottom: 0in;">Ongoing professional education</p>
<p style="margin-bottom: 0in;">Sans CISSP + Track</p>
<p style="margin-bottom: 0in;">University of Oklahoma extension – Fire Science</p>
<p style="margin-bottom: 0in;">Cisco Networking Academy</p>
<p><strong>Similar Posts:</strong>
<ul class="similar-posts">
<li><a href="http://www.colinmcnamara.com/what-does-it-take-to-pass-the-ccie-exam/"  rel="bookmark" title="June 16, 2007">What does it take to pass the CCIE exam?</a></li>
<li><a href="http://www.colinmcnamara.com/cisco-certified-design-expert-ccde-officially-released-by-cisco/"  rel="bookmark" title="January 22, 2008">Cisco Certified Design Expert &#8211; CCDE &#8211; officially released by Cisco</a></li>
<li><a href="http://www.colinmcnamara.com/about/"  rel="bookmark" title="January 5, 2008">About Colin McNamara</a></li>
<li><a href="http://www.colinmcnamara.com/ill-be-at-cisco-live-2008-networkers-in-orlando-all-week/"  rel="bookmark" title="June 23, 2008">I&#8217;ll be at Cisco Live 2008 (networkers) in Orlando all week</a></li>
<li><a href="http://www.colinmcnamara.com/where-is-colin-passing-the-vcp-vmware-certified-professional-exam/"  rel="bookmark" title="October 21, 2008">Where is Colin ? Passing the VCP exam (VMware Certified Professional)</a></li>
<li><a href="http://www.colinmcnamara.com/challenges-integrating-vmware-into-cisco-networks/"  rel="bookmark" title="March 15, 2008">Challenges integrating VMware into Cisco networks</a></li>
</ul>
<p><!-- Similar Posts took 9.967 ms --></p>
<p>--Colin McNamara
<br/><br/><a href="http://www.colinmcnamara.com/resume-colin-mcnamara-ccie-18233/">Resume &#8211; Colin McNamara, CCIE #18233</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.colinmcnamara.com/resume-colin-mcnamara-ccie-18233/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
