How to Build a Robust Campus Network
Robust networks must be properly planned and cannot be constructed haphazardly by simply putting standalone components together. The network designers need to identify the network requirements, identify best solutions to meet the needs of the business, and plan for future expansion.
Network Requirements
Today's business networks must be available nearly 100 percent of the time and they should also be smart enough to protect against unexpected security threats. The networks should be designed in a manner that accommodates changing traffic loads as well as maintaining consistent application response times. The following list of requirements must be kept in mind while building an intelligent network:
Network uptime
Reliable application delivery, as well as response times
Network security
Network adaptability to growth and business changes
Ease of network troubleshooting
The following design principles must be kept in mind:
Compiling the network requirements
Analyzing your existing network
Preparing for a preliminary design
Deploying the network
Monitoring and redesigning the network
Maintaining design documentation
In addition to the mobility required for campus network access, a campus network must also accommodate a wide spectrum of performance and availability requirements for client application access. Many business applications are adequately supported by conventional Fast (100 Mbps) or Gigabit Ethernet (1 GbE) connectivity, although some very high-performance client applications require 10-GbE links. With current improvements to wireless technologies, access points (APs) could push up to 5 Gbps that are suitable for laptop and mobile applications. Specific applications, such as VoIP, require additional performance guarantees in the form of Quality of Service (QoS) support and traffic policing.
Redundant network devices and links for High Availability (HA) are required for all mission-critical applications and must have failover capability in the event of an individual link or interface outage. A properly designed campus network infrastructure must be sufficiently flexible to provide the required bandwidth and availability per workgroup or application as business requirements change. The variability of client connectivity requirements also impacts other layers of the network infrastructure as client traffic is funneled to the network core and data center.
The large number of client devices at the campus layer poses an ongoing security challenge. A network is only as secure as its weakest link, so a large, dispersed campus network must be purposely provisioned with distributed security mechanisms to eliminate vulnerabilities. Access Control Lists (ACLs), authentication, virtual private networks (VPNs), Media Access Control Security (MACsec), Internet Protocol Security (IPsec), and other safeguards restrict network access to only authorized users and network devices and block the penetration into the campus network itself. Financial and health-related industries are now obliged to protect customer and patient information to comply with government regulations. Compared to the security mechanisms typically in place in the data center, the campus network is far more vulnerable to malicious attack. Security for the campus network must therefore be constantly reinforced and monitored to avoid exposure. The Ruckus ICX campus switches are equipped with all the necessary security features to defend against vulnerabilities in campus networks.
The campus network is dispersed inherently due to the diversity of client devices. Centralized uniform management is essential for maintaining performance and availability and for enforcing corporate security policies. As new technologies, such as wireless LAN (WLAN), are introduced to facilitate user access, the campus network management framework must integrate new device and security features to ensure stable operation and provide the necessary safeguards against unauthorized intrusion. Comprehensive integrated network management tools, such as SmartZone (SZ), Ruckus Cloud, and other automation tools offered by Ruckus, can monitor traffic patterns throughout the campus network to proactively identify potential bottlenecks for network tuning on both wired and wireless network devices.
With potentially thousands of workstations, laptops, smartphones, and other end devices, and hundreds of access points, network switches, and routers, the campus network represents a substantial hardware investment. One component is the initial cost of the equipment itself, but footprint, cooling, and power consumption also contribute to the ongoing total cost of ownership (TCO) expenses. Due to the dispersed nature of the campus network infrastructure, these costs are less readily identified than comparable operational overhead in the data center. However, they should still be factored into the overall campus network design and product selection. Integrating more energy-efficient network infrastructure elements and leveraging technologies such as Power over Ethernet (PoE) dramatically reduces ongoing operational expenses (OpEx) and minimizes the impact of the network on the corporate budget. In addition, consolidation of network assets by using more efficient high-port-count switches both streamlines management and reduces energy consumption. The 1RU campus switches offered by Ruckus can essentially be a substitution for chassis because they support distributed stacking as opposed to being centralized to one location.
Flexible Design and Its Benefits
To meet the most essential design goals (including scalability, availability, security, and manageability), a network must be built for flexibility as well as growth. A hierarchical design is used to group devices into multiple networks in a layered approach. The following three basic layers make up the hierarchical design:
The access layer connects end users and devices. A tiered campus network design provides the flexibility to support multiple capabilities at the access layer (or network edge). Depending on application requirements, high-performance clients can be provisioned with multiple 1- or 10-GbE interfaces for maximum throughput to the aggregation and core layers.
Due to the high availability, high-performance, and security requirements that can vary from one department to the next, the access layer switch infrastructure should provide multiple speeds, rapid failover capability, and VPN and other security protocols as required. Unified communications, such as concurrent VoIP, streaming media, and conventional data transactions, may require additional functionality for QoS delivery and PoE. In addition, applications requiring wireless connectivity need both wireless LAN (WLAN) access points as well as centralized management to ensure stable and secure connectivity.
Access layer switches are typically housed in wiring closets distributed on multiple floors of each building on the enterprise campus network. These in turn are connected to aggregation layer switches that feed traffic to other segments or to the network core. To accommodate the fan-in of multiple access layer switches to the aggregation layer, high performance uplinks are required. Currently, these are up to 100-GbE uplinks, which can be provided with ICX switches.
The aggregation layer interconnects smaller local networks. The campus aggregation or distribution layer funnels transactions from multiple access layer switches to the network core. Because each aggregation layer switch is responsible for multiple upstream access layer switch traffic flows from hundreds of users, aggregation layer switches should have high availability architectures—including redundant power supplies, hot-swappable fans, high-performance backplanes, redundant management modules, and high-density port modules. Aggregation layer switches are typically Layer 2 or Layer 3 switches with support for robust routing protocols to service both the upstream access and downstream core layers. Ruckus ICX switches support full IPv4 and IPv6 protocols, RIPv1/v2, OSPFv2/v3, and BGP.
The core layer connects the aggregation layer devices. The core layer represents the heart of the data network infrastructure. Transactions from campus clients to data center servers or to external networks must pass through the core with no loss in data integrity, performance, or availability. Core switch architectures are therefore designed to support 99.999 percent ("five nines") or greater availability and high-density modules of high-performance ports. The Ruckus ICX 7850 switch can provide the services and high-bandwidth capabilities needed in the core layers.
Collapsed Core and Distribution
The three-tier model is widely used in enterprise networks that scale over a period. Certain small business networks do not necessarily grow over time; these networks are small enough to be served by a collapsed core and distribution design. Ruckus recommends a few designs to cater to these networks because it reduces the overall cost of deployment, as well as OpEx.