Professional Documents
Culture Documents
v1.5
Brad Hedlund
Solutions Architect, Data Center
CCIE #5530, VCP
February 2010
bhedlund@cisco.com
Isolation provided by
physical cabling
Isolation provided by
switch configuration
Attaching differing
isolation policies together
results in the lowest
common denominator
policy
Server virtualization
creates a network inside
the Host, a virtual network.
Conventional thinking:
“physically separate
vSwitches” is the solution.
Source: http://faz1.com/blog/2009/08/20/two-vswitches-are-better-than-1-right/
… and missed
opportunities.
Fewer adapters
DVS inclusive
DVS inclusive
Switch Consolidation
IP Source Guard
-duplicate IP, Spoofed IP protection
DHCP Snooping
-Rouge DHCP server protection
VEM
Dynamic ARP Inspection
-Man-in-the-middle protection
MAC ACL’s
Port Security