Professional Documents
Culture Documents
Mng My Tnh 2
Mc lc:
I) Yu cu kin trc h thng..............................................................................2 II) Thit k h thng.............................................................................................3 III) Tnh ton h thng.........................................................................................8 IV) Dung kt hp gia Priopriety va Open source Softwares.........................10 V) Bao mt va an toan khi xay ra s c, nng cp h thng............................12 VII) M phng bng phn mm.........................................................................15
Ta building ti tr s cao khong 2 tng, tng 1 c trang b 1 phng k thut mng v Cabling Central Local (Phng tp trung dy mng v patch panel). Ngn hng dng Small Enterpirise, bao gm: 100 workstations, 3 servers, 20 network equipment. Dng cng ngh mi v h tng mng, 100/1000MBps, s dng cng ngh mng dy v mng khng dy. Dng kt hp gia Licensed v Open source Softwares. Kt ni vi bn ngoi bng Leased line v ADSL. ng dng vn phng, client- server, a phng tin, database. Bo mt cao, an ton khi xy ra s c, d dng nng cp h thng.
Ngn hng c nhu cu kt ni n 2 chi nhnh khc 2 thnh ph ln nh Nha Trang v Nng. Mi chi nhnh cng c thit k tng t nh tr s nhng quy m nh hn: - Ta nh cao khong 2 tng, tng 1 c trang b 1 phng k thut Mng v Cabling Central Local (Phng tp trung dy mng v patch panel). BBB dng chi nhnh: 50 workstations, 3 Servers, 5 Network Equipments.
2. Thit k h thng
2.1. Cu trc h tng mng tr s ngn hng: Tm hiu cu trc mng lin quan n ta nh: Cu trc bo mt mng d kin xy dng s da trn cu trc mng bao gm cc phn sau: Phn h kt ni Internet v truy cp t xa Phn ny c trang b cc thit b kt ni Gateway Cisco Router ring kt ni vi mngInternet, cho php m rng v nng cp tc cng kt ni Internet tu theo nhu cu pht trin. Ngi dng truy nhp vo mng c xc thc tu theo quyn truy nhp vo mng ni bhoc Internet v CSDL dng xc thc c qun l tp trung trn my ch ACS t vngqun tr h thng. Phn h mng DMZ Gm h thng my ch Web, E-mail, dnh cho khch hng, ni b truy nhp, trn myc h W e b g m c c c h t h n g g i a o d c h t r n W E B c a N g n h n g , I n t e r n e t B a n k i n g , h o m e Banking, cc thng tin qung co, tra cu cc sn phm ca ngn hng, cc h thng o to, dyhc in t ni b. My ch Email ca cc ti khon ni b hay khch hng, my ch Web c ci cc b lc theo cc ni dung, cc a ch trang WEB, ngoi ra ti khu vc ny cn c cc my ch Virus kin tra virus i vi cc thng tin vo ra Internet. Phn h mng ni b: Bao gm cc client t trn cc tng ca ta nh, phc v cho cc nhn vin lm vic,duyt web, gi mail... Ngoi ra cn c th phn theo cch sau: Phn h my ch v ng dng: Cc my ch ng dng cha cc CSDL dnh cho cc ng dng , ht sc quan trng dovy khu vc ny cn c m bo mc an ninh bo mt cao. Phn h qun tr mng Bao gm cc my ch qun tr an ninh, my ch xc thc , my ch qut cc dch v trnmng (IDS) Phn h kt ni ra bn ngoi (EXTRANET) Dnh cho cc kt ni t cc n v bn ngoi hoc bn ngoi truy cp vo mng ca Ngnhng Phn h my ch CSDL Cc my ch ng dng cha cc CSDL chnh, ht sc quan trng do vy khu vc ny cnc m bo mc an ninh bo mt cao nht. Phn h kt ni WAN ca ngn hng Phn kt ni vo cng Gateway Firewall, nhm bo v cc giao dch t bn ngoi vo. S thit k c m t theo s di y:
2.2. M hnh: - H thng s dng 1 router chnh dng kt ni tt c cc workstations ti cc phng ban vi h thng server, v kt ni ra ngoi internet. - Kt ni internet t bn ngoi i vo h thng mng cng ty thng qua thit b trung gian gateway v h thng tng la nhm tng cng bo mt cho h thng mng ca ngn hng. Kt ni ny c truyn qua ng leased line do ISP cung cp. - Kt ni t chi nhnh i vo h thng mng cng ty thng qua h thng tng la nhm phng trng hp gi mo. Kt ni ny c truyn qua ng leased line do ISP cung cp. - H thng DMZ c a vo s dng tng an ton cho h thng mng. Mi kt ni hay d liu t bn ngoi s c a vo h thng DMZ x l trc, nu thng tin an ton s c chuyn tip n cc b phn trong cng ty cng nh h thng server ca cng ty. - ng truyn ADSL s c dng cho kt ni wifi trong ngn hng v khng c kt ni vo h thng mng ca cng ty nhm ngn chn cc kt ni l thng qua mng khng dy. Wifi c a vo nhm mc ch phc v cho nhu cu truy cp internet ti ch ca khch hng, hay nhu cu gii tr, s dng cc ng dng internet khc ca nhn vin cng ty trong gi ngh tra, m cc ng dng khng c ci t trong Application Server. - Cc workstations ca mi tng s a vo cng 1 VLAN theo tng phng ban khc nhau. Ti chi nhnh s lng workstations nh nn tt c cc workstations cng c ni vo 1 switch, v vic phn chia VLAN cng c thit lp tng t nh tr s chnh. Ngoi ra h thng server s c chia thnh 1 VLAN ring.
S VLAN ti chi nhnh 1 c chia bi bng IP sau: VLAN VLAN1 VLAN2 VLAN3 VLAN4 VLAN5 VLAN6 Phng Ban Phng Server Gim c Phng Hnh Chnh Phng Qun L Nhn S Ti Chnh & K Ton Quan H Khch Hng a ch IP danh nh Chi tit - Min cung cp IP 192.100.2.0/24 192.100.6.0/24 192.100.8.0/24 192.100.4.0/24 192.100.9.0/24 192.100.11.0/24 192.100.2.1 ->192.100.2.254 192.100.6.1->192.100.6.254 192.100.8.1->192.100.8.254 192.100.4.1->192.100.4.254 192.100.9.1->192.100.9.254 192.100.11.1->192.100.11.254
S VLAN ti chi nhnh 2 c chia bi bng IP sau: VLAN VLAN1 VLAN2 VLAN3 VLAN4 VLAN5 VLAN6 Phng Ban Phng Server Gim c Phng Hnh Chnh Phng Qun L Nhn S Ti Chnh & K Ton Quan H Khch Hng a ch IP danh nh Chi tit - Min cung cp IP 192.200.2.0/24 192.200.6.0/24 192.200.8.0/24 192.200.4.0/24 192.200.9.0/24 192.200.11.0/24 192.200.2.1->192.200.2.254 192.200.6.1->192.200.6.254 192.200.8.1->192.200.8.254 192.200.4.1->192.200.4.254 192.200.9.1->192.200.9.254 192.200.11.1->192.200.11.254
Gi v nhn mail. Duyt web. Cung cp dch v web server bn ngoi truy cp. Cp nht c s d liu vi cc tr s khc.
3.1. Ti tr s chnh: 3.1.1. Mng c dy: 3 Server: Tng dung lng upload v download 500MB/ngy. Gi cao im: Sng: 9h 11h (thi lng 2 ting) Chiu: 15h 16h (thi lng 1 ting) Gi cao im trao i 80% d liu trong ngy: -> Bandwith = 3 x 500 x 0.8/(3 x 3600) = 0.111 MB/s -> Thourghput = 3 x 500 / (8x 3600) = 0.052 MB/s 100 Workstations: Tng dung lng upload v down load 100MB/ngy. Gi cao im: Sng: 9h 11h (thi lng 2 ting) Chiu: 15h 16h (thi lng 1 ting) Gi cao im trao i 80% d liu trong ngy: -> Bandwith = 100 x 100 x 0.8/(3 x 3600) = 0.74 MB/s -> Thourghput = 100 x 100 / (8x 3600) = 0.35 MB/s Tng Thourghput = 0.052 + 0.35 = 0.4MB/s =3.2Mb/s. Tng Bandwith = 0.111 + 0.74 = 0.851 MB/s = 6.8Mb/s 3.1.2. H thng mng khng dy: Lng d liu trao i mi laptop trong 1 ngy vo khong 50MB Gi cao im: Sng: 9h 11h (thi lng 2 ting) Chiu: 15h 16h (thi lng 1 ting) Gi cao im mi laptop trao i 80% d liu trong ngy. S lt khch hng trong 1 ngy vo khong 200 lt. S lt khch hng vo lc cao im vo khong 80 lt. -> Throughput = 200 x 50 /(8 x 3600) = 0.35MB/s = 2.8Mb/s. ->Bandwidth = 80 x 50 x 0.8/(3 x 3600) = 0.3MB/s = 2.4Mb/s
3.2. Ti Chi nhnh: 3.2.1. Mng c dy: 3 Server: Tng dung lng upload v download 500MB/ngy. Gi cao im: Sng: 9h 11h (thi lng 2 ting) Chiu: 15h 16h (thi lng 1 ting) Gi cao im trao i 80% d liu trong ngy: -> Bandwith = 3 x 500 x 0.8/(3 x 3600) = 0.111 MB/s -> Thourghput = 3 x 500 / (8x 3600) = 0.052 MB/s 50 Workstations: Tng dung lng upload v down load 100MB/ngy. Gi cao im: Sng: 9h 11h (thi lng 2 ting) Chiu: 15h 16h (thi lng 1 ting) Gi cao im trao i 80% d liu trong ngy: -> Bandwith = 50 x 100 x 0.8/(3 x 3600) = 0.37 MB/s -> Thourghput = 50 x 100 / (8x 3600) = 0.175 MB/s Tng Thourghput = 0.052 + 0.175 = 0.227MB/s = 1.816Mb/s Tng Bandwith = 0.111 + 0.37 = 0.481MB/s = 3.848 Mb/s 3.2.2. H thng mng khng dy: Lng d liu trao i mi laptop trong 1 ngy vo khong 50MB Gi cao im: Sng: 9h 11h (thi lng 2 ting) Chiu: 15h 16h (thi lng 1 ting) Gi cao im mi laptop trao i 80% d liu trong ngy. S lt khch hng trong 1 ngy vo khong 100 lt. S lt khch hng vo lc cao im vo khong 50 lt. Throughput = 100 x 50 /(8 x 3600)= 0.087MB/s = 0.7Mb/s. Bandwidth = 50 x 50 x 0.8/(3 x 3600) = 0.185MB/s = 1.48Mb/s. Vic tnh throughput v bandwidth nh vy ta tnh ton mc p ng gi cao im th mng vn hot ng tt.
Trnh duyt web: Internet Explorer (IE) c tch hp sn trong Windows, nhng Mizilla Firefox li l trnh duyt web c nhiu tnh nng u vit hn, Firefox cng l mt phn mm Open Source. Web server: S dng b phn mm tch hp nh WAMP server h tr c Apache, Mysql, Php y l b phn mm m ngun m tng i tt cho web server.
11
12
5.4. Cc gii php bo mt: - Bo mt mc mng: Bo mt ng truyn, bo mt cc thng tin lu truyn trn mng. c thc hin bng hnh thc m ha thng tin trn ng truyn, cc cng c xc nh tnh ton vn v xc thc ca thng tin. - Bo mt lp truy cp: Bo mt truy cp ca ngi dng quay s (dial-up): To cc knh VPN cho cc kt ni dial-up.. - Firewall/IDS: Ti cc khu vc cung cp cc my ch truy cp cn b tr cc tng la km cc b d tm tn cng IDS m bo ngn chn cc truy cp tri php hay cc dng tn cng ngay t cng vo mng. - Bo mt thit b v my ch: Cc thit b mng nh Router, Switch, firewall l cc im nt mng ht sc quan trng v cn c bo v. - Bo mt H iu hnh v ng dng: Thng xuyn sao lu, cp nht cc bn v li ca h iu hnh, s dng cc phn mm b sung (Patch) bt l hng trn cc h iu hnh, m bo h thng lm vic n nh. - Bo mt mc C s d liu: C th ni CSDL l li ca ton b h thng bo mt thng tin, ton b thng tin quan trng mang tnh cht sng cn c tp trung trn cc CSDL, trong thit k CSDL c t mc u tin cao nht. 5.5. An ton khi xy ra s c: - Vi ng kt ni ra internet: Ta thu c hai ng leased-line 1.2Mps v ng ADSL 8Mbps, ng kt ni chnh l ng leased-line v s dng c ch load-balancing nhm chia ti ca ng leased-line qua ng ADSL khi ng leased-line b qu ti hay gp s c. - Vi cc thit b kt ni ra internet: Phi c c ch d phng, lc bnh thng th mi kt ni din ra theo ng chnh, khi mt thit b trong ng kt ni chnh gp s c (chng hn nh router) th lp tc phi chuyn sang ng d phng, c ch ny c th thc hin c bng cch set thng s priority cho thit b, thit b no c priority ln hn s l thit b cho ng chnh v khi thit b trong ng chnh b s c th lp tc h thng s s dng thit b ca ng d phng m bo cho kt ni c thng sut. - Vi min DMZ: Cn c backup server cho cc server web, mail, database... v phi backup thng xuyn khi xy ra s c d liu trn cc server th ta s khng b mt d liu m bo cho h thng mng hot ng bnh thng. - Vi phn h mng ni b, vic s dng cc switch c c ch spanning-tree gip chng ta to ra cc ng kt ni d phng m khng b loop, nhm m bo khi switchchinhs b s c th switch d phng s hot ng v khng lm cho hot ng ca ngn hng b gin on. - T chc mt phng k thut chuyn v h thng mng gii quyt cc vn khi h thng mng xy ra s c.
13
5.6. Nng cp h thng: H thng mng c xy dng phi m bo cho vic nng cpd dng khi cn thit, chng hn nh ngn hng tng thm nhn s, s lng chi nhnh cng nh i tc tng ln, cc server c truy cpnhiu hnDo trong thit k ta cng tnh n cc vn ny.Hin ti gi s s nhn vin l khong 100 ngi gi s c chia u trn cc tng th mi tng c 50 ngi, ta b tr mi tng 4 switch 24 port tcl c th p ng cho mi tng l 96 ngi, v vy khi c thm nhnvin th ta cng khng cn phi thit k li hay mua thm switch. i vi vn bng thng ta cng tnh n h s an ton l 20% nhm m b o h thng hot ng n nh v khi c nhu cu tng bng thng th ch cn ng k t h a y i g i c c v i n h c u n g c p d c h v(ISP). Vic s dng cc thit b mng ca Cisco cng ty hng u v thit b mng gip cho ta c h tr k thut tt hn, thit b nnh hn, v nht l trong cc sn phm ca Cisco thng c tch hp sn cc cng ngh mi, ph hp vi yu cu s dng
14
15