Active Directory Migration - Cisco

1y ago
13 Views
2 Downloads
614.12 KB
20 Pages
Last View : 1m ago
Last Download : 3m ago
Upload by : Baylee Stein
Transcription

Active DirectoryMigrationHow Cisco IT Migrated toMicrosoft Active DirectoryA Cisco on Cisco Case Study: Inside Cisco ITPresentation ID 2007 Cisco Systems, Inc. All rights reserved.Cisco Public1

Overview ChallengeDeploy a single directory solution for all NOS directories as wellas an enterprise directory SolutionMigrate to Microsoft Active Directory, automating the migrationand provisioning processes as much as possible ResultsROI in 16 months: anticipated 48-month savings of 5.8 to 8.1million Next StepsMigrate MeetingMaker and POP email server directoriesPresentation ID 2007 Cisco Systems, Inc. All rights reserved.Cisco Public2

Challenge: Consolidate MultipleDirectories Cisco IT maintained separate NOS and LightweightDirectory Access Protocol (LDAP) directories for eachapplicationMail servers, MeetingMaker calendar servers, various Oracleapplications, Windows, UNIX, and Macintosh desktops50 directories in lab environment alone! Users had to keep track of multiple user accounts andpasswords Administrators had to be trained on different systemsand update multiple directories as employees joined orleft Cisco Cisco developers had to write different code for everydirectory their applications would accessPresentation ID 2007 Cisco Systems, Inc. All rights reserved.Cisco Public3

Challenge: Reduce Directory Costs andMaintenance RequirementsIT faced its own set of problems relating to maintainingmultiple directories: High costsTraining to support each directoryLicensing fees Complicated compliance with Sarbanes-Oxley ActThe more directory environments, the harder to enforceappropriate for each individual AccountabilityIf a problem emerges, which directory group is in charge?Presentation ID 2007 Cisco Systems, Inc. All rights reserved.Cisco Public4

Solution: Microsoft Active Directory Active Directory provides all functions that Cisco ITneeds, in one product:Enterprise directoryNOS directoryLDAPv3Public Key Infrastructure (PKI) and Kerberos security servicesNetwork device management capabilities No separate license fee because it’s built into Windowsoperating systemPresentation ID 2007 Cisco Systems, Inc. All rights reserved.Cisco Public5

Solution: Consolidate to ActiveDirectoryPresentation ID 2007 Cisco Systems, Inc. All rights reserved.Cisco Public6

Solution: Architecture Deployed in 12location on Ciscoall-packet network(CAPnet) High bandwidthenables fastresponse forCisco usersworldwide as theyauthenticatePresentation ID 2007 Cisco Systems, Inc. All rights reserved.CHMLONAMSBEIRTPBRUSJCSINRCHBGLSYDCisco Public7

Solution: Geography-Based Domains Five domain controllers at each deployment site:Root domainThree child domains based on geographyRedundant domain for local geography Cisco employees who travel can be authenticatedlocallyPresentation ID 2007 Cisco Systems, Inc. All rights reserved.Cisco Public8

Solution: Geography-Based Domains(Contd.) Authentication time reduced from minutes to seconds insome casesCisco.comAsiaPac.cisco.comGroupsUsers(Active / Inactive)Americas.cisco.comComputers(Workstations / Servers)EMEA.cisco.comActive Directory DomainOrganizational UnitPrintersApplicationsPresentation ID 2007 Cisco Systems, Inc. All rights reserved.Cisco Public9

Solution: Automated Migration Automating migration reduces business risk Cisco IT developed automated utility to migrate fromprevious Windows NT 4 NOS directoriesPopulates user accounts in Active DirectoryMigrates group accounts from Windows NT4 to Active DirectoryMigrates security identifiers (SIDs)Presentation ID 2007 Cisco Systems, Inc. All rights reserved.Cisco Public10

Solution: Automated Migration Script launcheswhen user logs into Windows NT4Enables ActiveDirectory useraccountSets passwordMore 99% of Cisco usersmigrated to ActiveDirectory with nohuman interventionPresentation ID 2007 Cisco Systems, Inc. All rights reserved.Cisco Public11

Solution: Automated Provisioning Motto: “Provision as much data as possible, master aslittle data as possible in Active Directory” 100 batch-provisioning scripts run at daily intervalsfrom 15 minutes to 24 hoursEmployees (feed from PeopleSoft HR system)GroupsSID historyMailboxesMail aliasesPrintersSite topologySchema extensionsOrganizational unitsPresentation ID 2007 Cisco Systems, Inc. All rights reserved.Cisco Public12

Solution: Automated Updates toNetwork Topology Directory services provide network topologyIT staff refer to topology to find the fastest connection tonetwork resourcesIncorrectly-configured site topology can affect availability ofdirectory-enabled applications Active Directory requires manual topology updatesBut the Cisco network changes daily, making manual updatesimpractical A challenge begging for automation Presentation ID 2007 Cisco Systems, Inc. All rights reserved.Cisco Public13

Solution: Automated Updates toNetwork Topology Cisco IT wrote a script that automatically updatestopology each dayThe script pulls config files from Cisco routers and theninjects this information into Active DirectoryPresentation ID 2007 Cisco Systems, Inc. All rights reserved.Cisco Public14

Solution: Replication Multi-master replication feature in Active Directoryreplicates a change made at any of Cisco’s 12 ActiveDirectory sites High bandwidth of CAPnet sites avoids bandwidthclogging during replication To ensure rapid recovery during disasters, Cisco ITmasters data in a separate database, not ActiveDirectoryReduces riskImproves auditingProvides IT with greater control over which systemadministrators can make changes, and how oftenPresentation ID 2007 Cisco Systems, Inc. All rights reserved.Cisco Public15

Solution: Web-Based ProxyManagement Local changes todomain controllerresult in inconsistentserver configurations,which complicatemaintenance Cisco IT developed aWeb-based proxyservice Now localconfiguration changeson server; ActiveDirectory dataremains unchangedPresentation ID 2007 Cisco Systems, Inc. All rights reserved.Cisco Public16

Results: ROI in 16 Months! Migration accomplished for 630 per Windows desktop,a result of automated migration utilityCompares to 2,100 to 3000 industry average (source:Gartner) One-time migration cost savings: 1.5 million 48-month operational cost savings for Windowsservices: 2.3 millionPresentation ID 2007 Cisco Systems, Inc. All rights reserved.Cisco Public17

Results: ROI in 16 Months! (Contd.) 48-month operational cost savings for UNIX services: 2million compared to Sun One or 4.3 million compared to SunNetwork Information Services (NIS ) 4,000,000Cumulativecost withoutautomation 3,500,000BreakevenAt 16 months 3,000,000CumulativeSavings to Ciscoafter 48 months: 2.3 M 2,500,000CumulativeCost 2,000,000 1,500,000Cumulativecost withautomation 1,000,000 500,000 01713192531374349Time (Months)Presentation ID 2007 Cisco Systems, Inc. All rights reserved.Cisco Public18

Next Steps: Migrate Other Directories MeetingMaker directories POP mail server directoriesPresentation ID 2007 Cisco Systems, Inc. All rights reserved.Cisco Public19

To read the entire case study, or for additional Cisco IT case studies on avariety of business solutions, visit Cisco on Cisco: Inside Cisco ITwww.cisco.com/go/ciscoitPresentation ID 2007 Cisco Systems, Inc. All rights reserved.Cisco Public20

Migrate to Microsoft Active Directory, automating the migration and provisioning processes as much as possible Results ROI in 16 months: anticipated 48-month savings of 5.8 to 8.1 million . Active Directory provides all functions that Cisco IT needs, in one product: Enterprise directory NOS directory

Related Documents:

Cisco ASA 5505 Cisco ASA 5505SP Cisco ASA 5510 Cisco ASA 5510SP Cisco ASA 5520 Cisco ASA 5520 VPN Cisco ASA 5540 Cisco ASA 5540 VPN Premium Cisco ASA 5540 VPN Cisco ASA 5550 Cisco ASA 5580-20 Cisco ASA 5580-40 Cisco ASA 5585-X Cisco ASA w/ AIP-SSM Cisco ASA w/ CSC-SSM Cisco C7600 Ser

DNS is a requirement for Active Directory. Active Directory clients such as users computers) use DNS to find each other and locate services advertised in Active Directory by the Active Directory domain controllers. You must decide whether DNS will be integrated with Active Directory or not. It is easier to get Active Directory up and

An Active Directory forest is a collection of one or more Active Directory domains that share a common Active Directory schema . Most Active Directory environments exist with one Active Directory domain in its own Active Directory forest .

Supported Devices - Cisco SiSi NetFlow supported Cisco devices Cisco Catalyst 3560 Cisco 800 Cisco 7200 Cisco Catalyst 3750 Cisco 1800 Cisco 7600 Cisco Catalyst 4500 Cisco 1900 Cisco 12000 Cisco Catalyst 6500 Cisco 2800 Cisco ASR se

Cisco Nexus 1000V Cisco Nexus 1010 Cisco Nexus 4000 Cisco MDS 9100 Series Cisco Nexus 5000 Cisco Nexus 2000 Cisco Nexus 6000 Cisco MDS 9250i Multiservice Switch Cisco MDS 9700 Series Cisco Nexus 7000/7700 Cisco Nexus 3500 and 3000 CISCO NX-OS: From Hypervisor to Core CISCO DCNM: Single

Cisco Nexus 7706 Cisco ASR1001 . Cisco ISR 4431 Cisco Firepower 1010 Cisco Firepower 1140 Cisco Firepower 2110 Cisco Firepower 2130 Cisco FMC 1600 Cisco MDS 91485 Cisco Catalyst 3750X Cisco Catalyst 3850 Cisco Catalyst 4507 Cisco 5500 Wireless Controllers Cisco Aironet Access Points .

Sep 11, 2017 · Note: Refer to the Getting Started with Cisco Commerce User Guide for detailed information on how to use common utilities for a record in Cisco Commerce. See Cisco Commerce Estimates and Configurations User Guide for more information.File Size: 664KBPage Count: 5Explore furtherSolved: Cisco Serial Number Lookups - Cisco Communitycommunity.cisco.comHow to view and/or update your CCO profilewww.cisco.comSolved: How do I associate a contract to my Cisco.com .community.cisco.comHow do I find my Cisco Contract Number? - Ciscowww.cisco.comPower calculator tool - Cisco Communitycommunity.cisco.comRecommended to you b

Apr 05, 2017 · Cisco 4G LTE and Cisco 4G LTE-Advanced Network Interface Module Installation Guide Table 1 Cisco 4G LTE NIM and Cisco 4G LTE-Advanced NIM SKUs Cisco 4G LTE NIM and Cisco 4G LTE-Advanced NIM SKUs Description Mode Operating Region Band NIM-4G-LTE-LA Cisco 4G LTE NIM module (LTE 2.5) for LATAM/APAC carriers. This SKU is File Size: 2MBPage Count: 18Explore furtherCisco 4G LTE Software Configuration Guide - GfK Etilizecontent.etilize.comSolved: 4G LTE Configuration - Cisco Communitycommunity.cisco.comCisco 4G LTE Software Configuration Guide - Ciscowww.cisco.comCisco 4G LTE-Advanced Configurationwww.cisco.com4G LTE Configuration - Cisco Communitycommunity.cisco.comRecommended to you b