background image

 

VitalQIP Product Description 

 
 

Copyright © 2011 Alcatel-Lucent Technologies 

USE PURSUANT TO COMPANY INSTRUCTIONS 

Page 

28

 of 

50

 

 

 

VitalQIP software continues its market-leading support of Microsoft Windows DNS/DHCP servers with 
support of sites and subnets in Active Directory. VitalQIP software currently manages information 
about subnets and subnet organizations, which are used to model Windows sites. 

To avoid the tedious and error prone task of having to re-enter the information into the Windows 
management console, VitalQIP software provides an export mechanism for the subnet and subnet 
organization information to be retrieved and imported into the Windows 2000 Active Directory as 
subnets and sites. 

Microsoft Secure Zones 

A zone may be marked as secure only if it is Active Directory integrated. Non-directory integrated 
zones cannot be secured.  When a secure dynamic update is made to a secure zone, the security 
verification generally occurs in two stages. First the GSS-TSIG protocol is used to verify the identity of 
the updater. Second, the DNS server takes the update and uses the updater‟s security context to 
update Active Directory with the new information. At this stage Active Directory‟s access security 
mechanism is invoked for this “secure zone”.  

Active Directory keeps access control information with each entry in Active Directory. This access 
control information specifies who owns the entry and who is allowed to access it.  If the access 
control information does not forbid the updater from making changes to the Active Directory entry it 
is trying to modify, then the update succeeds. At this stage, if the entry had no security or did not 
previously exist, the access control information for the entry is updated such that only the updater 
(and administrators) is allowed to make changes to the entry.   There is one exception to this rule. 
That is when the updater is a member of a special security group called DNSUpdateProxy. Objects 
created by members of the DNSUpdateProxy group have no security; therefore, any authenticated 
user can take ownership of the objects. 

While VitalQIP will not store the Active Directory access control information, it will require the user 
to create two new Windows 2000 users for QIP. One will be a normal user, referred to as a Strong 
user. The other will be a member of the DNSUpdateProxy security group, referred to as a Proxy user.  

When static objects and RRs are modified in a secure zone, VitalQIP will use the Strong user context 
to do the update. This will cause VitalQIP to be the only user that is allowed to modify those entries, 
thus locking out random clients from stealing DNS entries that were entered by VitalQIP.  When EDUP 
objects and RRs are updated, the Proxy user context will be used, thus allowing external users to 
make modifications (and take ownership of) those entries. 

When dynamic objects are updated, the user may possibly want to allow the DHCP client to take 
ownership of the name and make subsequent updates to DNS itself. In this case, QIP will use the Proxy 
user context. On the other hand, users may feel more comfortable with VitalQIP managing the DNS 
updates for the dynamic clients and not allowing the dynamic clients to update the zone at all. In this 
case QIP will use the Strong user context to do the updates, thus locking any other users out of being 
able to modify the information. The screen shot below gives an example of the configuration of these 
user types for secure zones. 

Changed Records Push 

Содержание VitalQIP 7.3

Страница 1: ...VitalQIP 7 3 DNS DHCP IP Address Management Solution Product Description guide...

Страница 2: ...zing the address space effectively and efficiency 7 1 3 6 What s New with the VitalQIP Next Generation Platform 8 1 4 Benefits 9 2 Product Capabilities 10 2 1 Core Product 11 2 1 1 User interface 11 2...

Страница 3: ...5 Operations and administration 43 5 1 Security 43 5 2 Disaster Recovery 44 6 VitalQIP 7 3 new Features 44 6 1 1 New next generation web based GUI 44 6 1 2 Global Search Engine 45 6 1 3 VisualIP space...

Страница 4: ...ce was subnetted and which addresses were assigned where Now fifteen years later and over 850 customers worldwide VitalQIP is still the industry leading product The basic requirements of IP Address Ma...

Страница 5: ...P address was critical to communicate the request over an IP network A directory like function was needed to provide a node name to IP address this function evolved to what we now know as the Domain N...

Страница 6: ...a reasonably sound understanding of binary arithmetic is required for proper subnetting Today and in the future the complexity of subnetting growing networks and even as far as the introduction of IP...

Страница 7: ...g and when Historically there was not as much concerns of rogue devices appearing on a network or rogue users because the IP Address Space was not as limited and things like security break ins did not...

Страница 8: ...pplication introduces new features as well as look and feel to continue to provide the most cutting edge solution in the market today With today s increased focus on converged technologies the acceler...

Страница 9: ...over capabilities and multiple DNS server redundancy maximize availability of IP address and name services to clients keeping them productive despite failures Flexibility to support existing BIND or M...

Страница 10: ...and through implementation of customer suggestions the product has evolved over the years to ensure that existing customers and future customers and continue to leverage the most proven product in th...

Страница 11: ...ed over the years from offering multiple interfaces to now focusing on the next generation platform offering a new web based GUI Web 2 0 Web GUI Command Line Interface Soap XML interface C C API Vital...

Страница 12: ...talQIP functions into a larger management system infrastructure may choose this interface The API provides a rich set of C C calls 2 1 2 Features The following are the key features of the VitalQIP pro...

Страница 13: ...cal storage and reporting of IP and MAC addresses DHCP lease actions such as grant renew release and decline lease expiration dates and VitalQIP IP object adds modifies and deletes ENUM Manager Simpli...

Страница 14: ...on products MyView Tab MyView Management Allows for the administration and set up of personal views shared views or myView to be set up for users or shared by users This enables a master or organizati...

Страница 15: ...nistration of DNS related configuration parameters Zones Add modify and delete of DNS forward and reverse zones as well as Bind DNS Views DNS servers Add modify and delete of DNS servers Including all...

Страница 16: ...ibutes themselves and attribute groups 1 Attributes are individual pieces of information you want to associate with items in the VitalQIP Database Examples could be Employee Badge Number Manager s Nam...

Страница 17: ...an offline mode even when it is not connected to VitalQIP database The same profile information is then used to extract the corresponding data from VitalQIP VitalQIP AutoDiscovery includes a configura...

Страница 18: ...hree components of a discovery job A fourth request handler not shown in the illustration permits all components to be run as a single request 2 1 4 Flexibility in Supporting Multi Vendor Solution Vit...

Страница 19: ...VitalQIP Product Description Copyright 2011 Alcatel Lucent Technologies USE PURSUANT TO COMPANY INSTRUCTIONS Page 19 of 50 2 1 5 VitalQIP Appliance Based Solution...

Страница 20: ...lQIP functions It is intended to serve those applications that must invoke VitalQIP functions but cannot or should not use the existing command line utilities Each API routine returns an integer indic...

Страница 21: ...net community The AMS appliance provides the Nagios server which appliance customers can use the web based GUI to monitor all aspects of VitalQIP and the appliance management system Nagios also allows...

Страница 22: ...ile information and DHCP Bootp objects managed by the server Administrator Profile Report Report of a specified administrator s profile information Administrative Role Report Reports specified Adminis...

Страница 23: ...ility of deploying on a Server or Alcatel Lucent Appliance Solution The user interface delivers a true Windows look and feel An icon driven hierarchy makes for easier navigation Maintains asset and ot...

Страница 24: ...n be based on an Oracle or Sybase engine and can reside on a Sun Solaris Windows Redhat Linux or Alcatel Lucent Appliance Alcatel Lucent Technologies currently ships VitalQIP software with a run time...

Страница 25: ...ftware customers can easily create a base of network and customer information that allows defining and managing subnets and network services The Lucent DHCP and DNS Servers allow leveraging key inform...

Страница 26: ...erberos network authentication protocol Single Login for VitalQIP software VitalQIP software supports a single database login eliminating a database level login for each VitalQIP software administrato...

Страница 27: ...d database access security and to customize the failure result message e g instructing the user to contact the help desk Redundant Schedule Service Schedule Service redundancy has been implemented in...

Страница 28: ...curity or did not previously exist the access control information for the entry is updated such that only the updater and administrators is allowed to make changes to the entry There is one exception...

Страница 29: ...t DHCP Server supports a many to one hot fail over to another DHCP server in the event of server outage This feature provides the high availability and reliability required for IP address services DNS...

Страница 30: ...rsions Corporate extensions allow for additional directives statements to be included in named boot and named conf files Domain extensions provide the ability to include data files not managed by Vita...

Страница 31: ...rfaces can be dynamically updated to primary and secondary DNS servers Alcatel Lucent provides the additional functionality to secondary DNS servers so corporations could point a client s primary reso...

Страница 32: ...st names currently active in a DHCP server s lease files Alcatel Lucent has implemented several new policies that are included in the VitalQIP software release DHCP Intelligent Templates By re using i...

Страница 33: ...vendor s DHCP can interoperate with any other vendor s DHCP as a fail over server Currently Alcatel Lucent Technologies is the only vendor to provide a DHCP server based on the fail over draft Fail ov...

Страница 34: ...tracks DHCP lease information VitalQIP static and dynamic object definitions and Domain Controller login logout information A domain controller is a system dedicated to processing user authentication...

Страница 35: ...purposes It can be used for determining server placements and load balancing Any status change can result in an alert for example like a DNS process or the message service process Alerts are handled t...

Страница 36: ...hen creates the device associates them both and assigns a User Class At this point QIP will update the DHCP cache with the MAC User Class mapping When the device comes onto the network it already exis...

Страница 37: ...inistering ENUM records is via a VitalQIP ENUM Web GUI The ENUM Manager GUI allows an administrator to manually create update delete and search the NAPTR records The administrator simply populates a f...

Страница 38: ...solving many issues with their architectures and can be rolled out all at once or incrementally over time The following are some benefits to this option Customer Issue or Need How we address the issu...

Страница 39: ...s space and reliably deliver critical IP name and address services In step with new technology and services VoIP ENUM RFID IPv6 Mobile HSD and IP Video etc The VitalQIP Appliance Manager AM solution h...

Страница 40: ...lized Appliance Management Software AMS maintains and inventory of software packages and appliances A Secure token based appliance authentication process keeps the network secure Configuration of serv...

Страница 41: ...e quickly taken offline if suspicious behavior is observed providing even more security around the overall architecture In addition any appliance can be rebooted from the centralized AMS Appliance Arc...

Страница 42: ...nces On a traditional server VitalQIP supports Sun Solaris Window and Redhat Linux for the Enterprise server On the Alcatel Lucent Appliance Redhat Linux is supported 3 2 2 High Availability Architect...

Страница 43: ...faces or from CLI commands This is further enhanced by the ability to deploy VitalQIP architecture on a full appliance based solution This easies not only the set up but also the administration and pa...

Страница 44: ...y This means that a single secondary DHCP server can be the backup for multiple primary DHCP servers located at different sites The transition between primary and secondary servers is totally transpar...

Страница 45: ...Address Allocation etc Customers who need to search across different modules have to execute multiple searches or create scripts to accomplish the search Users have the ability to create new search pr...

Страница 46: ...ce Visual IP Space will allow administrators to quickly add modify and delete objects as well as review status of all objects on each subnet Visual IP space can be used as the only screen administrato...

Страница 47: ...e appliance or through appliance group from the AMS GUI This helps the AMS GUI administrator to plan in advance and schedule the package deployment during off peak hours 7 1 2 SNMP on the AMS SNMP on...

Страница 48: ...yslog Servers enable AMS GUI users to define up to a maximum of 10 remote logging servers for each individual appliance from AM 1 7 onwards 8 IMPLEMENTATION CONFIGURATION AND TESTING SOFTWARE INTEGRAT...

Страница 49: ...uest The VitalQIP roadmap is updated monthly and is available internally at http insolutions web Alcatel Lucent com go roadmap access shtml APPENDIX I ACRONYM GLOSSARY API Application Programming Inte...

Страница 50: ...e TCP IP suite URL Uniform Resource Locator e g http www Alcatel Lucent com APPENDIX II AVAILABILITY AND ORDERING VitalQIP is available today Please see contact the local sales or partner for pricing...

Отзывы: