CCDE Enterprise Case Study Part 16 – Can Toolmate Remove Its Internet Edge?
As Jacobs moves deeper into SD-WAN transformation, one of the most important architectural decisions now emerges:
Question 15
Can Toolmate fully decommission its local Internet edge and instead use the upgraded 10Gbps resilient Internet edge at Jacobs DC as a secondary SD-WAN termination point?
Correct Answer:
❌ No
Toolmate still requires its own Internet edge because:
- Public-facing Toolmate services still exist locally
- B2B VPN connectivity terminates locally
- DMZ applications rely on Toolmate ISP presence
- Removing the Internet edge introduces architectural dependency risks
Table of Contents
- 1. Understanding the Design Problem
- 2. Why the Answer Is No
- 3. SD-WAN Underlay Transformation
- 4. Internet Edge Architecture
- 5. DMZ Dependency Analysis
- 6. DCI and Fate Sharing Risks
- 7. Enterprise WAN Mathematics
- 8. SD-WAN Configuration Examples
- 9. Security Design Considerations
- 10. Machine Learning and WAN Analytics
- 11. Related Articles
1. Understanding the Design Problem
James Medina proposes:
- Replacing secondary MPLS links with Internet circuits
- Migrating to SD-WAN overlays
- Using Jacobs DC as centralized resilient Internet access
- Potentially removing Toolmate Internet connectivity
At first glance, this appears logical.
If:
$$ Jacobs\\ DC\\ Internet\\ Capacity \ge Toolmate\\ Requirements $$then perhaps:
$$ One\\ Shared\\ Internet\\ Edge $$could reduce:
- Operational cost
- Circuit cost
- Management complexity
However:
๐ก Critical Architectural Principle
WAN transport resiliency does NOT automatically replace:
$$ Local\\ Service\\ Dependencies $$2. Why the Answer Is No
The key requirement appears here:
The DMZ hosts a single non-load-balanced DMZ segment for publicly reachable web services for the Toolmate online presence.
This means:
- Toolmate hosts Internet-facing applications
- Toolmate requires inbound Internet reachability
- Toolmate maintains public services locally
Therefore:
$$ Toolmate\\ ISP\\ Edge \neq Branch\\ Internet\\ Access\\ Only $$Instead:
$$ Toolmate\\ ISP\\ Edge = Critical\\ Public\\ Service\\ Infrastructure $$Why This Is Important
Many engineers incorrectly assume:
$$ Internet\\ Edge = User\\ Internet\\ Browsing $$But enterprise Internet edges often provide:
- DMZ hosting
- B2B VPNs
- Public web applications
- NAT services
- External DNS services
- Partner connectivity
Removing the Toolmate ISP edge would therefore break:
- Toolmate online store access
- External B2B integrations
- Public application reachability
3. SD-WAN Underlay Transformation
The architecture evolves from:
$$ Dual\\ MPLS $$toward:
$$ MPLS + DIA $$where:
- MPLS provides deterministic enterprise transport
- DIA provides low-cost Internet underlay
- SD-WAN overlays abstract transport selection
Hybrid WAN Equation
$$ Hybrid\\ WAN = MPLS + Broadband + LTE + Policy $$Why Enterprises Like Hybrid WAN
| MPLS | Internet |
|---|---|
| Predictable latency | Lower cost |
| QoS support | High bandwidth |
| Enterprise SLA | Rapid deployment |
| Private transport | Cloud optimized |
SD-WAN intelligently combines both.
4. Internet Edge Architecture
A modern Internet edge performs:
- NAT
- Firewall inspection
- DDoS mitigation
- Public application publishing
- VPN termination
- Security inspection
Toolmate currently hosts:
- Online retail services
- Tool hire systems
- B2B VPN services
Therefore:
$$ Removing\\ Toolmate\\ Internet\\ Edge $$creates:
$$ Service\\ Dependency\\ Risk $$5. DMZ Dependency Analysis
Toolmate uses:
$$ DMZ\\ Architecture $$for:
- Public-facing applications
- Internet separation
- Security zoning
Important Design Observation
The Toolmate DMZ is:
single non-load-balanced DMZ segment
This already introduces:
- Single points of failure
- Scalability limitations
- Operational risk
Removing the local ISP would worsen:
$$ Dependency\\ Concentration $$Risk Concentration Formula
$$ Risk \propto Dependency\\ Density $$6. DCI and Fate Sharing Risks
If Toolmate relied entirely on Jacobs Internet access:
$$ Toolmate\\ Internet = Jacobs\\ ISP + DCI + Jacobs\\ Firewalls $$This creates:
- Fate sharing
- Interdependency
- Failure domain expansion
Failure Scenario Example
| Failure | Impact |
|---|---|
| Jacobs ISP outage | Both Jacobs and Toolmate affected |
| DCI outage | Toolmate isolated from Internet |
| Jacobs firewall issue | Toolmate public services fail |
๐ฏ Enterprise Architecture Principle
Do not centralize services if doing so:
$$ Increases\\ Failure\\ Blast\\ Radius $$7. Enterprise WAN Mathematics
Availability Formula
$$ Availability = \frac{MTBF}{MTBF + MTTR} $$Compound Dependency Formula
$$ Total\\ Availability = A_1 \times A_2 \times A_3 $$If Toolmate depends on:
- DCI
- Jacobs ISP
- Jacobs Firewall
then overall availability becomes:
$$ A_{total} = A_{DCI} \times A_{ISP} \times A_{Firewall} $$This often reduces overall resiliency.
8. SD-WAN Configuration Examples
Example – DIA Tunnel Interface
interface Tunnel100 ip unnumbered GigabitEthernet0/0 tunnel source GigabitEthernet0/0 tunnel mode ipsec ipv4
Example – SD-WAN SLA Policy
policy
app-route-policy CRITICAL-VOICE
sequence 10
match application voip
action accept
set preferred-color mpls
Example – Internet Backup Policy
policy
app-route-policy INTERNET-BACKUP
sequence 20
match application all
action accept
set preferred-color biz-internet
9. Security Design Considerations
James Medina proposes:
$$ SD\\text{-}WAN\\ Native\\ Security $$instead of dedicated store firewalls.
This reduces:
- Hardware cost
- Operational complexity
- Rack footprint
However:
- Policy consistency becomes critical
- DIA security must be locally enforced
- ZTNA becomes important
- SASE evolution becomes likely
Useful Security References
- Modern Web Filtering with Cisco ASA
- Enhancing IKE Phase 1 Security
- SSL VPN on Cisco IOS
- Cisco IPS Evolution
10. Machine Learning and WAN Analytics
Modern SD-WAN solutions increasingly use:
- Machine learning
- Predictive analytics
- Anomaly detection
- Traffic forecasting
for:
- SLA prediction
- Path optimization
- Capacity planning
- Congestion avoidance
Useful Analytics References
11. Related Articles
CCDE Enterprise Case Study Series
- Part 1 – Enterprise Architecture
- Part 8 – SD-WAN Transformation
- Part 12 – SD-WAN Architecture Explained
- Part 13 – WAN Transport Selection
- Part 15 – 5G and DIA Integration
- CCDE SD-WAN Design Part 17: Building a Fully Resilient Enterprise SD-WAN Headend Architecture
Final Conclusion
Although SD-WAN provides:
- Transport abstraction
- Dynamic failover
- Hybrid WAN flexibility
it does NOT automatically eliminate:
$$ Local\\ Internet\\ Service\\ Dependencies $$Toolmate still requires:
- Public-facing services
- DMZ hosting
- B2B VPN connectivity
- Independent Internet presence
Therefore:
❌ Toolmate cannot safely decommission its Internet edge.
Doing so would:
- Increase dependency on Jacobs infrastructure
- Create fate-sharing risks
- Expand failure domains
- Threaten public service availability
No comments:
Post a Comment