Modern enterprise networks consist of LAN, WLAN, WAN, SD-WAN, firewall, data center, and cloud solutions from multiple vendors. Understanding the overall environment using only individual management systems, command-line tools, and manually maintained documentation is becoming increasingly difficult.
Modern network analysis and automation platforms collect significantly more information from network devices than traditional SNMP-based monitoring. Based on this information, they can automatically build an up-to-date view of the network topology, routing, dependencies, and changes.
The objective is not to replace network experts with automation, but to provide them with substantially better visibility and tools for network operations, planning, and troubleshooting.
Automatically Generated Network Topology
Keeping documentation up to date is one of the most common challenges in large networks. Traditional network diagrams quickly become outdated because changes in the network are not automatically reflected in the documentation.
A modern network analysis platform can create a dynamic view based on the network’s actual configuration and operational state.
Depending on the solution, it can visualize, for example:
- L2 and L3 topology
- IP networks and VRFs
- BGP, OSPF and other routing protocols
- BGP neighbors, AS topology and routing paths
- WAN, SD-WAN and data center connectivity
- firewalls and network segmentation
- overlay and underlay architectures
- end-to-end network paths between devices or applications
- network changes and historical states
This means that documentation is no longer a separate drawing that must be manually maintained, but rather a view generated as far as possible from the actual state of the network.
Faster Troubleshooting and Change Analysis
In a complex multi-vendor network, identifying the root cause of an issue often requires collecting information from several systems and network devices.
Typical questions include:
- Which path does traffic take from source to destination?
- Why was a specific BGP route selected?
- Which routes does a neighbor advertise, and which of them are accepted?
- Through which VRF or network segment does the traffic pass?
- Did routing change after the latest network modification?
- Is the configuration consistent across different sites?
- Are there deviations from the intended network architecture?
When topology, configuration and operational state can be analyzed in the same system, many manual steps can be automated and troubleshooting can be significantly accelerated.
Challenges in Network Automation
Network automation is still often built using individual scripts. These can be highly effective for limited use cases, but in large, multi-vendor, hybrid environments, maintainability can quickly become a challenge.
Typical issues include:
- poor scalability of scripts in multi-vendor environments
- dependency on the expertise of individual employees
- network information being distributed across multiple management and monitoring systems
- limited integration with Service Management and monitoring platforms
- manual and rapidly outdated network documentation
- difficulty assessing the impact of planned changes
- High effort required for network compliance validation
- Configuration deviations and routing issues are being detected only after an incident
The purpose of an automation platform is to make network information structured and reusable and to enable recurring NetOps tasks to be automated without building every use case from scratch.
Network Compliance and Continuous Validation
Network security and architecture requirements can be continuously validated against information collected directly from network devices. Checks can include, for example:
- routing and BGP configurations
- firewalling and network segmentation
- configuration consistency
- software versions
- standardized network services
- internal architecture and security requirements
Scheduled validation enables the identification of deviations before they result in an outage or a security incident.
Multi-Vendor Environments and Integrations
Large enterprise networks are rarely built around a single vendor. One of the most important requirements when selecting a network automation and documentation solution is, therefore, the ability to collect and correlate information from multiple vendors.
The solution should be capable of analyzing routers, switches, firewalls, WLAN, SD-WAN, and data center environments, and integrate with other enterprise IT systems through APIs.
Independent Solution and Technology Consulting
5Feet Networks helps organizations evaluate network automation, dynamic documentation and network analysis solutions from a vendor-neutral perspective.
The starting point is the customer’s network, operational processes and objectives — not a specific product.
- Our expert services include
- assessment of existing NetOps and documentation processes
- Definition of network automation and network analysis use cases
- Comparison of technology alternatives
- planning and management of Proof of Concept projects
- Evaluation of multi-vendor network discovery and visibility solutions
- development of L2/L3, BGP and routing visibility
- deployment planning and project support
- integration and automation design
- development of continuous network validation and compliance processes
Solutions can be deployed in the customer’s own environment, as a cloud service, or as a hybrid model depending on the use case and security requirements.
