cyb505
Running head: Network Design
Network Design
Deyvin H. Mariscal
Grand Canyon University: ITT – 307
March 1, 2020
1
This study source was downloaded by 100000797002792 from CourseHero.com on 08-09-2021 19:49:55 GMT -05:00
https://www.coursehero.com/file/78817094/Network-Designdocx/
Th is
stu dy
re so
ur ce
w as
sh ar
ed v
ia C
ou rs
eH er
o. co
m
Network Design
Introduction
The Network Diagram explains how the designing of where to place Firewalls, IDS/IPS,
DMZ, Vlans, Border and Gateway routers, private IP addressing, Isolated Server Subnets,
Network Access Control, and VPN concentrator. It is important to have each of these devices and
where to place them within the company. Also explaining the secure network design of the
elements and justification, and to provide details of the “layered security” in the diagram.
In the diagram, there will be a cloud to start off. It will connect two routers. One of the
routers shall have private IP address that will lead to the DMZ/Subnet 1. The second router will
have private IP address as well but will be for the VPN/Subnet 2. In the VPN there will be a
Firewall, VPN concentrator, and several devices. Each of the devices will have a private IP
address set as a class B and it will be 172.16 on every device. In the DMZ, there shall be a
Firewall and an IPS after the Firewall. This will detect any data that come in and through the
DMZ. There will be a Layer 3 switch in the DMZ with two different kind of servers. The servers
will have an Active Directory and a Web Server. There will be another Firewall after the servers
and another IPS after the Firewall. Out of the DMZ area there will be a Border Gateway Routers,
that will help send packets between the autonomous system. Router 2 will connect with another
Layer 3 switch connected to the Product Support department, and Engineering department.
Router 3 will connect to another Layer 3 switch to the Administration department and Human
Resource department. Each department will have their own Vlan 10 – 40 and there will be
isolated subnets in each department will be 3 – 6. Every department will have a Wireless Access
2
This study source was downloaded by 100000797002792 from CourseHero.com on 08-09-2021 19:49:55 GMT -05:00
https://www.coursehero.com/file/78817094/Network-Designdocx/
Th is
stu dy
re so
ur ce
w as
sh ar
ed v
ia C
ou rs
eH er
o. co
m
Network Design
Point to connect mobile devices and other devices, it will be protected by a Firewall. In all
departments, there will be workstations and printers for employees to use.
The elements in the diagram is using the application layer where people use the email,
and data transfer, such as Telnet, HTTP, and FTP. It will be within the DMZ where the data is
stored. The next element would be using the presentation layer of data encryption that translate
the application to the network. Which users will send a MPEG, JPEG, and TIFF data encryption,
that is within the DMZ. Another element would be the session layer that is manages the
connection. This is provided in the DMZ which will have deal with a SQL program. The
Transport layer is another element in the diagram, and it would be part of the Border Gateway
Router. The next element is the Network Layer, all the routing in the Border Gateway Router
(BGR) will connect and send packets. The data link will be having the packets in the BGR from
the physical layer. The next element is the Physical Layer which would have all the mechanical
devices send to the DMZ.
3
This study source was downloaded by 100000797002792 from CourseHero.com on 08-09-2021 19:49:55 GMT -05:00
https://www.coursehero.com/file/78817094/Network-Designdocx/
Th is
stu dy
re so
ur ce
w as
sh ar
ed v
ia C
ou rs
eH er
o. co
m
Powered by TCPDF (www.tcpdf.org)