cyb505

maria@12
Network_Design.docx.pdf

Running head: Network Design

Network Design

Deyvin H. Mariscal

Grand Canyon University: ITT – 307

March 1, 2020

1

This study source was downloaded by 100000797002792 from CourseHero.com on 08-09-2021 19:49:55 GMT -05:00

https://www.coursehero.com/file/78817094/Network-Designdocx/

Th is

stu dy

re so

ur ce

w as

sh ar

ed v

ia C

ou rs

eH er

o. co

m

Network Design

Introduction

The Network Diagram explains how the designing of where to place Firewalls, IDS/IPS,

DMZ, Vlans, Border and Gateway routers, private IP addressing, Isolated Server Subnets,

Network Access Control, and VPN concentrator. It is important to have each of these devices and

where to place them within the company. Also explaining the secure network design of the

elements and justification, and to provide details of the “layered security” in the diagram.

In the diagram, there will be a cloud to start off. It will connect two routers. One of the

routers shall have private IP address that will lead to the DMZ/Subnet 1. The second router will

have private IP address as well but will be for the VPN/Subnet 2. In the VPN there will be a

Firewall, VPN concentrator, and several devices. Each of the devices will have a private IP

address set as a class B and it will be 172.16 on every device. In the DMZ, there shall be a

Firewall and an IPS after the Firewall. This will detect any data that come in and through the

DMZ. There will be a Layer 3 switch in the DMZ with two different kind of servers. The servers

will have an Active Directory and a Web Server. There will be another Firewall after the servers

and another IPS after the Firewall. Out of the DMZ area there will be a Border Gateway Routers,

that will help send packets between the autonomous system. Router 2 will connect with another

Layer 3 switch connected to the Product Support department, and Engineering department.

Router 3 will connect to another Layer 3 switch to the Administration department and Human

Resource department. Each department will have their own Vlan 10 – 40 and there will be

isolated subnets in each department will be 3 – 6. Every department will have a Wireless Access

2

This study source was downloaded by 100000797002792 from CourseHero.com on 08-09-2021 19:49:55 GMT -05:00

https://www.coursehero.com/file/78817094/Network-Designdocx/

Th is

stu dy

re so

ur ce

w as

sh ar

ed v

ia C

ou rs

eH er

o. co

m

Network Design

Point to connect mobile devices and other devices, it will be protected by a Firewall. In all

departments, there will be workstations and printers for employees to use.

The elements in the diagram is using the application layer where people use the email,

and data transfer, such as Telnet, HTTP, and FTP. It will be within the DMZ where the data is

stored. The next element would be using the presentation layer of data encryption that translate

the application to the network. Which users will send a MPEG, JPEG, and TIFF data encryption,

that is within the DMZ. Another element would be the session layer that is manages the

connection. This is provided in the DMZ which will have deal with a SQL program. The

Transport layer is another element in the diagram, and it would be part of the Border Gateway

Router. The next element is the Network Layer, all the routing in the Border Gateway Router

(BGR) will connect and send packets. The data link will be having the packets in the BGR from

the physical layer. The next element is the Physical Layer which would have all the mechanical

devices send to the DMZ.

3

This study source was downloaded by 100000797002792 from CourseHero.com on 08-09-2021 19:49:55 GMT -05:00

https://www.coursehero.com/file/78817094/Network-Designdocx/

Th is

stu dy

re so

ur ce

w as

sh ar

ed v

ia C

ou rs

eH er

o. co

m

Powered by TCPDF (www.tcpdf.org)