Comprehensive AAP and Powerpoint slide.
Network Requirements
· Design & configure enterprise campus model design
· State of the art VoIP and Data Network
· Provide faster Network services
· LAN speed minimum 100 MB and Internet speed minimum 54 MB
· Use appropriate Cisco switch models
· Integrate voice and data network to reduce cost
· 100% connectivity with a minimum number of outside lines for dialing outside numbers.
· Access layers switches
· One port for each device
· Provision for 100% growth
· Server farm switches
· Assume 6 NIC cards in each server and one NIC card uses one port of switch
· Dual processors and dual power supply
· Centralize services and servers
· Built-in redundancy at:
· building core layer and building distribution layer and access layer
· workstation level
· uplinks connection to Building Distribution layer for Building Access layer
· Aggregate routing protocols with hierarchal IP scheme
· TCP/IP protocols for the network
· Guest network must support AppleTalk protocol
· Fast and secure wireless services in the lobby and two large conference rooms
· minimum 54 Mbps of bandwidth
· Video conference and multicast services
· Extra switch capacity at for authorized users to attach their notebook PCs to the network
· Port Security, Sticky MAC, 802.1x protocols to ensure only authorized systems
· IP addressing redesign that optimizes IP addressing and IP routing with IPv6 migration provisions
· Internal/External DNS
· Dual stack, 6to4 tunnel capability or NAT-PT for IPv6 transition
· Site-to-site VPN must be mutually authenticated and utilize cryptographic protection
· PSTN dial-up
· must authenticate with username and OTP
· RADIUS/NAP
· Based on equipment inventory and other requirements:
· Access Layer port count:
· 94 ports for phones, but by utilizing network port on phone this number can be reduced in half to 47. 47 additional ports will be needed for the extra phone in offices.
· 107 ports for desktop/workstation. In most cases a workstation will connect to a phone using the trunking capability of the access switch and the phone.
· Distribution/datacenter
· 240 ports (6 ports per server; 40 servers total)
Security Requirements
· Multilayer security or defense-in-depth security
· Smart card w/ PIN
· Classified Network
· Data Separation from Unclassified network
· Physical Security
· Locks / Smart Cards to access area/systems (multi-factor authentication)
· IPSEC
· No Internet Access
· No USB/Removable Media/Printers/CD Burners (disabled by GPO)
· Encrypted network must use SSL
· Public Servers
· HTTPS (SSL)
· Provide secure means of customer purchase and payment over Internet
· Inside DMZ
· NAT
· Identity Check (User authentication/ Certificate)
· Secure key applications and servers without using encryption on all devices
· Security policies in place to stop sniffing and man-in-the-middle attacks
· Data transmitted on the classified network must be cryptographically protected throughout the network
· Data crossing wide-area links should undergo another layer of cryptographic protection
· All devices must be mutually authenticated and cryptographic protection should be provided.
· Users should undergo periodic user awareness training program on network threats and good security practices
· Acceptable Use Policy to define appropriate user behavior and security configuration settings
· Resolve current security audit problems
· Physical security
· Email protection to protect unclassified and sensitive business emails
Active Directory Requirements
· Centralize all services and servers
· Implement Failover cluster services
· File classification infrastructure feature
· IP Address Management (IPAM)
· DHCP (for employee systems)
· Exchange/Outlook (Sending and receiving e-mail)
· Windows Deployment Services
· File Server
· FSRM (quota & file screening)
· OU Infrastructure
· Role-Based
· Department-based OUs
· Global/ Universal/ Local groups
· Utilize least privileged principle for membership
· (delegate group ownership for adding/removing users)
· GPOs
· Configure Netscape or Microsoft’s Internet Explorer
· Block removable media on classified network
· Create appropriate GPO and GPO policies
· Bitlocker
· BitLocker encryption technology for devices (server and Work station) disc space and volume
· Enable a BitLocker system on a wired network to automatically unlock the system volume during boot
· GPO enforced Used Disk Space Only or Full Encryption is used when BitLocker is enabled
· Enable BranchCache
· Implement Cache Encryption to store encrypted data by default
Other
· Reduce the operating cost from 30 to 15 percent in two to three years by using an automated system for buying and selling
· Software Support
· Microsoft Office 2014
· Netscape or Microsoft’s Internet Explorer
· Custom Applications
· Market Tracking Application. This application will provide real-time status of stock and bond market to brokers and their clients
· Stock and Bond Analytical Application. This application will provide analysis of stock and Bond to Brokers only.
· Centralized AV/Malware Software
· Quarantine for non-compliant user systems
· Stateful firewall to protect inbound traffic from viruses, malware, or unauthorized access.