Assessment Plan
Design Requirements 2
2 Assignment – Design Requirements
Introduction
The assignment for week two was to generate design requirements that show an understanding of the customer’s needs and direction the project should begin to take. According to the Design Requirements document (UMUC, n.d.), “the requirements include but are not limited to:
· Design Requirements of LAN, VOIP and Wireless
· Design Requirements of Security
· Design Requirements of Active Directory”
The requirements were generated from the information provided in the Case Study World Wide Trading Company document. (UMUC, n.d.)
Local Area Network Requirements
|
Lan Business Goals |
LAN Design Requirements |
|
Provide A Modular, Scalable Network |
Implement modular design recommended by vendor that can scale up or down depending on company needs.
Implement network switching devices with at least 20% capacity reserved for future use.
|
|
Provide Availability And Redundancy |
Implement network redundancy such as Spanning Tree Protocol and procure warm and cold spares for mission critical devices |
|
Optimize IP Addressing And Routing Schema |
Implement logical IP addressing scheme that provide security and efficiency to include route summarization |
|
Security And Defense In Depth Of Network |
Implement security controls for all layers of the OSI model. (Port Security, encryption, VPN tunnels, Firewalls etc.) |
|
Provide Faster Network Services |
Implement Gigabit connections to access layer devices and 10 Gigabit connections between core and distribution layers.
Implement 10Gigabit connections to all high utilization servers (File Servers, Exchange, AD) |
|
Power |
Implement Power over Ethernet (PoE) to support device power needs |
Voice over Internet Protocol (VOIP) Requirements
|
VOIP Business Goals |
VOIP Design Requirements |
|
Integrate Voice And Data Networks |
VoIP phones should share existing LAN cabling using pass through connection to provide data connection to the corresponding workstation. Reduces need for separate site based PBX.
|
|
Power |
Switches should provide Power over Ethernet to reduce need for power adapters on phones and other devices that are PoE capable. |
|
Scalability |
Leaving at least 20% spare ports on the switches will ensure that more VoIP instruments can be added at a later date. |
|
100% Outside Dialing Capability With Minimum Number Of Outside Lines |
By using SIP (Session Initiated Protocol), the number of physical phone lines coming into the building can be minimized. |
|
Provide Wireless VOIP Capability Where Wired Services Are Not Present |
Recommend using wireless VoIP. |
|
Availability Of Services |
Having two separate ISP providers with a failover system. Also, call continuity, which would forward calls to specific mobile devices in case of an outage. Spare VoIP instruments should be on site in case of device faults.
|
|
Security
|
Purchase separate VoIP security software. Encrypt traffic. |
|
Manageability |
Managing voice network may require some training for IT department/users depending on experience. |
|
Bandwidth |
Estimate VoIP bandwidth usage based on previous call history, amount of users. Factor this figure in to the overall network bandwidth requirements. |
Wireless Local Area Network (LAN) Requirements
|
Wireless LAN Business Goals |
Wireless LAN Design Requirements |
|
Fast wireless service |
Implement a wireless LAN controller and access points to meet minimum network speed requirements |
|
Secure Wireless Service (Defense-In-Depth) |
Implement wireless networking hardware that supports IPSec encryption, secure mounting, wireless Intrusion Prevention System (wIPS), and CA certificate services |
|
Available Coverage In Three Rooms (Lobby And 2x Conference Room) |
Two redundant wireless LAN controllers can be implemented to support between 12 – 300 access points |
|
Provide guest access (Lobby) |
Guest access to the wireless can be handle by the receptionist. Keeping in-line with defense-in-depth, guest will have to register with the receptionist for a guest access login |
|
IP Scheme redesign |
The wireless LAN section of the network can have its own subnet applied using route summarization |
|
Support for Bonjour services (AFP protocol) |
The wireless LAN controller has the Bonjour gateway solution which includes support for the Apple Filing Protocol (AFP) |
|
Support for IPv6
|
Although IPv6 is not an immediate requirement, both the wireless LAN controller and access points support IPv6 functionality |
Security Requirements
|
Security Business Goals |
Security Design Requirements |
|
Secure means of customer purchase and payment over the Internet |
Secured web server using one of the approved session encryption protocols i.e. SSL/TLS inside of a DMZ to protect private network
|
|
Secure Wireless Services To Lobby And Large Conference Room |
WAN access points should provide maximum coverage of areas (overhead), on single SSID with varying channels and possible two factor authentication |
|
Separation Of Internet Connectivity From Other Unclassified Networks |
Recommended use of a combination hard line and wireless, in addition to VLANs to separate public and private access |
|
Increased Logical Control System Authentication |
A combination of username, password, and session initiation server-side (i.e. Kerberos) could provide for extra security |
|
Dissolve Clear Text Transfer Of Business Information Between Server And Client |
Recommend building-wide encryption standard between server and client, through any manner of protocol (SSL/TLS) or service (RADIUS) |
|
Control Put In A Place To Prevent Local Users From Removing Data From Systems |
Utilizing Active Directory and managing USB access can control access by local users in a centralized location |
|
Secure Email To Control For Business Sensitive Data |
Proxy servers attached to internal and external communications can challenge for criteria and curtail exchange of data |
|
Secure Confidential Data Transmitted Through End User Laptops |
Suggest aggressive registration of end user devices to be used for business purposes, in conjunction with Access Control Lists on switches and routers |
|
Central Storage Of Classified Data, Away From Unclassified Network |
Recommend storage pools which can be designated to one or more servers and placed behind any number of firewalls and Access Control List controls |
Active Directory and Server Requirements
|
Active Directory Technical Goals |
Active Directory Design Requirements |
|
Utilize Active Directory To Manage User Rights, Access And Security Requirements |
Implement Organizational Units (OU) that mirror the company and allow for the managing of users and devices
Develop Group Policy Objects (GPO) to manage OUs
Implement Global, Universal and Local groups to manage users
Implement architecture to support AD (AD DS, DNS, AD Federation Services, Certificate Authority, Read Only DC) |
|
Encryption Of Data At Rest And In Motion |
Implement BitLocker, Branch Cache, and other features that provide data encryption throughout the corporate network
|
|
High Availability Services |
Implement Failovers and Clustering through physical and virtual machines across multiple locations to provide disaster recovery |
|
File Classification Tools To Protect Data |
Implement Microsoft File Server Resource Management |
|
Tools To Manage Devices On Network |
Implement Microsoft IP Address Management |
|
Multifactor Authentication |
Implement Smart Cards and Pins as authentication factors |
|
Remotely Deployed Operating Systems |
Implement Windows Deployment Services
|
References
UMUC. (n.d.). Case Study World Wide Trading Company. Retrieved January 25, 2016, from https://learn.umuc.edu/d2l/le/dropbox/173660/290354/DownloadAttachment?fid=4908850
UMUC. (n.d.). Design Requirements. Retrieved January 25, 2016, from https://learn.umuc.edu/d2l/le/dropbox/173660/290354/DownloadAttachment?fid=4908852