Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 259
  • Last Modified:

Network Design Review

experts, need your expert opinion for our network design.

main focus is on High Availability.

where we want to know what more hardware can be added in contrast to SECURITY.

 Network Design Review
0
osloboy
Asked:
osloboy
  • 2
1 Solution
 
Ernie BeekExpertCommented:
Well imho this is looking very good already :)
One thing perhaps, what exactly is that WAN zone?
0
 
harbor235Commented:


Your drawing has most zones connected to one switch, is that correct?
Seperate switch for the DMZ or is it the same switch logically seperated?

There is no IDS/IDP functionality inside of the firewalls? I would use basic firewall IDS/IDP on the external and DMZ interfaces and use the full blown IDS/IDP on the interior networks, you already know there is bad stuff happening on the outside, let your firewalls do some work.

How are the zones connected to the infrastructure, are there additional layer 2 devices?

Are your distribution switches layer 2 or layer 3?  Your visio symbol indicates layer 3, where is the layer 3 interfaces for each zone?

There are many ways to secure this environment, 802.1x, port security, dhcp snooping, ip source guard, smart IP addressing and filtering, secure trunking practices, anti spoofing filters, the list is long.

My questions would be:
Why are the zones conencted to a single switch?
Why are the internal server farms conencted to the access switch?
What are your security policies between zones?
How is your address space advertised? Do you have routers at teh edge?

There really is allot you could do

harbor235 ;}

harbor235 ;}

0
 
osloboyAuthor Commented:
erniebeek: WAN ZONE is for Remote Branches connectivity.

harbor235:

Why are the zones conencted to a single switch? its not a Single Switch, they are two and redundent.

Why are the internal server farms conencted to the access switch? to keep internal traffic seprate from INTERNET and outside traffic.

What are your security policies between zones? there is none right now, please suggest any good READINGs

How is your address space advertised? Do you have routers at teh edge? not clear what is your point, only Routers are @ INTERNET LINKS and WAN LINKS



0
 
osloboyAuthor Commented:
horrible response time, experts on vacation
0

Featured Post

Become an IT Security Management Expert

In today’s fast-paced, digitally transformed world of business, the need to protect network data and ensure cloud privacy has never been greater. With a B.S. in Network Operations and Security, you can get the credentials it takes to become an IT security management expert.

  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now