Title: Is Your Network Infrastructure Bullet Proof
1Is Your Network Infrastructure Bullet
Proof? October 17, 2006
2My Background
- Been with Wake Tech and the ITS team for nearly
11 years - Previously in the Private Sector as an Engineer
- Reliability/Failure Analysis Engineer
- Test Design Engineer
- Nearly 23 years of Experience in the Computer
Industry - I Love the Pittsburgh Steelers
3What Makes a NetworkBullet Proof?
- A Good Philosophy Hard Work
- Hardware That Operates at Wire Speed
- Knowledgeable Personnel Always Looking for Better
Ways to Conduct Business - Continual Monitoring of the Network
- A Simple Security Policy
- Senior Management That Supports It
4Information Technology Services Mission
- The mission of Information Technology Services at
Wake Technical Community College is to support
Student Learning, Faculty Teaching and College
Operations through the use of Information
Technology
5Information Technology Services Philosophy
- The most important relationship on campus is that
between the Student and the Instructor.
Everything else on campus is in support of that
relationship.
6Wake Techs Network Hardware
- Top Layer 5500 for IPS Protection
- FATPipe for Continuity of ISP Circuits
- Cisco ASA 5540 for Main PIX Plus VPN
- Multiple Cisco PIX Engines Throughout the Network
- Cisco Routers for WAN and ME Circuits
- HP ProCurve Family of Switches for Core Routing
Switch, Intermediate Routing Switches, and Edge
Switches - Currently Replacing HP ProCurve Switches with New
HP ProCurve PoE switches in Preparation of VoIP
7Wake Techs Core Network
MCNC
TWC
Top Layer
2 Circuit Connections
FAT Pipe
ASA 5540
HP 9315 Routing Switch
8Top Layer 5500 Intrusion Prevention System Device
MCNC
TWC
Top Layer
9Front Panel View
10Complete Security Report
11Real-Time Blocked Detected Attacks
12Real-Time Graph of Traffic
13Host Group Screen Allows Custom Policy Definitions
14Rate Based Policy Controls Data Flood Traffic
15Report Table By ServiceCheck Out Yahoo IM
16Top Layer is Delivered with Pre-Defined Rules
17Drilling Down on Rules Shows Individual Network
Violations
18Traffic Blocked from ONE Server
19Security Event Filter
20FATPipe WARP Balancer
MCNC
TWC
Top Layer
2 Circuit Connections
FAT Pipe
21Monitor the Health of IncomingISP Links
22Policy Routing Page
23Add or Edit Policy Rules
24DNS Configuration PageFATPipe has to be the DNS
server
25Reverse Mapping Settings Allow Inbound Traffic
from Multiple ISPs to a Single Server
26Internal Static Routes for Public Private
Numbers NEED Defined or the FATPipe Will Attempt
to Route Numbers Externally
27Diagnostics Page Helps Troubleshoot Problems
28Cisco ASA 5540
MCNC
TWC
Top Layer
2 Circuit Connections
FAT Pipe
2 Connections
ASA 5540
29Cisco ASA 5540 Initial Screen Displays Valuable
Information Link Status, Bandwidth Usage, Error
Messages, and CPU Memory Usage
30GUI Configuration Page
31NAT/PAT PolicyConfiguration Page
32VPN Services Configuration Page
33Static Routes MUST Be Setup for Internal Addresses
34All Users, Groups, Access Levels are Setup by
the Device Administration Page
35Easy Definition of TFTP Server to Load/Store
Configurations
36Device Specific Configurations are Done on the
Properties Configuration Page
37VPN Setup Wizard Page
38Monitor All Device Activity on a Single Page
39Monitor the Device with Real-Time Graphs
40IP Audit Rules Page. This Feature is Disabled
Because of the Top Layer IPS
41For CLI Users SSH or the Command Line Tool in
the ASDM GUI are Available
42HP ProCurve 9315 Routing Switch
MCNC
TWC
Top Layer
2 Circuit Connections
FAT Pipe
2 Connections
ASA 5540
Manage Entire LAN with PCM
HP 9315 Routing Switch
43HP PCM Firmware Update Wizard
44HP ProCurve Devices Page
45IP Route Table
46Other Discussion Topics That NeedNetwork Security
- Desktop Security Anti-Virus Solutions
- Email Security Anti-Virus Anti-Spam Solutions
- Wireless Access for Students Sandbox Solution
- Non-College Computers on Your Network
47Wake Techs ITS Crew
- Dr. Darryl McGraw Chief Information Officer
- Leigh Anne Dupree Director, IT Help Desk
Support - Chris Keefer Director, Systems
- Chris Wheeler Director, Network Services
- Tim Nicholson Manager, Administrative Computing
- Dale Weaver Manager, Web Services
- Fred Zahn Manager, Network Services
- Carlos McCormick Manager, Instructional
Technologies - Alec Woodruff IT Systems Engineer
- Buddy Gilmore IT Voice Engineer
- Jason Pickard Senior Systems Analyst
- Thomas Guettler Senior IT Analyst
- Ernest Youngblood Help Desk Analyst
- Cary Osborne IT Analyst
- Frank Spikes IT Analyst
- Dave Goldstein IT Technician
- Jeremy Blalock IT Technician
- Liz Winfrey Web Designer Specialist
- Susan Fenn Programmer/Analyst
48Question PeriodAnswers are OptionalOpinions are
always Given
- Visit Wake Techwww.waketech.edu
- Visit our ITS its.waketech.edu
- My Email cpwheeler_at_waketech.edu