Title: NETWORK DESIGN PROJECT SUNNYSLOPE ELEMENTARY SCHOOL
1NETWORK DESIGN PROJECTSUNNYSLOPE ELEMENTARY
SCHOOL
RANDY CROCKETT - ASH RAND - DIRK FRETZ - DANIEL
CURTIS
2Acknowledgements
- Professor Gulledge
- Professor Sherwood
- Professor Bruyn
- Cisco Networking Academy
- DeVry University
DANIEL CURTIS
3Presentation Overview
- Sunnyslope Elementary Stats
- WAN Design
- IP Addressing
- Hardware/Software
- LAN Design
- Security Network Management
- Additional Network Project Factors
- Summary
DANIEL CURTIS
4Sunnyslope Elementary School Washington
Elementary School District
- 240 E. Vogel Phoenix, AZ 85020
- Principal Mrs. Lori McAllister
- Office Hours 730am to 330pm
- Grades Pre-K to 6 Enrollment 845
- Phone (602) 347-4300 Fax (602) 347-4320
DANIEL CURTIS
5Washington ElementarySchool DistrictWide Area
Network
DANIEL CURTIS
6WAN Implementation
7Internet Connectivity
8Washington ElementarySchool District IP
Addresses
DANIEL CURTIS
9IP Addressing Scheme
- District Network IP Addresses
- Network IP Address 10.1.0.0
- Class A Private Address
- 8 Borrowed Bits
- Subnet Mask 255.255.0.0
- The ability to support 254 Subnets
- 65,534 Hosts Per Subnet
- Added Security Due to Private Address
DANIEL CURTIS
10IP Addresses for Hubs Schools
11Sunnyslope IP Addresses
- Curriculum, Admin, and Cluster Heartbeat
separated by Subnets, VLANs, and ACLs. - Sunnyslope Subnet Range 10.6.0.0 10.10.0.0
- Curriculum Subnet 10.6.0.0
- Administration Subnet 10.7.0.0
- Cluster Heartbeat subnet 10.8.0.0
- Curriculum Addresses DHCP
- Administrative Addresses Static
- Cluster Heartbeat Address Static
DANIEL CURTIS
12District SchoolHardware Software
RANDY CROCKETT
13WAN Internet Security
- Double Firewall Implementation
- Demilitarized Zone (DMZ)
Cisco PIX 535
RANDY CROCKETT
14Switches
Cisco Catalyst 3750G-12S12 Gigabit Ethernet SFP
Ports
Cisco Catalyst 2970G-24TS24 Ethernet 10/100/1000
ports and 4 (SFP)
RANDY CROCKETT
15Routers (Layer 3)
Cisco Catalyst 6506
Cisco 2621XM
- Will Support our 20 T1 Lines
- Will incorporate our IDS
16Workgroup Servers Dell PowerEdge 2650
RANDY CROCKETT
17Enterprise Servers PowerEdge 6650
RANDY CROCKETT
18Proxy/Cache/Content Filtering
- Red Hat Linux
- Secondary DNS server
- Squid Proxy Server
- Conserve Bandwidth Resources
- Websense Enterprise v5
- Filter Inappropriate Content
RANDY CROCKETT
19Clustering
- For Terminal Services and Databases
- High Availability
- Scalability
- Ease of Administration
- Inexpensive Hardware
- Load Balancing
- Distributed Computing
RANDY CROCKETT
20Terminal Server
- High Availability of Information
- Ease of Administration
- Inexpensive Workstations
- Linux Workstations
RANDY CROCKETT
21Sunnyslope ElementaryCampus Wiring Layout
DIRK FRETZ
22Sunnyslope CampusNetwork/Wiring Diagram
- MDF (Main Distribution Facility) Location
- IDF (Intermediate Distribution Facility)
Locations - CAT5e (1 Gbps) Cable Drops Per Room
- Multi-Mode Fiber Optic Line (1 Gbps) IDF to MDF
DIRK FRETZ
23Sunnyslope Campus
DIRK FRETZ
24Cable Amounts Required CAT5e (1 Gbps)
25Cable Amounts Required CAT5e (1 Gbps)
DIRK FRETZ
26Cable Amounts Required Multi-Mode Fiber Optic (1
Gbps)
DIRK FRETZ
27WAN LAN Security
WAN LAN Security
ASH RAND
28WAN/LAN Security Measures Network Management
- External Security
- Operational Security
- Surveillance
- Passwords
- Auditing
- Access Rights
- Viruses
ASH RAND
29External Security
- All MDFs, IDFs, and Cabinets Will be Locked
- Cabinet Trigger Signals a Pager if AnyCabinets
or Rooms be Opened
ASH RAND
30Operational Security
- Limit Who can Use the System
-
- When They can Use the System
ASH RAND
31Surveillance
- Video Cameras
- Deterrent
- Identification
- Placed in Key Locations
- Intrusion Detection
- Data Flow Monitoring for Unusual Activity
- Content Filtering
ASH RAND
32Passwords
- All Network Entry Will be Password Protected
- Passwords Must be Changed Every 90 Days
- Password Criteria
- At Least 8 Characters
- At Least One Alpha Character
- At Least One Numeric Character
- At Least One Upper Case Character
ASH RAND
33Auditing
- Software to Monitor Every Transaction
- Electronic Log Will Record
- Date, Time, and Owner of Each Transaction
ASH RAND
34Access Rights
- Who has Access Rights to the Resource(s)
- How the User may Access the Resource(s)
- Read, Write, and Execute Access
OK
OK
OK
NO!
ASH RAND
35Guarding Against Viruses
- Anti-Virus Software Will Include
- Signature-Based Scanning
- Terminate-and-Stay-Resident Monitoring
- Multi-Level Generic Scanning
ASH RAND
36ACLs VLANs SECURITY
ASH RAND
37Security Policy
- Network Administrators Will
- Endeavor to Protect the Networks Systems for
Which They are Responsible - Network Users Will
- Abide by the Appropriate Use of Information
Technology Policy of the School District - Abide by Departmental Policies Governing
Connection to Departmental Networks
ASH RAND
38AdditionalNetwork Project Factors
DIRK FRETZ
39Cost Breakdown
DIRK FRETZ
40Cost Breakdown (Cont)
41Cost Breakdown (Cont)
42Network Testing Plan
- After Setting Up the Network,
- Tests Will be Run to Determine
- Connectivity
- Contingency
- Throughput
- Security
DIRK FRETZ
43Contingency Plan
DellPowerVault 122T
APC Smart-UPS 1000VA/670W
- UPS
- Backups
- Redundancy
- Extra Hardware
- Ideal for remote, distributed, or LAN server
backups - Great for application servers that need
unattended backup - Max capacity of 1.6TB (compressed)
- Max backup rate of 108GB/hr (compressed)
- Automatic Self Test
- Automatic Voltage Regulation (AVR)
- Intelligent Battery Management
- Network-grade line conditioning
- PowerChute Smart-UPS Software
DIRK FRETZ
44Environmental Controls
- Temperature Will be Maintained at 21º C / 69.8 º
F - Humidity Level Will be Maintained Between 30-50
DIRK FRETZ
45Project Timeline
DIRK FRETZ
46Final Stages
DANIEL CURTIS
47Options and Future Growth
- SLA
- Ring and Mesh
- Voice over IP
DANIEL CURTIS
48Service Level Agreement
DANIEL CURTIS
49Pilot Network
- We will be Demonstrating
- ACLs (Access Control Lists)
- Cluster Terminal Services
- Linux Workstations
DANIEL CURTIS
50Summary
- Sunnyslope Elementary Stats
- WAN Design
- IP Addressing
- Hardware/Software
- LAN Design
- Security Network Management
- Additional Network Project Factors
- Summary
DANIEL CURTIS
51RADD NETWORKING, INC.
DANIEL CURTIS