Examine Network Security principles, protocols and standards.
Unit 17 Network Security - Higher National Diploma in Computing
Learning Outcomes
LO1. Examine Network Security principles, protocols and standards.
LO2. Design a secure network for a corporate environment.
LO3. Configure Network Security measures for the corporate environment.
LO4. Undertake the testing of a network using a Test Plan.
Assignment Brief and Guidance:
EMC Finance is a well-known Finance company established in Kandy with more than 5000 customers and 8 branches island wide. Director board of EMC Finance hasdecided to restructure and enhance the computer network at Head office with up to date security measures to face the emerging security threats worldwide. You have been appointed as the Network Security Engineer for EMC Finance and it is now your responsibility to plan and implement a secure network that fulfils the company`s expectations.
Main requirements are as follows but NOT limited to;
1. Head office LAN need to be a Gigabit Ethernet and all Network devices need to be compatible with each other for maximum performance.
2. All the network devices such as Routers, Switches, Firewalls etc. should be manageable and only secure logins need be allowed on all devices.
3. AAA should use for Network Device login Authentication where possible and Syslog Server should use for record logging events, while having NTP server for time.
4. All publicly available resources including public web servers need to be separated from the main network and should move to a separate subnet. Only Secure Web Access should be enabled for web servers.
5. Design aSAN (Storage Area Network) implementation for saving Data for the Internal Network.
6. Network design should follow the Hierarchical Network Design Model.
7. End user authentication and managing of security polices need to centralized.
8. Internet usage management and URL filtering need to be enforced.
9. Communication between the Head office and the Branch offices need to be highly secured.
10. Quality of service (QoS) should be implemented where possible.