180 likes | 197 Views
Design a scalable, secure home office network solution meeting given specifications. Evaluate design and user feedback.
E N D
Design Unit 26 Design a small or home office network HND in Computing and Systems Development
Learning outcome 2 • Be able to design small or home office networks • Devices: number of connected devices; anticipated participation • Bandwidth: average load; peak load; local Internet availability; cost constraintCommunications plan from lesson 2 • Users: quality expectations; concept of system growth • Applications: requirements eg security, quality of service • Communications: considerations eg suited to devices, suited to users, lifestyle preferences, commercial requirements • Scalable: considerations eg supporting device growth, supporting additional devices, bandwidth use trend change • Security: considerations eg addressing policy, device participation, firewall rules, encryption preference
LO2 Assessment criteria 2.1 Design a small or home office network solution to meet a given specification 2.2 Evaluate the design and analyse user feedback
Previously …. • You created a physical and logical network design • There are still design decisions to be made • Namespaces • Operating systems • Applications • Scalability • Security
Namespaces • Names are needed for accounts, machines, shares, emails, directories • What are the rules for naming • Formulaic – eg T202Bay12 • Thematic – eg Chewie, Leiai, Deathstar • Functional – Staff007, Student40917 • Descriptive – Staffshare, Studshare, T104Printer • Can be difficult to stick to one type • Often mixed, with one type dominant
Namespace example • Student userIDs are their MIS number • Staff userIDs are their SurnameInitial • Email addresses are the UserID@domain name • Home directories are UserID • Servers are Starwars names • PCs are BayNumberRoomNumber • Printers are PrinterTypeLocation
Activity • Decide on the namespace policies for MWS
Operating systems • Choices for servers, desktops, laptops, mobiles, tablets • Open source – Linux • Proprietary • Microsoft • Apple • Google • Consider cost, support, features, technical knowledge • Make a justified recommendation for MWS
Applications for MWS • Office • Manufacturing • Payroll • Accounting
Scalability • How easy will it be for the network to grow with the business? • Server file space and additional users • Network ports • Increased bandwidth • More CNC machines • Assess your design for scalability. How will it cope if the business grows to 4 times the size • Employees • Extra building • Machines and devices
Security • Wireless LAN • No Default Settings – change SSID and Admin account • Cell Sizing – modify transmitter power • SSID Naming – use a meaningless name • Cloaking – turn of broadcast SSID name • MAC Filters – et allowable MAD addresses • Encryption – use WPA2 • Restricted IP – set IP ranges in DHCP • Turn off unnecessary services
Password security • Set minimum and maximum lengths • Passwords should use three of four of the following four types of characters: • Lowercase • Uppercase • Numbers • Special characters such as !@#$%^&*(){}[] • Require a number of unique passwords before an old password may be reused - say 24 • Set a maximum password age - 60 days
Password security • Account lockout threshold - 4 failed login attempts • Reset account lockout after 30 minutes. • Password protected screen savers should be enabled and should protect the computer within 5 minutes of user inactivity • Rules that apply to passwords apply to passphrases which are used for public/private key authentication
Malware protection • Anti virus • Update OS and applications • Firewalls • Software in OS • Built into routers • Appliances
Security appliances • Unified threat management (UTM) • network firewalling • network intrusion prevention • gateway antivirus (AV) • gateway anti-spam • VPN (virtual private network) • content filtering • load balancing • data leak prevention • on-appliance reporting • Easy to manage but comprehensive
Examples • WatchGuard Firebox T10 • Easy to install • Web interface • Subscription updates • Priced feature set (£300-700) • Check Point 600 Appliance • Easy to install • Web interface • Can pay for management (£20/month) • £300
Security for MWS • Write a brief security and recommend any security products for MWS