Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > Server Security > What is your network infratructure security ?

Reply
Thread Tools Display Modes

What is your network infratructure security ?

 
 
Eric
Guest
Posts: n/a

 
      07-07-2009
Hello,
(first sorry if I make mistakes as I am not fluent ;-)).

I am working for a big company and we would like to secure our network
infrastructure (Lan ip addresses etc...).

Here is the situation.
Actually, we can say that we have no network security as our
workstations and our servers are in the same LAN (10.10.x.x/16).

We would like to secure this by restructuring our LAN.

I was thinking about doing that :

1. Segment the network by zone (critical, Important, Normal).
2. Each zone will have a specific network address.
3. Each zone will have two sub-zone with two VLANs. The first sub-zone
will be for the "presentation servers" (like IIS etc...) and the second
sub-zone will protect the datas (SQL Server, specific applications
etc...)

Then a user will :
- only be able to connect to the needed zone (he will not have any
access to the "critical" zone if not needed).
- only be able to connect to the first sub-zone (IIS) and never to the
SQL Server for every zone.

What do you think about this infrastructure ?

Should it be too "heavy" for our network administrators to configure
them ?

Do you have others ideas ?

Thanks

--
Eric


 
Reply With Quote
 
 
 
 
Meinolf Weber [MVP-DS]
Guest
Posts: n/a

 
      07-07-2009

Hello Eric,

Domain internal you can of course separate workstations and servers with
VLANs. But for your users you also have the need to access all applications
like SQL, IIS etc. i assume, so with all subnets you have to make sure they
can work.

Your current ip range consist of 65534 hosts, do you need that amount of,
you have really big broadcasting domain that way?
Network: 10.10.0.0
Network mask: 255.255.0.0
First host address: 10.10.0.1
Last host address: 10.10.255.254

To secure your network you have to use firewalls, not subnets. But therefore
you have also to make sure, that domain controllers for example, must replicate
and therefore needs different ports to be open.

So i think, deviding the big ip range in multiple subnets is fine. But "blocking"
domain internal traffic doesn't really help.

Use access control to servers and configure the user workstations to allow
or disallow applications and tasks they are able to do. Also configure shared
folders for your needs and most important, don't make your users local admin.

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


> Hello,
> (first sorry if I make mistakes as I am not fluent ;-)).
> I am working for a big company and we would like to secure our network
> infrastructure (Lan ip addresses etc...).
>
> Here is the situation.
> Actually, we can say that we have no network security as our
> workstations and our servers are in the same LAN (10.10.x.x/16).
> We would like to secure this by restructuring our LAN.
>
> I was thinking about doing that :
>
> 1. Segment the network by zone (critical, Important, Normal).
> 2. Each zone will have a specific network address.
> 3. Each zone will have two sub-zone with two VLANs. The first sub-zone
> will be for the "presentation servers" (like IIS etc...) and the
> second
> sub-zone will protect the datas (SQL Server, specific applications
> etc...)
> Then a user will :
> - only be able to connect to the needed zone (he will not have any
> access to the "critical" zone if not needed).
> - only be able to connect to the first sub-zone (IIS) and never to the
> SQL Server for every zone.
> What do you think about this infrastructure ?
>
> Should it be too "heavy" for our network administrators to configure
> them ?
>
> Do you have others ideas ?
>
> Thanks
>



 
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
network security key Peter Mac Windows Vista Security 4 01-06-2010 04:10 AM
infratructure preparations for Windows 2008 domain upgrade jprstokato Windows Update 4 10-16-2008 08:23 AM
Re: infratructure preparations for Windows 2008 domain upgrade PA Bear [MS MVP] Windows Server 4 10-16-2008 08:23 AM
Network runs fine with open security and not with security Niffty Nev Windows Vista Security 4 01-27-2008 02:42 AM
network security key-HELP plumpkin6 Windows Vista Administration 1 01-12-2008 05:19 PM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59