UNM Enterprise Firewall Service Design & Operations
Our Goals Protect Data Center and Campus Networks Prevent breaches and outages Provide accessible internet services 11/12/2018
Enterprise Firewall Features Application Visibility and Control (App-ID) User Visibility (User-ID) IPS Anti-Malware Network-level Antivirus Exploit Protection Logging and Reporting Wildfire sandboxing Active/Passive Redundancy IPv6 Capable VPN services Full routing and switching capability 11/12/2018
Architecture Separate Firewalls for each service area Lobo Zone for Departments Data Center Branch Campuses Remote Offices Voice-over-IP Networks Redundant Firewalls in each area High Speed Backbone 100G internet connectivity 11/12/2018
Remote Office and Cloud Connectivity IPSEC tunnels with IKEv2 Utilizing DSL links on remote campuses Dedicated Fiber = Expensive Encrypted connectivity to cloud services Data Center Redundancy 11/12/2018
What is a Security Policy on the firewall? Describes what is allowed or denied Initiating IP Address, Country, or User Destination IP address, Country, or User What Application What Ports and Protocols 11/12/2018
Firewall Operations All departments have basic security policy Vulnerability Protection Anti-Malware Known bad actors Allowed outbound traffic from UNM networks Specific security policy rules can be made upon request 11/12/2018
How do I make a request to change security policy? Enter a ticket in Help.UNM - Refer to FastInfo #5474 Initial consultation with IT Data Network Group Ticket sent to Information Security & Privacy Office Application name: Source (Un-trust) IP(s): Destination (Trust) IP(s): Network port(s) and protocol(s): Function: Justification: Implementation and Testing by IT Data Network Group 11/12/2018
Firewall Roadmap FY19 More segmentation for departments Client based VPN access Wireless Migration 11/12/2018
Central Management Demo 11/12/2018
Thank you for listening! For support visit https://help.unm.edu Or call us at 505-277-5757 11/12/2018