Design Unit 26 Design a small or home office network HND in Computing and Systems Development
Timeline Week Activity 1 10 LO2 Devices, Bandwidth, Users 2 11 LO2 Applications, Scaling, Security 3 12 Assignment 2 LO2 4 13 LO3 Device installation 5 Introduction 14 LO3 Network installation 6 LO1 Capacity 15 LO3 Testing 7 LO1 Usage 16 L04 User access, maintenance 8 LO1 Security 17 LO4 Improvements 9 Assignment 1 LO1 18 Assignment 3 LO3 & 4 (mostly witness)
Learning outcome 2 Be able to design small or home office networks Devices: number of connected devices; anticipated participation Bandwidth: average load; peak load; local Internet availability; cost constraint Communications plan from lesson 2 Users: quality expectations; concept of system growth Applications: requirements eg security, quality of service Communications: considerations eg suited to devices, suited to users, lifestyle preferences, commercial requirements Scalable: considerations eg supporting device growth, supporting additional devices, bandwidth use trend change Security: considerations eg addressing policy, device participation, firewall rules, encryption preference
LO2 Assessment criteria 2.1 Design a small or home office network solution to meet a given specification 2.2 Evaluate the design and analyse user feedback
Previously …. You created a physical and logical network design There are still design decisions to be made Namespaces Operating systems Applications Scalability Security
Namespaces Names are needed for accounts, machines, shares, emails, directories What are the rules for naming Formulaic – eg T202Bay12 Thematic – eg Chewie, Leiai, Deathstar Functional – Staff007, Student40917 Descriptive – Staffshare, Studshare, T104Printer Can be difficult to stick to one type Often mixed, with one type dominant
Namespace example Student userIDs are their MIS number Staff userIDs are their SurnameInitial Email addresses are the UserID@domain name Home directories are UserID Servers are Starwars names PCs are BayNumberRoomNumber Printers are PrinterTypeLocation
Activity Decide on the namespace policies for MWS
Operating systems Choices for servers, desktops, laptops, mobiles, tablets Open source – Linux Proprietary Microsoft Apple Google Consider cost, support, features, technical knowledge Make a justified recommendation for MWS
Applications for MWS Office Manufacturing Payroll Accounting
Scalability How easy will it be for the network to grow with the business? Server file space and additional users Network ports Increased bandwidth More CNC machines Assess your design for scalability. How will it cope if the business grows to 4 times the size Employees Extra building Machines and devices
Security Wireless LAN No Default Settings – change SSID and Admin account Cell Sizing – modify transmitter power SSID Naming – use a meaningless name Cloaking – turn of broadcast SSID name MAC Filters – et allowable MAD addresses Encryption – use WPA2 Restricted IP – set IP ranges in DHCP Turn off unnecessary services
Password security Set minimum and maximum lengths Passwords should use three of four of the following four types of characters: Lowercase Uppercase Numbers Special characters such as !@#$%^&*(){}[] Require a number of unique passwords before an old password may be reused - say 24 Set a maximum password age - 60 days
Password security Account lockout threshold - 4 failed login attempts Reset account lockout after 30 minutes. Password protected screen savers should be enabled and should protect the computer within 5 minutes of user inactivity Rules that apply to passwords apply to passphrases which are used for public/private key authentication
Malware protection Anti virus Update OS and applications Firewalls Software in OS Built into routers Appliances
Security appliances Unified threat management (UTM) network firewalling network intrusion prevention gateway antivirus (AV) gateway anti-spam VPN (virtual private network) content filtering load balancing data leak prevention on-appliance reporting Easy to manage but comprehensive
Examples WatchGuard Firebox T10 Check Point 600 Appliance Easy to install Web interface Subscription updates Priced feature set (£300-700) Check Point 600 Appliance Can pay for management (£20/month) £300
Security for MWS Write a brief security and recommend any security products for MWS