How Purdue University Calumet maintains sanity in a campus BYOD environment Presented by: Tim Loudermilk - Supervisor of Network Administration.

Slides:



Advertisements
Similar presentations
Designing for Pervasive Network Security. Designing for Security Our aim in this section will be to concentrate on how campus Networks can be designed.
Advertisements

Network Systems Sales LLC
Introducing New Additions to ProSafe Advanced Smart Switch Family: GS724TR and GS748TR (ProSafe 24 and 48-port Gigabit Smart Switches with Static Routing)
Agenda Product Overview Hardware Interfaces Software Features
MikroTik Vendor Session © MikroTik MikroTik Vendor Session WISPNOG February th, 2005 Chicago, IL.
5.1 Overview of Network Access Protection What is Network Access Protection NAP Scenarios NAP Enforcement Methods NAP Platform Architecture NAP Architecture.
Page 1 MOTOROLA and the Stylized M Logo are registered in the US Patent & Trademark Office. All other product or service names are the property of their.
Wireless and Network Security Integration Defense by Hi-5 Marc Hogue Chris Jacobson Alexandra Korol Mark Ordonez Jinjia Xi.
Campus LAN Overview. Objectives Identify the technical considerations in campus LAN design Identify the business considerations in campus LAN design Describe.
Multi-Layer Switching Layers 1, 2, and 3. Cisco Hierarchical Model Access Layer –Workgroup –Access layer aggregation and L3/L4 services Distribution Layer.
Team MAGIC Michael Gong Jake Kreider Chris Lugo Kwame Osafoh-Kintanka Wireless Network Security.
Presented by Serge Kpan LTEC Network Systems Administration 1.
© 2003, Cisco Systems, Inc. All rights reserved. FWL 1.0— © 2003, Cisco Systems, Inc. All rights reserved.
WIRELESS SECURITY DEFENSE T-BONE & TONIC: ALY BOGHANI JOAN OLIVER MIKE PATRICK AMOL POTDAR May 30, /30/2009.
D-Link Unified Access Point
Introductory deck to Avaya WLAN 9100 Series
A Guide to major network components
WiNG 5.3.
Mesh Network Technical Guide for the Mesh AP Topic 2 Installation Knowledge / Network Design Copyright © PLANET Technology.
Being Proactive with Computer Posture Assessment Department of Housing and Residence Education Charles Benjamin.
Wireless Network Security. Access Networks Core Networks The Current Internet: Connectivity and Processing Transit Net Private Peering NAP Public Peering.
802.11n Wireless Portable AP/Router WNRT / 33 Outline  Product Overview  Product Features  Product Applications  Operation Mode  Web UI 
Technical Training: DAP-1360 Wireless N Access Point DAP-1360.
195Eg Ethernet Wired LAN 195Eg. Wireless Ethernet Setting IP Address Using Utility Programs Begin Programming Definition Selection Programming Modes of.
Networking Components
TEW-812DRU Training. TEW-812DRU AC1750 Dual Band Wireless Router.
The Operator Neutral Access At KistaIP. KistaIP ? Is a student dorm with 144 apartments.
OASIS V2+ Next Generation Open Access Server CSD 2006 / Team 12.
Dartmouth’s Wireless Network May 16, 2005 David W. Bourque.
Virtual LAN Design Switches also have enabled the creation of Virtual LANs (VLANs). VLANs provide greater opportunities to manage the flow of traffic on.
Semester 3, v Chapter 3: Virtual LANs
Wireless Networks 2015 CTSP Course CTSP Clsss Wireless - February
Altai Certification Training Backend Network Planning
Common Devices Used In Computer Networks
ACM 511 Chapter 2. Communication Communicating the Messages The best approach is to divide the data into smaller, more manageable pieces to send over.
Implementing Network Access Protection
© Aastra – 2012 SIP-DECT 4.0 RFP 43 WLAN June 2012.
Wireless standards Unit objective Compare and contrast different wireless standards Install and configure a wireless network Implement appropriate wireless.
Module 2: Installing and Maintaining ISA Server. Overview Installing ISA Server 2004 Choosing ISA Server Clients Installing and Configuring Firewall Clients.
NETWORKING COMPONENTS AN OVERVIEW OF COMMONLY USED HARDWARE Christopher Johnson LTEC 4550.
Module 9: Designing Network Access Protection. Scenarios for Implementing NAP Verifying the health of: Roaming laptops Desktop computers Visiting laptops.
Bluesocket vWLAN Overview. Its ALL about n……
Configuring Network Access Protection
Networking Devices.
Chapter 4 Version 1 Virtual LANs. Introduction By default, switches forward broadcasts, this means that all segments connected to a switch are in one.
7.4 Update - ISE Session.
© 2007 Cisco Systems, Inc. All rights reserved.Cisco Public ITE PC v4.0 Chapter 1 1 Communicating over the Network Network Fundamentals – Chapter 2.
Networking Components William Isakson LTEC 4550 October 7, 2012 Module 3.
Presented by Ian Mearns FUSD. Fresno Unified School District 5,000 teachers & 4,000 support / administrative staff 75,000 students 110 schools and admin.
BYOD Technical workshop Simon Bright - E2BN Philip Pearce – E2BN.
© ExplorNet’s Centers for Quality Teaching and Learning 1 Install, configure, and deploy a SOHO wireless/wired router using appropriate settings. Objective.
Model: DS-600 5x 10/100/1000Mbps Ethernet Port Centralized WLAN management and Access Point Discovery Manages up to 50 APs with access setting control.
User-group-based Security Policy for Service Layer Jianjie You Myo Zarny Christian Jacquenet
Networks and Security Great Demo
Wireless Access Point Product Overview
Wireless Ethernet Programming
Instructor Materials Chapter 1: LAN Design
IFIP-UNU ADVANCED COURSE ON NETWORKING AND SECURITY Module II-Wireless Communications Section 5 Access Points.
Product Introduction --AP Controller M3 Yaojun 26/12/2015
Wireless IP products: GWN series
Optical-Based Switching Solutions
Wireless Access Point Product Overview
Implementing Network Access Protection
EMG6765-Q10A AC2200 Gigabit Ethernet MoCA Gateway
Virtual LANs.
2018 Real Cisco Dumps IT-Dumps
2018 Real CompTIA N Exam Questions Killtest
Instructor Materials Chapter 8: Applied Networking
What’s New In WatchGuard Wi-Fi Cloud v8.6
Introduction to the WatchGuard AP Device
Presentation transcript:

How Purdue University Calumet maintains sanity in a campus BYOD environment Presented by: Tim Loudermilk - Supervisor of Network Administration

ABOUT PURDUE UNIVERSITY CALUMET An academically comprehensive regional university and part of the Purdue University system Located in Hammond, Indiana (less than 25 miles southeast of downtown Chicago). 19-building, 167-acre neighborhood campus An enrollment of over 10,000 students Athletics program sponsoring 12 sports. A residential campus offering apartment- style, private bedroom living for about 750 students

PURDUE CALUMET - NETWORKING TEAM The Purdue Calumet Networking Team is a part of the Information Services division and consists of: 1 Supervisor 2 Full time network administrators 2 Student workers Responsible for the management, maintenance, and security of the entire campus data network: Fiber Optic and Copper cable plant management WAN, LAN, WLAN administration Firewall, IPS, NAC, SIM, and End Point Security administration IP/DNS distribution and management Compliance (PCI, HIPAA, FERPA, CALEA)

PURDUE CALUMET CAMPUS DIAGRAM

PURDUE CALUMET NETWORK CHALLENGES Small team Responsible for: Over 7,000 network ports spread across 19 buildings A campus wireless network serving over 2,500 concurrent users and over 7,000 unique devices per day Network support in Residence hall housing over 700 student BYOD specific challenges Public University – academic freedom Device to User Identification (CALEA, DMCA) Onboarding of personal devices Security Bandwidth/QOS

LEGACY NETWORK Wired All wired ports across campus were plug and go. You plugged in and received an IP via DHCP. Static MAC locking, VLANS, and port policy were implemented to control unwanted devices and services such as DHCP/DNS/WEB servers from being deployed on the edge. Wireless Wireless network was built for coverage, based on 2.4Ghz even though hardware was dual radio 2.4/5Ghz x via PEAP was used for security. Multiple SSID’s were enabled to maintain backwards security (dynamic WEP/WPA/WPA2) and client (802.11b) compatibility.

SOLUTIONS TO CHALLENGES Comprehensive suite of Network management tools Netsight Suite - Simplifies day to day network management Netflow enabled distribution switches – LAN visibility BYOD specific 802.1x and NAC provide user identity and device data Cloud Path Xpress Connect assist in 802.1x on-boarding Layered Security approach NAC enforcing dynamic policies at wired or WLAN edge Strict wireless filters (remove un-necessary multicast/broadcast traffic from the WLAN which reduces unnecessary airtime) MU to MU blocking on the WLAN Strict firewall policy for BYOD segments Bandwidth rate-limits in place on BYOD WLAN network segments at controller Allot Net Enforcer providing packet shaping across all campus networks

CURRENT NETWORK OVERVIEW - WIRED All 6,500 end user wired ports are configured for MAC authentication providing end system visibility through NAC. NAC agent installed on all university owned workstations, providing end system compliance reports. Dynamic port security policies configured on end systems connecting to the network based on NAC rules and end system group membership. MAC locking set in NAC on all office workstations to assist desktop team with inventory control. Web based MAC registration configured on all open access walk-up ports and in residence halls. Agent based end system security assessment required in Residence halls

EXTREME/ENTERASYS ONEVIEW DASHBOARD

ONEVIEW NAC END SYSTEM VISIBILITY

ONEVIEW NAC END SYSTEM PROFILE

EXTREME/ENTERASYS ONEVIEW WIRELESS

PROXY RADIUS NAC VISIBILITY We proxy radius all wireless requests to our NAC servers, which then proxies through to our open source freeRadius servers.

QUARANTINE WIRELESS DEVICES

DYNAMIC WIRELESS POLICES

ON-BOARDING WITH CLOUDPATH “Calnet Setup” SSID. Users are redirected to our XpressConnect web server. Push multiple SSID configs to devices for failover or backward compatibility.

TOOLS - WLAN Metageek Eye P.A. Capture from AP into Wireshark via controller or capture from Macbook

TOOLS – OPEN SOURCE Zenoss AP bandwidth monitoring SNMP dhcp pool monitoring Set notification thresholds

PACKET SHAPING - ALLOT NETENFORCER AC 1440 osX mavericks update via iTunes in wireless Subnet To throttle or not to throttle, that is the question.

WIRELESS IMPROVEMENTS Increase AP density in high traffic areas and provide full 5Ghz band coverage. Disable legacy SSIDs. Create WPA2/AES only SSID to support full n modulation rates. Enable Guest and Calnet Setup on every other AP. Switch radio mode to a/n & g/n only. Enable auto 40Mhz channel width on a radios. New iPhones support 40Mhz A channel width Increase minimum basic rates in high density areas to fix sticky clients. Create AP filters to block unnecessary broadcast. Continue to enable MU/MU blocking. Enable MAC based auth on WPA-PSK SSID (dorm media device support) Dump airplay multicast on local LAN to decrease controller traffic. EduRoam Support Increase AP density in high traffic areas and provide full 5Ghz band coverage. Disable legacy SSIDs. Create WPA2/AES only SSID to support full n modulation rates. Enable Guest and Calnet Setup on every other AP. Switch radio mode to a/n & g/n only. Enable auto 40Mhz channel width on a radios. New iPhones support 40Mhz A channel width Increase minimum basic rates in high density areas to fix sticky clients. Create AP filters to block unnecessary broadcast. Continue to enable MU/MU blocking. Enable MAC based auth on WPA-PSK SSID (dorm media device support) Dump airplay multicast on local LAN to decrease controller traffic. EduRoam Support

LIVE DEMO Live Demo (Time Permitting)

QUESTIONS

THANK YOU!