Campus Firewalling Dearbhla O’Reilly Network Manager Dublin Institute of Technology
Overview n Context of Firewall for DIT n Firewall Experiences n Mobile Network with Firewall n Where we are now ? n Where we are now ?
Background to DIT Firewall n Presentation in 2000 to IT Group on Firewall role in - Security - Bandwidth - Content (web)
Issues n Security - Educational institutions are prime targets - CPU power, bandwidth, disk space. Attacks - web page, spam, port scans, logon attempts n Bandwidth - Competition for traffic prioritisation and network utilisation n Content - Viewing inappropriate web content, serving content from DIT
Firewall Solutions n Security - Assist in protecting users, information, operation and reputation n Bandwidth - Allow core services run efficiently n Content – Designated Web Servers
Perimeter Firewall D.I.T.HEAnet
Implementation n Deny all and allow approved services n Standard set of services - desktop n Procedure - Internet Service Server Registration Form based on now Archived JISC Project – Use of Firewalls in Academic Environment. Archived
Firewall Use & Maintenance n Form - List of Ports to/from and Why ? n Server Administrator – Security, Patching, Responsibility. n Head of School/Section – Approves and complies with DIT & HEAnet Policies
Registration Conditions n n Any service may be blocked without notice if network & systems staff suspect a security breach n n All services are provided for the server specified and should not operate as a proxy n n All approvals are subject to review by ISSC n n Firewall rule-sets for servers/services will be audited on a regular basis
Experiences n Paper Forms - by User n Firewall Rules are – by Service n ~200 Firewall Rules n Requirement for Rule Management Software n Firewall Rule Maintenance
Maintenance Experience n Logs - mainly used for real-time support n Firewall Maintenance - Backup/Recovery, Log Rotation, Patches, Upgrades etc.
Mobile Network Requirements n Wired & Wireless Connectivity for Student Laptops n Separate Projects starting to address Identity for Staff & Students n Service needed to be provided
D.I.T.HEAnet Mobile Perimeter Firewall
Mobile Network & Firewall n Traffic from mobile network in all sites passes through Bluesocket authentication gateway n Traffic from DIT mobile network into DIT fixed network is filtered through the same ruleset as applies to all external traffic n Traffic from DIT mobile network for external destinations is filtered through the same ruleset as standard outgoing DIT traffic
Mobile Network Access with Timed Firewall Rule
MRTG - Mobile Network Access
Limitations/New Requirements n Gigabit Ethernet n IPv6 Support n Performance n Reporting/Logging
Procurement Process n Request for Quotes n Based on Requirements n Award Criteria – Quality and Functional Characteristics, Technology, Cost, Supplier – Support, Maintenance, Experience.
Requirements n Functionality & Use of existing system n Technology Updates - IDS - IPS - Deep-packet inspection n Service Availability Options
Thank You & Questions?