1 Network-level Security at UVa Jim Jokl Common Solutions Group January 2006
UVaNet Security Logical View Level 3 Zone Level 1 Backbone Level 2 Backbone Fire Wall Level 3 Zone Level 3 Zone Users Clinical Network Users Internet VPN Joint VPN Fire Wall “existing U.Va. network” “more secure” VPN Fire Wall VPN Users
3 UVa Network Security Summary Technical Operates at the network jack level VLAN-based in wiring closets Separate routed backbone links (~ building-level subnets) No inbound connections via firewall allowed to More Secure network (remote VPN access is available) Level-3 zones are customized based on user needs Policy-basis Requirements for computers on More Secure network developed via a process with departmental technical contacts Management delegated to departmental staff who use web-based tools to manage ports (speed, duplex, VLAN, diagnostics, etc)
4 Some Reference URLs Network-layer security IP address space allocation