By Md Muhtashim Jahin
The project was performed in the Industrial Network Cybersecurity (INCS) Lab of British Columbia Institute of Technology (BCIT). BCIT’s INCS lab using Industry-Standard Cisco infrastructure and Dell rack servers—exactly the kind of gear you’d find in Big Corporate Environments (10,000+ Employees).
Network Security Architecture and Configuration of an Enterprise Network Infrastructure for a Property Management Firm with headquarters in Vancouver and a branch office in Toronto. The firm employs over 300 staff members across various departments, necessitating a secure, efficient, and scalable network architecture to support daily operations.
The Vancouver headquarters hosts the primary IT infrastructure and accommodates the following departments:
The Toronto branch office houses the same departments except for Administration, relying on the Vancouver data center for centralized IT services. All core network services, including DNS, DHCP, Web Server, and SMTP, are hosted at the Vancouver office, with a secure, high-speed WAN link connecting both locations.
Firewall: Cisco Firepower 1010
Router: Cisco 4000 Series Integrated Services Router (ISR)
Switch: Cisco Catalyst C9200-48P Layer 3 Switch
Wireless Access Point: Cisco Catalyst CW9163E Tri Band IEEE 802.11a/b/g/n/ac/ax/h/d 3.90 Gbit/s
Server: Dell Rack Servers
Network Overview
The project aims to implement a robust, secure, and scalable network infrastructure that ensures high availability and optimal performance for business operations. The proposed solution incorporates:
Network Component Roles
To achieve optimal performance, security, and redundancy, the network will include:
Cisco Firepower Firewalls: Securing internal and external traffic while enforcing security policies.
DHCP & DNS Servers: Managing IP addressing and domain name resolution.
Email & Web Servers: Enabling seamless communication and web hosting.
WAN Optimization: Reducing latency and ensuring smooth data transfers between offices.
Configured Security Solutions
To protect the corporate network from cyber threats and unauthorized access, the following security strategies will be implemented:
Network Segmentation with VLANs: Departments will be isolated using VLANs to enhance security and minimize unauthorized access between departments.
Firewall Security Zones: The firewall will establish multiple security zones, segregating public, private, and DMZ networks to enforce access controls and protect sensitive resources.
Layer 3 Core Switches with HSRP & LACP: Two Layer 3 core switches configured with Hot Standby Router Protocol (HSRP) for redundancy and Link Aggregation Control Protocol (LACP) for increased bandwidth and failover protection.
Access Switches with LACP: Each department will have two access switches connected using LACP for improved link reliability and load balancing.
Traffic Filtering & Inspection: Firewalls will inspect and filter traffic entering and leaving each security zone based on policies to prevent unauthorized access and mitigate cyber threats.
Access Control Lists (ACLs): Restricting unauthorized traffic within the network.
VPN Encryption: Secure IPsec VPN tunnels will provide encrypted communication between Vancouver and Toronto, ensuring the confidentiality and integrity of data transmitted over the WAN.
Redundant Network Infrastructure: HSRP ensures high availability of the core network by dynamically switching to a standby router in case of failure.
Regular Security Audits: Monitoring and updating network security policies to align with evolving cybersecurity threats.