WACHEMO UNIVERSITY
COLLEGE OF ENGINEERING AND TECHNOLOGY
Department of Information Systems
Course Name: System and Network Administration
Group member ID no.
1 TEWODROS TADESE…………………………1501356
2 YITBAREK JEMAL.....................………1501406
3 TESHOME TAMIRE.............................1501351
4 Melese Mathewos ............................1501090
Mini Intetnet Cafe Networking Proposal
TABLE OF CONTENTS
1 Executive SummaryProject Goals &
2 DeliverablesInfrastructure Design
3 PhilosophyRecommended Hardware & Technical 4 SpecsNetwork
Addressing & Service
5 ConfigurationCybersecurity & Operational
6 OversightPhysical Infrastructure & Facility
7 PlanningPhased Deployment RoadmapBudgetary
8 Outline & Financial ConsiderationsOngoing
9 Support, Data Integrity & Contingency
10 PlanningSupplemental Materials:
11 Visual Infrastructure Map
1. Executive Summary
This document outlines a robust and scalable technical infrastructure plan for a
compact internet café, supporting 8 to 16 concurrent users. The proposed solution
extends beyond basic connectivity to establish a secure, manageable, and professional
business environment. The core architecture is a high-performance wired network,
augmented by a segregated wireless guest network, centralized user session
management, and a structured cabling system. This design emphasizes operational
stability, customer data security, administrative control, and a strong foundation for
potential future expansion.
2. Project Goals & Deliverables
Primary Goals:Deliver consistent, high-availability internet connectivity for all client
[Link] a secure, accountable user access system integrated with time
tracking and [Link] a maintainable network environment that can adapt to
growing [Link] customer data and network integrity through layered
security measures.
Key Deliverables:A complete end-to-end infrastructure design, including LAN
segmentation and service roles.A detailed bill of materials (BOM) with minimum and
recommended hardware specifications.A logical and physical deployment plan with a
visual network schematic.A phased implementation checklist and a framework for
ongoing operational costs..
3. Infrastructure Design Philosophy
The network will be a structured Ethernet LAN employing a star topology for
maximum reliability and ease of troubleshooting. A client-server management
model will be utilized, with a central server handling authentication, billing,
and policy enforcement. For enhanced security, the design incorporates
network segmentation:Core Principle: All critical traffic flows through a central,
managed network [Link] Flow: Internet > ISP Modem > Security Router
> Managed Switch > [Link] Strategy: The use of Virtual
LANs (VLANs) is recommended to isolate the public Wi-Fi network from the
primary client stations and the administrative management network,
minimizing security [Link]: Primary user stations connect via wired
Gigabit Ethernet; a dedicated Wireless Access Point provides filtered internet
access for guest mobile devices.
4. Network Addressing & Service Configuration
Primary Network: [Link]/24 (example range)Static IP Reservations:Router LAN Interface:
192.168.1.1Management Server: 192.168.1.10Network Printer/Other Devices: [Link] -
192.168.1.20Dynamic Address Pool (DHCP): [Link] - [Link] (for client PCs and
guest devices).Router Setup: Configure DHCP with the above scope, set DNS (consider using
a filtered public DNS like [Link] or [Link]), enable the firewall, and disable remote WAN
[Link] Structure (Recommended):VLAN 100 (Native): Management (Server,
5 Recommended Hardware & Technical Specs
ISP Modem: Device compatible with the local service provider's technology (e.g.,
Fiber, VDSL).Business-Grade Router: Must include stateful firewall, NAT, DHCP
server, and support for VLAN routing (inter-VLAN routing). Dual WAN support is
a valuable option for backup [Link] Layer 2 Switch: 16/24 port
Gigabit Ethernet switch with VLAN, Quality of Service (QoS), and port monitoring
[Link] Server: A dedicated, reliable [Link]: Quad-core
processor (Intel i5 or equivalent)RAM: 16 GB DDR4Storage: 500 GB SSD (for OS
and applications) + 1 TB HDD (for user data and logs)Function: Hosts café
management software (billing, access control), acts as a local cache/server for
updates, and provides content filtering
Client Stations: PCs with specifications suitable for general web browsing and
light [Link] Wireless Access Point: Supports dual-band 802.
11ac/ax, multiple SSIDs, and client isolation for the guest [Link]
Protection: An Uninterruptible Power Supply (UPS) with adequate capacity to
safely shut down the server, router, and switch during a power [Link]
Cabling: Cat6 or Cat6a cabling, a labeled patch panel, and quality RJ-45 keystone
jacks at each station
Admin)VLAN 200: Wired Client StationsVLAN 300: Guest Wi-Fi (with bandwidth limits)
6. Cybersecurity & Operational Oversight
Network Perimeter: Activate the router's firewall; disable unused services;
implement MAC address filtering for the management [Link] & Content
Management: Utilize the café management software for mandatory login, time
tracking, and automated billing. Implement application-aware content filtering on the
server or router to block malicious sites and manage bandwidth-heavy protocols.
Auditing & Performance: The server should maintain detailed logs of user sessions
and financial transactions. Configure QoS on the switch to prioritize latency-sensitive
traffic and prevent bandwidth abuse by a single [Link] Security: Deploy a
separate, firewalled SSID for guests. Use WPA2-Enterprise or a captive portal for the
guest network to control access. Ensure client isolation is enabled on the guest VLAN.
Physical Safeguards: Install all core networking equipment (server, switch, router) in a
locked, ventilated cabinet. Consider a digital video recording system for premises
security.
[Link] Deployment Roadmap
Phase 1 - Planning: Finalize floor plan; mark cable drop points; confirm equipment
[Link] 2 - Procurement: Order all hardware, software licenses, and cabling
[Link] 3 - Physical Installation: Mount racks, run and terminate cables, install
workstation furniture and [Link] 4 - System Configuration: Configure router,
switch VLANs, server OS, and café management software. Create a standard image
for client [Link] 5 - Integration & Testing: Connect all devices; test connectivity,
speed, VLAN segregation, and management software functions. Test backup and
restore [Link] 6 - Staff Training & Launch: Train operators on the
management software, basic troubleshooting, and daily opening/closing procedures.
8. Physical Infrastructure & Facility Planning
Cabling: Install certified Cat6 cabling in conduit or raceways for protection and
professionalism. All cable runs must be within the 90-meter Ethernet [Link]
Management: Dedicate grounded electrical circuits for the networking cabinet and
client stations. Connect all critical infrastructure to the UPS and other equipment to
surge-protected power [Link] Planning: Design the layout for efficient cable
management, proper airflow around equipment, and ease of access for maintenance.
Ensure workstations have adequate space and power outlets
Begin a pilot operation phase with close monitoring
9. Budgetary Outline & Financial Considerations
Note: Costs are approximate and vary by region and brand)
16-Port Managed Gigabit Switch: 20,000 - 45,000ETB
Management Server System: 55,000 - 120,000ETB
Client PCs (8 units @): 35,000 - 60,000 ETB
eachCommercial Wireless AP: 10,000 - 25,000ETB
Structured Cabling & Accessories: 20,000 - 55,000UPS
System: 35,000ETB - 60,000ETB
Installation Labor &Miscellaneous: 25,000 - 70,000ETB
Estimated Total Capital Outlay (8 stations): 310,000 - 715,00ETB
10. Supplemental Materials: Visual Infrastructure Map
A detailed diagram will be provided separately, illustrating the physical
and logical connections between all components:
Internet Service Provider (ISP) Demarcation Point
Security Gateway / RouterCore Managed Switching
LayerManagement & Application ServerWired
Client Access LayerSecured Wireless Guest Access Point
11,. Ongoing Support, Data Integrity & Contingency
Planning
Preventive Maintenance: Schedule monthly reviews of system logs
and updates. Perform quarterly physical inspections and UPS
battery tests. Update firmware annually in a controlled manner.
Backup Strategy: Implement a 3-2-1 backup rule for server data:
maintain 3 total copies, on 2 different media (e.g., server HDD +
external drive), with 1 copy stored off-site or in a secure cloud
service. Test restoration [Link] Plan: Establish a service
agreement with a local IT provider for hardware failures. Maintain
thorough, updated documentation of all configurations and
passwords in a secure location.
Appendix
Network Connectivity Diagram contains a labeled network connectivity
diagram showing how the modem, router, switch, server, client PCs and
wireless access points connect in a star topology centered on the switch.
- ISP Modem: Connection to Internet Service Provider
- Router: WAN to LAN gateway (NAT, firewall)
- Switch: Central distribution (managed)