Comprehensive Network Design Plan
Comprehensive Network Design Plan
In the HQ, 6 TP-Link access points with Omada controllers are used at a total cost of 21,000, while in Branch 2, 3 such access points are used at a total cost of 10,500. The purpose of these access points is to ensure WiFi connectivity .
Kaspersky endpoint security on primes is employed to ensure the security of PCs and laptops, particularly against malware and unauthorized access. This security measure is supplemented by storing backups in the cloud using Veeam software, thereby safeguarding data against potential disasters. Additionally, purchasing original software for Windows and Office further enhances device security .
The network infrastructure planning considers a 50% increase in end-user devices, requiring HQ to support 105 devices and Branch 2 to support 35 devices. This involved adding access points to ensure sufficient WiFi coverage and scaling up the network infrastructure including switches, patch panels, and cabling, to meet the expanded capacity needs .
Investing in original software licenses is crucial to the security strategy as it ensures that the systems are free from vulnerabilities often exploited due to using pirated or outdated software versions. It enables access to vendor support, regular updates, and patches that safeguard against newly discovered threats .
At the HQ, 5 patch panels are used at a total cost of 8,590, and at Branch 2, 2 patch panels are used costing 3,436. These patch panels are crucial for terminating network cables, helping manage connections, and enhancing the network's scalability and maintenance .
The primary purpose of using MPLS (Multiprotocol Label Switching) is to connect the HQ and the 2nd branch through the ISP, serving as the main network connectivity solution. Components supporting MPLS' deployment include routers like the Cisco ASR for establishing these critical connections .
The strategies proposed for ensuring network redundancy and failover include using an MPLS connection as the main connection between the HQ, ISP, and the 2nd branch. In case of MPLS failure, a WiMAX connection is suggested as a more stable backup, and a site-to-site VPN using an internet connection is noted as a less stable alternative. Additionally, two internet ADSL or leased lines are recommended for end-user connectivity and can be used in the site-to-site VPN connection .
The chosen firewall solution, employing two Forigate firewalls, balances security features and redundancy by providing failover capacity should one firewall fail. This system enables continuous secure operations, including two-factor authentication and secure VPN connections while implementing comprehensive security profiles for attack prevention .
Network security is enhanced by using two Fortinet firewalls running together to ensure redundancy and failover in case one fails. This setup is augmented by using two-factor authentication and VPN secure connections from users to the servers, along with security profiles that include web filtering, application control, IPS, and IDS to combat potential attacks .
Veeam backup software is an integral part of the disaster recovery strategy, providing robust solutions for data backup and recovery in case of unforeseen events. It ensures that all critical data can be recovered, thus maintaining continuity and minimizing downtime during disasters, aligning with the cloud-based backup approach .