0% found this document useful (0 votes)
4 views5 pages

Comprehensive Network Design Plan

The document outlines a network design for two branches, detailing infrastructure needs, equipment, and security measures. Branch 1 (HQ) will support 105 users while Branch 2 will support 35 users, with a total estimated cost of 1,245,321 and 692,571 respectively. The design includes MPLS connections, backup solutions, and security protocols to ensure reliable and secure operations.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
4 views5 pages

Comprehensive Network Design Plan

The document outlines a network design for two branches, detailing infrastructure needs, equipment, and security measures. Branch 1 (HQ) will support 105 users while Branch 2 will support 35 users, with a total estimated cost of 1,245,321 and 692,571 respectively. The design includes MPLS connections, backup solutions, and security protocols to ensure reliable and secure operations.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd

Network Design

ADSL ADSL
Leased LIne Leased LIne
Site to Site vpn
Through internet
As backup

Branch 2
Data Center Branch 1 2nd location

Branch 2 Details :
Branch 1 details :
- 20 Users
- 70 users
- 2nd branch
- HQ
Wimax as another backup solution
Network Design , Infrastructure HQ fixed
assets
 Branch 1 ( HQ )
 Assume increase 50% so no of End users (devices) will be 105 .
 I will make network infrastructure to service this number and also adding a
suitable number of Access points to insure WIFI connectivity .
 So needs in the HQ will be 110 points to serve
no Item Description QTY unit price total price
1 patch panels patch panels to terminate network cables 5 1718 8590
2 Switch 24 port Dlink switch 24 with poe 5 111250 556250
3 patch cord small patch cord 1 m for point connection to switch 111 71 7881
4 patch cord patch cord 3 m to end users connection 111 150 16650
5 cable organiser Metal cable organiser to handling the patch cords 5 350 1750
6 end points the end point termination from end user side 110 180 19800
7 cables roll of 305 m cables cat6 23 6800 156400
8 network rack a rach 42 U 1 15000 15000
9 access points tplink access point with omada controller 6 3500 21000
10 Router cisco asr router for MPLS connection 1 75000 75000
11 Firewalls Fortinet Ngfirewall for securing the connections ,VPN 2 75000 150000
12 Server Dell Server for Domain , DNS , backup solution , Antivirus 1 112000 112000
13 end point security software end point security on primes 105 1000 105000
1245321
Network Design , Infrastructure branch2 fixed
assets
 Branch 2
 Assume increase 50% so no of End users (devices) will be 35 .
 I will make network infrastructure to service this number and also adding a
suitable number of Access points to insure WIFI connectivity .
 So needs in the HQ will be 35 points to serve
no Item Description QTY unit price total price
1 patch panels patch panels to terminate network cables 2 1718 3436
2 Switch 24 port Dlink switch 24 with poe 2 111250 222500
3 patch cord small patch cord 1 m for point connection to switch 35 71 2485
4 patch cord patch cord 3 m to end users connection 35 150 5250
5 cable organiser Metal cable organiser to handling the patch cords 2 350 700
6 end points the end point termination from end user side 35 180 6300
7 cables roll of 305 m cables cat6 8 6800 54400
8 network rack a rach 42 U 1 15000 15000
9 access points tplink access point with omada controller 3 3500 10500
10 Router cisco asr router for MPLS connection 1 75000 75000
11 Firewalls Fortinet Ngfirewall for securing the connections ,VPN 2 75000 150000
12 Server Dell Server for Domain , DNS , backup solution , Antivirus 1 112000 112000
13 end point security software end point security on primes 35 1000 35000
692571
Network connection
 I Will use an MPLS connection between the HQ , ISP and the ISP , 2nd branch
as main , backup . To connect the two branches together to maintain the
services between them.
 Also I will use another connection as a backup or failover instead of MPLS if
failure – I have two solutions
 WiMAX connection . More stable .
 Site to site VPN using internet connection . Less stable .
 Also I am using two internet ADSL or leased lines for internet connectivity
for the end users , can be used in site to site VPN connection
Security

 I will use two Forigate Firewalls running together to ensure


redundancy and failover in case one of them is dead . Also can be
used as two factor authentication , vpn secure connection from users
to the servers .
 Also I will create the security profiles to be used in web filter ,
application control , ips , ids to ensure security from any attacks.
 for the end users , I will use Kaspersky endpoint security on primes
solution with backup on the cloud. to ensure the security on the
pcs , laps .
 Also I will buy original software for the windows , office .
 To ensure the files safety I will use Veeam as a backup software in
case of any disaster happened .

Common questions

Powered by AI

In the HQ, 6 TP-Link access points with Omada controllers are used at a total cost of 21,000, while in Branch 2, 3 such access points are used at a total cost of 10,500. The purpose of these access points is to ensure WiFi connectivity .

Kaspersky endpoint security on primes is employed to ensure the security of PCs and laptops, particularly against malware and unauthorized access. This security measure is supplemented by storing backups in the cloud using Veeam software, thereby safeguarding data against potential disasters. Additionally, purchasing original software for Windows and Office further enhances device security .

The network infrastructure planning considers a 50% increase in end-user devices, requiring HQ to support 105 devices and Branch 2 to support 35 devices. This involved adding access points to ensure sufficient WiFi coverage and scaling up the network infrastructure including switches, patch panels, and cabling, to meet the expanded capacity needs .

Investing in original software licenses is crucial to the security strategy as it ensures that the systems are free from vulnerabilities often exploited due to using pirated or outdated software versions. It enables access to vendor support, regular updates, and patches that safeguard against newly discovered threats .

At the HQ, 5 patch panels are used at a total cost of 8,590, and at Branch 2, 2 patch panels are used costing 3,436. These patch panels are crucial for terminating network cables, helping manage connections, and enhancing the network's scalability and maintenance .

The primary purpose of using MPLS (Multiprotocol Label Switching) is to connect the HQ and the 2nd branch through the ISP, serving as the main network connectivity solution. Components supporting MPLS' deployment include routers like the Cisco ASR for establishing these critical connections .

The strategies proposed for ensuring network redundancy and failover include using an MPLS connection as the main connection between the HQ, ISP, and the 2nd branch. In case of MPLS failure, a WiMAX connection is suggested as a more stable backup, and a site-to-site VPN using an internet connection is noted as a less stable alternative. Additionally, two internet ADSL or leased lines are recommended for end-user connectivity and can be used in the site-to-site VPN connection .

The chosen firewall solution, employing two Forigate firewalls, balances security features and redundancy by providing failover capacity should one firewall fail. This system enables continuous secure operations, including two-factor authentication and secure VPN connections while implementing comprehensive security profiles for attack prevention .

Network security is enhanced by using two Fortinet firewalls running together to ensure redundancy and failover in case one fails. This setup is augmented by using two-factor authentication and VPN secure connections from users to the servers, along with security profiles that include web filtering, application control, IPS, and IDS to combat potential attacks .

Veeam backup software is an integral part of the disaster recovery strategy, providing robust solutions for data backup and recovery in case of unforeseen events. It ensures that all critical data can be recovered, thus maintaining continuity and minimizing downtime during disasters, aligning with the cloud-based backup approach .

You might also like