Cisco Network Switches Juniper Firewall Clusters



Similar documents
IP Telephony Management

PowerLink Bandwidth Aggregation Redundant WAN Link and VPN Fail-Over Solutions

Smart Tips. Enabling WAN Load Balancing. Key Features. Network Diagram. Overview. Featured Products. WAN Failover. Enabling WAN Load Balancing Page 1

Document No. FO1101 Issue Date: Work Group: FibreOP Technical Team October 31, 2013 FINAL:

Note: This case study utilizes Packet Tracer. Please see the Chapter 5 Packet Tracer file located in Supplemental Materials.

High Availability Branch Office VPN

Troubleshooting and Maintaining Cisco IP Networks Volume 1

Disaster Recovery Design Ehab Ashary University of Colorado at Colorado Springs

WAN Failover Scenarios Using Digi Wireless WAN Routers

Lab Diagramming External Traffic Flows

Recommended IP Telephony Architecture

John Ragan Director of Product Management. Billy Wise Communications Specialist

How To Connect To Bloomerg.Com With A Network Card From A Powerline To A Powerpoint Terminal On A Microsoft Powerbook (Powerline) On A Blackberry Or Ipnet (Powerbook) On An Ipnet Box On

Course Venue :- Lab 302, IT Dept., Govt. Polytechnic Mumbai, Bandra (E)

21 st Century Campus Network Responsibility Matrix 5/26/10

DC Cook Plant Process Computer Replacement Project

Campus Network Best Practices: Core and Edge Networks

NETE-4635 Computer Network Analysis and Design. Designing a Network Topology. NETE Computer Network Analysis and Design Slide 1

Configuring DHCP Snooping

Configuring a customer owned router to function as a switch with Ultra TV

JOB READY ASSESSMENT BLUEPRINT COMPUTER NETWORKING FUNDAMENTALS - PILOT. Test Code: 4514 Version: 01

Networking Devices. Lesson 6

Barracuda Link Balancer

Basic IPv6 WAN and LAN Configuration

Associate in Science Degree in Computer Network Systems Engineering

DRO-210i LOAD BALANCING ROUTER. Review Package Contents

Emerson Smart Firewall

Lab Developing ACLs to Implement Firewall Rule Sets

OVERVIEW OF TYPICAL WINDOWS SERVER ROLES

Session Title: Exploring Packet Tracer v5.3 IP Telephony & CME. Scenario

Fundamentals of Windows Server 2008 Network and Applications Infrastructure

Security Design.

RuggedCom Solutions for

It should be noted that the installer will delete any existing partitions on your disk in order to install the software required to use BLËSK.

Using High Availability Technologies Lesson 12

1 PC to WX64 direction connection with crossover cable or hub/switch

Top-Down Network Design

SSL-VPN 200 Getting Started Guide

Any-to-any switching with aggregation and filtering reduces monitoring costs

For extra services running behind your router. What to do after IP change

Designing a Windows Server 2008 Network Infrastructure

iboss Enterprise Deployment Guide iboss Web Filters

SCOPE DOCUMENT. Trade Name IT- Network Systems Administration Post- Secondary DATE OF DISTRIBUTION VIA WEBSITE

Cisco RV082 Dual WAN VPN Router Cisco Small Business Routers

Lab Diagramming Intranet Traffic Flows

Unified Threat Management

Module 1: Overview of Network Infrastructure Design This module describes the key components of network infrastructure design.

Interconnecting Cisco Networking Devices: Accelerated (CCNAX) 2.0(80 Hs) 1-Interconnecting Cisco Networking Devices Part 1 (40 Hs)

RAS Associates, Inc. Systems Development Proposal. Scott Klarman. March 15, 2009

estadium Project Lab 8: Wireless Mesh Network Setup with DD WRT

How To - Configure Virtual Host using FQDN How To Configure Virtual Host using FQDN

Multi-Homing Security Gateway

Configuring High Availability for Embedded NGX Gateways in SmartCenter

Configuring WAN Failover with a Cisco 881 Router and an AirLink ES440

Basic Network Configuration

Document No. FO1004 Issue Date: Draft: Work Group: FibreOP Technical Team July 23, 2013 Final: Single Static IP Customer Owned LAN Router Support

CCNP SWITCH: Implementing High Availability and Redundancy in a Campus Network

PREPARED FOR ABC CORPORATION

VPN Only Connection Information and Sign up

Data Center Security 100% UPTIME PUZZLE. Page 1

Firewall VPN Router. Quick Installation Guide M73-APO09-380

IT-AD08: ADD ON DIPLOMA IN COMPUTER NETWORK DESIGN AND INSTALLATION

Layer 3 Network + Dedicated Internet Connectivity

Local Area Networks (LANs) Blueprint (May 2012 Release)

MEDIAROOM. Products Hosting Infrastructure Documentation. Introduction. Hosting Facility Overview

Chapter 2 Connecting the FVX538 to the Internet

Load Balance Router R258V

Network System Design Lesson Objectives

Magnum Network Software DX

Overview of Routing between Virtual LANs

Deploying Windows Streaming Media Servers NLB Cluster and metasan

State of Texas. TEX-AN Next Generation. NNI Plan

CUSTOMIZED ASSESSMENT BLUEPRINT COMPUTER SYSTEMS NETWORKING PA. Test Code: 8148 Version: 01

Implementing, Managing, and Maintaining a Microsoft Windows Server 2003 Network Infrastructure: Network Services (5 days)

1 Basic Configuration of Cisco 2600 Router. Basic Configuration Cisco 2600 Router

GlobalSCAPE DMZ Gateway, v1. User Guide

EdgeRouter Lite 3-Port Router. Datasheet. Model: ERLite-3. Sophisticated Routing Features. Advanced Security, Monitoring, and Management

Security Frameworks. An Enterprise Approach to Security. Robert Belka Frazier, CISSP

F5 Configuring BIG-IP Local Traffic Manager (LTM) - V11. Description

IT Discovery / Assessment Report Conducted on: DATE (MM/DD/YYY) HERE On-site Discovery By: AOS ENGINEER NAME Assessment Document By: AOS ENGINEER NAME

: Interconnecting Cisco Networking Devices Part 1 v2.0 (ICND1)

Chapter 4 Customizing Your Network Settings

ExamPDF. Higher Quality,Better service!

ACME Enterprises IT Infrastructure Assessment

SCADA/Business Network Separation: Securing an Integrated SCADA System

Configuring IPsec VPN with a FortiGate and a Cisco ASA

Figure 41-1 IP Filter Rules

NETWORK ADMINISTRATOR

Virtual Web Appliance Setup Guide

NETWORK SYSTEMS ENGINEER II

Load Balancing for esafe Gateway 3.0 when using Alteon s AD2 or AD3

Release Notes. SonicOS is the initial release for the Dell SonicWALL NSA 2600 network security appliance.

VLANs. Application Note

Updating Your Network Infrastructure and Active Directory Technology Skills to Windows Server 2008

Vocational Skills Contest

Cisco Certified Network Associate (CCNA) 120 Hours / 12 Months / Self-Paced WIA Fee: $

Device Interface IP Address Subnet Mask Default Gateway

Transcription:

Cisco Network Switches Juniper Firewall Clusters

Cisco Network Infrastructure

Cisco Network Infrastructure Core Network Consists of 4 Cisco 4506 switches 10 Gig E Fiber Optic Connections between switches Multiple blades provide various connection capabilities at core network locations From 10mb Copper or Fiber to 1 gb Provides Future Expansion Capabilities Redundantly

Cisco Network Infrastructure Distribution to Various Secured Areas via Cisco 3750 s Distributed Switches Provide Local Connection Needs All Distributed Networks Installed in Locked Cabinets. Distributed Network Provides Multiple VLANs for Network Isolation.

Cisco Network Infrastructure

Cisco Network Infrastructure PPC Network Provides Complete Isolation of PPC Systems From Business LAN/ WAN PPC Network Provides Secure Connections to our Emergency Operations Facility, EOF, and Technical Support Facility, TSC PPC Simulators are included in PPC Network Network Includes Long Reach Ethernet Remote Offsite Connections use VPN Thru Corporate Gateways

Fiber Optic Backbone Support Millstone Site Contains 3 Nuclear Units (MP2 and MP3 Operational) Approx 500 Acres on long Island Sound Millstone Site Support Includes Simulators, Training Facility, Emergency Facilities, and Fire Training Building Large Fiber Optic Infrastructure to Support Interconnection of Buildings

Fiber Optic Backbone Support Majority of Buildings Interconnected by Fiber optic Cables. 62.5/125 micron Multimode Provides Majority of Fiber 50/125 micron Single mode Provides gb optical Connections Optical infrastructure Supports WAN/LAN Process Computer Network and Security Network.

Fiber Optic Backbone Support Centrally Located Connection Points MP2 and MP3 New Systems being added to PPC Network Utilize F/O Expansion of PPS Network to new areas of Plant considers future growth needs Termination, Testing and Validation of cabling provided by outside and in house support.

Independent Routers provide Automatic Failover ability Network Routing PPC Network routing is provided by two independent clusters MP2 and MP3 Juniper Firewalls provide all route paths for PPC network traffic

Domain Name System PPC Network use Windows 2008 servers for DNS Four DNS servers exist in PPC network PPC Lab, MP2, MP3 provide primary and secondary Servers Lab DNS provides secondary for MP2 and MP3 Simulator contains fourth DNS as a read only

Domain Name System ALL PPC Device Nodes use static IP addresses DHCP is disabled DNS Servers are connected on private Vlan or DMZ DNS Servers are located in three area s of the site MP2 computer room, MP3 computer room and PPC Lab Emergency Power is provided to Primary DNS servers

Network Support For Active Directory Servers 4 Severs Provide Active Directory Services Mp2 DC, MP3 DC, Lab DC, and Simulator RODC Active Directory Servers located in separate buildings AD Servers are on vital power supplies Domain Controllers are in private VLAN Active directory services allowed to operations workstations and PPC servers

Network Support For Active Directory Servers Domain Roles are shared between Lab DC and MP3DC Shared Active directory roles Domain naming FSMO Holder (LabDC) RID Operations Master (LabDC) PDC Operations Master (Lab DC) Infrastructure Operations Master (MP3)

Integration Of Firewalls into PPC Network

Integration Of Firewalls into PPC Network Network Isolation and Security provided by two independent Juniper ISG2000 clusters Each Unit, MP2, and MP3, contain 1 cluster Unit clusters manage all discrete unit traffic to Plant Process Computers Unit Clusters provide network route paths (network routers) Clusters also provide Intrusion Detection and Prevention (IDP), for allowed traffic

Integration Of Firewalls into PPC Network Juniper Firewalls provide network security, alert notifications, and IDP protection for network nodes Firewalls allow for future expansion and network changes Firewalls are centrally managed, from secured PPC Lab area All firewall logs are stored on management station Database is centrally managed

Integration Of Firewalls into PPC Network Firewalls contain local copies of all configurations and security policies Firewalls can be managed individually Individual cluster management, can also be done by, command line interface, or Web interface thru secure connections Management station utilizes standalone Linux Server Management station system backups performed backup utility, from backup server

Firewall Fundamental Policy And IPD Practices Each Firewall Cluster contain discrete security policies Allowed traffic is specific Source --- Destination --- Service Connections are initiated from higher security level Allowed traffic is filtered thru firewall IDP blade Administrator sessions require user authentication

Firewall Fundamental Policy And IPD Practices Firewall practices are governed by Dominion cyber security policy System administrators for PPC network are part of Plant Process computer group Firewall administrators require FW training Plant Process Computer personnel require more stringent security checks

Introduction of New Systems Into Plant Process Computers New IP based systems added to redundant core network switches Core switches provide variety of connection types Plant design supports new fiber optic cable installations Plant Process computers support legacy RS232 connections thru IP to serial converters Multimode and single mode optical support thru hybrid cabling

Introduction of New Systems Into Plant Process Computers New cabling now entering remote area s of plant Allows for future distribution of Data Acquisition system components Allows for multiplexing of Network based systems Mp3 added six new IP based systems last outage, now interfaces with over 18 systems MP2 adding several new systems as well, all IP based

Introduction of New Systems Into Plant Process Computers Types of new systems being integrated in MP PPC s Main Transformers Turbine Vibration Monitoring Vital Buss Power Monitors Solar Flare Monitors Variable Frequency Drives (circ water) ISO Buss Cooling Systems RCP Vibration Monitors Chemistry Sample Sink Data