150 likes | 237 Vues
This project proposal outlines the implementation of Virtual LANs (VLANs) to enhance virus containment strategies in university networks. The solution involves segregating network traffic into secure and default VLANs, with automated tools for switching between them. The proposed layout includes secure, default, and quarantine server switches to manage traffic redirection efficiently. Possible implications and future expansions are discussed to improve network security and efficiency.
E N D
Implementation of Virtual LANs for Virus Containment Aaron Soto April 11, 2005 In partnership with: New Mexico Tech Information Services Department
Outline • Problem Statement • What is a VLAN? • How can it help? • Proposed Solution • Layout • Implications • Details • Future Expansion
Problem Statement • Universities are prone to viruses • PCs are frequently not running AV software • Staff constantly monitors network traffic • Ports disabled if viruses are detected • Students unable to clean / patch PC • Without Internet, more effort is necessary • Students frequently frustrated
Background: VLANs SWITCH
SWITCH Background: VLANs SWITCH
Proposed Solution • Implement two VLANs: • Default: Quarantined, DHCP • Secure: Safe, Virus-free, Static IP • Automated tools can switch VLANs • Traffic can be redirected/forwarded • Allow sites like Windows Update, SARC, etc. • Redirect other traffic to quarantined server
Current Layout INTERNET IN-BUILDING SWITCH 0 FIREWALL SWITCH 1 SWITCH 2
Proposed Layout: Overview INTERNET IN-BUILDING SWITCH 0 SECURE SWITCH 1 DEFAULT SWITCH 2 QUARANTINESERVER
Proposed Layout: In-Building IN-BUILDING 1 2 3 4 5 6 13 14 15 16 17 18 7 8 9 10 11 12 19 20 21 22 23 24 DEFAULT PACKET SECURE PACKET
Proposed Layout: Backbone INTERNET SECURE FIREWALL DEFAULT QUARANTINESERVER
Proposed Layout: Server FIREWALL • DHCP Server • Apache Web Server • IP Masquerading (ipChains) DEFAULT QUARANTINESERVER
Possible Implications • Firewall • Forward traffic depending on VLAN tag • Quarantine Server • Must be frequently re-evaluated to… • Be kept secure from viruses/worms • Select valid traffic to forward • Is not designed to take full load • Switches • Must have VLAN support
Future Expansion • Automated Port Activation Requests • Allow students to register with ISD online • Integration with Banner? • Automated Virus Detection and Quarantine • Detect virus activity and switch VLANs • In progress • More detailed communications • Specific information / instructions • Would require multiple VLANs • For a later stage
Implementation of Virtual LANs for Virus Containment Questions? Aaron Soto asoto@admin.nmt.edu (505) 835-5945