• Home
  • Southern New Hampshire University
  • Network Defense CYB-310-T5690
  • Network Reconfiguration and Security Strategy

Network Reconfiguration and Security Strategy

7 - 2 Project Three Submission: Restructuring Status Report Joshua Minnick Information Technology Department, Southern New Hampshire University CYB-310 Network Defense Professor Kevin Kenna February 25, 2024 I. Network Reconfiguration Cloud WebServer vm nato EdgeFirewall em0 em1 ServerRouter fo/ o fo/ 1 e2 ServerSwitch el e0 e2 e0 AuthServer vm e0 20 BackboneSwitch e1 QustExpPC2 vm PQ ClistExp PCI vm 8 ·2 e0 CustExpSwitch CoreRouter fo/0 f1/0 fo/ 1 HRSwitch e0 HRPC3 vm e3 e0 e3 CustExpPC3 e4 Vm e0 CustEpl04 e0 Mm e6 le5 CustExpPO6 eo vm e0 vm CustExpPC5 e1 HRPC1 vm e2 HRPC2 vm e0 Network Diagram II. Traffic Flow Configuration ServerRouter#conf Configuring from terminal, memory, or network [terminal]? t Enter configuration commands, one per line. End with CNTL/Z. ServerRouter(config)#interface fastethernet 0/0 ServerRouter(config-if)#ip address 192.168.1.3 255.255.255.0 ServerRouter(config-if)#exit ServerRouter(config)#interface fastethernet 0/1 ServerRouter(config-if)#ip address 192.168.4.1 255.255.255.0 ServerRouter(config-if)#exit ServerRouter(config)#exit ServerRouter# *Mar 1 00: 25 : 38. 083: %SYS-5-CONFIG_I: Configured from console by console ServerRouter# ServerRouter Configuration CoreRouter#conf t Enter configuration commands, one per line. End with CNTL/Z. CoreRouter(config)#interface fastethernet 0/0 CoreRouter(config-if)#ip address 192.168.1.2 255.255.255.0 CoreRouter(config-if)#exit CoreRouter(config)#interface fastethernet 0/1 CoreRouter(config-if)#ip address 192.168.2.1 255.255.255.0 CoreRouter(config-if)#exit CoreRouter(config)#interface fastethernet 1/0 CoreRouter(config-if)#ip address 192.168.3.1 255.255.255.0 CoreRouter(config-if)#exit CoreRouter(config)#exit CoreRouter# *Mar 1 00:26:48.327: %SYS-5-CONFIG_I: Configured from console by console CoreRouter# CoreRouter Configuration Firewall / Rules / WAN The changes have been applied successfully. The firewall rules are now reloading in the background. Monitor the filter reload progress. × Floating WAN LAN Rules (Drag to Change Order) States Protocol Source Port Destination Port Gateway Queue Schedule Description Actions x 0/0B * RFC 1918 networks * * Block private networks x 0/0 B * Reserved Not assigned by IANA . + + Block bogon networks x 0/0 B IPV4 TCP WAN net 1 A 80 (HTTP) nono x 0/0 B IPv4 TCP WAN net + * 443 (HTTPS) + none V 0/0 B IPV4 TCP WAN net * 192.168.4.2 80 (HTTP) * none 0/0B IPv4 TCP WAN net 192.168.4.2 443 (HTTPS) + none 1 Add Delete 1 Add + Separator Save Firewall Rules to Control Traffic for Port 80 (HTTP) and Port 443 (HTTPS) III. Organizational Security Strategy Restructuring the network in this way has greatly improved the security posture of the organization in multiple ways. The segmentation of the network using multiple routers and switches increases the ability to route traffic properly and contain data within each segment, so it is not accessible without proper authorization. The configuration of