MOD002703 - Advanced Network Security Principles - Case Study

Download Solution Order New Solution

Assignment Task

Case Study

Callister Inc. is new in Manchester and has opened a branch in Cambridge. The company has designed its network, but the design has several security flaws. They have approached Anglia Ruskin University with a consulting contract where brilliant students in MSc in Cyber Security students will design, implement and document a proper security solution that can accommodate the requirements of the company. This document describes the current state of the network as well as the security requirements of Callister Inc. Finally, it describes the final deliverables for this assignment. Topology and Initial Configuration The company has headquarters in Manchester and a branch in Cambridge. Figure 1 depicts the current topology of the company’s network. The network is structured as follows:

Public Network

This network is outside Callister Inc. management and should not be changed. It has a HTTPS server, accessible through the https://google.com/ URL, a PC representing a teleworker (i.e. belongs to the company but works remotely), a PC representing an outsider to the company, a DNS server that is used by devices belonging to the Public Network, and a DHCP server to provide IP address to devices connected to the Public Network. The ISP router belongs to the Public Network and therefore should not be modified (assume that ISP has been configured properly).

DMZ

This is the demilitarised zone of Callister Inc. and contains all servers that are public to internal and external areas. This is under the management of the company and should be considered within your security design. It contains the company’s web server (https://Callister.com/), an email server and, a DNS server that is used by users of MANCHESTER HQ and CAMBRIDGE BRANCH. The DMZ servers are known externally through their external IP addresses and internally through their internal IP addresses, which means that static NAT has been configured in the DMZ_NAT router to perform this translation. All external devices trying to communicate with the DMZ servers need to use the public (external) IP addresses. 

Manchester HQ

This is the internal network of the Manchester headquarters and is also under the management of the company. The Manchester_NAT router is the one implementing NAT translation, which means that all the devices connected to Manchester_NAT use private IP addresses to communicate internally between them but when connecting to devices on the other side of Manchester_NAT they will use the public IP address assigned by the dynamic NAT translation.

Cambridge Branch

This network has all devices of the Cambridge branch that are under the management of Callister Inc. The Cambridge_NAT router implements NAT translation to allow devices connected to it to communicate with the rest of the devices. All the devices connected to Cambridge_NAT use private IP addresses to communicate internally between them but when connecting to devices on the other side of Cambridge_NAT they will use the public IP address assigned by the dynamic NAT translation.

This MOD002703 - IT Computer Science Assignment Help has been solved by our IT Computer Science Experts at My Uni Paper. Our Assignment Writing Experts are efficient to provide a fresh solution to this question. We are serving more than 10000+ Students in Australia, UK & US by helping them to score HD in their academics. Our Experts are well trained to follow all marking rubrics & referencing style.

Get It Done! Today

Country
Applicable Time Zone is AEST [Sydney, NSW] (GMT+11)
+

Every Assignment. Every Solution. Instantly. Deadline Ahead? Grab Your Sample Now.