How to design a secure network?

Wide Area Network Design Case Study. evaluate the problems of this WAN network?

  • Agency has hired a Network Consultant Group to design their network. As a network consultant you need to design a wide area network for the company. The company’s headquarter is in London. It has two branches in Edinburgh and Cardiff. In the current WAN, the two branches are connected to the headquarters through dedicated 64Kbps data circuits. Voice traffic is carried on separate 64Kbps circuits. The company is expanding. It is going to open a new site in Hong Kong and New York in the next few months. As the network consultant to the company, you have been asked to design a scalable, reliable, cost effective and fault-tolerant WAN infrastructure to replace the existing WAN. The company would like to use VOIP for voice traffic. The company is planning to roll out an ongoing distance-learning program to train new employees. Each site will have a training room with digital videoconferencing systems. The company has contracted ISP1 for internet connectivity with fault tolerance at London location. You need to design a new WAN that supports the new distance-learning program and improves the performance of the existing WAN to support more efficient operation. The new WAN should be able to support some staff to login the enterprise network from home.

  • Answer:

    First things first...using old 64kbps leased lines, that is DS0 back in the day. These days the only WAN technology really being implemented on that scale is MPLS (Multiprotocol Label Switching) and BGP in between. It will be a lot cheaper than leased lines and has the benefit of having excellent QoS (Quality of Service) support for your VOIP traffic. Additionally you may want to investigate VPN concentrators / Citrix for the dial in VPN strategy. Essentially you will have each one of your sites running their own IGP (Interior Gateway Protocol) and a link to an ISP that provides you access to their MPLS service. Between sites/through the cloud you will have BGP handling all of the (hopefully summarised) site to site routes. Additionally you need an internet connection with a VPN concentrator at the edge of each site (or something similar) that terminates home VPN connections. The staff will essentially dial into this using something like a dynamic access list. You can do it quite easily without BGP however over those distances I'd advise using it. Here's a near picture I drew: http://img24.imageshack.us/img24/1585/mplso.jpg

simon at Yahoo! Answers Visit the source

Was this solution helpful to you?

Related Q & A:

Just Added Q & A:

Find solution

For every problem there is a solution! Proved by Solucija.

  • Got an issue and looking for advice?

  • Ask Solucija to search every corner of the Web for help.

  • Get workable solutions and helpful tips in a moment.

Just ask Solucija about an issue you face and immediately get a list of ready solutions, answers and tips from other Internet users. We always provide the most suitable and complete answer to your question at the top, along with a few good alternatives below.