百家乐怎么玩-澳门百家乐官网娱乐城网址_网上百家乐是不是真的_全讯网888 (中国)·官方网站

Admin Firewall Deployment

by Cyril Ha


Background?

Information System Security has been a key concern over the past many years as more and more business processes rely on Information Technology to operate.  Alike many other organizations, the usual first line of defense would be Internet protection with security devices such as a perimeter firewall.  However, this type of protection cannot address the challenges posed to network security for universities.  Security enhancement at universities is even more challenging as security control and academic freedom, at certain extent, conflict with each other, and there are just too many devices connecting to the network with different purposes and usages.

To address these challenges, the Computing Services Centre (CSC) has been implementing internal admin firewalls to better segregate departmental networks and to guard undesirable internal traffic within the campus network.

These internal firewalls are Next Gen?eration Firewalls (NGFWs).  NGFW provides additional protection comparing to the traditional ones which monitors traffic from Open Systems Interconnection (OSI) layer 2 (Data Link Layer) through layer 7 (Application Layer).  Policies can be defined based on user and application, rather than low-level network ports and addressing.  For example, NGFW includes integrated intrusion detection systems (IDS) and intrusion protection systems (IPS) that detect attacks based on traffic patterns, user behaviour, threat signatures, etc.  These functionalities perform deeper inspection and improve packet-content filtering of network traffic up to the application layer. 

 

Current Situation

As shown in figure 1 below, the existing departmental networks are interconnected via the CityU campus Core network.  Traffic can flow freely between the departmental networks; hence, if a workstation has been infected by virus / ransomware, workstations in another department may also get infected.

 Figure 1:  High Level Network Diagram of Current Departmental Network Setup

 

Admin Firewall Deployment Approach

A pair of admin firewalls are deployed to mitigate similar threats and they will act as barriers between each departmental network and the CityU Core network.

Upon completion, firewall policies would be deployed to control the traffic flow amongst departmental networks.  In principle, traffic will be allowed on a need basis, and the firewalls will block all unknown and unregistered inter-departmental traffic.

Diagram below shows the high-level design and the traffic flow after implementing the admin firewalls.

 Figure 2:  High Level Network Diagram with Admin Firewall added

 

Migration Steps

The migration of each departmental network under the Admin Firewall protection will be done in several phases as listed in the table below:

#

Phase

Duration

Description

Objective

1

Traffic re-route

30 minutes

Re-route departmental traffic to pass through the Admin Firewall

Departmental traffic need to go through the Admin Firewall for inspection, classification, control and protection

2

Monitoring

Two weeks after migration

Firewall will monitor but not block the traffic

Learn the traffic pattern as the input to define firewall rulesets

3

Firewall ruleset testing and fine-tuning


At least four weeks after monitoring phase

 

Firewall rulesets will be implemented and allow all traffic by default unless controlled by rulesets

Test and fine-tune the firewall rulesets

4

Protecting

After ruleset testing phase

Firewall will protect the department and deny all traffic by default if the traffic is not allowed by the rulesets

Protect the department with firewall rulesets

 

Implementation Plan

The migration process will be conducted in sequence initially for administrative departments.  The Central IT will be amongst the first to migrate to the firewall protected networks.  After the Central IT migration, Internet of Things (IoT) networks such as the Car Park System and the EV Charger Systems will subsequently be migrated.  Other administrative departments will follow.

 

??

百家乐永利娱乐场开户注册| 什么风水适合做生意| 澳门百家乐怎么玩| 爱婴百家乐官网的玩法技巧和规则| 百家乐筹码套装包邮| 真人百家乐官网澳门娱乐城| 百家乐赢钱打| 定制百家乐官网桌垫| 月亮城百家乐的玩法技巧和规则 | 百家乐官网投注限额| 百家乐代理商博彩e族| 汝阳县| 百家乐赌场筹码| 百家乐官网洗码| 澳门百家乐论坛及玩法| 百家乐官网机器二手| 乐天堂百家乐赌场娱乐网规则| 百家乐官网开户送彩网址| 骰子百家乐的玩法技巧和规则 | 百家乐画哪个路单| 个人百家乐官网策略| 送彩金百家乐的玩法技巧和规则 | 狮威百家乐赌场娱乐网规则| 百家乐官网输钱的原因| 555棋牌游戏| 天天百家乐游戏| 百家乐官网视频麻将游戏| 大发888游戏下载投注| 澳门百家乐奥秘| 百家乐官网常用公式| 百家乐官网磁力录| 大发888官方下载168| 百家乐官网策略介绍| 菠菜百家乐官网娱乐城| 威尼斯人娱乐城存取款| 赌场百家乐玩法介绍| 澳门百家乐官网新濠天地| 崇左市| 太阳城在线娱乐| 百家乐秘诀| 青鹏棋牌游戏下载|