|
Internet Content Filtering
For a regional Bank, ITS established an Internet connection
and installed a Microsoft Exchange mail server. A Cisco PIX firewall
was installed to protect the internal LAN. A WebSense web "content
filter" was installed on a separate server and was configured to
work with the PIX firewall to block access to non-business web
sites. The WebSense server not only blocks access to offensive
Internet web content, but also provided reports on attempts to
access unauthorized web sites.
Secure Business Partner Connections
ITS designed and implemented a network with multiple security
zones. This particular client had a need to connect to several
different business partners, all of which had stringent security
requirements. ITS Networking Services was able to design the network
so that the business partners could each access the resources they
needed on the client's network (and only those), but could not
access each others' networks.
The solution employed a Cisco Catalyst switch with multiple
defined VLAN's, along with a Cisco PIX firewall with six ethernet
interfaces. The system was designed so that each business partner
had their own "DMZ" network. Firewall rules were established to
control the network traffic between the various VLAN's.
Redundant Firewall Installation
ITS Networking Services recently installed a redundant PIX
firewall configuration for a client that was particularly concerned
about reliability. This client hosts their own mail server and
several web servers, so it was important that the Internet
connection be reliable. The two Cisco PIX firewalls are configured
in failover mode so that if either PIX fails, the other PIX assumes
all firewall duties. The solution also allows us to upgrade firewall
software and/or rules with minimal down time. The client has been
pleased with this solution, which has performed as
advertised.
Network Intrusion Detection
ITS Networking Services was recently engaged by a client to
develop an effective distributed network intrusion detection system
based on open-source software. The goal of this project is to pull
together a set of GNU-licensed solutions, including SNORT, Barnyard,
MYSQL, and ACID, to create a complete network intrusion system. This
project is not yet complete, but we are excited by what we have seen
so far. |