Presentation is loading. Please wait.

Presentation is loading. Please wait.

Royal Palm WAN & LAN Layout and Design

Similar presentations


Presentation on theme: "Royal Palm WAN & LAN Layout and Design"— Presentation transcript:

1 Royal Palm WAN & LAN Layout and Design
Cisco TCS Royal Palm WAN & LAN Layout and Design By Team MANNIMAL

2 Overview/Executive Summary
Our Wide Area Network will use the IGRP routing protocol. The WAN will pass only Novell IPX and TCP/IP traffic. Routers will be programmed to disallow other protocols. Every LAN will have access to the internet and a series of servers will be online to automate all of the district's administrative and curricular functions. Since our WAN will be functional for 7-10 years, LAN throughput is allowed to grow 100 times, WAN core throughput 10 times, and District Internet Connection throughput 10 times. Our WAN allows a minimum of 1 Mbps for each host computer and 100 Mbps to the server hosts. Our LAN is Royal Palm and we will be working it into Shaw Butte as much as possible. There will be data connectivity between all schools. The WAN will be based on a 2-layer hierarchical model. Regional hubs will be established for Shaw Butte, the District Office/Data Center, and Service Center to form a very fast WAN core network. High-end routers will be installed in each WAN core location. The District Office/Data Center will provide a Frame Relay link to the Internet, which will be used for the rest of the WAN. No other connections to the outside are permitted because of security risks. Fiberoptic T1 leased lines will connect the WAN core and the core to the Internet. The whole T1 line will be leased. The IP address for the network will be and 7 bits will be borrowed for subnetting to produce 126 subnets. This leaves around 510 hosts per subnet and meets the 100 times growth requirements. The Subnet mask would be

3 WAN Specs

4 WAN Protocols

5 WAN Router Config Configuring PPP over T1 lines:
Router(config)# int s1 Router(config-if)# encapsulation ppp Router(config-if)# ppp authentication chap Router(config-if)# ppp chap hostname Manimal Router(config-if)# ppp chap password manna Implementing IPX: Router(config)# ipx routing Router(config)# ipx maximum-paths 2 Router(config)# int Ethernet 0.1 Router(config-if)# encapsulation novell-ether Router(config-if)# ipx network Configuring Frame Relay on a Router: Router# enable Router# (password) Router# config t Router(config)# int s0 Router(config-if)# encapsulation frame-relay cisco Router(config-if)# frame-relay lmi-type cisco Router(config-if)# bandwidth 10000 Router(config-if)# frame-relay local-dlci 100 Router(config-if)# keepalive 20 In Service Center: Router(config-router)# network Router(config-router)# network In District Center: Router(config-router)# network Router(config-router)# network In Shaw Butte: Router(config-router)# network Router(config-router)# network Implementing an ACL for Security: Router(config)# access-list 1 deny To Enable IGRP in Royal Palm: Router(config)# router igrp 100 Router(config-router)# network

6 File Servers Location of Domain Name/ Services- Domain Name Services (DNS) and delivery will be implemented in a hierarchical fashion with all services located on the master server at the district office. Each District Hub location will contain a DNS server to support the individual school serviced out of that location. Each school site will also contain a host for DNS and services (local post office) that will maintain a complete directory of all staff personnel and student population for that location. The school host will be the local post office box and will store all messages. The update DNS process will flow from the individual school server to the hub server and to the district server.

7 File Servers cont. Administrative Server Location, Purpose and Availability- Each school location will contain an Administration server which will house the student tracking, attendance, grading, and other administrative functions. Application Server Location, Purpose and Availability- All computer applications will be housed in a central server at each school location. This Server will be running TCP/IP as its OSI layer 3&4 protocols and will be made available to anyone at the school site. Departmental or Workgroup Servers Placement- Any other servers at the school sites will be considered departmental servers and will be placed according to user group access needs. Library Server Location, Purpose and Availability- The Library server will contain an online library for curricular research. The Server will be running TCP/IP as its OSI layer 3&4 protocols and will be made available to anyone at the school site

8 WAN Addressing Scheme Addressing Scheme
The IP addressing scheme for our WAN will utilize static addressing for the administrative networks. However, for curriculum computers, we will use Dynamic Host Configuration Protocol (DHCP) to dynamically assign addresses. This reduces the amount of work the network administrator must do and it also allows addresses that are no longer used to be reused by other network devices. The District Office will administer the IP addresses. The WAN will use Network Address Translation (NAT) and Simple Network Management Protocol (SNMP). The District Office will have total management control over the entire WAN and there will be a regional management host on each regional hub to support each area. The District Office will have all of the super-user passwords for network devices for security reasons. There are 7 Groups of IP addresses that will be used in our network: WAN Core Data Center Router to Site Routers Service Center Router to Site Routers Shaw Butte Router to Site Routers Schools Connected to Service Center Hub Schools Connected to Shaw Butte Hub Schools Connected to District Center Hub

9 WAN Addressing Scheme WAN Core: (Subnet Mask is always 255.255.254.0)
Location Connects to Assigned Port IP Assigned Port ID Wire Address DC S0 SC S DC S1 SC S DC S2 SC S DC S3 SC S DC S4 SB S DC S5 SB S DC S6 SB S DC S7 SB S SC S4 SB S SC S5 SB S SC S6 SB S SC S7 SB S

10 WAN Addressing Scheme Service Center Router to Site Routers: DC = Data Center SC = Service Center (Subnet Mask is always ) SB = Shaw Butte Location Connects to Assigned Port IP Assigned Port ID Wire Address SC S8 SC2 S SC S9 Abe Lincoln S SC S Lookout Mtn. S SC S Moon Mtn. S SC S Blue Sky S SC S Sahuaro S SC S Sunburst S SC S Sweetwater S SC S Tumbleweed S SC S Mtn. Sky S SC S Acacia S SC S Sunset S SC BRI0 Community School BRI0

11 WAN Addressing Scheme Data Center Router to Site Routers:
(Subnet Mask is always ) Location Connects to Assigned Port IP Assigned Port ID Wire Address DC S DC S DC S Cholla S DC S Chaparall S DC S Desert Foot S DC S Ironwood S DC S John Jacobs S DC S Lake View S DC S Washington S DC S Road Run S DC S Mtn. View S DC S Sunny Slope S DC S Desert View S DC S Internet (ISP) ISP provided ISP provided ISP provided

12 WAN Addressing Scheme Shaw Butte Router to Site Routers:
(Subnet Mask is always ) Location Connects to Assigned Port IP Assigned Port ID Wire Address SB S8 SB2 S SB S9 Arroyo S SB S Palo Verde S SB S Orangewood S SB S Ocotillo S SB S Maryland S SB S Manzanita S SB S Cactus Wren S SB S AltaVista S SB S Royal Palm S SB S R.E. Miller S

13 WAN Addressing Scheme Schools Connected to Service Center Hub:
(Subnet Mask is always ) Location Connects to Administration IP (E1) Curriculum IP (E0) SC S SC N/A SC S Sunset / SC S Acacia / SC S Mountain Sky / SC S Tumbleweed / SC S Sweetwater / SC S Sunburst / SC S Sahuaro / SC S Blue Sky / SC S Moon Mountain / SC S Lookout Mtn / SC S Abraham Lincoln / SC BRI Comm. School

14 WAN Addressing Scheme Schools Connected to Shaw Butte Hub:
(Subnet Mask is always ) Location Connects to Administration IP (E1) Curriculum IP (E0) SC S SB / SC S Arroyo / SC S Palo Verde / SC S Orangewood / SC S Ocotillo / SC S Maryland / SC S Manzanita / SC S Cactus Wren / SC S Alta Vista / SC S Royal Palm / SC S R. E. Miller /

15 WAN Addressing Scheme Schools Connected to District Center Hub:
(Subnet Mask is always ) Location Connects to Administration IP (E1) Curriculum IP (E0) SC S DC N/A SC S Cholla / SC S Chaparral / SC S Desert Foothill / SC S Ironwood / SC S John Jacobs / SC S Lake View / SC S Washington / SC S Road Runner / SC S Mountain View / SC S Sunnyslope / SC S Desert View /

16 Security Issues and Concerns
Number of Logical Network Classifications-The network will be divided into three logical network classifications, Administrative, curriculum and external with secured interconnections between them. Services Exposed to the Internet-Internet Connectivity will utilize a double firewall implementation with all Internet-exposed applications residing on a public backbone network. For security reasons, the only services exposed to the internet will be DNS and . WAN Security via Router- By utilizing Access Control Lists (ACLs) on the routers, all traffic from the curriculum LANs will be prohibited on the administration LAN. Exceptions to this ACL can be made on an individual basis. Applications such as and directory services will be allowed to pass freely since they pose no risk. User ID and Password-A user ID and Password Policy will be published and strictly enforced on all computers in the district.

17 Summary LAN Network Specifications: Materials used-
Cat 5 UTP horizontal cabling Fiber backbone cabling Type of Ethernet 100 Base-TX from MDF to each IDF 10 Base-T from IDF to hosts One MDF located within the POP; Nine IDFs located throughout the campus The use of the Dell “Wireless Classroom” has been proposed but has not been monetarily accounted for IGRP and IP have both been implemented Two V-LANs have been set up; one for Students another for Faculty/Administration There are two ACLs and a Firewall to provide added network security

18 Royal Palm School Budget:
LAN Budget Royal Palm School Budget: Number Item Name Each Total 1 Cisco 2500 Router $ $ 2 Cisco Catalyst 2912 Switch $ $10,225.90 9 Cisco Catalyst /100 Switch $ $ 1 Cisco PIX 515 Firewall $ $ 173 TAA Compliant 12 Port 10/100 Hub $ $38,873.42 16 Ellipse 800 USB Free Standing UPS 800VA $ $ 1 72x36x19 Startech Computer Rack $ $ 9 72x30x19 Startech Computer Rack $ $ Total: $75,868.68

19 WAN Budget Number Item Name Each Total
Washington School District WAN Budget: Number Item Name Each Total 1 Cisco 7507 Router $19, $19,395.00 2 Cisco 3600 Router $4, $9,198.00 36 Cisco 2500 Router $ $81,574.20 1 T1 Setup Charge $ $500.00 1 T1 Leased Line Cost (annually) $9, $9,120.00 Total: $119,787.20

20 LAN Logical Diagram

21 LAN Wire Diagram

22 LAN IP Addressing Scheme
IP Addressing Scheme for the Royal Palm School Network IP Address: Subnet Mask: 6 Subnets allowed: 2 used ( , ) and 4 for future expansion ( , , , )

23 LAN Subnet 1: Administration
Network IP Address: Reserved Server IP Addresses: /23 Reserved Switch IP Addresses: /47 Reserved Router IP Addresses: /71 Reserved for Network Admin.: /254 Building 1: to Building 2: to Building 3: to Building 4: to Building 5: to Cafeteria: to Science Building: to Computer Building: to

24 LAN Subnet 2: Students Network IP Address: Reserved Server IP Addresses: /23 Reserved Switch IP Addresses: /47 Reserved Router IP Addresses: /71 Reserved for Network Admin.: /254 Building 1: to Building 2: to Building 3: to Building 4: to Building 5: to Cafeteria: to Science Building: to Computer Building: to This leaves more than ample room for growth for each building and reserved address.

25 LAN ACL Implementation
Router(config)# access-list 169 permit tcp eq=25 Router(config)# access-list 169 permit tcp eq=53 Router(config)# access-list 169 permit tcp eq=80 Router(config)# access-list 169 deny ip Router(config)# access-list 169 permit any any Router(config)# int e1 Router(config-if)# ip access-group 169 in Router(config-if)# exit This ACL allows the students only DNS, , and HTTP access and increases the network’s security.

26 LAN Router Config Routed Protocol: IP Routing Protocol: IGRP
Internal network address: External network address: Autonomous system number: 69 IGRP: (in config t mode at router) Router(config)# hostname Mannimal Mannimal(config)# router igrp 69 Mannimal(config)# network Mannimal(config)# network This sets up IGRP as the router’s routing protocol and names the router Mannimal. IP: Mannimal(config)# int s0 Mannimal(config-if)# ip address Mannimal(config-if)# clockrate 56000 Mannimal(config-if)# exit Mannimal(config)# int e0 Mannimal(config-if)# ip address Mannimal(config)# int e1 Mannimal(config-if)# ip address This sets up IP addressing for the router and router interfaces.

27 LAN to LAN Concerns

28 Internet Connectivity
All of the Internet connectivity supplied will be through the District Office and will be highly controlled and bandwidth will be upgraded as usage dictates. Our connection will have two firewalls to protect theinner public network. ACLs will keep curriculum from administration and will help with the firewalls. Inside the network, DNS, , and other servers will be allowed to transmit freely. Each school will havea partition of the public network to put on the World Wide Web as well.

29 User Policies User ID and Password-A user ID and Password Policy will be published and strictly enforced on all computers in the district. LAN security via Router: All LANs will have an Access Control List (ACL), this creates a firewall from the teacher LAN to the student LAN. The teachers can see onto the students curriculum but the students do not have access to the teacher's.

30 Recommendation/Final Assessment
The preceding proposal provides internetwork connectivity throughout the Royal Palm Middle School, as well as access to the Internet for all classrooms and hosts. While ensuring reliability and manageability, our network is both scalable and adaptable. The network also provides security preventing unauthorized access throughout the entire network. Finally, the network we designed is cost effective and provides for further growth and development.

31 Credits Special Thanks go out to Tony because without him this project could not have been possible Thanks to Big Manna Dawg Theman is STILL Cisco god Jarret, Get Your Own Sock Alex still rules the 100’s club


Download ppt "Royal Palm WAN & LAN Layout and Design"

Similar presentations


Ads by Google