Presentation is loading. Please wait.

Presentation is loading. Please wait.

Technology Update TSAG Meeting 10/10/02. Announcements: DNS Cleanup Send periodic ICMP ping probes to all DNS entries (8/26- 9/13) Correlate data obtained.

Similar presentations


Presentation on theme: "Technology Update TSAG Meeting 10/10/02. Announcements: DNS Cleanup Send periodic ICMP ping probes to all DNS entries (8/26- 9/13) Correlate data obtained."— Presentation transcript:

1 Technology Update TSAG Meeting 10/10/02

2 Announcements: DNS Cleanup Send periodic ICMP ping probes to all DNS entries (8/26- 9/13) Correlate data obtained from probes (9/16-9/19) Inform TSAG of DNS names to be deleted (  10/7)  Purge all 501 defunct DNS names (  10/18) Account Cleanup: Collecting information from you.  Number of Accounts: 41,338  Number of Faculty/Staff:~ 3,000  Number of Students:~30,000(~ 8K ???) Experimental IRC chat room established for the Helpdesk.  hostname:irc.csun.edu  chat room:#helpdesk

3 Network Access Control: Purpose:  To limit DDOS attacks launch at and from the campus  To address Copyright Infringement problems  To reduce the amount of SPAM received and generated  Et cerate Some Outcomes:  Large amounts of available bandwidth has been reclaimed  Triage time for potential network problems reduced  A much more stable computing infrastructure Initial Goal:  To deploy a Firewall around the Campus in which only “Internet Servers” are accessible from off-campus. Internet Server: A server that intentionally provides one or more services to individuals off campus

4 A One Year Anniversary Slide Current Problems:  SPAM generated on campus  Denial of Service (DOS) (e.g., port scans)  Copyright Infringement being addressed by… Stop gap approach  Blocking port 25 (SMTP) from open labs  Blocking incoming traffic to Housing (TSAG slide from Oct 11, 2001)

5 Network Access Control: Recent Changes to Inbound Traffic:  Many units have put in requests to apply/refine ACLs fro there areas: Oviatt Library, Education, Sierra Hall, Jerome Richfield, FOB, University Hall, A&R, A&F, …  Example of available bandwidth reclaimed time Application of Subnet Blocking

6 Proposed Edge ACL Changes Block all inbound ports in the range: 513-1024 Block all inbound ports assigned to the following protocols:  hp-3000-telnet: 2564  tl1-*: 3081-3083 (e.g., tl1-telnet)  scpi-*: 5024-5025 (e.g., scpi-telnet)  Pcanywhere: 5631 and 5632 Target date: October 4  11 Next step: Block all inbound connections to non-Internet Servers.

7 Virtual Private Networking Purpose: To provide a seamless, secure, entry point to campus resources. VPN users are not affected by ACLs applied at the Campus/Internet boundary. Preproduction Service Installed: vpn.csun.edu Authenticates using your Campus Account, i.e., it works with the campus directory! Clients available: http://www.csun.edu/helpdesk/vpnhttp://www.csun.edu/helpdesk/vpn

8 What does the VPN do? Encrypted Traffic:


Download ppt "Technology Update TSAG Meeting 10/10/02. Announcements: DNS Cleanup Send periodic ICMP ping probes to all DNS entries (8/26- 9/13) Correlate data obtained."

Similar presentations


Ads by Google