Presentation is loading. Please wait.

Presentation is loading. Please wait.

Mobile Computing and Security Authenticated Network Access (ANA) Jon Peters Associate Director Dave Packham Manager of Network Engineering NetCom University.

Similar presentations


Presentation on theme: "Mobile Computing and Security Authenticated Network Access (ANA) Jon Peters Associate Director Dave Packham Manager of Network Engineering NetCom University."— Presentation transcript:

1 Mobile Computing and Security Authenticated Network Access (ANA) Jon Peters Associate Director Dave Packham Manager of Network Engineering NetCom University of Utah Copyright David Packham and Jon Peters, 2001. This work is the intellectual property of the author. Permission is granted for this material to be shared for non-commercial, educational purposes, provided that this copyright appears on the reproduced materials and notice is given that the copying is by permission of the author. To disseminate otherwise or to republish requires written permission from the author.

2 University of Utah, located in Salt Lake City Department of Network & Communication Services (NetCom) responsible for campus network backbone, phone service, security, email, help desk, phone operators Hosting the 2002 Winter Olympic opening and closing ceremonies, and the athletes’ residence village Background

3 Purpose of Presentation Authentication through a firewall. Authenticated network access (ANA).

4 Driving Need

5

6

7

8 Design Requirements Security Performance Scaling Cost Global authentication database model Minimum client side configuration Multi-platform support

9 Authentication through a firewall

10 Security Performance Scaling Cost

11 Authenticated Network Access (ANA) Components (2) redundant HSRP router capable of supporting multiple interfaces or virtual sub-interfaces and the ability to associate a user supplied MAC address per each interface. (2) redundant DHCP servers with (2) network interface cards each. (2) redundant LDAP server with (2) network interface cards. (2) redundant WWW/DNS server with (2) network interface cards. (2) redundant VLAN policy server with (2) network interface cards. Fully switched network capable of spanning certain vlans throughout the mobile computing area.

12 ANA

13 ANA Process Initial connection Authentication to network Continuance of lease Link down or release of IP address

14 ANA Client ANA Client connects to ANA controlled Cisco switch ANA Controlled Switch

15 ? To which VLAN should this port belong? ANA Controlled Switch Cisco VPS1100

16 Place port in default VLAN for VTP domain. ANA Controlled Switch Cisco VPS1100

17 ANA Client ANA v3 Client requests and receives a DHCP address

18 ANA Client Client requests authentication page by launching a browser

19 ANA v3 Cisco VPS1100 ANA v3 commands the VPS server to place the switch port into a new VLAN

20 VPS server places the switch port into the VLAN assigned to the port via ANA v3 ANA Controlled Switch Cisco VPS1100

21 ANA Client Client has full access to open network

22 ANA Security – switched, logged, VPN usable Performance - < 30k Scaling – 50,000 S/F/S. +- 5000/day Cost – Log linear Global authentication, NID, LDAP, modular Minimum client side configuration – NONE! Multi-platform support – Linux/PDA/Mac

23 Daily Graphs

24 Long Term Graphs

25 Summary of Activity Average Number of Visits per Day on Weekdays468 Average Number of Hits per Day on Weekdays32,956 Average Number of Visits per Weekend1,009 Average Number of Hits per Weekend49,250 Most Active Day of the WeekWed Least Active Day of the WeekMon Most Active DateOctober 01, 2000 Number of Hits on Most Active Date58,379 Least Active DateSeptember 20, 2000 Number of Hits on Least Active Date5,624 Most Active Hour of the Day18:00-18:59 Least Active Hour of the Day06:00-06:59

26 Current Development Plan Addition of wireless networks and other devices. Addition of remote access users through VPN’s. Bandwidth and usage notifications. Post login licensed software download.

27 Email Address ANA@Utah.EDU Web Server – http://www.netcom.utah.edu/ana Current Development Team Dave Packham Steve Scott Justin Kim Andrew Reich Mindy Sartor Past Team Members John Storm Kyle Mallory Alexander Quilter


Download ppt "Mobile Computing and Security Authenticated Network Access (ANA) Jon Peters Associate Director Dave Packham Manager of Network Engineering NetCom University."

Similar presentations


Ads by Google