150 likes | 236 Views
Implementation of Virtual LANs for Virus Containment. Aaron Soto April 11, 2005 In partnership with: New Mexico Tech Information Services Department. Outline. Problem Statement What is a VLAN? How can it help? Proposed Solution Layout Implications Details Future Expansion.
E N D
Implementation of Virtual LANs for Virus Containment Aaron Soto April 11, 2005 In partnership with: New Mexico Tech Information Services Department
Outline • Problem Statement • What is a VLAN? • How can it help? • Proposed Solution • Layout • Implications • Details • Future Expansion
Problem Statement • Universities are prone to viruses • PCs are frequently not running AV software • Staff constantly monitors network traffic • Ports disabled if viruses are detected • Students unable to clean / patch PC • Without Internet, more effort is necessary • Students frequently frustrated
Background: VLANs SWITCH
SWITCH Background: VLANs SWITCH
Proposed Solution • Implement two VLANs: • Default: Quarantined, DHCP • Secure: Safe, Virus-free, Static IP • Automated tools can switch VLANs • Traffic can be redirected/forwarded • Allow sites like Windows Update, SARC, etc. • Redirect other traffic to quarantined server
Current Layout INTERNET IN-BUILDING SWITCH 0 FIREWALL SWITCH 1 SWITCH 2
Proposed Layout: Overview INTERNET IN-BUILDING SWITCH 0 SECURE SWITCH 1 DEFAULT SWITCH 2 QUARANTINESERVER
Proposed Layout: In-Building IN-BUILDING 1 2 3 4 5 6 13 14 15 16 17 18 7 8 9 10 11 12 19 20 21 22 23 24 DEFAULT PACKET SECURE PACKET
Proposed Layout: Backbone INTERNET SECURE FIREWALL DEFAULT QUARANTINESERVER
Proposed Layout: Server FIREWALL • DHCP Server • Apache Web Server • IP Masquerading (ipChains) DEFAULT QUARANTINESERVER
Possible Implications • Firewall • Forward traffic depending on VLAN tag • Quarantine Server • Must be frequently re-evaluated to… • Be kept secure from viruses/worms • Select valid traffic to forward • Is not designed to take full load • Switches • Must have VLAN support
Future Expansion • Automated Port Activation Requests • Allow students to register with ISD online • Integration with Banner? • Automated Virus Detection and Quarantine • Detect virus activity and switch VLANs • In progress • More detailed communications • Specific information / instructions • Would require multiple VLANs • For a later stage
Implementation of Virtual LANs for Virus Containment Questions? Aaron Soto asoto@admin.nmt.edu (505) 835-5945