Network security implementation using ASA, IPS, VPN

Assume that you are working as a Network Security Engineer at Finance Solutions Pvt, Ltd at London. You have been asked to implement and test network security of Finance Solutions Company. The network topology of Finance Solutions is given below:

Finance Solutions Network Topology

Your main task is to design and implement network security with direct link to Internet/Wide Area Network (WAN) in a series of Block Tasks. You should be able to design and implement Site-to-Site VPN Tunnel, ASA Firewall and IOS based Intrusion Prevention System (IPS) along with basic device hardenings to secure organisation Local Area Network (LAN) using appropriate network simulation environment. The organisational network enable integration with IPSec VPN that allow strong encryption to ensure confidentiality and integrity. The network and security services can be designed using well known network simulators.

Your work must be presented in the form of a Project Report and be no longer than 3000 words (excl. references, figures, tables and appendices) plus a facing page that includes the executive summary. This should be typed on A4 paper and use a font size Arial 11 single spacing. For completeness, you may if you wish include additional material in an appendix but this will not contribute to the marks.

Portfolio Task(s):

Block A: Network Architecture and Communication [30 marks]

  1. Implement basic device hardening with the following services fully running and functional, DHCP server, DNS Server, Web Server and Sys log Server.
  2. Allocate and distribute the IP addresses to network and end devices according to given design both static configuration and dynamic configuration via DHCP server.
  3. Implement and configure Dynamic Routing using RIPV2 protocol to demonstrate effective routing on WAN network between internal and external site.
  4. Configuring appropriate VLAN trunking for multiple VLAN’S to segment the traffic in separate broadcast domain for security reasons.
  5. Design and implement fully functional Inter-Vlan routing using IEEE 802.1X encapsulation standard to demonstrate connectivity between business sites.

Sample Solution