How to set up network

pmark

Senior member
Oct 11, 1999
921
1
81
Hi all,

I'm trying to secure our company's network and I'm not so sure which devices we need. We have 3 groups of computers/servers. Computers from each group should not have access to the other groups computers. I was thinking that I would need to setup VLANs or just use separate subnets for this, but I'm unsure on which one. I also need to provide VPN access separately to each computer group. All of these computers need to be behind a firewall.

From reading the previous posts, it seems like I would need a Juniper SRX100, fortigate 60c, or a Cisco ASA 5505. Is that all that I would need? Would that one device be able to handle the firewall, VLANs, and VPN access? I want something that isn't going to require a lot of upkeep as I'll be the one supporting it (and I don't want to spend too much time maintaining it)

Thanks!
 

drebo

Diamond Member
Feb 24, 2006
7,034
1
81
Hire someone to do it for you. You'll save yourself a hell of a lot of headache.

VLANs themselves will not prevent L3 traffic, particularly if you want all three VLANs to share the same Internet connection. You need to restrict that traffic with ACLs.

An ASA5505 cannot trunk VLANs without the Sec+ license, which prices it far above the competition (you can get around this with a L3 switch, but then you're really above the competition). My recommendation would be the Juniper SRX100B.
 

yinan

Golden Member
Jan 12, 2007
1,801
2
71
Just use one subnet and create a domain and use Windows permissions to separate access.
 

pmark

Senior member
Oct 11, 1999
921
1
81
Just use one subnet and create a domain and use Windows permissions to separate access.

I forgot to mention that one of the servers is a Linux machine so using just Windows permissions won't work.
 

yinan

Golden Member
Jan 12, 2007
1,801
2
71
Linux can integrate with AD/LDAP. But anyways with the LINUX server if you dont integrate it users wont have permissions to access it. Separate networks really seems like overkill for this situation.
 

Tbirdkid

Diamond Member
Apr 16, 2002
3,758
4
81
Not so sure i believe in the single subnet idea. Reason being, whether or not they are running UC in this network, or whatever. I have always seperated printer, phone, and server traffic from standard day to day traffic. Honestly, without doing an assessment on what all you need, we would be winging it. However, I almost always recommend at least a Cisco ASA 5505 for its Vlan management, firewalling, and vpn connectivity. Especially with an outside static ip.

Im with Drebo, hire someone if you dont know how to setup an ASA.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |