What is your network infratructure security ?



Hello,
(first sorry if I make mistakes as I am not fluent ;-)).

I am working for a big company and we would like to secure our network infrastructure (Lan ip addresses etc...).

Here is the situation.
Actually, we can say that we have no network security as our workstations and our servers are in the same LAN (10.10.x.x/16).

We would like to secure this by restructuring our LAN.

I was thinking about doing that :

1. Segment the network by zone (critical, Important, Normal).
2. Each zone will have a specific network address.
3. Each zone will have two sub-zone with two VLANs. The first sub-zone will be for the "presentation servers" (like IIS etc...) and the second sub-zone will protect the datas (SQL Server, specific applications etc...)

Then a user will :
- only be able to connect to the needed zone (he will not have any access to the "critical" zone if not needed).
- only be able to connect to the first sub-zone (IIS) and never to the SQL Server for every zone.

What do you think about this infrastructure ?

Should it be too "heavy" for our network administrators to configure them ?

Do you have others ideas ? :D

Thanks

--
Eric


.



Relevant Pages

  • Re: Is this possable with exchange and no ISP
    ... What I would do is just setup email for the AD domain. ... follow the directions below and instead setup DNS in a new primary zone (and ... Create an MX record for the domain pointing to your Exchange server. ... > dc i create pointers and mx records for the 2 computers on their network. ...
    (microsoft.public.exchange.setup)
  • Re: Vista clients became unresponsive after network move
    ... If the configured reverse lookup zone is empty you have to check the "create ... The computers detected a new network, ... Connection-specific DNS Suffix  . ...
    (microsoft.public.windows.server.networking)
  • Re: Overlapping Reverse Zone Files
    ... So the proposal was the Forest 1 would have a reverse primary zone ... This post is a lot more clear about your actual network than your original ... In fact to make reverse lookups seamless across the enterprize ths would be ... all DNS servers should have: ...
    (microsoft.public.windows.server.dns)
  • Re: .Net security for shared network driver
    ... > network driver, we also installed a security package on each desktop to ... > choose the Zone code group; within in the Zone we made Local Intranet ... If it has any dots, it is assumed to fall in the internet zone. ...
    (microsoft.public.dotnet.languages.csharp)
  • Re: recursive DNS servers DDoS as a growing DDoS problem
    ... (list of trusted peers who can request your zone files) ... allow-query {locals;}; ... This lets anyone on your network, and others you might trust, full ... Copy the bind config fully so you have two copies. ...
    (Bugtraq)

Loading