پن کیا گیا ٹویٹ

Just completed a project on Securing and Hardening an Enterprise Branch Office Network
1. Introduction
This document presents the design, implementation, and security hardening of an enterprise branch office network. The project simulates a real-world branch deployment using Cisco Packet Tracer and applies layered security principles across switching, routing, and wireless infrastructure. The objective is to ensure secure inter-department connectivity while mitigating insider threats and unauthorized access.
2. Project Objectives
The primary objectives of this project are:
i. To design a scalable and secure branch office network
ii. To implement VLAN-based network segmentation
iii. To enforce Layer 2 security controls on access switches
iv. To secure Layer 3 access and management on the router
v. To deploy a secure wireless infrastructure
vi. To enable secure remote management using SSH version 2
3. Network Topology Overview
The network consists of a single router, two Layer 2 switches, a wireless LAN controller, two lightweight access points, end-user devices, and a centralized server. The design follows a router-on-a-stick model to provide inter-VLAN routing and centralized DHCP services.
A dedicated Management VLAN (VLAN 99) is used for managing network devices, ensuring that management traffic is isolated from user data traffic.
4. Network Devices and Roles
4.1 Router (R1)
i. Acts as the default gateway for all VLANs
ii. Provides inter-VLAN routing
iii. Serves as the DHCP server
iv. Enforces Layer 3 access control using extended ACLs
v. Secured for remote access using SSH version 2
4.2 Switches (S1 & S2)
i. Provide Layer 2 connectivity
ii. Enforce VLAN segmentation
iii. Implement switch hardening and Layer 2 security features
iii. Host management SVIs on VLAN 99
4.3 Wireless Infrastructure
i. The WLC manages wireless access
ii. Lightweight access points provide wireless coverage
iii. Separate VLANs are used for staff and guest wireless users
4.4 Server
i. Acts as a Syslog and TFTP server
ii. Accessible only to authorized VLANs
5. VLAN and IP Addressing Scheme
@akintunero @ireteeh @Agina_Devnet @segoslavia @lanceeihoda
#cybersecurity #Networking #networksecurity #security #cisco


English















