Demonstration and Detailed Status Update : 668845

Question:

 

Answer:

1.   Introduction

Virtucon is chosen by Globex Corporation to design and build a new corporate network for their three sites; Albury, Griffith and Wagga Wagga. Virtucon team begin the first phase of the development which required to produce all relevant documents that will ensure the project succeeds.

Globex Corporation was established in 2013 as a result of merging two companies; Riverina Precision Farming and BT &Sons Farming Equipment. The company has two arms of business represented in each of its sites. Wagga Wagga is the head office for Globex Farming Equipment, Griffith is the head office for Globex Precision Farming, and Albury site coordinates Parts and Services and Administrative support for both Wagga Wagga and Griffith.

The company, through its aims, provides different agricultural solutions to farmers. Most of these solutions are done over the network which means that the network must be stable and with the smallest down time possible. Some of the solutions provided by the company include: Farm equipment fleet positions and alerts, farm equipment fleet health and performance, data file transfer, vehicle to vehicle data exchange, and soil mapping using sensors.

Globex Corporation has many customers, and employees spread out in NSW. In order to accommodate all the users and deliver their services efficiently, the company has to have a reliable network. Having the size of the company in mind, the team members established that the upgrade will not only possess several challenges to the team but also require a lot of time and resources. However, it can be concluded that the upgrade is necessary for the company to operate efficiently.

2.   Project Overview

Globex Corporation hired our Virtucon Pty Ltd team, to design and build a new corporate network for them. The company was needed to upgrade their network since their existing network could no longer support their increasing number of users as well as the size of the company, which affected after the merging of two large regional companies.

Working as a team, we were able to come up with the following documents: Project Proposal, Requirements Specification, Project Charter and Management Plan and also designed the network diagrams for different company office locations. The main aim of having a project charter and management plan is to document and tracks the necessary information which was required by the stakeholders to make decisions for the progression of this project.

Despite being prepared to deal with this task as a team, different challenges swept us off our feet from time to time. Some of the constraints we encountincluded: difficulty meeting deadlines, inadequate knowledge and experience to deal with the subject hence more research had to be done and few group meetings with team members. Every time we encountered a challenge we met, discussed and documented the possible solutions.

The main aim of the project is to upgrade the network structure of Globex Company whose need for a network upgrade was to implement a secure VPN in a full mesh topology and a HTTPS connection over the internet. We aimed to address the need for a reliable network structure by designing and building a new corporate network for Globex’s offices: Griffith, Wagga Wagga and Albury.

One goal of the upgrade was to enable easy and secure access of services to the clients of the company. Additionally, we envisioned that it is necessary to host a cloud server using any of the following AWS, Azure and Google Cloud sevices. Primarily, the cloud server was to be accessed by server 1, in each location, as VPN server and Firewall and by server 2, in each location, as intranet ad VoIP server.

3.   The Network System of Globex

The existing network structure of Globex does not support many users and is more vulnerable to attacks. The data is not secured enough since there are no storage backups mentioned hence data can fall into the wrong hands during transmission. Additionally, attacks can be spread through data that has to be transmitted from one location to another. The fact that each site is independent increases the unavailability of services when one site is down, reduces the ease of communicating and delivering services efficiently.

The system is generally outdated and pose risk to the company’s data integrity, reduces ability to deliver services on time and affects the efficiency of machine equipment fleet monitoring. There is a big probability that hackers can hack the existing network structure because it does not meet the necessary security standards. It will also be hard for the company to recover from disasters that result in data loss since there are back up facilities. Finally, clients might unsubscribe from the company’s services because the company cannot afford to offer quality services with their existing network structure.

4.   Project Prototype

Each location has a network layout designed to meet all the upgrade standards. The network diagram is designed as a prototype for the actual network setting; the prototype diagram will therefore be followed during the actual installation. All IP addresses will be mapped accordingly. Below are the network layout diagrams for different company sites.

4.1. Albury

The network structure of Albury will have the following resources: 30 desktop computers, 2 printers, 4 switches, firewall and two servers. There are two routers configured together so as to keep the network traffic from affecting either of the routers. The routers are assigned default static routes which ensures the routing table is easily maintained in the network. Albury’s network has 8 VLAN’s used by its main departments. VLAN provides a better security and reduce the need of having routers deployed on a network to contain broadcast traffic. A firewall is also implemented to secure the network.

2

 

Figure 1 LAN Diagram for Albury

 

 

4.2. Wagga Wagga

 

The network structure of Wagga Wagga will be made up of 29 computers and two routers, one firewall, 4 switches, 2 printers, 8 VLANs for different departments and two servers. VLAN will be used for each department in order to improve the network management while increasing the consistency. This site uses a static route configuration. A firewall will be implemented so as to prevent unauthorized access to the network.

1

 

Figure 2 LAN Diagram for WaggaWagga

 

 

 

 

4.3. Griffith

 

Griffith’s Network will have 31 computers as seen in the network diagram below. Separate VLANs will be utilized for each department in order to reduce the network’s traffic.

3

Figure 3 LAN Diagram for Griffith

 

 

4.4. Wide Area Network (WAN)

 

Having seen the network structure of each location, we should not forget that Globex need a corporate network therefore all the three locations must be connected together to form one Wide Area Network (WAN). The connection will be achieved by establishing another cloud location where all the three sites will connect to. The WAN diagram is shown below.

 

4

Figure 4 WAN Diagram for Griffith

 

 

 

4.5. Features of the New System

 

Before designing the new system, all the existing problems will first be identified. The new system will fix all the deficiencies from the existing network structure and improve security, speed, communication and availability.

 

Firewall will be used to protect the system from external attacks. Since all locations are interlinked to form one WAN, each site will be configured to support failover; that is, if one location is down, users will still receive services as usual since traffic will be redirected to another location. Cloud storage will also be included in the new system so as to ensure use of portable storage media, that could endanger the network system, is reduced. Additionally, cloud storage acts as a data backup solution, hence use to recover company data after a disaster or system crash. User accounts for both employees and clients will be implemented so as to ensure confidentiality and integrity of data is maintained since data will only be accessible to relevant users.

 

Despite facing many difficulties of implementing this system, our team is prepared to research and meet all the goals that have been set by Globex as well as by the team its self. The team is prepared to meet all changes that may be met as the project progresses. Some of the focus areas that the team will ensure are met include:

 

 

4.6. Reliable Data Backup and Distribution

 

The advantages of having a reliable data backup system is described in Project Management Plan. All companies’ backup their data in order to recover fast when disaster strikes. The company should Purchase a Secured Backup Plan. Globex specifies the cloud system will use AWS, Azure or Google Cloud or a combination of the options provided. Our team will ensure that permissions are granted to relevant departments or users to access relevant data and that data being stored is safe from malware. We will achieve this by setting up firewalls, user accounts and installing updated antivirus protection software to all the computers in the network.

 

Data being sent outside the company’s network, over the internet, will be securely transmitted in encrypted forms to ensure only intended users can open and read it. In most transmissions, Virtual Private Networks (VPNs) will be used to maintain the confidentiality.

 

 

4.7. Reliable Service Delivery

 

Most clients often subscribe to services provided by companies if they are reliable and dependable. This is one of the main goals of upgrading the network system. To ensure that services are available at all times, the team configures the system to support failover. Failover is where users on one server are redirected to another server during failures. Since each site has a server, the team will ensure users are redirected to another site’s server when during failure or when maintenance is being done.

 

 

4.8. Communication

 

Communication is one of the most important aspects in Globex Company. For effective communication, the team will ensure the following are incorporated in the network upgrade:

 

  • VoIP will be used for video conferences which is required for communication between clients and employees and vehicle to vehicle communication.
  • Secured Communication will be achieved by ensuring malware is kept off the system, old or ghost accounts are disabled and all users are trained on security.

 

 

4.9. Management and Updates

 

Upon completion of the Network upgrade, all documents will be submitted to the Company to start the contract termination process. The team is only responsible for upgrades. If the company will wish to have the team manage the new network, then a new contract specifying the job will have to be written.

 

 

5.   Test Plan

 

This document has specified network testing and usability testing for the prototype designed. However, after installing the network, there are more things to be tested in a real setting compared to what was tested in a prototype.

5

Reasons for Assessment of Globex Network

 

  • Ensure that all the requirements, as specified by both the business requirements and user requirements documents, are met.
  • Verify that all the devices are compatible with the software, and are able to connect to the network.
  • Determine additional improvements not set in the contract but crucial for future research.
  • Improve risk and disaster management and recovery.
  • Determine all connectivity issues and create solutions for them.
  • Obtain acceptance from Globex to sign the end of contract service.

 

 

5.1. Network Testing

 

Every aspect of the network that could pose risk to the user or the organization will be tasted and mark as passed or failed. Failed tests items will then be assessed by the team and resolved. The network acceptance items are tabulated in the form below.

 

Test Objective Functionality Pass Fail Checked by;
Network Connectivity ·         The network is set appropriately and all approved networking standards are used.

·         IP addresses are assigned as specified in the IP address table in the Network Design Document.

·         Ping all the devices and domains.

·         Use traceroutes to determine if expected paths are followed by data packets.

·         There is a consistent distribution of names by the DNS.

·         The DHCP conveys out addresses appropriately.

     
Application Connectivity

 

·         VoIP is working and shows all active conferences and saves the conference history.

·         Firewalls and proxies are detecting and restricting suspicious network while allowing appropriate traffic only.

·         All computers are able to connect to the internet and to the cloud storage.

     

 

 

 

5.2. Usability Testing

 

This test is intended to ensure the client or end user of Globex is able to access services they subscribe to. The test considers the ease of use, availability, and security. Some of the test items are tabulated below.

 

Test Objective Functionality Responsible
 

Network Efficiency

 

·         How easy is it for the user to connect to the network?

·         How many users can connect at the same time?

·         Can the user perform all the tasks without help?

 

 

 

Niroshan Senarath

 

Interface Efficiency

 

·         Is the web pages responsive and user friendly?

·         Does the user appreciate the layout?

·         How long does it take to load a page?

·         Does the user relate icons used to correct representations?

 

 

 

 

 

Don Mudalige

 

Accuracy

 

·         Are all the information presented to the user accurate? For example, are the contact information and user manuals updated?

·         Are all the links redirecting to appropriate pages accurately?

 

 

 

 

 

Kusuminda Arangalla

 

Tolerance

·         Can the system withstand attacks and injections from hackers?

·         Can the firewall filter suspicious links?

·         Is the antivirus updated and able to detect malware?

 

 

Niroshan Senarath

Don Mudalige

Kusuminda Arangalla

 

6.   Implementation – summarize description

 

 

This implementation is included 9 servers and three client PCs. The main server is located at Wagga Wagga site. All the servers and client pcs are secured and connected successfully.

 

 

 

Server 1 – globex.com

6

Server 2 – wagga.globex.com

 

Server 3 – Backup server for the Wagga Wagga site

7

Server 4 – Albury.globex.com

 

Server 5 – Backup server for the Albury site

 

Server 6 – Griffith.globex.com

 

Server 7 – Backup server for the Griffith site

 

Server 8 – Main file Server (located at Wagga Wagga site) – File1 and File2 servers are clustered.

8

Server 9 – Backup file server (located at Albury site) – This server is automatically up and running incase of a disaster and main server goes down.

 

Each site is installed with one client pc for the testing purpose. All users for the three sites were created and tested. More client pcs can be installed later.

 

 

In this documentation, we have included the VOIP installation for the GLOBEX.

And also, we have taken few more security measures to secure the servers.

 

 

7.   Windows Server Installation

 

We used VMWare to implement this virtual network.

 

 

7.1. Installing DHCP, Active Directory and DNS Server Roles In main server GLOBEX (globex.com)- This main server is located at Wagga Wagga

 

Open the server manager and Select Add Roles and Features Select Role-based or feature-based installation and click the next button.

 

 

 

Select the server that you want to install the role on and click the next button

9

On the next screen tick, Active Directory Domain Services and DHCP Server& DNS

This will bring up the Active Directory Domain Services Configuration Wizard. You want to select “Add a new forest” and give the domain a name. It is better to use the <domain name>.local or a subdomain of a domain that you control. Then select next.

Next choose the forest function level. If you are just using server 2012 R2 then select that otherwise select the lowest version of Windows Server that you are going to have joined to the domain, give the domain a DSRM password (make sure you document this password) and select next.

Keep clicking next though the wizard. At the end of the configuration wizard you will be signed out and the server will be rebooted. Once the server is rebooted it will be a domain controller.

Log into the server and open DHCP in the start menu.

 

7.1.    Giving Authorization

 

 

 

 

This will open the “New Scope Wizard”, give the scope a name and description and click next.

 

 

Now you will need to set the IP range. To do this enter a start IP and end IP that is on the same subnet as you.

You will want to make sure that these IP addresses are available.

10

 

7.1.    Configuring Time frame

 

 

 

 

 

8.   Installing Active Directory and DNS In Wagga Wagga server

 

Set up a static IP address on the network adapter, to do this:

  • Open the network and sharing centre
  • Click on Change Adapter Settings
  • Right click on the network adapter
  • Select Properties
  • Select Internet Protocol Version 4
  • Click Properties
  • Type in your Static IP address configuration
  • Click OK

 

11

 

 

 

8.1.    Installing Active Directory and DNS

Open the server manager and Select Add Roles and Features Select Role-based or feature-based installation and click the next button.

On the Before You Begin screen select next

Select Role-based or feature-based installation and click the next button.

Select the wagga wagga main server that you want to install the role on and click the next button

 

 

 

 

 

 

On the next screen tick, Active Directory Domain Services and DNS Server.

Note:- DNS server configurations are done in the process of Active Directory configuration.

 

 

 

 

12

 

 

 

 

This will bring up the Active Directory Domain Services Configuration Wizard. Then select “Add a new domain to an existing forest”. Give the parent domain a name as globex.com and new domain name as wagga. Then select next.

 

 

 

 

give the domain a DSRM password

 

13

 

 

Ping main Globex server with Wagga Wagga Server – Successful

 

 

 

 

Ping Wagga Wagga Server with domain “Globex.com” – Successful

 

Ping Globex server with Wagga Wagga server – Successful

 

 

 

 

8.2. Installing Active Directory and DNS in Albury Server

 

14

 

Creating Static IP Address in Alburry Server

  • Open the network and sharing centre
  • Click on Change Adapter Settings
  • Right click on the network adapter
  • Select Properties
  • Select Internet Protocol Version 4
  • Click Properties
  • Type in your Static IP address configuration
  • Click OK

 

 

 

 

 

Following same steps are, we used before, to install Active directory through server manager.

 

 

 

 

16

 

 

 

In domain service configuration choose domain type as ‘Child Domain’

Parent domain name configured as ‘globex.com’ and new domain as ‘Albury’

 

 

 

Ping Albary server with main Globex server (192.168.100.10) – Successful

Ping Albury server with Wagga Wagga server (192.168.100.15) – Successful

 

ping Albury server with domain (globex.com) – Successful

 

17

 

 

9.   Installing Active Directory and DNS In Griffith Server

 

Creating Static IP Address in Griffith Server

 

 

Following same steps as before, install active directory

 

 

 

Active directory installation completed

 

 

In domain service configuration choose domain type as ‘Child Domain’

Parent domain name configured as ‘globex.com’ and new domain as ‘Griffith’

 

 

 

 

 

Ping Griffith server with main Globex server (192.168.100.10) – Successful

Ping Griffith server with main domain (globex.com) – Successful

Ping Griffith server with Wagga Wagga domain (wagga.globex.com) – Successful

Ping Griffith server with Albury domain (Albury.globex.com) – Successful

 

 

17


 

10.         Users

 

10.1.             Wagga Wagga user create

 

User create for Caroline Garcia

 

 

setting up password

user create for Duane Denison

 

 

 

setting up password

 

 

 

19

user summary

 

 

 

 

user create for Jeordie White

 

 

setting up password

user summary

 

 

 

10.2.             All users created for Wagga Wagga site and tested

 

 

20

 

10.3.             Albury user create

 

 

user create for Mark Baker

 

 

setting up password

 

 

User create for Billy Gould

 

 

 

setting up password

 

 

 

 

user summary

 

 

 

 

user create for Aaron Rossi

 

 

 

setting up password

 

 

 

 

user summary

 

 

10.4.             All users created for Albury site and tested

21

 

10.5.             Griffith user create

 

User create for Belinda Bencic

 

 

 

setting up password

 

user create fir Shuai Peng

 

 

 

setting up password

 

 

 

 

user summary

 

 

 

User create for Anders Colsefni

 

 

setting up password

 

 

 

 

user summary

 

10.6.             All users created for Griffith site and tested

 

 

 

 

11.         Security – Host firewall

 

Firewall is a network security system that prevents unauthorized access to or from a network such as intruders, hackers & malicious code. We used inbuilt windows firewall and the security system to prevent unauthorized access and to provide better secured environment.

 

 

 

Steps for the firewall configuration listed below;

1) Open the Server Manager from the task bar.

2) In the right-hand side of the top navigation bar, click Tools and select Windows Firewall with Advanced Security.

 

 

 

 

3) Select the Inbound Rules under Windows Firewall with Advanced Security on the left side of the management console.

4) From the right side of either the Inbound Rules or Outbound Rules tab click New Rule.

5) The new rule wizard launches.

6) Elect Custom from the Rule Type radial button and click next.

7) Select the Program association for the Custom Firewall Rule as either all programs or specify the path to a program and click next.

 

8) From the Protocol type field select the protocol type and click next. Select File and printer sharing on rule type.

 

9) Select allow connection on Action console;

 

10) Rules has been selected

 

 

 

22

 

 

11) File and printer sharing connections are enabled on Group policy management editor.

 

 

12) Creating another inbound rule as a custom rule

 

 

 

 

 

 

 

 

13) Select protocol type as a TCP and the port number should be 80

 

 

14) Elect an IP address association for both local and remote addresses and click next.

 

15) Allow the connection.

 

 

 

 

16) Select which profiles to associate with the custom rule, Domain, Public, or Private, and click next.

 

 

 

17) Provide a name for Firewall rule and click Finish.

 

 

 

18) After the finish creating the rule, it’s automatically enabled.

 

 

 

 

 

 

 

 

 

 

12.         Syslog server

 

Syslog is a way for network devices to send event messages to a logging server this server known as a Syslog server. The Syslog protocol is supported by a wide range of devices and can be used to log different types of events. For example, a router might send messages about users logging on to console sessions, while a web-server might log access-denied events

Resource monitor and performance monitor acted as a Syslog server in Globex network.

Here are the ways to find resource monitor on Windows Server 2012.

 

1) Type Resource Monitor or resource into the Start Menu search box, and enter

Or

 

2) Type resmon.exe into the Start Menu search box and press enter

Or

 

 

 

3) Go to “All Programs -> Accessories -> System Tools -> Resource Monitor”.

 

 

 

Here is the way to find resource monitor on Windows Server 2012.

 

1) Type Performance Monitor into the Start Menu search box, and enter

 

 

Performance monitor

 

 

 

 

 

 

13.         SNMP Server

 

Simple Network Management Protocol (SNMP) is an Internet-standard protocol for collecting and organizing information about managed devices on IP networks and for modifying that information to change device behaviour.

Steps of Installation SNMP Installation listed below

1) From the Control Panel, in the “Programs” heading, choose “Turn Windows features on or off”.

2) Select the “Role-based or feature-based installation” and choose next.

3) Choose “Select a server from the server pool” and in the Server Pool area, select the server you wish to install SNMP on.  Click next.

4) Click next on the “Select server roles” page.

5) In the “Select features” page, scroll down to “SNMP Service” in the Features box and check the box to the left.  Click next.

 

 

 

 

6) Click Install on the confirmation page.

7) When the install completes, you can go in to Services and configure SNMP.

8) Go to Control Panel > “Turn Windows features on or off”

9) Click next until you get back to the “Select features” page.

10) Scroll down to and expand “Remote Server Administrator Tools”

11) Expand “Feature Administration Tools”

12) Select “SNMP Tools” and click next.

13) Click Install on the confirmation page

14) Make the SNMP Trap Service manual Start

14.         Intranet

 

14.1.             Albury server IIS installation

 

A web server is a system that allows computers of a network to access the resources using a web browser or using web-formatted addresses.

Step one: Install the Web Server (IIS) role

Open the Server Manager and click Add Roles and Features:

 

 

 

 

 

 

 

 

 

 

 

 

Select the server roles tab;

 

 

Select the Role-based or feature –based installation

Select a server form the server pool

 

 

Select Web Server (IIS)

Click next on feature tab

 

 

Leave the default configuration on this window and click next;

 

Click on install button

 

 

Installation complete

Go back to the Server Manager.

 

Select Internet Information Services (IIS) Manager from the Manage menu

IIS manager page

 

Click Add Website

Specify at least the site name and path. Click Ok:

 

 

 

 

 

 

 

 

 

 

Start a browser. Set the web address (URL) as one of the following:

http://globex.com

 

 

 

 

 

 

 

 

 


 

14.2.             Griffith Server IIS installation

 

A web server is a system that allows computers of a network to access the resources using a web browser or using web-formatted addresses.

Step one: Install the Web Server (IIS) role

Open the Server Manager and click Add Roles and Features:

 

 

 

 

Select the server roles tab;

 

 

Select the Role-based or feature –based installation

 

Select a server form the server pool

 

Select Web Server (IIS)

Click next on feature tab

 

Leave the default configuration on this window and click next; Click on install button

 

Go back to the Server Manager. Select Internet Information Services (IIS) Manager from the Manage menu

Click Add Website

 

 

 

 

Specify at least the site name and path. Click Ok:

 

Start a browser. Set the web address (URL) as one of the following:

http://globex.com

14.3.             Wagga Wagga server IIS installation

 

A web server is a system that allows computers of a network to access the resources using a web browser or using web-formatted addresses.

Step one: Install the Web Server (IIS) role

Open the Server Manager and click Add Roles and Features:

 

 

 

 

 

 

 

 

 

 

 

 

Select the Role-based or feature –based installation

 

Select a server form the server pool

 

 

 

Select Web Server (IIS)

 

Leave the default configuration on this window and click next;

 

Installation complete

 

 

Go back to the Server Manager.

 

Select Internet Information Services (IIS) Manager from the Manage menu

 

 

 

Click Add Website

 

 

Specify at least the site name and path. Click Ok:

 

 

 

 

 

 

 

 

 

 

 

 

 

Start a browser. Set the web address (URL) as one of the following:

http://globex.com

 

 

 

 

 

 

 

 

15.         Disaster recovery (failover clustering)

 

  • We have created two node servers (file1 and file2) as a node along with domain controller(globex.com)
  • We have assigned 192.168.100.35 ip address on file 1servers and 192.168.100.40 ip address on file 2 server

 

 

 

 

  • Join the both node servers with domain server (globex.com)

 

 

 

 

15.1.             Configuring Cluster Shared Volumes and the VM Role

 

 

  • On domain server ,go to server manager select server roles then click on Iscsi target server

 

 

  • Then click install

 

 

  • On iSCSI editor click new iSCSI virtual disk wizard
  • Name the virtual disk wizard as cluster

 

 

  • Select the disk size as 10GB

 

 

 

  • Name the file cluster on target name and access section

 

 

 

  • Select node 1 server(file1.globex.com) on query initiator computer for ID

 

 

 

  • Access disk created successfully

 

 

  • the volume list has been selected

 

 

  • cluster server connected on file 1 node server

 

 

 

 

 

 

 

 

 

 

  • Cluster Shared Volumes, as shown in below

 

 

15.2.             Adding the Failover Clustering Feature

 

  • The first step in creating a two-node Server 2012 failover cluster is to add the Failover Clustering feature using Server Manager. We did the installation on both node servers(file 1 server and file2 server)
  • Select Local Server and scroll down to the ROLES AND FEATURES section
  • From the TASKS drop-down list, select Add Roles and Features
  • Installation on node 1 server

 

 

  • Installation on node 2 server

 

 

 

  • Click Next to go to the Select installation type page
  • On the Select destination server page, select the server
  • On the Select features page, select the failover clustering
  • Click the Add Features button and click next

 

 

 

 

 

 

  • Then click the install button.
  • Validating the Failover Clustering
  • Select the Failover Cluster Manager option on the Tools menu in Server Manager
  • In the management panel, select Validate a Configuration wizard

 

 

 

 

 

  • Select the servers in select servers or cluster section. We have selected globex.com and file2.globex.com

 

 

  • select run all tests in Testing option section

 

 

 

  • Confirmation of settings and validate.

 

15.3.             Configuring Cluster Shared Volumes and the VM Role

 

15.3. Creating a cluster

 

  • Select Create cluster on management panel and name the cluster and IP address

 

 

  • Summary of cluster wizard

 

  • Click the Configure Roles link in the Actions pane to launch the High Availability wizard.
  • Select file server for general use

 

 

 

 

  • Select cluster disk2 in select storage section

 

 

  • Confirmation on the settings IN High availability wizard

 

 

 

 

16.         File Share

 

Creating a shared folder in main server

 

 

 

 

 

Give read and write access to everyone to this shared files.

 

 

 

 

 

Create three more folders for each three sites inside of the “Shared Files”.

 

Everyone got access to files read only. Only within each site members got read and write access.

 

16.1.             Wagga Wagga File Permission

 

 

 

16.2.             Albury File Permission

 

 

 

16.3.             Griffith File Permission

 

 

 

 

Test files from client PC – Files can access successfully.

.

 

 

 

 

 

 

17.         Backups

 

We have schedule daily backups to file1 server and there will be major backups weekly to the file1 server. File1 server is currently located at Wagga Wagga site. These backups are saved in a virtual disk and it can be access by file2 server. File2 server is located at Albury site. In case if disaster happened in Wagga Wagga site and damage the servers, File2 Server will be automatically going up and all the files can be recovered from there.

 

A Windows server backup allows backup and recovering the Operating system, application system, applications and data. It also allows scheduling backups and protecting the entire server or specific volumes. Installation steps are listed below.

 

 

  • Open Server Manager; click Manage and “Add Roles and Features”

 

 

 

  • Click next.

 

 

 

  • Select the server and click next.
  • Select the feature

 

 

  • Select “Windows Server Backup“. Click Next and install

 


 

  • After the installation finish go to the server manager and click windows server backups.

 

 

 

  • Click back up schedule in the right panel

 

 

 

 

  • We have scheduled a backup once a day at 9:00 pm

 

 

  • Select the location for backup

 

 

 

  • Set up the username and password for administration

 

 

 

  • Confirmation summary

 

 


 

18.         VPN

 

VPN known as Virtual private network gateway which clients can connect to an organization’s private network using the Internet.

  • Connect two private networks using a VPN connection using the Internet.
  • A dial-up remote access server, which enables users to connect to a private network using a modem.
  • Network addresses translation (NAT), which enables multiple users to share a single public network address.

 

Installation steps are listed below

  • Click the Server Manager button on the task bar to open the Server Manager

 

  • Click Manage and click Add Roles and Features. The Add Roles and Feature Wizard opens.

 

  • Select Role-based or feature-based installation and then click next.

 

  • Click Select a server from the server pool, Scroll down and select Remote Access

 

  • select Add Features, and then click Next

 

 

  • Install web server

 

 

 

  • Installation process
  • Configure the routing and remote access server

 

 

 

 

  • Select custom configuration

 

 

  • Selecting services on the Custom Configuration page.

 

 

 

 

 

  • Open Server Manager. Click Tools > Routing and Remote Access.

 

 

  • Configure remote access

 

 

 

 

 

  • Enable IPv4 forwarding

 

 

 

 

  • Select user (Brad Hallen) and give Network Access Permission

 

 

  • Enable firewall on routing and remote access

 

 

  • Connect to a workplace on client PC

 

 

  • Choose a connection option

 

 

  • Assign the internet address

 

 

  • Connect to VPN connection

 

 

 

  • Allow the protocols

 

 

 

  • Sign in as Brad Hallen

 

 

 

 

 

19.         VoIP

 

 

VoIP is known as voice over internet protocol. VoIP is a technology allows to making voice calls using a broadband Internet connection.

 

 

 

 

 

 

 

 

 

19.1.             Active Directory Cerificate Service Configuration

 

Click on configure active directory certificate services

 

 

 

 

Select Cerification Authority

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

19.2.             Configure Features

 

 

 

 

 

 

 

20.         VOIP – Office SIP

 

20.1.             Office SIP server

Download the latest release (non beta) software from the OfficeSIP site (http://www.officesip.com )

 

 

 

 

20.1. Office SIP Server installation

 

 

 

 

 

 

 

20.1. Configure office SIP server

 

 

 

 

 

Give domain name for SIP server

 

 

20.1. Create New User

 

 

 

 

Pull-in-user from active directory

 

 

20.2.             Office SIP messenger

20.2. Download SIP messenger

 

 

 

 

20.2. Office SIP messenger installation

 

 

 

 

 

 

20.2. Configure SIP messenger

 

 

 

Login – Successful

 

 

 

 

 

20.2. Login to a client PC and configure ISP messenger

 

 

 

 

Install .Net to install ISP messenger

 

 

 

 

 

 

 

 

20.2. Add Contacts

 

 

Add contacts from the client PC

 

 

 

Both contacts are online

 

 

 

Messenger works successfully – both clients can send and receive messages.

 

 

 

20.3.             Office SIP softphone

 

20.3. Download OfficeSIP softphone from

Use this link for the download  http://www.officesip.com/softphone.html

 

20.3. SIP Softphone installation

 

 

 

 

 

 

 

Install OfficeSIP Softphone in client

 

 

 

 

 

 

 

Connected – Successfully

 

 

 

Office SIP offers multi-user-video conference as well. This feature can be installed if client chosen to have video conference meetings.

 

Download Multi-User-Video Conference client download

MUV client installation

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 


 

21.         Intrusion Detection System (IDS)

 

IDS examine all internet traffic for all sites.IDS alerts administrator to high or critical treats. It logs relevant information to syslog server.

 

We installed Cisco Catalyst 6500 Enhanced 3-Slot Chassis IDS device in each server in Wagga Wagga, Albury and Griffith. The device Costs $2,586.18.

 

Product description about the device on following link.

http://www.cisco.com/c/en/us/products/interfaces-modules/catalyst-6500-series-intrusion-detection-system-idsm-2-services-module/index.html

 

 

 

 

 

 

 

 

 


 

22.         Network firewall

 

 

This device monitoring the network traffic and restrict access from untrusts networks to trusted networks.

We are going to install CISCO (ASA5506-SEC-BUN-K9) ASA 5506 firepower device in each server in Wagga Wagga, Albury and Griffith. The device Costs $1436.

 
Product description about the device please find in following link.

http://www.cisco.com/c/en/us/products/security/firepower-9000-series/index.html

 

 

 

 

 

 

 

23.         Reflection

 

Our project endeavour to provide the best network layout and design for Globex cooperation. After carefully considering the best output that will fully equip our client requirements. In this project, we have carefully strategized and researched the method that we will implement to spread across Globex network to provide the best service.

 

The main aim is to meet the client’s requirements and if the requirements are met, the project will roll across the entire three main sites in Wagga Wagga, Albury & Griffith. The strategy that we create is an advanced network system between three sites with a secured communication lines and file sharing systems. In this system, we implemented a file server, good security system, Backup system, Disaster recovery system, VPN, Intranet and communication method.

 

We have implemented 4 main servers for the globex corporation. To implement this project in virtual environment, all three members done research on the equipment for the PC’s and built a most suitable performing PC for this project.

All members gathered in a one place and we have researched about the VMware and Hyper-V software. After that we decided to do the project using VMware because we have found better tutorials, articles from the Google and YouTube. We installed VM ware on our host PC and start to implement the project. At first step, we installed 4 servers and fully updated using different PCs (We did this because of the previous experience). We chose Windows 2012 R2 for the Servers and windows 8 for the client PCs. Then all of us installed the main server (GLOBEX.com) using VM ware and configured. The next step is creating unique domain name for the project (globex.com). Then we Installed 3 servers separately for Wagga Wagga, Albury and Griffith. Next step was to install addition backup server for each site. Next step was pinging each other after the configurations are done. But in very first time pinging was unsuccessful. Then had to research and find the reasons for the error. We identified and fixed and all servers and client PCs connection successful. Active directory, DHCP and DNS installation to the main server (Globex.com) was success in our first attempt. we followed Windows server 2012 manual and tutorials for this installation.

 

 

Niroshan implement the Wagga Wagga server and did all configurations including installation of DHCP, Active directory and DNS. After connect the Wagga Wagga server with the domain server (globex.com) successfully, Don implement Albury server and install the Active directory, DNS and connect with the domain. Finally Kusuminda installed the Griffith server and install the Active directory, DNS and connect with the Globex domain.

 

Niroshan installed the Client pc and connected with the Wagga Wagga server and setup the internet successfully. Sam and Kusuminda did the same with Albury and Griffith servers. We have created two node servers (file1 and file2) as file backup system and a disaster recovery system. Kusuminda installed file 1 server and Don install file 2 servers. Niroshan done all the configuration including clustering setup between two file servers. We all work together on implementing file server, disaster recovery system, security system and the VoIP.

 

 

On the initial project phase client requirements, have been established and there are few categories we need to meet;

 

23.1.             Effective Communication

Strategy

  • Provide secured communication
  • VoIP for conference and meetings that required face to face interaction
  • Speed dial services for fast and efficient in store and other branch product check

 

 

 

23.2.             Secured & Centralized Data Distribution

 

Strategy

 

  • Firewall Will be present we will be using Cisco IOS firewall and in built windows firewall for the servers and the client PCs.
  • Security through VPN works by utilizing the shared network system while keeping the confidentiality of data through security systems and tunnelling protocol

 

23.3.             Back Up, Management and Updates

 

Back Up – We will be using separate server to do the backups. There will be small backups daily and major backups weekly. All staff encourage to save a backup copy of their files to the server shared folder in each site to avoid any data lost.

 

 

23.4.             Disaster recovery

 

We have clustered servers. If one server goes down other on will be automatically up and running. Staff will be able to work as usual without any interruptions.

 

 

 

23.5.             Strength and weaknesses

 

When we working on this project we all identify some Strength and weaknesses.

 

23.5. Strength

 

  • Good communication within the group

At the beginning of the project we had a clear communication about goal, task responsibilities feedback expectation there for we were able to finished tasks on time effectively.

 

  • Team building skills

Team building skills are necessary for every project to get things done on time as well as that help to achieve common goals.

 

 

  • Problem-solving Skills

As a group, we all worked hard and did lot of research to solve every problem we had. Sometimes there have been friendly arguments but we have all agreed and come up with one solution.

 

  • Enthusiasm

Plain and simple, we don’t like leaders who are negative – they bring us down. We want leaders with enthusiasm, with a bounce in their step, with a can-do attitude. We want to believe that we are part of an invigorating journey – we want to feel alive. All three of us worked hard to accomplished this project as real leaders.

 

  • Happiness

No matter how hard we had to work on this project to make it successful, we all                enjoyed every minute of that. When we working together we didn’t even notice       the time goes.

 

23

 

 

23.5. Weaknesses

 

  • Longer process

According to our project, sometimes it takes longer to produce a desired result. Teams typically need to go through a variety of processes, such as start the installation from the beginning using another fresh copy when the current server gives issues.

 

  • Time Management

Time management was the most challenging part for us. It was hard to find common time for all of us. Some members were absent on the group meeting days;             therefore, we were not able to exchange all ideas with every member. Sometimes we had to work through the mid night to complete this project successfully.

 


 

24.         Conclusion

 

Since this project will have a tremendous impact for future projects relating to Globex corporation, it is indeed essential that we address and give importance to what the clients requested us to focus upon. Since this project will be put together from scratch, the challenge is ensuring that the client expectations will be met

Providing an excellent network between three sites including a good security system with intrusion detection, file server, disaster recovery system, backup system, intranet, VoIP and virtual private network. We were able to complete all these tasks by lot of research and the knowledge we got from the lecturer. This project improved our skill knowledge and it helped us to know how to work in a real working environment by making us confident.

 

 

25.         Reference

 

Charles sturt university, . (2016). About Globex. Retrieved 05 January, 2017, from globex.uimagine.edu.au

 

 

Valerio, P. (2015). Peer-To-Peer Cloud Storage Promises Security, Reliability. Retrieved 05 January, 2017, from http://www.networkcomputing.com/cloud-infrastructure/peer-peer-cloud-storage-promises-security-reliability/269238553

 

 

Valdes, R. (2001). How VoIP Works. Retrieved 15 January, 2017, from http://computer.howstuffworks.com/ip-telephony.htm

 

 

Philips, P. (2017). White Paper: An introduction to network testing. Retrieved 15 January, 2017, from http://www.computerweekly.com/feature/White-Paper-An-introduction-to-network-testing

Itsuppliesdirect. (2017). Cisco Catalyst 6500 Enhanced 3-Slot Chassis. Retrieved 20 January, 2017, fromhttps://www.itsuppliesdirect.com.au/Cisco-Catalyst-Enhanced-3-slot-chassi-33741?gclid=Cj0KEQiAtqHEBRCNrdC6rYq9_oYBEiQAejvRl3mDE2gC5kakyH5FDgoarCQMRfeB5vdT8-6xqV1nrmgaAuss8P8HAQ

Melbourneglobal. (2017). Cisco ASA 5506.Retrieved 20 January, 2017, from http://www.melbourneglobal.com.au/cisco-asa5506-sec-bun-k9-asa-5506-with-firepower-servicesand-sec-plus-license/?utm_medium=googleshopping

Australian Phone Company. (2017).VoIP virtual Cloud PBX and SIP Trunking termination for Business. Retrieved 20 January, 2017, from https://www.australianphone.com.au/business

Voicesource. (2006). VOIP / IPPBX Voice Recording. Retrieved 20 January, 2017, fromhttp://www.voicesource.co.za/product_info.php?products_id=452

Youtube. (2013). Windows Server 2012: Creating a Two-Node Cluster. Retrieved 20 January, 2017, fromhttps://www.youtube.com/watch?v=OGIs5M_gqAU

Youtube. (2013). Server 2012 Windows backup and restore. Retrieved 20 January, 2017, fromhttps://www.youtube.com/watch?v=CraR01ya9ds

Youtube. (2013). Installing Active Directory, DNS and DHCP to Create a Windows Server 2012 Domain Controller. Retrieved 20 January, 2017, from https://www.youtube.com/watch?v=0WyBxwJD_c0

Youtube. (2013). How to set up a web server using IIS (Internet Information Services). Retrieved 20 January, 2017, fromhttps://www.youtube.com/watch?v=tNAdv1EPj-I