|
We studied the client requirements and suggested
the best possible practices for authentication,
authorization, and remote access, secure Web presence
and firewalls. This involved evaluating various
products within the given cost constraint. Based
on the study, we suggested redundant network security
architecture with no single point of failure.
We added to the client's infrastructure two data
centers with redundant DS3 links to Internet and
different DMZ for the administrative & backend
access to the Web Servers. Technological changes
for security deployment involved PIX firewalls,
screening routers and screening devices at boundary
points.
A redundant Cisco Secure ACS Tacacs+ server was
mooted for user authentication of the outbound
Internet traffic by the PIX firewall. Network
and host based IDS served as detective measures
to monitor and respond on internal network. We
also carried out implementation of SSL and use
of digital certificates on Web servers. We used
Netegrity Siteminder for corporate authentication
/ authorization for Web resources, netscape LDAP
for centralized directory & policy implementations
and IPSec enabled VPN access for all the telecommuters
& agents .
|