Reference no: EM131479885
Assignment: Wireless Design
Background Information for World-Wide Trading Company
World-Wide Trading Company (WWTC) is a large online broker firm in the Hong Kong. The trading company has a staff of 9,000 who are scattered around the globe. Due to aggressive growth in business, they want to establish a regional office in New York City. They leased the entire floor of a building on Wall Street. You were selected as a contractor (your group) to build a state of the art high availability, secure network. The President of the company asked you to set up the state of the art network by end of this year. He shared with you the organizational structure and a list of the 100 employees. The current floor of the new site is solid and gigabit network can be set up on existing network wiring. Also, the existing power supply will meet the client's current and future demand. The President has required these business goals:
Business and Technical Goals
- Increase revenue from 10 billion to 40 billion in three to four years
- Reduce the operating cost from 30 to 15 percent in two to three years by using an automated system for buying and selling.
- Provide secure means of customer purchase and payment over Internet.
- Build a high availability, moderate confidentiality and moderate integrity unclassified network (based on The National Institute of Standards and Technology- NIST)
- Build a classified network with high confidentiality, moderate integrity, and moderate availability (based on NIST)
- Allow employee to attach their notebook computers to the WWTC network and wireless Internet services.
- Provide state of the art VoIP and Data Network
- Provide Active Directory, DNS, and DCHP services
- Provide faster Network services
- Provide fast and secure wireless services in the lobby, conference rooms (100x60), and the cubical areas.
- WWTC Active Directory Design
WWTC office at New York is largely autonomous and few IT personnel to take care of day-to-day IT support activities such as password resets troubleshoot virus problems. You are concerned about sensitive data store in this location. You want to deploy a highly developed OU structure to implement security policies uniformly through GPO automatically at all domains, OU, and workstations.
At this location Windows Server 2012 R2 is required providing the following 10 AD features:
1. Use BitLocker encryption technology for devices (server and Work station) disc space and volume.
2. Enables a BitLocker system on a wired network to automatically unlock the system volume during boot (on capable Windows Server 2012 R2 networks), reducing internal help desk call volumes for lost PINs.
3. Create group policies settings to enforce that either Used Disk Space Only or Full Encryption is used when BitLocker is enabled on a drive.
4. Enable BranchCache in Windows Server 2012 for substantial performance, manageability, scalability, and availability improvements
5. Implement Cache Encryption to store encrypted data by default. This allows you to ensure data security without using drive encryption technologies.
6. Implement Failover cluster services
7. Implement File classification infrastructure feature to provide automatic classification process.
8. IP Address Management (IPAM) is an entirely new feature in Windows Server 2012 that provides highly customizable administrative and monitoring capabilities for the IP address infrastructure on a corporate network.
9. Smart cards and their associated personal identification numbers (PINs) are an increasingly popular, reliable, and cost-effective form of two-factor authentication. With the right controls in place, a user must have the smart card and know the PIN to gain access to network resources.
10. Implement Windows Deployment Services to enables you to remotely deploy Windows operating systems. You can use it to set up new computers by using a network-based installation.
Other AD Deliverables:
• Create Active directory infrastructure to include recommended features
• Create OU level for users and devices in their respective OU
• Create Global, Universal, Local group. Each global group will contain all users in the corresponding department. Membership in the universal group is restrictive and membership can be assigned on the basis of least privileged principle. (For design purpose, you can assume that WTC as a Single Forest with multiple domains).
• Create appropriate GPO and GPO policies and determine where they will be applied.