Restricted/Limited Access Network project meeting
Monday, April 1, 2013; 3:00 p.m.; AISB-208
Invited
Phil Benchoff, Jacob Dawson, Marc DeBonis, William Dougherty, Brian Jones, Ron Keller, Jeff Kidd, Philip Kobezak, Greg Kroll, Steve Lee, Randy Marchany, Christine Morrison, Rich Sparrow, Lucas Sullivan
Agenda
- Review action items and comments from 20130318 - March 18, 2013 RLAN Project Status Meeting
- Testing is done with Stonesoft and DNS – ITSO has worked out a process for generating a network range list and is ready to implement at the ASAs.
- The SIEM has had no network connectivity for five days now – does anyone have a time estimate for it coming back online?
- Updates on any other RLAN connection requests
- Any further testing on whitelisting/blacklisting and the results
- RLAN FAQ
- RLAN presentation at DCSS
- Open Forum
Attended
Phil Benchoff, Jacob Dawson, Brian Jones, Ron Keller, Philip Kobezak, Greg Kroll, Bryant Sparks, Rich Sparrow, Brad Tilley, Lucas Sullivan
Agenda
- Review action items and comments from 20130318 - March 18, 2013 RLAN Project Status Meeting
- Action item: Phillip will work with Vivian to get the ISB connections approved and test the web application.
- Done. System is called IRON. Restricted access to rlan.iso.vt.edu
- Action item: The ITSO will get the Bursar's office to use their web application to get the ITSO approval and send an order to CNS Ordering & Provisioning (O&P).
- Done. Steve Huff (Bursar's office) connections approved by ITSO.
- An issue discussed is how to get portal information back to the ITSO when an approved user needs a new portal installed (new wiring) as part of the RLAN order?
- The ITSO requested that these Bursar orders be expedited at no extra cost. The CNS ICR states that there can be up to two weeks from the time of order to finished installation.
- CNS requested that the ITSO or Bursar get portal information (as many as possible) back to them ASAP so this can get completed ASAP.
- Action item: Phillip will talk with Steve Huff and get portal information for RLAN connections to CNS.
- To avoid delays in processing the other connections for the Bursar's office the ITSO will try to get them to active connections in groups or batches instead of just one port at a time.
- Action item: Greg will contact Susan to determine the status and if it is finished Greg will send it to Luke so he can run it by the KnowledgeBase team.
- Greg contacted Susan and there was an exchange of emails between all interested parties but we're not sure if this is complete.
- Action item: Greg will find out the status of FAQ document.
- Action item: Details will be worked out between the ITSO and CNS. (Note: domain names for computers on RLAN)
- It was discussed and decided that department network liaison will request domain names from hostmaster. Ron will send IP address info to hostmaster.
- Action item: Phillip will work with Vivian to get the ISB connections approved and test the web application.
- Testing is done with Stonesoft and DNS – ITSO has worked out a process for generating a network range list and is ready to implement at the ASAs.
- ITSO has determined that host based whitelisting does not work, it does, however, work for blacklisting.
- ITSO has a script they run to generate a network range list for *. hosts
- Departments can further restrict their own users with their own lists
- Procedure for requests is as follows:
- User requests host to be added.
- Host is approved by Department Head.
- Host is approved by ITSO.
- ITSO script is run to generate IP address list.
- ITSO sends list to CNS to update ASA's.
- Request goes into the CNS change management system.
- One caveat: for this RLAN pilot there may be need for some "emergency" additions.
- As an example the Bursar's initial list of 30 domains generated 200 IP address ranges. However, it is hoped that this initial list may cover the needs of several other departments in the pilot.
- The SIEM has had no network connectivity for five days now – does anyone have a time estimate for it coming back online?
- Ron mentioned that this may be a problem with some new equipment that belongs to Marc DeBonis. Ron hopes to have this fixed tomorrow.
- Updates on any other RLAN connection requests
- We are working with the Bursar's office to get their configuration established.
- Any further testing on whitelisting/blacklisting and the results
- Phillip was told that CNS could handle IP address ranges. Phillip will send these to Steve Lee and cc: Ron Keller.
- RLAN FAQ
- See 1c above. It was decided that the changes made to date are good enough and this should be published.
- Randy Marchany will become the owner of this document for update purposes.
- RLAN presentation at DCSS
- Rich Sparrow will check with Susan.
- Open Forum
- None