Restricted/Limited Access Network project meeting
Monday, January 13, 2014; 3:00 p.m.; AISB-208
Invited
Phil Benchoff, Jacob Dawson, Marc DeBonis, Brian Jones, Ron Keller, Philip Kobezak, Greg Kroll, Steve Lee, Randy Marchany, Rich Sparrow, Lucas Sullivan, Brad Tilley
Agenda
- Scheduling of test new test ports to be configured
- Scheduling the remainder of the ports from the Pilot groups to be reconfigured
- Discussion of needed procedures for adding additional groups
- Discuss maintenance windows
- Discussion of testing for RLAN to be delivered thru the VOIP phone connection. This may be a good time to discuss since William and Brian will be at the meeting at the same time
- ITSO needs a SPAN of the border RLAN traffic
Attended
Phil Benchoff, Jacob Dawson, Brian Jones, Ron Keller, Philip Kobezak, Greg Kroll, Steve Lee, Randy Marchany, Rich Sparrow, Lucas Sullivan, Brad Tilley
Agenda
- Scheduling of test, new test ports to be configured
- For Student Services users.
- Set ports to just RLAN.
- Ron can make the necessary changes as soon as noon tomorrow (1/14/2014).
- Scheduling the remainder of the ports from the Pilot groups to be reconfigured
- These would probably be done in larger groups of 20 or more users at once.
- Not sure how soon this needs to be done. Rich will contact Ron when needed.
- Discussion of needed procedures for adding additional groups
- Brian and Christine Morrison are working on a completing an MOU for this purpose. Desired in order to formalize adding new groups to RLAN.
- Pricing should already be nailed down. Contact Bill Blevins for pricing.
- Discuss maintenance windows
- What should be advertized/announced to users?
- There was some discussion about the need/desire for separate maintenance announcements from CNS for the network and ITSO for IDS/IPS.
- It was agreed to have one avenue for maintenance announcements and to use the VT-DNET LISTSERV. Action item: The ITSO will send Phil Benchoff a list of employees that can/should post to the VT_DNET LISTSERV.
- Done 14 Jan by PB and RBT
- There is a long-standing, historical maintenance window of 3-7am Tuesdays and Thursday. It was agreed to use this window for RLAN maintenance. Any scheduled maintenance outside this window must be announced.
- CNS and ITSO agreed to coordinate and/or inform each other of any planned RLAN maintenance.
- Discussion of testing for RLAN to be delivered thru the VOIP phone connection. This may be a good time to discuss since William and Brian will be at the meeting at the same time
- This topic deferred until next meeting when William will be attending.
- ITSO needs a SPAN of the border RLAN traffic
- To clarify, this is the RLAN border, between the RLAN and the regular university network.
- The purpose is so the ITSO can detect malware before it gets filtered by RLAN border hardware.
- Ron agreed to let Brad know before this is done so the ITSO knows what is happening when they begin seeing this traffic.
- Use "netrecon" to get switch, port information. If this is not the information Phillip is looking for let Ron know.
- Open forum
- It was suggested that we open outbound RLAN traffic to specific IP address ranges for a department in order to make it easier to restrict them at a later date.
- This is being called the "transition phase" of the RLAN project where we will temporarily open outbound traffic.
- Brad mentioned that most other places use a blacklist on a "blessed" DNS server to stop drive-by infections. We should give serious thought to building a blessed DNS server inside the RLAN and force clients to use it.