Restricted/Limited Access Network project meeting
Monday, March 4, 2013; 3:00 p.m.; AISB-208
Invited
Phil Benchoff, Jacob Dawson, Marc DeBonis, William Dougherty, Peter Franchi, Brian Jones, Ron Keller, Jeff Kidd, Dean Kirstein, Philip Kobezak, Greg Kroll, Steve Lee, Randy Marchany, Christine Morrison, Rich Sparrow, Lucas Sullivan
Agenda
- Review action items from 20130218 - February 18, 2013 RLAN Project Status Meeting
- Status Updates
- ITSO web form application
- Vivian web application test?
- Project scope establishes pilot end date of July 1, 2013
- Whitelisting/Blacklisting/Firewalling/Intrusion Detection & Prevention?
- ISB RLAN connections?
- Other status updates?
- ITSO web form application
- Demonstrate TMG system to see how CSDI is doing blacklisting/whitelisting and filtering (Marc)
- Open forum
- RLAN FAQ, Heard from Susan?
Attended
Phil Benchoff, Jacob Dawson, Marc DeBonis, Brian Jones, Philip Kobezak, Greg Kroll, Steve Lee, Randy Marchany, Rich Sparrow, Lucas Sullivan, Brad Tilley
Meeting Notes
- Review action items from 20130218 - February 18, 2013 RLAN Project Status Meeting
- None
- Status Updates
- ITSO web form application
- Being tested. The associated database was "flushed" and so needs to be repopulated.
- CNS Ordering & Provisioning can help test. Contact Bill Blevins to arrange testing by O&P.
- Project scope establishes pilot end date of July 1, 2013
- Note: The pilot end date is July 1, 2013 not August 1, 2013.
- Whitelisting/Blacklisting/Firewalling/Intrusion Detection & Prevention?
- ITSO has run into problems with whitelisting using Stonesoft. Phillip is working with the Stonesoft R&D people. At this point Phillip says he cannot confirm whether this will work with Stonesoft.
- A newer version of "Bond" seems to be working as expected.
- Still giving consideration to running DNS inside the RLAN, which will provide another layer of security.
- There are questions/doubts about whether a whitelist can be maintained.
- ISB RLAN connections?
- These are needed by ITSO to help with testing ASAP.
- A total of 6 connections have been approved by ITSO. As soon as the web application database is repopulated these orders can proceed.
- Other status updates?
- The ITSO is ready for the Bursar's office (Melinda West) to be added to the pilot.
- The Unified Communications project is testing Virtual Private Network (VPN) connections which seem to be working. Something very similar could be used for the RLAN if needed.
- ITSO web form application
- Demonstrate TMG system to see how CSDI is doing blacklisting/whitelisting and filtering (Marc)
- Marc demonstrated Microsoft Forefront - Threat Management Gateway 2010.
- This software was purchased for the CSDI project. There is a per user license cost.
- TMGM.mig-dev.w2k-dev.vt.edu
- A "farm" of these could be set up and users would have to go through it for access to RLAN.
- Randy mentioned that the whitelist and blacklist used by this system should match what the ITSO is using for the RLAN. Marc said he is try to "open it up" to others like the ITSO.
- Open forum
- Tim Rhodes has a few licenses for SPLUNK.
- Action item: Greg will contact Susan Brooker-Gross regarding the status of the RLAN FAQ.
1 Comment
Marc DeBonis
Mar 06, 2013In reference to the TMG demo. Right now TMG fronts all traffic from the CSDI guests. If the go to the Internet, TMG is protecting them. When we have CSDI guests that are routed through the RLAN, both TMG and whatever ITSO/CNS filter will also be in effect. I did not hear Randy's comment about BL/WL having to match between CSDI and others.