The challenge of integrating the networks of 3 University Museums

28
1 The Challenge of Integrating the Networks of Three University Museums Jonathan Moffett : Ashmolean Anjanesh Babu : Ashmolean Sarah Phibbs : OUMNH Haas Ezzet : Pitt Rivers ICTF 2012 5 July 2012

description

How the Ashmolean, Pitt Rivers and University Museums, in cooperation with the Computing Services, implemented a joint Firewall and set up cross-museum wireless access, via a Fortigate 200B cluster, Aerohive Access Points and many Gliffy diagrams

Transcript of The challenge of integrating the networks of 3 University Museums

Page 1: The challenge of integrating the networks of 3 University Museums

1

The Challenge of Integrating the Networks of���

Three University Museums

Jonathan Moffett : Ashmolean

Anjanesh Babu : Ashmolean

Sarah Phibbs : OUMNH

Haas Ezzet : Pitt Rivers

ICTF 2012 5 July 2012

Page 2: The challenge of integrating the networks of 3 University Museums

2

Museum 1: Ashmolean

http://www.ashmolean.org

Page 3: The challenge of integrating the networks of 3 University Museums

3

Museum 2 : Natural History Museum

http://www.oum.ox.ac.uk

Page 4: The challenge of integrating the networks of 3 University Museums

4

Museum 3 : Pitt Rivers Museum

http://www.prm.ox.ac.uk

Page 5: The challenge of integrating the networks of 3 University Museums

5

•  Collections Management

•  Academic Research

•  Displays / Exhibitions

•  Education / Outreach

•  University Teaching

•  Events

•  Collections Online

What we do

Page 6: The challenge of integrating the networks of 3 University Museums

6

Visitors

•  Visitor Numbers : around 2 million

•  Around 3 million virtual visitors

•  Free to visit

•  300 - 400 staff

•  6.5 FTE ICT Staff

Page 7: The challenge of integrating the networks of 3 University Museums

Why Integrate our Networks?

•  Security Considerations

•  Museums Reviews

•  External funding

•  Greater access to collections

Page 8: The challenge of integrating the networks of 3 University Museums

8

in house

Ashmolean Natural History Pitt Rivers

The Museum Networks in 2010

Page 9: The challenge of integrating the networks of 3 University Museums

Challenges

•  Accommodate the variations

•  Resources

•  F unding (ACE / Renaissance )

•  Maintaining operational continuity

Page 10: The challenge of integrating the networks of 3 University Museums

FW 3!FW 2!FW 1!

Solutions: Option 1: Stand alone

Page 11: The challenge of integrating the networks of 3 University Museums

FW 3!FW 2!FW 1!

Solutions: Option 2: mix & match

Page 12: The challenge of integrating the networks of 3 University Museums

FW 3!FW 2!FW 1!

Solutions: Option 3: match & mix

Page 13: The challenge of integrating the networks of 3 University Museums

13

Solutions: Option 4: Working Together

QinQ

QinQ

c o r e

Page 14: The challenge of integrating the networks of 3 University Museums

14

Scale of the problem

The Ashmolean

Natural History Museum

Pitt Rivers

1 mile

Page 15: The challenge of integrating the networks of 3 University Museums

15

OUCS : The Front Door System

OUMNH

PRM

The Ashmolean Site Default VLAN

Other vlans

Site Default VLAN

Other vlans

Ash-Frodo PRM-Frodo

OUM-Frodo

VLAN Aggregator

QinQ

QinQ

QinQ QinQ

802.1Q Trunks

Site VLANS

Page 16: The challenge of integrating the networks of 3 University Museums

16

Firewall Hardware

Core Switch : Cisco 3750-X

FORTIGATE 200B FORTIGATE 200B

FORTIANALYSER 100C

Active Firewall Passive Firewall

Eaton Source Switching Eaton EA 1000VA 2U Eaton EA 1000VA 2U

Mains Power Mains Power

Page 17: The challenge of integrating the networks of 3 University Museums

17

Fortinet: Advantage

VDOM 1 VDOM 2 VDOM 3

One Physical Unit

Page 18: The challenge of integrating the networks of 3 University Museums

18

Fortinet: did we get this right?

2010 2012

Page 19: The challenge of integrating the networks of 3 University Museums

19

Aerohive advantages : wireless

•  Single WPA2 network – multiple vlans

•  Distributed architecture (‘the Hive’)

•  Mesh network

•  Feature rich

•  Cost effective

PPSK

Page 20: The challenge of integrating the networks of 3 University Museums

20

Aerohive: Single SSID: Multiple VLans

Ash – MAC filter

OUM – MAC filter

PRM – MAC filter

ASH – user list

OUM– User list

PRM– User list

PRM VLAN

OUM VLAN

Ash VLAN

WPA2 – PSK SSID

Page 21: The challenge of integrating the networks of 3 University Museums

21

Getting the tingles

• Wireless Network growing

•  Static devices up

•  Reduction in number of attacks

•  Visibility into usage patterns

•  Simplified management

Page 22: The challenge of integrating the networks of 3 University Museums

22

in house

A recap of how we were before ........

Page 23: The challenge of integrating the networks of 3 University Museums

Where we are now: Service Layers

? edge

Page 24: The challenge of integrating the networks of 3 University Museums

24

Reduce the Chatter

DNS

DHCP

0101010100101101010100101010101011

DNS

DHCP 0101010100101111

Core

Page 25: The challenge of integrating the networks of 3 University Museums

25

Push to the Edge <the future>

Push IT Expertise to the edge

Page 26: The challenge of integrating the networks of 3 University Museums

26

User-Savvy Tech

•  Not tech savvy users

•  Simpler tools to get things done - e.g. codiqa, online ‘noCode’ app development

•  This is the future we are anticipating

•  Enablers for change

Page 27: The challenge of integrating the networks of 3 University Museums

27

Eternally grateful to

•  Alistair James (OUCS Network Operations Manager)

•  Pierre Ramsay (OUCS Network Control)

•  Mark Siddle (Network Operations)

•  Stephen Madeley (Network Operations)

•  Christopher Burchell (Network Operations)

•  Entire OUCS Networks team

•  Oxford University IT Support Staff Group

Page 28: The challenge of integrating the networks of 3 University Museums

28

Any Questions ?