| |
ENVIRONMENT
The British American International (BAI) Inc. Washington office
was newly established for web development, e-mail collaboration, and as
a corporate meeting facility for U.S. business. The office supported nine
(9) internal employees and forty-five (45) remote employees, some staff
members were located overseas. The office was not connected directly to
any other corporate site and had Internet connection via a separate ISP. BAI has license for a Windows NT 4.0 domain, Windows 2000 Server,
Windows 2000 Professional, and Exchange 5.5 messaging system.
CHALLENGE
3H Technology (3H) was tasked to design and deploy a Windows network
environment to support BAI's web development, e-mail infrastructure, and
the following supporting functions:
- Set a user account management solution to support both internal and
international users.
- Implement a network address translation (NAT) architecture to support
a secure robust internal IP address scope with minimal public IP addresses.
- Enable DHCP to manage a limited IP address scope while providing
internet connection for remote visitors.
- Deploy DNS and WINS in support of NetBios names resolution.
- Provide a dynamic backup solution of critical systems and databases.
- Configure an advanced anti-virus solution.
SOLUTION
A Windows NT 4.0 domain was installed with two domain controllers
and five Windows 2000 member servers. Windows 2000 Professional was installed
on all desktops and laptops. 3H customization of BAI's network environment
included:
- User account policies were configured to implement the latest security
procedures. Directory access was restricted to user groups that in turn
passed access to accounts. This solution provides a decentralized security
policy outside of any one account and provides the greatest level of
flexibility and accountability.
- A 128-bit security upgrade was applied to all the operating systems
to provide the highest level of security. The 128-bit upgrade was prohibited
outside the United States.
- A Windows 2000 NAT solution was deployed to provide BAI with virtually
unlimited IP addresses with only a few public IP addresses. This solution
enables internet traffic to be routed to the appropriate sub-network,
depending on the IP packets. The NAT architecture restricted both port
and protocol and was configurable to restrict or favor certain IP scopes
and addresses.
- A DHCP scope was configured to provide BAI with both manageability
and accountability of their IP address scope. Coupled with NAT, BAI
was able to maintain an accurate and reliable IP address scope for more
than 100 IP addresses.
- 3H resolved previous DNS record failures. Microsoft WINS service
was installed on the back-end sub-network to manage NetBios name resolution
while DNS was used to manage Internet name resolution. 3H configured
and managed a separate DNS server within the NAT zone to minimize the
effect of internal IP changes on development servers.

- Veritas Backup Exec was deployed to enable BAI to safeguard critical
data. 3H continued to support BAI in managing effective deployment of
Veritas to ensure all critical data was in the backup scheme. 3H developed
maintenance plans within SQL that provided consistency checks and data
transfer checks to ensure the viability of each database.
- Norton Anti-virus software was installed on all servers, workstations,
and laptops to provide BAI with a reliable protective shield from software
viruses. 3H configured Norton with dynamic updates and software pushes
to ensure the latest anti-virus software installation.
|
|