Jump to content

uccert

Members
  • Posts

    12
  • Joined

  • Last visited

Reputation

10 Good

About uccert

Personal Information

  • Biography
    Network consultant with over 20+ years industry experience. Ex-military having served 5 years in the Royal Signals working on a secure mobile battlefield network.

    Here to share industry best practice around Security and Networking.
  • Occupation
    Network Consultant
  • Location
    Wiltshire

Employer (optional)

  • Company Represented
    UCcert limited
  1. uccert

    Vlans

    Good Morning Tony - have I ever worked directly in a school - no. I get it that schools are time and money constrained but you can't call into judgement my knowledge of how schools operate because I've never worked in a school as a direct employee. I work extensively within schools and MAT's as a trusted advisor concerning their networks and have done for over a decade and continue to do so. I take what I've learnt and experienced in a commercial/enterprise world and apply that knowledge within the edu sector.
  2. uccert

    Vlans

    A small price to pay to redesign and repurpose than deal with the consequences of a breach. You've mentioned using pupil machines for training a couple of times now. Wouldn't take much to drop those machines in the relevant VLAN for training purposes then revert back?
  3. uccert

    Vlans

    Good morning. I'm sure I'll get a pasting again here but I'm a big boy. Yes....implement those vlan's but you'll need to implement some form of access control (ACL, DMZ) to stop inter-vlan routing between your Pupil VLAN and others. Is your firewall beefy enough to move your L3 interfaces off your network switches and onto the firewall to give you greater granularity of control between your subnets/VLAN's? There is some great content on the Mitre website which gives a high level view of what steps you can take to improve your posture. https://attack.mitre.org/mitigations/M1030/
  4. For all VoIP/UC&C deployments I would recommend a dedicated data circuit for your SIP trunks and voice traffic. Makes troubleshooting much simpler and keeps your telephony off your data network. Are you using Direct routing with your SIP trunks terminated on an SBC or Microsoft Teams calling plans? Highly recommend Audiocodes SBC's. Compared with a Cisco SBC they're a breeze to configure and troubleshoot with.
  5. uccert

    Vlans

    Good Morning - this was all meant with the best intentions but has clearly gotten a few backs up. I'm not going to try and backtrack and make amends etc. The vast majority of the networks we see day in and day out are quite basically a mess. No documentation, flat networks etc... How can you protect something if you don't know whats on your network. I'm not saying every school is like this, far from it. There are clearly some technically sound people on this board who are up against the kosh in terms of budgets, time etc. We've only gone into a single school in the last 2-3 months where they truly made it difficult for us to get onto their network and I was pleasantly surprised. Have a good day everyone.
  6. uccert

    Vlans

    I disagree with all of this. You need to be segmenting your networks as much as possible. Your staff and pupil devices don’t need to communicate with each other. Your pupil devices don’t need to have access to your SIMs servers. You need to be implementing ACLs on your network to stop an attacker from flowing laterally around your network. You should at least be making it more difficult for them!
  7. uccert

    Vlans

    Seriously! How big is your network? That’s a terrible way to design and manage your network. Your whole network is just one large collision domain. And from a security perspective you have no network segmentation so any pupil can access your staff devices and servers.
×
×
  • Create New...