cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
440
Views
0
Helpful
1
Replies

Network Security

csco10721541
Community Member

Drea all,

I'm a young engineer with less than 6 month experinace.

My boss is on my neck to configure a complete security for a bank with a number of remote sites, on some sites they have Cisco 831,on some 2600,some 1750, some 1760,and the main office 3660 and also iSA server.One of the branches have a radio link to the hd office and others are through internet service providers via stalite.My idea of it is to config IPSEC from the rmote branches to the main office.

Then implement AAA at the rmote branches.

Will this be sufficient and for 6 month exp. am I too slow?

Thanks.

1 Reply 1

ahbanks
Level 3
Level 3

First, we need to define 'complete security'.

The only 100% secure machine is one that is locked in the bank vault, disconnected from the network, and unplugged! 🙂

IPSec tunnels would be a good option for securing bank traffic. Depending on the number of sites, you may want to consider a VPN concentrator; if yo don't have a firewall, I would highly recommend one for each site connected to the internet.

Internet access needs to be closely watched. If internet access is given, a zombied machine can be remotely controlled, and data leaked. A machine can be zombied in many ways, web install, social engineering, etc.

The fact that you're posting this question tells me you're not too slow! However, you may want to consult a partner if this configuration needs to be done rapidly.