Showing posts with label Network. Show all posts
Showing posts with label Network. Show all posts

Wednesday, September 28, 2011

Designing Small Business Computer Network - What Should You Do?

Basically designing small, medium, or enterprise class computer networks are principally similar. You need to design your private network infrastructure to provide the availability and reliability of network resources; network security system to protect your network resources against any types of threats, and secure global communication system. Small business computer network should include these three aspects: the private network; the end-point security system for internet threats protection; and a secure way in providing system communication with global internet.

For example, in your business network you need to provide database application to support your finance management, and an email server to support your business communication, you allow authorized users to connect via internet from homes, or probably you need to link other branch offices via WAN cloud connection. Dig as much information as possible before designing your small business network. The following lists some areas you probably need to implement in your design.

Sonicwall

Software Applications

You need to drill down the requirements each of the main element of your core business needs. For example, you need a database application to support your finance management. What application software to purchase, contact the vendor and ask them to provide a presentation about their product and see if their product can meet your finance need. How critical your application to support your business will be, if you don't accept any downtime - you need to provide redundant servers and configure them as failover / failback system. You can dig more information to meet your business need regarding the finance management.

User Account Management

What about user account management? How do you manage the security of your network resources, who can access or deny certain resources and how they can access them? This will help you to design your logical infrastructure need, for example you need to implement Windows server with Active directory (AD) system which should be integrated with your DNS.

With AD infrastructure, you can create group policies that meet your security needs based on different level of user groups. If you implement a Windows server AD, you need to think about how to manage the patches. How all the computers update the Windows patches and other critical security update, will they download the patches direct from the internet or will you deploy a WSUS patches management system? With WSUS, you can manage all the computers within the network to download the Windows update from your WSUS server, not individually download direct from the internet. This will reduce the latency of your internet bandwidth.

Backup System

What about the backup system? How many data file servers are you going to deploy including the Email system? Will you install a tape drive backup system in each of the server or manage all the backup system centrally using Autoloader backup solution? When your business data grows, you need to implement such Autoloader backup system to centrally manage the backup of all the servers to reduce administration and cost overhead.

Network Security

What about endpoint security protection? When you provide the internet access for your users, how can you manage the security? We know that Internet is where all the bad and good things exist. Internet threats such as hackers and malware are evolved all the time to get smarter to detect and penetrate any vulnerabilities of your network system. How can you manage the internet threats, do you have security experts in taking care of your endpoint security system? Probably you need to implement UTM (unified Threat Management) appliance - an-all-in-one solution for your endpoint security system such as SonicWALL NSA 2400 network security appliance.

Email System

What about Email system? Will you manage your own Email system inside your private network? If so, you need to buy a domain name which represents your organization for example Your-Company. Com. You need to liaise with your ISP to host your domain record in their DNS server using one of your public IP address. You need to manage the firewall to allow the email traffic to flow in and out securely based on security policy of your organization.

Collecting data as much as possible regarding your small business computer network requirements is very essential before you can design the infrastructure to provide the availability and reliability of the network resources securely.

Designing Small Business Computer Network - What Should You Do?

Sunday, September 25, 2011

To configure a Windows NTP Network Time Server

Time synchronization on your computer is very important in modern computer networks, precision and time synchronization in many applications, particularly time-critical transactions. Imagine buying a ticket, only to be told at the airport that the ticket was bought twice because it was later on a computer with a slower clock sold!

Modern computers internal clocks called Real Time Clock chips (RTC) must provide the date and time information. ThisChips in battery, so that even during a power outage, they can get the time to keep, but personal computers are not insured for the perfect watch. Its design is optimized for mass production and low cost, rather than by exact time.

Sonicwall

For many applications this is very appropriate, though often machines need time to communicate with other computers on the network and when computers are not in tune with each other problems arise as the network files are synchronizedor in some environments even fraud!

Microsoft Windows 2000 includes a time synchronization tool in the operating system called Windows Time (W32Time.exe) that are configured as a network server can be used to build. Microsoft and others are strongly advised to configure a time server with a hardware source rather than on the Internet, where there is no authentication.

If you need to configure the Windows Time service to use the internal hardware clock, then first check thatw32time is in the list of system services in the registry to verify:

Click Start, Run and type regedit and click OK.

Click the following registry entry:

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesW32Time

We strongly recommend that you back up the registry can cause serious problems if you edit the registry, the changes to the registry at your own risk.

At the startup configuration for an internal clock, click onthe following subkey:

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesW32TimeParameters

In the right pane of ReliableTimeSource mouse, then click Edit.

Edit in DWORD Value, type 1 in the Value field, then click OK

Close the Registry Editor

To start the Windows Time Service click Start, Run (or alternatively the system prompt).

Type: net stop w32time & & net start w32time

Then press Enter.

To reset the local computers'Time, following on all computers except the time server which must not be synchronized with itself:

w32tm-s

Configured to use the Windows Time service to an external source, click Start, Run and type regedit then click OK.

Locate the following subkey:

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesW32TimeParameters

In the right pane, right-click Type then click Modify, in edit mode value of the type NTP in the Value data box, click OK.

Now, inReliableTimeSource click the right pane, then click Edit.

In the Edit DWORD Value, type 0 and click OK.

Right click NtpServer in the right pane, click Edit.

In Edit Value, type the Domain Name System (DNS), each DNS must be unique.

Now click on OK.

For Windows 2000 Service Pack 4, you must configure the time correction settings to do this are:

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesW32TimeParameters

In the right paneRight on MaxAllowedClockErrInSecs, then change the Edit DWORD Value, type a time in seconds to get the maximum number of seconds between the local clock and the time from NTP servers to new, valuable time.

Click OK.

To find the polling intervals:

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesW32TimeParameters

In the right pane, right-click the period, and then click Edit.

In the Edit DWORD Value, type24 OK

Close the Registry Editor

Click Start, then Run and type the following and press Enter:

Net stop w32time & & net start w32time

To reset the local computer time, the following on all computers except the time server which must not be synchronized with itself:

Network Time Protocol (NTP) is an Internet protocol for the transfer of accurate time using time together and provides information so that you can get a precise time

To enableNetwork Time Protocol, and click NTPServer:

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesW32TimeTimeProvidersNtpServer

In the right pane, click Enabled, and then click Edit.

Edit DWORD Value, type a value below, then click OK.

Now you go back and click on

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesW32TimeParametersNtpServer

Pane, right-click NtpServer, then change the Edit DWORD Value Type DataPane, right-click NtpServer, and then change the Edit DWORD Value data, type the Domain Name System (DNS), each DNS must be unique and 0x1 must be attached to the end of each DNS name otherwise changes are not effective.

Now click on OK.

Locate and click on the following

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesW32TimeTimeProvidersNtpClientSpecialPollInterval

In the right pane of SpecialPollInterval mouse, then click Edit.

In EditDWORD Value, under Value, enter the number of seconds to click for each poll, ie 900 will poll every 15 minutes, and then click OK.

To configure the time correction settings, locate:

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesW32Timeconfig

Pane, right-click MaxPosPhaseCorrection, then change the Edit DWORD Value box, under Base, click Decimal value, enter a time in seconds as 3600 (one hour), then click OK.

Now go back andClick:

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesW32Timeconfig

Pane, right-click MaxNegPhaseCorrection, and then click Edit.

In the Edit DWORD Value box, under Base, click Decimal, under Value data type the time in seconds that you want to survey as 3600 (polls in 1 hour)

Close the Registry Editor

Now restart the Windows Time service, click Start, then Run (or alternatively the system command prompt) and type:

net stop w32time & & net startw32time

And one on each computer, with the exception of the server time:

W32tm / s

And this is your time server should be operated.

To configure a Windows NTP Network Time Server

Secure Computer Network Remote Access Options For Teleworkers

There are numerous benefits to providing members of your organization or business with reliable, secure and feature rich remote access options. The term "teleworker" refers to an alternative worker model that accommodates employees that mostly work from home or are always on the go. Remote access options come in many flavors. Listed below are some of the most common secure remote access solutions in use today.

A virtual private network or VPN connection provides a secure link from a remote location back to the main office. A firewall, multi-purpose router, dedicated VPN appliance or a server operating system that includes VPN support would be installed and configured at the main office location to provide a VPN termination point for remote clients. Internet Protocol Security (IPsec) and Secure Sockets Layer (SSL) are common protocols used by VPN services to provide encryption and security for remote access connectivity over the internet.

Sonicwall

So how do teleworkers connect? In most cases, a VPN connection is initiated through either software residing on the computer or a hardware based client. Operating systems from Microsoft (XP, Vista, and Windows 7) include built-in VPN connectivity support. Cisco, SonicWALL, Netgear, Fortinet and numerous other vendors of VPN products all offer client and clientless (sometimes also referred to as thin client) based VPN connectivity options. Clientless VPN connectivity is usually established through your web browser utilizing a small active x control or java applet in combination with SSL to create a secure connection to the main office. A hardware based VPN client is usually a router that is able to establish a dedicated secure connection back to the home office.

Once a secure remote connection is in place, teleworkers can access whatever resources are explicitly made available. The most common application and resource delivery method is usually through a server or desktop remote terminal session. Remote desktop connectivity provides the "as if you were sitting there in the office" experience. Server based remote session services allow for numerous users to connect to a single server all at the same time. A desktop computer that allows remote sessions is generally one to one.

Secure remote access from home or while on the road can help to foster greater productivity and efficiency. Moving to a virtual office teleworker employee or associate model also has the added benefit of potential cost savings as the need for traditional centralized office space lessens.

Secure Computer Network Remote Access Options For Teleworkers