Network Assessment Network Assessment Summary
Total Page:16
File Type:pdf, Size:1020Kb
Network Assessment Network Assessment Summary CONFIDENTIALITY NOTE: The information contained in this report document is for the exclusive use of the client specified above and may contain confidential, privileged and non-disclosable information. If the recipient of this report is not the client or Prepared for: addressee, such recipient is strictly prohibited from reading, photocopying, distributing or otherwise using this report or its contents in any way. SAMPLE Scan Date: 01/01/1959 Prepared by: SAMPLE Network Management Plan NETWORK ASSESSMENT Network Assessment Locations and Contact Information o Fidelis Communications Office #1 o 580 Industry Dr o Tukwila, WA 98188 o 1 (425) 988-2633 o Manager: Fidels o Asst Mgr: Fidelis o Fidelis Communications Office #2 o 580 Industry Dr o Tukwila, WA 98188 o 1 (425) 988-2633 o Manager: Fidels o Asst Mgr: Fidelis o Fidelis Communications Office #3 o 580 Industry Dr o Tukwila, WA 98188 o 1 (425) 988-2633 o Manager: Fidels o Asst Mgr: Fidelis o Fidelis Communications Office #4 o 580 Industry Dr o Tukwila, WA 98188 o 1 (425) 988-2633 o Manager: Fidels o Asst Mgr: Fidelis o Fidelis Communications Office #5 o 580 Industry Dr o Tukwila, WA 98188 o 1 (425) 988-2633 o Manager: Fidels o Asst Mgr: Fidelis PROPRIETARY & CONFIDENTIAL PAGE 2 of 66 Network Management Plan NETWORK ASSESSMENT Focus of Assessment o Define - Definition of the business and user requirements for the network. o Discover - Discovery of devices on the network. A Fidelis Communications engineer will gather high-level/global information on the network. o Analyze - In the analysis phase a comparison of the network design to the business and user requirements is made. The result is a list of deltas. o Recommend – Using issues identified in analyze phase, consultants focus on those that require prompt attention and have a significant impact on the network and the business. The recommendations are influenced by timeliness, ability to manage technology, cost, and future plans. o Pressing Concerns: o Wireless security o User account security o Lack of backup solution o Speed of IT services o Upcoming Projects o Two new locations Main Application Discovery Overview o Critical line-of-business application: Point of Sale (Point of Sale System), MS Office, QuickBooks, DropBox (File Server), Spectrum (Accounting), and ADP (Time Keeping). o Antivirus: AVG Free (Server) and Microsoft Security Essentials (Workstations). o Backups – None identified as active. o Email: Google Apps. Network Discovery Overview o Internet Connectivity . Fidelis Communications #1 - Century Link . Fidelis Communications #2 - Comcast . Fidelis Communications #3 - Comcast . Fidelis Communications #4 / #5 - Comcast PROPRIETARY & CONFIDENTIAL PAGE 3 of 66 Network Management Plan NETWORK ASSESSMENT Network Discovery Overview o Fidelis Communications #1 o NetGear Firewall o Dell PowerConnect 5524 (Data Switch) o Dell PowerConnect 3542 (VoIP Switch) o (2) Cisco Switch / Router o TRENDNet Switch o NetGear Switch o Camera System and DVR o Fidelis Communications #2 o NetGear Firewall o Dell PowerConnect 5524 (Data / Video Switch in Admin Rack) o (2) Linksys 10/100 Switch o Cybera Switch o Linksys TV042 Switch o LinkSys Wireless Router o Direct Connect Box o DMX Pandora Commercial Device o Direct Connect Box o Cisco WiFi AP o WiMax Modem o Fidelis Communications #3 o Comcast Modem o Dell PowerConnect Switch o NetGear Firewall (no active credentials) o Netgear Switch for POS o LinkSys Switch for POS o Fidelis Communications #4 / #5 o Comcast Modem o Dell PowerConnect Switch o Direct Connect Box o DMX Pandora Commercial Device o Cisco WiFi AP o NetGear Firewall (no active credentials) o Point of Sale Systems managed by Ppoint of SALE o Pump Workstations managed by SAMPLE o TripLite UPS (Fidelis Communications #3, Fidelis Communications #4). o Various CAT5, CAT5e, & CAT6 cables with various colors used. PROPRIETARY & CONFIDENTIAL PAGE 4 of 66 Network Management Plan NETWORK ASSESSMENT Hardware & Infrastructure Discovery Overview o Server1: Silicon Mechanics, SBS 2011 (Active Directory Services, DCHP, DNS). o Server2: Silicon Mechanics, Server 2008 R2 (SQL Database, Backup AD, DHCP, DNS). o Workstations: Dell workstations. All workstations running Windows 7 x 64 Pro or Ultimate. o Local Domain fidelis.local. Recommendations Security - Server Critical Issues Approve waiting updates on server for deployment. Set schedule for Windows / 3rd Party Application Updates. Centralized Anti-Virus. Replace current free version (AVG Free) Disable / remove remote access and management software from previous IT service provider. Clean up old user and computer accounts from Active Directory (Multiple users and workstations in Active Directory that have not been on the network for >6 months). Fix Active Directory replication issue (Server2 not replicating) Future Considerations Servers are currently 44 Months old. Plan for replacement. Virtualization of second server (possible). Add all employees to network for tracking purposes. Implement a centralized patch management for Windows and 3rd party applications. Security – Workstations Critical Issues Perform regular security updates on workstations. Add Anti-Virus to workstations currently missing AV. Disable / remove remote access and management software from previous IT service provider. Join all workstations to server domain. 2 workstations currently out of Dell Warranty Support. Future Considerations Replace workstations older than 3-4 years old. Standardize local administrator passwords. Rename workstations to standard naming convention. Performance Critical Issues None Future Considerations Cable management and cleanup. Locking patch cords on critical systems. Color code patch cords for easy identification of systems. PROPRIETARY & CONFIDENTIAL PAGE 5 of 66 Network Management Plan NETWORK ASSESSMENT Network / Infrastructure Critical Issues Replace current NetGear (better web filtering, controlling bandwidth) Add new firewall to each location (Except Yelm Store) Replace 10/100 Switches with 48 Port Gb Switch (Yelm) Create site to site VPN for domain network connectivity Consolidate Admin switches Install UPS for all network equipment Update firmware on router and managed switches Replace all wireless device with business grade device. Future Considerations If install date of current batteries on UPS unknown, replace batteries. Consider restricting access to non-business relates sites (malware, port, etc.) Add Tripp Lite Rack to Yelm Location. Install network rack to organize and protect network equipment. Backup Critical Issues No current backup. Previous backups inactive. Implement backup solutions. Future Considerations None Wireless Critical Issues Update Firmware Future Considerations Standardize SSID / Passwords. Telecommunications – SAMPLE - (Internet Based) Critical Issues None Future Considerations At end of contract consider upgrading phone system. With site to site VPN connection can add business phones to store locations. Other Critical Issues None Future Considerations Implement Office365 Solution. Transition from DropBox to OneDrive or server based file share. Implement 24x7 Managed Services for workstations and servers. PROPRIETARY & CONFIDENTIAL PAGE 6 of 66 Network Management Plan NETWORK ASSESSMENT Fidelis #1 Fidelis #2 PROPRIETARY & CONFIDENTIAL PAGE 7 of 66 Network Management Plan NETWORK ASSESSMENT Fidelis #3 Fidelis #4 and #5 Express Store Lakewood Store PROPRIETARY & CONFIDENTIAL PAGE 8 of 66 Network Management Plan NETWORK ASSESSMENT Risk Report Discovery Tasks The following discovery tasks were performed: Detect Domain Controllers Identifies Domain Controllers and Online status FSMO Role Analysis Enumerates FSMO roles at the site Enumerate Organization Units and Lists the Organizational units and Security Groups with members Security Groups User Analysis List of users in AD, status, and last login/use, which helps identify potential security risks Detect Local Mail Servers Mail server(s) found on the network Detect Time Servers Time server(s) found on the network Discover Network Shares Comprehensive list of Network Shares by Server Detect Major Applications Major apps / versions and count of installations Detailed Domain Controller Event Log List of event log entries from the past 24 hours for the Directory Analysis Service, DNS Server and File Replication Service event logs Web Server Discovery and List of web servers and type Identification Network Discovery for Non-A/D List of Non-Active Directory devices responding to network Devices requests Internet Access and Speed Test Test of internet access and performance SQL Server Analysis List of SQL Servers and associated database(s) Internet Domain Analysis “WHOIS” check for company domain(s) Password Strength Analysis Uses MBSA to identify computers with weak passwords that may pose a security risk Missing Security Updates Uses MBSA to identify computers missing security updates System by System Event Log Analysis Last 5 System and App Event Log errors for servers External Security Vulnerabilities List of Security Holes and Warnings from External Vulnerability Scan Risk Score The Risk Score is a value from 1 to 100, where 100 represents significant risk and potential issues. Several critical issues were identified. Identified issues should be investigated and addressed according to the Management Plan. PROPRIETARY & CONFIDENTIAL PAGE 9 of 66 Network Management Plan NETWORK ASSESSMENT Issues Summary This section contains a summary of issues