Skip to content

Latest commit

 

History

2 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

IRONVEIL

Made by Austin BC

IRONVEIL is an enterprise network security architecture project that models a resilient, segmented, multi-floor company network for a workforce of approximately 600 users. The design combines Cisco ASA perimeter security, dual-ISP connectivity, redundant multilayer switching, VLAN segmentation, OSPF routing, HSRP gateway redundancy, DMZ services, centralized DHCP/DNS/RADIUS infrastructure, wireless LAN services, and VoIP.

Disclaimer: This repository documents is a LAB enterprise network design. Configurations are intended for portfolio, design, simulation, and architecture review purposes. Lab passwords and sample addressing must be replaced before any production use.

Table of Contents

Executive Summary

IRONVEIL transforms a campus-style enterprise network into a security-focused reference architecture. The network is divided into operational zones and VLANs, protected by redundant Cisco ASA firewalls, and routed through a resilient core. Department access switches provide wired user access, voice endpoints, wireless access-point connectivity, and blackhole handling for unused ports.

The design emphasizes controlled traffic flow, survivable connectivity, and clear operational ownership. Cisco ASA security levels and ACLs separate inside, DMZ, and outside zones. NAT enables internal and DMZ networks to reach external services. OSPF provides dynamic routing across the simulated enterprise and ISP/cloud edge. HSRP provides first-hop gateway availability for major VLANs. EtherChannel with LACP strengthens the core interconnect, while PortFast and BPDU Guard harden access-layer edge ports.

Enterprise topology overview

Figure 1: Full enterprise topology showing internet/cloud simulation, dual ISP routers, redundant ASA firewalls, core switching, departmental access layers, DMZ/server networks, wireless, and voice services.

Architecture Overview

The architecture is organized into six major layers:

Layer Role Primary Components
Internet and cloud simulation Represents external clients and upstream networks Cloud router, cloud switch, foreign/client PCs
ISP edge Provides dual upstream paths CONVERSE-ISP router, PLDT-ISP router
Security perimeter Enforces zone separation and NAT Cisco ASA 5500-X firewalls
Core/distribution Provides routed campus backbone and gateway redundancy Catalyst 3850 multilayer switches
Access layer Connects departments, APs, phones, and user endpoints Catalyst 2960 access switches
Services Hosts DMZ, inside servers, wireless control, voice, DHCP/DNS/RADIUS DMZ switch, inside server switch, WLC, voice gateway

The design uses a defense-in-depth model: upstream resilience at the WAN edge, firewall segmentation at the perimeter, Layer 3 segmentation in the core, VLAN isolation at access, and controlled remote administration through a management-only ACL model.

Repository Navigation

Path Purpose
docs/architecture-overview.md Expanded architecture narrative and topology breakdown
docs/addressing-and-vlans.md VLANs, subnets, gateway model, and addressing notes
docs/security-architecture.md ASA zones, ACLs, NAT, DMZ, and management-plane security
docs/routing-redundancy.md OSPF, HSRP, EtherChannel, dual ISP, and failover considerations
docs/wireless-voice-services.md WLC, lightweight AP, SSID, and Cisco voice gateway design
docs/implementation-flow.md Practical build order for deploying the lab
docs/testing-validation.md Validation checklist and non-fabricated test guidance
docs/lessons-learned.md Engineering takeaways from the project
docs/future-enhancements.md Professional next-step improvements
configs/ Device configurations split by role
diagrams/ Extracted PDF diagrams and screenshots with descriptive filenames
screenshots/ Reserved for future validation evidence captures
assets/image-inventory.md Inventory of every extracted visual asset
references/source-scope.md Sanitized source scope and assumptions

Key Objectives

  • Build a secure enterprise network for a three-floor company building.
  • Segment departments and services using VLANs and routed interfaces.
  • Protect the perimeter with Cisco ASA inside, outside, and DMZ zones.
  • Support redundant internet access through two ISP paths.
  • Provide high availability through HSRP and redundant core switching.
  • Use OSPF to exchange routes between the enterprise, firewall, ISP, and cloud simulation.
  • Centralize DHCP for enterprise networks through Active Directory DHCP.
  • Support wireless access through a Cisco WLC and lightweight access points.
  • Support IP telephony with a Cisco voice gateway and a dedicated voice VLAN.
  • Harden access ports with PortFast, BPDU Guard, and blackhole VLAN assignment.

Technologies Used

Technology Project Role Why It Matters
Cisco ASA 5500-X Security perimeter Enforces zone-based control between inside, DMZ, and outside networks.
Cisco Catalyst 3850 Core multilayer switching Provides routed SVIs, HSRP gateways, and resilient campus switching.
Cisco Catalyst 2960 Access and service switching Provides departmental endpoint connectivity and server/access VLAN presentation.
VLANs Segmentation Separates management, LAN, WLAN, voice, inside servers, and unused ports.
OSPF Dynamic routing Allows routing changes to propagate across core, firewalls, ISPs, and cloud simulation.
HSRP Gateway redundancy Provides virtual default gateways for VLANs if a core switch fails.
EtherChannel/LACP Link aggregation Bundles core switch interconnects for bandwidth and link resilience.
STP PortFast and BPDU Guard Layer 2 protection Accelerates safe endpoint port startup and protects against rogue switch attachment.
NAT Address translation Allows internal and DMZ networks to communicate externally through firewall interfaces.
ACLs Traffic control Restricts management access and controls permitted ICMP, HTTP, and DNS flows.
Active Directory DHCP Address assignment Centralizes IP leasing for data, wireless, and management/client VLANs.
DNS Name resolution Supports enterprise and service reachability.
RADIUS Authentication services Represents centralized identity support for controlled access services.
Cisco WLC and LAPs Wireless Centralizes SSID and lightweight AP management.
Cisco Voice Gateway VoIP Provides telephony services and DHCP option 150 for IP phones.

Network Topology Summary

The topology begins with simulated global clients connected through an internet/cloud segment. Two ISP routers provide upstream paths into the enterprise edge. The perimeter contains two Cisco ASA firewalls with outside, inside, and DMZ-facing interfaces. Behind the firewalls, two multilayer core switches provide campus routing, VLAN gateways, HSRP redundancy, OSPF participation, and LACP-based inter-switch connectivity. Department access switches connect wired clients, IP phones, wireless AP segments, and unused blackhole ports.

Core switch HSRP and EtherChannel design

Figure 3: Core switch redundancy model showing HSRP gateway roles and LACP/EtherChannel between the multilayer switches.

Department access layer layout

Figure 4: Department access-layer layout showing repeated access-switch patterns for user, wireless, voice, and unused-port segmentation.

VLAN and Subnet Design

VLAN Name Subnet Function
10 MGT 192.168.10.0/24 Management network and authorized remote administration source.
20 LAN 172.16.0.0/16 Primary wired enterprise user network.
50 WLAN 10.20.0.0/16 Wireless client and WLC/LAP-connected network.
70 VoIP 172.30.0.0/16 IP phone and voice gateway services.
90 InsideServers 10.11.11.32/27 Internal server infrastructure, including DHCP and DNS.
199 BlackHole Not routed Shutdown VLAN for unused access-layer ports.

HSRP uses .1 as the virtual gateway pattern for major VLANs. Core switch addressing follows the design note where Core SW2 uses .2 and Core SW1 uses .3 on VLAN SVIs. VLAN 90 uses 10.11.11.33 as the virtual gateway, with individual core switch SVIs assigned from the same inside-server range.

Security Architecture

IRONVEIL uses segmentation and perimeter control as its primary security model:

  • Inside zones connect protected enterprise VLANs and core routing domains.
  • DMZ zone hosts public-facing or semi-public services such as web, email, FTP, app, and NAS-style services.
  • Outside zones connect to ISP and internet/cloud simulation paths.
  • Management access is limited to the management subnet through standard ACL logic on access switch VTY lines.
  • Unused access ports are placed into the blackhole VLAN and administratively shut down.
  • ACLs permit only documented inspection/test services such as ICMP, HTTP, and DNS where configured.
  • NAT translates inside and DMZ networks to firewall outside interfaces.

Firewall zone design

Figure 5: ASA firewall zoning model showing inside NAT domains and outside static/default route paths.

Firewall and DMZ Design

The firewall layer uses Cisco ASA interfaces with clear security levels:

Zone Security Level Purpose
Inside 100 Trusted enterprise-facing connectivity from core switches.
DMZ 70 Controlled server segment for exposed or shared services.
Outside 0 Untrusted ISP-facing connectivity.

The DMZ contains web, email, FTP, application, and NAS/storage services connected through a dedicated DMZ switch. The DMZ subnet in the source design is 10.11.11.0/27, separate from the inside-server subnet used behind the campus core.

DMZ server farm

Figure 6: DMZ/server farm segment with dedicated service hosts connected to the DMZ switch.

NAT rules are defined per source subnet and firewall interface pair. This makes the translation intent explicit: DMZ traffic can translate through outside interfaces, wired LAN traffic can translate through inside-to-outside mappings, and WLAN traffic has separate object definitions for both firewall paths.

Routing and Redundancy Design

OSPF process 35 is used across the design for dynamic route advertisement. The core switches advertise management, LAN, WLAN, inside-server, and transit networks. Firewall and ISP routers advertise the relevant outside and point-to-point networks. Cloud simulation networks are advertised from the internet cloud router.

HSRP is configured between Core SW1 and Core SW2. Core SW1 is active for VLANs 10 and 20, while Core SW2 is active for VLANs 50 and 90. That split distributes gateway responsibility while preserving a virtual default gateway for clients.

Dual ISP routing is represented by two upstream routers:

  • CONVERSE-ISP connects the 105.100.50.0/30 and 105.100.50.4/30 firewall edge networks.
  • PLDT-ISP connects the 197.200.100.0/30 and 197.200.100.4/30 firewall edge networks.

Dual ISP edge routing

Figure 7: Dual ISP edge segment with separate upstream routers and point-to-point transit networks.

Cloud router segment

Figure 8: Cloud/internet router segment representing external reachability through the simulated internet.

Wireless Architecture

The wireless design uses a Cisco Wireless LAN Controller with lightweight APs. Wireless users are separated from the wired LAN through VLAN 50, and the controller must be connected to the VLANs required for LAP management and wireless client traffic. The source design identifies multiple SSID groups: Employees, Guest, Auditors, and Corporates.

The WLC configuration in the lab uses placeholder administrative credentials and shared wireless passwords. Those values are intentionally treated as lab-only and should be replaced with enterprise identity integration, per-SSID policy, and centralized authentication in any real deployment.

WLC and voice services segment

Figure 9: Wireless LAN controller and voice gateway services segment.

VoIP Architecture

Voice endpoints are isolated into VLAN 70. The Cisco voice gateway uses a router subinterface with dot1Q 70, provides DHCP for phones, and supplies option 150 pointing phones to the call-control source address. The lab configuration supports up to 30 phones and 30 directory numbers.

Access switches use switchport voice vlan 70 for IP phone ports rather than treating phones as ordinary data access ports. This preserves the separation between data and voice traffic while keeping endpoint deployment practical at the access layer.

Server Infrastructure

The inside server segment supports DHCP, DNS, RADIUS, and WLC-related services. Active Directory DHCP is responsible for leasing addresses to enterprise departments and non-voice network segments, while the voice gateway handles DHCP for IP phones.

Inside server farm layout

Figure 10: Inside server network containing DHCP, DNS, RADIUS, and associated service nodes.

The server switch is unique because it trunks selected ports and presents access ports for inside-server and WLAN-related infrastructure.

Configuration Highlights

Important configuration areas are split into files under configs/:

  • Core VLANs, routed interfaces, SVIs, HSRP, OSPF, and EtherChannel.
  • ASA interfaces, security levels, static/default routing, OSPF, NAT objects, and ACL bindings.
  • Department access switch baseline with SSH, management ACL, VLANs, data ports, voice ports, AP ports, and blackhole shutdown ports.
  • DMZ switch hardening with PortFast and BPDU Guard.
  • Inside server switch trunk/access layout.
  • ISP and cloud router OSPF configurations.
  • Voice gateway subinterface, DHCP pool, and telephony-service configuration.

Example HSRP pattern:

interface Vlan20
 ip address 172.16.0.3 255.255.0.0
 ip helper-address 10.11.11.36
 standby 20 ip 172.16.0.1

Example firewall NAT pattern:

object network INSIDE1-OUTSIDE1
 subnet 172.16.0.0 255.255.0.0
 nat (INSIDE1,OUTSIDE1) dynamic interface
Core and firewall configuration entry points

Testing and Validation

The source document states that reliability, performance, and security were tested, but it does not provide detailed test logs or packet captures. This repository therefore documents a validation plan rather than inventing results.

Recommended validation areas:

Area Validation Method
VLAN segmentation Confirm endpoints receive expected subnet addressing and cannot access unauthorized VLANs.
HSRP Shut down an active SVI/core path and verify default gateway continuity.
OSPF Confirm neighbor formation and route propagation across core, firewall, ISP, and cloud routers.
NAT Verify inside and DMZ networks translate through expected ASA outside interfaces.
ACLs Confirm management access is accepted only from VLAN 10 and denied elsewhere.
DMZ Verify only intended services are reachable through firewall policy.
Wireless Confirm WLC-managed AP association and SSID-to-VLAN behavior.
VoIP Confirm phone DHCP, option 150 delivery, and directory number assignment.

Lessons Learned

  • Redundant connectivity is most useful when routing, gateway design, and interface addressing are documented together.
  • Security zones should be named consistently because NAT and ACL logic depend on exact interface mappings.
  • Voice networks need their own access-layer treatment; switchport voice vlan is cleaner than mixing phone traffic into ordinary access VLAN logic.
  • DHCP relay should be planned early so every routed VLAN has a clear path to the correct DHCP authority.
  • Blackhole VLANs and shutdown ports are simple but important controls for unused edge interfaces.
  • A professional network design is easier to operate when diagrams, configs, and implementation flow remain synchronized.

Future Improvements

Potential enhancements are documented as future work, not as implemented features:

  • Zero Trust policy model for identity-aware segmentation.
  • SIEM integration for firewall, switch, wireless, and server telemetry.
  • IDS/IPS sensors at the internet edge and DMZ boundary.
  • Centralized syslog, NetFlow, and configuration archive services.
  • Network Access Control for wired and wireless admission control.
  • Backup internet failover testing with measured convergence times.
  • Infrastructure as Code documentation using templates or network automation tooling.
  • Monitoring dashboards for availability, interface health, wireless clients, and voice status.
  • Disaster recovery runbooks for firewall, core switch, DHCP/DNS, and WLC restoration.
  • Cloud security extension for hybrid connectivity and cloud workload segmentation.

Repository Tree

.
|-- README.md
|-- CHANGELOG.md
|-- assets/
|   |-- image-inventory.md
|   `-- pdf-image-manifest.tsv
|-- configs/
|   |-- README.md
|   |-- access-switches/
|   |   `-- department-access-switch-template.cfg
|   |-- core-switches/
|   |   |-- common-vlan-trunks.cfg
|   |   |-- core-sw1.cfg
|   |   `-- core-sw2.cfg
|   |-- dmz/
|   |   `-- dmz-switch.cfg
|   |-- firewalls/
|   |   |-- fw1.cfg
|   |   `-- fw2.cfg
|   |-- routers/
|   |   |-- cloud-router.cfg
|   |   |-- cloud-switch.cfg
|   |   |-- isp-router-1-converse.cfg
|   |   `-- isp-router-2-pldt.cfg
|   |-- server-switches/
|   |   `-- inside-server-switch.cfg
|   `-- voice/
|       `-- voice-gateway.cfg
|-- diagrams/
|   |-- README.md
|   |-- cloud-router-segment.png
|   |-- core-switch-hsrp-etherchannel.png
|   |-- department-access-layer-layout.png
|   |-- dmz-server-farm.png
|   |-- dual-isp-edge-routing.png
|   |-- enterprise-topology-overview-page-01.png
|   |-- enterprise-topology-overview-page-02.png
|   |-- firewall-zone-design.png
|   |-- inside-server-farm-layout.png
|   `-- wlc-voice-services-segment.png
|-- docs/
|   |-- addressing-and-vlans.md
|   |-- architecture-overview.md
|   |-- future-enhancements.md
|   |-- implementation-flow.md
|   |-- lessons-learned.md
|   |-- routing-redundancy.md
|   |-- security-architecture.md
|   |-- testing-validation.md
|   `-- wireless-voice-services.md
|-- references/
|   `-- source-scope.md
`-- screenshots/
    |-- README.md
    `-- .gitkeep

About

Defense-in-depth enterprise network architecture focused on trust-boundary enforcement, resilient service delivery, segmented routing, and secure operational control.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors