Network Segregation and DMZ Project

Job ID: 37315219

Budget: $30 – $250 CAD

Network Segregation and DMZ Project

I am looking for a freelancer who can help me with a project involving network segregation and DMZ implementation.

Current Network Structure:
- Please specify the current network structure as it was not provided in the questionnaire.

Specific Security Requirements:
- Yes, there are specific security requirements and regulations that need to be followed.

Equipment or Software in Place:
- Please specify the equipment or software currently in place for network segregation and DMZ implementation as it was not provided in the questionnaire.

Ideal Skills and Experience:
- Experience in network segmentation and DMZ implementation.
- Strong knowledge of network security protocols and regulations.
- Proficient in configuring firewalls and routers.
- Familiarity with best practices for network segregation and DMZ implementation.
- Excellent problem-solving and troubleshooting skills.

If you have the required skills and experience, please submit your proposal for further discussion.

Network Segregation and DMZ Project
Network Segregation and DMZ Project

Complete a migration from one network topology 1 to topology 2. To achieve this, you must divide the network into separate security zones using VLANs, routing policies, and stateless firewalls if needed. By grouping these devices together, the security team can better manage and monitor the security posture of the devices within the zone. You must also identify the appropriate security zone for each device based on their security requirements and define how they communicate with other devices within their respective security zones.
In addition, you must implement a DNS solution that separates traffic between private and public DNS servers, allowing only authorized endpoints to query private DNS servers and any endpoint to query public DNS servers. Also, you must switch from static routing to dynamic routing protocol (OSPF) during the migration process (See FRR (frrouting.org/).
Moreover, you must segregate network traffic between security zones using VLANs, routing policies, and stateful L3 firewall. In addition, you will complete implementation of split DNS security pattern. The private DNS resolves queries for company's internal resources and only authorized endpoint allows to query Private DNS. Public DNS resolves queries about any public-facing assets and any endpoint allows to query Public DNS. All host firewalls must be configured using ansible or python script.

Also, you are required to design a DMZ zone. Your DMZ design must meet certain criteria, including inspecting all external connections with IDS sensors and securing web applications using WAF. In addition, network traffic should never flow directly between the external and internal firewalls, as this exposes the internal network to potential threats. Instead, all external connections should be terminated within the DMZ zone. Network firewalls and proxies should be configured using Ansible or Python script to automate the process and avoid manual configuration errors.
During this, you will be responsible for deploying two web vulnerable applications (websploit.org/).

Note: Everything is on Vmware.Please read the attached document first and dont waste my time if you cant do it, I need it asap.