4.2 Current IT architecture

This section provides background information about the existing Armando Banking Brothers Company IT architecture, including the network infrastructure, security infrastructure, and the middleware/application infrastructure.

4.2.1 Network infrastructure

Next we describe the logical network components that make up the ABBC network (Figure 4-1). ABBC has developed the network and application security infrastructure in line with the IBM MASS security model. The network has the following major security zones:

￿Uncontrolled zone/Internet, external networks

￿Controlled zone/demilitarized zone (DMZ)

￿Controlled/intranet

￿Restricted/production network

￿Restricted/management network

 

LAN

 

Dialup

 

Production

Client

Branch

Network

 

 

 

Office

 

Branch

 

Production

WAN

Servers

Office

 

 

DMZ –2

 

 

VPN & R-access

 

TCM SCM

Compliance

& Remediation

Internet

VPN

Client

Partner

WAN

External Network

DMZ –1

Server

DMZ –3

Ext network

DMZ

Core

LAN

Intranet

Virtual Private

network

Wireless

Access point

LAB

NMS

ACS

 

Management

 

Network

Firewall

Intrusion detection

 

System

Router

 

Figure 4-1 ABBC current network diagram

Chapter 4. Armando Banking Brothers Corporation 79

Page 97
Image 97
IBM Tivoli and Cisco manual Current IT architecture, Network infrastructure