|
|
U-M Virtual Firewall ServiceOverviewThe U-M Virtual Firewall Service is a new network security service available to academic and administrative units on the Ann Arbor campus. The service is designed to provide uniform and centralized perimeter protection against outside threats to the University's various data networks. This security effort is a joint collaboration between ITSS (Information Technology Security Services) and ITCS (Information Technology Central Services). The ITCom group within ITCS is responsible for coordinating the hardware, software, and deployment of the service. Individual units that subscribe to the service will have the ability to control their own virtual firewall or choose to have ITCom administer it for them. Units can easily integrate the service as a replacement for a current firewall, as an addition of a security zone (dmz), or as a basic perimeter security firewall. The service uses products from Check Point Software Technologies to provide a traditional firewall that can support point-to-point tunnels, packet inspection of either bound transmissions, and full-featured event logging. The service deployment currently includes four firewall clusters located around the campus. Each cluster uses a two-node primary/standby configuration and each is initially provisioned to operate up to 10 virtual firewalls. This platform will permit easy access to a firewall by most campus units. Management and log servers are located in the Arbor Lakes Data Center (ARBL), 4251 Plymouth Rd. Virtual Firewall Deployment Overview
Subscription ProcessUnit IT managers interested in using this service should contact their ITCom Project Manager to begin an assessment of unit goals, infrastructure, and operating constraints. Please note that the service may not be appropriate for every individual unit. There is no charge to the unit for the firewall software and licensing, but charges could occur from network changes that may be required during the integration of the components into a unit. If the assessment indicates the unit qualifies for the service, a formal Firewall Service Agreement is prepared that outlines high level roles and responsibilities of ITCom and the unit, training requirements, operating and reporting guidelines, and trouble resolution procedures. This agreement is required even if a unit has a current Network Service Agreement in place. Questions Your ITCom Project Manager Will Ask
|