Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Comment: Migrated to Confluence 5.3

...

  • In special circumstances, especially for Cornell-owned hardware, they can be put consider putting them on Cornell's "GreenNet" (ethernet)
  • ChemIT's networks are reserved for systems managed by ChemIT
    • Configuration, Active Directory log-in (enforcing p/w strength and consequences), patching oversight, anti-virus oversight.

...

Recommendations/
Preferences

 

Boot 1

Boot 2

Host

Guest

Network:
ChemIT or
GreenNet

Notes

 

Option 1

Windows

Debian

N/A

N/A

GreenNet

Easiest to set up.
Can ChemIT manage a Windows system on GreenNet?
Safest for Research group's network (Freed's and CCB's).
John must run VPN to connect to Eldor.
Up to John to figure out a way to SSH to the system (since no static IP).

 

Option 2

Windows

When Debian, but only run as a boot OS when h/w performance needed: .
Debian

Windows

Debian, from Boot 2 installation partition. Run Debian this way, unless need h/w performance.

ChemIT: FreedNet, if Windows is indeed usually running.

Doable? Cost-effective, time-wise?
Any easier for maintenance?

 

Option 3 ?

 

 

 

 

 


Windows

Debian

N/A

N/A

ChemIT: FreedNet

Easiest to set up.
Safest for John's computer.
Higher risk for Freed's Research group's systems.
No SSH to system

 

Option
4

Windows

Debian

N/A

N/A

ChemIT: Public IP

Easiest to set up.
Safest for John's computer.
Higher risk to CCB's Research group's systems.
Can SSH to system  

Specifics

OSes

John responsible for dual-boot capabilities. Can pull all networking info from Windows OS's configuration.

...

No VPN required to print or access CIT SFS file shares.

ChemIT network

In general, these networks are reserved for systems managed by ChemIT.

  • Configuration, Active Directory log-in (enforcing p/w strength and consequences), patching oversight, anti-virus oversight.
    • A secure configuration for desktops includes not running server-like software (like SSH).
  • ChemIT responsible for the security of these networks.

The Freed research network has strong protections, by both a Strong protections by router and ACLs.

  • Does not permit in-bound SSH to desktop.

Systems in the ChemIT network are more vulnerable to each other than from outside-the-network systems.

  • Thus, must exert efforts to prevent situations in which a single compromised system becomes a launching-point to all the other systems on that same network.