Having Networking and Security Problems From Growing Too Quickly?

Your network is the backbone of all communications going in and out of your company. All companies started small when they implemented their network, but some don’t adjust as they grow, and this is where most problems come in with a flat network in place. 

As a company grows, more devices are added, such as workstations, laptops, tablets, smartphones, servers, switches, firewalls, and the list keeps growing over time. Over the last several years, a new category has emerged called Internet of Things (IoT) devices, and these are everywhere. They, too, require an IP address, and that adds to the problem. If nothing is done to segregate the traffic, there will be a point where network performance degrades.

Dealing with a slow network is bad enough, but what about security? Do all your users have access to your financial data or any other sensitive data? 

You’d be surprised by what we’ve found when we start doing security audits that leave most owners and managers shocked. Users are curious and will explore file shares if they are wide-open. 

Common Issues

Let’s look at the first issue of network performance degradation due to too many devices, why it happens, and some examples.

The term used to describe this is Broadcast Storm. This is when an abnormally high amount of specific traffic called broadcast packets is present on the network in a short amount of time. When this happens, it has the effect of bringing your systems to a crawl, or worse, making them unusable.   

The list of effects you’ll see are:

  • Slow login times
  • Printing will be delayed or not functional
  • Voice-over-IP calls will drop or call quality severely degraded
  • Applications will hang
  • Websites will not load 
  • And a whole range of other issues

Our next issue would be security. When starting, most companies have one subnetwork, and all desktops and servers can communicate with each other with no logical separation through multiple subnets. Everything is fast until you start to grow. 

There are two issues here:

  1. Not all systems should be able to communicate with each other. 
  2. Users should not be allowed to reach sensitive systems unless they are explicitly granted access. 

Why should users not have access to all systems or shares has been mentioned briefly, but what are other risks?

Let’s assume that just one user within your company gets a virus. If that one user has access to all your shares, that one employee just spread the infection, thus spreading it company-wide. 

It’s not uncommon for public-facing web servers to access data on in internal network share. If your web server is compromised, you could now be serving up malware to users worldwide unknowingly.

Fixes

Network performance issues can be addressed by breaking up the network by the use of additional subnets to lower your broadcast domains. Making these changes will reduce the amount of traffic the nodes on the network needs to listen in each subnet, thus improving performance.

Additionally, if you have older networking equipment, you would benefit from newer and faster hardware. We are also making the assumption network hubs are not being used anywhere within the network.

In regards to security, network segregation and segmentation will allow you to apply proper security to each segment of your network and offer you protection by preventing access to systems from those that should not have access.

Through the use of firewalls, access lists, and other technologies like Cisco TrustSEC, you can achieve these two goals of network segregation and segmentation to protect your company and your sensitive data.

Making the changes stated above is not something that should be done by the inexperienced. However, with a careful mapping of your network, extensive planning, and execution, you can be better protected from emerging security risks and have peace of mind. 

Let R&B Networks help by having our certified Cisco CCIE do network analysis and security scans to see what can be improved. Give us a call or send us a quick email.