Přístupnostní navigace
E-application
Search Search Close
Master's Thesis
Author of thesis: Ing. Richard Stupka
Acad. year: 2024/2025
Supervisor: Ing. Anna Kubánková, Ph.D.
Reviewer: Ing. Jan Dvořák, Ph.D.
This thesis explores the design and implementation of a secure access solution for external workers connecting to the corporate network of Racom. The study begins with a detailed analysis of the current network environment, focusing on VLAN segmentation and VPN connection options. The aim of this work is to propose a secure environment for external workers, enabling them to access selected corporate resources without requiring dedicated Ethernet connections. The implementation utilizes the 802.1X protocol for user authentication and authorization, which enables dynamic assignment to appropriate VLANs based on Active Directory information. This approach provides a high level of security with the flexibility to access from any port in the network. For monitoring external worker activities, a comprehensive system was implemented based on collecting and analyzing logs from the Sophos XG firewall and SNMP monitoring of the network infrastructure. The monitoring solution uses a combination of rsyslog and Zabbix tools for centralized collection, filtering, and analysis of security events. The entire system was tested in a controlled environment, which demonstrated its effectiveness in detecting security incidents and automatically responding to potential threats. The implemented monitoring enables real-time tracking of external worker activities through a specialized dashboard. The results show that the combination of the 802.1X protocol and a comprehensive monitoring system significantly enhances the security of network infrastructure while maintaining flexibility for external worker connections. The proposed solution provides an effective tool for managing access to corporate resources and proactive detection of security threats.
Secure access, external workers, corporate network, VLAN segmentation, Proof of Concept, network security, Racom, 802.1X, RADIUS, monitoring
Date of defence
09.06.2025
Result of the defence
Defended (thesis was successfully defended)
Grading
B
Process of defence
Student prezentoval výsledky své práce a komise byla seznámena s posudky. Student obhájil diplomovou práci a odpověděl na otázky členů komise a oponenta. Uveďte, jak by bylo složité a co by bylo potřeba změnit ve Vašem návrhu v případě implementace podpory protokolu IPv6 v síti firmy? Jak by Váš návrh reagoval v případě velkého množství pokusů o připojení (především neautentizovaných, nebezpečných) do sítě firmy v určitý časový okamžik? Co vše by se muselo v rámci této firmy upravit, změnit a dokoupit pro bezproblémový provoz Vašeho navrženého systému? Student dostatečně vysvětlil otázky.
Language of thesis
Czech
Faculty
Fakulta elektrotechniky a komunikačních technologií
Department
Department of Telecommunications
Study programme
Communications and Informatics (MPC-TIT)
Composition of Committee
prof. Ing. Jaroslav Koton, Ph.D. (předseda) Ing. Vojtěch Myška, Ph.D. (člen) Ing. Martina Radilová, Ph.D. (člen) Ing. Pavel Hanák, Ph.D. (člen) Ing. David Kohout (člen) prof. Ing. Radek Martinek, Ph.D. (místopředseda) doc. Ing. Tomáš Horváth, Ph.D. (člen)
Supervisor’s reportIng. Anna Kubánková, Ph.D.
Grade proposed by supervisor: B
Reviewer’s reportIng. Jan Dvořák, Ph.D.
Grade proposed by reviewer: C
Responsibility: Mgr. et Mgr. Hana Odstrčilová