Building a University and Secondary School Network with Fortinet

We rebuilt the Hungarian Dance University's network on a star-topology 10 Gbps optical backbone, with SD-WAN, centrally managed Wi-Fi and support for 4K online broadcasts.

The client

Who This Is About

The institution opened in September 1950 as the State Ballet Institute, became the Hungarian Dance Academy in 1990 and the Hungarian Dance University in February 2017. It also maintains a secondary school and a boarding house, so the network must serve university teaching, secondary education, residential accommodation and a broadcast studio at once.

ARLITECH is the first and longest-standing Fortinet partner in Hungary, distributing the vendor's products since 2007. No other company in Hungary has integrated and deployed devices spanning every generation from the A series hardware to the G series systems.

1000
Users served
10 Gbps
Optical backbone
4K
Online broadcast
Who This Is About
ClientHungarian Dance University
SectorEducation, undergraduate and postgraduate university
Users1000 students, teachers and staff
LocationBudapest, Hungary
Integrated products

What We Deployed

The work

Tasks and How We Solved Them

Every task is solvable once it can be broken into parts. The task first, the implementation beneath it.

  1. The highest possible protection against attacks from the internet: DoS, Web Filter, AntiVirus, IPS, DNS Filter, File Filtering, Application Control, first-level email filtering, VoIP protection, WAF and SSL/SSH inspection.

    A new FortiGate firewall system was deployed with full UTP (Unified Threat Protection) functionality. It also controls the active network elements and the Wi-Fi network, at speeds up to 10 Gbps.

  2. Centrally managed active network devices. Ending unexpected outages and resolving throughput and speed problems.

    The previous, obsolete active devices caused regular outages, and their minimal performance meant constant stuttering. Every switch was replaced with high-performance FortiSwitch units managed from the firewall. Security Fabric shows in real time when a switch or access point loses connection, overheats, or suffers a failed physical port.

  3. Building a star-topology 10 Gbps optical backbone.

    The previous 1 Gbps optical backbones were replaced with a 10 Gbps star-topology optical network.

  4. Dynamic bandwidth management of internet traffic.

    Traffic of differing priority is regulated with FortiGate Traffic Shapers and Traffic Shaping Policies. Alongside daily work, the boarding house, the Wi-Fi network, secondary and university teaching, the computer rooms and the studio all required prioritised, dynamically adjusting treatment.

  5. Lossless operation of the VoIP network provided by an external supplier.

    Because the telephone exchange is hosted at an external provider, the VoIP network received its own VLAN with high priority and guaranteed bandwidth. The quality problems caused by the previous network disappeared entirely.

  6. A centrally managed Wi-Fi network capable of serving thousands of devices.

    Many students study at the university and the secondary school, and guests and visiting speakers arrive for conferences and performances. The Wi-Fi network had to serve thousands of devices in real time. Every switch deployed is PoE-capable, powering the access points, and their status is queryable through Security Fabric.

  7. Protecting traffic crossing the Wi-Fi network.

    Wi-Fi networks are protected by Web Filter, AntiVirus, DNS Filter, File Filtering, Application Control and SSL/SSH inspection security profiles, so students cannot download harmful content or launch attacks from potentially infected devices. Connection to SSIDs visible beyond the university's premises is protected with IPS and WIDS profiles.

  8. Real-time central logging and monitoring, avoiding untraceable faults.

    A FortiAnalyzer-VM was configured in the university's virtual environment. It provides centralised log collection and unified visibility across network and security devices, with real-time system monitoring, pre-built reports, built-in SIEM and SOAR, and advanced threat detection.

  9. Reducing the human resources required for operations and minimising human error.

    Because the whole network is integrated into the firewall, operations are handled centrally. This substantially reduces resource demand, limits the scope for mistakes, and removes any need for local configuration on the switches.

  10. Protecting critical services and systems, and achieving the greatest possible network segmentation.

    Critical systems and web servers moved into separate VLANs with strict firewall rules and maximum-protection security profiles. Both the physical and the Wi-Fi network are segmented as far as possible: every separable group, building and function received its own VLAN.

  11. Implementing filtering between VLANs.

    Filtering between VLANs (AntiVirus, IPS, File Filtering) is performed by the FortiGate firewall. The solution is this simple because the firewall routes traffic between SSIDs and VLANs while also acting as switch and Wi-Fi controller.

  12. Protecting internet-published services with a WAF.

    A FortiWeb-based WAF (Web Application Firewall) was commissioned at the university to protect internet-published web servers and web-based services.

  13. Securing online broadcasts from the internal network to the internet.

    Guaranteeing uninterrupted bandwidth for internet-published 4K broadcasts was a critical task. This too was solved with Traffic Shaping.

  14. Repelling attacks arriving from every part of the world.

    The university has students from many countries and is an internationally recognised arts university, so attacks arrive continuously. Because of that visibility, traffic cannot be restricted on a Geolocation basis, so we applied specialised security profiles created specifically to protect the web servers.

  15. Establishing SD-WAN.

    Multiple internet lines from multiple providers had to be configured into an SD-WAN zone with dedicated SD-WAN rules, for availability and load distribution.

Outcome

What the Deployment Delivered

Built on the 10 Gbps star-topology optical backbone, the university's network became stable and the earlier stuttering and outages ended. Through central management and Security Fabric, operations run from a single interface, and 4K online broadcasts proceed undisturbed alongside daily teaching traffic.

Planning a Similar Project?

Let us look at what this would mean in your environment. We start with a 30 minute, no-charge scoping call.