We rebuilt the Hungarian Dance University's network on a star-topology 10 Gbps optical backbone, with SD-WAN, centrally managed Wi-Fi and support for 4K online broadcasts.
The institution opened in September 1950 as the State Ballet Institute, became the Hungarian Dance Academy in 1990 and the Hungarian Dance University in February 2017. It also maintains a secondary school and a boarding house, so the network must serve university teaching, secondary education, residential accommodation and a broadcast studio at once.
ARLITECH is the first and longest-standing Fortinet partner in Hungary, distributing the vendor's products since 2007. No other company in Hungary has integrated and deployed devices spanning every generation from the A series hardware to the G series systems.
| Client | Hungarian Dance University |
|---|---|
| Sector | Education, undergraduate and postgraduate university |
| Users | 1000 students, teachers and staff |
| Location | Budapest, Hungary |
Every task is solvable once it can be broken into parts. The task first, the implementation beneath it.
A new FortiGate firewall system was deployed with full UTP (Unified Threat Protection) functionality. It also controls the active network elements and the Wi-Fi network, at speeds up to 10 Gbps.
The previous, obsolete active devices caused regular outages, and their minimal performance meant constant stuttering. Every switch was replaced with high-performance FortiSwitch units managed from the firewall. Security Fabric shows in real time when a switch or access point loses connection, overheats, or suffers a failed physical port.
The previous 1 Gbps optical backbones were replaced with a 10 Gbps star-topology optical network.
Traffic of differing priority is regulated with FortiGate Traffic Shapers and Traffic Shaping Policies. Alongside daily work, the boarding house, the Wi-Fi network, secondary and university teaching, the computer rooms and the studio all required prioritised, dynamically adjusting treatment.
Because the telephone exchange is hosted at an external provider, the VoIP network received its own VLAN with high priority and guaranteed bandwidth. The quality problems caused by the previous network disappeared entirely.
Many students study at the university and the secondary school, and guests and visiting speakers arrive for conferences and performances. The Wi-Fi network had to serve thousands of devices in real time. Every switch deployed is PoE-capable, powering the access points, and their status is queryable through Security Fabric.
Wi-Fi networks are protected by Web Filter, AntiVirus, DNS Filter, File Filtering, Application Control and SSL/SSH inspection security profiles, so students cannot download harmful content or launch attacks from potentially infected devices. Connection to SSIDs visible beyond the university's premises is protected with IPS and WIDS profiles.
A FortiAnalyzer-VM was configured in the university's virtual environment. It provides centralised log collection and unified visibility across network and security devices, with real-time system monitoring, pre-built reports, built-in SIEM and SOAR, and advanced threat detection.
Because the whole network is integrated into the firewall, operations are handled centrally. This substantially reduces resource demand, limits the scope for mistakes, and removes any need for local configuration on the switches.
Critical systems and web servers moved into separate VLANs with strict firewall rules and maximum-protection security profiles. Both the physical and the Wi-Fi network are segmented as far as possible: every separable group, building and function received its own VLAN.
Filtering between VLANs (AntiVirus, IPS, File Filtering) is performed by the FortiGate firewall. The solution is this simple because the firewall routes traffic between SSIDs and VLANs while also acting as switch and Wi-Fi controller.
A FortiWeb-based WAF (Web Application Firewall) was commissioned at the university to protect internet-published web servers and web-based services.
Guaranteeing uninterrupted bandwidth for internet-published 4K broadcasts was a critical task. This too was solved with Traffic Shaping.
The university has students from many countries and is an internationally recognised arts university, so attacks arrive continuously. Because of that visibility, traffic cannot be restricted on a Geolocation basis, so we applied specialised security profiles created specifically to protect the web servers.
Multiple internet lines from multiple providers had to be configured into an SD-WAN zone with dedicated SD-WAN rules, for availability and load distribution.
Built on the 10 Gbps star-topology optical backbone, the university's network became stable and the earlier stuttering and outages ended. Through central management and Security Fabric, operations run from a single interface, and 4K online broadcasts proceed undisturbed alongside daily teaching traffic.