We rebuilt the entire network of the Municipality of Gödöllő: a redundant firewall, centrally managed switching and Wi-Fi, and the integration of external institutions into a single management plane.
A municipal network serves administrative work, public services and online broadcasts at once, while protecting critical systems is a statutory expectation. At the Municipality of Gödöllő the previous, obsolete active devices caused regular outages, and managing the network required local, per-device configuration.
ARLITECH engineers assembled a task list whose resolution is decisive for the stable operation of a municipal IT system. The work was complex, but the support of the Municipality's leadership secured its successful delivery.
| Client | Municipality of Gödöllő |
|---|---|
| Sector | Local government, public sector |
| Users | 300 staff and guests |
| Location | Gödöllő, Hungary |
Every task is solvable once it can be broken into parts. The task first, the implementation beneath it.
A new, redundant FortiGate firewall system was deployed with full UTP (Unified Threat Protection) functionality. It also controls the active network elements and the Wi-Fi network, at speeds up to 10 Gbps.
Every switch was replaced with high-performance FortiSwitch units managed from the firewall. Network speed increased several times over, outages and stuttering ended, and nothing needs local configuration any more. Security Fabric displays the physical topology of connected devices, cutting time spent on operations and fault finding to a fraction.
Traffic of differing priority towards the internet is regulated with FortiGate Traffic Shapers and Traffic Shaping Policies. Alongside daily work, public administration and online broadcasts received prioritised, dynamically adjusting treatment.
The VoIP exchange running in the virtual environment received its own VLAN with high priority and guaranteed bandwidth. The quality problems caused by the previous network disappeared entirely.
Many staff, guests and visiting speakers arrive and events are held, so several hundred devices had to be served simultaneously. Every deployed switch is PoE-capable, powering the access points, and their status is queryable through Security Fabric.
Wi-Fi networks are protected by Web Filter, AntiVirus, DNS Filter, File Filtering, Application Control and SSL/SSH inspection security profiles. Connection to SSIDs visible beyond the Municipality's premises is protected with IPS and WIDS profiles. All of this runs on the FortiGate firewall, since it is the controller for the FortiAPs.
A FortiAnalyzer-VM was configured in the Municipality's virtual environment. It provides centralised log collection and unified visibility across network and security devices, with real-time system monitoring, pre-built reports, built-in SIEM and SOAR, and advanced threat detection.
Because the whole network is integrated into the firewall, operations are handled centrally. This substantially reduces resource demand, and the integration itself limits the scope for mistakes.
Critical systems and web servers moved into separate VLANs with strict firewall rules and maximum-protection security profiles. Both the physical and the Wi-Fi network are segmented as far as possible: every separable group, building and function received its own VLAN.
Filtering between VLANs (AntiVirus, IPS, File Filtering) is performed by the FortiGate firewall. The solution is this simple because the firewall routes traffic between SSIDs and VLANs while also acting as switch and Wi-Fi controller.
A WAF (Web Application Firewall) was commissioned to protect published web servers and web-based services. Bandwidth for internet-published broadcasts is likewise secured through Traffic Shaping.
The Municipality maintains relations with local governments in many countries and is an internationally recognised authority, so attacks arrive continuously. Because of that visibility, traffic can only be restricted minimally on a Geolocation basis, so we applied specialised security profiles created specifically to protect the web servers.
Using Security Fabric, the FortiGate firewalls of every external institution, nursery and kindergarten were integrated into the central firewall and FortiAnalyzer. This delivered a centrally managed firewall rule set and central logging.
A redundant FortiMail system was integrated, forwarding incoming mail to the internal mail servers according to predefined rules. Its functions include mail forwarding by IP, domain and ACL, spam filtering, virus filtering, content filtering, quarantine management, and blacklists and whitelists. Logging and reporting run in FortiAnalyzer, and FortiMail is also part of the Security Fabric.
Following deployment, network bandwidth increased by an order of magnitude and response times for servers and internet access fell. Centralising operations cut fault-finding time to a fraction, and the external institutions became part of a single, uniformly managed security system.