Professional Documents
Culture Documents
Network Connection Scheme For Station Lan For Farakka STG3
Network Connection Scheme For Station Lan For Farakka STG3
DRG. No.
NOT BE USED DIRECTLY OR INDIRECTLY IN ANY WAY DETRIMENTAL TO THE INTEREST OF THE COMPANY.
THE INFORMATION ON THIS DOCUMENT IS THE PROPERTY OF BHARAT HEAVY ELECTRICALS LTD. IT MUST
NETWORK CONNECTION SCHEME FOR
PI SERVER
TFT
NTPC IT LAN
SERVICE BUILDING
M/C
NO
INTERFACE SWITCH
ARUBA 2930F
M/C
M/C
M/C
1 3 5 7 9 11 13 15 17 19 21 23 AX CX
L3COMSW-A
2 4 6 8 10 12 14 16 18 20 22 24 BX DX
FIREWALL (IPS)
(FW1-A)
FORTIGATE FG61F
DMZ : DMZ & LAN1, IP : 172.16.200.151 / 16
POWER CONSOLE LAN
WAN1 WAN : LAN3, IP : 192.168.9.99 / 24
WAN2 DMZ 7 6 5 4 3 2 1
LAN : LAN4, IP : 172.16.200.251 / 16 MGMT:
USB
WAN2, IP : 10.10.10.2/24
DEFAULT : LAN5 : 192.168.1.99
MGMT
TFT
UPS
L3CORESW-A
IP ADDRESS : 172.16.200.250
MANAGEMENT PORT IP : 10.10.10.4
L3CORESW-A 1 3 5 7 9 11
1 3 5 7 9 11 13 15 17 19 21 23 L2GIGSW-A
2 4 6 8 10 12
2 4 6 8 10 12 14 16 18 20 22 24
MGMT TO L2GIGSW1-A
PORT-16
MC MC MIRROR
TO FW2-A
PORT-4
CHP WS SPARE SPARE IDS
SOPHOS XG-85
WAN IP : 10.10.10.100
DMZ IP : 172.18.160.100
LAN IP : 192.168.11.200
DMZ NETWORK
STNLANSVR2 GATEWAYPC
172.16.160.153 172.18.160.154
TEWAY:172.16.200.251 GATEWAY:172.16.200.251 STAND ALONE
TEST SERVER
NOTE :
UPS
LEGEND :
M/C MEDIA CONVERTER
CISCO C2960
UTP CABLE NET-A
13 15 17 19 21 23 AX CX
L2GIGSW-A
FO CABLE NET-A
VLAN 1- PORT(13-24):10.10.10.5(MANAGEMENT)
14 16 18 20 22 24 BX DX VLAN 2- PORT(1-12):172.16.200.150
MANAGMENT CABLES
FP : FIBER PORT
DELL PE T440
NMS SERVER J2R4BW3
NOTE
1. To have security and isolation across various network segments of Station LAN, (FW2-A with IPS) -is configured as two virtual firewalls.
The first virtual firewall with DMZ and LAN port-1 is configured as transaparent mode for connectivity between DCS network and DMZ/Station LAN network
and Second virtual firewall with Lan port-4 & LAN port 3 is configured in NAT mode for connectivity between Plant network and DMZ/StationLAN network.
CE/1XXX-SHC-56-02
FIRST ANGLE PROJECTION
DRG. No.
NOT BE USED DIRECTLY OR INDIRECTLY IN ANY WAY DETRIMENTAL TO THE INTEREST OF THE COMPANY.
THE INFORMATION ON THIS DOCUMENT IS THE PROPERTY OF BHARAT HEAVY ELECTRICALS LTD. IT MUST
NETWORK CONNECTION SCHEME FOR
INTERFACE SWITCH
ARUBA 2930F
M/C
M/C
M/C
M/C
1 3 5 7 9 11 13 15 17 19 21 23 AX CX
L3COMSW-A
MGMT PORT 2 4 6 8 10 12 14 16 18 20 22 24 BX DX
FIREWALL (IPS)
(FW1-A)
FORTIGATE FG61F
DMZ : DMZ & LAN PORT 1, IP : 172.17.200.151/16
POWER CONSOLE LAN
WAN1
WAN : LAN3, IP : 192.168.10.99 / 24
WAN2 DMZ 7 6 5 4 3 2 1 LAN : LAN PORT 4, IP : 172.17.200.251 / 16
USB
MGMT: WAN2, IP : 10.10.9.2/24
DEFAULT : LAN5 : 192.168.1.99
MGMT( LAN2):10.10.9.2/24
L3CORESW-B
DEFAULT PORT1 : https://172.17.16.16 : 4444
STNLANSVR
172.17.160.1
INTERNAL NETWORK
GATEWAY:17
MGMT
L3CORESW-B
UPS
IP ADDRESS : 172.17.200.250
MANAGEMENT IP : 10.10.9.4
1
L3CORESW-B
1 3 5 7 9 11 13 15 17 19 21 23 L2GIGSW-B
2
2 4 6 8 10 12 14 16 18 20 22 24
MGMT TO L2GIGSW1-B
PORT-16
MC MC MIRROR
TO FW2-B
LAN1
CHP WS SPARE SPARE IDS
DMZ NETWORK
TFT
TFT TFT
UPS
NOTE :
CISCO C2960 IP ADDRESS ASSIGNMENT CAN VARY DEPENDING ON SITE REQUIREMENT.
3 5 7 9 11 13 15 17 19 21 23 AX CX
L2GIGSW-B
LEGEND :
VLAN 1- PORT(13-24):10.10.9.5(MANAGEMENT)
4 6 8 10 12 14 16 18 20 22 24 BX DX
VLAN 2- PORT(1-12):172.17.200.150 M/C MEDIA CONVERTER
FP : FIBER PORT
NOTE
1. To have security and isolation across various network segments of Station LAN, (FW2-A with IPS) -is configured as two virtual firewalls.
The first virtual firewall with DMZ and LAN port-1 is configured as transaparent mode for connectivity between DCS network and DMZ/Station LAN network
and Second virtual firewall with Lan port-4 & Lan port 3 is configured in NAT mode for connectivity between Plant network and DMZ/StationLAN network.
CE/1XXX-SHC-56-02