Planning a big deployment...

Started by deanwebb, October 15, 2016, 11:38:13 AM

Previous topic - Next topic

deanwebb

 :matrix:

NAC project, global rollout, 400K+ endpoints, three years to full enforcement, and who gets asked to plan the whole thing? Me.

It's a stretch, for sure, but I'm really getting into this. I'm not labbing this weekend, I'm drawing up plans for a very complicated operation. I'm stoked, and this is where I can take all the stuff I've learned about doing NAC in a limited way and scale it out for the global enterprise.

:challenge-accepted:

But make no mistake, this is not an easy thing. I made an outline of things to consider last night and it ran to just shy of 7 pages. Now I'm fleshing out the outline and creating a timeline from it. Having some project management experience is good because it helps me think of which tasks can be done in parallel and which have to be done in serial.

If I accidentally write a book on this subject, I hope I'll be able to get it edited and published, that's for sure.
Take a baseball bat and trash all the routers, shout out "IT'S A NETWORK PROBLEM NOW, SUCKERS!" and then peel out of the parking lot in your Ferrari.
"The world could perish if people only worked on things that were easy to handle." -- Vladimir Savchenko
Вопросы есть? Вопросов нет! | BCEB: Belkin Certified Expert Baffler | "Plan B is Plan A with an element of panic." -- John Clarke
Accounting is architecture, remember that!
Air gaps are high-latency Internet connections.

Dieselboy

Sounds like fun. What's your approach?

My biggest rollout has not even been 10% of your project.

deanwebb

Monitor everything before enforcing anything.

Then enforce by degrees, testing all the way.
Take a baseball bat and trash all the routers, shout out "IT'S A NETWORK PROBLEM NOW, SUCKERS!" and then peel out of the parking lot in your Ferrari.
"The world could perish if people only worked on things that were easy to handle." -- Vladimir Savchenko
Вопросы есть? Вопросов нет! | BCEB: Belkin Certified Expert Baffler | "Plan B is Plan A with an element of panic." -- John Clarke
Accounting is architecture, remember that!
Air gaps are high-latency Internet connections.

Nerm


deanwebb

Indeed... monitoring is pretty straightforward. It's getting to enforcement for all our sites that will be the biggest mess.

1. Deploy ForeScout CounterACT NAC
2. Monitor everything
3. ? ? ?
4. PROFIT!
Take a baseball bat and trash all the routers, shout out "IT'S A NETWORK PROBLEM NOW, SUCKERS!" and then peel out of the parking lot in your Ferrari.
"The world could perish if people only worked on things that were easy to handle." -- Vladimir Savchenko
Вопросы есть? Вопросов нет! | BCEB: Belkin Certified Expert Baffler | "Plan B is Plan A with an element of panic." -- John Clarke
Accounting is architecture, remember that!
Air gaps are high-latency Internet connections.

icecream-guy

Quote from: deanwebb on October 17, 2016, 09:10:37 AM
Indeed... monitoring is pretty straightforward. It's getting to enforcement for all our sites that will be the biggest mess.

1. Deploy ForeScout CounterACT NAC
2. Monitor everything
3. DOCUMENT
4. PROFIT!
:professorcat:

My Moral Fibers have been cut.

Nerm

Document? Who wants to document? lol

deanwebb

This is what we hire tech writers for, this documentation thing...

But now I'm considering how many people we need and for how long in order to take care of certain tasks. Project management, baby! I'll also get into questions of budget for gear... and travel...
Take a baseball bat and trash all the routers, shout out "IT'S A NETWORK PROBLEM NOW, SUCKERS!" and then peel out of the parking lot in your Ferrari.
"The world could perish if people only worked on things that were easy to handle." -- Vladimir Savchenko
Вопросы есть? Вопросов нет! | BCEB: Belkin Certified Expert Baffler | "Plan B is Plan A with an element of panic." -- John Clarke
Accounting is architecture, remember that!
Air gaps are high-latency Internet connections.

Otanx


Nerm

Quote from: deanwebb on October 18, 2016, 11:03:58 AM
This is what we hire tech writers for, this documentation thing...

But now I'm considering how many people we need and for how long in order to take care of certain tasks. Project management, baby! I'll also get into questions of budget for gear... and travel...

You have people dedicated to writing documentation? That is awesome!

deanwebb

Welcome to Major Global Multinational, Inc. And while we have writers for everything, those writers write procedures for everything...
Take a baseball bat and trash all the routers, shout out "IT'S A NETWORK PROBLEM NOW, SUCKERS!" and then peel out of the parking lot in your Ferrari.
"The world could perish if people only worked on things that were easy to handle." -- Vladimir Savchenko
Вопросы есть? Вопросов нет! | BCEB: Belkin Certified Expert Baffler | "Plan B is Plan A with an element of panic." -- John Clarke
Accounting is architecture, remember that!
Air gaps are high-latency Internet connections.

Nerm

I work for a large (IMO) global company but we don't have technical writers. Well if we do I don't know any of them lol.

wintermute000

we're supposed to have them, but I"ll be f--ked if I know who actually gets to use them, or what the f--k they actually write, as all the doco I've ever seen have been hammered out by engineers desperately trying to get if off their plate

deanwebb

One of those problems of a company of a certain size...
Take a baseball bat and trash all the routers, shout out "IT'S A NETWORK PROBLEM NOW, SUCKERS!" and then peel out of the parking lot in your Ferrari.
"The world could perish if people only worked on things that were easy to handle." -- Vladimir Savchenko
Вопросы есть? Вопросов нет! | BCEB: Belkin Certified Expert Baffler | "Plan B is Plan A with an element of panic." -- John Clarke
Accounting is architecture, remember that!
Air gaps are high-latency Internet connections.

icecream-guy

Quote from: deanwebb on October 21, 2016, 09:10:00 AM
One of those problems of a company of a certain size...

added it to the thread
:professorcat:

My Moral Fibers have been cut.