Network Architecture and Implementation Brief

Site Location: Dhaka Polytechnic Institute, Computer Science & Engineering (CSE) Department

Infrastructure Scope: Core Routing, Fiber Distribution, High-Availability Access Layer, and Structured Cabling

Executive Summary

This document outlines the finalized network architecture for the Computer Science & Engineering (CSE) Department at Dhaka Polytechnic Institute. Designed to support rigorous academic workloads, the infrastructure leverages a hybrid fiber-copper topology to ensure uncompromising high availability, strict logical segmentation, and scalable throughput. By deploying an Allied Telesis routing and switching core, reinforced by a robust Spanning Tree Protocol (STP) redundancy model, the architecture guarantees resilient connectivity across all five laboratory environments.

Dhaka Polytechnic Institute CSE Department Network Layout
Figure 1: Finalized Physical and Logical Redundancy Topology for the CSE Department

1. Core & Edge Routing Architecture

The perimeter and logical core of the CSE department network are centralized to enforce strict security governance and efficient traffic management.

Gateway and Perimeter Security

The network perimeter is secured and routed by an enterprise-grade Allied Telesis Edge Router/Firewall. This device serves as the primary gateway to the wider campus network and the external ISP. Beyond standard NAT and static routing, the firewall engine actively performs stateful packet inspection, intrusion detection, and access control. By filtering inbound and outbound traffic, it secures the academic environment from external threats while shaping bandwidth to prioritize critical educational services over recreational traffic.

Logical Segmentation (VLAN Integration)

To isolate broadcast domains, enhance security, and prevent localized network events (such as broadcast storms in a single lab) from degrading the entire department's performance, the Edge Router manages five distinct Virtual Local Area Networks (VLANs).

Centralized Compute Infrastructure

Directly connected to the core routing layer is a high-performance Dell Server[cite: 1]. This server acts as the localized data center for the CSE department, hosting critical internal services[cite: 1]:

2. Fiber Backbone & Distribution Layer

To support the heavy data throughput required by modern computer science curricula, the primary distribution matrix relies entirely on a high-speed optical backbone.

The Primary Distribution Node

Room 208 serves as the department's Main Distribution Frame (MDF). It houses the central SFP Aggregation Switch, an Allied Telesis device strictly dedicated to high-speed data transit. This node acts as the optical hub, aggregating all traffic from the downstream labs before passing it to the Edge Router.

Single-Mode Fiber Trunk Chain

The primary data highway between the Aggregation Switch in Room 208 and the individual access switches in Labs 1 through 5 is constructed using Single-Mode Fiber Optics.

3. High-Availability, Redundancy & Spanning Tree Protocol (STP)

The defining engineering achievement of this architecture is its dual-path redundancy. It is specifically designed to survive physical cable cuts or optical transceiver failures without requiring manual administrative intervention.

Dedicated Copper Failover Paths

Operating in parallel to the primary fiber backbone is a redundant copper underlay. The Allied Telesis Edge Router utilizes five dedicated Ethernet ports—each mapped explicitly to one of the five lab VLANs. From these ports, dedicated Cat6 copper Ethernet connections run directly to standard RJ-45 Ethernet ports on the Allied Telesis access switches within each respective lab.

Automated Loop Prevention (STP Convergence)

Running active parallel connections (fiber and copper) between two network nodes inherently creates a Layer 2 routing loop, which would typically result in a catastrophic broadcast storm. To engineer around this, the Spanning Tree Protocol (STP) is actively enforced across the entire switching topology.

4. Lab Access Layer (Labs 1–5)

The access layer is standardized across all five laboratories, providing a uniform, high-performance, and easily maintainable environment for students and faculty.

Edge Switching Infrastructure

Every laboratory is equipped with a dedicated Allied Telesis Access Switch. These switches receive the high-speed optical feed from Room 208 and distribute network access to the local environment. They are configured with port security features (such as BPDU Guard) to shut down any ports if a student attempts to connect unauthorized networking equipment that could compromise the STP topology.

Structured Cabling and Workstation Delivery

Each lab supports approximately 35 PC workstations. Network delivery to these PCs is achieved through a rigid structured cabling methodology:

Wireless Integration

To support modern academic mobility, enterprise-grade Cisco Access Points (APs) are deployed centrally within each lab room, broadcasting a unified SSID (LabX-WiFi).

5. Active Directory Domain Services (ADDS) & Directory Integration

To streamline network administration, security policy enforcement, and user credential management, an enterprise-level identity management framework has been integrated into the infrastructure.

Domain Controller and DNS Deployment

The primary Domain Controller and supporting DNS services are successfully implemented and hosted within VLAN 20[cite: 1]. This ensures localized, low-latency name resolution and reliable authentication channels for connected network nodes.

Organizational Unit (OU) Structure

To establish granular access controls, Group Policy Objects (GPOs), and administrative delegation, structured user accounts have been systematically created and organized into four distinct semester OUs[cite: 1].

Workstation Domain Integration and Scalability

As part of the initial rollout phase, all machine endpoints located within **VLAN 20** have been fully joined and integrated into the ADDS domain[cite: 1]. Furthermore, architectural provisions are established to systematically onboard and connect endpoints from **all other department VLANs** to the ADDS domain in future deployment phases[cite: 1].