This document outlines the finalized network architecture for the Computer Science & Engineering (CSE) Department at Dhaka Polytechnic Institute. Designed to support rigorous academic workloads, the infrastructure leverages a hybrid fiber-copper topology to ensure uncompromising high availability, strict logical segmentation, and scalable throughput. By deploying an Allied Telesis routing and switching core, reinforced by a robust Spanning Tree Protocol (STP) redundancy model, the architecture guarantees resilient connectivity across all five laboratory environments.
The perimeter and logical core of the CSE department network are centralized to enforce strict security governance and efficient traffic management.
The network perimeter is secured and routed by an enterprise-grade Allied Telesis Edge Router/Firewall. This device serves as the primary gateway to the wider campus network and the external ISP. Beyond standard NAT and static routing, the firewall engine actively performs stateful packet inspection, intrusion detection, and access control. By filtering inbound and outbound traffic, it secures the academic environment from external threats while shaping bandwidth to prioritize critical educational services over recreational traffic.
To isolate broadcast domains, enhance security, and prevent localized network events (such as broadcast storms in a single lab) from degrading the entire department's performance, the Edge Router manages five distinct Virtual Local Area Networks (VLANs).
Directly connected to the core routing layer is a high-performance Dell Server[cite: 1]. This server acts as the localized data center for the CSE department, hosting critical internal services[cite: 1]:
To support the heavy data throughput required by modern computer science curricula, the primary distribution matrix relies entirely on a high-speed optical backbone.
Room 208 serves as the department's Main Distribution Frame (MDF). It houses the central SFP Aggregation Switch, an Allied Telesis device strictly dedicated to high-speed data transit. This node acts as the optical hub, aggregating all traffic from the downstream labs before passing it to the Edge Router.
The primary data highway between the Aggregation Switch in Room 208 and the individual access switches in Labs 1 through 5 is constructed using Single-Mode Fiber Optics.
The defining engineering achievement of this architecture is its dual-path redundancy. It is specifically designed to survive physical cable cuts or optical transceiver failures without requiring manual administrative intervention.
Operating in parallel to the primary fiber backbone is a redundant copper underlay. The Allied Telesis Edge Router utilizes five dedicated Ethernet ports—each mapped explicitly to one of the five lab VLANs. From these ports, dedicated Cat6 copper Ethernet connections run directly to standard RJ-45 Ethernet ports on the Allied Telesis access switches within each respective lab.
Running active parallel connections (fiber and copper) between two network nodes inherently creates a Layer 2 routing loop, which would typically result in a catastrophic broadcast storm. To engineer around this, the Spanning Tree Protocol (STP) is actively enforced across the entire switching topology.
The access layer is standardized across all five laboratories, providing a uniform, high-performance, and easily maintainable environment for students and faculty.
Every laboratory is equipped with a dedicated Allied Telesis Access Switch. These switches receive the high-speed optical feed from Room 208 and distribute network access to the local environment. They are configured with port security features (such as BPDU Guard) to shut down any ports if a student attempts to connect unauthorized networking equipment that could compromise the STP topology.
Each lab supports approximately 35 PC workstations. Network delivery to these PCs is achieved through a rigid structured cabling methodology:
To support modern academic mobility, enterprise-grade Cisco Access Points (APs) are deployed centrally within each lab room, broadcasting a unified SSID (LabX-WiFi).
To streamline network administration, security policy enforcement, and user credential management, an enterprise-level identity management framework has been integrated into the infrastructure.
The primary Domain Controller and supporting DNS services are successfully implemented and hosted within VLAN 20[cite: 1]. This ensures localized, low-latency name resolution and reliable authentication channels for connected network nodes.
To establish granular access controls, Group Policy Objects (GPOs), and administrative delegation, structured user accounts have been systematically created and organized into four distinct semester OUs[cite: 1].
As part of the initial rollout phase, all machine endpoints located within **VLAN 20** have been fully joined and integrated into the ADDS domain[cite: 1]. Furthermore, architectural provisions are established to systematically onboard and connect endpoints from **all other department VLANs** to the ADDS domain in future deployment phases[cite: 1].