Recent Projects

Site-to-Site Network Connectivity Deployment for Centralized Security Management

Secure Inter-Site Routing to Support BitLocker Encryption and Azure Virtual Desktop Decommissioning

Q3 2024

Eliminating Network Silos to Strengthen Security and Compliance

This Maryland health department needed to establish secure connectivity between its headquarters and a remote facility to support a broader security modernization initiative. While the remote site had internet access, it lacked direct connectivity to headquarters-based resources such as Active Directory, file servers, DHCP services, and centralized policy management systems.

This limitation created significant challenges for the health department’s planned BitLocker encryption rollout and Azure Virtual Desktop (AVD) decommissioning project. Without direct access to headquarters infrastructure, administrators could not consistently apply security policies, manage encryption centrally, or ensure compliance with organizational standards across locations.

The disconnected environment also created operational inefficiencies, including limited access to shared resources, challenges with inter-site printing, and inconsistent management practices. To address these concerns, the department partnered with Data Networks to implement a secure site-to-site network connectivity solution that would unify the two locations and provide the foundation for centralized security and management.

Building Secure Site-to-Site Network Connectivity

Data Networks designed and implemented a secure site-to-site network connectivity architecture leveraging the health department’s existing Juniper networking infrastructure. The project utilized SRX320 and SRX345 firewalls along with Juniper EX-series switches to establish direct routing between headquarters and the remote facility.

Juniper SRX320 firewall
Juniper SRX345 firewall

The engagement began with a comprehensive review of network infrastructure at both locations, including switch capacity, firewall interfaces, and physical connectivity requirements. Data Networks worked closely with the department’s IT team to validate hardware readiness, establish communication pathways, and prepare both environments for deployment.

To facilitate communication between sites, Data Networks configured a dedicated inter-site subnet and established secure routing between headquarters and the remote location. Static routing policies were implemented to ensure traffic destined for shared resources, security management systems, and BitLocker administration services could traverse the connection reliably and securely.

site-to-site network solution design

The project also included the configuration of Layer 2 interfaces on Juniper EX-series switches at both locations, enabling traffic to be efficiently forwarded through the firewall infrastructure and routed between sites. This design created a streamlined network architecture while maintaining appropriate security controls and segmentation.

Enabling Centralized Security and Improved Operational Efficiency

A critical component of the deployment involved configuring DHCP relay services on the remote site’s SRX firewall. This allowed systems at the remote location to receive IP addressing and network configuration directly from headquarters-based DHCP services, further centralizing infrastructure management and reducing administrative complexity.

engineer deploying site to site network

Once connectivity was established, Data Networks conducted comprehensive testing to validate communication between sites, verify access to shared resources, confirm printer functionality, and ensure devices at the remote location received the correct DHCP assignments. The team also verified that network traffic required for BitLocker policy management and other security services flowed properly between environments.

The completed site-to-site network connectivity solution provides the health department with a unified network architecture that supports centralized administration, improved security governance, and consistent policy enforcement across locations. The enhanced connectivity enables headquarters administrators to manage encryption policies, Active Directory services, and other critical infrastructure resources from a single location while maintaining compliance and security standards.

By eliminating network silos and establishing direct communication between facilities, the health department now benefits from improved operational efficiency, stronger security controls, and a scalable foundation that supports future technology initiatives. Data Networks concluded the engagement with comprehensive documentation, configuration details, and project review sessions to ensure long-term success and ongoing manageability.

Tags: SLG, local government, healthcare, networking, Microsoft