Milestones All-Round

Project Stonehenge & New Managed Service

Recent ITSUS Achievements and Project Insights

Over the past few months, ITSUS had the opportunity to re-design and upgrade an important network for English Heritage’s flagship site, Stonehenge.

Located within the Sailsbury Plain, Wiltshire England, Stonehenge attracts over 1.4 million visitors annually, being an historically and culturally important site. Managing the site’s network, which supports both daily operations of staff and visitors, requires an infrastructure that spans several hundred meters across multiple buildings with varied uses. These include general daily operations, the education centre, the 360° virtual experience museum and exhibition, the café, and the impressive gift shop.

My first experience of visiting Stonehenge and appreciating the site began several months prior, from the initial preparation of reading network high-level target architecture documentation, to visiting the site alongside ITSUS’s Senior Technical Network Engineer, Robert Fieldhouse.

The high-level target architecture documentation included the initial setup and previous network designs, target architecture, and project involving two distinct stages of network upgrades. The documentation provided an overview of the current setup, and the hardware involved, moving into the technical dependencies, physical resources, and opportunities. Preliminary tasks were highlighted, including an audit and complete hardware scope, ensuring a bill of materials was complete and appropriate for the project.  Assumptions were also listed for the client, covering everything from the build to the all-important licencing of products. Further documentation included the enhancements to both network resilience and network security, whilst also reducing network complexity.

ITSUS and EH team members at Stonehenge

Understanding the Landscape – Visiting Stonehenge

A site audit brought the documentation to life. The day consisted of myself and Robert Fieldhouse, visiting Stonehenge to meet with English Heritage personnel. Our goal was to visit all the required locations of the site, capture the latest up-to-date information to enhance the current plans and check or highlight any –  

RAIDOs:            Risk   |   Assumption   |   Issue   |   Dependency   |   Opportunity

RAIDO icon

There is nothing like visiting in-person to give a real understanding of how a site works, including the day-to-day operations and the services between different buildings. This visit also provided further opportunities to review each building’s communications (comms) cabinet, the available access, and physical work required.

During the site visit, up-to-date audit tests were conducted to fill-in any missing information from previous documentation provided, and to confirm the current known or any unknown information from previous documentation and configuration captures. A physical audit both by sight and on the devices themselves, highlighted RAIDOs that would not have been otherwise known. These could then be resolved or planned beforehand to ensure the smooth running of the project.

Audit and Assurance

PuTTY was certainly a valuable tool used throughout the project, during audits, the installation itself, including the pre and post checks, and setting up the devices. PuTTY is a brilliant free tool very widely used, that not only connects and manages systems but can record keystrokes capturing each query saving these into a file. This is a useful feature for keeping a reminder of all the tests whilst providing a record that can be shown to clients to demonstrate the status of the devices before and after changes.

Recording tests in PuTTY requires making a couple of selections before starting a session by selecting:

Logging > All session output >

Create a Log file name: (see below example putty.log)

Return to Session. Enter the host information to connect to.

Unticking the Include header box can also help to keep the file more organised.

When happy with the selections, select Open to begin your tests / configuration checks. PuTTY will then start recording the session output including any text entered.

Screenshot of the PuTTY tool used.

After completing each test, a backup text file of the current configuration was created in the flash memory location, for example:

Screenshot of flash memory location example.

Press Enter when happy with the information, to create a backup of the current configuration should it be needed later for any reason.

ITSUS Expertise

Early in the project I noticed my colleague’s meticulous planning, vast knowledge of devices and extensive experience. Within moments of viewing the first comms cabinet during the first audit, Robert recognised the architecture, identifying each device, the setup, and various network ports and their probable uses, followed by physically logging into the device’s management ports to confirm them, as if having worked on the site for years. Robert’s experience designing and working on network solutions was evident throughout this and subsequent visits, having previously worked on military projects and assignments including NATO. Not only showcasing high-level of expertise understanding complex designs, but genuine enthusiasm to produce the very best results in everything, always going the extra mile. Exceptionally detailed designs (written in record time for the client) were a testament to this.

New Opportunities and Tailored Designs

From conducting the physical site audit, the high-level and low-level designs (HLD/LLDs) were then populated with the latest confirmed information. The re-design for the site included increased security, upgraded physically and digitally, with the latest technologies and redundancies. This information fed into further documentation laying out the strategic plan moving forward, including detailed plans for timings, testing, contingency plans, each step in order, including what service would be affected at each stage keeping the client informed.

Partnership Working

Throughout this time, regular meetings were held and clear documentation produced, updating the client informed at each stage. Documentation timescales were brought forward and completed earlier than planned. Once again, I must highlight my colleague’s work, as the feedback given by the customer highly praised the plans and documents that were produced. The thoroughness and details of the planning and reports were particularly noted. Speaking to my colleague, I learnt that his working practices have been shaped by prior assignments for the MOD and other defence-related contracts, as well as his personal experience over the past 15 years. Handling very in-depth information and stringent requirements becoming a daily routine.

The Importance of Planning

The things you do not often hear about: Rollback Planning.

Although no rollbacks were anticipated, each stage included plans for rollbacks and subsequent testing, with detailed timings and procedures for each outage. Nothing can be 100% known, there can be external power outage for example, which can occur without notice, or rare unknown unknowns. I believe that the meticulous planning throughout the project was the primary reason no rollbacks were necessary, but still vitally important to include.

ITSUS Internal Lab and Testing Phase

Following on from the initial planning stages, hardware was shipped to ITSUS HQ, unboxed and physically setup in a network lab to mirror the proposed live environment as close as possible, setting up the devices, conducting multiple tests.

Although I cannot write more detail here for security reasons, the setup and testing phase was an extremely valuable and enjoyable process getting hands-on with the equipment, I learnt a lot during this time.

Further return visits on-site by myself, Robert, and Senior Consultant, Richard John, allowed the safe return of the hardware, preparations, and final checks ready for the migration.

The Migration and Implementation

The migration dates finally arrived, meeting staff onsite, followed by carrying out prepared test plans and documenting the outcome, whilst waiting for the outage times to arrive to conduct the main body of work. These tests were vital, to not only show the state of the network before the upgrades, but also after the migrations, including a capture of every keystroke made within the handy recorded PuTTY files for future reference.

To maximise the time available before the main outage, unaffected sites were visited and work began labelling network cables before removal, followed by removal and replacement of the hardware, re-instating cabling and post checks before the main outage.

The time outage arrives. More labelling of cables, pre-test, configuration captures before and after replacement of hardware, including a tidy of the cabling, which over the years, had turned into a spaghetti junction. I asked the question on how network sites often become a mass of tangled cables. I learnt that the issue can sometimes be due to multiple years of contracts where work is conducted by different agencies, but cabling not being specified as part of the contract to ensure that adequate time and cable tidying are accounted for. Therefore, the job can sometimes be completed in  the fastest and most cost-effective manner, often leaving the cable management in such a way that it is applied by the quickest route, with several meters of cables being used to connect smaller distances or vice versa stretching cabling across blocking physical access of the network ports, making future work extremely difficult and precarious for the data it serves. Back to the migration, each device cable labelled ready and power cables located, the physical swap of hardware began. Working together to remove and replace each device. It was particularly useful to work from each side of the devices routing cables, finally replacing the hardware, and setting up the new structures of ordered cabling. With the cables already labelled, the replacements were swift.

Image of cables.

There were three elements of the migration that stood out for me, the first night of the migration where most of the replacements took place, the before and after result of the worst affected comms cabinet with the tangled cables, followed by preparations leading to the final installations and implementing a new Managed Service.

A New Managed Service

Part of this project gave rise to the opportunity of creating a Managed Service for English Heritage, where ITSUS will continue to assist with the network architecture prioritising device availability. Again, I cannot go into too much detail here but would like to say thank you to those people involved. This is another area where I am proud to have been part of this project, to have had the opportunity to work alongside highly skilled ITSUS Engineers and Consultants helping to create a new Managed Service milestone for ITSUS.

ITSUS are growing our Managed Service capabilities, and Stonehenge makes an exciting addition to this portfolio.

Image of Stonehenge at night.

Final Thoughts

Many thanks to Shahid, Robert, Richard, Paul, all those involved throughout the project at ITSUS, and English Heritage for making it possible to be involved in this important project. I have gained valuable knowledge and skills from this experience and hope the ITSUS English Heritage partnership continues for future collaborations.

Working with ITSUS really is ‘Secure Communications, Expertly Delivered.’ Expertise in delivering Networks and Cyber Security solutions with a team of highly experienced Engineers and Consultants who take pride in each project, delivering defence quality solutions with precision and care.

If you would like to enquire about the solutions that ITSUS provides, or discuss future opportunities or requirements, please reach out to our team. Ask for our latest service catalogue or let us know what you need.

Natalie is a Cybersecurity Consultant with over 20 years experience providing IT & cyber support and developing technology services.

More Articles

People sat around a table in a meeting room

How SLRs and BAS Strengthen Resilience

Recently, ITSUS Consulting has been demonstrating two solutions that can help organisations strengthen cyber resilience. Palo Alto’s – Security Lifecycle Review (SLR) and Keysight’s Threat Simulator, Breach and Attack Simulation (BAS).

Read More »
Cyber Security Background with Padlock

Palo Alto Networks’ Prisma SASE 3.0

We live in an era where complex digital transformation and remote working are the norm, offering new opportunities for empowering workers, but also bringing increased challenges in IT management and security to organisations.

Read More »