by
immad girach , Assistant Director , Federal Government
in order to secure your enterprise network perimeter, I recommend the following:
install firewall between users and internet, so that policies can be made to allow who accesses what.
use VLANS in the network so that every department is isolated from others. Things like malicious broadcasts and sharing violations don't affect other departments.
use switchport security feature to lock the workstations with MAC addresses.Nowadays, almost all enterprise switches provide the said feature.
maintain and view daily network access log.
keep backup of configuration files and other important data at a safe location.