+ Post New Thread
Results 1 to 8 of 8
General Chat Thread, Network progress in General; This week is going to be very interesting as I'm trying to implement my subnet, vlan and authentication changes all ...
  1. #1
    DMcCoy's Avatar
    Join Date
    Oct 2005
    Location
    Isle of Wight
    Posts
    3,421
    Thank Post
    10
    Thanked 486 Times in 426 Posts
    Rep Power
    110

    Network progress

    This week is going to be very interesting as I'm trying to implement my subnet, vlan and authentication changes all in one go.

    I thought I might add a few posts now and then of progress if anyone else is interested in 802.1x and procurves.

    Monday, day 1

    I changed all the ip addresses of the servers (all 20+) in line with their new ranges to match the vlans. I have split the servers across 2 VLANs one for general access servers and one for admin.

    Tuesday.

    I have the new HP5412zl sat on my desk.

    Most vlans have been created, ip routing has been enabled on the switch and those vlans that need it have been assigned an ip address and DHCP helper.

    ACLs: I am now experimenting with ACLs to block traffic from being routed to the admin VLAN from those that don't need access. This is a feature of the 54xx switches.

    ACLs working! I can apply ACLs to the vlans to stop traffic being routed to specified VLANs.

    Wednesday

    Today will be a reconfiguration of my ESX servers to bring them inline with the new vlans and their IDs on the new switch before I can start with 802.1x.

  2. #2
    DMcCoy's Avatar
    Join Date
    Oct 2005
    Location
    Isle of Wight
    Posts
    3,421
    Thank Post
    10
    Thanked 486 Times in 426 Posts
    Rep Power
    110

    Re: Network progress

    ESX boxes now have the new vlans and the virtual servers have the correct gateways and subnet masks.

    Routing is working between the relevant vlans and I have a default route on the switch to forward internet traffic to the firewall (spent a good 20 mins trying to get the internet working with it still plugged in to the *old* switch )

    DHCP is handing out addresses on the correct subnets and machines can login again. ACLs are off while i'm testing everything.

    Static routes have been put on the ISA and shorewall servers to return packets to the vlans as they can't have the gateway set as their vlan for obvious reasons.

    I'll dig out my test 2626 with a working 802.1x setup and test a few ports on the new switch today.

  3. #3
    DMcCoy's Avatar
    Join Date
    Oct 2005
    Location
    Isle of Wight
    Posts
    3,421
    Thank Post
    10
    Thanked 486 Times in 426 Posts
    Rep Power
    110

    Re: Network progress

    Got 802.1x working on a test port, I've had to present an interface from the radius server on the switch managment vlan otherwise the request appears to IAS from the gateway rather than the switches managment interface. I still need to test a connected switch as a supplicant but I'll probably get to that tomorrow.

    I'm still thinking about my guest vlan, I'm going to authenticate the machines rather than the users, so I'm going to need to have some domain and dhcp services available somewhere. I'm probably going to have to allow the guest vlan to be routed as I really don't want to start adding additional interfaces to a DC to allow ghosted machines to join the domain. I will probably use the ACLs to limit traffic from the guest vlan to only domain, dhcp, dns, PXE (for ghosting) to the specified servers.

    I'll probably change this round when I get a standalone 802.1x authenticator for windows.

    I'm also pretending the mac suites don't exist :P I know they have some 802.1x support but I suspect it has some hideous flaw as usual (like trying to make trunks or vlans work on os x).

    Hubs were just so much easier (only going to be one hub left after this summer! Just 3 more switches to go!)

  4. #4

    Geoff's Avatar
    Join Date
    Jun 2005
    Location
    Fylde, Lancs, UK.
    Posts
    11,802
    Thank Post
    110
    Thanked 583 Times in 504 Posts
    Blog Entries
    1
    Rep Power
    224

    Re: Network progress

    I'm also pretending the mac suites don't exist Razz I know they have some 802.1x support but I suspect it has some hideous flaw as usual
    http://docs.info.apple.com/article.html?artnum=303471

    Only catch is that you need to upgrade 10.4.6 or later.

  5. #5
    DMcCoy's Avatar
    Join Date
    Oct 2005
    Location
    Isle of Wight
    Posts
    3,421
    Thank Post
    10
    Thanked 486 Times in 426 Posts
    Rep Power
    110

    Re: Network progress

    Like I said, some hideous flaw

    I want to do machine authentication, user would allow non domain machines to be used by simply having a valid user account.

    All in all its completely usless, I should have expected as much.

  6. #6
    DMcCoy's Avatar
    Join Date
    Oct 2005
    Location
    Isle of Wight
    Posts
    3,421
    Thank Post
    10
    Thanked 486 Times in 426 Posts
    Rep Power
    110

    Re: Network progress

    Working on the guest VLAN at the moment. I have ghost working and enough services allowed through to a single DC to join the domain. Spent 2 hours trying to find the right combination of ports to open, also have to use a fixed rpc port for ntds. It seems joining the domain uses more stuff than the authentication list of ports from microsoft. I didn't want to allow all ports though so kept trying until I *think* its working.

    Supplicant switch after lunch. Then its the final list of additional vlans for the main areas of the school (plus wifi ones etc). Then I can start reconfiguring all the other switches.

  7. #7
    DMcCoy's Avatar
    Join Date
    Oct 2005
    Location
    Isle of Wight
    Posts
    3,421
    Thank Post
    10
    Thanked 486 Times in 426 Posts
    Rep Power
    110

    Re: Network progress

    A slight lapse in my usually well thought out plans last week. I don't want any other switches to be suplicants as that would restrict their uplink to one untagged vlan anyway. I got distracted by reading through the HP manual (not *all* of it). I will simply make the uplinks fully tagged with the relevant links as you would expect, and as I had previously tested!

    I've decided to remove the last of our unmanaged switches and the last 10Mb hub (yes! there is one left). I've picked the Procurve 2510-24s as temporary replacements for now as it enables the vlans and 802.1x, 1Gb uplink and actually fits in the existing cabinets.

    I've decided to just use a seperate vlan for the macs as until they get some idea of *system* level authentication then its not worth bothering with. I might investigate MAC based radius autentication for them instead.

  8. #8

    Join Date
    Jul 2005
    Location
    Leicestershire
    Posts
    50
    Thank Post
    0
    Thanked 0 Times in 0 Posts
    Rep Power
    0

    Re: Network progress

    only of vague relevence, but i wanted an excuse for starting to post again -
    I can highly recommend the cisco CCNA course for help with this sort of stuff (obv you've got to pull some strings to get your school to pay the £1500 fee - like the big red button threat or something).

    It covers sub and super netting, acl's, vlans, all the command line stuff, security, a bit of wireless, and loads of other useful snippets.

    Obv not many schools implement cisco kit, but i've only found 4 or 5 syntax difference between the HP CLI and the Cisco... Deffo a good partner to the procurve CLI.

    Also, it's the gatway to the £30k job... allegedly - not that i've found one yet

    there we go.

    cheers

    Adam

SHARE:
+ Post New Thread

Similar Threads

  1. Connecting a Windows network to an RM managed Network
    By Scruff in forum Wireless Networks
    Replies: 4
    Last Post: 8th February 2010, 11:53 PM
  2. Replies: 2
    Last Post: 15th February 2008, 04:22 PM
  3. Map network drives on wireless network
    By woody in forum Windows
    Replies: 24
    Last Post: 1st December 2007, 06:27 PM
  4. terminating CAT5E network cables in network cabinets
    By broc in forum Network and Classroom Management
    Replies: 7
    Last Post: 10th July 2007, 11:54 AM
  5. RM network with Vanilla Network
    By kevin in forum Wireless Networks
    Replies: 2
    Last Post: 29th March 2007, 12:54 PM

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •