+ Post New Thread
Results 1 to 8 of 8
Wired Networks Thread, To VLAN or not to VLAN... that is the question! in Technical; We currently have two IP ranges provided by the SWGfL and due to the way they setup the routing through ...
  1. #1
    neilault's Avatar
    Join Date
    Apr 2008
    Location
    Newton Abbot
    Posts
    47
    Thank Post
    4
    Thanked 1 Time in 1 Post
    Rep Power
    0

    Question To VLAN or not to VLAN... that is the question!

    We currently have two IP ranges provided by the SWGfL and due to the way they setup the routing through thier router it turns out that all traffic on the secondary range is capped at 30MB speeds and therefore has very slow network access at busy times!

    SWGfL recommend that the routing is done at our network level via a layer 3 switch and to therefore VLAN the two ranges. Obviously this is a huge lot of work to configure each switch (we have over 50) and as I understand it each port will belong to a particular VLAN and would require planning.

    The other option as I see it, is to request a complete new IP range big enough to accomodate all the IPs we need and setup everything on this new range and therefore not need any routing. I know we would have to run both IPs on our servers until the external domain records were updated.

    To further complicate things we have BT installing a new VoIP system in the next couple of weeks and they have not suggested setting that up on a VLAN but woul dit be advisable to do?

    What would you do? VLAN or new IP range?

    Please help!
    Last edited by neilault; 7th April 2011 at 12:53 PM.

  2. #2

    nephilim's Avatar
    Join Date
    Nov 2008
    Location
    Dunstable
    Posts
    12,179
    Thank Post
    1,648
    Thanked 1,973 Times in 1,445 Posts
    Blog Entries
    2
    Rep Power
    443
    If you had the option to accomodate a larger IP range, and can change the IP ranges in all of the machines then do that. Go with VLAN second.

  3. #3

    Join Date
    Mar 2010
    Location
    Adelaide
    Posts
    133
    Thank Post
    2
    Thanked 19 Times in 17 Posts
    Rep Power
    13
    Assuming you have a largish network (based on 50 switches x 24 ports avg), I would begin thinking about introducing VLANs. On a flat network you're pretty much running on a single VLAN so adding a couple will still have you working until you begin moving over.

    Main reason would be to limit the impact of broadcasts. Depending on your network would could use VLANs to further segment it down to smaller areas.

  4. #4
    cpjitservices's Avatar
    Join Date
    Jul 2010
    Location
    Hessle
    Posts
    2,503
    Thank Post
    519
    Thanked 292 Times in 268 Posts
    Rep Power
    83
    yeah segmentation would be good

  5. #5

    Join Date
    Mar 2011
    Location
    Canberra
    Posts
    108
    Thank Post
    0
    Thanked 10 Times in 10 Posts
    Rep Power
    12
    Quote Originally Posted by _Adam_ View Post
    Assuming you have a largish network (based on 50 switches x 24 ports avg), I would begin thinking about introducing VLANs. On a flat network you're pretty much running on a single VLAN so adding a couple will still have you working until you begin moving over.

    Main reason would be to limit the impact of broadcasts. Depending on your network would could use VLANs to further segment it down to smaller areas.
    Wouldn't think...would be doing at this size...

  6. #6

    Join Date
    Jun 2010
    Posts
    66
    Thank Post
    1
    Thanked 6 Times in 5 Posts
    Rep Power
    16
    VLAN's are good to segment your network. mitigating broadcasts. You can also dice and slice your network introducing a security layer into the network.

    Ignoring the broadcast advantages, the alternative is to chuck in a single layer 3 switch and make your allocated IP address range, which you get 30Mb as a DMZ and choose your own address range and then use NAT. You can also throw in VLAN's on top. Using your own IP address range you can add transparent proxying if required.

    We use around 7 or so VLAN's for different functions, one is to keep Admin away from Curriculum machines.
    Last edited by bantonia; 18th March 2012 at 07:45 PM.

  7. #7
    IrritableTech's Avatar
    Join Date
    Nov 2007
    Location
    West Yorkshire
    Posts
    822
    Thank Post
    91
    Thanked 184 Times in 150 Posts
    Rep Power
    66
    Personally I would vlan. I'm guessing from the amount of switches, your network is fairly large? I like to vlan and reduce the broadcast domains on anything bigger than a /22 subnet.

    I'd also go for a new subnet from SWGFL (we did) because our LEA does not like natting addresses. They like to know what machine a request comes from.

    Speak to SWgfL they are there to help. They might also get you in touch with a neighbouring school who have had the same problem to fix.
    Last edited by IrritableTech; 18th March 2012 at 07:59 PM.

  8. #8

    Join Date
    Jun 2010
    Posts
    66
    Thank Post
    1
    Thanked 6 Times in 5 Posts
    Rep Power
    16
    Quote Originally Posted by IrritableTech View Post
    Personally I would vlan. I'm guessing from the amount of switches, your network is fairly large? I like to vlan and reduce the broadcast domains on anything bigger than a /22 subnet.

    I'd also go for a new subnet from SWGFL (we did) because our LEA does not like natting addresses. They like to know what machine a request comes from.
    I Agree, VLAN's the way to go but VLAN's tend to multiply and you end up NATing anyway. Whatever the LEA likes or dislikes, it is up to the School/College Leadership Team or the Network Manager to decide what goes. True the LEA might like to know where the traffic is originating so they can tie down security such as AVCO transfers but when the member of the admin team is absent and your finance person requires a transfer of documents then you are stuck to go to that one machine. By giving them the NAT address any one of your machines in those NATted address ranges can do the job if the software is installed.

    There are advantages of doing VLAN's, DMZ and NAT.

SHARE:
+ Post New Thread

Similar Threads

  1. HP Vlan Question
    By jwc1972 in forum Wireless Networks
    Replies: 0
    Last Post: 1st March 2011, 03:07 PM
  2. VLan question
    By Simcfc73 in forum Wireless Networks
    Replies: 7
    Last Post: 22nd October 2010, 11:50 AM
  3. QUICK VLAN QUESTION
    By andydis in forum Wireless Networks
    Replies: 3
    Last Post: 19th August 2010, 10:07 AM
  4. VLAN and ISA question
    By localzuk in forum Wireless Networks
    Replies: 0
    Last Post: 23rd October 2007, 01:33 PM
  5. vlan VoIP question
    By CyberNerd in forum Wireless Networks
    Replies: 4
    Last Post: 14th June 2007, 07:57 PM

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •