Jump to content

Recommended Posts

Posted

Hi Everyone,

 

so it's come to the point where we need V-lans.

 

i understand the concept (hence knowing it's time to implement them) but am not really sure what to do for the best,

 

as we have over 500 devices and only 12 cab locations i was thinking of segregating the network in two ways.

 

1. by cab location

2. Or Device location I.e It Suite etc

 

if i go for option 1 would i just need to put all ports into say vlan 2 and leave the uplinks on the default vlan 1 ? so other traffic can pass ?

 

so my setup would look something like

 

Cab 1 - All ports vlan 2 uplink(s) vlan 1

Cab 2 - All ports vlan 3 uplink(s) vlan 1

Cab 3 - All ports vlan 4 uplink(S) vlan 1

 

Or option 2 would be cab 1 switch 1, ports 1-20 vlan 2 uplink vlan 1 ports 21-47 vlan 4 etc

 

any help ideas, or best practice much appreciated as always,

Posted

The way we do it is:

 

Servers

Printers

Wireless (8 vlans)

Boilers

TVs

VoIP phones

Admin PCs

accounts PCs

ICT tech PCs

Catering Tills

Curriculum PCs (separate vlan per building, 10 buildings)

Internet router

  • Thanks 1
Posted
so it's come to the point where we need V-lans.

 

Why?

 

Not sure what would be best the switches support l3 routing so can i use that or would i be better investing in a separate router

 

Stick with a good L3 Switch, as effectivly it is a router with multiple ports. Unlike a router which ususaly has limited port capacity which can become a problem.

 

Rob

Posted

As we already use Sonicwalls at our border gateway we use this to provide DHCP and inter VLAN routing, on many of our smaller sites its just easier to manage.

On bigger LANs the L3 switch is obviously the better option.

Using a simple router between port based VLANs is a good way to start and learn but L3 switches have far more throughput capability and cope with many VLANs easily.

Posted

Hi all thanks for your input. we need to implement the vlans as the broadcast traffic is quite high and the performance is starting to drop slightly i want to regain the performance (and all being well improve it) by implementing vlans i feel this would be the best way forward as we have good switches which like many we currently only use a fraction of the functionality available (Stacking, RSTP & Qos) am planning on using the l3 routing on the switches.

 

cheers

Posted
The way we do it is:

Admin PCs

accounts PCs

ICT tech PCs

 

Why do you make a separate vlan for each of these? There's no real security benefit behind it considering everything can be secured at a file and authentication level so why would you need to add these to separate vlans from their local areas?

 

Genuine question by the way, I'm not trying to sound argumentative.....though i can't help but see this as a mostly pointless exercise that it seems many here partake in, some even taking it to another level by splitting teacher and student machines vlans. I'm more interested in being convinced otherwise than trying to convince others that they're wrong in doing so though, but i remain very skeptical :)

Posted
Hi MrBios ! well personally i agree it comes down to need & choice. I want to segregate areas of the LAN to improve performance primarily the security benefit comes in as an additional definitive layer by giving the ability to effectively "hide" different devices / sections of the network from each other you are ensuring a more complete security structure throughout the Lan but by doing so your obviously adding an additional layer of management and complexity (depending on how its setup and also what the documentation includes) i have worked in a school with over 100 vlans. (in my view uber excessive) wherby admin printers were egregated from student printers!
Posted
i have worked in a school with over 100 vlans. (in my view uber excessive) wherby admin printers were egregated from student printers!

 

rediculous rather than excessive.

 

we only have about 8 major vlans ( if that )

 

what is you switch processor load, the droped packets, crc, runts , etc.

 

appart from boot dhcp, what are the sources of the broadcasts?

 

Rob

Posted (edited)
Hi MrBios ! well personally i agree it comes down to need & choice. I want to segregate areas of the LAN to improve performance primarily the security benefit comes in as an additional definitive layer by giving the ability to effectively "hide" different devices / sections of the network from each other you are ensuring a more complete security structure throughout the Lan but by doing so your obviously adding an additional layer of management and complexity (depending on how its setup and also what the documentation includes) i have worked in a school with over 100 vlans. (in my view uber excessive) wherby admin printers were egregated from student printers!

 

I can understand the desire to hide a device from another device, if that device held anything of importance on it, but are your users in accounts really storing sensitive data on their client PCs anyway? Probably not, because most of the time we have network storage, things like FMS have everything stored in a database, that database requires authentication and is also held in a server, those servers are on a separate vlan....you see what I'm getting at right?

 

End of the day i think my real question is what are you actually trying to protect? I can obviously only speak for myself here but the only sensitive data on my network is either A. in teacher shares/home folders or B. in SIMs/FMS both of which are secured from prying eyes with share security, file level security, database authentication etc. Those sensitive items are only visible to a client PC once a user has logged on, nothing sensitive is on the machines themselves. So where's the security benefit?

 

The benefits to limiting broadcast traffic from PCs isn't going to be anywhere near as great as the benefit to limiting service broadcast traffic such as printers, tv systems, apple devices etc, so again from a performance standpoint i'd still argue that the additional management complexity isn't worth the effort. Especially when talking about admin/finance/office PCs we're taking 10s of PCs not 100s.

Edited by mrbios
Posted

Close, its one of the core switches for just one site but we are doing layer 3 to the edge via OSPF so each uplink has its own vlan.

 

Our edge switches probably have between 12 to 16 vlans (Data,Voice,CCTV,IPTV,Printers,Cashless Vending,Wifi,Guest Data, Guest Wifi,Management, Plus 2 to 8 uplinks)

Posted

We did it by cab with /24 VLANs when we did it 18 months ago, so (for example) MFL is all on one VLAN because it comes out of one cabinet in that block, same with English, Humanities... the only exceptions are major IT rooms, which tend to have a switch in situ for a single room so they're on /25 ranges, and printers which are on their own VLAN across the site - random ports here and there on every switch, with different colour patch cables for them.

 

We route at the furthest point - i.e. if a cab has stacked level 3 switches that service an entire VLAN, route there. If a VLAN spans multiple non-stacked switches then it has to be routed at the core (e.g. printers, some cabs with older switches). Saves on traffic on the backbone.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...