bogart88 Posted June 23, 2014 Posted June 23, 2014 I have inherited network running 10.0.0.0/16 in one building with about 500 nodes is it worth my time to create separate vlans for wireless,printers,desktops etc?
mikeyd101 Posted June 23, 2014 Posted June 23, 2014 In my experience no, just 1 extra thing you have to deal with. We had huge issues with incorrect vlan configurations at our High School Campus, so we were a bit burnt by vlans and may effect recommendation. We have simplified to 1 vlan per campus site and our wifi merged with no guest access. Possibly with the exception of wireless, if you want more control on that then it may be worth a vlan.
mrbios Posted June 23, 2014 Posted June 23, 2014 (edited) Yes, absolutely! Don't over complicate it though, keep it simple, printers, wireless, door access control systems, infrastructure, segmenting different building or sites etc. Anything simple that will cut out broadcast traffic. One thing i would not recommend though is what i've seen once or twice on here, and that's different vlans for student and teacher PCs. Well over the top and over complicating things in my opinion, can only see something like that causing headaches for no great benefit. Edited June 23, 2014 by mrbios
rob_coles Posted June 23, 2014 Posted June 23, 2014 We've got geographical vlans, IT suites, buildings & guest access and voip. Mainly to reduce broadcast traffic. Keep it simple
DMcCoy Posted June 23, 2014 Posted June 23, 2014 Yes, absolutely! Don't over complicate it though, keep it simple, printers, wireless, door access control systems, infrastructure, segmenting different building or sites etc. Anything simple that will cut out broadcast traffic. One thing i would not recommend though is what i've seen once or twice on here, and that's different vlans for student and teacher PCs. Well over the top and over complicating things in my opinion, can only see something like that causing headaches for no great benefit. Benefits include: Different ACLs allowing students/teachers access to different servers/resources Different filtering/firewall rules based on student/teacher subnets Windows firewall ACLs based on subnet, eg not allowing student machines smb access to staff machines (I'm sure you use different user/pass for local admin users on staff/student builds, so this is less of an issue - admin on one local, admin on them all and profiles become vulnerable). I found it to be worth the time, it's just another vlan after all, but I was using 802.1x for automatic vlan assignment based on machine group membership, so it didn't take long.
mrbios Posted June 23, 2014 Posted June 23, 2014 Benefits include: Different ACLs allowing students/teachers access to different servers/resources Different filtering/firewall rules based on student/teacher subnets Windows firewall ACLs based on subnet, eg not allowing student machines smb access to staff machines (I'm sure you use different user/pass for local admin users on staff/student builds, so this is less of an issue - admin on one local, admin on them all and profiles become vulnerable). I found it to be worth the time, it's just another vlan after all, but I was using 802.1x for automatic vlan assignment based on machine group membership, so it didn't take long. Seems like a big over complication of the network configuration when all those things can be done through easier to manage and customise methods. One question for you though, what happens if a student logs into a teacher PC? Do the instantly get teachers filtering rules or are you combining the subnet rules with user based rules? (which would seem like you'd just be doing the same thing twice but in different ways)
robjduk Posted June 23, 2014 Posted June 23, 2014 can cause issues in some cases but from my school's experience it is good to VLAN your wireless at minimum. We had a ruckus deployment and it completely fell on its arse until VLANS were made. Im considering adding a VLAN to our media departments iMacs soon.
DMcCoy Posted June 23, 2014 Posted June 23, 2014 Teacher machines that were just classroom machines had the same access as student machines, it stopped staff wondering off with outlook open, whiteboard machines had custom desktops to avoid all those helpfully named files on the desktop when smt login on a board. Drive mapping was controlled via subnet too so there was less mapped when logging into a student subnet, along with the multiple server subnets. Internet filtering was a combination of user and a small number of subnet rules. It *can* be complicated yes, but it doesn't have to be if you plan carefully. Vlans are just repeating the same process each time so the number doesn't matter as long as it's reasonable enough to still see an overview of what is allowed where. It's really useful when you apply it to things like item level targeting with gpp.
newpersn Posted June 23, 2014 Posted June 23, 2014 We vlan ' ed about 2 years ago. Each floor on its own. It rooms on there own Wireless on its own. Servers are on its own. Best move ever. Worth the time it takes to set up.
Jasbo Posted June 24, 2014 Posted June 24, 2014 We are looking to vlan to separate wifi and servers this summer, looking forward to it... Kinda :s
simpsonj Posted June 24, 2014 Posted June 24, 2014 Apologies for the slight thread hijack, but can anyone point me at a good 'teach yourself vLanning' website, book or training course? I'm pretty keen to vLan off the wireless and servers myself!
fiza Posted June 24, 2014 Posted June 24, 2014 @simpsonj Try this : How Virtual Local Area Networks (VLANs) Work - For Dummies 1
featured_spectre Posted June 24, 2014 Posted June 24, 2014 In my old school we did it, and colour coordinated everything also. Printers/MFDs were Red Thin Clients were Orange VOIP was Yellow Telephones/Faxes were Green Servers were Blue VPN was Purple Class Rooms with PCs were Black (includes science, english, maths, IT etc) Wifi was Grey DMZ was White
Gibson335 Posted June 24, 2014 Posted June 24, 2014 VLANs can be useful, but can also be overcooked. They can also be a bugger to remember during that brief moment of panic when something goes wrong. Planning and recording are the key. 1
dcsdne Posted June 24, 2014 Posted June 24, 2014 I vlan Wifi into different segments to control BYOD, Staff then students. I will probably expand soon. My feeling with VLANing is if you are comfortable then go for it. VLANing can provide some really nice control, but you do expand your config. I administrate about 200 switches procurve/enterasys. Just make sure to back up your configs.
pete Posted June 24, 2014 Posted June 24, 2014 Yes, it's worth it. We split VOIP, CCTV, storage (NFS/iSCSI), management, monitoring and test* off into separate VLANs. At the moment I'm planning an 802.1x implementaton so that when we BYOD, it doesn't matter whether it's a wired or wireless client, it gets slung in the correct VLAN.
bogart88 Posted June 26, 2014 Author Posted June 26, 2014 Thanks all great advice.... I am going to do vlans mostly because of the wireless and the mac lab
HTCPCP Posted June 27, 2014 Posted June 27, 2014 All geographically VLaned here too. The only non geographical Vlanning is the Wifi, Servers, Cameras and printers which are site wide. Really glad we went down that route, managed to use it as an excuse to get the governors to fund a new core switch, some new cabling and replace the older switches around the school! Was a bit of a hassle to set up, partly down to us not paying enough attention when we were plugging in the workstations in one of our switches which caused a loop in the system.
Joanne Posted June 27, 2014 Posted June 27, 2014 I was involved in installing networks in new high schools earlier this year and the company we were subcontracting for did the VLAN thing and the colour co-ordinated patch cables. They had VLANS for everything. I always had to go in and change ports for them, it became infuriating. If it is your own, established network though, then it should be a breeze. Just plan it all out first. I was working with Huawei switches and they can only be configured via command line. Lovely. Make sure you know all the ip's for switches and get them all telnetted up, so you can access them remotely if needs be. Makes it easy to quickly change a port then. I think in an environment where there are lots of different types of traffic VLANS can be very beneficial.
DPrince Posted June 27, 2014 Posted June 27, 2014 We vlan here - very worthwhile. The key to it is to make sure it is all well documented. We have four network documentation folders (one in the server room, one for the senior tech, one for the NM, and one for my house, for remote support). It contains a list of all the switches with details, servers, printers, wireless units, plus a graphical representation for every switch showing which port is allocated to which vlan, along with details of certain port usage. Each switch cabinet has a similar diagram inside. It makes managing it all a lot easier!
ColinP Posted June 27, 2014 Posted June 27, 2014 Yes Vlans here - Nice and simple We have one for phones , one for windows network and one for ipads/apple-tv <- this made such an improvement on the quality of the connections 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now