Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Recommended Posts

Posted

Hello!

I am a newbie in networking and I am currently working on one private school network design (wired and wireless combined).

 

I would like to get some feedback that what I am doing is correct or at least reasonable.

 

Boarding school (students dorms including). 100 students, 25 employees. Hardware: mainly cisco (catalyst 3550;3500, 2900, 2950). Core switch (layer 3), others layer 2.

VLANs - management (IP-hosts- 64), employees (IP-hosts- 64), students (512), guests (256).

Management VLAN1:Network: 192.168.1.192/26; Hosts: 192.168.1.193-254 (62)

Guests VLAN2: Network: 192.168.2.0/24;Hosts: 192.168.2.1 - 254 (254)

Employees VLAN3:Network: 192.168.3.192/26;Hosts:192.168.3.193-254 (62)

Students VLAN4: Network: 192.168.4.0/23; Hosts: 192.168.4.1 – 5.254 (510)

Network.jpg

1. Can I take just like that an IP address and start to subnet in my network (like I did above)?

2. Should I put a switch between core switch and server/wireless controller?

3. How does the wired network identifies who is using it (teacher, student or guest)? In wireless they log in with their SSID but what about classroom/library wired outlets?

4. Could I use the software based cisco built-in firewall also or is separate firewall box more worth?

5. What would be easiest tools to manage the small network?

6. We have one school server(windows server 2012) with database and shared storage (using SMB). What would be a smart backup system for that?

 

I am very thankful for help and any advice :-)

Posted

Your switches should not be wired like that - where 2 access layer switches are daisy chained, rather the access layer switches should each connect to the core / distribution switch.

 

Unless you're internal network ip addresses are assigned by someone else I would just use a /24 for each subnet.

 

The VLANs would be created on the Core switch and each VLAN which requires routing would have a virtual interface assigned to them. These virtual interfaces would point to the DHCP server on your network so that when a client requests a IP from a VLAN they will be assigned an IP as defined in your DHCP server for that scope.

  • Thanks 1
Posted

Thank You for the advice Muz!

I was planning to subnet it like this because not to waste hosts (according to needs). How can you use each subnet /24 if students subnet would need at least 450 hosts. Should not that be /23 in order to reach 510 hosts?

Most of the users are using their own laptops. That is what I do not get - if I am a guest and plug my cable in for example in the library outlet, I should get straight access to internet. How does the core switch identify (and DHCP sends me an IP from guest subnet scope) that I am the guest not a student and directs me to Guest VLAN?

Posted

You can use a /23 if you want but it's not recommended for wireless subnets.

 

Ports on the access layer switches will be assigned to the required VLAN, for example you can have a WAP on VLAN 3 which may be 10.21.21.0/24 and therefore if your DHCP server has a scope defined for that subnet then you will get an ip address for it. The VLAN interface will point to the DHCP server so it will not actually be doing the DHCP.

 

The VLAN interface channels all the traffic from the VLAN and routes it to the router, this is how devices from the VLAN get internet access.

 

The only way you can authenticate users like you want on the wired VLANS is to use a RADIUS server and 802.1x on your switches, this way wired devices would be placed into a guest VLAN until they were authenticated with the RADIUS server.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...