techie08 Posted January 14, 2015 Posted January 14, 2015 Hi Everyone We currently run a flat network with about 600 devices and im looking at VLANing off the whole network. We current use the IP range provided by the LEA/SWGFL giving 2032 ip addresses i want to know if its better to subnet off this range or use something like 192.168.x.x? Thanks
FragglePete Posted January 14, 2015 Posted January 14, 2015 We did this over the Summer, it's made a massive improvement on the network as a whole but we did run into an issues with our ISP, SWGfL with regards to how we did NAT out on to their network. Essentially all our traffic was seen coming from one IP address which was then dealt with just one proxy server for filtering and caching at SWGfL - at busy times, this resulted in extremely slow internet performance. This is compounded by the unique way Swindon schools get their internet connectivity from the grid via the LEA. To resolve this, we introduced Sophos UTM Essentials (free edition) on an old server, which used NAT Masquerading so now each VLAN we have comes from a different IP address on our allocated range from SWGfL. Over time I've been segmenting the network into even smaller chunks to make things better. So far, so good. Just check with your ISP and talk to other schools in your area on the same ISP to see what their approach has been. Pete 1
mrbios Posted January 14, 2015 Posted January 14, 2015 (edited) Yes, definitely! I'd recommend using a 172.16.x range or something though, i may just be fussy in saying that but so many devices come with default 192.168 addresses that i don't like using that (You can ignore that advice though if you like) 172.16.x.x/19 internal network would likely be big enough and give you enough potential for lots of vlans. Then vlan internally so that printers etc are on their own and so on. Edited January 14, 2015 by mrbios 1
FragglePete Posted January 14, 2015 Posted January 14, 2015 Just to add, we use the 172.17.x.0/22 range for each subnet - with the X being the VLAN number so it's makes things a little simpler when trying to see whats going on where. Pete
mrbios Posted January 14, 2015 Posted January 14, 2015 Not to directly disagree with fragglepete, but i'd like to draw your attention to advice such as this: https://supportforums.cisco.com/discussion/9762951/broadcast-domain-size obviously dependent on the circumstances and what devices are in each vlan, but try and keep your vlans as small as your setup will allow.
FragglePete Posted January 14, 2015 Posted January 14, 2015 Agree with the sizing, it doesn't need to be a /22 and we certainly don't run enough devices in each VLAN to go up to the 1022 hosts it would support. None of our VLANs have more than 100 devices in each one. Pete
techie08 Posted January 14, 2015 Author Posted January 14, 2015 Thanks guys. Just out of curiosity, how many VLANs do you have? and what are they used for? I dont want any more VLANs that i have to just to keep it simple!
synaesthesia Posted January 14, 2015 Posted January 14, 2015 (edited) Wan-Curr? Reminds me of one of our computers being called AssHead. You can see why they're called that sensibly but can never look and not giggle.... 7 vlans here, servers, printers, wifi, cctv, site1 clients, site2 clients. Wifi is on a /20 (may as well think ahead; 1022 IPs is certainly not enough for secondary wireless with guest access). Each site vlan is /22 and everything else is /24 (we have isolated vlan I haven't included, that and the cctv are on /25) Frankly, most wireless devices won't have that much chatter on; the worst for chatter by a long way are printers; stick wireshark on that vlan and you just get spammed! Edited January 14, 2015 by synaesthesia
techie08 Posted January 14, 2015 Author Posted January 14, 2015 Here's my VLAN setup[ATTACH=CONFIG]28334[/ATTACH] Do your Switch IP address reside on the management VLAN? or another VLAN?
mrbios Posted January 14, 2015 Posted January 14, 2015 (edited) Thanks guys. Just out of curiosity, how many VLANs do you have? and what are they used for? I dont want any more VLANs that i have to just to keep it simple! 6 x vlans for separate buildings or site sections (5 buildings, one split in two virtually due to new build in 2009). None are larger than /24 3 x wireless vlans (Guest, internal secure radius auth, then the last one is ipads+learnpads that we own) of varied sizes, two are /23 and the other is /21 (guest). The wireless vlans all have spaces left in the choice of subnets i've used incase they ever need to grow. Same for a few of the building vlans. 2 x iSCSI vlans 1 x Print vlan 1 x Paxton door system 1 x ip backbone 1 x infrastructure vlan We used to have a video vlan for an old igmp TV system we had too but i got rid of that last year. Edited January 14, 2015 by mrbios
Muz Posted January 14, 2015 Posted January 14, 2015 Do not go bigger than a /24 per subnet, you're only asking for trouble if you ever have a infected computer / dodgy NIC. If your LEA uses the 10.x.x.x address space then you could always subnet 172.16.x.x address space.
rickypike Posted January 14, 2015 Posted January 14, 2015 yeah it made my giggle too but it was the best abbreviated name i could think of for a wide area network feed on the curriculum side and it keeps me amused everytime I log into Putty!!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now