Jump to content

Recommended Posts

Posted

Hi Everyone

 

We currently run a flat network with about 600 devices and im looking at VLANing off the whole network. We current use the IP range provided by the LEA/SWGFL giving 2032 ip addresses i want to know if its better to subnet off this range or use something like 192.168.x.x?

 

Thanks

Posted

We did this over the Summer, it's made a massive improvement on the network as a whole but we did run into an issues with our ISP, SWGfL with regards to how we did NAT out on to their network. Essentially all our traffic was seen coming from one IP address which was then dealt with just one proxy server for filtering and caching at SWGfL - at busy times, this resulted in extremely slow internet performance. This is compounded by the unique way Swindon schools get their internet connectivity from the grid via the LEA.

 

To resolve this, we introduced Sophos UTM Essentials (free edition) on an old server, which used NAT Masquerading so now each VLAN we have comes from a different IP address on our allocated range from SWGfL. Over time I've been segmenting the network into even smaller chunks to make things better. So far, so good.

 

Just check with your ISP and talk to other schools in your area on the same ISP to see what their approach has been.

 

Pete

  • Thanks 1
Posted (edited)

Yes, definitely!

 

I'd recommend using a 172.16.x range or something though, i may just be fussy in saying that but so many devices come with default 192.168 addresses that i don't like using that :p (You can ignore that advice though if you like)

 

172.16.x.x/19 internal network would likely be big enough and give you enough potential for lots of vlans. Then vlan internally so that printers etc are on their own and so on.

Edited by mrbios
  • Thanks 1
Posted

Just to add, we use the 172.17.x.0/22 range for each subnet - with the X being the VLAN number so it's makes things a little simpler when trying to see whats going on where.

 

Pete

Posted

Agree with the sizing, it doesn't need to be a /22 and we certainly don't run enough devices in each VLAN to go up to the 1022 hosts it would support. None of our VLANs have more than 100 devices in each one.

 

Pete

Posted
Thanks guys. Just out of curiosity, how many VLANs do you have? and what are they used for? I dont want any more VLANs that i have to just to keep it simple!
Posted (edited)

Wan-Curr?

 

Reminds me of one of our computers being called AssHead. You can see why they're called that sensibly but can never look and not giggle....

 

7 vlans here, servers, printers, wifi, cctv, site1 clients, site2 clients. Wifi is on a /20 (may as well think ahead; 1022 IPs is certainly not enough for secondary wireless with guest access). Each site vlan is /22 and everything else is /24 (we have isolated vlan I haven't included, that and the cctv are on /25)

 

Frankly, most wireless devices won't have that much chatter on; the worst for chatter by a long way are printers; stick wireshark on that vlan and you just get spammed! :D

Edited by synaesthesia
Posted (edited)
Thanks guys. Just out of curiosity, how many VLANs do you have? and what are they used for? I dont want any more VLANs that i have to just to keep it simple!

 

6 x vlans for separate buildings or site sections (5 buildings, one split in two virtually due to new build in 2009). None are larger than /24

3 x wireless vlans (Guest, internal secure radius auth, then the last one is ipads+learnpads that we own) of varied sizes, two are /23 and the other is /21 (guest). The wireless vlans all have spaces left in the choice of subnets i've used incase they ever need to grow. Same for a few of the building vlans.

2 x iSCSI vlans

1 x Print vlan

1 x Paxton door system

1 x ip backbone

1 x infrastructure vlan

 

We used to have a video vlan for an old igmp TV system we had too but i got rid of that last year.

Edited by mrbios
Posted

Do not go bigger than a /24 per subnet, you're only asking for trouble if you ever have a infected computer / dodgy NIC.

 

If your LEA uses the 10.x.x.x address space then you could always subnet 172.16.x.x address space.

Posted
yeah it made my giggle too but it was the best abbreviated name i could think of for a wide area network feed on the curriculum side and it keeps me amused everytime I log into Putty!! :)

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...