Jump to content

Recommended Posts

Posted

I am looking into the possibility of setting up VLANs on my network but I'm unclear on a few things.

 

Background

 

On the device side at the moment my network has:

 

 

  • 7 servers (2 physical, 5 virtual)
  • 45 laptops
  • 77 desktops
  • 24 printers
  • 5 iPads
  • 5 IP phones (the rest are digital)
  • 2 NASs

 

We will soon be purchasing 30+ additional iPads and possibly a CCTV system with at least 3 cameras. We have a new Ruckus wireless network with 10 access points. For switches I have 3 HP 2920-48G (linked with 10GB fibre), 2 HP 2530-48G and 2 Netgear GS724TP (4GB link agg.) There are a few classrooms and offices that do not have enough network points and so Netgear Gigabit desktop switches are used. There is no possibility of rewiring.

 

I have a 10.xxx.xxx.xxx /23 IP range though I have been told I can only use half for curriculum so 250 addresses are being wasted because we only have a couple of admin PCs on the LA admin network.

 

There are no issues with the way the network is currently set up but I think that adding a lot more Apple devices and CCTV cameras may cause performance issues with broadcasts etc. This is something I have never done in the real world, having only very briefly set up VLANS on Cisco switches at university.

 

I’ve done quite a lot of research into VLANs, including reading the threads on here. A lot of people seem to be setting up VLANS this year!

I’ve read conflicting advice; some people say that all data devices (servers, PCs, printers) should be together in a data VLAN. Other people say that servers and printers should be in their own VLANs. I’m more inclined to go with the first option, at least at first.

 

I think I’d like:

VLAN 1 – nothing (best practice, apparently)

VLAN 2 – management

VLAN 3 – data

VLAN 4 – VOIP

VLAN 5 – CCTV

VLAN 6 – Apple

VLAN 7 – internet only (for guest WiFi)?

 

Does anyone have any comments on this? Does the naming scheme and classification look okay?

 

Secondly, how do VLANS play with unmanaged desktop switches? Even in my own office I have a VOIP phone, NAS and my PC on the same desktop switch because there is only one wall point. I don’t want to connect my PC through the phone because I don’t want it limited to 100Mb. The phone has the ability to work with VLANs. If a switch figures out which VLAN a device is in by the port it is connected to how would it work with multiple device types connecting to the port? I can't get my head around it.

 

Thanks in advance!

Posted (edited)

VOIP phones are normally tagged on voice and then any non tagged data is passed through so you can have a PC plugged in on different vLAN.

 

Some UnManaged switches do support vLANS and I think the GS724TP does, I think you are along the right lines with what you have done.

 

Use one of the switches to do your vLAN routing to route traffic between the vLANs. There are plenty of threads on here which should point you in the right direction.

 

As you are a bit governed by the LA you may need them to do some stuff on firewalls/routers for you

Edited by Davit2005
Posted

I think you have too many vlans. It would be ideal to separate all that traffic but for 150 devices i don't think it is worth the hassle.

 

You need to remember which ports are on which vlan, plugging it into the wrong one without tagging it will cause problems. You definitely need one for the guest wifi, the others are just ideal if you are good at record keeping!

Posted (edited)
I think you have too many vlans. It would be ideal to separate all that traffic but for 150 devices i don't think it is worth the hassle.

 

You need to remember which ports are on which vlan, plugging it into the wrong one without tagging it will cause problems. You definitely need one for the guest wifi, the others are just ideal if you are good at record keeping!

 

 

It's true it's a lot of effort, but at the same time what the OP is proposing is pretty close to best practice. If the OP has a fairly small network then a) record keeping is not tedious b) there is probably time available to expend the effort!

 

I would probably have split it out the same in all honesty, and depending if you had lots of printers, you could split those off too.

 

Oh, and depending on what your router is, you might want to set up the guest internet vlan to bypass all of your internal services and pick up it's DHCP/DNS from your router instead as it is guest.

Edited by Oaktech
Posted

Looking at this... I'm inclined to think key point is "Secondly, how do VLANS play with unmanaged desktop switches?" - as that's going to mean that all data hitting that unmanaged switch is going to need to have been tagged when leaving the device that sends it right?

 

We are also talking a small number of devices.

 

I'm inclined to think that 3-4 VLAN's probably make sense and keep it simple:

 

1) VLAN -> "Public/Guess Wifi" -> non-school owned devices etc can sit on here. IF switches allow, keep seperate to being able to hit main network

2) VLAN -> "Private/School Wifi" -> school owned devices live on here - that's 45 laptops + 35 ipad's

 

That would mean that AP's would need to be able to tag devices to 2 vlan's, and I'll assume the AP's go directly into one of the HP switches (and not hit the desktop unmanaged switches)

 

This then leaves the following devices:

 

7 servers (2 physical, 5 virtual)

77 desktops

24 printers

5 IP phones (the rest are digital)

2 NASs

 

i.e. 100 devices.

 

At which point, unless the network is going to grow a lot, I'm kinda thinking it's probably not worth the hassle of trying to split those into multiple vlan's (especially given the unmanaged kit knocking around). Also assuming from the numbers it's likely to be a primary school so kids aren't going to be fiddling too much. So Vlan 3 would then 'hard-wired devices' basically

 

That splits off the wireless (where you might care about broadcasts) and the wired - without having to worry about updating things if stuff moves around..

 

Equally as Oaktech says - for such a small network, could easily put in the effort to do things properly.

 

IF you could keep existing ip's on devices, and add new vlan's with different ip's for private/public wifi, i'd probably be inclined to keep the devices together. If you need to change everything's ip etc, splitting out completely might be a better way to go (assuming the unmanaged switches knocking around don't then cause issues)

  • Thanks 1
Posted
I used 1810 HP's at last place, they support vLANS and are un-managed. 1810's aren't the best to work with but I also have a few at home on which I have multiple vLANS coupled to a Cisco Layer 3 switch and they work fine.
Posted

Printers tend to be very noisy on the network so that's usually one of my first ones to VLAN off.

You might want to download Wireshark and see what the traffic is like on your network which will help you to decide how to split it.

Posted

Thanks for all the advice everyone. I think I'll follow minimoo's advice and get the wireless network VLANed off. At the minute we don't really have guest WiFi because they still hit the Lightspeed filter at the other end of our internet connection which authenticates against our AD meaning they need to have a school username & password. Our network is likely to grow but any new devices are likely to be laptops.

 

Ideally I'd have printers, VOIP and servers/PCs in seperate VLANs but for now at least it's going to be too much hassle with the 5 or 6 rooms relying on desktop switches.

 

I've checked the amount of broadcast packets my PC is receiving (and it's not too many to be honest). I suppose I should port-mirror on the core switch and do it properly though.

Posted (edited)

We don't have any unmanaged switches, but we use both HP 2920s and 2530s like you, in roughly the same size environment. I kept our servers, client machines, and printers as untagged VLAN 1 (no point separating them out for this small an environment), but created other VLANs for DMZ, CCTV, Voice, WiFi, and management access (for things like iLO/DRAC and UPSes). I then used QoS on our switches to give CCTV and voice higher priorities than all other VLANs.

 

I quite like this setup for our environment, but I'll be rethinking it next year when building starts for our expansion.

 

In your position I would look at getting rid of the unmanaged/web managed switches in favour of some more managed HP switches if your budget allows (since you can't pull more cable). Your VLANs look good, but I would keep the 'Apple' devices in your WiFi VLAN unless you start getting Apple TVs (they get quite chatty).

 

Don't forget to implement STP!

Edited by Blue_Cookeh
Posted

I would add a couple more VLANs:

 

MGMT VLAN (For Switching)

SVRMGMT

Staff VLAN (Wireless SSID)

Student VLAN (Wireless SSID)

Printer VLAN

Projector VLAN

Posted
I would add a couple more VLANs:

 

MGMT VLAN (For Switching)

SVRMGMT

Staff VLAN (Wireless SSID)

Student VLAN (Wireless SSID)

Printer VLAN

Projector VLAN

 

If some is good, more must be better right! :)

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...