JordanT91 Posted October 19, 2015 Posted October 19, 2015 I am looking into the possibility of setting up VLANs on my network but I'm unclear on a few things. Background On the device side at the moment my network has: 7 servers (2 physical, 5 virtual) 45 laptops 77 desktops 24 printers 5 iPads 5 IP phones (the rest are digital) 2 NASs We will soon be purchasing 30+ additional iPads and possibly a CCTV system with at least 3 cameras. We have a new Ruckus wireless network with 10 access points. For switches I have 3 HP 2920-48G (linked with 10GB fibre), 2 HP 2530-48G and 2 Netgear GS724TP (4GB link agg.) There are a few classrooms and offices that do not have enough network points and so Netgear Gigabit desktop switches are used. There is no possibility of rewiring. I have a 10.xxx.xxx.xxx /23 IP range though I have been told I can only use half for curriculum so 250 addresses are being wasted because we only have a couple of admin PCs on the LA admin network. There are no issues with the way the network is currently set up but I think that adding a lot more Apple devices and CCTV cameras may cause performance issues with broadcasts etc. This is something I have never done in the real world, having only very briefly set up VLANS on Cisco switches at university. I’ve done quite a lot of research into VLANs, including reading the threads on here. A lot of people seem to be setting up VLANS this year! I’ve read conflicting advice; some people say that all data devices (servers, PCs, printers) should be together in a data VLAN. Other people say that servers and printers should be in their own VLANs. I’m more inclined to go with the first option, at least at first. I think I’d like: VLAN 1 – nothing (best practice, apparently) VLAN 2 – management VLAN 3 – data VLAN 4 – VOIP VLAN 5 – CCTV VLAN 6 – Apple VLAN 7 – internet only (for guest WiFi)? Does anyone have any comments on this? Does the naming scheme and classification look okay? Secondly, how do VLANS play with unmanaged desktop switches? Even in my own office I have a VOIP phone, NAS and my PC on the same desktop switch because there is only one wall point. I don’t want to connect my PC through the phone because I don’t want it limited to 100Mb. The phone has the ability to work with VLANs. If a switch figures out which VLAN a device is in by the port it is connected to how would it work with multiple device types connecting to the port? I can't get my head around it. Thanks in advance!
Davit2005 Posted October 19, 2015 Posted October 19, 2015 (edited) VOIP phones are normally tagged on voice and then any non tagged data is passed through so you can have a PC plugged in on different vLAN. Some UnManaged switches do support vLANS and I think the GS724TP does, I think you are along the right lines with what you have done. Use one of the switches to do your vLAN routing to route traffic between the vLANs. There are plenty of threads on here which should point you in the right direction. As you are a bit governed by the LA you may need them to do some stuff on firewalls/routers for you Edited October 19, 2015 by Davit2005
win Posted October 19, 2015 Posted October 19, 2015 I think you have too many vlans. It would be ideal to separate all that traffic but for 150 devices i don't think it is worth the hassle. You need to remember which ports are on which vlan, plugging it into the wrong one without tagging it will cause problems. You definitely need one for the guest wifi, the others are just ideal if you are good at record keeping!
Oaktech Posted October 19, 2015 Posted October 19, 2015 (edited) I think you have too many vlans. It would be ideal to separate all that traffic but for 150 devices i don't think it is worth the hassle. You need to remember which ports are on which vlan, plugging it into the wrong one without tagging it will cause problems. You definitely need one for the guest wifi, the others are just ideal if you are good at record keeping! It's true it's a lot of effort, but at the same time what the OP is proposing is pretty close to best practice. If the OP has a fairly small network then a) record keeping is not tedious b) there is probably time available to expend the effort! I would probably have split it out the same in all honesty, and depending if you had lots of printers, you could split those off too. Oh, and depending on what your router is, you might want to set up the guest internet vlan to bypass all of your internal services and pick up it's DHCP/DNS from your router instead as it is guest. Edited October 19, 2015 by Oaktech
minimoo Posted October 19, 2015 Posted October 19, 2015 Looking at this... I'm inclined to think key point is "Secondly, how do VLANS play with unmanaged desktop switches?" - as that's going to mean that all data hitting that unmanaged switch is going to need to have been tagged when leaving the device that sends it right? We are also talking a small number of devices. I'm inclined to think that 3-4 VLAN's probably make sense and keep it simple: 1) VLAN -> "Public/Guess Wifi" -> non-school owned devices etc can sit on here. IF switches allow, keep seperate to being able to hit main network 2) VLAN -> "Private/School Wifi" -> school owned devices live on here - that's 45 laptops + 35 ipad's That would mean that AP's would need to be able to tag devices to 2 vlan's, and I'll assume the AP's go directly into one of the HP switches (and not hit the desktop unmanaged switches) This then leaves the following devices: 7 servers (2 physical, 5 virtual) 77 desktops 24 printers 5 IP phones (the rest are digital) 2 NASs i.e. 100 devices. At which point, unless the network is going to grow a lot, I'm kinda thinking it's probably not worth the hassle of trying to split those into multiple vlan's (especially given the unmanaged kit knocking around). Also assuming from the numbers it's likely to be a primary school so kids aren't going to be fiddling too much. So Vlan 3 would then 'hard-wired devices' basically That splits off the wireless (where you might care about broadcasts) and the wired - without having to worry about updating things if stuff moves around.. Equally as Oaktech says - for such a small network, could easily put in the effort to do things properly. IF you could keep existing ip's on devices, and add new vlan's with different ip's for private/public wifi, i'd probably be inclined to keep the devices together. If you need to change everything's ip etc, splitting out completely might be a better way to go (assuming the unmanaged switches knocking around don't then cause issues) 1
Davit2005 Posted October 20, 2015 Posted October 20, 2015 I used 1810 HP's at last place, they support vLANS and are un-managed. 1810's aren't the best to work with but I also have a few at home on which I have multiple vLANS coupled to a Cisco Layer 3 switch and they work fine.
teejay Posted October 20, 2015 Posted October 20, 2015 Printers tend to be very noisy on the network so that's usually one of my first ones to VLAN off. You might want to download Wireshark and see what the traffic is like on your network which will help you to decide how to split it.
JordanT91 Posted October 20, 2015 Author Posted October 20, 2015 Thanks for all the advice everyone. I think I'll follow minimoo's advice and get the wireless network VLANed off. At the minute we don't really have guest WiFi because they still hit the Lightspeed filter at the other end of our internet connection which authenticates against our AD meaning they need to have a school username & password. Our network is likely to grow but any new devices are likely to be laptops. Ideally I'd have printers, VOIP and servers/PCs in seperate VLANs but for now at least it's going to be too much hassle with the 5 or 6 rooms relying on desktop switches. I've checked the amount of broadcast packets my PC is receiving (and it's not too many to be honest). I suppose I should port-mirror on the core switch and do it properly though.
Blue_Cookeh Posted October 20, 2015 Posted October 20, 2015 (edited) We don't have any unmanaged switches, but we use both HP 2920s and 2530s like you, in roughly the same size environment. I kept our servers, client machines, and printers as untagged VLAN 1 (no point separating them out for this small an environment), but created other VLANs for DMZ, CCTV, Voice, WiFi, and management access (for things like iLO/DRAC and UPSes). I then used QoS on our switches to give CCTV and voice higher priorities than all other VLANs. I quite like this setup for our environment, but I'll be rethinking it next year when building starts for our expansion. In your position I would look at getting rid of the unmanaged/web managed switches in favour of some more managed HP switches if your budget allows (since you can't pull more cable). Your VLANs look good, but I would keep the 'Apple' devices in your WiFi VLAN unless you start getting Apple TVs (they get quite chatty). Don't forget to implement STP! Edited October 20, 2015 by Blue_Cookeh
IanT Posted October 21, 2015 Posted October 21, 2015 I would add a couple more VLANs: MGMT VLAN (For Switching) SVRMGMT Staff VLAN (Wireless SSID) Student VLAN (Wireless SSID) Printer VLAN Projector VLAN
Oaktech Posted October 22, 2015 Posted October 22, 2015 I would add a couple more VLANs: MGMT VLAN (For Switching) SVRMGMT Staff VLAN (Wireless SSID) Student VLAN (Wireless SSID) Printer VLAN Projector VLAN If some is good, more must be better right!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now