alfatec Posted July 19, 2016 Posted July 19, 2016 Hi, has anybody got their Macs on a seperate VLAN and also integrated into Active Directory where the file and Domain controllers are on VMWare. Just need a few pointers in the right direction.
alfatec Posted July 19, 2016 Author Posted July 19, 2016 So just wondering how you setup the Domain Controllers and File servers to access the Apple Vlan or did you just Tag the Apple Vlan to all the Virtual hosts?
Davit2005 Posted July 19, 2016 Posted July 19, 2016 You'd normally use a layer 3 switch for routing between the vLANs TBH. If you have a requirement to segregate traffic for another purpose and need to keep some servers specificcaly on that vLan then that require a bit more work?? We have a MAC vLAN here and all the routing is done on the Layer 3 switch, there is some storage space on the same vLAN for media but that is it. The MACs autheticate against the DC and get DNS/DHCP the same as the Windows machines do.
pantscat Posted July 19, 2016 Posted July 19, 2016 Yep, as @Davit2005 has said, normally your core switch would do the routing. If you explain your setup and what you want to do I'm more than happy to advise. Ant
alfatec Posted July 19, 2016 Author Posted July 19, 2016 Thanks for that. All our students and staff use the Macs and login with their Active Directory usernames and passwords so we need access to the DC's. The students have their own file server for their home drives and shared area and the staff have their own file server for home drives and shared areas. We also use Kerberos authentication through our Smoothwall filtering. What setup do you have on your Layer 3 switch's? We use VMWare 5.5 and all hosts are connected into a HP 5412 RZL2. We have a single generic VLAN for all networks.
pantscat Posted July 19, 2016 Posted July 19, 2016 Ok - with an HP 5412 it's very straightforward. Make sure that the MAC vlan is assigned an IP address and this is set as the default gateway for all your mac clients. Then you need to turn on routing on the switch - "ip routing", then "ip route 0.0.0.0 0.0.0.0 10.10.10.10" - where 10.10.10.10 is the internal address of your edge firewall. If you need a hand with the CLI commands for the HP switch, just shout.
alfatec Posted July 19, 2016 Author Posted July 19, 2016 OK excellent. Will give that a try next week when everyone is off. Thanks again for your help.
Davit2005 Posted July 19, 2016 Posted July 19, 2016 OK excellent. Will give that a try next week when everyone is off. Thanks again for your help. Are the MAC's statically assigned ip addresses??
pantscat Posted July 19, 2016 Posted July 19, 2016 Are the MAC's statically assigned ip addresses?? That's a good point - assuming that they're using DHCP currently there are a couple of more steps you need to do: 1. setup a DHCP scope for the new VLAN 2. add an ip helper command to your core switch to point at your DHCP server. You may also need to change your main DHCP scope (and any static devices) to point at the core switch as a default gateway. 1
pantscat Posted July 21, 2016 Posted July 21, 2016 I'd recommend switching to DHCP unless you've got a good reason to keep them static... seems like an unnecessary administration overhead.
Mustang Posted July 22, 2016 Posted July 22, 2016 You haven't said why you want the Macs in there own vlan, if everything else is in a single vlan why not put the macs in there as well? seems to me like you don't fully understand why your doing it. If you really do want to segregate you should look at doing it for Servers, Phones, Client Access, Printers, Private WiFi Client Access, Guest WiFi Client Access, CCTV etc
ITGuyWestMidlands Posted July 24, 2016 Posted July 24, 2016 Anybody fancy sharing their mac vlan acl?
pantscat Posted July 25, 2016 Posted July 25, 2016 Anybody fancy sharing their mac vlan acl? Depends rather on what you're running in the core and what you do and don't want your Macs to have access to.
jtotheb Posted July 26, 2016 Posted July 26, 2016 (edited) Anybody fancy sharing their mac vlan acl? Bare minimum would be allowing DHCP and the following from http://training.apple.com/pdf/Best_Practices_for_Integrating_OS_X_with_Active_Directory.pdf UDP 53! ! - DNS TCP 88! ! - Kerberos TCP 389 ! ! - LDAP TCP/UDP 464! - Kerberos Password Changes (KPasswd) TCP 3268! ! - Global Catalog (LDAP) (+ntp to the appropriate servers) We then add 443 to webservers, 445 to fileservers, plus 8080 to our proxy. That's ours in a nutshell. Edited July 26, 2016 by jtotheb 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now