Jump to content

Recommended Posts

Posted

Hi,

 

We currently have a flat network with a subnet of 255.255.252.0 & IP addresses that begin with 10.

We are moving to a new building & will be getting all new switches / core switches, a new security camera system, Aerohive WifI and a few other bits.

 

The firm who are setting up the switches have strongly suggested that

 

a) We segment the network with VLANS

b) We extend our current IP capacity with different subnets or private IP ranges for the cameras / wifi etc.

 

(a) Makes total sense - has anyone had to do this from scratch, our thinking at the moment is we need to keep things as simple / manageable as possible

(b) I have absolutely no idea where to start with this, is it easy to do? Can it be done from within DHCP itself (we use Server 2012) are there serious gotchas to watch out for? Again; if anyone has had to do this themselves, I'd be really interested to know how you went about it.

Posted

It seems that the firm installing the switches haven't really explained things to you very well.

 

Each VLAN will be a separate subnet - so you will have to modify your internal IP addressing somewhat.

 

For example:

 

VLAN 1 - Servers - 10.1.1.1 - 10.1.1.254 (subnet 255.255.255.0)

VLAN 2 - Printers - 10.1.2.1 - 10.1.2.254 (subnet 255.255.255.0)

VLAN 3 - Wired Clients - 10.1.3.1 - 10.1.3.254 (subnet 255.255.255.0)

VLAN 4 - WiFi Clients - 10.1.4.1 - 10.1.4.254 (subnet, yep, you guessed it, 255.255.255.0)

etc...

 

Any of these subnets that require DHCP IP addresses could get them from your DHCP server - you'd have a separate scope for each VLAN/subnet.

 

It's straightforward to do as long as you plan it correctly - feel free to ask any specific questions.

  • Thanks 1
Posted

Is your firewall managed by yourselves or externally?

If externally, and you don't have room for enough VLANs in your IP range to suit your requirements you can add a firewall to the mix and have an internal network which doesn't need to hit the internet.

 

We are currently in the process of implementing this at my place, all access control, projectors, etc will sit internally with no access to the internet, we will have some student computers NATTING to an IP provided by LGFL. things like staff computers which need VPN access will sit on the range provided by LGFL.

Posted

I was/am in a similar position to you, moving from a flat network running on the default VLAN 1 across all switches. Life was good. Then we wanted to replace our old phone system with a VOIP setup and this requires the introduction of VLANs as we want to implement Quality of Service as well. We haven't made any changes to our network yet, but I found this to be a really helpful read to understand about VLANs/subnets: Cisco Networking Academy's Introduction to VLANs > Objectives

 

It's all Cisco-based so be careful if you're using HP switches, for example, because terms like "trunk" have different meanings for HP vs Cisco. The principles from the articles are the mostly the same though.

 

I'm still not totally sure about the routing side of things because all of our switches are layer 2 devices. You'll need a layer 3 device (e.g. a router) to route traffic between subnets, so that they know how to talk to each other. From what I've read, having a core switch which is layer 3 capable is preferable so you can configure all the routes on that. Unfortunately we don't have one and we're also getting a new firewall and routers from a new ISP, so these unknowns are creating a bit of uncertainty for us at the minute.

Posted

I am in similar position, I am not to go over 254 hosts in a subnet. But then for wifi I need more hosts.

 

So do I achieve this???

Posted
I am in similar position, I am not to go over 254 hosts in a subnet. But then for wifi I need more hosts.

 

So do I achieve this???

 

Ideally it's best to keep the subnets smaller as this will decrease the amount of broadcast traffic. Perhaps you could further segregate your WiFi clients by type or by security/access requirements, e.g. a VLAN for student laptops, another for iPads/tablets, and another for any staff devices.

 

In vlans.. Different subnets can be use?

 

/21,/22 and /23?

 

For servers I will go for/21

Wired /22

 

Yes, nothing stopping you, technically, from having different subnet masks. /21 is a huge subnet though, 2048 possible hosts... seems overkill for a server VLAN.

Posted
What is stopping you from going over 254 hosts in a subnet?

 

The simple answer is the more devices you have on a Subnet the more broadcast traffic you will get. But you will want to keep devices that send a lot of broadcast seperate to other traffic, Access Control, Building Management Systems, etc..

 

I don't think there is a need to go over board, we have a vlan per building/area, then we have different vLANs for each VOIP, Access Control etc. Some of our vLANS are allowing for 1024 hosts but we never really half touch that.

Posted

Having joined a school some years ago now that had a flat network with slow log on's etc etc

I have sliced and dices our network with a private range I would recommend this highly.

First thing is to check out you core switch to see if can route and then check out what the edge switches can do.

Next assuming you having routing capability within the switching take a look at your site and a make a lose plan as to how you are going to subnet/VLAN your site.

 

Out site is made up of many buildings so for us each building has a subnet/VLAN and then some site wide VLAN's for switch management, printing, cctv & wifi.

 

To keep our network nice and easy all VLAN's have a /24 network except wifi and we try to run around 100 devices per VLAN to keep broadcast nice a low which make the network nice a quick.

 

Our edge to desktop is 1GB With edge to core 2 or 4 GB and the core itself 20GB stacked switches and 20GB connections to the hosts, this works very well and idles most of the time.

Posted

Hi, thanks to all who posted, some really useful stuff here to get me going.

 

I understand the concept of VLANS (segregated network = less broadcast traffic etc) and we will be getting all new HP switches/routers/core switches, so we will have the capability to do what we want.

 

The first part is to decide on what needs to be segregated, so far we are looking at:

 

Curriculum (Servers / workstations / printers)

Wireless Curriculum

Wireless Guest

Management (switches etc)

VOIP

Media / Digital signage

Cashless Catering

MACs

 

Has anyone got strong opinions on whether we should split this further? put the printers on their own segment, do the same for staff / student wireless access etc.

Posted

1) Put servers/workstations/printers all in separate vlans

 

2) door access control??

3) av management e.g projectors

4) anything you could have in future which doesn't lie in those caregories.

Posted

One thing I'm still a little confused by: Am I better off setting up multiple scopes within DHCP ... or, where possible (CCTV?) give things static IP addresses in a unique IP range?

 

Hope that makes sense!

Posted

Personally I have created dedicated VLAN's and DHCP scopes for each service i.e. printers, CCTV, Wi-Fi etc etc as some devices broadcast within the subnet as part of their normal operation which will just make that network busy.

I also try to keep the number of Devices per subnet to around 100 with 200 IP's with the scope which allows a nice overhead if you need to add say another IT suite in a building.

Posted

I would setup multiple scopes for each VLAN and then use DHCP reservations where appropriate.

 

This means that it's all done from a single point of administration.

 

Use DHCP failover (a nice littel feature in 2012) to ensure that you've got some redundancy just in case.

Posted
I would setup multiple scopes for each VLAN and then use DHCP reservations where appropriate.

 

This means that it's all done from a single point of administration.

 

Use DHCP failover (a nice littel feature in 2012) to ensure that you've got some redundancy just in case.

 

Administration wise, that does make sense. Surprisingly we already use DHCP failover!!!

 

I feel like I'm in a bit of an odd position. The company chasing me for the IP ranges of the VLANs will be programming all the switches and setting them up in the new school so its a lot more abstract to me than it would be if I was setting up the whole thing from scratch. I wont be doing ANYTHING on the switches at all.

 

Is it really as simple (for me) as creating new scopes / IP ranges in DHCP & so long as each scope has a different broadcast address... it's job done?

Or am I making some terrifying, cataclysmic assumption?!

Posted (edited)
Administration wise, that does make sense. Surprisingly we already use DHCP failover!!!

 

I feel like I'm in a bit of an odd position. The company chasing me for the IP ranges of the VLANs will be programming all the switches and setting them up in the new school so its a lot more abstract to me than it would be if I was setting up the whole thing from scratch. I wont be doing ANYTHING on the switches at all.

 

Is it really as simple (for me) as creating new scopes / IP ranges in DHCP & so long as each scope has a different broadcast address... it's job done?

Or am I making some terrifying, cataclysmic assumption?!

 

Each SUBNET has it's own broadcast address, it would be the last/highest address in the subnet simple example below i.e:

10.0.0.0/8 would have broadcast address of 10.255.255.255

172.16.0.0/16 would have broadcast address of 172.16.255.255

192.168.1.0/24 would have broadcast address of192.168.1.255

 

I don't know the in's and out's of the agreement but make sure you get documentation at the end from the company ideally in a Visio, unless all admin is going to be done by them as well.

Edited by Davit2005
Posted
Each SUBNET has it's own broadcast address, it would be the last/highest address in the subnet simple example below i.e:

10.0.0.0/8 would have broadcast address of 10.255.255.255

172.16.0.0/16 would have broadcast address of 172.16.255.255

192.168.1.0/24 would have broadcast address of192.168.1.255

 

I don't know the in's and out's of the agreement but make sure you get documentation at the end from the company ideally in a Visio, unless all admin is going to be done by them as well.

 

Hi , Thanks to everyone who replied. All looks to be in hand now & from my end really easy. Although very weird because as I said in a previous post, not getting to set up the switches themselves and have a play has made it very hard to visualise & easy to overcomplicate.

Posted
Perhaps as part of the setup and handover they can walk you through the config and how everything is put together? That's the sort of thing I normally do (as well as comprehensive documentation, of course!)...
  • 1 month later...
Posted

Hi, just to return to this : the company who are setting up the VLANs (& other stuff such as WiFi!) will provide basic training and leave us with a full operating manual. So that's good!

 

I'm setting up the new scopes now, quick question ... and this may seem ... daft

 

If I have a planned scope of 10.51.8.0 / 10.51.11.255 with subnet mask 255.255.252.0

When I set up the scope in DHCP are my start / end IPs 10.51.8.1 / 10.51.11.254 ?

Posted

Yep - that's fine as a DHCP range, technically speaking.

 

But, that's quite a big subnet and will give you a pretty big broadcast domain, which is one of the things VLANs help to avoid. Are you sure you need 1024 hosts?

Posted
Yep - that's fine as a DHCP range, technically speaking.

 

But, that's quite a big subnet and will give you a pretty big broadcast domain, which is one of the things VLANs help to avoid. Are you sure you need 1024 hosts?

 

It's for the wireless curriculum, if at some point (and this is probably a big IF) we end up with 900-1000 students (or thereabouts) and every student has a personal device, we'll be covered....

At least that's the plan!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...