Jump to content

Recommended Posts

Posted

I've purchased a new Meraki Wi-Fi solution for our school and I would like to put it on a separate VLAN. I've only ever really worked with flat networks before and would like to try to configure this myself before I ask for help from any 3rd parties.

 

We have 4 cabinets in school. Cabinet 1 is where the LGfL fibre connection comes in that goes to the LGfL Cisco router. This then feeds out to a Cisco ASA (All managed by LGfL) which then feeds out to some unmanaged Netgear switches around the school in 3 other cabinets, connected by fibre. I have asked LGfL to assign me a new IP range for the new VLAN that I would like to use with the 4 new 24 port Meraki M225 switches that I have purchased that I will connect up in each cabinet using spare fibre connections.

 

Where I am a bit confused is what configuration I need to do on our servers and/or switches so that anyone accessing the Wi-Fi can communicate with the 2 data domains (Admin and Curriculum - Yes, I know! I've inherited it and will be getting rid of 2 domains ASAP!) whilst still keeping everything secure and not clogging up bandwidth.

 

I do have the option of asking for help, but rather than getting a 3rd party to do it, I'd like to learn how to do it myself.

 

So, any ideas?

Posted

Depends how complex / future proof you want it to be.

 

Can you manage the netgear switches?

Do you need the new switches to carry both vlans? (might you want to use the extra switch capacity for the domain network)

Would all the switches connect directly back to the ASA?

 

My inclination is that most of the necessary config (especially for having the servers accessible from both vlans) would be managed on the router or the ASA. If everything goes straight back to the ASA and you only need one vlan per switch then all the config would be there, and your satellite switches are running in "dumb" single vlan mode. With zone bridging (or whatever cisco call it) to allow for communication between the vlans - in this instance the servers are none the wiser so no config necessary.

 

If your servers have multiple network ports, youcould put one port on either vlan and allow access that way.

Posted

Can you manage the netgear switches?

Nope, they're pretty basic from the looks of it.

 

Do you need the new switches to carry both vlans? (might you want to use the extra switch capacity for the domain network)

Yes, this would be really handy!

 

Would all the switches connect directly back to the ASA?

Maybe, but it doesn't look like there are that many ports on the ASA, so they may daisy chain off another switch

Posted

I'd probably put the new meraki switches in as the primary switch in each cabinet, then have the NG switches coming off them.

 

Then it's just a case of setting up the new vlan on meraki, assigning it to the ports ( you want to set them as "access" ports with the VLAN set) and making sure fiber connections are trunk ports (that will carry all vlans), and obviously make sure the ports the NG switches go back to are on the original domain vlan (set as access ports).

Traffic from an unmanaged switch should get the vlan tagging from the first managed port it goes into, but it's worth testing this after you've got the rest of the config down.

 

The rest would be done by the router or ASA.

 

https://documentation.meraki.com/MS/Deployment_Guides/Advanced_MS_Setup_Guide

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...