casa Posted February 8, 2017 Posted February 8, 2017 Hi folks Bit of advice, we currently have a vlan segmented network consisting of 6 HP switches and 1 cisco switch in 2 locations. The Hp switches are all configured for Intervlan routing, we have the following vlans. Admin, Voip, Wireless Access, Guest Wireless, Curriculum and Security. It is a brand new school configured by sub contractors as part of the new build. Everything works fine, and all devices get there correct ip address from our server. We are about to move to a new internet provider, they have given us a range of Ip Addresses for us to use, I have just found out today, with no consultation that the 3rd party provider who are going to facilitate the move has decided to flatten the entire network, and to secure the admin side devices with dhcp reservations . Currently we have about 140 devices connected to the network, including wifi access points, cctv, electronic doors, voip phones and a guest network, all on its own vlans. What are the advantages and disadvantages of the flattening of the network ? Many Thanks. Casa
TechMonkey Posted February 8, 2017 Posted February 8, 2017 Disadvantages: Less secure, more network noise, more chance of a network storm. Advantages: Simpler to manage..... Less chance of patch cable colours clashing. I'd be asking their reasoning for the move and why your ISP is dictating your internal network addressing. Seems a backward step to me.
FN-GM Posted February 8, 2017 Posted February 8, 2017 Even if they did specify the IP range. You can subnet that down and stuff have all your vlans within that range. I can't see why anyone would flatten the network??
ellsandell Posted February 8, 2017 Posted February 8, 2017 (edited) Flattening the network would be backwards step in my eyes. You are the Customer, I would push them to explain why and ask them to retain the current config. Sounds all a bit amateur... As @FN-GM says you can split down the given range between the VLANs. Edited February 8, 2017 by ellsandell
casa Posted February 8, 2017 Author Posted February 8, 2017 (edited) Thanks Tech and FN-GM The reason they gave for flattening the network is as follows There is no security setup between your existing Vlans at the moment and anyone can route from one subnet to another. It will be far simpler for you to administer the network going forward if you have everything on the same Vlan. We will add extra protection to your admin to make sure the SIMS F:drive is secure my reply was as follows I control access to the subnets via the HP Switches, all ports on the switches in cabinet B that are accessible via the classrooms are configured for curriculum traffic only. There are no ports open at the admin cabinet that will allow any one plugging in a device to obtain a admin ip address. We also have a guest wifi that separates clients machines from the core network, it would be a massive security risk if a rogue wifi connection was allowed onto the curriculum wifi. We are very happy with the current set up as this gives us great flexibility. Vlans required The reason for a new Ip address range is the provider working in conjunction with the provided firewall, can monitor and pin down users usage. Ps the new provider is Trustnet (LGFL) Edited February 8, 2017 by casa
victory2015 Posted February 8, 2017 Posted February 8, 2017 (edited) We have lgfl and have vlans configured.. id be very worried they are forcing you this way, seems lazy to be honest! vlans are required a very backwards step! Ours is configured as a stub network so i configure all the vlans on our core switch however i want. is this through atomwide? if so i can give u a senior contact if you don't get anywhere. Edited February 8, 2017 by victory2015
casa Posted February 8, 2017 Author Posted February 8, 2017 Great stuff folks, keep it going. Victory2015 my thoughts exactly seems the easy approach. It cant be that hard to redo the vlan ip addres's on the commander Hp Switch and redo the dhcp scopes on our server. The only problem could be the wireless HP Controller that needs a bit extra tinkling.
Davit2005 Posted February 9, 2017 Posted February 9, 2017 The reason for a new Ip address range is the provider working in conjunction with the provided firewall, can monitor and pin down users usage. Ps the new provider is Trustnet (LGFL) Every firewall that has user ID that I have worked with have relied on the IP address on the source machine which was normally mapped via a domain joined server of AD authenticated file share, unless you use NAT internally putting all devices on one network will not make a difference to how that works. The last thing you want is a noisy network device or a switching loop taking down the whole network and the VOIP And ask them to elaborate on this We will add extra protection to your admin to make sure the SIMS F:drive is secure When it comes to security vLANS should be part of a wide range measures, security by obscurity is not enough.
synaesthesia Posted February 9, 2017 Posted February 9, 2017 They sound like they don't fully know what they're doing... either they're a company not used to dealing with education clients, or education IT with not enough knowledge of networking! Even with zero security between vlans, saving your devices from the endless printer-chatter and broadcast storms is reason enough!
localzuk Posted February 9, 2017 Posted February 9, 2017 I would say that this is a bad idea for 2 simple reasons - VOIP and Guest Wifi. Both of those things should be segregated away from other parts of your network. The first for performance reasons, and second for security reasons.
caffrey Posted February 9, 2017 Posted February 9, 2017 Vlans alone for VOIP and wifi is more than justification, QOS on the VOIP and seperate wifi SSIDs on different VLANS (for guest access etc.)
Mr_Jiminy Posted February 9, 2017 Posted February 9, 2017 (edited) Good lord, this is all too similar to the problem we're experiencing with a number of our education clients, which are unfortunately under the grips of backwards mind-set local authority. Stand your ground and insist they accommodate you, not the other way around. Edited February 9, 2017 by Mr_Jiminy 1
PotNoodleTech Posted February 9, 2017 Posted February 9, 2017 I almost started with good lord too. Basically, they are just lazy and are happy to semi destroy all the hard work you've done using industry standard techniques and technologies just to make their lives easier going forward. Vlan for Voip and Vlan for Wlan are essential. If a company said that to me - I'd be moving on to another company. The company does what you need them to do, not the other way around.
TechMonkey Posted February 9, 2017 Posted February 9, 2017 Dare you, double dare you to just send them this pic in response 2
Koldov Posted February 9, 2017 Posted February 9, 2017 We were in the same boat with regard to LGfl giving us a new IP range. We did have to pay our 3rd party support to come in and change everything for us, but we stuck to our VLAN structure (and the onsite part was done by the engineer in half a day). Yes, we can route across it - maybe that's what they mean by saying your VLANs have no security and maybe there is a way to stop that. I do seem to remember a few years ago it became very fashionable to have a flattened network, seems to have swung back in favour of VLANs given the popular opinion here and with good reasons (as stated in the other posts).
mtillbrook Posted February 9, 2017 Posted February 9, 2017 everyone is in agreement on here - flattening your network isn't a good idea, especially when you are running VoIP. If you don't have VoIP at least on a seperate VLAN you will run into issues. It sounds to me like your provider just doesn't have the knowledge needed to cope with a small number of VLANs, thats why they want to flatten the network. Seeing as how its your network, my answer to them would be a firm No. If they can't setup things up in the way you, the person who runs the network, needs them to then tell them you'll go elsewhere. Not saying you will go elsewhere, just threaten them and see if they do have an engineer who knows what they are doing that will mystriously come out of the woodwork and setup your systems as you need them to!
casa Posted February 9, 2017 Author Posted February 9, 2017 Thanks for all the advice. We will stand our ground, just shown HT all the replies and he is with us all the way! 1
leegcvcc Posted February 9, 2017 Posted February 9, 2017 I had a case for isolating a particular VLAN which was bringing the whole network down. If I'd have had a flat network, we would have been down for days until I found the culprit, which I never did. The closest I came to was narrowing it down to a few ports, but the actual device was never found. I would get a BT leased line personally and have all the private addressed VLANs you like. Never had an outage of internet in 16 months now. ps. I work in a College and not for BT I'm surprised the LGFL don't bombard you with IP addresses if you have a legitimate cause. Never had an issue with the SWGFL when i used them. all the best
gh5000 Posted February 9, 2017 Posted February 9, 2017 (edited) LGfL will pretty much always want to give you a 255.255.248.0 IP range at the most although they might not think you're big enough for that range. As for changing the network range that is probably a certainty with the LGfL. They operate clients on a 10. range so if you currently use 192.168 or 172. addressing internally you will definitely have to change. If you're currently on a 10. range it may be that your internal addressing is used by another LGfL school. I have had the "we can't give you addresses without proper justification" response from them. We were running out of addresses on our BYOD range and there response was literally change your DHCP lease to a shorter time. There shouldn't be an issue with them giving you a stub network. And smaller random IP addresses from across the range. ie 10.212.64.0 255.255.255.0 for admin 10.188.185.0 255.255.255.0 for voip etc. My point being they definitely don't have enough clients to have saturated their IP addressing and not have enough smaller subnets to meet your needs. Hopefully that makes sense EDIT: Forgot to add that my advice would be to get a leased line or alternative provider. You will almost certainly save money unless you are going to use all the services the LGfL offers. Also find out what they are going to do to secure your SIMS share. If its just permissions I'm sure you do that already. Good luck Edited February 9, 2017 by gh5000
Popular Post casa Posted February 18, 2017 Author Popular Post Posted February 18, 2017 Hi all Update, all VLANS retained ! the engineers did a fantastic job and had everything changed over by dinner time. Am happy, Staff happy and most important of all the daily fix of YouTube access has greatly improved. Previous bandwidth 13Mb Many thanks to everyone who contributed to my concerns, with out professional guidance from you, there was no way I could of swayed it to take the sensible and logical approach. You are all stars in our schools ! Casa 5
ITGURU Posted February 19, 2017 Posted February 19, 2017 I used to have a flat network up until we had VOIP phones, after which I then VLAN'd VOIP, Access Control, CCTV etc. Despite being a site with 1200 clients and 22 servers, I've never noticed any difference in network performance, before or after the VLAN changes. However, we are on 10Gig backbone.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now