Jump to content

Recommended Posts

Posted

Hi folks

Bit of advice, we currently have a vlan segmented network consisting of 6 HP switches and 1 cisco switch in 2 locations. The Hp switches are all configured for Intervlan routing, we have the following vlans. Admin, Voip, Wireless Access, Guest Wireless, Curriculum and Security. It is a brand new school configured by sub contractors as part of the new build. Everything works fine, and all devices get there correct ip address from our server.

We are about to move to a new internet provider, they have given us a range of Ip Addresses for us to use, I have just found out today, with no consultation that the 3rd party provider who are going to facilitate the move has decided to flatten the entire network, and to secure the admin side devices with dhcp reservations .

Currently we have about 140 devices connected to the network, including wifi access points, cctv, electronic doors, voip phones and a guest network, all on its own vlans.

 

What are the advantages and disadvantages of the flattening of the network ?

 

Many Thanks.

 

Casa

Posted

Disadvantages: Less secure, more network noise, more chance of a network storm.

 

Advantages: Simpler to manage..... Less chance of patch cable colours clashing.

 

I'd be asking their reasoning for the move and why your ISP is dictating your internal network addressing.

 

Seems a backward step to me.

Posted

Even if they did specify the IP range. You can subnet that down and stuff have all your vlans within that range.

 

I can't see why anyone would flatten the network??

Posted (edited)

Flattening the network would be backwards step in my eyes. You are the Customer, I would push them to explain why and ask them to retain the current config. Sounds all a bit amateur...

 

As @FN-GM says you can split down the given range between the VLANs.

Edited by ellsandell
Posted (edited)

Thanks Tech and FN-GM

The reason they gave for flattening the network is as follows

There is no security setup between your existing Vlans at the moment and anyone can route from one subnet to another.

 

It will be far simpler for you to administer the network going forward if you have everything on the same Vlan.

 

We will add extra protection to your admin to make sure the SIMS F:drive is secure

my reply was as follows

 

I control access to the subnets via the HP Switches, all ports on the switches in cabinet B that are accessible via the classrooms are configured for curriculum traffic only.

There are no ports open at the admin cabinet that will allow any one plugging in a device to obtain a admin ip address.

We also have a guest wifi that separates clients machines from the core network, it would be a massive security risk if a rogue wifi connection was allowed onto the curriculum wifi.

We are very happy with the current set up as this gives us great flexibility.

Vlans required

 

The reason for a new Ip address range is the provider working in conjunction with the provided firewall, can monitor and pin down users usage.

Ps the new provider is Trustnet (LGFL)

Edited by casa
Posted (edited)

We have lgfl and have vlans configured.. id be very worried they are forcing you this way, seems lazy to be honest! vlans are required a very backwards step!

 

Ours is configured as a stub network so i configure all the vlans on our core switch however i want.

 

is this through atomwide? if so i can give u a senior contact if you don't get anywhere.

Edited by victory2015
Posted

Great stuff folks, keep it going. Victory2015 my thoughts exactly seems the easy approach. It cant be that hard to redo the vlan ip addres's on the commander Hp Switch and redo the dhcp scopes on our server.

The only problem could be the wireless HP Controller that needs a bit extra tinkling.

Posted

 

The reason for a new Ip address range is the provider working in conjunction with the provided firewall, can monitor and pin down users usage.

Ps the new provider is Trustnet (LGFL)

 

Every firewall that has user ID that I have worked with have relied on the IP address on the source machine which was normally mapped via a domain joined server of AD authenticated file share, unless you use NAT internally putting all devices on one network will not make a difference to how that works.

 

The last thing you want is a noisy network device or a switching loop taking down the whole network and the VOIP

 

And ask them to elaborate on this

We will add extra protection to your admin to make sure the SIMS F:drive is secure

 

When it comes to security vLANS should be part of a wide range measures, security by obscurity is not enough.

Posted

They sound like they don't fully know what they're doing... either they're a company not used to dealing with education clients, or education IT with not enough knowledge of networking!

Even with zero security between vlans, saving your devices from the endless printer-chatter and broadcast storms is reason enough!

Posted
I would say that this is a bad idea for 2 simple reasons - VOIP and Guest Wifi. Both of those things should be segregated away from other parts of your network. The first for performance reasons, and second for security reasons.
Posted (edited)

Good lord, this is all too similar to the problem we're experiencing with a number of our education clients, which are unfortunately under the grips of backwards mind-set local authority.

 

Stand your ground and insist they accommodate you, not the other way around.

Edited by Mr_Jiminy
  • Thanks 1
Posted

I almost started with good lord too.

 

Basically, they are just lazy and are happy to semi destroy all the hard work you've done using industry standard techniques and technologies just to make their lives easier going forward. Vlan for Voip and Vlan for Wlan are essential.

 

If a company said that to me - I'd be moving on to another company. The company does what you need them to do, not the other way around.

Posted

We were in the same boat with regard to LGfl giving us a new IP range.

 

We did have to pay our 3rd party support to come in and change everything for us, but we stuck to our VLAN structure (and the onsite part was done by the engineer in half a day).

 

Yes, we can route across it - maybe that's what they mean by saying your VLANs have no security and maybe there is a way to stop that.

 

I do seem to remember a few years ago it became very fashionable to have a flattened network, seems to have swung back in favour of VLANs given the popular opinion here and with good reasons (as stated in the other posts).

Posted

everyone is in agreement on here - flattening your network isn't a good idea, especially when you are running VoIP. If you don't have VoIP at least on a seperate VLAN you will run into issues. It sounds to me like your provider just doesn't have the knowledge needed to cope with a small number of VLANs, thats why they want to flatten the network.

 

Seeing as how its your network, my answer to them would be a firm No. If they can't setup things up in the way you, the person who runs the network, needs them to then tell them you'll go elsewhere. Not saying you will go elsewhere, just threaten them and see if they do have an engineer who knows what they are doing that will mystriously come out of the woodwork and setup your systems as you need them to!

Posted

Thanks for all the advice.

We will stand our ground, just shown HT all the replies and he is with us all the way!

  • Thanks 1
Posted

I had a case for isolating a particular VLAN which was bringing the whole network down. If I'd have had a flat network, we would have been down for days until I found the culprit, which I never did. The closest I came to was narrowing it down to a few ports, but the actual device was never found.

 

I would get a BT leased line personally and have all the private addressed VLANs you like. Never had an outage of internet in 16 months now. ps. I work in a College and not for BT :)

 

I'm surprised the LGFL don't bombard you with IP addresses if you have a legitimate cause. Never had an issue with the SWGFL when i used them.

 

all the best

Posted (edited)

LGfL will pretty much always want to give you a 255.255.248.0 IP range at the most although they might not think you're big enough for that range.

 

As for changing the network range that is probably a certainty with the LGfL. They operate clients on a 10. range so if you currently use 192.168 or 172. addressing internally you will definitely have to change. If you're currently on a 10. range it may be that your internal addressing is used by another LGfL school.

 

I have had the "we can't give you addresses without proper justification" response from them. We were running out of addresses on our BYOD range and there response was literally change your DHCP lease to a shorter time.

 

There shouldn't be an issue with them giving you a stub network. And smaller random IP addresses from across the range. ie

 

10.212.64.0 255.255.255.0 for admin

10.188.185.0 255.255.255.0 for voip etc.

 

My point being they definitely don't have enough clients to have saturated their IP addressing and not have enough smaller subnets to meet your needs. Hopefully that makes sense

 

EDIT: Forgot to add that my advice would be to get a leased line or alternative provider. You will almost certainly save money unless you are going to use all the services the LGfL offers.

 

Also find out what they are going to do to secure your SIMS share. If its just permissions I'm sure you do that already.

 

Good luck

Edited by gh5000
  • 2 weeks later...
Posted

I used to have a flat network up until we had VOIP phones, after which I then VLAN'd VOIP, Access Control, CCTV etc.

Despite being a site with 1200 clients and 22 servers, I've never noticed any difference in network performance, before or after the VLAN changes.

However, we are on 10Gig backbone.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...