Jump to content

Recommended Posts

Posted

I thought I'd got sorted ready for VLANing my main network but while testing I've got stuck and the more I look in to it the more confused I'm getting.

 

So, the overview is this. I currently have my main network on VLAN 1 with some BYOD networks on VLAN 60, 70 and 80. The BYOD networks use our Smoothwall as the gateway with DHCP etc all handled by that. The Smoothwall does some routing to allow access to our portal web server and ruckus for authentication etc.

My next step is to VLAN our main network up to reduce broadcast traffic. In time I'd also like to introduce client access lists for but the moment all these new VLANS would be interconnected. Here are the VLANs I'm proposing:

UWS VLANs.PNG

 

Currently our main network is on 172.16.0.0/16.

 

I had hoped to use an existing switch to route between the VLANs, but its a V1920 which although it should support interLAN routing, it doesn't work and a lot of people seem to report the same. So I need to find another core switch, with really no budget and nothing more than a V1920 and a Smoothwall to do it. I think I might end up having to buy a core switch but it needs to be in the lower hundreds range if I do.

 

So what I'm after is suggestions and how you have this setup? Our networks is pretty small as we're a secondary with under 300 pupils (Yep that small) but I have configured my Hyper-V hosts and servers with teamed LAN so I'd like to have more than 1Gbps of routing between the LANS. I could use the Smoothwall but I'd only get 1Gbps on each LAN. Ubiquiti kit seems to be the thing to have at the minute with low cost but good features, however I'm a little lost as to which one I need.

 

Thank you in advanced.

Posted (edited)

OK do you need to VLAN?

How many devices do you have on the network?

I work on about 150/200 devices per subnet/VLAN

Teamed connections to servers make sure you use LACP on both the switch ports and the server port configuration or you will not be able to use more than 1GB, be aware that if you bind say 4 x 1GB connections it's not a 4GB connection it still 4 x 1GB, but this is much better than the whole network trying to connect to the server over 1 x 1GB port.

The best way to route your network is to have a core switch that can terminate each network/VLAN and route these networks, then you will need a network between the core switch and your firewall/router so you can use any IP range on the school side I would suggest using a private range like 10.x.x.x or 172.x.x.x.

We use a very simple configuration with VLAN and ip ranges, 10.0.10.x would be VLAN 10 and 10.0.11.x would be VLAN 11 and so on, so this make fault finding a little easier as you can check the IP address and know which VLAN it's on.

Edited by Techforyou
Posted

I've had a lot of problems with PXE boot and I'm hoping reducing the amount of broadcast traffic on our LAN will solve this. We also have VOIP system on our main LAN and we're likely to be installing IP CCTV soon so I thought now was the time to separate it up.

 

Have done a load of work over the weekend I've come up with the following:

2x Ubiquiti 24 Port EdgeMax Switch Lite

1x 2 Pack 10Gbps fibre module

1x Fibre cable for above

 

This gives me some redundancy by having two switches. I'll split my servers across the two switches and configure spanning tree to make both roots so it keeps all ports forwarding. I'll also split my VLANs across both switches so the server VLAN (Infrastructure) has Core 1 as the default gateway, but all my other VLANs (Domain clients etc) have Core 2. My thinking is 95% of traffic will be between clients and servers, so this should spread the load across both switches. If one fails I just need to switch the default gateway.

 

The cost of the above should be justifiable for what we get out of it.

Posted
I'd have a look at these for Core https://www.ubnt.com/edgemax/edgeswitch-16-xg/ or the Unifi Version with a router.

 

Also the switches you've listed above aren't 10Gb

 

Your quite right, the 48 port version goes to 10Gbps but the 24port doesn't. I don't think I really need it so to keep the budget down I just create a trunk between them. The problem with the XG is we don't have any fibre modules in the server and replacing our current fibre modules would bump the price up. So I'll keep the existing HP modules and try them in the EdgeSwitch. If they don't work I'll leave them in my HP switches and use the connection from each of those to the core switches.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...