Jump to content

Recommended Posts

Posted

Hi everyone,

 

I'm about to reorganise our network and I feel like I need to do a sanity check before I take the plunge.

 

I've planned out the VLANs needed and done VLSM for the subnets. I've also drawn it all up on a network map so I don't miss anything when I actually come to implement.

 

We recently moved ISP but stuck with the major network allocation that we had before for the sake of simplicity (plus it'll support 8000 hosts so I've no urgent need to change things up); I've broken this up in to subnets for VLANs as needed (and done this in a way that means servers/core infrastructure retain same addressing).

 

All HP switches with a Layer 3 main core which is fibre'd out to distribution switches around the school.

 

ISP Router upstream from the core.

 

So - trying to put together a bit of a checklist and I've a few areas that I'm not overly certain of...

 

  • Configure VLANs with addresses on core switch
  • Configure VLANs on all other switches
  • Configure VLANs in ESXi/tag interfaces as required
  • Set up DHCP scopes as required
  • Configure trunks between core/distribution/access switches
  • Tag access ports as required
  • Adjust statically addressed devices to match their new subnet

 

My queries are:

  • Inter-vlan routing - is there anything specific I need to do (other than enabling IP routing on the core) to ensure that traffic can travel between VLANs?
  • ISP router - do they need to add routes to the new subnets?
  • Guest Wifi - how do I ensure that a specific VLAN can't reach anything other than the internet? ACL/routing table? Unsure!

 

Please let me know if I've missed anything or am doing anything completely wrong and any advice on my queries greatly appreciated.

  • Thanks 1
Posted

Sounds like you've got a good list there.

 

Which switches are you using? HP have several different kinds which may affect how you configure this on the switches.

 

On our A5800 core, we set a VLAN interface on each VLAN. This then added the routes for these VLANs automatically. We just needed to set the main gateway for our ISP, and dhcp forwarding on each vlan interface for dhcp and MDT/PXE booting.

 

On each switch, you will need to define the VLANs you need on that switch (or just add all of them if its easier). You then set your uplink and downlink/trunk ports as tagged for each VLAN. For end user ports, you need to set these as untagged in the correct vlan. You should also check the PVID for each port. Some switches don't automatically set this the same as the untagged vlan The terminology for each switch can vary.

 

If you have any aggregated links (LACP) you need to make sure both ends are exactly the same, or it may not establish connection.

 

You will need to change your default gateways on anything that has static addresses. DHCP needs to be updated as well. You need a scope for each vlan.

 

For wifi, it probably depends on which system you use.

 

For your ISP link, they will need to set up a route to point at your router/core switch. When we did this, we had to setup a link segment. Its best to discuss this with your ISP, and coordinate a switch over time.

 

Its been a while for ESXI, but I think you set up a vlan trunk to your host, then look in the virtual switch settings. The alternative is to put the host on an untagged port on your servers VLAN, which would work if you don''t have any servers that need specific vlans (like phones, wifi, cctv etc)

  • Thanks 1
Posted

Cheers, Chris!

 

Core is 2920-24G, distribution and access switches are a bit of a mishmash of different models.. a quick glance over my network map shows a mix of 2920, 2610, 2626, 2520, 2510G, 6108, 2530, 2910al, 2824, 2810.... all managed and on latest available firmware at least!

 

LACP for aggregate links from distribution to access switches in each comm room so I'll keep a close eye on trunking for those!

 

The ISP bit I'm iffy'est about; when we switched they asked if we used VLANs and wanted the addressing for each subnet. Are they assuming that I'll be using their router as default gateway hmm.

 

I'm going to get through all the switches putting in VLANs and tagging trunks etc in preparation today.

Posted

  • Guest Wifi - how do I ensure that a specific VLAN can't reach anything other than the internet? ACL/routing table? Unsure!

.

 

Setup the same VLAN as your Guest WIFI on your firewall and have the firewall hand out DHCP addresses and forward DNS requests externally for that subnet.

Capture.PNG

Posted
Currently only have hosted firewall from ISP; setting up a pfsense box has been on the list for some time now. Probably a sensible time to make that happen.
Posted (edited)

Hi Ollie

First thing I would ask is do you need VLAN’s (how many IP addressable devices not just computers do you have?) are your edge switches connected directly to your core switch or do you have distribution switches in place?

How do you want to deal with things like printing, VoIP, CCTV etc will these be connected to their own subnet?

Will devices from different subnet be connecting via the same edge switch?

I see you are using a 24 port switch as you core switch so I little bit more of an overview as to where everything plug in would help understand your topology and where any bottle necks might be as you don’t want to be relaying on the buffering within you core switch.

With regards to guest Wi-Fi do you host anything like say a website that a guests would need to access if not then I would go very simple ask you ISP to provide a secondary network without a route to your primary network and connect your guests to that, your ISP might even provide DHCP within that network so you don’t have to.

Edited by Techforyou
  • Thanks 1
Posted

Already actually have a separate VLAN for IP voice traffic recently implemented but that sits on a completely different address range so not had any of the concerns around routing internet traffic.

 

VLAN requirement becoming more important re BYOD/guest and looking at bringing in IP CCTV to completely overhaul our current CCTV system. I also absolutely want to separate off servers/switch management from general use - my rough VLAN plan is:

 

- Management/infrastructure

- Servers

- Voice

- CCTV

- Printers

- Main

- Wireless

- BYOD/guest

 

Our network is arranged with distribution switches fed from the core all by 10GbE fibre except two low-use locations that are on 2Gb LACP links then access switches all on 2Gb links from the distribution.

 

I've considered putting the tech block on its own VLAN as there's ~150 machines there running off a single 10gig link from the core.

 

Hmm; I like the idea of having a secondary guest network; I may want to do slightly more granular control over access though - limiting year group access for example (as only our sixth form are allowed phones in school) and guest logins from our sign-in system.

Posted (edited)

OK so if you already have VoIP then have you got QOS setup or are you relying on the bandwidth of the core link having enough overhead?

There are many way to segregate off subnet’s but I went with simple, it can make is easier to trouble shot if there is a problem, I use the 10.0.x.x range so for example VLAN 10’s subnet is 10.0.10.x, VLAN 11- 10.0.11.x etc.

I do not have distribution switches all of my edge switch have 2 x links (LACP) back to our core stack with 1 link to the first core switch and the other to second core switch this removing single point of failure as much as is possible and increases overall bandwidth availability.

All servers connect to the core switch with and 2 x link same as the edge switching.

For IP ranges I use x.x.x.x/24 for 90% of subnets with a DHCP scope offering the first 200 address which leave the rest of the subnet for anything that might need to be assigned with a reservation.

If I need more address in an area i look to break up that area via something like the building, department or cabinet.

Wi-Fi we have 4 SSID’s all assigned to their own subnet with a x.x.x.x/23 subnet for each.

If I was you take a little time to make sure you are not going to overload a physical link to a single switch as the first things that will play up with be VoIP.

10 GB links we have around 75% of the edge switch’s connecting to the core with 2 x 10GB LACP link but this is well over the top bandwidth wise but I had a blinding deal when we were purchasing the edge switching and got the 10GB version of the edge switch for the same price of the 1GB so why not [emoji41] this did then highlight that some of our fibre runs were just over 350 meters which is why the whole campus has not been able to take advantage of the faster speeds yet.

We also have central printing so all MFD’s connect to their own subnet which has an ACL so users can not print directly to the printing device which would allow them bypass our Papercut solution.

Have you used VLAN’s yourself at all?

Are you going to be doing all this yourself?

Make sure you let staff know that the system will not be available for something like a whole week so you have time to resolve any problems that might come up.

 

If you have some spare switching set it up and test so you know what to expect when it come to D-day.

Edited by Techforyou
  • Thanks 2
Posted

Got QoS on the switches for the voice VLAN and having a separate VLAN itself stops the phone broadcast traffic from cluttering everything else up.

 

We've got so many 24/48 port switches for access spread out over such large distances it's not practical to directly link each access switch to the core; it was only thanks to remnants of some redundant fibre from an old network that I was able to get every distribution room pointing to any kind of core at all!

I've got the fibre to make it 20GbE to the tech block in future and I'll probably upgrade the biggest cluster of switches to one of those nice modular ones that can serve the whole block and cascade those faster switches elsewhere when I see the money! I've got spare switches meaning if anything does give up, I can switch out while HP warranty kicks in (next day replacement). It's not the best solution but I can rely on it.

 

For simplicity with my installation I've broken up the existing major network (ample in size) in to subnets adequately sized for each VLAN; and it means that I can keep server and switch IPs the same (especially useful for various NAT'ing and firewall rules that're done by the ISP currently - it's one less thing to break)

 

If the routing is right then I can't see how much can go wrong; I'll be doing the vast majority myself although have got a tech who will be checking specific port requirements (APs, printers) etc - going to configure everything I can in advance then take the plunge on a weekend.

 

I've contacted the ISP to see if anything needs doing on their end.

Posted

If you are going to change the core switch at some point than just to throw a spanner in the works have you considered merging you distribution and core switches into a core stack using the fibre you already have to create a ring and then most of not all your current edge switches can plug directly into your core.

I would setup you spare switching and just have a play it will help you understand.

 

There will undoubtedly be things that you did not foresee when making a major network topology change like this so just give yourself time to understand/ fix and problems.

I would do this work of during the summer holiday and book in some maintain time so there’s no pressure from staff that want to come in and use the system.

Posted
In regards to routing I would not route you internal network via the ISP’s router as it’s connection you your core is likely to be 1GB at best, so get you core switches to do the main routing within the network as this is much more efficient.
Posted

Stacking is something I've not given a huge amount of thought to in the past but it would be a nice way of bringing the distribution infrastructure together;l can definitely do it with IRF; maybe sometime in the future. Plenty else to worry about first!

 

And re doing the routing ourselves; agreed! I get twitchy around the ISP bits because I can't even see the config of their router, it's a big unknown that has a frustratingly large impact on my own infrastructure.

Posted
I've been considering putting a pfsense box in for some time; it's one of those projects best suited for the future though. No traffic issues as such, load is spread out nicely enough around the school.
Posted
What issue is there with using PFSense? Done right I see no issue. In my situation I'm also protected already by a perfectly adequate firewall.
Posted
I have to say I’ve not taken a good look into at the capability’s of pfsence so assuming the software can provide all the protection you need just make sure the hardware is up to job.
Posted

Everything is software.

 

Issues are: uptime, updates, knowing your config is secure, throughput, latency.

 

If your servers are clustered, no single point of failure etc, then software pfsense might be more reliable, but there's a complexity there that a computer in a box that just runs a firewall doesn't have. You know your LAN is safe because there's only 1 connection to the internet, and it's via that box, a misconfiguration of a virtual switch can't expose your LAN to the internet.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...