Jump to content

Recommended Posts

Posted

Evening all :)

 

I'm looking for some advice and guidance on creating new subnets and vlans on our network. I imagine this is something that quite a few people have already done.

 

With the exception of VMWare management, we're currently running one flat network at our school. Everything is on one VLAN and one 10.14.0.0/16 Subnet.

 

What we'd like to do is subnet and Vlan our network so that device are separated based on their functionality. For example, Student PC's, Staff PC's, Printers, Servers etc. I'm trying to formulate an overview of a plan, listing the steps to achieve this. Does anyone have any pointers on what I should be doing?

 

Our networking equipment is HP, with a 5400 series core. We also have a Smoothwall firewall that's currently acting as the default gateway.

 

 

We'd also like to use this exercise as a chance to implement a little network security. For example, would it be possible to stop PC's on the Student network from being able to access the MIS server?

Posted
Sounds like you already have a fairly good idea of what you are doing. You've already decided on how you wish to segment your network so really it's just a case of setting everything up. The 5400 Procurves are a dream to work on so setting up the VLANs shouldn't pose any problem. In our network we use the 5400 core to perform the routing and is the default gateway for all clients on site. We then IP route from the 5400 to the router provided by our ISP. In regards to your question on preventing student PCs from access your MIS server then you can indeed do this using access control lists. Provided of course that your MIS server doesn't reside on the same subnet as the student machines.
  • Thanks 1
Posted

In terms of ACL's for the MIS server, would we restrict the Student vlan to the specific IP address of the MIS server?

 

Are there any actions that you came across as part of the process that you'd not considered

 

Also, has anyone changed the IP address of their domain controller as part of resubnetting? Just wondered if you'd experienced any issues.

Posted (edited)

You can restrict single IPs or whole subnets using ACLs. You'd have to plan out the best case for yourself. For us there are no services on our staff subnet that student machines would need access to so we blocked access to the entire subnet. Your requirements may be different depending on where your services are located.

 

I don't think there was anything major that I hadn't considered.

 

I did do an IP change of our DC during a resubnet along with all of the other servers since we were changing our entire internal IP ranges. Just ensure that you put the IP helper addresses into each vlan on the switch so that it doesn't break DHCP and the core switch will need an IP on each subnet that it is to perform routing for.

 

I suppose the first thing to look at is how you are going to divide up your range of addresses. Some subnets might not need to be as large as others so you can use different subnet masks for each one. Get your new scopes configured so that when you effect the switch you can simply enable them.

Edited by NetworkServices
Posted
Great. In terms of services on the staff subnet, what do you have on your staff subnet? Is it just staff PC's?. Do you have servers/services on different subnets based on whether staff or students require access, or one subnet for servers.
Posted

I divided mine up into 9 different subnets.

 

Staff - Contains all staff workstations

Wireless - Contains all domain joined wireless clients

Hotspot - BYOD subnet which is blocked off from accessing all other subnets via an ACL (except for DHCP/DNS of course)

CCTV - For all of the CCTV cameras. This uses an ACL to prevent access to the cameras from anywhere except our management machines

VOIP - For IP phones

Admin - Servers, Printers, our management machines and other miscellaneous devices.

Student VLAN is split into three different subnets depending on where they are located. For example Old Building, New Building, New New Building etc.

 

I don't think I have anything in the staff VLAN aside from Staff workstations. I mean you could put your MIS in here if you wanted to minimize routed traffic but I always prefer to put all servers on a dedicated subnet and the 5400 switch will route at line speed anyway so you likely won't notice any difference.

  • Thanks 1
Posted

In terms of the DC's, I've been thinking (which I know can be dangerous)

 

Perhaps, would it be better to commission two new Domain Controllers on the new subnet and decommission the old DC's, rather than change the subnet on the existing DC's? Or, am I being over cautious?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...