rlculver Posted April 16, 2020 Posted April 16, 2020 Hi, I am looking to introduce VLANS to a small special school network. Teacher / Student / School Admin - VLAN10 (192.168.10.x) - They access the same server / printer. Guest Network - VLAN20 (192.168.50.x) - Need to provide only internet access and no access to printers / server. I know VLAN10 have a few groups, but they all access the same server and printers. Was thinking of having printers (2 x Copiers) on a separate VLAN, but is this necessary for such a small network ? Look forward to you comments. Thanks Robert
Norphy Posted April 16, 2020 Posted April 16, 2020 As I see it, the main reasons to segment your network are: 1) Security - you might not want some people to access certain parts of your network. This can be achieved with ACLs and most likely other methods I'm not aware of. An obvious use for this would be a guest wireless network or maybe your CCTV. 2) To reduce the size of your broadcast domains. The general recommendation is that you don't have more than 500 devices per subnet otherwise broadcast traffic gets unmanageable. As a subset of this, you might have a device that's particularly chatty and sends out lots of broadcasts, so you might want to separate that out. 3) Organisation - Not a technical reason as such you may want to say "This area has that range of addresses" or "This kind of device lives in this address range", for example servers. For 1 and 3, the size of the organisation isn't too relevant. You never want Wifi guests to be able to access your production network whether you have 50 users or 500,000 users. As for separating out your photocopiers from the rest of the network, it might be worth doing if they broadcast a lot of traffic and those broadcasts are affecting your network performance (it's not unheard of with printers and photocopiers) or if you want to make sure that no-one but your reprographics department are able to use them as printers or otherwise access them over the network. I seem to be saying this a lot recently but honestly, there is no definitive right or wrong answer to this question. 1
rlculver Posted April 16, 2020 Author Posted April 16, 2020 Hi Norphy, Many thanks for your info. Totally understand. As I am dealing with a small school network, and I am not on site all the time, I was thinking of the following : - VLAN10 - Standard VLAN for network communication VLAN20 - VOIP Phone System, so I can control voice traffic (No Requirement for internal network communication) VLAN30 - Guest WiFi - No access to internal network. What are your thoughts?
Davit2005 Posted April 16, 2020 Posted April 16, 2020 (edited) Hi Norphy, Many thanks for your info. Totally understand. As I am dealing with a small school network, and I am not on site all the time, I was thinking of the following : - VLAN10 - Standard VLAN for network communication VLAN20 - VOIP Phone System, so I can control voice traffic (No Requirement for internal network communication) VLAN30 - Guest WiFi - No access to internal network. What are your thoughts? Other considerations worth thinking about are where you are going to have the gateway of the guest network, personally I'd put it on the firewall. This will make it easy to control what services guests will be able to access, if any on your internal network. As you should be either able to control it via ACLs on a Zone or Interface of the firewall. Do you have a layer 3 core switch capable of doing the routing for your internal traffic? VOIP should always be on it's own vlan, it is susceptible to interference from noisy devices. I seen where a phone has been put on same vlan as printers/desktops etc and it was unusable due to network noisy devices. Edited April 16, 2020 by Davit2005
rlculver Posted April 16, 2020 Author Posted April 16, 2020 Hi, I was going to use our firewall / filter device as our Gateway. I have a L2 switch, as was planning on our firewall / router providing the routing. Thanks
ITGURU Posted April 16, 2020 Posted April 16, 2020 As I see it, the main reasons to segment your network are: 1) Security - you might not want some people to access certain parts of your network. This can be achieved with ACLs and most likely other methods I'm not aware of. An obvious use for this would be a guest wireless network or maybe your CCTV. 2) To reduce the size of your broadcast domains. The general recommendation is that you don't have more than 500 devices per subnet otherwise broadcast traffic gets unmanageable. As a subset of this, you might have a device that's particularly chatty and sends out lots of broadcasts, so you might want to separate that out. 3) Organisation - Not a technical reason as such you may want to say "This area has that range of addresses" or "This kind of device lives in this address range", for example servers. For 1 and 3, the size of the organisation isn't too relevant. You never want Wifi guests to be able to access your production network whether you have 50 users or 500,000 users. As for separating out your photocopiers from the rest of the network, it might be worth doing if they broadcast a lot of traffic and those broadcasts are affecting your network performance (it's not unheard of with printers and photocopiers) or if you want to make sure that no-one but your reprographics department are able to use them as printers or otherwise access them over the network. I seem to be saying this a lot recently but honestly, there is no definitive right or wrong answer to this question. I've never understood number 2 - we have 700 desktop pcs all on the same main vlan and never have broadcast issues? 15kb/s is our idle broadcast traffic. Is it really only for high latency/slow links where it would be an issue?
synaesthesia Posted April 16, 2020 Posted April 16, 2020 Desktop PC's generally won't chatter much. Check the same figures on your printer vlan. (Stereotypical sexism alert!) PC's are like a load of drunken old men in a pub, they'll acknowledge eachother's existence, make it known when they're about to puke or pass out and let everyone know when it's time to go home. Printers however are like stereotypical women on a shopping spree; you can't shut them up for love nor money and even chatter away in their sleep. (No offence meant by this poor analogy of course, an old schoolfriend of mine used this once and it's stuck with me ever since). I'd add something about the strange devices invariably connected to your network even though you'd rather they didn't - you know the sort, cashless catering systems designed by Archimedes himself, "smart" heating systems you're fairly sure are sentient and plotting to kill us all and those ruddy little chinesium laptops that Mummy bought Johnny saying "It's every bit as good as Suzie's Dell but only cost £70" but conform to no standards for anything. We all know the sort, the label says it's an Intel ABGN yet when you plug it into the network it's screaming GIVE ME ALL THE TOKENS! like a crazy old civil war veteran who's forgotten what year it is.
ITGURU Posted April 16, 2020 Posted April 16, 2020 Desktop PC's generally won't chatter much. Check the same figures on your printer vlan. (Stereotypical sexism alert!) PC's are like a load of drunken old men in a pub, they'll acknowledge eachother's existence, make it known when they're about to puke or pass out and let everyone know when it's time to go home. Printers however are like stereotypical women on a shopping spree; you can't shut them up for love nor money and even chatter away in their sleep. (No offence meant by this poor analogy of course, an old schoolfriend of mine used this once and it's stuck with me ever since). I'd add something about the strange devices invariably connected to your network even though you'd rather they didn't - you know the sort, cashless catering systems designed by Archimedes himself, "smart" heating systems you're fairly sure are sentient and plotting to kill us all and those ruddy little chinesium laptops that Mummy bought Johnny saying "It's every bit as good as Suzie's Dell but only cost £70" but conform to no standards for anything. We all know the sort, the label says it's an Intel ABGN yet when you plug it into the network it's screaming GIVE ME ALL THE TOKENS! like a crazy old civil war veteran who's forgotten what year it is. All our printers, photocopiers, desktops and servers are all on the same vlan ! VLANS are only separate for CCTV, Access Control, Guest Wifi and Out of band server and switch management,
Guest Guest Posted April 16, 2020 Posted April 16, 2020 I wouldn't use class c address ranges, they could conflict if you were to later setup a VPN for example
rlculver Posted April 17, 2020 Author Posted April 17, 2020 Many Thanks for the Comments. I do not think I am going to have broadcast issues, due to the number machines on the network. Do you think this sounds OK. We can always adjust as the network develops ? VLAN10 - Standard VLAN for network communication VLAN20 - VOIP Phone System, so I can control voice traffic (No Requirement for internal network communication) VLAN30 - Guest WiFi - No access to internal network. Thanks
RobD Posted April 17, 2020 Posted April 17, 2020 If you're going to the effort then I'd put a printer vlan in too. Dont forget IP helpers and new DHCP scopes.
mavhc Posted April 17, 2020 Posted April 17, 2020 My suggestion is don't bother, just making things more complicated for no real gain. What problems are you having now that VLANs will solve?
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now