Jump to content

Recommended Posts

Posted

Hi,

 

So most the networks I have built for our Trust are either Dell (inherited) or HPE/Aruba. I would usually have a L3 core switch that would do all the routing and VLAN's however I am trying to plan it out for 2 new networks next year for a couple of schools we have sponsored and in need of refreshment.

 

We are going with Ubiquiti as we have used their switches and access points the last 4 years with no issues, but obviously planning on scaling up our UniFi capabilities by trunking fibre into a UniFi core switch, creating VLANs etc.

 

With our cloud controller we have already got configured for the Trust - I noticed we can create Corporate Networks with the IP range and subnet and it will work out the scope for you and give it a VLAN number, UniFi works out the routing by the look of it automatically.

 

Schools currently getting /24 internal range so I'll dissect that into several VLANs how I would usually do this on HP/Aruba Core.

 

However, I think we require a USG for this, but the standard USG only offers around 80-100mb throughput and BroadbandBuyer told me earlier that the USG-Pro-4 only really offers about 250Mb throughput - the schools will getting 1Gb broadband next year so seems a waste to not be able to use it with all this nice new kit we are potentially putting in.

 

Has anyone achieved this? If so please advice me what steps to take.

 

Thanks.

Posted

we have a HP Aruba core to do the routing (I will look at the version tomorrow, but it isn't anthing majour) and then everything else is Unifi. I don't really think the USG works for us in education with our extensive firewall and filtering we require.

 

I have the cabinet switches come back to a unifi 16-XG in the middle, which my server hosts also plug into, and then one 10gb link from the to the "routing core" as i call it and that has 1 port to the XG (for firwalls and filtering) and one to the VOIP server.

  • Thanks 1
Posted
we have a HP Aruba core to do the routing (I will look at the version tomorrow, but it isn't anthing majour) and then everything else is Unifi.

 

Out of curiosity, how nicely does the Aruba play with the Unifi in terms of fibre/dacs etc? Was considering a similar route, but most older threads I've seen seem to say they don't play nicely. Seemed a nice combination of powerful routing (with servers on aruba on our setup), and then all the edge unifi etc

 

Many thanks,

Steve

Posted

Fibre is not a problem at all, had to turn off the setting where it wants it to be a HP fibre module but everything works fine.

 

Make the VLAN, have it as tagged on the ports you want with your management/AP one as tagged traffic and put the VLAN number with the name you want in the unifi controller and it all works just fine.

  • Thanks 2
Posted
Fibre is not a problem at all, had to turn off the setting where it wants it to be a HP fibre module but everything works fine.

 

Make the VLAN, have it as tagged on the ports you want with your management/AP one as tagged traffic and put the VLAN number with the name you want in the unifi controller and it all works just fine.

This was the route I wanted to take with Aruba core setup and roll out UniFi on just layer 2 side with the controller it plays nicely with making VLAN only networks and putting number of VLAN in.

 

Working fine at one school we have done.

 

Only issue I have had so far is HP core to UniFi 16 port switch and created switch port profiles (vlan tags) for data vlan and access point vlan, that took some playing around.

 

UniFi SFP+ modules are pretty decent priced as well aren't they [emoji1303]

Posted
This was the route I wanted to take with Aruba core setup and roll out UniFi on just layer 2 side with the controller it plays nicely with making VLAN only networks and putting number of VLAN in.

 

Working fine at one school we have done.

 

Only issue I have had so far is HP core to UniFi 16 port switch and created switch port profiles (vlan tags) for data vlan and access point vlan, that took some playing around.

 

UniFi SFP+ modules are pretty decent priced as well aren't they [emoji1303]

 

They are very well priced.

 

I have the HP allow all VLANs over the port but then I can use switch port profiles for more than one VLAN with a default for no problems at all. But everyone works a little differently.

 

Personally, for our setups I wouldn't bother with a USG and have a decentish layer 3 switch in the middle somewhere. If those sites still have decentish core switches for VLANs, keep em ans use them

  • Thanks 1
Posted

If you are doing vlan routing it is best to keep it on a switch rather than a firewall (or Router on a stick)

 

The possible exceptions are where you'd prefer vlans seperated i.e. Guest networks, BOYD, CCTV etc. I'd personally route/terminate these on a firewall where it is sometimes easier to create rules than deal with switch ACLs but your mileage may differ. You are also going to be limited on the connection speed on firewall for your intervlan routing. So if you have a single 1GB port on the firewall all the clients are going to be using that 1GB including traffic not destined for external.

  • 1 month later...
Posted

Sorry to dig out this old thread.

 

After some research the last few days I am now thinking the following setup

 

ISP handover

Smoothwall Filter

UniFi Dream Machine Pro

 

 

From the dream machine create all VLANs and use it as the core

 

I can then uplink from UDM to 48 Port UniFi switch and then from there 10GB into the host.

 

There are only 2 cabs in the school which are supplied via linked between 1Gb CAT6 RJ45

 

 

 

 

Has anyone sucessfully got the ISP > Smoothwall > UDM-Pro setup?

Posted (edited)

Get something better than a UDM for core routing. Something like a proper layer 3 switch (e.g. Aruba/HP) and a separate router/firewall to make something like this: ISP > router > smoothwall > L3 switch > servers/clients (assuming the smoothwall is just the content filter and not the full firewall/filter product).

 

As the UDM will NAT everything the upstream smoothwall will show everything as coming from the WAN IP of the UDM.

 

does a fantasic job of describing the state of unifi routing products and puts it much better than I can (from 17:10 if the link doesn't take you there). Edited by computer_expert
  • Thanks 1
Posted (edited)

You could get a 2930f that has 4 x SFP+ ports and 24 x 1G ports for around 1K or cheaper and gives you the ability to move to a small stacked core using VSF although it is limited to the amount of SFP+ ports. But if you have small runs upto 100meters with 1G copper or even fibre using some Fibre to Ethernet convertors it should not pose to much of an issue. A VSF stack is flexible and as long as you use the same port types on each member. We use them as Edge switches or Top of Rack switches at work.

 

Even a Ubiquiti ES-16-XG would probably do the job although misses some Dynamic Routing, Stacking and some other but they may not be needed depends on your need.

 

Just think throwing a UDM in between your network and Smoothwall is going to complicate the setup and a Layer 3 switch may be the better option.

Edited by Davit2005
  • 2 weeks later...
Posted
Fibre is not a problem at all, had to turn off the setting where it wants it to be a HP fibre module but everything works fine.

 

Make the VLAN, have it as tagged on the ports you want with your management/AP one as tagged traffic and put the VLAN number with the name you want in the unifi controller and it all works just fine.

 

In terms of this setup, did you set up port trunks on your HP core to your UniFi switches?

 

If so - did you aggregate ports on UniFi end and set port profile to "All" to allow on vlans to pass through to uplink?

Posted (edited)

OK yeah to just tagg the vlans on the port of the HP 2930f that is connecting to the Unifi switch then on Unifi side either do add it to a profile (sorry do not have access to a Unifi switch anymore).

 

You are better off doing routing on a switch to be honest than using a router on a stick approach. Whilst doing the vlan routing on firewall will make segregation by use of security rules easy you can do the same on most core switches by using access control lists and applying these where necessary.

 

If you have not done any access control lists before just make sure you have physical access to the switch just in case you stuff something up and read up some documentation on doing them.

 

You don't need to do them but just bear in mind that if you use a core switch and terminiate the vlans there that by default there is nothing stopping users being able to access servers/devices on other vlans that have their default gateway on the same layer 3 switch.

 

Layer 3 switches are the way to go for vlan routing by sure.

Edited by Davit2005

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...