Jump to content

Recommended Posts

Posted

We are in the lucky position of having our CtC program fully funded including the replacement of all our Switches and Fiber connections.

 

Having had a basic flat network forever (due to being part of the LA Vlan), now no longer being part of the LA network how would you have your network and wireless setup going forward. Seeing as the contractor will be setting this all up and then transplanting the new network in I might as well take Advantage of that and get it set with the most features possible.

 

So how would you set up a new network and wireless structure, what Vlans would you have what wireless features would you take advantage of, the whole solution is Meraki.

 

Thanks in adavance.

Posted

You need to think about what types of devices and users you have on your network, and how you want to separate and firewall them off. So for example, BYOD, Staff, Student, Guest, BMS systems and Boilers, CCTV, Access Ctrl, Switches and servers etc

 

I'd recommend not having too many.

 

Also consider how many devices might be on each vlan. You might not have many student devices now, but what if the school grows, or students start connecting phones, laptops as well as the your student IT rooms? Changing this in the future might be complex.

 

You might also have to discuss with your ISP how to do the routing between the networks and the wider internet.

 

Some things like BMS and CCTV cameras might not need to be on a routable subnet if everything goes back to 1 recorder/server. You can normally add a second interface onto this vlan (Either trunked or as a second Physical interface)

  • Thanks 1
Posted

We separate our different types of devices or systems into different VLANs, including:

 

Staff desktops (Dot1x)

Student desktops (Dot1x)

Staff laptops (Dot1x)

Student laptops (Dot1x)

Servers

Server management (ILOs, vSphere, etc)

Network management

CCTV

Cashless catering

BYOD Wi-Fi

Guest Wi-Fi

Telephony

  • Thanks 2
Posted

CCTV, WiFi, BOYD, Servers, and management, BMS, ARX defo have on their own. Security and the noise that might interfere with other devices.

 

But vlans in themselves don't always provide security as if the gateways are on the same core switch they are normally able to talk to each other by default so you might want to think about ACLs.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...