Jump to content

Recommended Posts

Posted

Hi all,

 

When I inherited our network nearly 12 months ago it was just a basic/flat setup.

 

We have about 450 wireless clients, and about 30 (mixture of voip phones, printers, desktops) wired devices now live on the network.

 

I have been wanting to implement VLANs for a while, but just struggled to carry this out, amongst the long list of other stuff I have to do.

 

My first goal is to separate each SSID and place them onto their own VLAN. So when someone connects to Guest for example, they recieve an IP from that dedicated subnet. I can then adjust the filtering and add these separate subnet ranges so devices get the correct filtering automatically. After setting these up, I will then look into creating VLANs for our wired devices, but currently we rely much more on our wireless system, so I believe this takes precedence.

 

As our DHCP and DNS is all hosted router side by the ISP, I guess my first task is asking them to create these VLANs with the correct ranges and enable DHCP on them?

 

I can then go into UniFi and add the VLANs and subnets. This will allow me to assign each SSID to the relevant VLAN.

 

Can anyone see any further issues I might run into?

 

Thanks.

Posted (edited)

You want to try and limit SSIDs to as little as possible 3 max is ideal. Allocating vlan per role, device, access, etc would be ideal. Rather than having a SSID per vlan.

 

Do you have control over your IP space or is it under LEA/ISP. i.e. are you free to use any internal IP subnet you want.

 

I assume you have no layer 3 switch doing routing and all vlan gateways are on the ISP router/firewall

Edited by Davit2005
Posted (edited)
You want to try and limit SSIDs to as little as possible 3 max is ideal. Allocating vlan per role, device, access, etc would be ideal. Rather than having a SSID per vlan.

 

Do you have control over your IP space or is it under LEA/ISP. i.e. are you free to use any internal IP subnet you want.

 

I assume you have no layer 3 switch doing routing and all vlan gateways are on the ISP router/firewall

 

Hi, thanks for your reply.

 

We currently have 3 SSIDs. ****-STAFF ****-STUDENT ****-GUEST. So you would advise not having these on separate VLANs?

 

I don't want to go over the top (heard/seen horror stories in the past)

 

I do have access and control over the IP space, so I can supply the ISP with the subnets I would like to use.

 

We don't have any routing enabled on our switches currently, so yes, the VLANs would be configured on the router/firewall then I would add them to the UniFi console (This is for the SSIDs). I could then setup port tagging at a later date once those VLANs are configured.

 

Thanks.

Edited by HyperTech
Posted (edited)
Hi, thanks for your reply.

 

We currently have 3 SSIDs. ****-STAFF ****-STUDENT ****-GUEST. So you would advise not having these on separate VLANs?

 

I don't want to go over the top (heard/seen horror stories in the past)

 

I do have access and control over the IP space, so I can supply the ISP with the subnets I would like to use.

 

We don't have any routing enabled on our switches currently, so yes, the VLANs would be configured on the router/firewall then I would add them to the UniFi console (This is for the SSIDs). I could then setup port tagging at a later date once those VLANs are configured.

 

Thanks.

 

Not really, what I meant was to have the vlan assigned on a user/group basis but the same SSID for example. There might be more efficient ways to do it however these days.

Edited by Davit2005
Posted
Not really, what I meant was to have the vlan assigned on a user/group basis but the same SSID for example. There might be more efficient ways to do it however these days.

 

^ definitely this.

Combine the staff and student SSID's into a single "staff and students" SSID and then, based upon the type of device they login with (school owned or BYOD) and their groupID assign them into a VLAN using a RADIUS server.

We used to use a 'dirty' VLAN that we essentially treated as the internet for all BYOD, then an internal one that staff could access and another that students could access.

Posted

In an ideal world you should only have Curriculum and Guest SSID's

 

If you go back to basics, those are the only two types of devices in the school:

 

School owned devices for both staff and pupils = Curriculum

 

Anything that isn't school purchased = Guest.

  • Thanks 2
Posted
This is an interesting take. Didn't think about this method, although, having 3 SSIDs doesn't bother me that much. I just push the SSID out to devices anyway (Chromebooks, iPads etc) I also think it 'seems' more organised in my head, although probably not technically haha!
  • Thanks 2
Posted (edited)
I'd personally try to go down the radius route with a single SSID if that is possible. However Unifi now have 'Private Pre-Shared Key' which is a nice feature in theory. You can broadcast a single SSID and depending on the password supplied to connect you can tag users in a particular VLAN. https://www.unihosted.com/guides/configuring-private-pre-shared-keys-unifi-guide

 

Ah ok... I know what this is now. Sorry for the confusion, so with this feature, I assign a password to a particular VLAN.

 

So when a device connects to the single SSID, it will check what password it used to join, and subsequently place them in the corresponding VLAN? This sounds like exactly what I need. Thanks for explaining :)

Edited by HyperTech
Posted (edited)

The Unifi concept is a good one but you have the issue that if the password is compromised you could have students and staff on the same vlan as far as I see into the unifi method unless I am misunderstanding how it works?

 

And as some OS versons make it easy to share the password I would not rely on it personally.

Edited by Davit2005
Posted
In an ideal world you should only have Curriculum and Guest SSID's

 

If you go back to basics, those are the only two types of devices in the school:

 

School owned devices for both staff and pupils = Curriculum

 

Anything that isn't school purchased = Guest.

 

There's also Guest_unencrypted for all the old devices that don't do OWE people bring in

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...