Jump to content

Recommended Posts

Posted

We are nearly ready to purchase our replacement core switches.

 

We have a virtual RouterOS core currently and often plays up. (Have to virtualy turn it off and back on again before it will start passing traffic.)

 

We also do have the SWGfL router as well. (Yes, previously, the team had this setup.)

 

Virtual core x.x.4.1

Swgfl core x.x.7.254

 

2 vlans being used as well

 

1 using the grids range

BYOD range x.x.8.0/21 which is routed though the virtual core to go out on 7.254

 

Also, we would be looking at adding more vlans once we change the Internet provider.

 

We are also looking at moving away from SWGfL for internet/filtering, but this is another topic for another day.

 

Back on topic.

 

We are looking at 2x Aruba CX 6300M 24-Port SFP+ JL658A and stacking them.

 

My question: How easy is it to configure these switches?

 

We were looking to get some external help to install and configure these switches but seeing how simple or hard it is to do this ourselves.

 

Hope this makes sense.

 

(No sarcastic comments, please. 😂)

Posted
It depends. What do you need configuring? For example, are you planning on using ACLS or is an existing firewall managing traffic between your VLANS?
  • Thanks 2
Posted

I'd look at VSX rather than VSF for core, VSX is more suitable for core layer if using Aruba CX.

 

Once you get started it becomes relatively easy. You will likely need to create a route from the next hop i.e. firewall to the core for the subnets that terminate on the core. @FN-GM says about using firewall vs ACLs. Firewall rules are generally easier to configure, I'd certainly consider routing Guests, WiFi and maybe even servers at the firewall level rather than heavily using ACLs.

 

As soon as you enable routing on a switch it will most likely allow traffic unless you ACL.

  • Like 1
  • Thanks 1
Posted

We was looking at VSX for the 2 core switches.

Looking at our current core now - we have firewall rules between main and BYOD Network (DNS,Print Server, Papercut Webprint)

 

NAT Rule - Masquerade from BYOD

 

That's all i can see that's being used.

  • Like 1
Posted (edited)

Open traffic between VLANS (expect BYOD) is a bit of a security concern. I would seriously consider reviewing this at some point.

 

To answer your question, it should be fairly easy. Make sure you test. Also make sure you have everything, don't forget the basics such as SNMP configuration, DHCP Snooping, IP Helpers etc.

Edited by FN-GM
  • Like 1
  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...