Jump to content

Recommended Posts

Posted

Hi all,

 

So the big project for us at the moment is our network refresh. It's proabably a good 2-3+ years too late and we are having to do everything internally because the money for any kind of outsourced help simply does not exist - even next financial year. Becuase we are stretched for people as well - it's just me full time and my manager (who isn't even employed for anything IT related, he just happens to have the relevant knowledge and experience to be able to manage me and works with me on the bigger stuff, decisions etc), we are having to do this piecemeal, so we have discussed with some UniFi-experienced folks and planned accordingly. Bearing in mind neither one of us has done anything of this scale bfeore...!

 

Step 1 is the installation of the gateway, for which we have chosen the Dream Machine Pro Max, so that all the other UniFi stuff can talk to it properly.

 

Now, I've been told about using the default VLAN exclusively for UniFi devices and setting up another, separate VLAN for all other devices. We have a UniFi UPS that we will be running it off as we were warned that these gateways that run DBs can become corrupted if they don't have adequate time to shut down properly - not the kind of thing anyone wants to find when they get to work first thing on a Monday morning...! Aside from this, is there anything obvious I should know before going ahead with this?

 

Talk to me as if I know nothing, if you like - honestly I'd rather be told the same thing 100 times if it means there's something else that doesn't get missed. It also doesn't help that when we get things that are very straightforward we keep asking each other "Is it really that easy? Surely not!".....

 

Cheers,

Rupert

Posted

You don't need to use the default vlan, setup a specific management vlan.  Aim to not having any client traffic untagged on uplinks.

 

The Unifi controller can be kept on separate vlan ACL'd and then FQDNs used so the APs etc can talk to the controller.

 

If you are starting with the Unifi Dream Machine and you have control over your internal address space you have the option to create separate networks, take the opportunity 🙂 

  • Like 1
Posted

Ive done the following VLANs below, besides management and domain PCs everything is hosted by unifi.

Default has only the gateway, USW-WANS (not friendly on VLANS)

I set this up recently and moving other bits still. If you set content filter on then it breaks domain connections so be aware.

WAN DNS Servers use Quad9.

 

Also top tip as it helps performance ALOT is to do the following:

Cybersecure > Traffic Logging > Uncheck Data Retention to Auto then turn off Collect Historical Data.

image.png.cdd4ac64d9de668534bd15c275aeaaba.png

 

image.thumb.png.6a7015efc0111a15d87f66adf2d99d7b.png

  • Like 1
Posted

Not spoon-feeding here, just have some questions.

 

  • Are you using the Dream Machine as a controller only, or are you going to be routing your internet through it?
  • Do you have separate VLANs at the moment, if so what is doing the Intervlan Routing
  • Are you going to be adding Unifi Switches and APs throughout the site at the same time?

 

  • Like 1
Posted

All noted, thanks folks, we'll be collating everything before we do any work.

 

Davit2005 - with regards to creating separate networks, do you say this with any particular reasoning, or just if we want to?

 

AlphamaleZed - thank you. That makes sense, but it's a lot of VLANs!

 

BKGarry - 1. routing the internet through it

2. Not at present

3. Not at the same time, no, they will follow as it's being done piecemeal - so the gateway will go in first, switches will follow, and APs finally - then we will repeat at the other school site (we share a network as they are on the same premises, they are connected via point to point) using what we have learned from the process of actually doing it.

 

Cheers,

Rupert

Posted
33 minutes ago, td5roo said:

All noted, thanks folks, we'll be collating everything before we do any work.

 

Davit2005 - with regards to creating separate networks, do you say this with any particular reasoning, or just if we want to?

 

AlphamaleZed - thank you. That makes sense, but it's a lot of VLANs!

 

BKGarry - 1. routing the internet through it

2. Not at present

3. Not at the same time, no, they will follow as it's being done piecemeal - so the gateway will go in first, switches will follow, and APs finally - then we will repeat at the other school site (we share a network as they are on the same premises, they are connected via point to point) using what we have learned from the process of actually doing it.

 

Cheers,

Rupert

Yeah i know lol!

 

We have about 150x Cameras, 30x Switches, 80x APs, 100 Phones etc... so good to separate it.

Posted
1 minute ago, AlphamaleZed said:

Yeah i know lol!

 

We have about 150x Cameras, 30x Switches, 80x APs, 100 Phones etc... so good to separate it.

 

Jesus, that's a lot.

 

We're looking at maybe 20-30 APs max, ~10 switches, ~10 cameras (and controller/recorder), ~40 phones, and eventually our external doors/gates.

Posted
5 minutes ago, td5roo said:

 

Jesus, that's a lot.

 

We're looking at maybe 20-30 APs max, ~10 switches, ~10 cameras (and controller/recorder), ~40 phones, and eventually our external doors/gates.

yeah big school!

 

For you i would say maybe have VLANs for UNIFI (All UNIFI Stuff), VOIP, IOT (CCTV, Gates,Doors and whatever else. mine is smart lighting/plugs/future stuff etc..)

Then your Management VLAN for Servers, Domain PCs VLAN etc...

 

Also if your using UNIFI for switches look at setting up profiles, that way you an set a PC VLAN and Phone VLAN and can do bulk updates to stuff really handy having these profiles.

  • Like 1
Posted
1 minute ago, AlphamaleZed said:

yeah big school!

 

For you i would say maybe have VLANs for UNIFI (All UNIFI Stuff), VOIP, IOT (CCTV, Gates,Doors and whatever else. mine is smart lighting/plugs/future stuff etc..)

Then your Management VLAN for Servers, Domain PCs VLAN etc...

 

Also if your using UNIFI for switches look at setting up profiles, that way you an set a PC VLAN and Phone VLAN and can do bulk updates to stuff really handy having these profiles.

 

We're doing UniFi for everything, switches, APs, cameras, the whole lot, deliberately, so will do that - that makes good sense. Thanks!

Posted
1 minute ago, td5roo said:

 

We're doing UniFi for everything, switches, APs, cameras, the whole lot, deliberately, so will do that - that makes good sense. Thanks!

Yeah one VLAN would be great. Do you use smoothwall for firewall and filtering at the moment?

  • Like 1
Posted
13 minutes ago, AlphamaleZed said:

Yeah one VLAN would be great. Do you use smoothwall for firewall and filtering at the moment?

Currently we use Netsweeper which is provided by our broadband supplier.

Posted (edited)

Creating vlans makes laterall movement that much harder specifically when you can isolate with ACLs and firewalls (either host or network or ideally both)

 

To start with you don't want your CCTV on the same network as any other clients, that is a big no no.

 

Really any device should only be given access to the Internet if it requires it. Least privilege's model been best practice.

 

IoT should be defo be separated

 

If possible put servers on their own vlan too.

 

Depending on the size of the org I'd contemplate having different vlans for buildings, separate vlans for Building Management and access control too not only for security and noise but also if you have a switching loop on a client network it won't effect other areas.

 

Then separate Guest and BYOD for Staff/Student

 

If your Dream Machine is going to be a main router/firewall follow best practices too. I think that Unifi default is to allow traffic rather than deny by default but could be wrong on that.

 

If there is an upstream router it might complicate things slightly.

Edited by Davit2005
  • Like 2
  • 1 month later...
Posted

Hi all,

 

So the time has come - we've got the UDMPM and it's hopefully going in during the Easter break.

 

The added complications are that we still have a DC, and an upstream router from our broadband provider. This is going to be fun. :D

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...