Jump to content

Recommended Posts

Posted

I need a bit of guidance. I understand VLANs, but I have never set one up in practice, and am a little unsure of a few things especially with our LEA managed network.

 

Politics/PAT testing/antivirus aside for a moment, we have been asked to look in to the possibility of setting up wireless access for after hours governors meetings, and students. I don't want these on our network as you would expect, so, I presume we would want to set up a VLAN to put them on a private network. Even if we don't implement this, I'd still like to try it out as a learning exercise.

 

Our main network switches are provided by and managed by our LEA, but we have a few HP1800-24G switches which we can control.

 

How do I go about setting this up? If I put a port on one of our switches on to a private VLAN in one area of the school, how do I route this to our network for internet access? We also run Censornet for filtering, so would I need a second Censornet box on this new VLAN to provide the filtering?

 

Any pointers welcome.

  • Thanks 1
  • 9 months later...
  • 2 months later...
Posted

Hello,

 

I was lookng up information on setting up VLANs and came accross this posting. Wow...you must be a good teacher, becuase after searching through a lot of convoluted blurbs about VLAN networking, this posting was like a breath of fresh air. Crystal clear explanation for a new learner!

 

I have a question for you. Recently we set up an IP surveillance system that connected a bunch of IP cameras, a NAS box running on an iSCSI ethernet connection, and a basic office network that had access to the NVR recorder. The NVR, cameras and office are on the same network range. The iSCSI storage appliance is on a different network range. Both of these networks are connected to the NVR with two seperate NICs. I have these connections converging into a gigabit switch that is in turn connected to the two NVR network cards.

 

Is this the type of setup that should be using a VLAN capable switch (maybe also with QoS) to ensure smoother operation of both networks converging into one switch, or does it matter? I am wondering if there is inefficient data flow or collisions occurring because I have all this data streaming from cameras on one IP range, and a constant stream of data going to the NAS box on another IP range, all through an inexpensive D-Link switch. Perhaps I need to revisit this and set it up with a better switch to ensure smoother networking?

 

Hopefully you can give me your thoughts on this.

Posted

Im afraid I can't go into specifics here as each design is dependent on local topolgies and your internal politics!

 

But your ISCSI , Cameras and Office should be on different VLANs for sure.

 

It sounds like you have the ISCSI on a different IP range but still connected to the same switch as everything else?

 

This is far from ideal as even though the devices dont see each other at Layer 3 (IP) the switch will still see everyting at Layer2 (MAC)

So intensive ISCSI read/write operations is being chopped up by normal LAN traffic and vice versa.

 

If practical I would simply connect the ISCSI array directly to the NVR (ISCSI) NIC with a direct cable connection. If thats not possible (eg the NVR is too far away from the NAS) use a dedicated VLAN to isolate the traffic on the switch.

 

All of my LAN nodes are allowed to access our NVRs, we have 90 cameras connected to the NVR array VLAN_CCTV

The NVR Array has a LAN facing NIC with an IP address on our data network, VLAN_DATA

All camera traffic is contained on VLAN_CCTV

 

To view any camera a user logs in to the NVR and selects the camera(s) to be viewed this is then streamed to that user on the VLAN_DATA.

 

Hope that helps.

  • Thanks 1
Posted

Thanks that does help. It shouldn't be a big deal to connect the iSCSI directly. I will do that.

 

As far as the office goes there is only 2 computers not including the NVR. I suppose it would be ideal to have them on seperate VLANS, but as far as traffic goes, it's pretty much mostly the cameras streaming to the NVR.

 

I think we will just look at getting the iSCSI traffic off of the switch and leave it at that. Next time we do something like this, I'll be installaing a smart switch for sure.

 

Marc.

  • 3 years later...
Posted (edited)

@m25man, your explanation was excellent and helped me understand VLANs much better than any other site or explanation I've read. Thank you!

 

I do, however, have one question for you please?

I'm using UniFi WiFi points which allow me to create multiple SSIDs. I've created a "DainfernCollege" SSID (with no VLAN) and a "Guest WiFi" SSID (With a VLAN ID of 5). What do I tag the ports that these points are connected to as?

And what about the uplink ports? If I tag the outgoing traffic as 5, what about the rest of the traffic on the switch that isn't VLAN'd?

 

VLAN Diagram.jpg

Edited by Nick_Parker
Spelling... whoops!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...