Advertisement

05.08.2008 at 08:27PM PDT, ID: 23388346 | Points: 500
[x]
Attachment Details
Setting up VLANs. Will this work? Please See Diagram.
Hi,
We are experimenting with VLANs and want to know if the proposed scenario will work.
I have drawn a quick flowchart and attached it as a PDF document.
Can you please take a look and tell me what you think?

Questions:
" Will this work?
" What sort of Cisco Switch will be needed to manage the VLANs?
" Is it ok to have Hubs between the Cisco Switch and the offices? The hubs are only needed to create more
ports to plug into for each building. What should be used here?
" Is it ok to have the IP phones on their own VLAN?
" Is splitting up the VLANs by MAC addresses the way to go?
" If an office decided to install its own SBS server how will this affect everything? Would it be possible for an
office to install their own

I appreciate any input. Thanks for your time.

Cheers
Attachments:
 
Diagram of proposed system. Will this work?
 
Start your free trial to view this solution
Question Stats
Zone: Networking
Question Asked By: SM17CH
Question Asked On: 05.08.2008
Participating Experts: 2
Points: 500
Views: 0
Translate:
Loading Advertisement...
05.08.2008 at 11:02PM PDT, ID: 21530638

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.08.2008 at 11:15PM PDT, ID: 21530682

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.08.2008 at 11:18PM PDT, ID: 21530690

Rank: Master

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.08.2008 at 11:19PM PDT, ID: 21530698

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.08.2008 at 11:40PM PDT, ID: 21530751

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.08.2008 at 11:46PM PDT, ID: 21530776

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.08.2008 at 11:49PM PDT, ID: 21530783

Rank: Master

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.08.2008 at 11:53PM PDT, ID: 21530801

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.08.2008 at 11:53PM PDT, ID: 21530802

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.09.2008 at 12:01AM PDT, ID: 21530830

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.09.2008 at 12:05AM PDT, ID: 21530845

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.09.2008 at 12:17AM PDT, ID: 21530886

Rank: Master

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.09.2008 at 08:15PM PDT, ID: 21537716

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.09.2008 at 10:15PM PDT, ID: 21537932

Rank: Master

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.11.2008 at 04:18PM PDT, ID: 21543881

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.11.2008 at 05:35PM PDT, ID: 21544071

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.11.2008 at 05:48PM PDT, ID: 21544103

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.11.2008 at 05:50PM PDT, ID: 21544109

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.11.2008 at 06:41PM PDT, ID: 21544226

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.11.2008 at 09:11PM PDT, ID: 21544620

Rank: Master

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.11.2008 at 09:11PM PDT, ID: 21544621

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.11.2008 at 09:18PM PDT, ID: 21544637

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.11.2008 at 09:21PM PDT, ID: 21544645

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.11.2008 at 09:41PM PDT, ID: 21544688

Rank: Master

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.11.2008 at 09:48PM PDT, ID: 21544707

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.11.2008 at 09:57PM PDT, ID: 21544731

Rank: Master

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.11.2008 at 10:05PM PDT, ID: 21544752

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.11.2008 at 10:11PM PDT, ID: 21544763

Rank: Master

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.11.2008 at 10:15PM PDT, ID: 21544767

Rank: Master

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.11.2008 at 10:16PM PDT, ID: 21544770

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.11.2008 at 10:22PM PDT, ID: 21544784

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.11.2008 at 10:22PM PDT, ID: 21544786

Rank: Master

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
 
Loading Advertisement...
Microsoft
  • Internet Protocols
  • Applications
  • Development
  • OS
  • Hardware
  • Windows Security
Apple
  • Operating Systems
  • Hardware
  • Programming
  • Networking
  • Software
Internet
  • Search Engines
  • File Sharing
  • WebTrends / Stats
  • Spy / Ad Blockers
  • Web Browsers
  • New Net Users
  • Web Development
  • Chat / IM
  • Anti Spam
  • Web Servers
  • Anti-Virus
  • Email Clients
Gamers
  • Tips
  • Online / MMORPG
  • Puzzle
  • Emulators
  • Action / Adventure
  • Role Playing
  • Consoles
  • Game Programming
  • Strategy
  • Sports
  • Misc
  • Computer Games
Digital Living
  • Hardware
  • New Net Users
  • New Users
  • Software
  • Digital Music
  • Gaming World
  • Home Security
  • Apple
  • Networking Hardware
Virus & Spyware
  • Vulnerabilities
  • IDS
  • Encryption
  • Anti-Virus
  • Operating Systems Security
  • Software Firewalls
  • WebApplications
  • Cell Phones
  • Operating Systems
  • Internet
  • Hardware Firewalls
Hardware
  • Handhelds / PDAs
  • Displays / Monitors
  • Components
  • Networking Hardware
  • Peripherals
  • Laptops/Notebooks
  • Storage
  • Servers
  • Desktops
  • New Users
  • Misc
  • Apple
Software
  • System Utilities
  • Industry Specific
  • Network Management
  • Photos / Graphics
  • Page Layout
  • VMWare
  • Misc
  • Web Development
  • OS
  • CYGWIN
  • Voice Recognition
  • Message Queue
  • Quality Assurance
  • Security
  • Firewalls
  • MultiMedia Applications
  • Development
  • Database
  • Office / Productivity
  • Business Management
  • OS/2 Apps
  • Server Software
  • Internet / Email
ITPro
  • OS
  • Storage
  • Encryption
  • Operating Systems Security
  • Apple Hardware
  • Laptops & Notebooks
  • Servers
  • Networking Hardware
  • Peripherals
  • Devices
  • Displays / Monitors
  • WebTrends / Stats
  • Search Engines
  • Firewalls
  • WebApplications
  • IDS
  • Vulnerabilities
  • Email Clients
  • File Sharing
  • Spy / Ad Blockers
  • Web Browsers
  • Web Servers
  • Networking
  • Anti-Virus
  • Chat / IM
  • Anti Spam
Developer
  • Web Servers
  • Web Browsers
  • Game Programming
  • Dev Tools
  • Industry Specific
  • Office / Productivity
  • Database
  • CYGWIN
  • Web Development
  • Search Engines
  • File Sharing
  • WebTrends / Stats
  • Programming
  • Content Management
  • Application Servers
  • Protocols
Storage
  • Removable Backup Media
  • Storage Technology
  • Servers
  • Grid
  • Remote Access
  • Backup / Restore
  • Misc
  • Hard Drives
OS
  • Miscellaneous
  • Security
  • Development
  • Linux
  • VMWare
  • MainFrame OS
  • Unix
  • Apple
  • OS / 2
  • AS / 400
  • BeOS
  • Microsoft
  • VMS / OpenVMS
Database
  • Oracle
  • Miscellaneous
  • MySQL
  • Software
  • Sybase
  • Contact Management
  • PostgreSQL
  • Data Manipulation
  • Clarion
  • InterSystems Cache
  • Siebel
  • MUMPS
  • OLAP
  • SQLBase
  • SAS
  • GIS & GPS
  • 4GL
  • Berkeley DB
  • DB2
  • Informix
  • Interbase / Firebird
  • FoxPro
  • Reporting
  • LDAP
  • Filemaker Pro
  • MS SQL Server
  • dBase
  • MS Access
Security
  • Misc
  • Web Browsers
  • Software Firewalls
  • Operating Systems Security
  • File Sharing
  • Spy / Ad Blockers
  • Vulnerabilities
  • WebApplications
  • IDS
  • Anti-Virus
  • Encryption
  • Anti Spam
  • Email Clients
  • VPN
  • Chat / IM
Programming
  • Editors IDEs
  • Installation
  • Handhelds / PDAs
  • Multimedia Programming
  • System / Kernel
  • Algorithms
  • Game
  • Signal Processing
  • Project Management
  • Open Source
  • Database
  • Misc
  • Languages
  • Processor Platforms
  • Theory
Web Development
  • Scripting
  • Blogs
  • Web Servers
  • Software
  • Search Engines
  • Web Graphics
  • Images
  • Internet Marketing
  • Images and Photos
  • Components
  • Document Imaging
  • Web Languages/Standards
  • Illustration
  • WebApplications
  • Fonts
  • WebTrends / Stats
  • Authoring
  • Digital Camera Software
  • Miscellaneous
Networking
  • Protocols
  • Apple Networking
  • Network Management
  • Message Queue
  • Application Servers
  • Content Management
  • File Servers
  • Email Servers
  • Misc
  • Java Editors & IDEs
  • Wireless
  • Networking Hardware
  • Backup / Restore
  • System Utilities
  • ISPs & Hosting
  • Web Servers
  • Storage Technology
  • Removable Backup Media
  • Servers
  • Broadband
  • Grid
  • OS / 2
  • Novell Netware
  • Unix Networking
  • Windows Networking
  • Security
  • Telecommunications
  • Operating Systems
  • Linux Networking
Other
  • Community Advisor
  • Lounge
  • Community Support
  • New Net Users
  • Philosophy / Religion
  • Math / Science
  • Miscellaneous
  • URLs
  • Expert Lounge
  • Politics
  • Puzzles / Riddles
Community Support
  • Suggestions
  • New to EE
  • New Topics
  • Community Advisor
  • CleanUp
  • Announcements
  • General
  • Feedback
  • Input
  • EE Bugs
 
05.08.2008 at 11:02PM PDT, ID: 21530638
Questions:
" Will this work?      
 yes.
" What sort of Cisco Switch will be needed to manage the VLANs?

would depend on the number of users, if the end points require POE.

" Is it ok to have Hubs between the Cisco Switch and the offices? The hubs are only needed to create more
ports to plug into for each building. What should be used here?

I would not use hubs.  i dont' even think you can buy hubs any more.  it depends on the number of users - and the data throughput.
" Is it ok to have the IP phones on their own VLAN?

Recommended.

" Is splitting up the VLANs by MAC addresses the way to go?

VLANS should be split based on functional business areas.  

" If an office decided to install its own SBS server how will this affect everything? Would it be possible for an
office to install their own

Depends on how you were to do this - SBS has its own limitations.
 
05.08.2008 at 11:15PM PDT, ID: 21530682
We dont require POE but it would be nice for future expandability I guess.
Users would start at around 15 but could go up to 50 or a bit more. Can we start with something small and add to it later?

We need to figure out amount the amount of users that will be on each 'hub', but say it was 20 on each what would we need to look at?

Yes we will split the VLANs based on functional business areas but due to physical contraints it would be difficult to do it by physical ports on the Cisco router. Therefore we would need to differentiate the VLANs by MAC address or simiar.

Can we put a regular router/switch on its own VLAN? Then anything that is plugged into that switch will automatically become part of that VLAN?

Thanks again, I appreciate it.
 
05.08.2008 at 11:18PM PDT, ID: 21530690

Rank: Master

hi!
your diagram looks pretty good
still i suppose to use switches instead of hubs. hubs should never used nowadays (they work in half duplex mode - collisions and errors on switches, they resend each packet to all ports). it is possible to get very cheap (linksys, netgear) switches if price is an issue.
as for the equipment, I have no exp with mac-based vlans on cisco (do cisco switches support mac-based vlans?), but nortel switches do support mac-based vlans.
as for voice vlan - it is common practice to use separate vlans for voice and data.

still if you want to archive better scalability I would suggest using ordinal 802.1q based vlans and using switches, with vlan support.
as for cheapest, i can say that d-link switches work perfectly (we have more than 100 switches installed within our network)

Roman


 
05.08.2008 at 11:19PM PDT, ID: 21530698
are the work stations connecting through the IP phones? i.e. do you need 20 ports or 40 ports?
POE for the ip phones is advantagous.
VLANS are designed so that they cross over switches using trunk ports.  they can also cross geographically as needed.

you need to have a core switch, then distribution switches as you topology.

Switches have a native VLAN that all ports are assigned to by default.


 
05.08.2008 at 11:40PM PDT, ID: 21530751
Thanks all,

To give you all a bit more info on the scenario there is a main building with some small buildings surrounding. The main building will hold the servers and the core switch. We have cat 6 running from the main building to the smaller ones.

Therefore we need to put a 'sub switch' in each building so that we can split the ethernet out to each individual office within the buildings.

There may be a need for an extra switch in some of the individual offices. So in that case it would be Core Switch > Sub Switch for building > Sub Switch in individual office.

Overall the entire network may need to support 50-75 users. Each building will probably only have about 20-30 users with each office broken down into about 4 users.

Does this change the situation?
 
05.08.2008 at 11:46PM PDT, ID: 21530776
not really - the same VLAN options apply.  
you can terminate in each office to a distribution switch, and then the trunk the distribution switches to core switches in the central building.  or terminate all ports in the central building, to distribution switches then trunk to the core switches.  POE for the ip phones would also be a consideration here.

depends upon your security requirements - physical - network.

you need to look at the vlan security options for the trunks as well.

any user in any building can belong to any VLAN - provided the VLAN is configured on the switchport correctly.
 
05.08.2008 at 11:49PM PDT, ID: 21530783

Rank: Master

I don't think that additional information can affect your solution.
I suppose you can use gig core switch and sub switch with at least 2 gig ports.
 
05.08.2008 at 11:53PM PDT, ID: 21530801
i'd suggest high end CISCO 2950's as the core.  with either lower end 2950's or Catalyst Express500 for distribution.
 
you'd be much better off with the 2950's as the throughput is so much higher.  Check otu the switch throughputs when comparing which vendor / option to run with.




 
05.08.2008 at 11:53PM PDT, ID: 21530802
strike that - 2960's - the 50's are obsolete.
 
05.09.2008 at 12:01AM PDT, ID: 21530830
ok, all sounding good. Im going to have fun reading about all this stuff :)

Im a bit confused still about how it would work if a user in one of the offices plugged in their own switch. Would the devices plugged into this automatically get added to that offices VLAN?
 
05.09.2008 at 12:05AM PDT, ID: 21530845
the idea is that you want to prevent a user plugging in a switch.  This is a security threat. and the core and sitribution switches should be set to disallow that occuring.

the idea is that VLAN's are advertised by the core swtich and  the adminsitrator controls vlan assignment at the distribution switch level for the end users.  My suggestion would be to hire someone to set this up for you if you have sufficient budget, and transfer as much administration knowledge as you can thorughout the project.
 
05.09.2008 at 12:17AM PDT, ID: 21530886

Rank: Master

as for additional threats... I don't think automatic vlan propogation (vtp) is good idea. you can configure each switch (you will have only 4-5 of them) manually.
as to prevent loops - on cisco pvst is enabled by default.
2960 - rather good models, I would recommend them also.
 
05.09.2008 at 08:15PM PDT, ID: 21537716
what if one of the offices wants to plug in a wirless router for example?
 
05.09.2008 at 10:15PM PDT, ID: 21537932

Rank: Master

in order to avoid this you have several options:
1. policy enforcement
2. 802.1x implementation
3. disable free ports.

so the first and the last are most easy to archive. the 2nd option contains some hidden problems, like devices which does not support dot1x authentication.
 
05.11.2008 at 04:18PM PDT, ID: 21543881
but I want to allow it not block it. If an office wants to put in a wireless router to setup some roaming laptops I think they should be able to.

Would this work?
 
05.11.2008 at 05:35PM PDT, ID: 21544071
The idea is that you have administrative control over what user can and cannot do.

the concept here is to prevent exactly that - what happens if the person that does implement a wireless AP is attempting to remove sensitive information from the organisation ?
 
05.11.2008 at 05:48PM PDT, ID: 21544103
wouldnt the wireless AP only have access to whatever else is on its VLAN?
 
05.11.2008 at 05:50PM PDT, ID: 21544109
generally, yes.  however there are ways around it.
 
05.11.2008 at 06:41PM PDT, ID: 21544226
ok, to confirm and summarise....

>We get a Cisco switch to act as the 'core switch'
>The 'core switch' is connected to the ISA server and the Asterix IP phone server.
>The 'core switch' is also connected to the 'sub switches' in each building.
>We configure each office to be its on VLAN based on physical ports on the 'sub switch'. The IP phones become their own VLAN as well.

-If someone wants to have a wireless AP we can however not recommended.
-If someone wants their own SBS server we can. Just need to connect it to the VLAN switch and configure as normal?

Q: Are cisco 2960 switches the way to go across the board? Anything cheaper?
Q: The IP phones are able to connect 'inline' with the ethernet cable going to a computer nearby. We cant do this if we are seperating the VLANs based on physical ports on the switch can we?
Q: How hard is it to configure the VLANs. I havnt played with a cisco switch before.

Thanks again, really appreciate it.
 
05.11.2008 at 09:11PM PDT, ID: 21544620

Rank: Master

a: cisco can be replaced by any L2 switch with vlans and qos support (dell, hp?), if you want cisco - 2960 the smallest model.
a: you should check the manual for ip phone. possible, that your ip phone supports tagging and can have 2 vlans - voice and data.
a: rather easy, and straightforward