Question

Easiest way of implementing VLANs

Asked by: apolov69

I have a big LAN of almost 500 users, in a building of 3 levels, and I have 15 servers (MS-AD, DNS, applications ,etc) every network device  is  in the same  VLAN (1) the default. I have  cisco switches  2950 for edge switches and  a CISCO 4507 for core switch. Now I have network problems , regarding to  many broadcastings  problems, retransmissions, etc, With all these problems I have been advised to implement VLANS  in order to limit the  broadcastings,,but  I would like help  for  finding  the best way for implementing VLANS,, I just want to segment the  Servers,, and  each IDF of each floor. I don't need to segment per users, or per applications just for avoiding broacstings.
I attach a diagram for better understanding.

This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.

Subscribe now for full access to Experts Exchange and get

Instant Access to this Solution

  • Plus...
  • 30 Day FREE access, no risk, no obligation
  • Collaborate with the world's top tech experts
  • Unlimited access to our exclusive solution database
  • Never be left without tech help again

Subscribe Now

Asked On
2009-07-01 at 21:16:50ID24538616
Topics

Network Design & Methodology

,

Network Analysis Software

,

Network Switches & Hubs

Participating Experts
2
Points
500
Comments
6

Trusted by hundreds of thousands everyday for fast, accurate and reliable tech support.

  • "The time we save is the biggest benefit of Experts Exchange to Warner Bros. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange." Mike Kapnisakis, Warner Bros.
  • "Our team likes having a resource that is more secure than just using Google and most experts using this service really know their stuff. It's nice to look here first versus using Google." Dayna Sellner, Lockheed Martin
  • "Anytime that I've been stumped with a problem, 9 out of 10 times Experts Exchange has either the accepted solution or an open discussion of the potential solution to the problem." Kenny Red, eBay Inc.

See what Experts Exchange can do for you.

Got a question?

We've got the answer.

Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.

Screenshot of Experts Exchange Knowledgebase

Need individual assistance?

Our experts are ready to help.

If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.

Screenshot of Experts Exchange Knowledgebase

Want to learn from the best?

Read articles from industry experts.

Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.

Screenshot of an Article

Working on a long term project?

Store your work and research.

Save solutions to your questions, answers you’ve discovered through searching plus helpful articles in your personal knowledgebase for easy future access.

Screenshot of Experts Exchange Knowledgebase

Access the answers to your technology questions today.

Subscribe Now

30-day free trial. Register in 60 seconds.

What Makes Experts Exchange Unique?

Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Trusted by the world's most respected brands.

image of each brand's logo

Faithfully serving IT professionals since 1996.

Experts Exchange Logo

Try it out and discover for yourself.

Subscribe Now

30-day free trial. Register in 60 seconds.

Related Solutions

  1. what is vlan
    what is vlan is it the same with lan
  2. vlan
    I got a catalyst 2970 and 2 2621 routers. I'm attempting to create a vlan but don't know how. Can someone assist me how to start it from scratch?
  3. Cisco VLAN throughput problems
    Overview of scenerio...A complete Cisco network. 2950s used for access switches and 3550 for each building core with VLANs define at that core to route the VLANs (one VLAN per floor). If I do a throughput test with Chariot or iperf from port to port on same switch and same VL...
  4. Cisco networking and VLAN:s
    Hello, http://img356.imageshack.us/my.php?image=networktm8.jpg There is image of our network. (its not correct, but something like that) List of devices: 1 x Core Switch / Router ~40 x Cisco and HP swithes ~500 computers ~100 other network devices ONLY 1 VLAN and the ques...

Free Tech Articles

  1. WARNING: 5 Reasons why you should NEVER fix a computer for free.
    It is in our nature to love the puzzle. We are obsessed. The lot of us. We love puzzles. We love the challenge. We thrive on finding the answer. We hate disarray. It bothers us deep in our soul. W...
  2. SCCM OSD Basic troubleshooting
    SCCM 2007 OSD is a fantastic way to deploy operating systems, however, like most things SCCM issues can sometimes be difficult to resolve due to the sheer volume of logs to sift through and the dispe...
  3. Migrate Small Business Server 2003 to Exchange 2010 and Windows 2008 R2
    This guide is intended to provide step by step instructions on how to migrate from Small Business Server 2003 to Windows 2008 R2 with Exchange 2010. For this migration to work you will need the fo...
  4. Create a Win7 Gadget
    This article shows you how to create a simple "Gadget" -- a sort of mini-application supported by Windows 7 and Vista. Gadgets can be dropped anywhere on the desktop to provide instant information, ...
  5. Outlook continually prompting for username and password
    There have been a lot of questions recently regarding Outlook prompting for a username and password whilst using Exchange 2007. There are a few reasons why this would happen and I will try to cover t...
  6. Backup Exchange 2010 Information Store using Windows Backup
    There seems to be quite a lot of confusion around the ability to backup Exchange 2010 using the built in Windows Backup feature. This stems from the omission of this feature prior to Exchange 2007 s...

Cloud Class Webinars

  1. Avoiding Bugs in Microsoft Access
    Alison Balter takes and in-depth look at avoiding bugs in Access. In this webinar you will learn about using the immediate window to debug your applications, invoking the debugger, using breakpoints to troubleshoot, stepping through code, setting the next statement to execute, ...
  2. Top 10 Best New Features in Visio 2010
    Scott Helmers gives live demonstrations of the top 10 new features in Visio 2010. This webinar will teach you how to create compelling diagrams by adding shapes to the page with a single click, linking the shapes in a diagram to data in Excel (or SQL Server, or SharePoint), ...
  3. IT Consultant Business Secrets Revealed
    Michael Munger, Experts Exchange tech pro and IT consultant, pulls back the curtain on his very successful businesses and answers question on every IT consultant and business owner should know about. He shares secrets on what he did to solve the 5 most common problems in IT, ...
  4. Disaster Recovery and Business Continuity
    Quest CTO, Mike Billon, gives an overview of the steps involved in building a dunamic disaster recovery plan. Through case studies and an examination of software/hardware tooles for monitoring and testing, you'll gain a better understandin of where you are, where you want ...
  5. Organize Your Visio Diagrams with Containers and Lists
    Scott Helmers uses cross functional flowcharts, wireframe diagrams, data graphic legends and seating charts to teach you: how to ustilize all three new structured diagram components in Visio 2010, the best practices for organizeing shapes in previous version of Visio, how to organize ...
  6. How to Us Objects, Properties, Events and Methods in Microsoft Access
    Alison Dalter gives an in-depbth look at objects, properties, events and methods in Microsoft Access. In this webinar you will learn about using the object browser, referring to objects, working with properties and methods, working with object variables, understanding the ...

Join the Community

Give a Little. Get a Lot.

Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.

Join the Community

Answers

 

by: from_expPosted on 2009-07-01 at 23:00:10ID: 24760749

NOTE:
Please read this post till the very end before taking your network down. I assume that you have good knowledge about your current infrastructure, applications, IP addresses. Please ask all Q before actual migration. I also assume, that all workstations are using DHCP, otherwise it would be pain to migrate. However, if all PCs have static addresses, you will just need additional task force to reconfigure all PC's to use DHCP.


I would suggest the following migration scheme.

you create additional vlans on all switches for example:
vlan 2 - servers, created on the nearest switch to the servers and on a core 4507
vlan 3 - IDF 1, created on IDF 1 and core 4507
vlan 4 - IDF 2, created on IDF 2 and core 4507

Next thing to do - interconnect all remote vlans to core switch. to do this you need out of business time (I would suggest friday evening, so you will have time to implement new topology until monday morning) and possibly console access to switches.
you logon to IDF 1 switch and configure uplink port (let it be gi0/1) as tagged with 2 vlans current default and a new one vlan3 (for IDF 1)
configure terminal
int gi0/1
desc to_4507
switchport trunk allowed vlans 1,3
switchport mode trunk
end

at this point (if you were reaching IDF switch via 4507) your connection will be lost. Don't worry about that. so you perform the same task on 4507 for a port to IDF 1 switch.
configure terminal
int gi1/1
desc to_IDF1
switchport trunk allowed vlans 1,3
switchport mode trunk
end

now you should regain connectivity to IDF 1 switch.

In the same way you proceed with other IDFs.

Now you should be plan your IP topology carefully. Each vlan will have it's own IP subnet, so you have to configure your dhcp server (let it has IP of 192.168.100.1) with additional scopes.
Let's assume you are going to implement the following IP scheme (we are not interested in your current one, because you will migrate all PCs step by step to a new topology)
192.168.100.0/24 - servers vlan 2
192.168.101.0/24 - IDF 1
192.168.102.0/24 - IDF 2
192.168.103.0/24 - IDF 3 - etc

Sure thing 4507 should be a default gw for ALL vlans within your network and should also know where dhcp server is for each vlan:
configure terminal
int vlan2
name servers
ip address 192.168.100.254 255.255.255.0
int vlan3
name IDF1
ip address 192.168.101.254 255.255.255.0
ip helper-address 192.168.100.1
int vlan4
name IDF2
ip address 192.168.102.254 255.255.255.0
ip helper-address 192.168.100.1
int vlan5
name IDF3
ip address 192.168.103.254 255.255.255.0
ip helper-address 192.168.100.1
end

Firewall should be placed in additional vlan and switch shoud have it's default gw configured to firewall.
int vlan100
name fw_vlan
ip address 192.168.200.1 255.255.255.0
end
int gi1/10
desc firewall
switchport access vlan 100
end
ip route 0.0.0.0 0.0.0.0 192.168.200.254 ---- address of firewall

Firewall should be reconfigured to a new IP address and should also allow all your subnets to internet (if needed)
At this point you are ready to reconfigure servers with new IP addresses and place then into correct vlans.
conf  term
int gi1/2
desc dhcp_server
switchport access vlan 2
end

All servers shoud be rebooted after that, because they should reregister them selves in DNS.

At this point you shoud have fully functional infrastructure - servers are separated, they should be accessible from workstations (workstations should have 4507 as a default gw). If not, try to troubleshoot problems.

Only after this step you should move to the next step - moving PCs to new vlans.
To do that - move all ports on IDF1 switch to vlan 3 and reboot all PC in that switch in order to them to get new IP addresses.
Check: PCs in IDF1 should be able to get new IP with default gw, with access to internet, to servers.
If everything is ok - proceed to the next IDF.

Uff... Seems that is all.

 

by: uetian1707Posted on 2009-07-02 at 02:53:07ID: 24761689

Hi,

Please find attached the VLAN design template.

VLAN is a way of micro-segmenting a L2 / L3 topology into separate broadcast domains. Each VLAN is a separate broadcast domain, ie: all broadcasts are seen by devices within the same VLAN.
 
Inter-VLAN communication is restricted, requires a L3 routing device to communicate between broadcast domains.  
 
Couple of Benefits listed below
 
1. Saves excessive usage of physical connectivity
 
2. One link can pass all different broadcast seggregated packets to respective destinations
 
3. By using VTP further, we can also sync between devices making one as server and other clients. Updates will be sent automatically and devices will remain in sync upon any change recorded amongst them.
 
4. Different Vlans can be segmented across different deppt. for eg marketing and sales in the same building can be put under  tow seperate vlans. Both networks will remain seperate though using the same devices to flow.
 
5. Bandwidth is saved a lot as well. Further you can use etherchannels to segment the bandwidth for better flow of packets. 
 
 
Given the number of PC's you have, separation by device class just won't yield much of a result - your broadcast domain will still be equally flooded.
 
I'd recommend a mix of the two methodology. For example, lets take the subnet 10.0.0.0 and let us use the second octet for site, the third octet for vlan-id and the fourth as the host octet.
 
Site 1: 10.1.v.h
Finance: v = 20
HR: v = 25
IT: v = 20
etc
Switches/routers: v = 1
WAP's: v = 4, h = 200-254
Wireless clients: v = 4, h = 10-199
Printers: v = 5
Phones: v = 6
Management: v = 100
etc
 
Yes, that is a lot of address wastage but you get the idea. Generally we want to keep as much broadcast data into a single vlan as possible. If departmental devices can be on the same physical access layer device then that combined with dedicated vlan would be better again.

                                              
1:
2:
3:
4:
5:
6:
7:
8:
9:
10:
11:
12:
13:
14:
15:
16:
17:
18:
19:
20:
21:
22:
23:
24:
25:
26:
27:
28:
29:
30:
31:
32:
33:
34:
35:

Select allOpen in new window

 

by: apolov69Posted on 2009-07-02 at 13:04:09ID: 24767248

Thanks for your solutions!, I will certainly do what you are recommending,, I missed to tell  you that I have 12 accesspoints  for wireless users,, and  a TCPIP  subnet of  1022  host (22 subnet bits) ,, (179.7.X.X/255.255.252.0) ,, and  the question would be,, Do I need to assign separated ip subnets for each  VLAN? ,, or How Can I manage those IPs  in the  DHCP server?

Thanks!!

 

by: from_expPosted on 2009-07-02 at 22:19:53ID: 24770056

Yepp, you need separate IP subnet per vlan. You can manage DHCP scopes on DHCP server. Client in each vlan will get its lease from a correct pool for that vlan.
However you can consider if you need every IDF in its own vlan. Possibly you can group them according to departments.

 

by: from_expPosted on 2009-07-02 at 22:21:18ID: 24770063

as for wireless - my solution - to allow wireless only via firewall, however physically APs can share the same switches, but should be placed in special wifi vlan.

 

by: apolov69Posted on 2009-07-03 at 07:57:50ID: 31599063

Thank you for your solution!,,it is really complete a accurate!

20120131-EE-VQP-002

3 Ways to Join

30-Day Free Trial

The Experts

98% positive feedback on 31,087 answers since March 2000. angeliii is a Microsoft Most Valuable Professional for his work with MS SQL Server & Develoment.

He has also proven his knowledge of Visual Basic Programming, PHP Scripting and Oracle Databases.

The Experts

97% positive feedback on 10,752 answers since July 2000. lrmoore has more than 18 years experience in the networking industry.

The six-time Mircosoft MVPs specialties include firewalls, virtual private networking, and network management.

Testimonials

"...and excellent source for support... Kind of like having your very own IT dept." Electriciansnet

Testimonials

"I was apprehensive at signing up at first. However... it has already made my life as an IT administrator much easier." JaCrews

Testimonials

"WOW! You guys have great, active, and knowledgeable people on here." moore50

Business Clients

Business Clients

In the Press

"If you’ve got a question... Experts Exchange can supply an answer.”

In the Press

"...an invaluable aid for both IT professionals and those who require tech support."

In the Press

"where IT professionals provide quick answers on just about any topic"

Business Account Plans

Loading Advertisement...