VLAN Configuration Recommendations

Hello Fellow experts,
I am the LAN Administrator for a Central School District (All one physical Building) and I am considering implementing VLAN's in my network.  Putting the VLAN's in won't be a problem, as I'm relatively savvy in this respect, and yes I have the adequate hardware layer 2 switches throughout with Layer 3 at top of closets.  My question is, how you all would recommend segmenting or "organizing" the VLAN's....I have thought about doing it based upon what Wire Closet they are attached to, while providing separate VLAN's for the Servers and Network Printers.....But I am curious to know your suggestions/recommendations.  

Here are the end devices:

Each computer must connect to SERVER 1 for NAT and SERVER 2 for MAIL and DNS

55 Networked Laser Printers all managed by SERVER 3

Elementary School

75 Student Computers
25 Faculty Computers

Middle School

250  Student Computers
150  Faculty Computers

High School

250 Student Computers
150  Faculty Computers
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

What is the purpose of implementing VLANs? Security, Ease of Administration, Issues with Broadcasts?
Jandakel2Author Commented:
The purpose is to create a whole bunch of needless work for myself, just for the heck of it.
Do you have routing/trunking device so the VLANS will be able to communicate with each other, assuming you have a router you can:

Create one VLAN each for Elementary, Middle and High School Students with /24

One VLAN for Facultiy Computers with /22

Keep all ther servers on a seperate VLAN including management of routers/switches.

Use the router for communication amoung VLANs with ACL in place for traffic/bandwidht control.
Cloud as a Security Delivery Platform for MSSPs

Every Managed Security Service Provider (MSSP) needs a platform to deliver effective and efficient security-as-a-service to their customers. Scale, elasticity and profitability are a few of the many features that a Cloud platform offers. View our on-demand webinar to learn more!

First of all, I would recommend doing it with an eye based on 802.11x - port based authentication - so you can get to the point where you can identify a device as faculty or student.  I would create faculty vlans, student vlans, printer vlan, server vlan, and network management vlan.

I don't know your network designer expertise level, so please don't be offended if I come off as condescending.

Design downward - you would your entire network to be addressable behind one network IP.  In this case, I've chosen for the heck of it.  

This can give you 8 networks of 510 hosts each.

They are (I'm cheating and using SolarWinds excellent IP Subnet Calculator):

IP Address       :
Address Class    : Classless /20
Network Address  :

Subnet Address   :
Subnet Mask      :
Subnet bit mask  : nnnnnnnn.nnnnnnnn.nnnnsssh.hhhhhhhh
Subnet Bits      : 23
Host Bits        : 9
Possible Number of Subnets : 8
Hosts per Subnet : 510

Subnet      Mask      Subnet Size      Host Range      Broadcast      510  to      510  to      510  to      510  to      510  to      510  to      510  to      510  to

I would further subnet the first network into:

IP Address       :
Address Class    : Classless /23
Network Address  :

Subnet Address   :
Subnet Mask      :
Subnet bit mask  : nnnnnnnn.nnnnnnnn.nnnnnnns.shhhhhhh
Subnet Bits      : 25
Host Bits        : 7
Possible Number of Subnets : 4
Hosts per Subnet : 126

Subnet      Mask      Subnet Size      Host Range      Broadcast      126  to      126  to      126  to      126  to

Just for grins, I would reserve the first network

The second network is the MANAGEMENT network -  All network devices are going to get VLAN tags and their IP to manage the switches, routers, etc will be in the network.  This is for security - I will explain more later. is for servers.  You could break this down further and have 62 servers internally, and 62 in a DMZ, or whatever. is for printers.  You have a LITTLE room for expansion here, but not much (but you're holding 128 IP's at the bottom which you could further subnet to give you more to play with if you need them).

Now, you've got 6 nets for your schools - 3 faculty and 3 student.  I would put all 6 in different vlans.  Savvy students don't need to be able to pick on the elementary kids (or vice versa).  Elementary School teachers don't need access to the High School teacher vlan.  I've made them large so changes in student and faculty populations shouldn't be a problem.

VLAN 1 Default - don't use
VLAN 100 Network Management
VLAN 2 Servers
VLAN 3 Printers
VLAN 4 Student Elem.
VLAN 6 Student Mid.
VLAN 8 Student High
VLAN 10       Faculty Elem
VLAN 12       Faculty Mid.
VLAN 14 Faculty High

Now, with different vlans for different people - you can implement some security.

For instance:
- No one should be able to access the network management vlan except for you from a very specific IP address - but access from student nets should be impossible.
- Access from student nets to servers should be highly restricted - for instance only DNS and SMTP to the Mail server.
- Access to the Internet from Student Nets can easily be restricted with the SINGLE IP of ( - Because this encompases addresses from .0.1 to 7.254.
- Access to the Internet and Student Nets from Faculty Nets can easily be restricted and/or monitored with the SINGLE IP of ( - Because this encompases addresses from .8.1 to .15.254.

This is how I would do it.

Do you have port authentication?  If so, then you could drop anyone into the appropriate vlan based on your Port Auth (802.11x) infrastructure.

Hope this helps.

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
if you have a 6509 all loaded with 48 port switch modules, life is easy
if you have 1900s. 2900s, 3550s switches all interconnected with routers.. well may not be so easy.

biggest thing may be to segragate the faculty from the students.  This may be the most effective use of the VLAN as faculty may not all be housed in one area and depending on changes; faculty may be moved every so often.  depending on things; dynamic VLANs may be more appropriate than the Static port based VLAN.  You may want to sub divide faculty too, depending on the security you may want between these groups ( maybe you don't want teachers to view student medical records, so you separate them by VLAN and subnetwork)

The student body could be divided by classroom, floors, etc.  This will help keep all of the traffic separate, no need for printing job to go everywhere.  You may also want to set the servers on their own VLAN and subnet.  

One rule of theumb that we use, we associate the VLAN number to the subnetwork.  Makes life easy for us.  e.g. Teachers are on VLAN 3, so they are also on subnet

classroom 104 is on vlan 104 which is on subnet


What did you think about my VLAN design?  Did this help?  Have any more questions?

- PC
Jandakel2Author Commented:
Pseudo, I greatly appreciate the time and effort you put into your post.  It will help me immensely in my next endeavor.....should I decide to go that route (i'm still weighing sacrifice of time vs.  gained "productivity".  Pseudo, could you do me a favor and take a look at this post:  http://www.experts-exchange.com/Networking/Q_21823153.html#16513567   I have been looking at ways to integrate a Branch Office, and I would be curious to know what your input is on this endeavor....Thanks for all your help,  

It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today

From novice to tech pro — start learning today.