Solved

Benefits of VLANs

Posted on 2009-05-13
5
1,369 Views
Last Modified: 2012-08-13
I am trying to convert a currently fully switched, flat network over to a VLAN deployment with a Layer 3 HP ProCurve switch at the core. There are approximately 600 nodes on this network.

I would appreciate somebody informing me what the actual benefits of deploying VLANs, rather than simply plugging devices together in a switched fashion, would be for the network, bandwidth and any other factors you can think of.

Thanks :-)
0
Comment
Question by:tigermatt
5 Comments
 
LVL 21

Assisted Solution

by:from_exp
from_exp earned 140 total points
Comment Utility
you can separate broadcast domains.
So you can have servers vlan, workstations vlan, etc.
so any L2 problems in workstation vlan (misconfigured ip, broadcast storms, etc) will not affect servers.
0
 
LVL 21

Assisted Solution

by:from_exp
from_exp earned 140 total points
Comment Utility
again, it is a good practice, to separate test and development from rest of production network, SAN network (if iSCSI), management vlan, etc
0
 
LVL 2

Assisted Solution

by:Jitpar
Jitpar earned 80 total points
Comment Utility
VLAN is a way of micro-segmenting a L2 / L3 topology into separate broadcast domains. Each VLAN is a separate broadcast domain, ie: all broadcasts are seen by devices within the same VLAN.
Inter-VLAN communication is restricted, requires a L3 routing device to communicate between broadcast domains.  
Couple of Benefits listed below
1. Saves excessive usage of physical connectivity
2. One link can pass all different broadcast seggregated packets to respective destinations
3. By using VTP further, we can also sync between devices making one as server and other clients. Updates will be sent automatically and devices will remain in sync upon any change recorded amongst them.
4. Different Vlans can be segmented across different deppt. for eg marketing and sales in the same building can be put under  tow seperate vlans. Both networks will remain seperate though using the same devices to flow.
5. Bandwidth is saved a lot as well. Further you can use etherchannels to segment the bandwidth for better flow of packets.
 
0
 
LVL 10

Assisted Solution

by:ngravatt
ngravatt earned 70 total points
Comment Utility
segregating traffic has security benefits.

user departments and server functions should be in different IP address ranges.  

marketing on vlan x and engineering on vlan y
production servers on vlan a and development servers on vlan b

when setting up firewalls or monitoring devices or access lists, you can limit access (provide security) to these networks separately.
0
 
LVL 8

Accepted Solution

by:
ludo_friend earned 210 total points
Comment Utility
I generally group computers in my organisaton into small groups (vlans) based on thier department. this enables much simpler l3 filtering as I can filter by interface or subnet. this also gives you the ability to filter (ACL) what can pass between the vlans (i.e. marketing doesn't need to talk to accounts, IT needs to talk to everything). You'll be glad you did when a virus manages to get past your protections and only manages to infect 6 marketing computers rather then everything.
this has obvious security advantages, as well as the ability to set different qos for each vlan.
at 600 nodes, you're not quiet large enough to worry about broadcast storms and the likes, but I would be starting to segregate your network into smaller subnets and vlans more for its security and management advantages.
I also use it to section off development and production servers from eachother.
hope I've helped.
0

Featured Post

Better Security Awareness With Threat Intelligence

See how one of the leading financial services organizations uses Recorded Future as part of a holistic threat intelligence program to promote security awareness and proactively and efficiently identify threats.

Join & Write a Comment

This article is a how to to configure a UCS Ethernet-uplink portchannel via the console. It is easy to do and can be done quite quickly. In certain versions of the UCS manager the portchannel has issues coming up and this is a workaround. I am…
Problem Description:   Couple of months ago we upgraded the ADSL line at our branch office from Home to Business line. The purpose of transforming the service to have static public IP’s. We were in need for public IP’s to publish our web resour…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

763 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now