Network Design / VLAN advice

ITPOL
ITPOL used Ask the Experts™
on
Hi,

I'm after some advice on the best network design approach for my new network.

I have 5 Servers about 30 client PCs.  Two of the servers are domain controllers running DHCP and DNS, two are data file servers, and the other one will be WSUS/whatever else is needed.

Of the 30 PCs 22 are Production machines split into two groups.  The first 11 all point to server 1 to get their data, the second lot point to server 2 to get their data. The remaining are non-production machines used for internet access, email etc.
I have 2 3com 2900 (2928) Switches each with 24 ports, and a Draytek router providing internet access.

Here’s what I’d like to achieve;

I don’t want any of the production machines, the DCs, or the data servers to have internet access (inbound or outbound). I would like the 5th server, the WSUS server to have internet access and be available to the other machines to get their updates.
I would like to have some way of providing internet only access to some machines (i.e. can’t see the rest of the network)
I would like another group of PCs, I.e my own PC, that I can use to administer the other devices on the network but also have Internet access.

Ideally, if possible, I would like to use these switches in some sort of failover configuration, but I’m not sure of the right acronym to look up???

I’m under the impression I might be able to do this with VLANs, but I’m not sure how best to approach this.  I.e. should my group 1 PCs go into a VLAN with Server 1, and the same for server 2?

OR are my requirements too much for what I have?  I.e. Do I need to introduce some sort of DMZ or network access product?

Looking forward to your ideas, Thanks in advance.
Comment
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
Can you implement a firewall...if yes then it is a cake walk..A cisco ASA firewall is a very gud firewall...

Author

Commented:
Yes I can implement a firewall if required.  But i'm interested in how such a solution should be implemented.  For example, a firewall that just creates a barrier between by network and the internet is not what I am looking for.  I want to be able to segment parts of my network from each other.
There are various methods but the most effective and versatile would probably be cost prohibitive for a relatively small network such as implementing a Network Access Control solution.

In a small enterprise, IP access lists are the simplest ways of segmenting your network. Here is an overview of how it could be acheived....

You could meet all of your requirements with the addition of a layer 3 switch which could implement IP Access Lists. You would set it up as follows:

Each VLAN will have its own IP address range

VLAN 101 contains
Prod PCs 1-11
DC Server 1
Data Server1

VLAN 102 contains
Prod PCs 12-22
DC Server 2
Data Server 2

VLAN 103 contains
Internet PCs 23-30

VLAN 104 contains
WSUS server

VLAN 105 contains
Draytek router

Your own PC could reside in either VLAn 101 or 102 or you could create a new vlan just for yourself but thats overkill

You would then set up access lists as follows:
Permit all traffic from your PC to anywhere
Permit DC traffic between DC1 and DC2 to ensure they can stay in sync
Permit update traffic from vlans 101 and 102 to VLAN 104
you will need a nested ACL for the other PCs 23-30:
 - deny all traffic from vlan 103 to vlans 101 and 102
 - permit http, smtp etc from vlan 103 to any
By default, any traffic not explicitly allowed will be denied. Therefore by creating these vlans, pcs1-11 can communicate with DC server 1 and data server 1 and likewise for the other PCs and servers.

The above could be done with fewer vlans and ACL rules that matched more specific IP addresses / ranges rather than entire vlans and subnets.

Alternatively...
I am not that familiar with 3com switches but your first two points could be covered with the use of Private VLANs (PVLANs) if supported by the 3Com switch.

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial