Dell VLAN Question

Is it going to be feasible to setup a single VLAN for IP phones and a separate VLAN for each port with the phone VLAN on rash port?
Dennis PillowOwner G-Tech Consulting LLCAsked:
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Fred MarshallPrincipalCommented:
I don't find "rash port" referenced in the Dell documentation.....??

A separate VLAN for each port seems odd.  What is it you're wanting to do?
Dennis PillowOwner G-Tech Consulting LLCAuthor Commented:
My bad......fat fingers.... I meant each port. I have a 6248 Switch that feeds seven floors with multiple clients on each floor.  I am seeking a good way to completely isolate each client from the other.
Fred MarshallPrincipalCommented:
I'm unclear as to whether this is a VOIP issue or a more common networking issue that's not so related to VOIP?
Normally, everyone is on the same LAN of course.
And, in some instances, groups might be on a VLAN each.
And, I suppose this could be extended to a VLAN per port if the switch has the capacity for that.
So, if the VLANs are kept separate upstream then that should work I should think.
Not something I've ever tried to do...

As far as VOIP is concerned, there can be a VLAN just for VOIP which can coexist with all the others on the same ports.
But I've run into phone initialization where local DHCP service is needed at least for the first boot of a phone which has been "reset".
So, that may be a consideration.

It's always easier to have the VOIP on the same LAN as everytyhing else because services like DHCP are often just "assumed" by the phone service provider.  But then, some will argue that isolation isn't perfect, etc.
Learn Ruby Fundamentals

This course will introduce you to Ruby, as well as teach you about classes, methods, variables, data structures, loops, enumerable methods, and finishing touches.

Dennis PillowOwner G-Tech Consulting LLCAuthor Commented:
This is sort of a mess due to not being able to supply adequate wiring to each client. We have to deal with only one Network cable to each office on each floor.
We have a Mikrotik CCR that ties our 5Gb fiber network and gives out all the network configuration. There are 35 customers in this building and Each has phones and data.
That is why I am looking at using switches and VLANS.
Fred MarshallPrincipalCommented:
Much remains to be defined.  How many phone service providers is but one question.
Common configuration is to put all voice on one vlan and all data on another. The phone would be used to tag the vlan traffic as the computer would plug into the phone and the phone then into the wall jack. You can't isolate each one on their own vlan or you will then need to have 35 vlans that can route amongst themselves as the users will probably need to call each other. Data can be layer 3 and the VoIP can be layer two unless there is some underlying reason why it needs to communicate with something else on the network.
Dennis PillowOwner G-Tech Consulting LLCAuthor Commented:
I believe that If I make a drawing it would help explain my question.
Dennis PillowOwner G-Tech Consulting LLCAuthor Commented:
Here is a little drawing I put together to help explain my question. I hope it helps.
Fred MarshallPrincipalCommented:
OK.  Yes, that helps!  Questions for you to consider remain:

It is *very* common practice to put the phones and the computers on the same LAN with no VLANs.  In this case that might well be the computers and phones for one company on one VLAN each.  And, that is all.  This avoids issues with phone initialization, DHCP, etc.  I sense for your situation, this may well be preferable.

At issue for me is how you are planning to acquire and manage the telephone service?
Are you planning a single phone service provider and dole out telephone numbers to the companies?
Are the companies (or you) planning to have separate phone service providers for each company?
(This may be best as why would you want to be a middleman re: the phone services?).

1) Some phone service companies like to sell internet service to match their needs, etc.
2) Other phone service companies just use the primary internet service.  This means one firewall or one firewall per company and perhaps a few tweaks for the VOIP in the firewall.
If the phone service company provides their own internet service then you need to figure out how to provide firewalling capability for two internet connections.
I prefer #2 unless you have very stringent data firewalling needs and WANT to keep VOIP and Data separate altogether.
Bryant SchaperCommented:
Yes, you should be able to define a vlan for data and voice, and actually as many as you want for each.  You can even use passthrough ports on the phones so it would be switch --> phone --> PC.  Look for the feature called LLDP-MED this will allow the phones to pull the voice vlan, which on Cisco and Juniper can be setup per port, and then put the computer on the access vlan.

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
Fred MarshallPrincipalCommented:
Bryant Schaper makes a good point.  The phones often act as a passthrough for the local workstation on a desk.  That way, an additional cable isn't needed to add the phone.  I've set these up with a VOIP VLAN trunked with a data VLAN but haven't done it on a single LAN nor thought much about how that works.
Dennis PillowOwner G-Tech Consulting LLCAuthor Commented:
Thanks to you both for the great pointers.
I would be extremely hesitant about putting data and voice on the same vlan. If you have 10-15 users, probably not a problem. But if you starting getting much more than that it can start to degrade call quality when using VoIP and data on the same vlan. Keep in mind that VoIP is not TCP but UDP so if anything interrupts transmission that packet doesn't get resent and your call quality starts to degrade. Multiple separate vlans will also require routing to the call manager since it will be on a different subnet which in turn will also add latency to the call.

If they are all using the same phone system then I would highly suggest putting the VoIP traffic on it's own vlan and you can do whatever you want with the data. You also need to make sure that if you have multiple hops on the network to get to the call manager that you enable QoS also. If you do it the way your thinking, I would be extremely surprised at some point you don't have the offices complaining that their call quality sucks.
Dennis PillowOwner G-Tech Consulting LLCAuthor Commented:
I am going to build a separate VLAN for each customer and one vlan for the phones. They will have QOS setup and working thru our Phone system. This should provide a level of separation between customer offices and allow phone service of a good quality to be provided.

Do I want to set the Dell 6248 up as all ports "ACCESS WITH VLAN ALLOWED FOR PHONE AND PORT VLAN?
Bryant SchaperCommented:
will the phones be wired separate from the desktops or will they share?
Dennis PillowOwner G-Tech Consulting LLCAuthor Commented:
There is only one data cable to each office. In some cases the data and phones are separate and in some they share.
Bryant SchaperCommented:
Then you will want to create a voice vlan on the 6248 so the phones get that vlan, assuming LLDP-MED is supported, and the desktops get whatever the access vlan is.
Dennis PillowOwner G-Tech Consulting LLCAuthor Commented:
Good job! You got it!
Dennis PillowOwner G-Tech Consulting LLCAuthor Commented:
I'll let you guys know how it comes out setting up the Dell. I have the vlans setup in the router and the switch should be able to handle 35 clients.
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today

From novice to tech pro — start learning today.