ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Are VLANs Appropriate Here

    Scheduled Pinned Locked Moved IT Discussion
    17 Posts 4 Posters 973 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • scottalanmillerS
      scottalanmiller
      last edited by

      This is pretty much the bread and butter reasoning that people give for VLANs. Keeping workstations away from the servers to which they need to communicate creates massive bottlenecks. And definitely shows, at the very least, that your networking setup in the other thread is incorrect, for this description, there is no question, if you need these VLANs, it is in the switch, not the firewall, that your routing and ACLs should exist. The switch is a firewall here, just to be clear, but not the SonicWall.

      1 Reply Last reply Reply Quote 1
      • scottalanmillerS
        scottalanmiller
        last edited by

        Why is corp wifi its own VLAN? Why are servers their own VLAN? Why is VoIP its own VLAN? Those three all appear to be crippling your network and adding cost, without any benefit, certainly not any security because they talk to each other anyway. The firewall between them is a red herring, does nothing of benefit.

        If you wanted security from this style of model, the only logical way to handle it is to have every device or port on its own VLAN. It's extreme, but this is how secure shops do it. If you don't go to that level, the VLANs do essentially nothing, but still have loads of overhead.

        The guest wifi on its own VLAN (or physical LAN, either way) is generally a good way to go. This is different because it is literally a completely different, unrelated network and never talks to the others, so this is where a VLAN really makes sense for sure.

        1 Reply Last reply Reply Quote 0
        • DonahueD
          Donahue
          last edited by

          I am in the process of redoing my network. My plan is to just have a single VLAN, just for guest stuff that will not talk to anything else. If you have all those devices on separate VLANs, and they do need to talk to each other, then you may be introducing a unnecessary point of failure, specifically the L3 switch. If they can all be on the same VLAN, or untagged, then you should be able to drop in just about any switch in a pinch and keep the network up when there is an outage. Ask me how I know.

          scottalanmillerS 1 Reply Last reply Reply Quote 1
          • scottalanmillerS
            scottalanmiller @Donahue
            last edited by

            @Donahue said in Are VLANs Appropriate Here:

            I am in the process of redoing my network. My plan is to just have a single VLAN, just for guest stuff that will not talk to anything else. If you have all those devices on separate VLANs, and they do need to talk to each other, then you may be introducing a unnecessary point of failure, specifically the L3 switch. If they can all be on the same VLAN, or untagged, then you should be able to drop in just about any switch in a pinch and keep the network up when there is an outage. Ask me how I know.

            Also a major bottleneck as traffic has to be filtered between each of those networks. It's overhead at exactly the spot where you don't want it. If you were able to VLAN by department that didn't share anything (or essentially anything) you could make an argument for VLANs between, say engineering and finance, assuming that they didn't share any server resources. Then put engineering workstations and engineering servers on on VLAN, and financial workstations and servers on another VLAN.

            The easy way to tell if VLANs make sense for security is "do you need to allow traffic between them?" If the answer is yes, the VLAN is smoke and mirrors. If the answer is no, then you need to still see if the VLAN has value, but it means that potentially it does.

            1 Reply Last reply Reply Quote 1
            • WLS-ITGuyW
              WLS-ITGuy
              last edited by

              Not sure if this will muddy up the water but we have 3 VLANS on our network. All wired traffic (Servers, PCs, and VOIP) on VLAN 1, All Secured "corp" wifi on VLAN 2, and all student/guest wifi on VLAN3.

              VLAN 3 cannot communicate with VLAN 1 or 2 without ACLs

              VLAN1 and 2 can communicate with each other but cannot see anyone on VLAN 3

              1 Reply Last reply Reply Quote 0
              • DonahueD
                Donahue
                last edited by

                then why do VLAN 1 and 2 need to be on different VLANs?

                WLS-ITGuyW 1 Reply Last reply Reply Quote 2
                • WLS-ITGuyW
                  WLS-ITGuy @Donahue
                  last edited by

                  @Donahue said in Are VLANs Appropriate Here:

                  then why do VLAN 1 and 2 need to be on different VLANs?

                  Technically they don't but I kept all LAN traffic outside of the WIFI scope

                  DonahueD scottalanmillerS 2 Replies Last reply Reply Quote 0
                  • DonahueD
                    Donahue @WLS-ITGuy
                    last edited by

                    @WLS-ITGuy said in Are VLANs Appropriate Here:

                    @Donahue said in Are VLANs Appropriate Here:

                    then why do VLAN 1 and 2 need to be on different VLANs?

                    Technically they don't but I kept all LAN traffic outside of the WIFI scope

                    I am setting mine up so that all my stuff on the corp network can be switched, not routed. I am coming from a setup where everything was separated, and its was all inefficient. When my router blew up, it took most of my network with it because it all had to be routed.

                    WLS-ITGuyW scottalanmillerS 2 Replies Last reply Reply Quote 1
                    • scottalanmillerS
                      scottalanmiller @WLS-ITGuy
                      last edited by

                      @WLS-ITGuy said in Are VLANs Appropriate Here:

                      @Donahue said in Are VLANs Appropriate Here:

                      then why do VLAN 1 and 2 need to be on different VLANs?

                      Technically they don't but I kept all LAN traffic outside of the WIFI scope

                      No, if they can talk to each other the their traffic is not kept out of that scope. They are comingled, so what is the purpose of the VLAN?

                      1 Reply Last reply Reply Quote 1
                      • WLS-ITGuyW
                        WLS-ITGuy @Donahue
                        last edited by

                        @Donahue said in Are VLANs Appropriate Here:

                        @WLS-ITGuy said in Are VLANs Appropriate Here:

                        @Donahue said in Are VLANs Appropriate Here:

                        then why do VLAN 1 and 2 need to be on different VLANs?

                        Technically they don't but I kept all LAN traffic outside of the WIFI scope

                        I am setting mine up so that all my stuff on the corp network can be switched, not routed. I am coming from a setup where everything was separated, and its was all inefficient. When my router blew up, it took most of my network with it because it all had to be routed.

                        My VLANs are all at the switch level and my wireless controller.

                        1 Reply Last reply Reply Quote 0
                        • scottalanmillerS
                          scottalanmiller @Donahue
                          last edited by

                          @Donahue said in Are VLANs Appropriate Here:

                          @WLS-ITGuy said in Are VLANs Appropriate Here:

                          @Donahue said in Are VLANs Appropriate Here:

                          then why do VLAN 1 and 2 need to be on different VLANs?

                          Technically they don't but I kept all LAN traffic outside of the WIFI scope

                          I am setting mine up so that all my stuff on the corp network can be switched, not routed. I am coming from a setup where everything was separated, and its was all inefficient. When my router blew up, it took most of my network with it because it all had to be routed.

                          That's the boat that the OP is in, he has this massive bottleneck and risk in the router that isn't serving a purpose. Even without removing the VLANs, he could fix that by moving their crossover point to the switch.

                          1 Reply Last reply Reply Quote 0
                          • DonahueD
                            Donahue
                            last edited by

                            is this just a DHCP scope thing?

                            scottalanmillerS 1 Reply Last reply Reply Quote 0
                            • scottalanmillerS
                              scottalanmiller @Donahue
                              last edited by

                              @Donahue said in Are VLANs Appropriate Here:

                              is this just a DHCP scope thing?

                              Right, DHCP is affected, but not security.

                              DonahueD 1 Reply Last reply Reply Quote 0
                              • DonahueD
                                Donahue @scottalanmiller
                                last edited by

                                @scottalanmiller said in Are VLANs Appropriate Here:

                                @Donahue said in Are VLANs Appropriate Here:

                                is this just a DHCP scope thing?

                                Right, DHCP is affected, but not security.

                                I can see the argument of having two different DHCP scopes, one for wired and one for wireless. I cannot comment on if that is the best choice though, just that it makes sense.

                                scottalanmillerS 1 Reply Last reply Reply Quote 0
                                • scottalanmillerS
                                  scottalanmiller @Donahue
                                  last edited by

                                  @Donahue said in Are VLANs Appropriate Here:

                                  @scottalanmiller said in Are VLANs Appropriate Here:

                                  @Donahue said in Are VLANs Appropriate Here:

                                  is this just a DHCP scope thing?

                                  Right, DHCP is affected, but not security.

                                  I can see the argument of having two different DHCP scopes, one for wired and one for wireless. I cannot comment on if that is the best choice though, just that it makes sense.

                                  Based on what need? Just the fear that someone will hijack the secure wireless and perform a DHCP exhaustion attack? It's a huge amount of effort for a really trivial attack vector that has no serious impact.

                                  1 Reply Last reply Reply Quote 1
                                  • DonahueD
                                    Donahue
                                    last edited by

                                    no, I am saying that I could see that someone wanted to separate out their devices so each could have its own separate DHCP scope. I am not saying that this was a good idea, or that I would do it, just that I can see how VLAN's could be used to achieve that effect. Again, I am not saying this would be using VLANs correctly

                                    1 Reply Last reply Reply Quote 1
                                    • 1 / 1
                                    • First post
                                      Last post