Difference between revisions of "Information Systems:Wired Network (LAN) Infrastructure Redesign"
Jump to navigation
Jump to search
m |
m |
||
| Line 3: | Line 3: | ||
: VLAN 1 - Management VLAN, no devices |
: VLAN 1 - Management VLAN, no devices |
||
| − | : VLAN 10 - Corporate LAN - desktops, printers/print servers |
+ | : VLAN 10 - Corporate LAN - desktops, printers/print servers, RF guns, outbound NAT through Telus, Terago |
| − | : VLAN 20 - Storage LAN (for SAN iSCSI traffic), separate L3 domain, no default gateway |
+ | : VLAN 20 - Storage LAN (for SAN iSCSI traffic), separate L3 domain, no default gateway, no outbound internet access |
: VLAN 21 - Backup traffic |
: VLAN 21 - Backup traffic |
||
| − | : VLAN 30 - Guest VLAN |
+ | : VLAN 30 - Guest VLAN, outbound NAT through Telus, Terago, no access to corporate intranet |
| + | : VLAN 50 - Telus Corporate WAN, /27 (Superman WAN, Bart (public), Mail (public), Infoblox) |
||
| − | : VLAN 50 - WAN |
||
| + | : VLAN 51 - Terago Corporate WAN, /29 (Superman WAN, Bart (public), Mail (public), Infoblox) |
||
: VLAN 60 - DHL/Loomis LAN |
: VLAN 60 - DHL/Loomis LAN |
||
Revision as of 11:56, 15 July 2016
VLANs
The entire uniPHARM network is currently a single, very large broadcast domain. It is of utmost priority upon the purchase of new switches to segment the LAN into VLANs. Here are the proposed VLANs:
- VLAN 1 - Management VLAN, no devices
- VLAN 10 - Corporate LAN - desktops, printers/print servers, RF guns, outbound NAT through Telus, Terago
- VLAN 20 - Storage LAN (for SAN iSCSI traffic), separate L3 domain, no default gateway, no outbound internet access
- VLAN 21 - Backup traffic
- VLAN 30 - Guest VLAN, outbound NAT through Telus, Terago, no access to corporate intranet
- VLAN 50 - Telus Corporate WAN, /27 (Superman WAN, Bart (public), Mail (public), Infoblox)
- VLAN 51 - Terago Corporate WAN, /29 (Superman WAN, Bart (public), Mail (public), Infoblox)
- VLAN 60 - DHL/Loomis LAN
It is important to note that routing will be needed to route traffic between some of our VLANs.