Tuesday, February 12, 2019

Is this a good VLAN design or bad?

We have about 60 properties that are making a site to site connection to our data center. The locations are on a /24 scheme. Were implementing VOIP and IP Camera's so every VLAN has to be unique otherwise the site to site connection wouldn't work.

I was thinking of moving away from /24 to /16 so that all sites can still have the same VLAN IDS throughout to keep consistent

EG:

Location 47 right now is 172.25.47.0

VOIP would become 172.25.30.0

But now location 36 is 172.25.36.0

I can't use 172.25.30.0 for location 36 anymore

If I move to /16 I can do something like this

Location: 47

172.47.0.1 - Firewall IP

172.47.10.0 - Office VLAN

172.47.30.0 - VOIP VLAN

172.47.0.254 - Switch IP

now I can apply the exact same to location 36

172.36.0.1 - Firewall IP

172.36.10.0 - Office VLAN

172.36.30.0 - VOIP Vlan

If I keep /24 i'd basically have to start from .80 and each site would have there VOIP vlan like this:

.80 .81 .82 etc...

I don't think that would scale well.



No comments:

Post a Comment