Thursday, December 12, 2019

Trouble setting up VLANS with Juniper

Let me preface this by saying I am fairly new to networking; I've been studying to be a network engineer (with Cisco learning materials) and have obtained my CCNA Routing and Switching, but have no REAL experience in the field other than lab work and exams. I was recently taken on as an intern in a small company that has a super small IT department to work on some network projects they have. They have no in-house network anything and have been paying their ISP to set up any network related thing they may happen to need. The main issue I am running into is, I was trained solely on Cisco, and they solely use Juniper. I understand the concept of VLANS is universal, but I am finding the Juniper CLI difficult to master. My main goal here is threefold:

  • They have completely flat network with no Vlanning whatsoever, so first and foremost is get 2 Vlans, 1 for voice and 1 for data

  • Once I've done this, further segment the data vlan to have every department in its own VLAN (keeping full inter-connectivity, they will implement ACLs for the VLANs later down the line)

  • Help them migrate ISP's since they hate their current one and are swapping. This might actually be step one, as swapping around routers and all that might mess with previous configurations.

I am fully confident that I can manage the task ahead of me as the network is still quite small (they currently have 6 routers, which will be shrinking to 1 after the ISP swap, and 14 L3 switches, with maybe 200-500 hosts total, across about 5 sites). The scope of it is not enormous, but I have no resources to call upon other than what I already know and the internet.

The main questions I wanted to directly ask about are, do I need to add every Vlan to every switch, even if no ports on that switch are IN that Vlan, and as far as VOIP is concerned, since I'm implementing it after the network has been established for so long is it fine to just enable a voice vlan on every port on the switch so that I don't have to hunt down and find out which ports IP phones are on. Additionally to that last point, how to I make sure that the PCs attached to the phones aren't on the Voice Vlan and rather are on the data vlans (essentially putting a voice AND a data vlan on every port).

I have many other questions, but as I work on this and get more familiar these are the main two I'm trying to work out. I've looked on Juniper's website but the tech documentation is a little convoluted and I'm not 100% sure I'm doing this right. I appreciate any help I can get, and if further information is needed I can try and provide some insight.



No comments:

Post a Comment