Tuesday, June 1, 2021

Network design for new servers and switches. Design check and advice

Hi All, I've recently undertaken a project from an old IT system Admin in the company I work for with a few issues.

The main issue is that the guy i have taken over from as passed away taking with him a LOT of core system passwords as he setup a lot of these and did not write/document them or he did in an encrypted files that is basically useless to me.

I created a Rack diagram that's basic and is my rough idea of the layout so if you guys need an imager link or that kind i can provide that

Now I currently have 3 new servers on the way

2 x R440

1 x R540 - planning to run TrueNas - open to suggestions

3x power switchN2248X-ON

The Switches will be stacked connected via 40GBps uplinks.

each server will have dual SPF+ connections, 4 Gigabit NIC's and IDRAC enterprise

I plan to have four networks all class C ( 192.168.10.x, 192.168.15.x 192.168.20.x 192.168.200.x)

I plan to run ESXi on the servers however my CEO with the last System Admin preferred Hyper-V s i dislike the idea of a windows system running core of servers for their need to need to shutdown on the slightest update

1) are there other options besides EXSi//Hyper-V for enterprise? (ProxMox)?

2) these servers will be supporting around 200 users, is there any suggestions on the virtual setup of servers as currently i plan to have 2 VM's to run just DC's and authentication, 1 VM to run "Utilities" server for DNS, WSUS and the likes. Due to wireless access a Unifi controller must also be run on the servers

3) Management tools is another big area i am not so familiar with as I have really only assume this role for this project. Can anyone suggest management tools. We have used Spiceworks in the past However it has been buggy with AD authentication and the likes in the past and i would like to move away from it if possible can so any suggestions would be greatly appreciated

4) as for the router it is a FortiGate 60F with 4 LAN ports and 3 ISP/WAN ports and 1 DMZ that is currently unused

my question is does this topology currently sound like it will work fine as I have no one in my organisation to currently communicate this this off with the passing of my fellow IT member.

Any advice or suggestions would be great. Ive been doing networking for about 2 years now but its very different when you have to call the finial shots so thanks for any replies in advanced :D



No comments:

Post a Comment