LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 11-06-2013, 12:04 PM   #1
yzT!
Member
 
Registered: Jan 2013
Distribution: Debian
Posts: 168

Rep: Reputation: 2
Opinions about this network design


I've been tasked to design and implement the infrastructure of an organization. It has five servers with the following purposes:

- Web server: hosting the live application
- DB server: storing confidential data.
- App server: where developers perform their job.
- DB server 2: it has the same data as the other DB server.
- Test server: for playing around.

Requirements:

- Web server needs access to DB server.
- App server needs access to DB2 server.
- Test server may or may not access DB2 server (not sure about this).
- All servers need Internet connection.
- Use only a firewall, budget issues.

According to all the previous stated, I designed this scheme. Green indicates DMZ whereas red indicates VLANs.

http://i40.tinypic.com/rko906.jpg

What do you think? Is anything missing? Is the switch really needed? Could I just connect the four internal servers to the firewall, getting rid of VLANs?
 
Old 11-06-2013, 12:08 PM   #2
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
it looks broadly fine. As for the switch though, it depends what firewall you have. if you can carve it up for vlans internally then you certainly *could* do without the switch, but there are so many levels of firewall out there, we couldn't say. Note though there here the notion of the "dmz" is totally arbitrary compared to the other interfaces on the firewall.
 
Old 11-16-2013, 08:36 PM   #3
Andre.Smit
LQ Newbie
 
Registered: Nov 2013
Location: Bronkhortspruit
Distribution: SuSE - Kubuntu - OpenWRT
Posts: 22

Rep: Reputation: Disabled
Basic design looks fine. I would not leave out the switch though, as patching on a firewall as you change network config and do testing or setup is not good practice. Firewalls are expensive. It would also be good if you could have patch panels to save switch port patching for the same reason. Remember racks, PDUs, kvm switch & cables, patch cables, etc for budget.

Kind regards
Andre
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Network design SavoTU Linux - Networking 1 12-11-2011 12:09 PM
Network Design Help nedjinski Linux - Networking 1 10-10-2010 03:42 PM
Opinions on choosing the right network storage crontab Linux - Software 8 02-17-2009 09:56 PM
Network Design metallica1973 Linux - Security 6 04-09-2006 11:16 PM
Network Design for Larger Network goldcougar Linux - Networking 2 11-21-2003 10:58 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 11:52 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration