LinuxQuestions.org
Visit Jeremy's Blog.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 08-22-2016, 05:43 AM   #1
serafean
Member
 
Registered: Mar 2006
Location: Czech Republic
Distribution: Gentoo, Chakra
Posts: 997
Blog Entries: 15

Rep: Reputation: 136Reputation: 136
vlans - are they worth it (opinion thread)


Hi all,

I have a home network (cca 20 devices at full load). Basic topology:
Code:
                                                            VOIP gateway (2x)
                                                               |
WAN -- Router -- switch1 (apartment 1 ) - switch2 ( building hub )- apartment 2
               |                     |
              devices           apartment 3
Router is a Gentoo box.
Apartments 2 and 3 are completely out of my control.
I'm thinking about replacing switches 1 and 2 with managed switches, to create vlans in order to logically separate apartments.
Being a complete newbie to VLANs et al, I borrowed a managed switch, played with it a bit already, and am left wondering whether it is worth the setup complexity.
The main reason I'm considering this is L3 separation of networks (mainly for VOIP gateways)

The other main advantage I see is that I could put the WAN access on the main switch, with the router anywhere else on the network :
Code:
                            WAN                     VOIP gateway (2x)
                                \vlan1                /
Router -- switch (apartment 1 ) -- switch ( building hub ) -- apartment 2
                     |                              |
                  devices                   apartment 3
Any input would be welcome, me not being a network guru, I'm wondering if I'm overthinking/overcomplicating this...

Thanks,

PS : I hope the ascii art looks as it should, I haven't found how to make use of <pre/>
PPS: Not 100% sure this belongs in this forum, move if appropriate.
 
Old 08-22-2016, 05:55 AM   #2
TenTenths
Senior Member
 
Registered: Aug 2011
Location: Dublin
Distribution: Centos 5 / 6 / 7
Posts: 3,488

Rep: Reputation: 1558Reputation: 1558Reputation: 1558Reputation: 1558Reputation: 1558Reputation: 1558Reputation: 1558Reputation: 1558Reputation: 1558Reputation: 1558Reputation: 1558
If you have no control over what's being plugged in at the various apartments then you need to segregate traffic, either physically or with vlans.

All it takes is for a rogue DHCP server to be plugged in anywhere and you could theoretically open all DHCP guests on the network with the rogue DHCP server being able to redirect all traffic from hosts through an arbitrary default gateway.
 
1 members found this post helpful.
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
python: why threading.thread pass empty dictionary to function thread golden_boy615 Programming 0 03-31-2014 11:45 AM
[SOLVED] Questions not worth their own thread bonixavier Slackware 10 03-14-2011 12:32 PM
python thread safety: printing from thread to redirected stdout - safe? BrianK Programming 2 10-11-2010 11:28 AM
bonding and vlans. Bonding a vlan interface vs applying vlans to a bond interface JasonCzerak Linux - Networking 0 09-11-2008 09:59 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 04:44 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration