V
V
Vasya Pupkin2021-06-28 08:16:33
System administration
Vasya Pupkin, 2021-06-28 08:16:33

What steps to take to "disassemble" a large network?

There is a network with the 21st mask, i.e. about 2 thousand addresses. Tell me how it will be correct to disassemble all this economy, and bring everything back to normal through Vlans. It is the phased analysis that interests me, I don’t really understand it yet, so I don’t want to miss any important stage.
Offhand, the most obvious is:
1. Make areas in DHCP for each vlan so that it issues addresses.
2. Create Vlans on L3 switches and configure routing.
3. Create Vlans on the final L2 switches and configure tranks there.

What else needs to be done that I could be missing?

Answer the question

In order to leave comments, you need to log in

5 answer(s)
A
Artem @Jump, 2021-06-28
Tag

and bring everything back to normal through Vlans.
First you need to decide why you need Vlans, what tasks they will solve.
After that, design a network - decide what exactly and into which vlans you need to cram.

K
kekoz, 2021-06-30
@kekoz

"dismantling" a large network is not a task for which stages can be built.
For now, your task is to build a functional and logical network diagram that you / the authorities want to receive. But then it will be possible to solve the problem of the form “How to get what is functionally and logically already designed on the existing physical network”.

D
Dmitriy Loginov, 2021-06-28
@caramingo

I would also make a network map in parallel, where I would enter where which wealan is connected to which department / office,
and if I have to bypass almost all computers, I would also start a list where the name of the employee is indicated, his IP and poppy address.

A
Alexander, 2021-06-29
@UPSA

miss out?
My opinion - you immediately solve the problem that you did not set for yourself. Why Vlans? You have DHCP in the first place - put it in last. Your list is a way to solve a problem, not the problem itself.
In the first place is the census of network objects. Servers, printers and computers. Switches as a separate class.
Not any full name of the employee - today Ivan is sitting at the computer, and tomorrow Daria and Alexander comes to check the mail during lunch breaks. And also computers with printers can run around the floors and buildings. And temporary computers come running.
Based on the objects, start building a network. Based on Mac addresses, but even I don’t believe in it, there is always a smart one who knows how to change or, from practice, plug in a switch and not tell about it))). BUT I continue to reserve in DHCP for Mac.
There is a big tangled web - do what you want.
Collected group of objects - we set DHCP.
All servers are not necessarily in a common group.
And it is not necessary to connect DHCP for each vlan .

I don't think that one shared network and 2k addresses is the norm.
What is Norma?
For me (tired of fighting with the authorities) - everyone does what they want, and what can not be hidden))) I
forgot about telephony. as a separate task.

V
Vladimir Pilipchuk, 2021-07-08
@SLIDERWEB

The first thing to do is to create a target topology. Describe how it should be, what technologies should be used and how everything should be wired and configured. Only then can you move on to the change planning stage. You are now loading your gun to shoot yourself in the leg and in the head at the same time.
Let's say you switch to VLANs, register everything everywhere ..., stretch them throughout the network, in one beautiful place you get a non-obvious ring and the entire network lies via STP ... and all because allowed vlan is not configured anywhere .. Or ,
routing between two large network segments (BGP / OSPF / EIGRP) does not rise because there is a device between them with IGMP Snooping enabled and mcast does not go through.
Or, when working out QoS on the PortChannel, there is a big loss of packets, since the wrong aggregation mode is used ... and now you need to reselect everything ...
Or maybe you'd better not switch to VLAN, but immediately build a transport MPLS domain and do traffic engineering?

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question