Re: Need help controlling access between vlans



On Sep 27, 10:17 am, Trendkill <jpma...@xxxxxxxxx> wrote:
On Sep 27, 7:10 am, 1crazyri...@xxxxxxxxx wrote:





The new IT manager wants to bring in a third party to check our Cisco
network for problems. I want to do whatever I can to get a get a good
report. I have students and teacher on the same vlans and I think this
is something the consultant may point out. Students and teachers
access some of the same servers, printers, etc. Also, teacher
workstations use software that allows them to view the screens of
students and any VLAN can get to anything on any other VLAN. We have
eight buildings with 3750's at each building and a 4507 at the core.
We have 3560G's at each IDF with older 3com's daisy chained to them.
All IDF's, including other schools are trunked to the core. Can anyone
recommend best practice in this situation? I think I'd like to start
with blocking traffic from some vlans to other vlans. What approach do
I take when there are shared resources? Do I put those things on a
special vlan? What happens to my DHCP scopes?
What are the commands to prevent some vlans from being routed?
thanks

Provided you must separate the networks, create a new network/vlan
with a new dhcp scope for faculty, and assign ports as needed. I
would hope that none of your servers are DHCP, and that hostnames are
being used instead of IPs. With that being said, move those to a
third vlan that you can control via access-lists. Truthfully, rather
than pegging down the server vlan, I would peg down the student vlan
since that is probably your biggest security risk. Use ACLs to allow
what you want and block anything else. Depending on how loose or
strict the ACLs are on the student vlan, you may also want some ACLs
on the server network to only allow specific connection types from the
student vlan. It just depends what all you are trying to prevent/lock
down and how to best do that with ACLs.

If you can't move the servers due to IP address usage, then create two
new vlans for your dhcp clients. Your users shouldn't care provided
you do it during a specific time, and at worst, they may require a
reboot if they don't have access to the command prompt and ipconfig.

If you want vlans that are completely non-routed, just don't put a
router interface in the network, just create it on layer 2. Or just
put an ACL on the VLAN to deny any any.- Hide quoted text -

- Show quoted text -


Thanks for responding. Your suggestion to work on the student vlan is
a good one.

Here is my plan:
1. move students to their own vlan. Each of our 8 schools has a
separate vlan, so I will need to create 8 student vlans. I will need
to keep them separate because of scripts that run based on Active
Directory sites which uses subnets. **Will this create a lot of extra
work with ACL's?

2. create ACL on the student vlan to only allow traffic to specific
servers on the server vlan.

3. Allow staff vlans to connect to the student vlan (teachers run apps
to monitor student workstations)

4. Don't allow any vlan to talk to another vlan unless there is a
reason. In other words, currently no schools need to directly access
anything in any other school. They all access servers at our core.

Am I on the right track here?
Now all I need is some free open source software to monitor my
network.

thanks

.



Relevant Pages

  • Re: Need help controlling access between vlans
    ... network for problems. ... students and any VLAN can get to anything on any other VLAN. ... strict the ACLs are on the student vlan, you may also want some ACLs ...
    (comp.dcom.sys.cisco)
  • Re: Need help controlling access between vlans
    ... network for problems. ... students and any VLAN can get to anything on any other VLAN. ... strict the ACLs are on the student vlan, you may also want some ACLs ...
    (comp.dcom.sys.cisco)
  • network congestion ISA 2006
    ... I'm having some very strange problems with my network ever since I ... The other networks are for application servers, database servers, ... The ISA is right in the middle of all of this and filtering traffic between ... Everytime some tries copying a big file from the clients VLAN to any other ...
    (microsoft.public.isa)
  • Re: Need help controlling access between vlans
    ... network for problems. ... students and any VLAN can get to anything on any other VLAN. ... strict the ACLs are on the student vlan, you may also want some ACLs ...
    (comp.dcom.sys.cisco)
  • Re: Large VLAN Project - Advise
    ... I am beginning to look at adding VLAN's to our network, and am unsure how to approach the process - I have many Cisco certifications but have not taken on a project of this magnitude before, and would really appreciate any advise that may b out there. ... We have a comms room which houses all servers, ... I thought about configuring a seperate VLAN for each closet - unsure if this is the way to go, as the essential traffic pattern is all machines want to connect to the central servers, however my main concern is how to introduce VLAN's while still maintaining the legacy network. ...
    (comp.dcom.sys.cisco)