cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
332
Views
0
Helpful
3
Replies

Design Solution is Needed

avilt
Level 3
Level 3

I need some assistance on the network design. I have 4 plants each with around 30 HIS workstations. All these 4 plants are connected to a central location using fiber link (1gbps) which are then terminated on a ASA firewall. The issue is that all these 4 plants are in the same vlan/subnet which I see is not a good design. What are the best practices in terms of redesign?

 

One dedicated vlan for each plant, how should I terminate these at the central location?

Also how can I change the fiber uplink to 10gbps?

 

Do I need to have a dedicated management vlan for each plant?

1 Accepted Solution

Accepted Solutions

Leo Laohoo
Hall of Fame
Hall of Fame
Do I need to have a dedicated management vlan for each plant?

Yes.  

 

Let's say you require three (3) VLANs:  Data, Voice and Guest.   You put a fourth VLAN for Management of your appliance.  You have the option to use different VLANs per site or use the same VLANs.   Your call.  Won't make any difference because you can set VTP Mode to Transparent.  

 

The main point is that you can set each site to have it's own subnet.  

how should I terminate these at the central location?

Hub-and-spoke topology.  Each site advertises it's own subnet via routing protocl like OSPF.  All the site connects to the head office.

Also how can I change the fiber uplink to 10gbps?

You change the fibre optic module from SFP to SFP+.

View solution in original post

3 Replies 3

Leo Laohoo
Hall of Fame
Hall of Fame
Do I need to have a dedicated management vlan for each plant?

Yes.  

 

Let's say you require three (3) VLANs:  Data, Voice and Guest.   You put a fourth VLAN for Management of your appliance.  You have the option to use different VLANs per site or use the same VLANs.   Your call.  Won't make any difference because you can set VTP Mode to Transparent.  

 

The main point is that you can set each site to have it's own subnet.  

how should I terminate these at the central location?

Hub-and-spoke topology.  Each site advertises it's own subnet via routing protocl like OSPF.  All the site connects to the head office.

Also how can I change the fiber uplink to 10gbps?

You change the fibre optic module from SFP to SFP+.

One clarification on management vlan. I have only one switch in each plant. Is it worth dedicating a management vlan per plant? Is it really must (security reasons) to have a dedicated management vlan? Can I not use the data vlan since all I need is one management IP address for the switch to manage/monitor it.

You can use existing VLAN if you want.