- Community Home
- >
- Networking
- >
- Legacy
- >
- Switches, Hubs, Modems
- >
- Re: Incorporating MAC-based VLANs, RADIUS, GVRP, a...
Switches, Hubs, and Modems
1752801
Members
5532
Online
108789
Solutions
Forums
Categories
Company
Local Language
юдл
back
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Discussions
Discussions
Forums
Forums
Discussions
юдл
back
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Blogs
Information
Community
Resources
Community Language
Language
Forums
Blogs
Topic Options
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО02-05-2010 11:55 AM
тАО02-05-2010 11:55 AM
Incorporating MAC-based VLANs, RADIUS, GVRP, and ACLs - Best approach?
Hi All,
I am in the process of redesigning the network at my company and would appreciate some suggestions on how to achieve my goals using HP ProCurve switches.
My design calls for:
- At least 30 VLANs/subnets (and growing), 14 edge switches, and 1 core switch.
- Each VLAN needs to access the Internet, other specific VLANs (not all of them), and be accessible through VPN.
- All VLANs will be assigned dynamically using a RADIUS server based on the host's MAC address (MAC-based authentication).
Now, due to the amount of edge switches and the growing number of VLANs, I'm thinking about implementing GVRP for VLAN propagation, so I can ease the administration process. Also, I'm assuming that the best way to allow VLANs to see the Internet and specific VLANs is to implement ACLs either at the core switch or with RADIUS. The problem is that I've heard that GVRP and ACLs on the core switch don't work together; I think a way to overcome this is to handle the ACLs through the RADIUS server but... will that require all the edge switches to be Layer 3 with support for ACLs? That's going to get expensive!
My idea was to go with HP ProCurve 2510G for my 14 edge switches and either a 2910al or 6600 for my core switch.
What do you, guys, suggest as far as equipment and configuration?
I am in the process of redesigning the network at my company and would appreciate some suggestions on how to achieve my goals using HP ProCurve switches.
My design calls for:
- At least 30 VLANs/subnets (and growing), 14 edge switches, and 1 core switch.
- Each VLAN needs to access the Internet, other specific VLANs (not all of them), and be accessible through VPN.
- All VLANs will be assigned dynamically using a RADIUS server based on the host's MAC address (MAC-based authentication).
Now, due to the amount of edge switches and the growing number of VLANs, I'm thinking about implementing GVRP for VLAN propagation, so I can ease the administration process. Also, I'm assuming that the best way to allow VLANs to see the Internet and specific VLANs is to implement ACLs either at the core switch or with RADIUS. The problem is that I've heard that GVRP and ACLs on the core switch don't work together; I think a way to overcome this is to handle the ACLs through the RADIUS server but... will that require all the edge switches to be Layer 3 with support for ACLs? That's going to get expensive!
My idea was to go with HP ProCurve 2510G for my 14 edge switches and either a 2910al or 6600 for my core switch.
What do you, guys, suggest as far as equipment and configuration?
2 REPLIES 2
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО02-06-2010 01:56 PM
тАО02-06-2010 01:56 PM
Re: Incorporating MAC-based VLANs, RADIUS, GVRP, and ACLs - Best approach?
No you don't need 'Layer 3' switches to handle dynamic ACLs, the 2610 series of switches will use them just fine. Though it's worth noting that ACLs only apply on packets ingressing into the switch.
GVRP and static port ACLs work just fine on all ProCurve switches. If they don't this is a defect and should be logged.. who's spreading this misinformation?
I'd recommend against using 2510 series for this; especially when you're trying to use complex features such as these. They're essentially budget versions of the 2610s with a lot of software functionality stripped out. You will more than likely find a critical feature you need is missing on the 2510 series.
On my previous employers network we distributed 76 VLANs to 200 2610 series and 400 2626 series switches via GVRP, using concurrent 802.1X+Mac-Auth to perform the assignment. The intermediary (distribution) switches were a mixture of 5300 and 5400zl switches with port ACLs on their downstream links (used to protect VRRP instances on the core), these then connected to 3*8200 series at the core which served as the GVRP advertisement root (i.e. where all the VLANs were statically defined).
Your design will work, just don't skimp on the edge switches ;)
GVRP and static port ACLs work just fine on all ProCurve switches. If they don't this is a defect and should be logged.. who's spreading this misinformation?
I'd recommend against using 2510 series for this; especially when you're trying to use complex features such as these. They're essentially budget versions of the 2610s with a lot of software functionality stripped out. You will more than likely find a critical feature you need is missing on the 2510 series.
On my previous employers network we distributed 76 VLANs to 200 2610 series and 400 2626 series switches via GVRP, using concurrent 802.1X+Mac-Auth to perform the assignment. The intermediary (distribution) switches were a mixture of 5300 and 5400zl switches with port ACLs on their downstream links (used to protect VRRP instances on the core), these then connected to 3*8200 series at the core which served as the GVRP advertisement root (i.e. where all the VLANs were statically defined).
Your design will work, just don't skimp on the edge switches ;)
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО02-09-2010 03:18 PM
тАО02-09-2010 03:18 PM
Re: Incorporating MAC-based VLANs, RADIUS, GVRP, and ACLs - Best approach?
Arran, Thank you for your response.
The 2610s, as you suggest, do have a great set of features but unfortunately they are not Gigabit switches, which is a requirement I forgot to mention. So what would be my next Gigabit edge switch supporting dynamic ACLs, the 2910al?
The 2610s, as you suggest, do have a great set of features but unfortunately they are not Gigabit switches, which is a requirement I forgot to mention. So what would be my next Gigabit edge switch supporting dynamic ACLs, the 2910al?
The opinions expressed above are the personal opinions of the authors, not of Hewlett Packard Enterprise. By using this site, you accept the Terms of Use and Rules of Participation.
News and Events
Support
© Copyright 2024 Hewlett Packard Enterprise Development LP