Log in

View Full Version : OMO: Recommend me a switch and a firewall


Fordward
17-11-15, 07:52 PM
I know there's a few techhies on this forum, and it's a long time since I did a hands on technical job.

I'm looking for a new switch and firewall for the local community centre, who currently run their network off an 8 port hub uplinked to a 4 port LAN switch in the back of a Draytek Vigor firewall. These 10 ports are all utilised and they can't plug in anything else, like new PC's, new printers or their CCTV DVR.

They have two wireless access points which provide public wifi for the bar and village hall, and another client wifi for people renting the meeting rooms. These are all on the same /24 subnet as the server and all the office PC's and the network is open to internal attack from any member of the public connecting to that network. Ports are currently open from the internet straight into this internal network. When there's a lot of people in the building they run out of addresses within the DHCP scope.

So, I want to install a new switch and firewall.

The switch has to support VLAN's, either logically tagged, or untagged and assigned to physical ports, so I can create different segregated networks for the internal network, another for the public wifi, another for the client wifi, and another as a web facing DMZ, all on one switch. 24 port would be enough. 1Gbps RJ45 interfaces.

The firewall needs either 5 interfaces which are configurable, for these 4 different networks plus the WAN port, or it needs to support logical trunking so I can 802.1Q tag all these different networks over a single LAN interface (or a pair of interfaces if it and the switch support link aggregation, but this isn't a critical business so if I have to spend twice as much to get that redundancy I won't bother. The switch and firewall will both be single points of failure anyway).

So, keeping it as cheap as possible (this place is run as a charity where £1000 is a lot of money), what switch and firewall would you recommend?

Thanks

Littlepeahead
17-11-15, 09:03 PM
Oh dear god, I've no idea what you're on about. However, I work with a couple of guys who might and I'm sending them this!

pookie
17-11-15, 09:13 PM
If you are happy with draytek there is the 2860 which has 6 ports and and wireless n.

andrewsmith
17-11-15, 09:30 PM
I would say draytek
If you need further expansion use a netgear unmanaged switch behind

DJ123
17-11-15, 10:24 PM
Draytek have a brilliant pre sales team who will guide you to the correct configuration. Number is on their main site and a very good at what they do.

Fordward
17-11-15, 10:54 PM
OK, thanks. That would work for them, WAP'S and DVR straight into configurable interfaces on the firewall, uplink to an unmanaged switch on another interface for the internal network. I hadn't thought of doing it that way, too many years of enterprise datacentre design getting in the way of my thinking.

Trouble is that doesn't give them any expansion without adding more unmanaged switches to each firewall interface, which is why I was hoping managed switches had got a bit cheaper?

The other thing I forgot to mention was I want to add Web hygiene, a lot if teenagers starting to use the community centre and I don't want them all surfing porn, but I can do that by forwarding 80/443 to an externally hosted service if the functionality isn't on the firewall.

Sent from my SM-G900F using Tapatalk

Fordward
17-11-15, 10:56 PM
Oh dear god, I've no idea what you're on about. However, I work with a couple of guys who might and I'm sending them this!
Lol thanks :-)

Sent from my SM-G900F using Tapatalk

DJ123
17-11-15, 10:56 PM
Draytek do filters for the firewall, so easy to implement that. Or you could go down the Sonicwall route. Very effective & the majority of schools use them.

Fordward
17-11-15, 11:00 PM
Oh, if I'm going to plug WAP's directly into firewall ports, the firewall needs to offer DHCP services on each subnet connected to each interface.

Sent from my SM-G900F using Tapatalk

Fordward
17-11-15, 11:12 PM
Draytek do filters for the firewall, so easy to implement that. Or you could go down the Sonicwall route. Very effective & the majority of schools use them.
Great thanks. I'll phone Draytek pre-sales in the morning.

My world is all campus / datacentre, Cisco, HP/Comware, I don't deal with devices that cost less than 2 or 3 grand each. It's 15 years since I worked with anything SOHO.

Sent from my SM-G900F using Tapatalk

Fordward
17-11-15, 11:19 PM
Oh, if I'm going to plug WAP's directly into firewall ports, the firewall needs to offer DHCP services on each subnet connected to each interface.

Sent from my SM-G900F using Tapatalk

Unless of course the WAP's themselves offer DHCP? They are Draytek as well I think. Again I know nothing about them, I'm used to dealing with the likes of Cisco Aironet or Meraki, centrally managed stuff.
Oh, if I'm going to plug WAP's directly into firewall ports, the firewall needs to offer DHCP services on each subnet connected to each interface.

Sent from my SM-G900F using Tapatalk


Sent from my SM-G900F using Tapatalk

Littlepeahead
18-11-15, 07:24 AM
My two colleagues are having a look at this for you today.

Littlepeahead
18-11-15, 08:01 AM
They said...Would be handy to know what model Vigor they're running as these generally support VLAN tagging (802.1q). In which case, you would just need a new switch, probably a Netgear managed switch and they're good value for money.

Then they were chatting about donating stuff. Can you PM me your email address?

pookie
18-11-15, 08:16 AM
you can run a dhcp servers on each vlan assigned to different ports on the draytek 2860. You could use opendns and the web content filter.
It is pretty handy for remote access with the built in vpn. We use them as endpoints for remote users

atassiedevil
18-11-15, 08:39 AM
You can also use these.
Steep learning curve, but i have one and it's an amazing piece of kit for the money.
It will do all you need, including DHCP for different network segments, vlan tagging, vpn inbound, and it has an amazing feature set.

http://routerboard.com/CRS125-24G-1S-2HnD-IN

There are local distributors and all in mine was around £180 delivered.

Fordward
18-11-15, 09:24 AM
They said...Would be handy to know what model Vigor they're running as these generally support VLAN tagging (802.1q). In which case, you would just need a new switch, probably a Netgear managed switch and they're good value for money.

Then they were chatting about donating stuff. Can you PM me your email address?

Hi LPH, it's a Vigor 2820vn.

http://www.draytek.co.uk/products/legacy/vigor-2820#6-specification

Dropping you a PM now.

Littlepeahead
18-11-15, 07:24 PM
Got your PM. Sounds like we've got various stuff cluttering up the office that might help you out. I'll chat to the lads.