RatwareUK Case Study - vLAN / Firewall / IP Architecture / Advanced Networking



Background

RatwareUK had already installed a couple of physical servers, all running Microsoft Hyper-V with several virtual hosts for this particular client. However, the latest technical challenge was a different again. The company had ordered a high-speed, leased broadband connection to their new premises. The premises contained three separate organisations, all linked to the group of companies. Therefore, this new internet connection needed to be shared between three different local area networks (LANs) as the connection was to be used by three separate entities on site. Each LAN had to operate completely independently and could not be allowed to pass data to the others (as one of the networks was to be publicly accessible). However, each LAN had to be able to use the one common high-speed internet connection.

Problems Being Addressed

Currently, when considered together, the network had twelve 24 port switches and three physical servers. To avoid replacing all the network switches which were incompatible with virtual LANs (vLANs) and different subnets, the switches would have to be separated and linked up by to a separate designated vLAN.

A gateway would have to be chosen that supported vLANs on different local ethernet ports. The gateway's firewall would also have to be configured to dis-allow traffic between subnets and allow static routes to the wide area network (WAN).

The Approach Taken

A network map was designed by a technical architect at RatwareUK, mapping out the premises and its comms rooms. Network switches were than added to the map and each switch was allocated against one of three IP subnets. Engineers then decided to deploy a Draytek 3300V+ which would provide up to four vLANs which could operate individually and share the one internet connection.

All switch or server uplinks between cabinets on-site were implemented using yellow patch leads to indicate their importance. Then every switch was separated onto its designated virtual LAN.

The new Draytek gateway was then meticulously programmed on site using telnet commands and a web interface. Each vLAN was provided with its own independently controlled DHCP Server controlling IP assignment for each subnet.

The Solution

RatwareUK and the client were able to achieve one high-speed internet connection, servicing three completely different virtual LANs. This provided secure and robust internet access for three LANs on one site.

Photos

  1. IP architecture design in progress on site
  2. Photo of main comms cabinet with new Draytek gateway installed

Client

Due to the security nature of this case study the client has not been disclosed.