• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

Virtual networking layout

officeboy

n00b
Joined
Sep 28, 2011
Messages
38
Not sure if this should go in networking or here, this is my first real VM project, and I need security and as much resiliency as is reasonable. This is what I'm thinking of doing. Anyone see any problems?

Servers are dell R-710's 4 network ports each, switches are PowerConnect 2816, scada firewall/vpn is a dual WAN unit TBD.

Vlan2 should treat Vlan1 as untrusted and insecure. (Probably port based Vlans (the easiest for me to wrap my head around))

qaNkG.png


Thanks:D
 
Not enough info to really tell. On the surface it's good...stuff behind a firewall but that's about all I can tell. I will say this. I highly suggest not using VLAN1 for anything.
 
I highly suggest not using VLAN1 for anything.

Agreed.

I like to have my VM hosts be behind a switch/router that's only for managing the VMs, but that's because we have several hundred guests and it would be a nightmare if their internal networks were mangled up with the one we use for our workstations. Looks like that's maybe what your "Switch 16port-1" is for. I also have a heavy bias towards pfSense for network management as I detest the lack of standardization between the various embedded switch/router platforms. Might be worth looking into some options for consolidating your switches, VPN and firewalls, depending on your needs for ease of management and security.
 
Not enough info to really tell. On the surface it's good...stuff behind a firewall but that's about all I can tell. I will say this. I highly suggest not using VLAN1 for anything.

Why not use Vlan1 for anything? I've never used Vlans before but it seem like I should quit buying physical switches to keep things separate. So I tell myself, "Better figure out Vlans' quick".

Using Vlan1 made sense to me because these PowerConnect switches are only manageable from Vlan1 (a limitation that some online have expressed frustration about).

I am thinking about replacing the older Netgear switches (10/100) with something that at least has the same interface for management/control as these Dell switches.

I maybe could use a VM pfsense... but hmm, my head my not be able to work all those details out in the time frame I have been allotted.

(Also what additional detail would help, I also have a logical layout view)
 
Last edited:
I found this in reference to use of VLAN1. Was that your concern?

It seems like an OK risk to me as nothing else here uses anything but the default Vlan. My only real concern is keeping Vlan2 separate and secure.
 
Yes...it's just suggested not to use it. Really no reason to in most cases.
 
Back
Top