I need assistance to create company subnets
-
Hi friends,
I really need some assistance to create subnets in my network. Here some details of our configuration below. And I want basicly 4 different subnets as a sales group, developer group, r&d group and guest network. So basicaly what I want is to insulate each groups from each other : sales group will have full access to nas server and other all servers. dev group will have only access to internet and printers, r&d group will have also full access, guest will only have internet access but not LAN access to servers etc. Currently I have a ip pool that everybody connects but there are some basic issues that I want to prevent as I mentioned. So what is the basic way of doing it? Here are some hardware details,
We have pfsense installed up and running.
I have an ip pool currently which everybody can connect through access points and switches.- 7 access points connected to switches (no-smart or managable switch)
- Switches connect to a main patch panel in the server room.
- There are 2 internet providers currently working.
- Every devices connect to 1 main network.
- I need to create 4 different subnets and routing between subnets. For ex. Dev group needs printer and some other devices but not everything.
I will be so glad if I could hear from someone.
Thank you so much. -
This post is deleted! -
@bkyuksel said in I need assistance to create company subnets:
7 access points connected to switches (no-smart or managable switch)
Well that is a problem.. For you to segment your network you either need vlan capable devices switches and AP. Or you need to do it full physical where each network is on its own hardware.
Pfsense is capable of doing vlans - but you need the rest of your infrastructure to support it. So you need at min a vlan capable switch to use as core switch, downstream switches can be dumb as long as you plan on all devices connected to these dumb switches to be in the same network/vlan.
Same goes for your AP.. if they are dumb then you would plug them into different switch port that is only on the vlan you want all wireless devices to be on that connect to that AP.
I would really suggest you invest in some vlan capable switches and AP. Doesn't have to break the bank.. This can really be done on a shoestring budget if need be..
-
This post is deleted!