Hi,
First of all some background on the current setup...
The network is flat with trust being on a 10.0.0.0/16, gateway 10.0.0.254 which is on an SRX240 and a few VLANs on 24 subnets which are on a the HP 5412zl switch, the network is:
2 node SRX240H2 cluster active/passive, the active node connected to a HP 5422zl and passive to a HP 4204vl, the 5412 and 4204 are both connected. Then there are 2 user access switches (HP 4104gl) connected to the 4204vl, as below:
Active Passive
SRX240-1 SRX240-2
| |
HP 5412zl <- -> HP 4202vl
|
HP 4104gl x2
I will soon be replacing the user access switches with Juniper EX2200s in a 4 node virtual chassis or 2 separate ones. These will be connected to both the HP 5412vl and 4204vl switches.
At the same time as doing this I'll be separating the network into VLANs:
Servers: 10.0.0.0
Users ground floor: 10.0.1.0
Users first floor: 10.0.2.0
Printers: 10.0.3.0
Other network devices: 10.0.4.0
I stuck with those for ease as the servers are on that range now and are static. The user ones will get their IP from a Windows DHCP server.
Now finally the questions:
1) Is this a good way to separate the network?
2) If so is static routing the way to go with it being a small network?
3) Is it best to create these VLANs on the SRX interfaces so it acts as the gateway for all the VLANs?
Thanks
Ross