Hi All,
I am in the process of redesigning the network at my company and would appreciate some suggestions on how to achieve my goals using HP ProCurve switches.
My design calls for:
- At least 30 VLANs/subnets (and growing), 14 edge switches, and 1 core switch.
- Each VLAN needs to access the Internet, other specific VLANs (not all of them), and be accessible through VPN.
- All VLANs will be assigned dynamically using a RADIUS server based on the host's MAC address (MAC-based authentication).
Now, due to the amount of edge switches and the growing number of VLANs, I'm thinking about implementing GVRP for VLAN propagation, so I can ease the administration process. Also, I'm assuming that the best way to allow VLANs to see the Internet and specific VLANs is to implement ACLs either at the core switch or with RADIUS. The problem is that I've heard that GVRP and ACLs on the core switch don't work together; I think a way to overcome this is to handle the ACLs through the RADIUS server but... will that require all the edge switches to be Layer 3 with support for ACLs? That's going to get expensive!
My idea was to go with HP ProCurve 2510G for my 14 edge switches and either a 2910al or 6600 for my core switch.
What do you, guys, suggest as far as equipment and configuration?