I am reworking our networking infrastructure in prep. for implementing VLANs. Over the next few months we will be bringing additional servers online w\ roles including production\test database servers, web servers, application servers, etc. I am trying to find examples of how others have separated their servers - i.e all database servers on one VLAN, file servers on another, etc. Ideally, servers requiring incoming connections from untrusted subnet ranges will be separate from those allowing incoming connections from only a few static IPs, but I am not sure how best to lay out the new VLANs since I am new to this.
Any suggestions? Hopefully someone has gone through a similar situation and can help. Feel free to PM me if you'd rather keep this off board. Or feel free to just point me in a certain direction - I am fine w\ reading up on it, but haven't found much out there in the way of examples. Lastly, in case someone feels like mentioning this, we are a small department, so this will be happening over a long time and not going into production until I am comfortable w\ it - we aren't going to hire an outside expert.
Any suggestions? Hopefully someone has gone through a similar situation and can help. Feel free to PM me if you'd rather keep this off board. Or feel free to just point me in a certain direction - I am fine w\ reading up on it, but haven't found much out there in the way of examples. Lastly, in case someone feels like mentioning this, we are a small department, so this will be happening over a long time and not going into production until I am comfortable w\ it - we aren't going to hire an outside expert.