Solved

VLAN Setup How to create 2 networks but both with full internet conectivity (one switch)

Posted on 2006-10-31
6
701 Views
Last Modified: 2012-06-27
I have a router
http://broadband.motorola.com/consumers/products/VT2400/downloads/VT2442_User_Manual_US_UK.pdf

Conected to the router is a switch SMCGS16-SMART with 16 ports that supports VLans.
http://www.smc.com/index.cfm?event=viewProduct&localeCode=EN_USA&cid=7&scid=&pid=1485
(click on manual on the right)

Port 1 of the switch conects to the router, the router conects to the cable modem (for internet conectivity).

What I want to achieve is that Ports 2-8 are in a seperate LAN with internet conectivity and ports 9 to 16 in another LAN.The goal is that ports 9-16 DO NOT have access to ports 2-8.

My question is how do I need to setup my switch to seperate ports 2-8 and ports 9-16 so that both still have full internet conectivity.

Please do not point me to resources where I can read up about VLANS. I'd like direct instructions how to setup the switch... VLANS, PVID, TRUNKS or whatever is required. The link to the manual above shows what the user interfaces look like. I just want direct instructions so that it works.

Thanks.
0
Comment
Question by:mobile1
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
6 Comments
 
LVL 7

Expert Comment

by:knightrider2k2
ID: 17844186
If you seperate 2-8 and 9-16 into 2 VLANS, then they will not have direct access but they the traffic will be routed from the router and eventually they can connect to each other.

You have to block access on the router.
0
 
LVL 26

Expert Comment

by:lnkevin
ID: 17845362
1) Create Vlan number then set switchport range from 2-8....
2) Set ip for you network secment
3) Switchport mode trunk to trunk your Vlan if you want to connect your VLan
4) Configure sub interface in your router (bri0, bri1...) and set ip address according to your vlan IP address.

http://www.cisco.com/warp/public/793/lan_switching/3.html#assign

0
 
LVL 2

Expert Comment

by:HeavyWaterLTD
ID: 17846260
your switch may support VLANing but your router doesn't... I suggest you get a better router to do this.

Basically you need a router with 2 ethernet interfaces to route for both VLANS or a router that supports VLAN tagging (subinterfaces) as well as your switch. Then you can apply access-lists on each interface or subinterface to deny traffic.

Bottom line is..... you can separate your switch segment into different VLANS but you need a router present in each segment to route packets out of the VLAN (either logically through vlan tagging or physically through 2 separate interfaces).
0
Free Backup Tool for VMware and Hyper-V

Restore full virtual machine or individual guest files from 19 common file systems directly from the backup file. Schedule VM backups with PowerShell scripts. Set desired time, lean back and let the script to notify you via email upon completion.  

 
LVL 4

Expert Comment

by:tomerlei
ID: 17848267
If you can dedicate a computer with 3 NICs, you can connect the router to it and define the computer as a gateway for the 2 other NICs and connect each one to a different vlan.
0
 

Author Comment

by:mobile1
ID: 17850180
What about setting the router as VLAN 1 (port 1), ports 2-7 as members of VLAN 1 and VLAN 2, and ports 8-16 as members of VLAN 1 and VLAN 3. Would that work, or would I still have the problem that my router isn't up for the task.
0
 
LVL 2

Accepted Solution

by:
HeavyWaterLTD earned 500 total points
ID: 17853034
your router is not up to the task..... what you mentioned still only give your router access to only VLAN 1. your other VLANS have no way of talking to the router.
0

Featured Post

Free Backup Tool for VMware and Hyper-V

Restore full virtual machine or individual guest files from 19 common file systems directly from the backup file. Schedule VM backups with PowerShell scripts. Set desired time, lean back and let the script to notify you via email upon completion.  

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Use of TCL script on Cisco devices:  - create file and merge it with running configuration to apply configuration changes
I had an issue with InstallShield not being able to use Computer Browser service on Windows Server 2012. Here is the solution I found.
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…
Monitoring a network: why having a policy is the best policy? Michael Kulchisky, MCSE, MCSA, MCP, VTSP, VSP, CCSP outlines the enormous benefits of having a policy-based approach when monitoring medium and large networks. Software utilized in this v…
Suggested Courses
Course of the Month5 days, 5 hours left to enroll

635 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question