Expiring Today—Celebrate National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

VLAN Setup How to create 2 networks but both with full internet conectivity (one switch)

Posted on 2006-10-31
6
Medium Priority
?
711 Views
Last Modified: 2012-06-27
I have a router
http://broadband.motorola.com/consumers/products/VT2400/downloads/VT2442_User_Manual_US_UK.pdf

Conected to the router is a switch SMCGS16-SMART with 16 ports that supports VLans.
http://www.smc.com/index.cfm?event=viewProduct&localeCode=EN_USA&cid=7&scid=&pid=1485
(click on manual on the right)

Port 1 of the switch conects to the router, the router conects to the cable modem (for internet conectivity).

What I want to achieve is that Ports 2-8 are in a seperate LAN with internet conectivity and ports 9 to 16 in another LAN.The goal is that ports 9-16 DO NOT have access to ports 2-8.

My question is how do I need to setup my switch to seperate ports 2-8 and ports 9-16 so that both still have full internet conectivity.

Please do not point me to resources where I can read up about VLANS. I'd like direct instructions how to setup the switch... VLANS, PVID, TRUNKS or whatever is required. The link to the manual above shows what the user interfaces look like. I just want direct instructions so that it works.

Thanks.
0
Comment
Question by:mobile1
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
6 Comments
 
LVL 7

Expert Comment

by:knightrider2k2
ID: 17844186
If you seperate 2-8 and 9-16 into 2 VLANS, then they will not have direct access but they the traffic will be routed from the router and eventually they can connect to each other.

You have to block access on the router.
0
 
LVL 26

Expert Comment

by:lnkevin
ID: 17845362
1) Create Vlan number then set switchport range from 2-8....
2) Set ip for you network secment
3) Switchport mode trunk to trunk your Vlan if you want to connect your VLan
4) Configure sub interface in your router (bri0, bri1...) and set ip address according to your vlan IP address.

http://www.cisco.com/warp/public/793/lan_switching/3.html#assign

0
 
LVL 2

Expert Comment

by:HeavyWaterLTD
ID: 17846260
your switch may support VLANing but your router doesn't... I suggest you get a better router to do this.

Basically you need a router with 2 ethernet interfaces to route for both VLANS or a router that supports VLAN tagging (subinterfaces) as well as your switch. Then you can apply access-lists on each interface or subinterface to deny traffic.

Bottom line is..... you can separate your switch segment into different VLANS but you need a router present in each segment to route packets out of the VLAN (either logically through vlan tagging or physically through 2 separate interfaces).
0
Manage your data center from practically anywhere

The KN8164V features HD resolution of 1920 x 1200, FIPS 140-2 with level 1 security standards and virtual media transmissions at twice the speed. Built for reliability, the KN series provides local console and remote over IP access, ensuring 24/7 availability to all servers.

 
LVL 4

Expert Comment

by:tomerlei
ID: 17848267
If you can dedicate a computer with 3 NICs, you can connect the router to it and define the computer as a gateway for the 2 other NICs and connect each one to a different vlan.
0
 

Author Comment

by:mobile1
ID: 17850180
What about setting the router as VLAN 1 (port 1), ports 2-7 as members of VLAN 1 and VLAN 2, and ports 8-16 as members of VLAN 1 and VLAN 3. Would that work, or would I still have the problem that my router isn't up for the task.
0
 
LVL 2

Accepted Solution

by:
HeavyWaterLTD earned 2000 total points
ID: 17853034
your router is not up to the task..... what you mentioned still only give your router access to only VLAN 1. your other VLANS have no way of talking to the router.
0

Featured Post

Manage your data center from practically anywhere

The KN8164V features HD resolution of 1920 x 1200, FIPS 140-2 with level 1 security standards and virtual media transmissions at twice the speed. Built for reliability, the KN series provides local console and remote over IP access, ensuring 24/7 availability to all servers.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

WARNING:   If you follow the instructions here, you will wipe out your VTP and VLAN configurations.  Make sure you have backed up your switch!!! I recently had some issues with a few low-end Cisco routers (RV325) and I opened a case with Cisco TA…
This program is used to assist in finding and resolving common problems with wireless connections.
In this video we outline the Physical Segments view of NetCrunch network monitor. By following this brief how-to video, you will be able to learn how NetCrunch visualizes your network, how granular is the information collected, as well as where to f…
Monitoring a network: why having a policy is the best policy? Michael Kulchisky, MCSE, MCSA, MCP, VTSP, VSP, CCSP outlines the enormous benefits of having a policy-based approach when monitoring medium and large networks. Software utilized in this v…

719 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question