Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

VLAN Setup How to create 2 networks but both with full internet conectivity (one switch)

Posted on 2006-10-31
6
Medium Priority
?
716 Views
Last Modified: 2012-06-27
I have a router
http://broadband.motorola.com/consumers/products/VT2400/downloads/VT2442_User_Manual_US_UK.pdf

Conected to the router is a switch SMCGS16-SMART with 16 ports that supports VLans.
http://www.smc.com/index.cfm?event=viewProduct&localeCode=EN_USA&cid=7&scid=&pid=1485
(click on manual on the right)

Port 1 of the switch conects to the router, the router conects to the cable modem (for internet conectivity).

What I want to achieve is that Ports 2-8 are in a seperate LAN with internet conectivity and ports 9 to 16 in another LAN.The goal is that ports 9-16 DO NOT have access to ports 2-8.

My question is how do I need to setup my switch to seperate ports 2-8 and ports 9-16 so that both still have full internet conectivity.

Please do not point me to resources where I can read up about VLANS. I'd like direct instructions how to setup the switch... VLANS, PVID, TRUNKS or whatever is required. The link to the manual above shows what the user interfaces look like. I just want direct instructions so that it works.

Thanks.
0
Comment
Question by:mobile1
6 Comments
 
LVL 7

Expert Comment

by:knightrider2k2
ID: 17844186
If you seperate 2-8 and 9-16 into 2 VLANS, then they will not have direct access but they the traffic will be routed from the router and eventually they can connect to each other.

You have to block access on the router.
0
 
LVL 26

Expert Comment

by:lnkevin
ID: 17845362
1) Create Vlan number then set switchport range from 2-8....
2) Set ip for you network secment
3) Switchport mode trunk to trunk your Vlan if you want to connect your VLan
4) Configure sub interface in your router (bri0, bri1...) and set ip address according to your vlan IP address.

http://www.cisco.com/warp/public/793/lan_switching/3.html#assign

0
 
LVL 2

Expert Comment

by:HeavyWaterLTD
ID: 17846260
your switch may support VLANing but your router doesn't... I suggest you get a better router to do this.

Basically you need a router with 2 ethernet interfaces to route for both VLANS or a router that supports VLAN tagging (subinterfaces) as well as your switch. Then you can apply access-lists on each interface or subinterface to deny traffic.

Bottom line is..... you can separate your switch segment into different VLANS but you need a router present in each segment to route packets out of the VLAN (either logically through vlan tagging or physically through 2 separate interfaces).
0
Choose an Exciting Career in Cybersecurity

Help prevent cyber-threats and provide solutions to safeguard our global digital economy. Earn your MS in Cybersecurity. WGU’s MSCSIA degree program was designed in collaboration with national intelligence organizations and IT industry leaders.

 
LVL 4

Expert Comment

by:tomerlei
ID: 17848267
If you can dedicate a computer with 3 NICs, you can connect the router to it and define the computer as a gateway for the 2 other NICs and connect each one to a different vlan.
0
 

Author Comment

by:mobile1
ID: 17850180
What about setting the router as VLAN 1 (port 1), ports 2-7 as members of VLAN 1 and VLAN 2, and ports 8-16 as members of VLAN 1 and VLAN 3. Would that work, or would I still have the problem that my router isn't up for the task.
0
 
LVL 2

Accepted Solution

by:
HeavyWaterLTD earned 2000 total points
ID: 17853034
your router is not up to the task..... what you mentioned still only give your router access to only VLAN 1. your other VLANS have no way of talking to the router.
0

Featured Post

Concerto's Cloud Advisory Services

Want to avoid the missteps to gaining all the benefits of the cloud? Learn more about the different assessment options from our Cloud Advisory team.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Originally, this post was published on Monitis Blog, you can check it here . It goes without saying that technology has transformed society and the very nature of how we live, work, and communicate in ways that would’ve been incomprehensible 5 ye…
During and after that shift to cloud, one area that still poses a struggle for many organizations is what to do with their department file shares.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Monitoring a network: why having a policy is the best policy? Michael Kulchisky, MCSE, MCSA, MCP, VTSP, VSP, CCSP outlines the enormous benefits of having a policy-based approach when monitoring medium and large networks. Software utilized in this v…

876 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question