Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Divide Verizon FIOS network into separate subnets?

Posted on 2008-06-25
8
Medium Priority
?
2,285 Views
Last Modified: 2010-02-23
Here is the scenario:  A crisis intervention center that has a homeless shelter for its residents and an internal network of business-related computers.  Broadband comes in via Verizon FIOS through a ZyXel Prestige 861H-G1G2 modem that converts the FIOS phone signal to ethernet an then feeds an ActionTek Router which feeds the business systems..  My goal is to create two completely different networks--one for confidential internal use and another for use by the residents.  My original plan was to put a switch between the ZyXel Modem and the ActionTec router and run another router off of that switch, but for some reason, even when I try connecting directly to the ZyXel I cannot get out to the internet.  I can only get there via the ActionTek router (192.168.1.1).   I tried connecting a second router (192.168.2.1) to the ActionTek Router but I was able to cross back over and access the business systems that way, which I want to protect from that router.

I'm looking for ideas as to the most efficient way to create these two subnets.

Chuck
0
Comment
Question by:caaron
  • 4
  • 3
8 Comments
 
LVL 13

Accepted Solution

by:
kdearing earned 1500 total points
ID: 21871760
You need to configure the ActionTek for 2 VLANs.
Once that is done, you can restrict routing between the VLANs.

this link may help:
http://www.smallnetbuilder.com/content/view/30022/51/
0
 
LVL 1

Author Comment

by:caaron
ID: 21871793
I appreciate the link but I have no idea how to create VLANs or once done, how to keep them separate?  Can you provide specifics?  Can I keep the settings of the router for the Lan I now have running @ 192.168.1.1 and create a separate VLAN or do I need to create 2 VLANs?  I'd really need step by step guidance...

Chuck
0
 
LVL 13

Expert Comment

by:kdearing
ID: 21871867
I can get you started, but you'll need to consult a manual or the help pages.

To add a VLAN:
    go to the 'Network Connections' page
    select 'Advanced'
    click on the 'Edit' button for Ethernet

From there, you'll be able to select a specific LAN port and assign it to a different VLAN.

In order to restrict traffic between the VLANs, go to the 'Firewall Settings' section.
0
Concerto Cloud for Software Providers & ISVs

Can Concerto Cloud Services help you focus on evolving your application offerings, while delivering the best cloud experience to your customers? From DevOps to revenue models and customer support, the answer is yes!

Learn how Concerto can help you.

 
LVL 1

Author Comment

by:caaron
ID: 21888309
I spent most of today fighting with the Actiontec modem.  I was able to get a VLAN set up with it but I couldn't make it work.  Finally the router froze up and stopped responding, bringing down the whole network.  I contacted Verizon and they are bringing in a new modem tomorrow.  I was able to get the network up and running temporarily with another router I have.  I don't think using VLANs in the Actiontec is workable for me.  Is there another way I can set it up using separate hardware?
0
 
LVL 13

Expert Comment

by:kdearing
ID: 21888634
I have heard that navigating around the ActionTek configuration menu is pain in the a..
Realistically, you could use any VLAN-capable router.
0
 
LVL 1

Author Comment

by:caaron
ID: 21921634
I did write to Actiontec and got this as part of their response:

I also can include this walk through our engineers wrote.
Creating a VLAN using the BHR (4.0.16.1.15.2.9)
1.      Creating a VLAN
   a.      Select Network Connections/Advanced Connection/VLAN Interface
   b.      Make the Underlying Device the LAN Bridge
   c.      The VLAN ID can be any number from 1-4094, this will be the VLAN PVID
2.      Changing the IP Subnet
   a.      Select the VLAN/Settings/Internet Protocol/Use the Following IP Address
   b.      An example would be: 10.0.0.1 / 255.255.255.0
   c.      Under DNS Server enter the Primary and Secondary servers
   d.      From IP Address Distribution select DHCP Server
   e.      The range would be 10.0.0.2-254 / 255.255.255.0
3.      Configuring the VLAN on the Switch
   a.      Select Network Connections/Advanced/LAN Hardware Ethernet Switch/Settings
   b.      From 4 Port Ethernet Switch select Show
   c.      Assign the VLAN PVID number to the port desired (0-3)
              i.      Select Action for Port 0
              ii.      From Ingress select Tagged (Add VLAN Header)
              iii.      Leave the Egress set to Untagged
   d.      Be sure to connect the Ethernet cable to the port assigned the VLAN PVID
   e.      Your NIC should get an appropriate IP, like 10.0.0.2
   f.      Test by PINGing other addresses connected to the BHR
4.      Advanced Filtering (Blocking the VLAN from the LAN)
   a.      Select Security/Advanced Filtering
   b.      Under Incoming Packets find the VLAN
   c.      Make a New Entry, Under Matching select Source IP Address as ANY
   d.      For the Destination Address select Specify Address and click Add
   e.      Name the rule and click New Entry
   f.      Select IP Subnet to define the subnet you want to block
      i.      This will be (the LAN), 192.168.1.0 / 255.255.255.0
   g.      Repeat for the Outgoing Packets
5.      Test
   a.      You should no longer be able to PING between the 2 networks

I'll give it a try this week, but I'm really way over my head with this stuff...

Chuck

0
 
LVL 1

Author Comment

by:caaron
ID: 21983671
Setting up Vlans on the Actiontec router did not work for me.  It was too complex and Verizon's implementation of this router  differed from the Actiontec procedures.  I ended up resolving the problem by setting the Actiontec to 192.168.0.1 and running a line to a separate router at 192.168.1.1 for the internal wired network.  This prevents the wireless network (and associated access points) from getting into the wired network.

Chuck
0
 

Expert Comment

by:mignonnedavis
ID: 26836998
I know this has been closed for a while but I am going to be setting up an identical thing very soon.  I was wondering, in your solution, you say you ran another line to the separate router.  I'm assuming you mean you ran a crossover from the Actiontec to the other router, correct?  And DHCP is left enabled on both routers, I assume?
0

Featured Post

 [eBook] Windows Nano Server

Download this FREE eBook and learn all you need to get started with Windows Nano Server, including deployment options, remote management
and troubleshooting tips and tricks

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In the hope of saving someone else's sanity... About a year ago we bought a Cisco 1921 router with two ADSL/VDSL EHWIC cards to load balance local network traffic over the two broadband lines we have, but we couldn't get the routing to work consi…
Unable to change the program that handles the scan event from a network attached Canon/Brother printer/scanner. This means you'll always have to choose which program handles this action, e.g. ControlCenter4 (in the case of a Brother).
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Internet Business Fax to Email Made Easy - With  eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, f…

773 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question