Solved

Divide Verizon FIOS network into separate subnets?

Posted on 2008-06-25
8
2,032 Views
Last Modified: 2010-02-23
Here is the scenario:  A crisis intervention center that has a homeless shelter for its residents and an internal network of business-related computers.  Broadband comes in via Verizon FIOS through a ZyXel Prestige 861H-G1G2 modem that converts the FIOS phone signal to ethernet an then feeds an ActionTek Router which feeds the business systems..  My goal is to create two completely different networks--one for confidential internal use and another for use by the residents.  My original plan was to put a switch between the ZyXel Modem and the ActionTec router and run another router off of that switch, but for some reason, even when I try connecting directly to the ZyXel I cannot get out to the internet.  I can only get there via the ActionTek router (192.168.1.1).   I tried connecting a second router (192.168.2.1) to the ActionTek Router but I was able to cross back over and access the business systems that way, which I want to protect from that router.

I'm looking for ideas as to the most efficient way to create these two subnets.

Chuck
0
Comment
Question by:caaron
  • 4
  • 3
8 Comments
 
LVL 13

Accepted Solution

by:
kdearing earned 500 total points
Comment Utility
You need to configure the ActionTek for 2 VLANs.
Once that is done, you can restrict routing between the VLANs.

this link may help:
http://www.smallnetbuilder.com/content/view/30022/51/
0
 
LVL 1

Author Comment

by:caaron
Comment Utility
I appreciate the link but I have no idea how to create VLANs or once done, how to keep them separate?  Can you provide specifics?  Can I keep the settings of the router for the Lan I now have running @ 192.168.1.1 and create a separate VLAN or do I need to create 2 VLANs?  I'd really need step by step guidance...

Chuck
0
 
LVL 13

Expert Comment

by:kdearing
Comment Utility
I can get you started, but you'll need to consult a manual or the help pages.

To add a VLAN:
    go to the 'Network Connections' page
    select 'Advanced'
    click on the 'Edit' button for Ethernet

From there, you'll be able to select a specific LAN port and assign it to a different VLAN.

In order to restrict traffic between the VLANs, go to the 'Firewall Settings' section.
0
 
LVL 1

Author Comment

by:caaron
Comment Utility
I spent most of today fighting with the Actiontec modem.  I was able to get a VLAN set up with it but I couldn't make it work.  Finally the router froze up and stopped responding, bringing down the whole network.  I contacted Verizon and they are bringing in a new modem tomorrow.  I was able to get the network up and running temporarily with another router I have.  I don't think using VLANs in the Actiontec is workable for me.  Is there another way I can set it up using separate hardware?
0
What Is Threat Intelligence?

Threat intelligence is often discussed, but rarely understood. Starting with a precise definition, along with clear business goals, is essential.

 
LVL 13

Expert Comment

by:kdearing
Comment Utility
I have heard that navigating around the ActionTek configuration menu is pain in the a..
Realistically, you could use any VLAN-capable router.
0
 
LVL 1

Author Comment

by:caaron
Comment Utility
I did write to Actiontec and got this as part of their response:

I also can include this walk through our engineers wrote.
Creating a VLAN using the BHR (4.0.16.1.15.2.9)
1.      Creating a VLAN
   a.      Select Network Connections/Advanced Connection/VLAN Interface
   b.      Make the Underlying Device the LAN Bridge
   c.      The VLAN ID can be any number from 1-4094, this will be the VLAN PVID
2.      Changing the IP Subnet
   a.      Select the VLAN/Settings/Internet Protocol/Use the Following IP Address
   b.      An example would be: 10.0.0.1 / 255.255.255.0
   c.      Under DNS Server enter the Primary and Secondary servers
   d.      From IP Address Distribution select DHCP Server
   e.      The range would be 10.0.0.2-254 / 255.255.255.0
3.      Configuring the VLAN on the Switch
   a.      Select Network Connections/Advanced/LAN Hardware Ethernet Switch/Settings
   b.      From 4 Port Ethernet Switch select Show
   c.      Assign the VLAN PVID number to the port desired (0-3)
              i.      Select Action for Port 0
              ii.      From Ingress select Tagged (Add VLAN Header)
              iii.      Leave the Egress set to Untagged
   d.      Be sure to connect the Ethernet cable to the port assigned the VLAN PVID
   e.      Your NIC should get an appropriate IP, like 10.0.0.2
   f.      Test by PINGing other addresses connected to the BHR
4.      Advanced Filtering (Blocking the VLAN from the LAN)
   a.      Select Security/Advanced Filtering
   b.      Under Incoming Packets find the VLAN
   c.      Make a New Entry, Under Matching select Source IP Address as ANY
   d.      For the Destination Address select Specify Address and click Add
   e.      Name the rule and click New Entry
   f.      Select IP Subnet to define the subnet you want to block
      i.      This will be (the LAN), 192.168.1.0 / 255.255.255.0
   g.      Repeat for the Outgoing Packets
5.      Test
   a.      You should no longer be able to PING between the 2 networks

I'll give it a try this week, but I'm really way over my head with this stuff...

Chuck

0
 
LVL 1

Author Comment

by:caaron
Comment Utility
Setting up Vlans on the Actiontec router did not work for me.  It was too complex and Verizon's implementation of this router  differed from the Actiontec procedures.  I ended up resolving the problem by setting the Actiontec to 192.168.0.1 and running a line to a separate router at 192.168.1.1 for the internal wired network.  This prevents the wireless network (and associated access points) from getting into the wired network.

Chuck
0
 

Expert Comment

by:mignonnedavis
Comment Utility
I know this has been closed for a while but I am going to be setting up an identical thing very soon.  I was wondering, in your solution, you say you ran another line to the separate router.  I'm assuming you mean you ran a crossover from the Actiontec to the other router, correct?  And DHCP is left enabled on both routers, I assume?
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

Suggested Solutions

Title # Comments Views Activity
Access shared drive during VPN session 9 61
Wireshark 7 52
Flashing Cisco Meraki MR18 with OpenWRT firmware ? 5 45
server plus 2 40
Tired of waiting for your show or movie to load?  Are buffering issues a constant problem with your internet connection?  Check this article out to see if these simple adjustments are the solution for you.
Let’s list some of the technologies that enable smooth teleworking. 
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…

763 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

7 Experts available now in Live!

Get 1:1 Help Now