VLANs for a small office, what to use?

Ok, I'm in a pinch here....

I have $1000 to do the following

Client is the broadband provider for 2 other tenants in his office.  They have a total of 26 ports that we need to hooked into a switch.  Here is what I need...

Client 1 (landlord), Client 2 and Client 3 all need to share the same broadband connection, but be seperated via VLAN with ACL's.  Client 1 has EXTREMELY sensitive data that needs to be segregated.  They need to be on seperate subnets (obviously), but I am not allowed to introduce a server into their environment, so a server based DHCP server with 3 seperate scopes is out of the question.  They also want a firewall product to be integrated into this mix.  

What i think i know....

A nice L2/L3 switch will allow me to VLAN everybody off, either by port or by MAC, but does not address how to dish out different dynamically assigned addresses to each VLAN, nor does it address the firewall aspect.  I think the ASA 5505 Cisco would handle the firewall issue pretty well, as well as the DHCP, but once I get that 3rd VLAN, the licensing pushes it above $1000 just by itself.  I'm kind of at a loss as how to get this ball rolling and what hardware combination would be adequate.  The netgear L2/L3 switches look very good, but I know I'm going to have to get a 48 prt switch (although I could probably talk them into a 24 port and have them switch in the offices to free up some room) with is not cheap.  I think there is a sweet spot somewere in here, but I'm just not seeing it....

please ask questions and I will answer them

Many Thanks,

Danny Wheeler, MCSE
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Layer 3 switch is easily going to set you over $1,000. You could go with a Clarkconnect. http://www.clarkconnect.com/info/compare.php Its software that you would load on a system you would provide. You can install several NIC cards on the PC and those would become you VLANs. You could then use the dumbest switch(s) you can find, if high bandwidth isn't needed. http://www.clarkconnect.com/info/features.php It provides many useful features and its an enterprise solution. Good Luck
what network equipment do you already have there?

how is the wiring done? each tenant have an idf or do all network lines run rom the same closet?

how many connections are needed per tenant?
26 total how is this broken down?
I dont know if im being serious or not, this is just off the top of my head.

*any brand can be used
Get a linksys router w four port switch hook that up to the internet.
Get 3 other linksys routers, set them up as routers, not gateways. Put what would be their WAN ports on the same network as the first router connected to the internet.  Set each scope up as a different range, now you have 3 seperate networks. make sure the gateway router has routes in it for each of the other ranges(WAN Port of each other router on the same network). In the three network routers include the default gateway of thier wan ports as the internet router, dns could be the same internet router or you could just use some public internet dns.

if they need more switch ports buy cheep switches for each tennant.

im sure you can figure this out.

thats a laughable network for under a laughable $1000
Or try refurbished hardware.  


Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
Here is what you do. Get a Cisco 2950 48 Port switch off of Ebay, a decent one with a warranty. Should run you between $250 and $350. Also, get a Cisco 1721 router as well with an extra WIC-1ENET card. Make sure it has 32Mbyte of Flash and a minimum of 64Mbyte of RAM.

What you do is configure three vlans, one for each tenant and client. Next, configure trunking on the switch port that is plugged into the router and configure vlans with 802.1q encapsulation on the fast ethernet interface of the LAN side. You can then set up a different subnet for each tenant and client. The other ethernet card will plug into the broadband connection. You can configure NAT on the router to get them out to the internet. Each vlan on the router will have an IP address assigned to it which will then also allow you to create access lists to permit and deny traffic to each subnet accordingly.

This should work out for you very well and you will be well under the $1000 mark. If you need assistance with the configuration, please let me know and I can help you.
danlikey2Author Commented:
Actually guys, I figured this one out on my own...


Fortinet 60b


This router allows you to configure "VDOM"'s, or virtual domains, each acting like it's own seperate network WITH it's own seperate firewall with configurable settings.   Can be had for around $500.  It allows for for up to 10 VDOMs, each with it's own DHCP server built in, per interface, as well as port level ACL and seperation from other interfaces.   I won't need trunking, as I will just run a seperate cat6 into each VLAN on my switch to dish out DHCP to that particular VLAN (router comes with 8 interfaces).  I actually have used one of these in the past, and I would put the quality right up there with Cisco, without the name recognition.  The VDOM concept is new though, I did not know they could do that....

I will use the Cisco SMB SLM248G (rebranded linksys) for the switch, since I can pick it for $320 new, although I might entertain the notion of the used 2950.  We'll see, client wants new equipment.  It will allow me to configure the VLANs, and since I dont need to do tagging, just ports, it will be easy to drop a cable from the the interface on the Fortinet to the switch and have a segragated network.  Done!

This puts me at $850 (approx) for my laughable network, with only 2 pieces of equipment and a minimum amount of jumble.  It also uses some pretty good new equipment that is all fairly easy to reconfigure if the next IT guy is like me and not a Cisco guru....

Anywho, comments welcome, and I will find a way to distribute points even though I got this one on my own.  Good suggestions though.


It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Networking Hardware-Other

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.