Advice needed on configuring a router and VLANs

This is more about VLANs than the router, but I include the model information for completeness' sake. It is a WRVS4400N Linksys VPN Security Router - it has a wireless antenna and 4 physical ports, and supports VLANs.

The router allows for the creation of VLANs. My aim is to create VLAN 1 using two physical ports and the wireless antenna, while having the other two physical ports turned over to VLAN 2.

The router should provide DHCP for VLAN 1. There is a DHCP server on VLAN 2 so the router will not need to provide DHCP. This I have configured and believe to be correctly working.

VLAN 2 will be little more than a gateway between a server and modem on the other side of the router from the server e.g. Modem > Router > Server > Server's LAN.

To the nitty-grity - there is a JPG attached of the possible configurations for the ports from the router. For argument's sake, I'd like Ports 3, 4 and wireless in VLAN 1, with 1 & 2 in VLAN 2.

No DHCP traffic from VLAN 1 should enter VLAN 2.
VLAN 2 should be able to access NTFS shares on VLAN 1
VLAN 1 should not be able to access VLAN 2.
There will be VPN traffic on VLAN 2, but not VLAN 1.

I'm not familiar with how to assign ports for VLANs, so would appreciate an explanation of what Trunk, General and Access means and what the router means where it specifies "acceptable ingress type". I vaguely understand tagging frames from the OSI model, but if there is some special significance for VLANs, please explain that also. Finally, although I could probably figure out from that point how to configure it, a quick definition of how I should configure my ports would be really helpful.

Thanks for reading this question!
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.


IEEE 802.1.Q explains VLANS

A Trunk port is a port that carries data from multiple VLANS Such if you needed more that 4 ports in the future and want to add a switch that supports vlans and some ports on the new switch to be on vlan1 and vlan2 then you would plug the new switch into a trunk port to access both vlans.

Access port will be a port that is on a single vlan that is what you want to choose for your ports.  When configuring your ports as Access ports you shouldnt be able to choose tagged vs untagged. In a sense Untagged ports are Access ports and tagged are Trunk ports (the tags designate what vlan the traffic is for on a trunk port)

Just set all of your ports up as access ports since you are trying to make each port physically part of a single vlan.

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
AdoBeeboAuthor Commented:
I set all of the ports to access, divided across 2 VLANs, but hit a problem when some wireless DHCP clients didn't receive an IP address. I've removed the VLANs for now, and will revisit the configuration in a few days, then post back.

AdoBeeboAuthor Commented:
Cheers, good clear description
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today

From novice to tech pro — start learning today.