Advice needed on configuring a router and VLANs

Posted on 2008-11-14
Last Modified: 2012-05-05
This is more about VLANs than the router, but I include the model information for completeness' sake. It is a WRVS4400N Linksys VPN Security Router - it has a wireless antenna and 4 physical ports, and supports VLANs.

The router allows for the creation of VLANs. My aim is to create VLAN 1 using two physical ports and the wireless antenna, while having the other two physical ports turned over to VLAN 2.

The router should provide DHCP for VLAN 1. There is a DHCP server on VLAN 2 so the router will not need to provide DHCP. This I have configured and believe to be correctly working.

VLAN 2 will be little more than a gateway between a server and modem on the other side of the router from the server e.g. Modem > Router > Server > Server's LAN.

To the nitty-grity - there is a JPG attached of the possible configurations for the ports from the router. For argument's sake, I'd like Ports 3, 4 and wireless in VLAN 1, with 1 & 2 in VLAN 2.

No DHCP traffic from VLAN 1 should enter VLAN 2.
VLAN 2 should be able to access NTFS shares on VLAN 1
VLAN 1 should not be able to access VLAN 2.
There will be VPN traffic on VLAN 2, but not VLAN 1.

I'm not familiar with how to assign ports for VLANs, so would appreciate an explanation of what Trunk, General and Access means and what the router means where it specifies "acceptable ingress type". I vaguely understand tagging frames from the OSI model, but if there is some special significance for VLANs, please explain that also. Finally, although I could probably figure out from that point how to configure it, a quick definition of how I should configure my ports would be really helpful.

Thanks for reading this question!
Question by:AdoBeebo
    LVL 2

    Accepted Solution


    IEEE 802.1.Q explains VLANS

    A Trunk port is a port that carries data from multiple VLANS Such if you needed more that 4 ports in the future and want to add a switch that supports vlans and some ports on the new switch to be on vlan1 and vlan2 then you would plug the new switch into a trunk port to access both vlans.

    Access port will be a port that is on a single vlan that is what you want to choose for your ports.  When configuring your ports as Access ports you shouldnt be able to choose tagged vs untagged. In a sense Untagged ports are Access ports and tagged are Trunk ports (the tags designate what vlan the traffic is for on a trunk port)

    Just set all of your ports up as access ports since you are trying to make each port physically part of a single vlan.
    LVL 3

    Author Comment

    I set all of the ports to access, divided across 2 VLANs, but hit a problem when some wireless DHCP clients didn't receive an IP address. I've removed the VLANs for now, and will revisit the configuration in a few days, then post back.

    LVL 3

    Author Closing Comment

    Cheers, good clear description

    Write Comment

    Please enter a first name

    Please enter a last name

    We will never share this with anyone.

    Featured Post

    Looking for New Ways to Advertise?

    Engage with tech pros in our community with native advertising, as a Vendor Expert, and more.

    Problem Description:   Couple of months ago we upgraded the ADSL line at our branch office from Home to Business line. The purpose of transforming the service to have static public IP’s. We were in need for public IP’s to publish our web resour…
    In the world of WAN, QoS is a pretty important topic for most, if not all, networks. Some WAN technologies have QoS mechanisms built in, but others, such as some L2 WAN's, don't have QoS control in the provider cloud.
    After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
    After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

    737 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    18 Experts available now in Live!

    Get 1:1 Help Now