[Last Call] Learn about multicloud storage options and how to improve your company's cloud strategy. Register Now

x
?
Solved

Setting up VLAN to place access point on separate network

Posted on 2009-04-12
8
Medium Priority
?
690 Views
Last Modified: 2012-05-06
My current office LAN is setup as such:

Internet -->  Router --> Switch -->  Mulitple Computers & Access Point

I would like to put the Access Point on it own VLAN however I'm new to setting up VLAN's and I'm not sure of the terminology.  

Procurve 1800 Switch setup:

Port 1:  Router
Port 2:  PC1
Port 3:  PC2
Port 4:  PC3
Port 5:  PRINTER
Port 6:  Unused
Port 7:  Unused
Port 8:  Access Point

I would like to setup ALL PC's + Printer (Ports 2-5) and Router (port 1) on VLAN1 & the Access Point (Port 8) and Router (Port 1) on VLAN2.

I have created VLAN2 and checked boxs for ports 1 & 2.  

The part I dont understand is setting the Port Config Options:   The config menu allows me to make each port VLAN aware,  Ingress Filtering, and Tagged and Untagged  &  Allows to the set either PVID 1 or 2.

My goal is to have both VLAN1 and VLAN2 access the internet both not each other.   I want to isolate the access point so that the HOTSPOT doesn't have access to OFFICE computeres.  
0
Comment
Question by:drews77
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 3
8 Comments
 
LVL 3

Accepted Solution

by:
iserko earned 500 total points
ID: 24126281
The router will need to be VLAN capable (means that if you send it a VLAN trunk it will know how to divide them) or it should have 2 LAN ports or more and be able assign an IP to each interface, if you want to have internet on both VLANs.

Besides the router setup, you need to set the switch up as follows:
 * Ports 2-7 should be in VLAN1 untagged and not in any other VLAN
 * Port 8 should be in VLAN2 untagged and not in any other VLAN
 * Port 1 should be in both VLAN1 and VLAN2 and it should be tagged in both (only tagged, do not select it to be untagged). This will only work if your router can handle VLAN trunks

VLAN trunk is where you can send multiple VLAN connections over one single physical connection.

Hope this helps
0
 

Author Comment

by:drews77
ID: 24126290
I noticed the switch has compatiblity to create trunks.  Do I need to use this feature or are the VLANs automatically trunks to router.  I'm certain my router isn't VLAN capable.  Would you be able to suggest a router to use for this setup?  
0
 
LVL 3

Expert Comment

by:iserko
ID: 24126331
OK one thing here.

A VLAN trunk is named differently by HP (Procurve is their brand).
So on their switches VLANs are tagged and untagged. If a port is set as tagged for many VLANs, that makes it a VLAN trunk.

A HP Trunk is where you combine 2 or more physical connections into one logical connection. We won't be using that here.

So if you follow my instructions regarding tagged and untagged ports, you should be fine ... when you get an appropriate router.

The router I would suggest is a Cisco PIX/ASA (the cheapest one should do the trick)... however I must warn you that its set-up is for mostly advanced users (if you set it up via the console), it has a web server, but I've never used it.

I guess there are other routers around that do the same for less. I use a Linux router (old machine with 3 network interface cards) at home and my company.

You could also buy a Layer 3 switch ... that's a switch that can also route your packets from one VLAN to the other. But its a bit more expensive and is probably out of the question, since you already have a switch.
0
Looking for a new Web Host?

Lunarpages' assortment of hosting products and solutions ensure a perfect fit for anyone looking to get their vision or products to market. Our award winning customer support and 30-day money back guarantee show the pride we take in being the industry's premier MSP.

 

Author Comment

by:drews77
ID: 24126896
I see, a good alternate would be a L3 switch with my current router.
I'm guessing that the switch would be the gateway for the PC's in that case.  

If I keep the L2 switch and update the router:
Do you have any suggestion on what to do with the VLAN aware checkbox and the  Ingress Filtering checkbox?
0
 
LVL 3

Expert Comment

by:iserko
ID: 24126921
VLAN aware checkbox should be enabled only on port 1.

Ingress filtering is for filtering input packets I guess, unless you want to set up network access filters for certain computers I don't think you will need that. For example you wouldn't want PC3 communicating with PC2 so you would enable the ingress filtering (there must be a place to specify the rules though).
0
 
LVL 3

Expert Comment

by:iserko
ID: 24126925
And to answer your first question, yes and no ... the switch would have to be the gateway only on the VLAN that did not have the router.
0
 

Author Comment

by:drews77
ID: 24126993
I supspect the most professional, efficient and modern method of configuring a VLAN would be to use a L3 switch?
0
 
LVL 3

Expert Comment

by:iserko
ID: 24127130
Not really. Having a better router is the most efficient solution.
An L3 switch is only used if you really really need it (think ISP or very advanced LAN or you have too much money), which in your case you do not.

As for router, try something along the lines of:
http://shop.a-enterprise.ch/product_info.php?currency=EUR&cPath=31&products_id=29&language=en
or
http://www.applianceshop.eu/index.php/appliances/firewalls/m0n0wall-small.html

I've worked with m0n0wall before, its simple and lots of features. Not really enterprise worthy, but for up to 30 users it should suit you just fine.

Hope it helps
0

Featured Post

Tech or Treat!

Submit an article about your scariest tech experience—and the solution—and you’ll be automatically entered to win one of 4 fantastic tech gadgets.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I had an issue with InstallShield not being able to use Computer Browser service on Windows Server 2012. Here is the solution I found.
This month, Experts Exchange’s free Course of the Month is focused on CompTIA IT Fundamentals.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
NetCrunch network monitor is a highly extensive platform for network monitoring and alert generation. In this video you'll see a live demo of NetCrunch with most notable features explained in a walk-through manner. You'll also get to know the philos…

650 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question