Solved

Setting up VLAN to place access point on separate network

Posted on 2009-04-12
8
677 Views
Last Modified: 2012-05-06
My current office LAN is setup as such:

Internet -->  Router --> Switch -->  Mulitple Computers & Access Point

I would like to put the Access Point on it own VLAN however I'm new to setting up VLAN's and I'm not sure of the terminology.  

Procurve 1800 Switch setup:

Port 1:  Router
Port 2:  PC1
Port 3:  PC2
Port 4:  PC3
Port 5:  PRINTER
Port 6:  Unused
Port 7:  Unused
Port 8:  Access Point

I would like to setup ALL PC's + Printer (Ports 2-5) and Router (port 1) on VLAN1 & the Access Point (Port 8) and Router (Port 1) on VLAN2.

I have created VLAN2 and checked boxs for ports 1 & 2.  

The part I dont understand is setting the Port Config Options:   The config menu allows me to make each port VLAN aware,  Ingress Filtering, and Tagged and Untagged  &  Allows to the set either PVID 1 or 2.

My goal is to have both VLAN1 and VLAN2 access the internet both not each other.   I want to isolate the access point so that the HOTSPOT doesn't have access to OFFICE computeres.  
0
Comment
Question by:drews77
  • 5
  • 3
8 Comments
 
LVL 3

Accepted Solution

by:
iserko earned 125 total points
ID: 24126281
The router will need to be VLAN capable (means that if you send it a VLAN trunk it will know how to divide them) or it should have 2 LAN ports or more and be able assign an IP to each interface, if you want to have internet on both VLANs.

Besides the router setup, you need to set the switch up as follows:
 * Ports 2-7 should be in VLAN1 untagged and not in any other VLAN
 * Port 8 should be in VLAN2 untagged and not in any other VLAN
 * Port 1 should be in both VLAN1 and VLAN2 and it should be tagged in both (only tagged, do not select it to be untagged). This will only work if your router can handle VLAN trunks

VLAN trunk is where you can send multiple VLAN connections over one single physical connection.

Hope this helps
0
 

Author Comment

by:drews77
ID: 24126290
I noticed the switch has compatiblity to create trunks.  Do I need to use this feature or are the VLANs automatically trunks to router.  I'm certain my router isn't VLAN capable.  Would you be able to suggest a router to use for this setup?  
0
 
LVL 3

Expert Comment

by:iserko
ID: 24126331
OK one thing here.

A VLAN trunk is named differently by HP (Procurve is their brand).
So on their switches VLANs are tagged and untagged. If a port is set as tagged for many VLANs, that makes it a VLAN trunk.

A HP Trunk is where you combine 2 or more physical connections into one logical connection. We won't be using that here.

So if you follow my instructions regarding tagged and untagged ports, you should be fine ... when you get an appropriate router.

The router I would suggest is a Cisco PIX/ASA (the cheapest one should do the trick)... however I must warn you that its set-up is for mostly advanced users (if you set it up via the console), it has a web server, but I've never used it.

I guess there are other routers around that do the same for less. I use a Linux router (old machine with 3 network interface cards) at home and my company.

You could also buy a Layer 3 switch ... that's a switch that can also route your packets from one VLAN to the other. But its a bit more expensive and is probably out of the question, since you already have a switch.
0
 

Author Comment

by:drews77
ID: 24126896
I see, a good alternate would be a L3 switch with my current router.
I'm guessing that the switch would be the gateway for the PC's in that case.  

If I keep the L2 switch and update the router:
Do you have any suggestion on what to do with the VLAN aware checkbox and the  Ingress Filtering checkbox?
0
How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

 
LVL 3

Expert Comment

by:iserko
ID: 24126921
VLAN aware checkbox should be enabled only on port 1.

Ingress filtering is for filtering input packets I guess, unless you want to set up network access filters for certain computers I don't think you will need that. For example you wouldn't want PC3 communicating with PC2 so you would enable the ingress filtering (there must be a place to specify the rules though).
0
 
LVL 3

Expert Comment

by:iserko
ID: 24126925
And to answer your first question, yes and no ... the switch would have to be the gateway only on the VLAN that did not have the router.
0
 

Author Comment

by:drews77
ID: 24126993
I supspect the most professional, efficient and modern method of configuring a VLAN would be to use a L3 switch?
0
 
LVL 3

Expert Comment

by:iserko
ID: 24127130
Not really. Having a better router is the most efficient solution.
An L3 switch is only used if you really really need it (think ISP or very advanced LAN or you have too much money), which in your case you do not.

As for router, try something along the lines of:
http://shop.a-enterprise.ch/product_info.php?currency=EUR&cPath=31&products_id=29&language=en
or
http://www.applianceshop.eu/index.php/appliances/firewalls/m0n0wall-small.html

I've worked with m0n0wall before, its simple and lots of features. Not really enterprise worthy, but for up to 30 users it should suit you just fine.

Hope it helps
0

Featured Post

Enabling OSINT in Activity Based Intelligence

Activity based intelligence (ABI) requires access to all available sources of data. Recorded Future allows analysts to observe structured data on the open, deep, and dark web.

Join & Write a Comment

Data center, now-a-days, is referred as the home of all the advanced technologies. In-fact, most of the businesses are now establishing their entire organizational structure around the IT capabilities.
PRTG Network Monitor lets you monitor your bandwidth usage, so you know who is using up your bandwidth, and what they're using it for.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…

760 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now