Solved

Switch with vlan how to separate accounting from non accounting

Posted on 2011-03-25
3
366 Views
Last Modified: 2012-05-11
I am new to vlans but my smartswitch supports vlans.  I have a few pcs that are accounting related.  I want the accounting users to be able to connect with each other and the rest of the network but I want all other users not to be able to connect to accounting pcs.  The reason I need the accounting users to be able to connect to the other users because I have shared network printers that they use but i don't want the non accounting users to connect to accounting. The non accounting users need to be able to connect to the shared printers as well.
0
Comment
Question by:FASTECHS
3 Comments
 
LVL 35

Assisted Solution

by:Ernie Beek
Ernie Beek earned 167 total points
ID: 35213549
You could create three vlans: accounting, non-accounting and printers. That way you can make sure that both can reach the printers but not each other.
0
 
LVL 2

Assisted Solution

by:leetpriest
leetpriest earned 167 total points
ID: 35215150
Are the printers shared off of a server? Or are they shared from the non-accounting users?
0
 
LVL 3

Accepted Solution

by:
FWeston earned 166 total points
ID: 35216620
In order to do this, your switch will need to be a layer 3 switch (capable of routing between VLANs), or else you will need some other device such as a router or firewall that does the routing for you.

Essentially what you would do is create an accounting vlan (vlan 50) and a non-accounting vlan (vlan 100).  On the switch, assign IP addresses to each VLAN.  To keep it simple, lets say vlan 50 uses 192.168.50.124 and vlan 100 is 192.168.100.1/24.  Now enable IP routing on the switch.

At this point, PCs on VLAN 50 should be able to talk to PCs on VLAN 100 and vice versa.  Now, add access lists to deny the traffic you don't want to allow.  You'll have to look at the documentation for your switch to find the syntax for configuring ACLs.

Keep in mind that while a firewall will do stateful inspection, most switches do not.

What this means is if you add an ACL that denies traffic from vlan 100 to vlan 50, that will allow traffic from vlan 50 to get to vlan 100, but it won't let it get back.  So if you pinged a PC on vlan 100 from vlan 50, the ping traffic would reach it's destination, but the switch would block the reply traffic.

If you use a firewall, most of them are smart enough to dynamically inspect the traffic and permit the replys even though there is an ACL that would block that traffic by default.
0

Featured Post

Free Tool: Port Scanner

Check which ports are open to the outside world. Helps make sure that your firewall rules are working as intended.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Cisco Licensing for Wi Fi 4 53
Alot of sessions on a PC is generated 3 86
HP 2530 switch and routing 4 64
Windows routing: allowing Internet and L2TP VPN simultaneously. 2 52
Let’s list some of the technologies that enable smooth teleworking. 
Even if you have implemented a Mobile Device Management solution company wide, it is a good idea to make sure you are taking into account all of the major risks to your electronic protected health information (ePHI).
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…

726 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question