Link to home
Create AccountLog in
Networking

Networking

--

Questions

--

Followers

Top Experts

Avatar of activematx
activematx🇺🇸

Cisco SF-200 Smart Switch - How to make a VLAN?
Hi Experts,

This is my first time using a entry level Cisco Switch.  This is a SF 200-24 model.  I have attached a screenshot of the WebGUI and the administrative guide.  I would appreciate someone to help me in setting up a VLAN.  I could even give someone VNC access if they need it... or TeamViewer, but would prefer working through here.

Here is how I want it setup (pretty simple).

All of the ports on the switch (minus one) will be on one VLAN, and then one single port will be on another VLAN.  

I have the internet (WAN) coming in from port 1
I would like a specific port to be on its own network (VLAN).
All VLANs will share a single internet connection from our ISP.  This is from a cable modem, then to a Linksys RV082 VPN-Router, going into the switches port 1

I have a situation where I have another organization who wants to use our internet.  I don't want them to be able to access our network shares, etc.  I want them on their own subnet too (if possible).

 User generated image

Zero AI Policy

We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.


Avatar of activematxactivematx🇺🇸

ASKER

I have also attached the administrative guide for this switch. OL-22849-01.pdf

Avatar of jeroentbjeroentb🇳🇱

Under VLAN management all settings are found.
Create 3 VLAN's, one for WAN, one for local and one for the other company.
Assign the VLAN's to ports, set the ports as access ports.

Avatar of activematxactivematx🇺🇸

ASKER

Hi Jeroentb,

Thanks for chiming in.  I created the VLANs.  I have attached screenshots.  Not sure where to go from here.   User generated image User generated image User generated image

Reward 1Reward 2Reward 3Reward 4Reward 5Reward 6

EARN REWARDS FOR ASKING, ANSWERING, AND MORE.

Earn free swag for participating on the platform.


Avatar of jeroentbjeroentb🇳🇱

Ok ,in the interface page set each port to access instead of trunk, set pvid to the native vlan id for that port.
At the port to vlan page e23 is turned off with the current settings.

Avatar of activematxactivematx🇺🇸

ASKER

I changed them to access.  I am unable to change PVID when changing them to access (the ADMINISTRATIVE PVID gets greyed out when I choose Access)

Screenshots Attached.

 User generated image User generated image User generated image

Avatar of jeroentbjeroentb🇳🇱

Ok now i see where you go wrong ;)
I assume you manage via the vlan 1 interface, however put all ports except the one you are connected to to forbidden.
When you select a vlanid filter set the ports to untagged where you want that vlan to live.
Set the ports where you don't want that vlan to forbidden.
Can you send a screenshot from the vlan to port ui ?

Free T-shirt

Get a FREE t-shirt when you ask your first question.

We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.


Avatar of activematxactivematx🇺🇸

ASKER

User generated image

Avatar of jeroentbjeroentb🇳🇱

What options do you get when you click on an interface listbox ?

Avatar of jeroentbjeroentb🇳🇱

- Forbidden—The interface is not allowed to join the VLAN. When a port is
not a member of any other VLAN, enabling this option on the port makes
the port part of internal VLAN 4095 (a reserved VID).
- Excluded—The interface is currently not a member of the VLAN. This is
the default for all the ports and LAGs when the VLAN is newly created.
- Tagged—Select whether the port is tagged. This is not relevant for
Access ports.
- Untagged—Select whether port is untagged. This is not relevant for
Access ports.
VLAN Management
Defining VLAN Membership
Cisco Small Business 200 1.1 Series Smart Switch Administration Guide 168
12
- PVID—Port PVID is set to this VLAN. If the interface is in access mode or
trunk mode, the switch automatically makes the interface an untagged
member of the VLAN. If the interface is in general mode, you must
manually configure VLAN membership.


In short, if you want a port to be in a vlan set it to untagged, if not set it to excluded. Set ports in access mode.

Reward 1Reward 2Reward 3Reward 4Reward 5Reward 6

EARN REWARDS FOR ASKING, ANSWERING, AND MORE.

Earn free swag for participating on the platform.


Avatar of jeroentbjeroentb🇳🇱

Oh sorry, set pvid on the port to it's vlan ;)

Avatar of jeroentbjeroentb🇳🇱

So optionbox to untagged and pvid on the port to vlan page, if you don't want it in the vlan set it to excluded and pvid not selected.

Avatar of activematxactivematx🇺🇸

ASKER

What options do you get when you click on an interface listbox ?

I get no other options aside from 1UP.  However, clicking the join VLAN button brings up this window:



    User generated image

Free T-shirt

Get a FREE t-shirt when you ask your first question.

We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.


Avatar of jeroentbjeroentb🇳🇱

Ok, set to untagged and check pvid, than select the vlan and click on the right arrow when you do that.
You want to VNC ?

Avatar of activematxactivematx🇺🇸

ASKER

VNC:67.53.203.78

password:  experts

login:  m
password:  spahgetti

Avatar of jeroentbjeroentb🇳🇱

ok, my vnc viewer chrashes and i need to go to work, so i hope you can move on now ?
Remember the following:
-create vlan's (id 2,3 and 4)
-port to vlan page:
 -choose vlan 2
 -exclude ports that must not be member
 -untag ports and check pvid for the ports that you want as member
 -apply changes
 -choose vlan 3
 -repeat former steps excluding and untagging ports
 -choose vlan 4
 - again repeat former steps.

Reward 1Reward 2Reward 3Reward 4Reward 5Reward 6

EARN REWARDS FOR ASKING, ANSWERING, AND MORE.

Earn free swag for participating on the platform.


Avatar of activematxactivematx🇺🇸

ASKER

Thanks Jeroentb.  

I have to leave as well.  I will try this tomorrow morning.  If it works, You get A+ and all points.

Otherwise, I'll post a follow up.  thanks so much!  VNC is now off

Avatar of activematxactivematx🇺🇸

ASKER

I am about to try the suggestions posted from earlier.  My question though is, how does the IP Addressing work for these VLANS?

Will they all use the same IP Schema?  Or can I assign different Schemes for each VLAN?

Avatar of jeroentbjeroentb🇳🇱

If you want a router to be able to route/firewall between the segments you'll have to asign subnets to them, this is not done in the switch though you can assign an ip address to a vlan interface for management purpouse.

Free T-shirt

Get a FREE t-shirt when you ask your first question.

We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.


Avatar of activematxactivematx🇺🇸

ASKER

After further investigation it is not possible to create a VLAN with this switch.  I need to have a router that supports 802.1q tagging so that I can separate the networks.

ASKER CERTIFIED SOLUTION
Avatar of jeroentbjeroentb🇳🇱

Link to home
membership
Log in or create a free account to see answer.
Signing up is free and takes 30 seconds. No credit card required.
Create Account

Avatar of activematxactivematx🇺🇸

ASKER

Informing of not being able to setup two networks from the beginning would have been awesome.
Networking

Networking

--

Questions

--

Followers

Top Experts

Networking is the process of connecting computing devices, peripherals and terminals together through a system that uses wiring, cabling or radio waves that enable their users to communicate, share information and interact over distances. Often associated are issues regarding operating systems, hardware and equipment, cloud and virtual networking, protocols, architecture, storage and management.