VLAN Set-up

How do you set-up a VLAN?

I have never done this before and everything I read leads me down the wrong path.
Simply, I need a set of ports (12 ports total) to only allow traffic for 10.0.5.x leaving the rest of the switch to accept traffic for 172.20.1.x. Right now the entire switch will see traffic for both.

The test environment is using an HP ProCurve 2910al 24G Ethernet Switch.

Robert MohrAsked:
Who is Participating?
Tag or untag is about being able to communicate via a switch-port to some other device, configured same manner (or not if not configured same way).
You could carry more vlans over one link .
-If you wanted that, then you would differentiate the packets belonging to these vlans by tagging them (eventually untag one vlan). Then there would be no mix of packets belonging to the different vlans, so long the tagging and untag in both ends of the link was made the same way.
It is a quite common to have 2 devices communicate more vlans over one link, and doing so makes spanning tree easier to deal with.
With one link you would have to deal with subinterfaces on the router however.

If the networks can ping each other, then there must exist a routing process making this possible.
Traceroute (in windows : tracert) could show the way the packets travel.
AkinsdNetwork AdministratorCommented:
I'm trying to figure your request and match it up with features on the switch but I'll explain some things first.
- You can allow or block certain vlans from traversing a switch with "Allowed vlan" configuration on the trunk port connection to other switches.
- You can configure access-lists to block traffic from one vlan to another or  use private vlans to isolate one vlan from another

It seems to me that the access-list option is what you're asking for but I also think you're referring to port assignment. If port assignment, lets assume 10.0.5 network is vlan 10 and 172.20.1 network is vlan 172
Let's also assume there are 48 ports and the 1st 12 ports are to be reserved for vlan 10 and port 48 is your trunk / uplink

You will assign ports 1-12 to vlan 10 and ports 11 to 47 to vlan 172.

By "accepting", did you mean allowing the traffic to come through or devices connected to those ports should communicate on that vlan.
Robert MohrAuthor Commented:
My ignorance is the problem. Sorry. I think we want to isolate.

Here's the scenario. For PCI compliance we have to make sure our wireless traffic (10.0.1.x)  is completely segregated from our standard traffic (172.20.1.x).

Our main router has one interface assigned to 172.20.1.x traffic and another interface assigned to 10.0.1.x traffic.
From router we plug in both interface Ethernet cables from two interfaces into HP switch (taking up two ports). We want ports 1-12 to only allow for 172.20.1.x traffic and the remaining ports to allow for 10.0.1.x traffic.  

Based on this I think we want to ISOLATE traffic from one vlan to another on the switch since the vlans are set-up already on the isolated ports on the router.
How do you know if your security is working?

Protecting your business doesn’t have to mean sifting through endless alerts and notifications. With WatchGuard Total Security Suite, you can feel confident that your business is secure, meaning you can get back to the things that have been sitting on your to-do list.

AkinsdNetwork AdministratorCommented:
There are a few ways that this can be achieved

Option 1. Create access-list that deny traffic between the vlans and apply it either to the vlan interface or the trunk port

Option 2. Make the trunk port a promiscuous port, ports 1-12 isolated ports and the rest community ports

Option 3. Create policy map or vlan map that prevents intercommunication between the 2 vlans
You are to use a Procurve sw. like 2910al or some Cisco product fx.?    -I assume: 2910al.
Is the switch in question going to do routing?  -I assume: no ip routing should take place here

If you don't assign an IP to wireless-vlan on the switch, as far as I can see the 2 vlans are separated with ports 1-12 untagged in the wireless-vlan.
With 2 uplinks to main router , the spanning tree protocol could pull your leg.

My guess is , your router rather than the switch is responsible for "Right now the entire switch will see traffic for both."
You could provide output from "show running" for the experts to have a look at.
Robert MohrAuthor Commented:
So if I have two upload ports, one that is dedicated to 10.0.1.x and the second one that is 172.20.1.x and I don't want the two to be able to ping each other do I simply tag one group and untag the other? Spanning Tree is turned on.
Robert MohrAuthor Commented:
This is exactly what we ended up doing. Thank-you for your help!
glad to help
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.