Solved

SG300 VLAN Configuration

Posted on 2016-10-18
10
39 Views
Last Modified: 2016-11-23
I have a home network and I'm planning to install IP cameras and a Synology Surveillance station.  I created a VLAN to isolate the traffic from the IP cameras from the rest of my network. The SG-300 is configured for L3. Here’s my setup:

 Network Configuration
 The Static routing table in the SG-300 shows:

0.0.0.0            0      Default    192.168.1.1   Default                              2    1   VLAN1
192.168.1.0  24     Local                                  Directly Connected                  VLAN1
192.168.2.0 24      Local                                  Directly Connected                  VLAN2  

On the SG300, port 10 is configured for VLAN1, untagged, trunk. Port 1 and 2 are configured for VLAN2, untagged, access.

The traffic on VLAN2 appears to be isolated from VLAN1 and I can SSH into the Synology Surveillance box. I can ping the Synology box from the 192.168.1.0/24 subnet, however, if I SSH into the Synology box, I can’t ping out to the internet.

Any help would be appreciated.

Thanks,
Alan
0
Comment
Question by:alanandcorin
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 3
  • 2
10 Comments
 
LVL 6

Expert Comment

by:Niten Kumar
ID: 41849436
Check the NAT settings on the Netgear  router.  Is it NATing for 192.168.2.0 network.
0
 

Author Comment

by:alanandcorin
ID: 41850505
Nitenkumar, how could I check to know if it's NATing for the 192.168.2.0 network?  I can run linux commands from the Synology box on 192.168.2.4.  

Are the home Netgear routers capable or NATing to two networks? Is this possible with the standard firmware? Do I need to upgrade to DD-WRT or even another type of WiFi router?

Thanks for your help.
Alan
0
 

Author Comment

by:alanandcorin
ID: 41850853
Shouldn't it be possible for the SG300 to correctly route from VLAN2 to the internet with ACL rules?

Thanks,
Alan
0
What, When and Where - Security Threats from Q1

Join Corey Nachreiner, CTO, and Marc Laliberte, Information Security Threat Analyst, on July 26th as they explore their key findings from the first quarter of 2017.

 
LVL 6

Expert Comment

by:Niten Kumar
ID: 41850998
Are you a able to login to the console of the Netgear router?
0
 

Author Comment

by:alanandcorin
ID: 41851123
Sorry, there's no SSH nor Telenet access to the stock netgear firmware.
0
 
LVL 6

Expert Comment

by:Niten Kumar
ID: 41851165
How about web access?
0
 

Author Comment

by:alanandcorin
ID: 41851227
The router has remote management access, but all you'll get is the same GUI screens that I have access to.
0
 

Author Comment

by:alanandcorin
ID: 41851425
I updated my router to DD-WRT, so I can SSH and run commands from the console. What do you suggest?
0
 
LVL 29

Accepted Solution

by:
masnrock earned 500 total points (awarded by participants)
ID: 41852887
You should even be able to use the web interface of DD-WRT. Basically, you want to have 2 VLANs, each tied to whichever ports you'd like them set up to. That will allow you to have 2 physical connections to the switch, where you can configure the appropriate VLANs. The port that goes to the living room will obviously be configured to VLAN2, along with whichever ports will be going to the cameras.
0
 
LVL 29

Expert Comment

by:masnrock
ID: 41898861
Question answered
0

Featured Post

Free Backup Tool for VMware and Hyper-V

Restore full virtual machine or individual guest files from 19 common file systems directly from the backup file. Schedule VM backups with PowerShell scripts. Set desired time, lean back and let the script to notify you via email upon completion.  

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

How to set-up an On Demand, IPSec, Site to SIte, VPN from a Draytek Vigor Router to a Cyberoam UTM Appliance. A concise guide to the settings required on both devices
WARNING:   If you follow the instructions here, you will wipe out your VTP and VLAN configurations.  Make sure you have backed up your switch!!! I recently had some issues with a few low-end Cisco routers (RV325) and I opened a case with Cisco TA…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Suggested Courses

617 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question