Link to home
Start Free TrialLog in
Avatar of GCITech

asked on

any advantage to separating WAN into vlans before going to routers?

What is recommended way to deal with multiple WAN addresses (only 5) that ISP provides through one connection? I have in the past put the cable from ISP into small switch, then fed individual networks, or devices that use a WAN, from the separate ports on  the switch. I have seen networks, where everything is plugged into a large switch, and WAN IPs are available anywhere on the network you plug in, if you know the addresses. My main question is, if I am using the small switch to distribute the WAN to individual routers / devices, is there any advantage to set up Vlans, on the small switch so that port from isp is vlan'ed  (probably not a word) to each of the other ports individually, to separate WAN traffic from each other?

Avatar of Soulja
Flag of United States of America image

What type of switch are you using? My assumption is that the ip's you were given are part of the same subnet and use the same default gateway to your ISP, so separating them into separate vlan won't be possible, unless you use private vlans. That is why I asked the switch type and if it has that feature. Essentially private vlans will allow you to keep them in the same primary vlan, then separate into isolated secondary vlans. They will still be able to use the same default gateway which would reside on a promiscuous port. 
Alternatively additional wan ip's can be used to NAT to internal devices.
Avatar of Craig Beck
Craig Beck
Flag of United Kingdom of Great Britain and Northern Ireland image

Link to home
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of GCITech


Thanks for the input. Our circuits are at the end of ethernet, so we are able to assign different ip to different devices with their own IP. It is also true that they are all in the same subnet, with the same gateway. So it appears after you pointing that out to me, that there is no advantage to trying to separate them in the small switch, as they are all going to the same gateway. The switch is an inexpensive TPlink.
I like having all my devices with a wan address plugging into a switch that is "WAN ips only", just because it is more logical to me. Is a network as efficient, if the wan IPs are mixed in with a switch that is in one of the LANs?
(Configured with no loops)