What's new

Vlan configuration - Netgear GS108E

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

TomT

Regular Contributor
Hi
Currently I have a flat network all in the 192.168.8.x range.
The network is a mix of PC's, MAC's, Linux boxes, Youview x2, NAS and various other devices.

Some are home use others are for my office as I work from home. I currently use IP Tables rules to restrict access from some office devices to my home devices.

I'm thinking of using VLANs to help make this more secure and stop broadcasts between the devices.

I have an Asus RC-68U Router running merlin firmware which I know can do Vlans but I'm not planning on enabling it on there. I have a netgear FS116p 16 port (8 POE) 10/100 switch and a Netgear GS108E 10/100/1000 VLAN switch. Some of the other network devices have switches built in that are VLAN capable but I'm not planning on using the VLAN features on there, they are currently configured as a normal switch.

This is what I'm planning to do.

VLAN 1 - INTERNET Access
VLAN 5 - NAS VLAN
VLAN 10 - Home VLAN
VLAN 15 - Home Plugs VLAN
VLAN 20 - Office VLAN

GS108E
PORT 1 -> Router VLAN 1 accessible to all devices/ports (VLAN1)
PORT 2 -> NAS not accessible internally only via the Internet - used by my son to store UNI work (VLAN5)
PORT 3 -> HOME VLAN (VLAN10)
PORT 4 -> HOME VLAN (VLAN10)
PORT 5 -> Home Plugs - no access is needed to any internal devices, they need internet access (VLAN15)
PORT 6 -> OFFICE VLAN (VLAN20) -> 16 Port FS116P Switch to run the office hardware from.
PORT 7 -> OFFICE VLAN (VLAN20)
PORT 8 -> Spare for testing.

Using this link, I think I can set this up.. (But may need some help) :
http://www.smallnetbuilder.com/lanw...how-to-segment-a-small-lan-using-tagged-vlans

Any issues with the above setup ? should it work as I expect ? ie: all ports can access the internet, but the office and home are separated. Nothing internally can get to the NAS or Home Plugs.

I have a couple of IP Phones that have 2 LAN ports. If I plug the phone into a POE port on the FS116P on VLAN 20 - will it be able to talk to VLAN 10 ? The phone does support VLAN tagging so I can set it's local VLAN tag and Second VLAN tag.

If I plug my main PC and printer into the spare ports on the Asus RC-68U connected to VLAN1 will they have access to all devices on the network. (home, office, nas and home plugs) ? I'm hoping so..

Finally my son connects to his NAS via a VPN to the router. Once he connected to the router, will he be able to access his NAS ?

Thanks
 
A couple of things I have heard is the ASUS routers only support VLANs on WAN port side not the LAN port side. You did not mention wireless. Sounds like you will not be able to assign SSIDs to VLANs using a ASUS router. And of course there is the routing between VLANs. You will need some way to route between VLANs. A layer 2 switch cannot route layer 3 traffic and since ASUS does not support VLAN there will be no routing for a layer 2 switch. A layer 3 switch solve this but wireless may still be an issue. Correct me if I am wrong as I have never used an ASUS router.
 
What you can do using the network switch is to have multiple VLANs but have 2 cables connecting to the router in which they can be different networks.
 
Couple of point for clarification.

The FS116P will be connected to
PORT 6 -> OFFICE VLAN (VLAN20) -> 16 Port FS116P Switch to run the office hardware from.
PORT 7 -> OFFICE VLAN (VLAN20)

Would any device in that 16 port switch be on VLAN 20 ?
The router does support VLAN's I'm not sure if the wireless can be included, but I will check in the Merlin thread as it's his firmware I'm using.

Thanks
 
Looking at the Merlin thread it does look like the RC-68U will allow me to do VLANS
The VLAN.jpg shows how I've set the GS108E up.. does that look right ?

If I plug a device into port 03 and another into 06 then they can't talk to each other, but they can get out to the Internet.
If I connect the router to port 01 and I have a PC in a LAN port on the router, should that PC be able to access VLANs 10 & 20 (ports 03 & 06) as it can't.

I know the Asus router has VLANS setup for its LAN ports and they are all in VLAN 1.

Any idea how I get this to work.. once that sorted, I can look at the wifi and vpn.

Thanks :)
 

Attachments

  • VLAN.jpg
    VLAN.jpg
    129.5 KB · Views: 664

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top