2.6. Ensuring only known devices can use a network
Switching
→
VLAN
→
Advnaced
→
VLAN Membership
was used to show the
VLAN Membership
screen. The value 12 was typed into the
VLAN ID
field and
port 23 was added as an untagged member before the
APPLY
button was clicked.
wireless network
NAS
VLAN−B−22
g7
g2
VLAN−A−12
printer
g1
g19
PC 2
PC 1
192.168.8.7
Internet
gateway
switch
wireless extender
g23
192.168.8.240
192.168.8.9
192.168.8.107
192.168.8.31
Figure 2.4: Two VLANs dividing a LAN but sharing an Internet access
Because a new distribution of ports to VLANs had been introduced, the PVID of both VLANs needed
revision. The switch menu sequence:
Switching
→
VLAN
→
Advnaced
→
Port PVID Configuration
was used to bring up the
Port PVID Configuration
screen. First PVID 12 was applied to ports 1, 2,
7, and 23 before clicking the
APPLY
button. Then PVID 22 was applied to ports 19 and 23 (despite these
ports not having been changed on VLAN 22).
With URL
192.168.8.244
set in the configuration of the devices on both VLANs 12 and 22, all mem-
bers of each VLAN could access the Internet. However, members of one VLAN could not access the
other.
Any device connected to the switch could be shared by one or more VLANs on a switch by following
the above configuration appoach.
The problem with this technique of sharing is there is no control over access: any device on either
VLAN can access the shared device or devices. This contrasts to using ACL which can be applied to
routing VLANs as described in Section
??
. This is an advantage provided by the Layer 3 attributes of
the GS724Tv4 switch.
2.6
Ensuring only known devices can use a network
There is an opinion that only complex, or important, networks warrant the expense of network security
or network protection. But network security is available on a GS724Tv4 switch. This availability makes
assessment of what warrants securing an easier matter to decide. Small networks become candidates
for using network security.
Consider the network of Figure 2.5. It is a small network similar to that of Figure 2.1 but here all devices
having the same network address
192.169.14.0
on a single VLAN named
VLAN-FRED
. There is no
Internet connection. However, the existence of the wireless extender means the network is composed of
hardwired and wireless parts, i.e. wireless devices can connect onto the network as can devices which
plug into ports on the switch.
15