background image

 

 

VLAN-Definition

 

VLANs are logical subgroups within a Local Area Network (LAN), which combine user stations, 

and network devices into a single unit, regardless of the physical LAN segment to which they are 

attached. VLANs allow network traffic to flow more efficiently within subgroups. VLANs use 

software to reduce the amount of time it takes for network changes, additions, and moves to be 

implemented.  

 

Notes when setting-up VLANs  

 

 

• 

A VLAN does not have a minimum number of port  

• 

VLANs work at the OSI Layer 2 

 

• 

A VLAN can be created per unit, device or via logical connection/combination 

 

• 

Broadcast and Multicast traffic is transmitted only in the VLAN in which traffic is generated.  

 

• 

To allow traffic between VLAN a device working at protocol level (Layer 3) is required 

 

GSM7352S

M1

M2

M3

M4

48T

46T

44T

42T

47T

45T

43T

41T

1

3

5

7

9

11

13

15

17

19

21

23

25

27

29

31

33

35

37

39

41T

43T

45T

47T

2

4

6

8

10

12

14

16

18

20

22

24

38

40

42T

44T

46T

48T

26

28

30

32

34

36

Default IP route : 192.168.2.254

Internet

VLAN4

192.168.4.1/24

VLAN3

192.168.3.1/24

VLAN2

192.168.2.1/24

192.168.2.x/24

DG 192.168.2.254

192.168.3.x/24

DG 192.168.3.1

192.168.4.x/24

DG 192.168.4.1

ProSafe VPN Wireless ADSL Gateway

DGFV

338

LOCAL

1

2

3

4

5

6

7

8

10 0

Link/ACT

LINK/ACT

10 0

INTERNET

TEST

MODE L

WLAN

DSL

PWR

192.168.2.254/24

____ 

VLAN 4: Ports 0/41 

– 0/48 

         PVID = 4
         DHCP = 192.168.4.0/24

____ 

VLAN 3: Ports 0/21 

– 0/28 

         PVID = 3
         DHCP = 192.168.3.0/24

____ 

VLAN 2: Ports 0/1 

– 0/8 

         PVID = 2
         DHCP = 192.168.2.0/24

GSM7xxx - Shared access to the Internet across Multiple Routing VLANs using a Prosafe Firewall

DGFV338 

Static routes:
192.168,3.0 255.255.255.0 192.168.2.1

192.168.4.0 255.255.255.0 192.168.2.1

 

 

Содержание GSM7248v2 - ProSafe 48 Port Layer 2 Gigabit L2 Ethernet Switch

Страница 1: ...op Hardware differences among different models must be taken in consideration NOTE This document is not intended to illustrate how to perform full Layer3 separation for which Access Control Lists ACLs should be used Table of Contents VLAN Definition 2 Notes when setting up VLANs 2 1 Physical Setup 3 2 Logical Setup 3 3 Configuring the Switch management IP address 4 4 Creating a routing VLAN 6 5 Re...

Страница 2: ...rotocol level Layer 3 is required GSM7352S M 1 M 2 M 3 M 4 48T 46T 44T 42T 47T 45T 43T 41T 1 3 5 7 9 11 13 15 17 19 21 23 25 27 29 31 33 35 37 39 41T 43T 45T 47T 2 4 6 8 10 12 14 16 18 20 22 24 38 40 42T 44T 46T 48T 26 28 30 32 34 36 Default IP route 192 168 2 254 Internet VLAN4 192 168 4 1 24 VLAN3 192 168 3 1 24 VLAN2 192 168 2 1 24 192 168 2 x 24 DG 192 168 2 254 192 168 3 x 24 DG 192 168 3 1 1...

Страница 3: ...92 168 2 254 Static routes 192 168 3 0 255 255 255 0 192 168 2 1 192 168 4 0 255 255 255 0 192 168 2 1 GSM7352S VLAN1 Management VLAN IP 192 168 1 1 DG 192 168 1 254 DHCP disabled VLAN2 IP 192 168 2 1 DHCP enabled on DGFV338 192 168 2 0 24 DG 192 168 2 1 DNS 192 168 2 254 VLAN3 IP 192 168 3 1 DHCP enabled 192 168 3 0 24 DG 192 168 3 1 DNS 192 168 2 254 VLAN4 IP 192 168 4 1 DHCP enabled 192 168 4 0...

Страница 4: ... GSM7352S network protocol none Changing protocol mode will reset ip configuration Are you sure you want to continue y n y GSM7352S network parms 192 168 1 1 255 255 255 0 192 168 1 254 GSM7352S show network IP Address 192 168 1 1 Subnet Mask 255 255 255 0 Default Gateway 192 168 1 254 Burned In MAC Address 00 1F 33 E6 81 A5 Locally Administered MAC Address 00 00 00 00 00 00 MAC Address Type Burne...

Страница 5: ...s configured the Web Interface of the switch can be accessed It will possible to modify the Management IP configuration via System Management IP configuration including the IP address Subnet Mask Default Gateway and Management VLAN ID ...

Страница 6: ... by clicking on Unit 1 4 Select the correct option for each port that will be member of the VLAN Three options are available No membership no symbol appearing in the gray box underneath the port number Untagged membership U Tagged membership T In order to browse through the options just continuously click on the gray box until the correct one is set For this scenario we will be using the U Untagge...

Страница 7: ...ll the relevant VLANs have been added a summary can be found in the VLAN routing section of the menu In this case VLAN 2 3 and 4 have been added to the configuration A new Virtual port is assigned to each VLAN ...

Страница 8: ...ion must be accessed via Switching VLAN VLAN Membership In order to remove a port from the VLAN memberships just continuously click on the gray box underneath the port number until no symbol appears as in the picture below The VLAN Status page will show the update membership for all the VLAN ...

Страница 9: ...LAN1 membership to those ports that appear in any of the other VLANs to ensure total VLAN separation When setting a routing VLAN the PVID Port VLAN ID is automatically set to the VLAN ID This can be confirmed using the Port PVID Configuration page ...

Страница 10: ...er can be enabled via the System Services DHCP Server Configuration page To create a new DHCP pool access the DHCP Pool Configuration page 1 Select the Pool name for ease of configuration this might be same as the VLAN name if the pool will be associate to a VLAN ...

Страница 11: ... to a VLAN ensure that the IP address assigned to the VLAN falls within the network number or subnet specified in the pool For example VLAN 2 which in this scenario is assigned with IP address 192 168 2 1 and subnet mask 255 255 255 0 falls within the subnet 192 168 2 0 24 When creating the DHCP for VLAN2 we have made sure that the network address specified would be 192 168 2 0 with subnet mask 25...

Страница 12: ...per port basis including the VLAN virtual ports The picture below shows RIP enable on all the Virtual ports associated to each of the VLAN created and the Link State for each port as Link Down The reason for this is due to no device being plugged in any of the VLAN ports RIP requires at least one interface to be active in order for the protocol to be able to send routing updates ...

Страница 13: ...13 The next picture shows that at least one device has been connected to one of the ports in VLAN 2 Interface 0 2 1 and VLAN 4 Interface 0 2 3 changing the Link state to Link up ...

Страница 14: ... table A summary of the routes can be found in Routing Routing table Route configuration In the same page it is possible to set the DefaultRoute This is necessary to instruct the Layer 3 switch that any traffic not destined to the local VLANs should be sent to a Default Gateway In our scenario the Internet Default Gateway is the DGFV338 on IP address 192 168 2 254 The DefaultRoute is configured ac...

Страница 15: ...15 ...

Страница 16: ...c to devices in VLAN not directly attached to it static routes must be configured for each VLAN The following two pictures provide a summary of how this is achieved on the DGFV338 via the Network Configuration Routing page In this scenario two routes are required as two are the VLANs not directly connected to the DGFV338 LAN interface ...

Страница 17: ...nfiguration The switch does not save the configuration automatically every time a change is performed either via the CLI or the WEB GUI It is necessary to force the saving which can be achieved via Maintenance Save Config ...

Отзывы: