LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 07-19-2005, 03:09 PM   #1
KevinGuy
LQ Newbie
 
Registered: Jul 2003
Posts: 29

Rep: Reputation: 15
VLAN Question


Current Setup:
Separate Networks via Router

Is this possible?
Separate Networks via VLAN?

Let me know if you have any questions about what i have here and if it is possible to seperate those networks with VLANs.

Thank You!


Last edited by KevinGuy; 07-19-2005 at 03:52 PM.
 
Old 07-19-2005, 05:23 PM   #2
hlyrad
Member
 
Registered: Jul 2005
Location: Ab Ca
Distribution: Redhat EL Sun Mac OSX FC 3.0 & 4.0
Posts: 44

Rep: Reputation: 15
Generally speaking if your switch supports ACL's you can drop anything at that switch targeted between VLAN's. This will allow clients access to the router for regular queries and prevent inter VLAN fraternization.
You will need to check your switches manual for that information.
 
Old 07-19-2005, 07:41 PM   #3
neo77777
LQ Addict
 
Registered: Dec 2001
Location: Brooklyn, NY
Distribution: *NIX
Posts: 3,704

Rep: Reputation: 56
Well, first of all you said VLAN's and I don't see how you will benefit from the picture you presented, all your segments, including the internal IP of the firewall, are on the same segment - so you can just use switches chained together, avoiding loops. If you really ment to have 2 different networks for the intranets and a different network for uplink to the firewall then your switch (infront of the firewall) should support VLAN tagging (essentially, port connected to the firewall should be configured as trunk) - dot1q as an industry standard, or ISL or dot1q for Cisco equipment. On top of all that your firewall must have appropriate support for trunking (support for virtual interfaces, etc.). Unfortunately (or fortunately), mostly I have to deal with Cisco equipment on a daily basis, so I am not sure how other manufacturers' networking equipment is configured.
Hope this helps,
Best,
Boris.
 
Old 07-19-2005, 08:14 PM   #4
neo77777
LQ Addict
 
Registered: Dec 2001
Location: Brooklyn, NY
Distribution: *NIX
Posts: 3,704

Rep: Reputation: 56
Also, I assumed the switches are layer 2 only, and appropriate access control lists should be defined on the firewall to prevent one network to talk to another. If you use a layer2/3 switch between your fw and the intranets, the switch can be configured so that the routing decisions will be made on that switch for separate VLANs, in that case yu can apply access control lists on the Vlan interfaces of that switch, but if your fireawall has only one internal interface (from teh picture I thought it was the case), you wlll still need to dedicate one port on the switch to be in a trunk configuration, and slice the firewall's internal interface into 2 virtual interfaces if your intranets need access to outside world.
 
Old 07-21-2005, 12:59 PM   #5
KevinGuy
LQ Newbie
 
Registered: Jul 2003
Posts: 29

Original Poster
Rep: Reputation: 15
So if I were to go with a Cisco Layer 2/3 switch what would I be looking at in the way of hardware and the price?

Thanks ALOT for the replies - I still have allot of learning to do =)

As soon as I finish up college I will probably be looking into Cisco Certifications... You certified?
 
Old 08-02-2005, 09:56 PM   #6
neo77777
LQ Addict
 
Registered: Dec 2001
Location: Brooklyn, NY
Distribution: *NIX
Posts: 3,704

Rep: Reputation: 56
Sorry, didn't reply earlier. As far as cisco gear concerned - expensive. If you are willing to spend a premium go for 3750 series switches with advanced services image (if you are planning on layer2/3 make sure you get an EMI version of the switch - enhanced multilayer image), as for me, i could do with a standard multilayer image - SMI and trunk the uplink port(s) to the router - cost saving is sufficient to buy other pedigree for your network.
As for the certification - no I am not certified, I was thinking about getting CCNA and then CCNP, but I have no time whatsoever, job keeps me busy.
Regrds,
Boris.
 
Old 08-23-2005, 03:49 AM   #7
fhleung
Member
 
Registered: Aug 2004
Distribution: Lubuntu Live OS
Posts: 432

Rep: Reputation: 30
Setup VLAN

NewBie question:

Are there any way to setup a simple or small size VLan with Cisco router but not layer2/3 switch?
 
Old 08-23-2005, 07:35 AM   #8
scowles
Member
 
Registered: Sep 2004
Location: Texas, USA
Distribution: Fedora
Posts: 620

Rep: Reputation: 31
The answer to your question is yes and no.

Yes: If your switch is capable of vlan tagging and trunking.

No: If your switch is not capable of vlan tagging and trunking. (like a $50.00 linksys switch)

FWIW: A cisco router can be configured to do vlan switching on a single (physical) interface, but without the vlan tagging by the switch, the router does not know how to re-encapsulate the packet. i.e. the sub-interfaces

A good example of your question can be found here Skip to the network diagram chapter.
 
Old 08-23-2005, 07:35 AM   #9
cleidh_mor
Member
 
Registered: Mar 2005
Location: Glasgow, Scotland
Distribution: SuSE
Posts: 70

Rep: Reputation: 15
fhleung,

VLANs only exist in switched networks, so if you want to use a router and no switches, then VLANs make no sense. If on the other hand, you mean "is it possible to set up VLANs using a standard layer 2 switch and a Cisco router?" then the answer is yes - you can use "router on a stick". See the Cisco website for details on how to do this.

Hope this helps.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
VLAN Question teamchachi Linux - Networking 16 10-02-2005 05:09 PM
VLAN Routing teamchachi Linux - Networking 0 06-14-2005 09:54 AM
Vlan Markvw Linux - Networking 1 09-29-2003 08:33 AM
Linux for VLAN ? newbieA Linux - Networking 1 09-13-2003 11:34 AM
Connecting to a VLAN skumfrog Linux - Networking 2 03-13-2003 12:37 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 08:24 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration