• April 26, 2024, 05:05:15 PM
  • Welcome, Guest
Please login or register.

Login with username, password and session length
Advanced search  

News:

This Forum Beta is ONLY for registered owners of D-Link products in the USA for which we have created boards at this time.

Author Topic: VLAN with DFL-800  (Read 6305 times)

BALance

  • Level 1 Member
  • *
  • Posts: 5
VLAN with DFL-800
« on: August 22, 2010, 11:26:39 AM »

Hi everybody,

I've to setup VLANs at our company with two DGS-1248T and one DFL-800. Now we've one big LAN for our company (192.168.50.0/24). In addition we need a VLAN for another company located at our office and one for our conference rooms. So, here are the details:
- 192.168.50.0/24 (Company A, our company) [All ports on switch 1, some on switch 2]
- 192.168.60.0/24 (Guest net, e.g. conference rooms and WLAN) [Port 5..10 on switch 2]
- 192.168.70.0/24 (Company B, new company) [Port 11..16 on switch 2]
- 10.0.0.0/24 (DMZ) [Port at DFL-800]
The DFL-LAN port is connected to switch 1 on port 1 and port 2 is connected to switch 2 on port 1. And these rules should take effect:
- Company A has full access to DMZ and internet.
- Guests have access to company A and DMZ with special rules and full access to the internet.
- Company B has only access to the internet.

Because I'm little bit confused from reading manuals and articles about VLANs here are my concrete questions:
1. Can I use the LAN as it is for our company or do I have to convert it into a VLAN?
2. Do I have to configure port 1&2 at switch 1 and port 1 at switch 2 as "tagged"?
3. Can somebody give a short overview about the VLANs to be configured?

Thank you in advance and best regards.
Logged

Fatman

  • Poweruser
  • Level 9 Member
  • ****
  • Posts: 1675
Re: VLAN with DFL-800
« Reply #1 on: August 23, 2010, 08:15:12 AM »

You can use the LAN as is.
You will need to configure the DFL for whatever VIDs you wish yo use and ensure any non default VID traffic arrives at the DFL "tagged".
There is very little that is short about VLANs (except maybe the 802.1q header itself), the manuals for both products should get you past the creation, the hard part will be writing all your new IP rules on your DFL.
Logged
non progredi est regredi