Switch with 3 VLANs with a shared gateway to connect to the internet

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

Switch with 3 VLANs with a shared gateway to connect to the internet

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
Switch with 3 VLANs with a shared gateway to connect to the internet
Switch with 3 VLANs with a shared gateway to connect to the internet
2020-07-30 08:42:00 - last edited 2021-03-25 08:55:19
Hardware Version: V2
Firmware Version: 2.0.3 Build 20190516 Rel.33426(s)
 
Hi. Will it be possible to achieve this kind of setup?
Supposedly, the switch I have is L2 and L3 capability. I wanted to set this up as shown in the illustration.
Say, I wanted to make 3 VLANS, leaving the VLAN 1 as the default, that will somehow can connect to the internet using the port 1 which is directly connected to the router.
 
Is this somehow possible? Thank you
  0      
  0      
#1
Options
2 Reply
Re:Switch with 3 VLANs with a shared gateway to connect to the internet
2020-07-30 19:49:53 - last edited 2021-03-25 08:55:19

@JunPh Yes it is possible. I am assuming you are going to use a business grade router/firewall or a windows machine to do the DHCP.

  1  
  1  
#2
Options
Re:Switch with 3 VLANs with a shared gateway to connect to the internet
2020-07-30 21:28:40 - last edited 2021-03-25 08:55:19

 

JunPh wrote

 
Hi. Will it be possible to achieve this kind of setup?

 

in principle: yes, with your choosen topology: no.

 

You need to set the switch's default gateway to your router's IP (192.168.1.1) to forward traffic from one of the VLANs 10, 20 and 30 destined to an Internet service to the router. You can do so using VLAN 1 or port 1 being a routed port, but the VLAN's/routed ports's virtual interface (VIF, the IP for the switch as seen by the router) needs to be part of the 192.168.1.0/24 network, which means it must have an IP such as 192.168.1.2 or whatever, but not 192.168.0.1. See following topology (just ignore the switches in VLANs 10, 20 and 30 – since your clients are directly connected to the core switch):

 

 

Note also that you need to prevent unwanted Inter-VLAN routing using Access Control Lists (ACLs). But Inter-VLAN routing for traffic from clients to the Internet router as well as for replies from the Internet router to the clients needs to be enabled in such a topology, thus you cannot just turn off Inter-VLAN routing globally.

 

As @Merryworks wrote already, you need a DHCP server with an own DHCP address pool for the clients in VLANs 10, 20 and 30.

 

I recommend to use the built-in DHCP server of your T2600G switch to assign clients a dynamic IP according to the VLAN they are in. This DHCP server must also inform clients about their default gateway, which must be the VIF of the appropriate VLAN (e.g. 192.168.10.1 for clients in VLAN 10 etc.). To achieve this with the built-in DHCP server, you could define a L2 DHCP relay for those VLANs in the switch.

 

Since you have L2+ features in T2600G, make use of them. No Windoze DHCP server needed.

༺ 0100 1101 0010 10ཏ1 0010 0110 1010 1110 ༻
  1  
  1  
#3
Options