CPE510s to share internet only, not LAN

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
12

CPE510s to share internet only, not LAN

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
15 Reply
Re:CPE510s to share internet only, not LAN
2020-08-24 22:06:36

@R1D2 Just a dumb switch. I could get a small managed switch to allow me to create separate VLANs. Overkill?

  0  
  0  
#12
Options
Re:CPE510s to share internet only, not LAN-Solution
2020-08-24 22:36:06 - last edited 2020-08-24 22:55:25

 

DanAir wrote

Just a dumb switch. I could get a small managed switch to allow me to create separate VLANs. Overkill?

 

No overkill, but the solution for your guest network.

 

With a managed switch you can use an asymmetric VLAN to split your LAN into two isolated VLAN segments and share a common resource such as an Internet router. But note that this is kind of a »poor man's guest network« since both LAN segments (VLANs) still use the same broadcast domain of the LAN, which means the router will send broadcasts to both LAN segments. However, access to devices in a different LAN segment from within another LAN segment is not possible.

 

Setup of a managed switch (e.g. a TL-SG108E):

 

  • VLAN 1: the shared resource (Internet router) connected to switch port #1.
  • VLAN 2: your guest LAN segment in house 2, that's the CPE in house 1 connected to switch port #2.
  • VLAN 3: your private LAN segment in house 1, PCs, laptop etc. connected to switch port #3 (and ports #4 to #8 if needed).

 

Port settings:

  • Set port #1 (router) as untagged member of VLANs 1, 2 and 3, PVID=1.
  • Set port #2 (guest LAN via CPE link) as untagged member of VLANs 1 and 2, PVID=2.
  • Set port #3 (private LAN) as untagged member of VLANs 1 and 3, PVID=3. Likewise with ports 4 to 8.

 

Effects:

  • Traffic from guest LAN to private LAN or vice versa is not possible.
  • Traffic from guest LAN gets tagged with VLAN ID 2 and reaches the router which is a member of VLAN 2.
  • Traffic from private LAN gets tagged with VLAN ID 3 and reaches the router which is also a member of VLAN 3.
  • Traffic from the router back to the clients gets tagged with VLAN ID 1 and reaches the client in guest or private LAN which are also members of VLAN 1.

 

Note that you must not use the router's built-in switch in such a topology (except for the uplink of the managed switch and other shared devices such as network printers etc.).

 

༺ 0100 1101 0010 10ཏ1 0010 0110 1010 1110 ༻
Recommended Solution
  1  
  1  
#13
Options
Re:CPE510s to share internet only, not LAN
2020-08-24 22:44:24
Hugely helpful, thank you. If I connect a dumb switch to port #3 on the managed switch, will all traffic across that dumb switch act like it’s within VLAN 3? I use about 16 ports across two dumb switches so I’m asking whether I need a 16-port managed switch or I can get away with a 4 or 8-port by reusing the dumb switches.
  0  
  0  
#14
Options
Re:CPE510s to share internet only, not LAN
2020-08-24 22:50:22 - last edited 2020-08-24 22:53:31

 

DanAir wrote

If I connect a dumb switch to port #3 on the managed switch, will all traffic across that dumb switch act like it’s within VLAN 3?

 

Yes. No need to replace the 16-port dumb switches. But note the edit in my post: you must not use the router's built-in switch anymore with that topology to connect other devices (except shared devices such as a network printer etc.).

༺ 0100 1101 0010 10ཏ1 0010 0110 1010 1110 ༻
  0  
  0  
#15
Options
Re:CPE510s to share internet only, not LAN
2020-08-24 22:55:24

@R1D2 Got it. Understood. Thanks again.

  0  
  0  
#16
Options