Thursday, March 15, 2018

Possible to isolate ports but all share same internet router via VLAN?

Hi guys,

Got an Allied Telesis AT-9000/24. Layer 2 switch I believe. I want to create a system where I have several ports all isolated from each other but able to access the internet (guest network), and another group of ports that are able to talk to each other, and the internet (clean network).

What I figured was I would create a seperate VLAN for each guest port (untagged) and then add the internet router to this (untagged as it does not have any vlan functionality)

Then I would create another VLAN for all the clean ports to share (untagged) and the router once again for internet access (untagged).

The router would dish out DHCP to all clients on same subnet.

Have seen this setup working perfectly on a TP-Link router but from everything I read on the internet you cant have the router port for example untagged on several VLAN's, but yet you can on the TP-Link.... what the? My switch does not allow this.

See this article here https://www.tp-link.com/us/faq-788.html you can see their VLAN 101 and 102 both have port 9 untagged for their router, how?



No comments:

Post a Comment