Great Circle Associates Firewalls
(August 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: 3C Switch
From: Alex Fournier <afournie @ tactik . com>
Date: Fri, 29 Aug 1997 17:56:15 -0400
To: InterSerF Support Team <support @ interserf . net>
Cc: firewalls @ GreatCircle . COM
References: <3 . 0 . 3 . 32 . 19970828184405 . 0076e710 @ mail . interserf . net>
Reply-to: afournie @ tactik . com

Hi, 

here's what I see:

1)

If you have 5 VLANS connected to your 1 router interface through a
repeater (HUB) they're not VLANs anymore...

2)

Are the VLANs using a same IP subnet? you say all 5 VLANs use addresses
from a same class C, do you mean they also share a netmask of
255.255.255.0?  If so, then the stations on two VLANs will try to
address each other without using the router (arp).  So you need an IP
subnet for each VLAN And then your router interface would need an adress
for each VLAN.

But like mentionned in 1), because your VLANs are connected together
through a HUB, you lost your VLAN effect...
Creating 5 VLANs would only be useful if you had 5 router (or firewall)
interfaces to connect them to.

What advantages were you hoping to gain from using the VLAN features?

Alex




But anyway, what is it you want the VLANs for if you only have 1 router
interface to connect them to?




InterSerF Support Team wrote:
> 
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
> 
> I have seen some folks on this list a couple of weeks ago that were
> discussion switches and specifically the 3Com switches. So I know we
> have some switch experts out there. I need some help as I can't get
> any from the documentation or maybe my brain is just too fried to
> understand it. Sometimes I can't see the forest for the trees which
> can make you feel dumb as a rock!
> 
> We have the 3Com Switch 1000 - 24 port. It is setup with several (5)
> VLAN's. All NIC's on all 5 VLAN's are using an ip from the same class
> 
> C address and yet I don't seem to be able to communicated between the
> 
> VLAN's. Now I realize that the idea is to gain better control and
> security over your network and the separated VLAN's are only supposed
> 
> to be able to talk to each other through the router. All 5 backbone
> ports are setup correctly (including security off) and are connected
> to a repeater (only a short distance away) which is connected to the
> network gateway router (Cisco 2501). Do I need to be "routing" these
> VLAN's on an individual basis? What I mean is, do I need to add 5 new
> 
> routes to the cisco? The IP on the switch ether is also one from the
> same class C. Does this ether need to be included in the cisco
> router? The cisco is already routing the whole class C anyway.
> Subnetting seems to be redundant and a waste of IP's since I already
> have a switch. I have been over this many times in the last couple of
> 
> days and can't seem to get a handle on it. I would appreciate any
> help and/or suggestions. Thanx.................
> 
> -----BEGIN PGP SIGNATURE-----
> Version: PGP for Personal Privacy 5.0
> Charset: noconv
> 
> iQA/AwUBNATLtBTZAcUPcPuvEQIr2wCfSzWumbDMR5n209DEkTm5uBhFTBUAn0Td
> 5Fbv1ToIDb+PpATuKkup1xuM
> =DIzO
> -----END PGP SIGNATURE-----
> 
> <><><><><><><><><><><><><><><><><><><><><><><><><><><><>
>  System Administrator   http://www.interserf.net
>  InterSerF Support Team - Internet Services of Fredbrg
>  11901 Main Street      Fredericksburg, Virginia 22408
>  (540) 371-4195 Voice   (540) 371-4197 FAX
> <><><><><><><><><><><><><><><><><><><><><><><><><><><><>

-- 
Alex Fournier
Développement
Bell -- groupe Tactik


References:
  • 3C Switch
    From: InterSerF Support Team <support @ interserf . net>
Indexed By Date Previous: [no subject]
From: "Spikeman" <spikeman @ myself . com>
Next: Re: NetRanger
From: BlackNet Runner <br @ ldl . net>
Indexed By Thread Previous: 3C Switch
From: InterSerF Support Team <support @ interserf . net>
Next: RE: 3C Switch
From: "Messano, Jim" <jim . messano @ lmco . com>

Google
 
Search Internet Search www.greatcircle.com