VLAN Configuration for networking scrub

EvilNeverSleeps

Junior Member
Oct 30, 2012
14
0
66
Hello everyone!

As i'm a scrub when it comes to networking (still learning the ropes) i have a question how should i configure my devices so everything would work as presented on diagram.




Question is, how should i configure the ports on switches? Which ones should be trunks (tag, untag?) I never set up a VLAN before so i'm kinda lost on it.

What i want is depending on MAC adress, device connected to one of APs would get put into VLAN it belongs. What i want is that VLAN 1 and VLAN 2 would not see each other ever (kinda idea of VLAN, isn't it? )

I'm not asking for someone do it for me but just provide some tips where should i begin so i could get a grasp on topic and start working on it

Regards and Thank you in advance!
 

theevilsharpie

Platinum Member
Nov 2, 2009
2,322
14
81
For the most part, network devices that are expected to work with multiple VLANs (i.e. your switches and access points) will interlink using tagged ports, and the network will expect those devices to insert the appropriate VLAN tags before sending traffic upstream. Hosts usually want untagged ports, although you can tag additional VLANs to an untagged port if needed.

If you want to make VLAN assignments based on certain criteria, you'll want to use 802.1x. 802.1x works in conjunction with RADIUS and some type of directory service (e.g., Active Directory) to authenticate users and devices, which you can leverage to place users/computers in the appropriate VLAN. Normally, authentication (and subsequent placement decisions) are done using passwords or certificates, but you may be able to use MAC address instead.
 

spidey07

No Lifer
Aug 4, 2000
65,469
5
76
True about the radius and AP integration, you can do it but will be more complicated than need be.

How about using two SSIDs? SSID1 maps to vlan 1, SSID2 maps to vlan 2. Then each interswitch link would be a trunk and each AP switchport would also be a trunk. This would have two completely seperate layer2 networks (really what a vlan is). APs have no trouble running multiple SSIDs if they are business class.

How you route things depends on capabilities of your router and/or layer3 switch. You'd need a router to have interfaces into vlan 1 and 2.
 

RadiclDreamer

Diamond Member
Aug 8, 2004
8,622
40
91
An easy way to think about it is this. If you need a vlan to retain its dot1q tag across a link then it needs to be a trunk on both sides. Otherwise with an access port the traffic is not tagged.

For example, i need vlan 1,2,3 to go across a link. I would trunk both sides
If i set the port to access port and assign it to vlan 2 but dont trunk, the traffic will be seen on the other side, but it will just be in whatever vlan it was tagged on the receiving side since the tagging is not kept in tact.
 

spidey07

No Lifer
Aug 4, 2000
65,469
5
76
A frequent method to have mutliple SSIDs on an AP is to trunk to the AP, map and tag each individual SSID to a vlan.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |