networking-forum.com
Community BlogCommunity Wiki * Register  * Search  * Login
View unanswered postsView active topics

All times are UTC - 6 hours [ DST ]



Post new topic Reply to topic  [ 12 posts ] 
Author Message
 Post subject: inter vlan routing
PostPosted: Tue Mar 20, 2012 1:32 pm 
Offline
New Member
New Member

Joined: Tue Mar 20, 2012 1:25 pm
Posts: 5
hello,


in my network i got a switch with 4 vlan's configured
vlan 10
vlan 20
vlan 30
vlan 40


in vlan 40 i have my domain controller for my existing domain
i have read that seperate vlan's can't have contact without a lollipop router ( router on a stick, inter vlan routing)
i want that users in vlan 10, vlan 20 and vlan 30 can have access to my domain controller in vlan 40
but they can't have access to each other.

how can i solve this?


kind regards


Top
 Profile  
 
 Post subject: Re: inter vlan routing
PostPosted: Tue Mar 20, 2012 1:57 pm 
Online
Post Whore
Post Whore
User avatar

Joined: Tue Aug 21, 2007 2:15 pm
Posts: 8284
Location: Frederick MD
Certs: Instanity
you need to create sub interfaces on your router and trunk the vlans to the router port.
the router on a stick will route between vlans

http://blog.alwaysthenetwork.com/tutori ... -tutorial/

_________________
"If you're good at anticipating the human mind. It leaves nothing to chance."
-Jigsaw


Top
 Profile  
 
 Post subject: Re: inter vlan routing
PostPosted: Tue Mar 20, 2012 3:13 pm 
Offline
Ultimate Member
Ultimate Member
User avatar

Joined: Mon Dec 31, 2007 11:18 am
Posts: 762
Location: Minnesota
Certs: CCNP, CCIP
Your switch doesnt support VLAN interfaces?

_________________
http://www.dasblinkenlichten.com
@blinken_lichten


Top
 Profile  
 
 Post subject: Re: inter vlan routing
PostPosted: Tue Mar 20, 2012 5:30 pm 
Offline
New Member
New Member

Joined: Tue Mar 20, 2012 1:25 pm
Posts: 5
Hello,

Thanks for the reply , the problem is However , that when i configure sub interfaces
And a lollipop Router that all my vlans Can reach each other, and i only want that Vlan
10,20,30 Can reach Vlan 40 and not that Vlan 10, 20 and 30 Can reach each other, Vlan 10,20,30 must nr
Completely seperated from each other, they only need to reach Vlan 40 to log into domain.because the domain controller is there.


Top
 Profile  
 
 Post subject: Re: inter vlan routing
PostPosted: Tue Mar 20, 2012 7:09 pm 
Offline
Ultimate Member
Ultimate Member
User avatar

Joined: Mon Dec 31, 2007 11:18 am
Posts: 762
Location: Minnesota
Certs: CCNP, CCIP
Seems like a design issue. Private VLANs? Or move the domain controller? ACLs if yuo have to...

_________________
http://www.dasblinkenlichten.com
@blinken_lichten


Top
 Profile  
 
 Post subject: Re: inter vlan routing
PostPosted: Tue Mar 20, 2012 7:49 pm 
Offline
Post Whore
Post Whore

Joined: Sat Jun 07, 2008 11:06 am
Posts: 2553
Location: Grand Rapids, MI
Certs: CCNP, CCDP
Get the routing working, and then filter out the traffic you don't want to allow via ACL's.


Top
 Profile  
 
 Post subject: Re: inter vlan routing
PostPosted: Wed Mar 21, 2012 4:49 am 
Offline
Ultimate Member
Ultimate Member
User avatar

Joined: Thu Jan 13, 2011 5:10 pm
Posts: 984
Location: Leeds, UK
Certs: CCIE R&S #38338, CCNP, CCIP
Fred wrote:
Get the routing working, and then filter out the traffic you don't want to allow via ACL's.


this.

Alternatively if you have something like a 3560 then you could look into Private VLAN's as others have said, what switch are you using?

_________________
---
David
CCIE R&S #38338, CCIP, CCNP

http://networkbroadcast.co.uk - My Blog
http://twitter.com/davidrothera


Top
 Profile  
 
 Post subject: Re: inter vlan routing
PostPosted: Wed Mar 21, 2012 5:00 am 
Online
Post Whore
Post Whore
User avatar

Joined: Mon Nov 16, 2009 8:10 pm
Posts: 2520
Location: San Diego, CA
Certs: CCNP, BCNE, Network+, Security+
Yes, private VLAN or ACL.

_________________
Regards,

Steven King
San Diego Cisco User Group - http://www.sdcug.com
"The only time something is impossible is when you think it is." - Kevin Corbin, CCIE #11577


Top
 Profile  
 
 Post subject: Re: inter vlan routing
PostPosted: Wed Mar 21, 2012 9:27 am 
Offline
New Member
New Member

Joined: Tue Mar 20, 2012 1:25 pm
Posts: 5
hello,

thanks for the advice, i will give it a try with private vlan's


kind regards


Top
 Profile  
 
 Post subject: Re: inter vlan routing
PostPosted: Thu Mar 22, 2012 10:50 pm 
Offline
Post Whore
Post Whore

Joined: Sat Jun 07, 2008 11:06 am
Posts: 2553
Location: Grand Rapids, MI
Certs: CCNP, CCDP
s5056188 wrote:
thanks for the advice, i will give it a try with private vlan's

My original advice holds: Get the routing working first.

Once you have full connectivity, then you can figure out how to block the traffic you don't want. Private VLANs will be harder than ACL's, but both would work. But if you don't have the underlying connectivity established first, then you're building security on top of a pile of shit, and you can't predict how that's going to turn out.


Top
 Profile  
 
 Post subject: Re: inter vlan routing
PostPosted: Fri Mar 23, 2012 9:53 am 
Online
Post Whore
Post Whore
User avatar

Joined: Tue Aug 21, 2007 2:15 pm
Posts: 8284
Location: Frederick MD
Certs: Instanity
Fred wrote:
s5056188 wrote:
thanks for the advice, i will give it a try with private vlan's

My original advice holds: Get the routing working first.

Once you have full connectivity, then you can figure out how to block the traffic you don't want. Private VLANs will be harder than ACL's, but both would work. But if you don't have the underlying connectivity established first, then you're building security on top of a pile of shit, and you can't predict how that's going to turn out.



that what I was thinking, if you can't get router on a stick working, private vlans would much more difficult.

_________________
"If you're good at anticipating the human mind. It leaves nothing to chance."
-Jigsaw


Top
 Profile  
 
 Post subject: Re: inter vlan routing
PostPosted: Wed Mar 28, 2012 1:20 pm 
Offline
New Member
New Member

Joined: Tue Mar 27, 2012 2:13 pm
Posts: 3
Certs: CCNA, CCNA Voice
If this is a DHCP server, it sounds like an "ip address helper" solution...thou im not sure if this would solve this case.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 12 posts ] 

All times are UTC - 6 hours [ DST ]


Who is online

Users browsing this forum: carfret, javin, niallnf, Reggle, williamtyrell78, yogidrasil and 32 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB® Forum Software © phpBB Group