VLANs FLEX 200 + XGS 1930 + HP Switch

itcrt
itcrt Posts: 19  Freshman Member
First Comment Friend Collector First Anniversary
edited May 9 in Security

Hello, how can i setup a 3 Vlan - VLAN1 (private) VLAN20(guest) VLAN30 (TV spot)

VLAN1 (DHCP - 192.168.232.1) - i whant to see all servers and clients

VLAN20 - This is isolated clients (DHCP 192.168.50.1) but can see PC and TV from VLAN1

VLAN30 (DHCP 192.168.100.1) - isolated TV, but can see PC and TV from VLAN1

I have zyxel switch xgs1930-52 and USG Flex 200 and Switch HPE 1820

not conected to nebula.

All Replies

  • WJS
    WJS Posts: 155  Master Member
    5 Answers First Comment Friend Collector Second Anniversary

    For example,

    1)you can make lan1 as vlan1

    2)Then creating VLAN20/30 set Base Port lan1 ,interface type "internal", VLAN ID , IP address also dhcp service.

    By the way, I think create customize zone for respective vlan since it's better for design secure policy

    3)Creating policy to restrict service as you want.

    From zone: vlan20 can't go anywhere but can see PC and TV on vlan1. and so on.

    4)For XGS1930 uplink port (connected to HP or Firewall),

    Act as Trunk port and allow vlan tag 20 , 30 ( I assume native vlan is 1)

    5)For HPE1820 uplink port (connected to XGS1930).

    Again set Trunk port and allow vlan tag20, 30.

    6)Use access port for other ports connected to the computer and set the proper VID.

  • itcrt
    itcrt Posts: 19  Freshman Member
    First Comment Friend Collector First Anniversary

    When i add VLAN ID in my PC Ethernet Controller I get IP addresses via DHCP,

    but if I do not enter the VLAN ID in my PC Ethernet Controller , I do not receive IP addresses

    why?

    VLAN 20

    VLAN 1

    VLAN Trunk

    IP Status Detail


  • WJS
    WJS Posts: 155  Master Member
    5 Answers First Comment Friend Collector Second Anniversary

    The ports connected to PC do not need Tagging (Trunk) .

Security Highlight