Jump to content

Recommended Posts

Posted (edited)

I'm trying to get my head around VLANs in order to get a suitable BYOD system going. I've given up with wpad and pac as I think it'll end up with a queue at our door each lesson. I want to have a proper go at this next week (half term), but had a preliminary look yesterday and last night and am even more confused now than I was before - it's entirely possible that I've fundamentally misunderstood something here!

 

Our Ruckus system sends out two WLANs for our stuff here (one for our laptops etc whose key rarely changes, and one for stuff such as staff phones whose key does change periodically).

There are currently no (well, one, I suppose) VLANs; I haven't configured any - everything is set to VLAN1 and PVID1 as it came out of the box.

I'm adding another WLAN, with AD Authentication, for pupil BYOD. Ruckus appears to be able to add a VLAN tag to traffic from a particular WLAN, so I'm setting the BYOD to VLAN2. So far I think I'm ok - now comes the sketchy bit that I need to check; please can someone confirm that the logic here is correct before I break my network (we have Netgear FSM726 switches if that helps / makes a difference)?

 

I have a Smoothwall transparent proxy to sit between the VLANs, provide DHCP for the BYOD, and send everything to the LEA proxy; so I need the "green" connected to VLAN2 (that is a port with a PVID set to 2) and the "Red" connected to VLAN1 (like everything else on the network is at the moment)?

The port that the access point comes into the switch on needs to be a trunk, as it carries traffic on both VLANs, as do all the connections between switches that carry BYOD traffic? Does the zonedirector need a trunk as well or does the traffic go straight from the AP into the network?

Here's a diagram of what I'm trying to do in case it's easier (just one switch shown here) RuckusBYOD1.png

 

Now, to muddy the waters somewhat, I tried setting that up last night, setting green to 10.x.x.6 and red to 10.x.x.7 . before fiddling with any switch port settings. With my workstation connected to the same switch (wired) I set off a ping, pinging both addresses and another which is an-other server. When I changed the PVID of the green port on the switch, I was expecting to stop getting pings back from it, but I expected the red to carry on replying; but they both stopped... "an-other" kept going - reversibly and reproducably - what's going on there please?

 

Many thanks!

Edited by BatchFile
Posted
been doing a bit more poking around (carefully!). What's the difference between tagging (or untagging) a port in a VLAN and setting the PVID on it?
Posted

Haven't used netgear for a while, but I'm fairly sure they follow hp.

 

Untagged - this is generally used when the end device doesn't know about VLANs. All Untagged packets on a port will be tagged with the corresponding Vlan. Packets tagged with another Vlan will not be transmitted.

 

Tagged - packets which have already been tagged by another device.

 

So for arguments sake, you've got your switch and on port 1 is a workstation, port 2 a server and port 3 one of your APs you might do the following...

 

Port 1 - Untagged Vlan 1. The workstation doesn't know or indeed care about VLANs. It's a background function.

Port 2 - Tagged Vlan 1. You decide to set the Vlan on the server NIC driver (I do all my tagging at the switch though in reality).

Port 3 - Untagged Vlan 1 and tagged Vlan 2. Your APs can talk to the controller, your curriculum traffic would be tagged by the switch, but your byod traffic can also pass over this switch port.

 

Ports can only be Untagged in one Vlan (if the packet is not tagged, tag it in this Vlan) but can be tagged in many.

 

Normally you would use different subnets for different VLANs. At the moment it looks like both your VLANs are in the same subnet.

  • Thanks 1
Posted

You would Tag (T) a port on the netgear to get it to sent multiple vLans through that port. Mainly used for connecting switches together or another end device that is dealing with multiple vLans

Untagging (U) says that that port can see that vLan

Nothing (Blank) means that port is not a member of that vLan

pVID will set the default vLan for that port, assuming it is a member of multiple vLans.

 

We have our Ruckus Controller and access point ports Tagged for both our primary vLan and the BYOD vLan (1 and 30 respectively)

Our BYOD gateway port is set as vLan 30 Untagged (your green connection)

All switch uplinks from AP back to the core have the uplink Tagged at both ends for vLan 30 (since the newer netgear switches will not allow you to alter vLan 1 for some reason)

  • Thanks 1
Posted

It's all going well now - I've got a teeny tiny Vlan2 running around a core switch wth an AP, Zonedirector and proxy with DHCP as above (went with IpFire in the end - I just like it) and it seems to work well. Devices connecting to the AP on the BYOD lan are now getting BYOD addresses (192.168.x.x) rather than "school" ones (10.x.x.x) and devices connecting to the other LANs are getting the right ones too. All that's left to do now is a bit of repatching, joining a switch in each of the other cabs to the core switch I've been fiddling with, and tagging appropriately, which I'll do in half term.

 

Just one last question (hopefully): I should be able to avoid it, but just out of curiosity what happens if there's an unmanaged switch along the route? do they untag packages or just pass them on blindly?

Posted

Hi @BatchFile glad to hear you got yours working.

 

I am trying to achieve exactly the same thing. Ruckus wireless with HP switches.

 

I have attached a rough layout of one section of our network where we are trying to get a BYOD network for us.

 

Can't get my head 100% around where needs to be tagged, untagged and truncked?

 

Our Smoothwall box is going to act as our dhcp for the BYOD devices.

 

Hoping to use:

 

VLAN 1 = school owned devices

VLAN 2 = BYOD

 

Any chance anyone could write on my plan where it needs to be tagged etc?

 

Also do you need to change any settings on the actual AP's (Zf7363's) or on the zone director (3050) other than in configure, WLAN, edit, advanced options and ACCESS VLAN?

 

Any help or advice would be greatly appreciated.

 

 

ImageUploadedByEduGeek1414596012.869433.jpg

Posted

What do you want to use the red and green links for?

P1 and p1 need to be tagged and any VLANs you use for WiFi.

You also need to add a VLAN tag on the WLANs on the zone director.

Posted

So tag port 1 on the core with 1 and 2 (for our vlans)

 

The red and green is the way the smooth wall box was setup. Red is the dirty feed and green the clean feed. If that helps :)

Posted

I'd go along the lines of the following following your thoughts...

 

Core

P1 tagged Vlan 1 & tagged Vlan 2

P2 Untagged Vlan 1 & tagged Vlan 2

P33 & P35, I'm not sure until you explain dirty and clean...

 

Poe

P1 Untagged Vlan 1 & tagged Vlan 2

P2 Untagged Vlan 1 & tagged Vlan 2

P16 tagged Vlan 1 & tagged Vlan 2

 

Everything else would probably be Untagged Vlan 1.

 

Should point out Vlan 1 is best off not used for management, but many do without issue.

Posted
I'd go along the lines of the following following your thoughts...

 

Core

P1 tagged Vlan 1 & tagged Vlan 2

P2 Untagged Vlan 1 & tagged Vlan 2

P33 & P35, I'm not sure until you explain dirty and clean...

 

Poe

P1 Untagged Vlan 1 & tagged Vlan 2

P2 Untagged Vlan 1 & tagged Vlan 2

P16 tagged Vlan 1 & tagged Vlan 2

 

Everything else would probably be Untagged Vlan 1.

 

Should point out Vlan 1 is best off not used for management, but many do without issue.

 

Hi @IrritableTech thanks for the advice.

 

As for the green (Clean) and Red (Dirty) connections.

 

Red is our internet feed from the core switch.

 

Green is our feed that goes into the smoothwall box and picks up the filtering settings and passes through the smoothwall box acting as our transparent proxy.

 

Effectively we want the traffic for BYOD to go down the green connection (Port 33) and out the red (Port 35) to the internet.

 

Thanks again

Posted (edited)

Nothing else needs to be done to the APs if you follow what I've suggested above. You just need to configure your BYOD SSID to use Vlan 2.

 

I presume your router is also connected to your core switch? Is it on another Vlan along with your 'dirty' feed?

 

It looks like port 33 - your clean feed - needs to be Untagged Vlan 1 and tagged Vlan 2. Your smoothie will need a virtual NIC setting up for your Vlan 2 subnet.

 

Did you say where your BYOD devices are getting dhcp from?

Edited by IrritableTech
Posted
Nothing else needs to be done to the APs if you follow what I've suggested above. You just need to configure your BYOD SSID to use Vlan 2.

 

I presume your router is also connected to your core switch? Is it on another Vlan along with your 'dirty' feed?

 

Hi

 

Yes the router is also attached to the core switch.

 

At first there were no VLAN's on the network. The ones i am creating as part of what i posted are the first, so i would assume that the port the router is attached to has no tagging etc yet.

 

Would any additional tagging/untagging be required on the ports 33 or 35 on the core switch?

 

Thanks

Posted (edited)

I think port 33 (sw green) should be Untagged Vlan 1 and tagged Vlan 2. But it depends on how you set up your smoothwall interfaces.

Port 35 (sw red) should be Untagged Vlan 1 as should the port where your router connects. You could also think about setting up a 'unfiltered internet' Vlan (Vlan 3) which is only tagged on those two devices and ensure people can't find a way of avoiding your smoothwall box. This is unless you have other devices which need to get straight to the Internet and not use your smoothwall.

 

Remember if you set up the Vlan on the end device (smoothwall, client, access point), the port should be Tagged, and if the end devices doesn't know about VLANs, the port should be Untagged.

Edited by IrritableTech
  • Thanks 1
Posted

Hi @IrritableTech I have done the tagging/untagging as suggested but when i try connect a device to our provisioning SSID (set up on VLAN 2) it just sticks on spinning around and doesn't connect.

 

I also saw about trunking ports, is this something we would need to do?

 

To create the VLANs we created them on the core switch and one POE switch at the moment. Would we need to create them on the AP's? or smooth wall box?

 

Thanks

Posted

Trunks are different depending on switch vendor. In HP world they are two links acting as one. In Cisco speak, they are generally links which carry data for more than one Vlan.

 

Your smoothwall NIC is probably best set as interface 1 Vlan 1 and interface 1.1 Vlan 2. As a result you'll need to set your green p33 to tagged Vlan 1 and tagged vlan2. Not Untagged as I suggested before.

 

Can you see if your smoothwall is getting a dhcp request and sending a response?

Posted

Your smoothwall NIC is probably best set as interface 1 Vlan 1 and interface 1.1 Vlan 2.

So is this something i would need to change on the smoothwall box itself? If so any pointers on where you do this? Our smooth wall box has two NIC's One we use as the red connection and one as the green.

 

Can you see if your smoothwall is getting a dhcp request and sending a response

Again sorry how would you do this?

 

Apologies for all the questions this is all really new territory to me.

 

We plugged our smooth wall box into a standalone switch with a laptop connected via ethernet and got an IP in the correct range immediately, so the DHCP side seems to be working fine.

Posted
Your smoothwall NIC is probably best set as interface 1 Vlan 1 and interface 1.1 Vlan 2.

So is this something i would need to change on the smoothwall box itself? If so any pointers on where you do this? Our smooth wall box has two NIC's One we use as the red connection and one as the green.

 

Can you see if your smoothwall is getting a dhcp request and sending a response

Again sorry how would you do this?

 

Apologies for all the questions this is all really new territory to me.

 

We plugged our smooth wall box into a standalone switch with a laptop connected via ethernet and got an IP in the correct range immediately, so the DHCP side seems to be working fine.

 

I don't use smoothwall, and it's been a while since I had a demo. I believe in the network section you should be able to create a virtual interface and you can also set a Vlan for it. Hopefully someone else can give you a better description.

 

It sounds like your dhcp service is working, but because you've done it on another switch, it suggests it wasn't using VLANs. A correctly assigned virtual Nic on your smoothwall should work then.

Posted
I don't use smoothwall, and it's been a while since I had a demo. I believe in the network section you should be able to create a virtual interface and you can also set a Vlan for it. Hopefully someone else can give you a better description.

 

It sounds like your dhcp service is working, but because you've done it on another switch, it suggests it wasn't using VLANs. A correctly assigned virtual Nic on your smoothwall should work then.

 

Thanks i'll have a look around it. So if i find out how to do it tagging the green NIC as VLAN 2 and red NIC as VLAN 1?

 

Thanks for all your help. If anyone else has any tips that would be great. I feel like i'm so close but just one little thing somewhere is stopping me.

Posted (edited)
Hi @BatchFile glad to hear you got yours working.

 

I am trying to achieve exactly the same thing. Ruckus wireless with HP switches.

 

I have attached a rough layout of one section of our network where we are trying to get a BYOD network for us.

 

Can't get my head 100% around where needs to be tagged, untagged and truncked?

 

Our Smoothwall box is going to act as our dhcp for the BYOD devices.

 

Hoping to use:

 

VLAN 1 = school owned devices

VLAN 2 = BYOD

 

Any chance anyone could write on my plan where it needs to be tagged etc?

 

Also do you need to change any settings on the actual AP's (Zf7363's) or on the zone director (3050) other than in configure, WLAN, edit, advanced options and ACCESS VLAN?

 

Any help or advice would be greatly appreciated.

 

 

[ATTACH]27303[/ATTACH]

 

I think others have answered this while I was having a few days off :-)

 

What I did in the BYOD VLAN was tagged (T) all the ports that would carry the traffic on any switches EXCEPT the port that the SmoothWall (IpFire in my case) GREEN connects to, which is untagged (U). Set the PVID of the green port to 2 as well.

 

In the "Other" (School devices) VLAN, all I had to do was remove ( ) (that's no T or U) the green port.

 

Turn on DHCP server on the Smoothwall, set its red to pick up an IP address from the main school DHCP server, configure it as a transparent proxy to point all traffic at either your main school proxy or LEA servers, and that's about it.

For troubleshooting, I found it useful to configure another port on the switch in the same way as the "green" (ie U in BYOD VLAN, PVID=2 and nothing in school VLAN), to connect a laptop in so you've got a wired device on the BYOD VLAN to verify DHCP etc taking ruckus out of the equation.

Edited by BatchFile
apostrophe's
Posted
I don't use smoothwall, and it's been a while since I had a demo. I believe in the network section you should be able to create a virtual interface and you can also set a Vlan for it. Hopefully someone else can give you a better description.

 

It sounds like your dhcp service is working, but because you've done it on another switch, it suggests it wasn't using VLANs. A correctly assigned virtual Nic on your smoothwall should work then.

 

I think it's the open source SmoothWall version @tj2419 is talking about - that's certainly what I'm talking about - it's a simple (to set up) firewall, DHCP etc. Mine's currently running on a 9 year old PC that used to be in one of the IT rooms!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...