BatchFile Posted October 21, 2014 Posted October 21, 2014 (edited) I'm trying to get my head around VLANs in order to get a suitable BYOD system going. I've given up with wpad and pac as I think it'll end up with a queue at our door each lesson. I want to have a proper go at this next week (half term), but had a preliminary look yesterday and last night and am even more confused now than I was before - it's entirely possible that I've fundamentally misunderstood something here! Our Ruckus system sends out two WLANs for our stuff here (one for our laptops etc whose key rarely changes, and one for stuff such as staff phones whose key does change periodically). There are currently no (well, one, I suppose) VLANs; I haven't configured any - everything is set to VLAN1 and PVID1 as it came out of the box. I'm adding another WLAN, with AD Authentication, for pupil BYOD. Ruckus appears to be able to add a VLAN tag to traffic from a particular WLAN, so I'm setting the BYOD to VLAN2. So far I think I'm ok - now comes the sketchy bit that I need to check; please can someone confirm that the logic here is correct before I break my network (we have Netgear FSM726 switches if that helps / makes a difference)? I have a Smoothwall transparent proxy to sit between the VLANs, provide DHCP for the BYOD, and send everything to the LEA proxy; so I need the "green" connected to VLAN2 (that is a port with a PVID set to 2) and the "Red" connected to VLAN1 (like everything else on the network is at the moment)? The port that the access point comes into the switch on needs to be a trunk, as it carries traffic on both VLANs, as do all the connections between switches that carry BYOD traffic? Does the zonedirector need a trunk as well or does the traffic go straight from the AP into the network? Here's a diagram of what I'm trying to do in case it's easier (just one switch shown here) Now, to muddy the waters somewhat, I tried setting that up last night, setting green to 10.x.x.6 and red to 10.x.x.7 . before fiddling with any switch port settings. With my workstation connected to the same switch (wired) I set off a ping, pinging both addresses and another which is an-other server. When I changed the PVID of the green port on the switch, I was expecting to stop getting pings back from it, but I expected the red to carry on replying; but they both stopped... "an-other" kept going - reversibly and reproducably - what's going on there please? Many thanks! Edited October 21, 2014 by BatchFile
BatchFile Posted October 21, 2014 Author Posted October 21, 2014 been doing a bit more poking around (carefully!). What's the difference between tagging (or untagging) a port in a VLAN and setting the PVID on it?
IrritableTech Posted October 21, 2014 Posted October 21, 2014 Haven't used netgear for a while, but I'm fairly sure they follow hp. Untagged - this is generally used when the end device doesn't know about VLANs. All Untagged packets on a port will be tagged with the corresponding Vlan. Packets tagged with another Vlan will not be transmitted. Tagged - packets which have already been tagged by another device. So for arguments sake, you've got your switch and on port 1 is a workstation, port 2 a server and port 3 one of your APs you might do the following... Port 1 - Untagged Vlan 1. The workstation doesn't know or indeed care about VLANs. It's a background function. Port 2 - Tagged Vlan 1. You decide to set the Vlan on the server NIC driver (I do all my tagging at the switch though in reality). Port 3 - Untagged Vlan 1 and tagged Vlan 2. Your APs can talk to the controller, your curriculum traffic would be tagged by the switch, but your byod traffic can also pass over this switch port. Ports can only be Untagged in one Vlan (if the packet is not tagged, tag it in this Vlan) but can be tagged in many. Normally you would use different subnets for different VLANs. At the moment it looks like both your VLANs are in the same subnet. 1
Boredguy Posted October 21, 2014 Posted October 21, 2014 You would Tag (T) a port on the netgear to get it to sent multiple vLans through that port. Mainly used for connecting switches together or another end device that is dealing with multiple vLans Untagging (U) says that that port can see that vLan Nothing (Blank) means that port is not a member of that vLan pVID will set the default vLan for that port, assuming it is a member of multiple vLans. We have our Ruckus Controller and access point ports Tagged for both our primary vLan and the BYOD vLan (1 and 30 respectively) Our BYOD gateway port is set as vLan 30 Untagged (your green connection) All switch uplinks from AP back to the core have the uplink Tagged at both ends for vLan 30 (since the newer netgear switches will not allow you to alter vLan 1 for some reason) 1
BatchFile Posted October 22, 2014 Author Posted October 22, 2014 Thanks both and Edugeek - still the best substitute for knowledge and training! Will have another go and no doubt be back.
BatchFile Posted October 23, 2014 Author Posted October 23, 2014 It's all going well now - I've got a teeny tiny Vlan2 running around a core switch wth an AP, Zonedirector and proxy with DHCP as above (went with IpFire in the end - I just like it) and it seems to work well. Devices connecting to the AP on the BYOD lan are now getting BYOD addresses (192.168.x.x) rather than "school" ones (10.x.x.x) and devices connecting to the other LANs are getting the right ones too. All that's left to do now is a bit of repatching, joining a switch in each of the other cabs to the core switch I've been fiddling with, and tagging appropriately, which I'll do in half term. Just one last question (hopefully): I should be able to avoid it, but just out of curiosity what happens if there's an unmanaged switch along the route? do they untag packages or just pass them on blindly?
IrritableTech Posted October 23, 2014 Posted October 23, 2014 I'd avoid it if possible, or keep it for one type of device only (ie. curriculum machines) and then tag the packets at the managed switch it uplinks too. Glad it is working for you. 1
tj2419 Posted October 29, 2014 Posted October 29, 2014 Hi @BatchFile glad to hear you got yours working. I am trying to achieve exactly the same thing. Ruckus wireless with HP switches. I have attached a rough layout of one section of our network where we are trying to get a BYOD network for us. Can't get my head 100% around where needs to be tagged, untagged and truncked? Our Smoothwall box is going to act as our dhcp for the BYOD devices. Hoping to use: VLAN 1 = school owned devices VLAN 2 = BYOD Any chance anyone could write on my plan where it needs to be tagged etc? Also do you need to change any settings on the actual AP's (Zf7363's) or on the zone director (3050) other than in configure, WLAN, edit, advanced options and ACCESS VLAN? Any help or advice would be greatly appreciated.
tj2419 Posted October 30, 2014 Posted October 30, 2014 Bump. Anyone have any advice? Hoping to have another look at this today cheers
Marshall_IT Posted October 30, 2014 Posted October 30, 2014 What do you want to use the red and green links for? P1 and p1 need to be tagged and any VLANs you use for WiFi. You also need to add a VLAN tag on the WLANs on the zone director.
tj2419 Posted October 30, 2014 Posted October 30, 2014 So tag port 1 on the core with 1 and 2 (for our vlans) The red and green is the way the smooth wall box was setup. Red is the dirty feed and green the clean feed. If that helps
Marshall_IT Posted October 30, 2014 Posted October 30, 2014 What do you mean by 'dirty' and 'clean'? Filleted and unfiltered? The out from the smoothwall is somewhere else i take it.
IrritableTech Posted October 30, 2014 Posted October 30, 2014 I'd go along the lines of the following following your thoughts... Core P1 tagged Vlan 1 & tagged Vlan 2 P2 Untagged Vlan 1 & tagged Vlan 2 P33 & P35, I'm not sure until you explain dirty and clean... Poe P1 Untagged Vlan 1 & tagged Vlan 2 P2 Untagged Vlan 1 & tagged Vlan 2 P16 tagged Vlan 1 & tagged Vlan 2 Everything else would probably be Untagged Vlan 1. Should point out Vlan 1 is best off not used for management, but many do without issue.
tj2419 Posted October 30, 2014 Posted October 30, 2014 I'd go along the lines of the following following your thoughts... Core P1 tagged Vlan 1 & tagged Vlan 2 P2 Untagged Vlan 1 & tagged Vlan 2 P33 & P35, I'm not sure until you explain dirty and clean... Poe P1 Untagged Vlan 1 & tagged Vlan 2 P2 Untagged Vlan 1 & tagged Vlan 2 P16 tagged Vlan 1 & tagged Vlan 2 Everything else would probably be Untagged Vlan 1. Should point out Vlan 1 is best off not used for management, but many do without issue. Hi @IrritableTech thanks for the advice. As for the green (Clean) and Red (Dirty) connections. Red is our internet feed from the core switch. Green is our feed that goes into the smoothwall box and picks up the filtering settings and passes through the smoothwall box acting as our transparent proxy. Effectively we want the traffic for BYOD to go down the green connection (Port 33) and out the red (Port 35) to the internet. Thanks again
tj2419 Posted October 30, 2014 Posted October 30, 2014 Also does anything extra need to be done to the access points themselves? Or should they just work? Cheers
IrritableTech Posted October 30, 2014 Posted October 30, 2014 (edited) Nothing else needs to be done to the APs if you follow what I've suggested above. You just need to configure your BYOD SSID to use Vlan 2. I presume your router is also connected to your core switch? Is it on another Vlan along with your 'dirty' feed? It looks like port 33 - your clean feed - needs to be Untagged Vlan 1 and tagged Vlan 2. Your smoothie will need a virtual NIC setting up for your Vlan 2 subnet. Did you say where your BYOD devices are getting dhcp from? Edited October 30, 2014 by IrritableTech
tj2419 Posted October 30, 2014 Posted October 30, 2014 Nothing else needs to be done to the APs if you follow what I've suggested above. You just need to configure your BYOD SSID to use Vlan 2. I presume your router is also connected to your core switch? Is it on another Vlan along with your 'dirty' feed? Hi Yes the router is also attached to the core switch. At first there were no VLAN's on the network. The ones i am creating as part of what i posted are the first, so i would assume that the port the router is attached to has no tagging etc yet. Would any additional tagging/untagging be required on the ports 33 or 35 on the core switch? Thanks
IrritableTech Posted October 30, 2014 Posted October 30, 2014 (edited) I think port 33 (sw green) should be Untagged Vlan 1 and tagged Vlan 2. But it depends on how you set up your smoothwall interfaces. Port 35 (sw red) should be Untagged Vlan 1 as should the port where your router connects. You could also think about setting up a 'unfiltered internet' Vlan (Vlan 3) which is only tagged on those two devices and ensure people can't find a way of avoiding your smoothwall box. This is unless you have other devices which need to get straight to the Internet and not use your smoothwall. Remember if you set up the Vlan on the end device (smoothwall, client, access point), the port should be Tagged, and if the end devices doesn't know about VLANs, the port should be Untagged. Edited October 30, 2014 by IrritableTech 1
tj2419 Posted October 30, 2014 Posted October 30, 2014 Hi @IrritableTech I have done the tagging/untagging as suggested but when i try connect a device to our provisioning SSID (set up on VLAN 2) it just sticks on spinning around and doesn't connect. I also saw about trunking ports, is this something we would need to do? To create the VLANs we created them on the core switch and one POE switch at the moment. Would we need to create them on the AP's? or smooth wall box? Thanks
IrritableTech Posted October 30, 2014 Posted October 30, 2014 Trunks are different depending on switch vendor. In HP world they are two links acting as one. In Cisco speak, they are generally links which carry data for more than one Vlan. Your smoothwall NIC is probably best set as interface 1 Vlan 1 and interface 1.1 Vlan 2. As a result you'll need to set your green p33 to tagged Vlan 1 and tagged vlan2. Not Untagged as I suggested before. Can you see if your smoothwall is getting a dhcp request and sending a response?
tj2419 Posted October 30, 2014 Posted October 30, 2014 Your smoothwall NIC is probably best set as interface 1 Vlan 1 and interface 1.1 Vlan 2. So is this something i would need to change on the smoothwall box itself? If so any pointers on where you do this? Our smooth wall box has two NIC's One we use as the red connection and one as the green. Can you see if your smoothwall is getting a dhcp request and sending a response Again sorry how would you do this? Apologies for all the questions this is all really new territory to me. We plugged our smooth wall box into a standalone switch with a laptop connected via ethernet and got an IP in the correct range immediately, so the DHCP side seems to be working fine.
IrritableTech Posted October 30, 2014 Posted October 30, 2014 Your smoothwall NIC is probably best set as interface 1 Vlan 1 and interface 1.1 Vlan 2. So is this something i would need to change on the smoothwall box itself? If so any pointers on where you do this? Our smooth wall box has two NIC's One we use as the red connection and one as the green. Can you see if your smoothwall is getting a dhcp request and sending a response Again sorry how would you do this? Apologies for all the questions this is all really new territory to me. We plugged our smooth wall box into a standalone switch with a laptop connected via ethernet and got an IP in the correct range immediately, so the DHCP side seems to be working fine. I don't use smoothwall, and it's been a while since I had a demo. I believe in the network section you should be able to create a virtual interface and you can also set a Vlan for it. Hopefully someone else can give you a better description. It sounds like your dhcp service is working, but because you've done it on another switch, it suggests it wasn't using VLANs. A correctly assigned virtual Nic on your smoothwall should work then.
tj2419 Posted October 30, 2014 Posted October 30, 2014 I don't use smoothwall, and it's been a while since I had a demo. I believe in the network section you should be able to create a virtual interface and you can also set a Vlan for it. Hopefully someone else can give you a better description. It sounds like your dhcp service is working, but because you've done it on another switch, it suggests it wasn't using VLANs. A correctly assigned virtual Nic on your smoothwall should work then. Thanks i'll have a look around it. So if i find out how to do it tagging the green NIC as VLAN 2 and red NIC as VLAN 1? Thanks for all your help. If anyone else has any tips that would be great. I feel like i'm so close but just one little thing somewhere is stopping me.
BatchFile Posted November 3, 2014 Author Posted November 3, 2014 (edited) Hi @BatchFile glad to hear you got yours working. I am trying to achieve exactly the same thing. Ruckus wireless with HP switches. I have attached a rough layout of one section of our network where we are trying to get a BYOD network for us. Can't get my head 100% around where needs to be tagged, untagged and truncked? Our Smoothwall box is going to act as our dhcp for the BYOD devices. Hoping to use: VLAN 1 = school owned devices VLAN 2 = BYOD Any chance anyone could write on my plan where it needs to be tagged etc? Also do you need to change any settings on the actual AP's (Zf7363's) or on the zone director (3050) other than in configure, WLAN, edit, advanced options and ACCESS VLAN? Any help or advice would be greatly appreciated. [ATTACH]27303[/ATTACH] I think others have answered this while I was having a few days off :-) What I did in the BYOD VLAN was tagged (T) all the ports that would carry the traffic on any switches EXCEPT the port that the SmoothWall (IpFire in my case) GREEN connects to, which is untagged (U). Set the PVID of the green port to 2 as well. In the "Other" (School devices) VLAN, all I had to do was remove ( ) (that's no T or U) the green port. Turn on DHCP server on the Smoothwall, set its red to pick up an IP address from the main school DHCP server, configure it as a transparent proxy to point all traffic at either your main school proxy or LEA servers, and that's about it. For troubleshooting, I found it useful to configure another port on the switch in the same way as the "green" (ie U in BYOD VLAN, PVID=2 and nothing in school VLAN), to connect a laptop in so you've got a wired device on the BYOD VLAN to verify DHCP etc taking ruckus out of the equation. Edited November 3, 2014 by BatchFile apostrophe's
BatchFile Posted November 3, 2014 Author Posted November 3, 2014 I don't use smoothwall, and it's been a while since I had a demo. I believe in the network section you should be able to create a virtual interface and you can also set a Vlan for it. Hopefully someone else can give you a better description. It sounds like your dhcp service is working, but because you've done it on another switch, it suggests it wasn't using VLANs. A correctly assigned virtual Nic on your smoothwall should work then. I think it's the open source SmoothWall version @tj2419 is talking about - that's certainly what I'm talking about - it's a simple (to set up) firewall, DHCP etc. Mine's currently running on a 9 year old PC that used to be in one of the IT rooms!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now