Jump to content

Recommended Posts

Posted

The HT has asked if I could setup a public wifi to allow staff internet access on their personal devices. The first thing I need is to create VLANs as we are a totally flat network. The switches are a mishmash of different HP models ranging from 1800-1810 and 1910-1920. The 'core' switch is a Netgear GSM 7224 which I've been looking for an excuse to replace for sometime.

 

I don't know much about VLANs and been told the HP 1920 which has static routing would do but I was under the impression I needed a high end switch to have VLANs?

 

If I can pull this off I want to add more VLANs to separate the network further so don't want to get trapped by getting the wrong switch.

Posted
To handle the routing, you want a Layer 3 switch. We have a HPE 5406R here doing it here. Then any layer 2 switch should be able to handle having VLANs on them.
Posted

If it's only for wifi access and not network you wouldn't really need the routing as you're not passing data between the VLANs.

 

When you're talking about separating the rest of the network then yes you'd want a nice core etc

 

Steve

Posted
If it's only for wifi access and not network you wouldn't really need the routing as you're not passing data between the VLANs.

 

When you're talking about separating the rest of the network then yes you'd want a nice core etc

 

Steve

 

Yes that's what I was thinking. How about the HP 2920 would that be ok?

Posted

We are just doing pretty much the same.

We have a Sophos UTM so I’ve setup one interface to give out a different range of IP addresses for WiFi .

On our HP main switch HP1920 I’ve untagged the port the UTM is plugged into.

I’ve tried tagging other ports on the main switch that have WiFi connected as a test and I can get it to work

Next step tomorrow is pass vlan down a fibre to HP 1920 and 1810.

Let me know how you get on

Someone told me about this the other week but took some thinking to learn what tagging and untagging meant.

I grabbed this from a HP forum

 

 

if you want that a port only belongs to one VLAN, set the port to UNTAGGED. If you want a port in more then one VLAN, you need to set it to TAGGED. If a host should belong to more than one VLAN, the port must be TAGGED (for example an VMware ESX Server with guests that belongs to different VLANs). If you want to uplink a switch to another, you need to set the uplink port to TAGGED, for each VLAN which should be accessible over the uplink

Posted
We are just doing pretty much the same.

We have a Sophos UTM so I’ve setup one interface to give out a different range of IP addresses for WiFi .

On our HP main switch HP1920 I’ve untagged the port the UTM is plugged into.

I’ve tried tagging other ports on the main switch that have WiFi connected as a test and I can get it to work

Next step tomorrow is pass vlan down a fibre to HP 1920 and 1810.

Let me know how you get on

Someone told me about this the other week but took some thinking to learn what tagging and untagging meant.

I grabbed this from a HP forum

 

 

if you want that a port only belongs to one VLAN, set the port to UNTAGGED. If you want a port in more then one VLAN, you need to set it to TAGGED. If a host should belong to more than one VLAN, the port must be TAGGED (for example an VMware ESX Server with guests that belongs to different VLANs). If you want to uplink a switch to another, you need to set the uplink port to TAGGED, for each VLAN which should be accessible over the uplink

 

We have a Sophos UTM too so my next question is on the wifi VLAN are you using the UTM for DHCP?

Posted (edited)

The 1920 has basic routing but I wouldn't want to use it as a core switch doing Intervlan routing, I'd use a chassis or multiple switches creating logical stack with no one point of failure.

 

I did use a SonicWall at a previous place, this handled DHCP for the Guest WiFi everything else was on a flat network due to dated core switch.

 

At my last place we had Intervlan routing on the core switch but I moved the Guest WiFi gateway to the firewall so we could give staff personal devices allowed to connect to specific internal resources via WiFi (VDI, email etc.) which worked quite well. THe DHCP was still handled by the Internal DHCP server for ease of management.

Edited by Davit2005

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...