timbo343 Posted December 11, 2012 Posted December 11, 2012 (edited) Ok, ive had a play about with VLANs before but this was about 2 years ago and i have kinda forgotten bits of what i need to do. I have a 4204vl switch and im just wanting to see what i can do with VLANs with it. Here is the config: ; J8770A Configuration Editor; Created on release #L.11.20 hostname "ProCurve Switch 4204vl" snmp-server contact "IT Dept" snmp-server location "Server Room" module 1 type J8768A module 2 type J9033A module 3 type J9033A module 4 type J9033A snmp-server community "public" Unrestricted vlan 1 name "DEFAULT_VLAN" untagged A1,A3-A24,B1-B24,C1-C24,D1-D24 ip address 172.16.24.24 255.255.248.0 ip helper-address 172.16.24.4 no untagged A2 ip igmp exit vlan 2 name "VLAN2" untagged A2 ip address 192.168.12.1 255.255.252.0 ip helper-address 172.16.24.4 tagged A1 exit spanning-tree The DHCP server is 172.16.24.4 255.255.248.0 running Server 2008 R2 on port B20 and i have configured it to give out 192.168.12.20 -192.168.15.254 255.255.252.0. The test laptop in VLAN 2 is connected to the switch on port A2 and with a static IP of 192.168.12.20 can ping 192.168.12.1 but cannot ping the DHCP server. Can someone help me out as im wanting to set up a BYOD for staff, students and Guests and dont want them touching the network, but only want them to access the net. If i'm using the wrong kinda switch, then fair enough, i may need to get a L3 switch as my core. Thanks Edited December 11, 2012 by timbo343
IanT Posted December 16, 2012 Posted December 16, 2012 (edited) That switch is good enough and its up to the job! - http://h18000.www1.hp.com/products/quickspecs/archives_Division/12435_div_v2/12435_div.PDF Enable ip-routing and wr mem - so vlans can talk to each other etc Set the laptop to pick up an ip via DHCP (not static) Make sure the DHCP Scope is activated and has all the correct info (default gateway etc etc) Typical LITE-Core config (not perfect but basic core) Startup configuration: ; Configuration Editor; Created on release #R.11.72 hostname "core-2560-01" max-vlans 50 time daylight-time-rule Western-Europe console inactivity-timer 15 trunk 27-28 Trk1 LACP ip default-gateway 10.52.5.254 ip routing timesync sntp snmp-server community "public" Unrestricted vlan 1 name "DEFAULT_VLAN" no ip address exit vlan 5 name "bmi_mgmt" untagged 3-11,13,15-23 ip address 10.52.5.254 255.255.255.0 ip helper-address 10.52.10.1 ip helper-address 10.52.10.2 tagged 1,Trk1 ip proxy-arp ip igmp exit vlan 12 name "bmi_prt" ip address 10.52.12.254 255.255.255.0 ip helper-address 10.52.10.1 ip helper-address 10.52.10.2 tagged Trk1 ip proxy-arp ip igmp exit vlan 10 name "bmi_svr" ip address 10.52.10.254 255.255.255.0 ip helper-address 10.52.10.1 ip helper-address 10.52.10.2 tagged Trk1 ip proxy-arp ip igmp exit vlan 16 name "bmi_wired" untagged 2,14 ip address 10.52.16.254 255.255.255.0 ip helper-address 10.52.10.1 ip helper-address 10.52.10.2 tagged 1,Trk1 ip proxy-arp ip igmp exit vlan 18 name "bmi_ilo" ip address 10.52.18.254 255.255.255.0 ip helper-address 10.52.10.1 ip helper-address 10.52.10.2 tagged Trk1 ip proxy-arp ip igmp exit vlan 65 name "bmi_mobdevs" ip address 10.52.65.254 255.255.255.0 ip helper-address 10.52.10.1 ip helper-address 10.52.10.2 tagged 23,Trk1 ip proxy-arp ip igmp exit vlan 66 name "bmi_bmiwifi" ip address 10.52.66.254 255.255.255.0 ip helper-address 10.52.10.1 ip helper-address 10.52.10.2 tagged 23,Trk1 ip proxy-arp ip igmp exit vlan 67 name "bmi_bmiguest" ip address 10.52.67.254 255.255.255.0 ip helper-address 10.52.10.1 ip helper-address 10.52.10.2 tagged 23,Trk1 ip proxy-arp ip igmp exit vlan 98 name "bmi_bmicctv2" ip address 10.52.98.254 255.255.255.0 ip helper-address 10.52.10.1 ip helper-address 10.52.10.2 tagged 23,Trk1 ip proxy-arp ip igmp exit vlan 99 name "bmi_bmicctv1" untagged 1 ip address 10.52.99.254 255.255.255.0 ip helper-address 10.52.10.1 ip helper-address 10.52.10.2 tagged 23,Trk1 ip proxy-arp ip igmp exit vlan 100 name "bmi_fwall" untagged 12,24 ip address 10.52.100.254 255.255.255.0 ip helper-address 10.52.10.1 ip helper-address 10.52.10.2 tagged Trk1 ip proxy-arp ip igmp exit vlan 192 name "bmi_leg1" ip address 192.168.1.254 255.255.255.0 ip helper-address 10.52.10.1 ip helper-address 10.52.10.2 tagged Trk1 ip proxy-arp ip igmp exit vlan 1920 name "TEST VLAN" ip address 192.168.0.254 255.255.255.0 tagged Trk1 ip proxy-arp ip igmp exit ip route 0.0.0.0 0.0.0.0 10.52.100.123 radius-server timeout 3 radius-server retransmit 1 radius-server host 10.52.10.1 key XXXXXX auth-port 1645 acct-port 1646 aaa authentication console login radius local aaa authentication console enable radius local aaa authentication telnet login radius local aaa authentication telnet enable radius local aaa authentication web login radius local aaa authentication ssh login radius local aaa authentication ssh enable radius local sntp unicast spanning-tree spanning-tree Trk1 priority 4 spanning-tree priority 0 force-version RSTP-operation password manager password operator Edited December 17, 2012 by IanT 1
timbo343 Posted December 17, 2012 Author Posted December 17, 2012 Cheers @IanT Just one last question, am i right in thinking that for clients on the VLANs other than VLAN1 i would need the ip route 0.0.0.0 0.0.0.0 x.x.x.x for them to access the internet. Thats the last thing im struggling with now
AngryTechnician Posted December 17, 2012 Posted December 17, 2012 The problem you are going to have here is that once you enable ip-routing, all the VLANs can talk to each other, so you are only separating broadcast and multicast traffic. All other traffic will pass between VLANs just fine, so your BYOD network is not secured from the main network. In order to secure the traffic, you need to define ACLs to stop traffic from passing unhindered - and the HP 4200 series does not support VLAN ACLs. 1
IanT Posted December 17, 2012 Posted December 17, 2012 ip route 0.0.0.0 0.0.0.0 x.x.x.x - this will be your router or firewall
gshaw Posted December 17, 2012 Posted December 17, 2012 The problem you are going to have here is that once you enable ip-routing, all the VLANs can talk to each other, so you are only separating broadcast and multicast traffic. All other traffic will pass between VLANs just fine, so your BYOD network is not secured from the main network. In order to secure the traffic, you need to define ACLs to stop traffic from passing unhindered - and the HP 4200 series does not support VLAN ACLs. This ^^^ Ours aren't routed at the moment so the BYOD VLAN is isolated but as soon as routing is on without ACLs everything might as well be on the same network
Ergo Posted December 17, 2012 Posted December 17, 2012 We have dealt with a number of schools who are looking at this, and in most cases the best solution we have used is to NOT enable VLAN Routing, but instead ask you Broadband supplier to enable a second port on your router for the Guest network with a separate IP range, and then simply connect that as the default gateway for the BYOD/Guest VLAN. Regards, Dave
john Posted December 17, 2012 Posted December 17, 2012 @timbo343 if you have got your nice shiny UTM you could let that do DHCP for the BYOD and just have the VLAN dump traffic to that to get out and then do Zone Bridging in that to allow the BYOD access back to set servers such as HAP, OWA etc....
timbo343 Posted December 17, 2012 Author Posted December 17, 2012 @john, someone mentioned that, though said utm doesnt arrive until feb and was trying to be one step ahead of the game before it arrived, turns out its kinda back fired on me. At the moment we can use a second port on the cisco router or even the cisco firewall but like i said might as well wait for the utm and see what that will enable us to do. Possibly looking at setting up a webdav server for when students and some staff want to bring in their own device. Thats another headache ive go on the go at the moment. Ok, ive got a HAP setup but i would rather that just be used for staff at home. Will have to see what the future brings
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now