I require some help with setting up a VLan system. I have read all the how to's and other posts on this site, which are extremely helpful, but my situation is not the same as what I've read and therefore require further help.
I run a small business from within my home which has a business internet service with no ports blocked. This enables my VPN, RDP and other internet resources to function when I travel. I have a second internet service from a different ISP, a residential service, with all but the standard internet ports blocked, which the kids and their friends use. And lastly, I've committed to hosting an FTP server from my home on the business ISP because the ports are not blocked.
My current business set up is a flat network. From my ISP modem I have a DLink DIR-655 router which has DHCP disabled. I have a Windows SBS 2003 server which handles the DHCP and DNS.
The schema looks like this:
ISP----> DLink DIR-655-----> Linksys 24 port unmanaged switch----> Hosts including SBS 2003 providing DHCP and DNS. The D-Link router is set up as the firewall and, as mentioned, does the routing. In this set up, the D-Link router was given a LAN address of 192.168.XXX.1/24 and DNS is pointed to the SBS 2003. The SBS was set up with an address of 192.168.XXX.XXX/24 and DNS of 192.168.XXX.XXX. This set up works well for a flat network, business only.
In order to host the FTP server, I need to use the business ISP, as their ports are not blocked, but I need to keep it separate from the business network. Through reading ALOT, I've resolved to believe that a VLAN is the best solution. This also got me to thinking that I could reduce costs and move the kids network onto another VLAN and eliminate the residential ISP.
I've purchased a NetGear GS108T smart switch to build the VLAN with but after several attempts, I cannot get it to function the way I want it to. The business network has internet access but the FTP VLAN and kids VLAN do not. This leads me to believe that I have my hardware placement incorrect and possibly even some of the VLAN details incorrect.
By following NetGear's instructions, I put the NetGear switch between the D-Link router and the Linksys switch, so it could get an LAN IP address for management and set up purposes. But I now think this is what's caused all my failures. Remember, the D-Link is part of the flat business network, therefore, the NetGear received an LAN IP of the flat business network.
My goal is to have three VLANs in my network, 1 for business, 1 for FTP and 1 for kids. The 3 should not be able to communicate with each other but should each have access to the internet. This setup would provide the necessary security for the business information. However, I use a business rated anti-virus/ internet security software that I'd like on all the hosts. This would require that the anti-virus Admin Console on the SBS server would need to communicate with all hosts across all LANs. It would be nice if one host on the business network had limited access to the FTP server to upload files.
I hope someone here can help me and work with me to build this system. I would first need to know all the hardware required and where it gets placed within the entire LAN, kind of like a topography. Then some help in setting up the VLANs would be great.
Thank you to everyone who cares to get involved.
I run a small business from within my home which has a business internet service with no ports blocked. This enables my VPN, RDP and other internet resources to function when I travel. I have a second internet service from a different ISP, a residential service, with all but the standard internet ports blocked, which the kids and their friends use. And lastly, I've committed to hosting an FTP server from my home on the business ISP because the ports are not blocked.
My current business set up is a flat network. From my ISP modem I have a DLink DIR-655 router which has DHCP disabled. I have a Windows SBS 2003 server which handles the DHCP and DNS.
The schema looks like this:
ISP----> DLink DIR-655-----> Linksys 24 port unmanaged switch----> Hosts including SBS 2003 providing DHCP and DNS. The D-Link router is set up as the firewall and, as mentioned, does the routing. In this set up, the D-Link router was given a LAN address of 192.168.XXX.1/24 and DNS is pointed to the SBS 2003. The SBS was set up with an address of 192.168.XXX.XXX/24 and DNS of 192.168.XXX.XXX. This set up works well for a flat network, business only.
In order to host the FTP server, I need to use the business ISP, as their ports are not blocked, but I need to keep it separate from the business network. Through reading ALOT, I've resolved to believe that a VLAN is the best solution. This also got me to thinking that I could reduce costs and move the kids network onto another VLAN and eliminate the residential ISP.
I've purchased a NetGear GS108T smart switch to build the VLAN with but after several attempts, I cannot get it to function the way I want it to. The business network has internet access but the FTP VLAN and kids VLAN do not. This leads me to believe that I have my hardware placement incorrect and possibly even some of the VLAN details incorrect.
By following NetGear's instructions, I put the NetGear switch between the D-Link router and the Linksys switch, so it could get an LAN IP address for management and set up purposes. But I now think this is what's caused all my failures. Remember, the D-Link is part of the flat business network, therefore, the NetGear received an LAN IP of the flat business network.
My goal is to have three VLANs in my network, 1 for business, 1 for FTP and 1 for kids. The 3 should not be able to communicate with each other but should each have access to the internet. This setup would provide the necessary security for the business information. However, I use a business rated anti-virus/ internet security software that I'd like on all the hosts. This would require that the anti-virus Admin Console on the SBS server would need to communicate with all hosts across all LANs. It would be nice if one host on the business network had limited access to the FTP server to upload files.
I hope someone here can help me and work with me to build this system. I would first need to know all the hardware required and where it gets placed within the entire LAN, kind of like a topography. Then some help in setting up the VLANs would be great.
Thank you to everyone who cares to get involved.
Last edited: