CircleTilde
IS-IT--Management
Hi
I've been assigned the task of getting straight internet access to a certain range of ports on a switch. I was told that using a VLAN would be the best solution. So I've done some research and am thoroughly confused. We don't use any VLAN's in our current network setup, and all of the switches that we use are different models of 3COM or Cisco, so the VLAN language is different for each switch.
So what I think that I've done is created a VLAN with ID of "6" on the 3COM 2952 switch, and used the ports 1-16 for that VLAN. I believe that I have them TAGGED, and the rest of the ports for that VLAN are non-members. Then I used the default VLAN 1 and did sort of the opposite, except I didn't have them TAGGED, I set them to UNTAGGED.
Next on the other switch, a 3COM 2948, I created VLAN 6 on there, and pointed it to just 1 port (10) and connected an ethernet cable from that port to our external internet switch (8-port). Looking at the settings on that 8-port managed switch, I found out that I can set up VLANs there as well.
Basically I'm wanting to wall off the first 16 ports on that first switch, and give direct access to the internet. I don't want any computers connected to those ports to see the rest of our network, nor do I want our network to see those computers, however I still want management capabilities.
What am I doing wrong? Do I need to set up a VLAN on EACH switch in between? I read about trunking and think I tried doing it, but there's not much reliable help on the internet regarding the same type of situation that I'm in.
I posted an attachment of a layout of our network segment. As of right now, I can manage the first switch from anywhere, and can only see things connected to ports 17-52.
I've been assigned the task of getting straight internet access to a certain range of ports on a switch. I was told that using a VLAN would be the best solution. So I've done some research and am thoroughly confused. We don't use any VLAN's in our current network setup, and all of the switches that we use are different models of 3COM or Cisco, so the VLAN language is different for each switch.
So what I think that I've done is created a VLAN with ID of "6" on the 3COM 2952 switch, and used the ports 1-16 for that VLAN. I believe that I have them TAGGED, and the rest of the ports for that VLAN are non-members. Then I used the default VLAN 1 and did sort of the opposite, except I didn't have them TAGGED, I set them to UNTAGGED.
Next on the other switch, a 3COM 2948, I created VLAN 6 on there, and pointed it to just 1 port (10) and connected an ethernet cable from that port to our external internet switch (8-port). Looking at the settings on that 8-port managed switch, I found out that I can set up VLANs there as well.
Basically I'm wanting to wall off the first 16 ports on that first switch, and give direct access to the internet. I don't want any computers connected to those ports to see the rest of our network, nor do I want our network to see those computers, however I still want management capabilities.
What am I doing wrong? Do I need to set up a VLAN on EACH switch in between? I read about trunking and think I tried doing it, but there's not much reliable help on the internet regarding the same type of situation that I'm in.
I posted an attachment of a layout of our network segment. As of right now, I can manage the first switch from anywhere, and can only see things connected to ports 17-52.