• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

Dash's new untangle & Vlans

dashpuppy

Supreme [H]ardness
Joined
May 5, 2010
Messages
6,163
Got me a new toy over the weekend, Power Connect 5224 24 port gigabit managed switch :) needs new fan's but that is VERY easy for me to cure.



Can any one explain or help me build vlans that are supported with untangle, id like to setup a new network using my new Dell Power Connect 5224 24 port managed gigabit switch.

I was told that i have to do them at the switch level, what ever that means etc etc. I don't know if untangle handles tagged or not tagged.

VERY NEW to vlans etc etc, so im learning, i have a separate new untangle 9.0 box and this power connect switch to learn with, when i'm done learning i will re-do it, then install it at home :) ( hopefully )

Can any one help ?

YeOldeStonecat, You said this:

I've not done separate LANs from within Untangle....I do them via a managed switch behind Untangle. But if you wanted to do it within Untangle..gotta get an appliance that has multiple NICs for your LAN side...and put a rack on each NIC.
 
Some pictures :)

Unit after cover was removed and fans removed, was consoled in to update firmware.

DSCN2915.JPG


New fan's SILENT but move tons of air.

DSCN2917.JPG


Logged into unit :)

DSCN2919.JPG
 
I had that exact Dell switch and man was it noisy! I use it in our server room at work now for my test network and even over the SAN / servers / aircon / cab fans I can stil hear that switch!

I replaced it at home with a HP Procurve 1800-24

I would be careful replacing PSU fans in this way as there is a chance of fire.
 
Does that switch do port based VLANs? If so...
Untangle green NIC into port 1
Now...for example, take ports 2-5 on that switch, called it VLAN1...make port 1 a member of that VLAN.
Take ports 6-10, call that VLAN2, make port 1 a member of that VLAN too
Take ports 11-15...call them VLAN3, make port 1 a member that VLAN too.

Any computer plugged into one of the VLANs cannot communicate with members of other VLANs. And visa versa.

Yet..since port 1..which leads to Untangle, is a member of every VLAN, naturally they all can use Untangle/the gateway.
 
Does that switch do port based VLANs? If so...
Untangle green NIC into port 1
Now...for example, take ports 2-5 on that switch, called it VLAN1...make port 1 a member of that VLAN.
Take ports 6-10, call that VLAN2, make port 1 a member of that VLAN too
Take ports 11-15...call them VLAN3, make port 1 a member that VLAN too.

Any computer plugged into one of the VLANs cannot communicate with members of other VLANs. And visa versa.

Yet..since port 1..which leads to Untangle, is a member of every VLAN, naturally they all can use Untangle/the gateway.

That's what i want to do :) Can i assign each port ( 6-10 _ and 11-15 different ip subnets tho ? or are they all on the same subnet ?
 
That's what i want to do :) Can i assign each port ( 6-10 _ and 11-15 different ip subnets tho ? or are they all on the same subnet ?

Stonecat's post will have them on the same subnet.

If you want them on different subnets you'd have to create virtual interfaces on the Untangle that bridge to the physical NIC. Each virtual interface would be a vlan's (that has a different subnet) gateway. There would also be some option to specify a VLAN ID. Thats VLAN tagging. I just did this last week on the pfsense box at work. I dont know if Untangle supports this stuff.

Have you ever heard of router on a stick? Same concept.
http://www.networkstraining.com/cisco-router-on-a-stick-with-switch/
 
Stonecat's post will have them on the same subnet.

If you want them on different subnets you'd have to create virtual interfaces on the Untangle that bridge to the physical NIC. Each virtual interface would be a vlan's (that has a different subnet) gateway. There would also be some option to specify a VLAN ID. Thats VLAN tagging. I just did this last week on the pfsense box at work. I dont know if Untangle supports this stuff.

Have you ever heard of router on a stick? Same concept.
http://www.networkstraining.com/cisco-router-on-a-stick-with-switch/

I might swap over to pfsense 2.0

Ideally id like to use the fiber ports, i know its still 1 gig but i have all the cables and proper things, EXCEPT the NIC that goes in the firewall i'm building, but that will be bought soon.

Hoping to buy a atom box with front mounted ports and lights switches etc etc, then I need pci-e fiber Ethernet card.
 
I might swap over to pfsense 2.0

Ideally id like to use the fiber ports, i know its still 1 gig but i have all the cables and proper things, EXCEPT the NIC that goes in the firewall i'm building, but that will be bought soon.

Hoping to buy a atom box with front mounted ports and lights switches etc etc, then I need pci-e fiber Ethernet card.

If you switch over to pfsense 2.0 for the love of god find a stable release and stick with it. I was on a rock stable build of RC2 beta. Then RC3 was released and once again... half my services wont start and the country block is all f'ed up which is leading to lots of spam on my forums :mad:

Was supposed to rebuild the thing this weekend, but re-doing the bathroom became my top priority, thanks to the g/f inviting over a house full of people today :mad::mad::mad::mad::mad::mad::mad::mad::mad::mad::mad:
 
If you switch over to pfsense 2.0 for the love of god find a stable release and stick with it. I was on a rock stable build of RC2 beta. Then RC3 was released and once again... half my services wont start and the country block is all f'ed up which is leading to lots of spam on my forums :mad:

Was supposed to rebuild the thing this weekend, but re-doing the bathroom became my top priority, thanks to the g/f inviting over a house full of people today :mad::mad::mad::mad::mad::mad::mad::mad::mad::mad::mad:

is 2.0 stable ? I love my untangle, but i want to eliminate 3 switches in my rack, and have my 3 sub-nets for security.
 
Fresh installs of any release have always been good for me. Its the inplace upgrades that seem to f' everything up. This on more than one occasion.

I wish I would have taken notice to which RC2 release i was on installed before RC3. That one ran great. After going to RC3 though the router gui seems really slow, packages wont start. I need a fresh install.
 
Speaking of untangle, I need to pop in a different nic into mine. I have some broadcoms in there now and a spare intel dual port. I don't think I have a low pro bracket though:(
 
Speaking of untangle, I need to pop in a different nic into mine. I have some broadcoms in there now and a spare intel dual port. I don't think I have a low pro bracket though:(

They are too hard to make. Sheers, clamp (preferably a vice), plyers, and a drill.
 
Despise the Free Lunch

What is offered for free is dangerous – it usually involves either a trick or a hidden obligation. What has worth is worth paying for. By paying your own way you stay clear of gratitude, guilt, and deceit. It is also often wise to pay the full price – there is no cutting corners with excellence. Be lavish with your money and keep it circulating, for generosity is a sign and a magnet for power.
 
Despise the Free Lunch

What is offered for free is dangerous – it usually involves either a trick or a hidden obligation. What has worth is worth paying for. By paying your own way you stay clear of gratitude, guilt, and deceit. It is also often wise to pay the full price – there is no cutting corners with excellence. Be lavish with your money and keep it circulating, for generosity is a sign and a magnet for power.

you have helped me out lots so I was returning the favor you dink!
 
That's what i want to do :) Can i assign each port ( 6-10 _ and 11-15 different ip subnets tho ? or are they all on the same subnet ?

You can if you want...dunno why you want to though, for SMB anyways. I'm not separating using subnets, I'm separating using port based VLANs in the switch itself. The switch creates a wall, or barrier, between VLANs you create. It doesn't matter that computers in VLAN 1 might be 192.168.1.103 and a computer in VLAN 2 will be 192.168.1.105....they still literally cannot pass traffic in between each other. The only thing they share is port 1...which is their gateway...going to the internet. Windows routing uses a gateway for traffic outside of the LAN.
 
You can if you want...dunno why you want to though, for SMB anyways. I'm not separating using subnets, I'm separating using port based VLANs in the switch itself. The switch creates a wall, or barrier, between VLANs you create. It doesn't matter that computers in VLAN 1 might be 192.168.1.103 and a computer in VLAN 2 will be 192.168.1.105....they still literally cannot pass traffic in between each other. The only thing they share is port 1...which is their gateway...going to the internet. Windows routing uses a gateway for traffic outside of the LAN.

Maybe that would be a better way to do it :) just have all the computers on .2.x and then do port based vlans.
 
Each VLAN should have its own subnet anyways. Now you can do /25 or /26, etc and still have the same overall /24 or /16.

I am not sure if that Dell switch will do it, but on the HPs I worked with you set the default route for the VLANs to something on VLAN 1 (or 2, or where ever you put your gateway).

For example:

Port 1 is untagged VLAN 1 tagged VLAN 2, and VLAN 3
Port 2 - 8 is untagged VLAN 2, tagged VLAN 3 and VLAN 1
Port 9 - 12 is untagged VLAN 3, tagged VLAN 1, and VLAN 2
Port 13 - 20 is untagged VLAN 1, tagged VLAN 2 and VLAN 3

VLAN 1: 192.168.36.0/24
VLAN 2: 10.10.36.0/2
VLAN 3: 172.16.36.0/24
Default gateway to the Internet: 10.10.36.1
MPLS gateway: 172.16.36.2

ip route 172.16.38.0 255.255.255.0 172.16.36.2
ip route 10.10.38.0 255.255.255.0 172.16.36.2
ip route 0.0.0.0 0.0.0.0 10.10.36.1

The switch will route between the VLANs if routing is turned on.

Devices plugged into ports 1, 13 - 20 would get an IP address of 192.168.36.x.
Devices plugged into ports 2 - 8 would get an IP address on 10.10.36.x
Devices plugged into ports 9 - 12 woudl get an IP address of 172.16.36.x

If your DC has multiple NICs you can put each one on a VLAN port, and have it serve up DHCP for all three VLANs.

Again my experience is with the HP switches.
 
Last edited:
keep in mind that ports can only be assigned to one vlan as untagged. but a single port can belong to multiple vlans as a tagged interface. if you are using port one as your "gateway." you would have it belong to VLAN1 as a untagged interface and VLAN2 as a tagged interface. Then the device you connect to port 1 (a router of some sort) would need to have an interface that is capable of decoding 802.1q traffic.

when a port is assgined to a vlan as tagged, the vlan header on the packet is remains and it is up to the connected device (such as router or "router a on stick") to decode and properly handle those tagged packets. an untaged port is where the switch strips the vlan header before it is passed to the interface. your laptop, desktop, game system... would connect to these ports.

if you have your untagle box connected to port 1 of the switch, the nic on the untagle box needs to be configured to handle 802.1q traffic. In order for traffic routing to work between the two vlans, they both needs to be on separate subnets.

i hope that all made sense....
 
Untangle doesn't support VLAN tagging....they're stripped off by Untangle. Hence my only doing port based...and I've always done them in the same subnet..since I'm just doing SMB (<255 computers, so class C networks).
 
Untangle doesn't support VLAN tagging....they're stripped off by Untangle. Hence my only doing port based...and I've always done them in the same subnet..since I'm just doing SMB (<255 computers, so class C networks).

exactly why i have been playing with pfsense, to learn these vlans and stuff.
 
keep in mind that ports can only be assigned to one vlan as untagged. but a single port can belong to multiple vlans as a tagged interface. if you are using port one as your "gateway." you would have it belong to VLAN1 as a untagged interface and VLAN2 as a tagged interface. Then the device you connect to port 1 (a router of some sort) would need to have an interface that is capable of decoding 802.1q traffic.
.

Sorry, I was trying to type that quickly before heading to lunch, and flipped tagged and untagged.


Untangle doesn't support VLAN tagging....they're stripped off by Untangle. Hence my only doing port based...and I've always done them in the same subnet..since I'm just doing SMB (<255 computers, so class C networks).

It wouldn't really matter. Untangle would just need to know what to do with the other IP addresses. So it would need to know that it should hand off anything for 192.168.36.x to 10.10.36.254, and anything for 172.16.36.x to 10.10.36.254 also (if the IP addresses of the switch were 192.168.36.254, 172.16.36.254, and 10.10.36.254). Then let the switch do all the internal routing.

If the switch will do routing it makes it easier internally to just let it do its thing and any devices (like PCs) that don't understand VLANs don't need to know about it. The switch does, but nothing else on the network does.

However I think we are saying the same things, just different ways of looking at it. I tend to look at it from a switch/router point of view, as opposed to device view.
 
It would matter to me come time to manage the LAN..for the purpose of SMB.

What will do DHCP? Instead of having just 1x subnet (say..192.168.10.xxx)...what will manage multiple subnets now?

Say you gotta setup VPN for remote access...single subnet, or multiple policies now?
 
I can see that. I was managing a 300 person lan, with 5 domestic locations running VoIP on VLAN 3, and we were rolling out a SAN into VLAN 4. So my experience is more in Enterprise areas rather than Small Businesses.
 
Back
Top