Orbi WiFi 7 RBE973
Reply

Intervlan acces to single ip.

de-error
Aspirant

Intervlan acces to single ip.

Hello Community,

 

I am strugling with this for many hours now..

 

I have a network which is seperated in many Vlans.

In one of the Vlan's (110) there is a server which must be reachable from another vlan (120).

Enabling 'intervlan connect' does the job but this allows all trafic between the two subnets.

 

What is the smartest way to make this one host reachable from onother vlan?

 

I hope somebody knows.

 

Warm greetings,

Marco

 

 

 

 

Model: SRX5308|PROSAFE Gigabit Quad WAN SSL & IPSEC VPN Firewall
Message 1 of 18
DaneA
NETGEAR Employee Retired

Re: Intervlan acces to single ip.

Hi de-error,

 

Welcome to the community! 🙂

 

You may create another VLAN, let say for example VLAN130.  You may set the server on VLAN110 and the members of VLAN120 (that needs access to the server) as members of VLAN130.  

 

Another is, if ever the server has 2 ethernet ports, you may connect the first ethernet port to VLAN 110 then connect the second ethernet port to VLAN 120.  

 

 

Regards,

 

DaneA

NETGEAR Community Team

Message 2 of 18
de-error
Aspirant

Re: Intervlan acces to single ip.

 Thx DaneA for your reply.

 

The server has only one ethernet port and the software won't allow me to make it a member of multiple vlans's

 

Can you explain your answer a bit further? Is it a firewall setting you are talking about?

I don't understand how I would make the complete Vlan120 subnet and the server a member of a new Vlan.

I tried static routing but that did not help me till now. Maybe I'm doing something wrong.

 

Warm greetings,

Marco

 

Message 3 of 18
DaneA
NETGEAR Employee Retired

Re: Intervlan acces to single ip.

Hi de-error,

 

I have assumed that you are using a switch because my answer is applicable if you are using a switch.  Sorry for I have assumed. 😞   I should have asked you this first: what NETGEAR device/model are you using?

 

 

Regards,

 

DaneA

NETGEAR Community Team

 

 

Message 4 of 18
de-error
Aspirant

Re: Intervlan acces to single ip.

I use a SRX5308 as router and I use 3x GS752TXS as switch.

 

Most of the, if not all, clients are wifi users on a open bssid atached to vlan 120.

The ports where the AP's are connected are tagged on all vlans since I have many bssid on my AP's atached to those vlans.

I don't have a clue how to configure those ports so there is intervlan connect between 110 and 120.

 

warm greetings,

Marco

 

Message 5 of 18
JohnRo
NETGEAR Employee Retired

Re: Intervlan acces to single ip.

Hello de-error, 

 

With DaneA's suggestion, the interVLAN connection is not anymore necessary. All changes will be made on the switches, all you need to do is to add another VLAN (example mention VLAN130) once done add the server as a member of VLAN130 along with the other device(s) that needs access to the switch. This will let the devices talk to the server without letting the two subnets talk. 

 

Let us know if you have more questions. 

 

Thanks, 

Message 6 of 18
de-error
Aspirant

Re: Intervlan acces to single ip.

Hello JohnRo,

Can you tell me how to do that on the switches?

Warm greetings,

Marco

Message 7 of 18
JohnRo
NETGEAR Employee Retired

Re: Intervlan acces to single ip.

Hello de-error, 

 

There's nothing special actually, you'll just have to add another VLAN. Click here (go to page 97) for instructions on how to create a VLAN. For better understanding on what DaneA's suggestion is, I have an example below: 

 

VLAN10 - Server and network with 192.168.10.x IP

VLAN20 - Computers that needs to access the server and network with 192.168.20.x IP 

 

Problem: The computers needs to access the server but restrict other devices from each subnet to communicate. 

 

Solution: Add VLAN30 - members of VLAN 30 will be Server and Computers that needs access to server. 

 

You will have to make the Server a member of both VLAN10 and VLAN 30. Then, make the Computers that needs access to the server a member of both VLAN20 and VLAN30. 

 

After doing so, you will enable inter-VLAN routing on VLAN20 and VLAN30. 

 

Thanks, 

 

 

Message 8 of 18
de-error
Aspirant

Re: Intervlan acces to single ip.

Hello JohnRo,

 

Now I get it... Unfortunately this answers does not solve my issue.

The server that I use (it's actualy a wifi controller) does not have the abillity to be a member of two vlans.

And the clients can't be configured that way since it's a public network.

I do not have the acces (or the will 😉 to configure all clients that visit the network.

 

This information is already written above but maybe it's misunderstood.

I'm gonna try to rephrase my question:

 

When I enable intervlan connect in the SRX5308 the traffic I need is possible between the guest clients and the server (wifi controller). But this makes all traffic possible between the two Vlan's. I want to restrict the rest of the trafic between the Vlans exept access to the server. The Vlan where the server is in is the same vlan as all my essential devices are in (router, switches, AP's ect...) so I realy want to prevent unnecesary access to those devices.

 

I hope this clears things up...

 

Warm greetings,

Marco

 

 

 

 

Message 9 of 18
DaneA
NETGEAR Employee Retired

Re: Intervlan acces to single ip.

Hi de-error,

 

Is the WiFi controller a NETGEAR device also?  If yes, what is the exact model and the current firmware version of it?

 

 

Regards,

 

DaneA

NETGEAR Community Team

 

 

Message 10 of 18
de-error
Aspirant

Re: Intervlan acces to single ip.

Hi DanaA,

 

No, the wifi controller is a Ruckus Wirelles Zonedirector 1200.

Unfortunately It's not possible to enable another Vlan on this controller.

 

Warm greetings,

Marco

 

Message 11 of 18
DaneA
NETGEAR Employee Retired

Re: Intervlan acces to single ip.

Hi de-error,

 

Kindly post a screenshot or image of your current network setup for us to check if your goal can be achieve.  Make it detailed as possible.

 

 

Regards,

 

DaneA

NETGEAR Community Team

 

 

 

Message 12 of 18
de-error
Aspirant

Re: Intervlan acces to single ip.

Hello DaneA,

 

It's a very complicated network so that is gonna take me a while.

I was actualy counting on a solution within the SRX5308 with a firewallrule or something.

Isn't the SRX5308 capable of doing this?

 

Warm greetings,

Marco

Message 13 of 18
DaneA
NETGEAR Employee Retired

Re: Intervlan acces to single ip.

Hi de-error,

 

Setting up firewall rule on the SRX5308 is not applicable. For me, the Ruckus wireless controller should be connected to a switch and it should be a member of a Management VLAN configured on a switch.  For references, you can check some examples of deployment scenarios on pages 37-44 of the NETGEAR WC7600 wireless controller here.  

 

 

Regards,

 

DaneA

NETGEAR Community Team

Message 14 of 18
de-error
Aspirant

Re: Intervlan acces to single ip.

The network is already configured the way you describe.

The Controller is in the management VLAN (110) and doing it's job.

So that done. Now I'd like to move to the issue.

 

Clients who connect to VLAN 120 have to access the controler as wel.

So I enabled Intervlan connect.

To prevent acces from the devices on vlan 120 to the rest of my management devices I need a firewall rule or some other solution.

 

How?

Message 15 of 18
DaneA
NETGEAR Employee Retired

Re: Intervlan acces to single ip.

Hi de-error,

 

If ever the Ruckus wireless controller is connected to a port on the switch untagged on VLAN 110 and VLAN routing is enabled between VLAN 110 and VLAN 120 (note that VLAN routing is configured on the switch not on the SRX5308),  setting up access control list on the switch would possibly restrict some users on the VLAN 120 to access the Ruckus wireless controller.   For the the Access Control configuration, kindly check page 209 of the GS752TXS user manual here.  You may contact NETGEAR Support for technical assistance.

 

 

Regards,

 

DaneA
NETGEAR Community Team

 

 

Message 16 of 18
de-error
Aspirant

Re: Intervlan acces to single ip.

I think that does not solve the issue as well since I want to allow all clients on vlan 110 to acces the controller but not to other devices on vlan 110. Do you agree It will be better to get another router/firewall?

 

 

Message 17 of 18
DaneA
NETGEAR Employee Retired

Re: Intervlan acces to single ip.

Hi de-error,

 

You might want to at least try the suggestion I have mentioned about access control list.  For me, it just needs proper network setup and configuration. 

 

 

Regards,

 

DaneA

NETGEAR Community Team  

Message 18 of 18
Top Contributors
Discussion stats
  • 17 replies
  • 5234 views
  • 0 kudos
  • 3 in conversation
Announcements