× NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Orbi WiFi 7 RBE973
Reply

Are Private VLANs what I need?

sjhx
Aspirant

Are Private VLANs what I need?

I have a M4100-D12G with 2 subnets.

 

I would like to have subnet1 on ports 1-4 and subnet2 on ports 5-12 and not have any traffic travel between these.

I think private (community mode) VLANs are what's needed? Would this do what I wanted?

 

Simon.

Message 1 of 7
MikeD1234
NETGEAR Expert

Re: Are Private VLANs what I need?

Hi @sjhx,

Private VLANs, are as followed:

Private VLAN group allows you to create groups of users within a VLAN that cannot communicate with members in different groups but only within the same group.

Also see page #316 from the manual: ProSAFE M4100 Managed Switch Software Administration Manual Software Version 10.0.1 (netgear.com)

So, in this instance, they would share the same IP scheme (subnet), but the switch can allow or disallow them to communicate together, based on which group they are in.

From the sounds of it, you want regular VLANs, so then you need to have VLANs (DHCP etc.) configured at an end-point (i.e., Firewall, or on the M4100 DHCP), and then setup your VLANs.

Then, your firewall needs static routes, or, be VLAN aware, for routing.

Mike

Message 2 of 7
schumaku
Guru

Re: Are Private VLANs what I need?

Just two VLANs and no in case inter-VLAN routing enabled would not be sufficient?

Message 3 of 7
MikeD1234
NETGEAR Expert

Re: Are Private VLANs what I need?

Yes, two VLANs might work, but if they need to communicate something needs to be aware of it, and have an L3 interface for it.

Not sure if they have the option for that. Then, the option wouldn't be to bad, but if in case they need different subnets etc. a firewall/router or the switch with interfaces should do the trick.

Message 4 of 7
sjhx
Aspirant

Re: Are Private VLANs what I need?

Private VLAN group allows you to create groups of users within a VLAN that cannot communicate with members in different groups but only within the same group.

 

I think this is what I need. My subnet1 is 2 audio mixing consoles, plus wired and wireless remote controlers. I could have the ffirst 4 ports as group1 and the other 8 as group2.

 

This would be the same as using 2 separate switches?

Message 5 of 7
schumaku
Guru

Re: Are Private VLANs what I need?

Exactly what normal VLAN are used for.

Message 6 of 7
MikeD1234
NETGEAR Expert

Re: Are Private VLANs what I need?

Hi @sjhx,

yes, if you only have one subnet, and can't setup static routes/routing/vlans on your Firewall/router, then this could be a solution.

As @schumaku says, it's kind of the same as VLANs, and a more graceful solution would probably be using different subnet/VLANs, to differentiate between them with VLAN + IP scheme.

Your router/firewall, often should support static routes, and it's not to hard to configure once you have the routing to your switch configured correctly.

Mike

Message 7 of 7
Top Contributors
Discussion stats
  • 6 replies
  • 514 views
  • 0 kudos
  • 3 in conversation
Announcements