- Community Home
- >
- Networking
- >
- Legacy
- >
- Switches, Hubs, Modems
- >
- Re: 5406zl: VLAN Routing between some VLAN's but n...
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Discussions
Discussions
Forums
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-09-2006 03:01 AM
тАО11-09-2006 03:01 AM
We are considering the 5406zl-48G.
I've been studying the mauals. After enabling IP routing all VLAN can access each other.
That what we want. But wwhat to do I you don't want a VLAN to be able to see/access some of the other VLANS. Like a guest VLAN that will be handled by an external firewall/router.
Is it as simple as not assigning an IP address to that VLAN and then that VLAN isn't routed?
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-09-2006 08:51 AM
тАО11-09-2006 08:51 AM
SolutionAccess and inter-communication between VLANS can be controlled by access-lists, which are placed within the VLAN configuration context.
You can control the access and inter-communication between the VLANS like any other access-list either standard or extended, which can be configured to control inbound and outbound traffic.
an example of which is:
To permit inbound traffic to VLAN 10(192.168.10.0/24) routed from IP address 192.168.20./24(VLAN20).
Procurve 5406xl(config)#ip access-list extended test1
Procurve 5406xl(config-ext-nacl)#10 permit ip 192.168.10.0 0.0.0.255 0.0.0.0 255.255.255.255
Procurve 5406xl(config)#vlan 10
Procurve 5406xl(vlan-10)#ip address 192.168.10.1/24
Procurve 5406xl(vlan-10)#ip access-group test1 in
Procurve 5406xl(config)#vlan 20
Procurve 5406xl(vlan-10)#ip address 192.168.20.1/24
Procurve 5406xl(config)#ip routing
I hope this helps.
Jase
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-09-2006 09:05 AM
тАО11-09-2006 09:05 AM
Re: 5406zl: VLAN Routing between some VLAN's but not others
for further info on the configuration of ACL's for VLANS see module/chapter 7 of the following document;
ftp://ftp.hp.com/pub/networking/software/3500_5400_6200_AdvTrfGde-July2006-59913827.pdf
Regards,
Jase
P.S. if you have any more questions on the 5400zl just post them under this thread.
But I highly recommend the 5400zl, this is an excellent Layer3/4 switch, with a mass of features.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-09-2006 09:40 AM
тАО11-09-2006 09:40 AM
Re: 5406zl: VLAN Routing between some VLAN's but not others
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-09-2006 10:47 PM
тАО11-09-2006 10:47 PM
Re: 5406zl: VLAN Routing between some VLAN's but not others
The IP of the router that allows internet access for the clients in that VLAN should be the default gateway for these PCs. One link untagged in that VLAN sould go to the router, and the inside interface of the router should have IP in the same subnet with the PCs. That router should not be connected to any other VLAN, so it can't perform inter-VLAN routing.