Recommended Posts

That isn't a layer 3 switch that supports that. You would need a layer 4 to block/allow tcp ports like port 80.

True, but Layer 3 switches can do basic ACLs which is all that is really needed in this situation....we need to know the switch that the OP would intend to use for this solution.

True, but Layer 3 switches can do basic ACLs which is all that is really needed in this situation....we need to know the switch that the OP would intend to use for this solution.

You would have to look through but it is a layer 3 he said.

The OP question was vague at best.. Are vlans secure?

As posted already - "secure from what standpoint?"

Are there attacks against vlans - sure, can most of them be mitigated, again sure.. In what context and what risks are you concerned? Without some details of context and from what standpoint we can go round and round for weeks.

Most companies use vlans, and are considered "secure" enough for most business use.

The OP question was vague at best.. Are vlans secure?

As posted already - "secure from what standpoint?"

Are there attacks against vlans - sure, can most of them be mitigated, again sure.. In what context and what risks are you concerned? Without some details of context and from what standpoint we can go round and round for weeks.

Most companies use vlans, and are considered "secure" enough for most business use.

maybe you guys think too deep into the secureness ....

my approach is toward internal staff and guess.

yes i know there are certain attack that are able to penetrate vlans but tat is not what i am looking for.

my question is sort of simple, creating multiple vlans on a single switch(layer 3) that house staff,servers and guess connection.

what i want to achieve is that, servers are in 1 vlan and staff in 1 vlan and guess in 1 vlan

sort of some isolation where broadcasting will not be seen in either of them.

or should them be on seperate switch each with its own vlan.

which approach is better.

The depth of security depends on the need or how the individual perceives security. The requirement is different between securing your house or securing a government facility. By asking questions and entertaining different scenarios shows this.

You are fine if you are protecting your house by using a layer 3 switch to segment the networks. You may want a bit more if you are attempting to secure a government facility or a school (kids like to tinker a lot and really push what you think you know about security).

what i want to achieve is that, servers are in 1 vlan and staff in 1 vlan and guess in 1 vlan

sort of some isolation where broadcasting will not be seen in either of them.

But as you said one of them servers needs to be accessed by staff so if you have them in different VLAN they can?t access it unless you do bridging which is a more setup.

"if you have them in different VLAN they can?t access it unless you do bridging"

What?? You do not need to bridge to access other vlans, you would ROUTE between the vlans would be the normal way. This would normally be done on the switch with intervlan routing, or with each vlan having a connection to your router/firewall that would handle the routing between them.

Now depending on what is doing this routing would determine how granular you could get on your access controls. If what is routing has firewall features then you could prevent access on all kinds of things. You could limit access to IPs based upon port, you could limit on source IP. Depending on the feature set of your firewall you could even do some layer7 filtering if so desired. But no bridging is not a normal way to allow access between vlans.

They are completely different.. Your vlans would normally be on completely different L3 (ip) address space, so bridging traffic would most likely not even work.

Bridging is L2 and routing is L3 - why would you bridge in his setup??

Now if for some odd reason his vlans were using the same IP space, then sure you could bridge the traffic.. BUT would be the point - if he was going to do that, then he might as well just put them on the same vlan.

I never wanted the OP to do bridge I only put that in to keep sc302 happy or we go off on ?server 1 can be on vlan2 and workstations can be on vlan5, vlan2 can access vlan5 and vice versa.? again which fine you can do that with bridging/routing.

All I said was:

Any computer or server needing to access each other needs to be on the same VLAN.

Any computer or server not needing to access each other can be put in a different VLAN.

And pages later we are here I was just trying to make it simple for the OP.

If you are going to drag me into this again....

they do not need to be in the same vlan to have access to each other. You create a rule in the switch to deny access. all vlans, by default in a layer3 switch, have access to eachother if they are routable...how do you make one routable you may ask, give the vlan an IP address. You need to create a rule to deny access from 1 vlan to another, that is it...it is that simple.

and just so we are all on the same page:

maybe you guys think too deep into the secureness ....

my approach is toward internal staff and guess.

yes i know there are certain attack that are able to penetrate vlans but tat is not what i am looking for.

my question is sort of simple, creating multiple vlans on a single switch(layer 3) that house staff,servers and guess connection.

what i want to achieve is that, servers are in 1 vlan and staff in 1 vlan and guess in 1 vlan

sort of some isolation where broadcasting will not be seen in either of them.

or should them be on seperate switch each with its own vlan.

which approach is better.

and incase you don't know wtf a layer 3 switch is,

http://compnetworking.about.com/od/hardwarenetworkgear/f/layer3switches.htm

"A Layer 3 switch is a high-performance device for network routing. Layer 3 switches actually differ very little from routers. A Layer 3 switch can support the same routing protocols as network routers do. Both inspect incoming packets and make dynamic routing decisions based on the source and destination addresses inside. Both types of boxes share a similar appearance."

"Any computer or server needing to access each other needs to be on the same VLAN."

This would only be true if there was no routing available.. What kind of network would it be if there was no routing between segments? I would never in a million years think that showing me a network with multiple segments was not routing between them.

And the OP clearly stated

1 of them is a file server which store office files...

the 20 office computer has are able to read/write to a certain directory (eg . Office Doc) in D: drive

So clearly he is routing between the vlans..

And the OP clearly stated

1 of them is a file server which store office files...

the 20 office computer has are able to read/write to a certain directory (eg . Office Doc) in D: drive

So clearly he is routing between the vlans..

No we don't look at what the OP posted here:

https://www.neowin.net/forum/topic/1136988-switch-vlaning-issue/page__st__15__p__595531010#entry595531010

One of the servers is on VLAN 2 with x20 Office PC so clearly no one knows what the OP needs.

I agree, but wtf would you have 4 server nobody gets too. And the guest wireless can go nowhere? Just talk amongst themselves.

The network would be pointless -- again why would you think there is no routing on a network?

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • The flaw with this analysis is that this laptop has a cellphone CPU in it. In the Intel world, that would be an N150 and those are everywhere, even in low end laptops. You can get an N150 based NUC with 16GB RAM and 256GB-512GB SSD... NOT soldered in... for < $500 Canadian (around US$360). The problem is two fold: tech bloggers/writers on most tech site (like this one, ironically) overvalue Apple and apparently aren't in the same earnings class as most regular people. As a result, we get breathless articles about how everyone needs a folding phone when most people just cannot afford one... or really need one. And we get Apple used as the baseline metric regardless of whether that comparison makes any sense. If Dell or HP released a retail laptop with a cellphone motherboard, you'd be all over them for doing that - but Apple does it and it's genius. I see articles suggesting what Samsung - a company that basically started the foldable phone market and has built them for eight years - needs to do to compete with Apple's unreleased, unspecced and unseen folding phone. Sorry, no - if the Neo (really creative name there BTW - still, better than the Go, the other "creative" product name everyone's using) encourages PC makers to make cellphone laptops using lower end ARM processors, we all lose. It's a step backwards and a capitulation to the fact that semiconductor makers and computer OEMs (and tech bloggers) have totally lost the plot.
    • Everyone should install this extension and ignore games that use AI. https://chromewebstore.google....nnigaaeelfkeomjcngmnh?pli=1 https://addons.mozilla.org/en-US/firefox/addon/ai-warning-for-steam/
    • Malwarebytes Anti-Malware 5.6.0.256 by Razvan Serea Malwarebytes is a high performance anti-malware application that thoroughly removes even the most advanced malware and spyware. Malwarebytes version 5.**** brings comprehensive protection against today’s threat landscape so that you can finally replace your traditional antivirus. You can finally replace your traditional antivirus, thanks to a innovative and layered approach to prevent malware infections using a healthy combination of proactive and signature-less technologies. While signatures are still effective against threats like potentially unwanted programs, the majority of malware detection events already come from signature-less technologies like Malwarebytes Anti-Exploit and Malwarebytes Anti-Ransomware; that trend will only continue to grow. For many of you, this is something you already know, since over 50% of the users already run Malwarebytes as their sole security software, without any third-party antivirus. What's new in Malwarebytes 5.****: Unified user experience - For the first time, Malwarebytes now provides a consistent experience across all of our desktop and mobile products courtesy of an all new and reimagined user experience powered by a faster and more responsive UI all managed through an intuitive dashboard. Modern security and privacy integrations - Antivirus and ultra-fast VPN come together seamlessly in one easy-to-use solution. Whether you’re looking for a next-gen VPN to secure your online activity, or harnessing the power of Browser Guard to block ad trackers and scam sites, taking charge of your privacy is simple. Trusted Advisor - Empowers you with real-time insights, easy-to-read protection score and expert guidance that puts you in control over your security and privacy. Malwarebytes 5.6.0.256 changelog: Features and improvements Simplified adding files and folders to the Allow list to make managing your exclusions easier. Improved notifications for Webcam Monitoring. Issues fixed Resolved an issue preventing the Deep Scan results window from displaying when several threats are detected during a scan. Fixed text wrapping issues on the Settings page. Fixed an issue causing tray menu notifications to appear off-screen when using multiple external monitors. Download: Malwarebytes 5.6.0.256 | 436.0 MB (Free, paid upgrade available) Links: Malwarebytes Website | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Steam Next Fest returns with thousands of new demos to try out by Pulasthi Ariyasinghe Valve has been routinely kicking off demo festivals on Steam for years now, and the second drop of 2026 has just opened its doors. It's a great opportunity for any PC gamers to find some interesting games before they release. The June edition of Steam Next Fest is a week-long digital festival including gameplay slices from a large number of indie developers, though a few major publishers are involved this time too. Interested players can use the Next Fest hub page's various sorting and filtering options to easily sort through the hordes of demos available. The top buttons offer quick access to separate and important sorting options, including "By Genre, By Theme, By Feature," with each one offering more granular settings when clicked. At the same time, the built-in Steam tags system is also available below every page to discover new games more quickly. As always, logging in will also enable Steam gamers to utilize Valve's recommendation algorithms to find game demos they might like, specifically, depending on their past play and purchase histories. This time there is even a toggle now to swap between getting a random and personalized selection as Valve collects more data on the available demos. The Charts section is where you can find the most popular demos on the platform right now, offering up the most hyped titles in a simple list. Right at the kickoff, Mistfall Hunter, Empulse, Echoes of Aincrad, Onimusha: Way of the Sword, Over the Hill, Mortal Shell II, and more are trending. Expect this list to change as the week progresses. This edition of the Steam Next Fest is slated to end on June 22 at 10 AM PT. Valve's latest event is now open, and it can be accessed by going to the dedicated hub page here.
    • I lived and breathed MSN Messenger/Windows Live Messenger. Going to the mess.be website (still online with no changes since 2013) to download display pictures etc. I was a beta tester for Messenger Plus! and spent quite a lot of time on the MsgPlus! forums (a read-only copy is still online at https://shoutbox.menthix.net) Some old Neowin articles also https://www.neowin.net/news/messenger-plus-350/ good times but how time flies The main developer of Messenger Plus!, Cyril aka. Patchou has released a game https://store.steampowered.com/app/3275440/Pluralys/
  • Recent Achievements

    • One Year In
      ThatGuyOnline earned a badge
      One Year In
    • Week One Done
      Jeroen Wilms earned a badge
      Week One Done
    • Week One Done
      rolfus earned a badge
      Week One Done
    • One Month Later
      Leroy Jethro Gibbs earned a badge
      One Month Later
    • Conversation Starter
      flexorcist earned a badge
      Conversation Starter
  • Popular Contributors

    1. 1
      +primortal
      505
    2. 2
      +Edouard
      199
    3. 3
      PsYcHoKiLLa
      127
    4. 4
      Steven P.
      82
    5. 5
      ATLien_0
      76
  • Tell a friend

    Love Neowin? Tell a friend!