View Full Version : Segmenting Networks
DJ_Evergreen
14 Nov 2007, 6:24pm
Hello all,
I am trying to setup two networks so the two networks cannot communicate to each other but both networks can have internet access.
Here's my network diagram:
http://img61.imageshack.us/img61/1140/networksetupsl3.png
Router0 is a Ovislink SR-401E and Router1 is a WRT54G Router.
Right now Network 1 and Network 2 can both communicate to each other. I thought that setting it up this way would prevent this, but it doesn't. Does anyone know how this would be possible?
kryyst
14 Nov 2007, 6:37pm
In this configuration if you've just setup Router1 to point to router 0 as it's gateway and done nothing else then Network 2 should be able to see network 1 computers because it's wan and their ip's are on the same network. But network 1 shouldn't be able to see any devices on network 2 unless you are port forwarding them. Though it would be able to see Router 1. If you don't want network 1 or 2 devices to see each other you'd need another router to segment off network 1.
manuleka
15 Nov 2007, 12:45am
how about connecting them both to router 0?
DJ_Evergreen
15 Nov 2007, 1:03am
how about connecting them both to router 0?
That's what I'd like to do but router0 only has two interfaces.
Hmm... Looks like i'll have to throw another router in the mix... Perhaps this would work?
http://img221.imageshack.us/img221/7647/networksetup2vt2.png
RyderOCZ
15 Nov 2007, 1:15am
Each router is "NAT'ing" so each of the networks can talk to each other.
What are the default gateway's listed for each network?
Are the switches you are using managed or unmanaged?
kryyst
15 Nov 2007, 1:00pm
You second example will definitely do what you want it to do.
DJ_Evergreen
18 Nov 2007, 3:26am
So I was able to setup my network today like in the last picture I posted and it works! Thanks everyone for your input.
Kinetik
13 Dec 2007, 11:45pm
Glad it works. Could just use VLans in the future ;)
GrayFox
15 Dec 2007, 4:03pm
To prevent them from talking to each other you can use ACL's.
Also you should make use of 802.1Q. With that you can do all this with one router and one interface.
vBulletin® v3.8.1, Copyright ©2000-2009, Jelsoft Enterprises Ltd.