 | Member with 54 posts. | | |
06-Jul-2009, 10:21 PM
#16 | I finally got it to work. Apparently at least part of the problem was was a cabling issue.
I was not happy with the performance though, as it seemed to take a long time for a host to be able to access the internet from the second layer.
Can anyone think of another way to accomplish what i want? A friend recommended DD-WRT and set up seperate VLANS.
pk | | Senior Member with 1,333 posts. | | Join Date: Mar 2008 Experience: Clueless |
06-Jul-2009, 10:38 PM
#17 | Yes, you can accomplish it in another way. I've never played with DD-WRT so I can't comment there. But I have extensive experience with network devices with this type of native support. The basic setup you would need to do is to create two VLANs to get logical separation of the two areas of your network you want isolated. The router/firewall you use as the common connection to the internet has to support either multiple physical router interfaces where each physical interface is plugged into the respective VLANs. The other method is to use one physical connection for both VLANs into the router/firewall but you'll need to create sub-interfaces or virtual interfaces to allow routing of traffic from the VLANs. You also need ensure the router/firewall does not do inter-VLAN routing. Finally, you need to configure proper NATing which becomes harder if you only have a single public IP.
At the layer 2 level, you'll need either a single managed switch which understands VLAN tagging that's if DD-WRT adheres to the IEEE802.1Q standard. Or you'll have to buy two physical switches and plug each of them to a designated port for the VLAN they are to serve. | | Moderator with 96,672 posts. | | Join Date: Oct 2002 Location: South Eastern PA, USA Experience: Advanced age & experience |
07-Jul-2009, 09:16 AM
#18 | I'm curious as to your issues with the daisy-chained routers, I've done this a number of times and there has been no measurable performance hit on the secondary router.
Are you sure you don't have an MTU issue here? What kind of modem is the primary router connected to, make and model please?
__________________ Remember: Data you don't have at least two copies of is data you don't care about. Microsoft MVP - User Desktop Experience | | Senior Member with 1,333 posts. | | Join Date: Mar 2008 Experience: Clueless |
07-Jul-2009, 09:34 AM
#19 | I agree. Having the routers daisy chained should not impact performance measureably. In fact, my home setup has a Netgear FVS338 as the edge router and a Cisco ASA5505 right behind it. I see no issues with performance. | | Member with 54 posts. | | |
10-Jul-2009, 06:59 PM
#20 | To eliminate any hardware issues with the hand me down router, I bought a new second router (a Netgear WPN824) and hooked it up as planned. Everything seems to be working OK. I left both routers set on DHCP. ROUTER1 getting its IP address and DNS IP’s from the modem (ISP) and ROUTER2 getting its IP and DNS addresses from ROUTER1. I can ping both gateways (192.168.1.1 and 192.168.6.1) from a client on the 1.0 network, but cannot ping a client on the 6.0 network. I cannot ping 192.168.1.1 from a client on the 6.0 network, nor can I ping a client.
Am I good to go? Is this the best method for what i want to do?
I just don't have time to delve into the world of DD-WRT.
PK | | Moderator with 96,672 posts. | | Join Date: Oct 2002 Location: South Eastern PA, USA Experience: Advanced age & experience |
10-Jul-2009, 08:17 PM
#21 | Well, that's pretty much as expected. You are trying to communicate across the NAT layer, the whole point of the NAT layer "firewall" is to prevent outside access to machines on the router. | | Member with 54 posts. | | |
11-Jul-2009, 08:19 AM
#22 | So are you saying that I am successful and this is a way to accomplish my goal of two distinct networks with the same Internet access?
Are there any potential issues i should be aware of?
PK | | Moderator with 96,672 posts. | | Join Date: Oct 2002 Location: South Eastern PA, USA Experience: Advanced age & experience |
11-Jul-2009, 05:01 PM
#23 | You're talking about two networks, yet you're trying to connect between them. Are you trying to isolate network segments or do you want them all to be able to connect to each other? | | Member with 54 posts. | | |
11-Jul-2009, 07:13 PM
#24 | No, thats just it. I am trying to NOT communicate between the two. I want them completely isolated, with no risk of cross contamination.
My not being able to ping is a GOOD thing....right?
PK | | Moderator with 96,672 posts. | | Join Date: Oct 2002 Location: South Eastern PA, USA Experience: Advanced age & experience |
11-Jul-2009, 09:00 PM
#25 | Correct, that's a good thing. |  THIS THREAD HAS EXPIRED.
Are you having the same problem?
We have volunteers ready to answer your question, but first you'll have to join for free. Need help getting started? Check out our Welcome Guide.
|
Smart Search
| Find your solution! | |
Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | | |  WELCOME TO TECH SUPPORT GUY! Are you looking for the solution to your computer problem? Join our site today to ask your question -- for free! Our site is run completely by volunteers who want to help you solve your computer problems. See our Welcome Guide to get started.
| You Are Using: |
Advertisements do not imply our endorsement of that product or service.
All times are GMT -5. The time now is 11:51 AM.
Copyright © 1996 - 2009 TechGuy, Inc. All rights reserved.
Powered by vBulletin, Copyright © 2000 - 2009, Jelsoft Enterprises Ltd. | |
|