In article <Xns96F270A768497nntprogerscom@127.0.0.1>,
Lucas Tam <REMOVEnntp@rogers.com> wrote:
Are there any switches that support LAN segmentation by port? (i.e. Port 1
- 12 = 192.168.1.x, Ports 13 - 24 = 192.168.2.x?). Ideally we like to
segment the switch phyiscally (i.e. split a switch in 2, 3, etc?).
I'm pretty sure that any switch that supports VLANs will support port
based VLANs. The other ways of assigning VLANs are more advanced
features and will require a higher-end switch.
Unfortunately our firewall doesn't support VLANs... Can switches do VLAN
routing on their own?
A simple switch cannot route traffic between VLANs but you would be
using your Sonicwall to do that. I think the latest SonicOS does
support VLANs, but this is really only helpful if you want to do
multiple Zones per interface.
Setup a VLAN for each Zone. Each VLAN will have one port which will be
connected to that Zone's interface and other ports to connect to the
users you want in that Zone. If you need to move a user from one Zone
to another you just change the VLAN their port is associated with.
We use 3Com 4200 series switches for this but any VLAN aware switch
should work.
Note that while VLANs can make a single switch appear as several
distinct switches, their focus isn't security. The VLAN separation
inside a switch isn't nearly as secure from attack as actually using
separate switches would be. Closed VLANs are slightly more secure than
Open VLANs, but it may be that neither are secure enough for your needs.
--
Jim Prescott - Computing and Networking Group
jgp@seas.rochester.eduSchool of Engineering and Applied Sciences, University of Rochester, NY