Go Back   PCMech Forums > Help & Discussion > Networking & Online Security

Need Some Help? Type Your Keywords Here:

Reply
 
LinkBack Thread Tools Search this Thread Rate Thread Display Modes
Old 06-11-2003, 03:07 PM   #1
Member (12 bit)
 
Mr N8's Avatar
 
Join Date: Sep 2001
Location: Racine, WI
Posts: 2,094
Send a message via AIM to Mr N8 Send a message via Yahoo to Mr N8
Seperating Networks

I'm drawing a blank when it comes to this one.

The situation is that I have my main network on a series of switches that have access to our ISP router and our WAN router. This lets them see our 8 branches, all of our server, and have internet access. Marketing is on their own switch for file sharing, and they have dial-up connections for internet access.

What I want to do is give marketing access to our ISP router, since we have a t1, but not let them see the rest of the network.

What software or hardware would I need to do this. Attached is a rough sketch of what it currently looks like. Thanks.
Attached Images
File Type: gif net.gif (18.7 KB, 78 views)
Mr N8 is offline   Reply With Quote
Old 06-11-2003, 03:21 PM   #2
I am, in reality, a moose
Staff
Premium Member
 
mbossman2's Avatar
 
Join Date: Aug 1999
Location: RTP, NC
Posts: 2,439
Create a VLAN with just the marketing folks on it and another VLAN with everybody else. then trunk the uplink port from the marketing switch to the main network stack switch(es) and then trunk from that switch to the router. I see you are using Cisco, you can use the Cisco Cluster Management software to accomplish most of this, use the security wizard, this is a common task.

Couple of keys here:

1) make sure all switches support 802.1q trunking (most do)
2) make sure that the router itself supports 802.1q trunking (low end routers don't, but higher end ones may)
3) reconfigure the router to make sure that it is aware that there are 2 networks behind it (Marketing VLAN and the one with everybody else on it).
4) Make sure that you build in the ACL a (non) permission that does not allow the marketing folks to use the router as a layer 3 switch and jump back over to the part of the network you don't want them to access

HTH.
__________________
Veritas Principium Libertas

Traveling Moose
mbossman2 is offline   Reply With Quote
Old 06-11-2003, 04:39 PM   #3
Member (12 bit)
 
Mr N8's Avatar
 
Join Date: Sep 2001
Location: Racine, WI
Posts: 2,094
Send a message via AIM to Mr N8 Send a message via Yahoo to Mr N8
Thanks. I'll try it out, and see if I still have a job when I'm finished!
Mr N8 is offline   Reply With Quote
Reply

Bookmarks

Still Need Help? Type Your Keywords Here:


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 02:07 PM.
Powered by vBulletin® Version 3.8.6
Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.6.0