Two connections from router to switch

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

Two connections from router to switch

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
Two connections from router to switch
Two connections from router to switch
2023-11-06 11:52:30
Model: OC200  
Hardware Version: V1
Firmware Version:

Hello,

 

I'm trying to implement the following scenario, but don't see a solution because I always need to set a native network which causes a switching loop.

 

I would like to connect my Router (ER7206) to my switch via Port 1.

- on the switch the Port is configured to handle all my VLANs as tagged and the native VLAN is set to 1.

 

Besides this configuration I would like to connect Port 2 of the Router to a second port on the switch.

- here only one specific VLAN shall be active (for honeypot traffic)

- the physical seperation is important, because I have a probe inbetween this connection where I monitor all traffic.

- also I want to be able to physically cut the connection if needed without interuption of the other traffic.

 

Normally I would set the VLAN on this second connection to e.g. 100 and it would work. But here I need to set another VLAN as native, which causes problems. It seems that I create a switching loop.

Any solution for this?

BR
Sebastian

  0      
  0      
#1
Options
6 Reply
Re:Two connections from router to switch
2023-11-07 06:53:20

  @SebastianH 

 

I guess you want to set LAG/LACP between ER7206 and the switch, right?

I'm afraid the router doesn't support the LAG.

Just striving to develop myself while helping others.
  0  
  0  
#2
Options
Re:Two connections from router to switch
2023-11-07 07:50:27

  @Virgo not really.

I want to seperate the traffic between the two connections.

One tagged VLAN on link 2 and the other tagged VLANs on link 1.

  0  
  0  
#3
Options
Re:Two connections from router to switch
2023-11-07 13:15:08

  @SebastianH 

 

You may want 2 seperate switches for this setup.  

 

Port 1 on the router VLAN1 (Core VLAN, with ALL tagged) to Switch 1. 

 

Router Port 2 (VLAN 100).  Set VLAN 100 to only that port.  Plug in Switch 2.  

 

That maybe cleaner and easier for you in the long run.  

I can not teach anyone anything - I can only make them think - Socrates
  0  
  0  
#4
Options
Re:Two connections from router to switch
2023-11-07 13:39:16

  @KimcheeGUN 

Don't want to use 2 switches... But what you siad is possible a solution.

To use the connection directly as untagged. Would this be possible?
 to configure the LAN2 on the router as untagged VLAN100 (Switchport VLAN100) and also on the switch as native VLAN100 (and no tagged)?

  0  
  0  
#5
Options
Re:Two connections from router to switch
2023-11-07 15:24:07

  @SebastianH 

 

Maybe easier for you to do ALL profile on the Port1 on the router to port 1 on the switch.

 

Then trunk each port to what ever VLAN you need.  

 

Set all for ALL profile for port 2 for the AP.  Then set Trunk VLAN 2 Profile to Port 3 what a PC.  Just an example.  

I can not teach anyone anything - I can only make them think - Socrates
  0  
  0  
#6
Options
Re:Two connections from router to switch
2023-11-07 17:12:45

  @SebastianH 

 

I haven't done it yet, but have been thinking about this approach, why not isolate 2 ports on your switch, and only allow forwarding between them.  Let's say you isolate ports 5 and 6.  Connect port 5 to your 7206 and port 6 to your honeypot device (or tag it to whatever VLAN is needed, and then loop that into a 3rd port on your switch)?  Ugly, but should take care of re-writing your VLAN tags without causing looping--but expensive ports wise.

<< Paying it forward, one juicy problem at a time... >>
  0  
  0  
#7
Options