T1500G-10PS : is it possible, to allow only http https and whatsapp in vlan‘s
This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
T1500G-10PS : is it possible, to allow only http https and whatsapp in vlan‘s
Model :
Hardware Version :
Firmware Version :
ISP :
Hello.
My planned configuration at home is shown in the following picture. I already have the router, the switch and one EAP330
The router is a FritzBox 7490, which has two different LAN’s. Port 1-3 is the „default LAN“ (IP-Adress 192.168.x.y and on Port 4 is a guest-LAN activated (IP-Adress 172.31.179.x).
This means, that the FritzBox has two DHCP-Services running.
My plan is, to plug Port 1 on the switch to Port 1 on the FritzBox to use this as my family-net. Port 8 on the switch plugs to Port 4 on the FritzBox (own IP-Adress-Range with DHCP).
In the future three AP’s should be connected to the switch and broadcast two SSID’s (guest-net, family-net) with different VLAN-ID’s.
The VLAN-configuration in the switch is:
Port 1: VLAN-ID 1 untagged, VLAN-ID 100 untagged (PVID 1, 100)
Port 2: VLAN-ID 1 untagged
Port 3: VLAN-ID 1 untagged
Port 4: VLAN-ID 1 untagged
Port 5: VLAN-ID 1 untagged, VLAN-ID 100 tagged, VLAN-ID 200 tagged (PVID 1,100,200)
Port 6: VLAN-ID 1 untagged, VLAN-ID 100 tagged, VLAN-ID 200 tagged (PVID 1,100,200)
Port 7: VLAN-ID 1 untagged, VLAN-ID 100 tagged, VLAN-ID 200 tagged (PVID 1,100,200)
Port 8: VLAN-ID 1 untagged, VLAN-ID 200 tagged
Port 9/Port 10 (SFP): VLAN-ID 1 untagged
I read some descriptions here in the forum and hope, that these configuration will manage my network as follows:
- Users in the guest-net (VLAN-ID 200) will get an IP-Adress from the guest-net-DHCP on the FritzBox.
- Users in the family-net (VLAN-ID 100) will get an IP-Adress from the default-DHCP
- guests can not access the family-net
Will that work???
Or do i have to „tell“ the switch, to route VLAN-ID200-packets to Port 8 and VLAN-ID100-packets to Port 1 in another way?
Next idea is, that in this guest-net only allowes http, https and WhatsApp.
Do i have to create ACL’s (Extend-IP ACL) and bind them to the VLAN’s? Or can this be solved in another way?
Does anyone exactly knows, what ports WhatsApp will use??? I searched and found port 5222 and port 5223.
Here i configured one ACL for port 80 (http):
For my understanding: will all other ports be rejected, that have no ACL defined???
Or will this work like some kind of firewall: first, you forbid all and then you allow ACL’s with defined ports???
Sorry for all these questions. But try and error is not the way i want to go. Maybe i can get some hints to configure the system as it should be.
Thanks
maddinla
Hardware Version :
Firmware Version :
ISP :
Hello.
My planned configuration at home is shown in the following picture. I already have the router, the switch and one EAP330
The router is a FritzBox 7490, which has two different LAN’s. Port 1-3 is the „default LAN“ (IP-Adress 192.168.x.y and on Port 4 is a guest-LAN activated (IP-Adress 172.31.179.x).
This means, that the FritzBox has two DHCP-Services running.
My plan is, to plug Port 1 on the switch to Port 1 on the FritzBox to use this as my family-net. Port 8 on the switch plugs to Port 4 on the FritzBox (own IP-Adress-Range with DHCP).
In the future three AP’s should be connected to the switch and broadcast two SSID’s (guest-net, family-net) with different VLAN-ID’s.
The VLAN-configuration in the switch is:
Port 1: VLAN-ID 1 untagged, VLAN-ID 100 untagged (PVID 1, 100)
Port 2: VLAN-ID 1 untagged
Port 3: VLAN-ID 1 untagged
Port 4: VLAN-ID 1 untagged
Port 5: VLAN-ID 1 untagged, VLAN-ID 100 tagged, VLAN-ID 200 tagged (PVID 1,100,200)
Port 6: VLAN-ID 1 untagged, VLAN-ID 100 tagged, VLAN-ID 200 tagged (PVID 1,100,200)
Port 7: VLAN-ID 1 untagged, VLAN-ID 100 tagged, VLAN-ID 200 tagged (PVID 1,100,200)
Port 8: VLAN-ID 1 untagged, VLAN-ID 200 tagged
Port 9/Port 10 (SFP): VLAN-ID 1 untagged
I read some descriptions here in the forum and hope, that these configuration will manage my network as follows:
- Users in the guest-net (VLAN-ID 200) will get an IP-Adress from the guest-net-DHCP on the FritzBox.
- Users in the family-net (VLAN-ID 100) will get an IP-Adress from the default-DHCP
- guests can not access the family-net
Will that work???
Or do i have to „tell“ the switch, to route VLAN-ID200-packets to Port 8 and VLAN-ID100-packets to Port 1 in another way?
Next idea is, that in this guest-net only allowes http, https and WhatsApp.
Do i have to create ACL’s (Extend-IP ACL) and bind them to the VLAN’s? Or can this be solved in another way?
Does anyone exactly knows, what ports WhatsApp will use??? I searched and found port 5222 and port 5223.
Here i configured one ACL for port 80 (http):
For my understanding: will all other ports be rejected, that have no ACL defined???
Or will this work like some kind of firewall: first, you forbid all and then you allow ACL’s with defined ports???
Sorry for all these questions. But try and error is not the way i want to go. Maybe i can get some hints to configure the system as it should be.
Thanks
maddinla