Answer the question
In order to leave comments, you need to log in
How to get rid of excess traffic through VLAN?
The situation is as follows (I’ll say right away - the network is clumsy and inherited, but, as they say, we have)
Network diagram
-
+-----+ +-----+ +-----+
| DEV1| | DEV2| | PCS |
+-----+ +-----+ +-----+
| | |192.168.0.101/24
+-------+ +--------------+ +-------+ +-----+
| ISP 2 | | LAN 2 Switch | | ISP 1 | | SVT |
+-------+ +--------------+ +-------+ +-----+
| | | |192.168.0.100/24
|ETH1 |ETH3 |ETH6 |ETH7
+--+-----------+-----------------+ +--------------------------------+
| | BRIDGE1 | | BRIDGE2 | | | | BRIDGE2 | |
| +-----------+ +-----------+ | | +-----------+ |
| | | | | | |
| RB750 | | | | RB2011 | |
| | | | | | |
| +-----------+ +-----------+ | | +-----------+ +-----------+ |
| | VLAN1 | | VLAN2 | | | | VLAN1 | | VLAN2 | |
+--------------------------------+ +--------------------------------+
| ETH2 (LAN) 192.168.1.3/24 | ETH2 (LAN) 192.168.1.2/24
| |
| +----------------------------+ |
| | | |
-----| LAN 1 Switch |--------+
| |
+----------------------------+
| | | |
+-----+ +-----+ +-----+ +-----+
| PC1 | | PC2 | | DC | | DVR |
+-----+ +-----+ +-----+ +-----+
Answer the question
In order to leave comments, you need to log in
A lot has been written, but nothing is clear without ...
I have a simple question: why are you confusing L2 and L3 (VLAN and NAT).
I so understand that it is necessary to ask a question: ports of the switch in a trunk/aktsess?
It's just that if you have two different vlans, then why do you need NAT between them?
Make it easier.
Two vlan, two networks. Static routing between these networks.
Firewall only allow what you need. Everything else is prohibited.
Each subnet will go to the Internet only through its provider according to the rules of the firewall and configured masquerading.
You can still pervert and color the traffic, but this is still superfluous.
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question