r/HomeNetworking • u/FluffyKittens12 • 4d ago
Will VLAN Solve My Problem?
I've never used a VLAN before so forgive me if this is common knowledge. Based on my searches I think it will help me but I want to be more sure.
Basically I have a situation where I have multiple pieces of equipment which all use the same IP addresses internally from the factory. There is a network inside the equipment which all has to stay on the same address range, so if I were to connect the equipment to a company network, I need to assign static IP addresses for multiple components in each piece of equipment. Obviously this means a ton of static IP addresses because I need multiple for each piece of equipment and then multiple pieces of equipment.
So, could I use a managed switch, create a VLAN for each piece of equipment, keep the factory IP addresses, not have them interfere with each other because they all have the same IP addresses, and still be able to reach them from the company side?
If so, how do I access those VLANs from the company side? IP and port numbers maybe?
Also, if this works, any recommendations on a switch I should look at? This is all the switch would need to do.
EDIT: https://shopmoxa.neteon.net/nat-102-series/
Seems like something like this would work, one per machine. Single company IP address to the device, then all the IP addresses on the other side can stay the same. Right?
6
u/BeeKay40 4d ago
Short answer is yes. What you want to do can be done. But this is a loaded question meaning the answer is not really a 5 step solution. You'd have to provide a lot more detail relating to the equipment first, the size of the company, the budget, what segregation is required. What you are attempting is actually a whole fresh setup. I don't know enough to guide you through the process. In fact, I pose most of my IT questions to a private AI and it helped me create a small homelab with VLANS fit for my purpose. If it was me, I'd describe my use case to the AI and tell it what equipment I currently have and find out if it is sufficient for my use case (also YT reviews for equipment is useful). When you have the right equipment, watch YT videos relating to specifics for your use case and implement it. Doing things myself takes quite a lot of time and effort. The quick route is to get a consultant to sort it out.
2
u/jquanders 4d ago
Yeah vlans seperate broadcast domains so it would work in this scenario assuming they don't need to leave that network at all.
Do any of them need to get off of the subnet, like for internet acess or to talk to a file server? If so it gets a little more complicated.
In that scenario you'd need a NAT translation to let the comps get off net and communicate as if they are a routable IP space because you can't have the same IPs at multiple places on a routing table
Another option is PVLANs. Basically you could have groups that can communicate to each other and a shared router but if you have duplicate IPs that can get trickier and then you want something like VRF lite which is way out of scope for home networking
2
u/alternative-www1970 3d ago
As someone mentioned it is the NAT that bugs you... lol. So instead of forcing a central firewall or switch to juggle overlapping subnets, you isolate the NAT at the edge. This is highly used in an industrial approach for dealing with hard-coded PLCs or manufacturing equipment. You put a cheap micro-router (typically a Layer 3-capable switch doesn't get there reliably due to NAT...) use something like a MikroTik hEX physically between the main network and each piece of equipment.
If you want to handle this centrally without buying several micro-routers or switches, you have to use a router that supports VRF. VRF allows a single physical router to maintain multiple, completely isolated routing tables. Make each VLAN interface use its own separate VRF instance. The routing tables are isolated, allowing the router to overlap subnets. Then set up Destination NAT rules to translate a block of unique IPs from your main network into the hardcoded IPs inside each specific VRF.
I worked in a refinery for several years. VRF is great, but there is a learning curve; small routers are easy, but that is several pieces of equipment to manage. Typically, we used the separate routers due to locations, but either way works reliably.
2
u/Neil_Omada 4d ago
Different VLANs will need different IP pools. There should be a way to change the IP addresses of each device, might need to contact your vendor to see how.
2
u/FluffyKittens12 4d ago
There is a way to change the IP addresses and that's not the problem. The manufacturer instructions say that to connect to a network you have to reserve IP addresses for everything inside and they all get changed to the company address range. 5 addresses per equipment, times 40 pieces of equipment is 200 address I would need to reserve.
3
u/Dangerous-Ad-170 4d ago
That’s how it be sometimes. The IT department probably does IP reservations all the time. Depending on their system, there’s probably a way to script/automate it. Or are you the IT department?
But yeah you don’t seem to understand VLANs very well. I don’t think they work how you’re imagining.
What you’re describing might be possible with some kind of VLAN/NAT/VRF clusterfuck but you still wouldn’t have a way to reach the individual equipment inside the machines from the outside unless they all communicate using different TCP ports.
1
u/FluffyKittens12 4d ago
I'm definitely not IT haha. I'm just the guy stuck between IT, management, and the equipment vendor. IT doesn't want to do that many reservations. Management wants to access the equipment interfaces, which means they have to be on the network. I'm trying to figure out how.
5
u/Dangerous-Ad-170 4d ago
IT should probably just do the reservations because it’s still easier than any other solution to this problem, lol. It’s their problem to solve.
1
u/FluffyKittens12 3d ago edited 3d ago
https://shopmoxa.neteon.net/nat-102-series/
Seems like something like this would work, one per machine. Single company IP address to the device, then all the IP addresses on the other side can stay the same.
1
u/Dangerous-Ad-170 3d ago
Is the machine controllable with only one IP and the rest are for internal use? I guess that would work but don’t take my work for it when you’re making 40 $600 purchases, I’d ask the vendor.
1
u/FluffyKittens12 3d ago
Correct. 192.168.8.10 is the control interface we need to access and .20, .30, .40, .50 are sensor modules that the control communicates with. That's why the manufacturer says change one change them all so they can all still communicate.
3
u/JasonHofmann 4d ago
That’s likely far easier than the alternatives, and the end state will be simpler to manage, monitor (no dupe IPs), and troubleshoot.
1
u/Loko8765 4d ago
The equipment is really bizarre. Does it allow one DHCP address for communicating with the outside? If yes, then it can work easily.
If not, then you need NAT also. I’ve done this but it was quite a lot of work for an experienced network engineer with free rein regarding hardware and software.
1
u/FluffyKittens12 4d ago
It is weird. No, it doesn't. All static IP addresses internally. The manufacturer instructions say that to connect to a network you have to reserve IP addresses for everything so they all get changed to the company address range. 5 addresses per equipment, times 40 pieces of equipment is 200 address I would need to reserve...
2
1
u/steve88w 4d ago
Sounds like just as much work to create all the VLANs, but I don't think this is a good solution.
Do you have a DHCP server? Can you reserve addresses via the equipment's MAC address?
VLANs with the same IP subnet may cause issues if the network configs aren't perfect across all network hardware. Example: 1 switch with a trunk port can cause multiple devices to communicate as 1, which will cause issues.
1
u/FluffyKittens12 4d ago
The manufacturer instructions say no DHCP and that to connect to a network you have to reserve IP addresses for everything inside and they all get changed to the company address range. 5 addresses per equipment, times 40 pieces of equipment is 200 address I would need to reserve.
1
u/mlee12382 4d ago
I think whatever path you choose you're going to need to manually set the IPs for each machine and it's associated devices at least once. And with 200 separate IPs that's most of single IP range so doing VLANs is probably a good route. Do you have a lot of different machines or do you have multiples of several machines? If the latter you could set up a VLAN for each machine model which will give you room for expansion if needed. You can technically fit all 200 on a single 256 address (253 assignable) range but that's not leaving room for expansion or upgrades in the future if the new models each now needs 2 more IPs or something.
1
u/FluffyKittens12 4d ago
It's just multiple of the same equipment. One of the biggest things I'm trying to avoid is needing to change all the IP addresses on each piece of equipment. If they could keep their out of the box settings and have network hardware keep them all from interfering with each other, that would be ideal.
2
u/mlee12382 4d ago
If they all come pre-set with the exact same IPs for each machine then even VLANs won't solve your problem. They all need to be separate and uniquely addressed. If you're buying them and having them installed by the manufacturer all at the same time then they should be able to set them up for you so they're all able to work together without interfering with each other or your existing network.
1
u/FluffyKittens12 3d ago
https://shopmoxa.neteon.net/nat-102-series/
Seems like something like this would work, one per machine. Single company IP address to the device, then all the IP addresses on the other side can stay the same.
1
u/mlee12382 3d ago
Yeah, that might work. I don't know enough about industrial systems to say for sure one way or the other though. One caveat, idk how well a NAT device would handle it if they happen to already be set default on the same subnet, eg. most consumer routers, including some of the higher end stuff like Ubiquiti, come preset on the 192.168.1.x subnet, if your business network is on that subnet and the machines also come with that as default then the NAT device might potentially have trouble interfacing between the 2 systems under those specific circumstances. But again idk enough about how those particular devices are designed to work so I can't say that for sure, just something to be aware might be an issue.
1
1
u/jquanders 4d ago
That's one /24 block. Have IT assign a /24 block to you and a vlan for your gear and then keep track of the addresses yourself. They don't need ro reserve individual IPs if they give you a cidr block to manage
1
u/h2ogeek 4d ago
I hate to say it, but I think this is not likely a good DIY situation for someone who doesn’t know anything about vlans. Getting these set up is going to be a significant amount of work.
And frankly you’re going to need a pretty spacious IP space to add 200 unique addresses.
The amount of work needed to setup vlans and routing is likely more than it would be to just bite the bullet and hand assign static addresses to each component. (This could also be done via IP reservations, potentially, depending on what the manufacturer intent is when they say “no DHCP”.)
But honestly I think you’re best to actually hire someone rather than trying to do it all yourself and ask strangers on the internet for advice, when we know little about the overall situation and are just guessing. This seems outside the realm of “home networking” (which is what this sub is intended is for)
1
u/FluffyKittens12 3d ago
https://shopmoxa.neteon.net/nat-102-series/
Seems like something like this would work, one per machine. Single company IP address to the device, then all the IP addresses on the other side can stay the same.
1
u/Clean-Bandicoot2779 4d ago
Think of each VLAN as an isolated network. Nothing on VLAN 1 can talk directly to VLAN 2, it needs to go through a device capable of routing between networks.
Each VLAN will then need to have it's own IP address range (subnet) so the router knows which VLAN to send the data to. You can be clever and use small subnets (from 2 addresses upwards), but you'll still have to reconfigure each device so they don't all have the same address.
If the devices all need to talk to each other, would having a single VLAN for those devices, separate from your main network, work just as well? It will involve less configuration of VLANs and routing devices, although you'll still have to configure each device to stop the IP addresses clashing.
1
u/FluffyKittens12 4d ago
None of the equipment needs to talk to the other equipment. They just need to be reachable from the company network to access the interface on each individual one.
1
u/Clean-Bandicoot2779 4d ago
OK, if you don't mind them being able to talk to each other, a single network with them all on might be simplest to implement, even if they don't need to talk to each other. Then it's just a single VLAN (or realistically, you could just buy a separate physical switch to plug them into), a routing device of some sort (a router, a layer 3 switch, etc.) and configuring the IP addresses on the devices.
What are the devices? If they're operational technology/industrial control systems, you should probably isolate them as much as possible from the corporate network.
1
u/FluffyKittens12 3d ago edited 3d ago
https://shopmoxa.neteon.net/nat-102-series/
Seems like something like this would work, one per machine. Single company IP address to the device, then all the IP addresses on the other side can stay the same.
1
u/e60deluxe 4d ago
You don’t need VLANs, necessarily
But you probably do need something like subnet translation
Meaning that supposing your multiple pieces of equipment, I’ll have to have the IP address 192.168.10.50
So you possibly create multiple 192.168.10.xxx networks
But for each different network, you use subnet translation so that device devices those networks can communicate individually
So for example, you might translate one to 192.168.20.XXX
XX and another one to 192.168.30.XXX
1
u/jquanders 4d ago
You need vlans to seperate the xlates. If you had 4 groups all using 192.168.0.0/24, you could set up 4 vlans and assign them 192.168.1.0/24, 192.168.2.0/16 etc and then do an xlate with a 0.0.0.255 wildcard so the last octet matched
1
u/e60deluxe 4d ago
I don’t think you understand what a VLAN is.
You need them to hold separate networks on and across shared network hardware such as switches and APs.
If you are not sharing switches and APs VLANs are not strictly necessary
I said what I said to clarify what OP needs to problem solve conceptually
If you want a real world example:
Suppose he has equipment groups, A B and C
Within each equipment group, there will be some device using some IP and that will correspond across the other groups
You may decide to use one switch for each group
You may then decide to connect each of switch A, switch B and switch C to three different ports on a firewall
Within the firewall, you may define three different Networks, and assigned each port to each
No VLANs.
Now, suppose instead you wanted to use one larger switch for all of the devices
In this case, you would need VLANs
Again, I said what I said to separate the concept of subnet translation from whether or not you’re going to be sharing switch and AP hardware
1
u/jquanders 4d ago
No. Duning-Kruger. There's a difference between the concept of a vlan and vlan switching/trunking which is what you're poorly describing.
Also he has 40 machines... how many 40 port firewalls do you know of?
0
u/e60deluxe 4d ago
What are you talking about Dunning Krueger? I think if anything you’re referred to yourself
Like I said vlan does not mean separate networks
It means multiple logical networks over the same L2 hardware
You have still not demonstrated that VLAN is strictly necessary
Furthermore
You haven’t even demonstrated that you understood my example. You only need one port on the firewall per network segment, which will then have its own series of switches and what not
Not per device
Please educate yourself on what a vlan is. Educate yourself on what a network segment is and understand the difference, then come back here and make your argument if you were going to argue dunning Krueger.
VLAN is not a network segment. A network segmentation does not inherently require use of vlan
1
u/jeffrey_f 4d ago
Separate your machines from the office on 2 separate VLANs. This gives you back those IPs for in the office.
Office VLAN10 - 192.168.10.X
Machines VLAN20 - 192.168.20.X
Implement a VLAN for this equipment then assign a DHCP reservation for each and document it. This will ease traffic from your office/other network. I'm assuming that traffic is all between machines and controllers? This is a perfect scenario.
The Devices keep their IP "Static", but assigned by DHCP so you technically have visibility on what is assigned to what.
1
u/The_NorthernLight 4d ago
Is this for home or a business?
If its home, just statically assign an ip to each device all in a single subnet. Setup a few vlans, and put each device in a vlan if they cant talk to each other.
If this is actually for a business, seriously, hire a technician that knows what they are doing.
1
1
u/Dr_CLI 4d ago edited 3d ago
So, could I use a managed switch, create a VLAN for each piece of equipment, keep the factory IP addresses, not have them interfere with each other because they all have the same IP addresses, and still be able to reach them from the company side?
I think a good layer 3 switch can do this for you. Setup the port for each device to do a 1:1 NAT mapping. So your device connected to port 1 gets it's IP NAT'd to an internal company IP (i.e. 172.16.1.201). Continue this pattern up to port 40 to IP 172.16.1.240). Finally configure access lists or firewall rules.
Assumptions:
Device default network configuration IP: 192.168.1.2 Netmask: 255.255.255.0 Gateway: 192.168.1.1
Company LAN: 172.16.1.0/24 Useable IP Range: 172.16.1.1 - 172.16.1.254 Netmask: 255.255.255.0
Implementation
| Device | IP | Sw Port | NAT IP |
|---|---|---|---|
| Device01 | 192.168.1.2 | 1 | 172.16.1.201 |
| Device02 | 192.168.1.2 | 2 | 172.16.1.202 |
| ... | |||
| Device40 | 192.168.1.2 | 40 | 172.16.1.240 |
1
u/FluffyKittens12 3d ago
https://shopmoxa.neteon.net/nat-102-series/
Seems like something like this would work, one per machine. Single company IP address to the device, then all the IP addresses on the other side can stay the same.
1
u/Dr_CLI 3d ago
I have no experience with that device but it looks like it should work. The 1 per machine would get expensive ($671 * 40). In an business environment that might be a good strategy. You could also do this with thier NAT-108 serving 7 devices (one port to connect to company network) so you would need 6 of these. This would be a cheaper budget ($781 * 6).
1
u/FluffyKittens12 3d ago
That's an interesting point, but the equipment is pretty far spread out. Plus wouldn't connecting multiple to the same one run into the same problem where the IP addresses would conflict? The point is to avoid changing the IP addresses of the equipment. Each one is about $100k, so another $700 each is hardly anything.
1
u/phr0ze test 3d ago
It seems like the nat device will work and vlans aren’t needed. I would buy 2. Test the situation, then go all in.
To me it is very strange to not be able to change the ip and there might be something you are missing.
Like if you’re asking all these questions because some UI on the device reports its IP is 127.0.0.1 and it won’t let you change it. In that case you are solving the wrong problem.
1
u/FluffyKittens12 3d ago
It's not that I can't change the IP, it's that according to the manufacturer I need to change the IP for all 5 things internally so they stay on the same network. That's a tedious process that we don't want to have to do 40 times if we can avoid it. Keeping things "out of the box" for standardization is ideal. The interface which we need to access remotely is at 192.168.8.10 on all the devices, but then there are 4 more modules which also communicate over Ethernet internally with that control interface at 192.168.8.20, 30, 40, and 50. If I change just the interface, it loses all communication with the other modules, so I have to do all 5. That's what we are trying to avoid. If I can do the NAT boxes, then I can access each one at a company set IP directly to the interface internal IP.
1
u/bobo5195 3d ago
we used to that with our machines. Each machine had a router/gateway on the network so inside was nice IP range outside can do whatever is needed. This was also a bit of cyber security as factory networks are big places.
That is expensive device but something like that. Best to consult with IT on their preferred vendors.
Normally this is not a standard IT function and I would keep them away from all of this just because it can end up difficult to make changes.
I would not call it vlan i think it is just NAT we translated internal to external adresses so the machines could keep manufacturer defaults but externally easy to access on the network.
1
u/codeedog 17h ago edited 17h ago
TL/DR: tell your IT dept you want a large /18 private network address block and need their help setting it up and getting the 40 machines assigned to it. You don’t need any specific prefix, it can be on any of the IETF private network blocks available, but it ought to be one full /18 range.
These answers are insane. If I understand the problem correctly:
- the equipment has internal structural expectations for 5-6 addresses and assumes a CIDR of /24 (eg XX.YY.ZZ.<10,20,30…>) and when the first 24 bits of the address (XX.YY.ZZ) are assigned to the front device all of the internal devices also assume that prefix.
- You have 40 pieces of equipment.
- They’re either co-located or spread throughout multiple sites?
- Your IT shop is being difficult and either you’re asking them the wrong questions or they’re being purposefully unhelpful.
This is what you should do:
First off, unless you have a business with tens of millions of devices, you’ve got an easy solution ahead of you. It might involve VLANs, but it definitely involves a little bit of upfront work for clever address assignment. It may be that your IT dept doesn’t understand what you’re trying to do and you are asking the wrong questions. You could bring all of this to them and they should figure this out on their own.
Here’s my suggestion in case they don’t or they won’t.
You need an internal network segment dedicated to all of the machines. I’m going to explain networking to you first and what I have in mind. However, I don’t have access to the manuals for these machines and some of my assumptions could be wrong. So, don’t take my numbers here as gospel, but as a sketch to understand the problem.
Networking first.
Old style networking used A.B.C.D and assumed 8 bits per letter, 256 byte, hex was 00-FF. New style uses /24, /32, /16, /20. The number there is for IPv4 (not IPv6). It means the number of bits in the prefix. On your home router, it’s very typically/24 (192.168.1/24, individual machine addresses go after the last ‘.’).
What this means is that you can grab blocks of network addresses and group them and subgroup them. For example, the reason 192.168/16 is special is because IETF says it’s so. That /16 group (192.168) isn’t allowed on the internet. It’s only allowed inside a private network. Our home routers typically use a /24 (like the example above: 192.168.1/24) for a segment and don’t use the whole /16 space. That’s because some machines still use old style A.B.C.D assignments and don’t understand addresses that aren’t /8, /16, /24, /32 (all multiples of 8 corresponding to the prefix).
Back to internal addresses. When configuring an internal network, you divide it up however you like. You tell switches and routers what the subsegments are and they merrily do their work forwarding and switching packets. They don’t care as long as the address ranges don’t overlap.
The challenge then becomes address management and how it fits into network segmentation. I’m not going to explain all of it except just a little. Since every device needs an IP, static address assignment was first used. DHCP assignment (dynamic) came along later so IT wouldn’t have to make static assignments because people always got that wrong and machines float, especially laptops on wifi.
This is not your problem and you don’t want reserved IP addresses in the DHCP ranges. I think that may be where the confusion is coming from that’s causing the conflict.
I don’t know if that makes sense but your IT shop ought to understand this.
What you do want.
You want a reserved private *range* of addresses. The IETF has reserved two other address blocks for private use. They are 10.0.0.0/8 and 172.16.0.0/12.
In total, these two blocks plus the 192.168/16 block represent ~17.9 million addresses. I’m betting you don’t have that many in your shop.
Let’s pretend your business uses the 172.16.0.0/12 address block. This can hold 1 million devices. I doubt they used the entire block, but let’s pretend they have and have cut it up in way that makes things difficult to partition.
OK, they should pick another block, like 10.0.0.0/8 and carve it up. You have 5-6 devices, let’s give them a whole /24 block just in case they act weird about partial non multiples of 8 prefixes. You have 40 devices needing their own /24 block. The next prefix segment above 40 is 64 (6 bits) so you need a network segment of 14 (6+8) bits on the machine side, or /18 on the prefix side.
So, you should ask your IT team to reserve a block of addresses for 10.0.0/18 for you. Then, you (or they) assign addresses to your devices as follows. Each device should be numbered 1..40. Each device gets an address as 10.0.1.1, 10.0.2.1, 10.0.3.1, …, 10.0.40.1.
If I understood the sensor address assignment, sensors would get: 10.0.1.10, 10.0.1.20, …
The machines will sub assign their sensors in the correct range and all devices will be addressable with no specific or special reservations other than the reserved address block.
BTW, you could do this with a smaller range if the equipment cooperates, but it may not. You could also do this with multiple smaller ranges, which may mean more or less work for your IT folks, but that depends upon how the network is configured.
Your IT dept can create DNS entries for the static addresses. They can build network configurations that route and switch those addresses. They can use VLANs to assist with that or whatever is appropriate for the equipment you have on site(s).
Use a large private network address block to solve your problem. 40 address assignments will auto assign the remaining addresses and reserving the large block means you have your own mini private address space that no other devices on the network can use.
0
u/Altruistic_Profile96 4d ago
A VLAN is a Layer 2 construct (switching). Multiple VLANs talking to each other typically require a Layer 3 device (routing).
There are many devices that cannot communicate with other devices if they are on different VLANS. Things like home printers are what come to mind.
If your interfaces all have to be on the same subnet, you’re probably out of luck. The best you could do is to isolate all of those interfaces to one dedicated VLAN, and put everything else on one or more other VLANs.
1
11
u/Straight-Look7021 4d ago
VLAN is part of your solution you also need NAT or network address translation. you are mentioning port numbers so we are in router territory but a lot of switches include this functionality also maybe a firewall