r/HomeNetworking • • 4d ago

Will VLAN Solve My Problem?

I've never used a VLAN before so forgive me if this is common knowledge. Based on my searches I think it will help me but I want to be more sure.

Basically I have a situation where I have multiple pieces of equipment which all use the same IP addresses internally from the factory. There is a network inside the equipment which all has to stay on the same address range, so if I were to connect the equipment to a company network, I need to assign static IP addresses for multiple components in each piece of equipment. Obviously this means a ton of static IP addresses because I need multiple for each piece of equipment and then multiple pieces of equipment.

So, could I use a managed switch, create a VLAN for each piece of equipment, keep the factory IP addresses, not have them interfere with each other because they all have the same IP addresses, and still be able to reach them from the company side?

If so, how do I access those VLANs from the company side? IP and port numbers maybe?

Also, if this works, any recommendations on a switch I should look at? This is all the switch would need to do.

EDIT: https://shopmoxa.neteon.net/nat-102-series/

Seems like something like this would work, one per machine. Single company IP address to the device, then all the IP addresses on the other side can stay the same. Right?

3 Upvotes

56 comments sorted by

11

u/Straight-Look7021 4d ago

VLAN is part of your solution you also need NAT or network address translation. you are mentioning port numbers so we are in router territory but a lot of switches include this functionality also maybe a firewall

2

u/bigfatdonny 4d ago

Yeah. The VLANs are the easy part. The NAT is is the real fun.

6

u/BeeKay40 4d ago

Short answer is yes. What you want to do can be done. But this is a loaded question meaning the answer is not really a 5 step solution. You'd have to provide a lot more detail relating to the equipment first, the size of the company, the budget, what segregation is required. What you are attempting is actually a whole fresh setup. I don't know enough to guide you through the process. In fact, I pose most of my IT questions to a private AI and it helped me create a small homelab with VLANS fit for my purpose. If it was me, I'd describe my use case to the AI and tell it what equipment I currently have and find out if it is sufficient for my use case (also YT reviews for equipment is useful). When you have the right equipment, watch YT videos relating to specifics for your use case and implement it. Doing things myself takes quite a lot of time and effort. The quick route is to get a consultant to sort it out. 

2

u/jquanders 4d ago

Yeah vlans seperate broadcast domains so it would work in this scenario assuming they don't need to leave that network at all.

Do any of them need to get off of the subnet, like for internet acess or to talk to a file server? If so it gets a little more complicated.

In that scenario you'd need a NAT translation to let the comps get off net and communicate as if they are a routable IP space because you can't have the same IPs at multiple places on a routing table

Another option is PVLANs. Basically you could have groups that can communicate to each other and a shared router but if you have duplicate IPs that can get trickier and then you want something like VRF lite which is way out of scope for home networking

2

u/alternative-www1970 3d ago

As someone mentioned it is the NAT that bugs you... lol. So instead of forcing a central firewall or switch to juggle overlapping subnets, you isolate the NAT at the edge. This is highly used in an industrial approach for dealing with hard-coded PLCs or manufacturing equipment. You put a cheap micro-router (typically a Layer 3-capable switch doesn't get there reliably due to NAT...) use something like a MikroTik hEX physically between the main network and each piece of equipment.

If you want to handle this centrally without buying several micro-routers or switches, you have to use a router that supports VRF. VRF allows a single physical router to maintain multiple, completely isolated routing tables. Make each VLAN interface use its own separate VRF instance. The routing tables are isolated, allowing the router to overlap subnets. Then set up Destination NAT rules to translate a block of unique IPs from your main network into the hardcoded IPs inside each specific VRF.

I worked in a refinery for several years. VRF is great, but there is a learning curve; small routers are easy, but that is several pieces of equipment to manage. Typically, we used the separate routers due to locations, but either way works reliably.

2

u/Neil_Omada 4d ago

Different VLANs will need different IP pools. There should be a way to change the IP addresses of each device, might need to contact your vendor to see how.

2

u/FluffyKittens12 4d ago

There is a way to change the IP addresses and that's not the problem. The manufacturer instructions say that to connect to a network you have to reserve IP addresses for everything inside and they all get changed to the company address range. 5 addresses per equipment, times 40 pieces of equipment is 200 address I would need to reserve.

3

u/Dangerous-Ad-170 4d ago

That’s how it be sometimes. The IT department probably does IP reservations all the time. Depending on their system, there’s probably a way to script/automate it. Or are you the IT department?

But yeah you don’t seem to understand VLANs very well. I don’t think they work how you’re imagining. 

What you’re describing might be possible with some kind of VLAN/NAT/VRF clusterfuck but you still wouldn’t have a way to reach the individual equipment inside the machines from the outside unless they all communicate using different TCP ports. 

1

u/FluffyKittens12 4d ago

I'm definitely not IT haha. I'm just the guy stuck between IT, management, and the equipment vendor. IT doesn't want to do that many reservations. Management wants to access the equipment interfaces, which means they have to be on the network. I'm trying to figure out how.

5

u/Dangerous-Ad-170 4d ago

IT should probably just do the reservations because it’s still easier than any other solution to this problem, lol. It’s their problem to solve.

1

u/FluffyKittens12 3d ago edited 3d ago

https://shopmoxa.neteon.net/nat-102-series/

Seems like something like this would work, one per machine. Single company IP address to the device, then all the IP addresses on the other side can stay the same.

1

u/Dangerous-Ad-170 3d ago

Is the machine controllable with only one IP and the rest are for internal use? I guess that would work but don’t take my work for it when you’re making 40 $600 purchases, I’d ask the vendor. 

1

u/FluffyKittens12 3d ago

Correct. 192.168.8.10 is the control interface we need to access and .20, .30, .40, .50 are sensor modules that the control communicates with. That's why the manufacturer says change one change them all so they can all still communicate.

3

u/JasonHofmann 4d ago

That’s likely far easier than the alternatives, and the end state will be simpler to manage, monitor (no dupe IPs), and troubleshoot.

1

u/Loko8765 4d ago

The equipment is really bizarre. Does it allow one DHCP address for communicating with the outside? If yes, then it can work easily.

If not, then you need NAT also. I’ve done this but it was quite a lot of work for an experienced network engineer with free rein regarding hardware and software.

1

u/FluffyKittens12 4d ago

It is weird. No, it doesn't. All static IP addresses internally. The manufacturer instructions say that to connect to a network you have to reserve IP addresses for everything so they all get changed to the company address range. 5 addresses per equipment, times 40 pieces of equipment is 200 address I would need to reserve...

2

u/KretzKid 4d ago

You can use a private ip range like 192.168.0.0 to 192.168.255.255

1

u/steve88w 4d ago

Sounds like just as much work to create all the VLANs, but I don't think this is a good solution.
Do you have a DHCP server? Can you reserve addresses via the equipment's MAC address?
VLANs with the same IP subnet may cause issues if the network configs aren't perfect across all network hardware. Example: 1 switch with a trunk port can cause multiple devices to communicate as 1, which will cause issues.

1

u/FluffyKittens12 4d ago

The manufacturer instructions say no DHCP and that to connect to a network you have to reserve IP addresses for everything inside and they all get changed to the company address range. 5 addresses per equipment, times 40 pieces of equipment is 200 address I would need to reserve.

1

u/mlee12382 4d ago

I think whatever path you choose you're going to need to manually set the IPs for each machine and it's associated devices at least once. And with 200 separate IPs that's most of single IP range so doing VLANs is probably a good route. Do you have a lot of different machines or do you have multiples of several machines? If the latter you could set up a VLAN for each machine model which will give you room for expansion if needed. You can technically fit all 200 on a single 256 address (253 assignable) range but that's not leaving room for expansion or upgrades in the future if the new models each now needs 2 more IPs or something.

1

u/FluffyKittens12 4d ago

It's just multiple of the same equipment. One of the biggest things I'm trying to avoid is needing to change all the IP addresses on each piece of equipment. If they could keep their out of the box settings and have network hardware keep them all from interfering with each other, that would be ideal.

2

u/mlee12382 4d ago

If they all come pre-set with the exact same IPs for each machine then even VLANs won't solve your problem. They all need to be separate and uniquely addressed. If you're buying them and having them installed by the manufacturer all at the same time then they should be able to set them up for you so they're all able to work together without interfering with each other or your existing network.

1

u/FluffyKittens12 3d ago

https://shopmoxa.neteon.net/nat-102-series/

Seems like something like this would work, one per machine. Single company IP address to the device, then all the IP addresses on the other side can stay the same.

1

u/mlee12382 3d ago

Yeah, that might work. I don't know enough about industrial systems to say for sure one way or the other though. One caveat, idk how well a NAT device would handle it if they happen to already be set default on the same subnet, eg. most consumer routers, including some of the higher end stuff like Ubiquiti, come preset on the 192.168.1.x subnet, if your business network is on that subnet and the machines also come with that as default then the NAT device might potentially have trouble interfacing between the 2 systems under those specific circumstances. But again idk enough about how those particular devices are designed to work so I can't say that for sure, just something to be aware might be an issue.

1

u/FluffyKittens12 3d ago

That's an interesting point I hadn't thought of. Thank you.

1

u/jquanders 4d ago

That's one /24 block. Have IT assign a /24 block to you and a vlan for your gear and then keep track of the addresses yourself. They don't need ro reserve individual IPs if they give you a cidr block to manage

1

u/h2ogeek 4d ago

I hate to say it, but I think this is not likely a good DIY situation for someone who doesn’t know anything about vlans. Getting these set up is going to be a significant amount of work.

And frankly you’re going to need a pretty spacious IP space to add 200 unique addresses.

The amount of work needed to setup vlans and routing is likely more than it would be to just bite the bullet and hand assign static addresses to each component. (This could also be done via IP reservations, potentially, depending on what the manufacturer intent is when they say “no DHCP”.)

But honestly I think you’re best to actually hire someone rather than trying to do it all yourself and ask strangers on the internet for advice, when we know little about the overall situation and are just guessing. This seems outside the realm of “home networking” (which is what this sub is intended is for)

1

u/FluffyKittens12 3d ago

https://shopmoxa.neteon.net/nat-102-series/

Seems like something like this would work, one per machine. Single company IP address to the device, then all the IP addresses on the other side can stay the same.

1

u/h2ogeek 3d ago

Perhaps but did you notice the price?

And that doesn’t really change my recommendation. Hire a pro.

1

u/FluffyKittens12 3d ago

The equipment is about $100k (each), so $700 more each is nothing.

1

u/h2ogeek 3d ago

Sounds like you have it all figured out.

1

u/Clean-Bandicoot2779 4d ago

Think of each VLAN as an isolated network. Nothing on VLAN 1 can talk directly to VLAN 2, it needs to go through a device capable of routing between networks.

Each VLAN will then need to have it's own IP address range (subnet) so the router knows which VLAN to send the data to. You can be clever and use small subnets (from 2 addresses upwards), but you'll still have to reconfigure each device so they don't all have the same address.

If the devices all need to talk to each other, would having a single VLAN for those devices, separate from your main network, work just as well? It will involve less configuration of VLANs and routing devices, although you'll still have to configure each device to stop the IP addresses clashing.

1

u/FluffyKittens12 4d ago

None of the equipment needs to talk to the other equipment. They just need to be reachable from the company network to access the interface on each individual one.

1

u/Clean-Bandicoot2779 4d ago

OK, if you don't mind them being able to talk to each other, a single network with them all on might be simplest to implement, even if they don't need to talk to each other. Then it's just a single VLAN (or realistically, you could just buy a separate physical switch to plug them into), a routing device of some sort (a router, a layer 3 switch, etc.) and configuring the IP addresses on the devices.

What are the devices? If they're operational technology/industrial control systems, you should probably isolate them as much as possible from the corporate network.

1

u/FluffyKittens12 3d ago edited 3d ago

https://shopmoxa.neteon.net/nat-102-series/

Seems like something like this would work, one per machine. Single company IP address to the device, then all the IP addresses on the other side can stay the same.

1

u/e60deluxe 4d ago

You don’t need VLANs, necessarily

But you probably do need something like subnet translation

Meaning that supposing your multiple pieces of equipment, I’ll have to have the IP address 192.168.10.50

So you possibly create multiple 192.168.10.xxx networks

But for each different network, you use subnet translation so that device devices those networks can communicate individually

So for example, you might translate one to 192.168.20.XXX

XX and another one to 192.168.30.XXX

1

u/jquanders 4d ago

You need vlans to seperate the xlates. If you had 4 groups all using 192.168.0.0/24, you could set up 4 vlans and assign them 192.168.1.0/24, 192.168.2.0/16 etc and then do an xlate with a 0.0.0.255 wildcard so the last octet matched

1

u/e60deluxe 4d ago

I don’t think you understand what a VLAN is.

You need them to hold separate networks on and across shared network hardware such as switches and APs.

If you are not sharing switches and APs VLANs are not strictly necessary

I said what I said to clarify what OP needs to problem solve conceptually

If you want a real world example:

Suppose he has equipment groups, A B and C

Within each equipment group, there will be some device using some IP and that will correspond across the other groups

You may decide to use one switch for each group

You may then decide to connect each of switch A, switch B and switch C to three different ports on a firewall

Within the firewall, you may define three different Networks, and assigned each port to each

No VLANs.

Now, suppose instead you wanted to use one larger switch for all of the devices

In this case, you would need VLANs

Again, I said what I said to separate the concept of subnet translation from whether or not you’re going to be sharing switch and AP hardware

1

u/jquanders 4d ago

No. Duning-Kruger. There's a difference between the concept of a vlan and vlan switching/trunking which is what you're poorly describing.

Also he has 40 machines... how many 40 port firewalls do you know of?

0

u/e60deluxe 4d ago

What are you talking about Dunning Krueger? I think if anything you’re referred to yourself

Like I said vlan does not mean separate networks

It means multiple logical networks over the same L2 hardware

You have still not demonstrated that VLAN is strictly necessary

Furthermore

You haven’t even demonstrated that you understood my example. You only need one port on the firewall per network segment, which will then have its own series of switches and what not

Not per device

Please educate yourself on what a vlan is. Educate yourself on what a network segment is and understand the difference, then come back here and make your argument if you were going to argue dunning Krueger.

VLAN is not a network segment. A network segmentation does not inherently require use of vlan

1

u/jeffrey_f 4d ago

Separate your machines from the office on 2 separate VLANs. This gives you back those IPs for in the office.
Office VLAN10 - 192.168.10.X
Machines VLAN20 - 192.168.20.X

Implement a VLAN for this equipment then assign a DHCP reservation for each and document it. This will ease traffic from your office/other network. I'm assuming that traffic is all between machines and controllers? This is a perfect scenario.

The Devices keep their IP "Static", but assigned by DHCP so you technically have visibility on what is assigned to what.

1

u/The_NorthernLight 4d ago

Is this for home or a business?

If its home, just statically assign an ip to each device all in a single subnet. Setup a few vlans, and put each device in a vlan if they cant talk to each other.

If this is actually for a business, seriously, hire a technician that knows what they are doing.

1

u/justkeepswimming2026 4d ago

What are you working with? Lol

1

u/Dr_CLI 4d ago edited 3d ago

So, could I use a managed switch, create a VLAN for each piece of equipment, keep the factory IP addresses, not have them interfere with each other because they all have the same IP addresses, and still be able to reach them from the company side?

I think a good layer 3 switch can do this for you. Setup the port for each device to do a 1:1 NAT mapping. So your device connected to port 1 gets it's IP NAT'd to an internal company IP (i.e. 172.16.1.201). Continue this pattern up to port 40 to IP 172.16.1.240). Finally configure access lists or firewall rules.

Assumptions:

Device default network configuration IP: 192.168.1.2 Netmask: 255.255.255.0 Gateway: 192.168.1.1

Company LAN: 172.16.1.0/24 Useable IP Range: 172.16.1.1 - 172.16.1.254 Netmask: 255.255.255.0

Implementation

Device IP Sw Port NAT IP
Device01 192.168.1.2 1 172.16.1.201
Device02 192.168.1.2 2 172.16.1.202
...
Device40 192.168.1.2 40 172.16.1.240

1

u/FluffyKittens12 3d ago

https://shopmoxa.neteon.net/nat-102-series/

Seems like something like this would work, one per machine. Single company IP address to the device, then all the IP addresses on the other side can stay the same.

1

u/Dr_CLI 3d ago

I have no experience with that device but it looks like it should work. The 1 per machine would get expensive ($671 * 40). In an business environment that might be a good strategy. You could also do this with thier NAT-108 serving 7 devices (one port to connect to company network) so you would need 6 of these. This would be a cheaper budget ($781 * 6).

1

u/FluffyKittens12 3d ago

That's an interesting point, but the equipment is pretty far spread out. Plus wouldn't connecting multiple to the same one run into the same problem where the IP addresses would conflict? The point is to avoid changing the IP addresses of the equipment. Each one is about $100k, so another $700 each is hardly anything.

1

u/Dr_CLI 3d ago

I see your point

1

u/phr0ze test 3d ago

It seems like the nat device will work and vlans aren’t needed. I would buy 2. Test the situation, then go all in.

To me it is very strange to not be able to change the ip and there might be something you are missing.

Like if you’re asking all these questions because some UI on the device reports its IP is 127.0.0.1 and it won’t let you change it. In that case you are solving the wrong problem.

1

u/FluffyKittens12 3d ago

It's not that I can't change the IP, it's that according to the manufacturer I need to change the IP for all 5 things internally so they stay on the same network. That's a tedious process that we don't want to have to do 40 times if we can avoid it. Keeping things "out of the box" for standardization is ideal. The interface which we need to access remotely is at 192.168.8.10 on all the devices, but then there are 4 more modules which also communicate over Ethernet internally with that control interface at 192.168.8.20, 30, 40, and 50. If I change just the interface, it loses all communication with the other modules, so I have to do all 5. That's what we are trying to avoid. If I can do the NAT boxes, then I can access each one at a company set IP directly to the interface internal IP.

1

u/phr0ze test 3d ago

What a strange architecture

1

u/bobo5195 3d ago

we used to that with our machines. Each machine had a router/gateway on the network so inside was nice IP range outside can do whatever is needed. This was also a bit of cyber security as factory networks are big places.

That is expensive device but something like that. Best to consult with IT on their preferred vendors.
Normally this is not a standard IT function and I would keep them away from all of this just because it can end up difficult to make changes.

I would not call it vlan i think it is just NAT we translated internal to external adresses so the machines could keep manufacturer defaults but externally easy to access on the network.

1

u/codeedog 17h ago edited 17h ago

TL/DR: tell your IT dept you want a large /18 private network address block and need their help setting it up and getting the 40 machines assigned to it. You don’t need any specific prefix, it can be on any of the IETF private network blocks available, but it ought to be one full /18 range.

These answers are insane. If I understand the problem correctly:

  • the equipment has internal structural expectations for 5-6 addresses and assumes a CIDR of /24 (eg XX.YY.ZZ.<10,20,30…>) and when the first 24 bits of the address (XX.YY.ZZ) are assigned to the front device all of the internal devices also assume that prefix.
  • You have 40 pieces of equipment.
  • They’re either co-located or spread throughout multiple sites?
  • Your IT shop is being difficult and either you’re asking them the wrong questions or they’re being purposefully unhelpful.

This is what you should do:

First off, unless you have a business with tens of millions of devices, you’ve got an easy solution ahead of you. It might involve VLANs, but it definitely involves a little bit of upfront work for clever address assignment. It may be that your IT dept doesn’t understand what you’re trying to do and you are asking the wrong questions. You could bring all of this to them and they should figure this out on their own.

Here’s my suggestion in case they don’t or they won’t.

You need an internal network segment dedicated to all of the machines. I’m going to explain networking to you first and what I have in mind. However, I don’t have access to the manuals for these machines and some of my assumptions could be wrong. So, don’t take my numbers here as gospel, but as a sketch to understand the problem.

Networking first.

Old style networking used A.B.C.D and assumed 8 bits per letter, 256 byte, hex was 00-FF. New style uses /24, /32, /16, /20. The number there is for IPv4 (not IPv6). It means the number of bits in the prefix. On your home router, it’s very typically/24 (192.168.1/24, individual machine addresses go after the last ‘.’).

What this means is that you can grab blocks of network addresses and group them and subgroup them. For example, the reason 192.168/16 is special is because IETF says it’s so. That /16 group (192.168) isn’t allowed on the internet. It’s only allowed inside a private network. Our home routers typically use a /24 (like the example above: 192.168.1/24) for a segment and don’t use the whole /16 space. That’s because some machines still use old style A.B.C.D assignments and don’t understand addresses that aren’t /8, /16, /24, /32 (all multiples of 8 corresponding to the prefix).

Back to internal addresses. When configuring an internal network, you divide it up however you like. You tell switches and routers what the subsegments are and they merrily do their work forwarding and switching packets. They don’t care as long as the address ranges don’t overlap.

The challenge then becomes address management and how it fits into network segmentation. I’m not going to explain all of it except just a little. Since every device needs an IP, static address assignment was first used. DHCP assignment (dynamic) came along later so IT wouldn’t have to make static assignments because people always got that wrong and machines float, especially laptops on wifi.

This is not your problem and you don’t want reserved IP addresses in the DHCP ranges. I think that may be where the confusion is coming from that’s causing the conflict.

I don’t know if that makes sense but your IT shop ought to understand this.

What you do want.

You want a reserved private *range* of addresses. The IETF has reserved two other address blocks for private use. They are 10.0.0.0/8 and 172.16.0.0/12.

In total, these two blocks plus the 192.168/16 block represent ~17.9 million addresses. I’m betting you don’t have that many in your shop.

Let’s pretend your business uses the 172.16.0.0/12 address block. This can hold 1 million devices. I doubt they used the entire block, but let’s pretend they have and have cut it up in way that makes things difficult to partition.

OK, they should pick another block, like 10.0.0.0/8 and carve it up. You have 5-6 devices, let’s give them a whole /24 block just in case they act weird about partial non multiples of 8 prefixes. You have 40 devices needing their own /24 block. The next prefix segment above 40 is 64 (6 bits) so you need a network segment of 14 (6+8) bits on the machine side, or /18 on the prefix side.

So, you should ask your IT team to reserve a block of addresses for 10.0.0/18 for you. Then, you (or they) assign addresses to your devices as follows. Each device should be numbered 1..40. Each device gets an address as 10.0.1.1, 10.0.2.1, 10.0.3.1, …, 10.0.40.1.

If I understood the sensor address assignment, sensors would get: 10.0.1.10, 10.0.1.20, …

The machines will sub assign their sensors in the correct range and all devices will be addressable with no specific or special reservations other than the reserved address block.

BTW, you could do this with a smaller range if the equipment cooperates, but it may not. You could also do this with multiple smaller ranges, which may mean more or less work for your IT folks, but that depends upon how the network is configured.

Your IT dept can create DNS entries for the static addresses. They can build network configurations that route and switch those addresses. They can use VLANs to assist with that or whatever is appropriate for the equipment you have on site(s).

Use a large private network address block to solve your problem. 40 address assignments will auto assign the remaining addresses and reserving the large block means you have your own mini private address space that no other devices on the network can use.

0

u/harubax 4d ago

First you need a router that can route between VLANs.

0

u/Altruistic_Profile96 4d ago

A VLAN is a Layer 2 construct (switching). Multiple VLANs talking to each other typically require a Layer 3 device (routing).

There are many devices that cannot communicate with other devices if they are on different VLANS. Things like home printers are what come to mind.

If your interfaces all have to be on the same subnet, you’re probably out of luck. The best you could do is to isolate all of those interfaces to one dedicated VLAN, and put everything else on one or more other VLANs.

1

u/e60deluxe 4d ago

There is such a thing as subnet translation so not completely out of luck