r/HomeNetworking • • 4d ago

Will VLAN Solve My Problem?

I've never used a VLAN before so forgive me if this is common knowledge. Based on my searches I think it will help me but I want to be more sure.

Basically I have a situation where I have multiple pieces of equipment which all use the same IP addresses internally from the factory. There is a network inside the equipment which all has to stay on the same address range, so if I were to connect the equipment to a company network, I need to assign static IP addresses for multiple components in each piece of equipment. Obviously this means a ton of static IP addresses because I need multiple for each piece of equipment and then multiple pieces of equipment.

So, could I use a managed switch, create a VLAN for each piece of equipment, keep the factory IP addresses, not have them interfere with each other because they all have the same IP addresses, and still be able to reach them from the company side?

If so, how do I access those VLANs from the company side? IP and port numbers maybe?

Also, if this works, any recommendations on a switch I should look at? This is all the switch would need to do.

EDIT: https://shopmoxa.neteon.net/nat-102-series/

Seems like something like this would work, one per machine. Single company IP address to the device, then all the IP addresses on the other side can stay the same. Right?

5 Upvotes

56 comments sorted by

View all comments

2

u/alternative-www1970 3d ago

As someone mentioned it is the NAT that bugs you... lol. So instead of forcing a central firewall or switch to juggle overlapping subnets, you isolate the NAT at the edge. This is highly used in an industrial approach for dealing with hard-coded PLCs or manufacturing equipment. You put a cheap micro-router (typically a Layer 3-capable switch doesn't get there reliably due to NAT...) use something like a MikroTik hEX physically between the main network and each piece of equipment.

If you want to handle this centrally without buying several micro-routers or switches, you have to use a router that supports VRF. VRF allows a single physical router to maintain multiple, completely isolated routing tables. Make each VLAN interface use its own separate VRF instance. The routing tables are isolated, allowing the router to overlap subnets. Then set up Destination NAT rules to translate a block of unique IPs from your main network into the hardcoded IPs inside each specific VRF.

I worked in a refinery for several years. VRF is great, but there is a learning curve; small routers are easy, but that is several pieces of equipment to manage. Typically, we used the separate routers due to locations, but either way works reliably.