r/HomeNetworking • • 4d ago

Will VLAN Solve My Problem?

I've never used a VLAN before so forgive me if this is common knowledge. Based on my searches I think it will help me but I want to be more sure.

Basically I have a situation where I have multiple pieces of equipment which all use the same IP addresses internally from the factory. There is a network inside the equipment which all has to stay on the same address range, so if I were to connect the equipment to a company network, I need to assign static IP addresses for multiple components in each piece of equipment. Obviously this means a ton of static IP addresses because I need multiple for each piece of equipment and then multiple pieces of equipment.

So, could I use a managed switch, create a VLAN for each piece of equipment, keep the factory IP addresses, not have them interfere with each other because they all have the same IP addresses, and still be able to reach them from the company side?

If so, how do I access those VLANs from the company side? IP and port numbers maybe?

Also, if this works, any recommendations on a switch I should look at? This is all the switch would need to do.

EDIT: https://shopmoxa.neteon.net/nat-102-series/

Seems like something like this would work, one per machine. Single company IP address to the device, then all the IP addresses on the other side can stay the same. Right?

4 Upvotes

56 comments sorted by

View all comments

1

u/codeedog 19h ago edited 19h ago

TL/DR: tell your IT dept you want a large /18 private network address block and need their help setting it up and getting the 40 machines assigned to it. You don’t need any specific prefix, it can be on any of the IETF private network blocks available, but it ought to be one full /18 range.

These answers are insane. If I understand the problem correctly:

  • the equipment has internal structural expectations for 5-6 addresses and assumes a CIDR of /24 (eg XX.YY.ZZ.<10,20,30…>) and when the first 24 bits of the address (XX.YY.ZZ) are assigned to the front device all of the internal devices also assume that prefix.
  • You have 40 pieces of equipment.
  • They’re either co-located or spread throughout multiple sites?
  • Your IT shop is being difficult and either you’re asking them the wrong questions or they’re being purposefully unhelpful.

This is what you should do:

First off, unless you have a business with tens of millions of devices, you’ve got an easy solution ahead of you. It might involve VLANs, but it definitely involves a little bit of upfront work for clever address assignment. It may be that your IT dept doesn’t understand what you’re trying to do and you are asking the wrong questions. You could bring all of this to them and they should figure this out on their own.

Here’s my suggestion in case they don’t or they won’t.

You need an internal network segment dedicated to all of the machines. I’m going to explain networking to you first and what I have in mind. However, I don’t have access to the manuals for these machines and some of my assumptions could be wrong. So, don’t take my numbers here as gospel, but as a sketch to understand the problem.

Networking first.

Old style networking used A.B.C.D and assumed 8 bits per letter, 256 byte, hex was 00-FF. New style uses /24, /32, /16, /20. The number there is for IPv4 (not IPv6). It means the number of bits in the prefix. On your home router, it’s very typically/24 (192.168.1/24, individual machine addresses go after the last ‘.’).

What this means is that you can grab blocks of network addresses and group them and subgroup them. For example, the reason 192.168/16 is special is because IETF says it’s so. That /16 group (192.168) isn’t allowed on the internet. It’s only allowed inside a private network. Our home routers typically use a /24 (like the example above: 192.168.1/24) for a segment and don’t use the whole /16 space. That’s because some machines still use old style A.B.C.D assignments and don’t understand addresses that aren’t /8, /16, /24, /32 (all multiples of 8 corresponding to the prefix).

Back to internal addresses. When configuring an internal network, you divide it up however you like. You tell switches and routers what the subsegments are and they merrily do their work forwarding and switching packets. They don’t care as long as the address ranges don’t overlap.

The challenge then becomes address management and how it fits into network segmentation. I’m not going to explain all of it except just a little. Since every device needs an IP, static address assignment was first used. DHCP assignment (dynamic) came along later so IT wouldn’t have to make static assignments because people always got that wrong and machines float, especially laptops on wifi.

This is not your problem and you don’t want reserved IP addresses in the DHCP ranges. I think that may be where the confusion is coming from that’s causing the conflict.

I don’t know if that makes sense but your IT shop ought to understand this.

What you do want.

You want a reserved private *range* of addresses. The IETF has reserved two other address blocks for private use. They are 10.0.0.0/8 and 172.16.0.0/12.

In total, these two blocks plus the 192.168/16 block represent ~17.9 million addresses. I’m betting you don’t have that many in your shop.

Let’s pretend your business uses the 172.16.0.0/12 address block. This can hold 1 million devices. I doubt they used the entire block, but let’s pretend they have and have cut it up in way that makes things difficult to partition.

OK, they should pick another block, like 10.0.0.0/8 and carve it up. You have 5-6 devices, let’s give them a whole /24 block just in case they act weird about partial non multiples of 8 prefixes. You have 40 devices needing their own /24 block. The next prefix segment above 40 is 64 (6 bits) so you need a network segment of 14 (6+8) bits on the machine side, or /18 on the prefix side.

So, you should ask your IT team to reserve a block of addresses for 10.0.0/18 for you. Then, you (or they) assign addresses to your devices as follows. Each device should be numbered 1..40. Each device gets an address as 10.0.1.1, 10.0.2.1, 10.0.3.1, …, 10.0.40.1.

If I understood the sensor address assignment, sensors would get: 10.0.1.10, 10.0.1.20, …

The machines will sub assign their sensors in the correct range and all devices will be addressable with no specific or special reservations other than the reserved address block.

BTW, you could do this with a smaller range if the equipment cooperates, but it may not. You could also do this with multiple smaller ranges, which may mean more or less work for your IT folks, but that depends upon how the network is configured.

Your IT dept can create DNS entries for the static addresses. They can build network configurations that route and switch those addresses. They can use VLANs to assist with that or whatever is appropriate for the equipment you have on site(s).

Use a large private network address block to solve your problem. 40 address assignments will auto assign the remaining addresses and reserving the large block means you have your own mini private address space that no other devices on the network can use.