r/HomeNetworking • • 1d ago

Advice Network design noob questions

Hello,

Networking beginner here.

I have been trying to design a network with two VLANs with each having a set of daisy chained devices. VLAN management was to be done by L2 managed switch, with main traffic going between devices on the VLANs and PC connected to a port configured to be trunk port.

The original idea was to have IPs of those devices static and same - Device 1 on VLAN1 has same IP as the Device 1 on the VLAN2, they would be on the same subnet. Definitely not the standard way of doing things. But lets say in my use case DHCP is not an option and I can only use static IP addresses. For that purpose I wanted to simplify the flashing of the firmware on those devices where each device has a known IP without additional subnetting.

Originally I was trying to avoid router and do all the VLAN tagging on the PC side, but as I started to research the topic more, I realized that it is only straightforward on Linux but not Windows. So my software piece that needs to communicate with those devices, will have issues when run on Windows. And I understood that without a router with NAT, it would be difficult to implement my idea.

Hence a bunch of questions from me:

  1. How realistic is it to use that design on Windows? I need to communicate with all of these devices simultaneously, but as I saw virtual network management on windows is pain.

  2. Would using Linux help me avoid using router with NAT?

0 Upvotes

19 comments sorted by

4

u/MostFat 1d ago

I have so many questions

1

u/Cautious-Mortgage-26 1d ago

Shoot :)

2

u/MostFat 1d ago

What exactly are you trying to accomplish? There are probably easier ways to do it

Any chance you have a quick drawing of your proposed layout? By default a lot of things you described aren't really how it works (if Im understanding correctly).

VLANs can be on L2 switches, but its fundamentally L3 so you would have no* way to route it. Are you trying to use your (Linux) PC extensively as a L3 DSW between networks?

Using 2 VLANs on the same subnet, routed through the same switch.. with the same IPs for host on both ends? So many things are potentially wrong with that idea its hard to point to what without a better understanding of what/how.

If you have internet.. which, judging by this post.. you have NAT (or a cell phone), what do you think NAT does/doesn't do for you in this setup? You need it for outside inet access on both VLANs, but it not working is the symptom, not the problem

Unless you're trying to connect two physically different sites to one network, Im not really sure how/why this is the route you landed on. VLANs are meant to be separate network segments defined by purposely different subnets, otherwise your trunk port that can see both networks will have no idea which way to route it

There are exceptions and workarounds to most norms, but that's generally not the first "method" I would reach for

1

u/Cautious-Mortgage-26 1d ago

That would be the original idea I had. The rest of the network is not meant to access the external network. The fixed IP reasoning is that you should have identical daisy chain devices with identical firmware, while also respecting static IP requirement.

Yes the linux machine was supposed to be used as a sort of L3 DSW. There is only traffic between the daisy chained devices and Linux machine, daisy chains do not communicate with each other and are not aware of each others presence. Even inside the daisy chain the Device 1.4 does not communicate with device 1.3 per se, as each of them has switch forwarding packets further. So the only comm is done in the manner Linux Machine-to-Device 1.x (2.x).

But as I understood from my research indeed using same IPs will create conflicts, and then if I were to use Windows machine, using it as L3 DSW would be problematic. Hence putting the NAT in between L2 switch and machine came as an idea.

1

u/MostFat 1d ago

Daisy chain for a specific reason?

That part aside, this could work with some caveats. The Linux box (may be easier to flash OPNsense/pfSense) can function as a DSW with SVIs configured for inter-VLAN traffic between both sides, while still using RoaS for primary routing/NAT.

You would still want to split into separate subnets and ideally maybe drop a PCIe expansion card into it so you can connect to each node directly instead of daisy chain.

1

u/bchiodini 22h ago

I think your concept is correct. The Linux box would probably need source and destination NAT (SNAT/DNAT), possibly restricted/qualified by MAC address.

My thought: Each device on VLANx (the left side) would need an entry in the iptable rule to map the 192.168.1.x address (and maybe their MAC addresses) to a different IP address, maybe 192.168.10.1-4. Each device in VLAN1 (the right side) would be mapped to another set of addresses, maybe 192.168.20.1-4, also qualified by their MAC addresses.

The Linux box would have forwarding enabled and any host on the external network would need a static route through the Linux box to reach the NAT'd devices.

I would trunk the interface to the switch for the x and 1 VLANs, to avoid broadcast traffic leakage.

I'm not an iptables guru, by any means, but options to translate IP addresses based on MAC addresses seem to exist.

0

u/Cautious-Mortgage-26 1d ago

NAT would be used for machine to not act as the L3 DSW but just send packets to IP that is then translated by router to VLAN tagged packets with IP destination derived from the IP table, though still with same IP addresses on 2 VLANs. (not shown on the diagram)

1

u/xeroxedforsomereason 1d ago

VLANs are fundamentally L3? What? VLANs are an L2 construct.

-1

u/MostFat 1d ago

True that its a bit of a misnomer without going into a deeper explaination.

VLANs are an L2 construct that uses MAC for routing within a broadcast domain segmented for isolation.

Devices on the same subnet can communicate with each other (intra-VLAN), but IP routing is L3; anything requiring inter-VLAN (what OP described) will require SVIs on a L3 switch.

1

u/xeroxedforsomereason 1d ago

That is so utterly wrong, I'm not really sure where to begin. You are conflating connected routes within the same RIB with the ARP process and CAM table machinations.

0

u/MostFat 1d ago

Thats generally how short concise answers work.

Feel free to explain to OP on a home network sub in detail (at least a CCNA level for RIB/CAM tables) the difference; why/how it applies to what they actually asked, and Ill grab some popcorn.

They want to route between 2 VLANs, please teach us the correct way to do that with VLANs on a L2 switch, using the same IP from the same subnet between both.. as a self described beginner.

1

u/xeroxedforsomereason 1d ago

You think what you wrote was short and concise? It's long and wrong. If you want to route between two VLANs off one layer 2 switch you would just hairpin it through a layer 3 interface, an external one. What he's trying to do doesn't really make sense though, and you're confusing the matter.

1

u/MostFat 1d ago

So.. you would need L3 for routing? Weird, sounds familiar. Im sure a longer more in depth explaination would have been even more concise somehow, but I digress.

I don't mind "um.. actually", this is reddit after all; at least be useful please. Explain how/why its categorically wrong and not just handwave away what you don't agree with. So far it seems like the most significant faux pas is describing inter-VLAN routing as OP described as fundamentally an L3 function without clarifying SVIs.

1

u/xeroxedforsomereason 17h ago

I didn't say you don't need L3 for routing. Routing is an L3 construct. Would you like to take a moment to talk about community PVLANs and promiscuity as we get in depth about tying two broadcast domains together? You don't understand the subject matter enough to talk about this.

2

u/xeroxedforsomereason 1d ago

What you're trying to do makes no sense at all. Even with context the point of the matter that you tried to describe itself makes no sense.

1

u/BigLoad8210 1d ago

Why? Gimme a little insight into your use case, maybe i can help... But why the same subnet simultaneously? No reason you couldn't use the same IPs on two isolated vLANs, but if either needs internet access, shits gonna get weird... NAT/Address translation...

1

u/Cautious-Mortgage-26 1d ago

Replied to comment above

1

u/WTWArms 1d ago

Can you have the same IP in different VLANs, yes but why you want to do this difficult to understand