This document is intended to assist users in understanding how to create and manage multiple VLAN groups on N-Tron NT Series switches.
APPLICABLE PRODUCTS
N-Tron NT-5000 & NT-7000 Series switch models
PRE-REQUISITES
Untagged interfaces are considered access ports and should be used for connected devices that are VLAN unaware (PC, cameras, I/O, PLC etc.). Tagged interfaces are associated with trunk ports that are capable of managing multiple VLAN traffic over one interface and are usually connected to VLAN aware devices (managed switch, router, firewall, etc.). By default, all N-Tron switch interfaces are considered Untagged.
VLAN Configuration
Step 1. To start adding new VLANs to the switch select the + icon in the top right-hand corner of the page.
Step 2. Next, the Add new VLAN box will appear. Enter a VLAN ID and Name. Click on the Add button to display the new VLAN with no ports selected. If no Name is provided the switch will add a default VLAN.
Step 3. Click on the port numbers to specify a Tagged or Untagged interface. Select the floppy disk sprocket icon to apply the changes. Browse to System> Config web page to save the switch configuration.
VLAN Scenario 1
PLC VLAN 1 = Port 1 Tagged VLAN
Cell 1 VLAN 2 = Port 2 - 4 Untagged VLAN
Cell 2 VLAN 3 = Port 6 - 8 Untagged VLAN
VLAN Scenario 2:
Let's configure VLANs for a connection to a layer 3 switch trunk port using multiple IP subnets. The N-Tron switch is considered a layer 2 switch and has no routing capability. However, IP address can be configured for VLANs. These VLANs should be connected to a network device (layer 3 switch, router, firewall, etc.) with routing enabled.
In this example the switch management VLAN and native VLAN of the layer 3 device is set to 1. VLANs 2 & 3 are routed by the layer 3 device. However, network segmentation can be expanded by using different switch management VLAN, native VLAN, alone with removing N-Tron switch interfaces from the native VLAN, so they do not have access to the layer 3 network. Note: Consult your network administrator on the proper configuration of the layer 3 network device.
Interface Port DM1 is connected to a layer 3 switch using tagged and untagged acceptance. Routing is enabled on the layer 3 switch to establish communication between multiple IP subnets.
First, browse to System> IP Interfaces> Interfaces and configure the N-Tron switch with the correct VLAN, IP address, and gateway for the network.
N-Tron Switch = IP: 192.168.1.202 GW: 192.168.1.201
Layer 3 Switch = IP: 192.168.1.201 GW: 192.168.1.1
Machine 1 VLAN 2 = IP: 172.16.231.2 GW: 172.16.230.1
Machine 2 VLAN 3 = IP: 10.11.12.2 GW: 10.10.10.1
Next, configure VLANs for the N-Tron switch interfaces of connected devices. Machine 1 connected to interface 2 is configured for the 172.16.0.0/16 network. Machine 2 is connected to interface 6 with an IP address configured for the 10.0.0.0/8 network. Both interfaces are connected with devices that are VLAN unaware so only untagged acceptance is configured, and gateway IP address are configured within each machine IP address settings.
N-Tron Switch Uplink to Layer 3 Switch = VLAN 1 Port DM1 Tagged
Machine 1 IP: 172.16.231.100 GW: 172.16.230.1 = VLAN 2 Port 2 Untagged
Machine 2 IP: 10.11.12.200 GW: 10.10.10.1 = VLAN 3 Port 6 Untagged
VLAN Scenario 3:
In this example network the N-Tron switch default VLAN has been changed from 1 to 250. The native VLAN for the layer 3 switch has been set to 250 which requires an update to the N-Tron switch PVID (Port VLAN Identifier) settings. The PVID tells a switch which VLAN to assign to untagged incoming frames on that port.
N-Tron Switch = IP: 192.168.2.250 GW: 192.168.2.1
Layer 3 Switch = IP: 192.168.2.1 GW: 192.168.1.1
SCADA VLAN 2 = IP: 172.16.230.250 GW: 172.16.230.1
Robot VLAN 3 = IP: 10.55.64.73 GW: 10.10.10.1
The N-Tron switch interface DM1 use tagged acceptance for VLANs 2 & 3. Interfaces within VLAN 250 is configured to handle both tagged and untagged traffic. The SCADA & Robot VLAN interface 3 and 4 are connected to VLAN unaware devices using untagged acceptance for ingress traffic.
This example will accommodate networks that does not want to use VLAN 1 as the native VLAN. Make sure a new default VLAN is created and the correct PVID is set for individual interfaces before removing the N-Tron switch default VLAN 1.
N-Tron Switch Uplink to Layer 3 Switch = VLAN 1 Port DM1 Tagged
SCADA IP: 172.16.100.50 GW: 172.16.230.1 = VLAN 2 Port 2 Untagged
Robot IP: 10.56.65.100 GW: 10.10.10.1 = VLAN 3 Port 6 Untagged
Disclaimer
It is the customer's responsibility to review the advice provided herein and its applicability to the system. HMS makes no representation about specific knowledge of the customer's system or the specific performance of the system. HMS is not responsible for any damage to equipment or connected systems. The use of this document is at your own risk. HMS standard product warranty applies.
HMS Technical Support
If you have any questions or trouble, contact HMS Technical Support by clicking here.
For more information: Product warranty and return policy | HMS Networks