BS-G3024MR VLAN Network Segmentation and IP Filtering Setup Guide

This document provides a guide for setting up VLANs and IP filtering on the Buffalo BS-G3024MR Layer 3 Gigabit Intelligent Switch. It is intended for system administrators involved in the introduction or consideration of the BS-G3024MR series.

Table of Contents

Introduction

This guide details the basic setup procedures and key points for VLAN network segmentation and IP filtering using the Buffalo BS-G3024MR Layer 3 Switch. It covers VLAN configuration, routing setup, and hardware IP filtering.

The target audience includes system administrators implementing or considering the BS-G3024MR series. Basic knowledge of Port VLAN/Tag VLAN is assumed.

The information in this guide is based on the specifications and screens of the BS-G3024MR firmware Version 1.0.4.8 (August 2009 release).

This guide does not cover all features of the BS-G3024MR. It focuses on the essential functions for VLAN and routing setup, and IP filtering, providing step-by-step instructions.

The network configuration assumed in this guide is for a school environment, separating teacher and student networks and implementing IP filtering. This configuration can be adapted for small to medium-sized offices with minor modifications.

Network Configuration Diagram:

Teacher Network: VLAN 11, IP: 192.168.11.xxx

Shared Network: VLAN 13, IP: 192.168.13.xxx (Connect File Server/NAS)

Student Network: VLAN 12, IP: 192.168.12.xxx

Router: Local IP: 192.168.14.1

Internet Connection Network: VLAN 14, IP: 192.168.14.xxx

Management (Setup) Network: VLAN 1, IP: 192.168.10.xxx

Note: The latest firmware for the switch can be downloaded from the Buffalo website. Screen messages and procedures may change due to future specification updates. For features not covered in this guide, please refer to the product's setup guide or introduction guide (also available as PDF files on the Buffalo website).

Setup and Configuration Plan

Before installing and configuring a Layer 3 switch, it is recommended to plan the network's IP address scheme and the VLAN assignments for each port.

This guide outlines a network configuration for a school LAN environment, involving four VLANs: Teacher Network, Student Network, Shared Network, and Management Network. An additional VLAN is included for the internet access router.

Network Configuration (VLAN Configuration)

The following five VLANs will be configured:

IP Address Scheme and Layer 3 Switch IP Address Assignment

The IP addresses for each VLAN are as follows:

The internet router will be connected to VLAN 14 with its LAN side address set to 192.168.14.1.

DHCP Server Settings (if using the switch's DHCP server):

Note: DHCP assignment is not configured for VLAN 13 and VLAN 14 as no clients are expected to connect.

IP Filtering Considerations

The hardware IP filter will be configured with the following policies:

VLAN Access Rules:

Note: Hardware IP filtering offers various configuration options; this guide covers basic settings.

Layer 3 Switch Port Configuration and Connection Plan

The VLAN configuration for each port on the Layer 3 switch will be determined. Tag VLAN ports will be configured for connecting to other switches or access points that support Tag VLAN.

Port VLAN Assignment:

VLAN 1 (Management): Ports 1-2

VLAN 11 (Teacher): Ports 3-8

VLAN 12 (Student): Ports 9-16

VLAN 13 (Shared): Ports 17-18

VLAN 14 (Internet): Ports 19-20

Tag VLAN Ports: Ports 21-24

Note: VLAN 13 (Shared Network) does not require Tag VLAN configuration as it is not intended for inter-switch connections. Ports 25 and 26 are unused and will remain in VLAN 1. The internet router connects via ports 19 or 20. Connections to other switches or access points utilize ports 21-24.

Layer 3 Switch Setup Workflow

The following steps outline the Layer 3 switch configuration process:

  1. Connect the configuration PC to Port 1 (VLAN 1) of the Layer 3 switch.
  2. Setup Procedure 1: VLAN Network Segmentation
    • Configure the IP address for the Layer 3 switch.
    • Configure VLAN/IP status.
    • Configure VLAN ports.
    • Configure inter-VLAN routing (default gateway, RIP2).
    • Configure system security (admin username/password).
  3. Setup Procedure 2: Hardware IP Filter
    • Configure hardware IP filters.

MEMO: When connecting multiple switches or access points with default IP addresses (192.168.1.254), IP address conflicts may occur. Ensure unique IP addresses are assigned before connecting more than one device.

MEMO: For hardware IP filtering, it is recommended to complete all device configurations before applying filters to avoid difficulties in troubleshooting.

Note: This guide assumes the use of a Buffalo broadband router for internet connection, but other routers can also be used.

The guide includes information on the BS-G3024MR's simple DHCP server function. If your router supports DHCP scope functionality for each VLAN, you can use the switch's DHCP relay function to assign IP addresses via the router.

Layer 3 Switch Setup Procedures

Setup Procedure 1: VLAN Network Segmentation

1. Configure IP Address for Layer 3 Switch

The IP address of the Layer 3 switch is crucial as it is accessed via a web browser. This IP address also serves as the gateway address for the management VLAN.

There are three methods to change the switch's IP address:

  1. Access the default IP address of the product and change it via the web configuration screen.
  2. Change the IP address using AirStation Admin Tools Lite (free management tool).
  3. Connect via a console cable (RS-232C) and set the IP address. (Console cable setup is omitted in this guide; refer to the BS-G3024MR Reference Guide for details.)

Method 1: Using the Web Configuration Screen

This method allows IP address configuration without requiring a separate tool, provided the switch's IP address is still at its default setting.

If the initial IP address is unknown, use AirStation Admin Tools to change it.

  1. The default IP address of the Layer 3 switch is 192.168.1.254 (255.255.255.0). Configure your PC's IP address to be in the same network range (e.g., 192.168.1.253) and access the web interface using a web browser.
  2. Open a web browser and enter 192.168.1.254 in the address bar.
  3. The Layer 3 switch login screen will appear. Enter admin as the username and click OK. (No password is set by default).
  4. The web configuration interface will be displayed.
  5. Navigate to [Basic Settings] > [VLAN/IP Settings] > [VLAN/IP Status].
PC and Switch IP Configuration Example:

Configuration PC IP Address: (e.g.) 192.168.1.253

Subnet Mask: (e.g.) 255.255.255.0

Product IP Address: 192.168.1.254 (Default)

Subnet Mask: 255.255.255.0 (Default)

Changing the IP Address

  1. Click [Edit] next to the VLAN ID 1 entry in the 'VLAN Status' screen to change the IP address and subnet mask.
  2. Set the switch's IP address to 192.168.10.254 and the subnet mask to 255.255.255.0 (default).
IP Address Change Screen (VLAN 1 IP Address Setup):

After changing the IP address, you may need to reconfigure your PC's IP address to access the management interface if the network addresses differ.

Method 2: Using AirStation Admin Tools Lite

AirStation Admin Tools Lite is a free management tool from Buffalo for their business network products. It can be downloaded from the Buffalo website.

This tool allows you to search for Buffalo business network switches and access points on your network and easily change their IP addresses. It can find and display connected devices, enabling you to assign appropriate IP addresses even if you don't know the switch's IP beforehand.

MEMO: When setting up devices in a network, using AirStation Admin Tools can help in identifying devices and setting user-friendly passwords for security.

  1. Download and launch AirStation Admin Tools Lite from the Buffalo website (http://buffalo.jp).
  2. The tool will automatically scan the network for connected Buffalo business network devices. You can perform a manual rescan via the menu: [Edit] > [Rescan].
  3. Select the switch, then navigate to [Tools] > [Change IP Address].
  4. Follow the on-screen instructions to enter the new IP address (e.g., 192.168.10.254) and subnet mask (255.255.255.0).
AirStation Admin Tools Lite Interface:

The IP address configuration for the Layer 3 switch is now complete.

2. Create VLANs (VLAN 1, 11, 12, 13, 14)

Access the Layer 3 switch's web configuration screen as described in the IP address setup section.

  1. Navigate to [Basic Settings] > [VLAN/IP Settings] > [VLAN/IP Status].
  2. Begin by creating VLAN 11.
  3. In the 'Create New VLAN' section, enter the VLAN ID (e.g., 11), VLAN Name (e.g., VLAN11), IP Address (192.168.11.254), and Subnet Mask (255.255.255.0/24).
  4. Configure port settings: Ports 21-24 as 'Static Tagged', Ports 3-8 as 'Static Untagged', and the remaining ports as 'Not Member'. Click 'Set'.
New VLAN Creation Example (VLAN 11):

After the settings are saved, click 'Back'.

Repeat the process to create VLAN 12, VLAN 13, VLAN 14, and VLAN 1.

  • VLAN 12: IP Address 192.168.12.254, Ports 21-24 'Static Tagged', Ports 9-16 'Static Untagged', others 'Not Member'.
  • VLAN 13: IP Address 192.168.13.254, Ports 17-18 'Static Untagged', others 'Not Member'.
  • VLAN 14: IP Address 192.168.14.254, Ports 19-20 'Static Untagged', others 'Not Member'.
  • VLAN 1: IP Address 192.168.10.254. All ports default to 'Static Untagged'. No changes are needed for the management VLAN.

Refer to the port configuration diagram on page 5 of this guide.

Memo: PVID settings, described in the next section, are necessary for VLAN operation.

Layer 3 Switch Setup - Hardware IP Filter

Hardware IP filtering allows you to control data packet transmission between VLANs based on IP addresses and port numbers. This feature provides high-speed filtering without impacting transfer rates.

1. Configure Hardware IP Filter

  1. Create a condition list under [Advanced Settings] > [Hardware IP Filter] > [Condition List]. Name the list (e.g., 'oneway' for one-way access from student to teacher network) and click 'Add'.
  2. Configure the filtering action in the 'Create/Edit New Rule' screen. For example, to deny SYN packets from 192.168.12.0/24 to 192.168.11.0/24, set Action to 'Discard', Source IP to '192.168.12.0/24', Destination IP to '192.168.11.0/24', Protocol to 'TCP', and TCP Control Code to 'SYN'.
One-way Communication Setup (TCP SYN Discard):

This configuration achieves one-way communication by discarding SYN packets, which are essential for TCP/IP session establishment.

VLAN 11 (Teacher) to VLAN 12 Communication:

  • Discard TCP SYN packets from VLAN 12 to VLAN 11.
  • Permit other TCP communications from VLAN 12 to VLAN 11.
  • Permit ICMP (Ping) from VLAN 12 to VLAN 11.
  • Discard all other protocols from VLAN 12 to VLAN 11.

VLAN 12 (Student) to VLAN 11 Communication:

  • Discard TCP SYN packets from VLAN 12 to VLAN 11.
  • Permit other TCP communications from VLAN 12 to VLAN 11.
  • Permit ICMP (Ping) from VLAN 12 to VLAN 11.
  • Discard all other protocols from VLAN 12 to VLAN 11.

Note: To avoid issues during troubleshooting, it's recommended to allow ICMP (Ping) for communication from the user network to the management network.

The rule list will be generated based on the applied settings.

Rule List Example:
NoActionSource IPDestination IPProtocolSource PortDestination PortTCP Control CodeEdit/Delete
1Discard192.168.12.0/24192.168.11.0/24TCPANYANYSYNEdit/Delete
2Permit192.168.12.0/24192.168.11.0/24TCPANYANYANYEdit/Delete
3Permit192.168.12.0/24192.168.11.0/24ICMPANYANYANYEdit/Delete
4Discard192.168.12.0/24192.168.11.0/24ANYANYANYANYEdit/Delete

Similarly, configure settings to block communication from VLAN 13 to VLAN 14. Name this list 'stopall'.

Rule List Example (stopall):
NoActionSource IPDestination IPProtocolSource PortDestination PortTCP Control CodeEdit/Delete
1Discard192.168.13.0/24192.168.14.0/24ANYANYANYANYEdit/Delete

Apply the configured rules to specific ports. For example, apply 'oneway' to the student network ports (9-16) and Tag VLAN ports (21-24), and 'stopall' to the shared network ports (17-18).

Port Application of Rules:
PortInputOutput
1Not AppliedNot Applied
2Not AppliedNot Applied
3Not AppliedNot Applied
4Not AppliedNot Applied
5Not AppliedNot Applied
6Not AppliedNot Applied
7Not AppliedNot Applied
8Not AppliedNot Applied
9onewayNot Applied
10onewayNot Applied
11onewayNot Applied
12onewayNot Applied
13onewayNot Applied
14onewayNot Applied
15onewayNot Applied
16onewayNot Applied
17stopallNot Applied
18stopallNot Applied
19Not AppliedNot Applied
20Not AppliedNot Applied
21onewayNot Applied
22onewayNot Applied
23onewayNot Applied
24onewayNot Applied
25Not AppliedNot Applied
26Not AppliedNot Applied

The Layer 3 switch setup is now complete. Refer to the next page for information on the 'Simple DHCP Server Setup' for IP address assignment.

Reference Information: Simple DHCP Server Setup

This section provides information on configuring the simple DHCP server function of the BS-G3024MR.

For detailed instructions on IP address assignment using a router's DHCP scope function, consult your router's manual.

PDF preview unavailable. Download the PDF instead.

124030430-file-01 PrimoPDF PrimoPDF http://www.primopdf.com/

Related Documents

Preview Buffalo BS-GU2216P Gigabit PoE Network Switch Instruction Manual
Detailed user guide for the Buffalo BS-GU2216P, a 16-port Gigabit PoE Smart Managed Switch. Covers installation, setup, loop prevention, EEE features, specifications, safety, and troubleshooting.
Preview 公衆Wi-Fi向け設定事例集 第3版: BUFFALO FS-M1266
This document provides a collection of setting examples for public Wi-Fi using the BUFFALO FS-M1266. It covers initial setup, various public Wi-Fi deployment scenarios for different business types, and disaster preparedness configurations.
Preview FREESPOT導入キット FS-M1266 設定事例集
This document provides setup examples for the FREESPOT Introduction Kit FS-M1266, covering initial setup, internet connection, password changes, and specific configuration scenarios for various business environments. It details steps for small to medium-sized businesses, including restaurants and public facilities, with instructions on VLAN settings, ACL rules, and Wi-Fi configurations.
Preview Buffalo AirStation Pro WAPM-1266R Command Reference
This document provides a comprehensive command reference for the Buffalo AirStation Pro WAPM-1266R, detailing its command-line interface (CLI) syntax, usage, and parameters for network configuration and management.
Preview Buffalo Corporate Network Catalog 2025-08
Catalog of Buffalo's corporate network products, including Wi-Fi 6/6E routers, switches, and accessories, designed for business environments.
Preview Buffalo AirStation WZR2-G300N Quick Setup Guide
This guide provides quick setup instructions for the Buffalo AirStation Draft-N WZR2-G300N Wireless Router & AP, covering package contents, installation, AOSS secure connection, manual client setup, and technical support details.
Preview Buffalo LinkStation 200 Series NAS Setup Guide: Hardware, Software, and Backup Configuration
A comprehensive setup guide for Buffalo LinkStation 200 Series Network Attached Storage (NAS) devices. This guide covers hardware installation, NAS Navigator software setup for Windows and macOS, drive mapping, and configuring backups using NovaBackup and Time Machine.
Preview BUFFALO 法人向け 無線LANアクセスポイント WAPM-1266R 設定事例集
BUFFALO WAPM-1266R 無線LANアクセスポイントの設定事例を詳細に解説したガイド。バンドステアリング、WDS接続、マルチSSID、TagVLAN、DHCPサーバー機能、FREESPOT連携など、法人向けネットワーク構築の具体的な設定手順を提供します。