Multi-VLAN switching

HSA supports multi-VLAN for the LAN switch ports, and can optionally perform inter-VLAN routing between different VLANs. For example, we can assign the 4 GE LAN ports into different VLANs, and restrict host accesses across different VLANs. This will be useful to F&B/retails who want to share the same box for both Intranet and Internet access. With Multi-VLAN support, we can separate Internet and Intranet traffic for better security.

NOTE: please do note confuse Multi-VLAN switching with Multi-WAN trunking (next section).

Configuration scenarios:

CONFIGURATION SUMMARY


CONFIGURATION DETAILS

1. Access to HSA through local connection or via mfusion portal. see details.

2. Create new VLAN and assign switch ports to each VLAN (Network --> Switch). Enable VLAN functionality, Create new VLAN10 & 20.

 NOTE:

3. Create VLAN interface for each VLAN (eg. VLAN10 & VLAN20). This is similar to a typical Layer3 switch. We need to define a logical VLAN interface for each VLAN, and the VLAN interface becomes the default gateway (router interface) for that VLAN.

NOTE:

Follow the same steps for VLAN20, and we should have something like this:

4. Configure firewall rules to permit/restrict inter-VLAN access. In this example, we only allow VLAN10, VLAN20 and default VLAN traffic to go out to WAN, we don't permit any inter-VLAN access. We can change the rules to permit inter-VLAN access whenever neccessary.