Wondering how inter-vlan routing / internal firewall works with smart switches. Specifically the Netgear GS305/308 products.
I’m new to Peplink, Smart switches, and Vlans (at home). I’ve worked in technology and IT for more than 30 years and my dba job is very technical in nature. But I haven’t been able to work this out and I want to have a plan.
Here’s a semi accurate current picture. I currently do not allow inter-vlan routing for any vlan.
B One Router
Port 1 > Trunk (all vlans permitted) - Downlink GS308Ev4
GS308Ev4
Port 1 > Trunk (all vlans permitted) - UplinkToRouter
Port 8 > Trunk (all vlans permitted) - Downlink GS305E
GS305E
Port 1 > Trunk (all vlans permitted) - UplinkToGS308Ev4
Port 2 > Untagged Access vlan 11 - Iot device
Port 3 > Untagged Access vlan 13 - Security camera
Port 4 > Untagged Access vlan 12 - Roku Ultra
Port 5 > Untagged Access vlan 12 - Tivo mini
I don’t know if I did all this correct, I didn’t ask anybody, kinda just read and worked it out myself, and it works just fine so far. These devices (and others) on vlans 11, 12, and 13 do get assigned dhcp correct addresses and can see / communicate with each other. And when I put my laptop on a vlan 11 wifi, I can’t connect to vlan12 devices, and the like.
But I’d like to understand more about inter-vlan and firewalling for the wired devices that live on/through these switches.
The way I understand it now is if the Tivo Mini on vlan12 wants to talk to the Roku on vlan12, it can, and the traffic never leaves the GS305E switch. And if the Roku on vlan12 tries to talk to the Security camera on vlan 13, the switch drops the traffic as not allowed.
But what if I wanted to allow that? I enable inter-vlan routing for vlan 12 and 13. And do some internal filewall rules, like deny all, then allow this device, to that device. I get that part. What I don’t get is how does that traffic look? Doesn’t the GS305E still just drop the packets? It doesn’t know about the firewall rules or inter-vlan? Or does the trunk ports somehow pass that information down to the switches? Or am I required to wire each of those devices direct all the way back to the B One?