07-05-2018 06:49 AM
Hi,
I was wondering if anyone has setup the sbrio-9627 with interal Vlan tagging?
To tag for eksempel two different TCP ports with different vlans for network segregation?
Regards
Mrmas
09-06-2018 03:53 AM - edited 09-06-2018 03:57 AM
Hello Mrmas,
Yes, for the first part of your question, I did so. As the sbRIO-9627 is a Linux device, it's possible using standard Linux commands, and including it into some of the NI scripts used to automate the network set-up. This is what I did (there might be better ways, especially extending to hide the VLAN(s) from NI MAX which does not support VLANs):
I ssh'ed into my sbRIO and used opkg list-installed | grep vlan to check that the vlan support package is already installed.
Then I did this to set up a VLAN temporarily without changing config files. In case I locked myself out I could simply have rebooted the device to load the previous configuration letting me in again.
Afterwards, I implemented this into the configuration files:
Please be aware of these caveats of this approach:
Regarding the second part of your question, defining a VLAN id per TCP port: I have not tried this. As TCP ports are on OSI model layer 5 whereas VLAN tagging is Ethernet (= Level 2), you need additional configuration to reach this goal. I am sure it will work using the normal Linux tools. I personally would implement this using firewall rules with iptables, allowing only strictly defined routes.