republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Equipment Support » Hardware By Brand » Cisco » [Config] Secondary VLAN issue
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Help: IOS for 871 »
« [HELP] 2501 and 1900 with Fiber  
AuthorAll Replies

altu

join:2005-12-18
Beverly Hills, CA

reply to altu
Re: [Config] Secondary VLAN issue

VLAN1 is being used for management.

The default gateway for the 2950 is the application server on 10.27.22.100. The application server has also another network card 192.168.0.100 and does routing in between the two networks.

I wanted the secondary vlan on the port that connects to the PIX. Is that possible?

Thanks again.

aryoba
Premium,MVM
join:2002-08-22


edit:
December 19th, @09:26AM

1. Comment on "I need to set both of the switches to transparent"

In switch environment (read: VTP Domain), there MUST be one AND only one switch act as VTP Server to handle the switch management (i.e. VLAN and trunking info). Other switches must be in either VTP client or transparent. If your network only consists of two switches, one of them must be the VTP Server. You CANNOT set both switches as transparent.

2. VTP Server, Client, and Transparent assignment

If I were you, I would set the 3560 to be the VTP Server and the 2950 to be the VTP client or transparent. Since the 3560 is handling the inter-VLAN routing, it makes sense at the same time to be the VTP Server.

3. VLAN Management

DO NOT use VLAN 1 for user data since VLAN 1 is reserved for switch management. Setup a new VLAN for users on 3560 switch (i.e. VLAN 10) and a new VLAN for the PIX Firewall (i.e. VLAN 2).

4. VTP Domain name

Since both switches are to be in the same VTP Domain, both switches must have the same VTP Domain name. Otherwise VLAN and trunking info (among other things) are not known on both switches.

5. Subnet separations

The PIX inside (internal) interface subnet should be different than the subnet of 3560 users. As illustrated previously, VLAN 2 could belong to the PIX and VLAN 10 could belong to the 3560 users.

6. 2950 Default Gateway

The 2950 default gateway should be the 3560 interface VLAN 20 IP address since (again) the 3560 is handling the inter-VLAN routing.

7. The "spanning-tree portfast" command usage

The "spanning-tree portfast" command should be applied on ports only when those ports go to COMPUTERS ONLY. When such ports go to different device other than computers (i.e. firewall or router), there should be no "spanning-tree portfast" command applied.

8. The Application Box that acts as a router

Since basically there are at least two routers in your network (the 3560 and the application box), there should be some kind of routing protocol mechanism between the two. You might want to run dynamic routing protocol or just static routing.

CLARIFICATION:
I believe your network has two Internet gateways. One goes through the PIX and another goes through the application box. Is this true?

Or maybe the application box go to internal network?

Can you redraw your network setup? This time please include the 2nd network and everything.

Tips:
You can use the HTML code "PRE" and "/PRE" when drawing the network. Therefore you don't have to add the ***
Forums » Equipment Support » Hardware By Brand » CiscoHelp: IOS for 871 »
« [HELP] 2501 and 1900 with Fiber  


Tuesday, 02-Dec 05:46:29 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 9 years online! © 1999-2008 dslreports.com.
page compression OFF
Most commented news this week
· [94] AT&T Metered Billing Trial Hits Second Market
· [69] UDP BitTorrent Will Destroy The Interwebs!
· [57] Comcast Tries To Slow Verizon's Philly Entry
· [17] FCC To Vote On Free National Wireless Broadband
· [14] Clearwire May Slow WiMax Build
· [7] Embarq Rejected Higher Offer
· [7] Hawaii Telecom Files For Bankruptcy
· [6] Monday Evening Links
Most people now reading
· Is this a good thing for the net? [news,99366]
· Level 80 PVP gear info? [World of Warcraft]
· Maintaince Tonight or tomorrow? [TekSavvy]
· Upverting DVD players vs Blue ray DVD players. [General Questions]
· Extjs grid combo box. [Webmasters and Developers]
· Java SE Runtime Environment (JRE) 6 Update 11 [Security]
· Notice, new uTorrent Alpha may be able to evade throttling [TekSavvy]
· [WotLK] PVP gear at 80 [World of Warcraft]
· [WotLK] WotLK Instance Order? [World of Warcraft]
· Coalition Government Possible? [TekSavvy]