Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Equipment Support » Hardware By Brand » Cisco » [Config] Secondary VLAN issue
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Help: IOS for 871 »
« [HELP] 2501 and 1900 with Fiber  
AuthorAll Replies

altu

join:2005-12-18
Beverly Hills, CA
reply to altu
Re: [Config] Secondary VLAN issue

Services.

The application box streams services to the 10.x.x.x range and not to the 192.x.x.x range. But, it still needs the 192.x.x.x range for the internet service.

aryoba
Premium,MVM
join:2002-08-22


edit:
December 20th, @07:05AM

Assuming the application box acts as "full router", then you don't have to setup two subnets on it. Having two subnets in one box is a messy business and you really don't want to be in it. You can just use the 10.x.x.x, remove the 192.x.x.x, and still be able to go to the Internet.

Here are the steps:

1. Set the 3560 as VTP server and 2950 as VTP client

2. Create separate subnet for PIX inside interface, hosts of 3560, and hosts of 2950

As for the routing, static routes should be sufficient:

3. On the PIX, point the 10.x.x.x and 192.x.x.x traffic to the 3560 IP address.

4. I assume you can let the PIX default gateway as it is since it is working, correct?

5. On the 3560, point the 10.x.x.x traffic to the application box IP address. Set the default gateway to the PIX inside interface IP address

6. On the application box, set the default gateway to the 3560 IP address.

Here is an illustration:

1) Let's say the subnets and VLANs are
172.16.0.0/30 for PIX inside interface (VLAN 2)
10.26.0.0/30 for 2950 switch management (VLAN 3)
192.168.0.0/24 for 3560 hosts (VLAN 10)
10.27.22.0/16 for 2950 hosts (VLAN 20)

2) Set 3560 as VTP server and 2950 as VTP client
3560:
Switch(conf)# vtp mode server

2950:
Switch(conf)# vtp mode client

3) Assume the following IP addresses:
172.16.0.1 for PIX inside interface
10.27.22.250, 10.26.0.1, 172.16.0.2, and 192.168.0.250 for 3560
10.27.22.100 for the application box
10.26.0.2 for the 2950

4) PIX configuration
ip address inside 172.16.0.1 255.255.255.252
route inside 10.0.0.0 255.0.0.0 172.16.0.2
route inside 192.168.0.0 255.255.0.0 172.16.0.2
nat (inside) 1 0.0.0.0 0.0.0.0 0 0
global (outside) 1 interface

5) 3560 configuration
interface VLAN1
description Switch Management - DO NOT USE
shutdown

interface VLAN2
description PIX Inside Subnet
ip address 172.16.0.2 255.255.255.252

interface VLAN3
description 2950 Management
ip address 10.26.0.1 255.255.255.252

interface VLAN10
description 3560 Hosts
ip address 192.168.0.250 255.255.255.0

interface VLAN20
description 2950 Hosts
ip address 10.27.22.250 255.255.0.0

ip route 0.0.0.0 0.0.0.0 172.16.0.1

6) 2950 configuration
interface VLAN1
description Switch Management - DO NOT USE
shutdown

interface VLAN3
description 2950 Management
ip address 10.26.0.2 255.255.255.252

ip default gateway 10.26.0.1

7) Application Box
IP Address: 10.27.22.100
Subnet: 255.255.0.0
Gateway: 10.27.22.250
Forums » Equipment Support » Hardware By Brand » CiscoHelp: IOS for 871 »
« [HELP] 2501 and 1900 with Fiber  


Thursday, 08-Jan 00:29:29 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 9 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [160] New Comcast Throttling System 100% Online
· [111] After 10 Years Of Service, Charter Declares Home 'Unserviceable'
· [105] iTunes Dumps The DRM
· [71] AT&T, Verizon Stocks Tumble
· [54] Feds Start Wait List For DTV Converter Coupons
· [52] Cable To Grab 75% Of New Subs In 2009
· [46] DOCSIS 3.0 Gets Faster
· [39] Verizon Again Tweaks DSL Bundles
· [38] Netflix Via LG HDTVs
· [36] New Zealand's 'One Strike' Piracy Law
Most people now reading
· Can't order UVerse and then cancel TV later [AT&T U-verse]
· MLPPP: Fail - ERX06 [TekSavvy]
· Customers punished and sent to ERX06 ! [TekSavvy]
· anyone else getting high pings and slow speeds now? [TekSavvy]
· How to download windows 7 beta [Microsoft help]
· Comcast HSI Price [Comcast HSI]
· What's the issue with shipping to a PO Box? [General Questions]
· cashing a check for my child [General Questions]
· Powering AC worklights off of DC batteries [Home Repair & Improvement]
· Bandwidth Limits - All discussion here [Comcast HSI]