<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Management VLAN routing problem on 5304 in Switches, Hubs, and Modems</title>
    <link>https://community.hpe.com/t5/switches-hubs-and-modems/management-vlan-routing-problem-on-5304/m-p/4276701#M15787</link>
    <description>"which device have 10.27.58.244 ip"&lt;BR /&gt;it's cisco firewall.&lt;BR /&gt;Before 5304 was manageable over any of it's interfaces, by defining VID9 as management I wanted to restrict it to only one and also keep it accessible from other networks, that's why static route to reach it over external router/firewall. &lt;BR /&gt;</description>
    <pubDate>Mon, 29 Sep 2008 10:55:38 GMT</pubDate>
    <dc:creator>Igoris_1</dc:creator>
    <dc:date>2008-09-29T10:55:38Z</dc:date>
    <item>
      <title>Management VLAN routing problem on 5304</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/management-vlan-routing-problem-on-5304/m-p/4276691#M15777</link>
      <description>assigned VID9 as management, expected it to disappear from routing table, but it is still there and static route that was added to reach VID9 over firewall is not in the table.&lt;BR /&gt;See thread &lt;A href="http://forums12.itrc.hp.com/service/forums/questionanswer.do?admit=109447627+1222340288104+28353475&amp;amp;threadId=1259359" target="_blank"&gt;http://forums12.itrc.hp.com/service/forums/questionanswer.do?admit=109447627+1222340288104+28353475&amp;amp;threadId=1259359&lt;/A&gt; saying that:&lt;BR /&gt;"Management Vlan Subnet won't be inserted in the Routing Table and it will be accessible only from the Same Vlan"&lt;BR /&gt;It's not true, management VLAN is still 'connected' and VID9 is unreachable through firewall.&lt;BR /&gt; Status and Counters - VLAN Information&lt;BR /&gt;&lt;BR /&gt;  Maximum VLANs to support : 40&lt;BR /&gt;  Primary VLAN : DEFAULT_VLAN&lt;BR /&gt;  Management VLAN : valdymas&lt;BR /&gt;&lt;BR /&gt;  VLAN ID Name                 | Status     Voice&lt;BR /&gt;  ------- -------------------- + ---------- -----&lt;BR /&gt;  1       DEFAULT_VLAN         | Port-based No&lt;BR /&gt;  5       LAN3                 | Port-based No&lt;BR /&gt;  6       10.2.2.X             | Port-based No&lt;BR /&gt;  7       DMZ                  | Port-based No&lt;BR /&gt;  8       fire-fire            | Port-based No&lt;BR /&gt;  9       valdymas             | Port-based No&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;                                IP Route Entries&lt;BR /&gt;&lt;BR /&gt;  Destination        Gateway         VLAN Type      Sub-Type   Metric     Dist.&lt;BR /&gt;  ------------------ --------------- ---- --------- ---------- ---------- -----&lt;BR /&gt;  10.27.71.0/24      valdymas        9    connected            0          0&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 26 Sep 2008 10:35:05 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/management-vlan-routing-problem-on-5304/m-p/4276691#M15777</guid>
      <dc:creator>Igoris_1</dc:creator>
      <dc:date>2008-09-26T10:35:05Z</dc:date>
    </item>
    <item>
      <title>Re: Management VLAN routing problem on 5304</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/management-vlan-routing-problem-on-5304/m-p/4276692#M15778</link>
      <description>hi Igoris&lt;BR /&gt;&lt;BR /&gt;please send me sh run print</description>
      <pubDate>Sat, 27 Sep 2008 12:40:18 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/management-vlan-routing-problem-on-5304/m-p/4276692#M15778</guid>
      <dc:creator>cenk sasmaztin</dc:creator>
      <dc:date>2008-09-27T12:40:18Z</dc:date>
    </item>
    <item>
      <title>Re: Management VLAN routing problem on 5304</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/management-vlan-routing-problem-on-5304/m-p/4276693#M15779</link>
      <description>see attached config, I removed some non relevant lines.</description>
      <pubDate>Mon, 29 Sep 2008 04:54:51 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/management-vlan-routing-problem-on-5304/m-p/4276693#M15779</guid>
      <dc:creator>Igoris_1</dc:creator>
      <dc:date>2008-09-29T04:54:51Z</dc:date>
    </item>
    <item>
      <title>Re: Management VLAN routing problem on 5304</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/management-vlan-routing-problem-on-5304/m-p/4276694#M15780</link>
      <description>&lt;BR /&gt;you can write managemet vlan comman on switch for declare. &lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;sw(config)# management-vlan 9&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;cenk</description>
      <pubDate>Mon, 29 Sep 2008 09:57:39 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/management-vlan-routing-problem-on-5304/m-p/4276694#M15780</guid>
      <dc:creator>cenk sasmaztin</dc:creator>
      <dc:date>2008-09-29T09:57:39Z</dc:date>
    </item>
    <item>
      <title>Re: Management VLAN routing problem on 5304</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/management-vlan-routing-problem-on-5304/m-p/4276695#M15781</link>
      <description>it is already done, I probably accidentally deleted this from posted config.</description>
      <pubDate>Mon, 29 Sep 2008 10:02:09 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/management-vlan-routing-problem-on-5304/m-p/4276695#M15781</guid>
      <dc:creator>Igoris_1</dc:creator>
      <dc:date>2008-09-29T10:02:09Z</dc:date>
    </item>
    <item>
      <title>Re: Management VLAN routing problem on 5304</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/management-vlan-routing-problem-on-5304/m-p/4276696#M15782</link>
      <description>hi Igoris&lt;BR /&gt;&lt;BR /&gt;please send me true sh run print&lt;BR /&gt;&lt;BR /&gt;and sh ip route print &lt;BR /&gt;&lt;BR /&gt;cenk</description>
      <pubDate>Mon, 29 Sep 2008 10:15:05 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/management-vlan-routing-problem-on-5304/m-p/4276696#M15782</guid>
      <dc:creator>cenk sasmaztin</dc:creator>
      <dc:date>2008-09-29T10:15:05Z</dc:date>
    </item>
    <item>
      <title>Re: Management VLAN routing problem on 5304</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/management-vlan-routing-problem-on-5304/m-p/4276697#M15783</link>
      <description>see attached both outputs in one file.</description>
      <pubDate>Mon, 29 Sep 2008 10:29:21 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/management-vlan-routing-problem-on-5304/m-p/4276697#M15783</guid>
      <dc:creator>Igoris_1</dc:creator>
      <dc:date>2008-09-29T10:29:21Z</dc:date>
    </item>
    <item>
      <title>Re: Management VLAN routing problem on 5304</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/management-vlan-routing-problem-on-5304/m-p/4276698#M15784</link>
      <description>&lt;BR /&gt;??????????&lt;BR /&gt;&lt;BR /&gt;ip route 10.27.71.0 255.255.255.0 10.27.58.244</description>
      <pubDate>Mon, 29 Sep 2008 10:39:55 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/management-vlan-routing-problem-on-5304/m-p/4276698#M15784</guid>
      <dc:creator>cenk sasmaztin</dc:creator>
      <dc:date>2008-09-29T10:39:55Z</dc:date>
    </item>
    <item>
      <title>Re: Management VLAN routing problem on 5304</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/management-vlan-routing-problem-on-5304/m-p/4276699#M15785</link>
      <description>10.27.58.244 is the firewall, but this static route is not in the table, as 10.27.71.0/24 is still 'connected' regardless it's management VLAN</description>
      <pubDate>Mon, 29 Sep 2008 10:43:57 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/management-vlan-routing-problem-on-5304/m-p/4276699#M15785</guid>
      <dc:creator>Igoris_1</dc:creator>
      <dc:date>2008-09-29T10:43:57Z</dc:date>
    </item>
    <item>
      <title>Re: Management VLAN routing problem on 5304</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/management-vlan-routing-problem-on-5304/m-p/4276700#M15786</link>
      <description>which device have 10.27.58.244 ip&lt;BR /&gt;&lt;BR /&gt;managemet vlan isolated routing between vlans&lt;BR /&gt;but &lt;BR /&gt;you write ip route command for 10.27.71.0 network &lt;BR /&gt;delete this routing command for management vlan security</description>
      <pubDate>Mon, 29 Sep 2008 10:47:25 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/management-vlan-routing-problem-on-5304/m-p/4276700#M15786</guid>
      <dc:creator>cenk sasmaztin</dc:creator>
      <dc:date>2008-09-29T10:47:25Z</dc:date>
    </item>
    <item>
      <title>Re: Management VLAN routing problem on 5304</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/management-vlan-routing-problem-on-5304/m-p/4276701#M15787</link>
      <description>"which device have 10.27.58.244 ip"&lt;BR /&gt;it's cisco firewall.&lt;BR /&gt;Before 5304 was manageable over any of it's interfaces, by defining VID9 as management I wanted to restrict it to only one and also keep it accessible from other networks, that's why static route to reach it over external router/firewall. &lt;BR /&gt;</description>
      <pubDate>Mon, 29 Sep 2008 10:55:38 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/management-vlan-routing-problem-on-5304/m-p/4276701#M15787</guid>
      <dc:creator>Igoris_1</dc:creator>
      <dc:date>2008-09-29T10:55:38Z</dc:date>
    </item>
    <item>
      <title>Re: Management VLAN routing problem on 5304</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/management-vlan-routing-problem-on-5304/m-p/4276702#M15788</link>
      <description>vlan 9 L3 interface on your switch if you write managemet vlan command on switch for vlan 9 unable routing other L3 interface (namely vlan's)&lt;BR /&gt;&lt;BR /&gt;but if you write static routing  command vlan 9 (L3 interface) between other L3 interface (router or firewall) able routing vlan 9&lt;BR /&gt;&lt;BR /&gt;if you can want protech managemet&lt;BR /&gt;if you can want remote control your network switch &lt;BR /&gt;&lt;BR /&gt;you can use &lt;BR /&gt;managemet vlan &lt;BR /&gt;ip authorize manager&lt;BR /&gt;ssh&lt;BR /&gt;ssl &lt;BR /&gt;acl for managemet vlan network&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 29 Sep 2008 11:30:35 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/management-vlan-routing-problem-on-5304/m-p/4276702#M15788</guid>
      <dc:creator>cenk sasmaztin</dc:creator>
      <dc:date>2008-09-29T11:30:35Z</dc:date>
    </item>
    <item>
      <title>Re: Management VLAN routing problem on 5304</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/management-vlan-routing-problem-on-5304/m-p/4276703#M15789</link>
      <description>&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Issuing the management-vlan command will have several effects:&lt;BR /&gt;ô    First, it disables the ability for a switch to receive management traffic on any&lt;BR /&gt;IP address other than the one assigned to the management VLAN.&lt;BR /&gt;When you attempt to connect to the switch by specifying any other IP address&lt;BR /&gt;other than the one assigned to the Secure Management VLAN, you will&lt;BR /&gt;receive a typical error message for the application you are using (Telnet,&lt;BR /&gt;SSH, or web browser) indicating a connection could not be established. It&lt;BR /&gt;will appear not unlike a situation where a typical network disruption appears&lt;BR /&gt;to be the problem.&lt;BR /&gt;For example, for Telnet you will receive a message similar to the following:&lt;BR /&gt;â  Connecting To 10.1.2.1...Could not open connection to the host, on&lt;BR /&gt;port 23: Connect failedâ  .&lt;BR /&gt;ProCurve Device Management Security&lt;BR /&gt;Rev. 7.31 2 â   187&lt;BR /&gt;ô    Second, it disables any communication from outside the Secure Management&lt;BR /&gt;VLAN network.&lt;BR /&gt;Hidden ACLs are placed on the Secure Management VLAN, preventing any&lt;BR /&gt;and all network traffic from getting into Secure Management VLAN. So, for&lt;BR /&gt;example, you will not be able to ping the IP address of the Secure&lt;BR /&gt;Management VLAN from an IP address associated with any other VLAN.&lt;BR /&gt;In the case of a ping command, you will receive a â  Request timed-outâ   error&lt;BR /&gt;message.&lt;BR /&gt;ô    Third, it will allow management stations within the Secure Management&lt;BR /&gt;VLAN to source IP packets from that VLAN. For example, a management&lt;BR /&gt;station will be able to ping destinations in other user VLANs.&lt;BR /&gt;Operating notes for a Secure Management VLAN&lt;BR /&gt;ô    You can only use a static, port-based VLAN for the Secure Management&lt;BR /&gt;VLAN.&lt;BR /&gt;ô    The Secure Management VLAN does not support IGMP.&lt;BR /&gt;ô    If there are more than 25 VLANs configured on the switch, reboot the switch&lt;BR /&gt;after configuring the Secure Management VLAN.&lt;BR /&gt;ô    If you implement a Secure Management VLAN in a switch mesh&lt;BR /&gt;environment, all meshed ports will be members of the Secure Management&lt;BR /&gt;VLAN.&lt;BR /&gt;ô    Only one Secure Management VLAN can be defined on a switch. If one&lt;BR /&gt;Secure Management VLAN ID is saved in the startup-config file and you&lt;BR /&gt;configure a different VLAN ID in the running-config file without saving the&lt;BR /&gt;running-config to the startup-config, then the switch uses the running-config&lt;BR /&gt;version until you reboot the switch, at which time the Secure Management&lt;BR /&gt;VLAN will revert to the one in the startup-config.&lt;BR /&gt;ô    During a management session with the switch, if you define the Secure&lt;BR /&gt;Management VLAN that excludes the port through to which you are&lt;BR /&gt;connected on the switch, you will continue to have access only until you&lt;BR /&gt;terminate the session by logging out or rebooting the switch.&lt;BR /&gt;ô    Enabling Spanning Tree Protocol where there are multiple links using&lt;BR /&gt;separate VLANs, including the Secure Management VLAN, between a pair&lt;BR /&gt;of switches, Spanning Tree will force the blocking of one or more links. This&lt;BR /&gt;may include the link carrying the Secure Management VLAN, which will&lt;BR /&gt;cause loss of management access to some devices.</description>
      <pubDate>Mon, 29 Sep 2008 11:37:36 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/management-vlan-routing-problem-on-5304/m-p/4276703#M15789</guid>
      <dc:creator>cenk sasmaztin</dc:creator>
      <dc:date>2008-09-29T11:37:36Z</dc:date>
    </item>
    <item>
      <title>Re: Management VLAN routing problem on 5304</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/management-vlan-routing-problem-on-5304/m-p/4276704#M15790</link>
      <description>"Second, it disables any communication from outside the Secure Management&lt;BR /&gt;VLAN network. "&lt;BR /&gt;Is it true even using external router? Let's say I have several SNMP servers, located in different networks, so the only server able to reach switch is the one from management VLAN ip range? And what about desktops, located in management VLAN, isolated from outside?</description>
      <pubDate>Mon, 29 Sep 2008 12:21:05 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/management-vlan-routing-problem-on-5304/m-p/4276704#M15790</guid>
      <dc:creator>Igoris_1</dc:creator>
      <dc:date>2008-09-29T12:21:05Z</dc:date>
    </item>
    <item>
      <title>Re: Management VLAN routing problem on 5304</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/management-vlan-routing-problem-on-5304/m-p/4276705#M15791</link>
      <description>so, no solution for my problem. I will try to explain better what I'm trying to achieve:&lt;BR /&gt;1.restrict management access to only one VLAN, instead of many VLAN IP interfaces on my core 5304 switches. This is done by management VLAN statement.&lt;BR /&gt;2.Keep management VLAN accessible from other VLANs over external router/firewall, that means management VLAN 9 should be accessible from let's say VLAN 5 over static route to external router/firewall. At the moment static route can't be inserted into routing table, as same network is already there as 'connected', regardless it is defined as 'management'.</description>
      <pubDate>Fri, 03 Oct 2008 06:22:08 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/management-vlan-routing-problem-on-5304/m-p/4276705#M15791</guid>
      <dc:creator>Igoris_1</dc:creator>
      <dc:date>2008-10-03T06:22:08Z</dc:date>
    </item>
    <item>
      <title>Re: Management VLAN routing problem on 5304</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/management-vlan-routing-problem-on-5304/m-p/4276706#M15792</link>
      <description>&lt;BR /&gt;I do not think you accomplish both those things when using the management-vlan command, since that actually forbids any connections from outside this perticular VLAN.&lt;BR /&gt;&lt;BR /&gt;A solution would be to define some random VLAN with a IP address, but NOT as a "hard" management-vlan, and define your own accesslists which only allows telnet/ssh/snmp traffic from your desired VLANs, and the set up the correct routing on the switch and on your firewall.</description>
      <pubDate>Fri, 03 Oct 2008 06:37:24 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/management-vlan-routing-problem-on-5304/m-p/4276706#M15792</guid>
      <dc:creator>RicN</dc:creator>
      <dc:date>2008-10-03T06:37:24Z</dc:date>
    </item>
  </channel>
</rss>

