1748089 Members
4841 Online
108758 Solutions
New Discussion

MSR2003 VLAN

 
desalvo
Established Member

MSR2003 VLAN

my router is ver 7.1.059  and is a JG411A MSR 2003

i can not by any command get the router to do dot1q.

router will not accept the following commands:

<Router> system-view
[Router] interface ethernet 1/1.10
[Router-Ethernet1/1.10] ip address 1.0.0.1 255.0.0.0
[Router-Ethernet1/1.10] vlan-type dot1q vid 10
[Router-Ethernet1/1.10] quit

 

current config is as follows.:

#
version 7.1.059, Release 0306P30
#
sysname Plaza
#
clock timezone Z5 minus 01:00:00
clock protocol none
#
telnet server enable
#
dhcp enable
#
password-recovery enable
#
vlan 1
#
vlan 100
#
vlan 200
#
vlan 233
#
vlan 300
#
vlan 400
#
vlan 500
#
controller Cellular0/0
#
interface Aux0
#
interface NULL0
#
interface Vlan-interface100
ip address 10.101.1.254 255.255.255.0
#
interface Vlan-interface233
ip address 10.1.233.254 255.255.255.0
#
interface Vlan-interface500
ip address 10.101.5.254 255.255.255.0
#
interface GigabitEthernet0/1
port link-mode route
description SITE1_WAN
ip address 10.0.0.223 255.255.255.0
nat outbound port-preserved
nat server protocol udp global 75.145.xxx.xxx 50011 inside 10.101.1.11 50011
nat server protocol udp global 75.145.xxx.xxx 50012 inside 10.101.1.12 50012
nat server protocol udp global 75.145.xxx.xxx 50021 inside 10.101.2.21 50021
nat server protocol udp global 75.145.xxx.xxx 50022 inside 10.101.2.22 50022
nat server protocol udp global 75.145.xxx.xxx 55001 inside 10.101.1.10 55001
nat server protocol udp global 75.145.xxx.xxx 55002 inside 10.101.2.10 55002
nat static enable
undo dhcp select server
#
interface GigabitEthernet0/0
port link-mode bridge
port link-type trunk
port trunk permit vlan 1 100 200 233 300 400 500
#
scheduler logfile size 16
#
line class aux
user-role network-admin
#
line class tty
user-role network-operator
#
line class vty
user-role network-operator
#
line aux 0
authentication-mode password
user-role network-admin
set authentication password hash $h$6$8vBqVFg9h+F0Dukp$R4QjgZFSJ/zXJh7KCK1y93UhYMh4AjgIoNeUibgEF+UPSJ6gJmzLn/Z71pQJvQj3rllV1SetdW7wa0JxrFFA+Q==
#
line vty 0 4
authentication-mode scheme
user-role network-admin
user-role network-operator
set authentication password hash $h$6$k4IwqxQtqql0P2ea$+h5+fsl7WNPvhDVk0ectoBr5pBaydDaNiRq7hGW8WmZcd1XsGtJquMrpNDgYwye5Rt6GM4x/+NaKaew2vfqB6g==
#
line vty 5 63
authentication-mode scheme
user-role metwork-admin
user-role network-admin
user-role network-operator
set authentication password hash $h$6$bJHqvcQArirQuOlq$CL+fEhYp7PbLM35okBPa81kyYlHO/Yf1Ngi4GdUjUEEHMtzrtsimUpMlelnD/C6W75Z5DI1kqQ1JrLDdXWwRYg==
#
ip route-static 0.0.0.0 0 10.0.0.1
#
ntp-service enable
#
acl mac 4000
#
domain system
#
domain default enable system
#
role name level-0
description Predefined level-0 role
#
role name level-1
description Predefined level-1 role
#
role name level-2
description Predefined level-2 role
#
role name level-3
description Predefined level-3 role
#
role name level-4
description Predefined level-4 role
#
role name level-5
description Predefined level-5 role
#
role name level-6
description Predefined level-6 role
#
role name level-7
description Predefined level-7 role
#
role name level-8
description Predefined level-8 role
#
role name level-9
description Predefined level-9 role
#
role name level-10
description Predefined level-10 role
#
role name level-11
description Predefined level-11 role
#
role name level-12
description Predefined level-12 role
#
role name level-13
description Predefined level-13 role
#
role name level-14
description Predefined level-14 role
#
role name role1
rule 1 permit command system-view ; interface 0/0
rule 2 permit command system-view ; vlan 100
vlan policy deny
permit vlan 100 to 500
#
user-group system
#
local-user admin class manage
password hash $h$6$F4aEV33RvbUOQwbx$W+OZ3w8gTn1aDAQdpTSw9bLz6UNlAXwUpWnmMUHwpke2KMhBPtPVe/Z73fMsh5wMnjT5ghda+DW+YpAzVIgmSw==
service-type telnet http https
authorization-attribute user-role network-admin
authorization-attribute user-role network-operator
#
local-user desalvo class manage
password hash $h$6$kC8TcWy1gj0OJ8i4$TEO+VCDmHRCh9K/3Tad3bNCYV1WPZ8jstxfPIOrX35Ba2nN0aqIK6pgN13UpwZFbZ2ItUs6d06B71IG7OjHtMw==
service-type telnet http https
authorization-attribute user-role network-admin
#
local-user ronnie class manage
password hash $h$6$u1+O9Jruk0fZ2AG8$30N4op2m7op8QR/uUwJS0qRl5CkGy80m1qnU8z7ewnDDOAfenD7gBM5A6Uqd/BhvBJc2NYDT/tq4tYiNT7nHIQ==
service-type telnet http https
authorization-attribute user-role network-admin
authorization-attribute user-role network-operator
#
cwmp
cwmp enable
#
ip http enable
ip https enable
web idle-timeout 20
#

9 REPLIES 9
desalvo
Established Member

Re: MSR2003 VLAN

my purpose is to implement 802.1q.

i would like to have my VLANS encapsulated into a single port and trunked over to a HP2610.

the 2610 is already configured and works great with another brand router.

port 26 is my trunk port on the switch from the routers port GE0.

i would just like to add dhcp and the vlans and segragate them out in the switch letting the router take care of the dhcp per vlan and the default gateways per each..

thanks to all

 

 

akg7
HPE Pro

Re: MSR2003 VLAN

Hi,

This command will not work if you are adding under main interface.

There is need of subinterface.

#system view
#interface interface-type interface-number.subnumber
#vlan-type dot1q vid vlan-id O (Enable Dot1q termination on the subinterface, and configure the subinterface to terminate the Dot1q packets with the specified VLAN ID vlan-type dot1q vid vlan-id Optional)

 

Thanks!

Note: While I am an HPE Employee, all of my comments (whether noted or not), are my own and are not any official representation of the companyAccept or Kudo
desalvo
Established Member

Re: MSR2003 VLAN

Yes router will not accept sub interface commands.

 

akg7
HPE Pro

Re: MSR2003 VLAN

Hi,

Its working for me.

[MSR]int GigabitEthernet 5/1.3
[MSR-GigabitEthernet5/1.3]

 

Can you please log a case with support?

Thanks!

Note: While I am an HPE Employee, all of my comments (whether noted or not), are my own and are not any official representation of the companyAccept or Kudo
akg7
HPE Pro

Re: MSR2003 VLAN

Hi,

Also you can refer below link:

https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-c02659367

Thanks!

Note: While I am an HPE Employee, all of my comments (whether noted or not), are my own and are not any official representation of the companyAccept or Kudo
desalvo
Established Member

Re: MSR2003 VLAN

Thanks you AKG7 :  but i have tried many commands even another HP case open with no success in them helping me.

just want to encapsulate all vlan into a "trunk" to a switch where i can break them out to which ever port i want.

I have never not had success with HP.

 

this does not work

 #interface interface-type interface-number.subnumber
#vlan-type dot1q vid vlan-id O 

 

 

akg7
HPE Pro

Re: MSR2003 VLAN

Hi,

But this is working for me:

[MSR]int gi 5/0.1
[MSR-GigabitEthernet5/0.1]vlan-type dot1q vid 10
[MSR-GigabitEthernet5/0.1]

 

Can you please log a case with support.

Thanks!

Note: While I am an HPE Employee, all of my comments (whether noted or not), are my own and are not any official representation of the companyAccept or Kudo
desalvo
Established Member

Re: MSR2003 VLAN

thanks i got a case with them. we are on a conference in a few minutes.. thanks a bunch for your efforts.

 

 

 

sorimuthu
Occasional Visitor

Re: MSR2003 VLAN

HI Team

Can you please help, how to put the restriction on telnet from unauthorized users in public cloud.

i am facing some unauthorized people trying to telnet on HP MSR 2003 router. can you help me the commands for the same.