- Community Home
- >
- Networking
- >
- Switching and Routing
- >
- Comware Based
- >
- Re: Vlan Traffic Question For The Following Exampl...
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-04-2012 12:20 PM
04-04-2012 12:20 PM
In the example below I have the following question - let me say that by coming from a whole cisco environment prior to this job that my mind gets a bit cloudy on the untagging / tagging stuff. Here is my question
Will the port traffic from vlan 800 and vlan 700 traverse out over vlan 900?
Vlan 900 in this example is a fiber link on port 21 to another switch
Is this the way to do what I am asking?
Thanks in advance.
vlan 1
name "DMZ-PRI"
no ip address
no untagged 1-24
exit
vlan 800
name "DMZ-SEC"
untagged 2,4,6,8,10,12,14,16,18,20
ip address 10.50.0.4 255.255.255.0
exit
vlan 900
name "VLAN900"
untagged 21-24
tagged 1-20
exit
vlan 700
name "DMZ-PRI"
untagged 1,3,5,7,9,11,13,15,17,19
ip address 10.51.0.100 255.255.0.0
exit
Solved! Go to Solution.
- Tags:
- VLAN
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-05-2012 12:20 AM
04-05-2012 12:20 AM
Re: Vlan Traffic Question For The Following Example
No, since the vlan 900 doesnt have any ip address it cant route any traffic, only traffic within vlan 900 will traverse the port 21.
CCIE Service Provider
MASE Network Infrastructure [2011]
H3CSE
CCNP R&S
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-05-2012 04:50 AM
04-05-2012 04:50 AM
Re: Vlan Traffic Question For The Following Example
So having said this - if an ip address is on vlan 900 then this will pass data as expected.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-05-2012 04:54 AM
04-05-2012 04:54 AM
Re: Vlan Traffic Question For The Following Example
sure. depending on what you need to reach you'll also need the appropriate routes, or a default route.
CCIE Service Provider
MASE Network Infrastructure [2011]
H3CSE
CCNP R&S
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-05-2012 07:19 AM
04-05-2012 07:19 AM
SolutionLet me further clarify my setup as I may have mistated.
What this configuration represents is a 2 switch DMZ security zone connected to the dmz interface of an ASA 5520
The vlan config is as follows from both switches.
On switch A
vlan 1
name "not used"
no ip address
no untagged 1-24
exit
vlan 800
name "DMZ-SEC"
untagged 2,4,6,8,10,12,14,16,18,20
ip address 10.50.0.4 255.255.255.0
exit
vlan 900
name "VLAN900"
untagged 21-24
ip address 10.52.0.1 255.255.255.0
tagged 1-20
exit
vlan 700
name "DMZ-PRI"
untagged 1,3,5,7,9,11,13,15,17,19
ip address 10.51.0.3 255.255.255.0
exit
---------------------------------------------------------------------------------------------
On Switch B
vlan 1
name "not used"
no ip address
no untagged 1-24
exit
vlan 800
name "DMZ-SEC"
untagged 2,4,6,8,10,12,14,16,18,20
ip address 10.50.0.5 255.255.255.0
exit
vlan 700
name "DMZ-PRI"
untagged 1,3,5,7,9,11,13,15,17,19
ip address 10.51.0.4 255.255.255.0
exit
vlan 900
name "VLAN900"
untagged 21-24
ip address 10.52.0.2 255.255.255.0
tagged 1-20
exit
-------------------------------------------------
On switch A
I can ping
10.51.0.3
10.50.0.4
10.52.0.1
10.52.0.2 - So I am crossing the vlan 900 inface to the other switch
On switch A
I can ping
10.51.0.4
10.50.0.5
10.52.0.2
10.52.0.1 - So I am crossing the vlan 900 inface to the other switch
So even though I have tagged ports 1-20 on each switch on vlan 900 I can't seem to reach completely from one side to the other.
Will this not work or am I missing something rediculously obvious?
Thanks in advance.