- Community Home
- >
- Networking
- >
- Legacy
- >
- Switches, Hubs, Modems
- >
- Multiple routes between 5406 and FW
-
- Forums
-
Blogs
- Alliances
- Around the Storage Block
- Behind the scenes @ Labs
- HPE Careers
- HPE Storage Tech Insiders
- Infrastructure Insights
- Inspiring Progress
- Internet of Things (IoT)
- My Learning Certification
- OEM Solutions
- Servers: The Right Compute
- Shifting to Software-Defined
- Telecom IQ
- Transforming IT
- Infrastructure Solutions German
- L’Avenir de l’IT
- IT e Trasformazione Digitale
- Enterprise Topics
- ИТ для нового стиля бизнеса
- Blogs
-
Quick Links
- Community
- Getting Started
- FAQ
- Ranking Overview
- Rules of Participation
- Contact
- Email us
- Tell us what you think
- Information Libraries
- Integrated Systems
- Networking
- Servers
- Storage
- Other HPE Sites
- Support Center
- Enterprise.nxt
- Marketplace
- Aruba Airheads Community
-
Forums
-
Blogs
-
InformationEnglish
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
01-21-2010 12:59 PM
01-21-2010 12:59 PM
What is the best approach to configure a separate path between the FW and my LAN just for mgmt traffic and how is it configured on the 5406 end?
My thought was to use another interface on the FW, create a new security zone, assign a /29 network, create the VLAN on the 5406 and select a port to terminate to from the FW.
What is alluding me is how I create a route for this new VLAN on the 5406 so that when traffic crosses it, it has access to a mgmt vlan that all hosts have an interface in, without it being a route to the Internet.
Thanks,
David
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
01-22-2010 12:26 AM
01-22-2010 12:26 AM
Re: Multiple routes between 5406 and FW
You need a device directly connected on this vlan to access devices with addresses on this vlan.
You can create a vpn-tunnel that terminates in this vlan with an interface on your FW.
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
01-22-2010 05:36 AM
01-22-2010 05:36 AM
Re: Multiple routes between 5406 and FW
Would selecting an available physical interface on my FW, connecting it to a port on the switch that is assigned to the mgmt vlan and assigning an IP in the subnet of this vlan to the FW interface do the trick? Then, when I VPN in to the FW I could grant access to only this network from the VPN tunnel instead of the vlan that has access to every network and is the default route to the Internet from the LAN.
How would I prevent this mgmt only vlan from being routed by the switch once it is created? It looks like the switch creates a route the minute I give the vlan an IP address.
David
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
01-22-2010 06:34 AM
01-22-2010 06:34 AM
Solutionfrom access and security guide :
Secure Management VLAN
This feature creates an isolated network for managing the ProCurve switches
that offer this feature. When a secure management VLAN is enabled, CLI, Menu
interface, and Web browser interface access is restricted to ports configured
as members of the VLAN. For more information, refer to the chapter titled
â Static Virtual LANs (VLANs)â in the Advanced Traffic Management Guide.
from advanced traffic management guide
If you configure a Secure Management VLAN, access to the VLAN and to the
switchâ s management functions (Menu, CLI, and web browser interface) is
available only through ports configured as members.
configuration command is :
management-vlan
Hewlett Packard Enterprise International
- Communities
- HPE Blogs and Forum
© Copyright 2019 Hewlett Packard Enterprise Development LP