Switches, Hubs, and Modems
cancel
Showing results for 
Search instead for 
Did you mean: 

vlan routing advice

SOLVED
Go to solution
Joseph L. Casale
Regular Advisor

vlan routing advice

I have a problem where we are not ready to make system wide changes but I want to start with some of the implementation now. I have two 2650's connected to a 2824 and want to route between vlans on the 2824. All the network devices use a pix as their default gateway which would also change eventually to the 2824. In the meantime, we are out of logical interfaces on the pix and I need another vlan setup that needs routing (so the pix cant do this now). I planned to simply add a static route on the desktop that needs access to the vlan and point it to the IP of the 2824 for that applicable vlan.

Currently, there are multiple vlans on the 2824 and ip routing is disabled, and only one vlan has an ip. As far as I understand, I can enable ip routing (which turns off the configured default gateway) and I can add an IP to the new vlan in question.

Once this is done, if the network device on vlan1 has a route to the second vlan pointed to 2824's ip on its vlan, this should work? Is there anything else I need to do, can I also setup ACL's to explicitly allow/disallow certain traffic between the vlans?

Thanks!
4 REPLIES
cenk sasmaztin
Honored Contributor
Solution

Re: vlan routing advice

hi I make two config for you one config ip routing between vlan basic config conf procurve switch and internet router and dhcp scobe

because I think you want different config
routing between vlan via on cisco pix for use acl config between vlan
am I understand ?
there fore you look config secont.


cenk

CONFIG FRIST----------------------------------------------------------------------
*procurve 2848 switch config
web-management support-url "http://www.......

ip routing
timesync sntp
snmp-server community "public" Unrestricted

vlan 1
name "user"
untagged 2-20,25-48
ip address 10.0.10.1 255.255.255.0
ip-helper address 10.0.40.2
no untagged 1,21-24
exit
vlan 2
name "internet"
untagged 21
ip address 10.0.20.1 255.255.255.0
exit
vlan 4
name "server"
untagged 24
ip address 10.0.40.1 255.255.255.0
exit
vlan 5
name "user2"
untagged 22-23
tagged 47,48
ip address 10.0.50.1 255.255.255.0
ip-helper address 10.0.40.2
exit
vlan 10
name "management"
untagged 1
tagged 47,48
ip address 192.168.1.1 255.255.255.0
exit
ip route 0.0.0.0 0.0.0.0 10.0.20.2
managemet-vlan 10

note:
internet router in vlan 2 (for internet vlan) and lan ip address 10.0.20.2
dhcp server in vlan 4(for server vlan )and ip address 10.0.40.2
connect frist 2650 interface 47
connect second 2650 interface 48

--------------------------------------------------------------------------
*procurve 2650/1 switch config
web-management support-url "http://www.......


timesync sntp
snmp-server community "public" Unrestricted

vlan 1
name "user"
untagged 1-10,21-50
no untagged 11-20
exit
vlan 5
name "user2"
untagged 11-20
tagged 50
exit
vlan 10
name "management"
tagged 50
ip address 192.168.1.2 255.255.255.0
exit
managemet-vlan 10

note :connect to 2848 with interface 50
-----------------------------------------------------------------------------
*procurve 2650/2 switch config
web-management support-url "http://www.......


timesync sntp
snmp-server community "public" Unrestricted

vlan 1
name "user"
untagged 1-10,21-50
no untagged 11-20
exit
vlan 5
name "user2"
untagged 11-20
tagged 50
exit
vlan 10
name "management"
tagged 50
ip address 192.168.1.3 255.255.255.0
exit
managemet-vlan 10


connect to 2848 interface 50



------------------------------------------------------------------------
*internet router or firewall config

you can basic config on router or firewall for internet connetion .
After you make write static route (on router/firewall)for vlans
example:
ip route 10.0.50.0 255.255.255.0 10.0.20.1
ip route 10.0.40.0 255.255.255.0 10.0.20.1
ip route 10.0.20.0 255.255.255.0 10.0.20.1
ip route 10.0.10.0 255.255.255.0 10.0.20.1





--------------------------------------------------------------------------
*dhcp server config
you can create new scobe each user vlan

scobe 1
scobe name :vlan 1
ip pool:10.0.10.10----10.0.10.200
default gateway :10.0.10.1
dns:10.0.20.2(optional)

scobe 2
scobe name:vlan 5
ip pool 10.0.50.10----10.0.50.200
default gateway :10.0.50.1
dns:10.0.20.2(optional)

note:each scobe send dhcp offer packet associate vlan
---------------------------------------------------------------------------


CONFIG SECONT--------------------------------


----------------------------------------------------------------------
*procurve 2848 switch config
web-management support-url "http://www.......

ip routing
timesync sntp
snmp-server community "public" Unrestricted

vlan 1
name "user"
untagged 3-20,25-48
no untagged 1,3,21-24
tagged 1
exit
vlan 2
name "server"
untagged 24
tagged 1
exit
vlan 5
name "user2"
untagged 22-23
tagged 1,47,48
exit
vlan 10
name "management"
untagged 2
tagged 1,47,48
ip address 192.168.1.1 255.255.255.0
exit
managemet-vlan 10

--------------------------------------------------------------------------
*procurve 2650/1 switch config
web-management support-url "http://www.......


timesync sntp
snmp-server community "public" Unrestricted

vlan 1
name "user"
untagged 1-10,21-50
no untagged 1,11-20
exit
vlan 5
name "user2"
untagged 11-20
tagged 50
exit
vlan 10
name "management"
tagged 50
ip address 192.168.1.2 255.255.255.0
exit
managemet-vlan 10

note :connect to 2848 with interface 50
-----------------------------------------------------------------------------
*procurve 2650/2 switch config
web-management support-url "http://www.......


timesync sntp
snmp-server community "public" Unrestricted

vlan 1
name "user"
untagged 1-10,21-50
no untagged 11-20
exit
vlan 5
name "user2"
untagged 11-20
tagged 50
exit
vlan 10
name "management"
tagged 50
ip address 192.168.1.3 255.255.255.0
exit
managemet-vlan 10


connect to 2848 interface 50



------------------------------------------------------------------------
*internet router or firewall LAN Ä°NTERFACE config
IMPORTANT:THIS DEVICE CONNECT ON 2848 SWICH INTERFACE 1

interface FastEthernet0/0
no ip address
duplex auto
speed auto
!
interface FastEthernet0/0.1
encapsulation dot1Q 1
ip address 10.0.10.1 255.255.255.0
!
interface FastEthernet0/0.2
encapsulation dot1Q 2
ip address 10.0.11.1 255.255.255.0
!
interface FastEthernet0/0.5
encapsulation dot1Q 5
ip address 10.0.15.1 255.255.255.0
!
interface FastEthernet0/0.10
encapsulation dot1Q 10
ip address 10.0.110.1 255.255.255.0
!


vlan 1 pc default gateway ip address 10.0.10.1
vlan 2 pc default gateway ip address 10.0.11.1
vlan 5 pc default gateway ip address 10.0.15.1
vlan 10 oc default gateway ip address 10.0.110.1


AND YOU WANT MAKE ACL CONFÄ°G THIS NETWORK ADDRESS

cenk

Joseph L. Casale
Regular Advisor

Re: vlan routing advice

Hi,
I appreciate the detailed help.

I was hoping to not use the pix for acl's between vlans. It only has 10meg interfaces and a small allowable amount of interfaces. I would like to do everything in the 2824.

So to clarify a few things I don't see any routes in the 2650's, is this ok? I suppose clients will recieve a default gateway of the 2824's ip in that vlan which will provide routing?

Thanks again!
cenk sasmaztin
Honored Contributor

Re: vlan routing advice

hi

frist or secont example config routing operation

-----------------------------------------------
example config frist
all pc default gateway 2824 vlan interface address

and make routing operation
ip routing
*command on switch

ip route 0.0.0.0 0.0.0.0 10.0.20.2
*command on switch

ip route 10.0.50.0 255.255.255.0 10.0.20.1
ip route 10.0.40.0 255.255.255.0 10.0.20.1
ip route 10.0.20.0 255.255.255.0 10.0.20.1
ip route 10.0.10.0 255.255.255.0 10.0.20.1
*ip route command on firewall

-----------------------------------------------
exampel config second

I can create interface fastaehernet0/0 in sub interface
this device already router and make subinterface between
routing each vlan connect sub interface and routing between vlan's



interface FastEthernet0/0
no ip address
duplex auto
speed auto
!
interface FastEthernet0/0.1
encapsulation dot1Q 1
ip address 10.0.10.1 255.255.255.0
!
interface FastEthernet0/0.2
encapsulation dot1Q 2
ip address 10.0.11.1 255.255.255.0
!
interface FastEthernet0/0.5
encapsulation dot1Q 5
ip address 10.0.15.1 255.255.255.0
!
interface FastEthernet0/0.10
encapsulation dot1Q 10
ip address 10.0.110.1 255.255.255.0


cenk
cenk

cenk sasmaztin
Honored Contributor

Re: vlan routing advice

note for second config:pc default gateway address vlan associate subinterface address

cenk
cenk