Cisco 3560 & 3850 SW

Hy,
Please help with the following config:
Site A
SW 3850 ip routing
vlan1 (data) 10.35.247.248/24
vlan20 (voice) 10.35.249.248/24
vlan30 (thin clients) 10.35.248.248/24
vlan60 10.35.246.248
vlan80 video
int gi1/0/47 + gi1/0/48 HSRP GW ip route 0.0.0.0 0.0.0.0 10.35.247.254 (main route wan)
int gi1/0/46 layer 2 VPN to SITE B SW 3560X
int gi1/0/45 layer 3 VPN to SITE B SW 3560X via 10.35.247.250
Site B
SW 3560X ip routing vlan1 10.35.243.248/24
nt gi0/23 + gi1/0/24 HSRP GW ip route 0.0.0.0 0.0.0.0 10.35.243.254 (main route wan)
int gi0/22 layer 2 VPN to SITE A SW 3850
int gi0/21 layer 3 VPN to SITE A SW 3850 via 10.35.243.250
Questions:
What is the best config for the equipments above to:
 - HSRP on SITE A is used as default gw for SITE B also if the from there fails?
-  HSRP on SITE B is used as default gw for SITE A also if the from there fails?
- for layer 2 direct connect what is the best config (trunk ports, vlan clone etc..)?
- the main purpose for 2 VPN lines is redundancy for connection A-B sites. Should we only use one type of layer? (traffic between A-B will be voice (server is on site A backup will be on B), backup for servers (each site will have a DNS & a DC for the same domain), RDS traffic (terminal servers farm members on both sites)
Thank you for your time,

Forgot to add the question for OSPF config !?.
Thank you,

Similar Messages

  • Communication problem between Cisco 3560 and Cisco SG300.

    Dear Support,
    I have a Cisco SG300 and Cisco 3560 switches.
    3560 is my Core Switch and SG300 is access switch.
    From 3560 VLAN information is not passed to SG300.
    3560 Configuration:
    interface GigabitEthernet0/23
    switchport trunk encapsulation dot1q
    switchport trunk allowed vlan 1,2,10,11
    switchport mode trunk
    SG300 Configuration:
    interface gigabitethernet49
    spanning-tree link-type point-to-point
    switchport mode general
    switchport general allowed vlan add 2,10-11 tagged
    macro description switch
    Please suggest how this issue is resolve.
    Regards,
    JItesh Mahajan.

    Dear Aleksandra,
    Below Configuration is right or wrong for 3560 and SG300.
    3560 Configuration:
    interface GigabitEthernet0/23
    switchport trunk encapsulation dot1q
    switchport trunk allowed vlan remove VLAN 1
    switchport native vlan 1
    switchport trunk allowed vlan 1,2,10,11
    switchport mode trunk
    SG300 Configuration:
    interface gigabitethernet49
    spanning-tree link-type point-to-point
    switchport mode general
    switchport general allowed vlan add 2,10-11 tagged
    macro description switch
    Regards,
    JItesh Mahajan.

  • Embeded Event Manager on cisco 3560 switch

    Can someone help me please? I have EEM configured on cisco 3560 switch. The configuration is below. I want that switch inform me through email when device with particilular IP address become unavailable. For some reason this configuration is not good and I can't tell why. I already try to debug this with debug event manager action mail but didn't see any output .
    ip sla 11
    icmp-echo ip address
    frequency 20
    ip sla schedule 11 life forever start-time now
    event manager applet device-TEST
    event snmp oid 1.3.6.1.4.1.9.9.42.1.2.9.1.6.11 get-type exact entry-op lt entry-val "2" poll-interval 20
    trigger occurs 5 period 120
    action 02.0 mail server "ip address" to "[email protected]" from "[email protected]" subject "device is down"

    The mail part looks good, I'm not sure you are hitting the trigger right.
    Why not do a track on the ip sla instead of the snmp stuff?
    Here's a good example of that.
    https://learningnetwork.cisco.com/blogs/network-sheriff/2009/06/19/writing-your-first-eem-applet

  • Ivette manzur : Interface errors problems on cisco 3560

    Hello,
    I have a problem on one of the interfaces on a cisco 3560 switch. In fact, I set up a monitoring network recently (cacti), and I have a significant number of errors on the interfaces. the problem is that when I do a sh interface I see no errors, and even by making a clear counters it does not solve my problem .. I also changed the wiring with cat 6 cables but nothing has changed ..
    What are the main causes of errors on an interface of a switch? what should I do in this case?
    Thank you for your help in advance
    ivette manzur

    Hello,
    I've a e61i and I experience a similar problem. My phone work very well on WiFi network with no encryption as well as 64-bit wep.
    At home I've 2 wireless routers, both encrypted at 128 bits, one with WEP and the other with WPA. On both of them I can correctly obtain an IP thru DHCP, but the traffic do not go thru.
    By using IfInfo I think I discovered the reason of the problem (unless IfInfo is not working properly...) and it seems a bug related to the netmask, broadcast and gateway settings. The router is 192.168.15.1 and this is what I get:
    1) DHCP case -- I get two IP adresses: the 169.254.x.x and the one assigned to the router. DNS is also set properly, but both gateway, broadcast and netmask are set to 0.0.0.0 for both IPs.
    IP Addr: 169.254.162.106
    Netmask: 0.0.0.0
    Broadcast: 0.0.0.0
    Gateway: 0.0.0.0
    DNS1: 192.168.15.1
    IP Addr: 192.168.15.100
    Netmask: 0.0.0.0
    Broadcast: 0.0.0.0
    Gateway: 0.0.0.0
    DNS1: 192.168.15.1
    2) Static IP 192.168.15.64, netmask set to 255.255.255.0 and gateway and DNS set to 192.168.15.1. The 169.254.x.x disappears and I get only one IP which is set to:
    IP Addr: 192.168.15.64
    Netmask: 0.0.0.0
    Broadcast:192.168.15.255
    Gateway: 192.168.15.1
    DNS1: 192.168.15.1
    So in conclusion, it seems that with 128bit encryption, in the DHCP case gateway, broadcast and netmask are not assigned correctly! While in the Static IP case the netmask is still not assigned correctly!!!
    Hope this can help...
    --AP

  • Quick Question about Cisco 3560 and the Web Device Manager

    Alright, I have a quick question that I am curious about but I haven't found any information
    about it.
    When I log into my Cisco 3560 using the web portal to get to the Device Manager. Below the
    diagram of the switch, then under the Dashboard there is section called Switch
    Health, Port Utilization.
    Under the Switch Health there is Bandwidth Used, Packet Error. Those two options just sit
    at zero and do not move. The Port tilization graph is also sitting at zero.
    Is there a way to make them functional?

    Anyone notice performance increase or decrease of their HD when using the nVidia IDE SW drivers?  particularly with a 74GB Raptor?  I've also heard of burner issues when installing the IDE SW but have not used my burner yet.

  • Cisco Catalyst 3850 as ntp master

    Hi All,
    I have 2 x Cisco Catalyst 3850 stacked together. What are your recommendations if I use the C3850 as a ntp master for all edge switches connected in my network? All edge switches must be authenticated if it needs NTP sychronization. But other than that, what are the downsides?
    For example,
    1. I heard that switches do not have an internal clock so is a poor device to be a centralized NTP master.
    2. I have also read that switches also have slow CPU processors that may lack the processing required.
    3. Its NTP sychronization will use external NTP servers which are resolved into IP addresses (e.g. pool.ntp.org). IP address can change. What other more reliable NTP sources are there?
    4. Any other thoughts and comments are most welcome.

    Firstly, DO NOT use the command "ntp master".  Cisco do not recommend using this commands because this will confuse the NTP propagation inside the network.  
    Next, all Cisco devices do not have a dedicated clock.  All appliances need to get SNTP/NTP time synch from somewhere.  This "somewhere" could either be a dedicated GPS-based NTP server and/or a time synch somewhere out in the internet.  
    You can also use the command "ntp update-calendar".  This new command allows appliances to take regular "snapshot" of the time and save it into the NVRAM.  In case there was a reboot or a power failure, the appliance's time is not too far away instead of waiting 5 to 10 minutes for SNTP/NTP to synch.

  • Multiple HSRP instances on Cisco 3560 L3 EMI?

    Hi, can someone tell me if a Cisco 3560 L3 EMI can support HSRP for multiple vlan interafces?

    Hi Billy,
    SMI image does not support HSRP.
    Chek this link for more differnces
    http://www.cisco.com/en/US/products/hw/switches/ps646/products_configuration_example09186a0080169623.shtml
    HTH
    Ankur

  • Ipv6 HSRP gloabl unicast address on cisco 3560 switch

    Dear Team,
    We are using cisco 3560 switch. Now we are going to implement ipv6 in our network. But we are not disturbing to existing ipv4. my question is 1) Can we confiure the global unicast ipv6 address in ipv6 HSRP and 2) can cisco 3560 switch will support ipv4 and ipv6 standby group on same SVI ?                 

    YES

  • Multilayer Cisco 3560 Switched network

    Hi,
    I have a multilayer Cisco 3560 network. All sites are connected to each other using RIP V2. The area marked in red is what we are having an issue with.
    1. We have remote sites connected by microwave links using Cisco 3560.
    2. In the attached image "Site-1" inherits all the configuration from the Headoffice. They also get their internet connection from the Headoffice over the " 256Kbps DSL-DATALINK".
    3. The area marked in red are the 2 sites, they were connected to each other using a data link.
    4. The 100 Mbps microwave links were commissioned lately so we want to use these links for our Internet + Data connections.
    5. HEAD OFFICE switch is running the VTP Domain.
    Question
    1. I have rip version 2 running how do I get "SITE-1" to share the internet connection from Headoffice over the Wireless Links
    2. Site-1 should get the IP address from the HeadOffice DHCP server over the wireless links.
    3. The "DSL-DATALINK" should work as a backup/redundant link. If my 100 Mbps link is down it should automatically switch to the DSL link.
    Kindly give me your expert comments/suggestions in how do I go about achieving the above.
    Regards
    Sarfaraz

    RIP works on hop-count and it will prefer the DSL connection over the Wireless link (1 hop vs 4 hops).
    You can alter this behavior by creating an offset list on routes incoming the data link.
    router rip
    version 2
    offset-list 0 in 5 [data link interface]
    http://www.cisco.com/univercd/cc/td/doc/product/software/ios124/124cr/hirp_r/rte_rih.htm#wp999452
    You need to this on both routers (site1 and HQ).

  • Configuring rcp on ciscoworks LMS 2.5 and cisco 3560 switch

    Dear All,
    i am having LMS 2.5 and nearly 50 cisco 3560 in my network. And I want to configure rcp. How can I do it. Kindly help
    regards,
    RAHIL KHAN

    Have a look at this link for the server:
    http://www.cisco.com/en/US/docs/net_mgmt/ciscoworks_resource_manager_essentials/4.0/user/guide/swmgt.html#wp1328314
    For the device you'll need something like:
    username cwuser password 7 000C1C0A05
    ip rcmd rcp-enable
    ip rcmd remote-host cwuser 172.17.246.221 cwuser enable
    ip rcmd remote-username cwuser

  • How many Cisco Catalyst 3850 switches can make up a Cisco StackPower stack?

    I know the number of Cisco 3850 switches for stacking is 9, so, if I make up a Cisco StackPower stack, MAX is 9, too?

     Hi, emma, only 4 switches can become part of the same Cisco StackPower stack in a ring topology.
    For the Cisco 3850 switches stack number,there are two types:
    Up to 9 Cisco Catalyst 3850 switches can be stacked together to build single logical StackWise-480 switch since Cisco IOS XE Release 3.3.0SE. Prior to Cisco IOS XE Release3.3.0SE, up to 4 Cisco Catalyst 3850 switches could be stacked together.

  • Cisco Catalyst 3850 switches

     How many Cisco Catalyst 3850 switches can stack into a single logical entity?

     Hi, emma, only 4 switches can become part of the same Cisco StackPower stack in a ring topology.
    For the Cisco 3850 switches stack number,there are two types:
    Up to 9 Cisco Catalyst 3850 switches can be stacked together to build single logical StackWise-480 switch since Cisco IOS XE Release 3.3.0SE. Prior to Cisco IOS XE Release3.3.0SE, up to 4 Cisco Catalyst 3850 switches could be stacked together.

  • MTU Size Issue on Cisco 3560 Switch

    Could anybody tell me how to change MTU Size on a Cisco 3560 Switch.i mean to say whether it is to be changed on FastEthernet Interfaces or on VLAN 1 or on Global Configuration Mode and with which Command to change it.

    I am using MPLS on my Routers and the MTU size i have set on my Router Interfaces is 1524.
    When i do a normal ping from Customer's one site to another (where my Traffic has to pass through this Switch VLAN)i get a reply , but when a Ping with a Byte Size of 1500 or more the Packets get completely dropped.
    I think due to MTU Mistach bet. Switch and Router the Packets r getting droped,that is why i was trying to change it.
    could the Packets get dropped because of this reason.Please suggest.

  • DHCP and voice vlan on Cisco 3560 switch

    Greetings,
    I'm setting up a Cisco 3560 switch for voice and data comms. I'm looking for documentation with best practice guidelines for the following requirements.
    1. Using the Cisco 3560 as a DHCP server - Config examples.  Do I need to use different subnets for the voice and data vlans?
    2. Layer 2 CoS QoS  - I'm connecting Aastra phones as well as notebooks - I've been told that Aastra also makes use of the voice vlan config through LLDP and that Aastra phones supports CDP.
    Your assistance will be appreciated.

    Hi ,
    Cisco recommends that you have a separate vlan for  voice and data with different ip subnets for voice and data. You will need to configure the dhcp pool accordingly.
    Here is the config guide for setting up IOS DHCP server:
    http://www.cisco.com/en/US/docs/ios/12_0t/12_0t1/feature/guide/Easyip2.html
    Here is the LAN qos recommendations:
    http://www.cisco.com/en/US/docs/voice_ip_comm/cucm/srnd/7x/netstruc.html#wp1044009

  • How to configure a Cisco 3560 with MAC-based 802.1x authentication by radius server

    Hi dearI 
    How can I configure a Cisco 3560 to authenticate a client based on its mac address with 802.1x and radius server. Many tanks in advance!

    Olivier,
    You can't reference WLP visitor roles in weblogic.xml, but you can
    reference global roles (created using the WLS console):
    - <security-role-assignment>
    <role-name>PortalSystemAdministrator</role-name>
    <externally-defined />
    </security-role-assignment>
    -Phil
    "Olivier" <[email protected]> wrote in message
    news:[email protected]..
    >
    We need to have login page to our portal app.
    When using "form based" authentication is it possible to map the securityon a
    "entitlement role" ?
    Our need is to be abled to give direct url acces to some pages of theportal (for
    exemple by sending urls like"http://server/appcontextpath/appmanager/myportal/mydesktop?_nfpb=true&_page
    Label=mypage")"
    by email to portal users) and need a simple mecanism of authenticationbefore
    redirecting to the portal page.
    Inste

Maybe you are looking for

  • 320PPI  5cm x 5cm ,  and the mobile app that this image appear runs on a mobile phone of 200ppi disp

    IF I DO AN IMAGE in FW or PS of 320PPI  5cm x 5cm ,  and the mobile app that this image appear runs on a mobile phone of 200ppi display resolution, then resolution seem of image should be 200ppi ... in other words should adapt automatically????

  • XML Simple Transformation with Name attribute

    Current logic for reference: ERS tag is presented in XML file as: <ERSFlag>X</ERSFlag> Transformation logic to populate ERS flag value into PO_item structure is as:                   <tt:cond><ERSFlag>                     <tt:value ref="$po_item.ers_

  • Archive Utility and permissions

    I was wondering if there was a way to instruct Archive Utility to use the default permissions when expanding a file. Without a long-winded explanation...I have two users using the same iMac to download client files from various FTP sites. With one us

  • Creating connection error?

    hey all, i have created an application which when run through eclipse works 100% as expected. but when exported as a .jar i recieve an error from conecting to the database in question. String URL = "jdbc:mysql://82.110.105.79:3306/web79-j-clarkhou",

  • All sorts of problems with Address Book

    I am having a lot of problems with my Address Book all of a sudden. It started last Friday when out of nowhere my address book was empty. I used Time Machine to restore it and all was good, but then the next day, the same thing happened. Thankfully I