Configure vlan with SG 300-10P and SA 520
Hi All,
Forgive my ignorance but i need some help for basic configuration.
I bought for a little office a SA520 Security appliance (for future VPN with another distant office) and a SG 300-10P switch for connect 3 PC and 3 IP PHONE. THe SA 520 is the router. I must configure 2 VLANs on the switch :
VLAN2 : DATA (for PC)
VLAN3 : VOICE (for IP PHONE)
VLAN1 : DEFAULT.
How can i simply configure all ports ?
I would like to configure ports 1-4 on VLAN2 and ports 5-8 on VLAN3 and port G10 is reserved for the router SA520.
I want to divise network DATA/VOICE.
I think i must create a trunk on G10 for SA520 ...
Does anyone can help me?
Hi Julien,
Ok sounds like you are using the default vlan for management on the network and vlan 2 for data and vlan3 for voice.
I am using a simulator for this, my SA520 is loaned out at the moment.
Step 1 On the SA520 add vlan 2 and vlan 3 and label them data and voice respectively.
Step 2. Lets use switch port 4 on the SA520 as a trunked port to the SG-300.
(my intention is to use untagged vlan1, tagged vlan 2 and tagged vlan 3 on the uplink from the switch and the SA500.)
To do this I have to tell the SA520 that switch port 4 will be in trunking mode and not access mode.
You will have to tick off the membership of vlan 2 and vlan 3 on switch port 4.
Step 3. Now add some IP addresses for VLAN2 and VLAN3
Step 4. Create some DHCP scopes if that is what is needed on the SA520
So by now hopefully we have the SA520 with IP addresses associated with VLAN1, VLAN2 and VLAN3
We also have switch port 4 as a trunk interface
We are propogating untagged vlan1 and tagged vlan2 and tagged vlan3 to the SG-300 switch.
We have to do the opposite on the SG-300 switch.
If you are using G10 as the uplink to the SA520 you will note by default port 10 should already be in trunk mode.
switch port G10 should be tagged for vlan 2 and tagged for vlan3. By default Gi10 it will be untagged for vlan1.
Make sure you set up the rest of the switch ports appropriately.
regards Dave
Similar Messages
-
How do I add a Subnet and vlan with a catalyst 3550 and RV120
Hello Friends.
I have a scenario that i'm hoping i can get some help with. I'll be as detailed and descriptive as i can.
This is for a business with 100 employees nodes and 100 camera nodes all needing IP internet through private addressing and public gateway.
I have a business class gateway with a private range of 12 public addresses. Ther modem does nothing but act as a gateway since i have disabled the firewall and DHCP.
In place of the firewall and DCHP from the modem i have installed a RV120 Firewall with VPN. When installing i replicated the IP scheme of the modem as to not disturb and distrup the devices assigned addresses from that scheme from the modem. I did this because the owner could not have any down time or any disruption to the business operations.
The RV120 now acts as firewall , DHCP , and VPN. I'll address the subnet first. I's using 10.0.0.0/24 subnet range.
DHCP is assigning 10.1.10.50 - 10.1.10.100 the rest are static and i plan to use static DHCP with the IP and MAC assigned to each static DHCP address.
There are 100 cameras with static IP addresses in the range of 10.1.10.11 - 10.1.10.40, and 10.1.0.1.101 - 10.1.10.170.
VPN uses PPTP assigned address 10.1.10.6 - 10.1.10.10.
There are no layer 3 switches that i know of. Just a layer two that is the primary swith and ports have run out, and various out of the box switches and wireless access points connected to the primary switch.
I want to implement subnets into the network and VLANS as well on a new Layer 3 switche from cisco. Thinking 3550 from Cisco or one of the older layer 2 switches with layer three capabilities.
I also want to introduce a 192.168.0.0/24 IP range for the existing wireless network and segment the traffic from the rest of the traffic on other ranges.
I want to replace the 10.0.0.0/24 DHCP alltogether and the static addresses for end user nodes on the same network, but keep that range just for camera nodes segmented.
I want to implement a NEW end user IP range and VLAN for employee/guest networks using the 172.16.0.0/24 range.
Iv'e thought of replacing all the wireless nodes with RV120's and use VLAN. Dont know if that strategy works. Need to think it through.
I want the 192.168.0.0/24 IP range comunicate to with the 172.16.0.0/24 and possibly the 10.0.0.0/24 range.
Any advice on how to do this?
As a side note the next step after this is to install a server domain controller as all the computers are all stand alones in their own workgroups. It's a simultaneous project that will introdue a DCHP, WINS, DNS server.Hi Omid, it sounds like you're proposing the 3550 switch but you're not decided yet. The 3550 switch is a pretty old device and needs enhanced multilayer image. It may be more prudent to use a more current switch such as small business SG300 or SG500 as the feature set is more rich and it supports around 480 LAN connections.
To answer the inquiry, the RV120W, when you create a VLAN it will automatically create an IP interface. From this you may assign subnet as you like along with 'enable or disable' for inter vlan routing. Since the RV120W has this feature, a layer 3 switch is not required unless you are looking to keep the routing load smaller by routing locally with the switch.
With Catalyst or a small business switch you would need to create a VLAN. After creating the VLAN, on a Catalyst you can simply issue "switchport trunk encapsulation dot1q" on the desired interface and all VLAN will passage without issue. For a port connecting a user "switchport mode access" "native vlan xx" This will assign the port as untag member of the desired VLAN.
If using a small business switch, it is slightly different, you still create the VLAN but the command issue is a bit different "switchport trunk allowed vlan add xx" for the link to the router, where xx = the VLAN ID to tag to the router. For access client it remains the same as Catalyst. -
Help configuring Audition with Virtual Audio Cable and Skype
I'm using the latest version of Audition, along with Virtual Audio Cable and Skype for my PC (Windows 7). While I'm able to properly configure my own microphone (Edirol UA-25), to be captured by Audition on track 1, I can't seem to get track 2 configured properly to capture and record.
I seem to be missing a step.
Is there anyone that can help me properly configure or offer an alternative that will allow me to record my microphone and the Skype call on two separate tracks?
Thanks in advance for your expertise!Others may have made it work but I've never persuaded Audition to record a mic in one channel and line out (Skype) in the other. Since Audition it designed to work with a single ASIO audio interface, this makes sense.
My solution is to use a little utility called the iFree Skype recorder: Record Skype Calls with iFree Skype Recorder - Your FREE Skype call recorder software
It works well for me, keeping the outgoing part of the call and the incoming separate for easy editing later. It works fine with an external audio interface and good mic as long as Skype is set up to work that way.
The only drawback is that it records in MP3 not wave but, given the quality of most Skype calls, this isn't really a deal breaker. -
Bridging multiple VLAN with sg 200-08 and wap321
Hi all
Equipment:
ASA 5505
2x gs 200-08
2x wap321
Is there a possibility, to bridge 2 VLAN between one and another side with two WAP 321 and use the AP's also as WDS Bridge to extend the Wireless Network?
I need to extend the Range of the WLAN but also want to use 2 different VLAN on both sides of the network. There is no Possibility to establish a wired Connection, so i try to use the AP's in "workgroup bridge" mode, but i always can use only one VLAN on the other side.
Thanks for any helpHi Luis
The Problem is, there is no wired connection between the WAP321.
The topology is like this:
VLAN1------ASA5505-- --SG200-08---------WAP321 WAP321--------SG200-8-------VLAN1
I I
VLAN2--------------------------- -----------VLAN2
VLAN1 and VLAN2 are also available in the WLAN on 2 Different SSID's:
SSID: inside -> VLAN1
SSID: outside -> VLAN2
If i understand the Cluster mode right,there is a wired connection required between the WAP321 .
In meantime i tried to connect the WAP321 over WDS, but always only VLAN1 is available on the "right" side of the Network.
Is there a Possibility, to Bridge multiple VLAN's over a WDS connection?
Best Regards
Dominique -
I had an iTunes account on an old computer with over 300 songs then when I updated my computer to the MacBook Pro it deleted all my songs when I signed into iTunes. Is there a way I can get those songs back?
Did you put the songs on the new computer?
You should copy everything from your old computer or your backup copy of your old computer to your new one. -
How to configure SGE2000P with CISCO 7900 phones and data VLAN
Hello all
I am having problem setting up SGE2000P switches to work with my default data VLAN and additional voice VLAN. I am configuring it to pick IP address for phones from voice VLAN which is working fine but when I connect a PC on phone port it is also picking up an IP from Voice VLAN while default VLAN is data with different scope of IP.
Is there any good discussion or documents out there to help me resolve this issue before I pack these switches and purchase ESW 500 series. I have ESW 500 at another client and they are working fine out of the box but this guy is giving me hard time.
Any suggestions help will be appreciated
MoHI Muhammed,
I suggest you contact the Small Business Support Center for some help:
http://www.cisco.com/en/US/support/tsd_cisco_small_business_support_center_contacts.html
Regards,
Cindy Toy
Cisco Small Business Community Manager
for Cisco Small Business Products
www.cisco.com/go/smallbizsupport
twitter: CiscoSBsupport -
VLAN With secondary IP address and it's HSRP configuration.
Switch-1
interface Vlan200
ip address 10.X.X.1 255.255.254.0 secondary
ip address 192.X.X.1 255.255.255.0
standby 200 ip 192.X.X.7
standby 200 priority 110
standby 200 preempt
standby 66 ip 10.X.X.7
standby 66 priority 95
standby 66 preempt
Switch-2
interface Vlan200
ip address 10.X.X.4 255.255.254.0 secondary
ip address 192.X.X.2 255.255.255.0
standby 200 ip 192.X.X.7
standby 200 priority 95
standby 200 preempt
standby 66 ip 10.X.X.7
standby 66 priority 110
standby 66 preempt
is the above HSRP configuration correct.Hi Veera,
I have not tried it before, but the configuration does not seem to work since the syntax seems to wrong as you cannot type an ip address after secondary keyword. An example below.
(config-if)#standby 85 ip 10.127.1.130 secondary ?
<cr>
But your idea seems to work with exception of the above syntax mistake. A useful post can be seen below.
https://supportforums.cisco.com/discussion/9912176/hsrp-secondary-address
Hope this helps. Please always remeber to rate all useful posts.
Thanks
Madhu. -
Help w/Voice VLAN on SMB 300-10p
We have purchased serveral new SMB 300 switches to support our VoIP rollout and save cost. I'm use to using the CLI on cisco devices, but now i'm stuck figuring out the GUI that comes with these switches.
I have setup the Voice VLAN to be 100, i have setup the port type as general, and i have added the port to VLAN 4 (data vlan). when i plug the NEC phone into the switchport and the computer into the phone, the computer gets an IP in VLAN 4 but the phone gets an IP from VLAN 1 not VLAN 100.
Like i said i set the Voice VLAN to 100, but when i look at the Macro for the smartport it is saying the voice vlan is 1. Do i have to manually change the macro somehow? can i change the macro somehow?
Sorry i don't have a lot of info in this post. If you need to know how anything else is configured just ask i'll post it up.
Thanks
KarlHi Karl,
You can use the serial db9 console cable that came with it for a hardwired connection (I use putty):
Also you can enable telnet and/or ssh: Status and Statistics -> System Summary, look for TCP/UDP services status and then hit Edit, enable what you want, hit apply, and remember to save the config. Also, you can go right to Security -> TCP/UDP services to enable:
Best,
David
Please remember to rate helpful posts and identify correct answers. -
Configuring UC540 with 2x SPA525G2 (local and remote site)
Just got this new system installed and not sure to get full capability.
Here's my setup and feel free to send comments to help improve configuration.
I have two SPA525G2 phone one local connected to the UC540 and the other one is remote and connected over the built-in VPN
I have 4 incoming lines and we need to have both phone ringing all the time.
On each phone at least one user extension button, one monitor button to see the status of the remote extension, and one group voicemail
So that left me with only 2 buttons to control the 4 incoming lines.
How should i do this setup on the two remaining buttons ?Hello Pierre,
There are a lot of different approaches. The following are some of the approaches:
1. create a group for each if the incoming lines and put the extensions of the two phones in these groups.
2. Create extension for each line and make overlay buttons which include these extensions.
3. Use B-ACD or AA and send the calls there and then forward to the extensions of the phones.
HTH,
Alex
*Please rate helpful posts. -
Vlans with ESX 3.5 and Cat6509
have Esx 3.5 with 6 physical NICs. It connects to my Cat6509 running 12.x IOS code. Have downloaded the Vmware/cisco whitepaper and several vmKB articles. Still have some confusion here.
1) Plan to run ESX in VST (vlan Tagging) mode.
2) What is the deal with Native Vlan ID in Esx VST can't be the same as the native VlanID of the physical switch? Huh? Is this a fancy way of saying change the native Vlan from 1 to "anything" when handing off trunks to ESX?
The vmkb articls 1004048 which outline etherchannel, but doesn't specify changing the native vlan to something else.
Is it possible to etherchannel and trunk over the same nics with ESX?In ESX Virtual Switch Tagging (VST Mode) mode, you provision one port group on a virtual switch for each VLAN, and then attach the virtual machine's virtual adapter to the port group instead of the virtual switch directly. The virtual switch port group tags all outbound frames and removes tags for all inbound frames. It also ensures that frames on one VLAN do not leak into a different VLAN.
Native VLAN ID on ESX VST Mode is not supported. Do not assign a VLAN to a port group that is same as the native VLAN ID of the physical switch. Native VLAN packets are not tagged with VLAN ID on the out going traffic toward ESX host. Therefore, if ESX is set VST mode, it drops the packets that are lacking a VLAN tag. -
How to Configure iCloud with multiple iCloud accounts and one apple id
I need some help from the icloud experts. I almost have my arms around this, but not completely.
What I want to end up with is the following:
One account that both my wife and I use for shared contacts, calendars, photostream and find my device.
Separate account for my email among several devices.
Separate account for my wife for her email among several devices.
Now what I curently have is an apple id (*.mac.com), which is the main account used for purchases, etc. It has my mail, backups, and 25GB of space as a result from MobileMe.
I created a separate icloud account for my wife, using her Apple ID, so that her mail stayed separate from mine. However, now we have separate photo streams, contacts, etc, which is getting confusing and cumbersome.
I would like to keep my apple id as the main account since it already has the 25GB of space. So tell me if the following make sense.
I setup the master account using my apple id (the one with 25GB of space) for both of us, and enable the contacts and calendar syncing for all of our devices.
I turn the mail and Safari bookmarks syncing on for my devices; but turn it off for my wife's devices.
Then I use my wife's account on her devices to sync her mail, bookmarks, etc.
Would this work or is there another combination to use? Ideally a family oriented apple id would be good for the master account, but it wouldn't have the 25GB of space unless I purchased it. I'm trying to get around that if possible. I have tried to find something like this on the discussion boards but haven't had luck yet.
Thanks in advance for any help.Set up your mac.com account again on devices. Turn off Mail and other data syncing with this account on your wife's devices for data that you want to keep separate. Then set up a second ("secondary") iCloud account on your wife's devices to sync Mail.
If you already set up a separate iCloud account on your wife's devices, on her devices go to Settings>iCloud, tap Delete Account, then sign back in your your mac.com ID. Turn on the data you want to share with this account across all devices; don't turn Mail on. Then go to Settings>Mail,Contacts,Calendars>Add Account>iCloud and enter her separate iCloud credentials and turn Mail to On.
The only downside to this approach is that her email will be fetch, not push email. Push email is only supported in the main ("primary") account, not a secondary account.
The limitations to be aware of with secondary accounts are that only the primary account can be used for Photo Stream, Bookmarks, Documents, iCloud Backup and Find My Device. Also, push mail only works for the primary account; secondary account mail is fetch. -
I have noticed that I can not get my Relay module to turn off all of the channels, also I can only set the PWM modules down to ~4% output.
I have tried to "Reset" the factory defaults on the FP-1000. I've tried to configure the powerup states of the different modules, all with no luck.
I have made sure I am running with the latest firmware on the FP-1000
I did notice this problem before upgrading the firmware. Immediately after doing the upgrade the problem went away for a short while. Now it is back again.
My system is configured as follows:
1 FP-1000 network module @address 0
4 FP-TC-120 modules @1,
2, 3, 4
2 FP-TB-10 dual channel bases @ 5, 6
2 FP-PWM-520 modules @ 7, 8
1 FP-RLY-420 module @ 9
Something seems to me to be happening with my .iak file in FieldPoint Explorer, of course I could be completely off base.
I appreciate any insight anybody might have with this problem
Kerry Libberton
TDA Research
Wheat Ridge, COKerry,
There are several different things that may be going on here. First of all, there may be an issue with power consumption. A network module (FP-1000 in this case) is designed to source up to 9 Watts of power to I/O modules. This assumes an average of 1 Watt per module. Certain modules require more than 1 Watt, most require less leaving extra power for the ones that require more. In your configuration, you may be over this depending upon how your FP-TB-10's are populated. Assuming that the TB-10 is unpopulated, your consumption is 4 * 0.35 + 2 * .25 + 2 * 0.6 + 1.7. = 3.8 Watts. Thus, the load from the Dual Channel modules may not exceed 5.2 Watts. If you are using exclusively the Dual Channel Analog Out Current modules, you will overload the power supply.
Anothe
r thing to look at is when resetting the network module, check the box that says factory configuration. After the reset, uncheck the box and then configure your channels and power-up values (edit this device on each module).
Also, there are some times when relays may get "stuck" in an on position due to extremely high inductive loading. I have not seen that happen very frequently, but it does make me wonder, what type of load are you driving on the relay channels?
The PWM module, has 12 bit resolution, and will accept values of 0% for the output duty cycle. What value for the period have you set? -
Static VLAN with Cisco SF 300-24 - Configuration
Hello Everyone!
Let me start by saying that i am quite new to cisco equipment.
I have a new Cisco SF 300-24 and try to configure a static VLAN.
What Interface VLAN Mode should I Use? General or Trunk?
I am looking for a step by step instruction.
Any help would be appreciated,
Thanks!
JürgenHello Everyone!
Let me start by saying that i am quite new to cisco equipment.
I have a new Cisco SF 300-24 and try to configure a static VLAN.
What Interface VLAN Mode should I Use? General or Trunk?
I am looking for a step by step instruction.
Any help would be appreciated,
Thanks!
Jürgen -
How to create wrielesss vlan with diffrence configuration
how to create wireless vlans with different configuration in network?
device use only :
laptop = 30
desktop = 40
linksys wirelesss router = 1
switch 2960 = 1
router 1841 = 1
vlan 10 = lecturer(1 desktop & 1 laptop)
vlan 20 = student(29 laptop & 39 desktop)
Posted by WebUser ???? ?????????? from Cisco Support Community Appin this case we don't have enough budget t get WLC device....mybe use the autonomous ap....i use the linksys wireless routes as AP that connect to switch and create the VLANs 10 and VLANs 20 in the switch 2960, the switch connect to router 1841 that will ensure vlan connect each other.
Posted by WebUser ???? ?????????? from Cisco Support Community App -
Management vlan with the 1000V and UCS
If I want to use VLAN 10 for management, I would have to configure the following:
1000V -VM vEthernet port profile access port with VLAN 10, Ethernet uplink profile includes VLAN 10
UCS - vNIC in Service Profile, include VLAN 10, and include VLAN 10 in uplink trunk from UCS
Upstream switch: Include VLAN 10 in trunk port.
OK?
Now, this management VLAN, can I Iuse this for everything? I mean for 1000V management VLAN, vSPhere management, FI management and switch management? Or should for instance the 1000V management be different from the others?Hi Atle,
Yes, what you have mentioned is the correct in terms of activities you need to carry out. However i would like to add a few:
1) define the vlan on the UCS - unless you do this you will not be able to add it to the vnic. Plus once you have the vlan defined it will automatiaclly get added to the trunk list on the uplinks ports (unless you l2-disjoint configured)
You can have the same vlan for all the management, unless you have certain traffic you would not like certain device to see / reach.
./Abhinav
Maybe you are looking for
-
Deletion and Creation of Excel sheet
Hi, I have to remove the monthly spread sheet every time and create a new spread sheet while executing the code. The problem is when I run the code the records inserted into same spread sheet along with the previous records. So I need to delete the e
-
External hard drive foils boot?
So, I find my self saying this a lot recently, but this is one of the strangest things I've seen in a while. I have a 2010 MacMini that I just got refurbished - 8G RAM, 2.66, and I just replaced the HD to a 750 (the old one was failing). I have two e
-
When I went into the Facebook app on my iPhone 4S, I tried finding friends through my contact list. I thought only contacts with cellphone numbers matching a Facebook profile would appear to add as a friend. What's being populated are friends of my f
-
I'm getting some weird behavior. After a lot of change and publish cycles, iWeb is mixing up various images. The images have names like "shapeimage_3.png". iWeb can't seem to keep them straight. Opening some of the images on my iDisk and saving them
-
Are multiple processes more efficient in Solaris 2.6 ?
I am running performance measurement tests in a Solaris 2.6 environment. The tests run one message at a time through my application and measure the response time. I found that my app will process the test message more quickly when multiple instances