Configure vlan with SG 300-10P and SA 520

Hi All,
Forgive my ignorance but i need some help for basic configuration.
I bought for a little office  a SA520 Security appliance (for future VPN with another distant office) and a SG 300-10P switch for connect 3 PC and 3 IP PHONE. THe SA 520 is the router. I must configure 2 VLANs on the switch :
VLAN2 : DATA (for PC)
VLAN3 : VOICE (for IP PHONE)
VLAN1 : DEFAULT.
How can i simply configure all ports ?
I would like to configure ports 1-4 on VLAN2 and ports 5-8 on VLAN3 and port G10 is reserved for the router SA520.
I want to divise network DATA/VOICE.
I think i must create a trunk on G10 for SA520 ...
Does anyone can help me?

Hi Julien,
Ok sounds like you are using the default vlan for management on the network  and vlan 2 for data  and vlan3 for voice.
I am using a simulator for this, my SA520 is loaned out at the moment.
Step 1   On the SA520  add vlan 2 and vlan 3  and label them data and voice respectively. 
Step 2. Lets use switch port 4 on the SA520 as a trunked port to the SG-300.
            (my intention is to use untagged vlan1, tagged vlan 2 and tagged vlan 3 on  the uplink from the switch and the SA500.)
          To do this I have to tell the SA520 that switch port 4 will be in trunking mode and not access mode.
You will have to tick off the membership of vlan 2 and vlan 3 on switch port 4.
Step 3.  Now add some IP addresses for VLAN2 and VLAN3
Step 4.  Create some DHCP scopes if that is what is needed on the SA520
So by now hopefully we have the SA520 with  IP addresses associated with VLAN1, VLAN2 and VLAN3
We also have switch port 4 as a trunk interface
We are propogating untagged vlan1 and tagged vlan2 and tagged  vlan3 to the SG-300 switch.
We have to do the opposite on the SG-300 switch.
If you are using G10 as the uplink to the SA520 you will note by default  port 10 should already be in trunk mode.
switch port G10 should be tagged for vlan 2 and tagged for vlan3.  By default Gi10  it will be untagged for vlan1.
Make sure you set up the rest of the switch ports appropriately. 
regards Dave

Similar Messages

  • How do I add a Subnet and vlan with a catalyst 3550 and RV120

    Hello Friends.
    I have a scenario that i'm hoping i can get some help with. I'll be as detailed and descriptive as i can.
    This is for a business with 100 employees nodes and 100 camera nodes all needing IP internet through private addressing and public gateway.
    I have a business class gateway with a private range of 12 public addresses. Ther modem does nothing but act as a gateway since i have disabled the firewall and DHCP.
    In place of the firewall and DCHP from the modem i have installed a RV120 Firewall with VPN. When installing i replicated the IP scheme of the modem as to not disturb and distrup the devices assigned addresses from that scheme from the modem. I did this because the owner could not have any down time or any disruption to the business operations.
    The RV120 now acts as firewall , DHCP , and VPN. I'll address the subnet first. I's using 10.0.0.0/24 subnet range.
    DHCP is assigning 10.1.10.50 - 10.1.10.100 the rest are static and i plan to use static DHCP with the IP and MAC assigned to each static DHCP address.
    There are 100 cameras with static IP addresses in the range of 10.1.10.11 - 10.1.10.40, and 10.1.0.1.101 - 10.1.10.170.
    VPN uses PPTP assigned address 10.1.10.6 - 10.1.10.10.
    There are no layer 3 switches that i know of. Just a layer two that is the primary swith and ports have run out, and various out of the box switches and wireless access points connected to the primary switch.
    I want to implement subnets into the network and VLANS as well on a new Layer 3 switche from cisco. Thinking 3550 from Cisco or one of the older layer 2 switches with layer three capabilities.
    I also want to introduce a 192.168.0.0/24 IP range for the existing wireless network and segment the traffic from the rest of the traffic on other ranges.
    I want to replace the 10.0.0.0/24 DHCP alltogether and the static addresses for end user nodes on the same network, but keep that range just for camera nodes segmented.
    I want to implement a NEW end user IP range and VLAN for employee/guest networks using the 172.16.0.0/24 range.
    Iv'e thought of replacing all the wireless nodes with RV120's and use VLAN. Dont know if that strategy works. Need to think it through.
    I want the 192.168.0.0/24 IP range comunicate to with the 172.16.0.0/24 and possibly the 10.0.0.0/24 range.
    Any advice on how to do this?
    As a side note the next step after this is to install a server domain controller as all the computers are all stand alones in their own workgroups. It's a simultaneous project that will introdue a DCHP, WINS, DNS server.

    Hi Omid, it sounds like you're proposing the 3550 switch but you're not decided yet. The 3550 switch is a pretty old device and needs enhanced multilayer image. It may be more prudent to use a more current switch such as small business SG300 or SG500 as the feature set is more rich and it supports around 480 LAN connections.
    To answer the inquiry, the RV120W, when you create a VLAN it will automatically create an IP interface. From this you may assign subnet as you like along with 'enable or disable' for inter vlan routing. Since the RV120W has this feature, a layer 3 switch is not required unless you are looking to keep the routing load smaller by routing locally with the switch.
    With Catalyst or a small business switch you would need to create a VLAN. After creating the VLAN, on a Catalyst you can simply issue "switchport trunk encapsulation dot1q" on the desired interface and all VLAN will passage without issue. For a port connecting a user "switchport mode access" "native vlan xx" This will assign the port as untag member of the desired VLAN.
    If using a small business switch, it is slightly different, you still create the VLAN but the command issue is a bit different  "switchport trunk allowed vlan add xx" for the link to the router, where xx = the VLAN ID to tag to the router. For access client it remains the same as Catalyst.

  • Help configuring Audition with Virtual  Audio Cable and Skype

    I'm using the latest version of Audition, along with Virtual Audio Cable and Skype for my PC (Windows 7).  While I'm able to properly configure my own microphone (Edirol UA-25), to be captured by Audition on track 1, I can't seem to get track 2 configured properly to capture and record.
    I seem to be missing a step.
    Is there anyone that can help me properly configure or offer an alternative that will allow me to record my microphone and the Skype call on two separate tracks?
    Thanks in advance for your expertise!

    Others may have made it work but I've never persuaded Audition to record a mic in one channel and line out (Skype) in the other.  Since Audition it designed to work with a single ASIO audio interface, this makes sense.
    My solution is to use a little utility called the iFree Skype recorder:  Record Skype Calls with iFree Skype Recorder - Your FREE Skype call recorder software
    It works well for me, keeping the outgoing part of the call and the incoming separate for easy editing later.  It works fine with an external audio interface and good mic as long as Skype is set up to work that way.
    The only drawback is that it records in MP3 not wave but, given the quality of most Skype calls, this isn't really a deal breaker.

  • Bridging multiple VLAN with sg 200-08 and wap321

    Hi all
    Equipment:
    ASA 5505
    2x gs 200-08
    2x wap321
    Is there a possibility, to bridge 2 VLAN between one and another side with two WAP 321 and use the AP's also as WDS Bridge to extend the Wireless Network?
    I need to extend the Range of the WLAN but also want to use 2 different VLAN on both sides of the network. There is no Possibility to establish a wired Connection, so i try to use the AP's in "workgroup bridge" mode, but i always can use only one VLAN on the other side.
    Thanks for any help

    Hi Luis
    The Problem is, there is no wired connection between the WAP321.
    The topology is like this:
    VLAN1------ASA5505--  --SG200-08---------WAP321             WAP321--------SG200-8-------VLAN1
                                                 I                                                                                                 I
    VLAN2---------------------------                                                                                               -----------VLAN2
    VLAN1 and VLAN2 are also available in the WLAN on 2 Different SSID's:
    SSID: inside -> VLAN1
    SSID: outside -> VLAN2
    If i understand the Cluster mode right,there is a wired connection required between the WAP321 .
    In meantime i tried to connect the WAP321 over WDS, but always only VLAN1 is available on the "right" side of the Network.
    Is there a Possibility, to Bridge multiple VLAN's over a WDS connection?
    Best Regards
    Dominique

  • I had an iTunes account on an old computer with over 300 songs and I now have a MacBook Pro and when i signed into iTunes all the songs I had before were gone. How can I get my old songs back?

    I had an iTunes account on an old computer with over 300 songs then when I updated my computer to the MacBook Pro it deleted all my songs when I signed into iTunes. Is there a way I can get those songs back?

    Did you put the songs on the new computer?
    You should copy everything from your old computer or your backup copy of your old computer to your new one.

  • How to configure SGE2000P with CISCO 7900 phones and data VLAN

    Hello all
    I am having problem setting up SGE2000P switches to work with my default data VLAN and additional voice VLAN. I am configuring it to pick IP address for phones from voice VLAN which is working fine but when I connect a PC on phone port it is also picking up an IP from Voice VLAN while default VLAN is data with different scope of IP.
    Is there any good discussion or documents out there to help me resolve this issue before I pack these switches and purchase ESW 500 series. I have ESW 500 at another client and they are working fine out of the box but this guy is giving me hard time.
    Any suggestions help will be appreciated
    Mo

    HI Muhammed,
    I suggest you contact the Small Business Support Center for some help:
    http://www.cisco.com/en/US/support/tsd_cisco_small_business_support_center_contacts.html
    Regards,
    Cindy Toy
    Cisco Small Business Community Manager
    for Cisco Small Business Products
    www.cisco.com/go/smallbizsupport
    twitter: CiscoSBsupport

  • VLAN With secondary IP address and it's HSRP configuration.

    Switch-1
    interface Vlan200
    ip address 10.X.X.1 255.255.254.0 secondary
    ip address 192.X.X.1 255.255.255.0
    standby 200 ip 192.X.X.7
    standby 200 priority 110
    standby 200 preempt
    standby 66 ip 10.X.X.7
    standby 66 priority 95
    standby 66 preempt
    Switch-2
     interface Vlan200
    ip address 10.X.X.4 255.255.254.0 secondary
    ip address 192.X.X.2 255.255.255.0
    standby 200 ip 192.X.X.7
    standby 200 priority 95
    standby 200 preempt
    standby 66 ip 10.X.X.7
    standby 66 priority 110
    standby 66 preempt
    is the above HSRP configuration correct.

    Hi Veera,
    I have not tried it before, but the configuration does not seem to work since the syntax seems to wrong as you cannot type an ip address after secondary keyword. An example below.
    (config-if)#standby 85 ip 10.127.1.130 secondary ?
      <cr>
    But your idea seems to work with exception of the above syntax mistake. A useful post can be seen below.
    https://supportforums.cisco.com/discussion/9912176/hsrp-secondary-address
    Hope this helps. Please always remeber to rate all useful posts.
    Thanks
    Madhu.

  • Help w/Voice VLAN on SMB 300-10p

    We have purchased serveral new SMB 300 switches to support our VoIP rollout and save cost. I'm use to using the CLI on cisco devices, but now i'm stuck figuring out the GUI that comes with these switches.
    I have setup the Voice VLAN to be 100, i have setup the port type as general, and i have added the port to VLAN 4 (data vlan). when i plug the NEC phone into the switchport and the computer into the phone, the computer gets an IP in VLAN 4 but the phone gets an IP from VLAN 1 not VLAN 100.
    Like i said i set the Voice VLAN to 100, but when i look at the Macro for the smartport it is saying the voice vlan is 1. Do i have to manually change the macro somehow? can i change the macro somehow?
    Sorry i don't have a lot of info in this post. If you need to know how anything else is configured just ask i'll post it up.
    Thanks
    Karl                  

    Hi Karl,
    You can use the serial db9 console cable that came with it for a hardwired connection (I use putty):
    Also you can enable telnet and/or ssh: Status and Statistics -> System Summary, look for TCP/UDP services status and then hit Edit, enable what you want, hit apply, and remember to save the config. Also, you can go right to Security -> TCP/UDP services to enable:
    Best,
    David
    Please remember to rate helpful posts and identify correct answers.

  • Configuring UC540 with 2x SPA525G2 (local and remote site)

    Just got this new system installed and not sure to get full capability.
    Here's my setup and feel free to send comments to help improve configuration.
    I have two SPA525G2 phone one local connected to the UC540 and the other one is remote and connected over the built-in VPN
    I have 4 incoming lines and we need to have both phone ringing all the time.
    On each phone at least one user extension button, one monitor button to see the status of the remote extension, and one group voicemail
    So that left me with only 2 buttons to control the 4 incoming lines.
    How should i do this setup on the two remaining buttons ?

    Hello Pierre,
    There are a lot of different approaches. The following are some of the approaches:
    1. create a group for each if the incoming lines and put the extensions of the two phones in these groups.
    2. Create extension for each line and make overlay buttons which include these extensions.
    3. Use B-ACD or AA and send the calls there and then forward to the extensions of the phones.
    HTH,
    Alex
    *Please rate helpful posts.

  • Vlans with ESX 3.5 and Cat6509

    have Esx 3.5 with 6 physical NICs. It connects to my Cat6509 running 12.x IOS code. Have downloaded the Vmware/cisco whitepaper and several vmKB articles. Still have some confusion here.
    1) Plan to run ESX in VST (vlan Tagging) mode.
    2) What is the deal with Native Vlan ID in Esx VST can't be the same as the native VlanID of the physical switch? Huh? Is this a fancy way of saying change the native Vlan from 1 to "anything" when handing off trunks to ESX?
    The vmkb articls 1004048 which outline etherchannel, but doesn't specify changing the native vlan to something else.
    Is it possible to etherchannel and trunk over the same nics with ESX?

    In ESX Virtual Switch Tagging (VST Mode) mode, you provision one port group on a virtual switch for each VLAN, and then attach the virtual machine's virtual adapter to the port group instead of the virtual switch directly. The virtual switch port group tags all outbound frames and removes tags for all inbound frames. It also ensures that frames on one VLAN do not leak into a different VLAN.
    Native VLAN ID on ESX VST Mode is not supported. Do not assign a VLAN to a port group that is same as the native VLAN ID of the physical switch. Native VLAN packets are not tagged with VLAN ID on the out going traffic toward ESX host. Therefore, if ESX is set VST mode, it drops the packets that are lacking a VLAN tag.

  • How to Configure iCloud with multiple iCloud accounts and one apple id

    I need some help from the icloud experts. I almost have my arms around this, but not completely.
    What I want to end up with is the following:
    One account that both my wife and I use for shared contacts, calendars, photostream and find my device.
    Separate account for my email among several devices.
    Separate account for my wife for her email among several devices.
    Now what I curently have is an apple id (*.mac.com), which is the main account used for purchases, etc. It has my mail, backups, and 25GB of space as a result from MobileMe.
    I created a separate icloud account for my wife, using her Apple ID, so that her mail stayed separate from mine. However, now we have separate photo streams, contacts, etc, which is getting confusing and cumbersome.
    I would like to keep my apple id as the main account since it already has the 25GB of space. So tell me if the following make sense.
    I setup the master account using my apple id (the one with 25GB of space) for both of us, and enable the contacts and calendar syncing for all of our devices.
    I turn the mail and Safari bookmarks syncing on for my devices; but turn it off  for my wife's devices.
    Then I use my wife's account on her devices to sync her mail, bookmarks, etc.
    Would this work or is there another combination to use? Ideally a family oriented apple id would be good for the master account, but it wouldn't have the 25GB of space unless I purchased it. I'm trying to get around that if possible. I have tried to find something like this on the discussion boards but haven't had luck yet.
    Thanks in advance for any help.

    Set up your mac.com account again on devices.  Turn off Mail and other data syncing with this account on your wife's devices for data that you want to keep separate.  Then set up a second ("secondary") iCloud account on your wife's devices to sync Mail.
    If you already set up a separate iCloud account on your wife's devices, on her devices go to Settings>iCloud, tap Delete Account, then sign back in your your mac.com ID.  Turn on the data you want to share with this account across all devices; don't turn Mail on.  Then go to Settings>Mail,Contacts,Calendars>Add Account>iCloud and enter her separate iCloud credentials and turn Mail to On.
    The only downside to this approach is that her email will be fetch, not push email.  Push email is only supported in the main ("primary") account, not a secondary account.
    The limitations to be aware of with secondary accounts are that only the primary account can be used for Photo Stream, Bookmarks, Documents, iCloud Backup and Find My Device.  Also, push mail only works for the primary account; secondary account mail is fetch.

  • Using Fieldpoint Explorer, I am having trouble configuring outputs on my RLY-420 and PWM-520 modules attached to an FP-1000 network module

    I have noticed that I can not get my Relay module to turn off all of the channels, also I can only set the PWM modules down to ~4% output.
    I have tried to "Reset" the factory defaults on the FP-1000. I've tried to configure the powerup states of the different modules, all with no luck.
    I have made sure I am running with the latest firmware on the FP-1000
    I did notice this problem before upgrading the firmware. Immediately after doing the upgrade the problem went away for a short while. Now it is back again.
    My system is configured as follows:
    1 FP-1000 network module @address 0
    4 FP-TC-120 modules @1,
    2, 3, 4
    2 FP-TB-10 dual channel bases @ 5, 6
    2 FP-PWM-520 modules @ 7, 8
    1 FP-RLY-420 module @ 9
    Something seems to me to be happening with my .iak file in FieldPoint Explorer, of course I could be completely off base.
    I appreciate any insight anybody might have with this problem
    Kerry Libberton
    TDA Research
    Wheat Ridge, CO

    Kerry,
    There are several different things that may be going on here. First of all, there may be an issue with power consumption. A network module (FP-1000 in this case) is designed to source up to 9 Watts of power to I/O modules. This assumes an average of 1 Watt per module. Certain modules require more than 1 Watt, most require less leaving extra power for the ones that require more. In your configuration, you may be over this depending upon how your FP-TB-10's are populated. Assuming that the TB-10 is unpopulated, your consumption is 4 * 0.35 + 2 * .25 + 2 * 0.6 + 1.7. = 3.8 Watts. Thus, the load from the Dual Channel modules may not exceed 5.2 Watts. If you are using exclusively the Dual Channel Analog Out Current modules, you will overload the power supply.
    Anothe
    r thing to look at is when resetting the network module, check the box that says factory configuration. After the reset, uncheck the box and then configure your channels and power-up values (edit this device on each module).
    Also, there are some times when relays may get "stuck" in an on position due to extremely high inductive loading. I have not seen that happen very frequently, but it does make me wonder, what type of load are you driving on the relay channels?
    The PWM module, has 12 bit resolution, and will accept values of 0% for the output duty cycle. What value for the period have you set?

  • Static VLAN with Cisco SF 300-24 - Configuration

    Hello Everyone!
    Let me start by saying that i am quite new to cisco equipment.
    I have a new Cisco SF 300-24 and try to configure a static VLAN.
    What Interface VLAN Mode should I Use? General or Trunk?
    I am looking for a step by step instruction.
    Any help would be appreciated,
    Thanks!
    Jürgen

    Hello Everyone!
    Let me start by saying that i am quite new to cisco equipment.
    I have a new Cisco SF 300-24 and try to configure a static VLAN.
    What Interface VLAN Mode should I Use? General or Trunk?
    I am looking for a step by step instruction.
    Any help would be appreciated,
    Thanks!
    Jürgen

  • How to create wrielesss vlan with diffrence configuration

    how to create wireless vlans with different configuration in network?
    device use only :
    laptop = 30
    desktop = 40
    linksys wirelesss router = 1
    switch 2960 = 1
    router 1841 = 1
    vlan 10 = lecturer(1 desktop &amp; 1 laptop)
    vlan 20 = student(29 laptop &amp; 39 desktop)
    Posted by WebUser ???? ?????????? from Cisco Support Community App

    in this case we don't have enough budget t get WLC device....mybe use the autonomous ap....i use the linksys wireless routes as AP that connect to switch and create the VLANs 10 and VLANs 20 in the switch 2960, the switch connect to router 1841 that will ensure vlan connect each other.
    Posted by WebUser ???? ?????????? from Cisco Support Community App

  • Management vlan with the 1000V and UCS

    If I want to use VLAN 10 for management, I would have to configure the following:
    1000V -VM vEthernet port profile access port with VLAN 10, Ethernet uplink profile includes VLAN 10
    UCS - vNIC in Service Profile, include VLAN 10, and include VLAN 10 in uplink trunk from UCS
    Upstream switch: Include VLAN 10 in trunk port.
    OK?
    Now, this management VLAN, can I Iuse this for everything? I mean for 1000V management VLAN, vSPhere management, FI management and switch management? Or should for instance the 1000V management be different from the others?

    Hi Atle,
    Yes, what you have mentioned is the correct in terms of activities you need to carry out. However i would like to add a few:
    1) define the vlan on the UCS - unless you do this you will not be able to add it to the vnic. Plus once you have the vlan defined it will automatiaclly get added to the trunk list on the uplinks ports (unless you l2-disjoint configured)
    You can have the same vlan for all the management, unless you have certain traffic you would not like certain device to see / reach.
    ./Abhinav

Maybe you are looking for