General voip vlan config

We have a flat network of 6 3750g poe switches in a stack. default vlan1 for data.......we are getting ready to go to voip and am need some general guidance in setting up voice vlan. It seems some say the ports should be in trunk mode, others say no. Just looking for simple config examples for the setup. thank you

Hi Mark,
Welcome to the world of VoIP. This is a great question!My background is primarily voice so it is hard for me to describe why this is a Cisco "best practice". I do know that it is unnecessary to configure the switchport in Trunk mode because when you use the Voice VLAN (with a native vlan) command a "special" dot1q trunk is automatically setup. The reasons I have seen to support this setup are many and vary from minimizing Trunking overhead to ease of configuration and everything in between :) On the older 3500XL Switches the Trunk method was the only way to go, but on all newer versions the need for Sitchport mode Trunk is not necessary. Here is one of the better threads I have ever read on this issue (with some Tac links as well). There are some great answers from Mahesh,Paolo Sankar and others here.
http://forum.cisco.com/eforum/servlet/NetProf?page=netprof&forum=Unified%20Communications%20and%20Video&topic=IP%20Telephony&CommCmd=MB%3Fcmd%3Dpass_through%26location%3Doutline%40%5E1%40%40.1ddd5905/14#selected_message
Hope this helps!
Rob

Similar Messages

  • New VLAN config on Cisco router

    We are in the process of rolling out VOIP with new Cisco router
    configurations. When the VLAN config is changed on the router it can no
    longer ping the server. The router config is setup with secondary IP info
    so that we don't have to go thru the process of changing IP config on the
    NW 6.5 SP 6 servers.
    Has anyone seen this issue? Do I need to bind new VLAN ti IP NICs? Any
    other thoughts?
    Thanks for any help received,
    Todd W Carter

    On 6/5/2007 Todd W Carter wrote:
    > We are in the process of rolling out VOIP with new Cisco router
    > configurations. When the VLAN config is changed on the router it can no
    > longer ping the server. The router config is setup with secondary IP info so
    > that we don't have to go thru the process of changing IP config on the NW 6.5
    > SP 6 servers.
    >
    > Has anyone seen this issue? Do I need to bind new VLAN ti IP NICs? Any other
    > thoughts?
    When pinging from the router, the packets will be source from its primary
    ip address. If the server's subnet is part of the secondary IP address on the
    router, you must use an extended ping in the router for it to work.
    However, I recommend implementing router-in-a-stick instead of secondary IP
    addressing when creating multiple VLANs.
    On the router, you can create sub-interfaces under the LAN interface and deploy
    dot1q trunking. At the switch-port, configure dot1q trunking as well and the
    router
    will route between VLANs while providing a better design.
    This is outside of the scope of this forum so I recommend posting in the Cisco
    forums at http://forum.cisco.com/eforum/servlet/NetProf?page=main
    Thanks !
    Edison Ortiz
    (Routing & Switching, CCIE # 17943)

  • Solaris 10 X2100 VLAN config

    What are my options for configuring a virtual interface on an x2100 server with Sol10 Because the interface shows up as the type " nge0" I am assuming
    that the hardware does not support it per the info below. Is there another alternative or a software workaround ?
    -john
    The Solaris OS now supports VLANs on the following interface types:
    ce
    bge
    xge
    e1000g

    Looks like I just had the wrong VLAN config syntax.. and miss read the documentation. this works !
    bash-3.00# ifconfig -a
    lo0: flags=2001000849<UP,LOOPBACK,RUNNING,MULTICAST,IPv4,VIRTUAL> mtu 8232 index 1
    inet 127.0.0.1 netmask ff000000
    nge0: flags=1000843<UP,BROADCAST,RUNNING,MULTICAST,IPv4> mtu 1500 index 2
    inet 128.111.207.230 netmask ffffff00 broadcast 128.111.207.255
    ether 0:e0:81:5c:d3:6
    nge829000: flags=201000843<UP,BROADCAST,RUNNING,MULTICAST,IPv4,CoS> mtu 1500 index 4
    inet 10.0.0.62 netmask ffffff00 broadcast 10.0.0.255
    ether 0:e0:81:5c:d3:6

  • VOIP VLAN using 802.1q frames causing massive dropped packets

    I have a MBP 2.16 connected via 1Gbps Ethernet to my corporate network. I also have a Cisco 7960 VOIP phone and it seems that 802.1q VOIP VLANs are causing the MBPro's Marvell Yukon Gigabit Ethernet adapter to drop 1326 packets out of 3559. It's absolutely unusable at my office, where my laptop is my main machine. I'm having to use my Compaq N610c to browse the Internet and read e-mail. Apple, please update the driver and save me!!!

    I'd check a few things, are you sure the switch that you are connected to is really at 1000Base-T? If it is a Cisco switch I've seen all sorts of probems with auto-negotiation, I'd try to get your network administrator to "fix" the port at the speed you wish to run your network at (ie 100/1000) make sure the duplex is set correctly on the MacBook Pro (make sure it is set to the same as the switch). Also ensure that jumbo frames are enabled on the Cisco switch and make sure the MTU is set correctly for your network. This involves some tweaking of the ethernet interface in the network preferences of OS X.
    Of course if there are indeed 802.1q problems with the onboard NIC then you could get your network administrator to disable .1q frames on the port that your MBP is connected to, you won't be able to use a "loop through" port on a VoIP phone if the phone relies on .1q trunking, so you'll need a port for the phone and a seperate .1q clean port for the MBP.

  • Config view for VLAN config is not supported

    Hi folks,
    I have the following error when I try to view the VLAN config from RME->ConfigManagement->Version Tree.
    "Config view for VLAN config is not supported"
    I didn't found any information over the RME and Campus documentation.
    Anybody know what kind of error I'm issuing
    Thanks and Regards.
    Leonardo

    Hi Pablo,
    The VLAN.dat file cannot be used to be deployed via CiscoWorks, but it can be done manually:
    http://www.cisco.com/en/US/docs/net_mgmt/ciscoworks_resource_manager_essentials/4.3/user/guide/config.html#wp1311740
    The problem with viewing the VLAN.dat contents in the config viewer or change audit reports is also mentioned in the link below:
    http://www.cisco.com/en/US/docs/net_mgmt/ciscoworks_resource_manager_essentials/4.3/user/guide/chgaud.html#wp1060886
    Look for the "Details" row and there you will see the following:
    VLAN configurations cannot be compared because they are in binary format. In this case, the Details link will not be available and will be shown as NA.
    Hope this helps!

  • 1250AP VLAN config

    I am trying to configure VLANs on my 1250 autonomous AP. I have the sub-interfaces setup but still cannot connect to the LAN. I use 432 for my native vlan and then want to assign clients to vlan 543. Being a security guy, I do not use vlan 1, nor do I trunk vlan 1. Here's a snippet of my config, so tell me what I am missing. All interfaces are showing up-up.
    Thanks.
    int d0
    no ip add
    int d0.432
    encap dot1q 432 native
    bridge-group 1
    int d0.543
    encap dot1q 543
    bridge-group 2
    int g0
    no ip add
    int g0.432
    encap dot1q 432 native
    bridge-group 1
    int g0.543
    encap dot1q 543
    bridge-group 2

    I'd prefer to not post the entire config as it would take a lot of editing. :-)
    Both statements are there, and there is no issue with the SSID config. I'm just trying to get a connection to my RADIUS server, which the AP cannot connect to. I am not able to ping the server from the AP, so it has something to do with the vlan config, but I don't know where. The switch where the AP is connected is trunking and allows all vlans (at this point) except for 1.
    This is a head scratcher. :-)

  • Private Vlan config

    I have a question regarding private Vlan config. I have a DMZ switch where I need to be able for a particuilar server to communicate to the reset of the servers on port 8686 and deny the rest of the communications between them. I have this server on a poremiscuios mode and the other servers on isolated ports.For security reason how can apply this access list? on which vlan? I am running IOS on the switch connecting these servers. Thanks for your help

    the port is that the server(10.3.1.50. 255.255.0.0) that need to talk to all server is attached to:
    interface GigabitEthernet1/0/18
    description DZ1WEBSD001
    switchport private-vlan host-association 50 51
    switchport mode private-vlan promiscuous
    speed 100
    duplex full
    no mdix auto
    The subnet is 10.3.1.0 255.255.0.0
    Basically the 10.3.1.50 need to talk to all servers on this subnet on port 8686 and deny evrything else
    Thanks

  • Vlan database vs vlan config, rpr-plus...

    We have Catalysts 6500's that we are migrating to native ios mode, and have noticed in the docs (http://www.cisco.com/en/US/customer/products/hw/switches/ps708/products_configuration_guide_chapter09186a00800da705.html#wp1095579) that vlan configurations made from the vlan database mode are NOT replicated throught rpr-plus.
    While configuration of vlans through the global config mode isn't really a problem for future configs, we haven't found a way to easiliy convert vlan database configs to vlan-config...
    Is there such a way besides clearing vlan.dat and starting over?
    Also, after doing a clean config of vlans through vlan-config, there doesn't seem to be much (any?) diffrence either in the global config or the presence of the vlan.dat. Is the config supposed to look any diffrent when issued as vlan-config?
    TIA

    check out the following link on configuring vlans :
    http://www.cisco.com/en/US/products/hw/switches/ps708/products_configuration_guide_chapter09186a008007e711.html#wp1020848

  • LMS 4: VLAN config fetch failing for all devices

    LMS 4.0.1, standalone on W2K8 R2, new install
    Vlan config fetch is failing for all devices.  If I attempt to put a vlan.dat file in tftpboot and then manually copy a vlan.dat file from a device, the following is returned:
    TFTP: error code 2 received - 16739
    %Error opening tftp://server_name/vlan.dat (Permission denied)
    The Windows application logs ont the server log this:
    Log Name:      Application
    Source:        CRMtftp
    Date:          6/15/2011 2:07:49 PM
    Event ID:      3
    Task Category: None
    Level:         Error
    Keywords:      Classic
    User:          N/A
    Computer:      server_name
    Description:
    GetEffectiveRightsFromAcl failed: Overlapped I/O operation is in progress.
    (997)
    I tried restarting crmtftp, but no luck.  Any ideas what may be causing this?
    -Jeff

    I have the same issue with a freshly installed 4.2 version now:
    Log Name:      Application
    Source:        CRMtftp
    Date:          2/24/2012 12:30:50 PM
    Event ID:      3
    Task Category: None
    Level:         Error
    Keywords:      Classic
    User:          N/A
    Computer:      srvwienlms.nts.local
    Description:
    GetNamedSecurityInfo failed failed: The operation completed successfully.
    (0)
    I will also open a TAC case, lets see if we still have to stick with a3.x TFTP binary...
    br.herwig

  • Configuration Help 1130AG-VoIP-Vlans-Switch Configuration

    1130AG running c1130-k9w7-tar.124-3g.JA1, in autonomous mode.
    VoIP - Call manager 6x, Cisco phones only,
    Vlans - Open, secure data using WPA2, VoIP Vlan is using pre shared keys.
    Switch Configuration - C3548xl's, C356048ps, 6509 cores
    I have been looking for configuration examples to help me configure the interfaces from the 3546xl and the C356048ps switched to the 1130AG.
    Configuration between the C3548xl's, C356048ps, and 6509 cores on the trunk ports for QoS.
    The call Manager is on Vlan 210 and the Vlan for the wireless voice is 202.
    Any suggested links would be grate, I think I have found most of it but want to be sure.
    Thanks

    Just to expound upon the commands that were not working, I did use the /? switch to see available commands, so for example, the mls qos trust dscp command, I entered mls qos trust /? and the only option was cos.
    I globally configured the switches with:
    lldp run
    no lldp tlv-select power-management
    mls qos
    network-policy profile 50
    voice vlan 50 dscp 46
    All of these commands worked fine.  I was going to assign the network-policy 50 on each access port along with the commands of mls qos trust dscp, auto qos voip trust  too, but did not get to that step.

  • SF300-24P VLAN CONFIG QUESTION

    Hi please excuse my ignorance and lack of knowledge in this field as I am a complete newbie when it comes to Cisco switches and VLANS etc. but trying to learn.
    I have a Cisco 300-24P and need to create two separate networks (private and public) ports 1 - 10 for Private and ports 11 - 20 for Public. I then to need ports 21 - 24 for access points and that can access both private and public.
    I am assuming that would need to create two vlans (e.g. VLAN100 for private and VLAN200 for public). After reading a little I think I need to set ports 1- 20 to "access" and ports 21- G4 to "trunk".
    I have attempted this but don't think I have things quite right. Would it be possible for someone to either point me in the right direction or even send me a saved config that I could load and examine.
    Many thanks in advance for your help.

    Hello, 
    I think I can clarify a few things for you:
    1- The ports that are going to connect directly to end stations will need to be configured as access ports with the respective VLAN as untagged.
    2- The ports that are going to be connected to the AP's will need to be configured as trunks with VLAN 100 un-tagged and 200 tagged. The AP should be able to understand VLAN's, they should be configured with and IP address on VLAN 100.
    3- By default, the un-tagged VLAN is the same PVID.
    Notes:
    A few things to keep in mind:
    1- I see you already have a router on the network, this is the one that will determine if the VLAN's can talk to each other based on the Inter VLAN configuration. In general terms, if inter VLAN is enabled on the router then Public and Private will be able to share traffic, otherwise they wont.
    2- When creating VLAN's on the SG300 make sure that you are not assigning IP addresses to any other VLAN than your management VLAN, otherwise you could have issues with the routing.
    3- To make sure the connectivity between the VLANs is working as you expect, make sure to do all the testing from the hardwired PC's first, that way you will know if the issue is on the router or the switch.
    I hope this was helpful.

  • Vlan config 1242ag and HP 2824 switch

    Our new phone system has been put in place as of yesterday, how ever someone forgot to mention that we will have wireless handsets...my main issue is that i cant get the phones and the pc clients to connect at the same time.
    The AP (1242ag configuration attached) is allowing only the native traffice through either if its on vlan 1 or 20.
    Vlan 1 is Voice (I know this is a big no no though, The phone comp that installed the phone system did not do their homework) and the data is on vlan 20, if i leave vlan 1 native the wireless handsets will connect, and my pc clients are associate with the access point but do not get an ip address only the default one from the client adapter. if i move the native over to vlan 20 the computers get associated and an ip address are assigned but the phones will not connect. the PC clients are using WEP with static key, the phones are using AES CCM. I am not a cisco god but know my way around the cli interface, and with this issue i am getting better at it. any help would be great.

    Robert
    my suggestion is to save your current configuration using the GUI. then use the GUI to configure your Vlans. you may still need to use the CLI to tune hte configuration as not all the functions or options are available through the GUI but for configuring hte SSID's, Vlan's and encryption the GUI is the way to go.
    Here is the reference
    http://www.cisco.com/en/US/docs/wireless/access_point/12.3_2_JA/configuration/guide/s32vlan.html
    One thing i noticed is you have an IPaddress in the Radio config generally the only place the ipaddress is used in the AP config is for the BVI1.
    also make sure your swtch port is configured for dot1Q trunking.
    the reference has good examples for both GUI and CLI configuration.
    Bill

  • Red X on Network drives and Unknown Publisher when running apps after VLAN config

    We have been running the SG500-52P switches (2 switches stacked) for 2 years with No issues. We recently moved our office and added a new VoIP phone system. We had some trouble getting everything installed originally but its all working now with this one pesky problem. After putting the switches in Layer 3 mode, adding a VLAN for the phone system and setting up a route between VLAN1 (data) and VLAN2 (phones). We are now having this problem: Users are randomly getting Red X's showing disconnected network drives. There appears to be no pattern to when the disconnect happens. It can happen almost instantly after a reboot or sometimes be fine for a few days before disconnecting.  If you click on the drives you can access the data but the Red X DOES NOT go away. Although when accessing some applications we get an "Unknown Publisher" message and usually the program crashes. All our Workstations are Win 7 Pro and Servers are 2008 R2. We map server and NAS drives, when the issue happens is disconnects all the mapped drives and NOT just one server.

    Definitely not a good situation to be in, as you never know who will call and complain of loosing connectivity.  Have you opened a ticket with TAC?
    Unfortunately we don't get a lot of comments/questions on the SG series here.

  • Vlan config issues

    I have a 6509 with a vlan 105 configure. I have also added a vlan 100. vlan 100 and 105 work for internal routing. vlan 105 workstation can get to the internet. however any vlan 100 workstation can not access the internet. A tracert from a workstation on vlan 100 stops at the 6509. attached is the 6509 config, i have included IP just because they already have changed.
    any ideas? Does the port connecting to my firewall have to allow all vlan traffic? if so how do i do this.
    thanks,

    Hi,
    Please provide more information on setup( other devices, connectivity diagram) to have a clear idea, so that we can help you.
    From the config provided, i could see the following default route
    ip route 0.0.0.0 0.0.0.0 10.175.105.3
    What is 10.175.105.3 ? Is this your firewall / WAN router??
    Also what is the need for this static route.?
    ip route 10.175.100.0 255.255.255.0 10.175.105.3
    10.175.100.0/24 is the subnet for vlan 100, which a directly connected network on this switch. Hence you dont need that route. Remove that route.
    Finally whatever device is 10.175.105.3, please add a route in that device for vlan 100 so that traffic can reach vlan 100.
    The route that you should add in 10.175.105.3 is
    ip route 10.175.100.0 255.255.255.0 10.175.105.1.
    Hope this helps.
    -VJ

  • Multiple VLAN config help

    I need to configure our Cisco Aironet 1200's for multiple VLANs. VLAN101 is for public use & VLAN2 is for employees only. Existing config is attached.
    I need:
    1. To disable the broadcast of VLAN2's SSID so that only VLAN101 shows up in the SSID list for visitors. Right now both are showing up.
    2. To ensure the WEP key is setup correctly for VLAN2
    Thanks in advance for your help!

    So are you saying both SSID's are currently broadcasting?
    I would delete and re-create your client configurations. I don't think it's on the AP side.

Maybe you are looking for