Implementing Firewall behind Catalyst 2950 SI Switch

Hi,
Current Scenario:
2 x 3700 series routers in active-standby configuration (HSRP) . They are implementing IOS SLB and NAT.
Behind these a 2950-24 switch. This box has only the Standard Image.
Behind this again are a number of Windows servers requiring protection.
Requirement:
Implement Firewall Solution with SonicWall in order to protect a subset of these hosts.
Questions:
1. Can the Firewall be 'hung' off the switch and create port-based VLAN's?
2. Would this involve sub-interfaces on the Firewall? I read in SonicWall doc. that with appropriate Firmware upgrade, it can implement sub-interfaces, but requires a 802.1q-capable switch.
3. Leading on from 2., I believe 2950-24 cannot run 802.1q since it runs only a Standard Image(SI), according to CCO. Is this true?
4. Any other advice appreciated.
Thanks again.

Hi,
Yes you can, create two VLAN's on the switch, say 20 and 30. Assign ports for external firewall interface and routers on vlan 20. Assign ports for servers and internal interface on firewall on vlan 30.
You should not not need sub-interfaces as the firewall will have a separate external and internal interface.
Let me know if I have pointed you in the right direction or if I not gotten the right end of your question.

Similar Messages

  • Catalyst 2950 Switch flash_init error

    Hi Everyone,
    I'm new to Cisco products and have a small home lab set up. I have a Catalyst 2950 switch that I would like to restore to factory defaults. Here is the issue I'm having and can't figure out.
    I pull the power, telnet into the console port, hold the mode button and restore power. The boot loader (Version 12.1(11r) starts and says the usual message the system was interrupted prior to flash initialization (Paraphrasing here)
    I get to the switch: command line, enter flash_init. Flash states it initialized and then all I get is a < with an underscore under it prompt. Anything I try to type comes up as bizarre characters and I can not get back to a switch: prompt unless I reboot the switch manually. Unsure of what to do here.
    Thanks in advance!
    -Matt
    Telnet session:
    C2950 Boot Loader (C2950-HBOOT-M) Version 12.1(11r)EA1, RELEASE SOFTWARE (fc1)
    Compiled Mon 22-Jul-02 18:57 by antonino
    WS-C2950T-24 starting...
    Base ethernet MAC Address: 00:06:52:bb:c9:40
    Xmodem file system is available.
    The system has been interrupted prior to initializing the
    flash filesystem.  The following commands will initialize
    the flash filesystem, and finish loading the operating
    system software:
        flash_init
        load_helper
        boot
    switch: flash_init
    Initializing Flash...
    flashfs[0]: 4 files, 2 directories
    flashfs[0]: 0 orphaned files, 0 orphaned directories
    flashfs[0]: Total bytes: 7741440
    flashfs[0]: Bytes used: 3726848
    flashfs[0]: Bytes available: 4014592
    flashfs[0]: flashfs fsck took 7 seconds.
    ...done initializing flash.
    Boot Sector Filesystem (bs:) installed, fsid: 3
    Parameter Block Filesystem (pb:) installed, fsid: 4
    õíííííí   <---These characters appear no matter what keys I hit.

    Hi mattymattlynch
    Check the workaround on the following documents:
    http://www.cisco.com/c/en/us/support/docs/switches/catalyst-2950-series-switches/41845-192.html
    http://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst2950/software/release/12-1_22_ea11x/configuration/guide/scg/swtrbl.html
    If no luck , the flash might be corrupted and requires a replacement.
    Hope this helps
    -Randy-

  • DHCP on Cisco Catalyst 2950 Switch

    Hello
    I need to configure my cisco catalyst 2950 series switch in order to act as DHCP server for devices connected to its ports.
    Please say me, how to do that ?
    Thank you
    Narek

    Please find the sample DHCP configuration for one of the VLANs.
    Interface Vlan1
    description Cisco DHCP
    ip address 10.10.2.1 255.255.255.0
    ip dhcp pool cisco
    network 10.10.2.0 255.255.255.0
    default-router 10.10.2.1
    domain-name mydomain.com
    dns-server 10.10.2.10
    netbios-name-server 10.10.2.15
    lease 7
    A 24 hour lease is the default if left out and the netbios-name-server is WINS in the Windows world.
    If you want to use DHCP server for other VLANs as well create similar DHCP pools and assign the DG to the corresponding VLAN interface IP.
    HTH, rate if it does
    Narayan

  • Cisco 2950 l2 switch console problen

    Hi all, I got 2 old Cisco 2950 catalyst switch yesterday. But when I try to open console of both switches I am getting only blank terminal. I tried to open with putty and scureCRT, I tried another console cable, tried on another PC, but no luck. 
    I think previous owners might have disabled console. So is there any other way to take console or delete start-up conf file??

     Hello,
    I don't have a 2950 around to test, but as far is I know disabling the console is achieved issuing the "no exec" command on the console line, so it is a command in the start-up config. Therefore booting the switch in the rescue image should not take into account that command, so the console should be available in that mode. Have you tried that? To do so hold down the MODE button located on the left side of the front panel, while you reconnect the power cable to the switch. Release the Mode button after approximately 5 seconds when the Status (STAT) LED goes out. When you release the Mode button, the SYST LED blinks amber. 
    Here is the rest of the procedure:
    http://www.cisco.com/c/en/us/support/docs/switches/catalyst-2950-series-switches/12040-pswdrec-2900xl.html 
    PS:  I presume you are using the correct COM port and terminal settings, however I mention them bellow just to make sure:
    Bits per second (baud): 9600
    Data bits: 8
    Parity: None
    Stop bits: 1
    Flow Control: Xon/Xoff  (or none, in some documents)
    You can check if you are using the correct COM port in System Tools/Device Management if you are using a Windows device. 
    If this doesn't work check if the flash card can be removed (not sure on that old model), perhaps you can use it in other device and delete the startup config.

  • Cisco Prime 2.1 - Collection Failure 2950 Series Switch

    Hi All,
    I am trying to add various devices in the Cisco Prime Infrastructure 2.1, but with the followings I get a message: Collection Failure (Inventory Collection Status).
    Cisco Catalyst 2950 24 Switch
    Cisco Catalyst 2950G 24 EI DC Switch
    ¿Why I can't sync this devices?
    Kind Regards!
    JEFFERSSONQG

    Leo,
    I think you are not correct ...
    ( to be truth - I hope it ;- )  )
    in PI 2.2 the Cat 3550 is listed under the supported devices whereas the Cat 2950, 2955 are not:
    http://www.cisco.com/c/en/us/td/docs/net_mgmt/prime/infrastructure/2-2/release/notes/cpi_rn.html#pgfId-43885
    But the latter are listed as being supported in PI 2.1 (while the Cat 3550 is not...)
    http://www.cisco.com/c/dam/en/us/td/docs/net_mgmt/prime/infrastructure/2-1/supported/devices/pi21-supported-devices-list.xlsx?mdfid=284540974
    So hopefully it is just a matter of time to get them ALL on the list of supported devices for the current version of PI 2.2 ...
    I just saw that for Prime Network (Management SW for Service Providers) they even have Cat 3500XL on the list of supported devices... (but I do not know for which type of management they do support these devives, e.g. config, alarming,etc) 
    http://www.cisco.com/c/dam/en/us/td/docs/net_mgmt/prime/network/4-2/supported/vnes/CiscoPrimeNetwork-4-2-SupportedCiscoVNEs.pdf 

  • RARP Server for Catalyst 2950 Switch

    Is there a RARP Server capability for the Cisco Catalyst 2950 Switch? I know that Cisco Routers support an "ip rarp-server" command. Do Cisco Switches support RARP?

    To the best of my knowledge, the RARP protocol is working with cisco 2950 switch and also it supports in most of the cisco products.
    http://www.cisco.com/en/US/tech/tk648/tk361/technologies_tech_note09186a00800f0804.shtml

  • Catalyst 2950 switch

    Hello,
    I am using a catalyst 2950 switch and connecting machines which have the operating system as TRU64 UNIX 5.1B (HP make DS25 servers) and WINDOWS XP Professional. The WINDOWS machines are getting connected on the network ( I am able to PING each other), but the UNIX machines are not getting connected on the network. The port LED on the switch is normal (GREEN). The netstat -r command on the UNIX machine shows default as defgw (/etc/routes) and the IP of defgw is defined in the /etc/hosts file. But there is actually no such gateway.
    Please help me to get the UNIX machines connected on the network.
    Thank You very Much
    Best Regards
    S R Vijayan

    I wonder if the Windows machines are configured to use DHCP? If they are configured for DHCP and there is a DHCP server that is reachable, then it explains why the Windows machines have reachability to each other. If there is not a DHCP server available then the Windows machines are probably taking addresses in 169.254 (which is the default for Windows when it can not acquire from DHCP). This would also explain the ability of Windows machines to communicate with each other. Can the original poster clarify what IP addresses the Windows machines are using?
    Then the question becomes how are the Unix machines configured? Are they supposed to use DHCP? Is so is the DHCP server reachable? If not how is the interface on the Unix box configured?
    I also think that the suggestion about verifying whether the switch is configured with more than one VLAN is an excellent suggestion.
    HTH
    Rick

  • SNMP on Catalyst 2950 switch - possible?

    How can I add SNMP to my Catalyst 2950 switch? and what will this give me with regards to network monitoring etc. A lot of my networks go through this device and I what to get stats on port etc. I really hope you can help here.

    Hi Chandru,
    Here's what you should do. Firstly, go to the following site which will give you a list of MIBs supported on the 2950:
    http://www.cisco.com/en/US/products/hw/switches/ps628/products_configuration_guide_chapter09186a00800d84cc.html
    Then, open up the Cisco SNMP Object Navigator at:
    http://tools.cisco.com/Support/SNMP/do/BrowseOID.do?local=en
    Within that, click on 'View and Download MIBs' and then select the MIBs you are interested in to download/view them.
    As an example, you can get counters on memory pools from the CISCO-MEMORY-POOL-MIB
    Hope that helps - pls rate the post if it does.
    Regards,
    Paresh.

  • IP Accounting on catalyst 2950

    Hi all,
    Is there a way to find out traffic information from source IP to destination IP, like ip accounting used on routers, on the catalyst 2950 switch. My switch has the standard image.
    Also what performance impact would it have on the switch, if possible to implement.
    Thanks,
    George

    Hi dukenukem,
    no there is no way of interpreting flow information that way on a c2950. A c2950 is a L2 Device. Normally it doesn't really care about ip adresses.
    Regards,
    Sebastian

  • Help with Catalyst 2950 G

    Hi,
    I have a doubt about the Catalyst 2950 series, i need to pass both IP and OSI traffic trought a 2950 switch. Is it supported?
    Thanks

    The 2950 is a layer2 switch. Anything carried over ethernet will go, no matter which layer3 protocol is used.
    Regards,
    Leo

  • Cluster Management Software on Catalyst 2950

    Hi There,
    I was wondering if anyone would be kind enough to provide me with some help on getting the CMS software running on a Cisco Catalyst 2950 Switch. I have followed all the instructions I could find on getting the software to load from the Switch, but it will not load. Can anyone help me?
    Thank you in advance.
    John Grikes
    [email protected]

    You can start from: http://www.cisco.com/warp/public/473/59.html

  • Trunking Catalyst 2950 to Catalyst 3750 problem

    I cannot seem to figure out how to trunk a catalyst 3750 to a Catalyst 2950.
    I've set
    3750(config)#interface fastethernet 1/0/2
    switchport mode trunk
    switchport trunk encapsulation dot1q
    BUT my Catalyst 2950 does not offer the "switchport trunk encapsulation dot1q" command
    My 2950 is running IOS version 12.1(20)EA1a
    is there a work around for this situation. Our network still employs a bunch of these 2950's.

    The Catalyst 2950 series can only do 802.1Q trunking. It's the default, and only, choice. So there's no need to specify it when trunking.
    In fact, since you don't have a choice of which encapsulation to use, there's no need for a "switchport trunk encapsulation" command. Which is why it's missing from the Cat2950 switch IOS.
    This took me by surprise too, when I first transitioned out of the 3500XL series into 2950 and 3550 switches.

  • POST error Catalyst 2950

    I have a Catalyst 2950 series 12 prt. switch. When the switch is booting I receive the following error: "00:00:13: POST: Packet DA mismatch on port: 9"
    What does this message means? Can I still use this port?
    Kind regards,

    This is part of the power on self test(POST).
    The switch sets the interface to loopback and sends
    a packet. If anything is wrong or changed with
    the packet then you get an error. In this case
    the DA (destination address) was changed on
    the received packet. I assume since this is a
    switch they are referring to the layer2 address.
    I would think this would indicate a possible hardware
    failure.

  • CATALYST 2950 SERIES - CLEAR OPT TABLE & DISABLE CASH

    I have 2 cisco switches model - catalyst 2950 series, i recently had an network issue regarding an ip conflict with one of my member servers, after being on the phone with microsoft support for 6 days, we were able to resolve the problem by locating the correct mac address and clearing the "OPT table on the switches" by unplugging and replugging the power cord. In order to prevent this from happening again, Microsoft had asked me to contact cisco and ask the following questions, " Are these swiches managable via the gui?  and we also need to make sure that the "Arp Cash is disabled on the switches" can anyone help in this matter?  Thanks in advance.

    Hi Arrowext289,
    Thank you for your question.  However the Small Business Support Community is limited to Cisco Small Business Products.
    Your question below relates to a Cisco Classic Product which our community would not be able to help you with.
    The best area for you to post your question would be at the Cisco NetPro forums switching area located here: https://supportforums.cisco.com/community/netpro/network-infrastructure/switching
    Best regards,
    Cindy
    Cindy Toy
    Small Business Community Manager
    Customer Advocacy
    Cisco Systems, Inc.
    www.cisco.com/go/smallbizsupport

  • Catalyst 2950 bandwidth limitation

    Hello,
    please, can anyone tell me if it is possible to limit bandwidth on Catalyst 2950 switch on per VLAN basis.
    Thanks in advance.
    Maxime Frolov

    Hello Amit,
    I'll try to clarify my problem. I have a 2950 (Standard Image) with a giga uplink to a 6500. On the 2950 I have a VLAN composed of 4 ports. I' like to limit the use of the uplink link of this VLAN or at least of one port to 20%. Would it be possible on 2950 SI or I'll have to upgrade to EI whitch implyes hardware changes ? Or it just impossible on 2950 and I'll have to migrate to 3750 ?
    Regards.
    Maxime Frolov

Maybe you are looking for

  • ORA-01747 Error in jsp page

    Hi, I am getting Internal Servlet Error: javax.servlet.ServletException: SQL error: ORA-01747: invalid user.table.column, table.column, or column specification <%@ page language="java" %> <%@ page import="com.ora.jsp.sql.*" %> <%@ page import="com.or

  • Number range issue -urgent

    Hi ,      We are transferring master data from one system to another system. Since there would be clash of number ranges , we want to make number range as manual ( i.e. external ) for a given master data type. Since we don't want to do it manually ,

  • Running more than one batch on the same resource at the same time.

    Dear all, as i'm working in paper industry , i have to release more than one batch at the same time using batchable resource , but i have problem in declaring the resource usage , if i run 3 batches on the same resource for i hour , what is the resou

  • Not charging when connected to iTunes

    Can anyone help, our 2nd generation iPod Shuffle stops charging (i.e. the orange light stops blinking) when iTunes comes on the computer.  So as soon as I connect the shuffle it blinks orange but then when iTunes automatically comes on it stops.  I h

  • Dataelement and Datatype regarding photo

    hi this is praveen we are connecting .net to sap  . .net people  give photo to us so we have option in se78 direct we can insert photo but in my requirement is i need datatype and dateelement and table to insert a photo can any one pls help me thanki