ISA500 tagged WAN port

Hello,
I'm currently evaluating an ISA570W firewall.
The use case is to deploy it as an entry level firewall on FTTH internet access lines.
The ISP provides a CPE that requires internet trafic to be tagged on a specific VLAN.
I was a bit suprise when, after trying this configuration, finding out that the WAN port on the ISA500 can only be put in access mode.
Which effectively makes this device unusable.
Is there another way to set one of the ethernet interface in trunk mode and put it in the WAN zone with DHCP client enabled?
Thanks,

so I digged a bit further and found a document from Cisco's knowledgebase that describes steps by steps instructions for the WAN port: http://sbkb.cisco.com/CiscoSB/Loginr.aspx?login=1&pid=2&app=search&vw=1&articleid=3719
searching for vlan tag showed me a screen that allowed the setting of a tagged vlan on the WAN port but only available for PPPoE IP address assignement.
the VLAN tag option is not available with "DHCP Client" IP address assignement.
Is this something we could see in a future firmware release?
From what I've seen tagged vlan on the WAN port is a typical configuration requirement for FTTH services here in Switzerland.
Thanks,

Similar Messages

  • RV Support VLAN Tagging on WAN Port?

    Hi,
    I'd like to know if RV Series Router can support VLAN tagging on the WAN port itself? I need this cause my ISP using such method to connect to end user modem/router.
    Thank you.
    Regards,
    Danny

    Anything available other than this RV315W?  That model is only 10/100 on the LAN.  VLAN on the WAN is fairly standard for fibre installs and should be a feature across all SMB routers.

  • Can the AEBS untag a VLAN (802.1q) on the WAN port?

    My modem (actually a fibre optical network terminal) provides a DHCP ethernet port. I would like to use my airport extreme for routing and wireless. Normally this would be a very simple setup, except the the modem requires all traffic to go over a specific VLAN (802.1q tagged). So, for this to work I would need the Airport to be able to untag/tag a specific VLAN on its WAN port. Is this possible?

    I'll probably try to find the most minimal device that I can get to do transparent untagging of VLAN traffic. Not really sure where I might find that, but will start researching. I'd like to avoid using the current buggy router supplied by my ISP if at all possible!
    I would suggest that you look at the various products provided by Cisco. FWIW I use a Cisco RVS4000 as my "main" router and have set up a number of VLANs for my home network with it.

  • UC520 Router and ESW520 Switch I need tagged VLAN ports

                       I am trying to configure the WAN port to two Internet sources, one primary and one backup. I have no problems building two VLAN subinterfaces on the WAN port of the UC520 using CLI. However CCA will not allow me to build a port with two access VLANS on the ESW520. It seems that the only allowed tagged port is Phone + Desktop. Is there any way around this? A secret Port Role? A less restrictive device configuration manager?

    hi,
    I've tried connecting cisco to non cisco devices.Tagged ports simply means allowing different vlan to pass to that port and Untagged is passing only the native vlan.For your case since you want that two VLAN will communicate,port should be tagged.Tagged is simply trunking in terms to cisco.So that the 802.1q frames will pass that port.

  • RV320 - vlan on Wan Port

    Here in Brazil VIVO (from the spanish Telefonica group) is recently providing fiber links.
    Their fiber link is being splitted into 2 vlans: one for their IPTV (vlan id 20) and another for internet (vlan id 10).
    So, when they install on your house or company, they install 2 boxes: 1 ONT (Optical Network Terminal) and 1 router (which connects to the ONT and does the PPPoE auth on VLAN 10 and creates the internal VLAN for the IPTV - id20). 
    So, is it possible to replace their router with the RV320 and create tagged / untagged VLAns on Wan Ports and assigning ip address on each vlan (PPPoE for internet, DHCP for iptv)?
    The topology is basically like this:
    [Fiber Cable]
    ONT
    [Ethernet Gigabit]
    Router
    [Ethernet / Coaxial]
    Network Devices
    TVs (coaxial connection provided by 2. Router)
    PCs (wireless /ethernet connection provided by 2.Router)

    Hello, 
    Thank you for sharing the information about the DD-WRT firmware on other devices.Unfortunately the RV320 is not capable of such a feature, it is just not designed to do that.
    On the other hand we do have one unit that is capable of such configuration, it is the RV315W router. 
    Here is a link to the emulator for the unit so that you have an idea of its capabilities.
    http://www.cisco.com/assets/sol/sb/RV315W_Emulators/RV315W_Emulator_v1.01.03/index.asp.htm
    The feature you are looking for can be configured by going to Port settings, WAN, Wan interface settings, then you can configure the desired VLANs. 
    I'm not sure that this device is available in Brazil. If it is not available then you may have to consider using enterprise units or other devices.
    Please let us know if this is helpful.

  • I am unable to set up my new Time Capsule with my BT Home Hub - every time i connect the ethernet cable from Wan port to Home Hub, the internet signal drops

    Hi there -
    I've just purchased a new Time Capsule, and would like to set up a small home network with my Laptop, iMac and wireless printer. I'm following the first steps, but as soon as I connect an ethernet cable between the WAN port of the TC and the ethernet port of the HH, my BT internet connection drops out and I have to restart the HH. Upon which point it drops out again. The airport utility can see my TC, and gets as far as me typing in the new network name and setting up a password, but then it can't quite get through to the next stage. All the time it's just flashing amber.
    Please help!

    Setup the TC in bridge mode before you cannot it to the HH.
    Simply do the setup fully in isolation. And do it by ethernet.
    Setup wireless to create a wireless network.
    You can use either same SSID =Wireless name as the HH .. same security same password.
    Or use a different name and setup.. totally up to you.
    Update the TC and then plug it into the HH by ethernet.

  • EA2700 WAN PORT open to the world by default?

    I just noticed last night that my EA2700 router was accessible on the WAN port, from the Internet, on ports 80 and 53. I am running router firmware 1.0.14 and the update utility reports that there is no newer version.
    Remote management is NOT enabled (it defaults to port 8080 anyway) and I enabled and disabled it for good measure. Rebooted a few times, too.
    I then enabled and disabled the regular admin interface on HTTPS and turned off HTTP. That enabled the admin interface on port 443, but still left it enabled on port 80. And now both port 80 and 443 were accessible outside the firewall! And now I couldn't turn off port 443!
    I disabled UPnP and rebooted and still the ports were open to the Internet.
    Needless to say, I was pretty horrified by this discovery.
    I only leave one port forwarded, port 22, to SSH on an internal box. That is the only hole through my firewall I ever expect to see.
    As a fix for this problem, I added three new port forwards on port 80, port 53 and port 443, and mapped them all to a random port on an unused IP on my internal network. THIS and ONLY this finally made ports 80, 53, and 443 inaccessible from the Internet at large.
    What's going on here? It seems hard to believe that EVERY EA2700 device would have this issue or this would've come out long ago. Any ideas?

    https://superevr.com/blog/2013/dont-use-linksys-routers/

  • I have Fios. I have the TC connected via ethernet to the Fios router. TC WAN port ethernet to Fios Lan port. Then I just have the TC create a wireless network that is different than the Fios wireless network. How do I set up an Airport Extreme to the TC?

    The Airport Extreme is a 4th Gen unit. I just want to keep the TC wireless name to go further through my house.

    The Ethernet connection will be from one of the LAN <-> ports on the TC to the WAN port (circle of dots icon) on the AirPort Extreme.
    Then you can use AirPort Utility - Manual Setup to configure the AirPort Extreme as follows:
    Click the Wireless tab located just below the row of icons
    Wireless Mode = Create a wireless network (Not "extend a wireless network" as many users incorrectly think)
    Wireless Network Name = Same name as your TC network
    No check mark needed next to "Allow this network to be extended"
    Radio Mode = Automatic
    Channel = Automatic
    Wireless Security = Same setting as the TC network
    Wireless Password = Same setting as the TC network
    Confirm Password
    Click the Internet icon
    Click the Internet Connection tab
    Connect Using = Ethernet
    Connection Sharing = Off (Bridge Mode)
    Update to save settings and restart the entire network
    Computers on the TC network will now be able to move to the area where the AirPort Extreme is located and not have to "switch" networks. This is known as a "roaming" network.

  • Access to WAN Port 2 on an CISCO ISA 550 Firewall

    Hi all
    On a CISO ISA 550 Firewall i created a 2 WAN Port Failover whichs works fine. But how can access the WAN2 Port (see Attaments) from my Workstation even the WAN1 Port is up an runnig, i created also a new Zone and Firewall Rule but this dosen't work..
    Thanks for your help

    Upgrade Firmware...

  • Does the WAN port in client mode on the Airport Express?

    On an Airport Express (2012 version, 802.11n), has anyone tried the following configuration? Is the WAN port active in client mode? Do you have any suggestions on this or similar configurations?
    I am trying to use Airplay to stream music to two Klipsch G-17 speakers. As I have discovered and also documented by Apple on their web page http://support.apple.com/kb/HT4587 in the section
    "Connecting to an existing Wi-Fi network as part of a legacy WDS or Extended Network", this is true "Due to the overhead required for this configuration, you may expect AirPlay drop-outs such as intermittent loss of audio."
    Configuration now:
    All Airport Expresses are the 2012 802.11n version with a LAN and a WAN port.
    There is one Airport Express in a home basement. It is connected to an Internet connection. This Internet connection goes into this home basement.
    There is a second Airport Express on the second floor of this home.
    Now, both Airport Expresses connect fine with the "extend network" option. There is wifi coverage throughout this home. All works fine until Airplay is used to stream music to these two Klipsch G-17 speakers. There are intermittent and persistent pauses. I am experiencing the what Apple documented in this kb article. I am not able to connect the two Airport Expresses with an ethernet cable. I cannot run a cable from the basement to the second floor.
    Has anyone tried this following configuration? Or is there a different configuration that would work, and if so, could you provide the configuration details?
    1. Connect the first Airport Express via client mode to the second, second floor Airport Express.
    2. Set the network default gateway to the first, basement Airport Express.
    The attempt is to eliminate the extended network, with its Airplay dropouts. And allow access to the Internet via the wifi network.
    - end -

    If the Express joins a wireless network wirelessly, in other words its WAN port isn't connected to anything, the correct way to connect a wired client to it is by using its LAN port.
    I don't know what would happen if you were to connect a wired client to its WAN port instead — it's just not supposed to be used for that purpose. It won't permanently break anything if you were to try it though. If you were, the worst that would occur is that your network would become unresponsive as packets continuously traverse its WAN port in a circular fashion, which might require that you power down your router to reset your whole network.
    If you are already using your Express's LAN port and you need another, the way to provide more ports is to purchase an inexpensive ($10 or so) switch. Connect it to the LAN port and as many other pieces of equipment as the switch's available number of ports.
    You're correct about the first generation with the single Ethernet port. It could be used in either capacity depending on its configuration.

  • Do I need to buy an ethernet switch that has a WAN port

    I want to buy an Aiport Express to handle a WiFi only iPad and an old PPC iMac with 10.5.8 on it that has no WiFi card.  The iMac gets on the internet from a cable plugged directly into its ethernet port (using DHCP).  The cable comes off an antenna at the front of the cottage.  A signal hits the antenna from a broadcasting tower about half a mile away.
    I need to buy an ethernet switch for the Aiport Express to handle both the iPad wirelessly and the wired iMac.  Does the switch have to have a WAN port or can I buy one with five LAN ports?
    Message was edited by: Roy Vincent.  Spelling error

    So here's what I am planning to do.  I get myself an ethernet switch.  I plug my cable from my antenna into it.  I run a cable from one of its five ports into my iMac.  I run a cable from one of its other ports into my Airport Express.  I configure the Airport Express in Bridge Mode.  Now my wife can connect to the web wirelessly using the iPad and I can connect using the wired iMac --- and we can do so at the same time and indpendently of one another.   No?
    Sorry, but no.
    You only have one IP address.  With a switch feeding two devices, it will be a matter of chance as to which device gets the IP address.
    The other device will not be able to connect to the Internet, since a switch cannot "split" the connection.
    Instead, you need a simple wired router to "share" the public IP address that you receive. In turn, the router distributes "private" IP addresses to devices on your local network, so each device will be able to connect to the Internet. 
    As I mentioned, a switch cannot perform the functions of a router.

  • Can't configure both WAN ports on 1811 with SDM

    Hi,
    We recently procured an 1811 router to replace a SOHO linksys at a store we service. We needed redundant WAN interfaces to use the DSL as a backup to the main cable connection, and a Linksys RV082, while doing the job when it actually worked, died repeatedly. We decided after looking at the 1811's feature set to just get the Cisco and be done with it and not monkey with SOHO gear anymore.
    Where I'm having difficulty is SDM won't let me configure both WAN interfaces from the GUI, it only allows me to configure one. I have it configured, and the router is working nicely in the test lab but I need to get that other interface configured and failover enabled before I can put this thing into production.
    What am I doing wrong? Do I need to suck it up and learn IOS?
    Thanks,
    Todd Phipps
    Certco, Inc.

    I ended up figuring out the IOS commands to enable one fastethernet port as a primary and the other one as a backup (running both cable and DSL for redundancy; it's a grocery store that runs electronic transactions over IP so 100% availability is a must).
    The trouble I was running into in SDM is that while it would allow me to configure one WAN port through the GUI, the config options for the second one were grayed out. Now that both are configured through IOS the edit buttons for both WAN interfaces appear normally in SDM. It's almost as if Cisco didn't want users to be able to configure both interfaces graphically for initial setup.
    Now just to test it at the site before the store opens to see if the failover works...
    Todd

  • HT2497 do I connect my airport express to my modem via the WAN port and then connect to my imac via ethernet cable?

    Do I connect my airport express to my modem via the WAN port and then connect from airport express to my imac with ethernet cable? Is that how you "hard wire" the connection? Because when I do that, I still can't get online. Thanks.

    What is the make & model of your modem?
    You pretty much stated the correct wiring. There should be an Ethernet cable connected between the modem and the WAN (circle of dots) port on the AirPort Express base station.
    Anytime you change networking hardware it is always a good idea to perform a complete power recycle of that hardware. Check out the following AirPort User Tip for details. Please post back your results.

  • Time Capsule Internet WAN port is not working, what can I do to set it up?

    When I plug the ethernet cable from my router to my Time Capsule it should turn on a green light in the back of the TC, but this light is not turning it on anymore, and this port is not working, how can I set it up?
    I want to create a wireless network with the TC, but if this port (Ethernet WAN port) doesn't work, I can't, or can I? How?
    Then I want to use my 2 Airport Express to use the network that I want to create.
    I hope you can help me, thanks a lot.

    what model is the TC? A1xxx from the base please.
    How old and is the front LED otherwise showing it is operating OK?
    What is the network setup..? Is the TC bridged or router.. or is it in Join wireless network mode now..
    If the later.. the ethernet ports are turned off.. you need to do a factory reset of the TC.
    Factory reset.. Hold in reset button.. THEN power on the TC.. keep holding in reset for about 10sec until the front LED flashes rapidly.. there is a good chance the ethernet will work now.

  • AEBS: use WAN port as a LAN port ?

    Hello there,
    My Airport Extreme base station is connected to an Airport Express as a WDS wireless bridge (none of them distribute IP, there is a router on the network).
    I have two printers hooked on the AEBS, a USB one, and an Ethernet printer on the LAN port (Apple LaserWriter). Therefore, the WAN port is not used.
    I would like to connect a non-airport Mac to the network thanks to the AEBS.
    Can I plug the Mac with Ethernet on the WAN port or I must purchase an Ethernet switch to plug on the LAN port and then on the Mac and printer ?
    The documentation says the WAN port is for cable modem only but I don't see any hardware limitation that could allow only those device.
    Thank you for your help.
    PBook 12'   Mac OS X (10.4.9)  

    Thank you Duane for those infos.
    I didn't know that the difference between a WAN and a LAN port was a matter of IP adressing. Nice to know.
    I will try that ASAP, if there is no more post, that means it works great.
    Thanks again.

Maybe you are looking for

  • Database link creation problem

    localhost environment: OS:windows 2000 server Database:oracle 8.5 database name:orcl remotehost environment: OS:windows 2000 server Database:oracle 8.5 database name:orac These two servers in network and in the same workgroup like peer to peer.There

  • Call to a possibly undefined method setPropertyIsEnumerable?

    Hi,   I am trying to accomplish using doubleClick events on dateChoosers. Below is the code that is working:      <mx:VBox>               <mx:Label text="Simple DateChooser control."/>               <mx:DateChooser id="dateChooser1" doubleClickEnable

  • Working with movie clips

    I'm making an animation with movie clips inside the stage but if i put action in the end of these for go to another frame in the stage, dosnt let me because AS3.0 does'nt alow script inside buttons and MC's. Wath can i do for this issue. The new code

  • Canvio 3tb update not compatible with ZFS

    Hello, I have been using mutiple Canvio 3tb usb drives (all purchased this year) in striped sets on a backup server running FreeBSD 10 and utilising the ZFS filesystem. Recently I purchased two more identical drives to increase the pool but these are

  • Messages disappear when I drag them into inbox

    I had some messages that were in my whitelist folder. But whenever I dragged them into my inbox, they would disappear. The same thing happens when I drag messages from other folders into my inbox. Also, how long do the messages stay in the whitelist