Need help configuring multiple VLANs and SSIDs

Hi,
We bought a Cisco SGE2000P 24Port switch and 10 WAP4410N access points. Our intent is to provide a secure network to our LAN, and a guest network to the Internet.
We are thinking 3 VLANs would be best for this: VLAN 100 connected to the LAN, VLAN 1000 for the Internet Router and Filter, and VLAN 1100 for the Guest Wireless access.
We have the switch configured for all three of these, and 1 initial access point configured for the VLANS, too.
We have not yet moved the current Internet connection to VLAN 1000 because we aren't sure how to setup routing between VLANS.
Here are some specifics on how the traffic needs to route:
1. We have the DHCP server, which is the PDC, handling both scopes for the LAN and Guest VLAN.
2. The web filter in VLAN 1100 needs to authenticate with the DHCP server as there are different filter rules based on authenticated user. Any users coming from VLAN 1100 will have a default filter rule without requiring any authentication.
3. Certain traffic coming in from the Internet needs to be able to get to VLAN 100. The router has a built-in firewall that handles NAT and port forwarding, so as long as traffic can be forwarded to VLAN 100 we should be good.
4. Traffic on VLAN 1100 (guest Wireless network) should only be allowed to go to Internet (VLAN 1000).
Right now I have the VLANs configured and the ports assigned to the Access Points are set for TAGGED and on VLAN 100 and VLAN 1100.
The SGE2000P has the following IP addresses assigned to the VLANS:
10.7.3.252 - VLAN 100
10.7.40.254 - VLAN 1000
192.168.254.254 - VLAN 1100
Has anyone been able to setup a similar configuration? We have scoured the Internet for documentation but it seems to be very difficult to find!
Thank you!
Gary Smith

Based on your description of a 'Hybrid Port' this sounds like Cisco's 'Multi-VLAN Port' that was a feature of the 2900XL/3500XL series switches. This feature has however long since gone......
With a Cisco switch an access port supporting an Access VLAN & a Voice VLAN is effectively a Trunk with only one Tagged VLAN and the Native VLAN:
interface FastEthernet0/1
switchport mode access
switchport access vlan 10
switchport voice vlan 100
This results in the same configuration as:
interface FastEthernet0/1
switchport mode trunk
switchport trunk encapsulation dot1q
switchport trunk native vlan 10
switchport trunk allowed vlan 100
With the exception of CDP packets being sent advertising the Voice VLAN.
With regards to other IP Phone vendors and DHCP Vendor Options - the answer is it depends....
Nortel use Vendor Option 144 to inform the IP Phone of the Voice VLAN and Option 128 for the Server (PBX) to use. Ericsson uses Vendor Option 43 that can be configured to tell the IP Phone the VLAN and the Web server to read the config file from.
I don't think you will get this working automatically with your 3Com switches, you can however manually configure the VLAN on the Cisco IP Phones.
HTH
Andy

Similar Messages

  • Help with Multiple VLANS and IP Phone Setup.

    Although i have a 3com, I have a cisco IP Phone. I have the IP Phone connected to the 3com swithport using a hybrid port. It's a tagged member of vlan3 (voice net) and an untagged member of vlan1(native data)
    The ip phone gets the right DHCP address for vlan3 ( 10.x.x.x ) but the laptop connected to the ip phone gets the IP for vlan 3 as well.
    I want the laptop to get the IP of the native vlan ( 192.168.x.x)
    what would the port setup need to be ? does it need to be a trunk ? i have the PVID of the port set to vlan3, this allows the IP phone to get its vlan3 DHCP address.
    any help would be greatly appreciated.
    The 3com OS is very similar to the latest of CISCO IOS'.
    so explain wtih syntax and i'm sure the 3com can relate.

    Based on your description of a 'Hybrid Port' this sounds like Cisco's 'Multi-VLAN Port' that was a feature of the 2900XL/3500XL series switches. This feature has however long since gone......
    With a Cisco switch an access port supporting an Access VLAN & a Voice VLAN is effectively a Trunk with only one Tagged VLAN and the Native VLAN:
    interface FastEthernet0/1
    switchport mode access
    switchport access vlan 10
    switchport voice vlan 100
    This results in the same configuration as:
    interface FastEthernet0/1
    switchport mode trunk
    switchport trunk encapsulation dot1q
    switchport trunk native vlan 10
    switchport trunk allowed vlan 100
    With the exception of CDP packets being sent advertising the Voice VLAN.
    With regards to other IP Phone vendors and DHCP Vendor Options - the answer is it depends....
    Nortel use Vendor Option 144 to inform the IP Phone of the Voice VLAN and Option 128 for the Server (PBX) to use. Ericsson uses Vendor Option 43 that can be configured to tell the IP Phone the VLAN and the Web server to read the config file from.
    I don't think you will get this working automatically with your 3Com switches, you can however manually configure the VLAN on the Cisco IP Phones.
    HTH
    Andy

  • Need help with multiple devices and apple id

    Between my husband and myself, we have two Iphones, two Ipads, and one Imac.  I back all of them up on my Imac using ONE iTunes account....we prefer not use Icloud, and I think that helps keep the information on each device relatively separate from each other...no overlaps with contacts and calendars.  We have one APPLE id and password, that we use for Itunes and the App Store.   We just got the Iphone 6 for my husband, and it keeps asking him to enter his Icloud PW.(his recognized user name is his PRIMARY email address)...which presumably he does not have, nor does he need (or maybe he does I need some real guidance on that).  To keep this from making him crazy can I just delete his Icloud account, which again presumably, was created automatically with the new Iphone 6 set up??
    Similarly, I need to use FIND my Phone (etc), and HIS devices are not in MY listed devices....is this because he NEEDS his own APPLE ID, or is there a way to add his devices to my list of devices within the APP....I thought because we share the Itunes account they should all be in MY devices.
    Can someone help me make sense of this?
    THANKS!!

    Hello melissaben6250,
    Thank you for using Apple Support Communities. 
    I understand that you are not seeing your husbands new iPhone 6 in your Find My iPhone app. First, while you may "prefer not use iCloud", you are using it, at least in regards to Find My iPhone for your existing devices.
    Now, for your husband's phone and Find My iPhone. It sounds like during the setup of his phone, he logged in to his Apple ID and even possibly created another iCloud account. In order to see his phone on your existing Find My iPhone, it will have to log in to the iCloud account where the other devices are signed in. Take a look at this article on troubleshooting Find My iPhone, especially the first section on the device not appearing.
    iCloud: Troubleshooting Find My iPhone, iPad, iPod touch, or Mac - Apple Support
    Cheers,
    Jeff D. 

  • I need HELP configuring SanOs 203 and syslog server Please!

    I have a kiwi syslog server on a windows 2003 server to which i can not get my switches to send messages to it.
    can someone please help.
    I tried to configure from the cli and from the DUI without any luck.

    You say it does not configure or that it does not send messages when it is configured? Can you port a show log info. I do not have Kiwi syslog on my network but do run 3CDaemon with no problems with SAN/OS 2.0.3
    Is syslog server ping-able from switch?

  • Need Help Configuring Multiple Lines on SPA514G

    We just transitioned to VOIP with the 3CX system. We've got SPA514G voip phones on Firmware 7.5.5. If a user is on a call, and another call comes in, the second line key doesn't do anything. I've tried some things in the phone's configuration web UI which didn't work, and I've tried reading the manual but I can't make sense of it because I'm very new with this.
    What do I need to do to enable those keys to work for incoming calls? Let me know if there is any other information you need from me.

    We just transitioned to VOIP with the 3CX system. We've got SPA514G voip phones on Firmware 7.5.5. If a user is on a call, and another call comes in, the second line key doesn't do anything. I've tried some things in the phone's configuration web UI which didn't work, and I've tried reading the manual but I can't make sense of it because I'm very new with this.
    What do I need to do to enable those keys to work for incoming calls? Let me know if there is any other information you need from me.

  • Need Help Configure SQLSERVER 2005 and Eclipse

    I just installed eclipse 3.4.1, sqljdbc_1.2.28, and server 2005, and sqlexplorer version 3.5. I am trying to configure them, and I am having a really hard time. I would really appreciate it if someone could help me out. I have installed sqlexplorer in the eclipse plugin folder, I placed the jdbc in program file folder.
    Here is what I have done so far:
    I start eclipse and click on window->show view ->connection
    Name :Gagouche
    Drive: jdbc odbc bridge
    url: jdbc:sqlserver://localhost:1433/test
    auto logon = check
    username = gagouche
    password = test01
    auto commit = check
    I see the following message “Could not connect to bitbit\gagouche. The exact message is please check the url. “
    bitbit is the name of my computer. When I login to sqlserver 2005, it usually looks like this bitbit\SQLSERVER\gagouche. Where gagouche is my username and enter my password and it works fine.

    Sorry, I meant to say that it is not working. It gives me the following error message now:
    Ping Failed!
    Details:
    com.microsoft.sqlserver.jdbc.SQLServerException: The TCP/IP connection to the host has failed. java.net.ConnectException: Connection refused: connect
         at com.microsoft.sqlserver.jdbc.SQLServerException.makeFromDriverError(Unknown Source)
         at com.microsoft.sqlserver.jdbc.SQLServerConnection.connectHelper(Unknown Source)
         at com.microsoft.sqlserver.jdbc.SQLServerConnection.loginWithoutFailover(Unknown Source)
         at com.microsoft.sqlserver.jdbc.SQLServerConnection.connect(Unknown Source)
         at com.microsoft.sqlserver.jdbc.SQLServerDriver.connect(Unknown Source)
         at org.eclipse.datatools.connectivity.drivers.jdbc.JDBCConnection.createConnection(JDBCConnection.java:89)
         at org.eclipse.datatools.connectivity.DriverConnectionBase.internalCreateConnection(DriverConnectionBase.java:104)
         at org.eclipse.datatools.connectivity.DriverConnectionBase.open(DriverConnectionBase.java:53)
         at org.eclipse.datatools.enablement.msft.internal.sqlserver.connection.JDBCSQLServerConnectionFactory.createConnection(JDBCSQLServerConnectionFactory.java:27)
         at org.eclipse.datatools.connectivity.internal.ConnectionFactoryProvider.createConnection(ConnectionFactoryProvider.java:83)
         at org.eclipse.datatools.connectivity.internal.ConnectionProfile.createConnection(ConnectionProfile.java:355)
         at org.eclipse.datatools.connectivity.ui.PingJob.createTestConnection(PingJob.java:76)
         at org.eclipse.datatools.connectivity.ui.PingJob.run(PingJob.java:59)
         at org.eclipse.core.internal.jobs.Worker.run(Worker.java:55)
    Edited by: gagouche on Feb 9, 2009 8:08 PM

  • Multiple Vlans Per SSID

    Hi
    We are just putting in a new Controller - 5500 type
    We are using a WCS .
    Someone has raised the issue of whether we can have multiple vlans
    per SSID - as otherwise we may have very large broadcast domains
    due to the overall design being to have  Maybe 3 SSIDs
    Guest
    Staff
    Engineering
    I think in SWAN we could get away with dynamic vlans.
    We would like to have multiple vlans in each SSID to avoid the above.
    Can we do this in the new setup.
    Kind Regards
    Steve

    Hi Steve,
    yes it works just the same.
    Enable AAA override on the controller and have interfaces configured for each vlan. Then the ACS can simply push the vlan depending on the user authentication. Users are then split in separate vlans.
    Another way of doing is to group APs. You can have a group of APs serving SSID Guest in vlan 1, Employee in vlan 2 and another group of APs serving the same SSIDs but in vlan 3 and 4. It's "per-user" vlan load balancing or "geographic" vlan load balancing.
    However, broadcast domains should not be a major concern in wireless as broadcasts are blocked by default. The WLC will proxy for ARP and DHCP.
    Regards,
    Nicolas

  • Vlan and SSID not showing in AP Web Interface

    We have a couple of APs that do not show the Vlans and SSIDs through the AP web interface.  If you go to the SSID manager page in web interface, the page comes up but does not show any of the SSIDs configured.  The same goes for Services - Vlan.  That page comes up but does not show any Vlans configured.  If you telnet to the APs, you see the listed mssid and all the SSID interfaces.  The SSIDs on the APs are functional and working.  This just makes it difficult to use the web interface for these APs.  I have tried to compare running configs on APs where web interface is not showing this and on APs that it is showing but cannot see any differences.
    Thanks.

    Unsupported things are never documented. You can't possibly list all browsers that you don't support.
    But if it's not mentionned clearly as supported then it means "it might work but we never tested with it".
    Let us know how it goes with the 12.4.21
    Nicolas
    ===
    Don't forget to rate answers that you find useful

  • I need help, yesterday I installed and reinstalled the Yosemite system and take long to turn on my laptop, the bar takes to fill, and I'm worried. Can you help? thank

    I need help, yesterday I installed and reinstalled the Yosemite system and take long to turn on my laptop, the bar takes to fill, and I'm worried.
    Can you help? thank

    revert back to Maverick that is what I had to finally do. This was the worst upgrade I have ever seen. Hopefully you have Time Machine backup and can revert back. It was pretty painless except for a few issues. I will wait until Apple gets their stuff together on this upgrade or may never will.

  • Need help with Blog, Wiki and Gallery

    Hi Team,
    Need help with Blog, Wiki and Gallery startup. I have newly started visiting forums and quite interested to contribute towards these areas also.
    Please help.
    Thanks,
    Santosh Singh
    Santosh Singh

    Hello Santhosh,
    Blog is for Microsoft employees only. However, you can contribute towards WIKI and GALLERY using the below links.
    http://social.technet.microsoft.com/wiki/
    http://gallery.technet.microsoft.com/

  • Need help FLASH not launching and not uninstalling "licensing for this product has stopped working".

    Need help FLASH not launching and not uninstalling "licensing for this product has stopped working" and " you can only install one adobe product at a time please complete the other installation"  Flash was working absolutely fine before, I have no idea why this happened.

    I am having similar problem.  Can't open any of CS3 programs after trying to download Dreamweaver Trial, which wouldn't work because "couldn't remove DLM extention" error message.  So now I can not run Illustrator, Photoshop, or even Adobe Reader.  These are properly licensed for about a year. I get "License for product has stopped working".  Have 2 pending cases open with Adobe support (one for Dreamweaver trial, one for license problem) since 8/3 with NO ANSWERS - It says answers within 1-3 business days.  Was on phone support hold today for over 3 hours before line went dead with no help.  What is up with adobe support?  Can anyone help?

  • I need help importing navigation bars and rollover buttons from fireworks?

    I need help importing navigation bars and rollover buttons from fireworks, drop down menus and rollover states won't work!
    Thanks

    In my experience, the code created by graphics apps is less than satisfactory. And image based menus are very awkward for several reasons. 
    #1 If you decide to change your menu later, you must go back to your graphics app and re-craft the whole thing.  After 2-3 times of this, it gets old in a hurry.
    #2 Image based menus cannot be "seen" by search engines, screen readers and language translators.
    #3 CSS styled text menus are better for your site's visibility, accessibility and they are a snap to edit in Dreamweaver.
    That said, if you're still married to image based menus, use Fireworks to create images only. Use Dreamweaver's Image Rollover Behaviors to create your rollover scripts.
    Nancy O.

  • I need help configuring three products: WRVS4400N, WAG325N and WVC200

    Hello,
    I want your help in three linksys products as mentioned below:
    WAG325N ADSL2+ Router
    WVC200 PTZ CAMERA
    WRVS4400N VPN Router
    The computer connections and configuration of above linksys products which I am working with and which are connected with the above three linksys products at present are as follows:
    1) I have one server and one laptop.
    2) Laptop has two wireless adapters which I use to connect to the routers.
    3) The server is connected to the WRVS4400N Router through one of the four ethernet ports mentioned on backside of the WRVS4400N Router. The DHCP of this router is disabled by me and the router's default IP 192.168.1.1 was changed to 192.168.1.12
    4) The WRVS4400N router is connected to the Wag325N router for internet access to the server and server is connected to WRVS4400N Router as mentioned in point number 3 above.
    5) The WAG325N router is setup as per the instructions mentioned that came with the CD of this router. The only change that I have modified is the router's default IP. I have changed the default IP of WAG325N from 192.168.1.1 to 192.168.1.13 and DHCP is enabled on this router.
    The help that I want is step by step as follows:
    1) I want to configure the both routers in such a way so that I can access them from anywhere across the world i.e. remotely using internet.
    2) I have WVC200 Camera which I setup according to instructions mentioned in the CD and also configured the DDNS service. But when the " RJ45 Cable is connected " to my WAG325N router and Camera, then only the camera works properly. What I want is that after the setup is completed, I want to remove the RJ45 Cable connected from my camera to router and use the camera wirelessly from any location within the range of my above mentioned WAG325N router. I need flexibility to use my camera without cable connections from any location and any rooms of my house. I also configured the port forwarding and DDNS properly. The only problem is that if I remove the Cable after the setup of camera is finished, then the camera access is not working on LAN or internet(through DDNS). Whereas the same works on LAN and internet using the DDNS service, when the cable is physically connected to the WAG325N router. Also I want one more thing additionally other then this. I want to use this camera wirelessly by configuring the port forwarding options on both routers at a same time(i.e. simultaneously at once on WRVS4400N and WAG325N).
    3) Now as two DHCP cannot work at a same time and as my routers are connected with each other, So I have disabled the DHCP on WRVS4400N. Here I need help so that DHCP can be enabled on both at a same time. Because if the DHCP is not enabled on WRVS4400N then I have to give IP to the server which is connected with server. If I enable the DHCP then there are two DHCP's at a same time on same network and thus problems occurs in internet access to the server. So, what should I do in such a way so that I do not have to give any IP to my server and set it to automatic.
    4) This question is just for my knowledge so that I can use the above mentioned linksys purchases upto full extent possible in future. I want to know what is VPN and how is it usefull? What is the difference between VPN and VPN tunnel? How can VPN be used to access all my network resources connected with my server  in the above situation where my server is connected to WRVS4400N which in turn is connected to WAG325N?
    Thanks !
    Sincerely
    Kalpesh Sharma
    +91-79-25351208
    +919227435453
    Ahmedabad, India.

    for question number 1:
    you said that your main router is WAG325N, for you to remotely access the 2nd router is for you to forward the IP addr [192.168.1.12] on your first router and change its management port of your second router that is located on either the security tab or the administration tab on its User Interface
    to access your first router open and Internet Explorer and enter
    http://[public IP addr]:[management port]
    the PUBLIC IP or INTERNET IP is located on the status page of your router
    to access your second router just change the management port to
    ex.
    http://66.77.88.99:8080 first router
    http://66.77.88.99:8081 second router
    for question number 2:
    make sure that you have configured all wireless settings on both your camera and your main router WAG235N, once done save settings and power down your camera and power it back up.
    for question number 3:
    for you to enable DHCP on both routers your connection can go like so...
    from a regular port of your main router going to the INTERNET port of your second router [this way you can enable DHCP on both routers]. INTERNET is no problem, your cesond router will be able to get connection
    for question number 4:
    VPN - Virtual Private Network
    VPN tunnel -is/are connections from router to router [gateway to gateway]
    VPN is used to connect a diff network on a diff location for you to have access to the shared filed [it is like a file sharing through the internet]
    for you to be able to use VPN tunnel you have to connect to a different VPN router on a diff location. In that way you can get access to the other network 

  • Need Help in Remote Manager and OIM Configuration

    Guys,
    I am using OIM9.1.01 with Exchange 2010 , currently i have installed my remote manager on Exchange server, and its working fine. Now client want to remove Remote Manager from exchange server , and to be get install on some other server.
    will it possible to install Remote Manager on some other server than OIM and Exchange , if yes , how do i proceed with that.
    Thanks.

    Thanks Nishith Sirji,
    I am confuse about one thing , how do remote manager will understand "which database server is he going to create mailbox"? because currently I am executing powershell on exechange system only ,so no problem. but when i will installl it on some other system, how do my RM will know , where to create Maiilbox (which machine).
    do i need to configure my exchange box details anywhr in Remote Manager?
    Thanks.

  • Flex Connect Across Multiple VLANS same SSID

    I just need to find that if we have flex connect setup for differnet vlans using single controller, will roaming works when client connects to AP in a differnet VLAN but using same SSID.
    Example below:
    1) Client connects to AP on specific SSID mapped to VLAN 100, get an IP address ..all good at this point
    2) Client walks and connects to a differnet AP on same SSID but mapped to VLAN 200...at this point I observe client doesnt get a new IP address in fact it retain IP from step-1 and there is no connectivity
    3) Client walks back to first AP and connectivity is restored
    Why in step-2 client doesnt gets a new IP from VLAN 200 even when it shows connected to AP.

    Just to add to Rasika.... L3 isn't supported....I just ran into this a few days ago.... clients should request another dhcp when roaming to another FlexConnect AP that is mapped to a different VLAN.  The issue is, that some clients don't try to renew their dhcp address and gets stuck with the default 169.x.x.x.  I see this with Apple devices in general and what we are going to do is get rid of the multiple vlan setup (vlan per floor) and create a bigger vlan that the SSID will be mapped to.
    Thanks,
    Scott
    Help out other by using the rating system and marking answered questions as "Answered"

Maybe you are looking for

  • How do I use Home Sharing?

    I have two computers turned on with the same Apple ID, now how do I get music from 1 computer to another?

  • Why doesn't the HP printer show up in the printer setup utility?

    Can't understand why the HP2100 TN laserjet printer that is networked(ethernet) via a Snow basestation does not automatically show up in my list of printers. I also downloaded HP's drivers for it. My boyfriend's Powerbook running 10.3 is able to auto

  • I've encountered a browser hijack issue

    Note: I feel compelled to warn everyone that unless you're comfortable fixing a potential malware infection you should be careful in recreating my problem. I didn't plan to make the following URLs into actual links, but apparently the board does it a

  • Adobe Acrobat 5.0 and Windows 7 Problem

    How do I get Adobe Acrobat 5.0 and Windows 7 compatible so I can access my attachments to e-mails sent to me?

  • Everyday Life with

    I previously owned a Zen Xtra 30 gig and it was good but then I think my friend played around with it and might have dropped it. I also had run with it a little. There was a harddisk problem and my mom threw it out (could have sold it for parts). Now