New campus LAN/WAN harware Recommendations?

Hi there Cisco community..
We are currently in the process of looking for new office space to seat around 500 call centre and back-office staff.
The reason for this post is I haven't been in the market for buying new hardware for a number of years now and it would be good to know what the consensus is, as to what is the best hardware for this is at the moment.
At the existing office site (where all our staff currently reside) we have 4 x 6500 switches and two 3845 routers.
Our requirements are fairly standard and we aren't intending on having any data centre infrastructure at the new office site.
Features we currently use are:
     QoS for prioritisting VoIP and VDI traffic
     Netflow to monitor usage/performance (implemented on the WAN link interfaces of the 3845 devices)
In addition to these existing requirements at the new office we will likely:
      Deploy a corporate WLAN solution.
      Put in place a more advanced QoS solution.  At the moment we use ACLs to identify VDI traffic but I suspect we should be looking to use e.g. NBAR?
I'd greatly appreciate feedback regarding the following.
1) what your views are in terms of suitable hardware to meet the above requirements
2) whether it would be useful to think pragmatically, beyond the above, with respect to future proofing the office for forthcoming technology developments / changes to ways of working e.g. BYOD/home working?  Would this influence the choice of hardware?
3) Our existing switch software is comprehensive and we have been unrestricted by what features we can use.   Is the operating software purchase model more complicated these days i.e. will we find we need to buy features on a 'per feature' or 'bundle' basis?
Many thanks,
Andy

Disclaimer
The Author of this posting offers the information contained within this posting without consideration and with the reader's understanding that there's no implied or expressed suitability or fitness for any purpose. Information provided is for informational purposes only and should not be construed as rendering professional advice of any kind. Usage of this posting's information is solely at reader's own risk.
Liability Disclaimer
In no event shall Author be liable for any damages whatsoever (including, without limitation, damages for loss of use, data or profit) arising out of the use or inability to use the posting's information even if Author has been advised of the possibility of such damage.
Posting
"Best" is very subjective; also depends much on you requirements/needs.
If you've been happy with you 6500s and 3845s, I doubt you'll find much improvement with newer hardware, except perhaps for performance, because both your platforms can run IOS images that are either current or close to current.
(BTW, depending on your current 6500 hardware, you might be able to upgrade without replacing everything.)
The logical successor for the 6500 series are the 6800 series.  Just one 6807 or 6880, using IAs, might be sufficient to support all user users.
For your 3845s, the current ISR line covers a good range of bandwidth needs.  The 3845, for the same bandwidth capacity, might even be replaced by 2900 series.
For "future proofing", you'll probably want to use the "latest" hardware, as that's likely to have the longest support.  So, for example, if choosing a new ISR, you might want to go with the 4300 series.
Yes, licensing and software package selection has become more difficult, but I also understand Cisco is considering making it simpler, because of customer complaints.
For WLAN, you'll probably want to look at Cisco WLAPs and their controllers, some of which are cards that work in 6500s (don't know if they have them for 6807s too).
NBAR, may, or may not, help your QoS.  Some of it is just a pretty face on an ACL.  Some of it, though, can do much more than what you can within an ACL.  (Depending on your installed IOS version on your 3845s, they might already be able to do NBAR.)

Similar Messages

  • Campus LAN Access Switch recommendation

    Hi all,
    I am looking at the specs of 2960X switches and 3750v2 switches as possible replacements for some old 3750 switches which are approaching End OF Support.
    Am I right in understanding that the performance (both packet switching & backplane bandwidth) is better on the 2960X's than the 3750v2's? Although it looks like the 3750v2's are a lot more feature rich and also have dCEF.
    The datacheets for the 2960X report 80gig Stacking bandwidth, and 216Gbps backplane bandwidth and at least 70mpps whereas the 3750v2's are only 32gig switching fabric bandwidth and a maximum forwarding rate of 13mpps! Is there something I am missing here??
    I have no idea of costs, but just looking at getting the best value for money out of our Access Switches.
    The 3650's and 3850's look good too but I imagine they are pretty costly compared to the 2960's and I do not think we need integrated WLCs in our access switches as the AP's we have in our building are minimal.
    Any advice appreciated!
    Thanks
    Mario

    Disclaimer
    The Author of this posting offers the information contained within this posting without consideration and with the reader's understanding that there's no implied or expressed suitability or fitness for any purpose. Information provided is for informational purposes only and should not be construed as rendering professional advice of any kind. Usage of this posting's information is solely at reader's own risk.
    Liability Disclaimer
    In no event shall Author be liable for any damages whatsoever (including, without limitation, damages for loss of use, data or profit) arising out of the use or inability to use the posting's information even if Author has been advised of the possibility of such damage.
    Posting
    BTW, you realize, 3750v2s are end-of-sale?
    Correct, a 2960X might have higher fabric bandwidth and PPS ratings than a 3750v2, but that doesn't mean it's faster or better.  For fabric bandwidths and PPSs, you need to look at the needs of the ports on the device.
    A 3750v2 with 48 copper FE ports, and 4 SFP gig ports, has 8.8 Gbps of port bandwidth.  So a non-blocking fabric needs to support 17.6 Gbps.  As you note, the 3750v2 fabric is listed as 32 Gbps, so you're covered there.
    The same 8.8 Gbps of port bandwidth needs up to 13.0944 Mpps (1.488 Mpps per gig) for wire-rate for minimum size Ethernet.  Your noted 13 Mpps seems to cover that too.
    So, basically, a 3750v2 switch is wire-rate capable.
    When you get into stack bandwidth, even more that other switch parameters, there's lies, dam lies, and device performance specifications.  Trying to judge one stack architecture against the other, gets very complicated very quickly.
    On the 2960 series, I believe Cisco is "adding" each switch to switch ring link to an aggregate total.  In an ideal situation, if traffic only needed to go from switch 1 to switch 2, and from switch 2 to switch 3, then the aggregate summation does have a bandwidth advantage over StackWise "bus" like ring usage.  If traffic needs to go from between all 3 switches, traffic to from switch 1 to switch 3 will need to share the bandwidth also being used by traffic from switch 1 to switch 2.
    I.e. a 2960 80 Gbps doesn't mean you get 80 Gbps between just two switches, or the advantage of all 80 Gbps found within a maximum member 2960 stack.
    (As an aside, compare StackWise vs. StackWise Plus.  The latter has twice the physical bandwidth, but it also operates much "smarter".  Again, unwinding how stacks work, and their impact to your needs, is complicated.)
    There's also more to a switch's performance than raw bandwidths and PPS rates.  The switch's architecture, and other switch specifications, can make a big difference in real-world performance.  You'll find 3560/3750s with the fabric bandwidths and PPS rates same as some 49xx switches, but the latter often will deal with busy servers much, much better, due to different port buffering.
    All the above, also means, without some real analysis of both your needs and devices being considered, anyone's recommendations should be taken with a large grain of salt; including mine.  ;)
    That said, for simple L2 edge port usage, the less expensive 2960 series might be just fine for you.  If you want to reduce costs even more, you might also look at Cisco's SMB switches, some I think are also now stackable.

  • QoS for Live Communication Server/Video on LAN, WAN

    Hi,
    Imagine I need to deploy "Microsoft live communication server" or other type of video conferencing application on LAN and WAN throughout my organization.
    What type of QoS mechanism should I approach? CBWFQ? How about LLQ?

    Hi,
    have a look at "IP Videoconferencing Solution Reference Network Design (SRND)"
    http://www.cisco.com/application/pdf/en/us/guest/netsol/ns280/c649/ccmigration_09186a00800d67f6.pdf
    It covers among other things QoS in the WAN and in the Campus (LAN).
    In the WAN LLQ would be advisable, LAN QoS depends strongly on your swtches QoS capabilities.
    Hope this helps! Please use the rating system.
    Regards, Martin

  • E900 Wake on LAN/WAN

    Helly community!
    I'm fairly new but would like to ask someone for help.
    I would like to configure my PC to be able to use wake on LAN/WAN mainly for power issues, so I don't have to have it on all the time to access anything I need. I bought a Linksys Cisco E 900 2 weeks ago. Now I am getting really frustrated since as far as I know I did configure everything needed for it but it does not seem to work nor through WAN or even in LAN.
    What I did so far is:
    1. In my BIOS I could not find a seperate wake on lan option under power management but I did find a "Power on by pci(e) device which I have enable.
    2. I have a built in Realtek Ethernet card on my motherboard. In the setting I:
    Shutdown wake on lan - Disable
    Wake on magic packet - Enabled
    Wake on pattern match - Enabled
    Also the option to allow this device to wake up the computer using magic packet is also ticked.
    3. I use Windows 7 and have installed and started Simple TCP/IP Services
    4. I opened up UDP port 9 in Windows Firewall
    5. I have set single port forwarding in the E900 to my reserved IP for both TCP and UDP port on port 9 and just in case port 7.
    After all this it is not even working inside my LAN. Also I tried a port scanner and checking for open ports and UDP port 9 doesn't seem to be open. Why is that? Did I configure something wrong in the router?
    If someone could help me I would really appreciate it.
    Thank You in advance!

    Wake on LAN (WoL) is a technology that permits someone to turn ON a computer remotely.  The network adapter on the computer listens to network activity and will turn the computer ON once it receives a special data packet called a “Magic Packet” that triggers the boot up.  Wake on LAN is also referred to as Remote Wake-up.
    For Wake on LAN to work on a computer, it must have the following:
    •   a wired connection to an active computer network
    •   motherboard
    •   network adapter and adapter driver that supports the standard Magic Packet format
    •   computer basic input/output system (BIOS) configured for WoL
    •   an operating system that supports WoL
    •   all routers between the remote location and computer required to WoL must allow IP directed broadcasts and support IPv4
    Title: Wake on LAN feature and settings Article ID: 21418
    http://homekb.cisco.com/Cisco2/ukp.aspx?vw=1&docid=20e3824721bb44f6afb3093679a7e883_21418.xml&pid=80...
    Power Saving Remote Computing
    http://www.instructables.com/id/Power-Saving-Remote-Computing/step2/Enabling-Wake-On-LAN/

  • WCS - Adding Buildings to New Campuses

    I have many existing buildings with AP's already placed on floor plans.
    I would like to add them to Campuses. Is there a way to assign the existing buildings to new campuses without recreating everything?

    Not currently, but this is an feature request that will be looked at soon.

  • Route ISDN Voice calls over LAN/WAN

    Is it possible within the relms of normal Cisco LAN  to have an ISDN Line coming into one building, Connect it to a LAN/WAN so we could pick up the voice calls on the ISDN on the other end, In a different location?

    There are no CCM logs to tell you that, CUCM has nothing to do with the RTP, this is usually QoS issues, you always hear "nothing has changed" but they often overlook things they think are not worth mentioning, or that they think would have nothing to do. Make sure really nothing has changed.
    The only way to look at this would be to run a sniffer trace on both ends to see what you send, and you receive.

  • Script language for LAN, WAN, wireless?

    which scripting language are used for LAN, WAN, wireless to automate things etc? python, shell scripting? is there a tutorial available to i can refer to?

    It depends on what you are trying to do.
    Shell scripting is quite limited in what it can do when compared to a more general purpose scripting language such as Perl or Python. Nothing wrong with that and I have used shell scripts a lot when I was a Unix admin but for networking most of what I have seen in terms of script languages has been TCL, Perl and Python.
    You can use scripts to automate logging on to devices and executing commands, basically the script does what you would type in. To do this you can use Expect and Perl, Python and TCL all have Expect functionality (Expect was originally an extension to TCL).
    But you are still just basically automating what you yourself would type and you would run these scripts from a server, PC etc although if you have a lot of devices you need to update with the same details it can save a considerable amount of time and just as importantly if the script works it removes the human error element of configuring multiple devices and perhaps getting a few wrong.
    The next step is EEM where the device has an inbuilt TCL interpreter which means you can write applets or scripts that are stored on the device and can respond to specific things happening eg. if an interface goes up or down or the routing table is changed you can execute a set of commands.
    There is an EEM forum on here.
    I believe also that Nexus switches have an inbuilt Python interpreter which allows pretty much the same thing.
    The advantages of the interpreter being on the device is that it saves a lot of extra coding and you can get more information because Cisco have added libraries to those interpreters which are specific to the device and which provide you with a standard set of APIs which your script can use.
    As I said scripting can save a lot of time and there is an argument that all network engineers should at least now some scripting and this has become more of a hot topic with the promise of what SDN can achieve in the future although it has to be said there are already configuration management tools out there which make use of the above languages.
    It really depends on what you are trying to do and how much you want to automate things.
    In terms of tutorials etc. for all the major scripting languages there are a lot of online tutorials and books you can use.
    In addition there are sites where you can run your scripts online but to be honest it is easier to simply download the interpreter to your PC, laptop etc. and you should be able to find a compiled version of the interpreter for whatever OS you are running.
    Jon

  • I am new to Oracle, would you recommend some reading material

    I am new to Oracle, would you recommend some reading material? and the method to study Oracle. I also want to pass the OCA examination.

    Are you going to be a developer or an administrator? Oracle provides a WEALTH of documentaiton. At a minimum I recommend you read the Oracle Concepts Guide for the Oracle version you are using. That will explain in depth how Oracle works. Here is a link to the [Oracle 10gR2 Concepts Guide|http://www.oracle.com/pls/db102/to_toc?pathname=server.102%2Fb14220%2Ftoc.htm&remark=portal+%28Getting+Started%29|Oracle Concepts Guide].
    If you are going to be an administrator continue with the [Administrators Guide|http://www.oracle.com/pls/db102/to_toc?pathname=server.102%2Fb14231%2Ftoc.htm&remark=portal+%28Getting+Started%29|Administrators Guide] and the RMAN [Backup and Recovery Guide. |http://www.oracle.com/pls/db102/to_toc?pathname=backup.102%2Fb14192%2Ftoc.htm&remark=portal+%28Administration%29|Backup and Recovery]
    If you are a developer start reading the [Oracle SQL Reference|http://www.oracle.com/pls/db102/to_toc?pathname=server.102%2Fb14200%2Ftoc.htm&remark=portal+%28Getting+Started%29|SQL Reference] and [Oracle PL/SQL Reference|http://www.oracle.com/pls/db102/to_toc?pathname=appdev.102%2Fb14261%2Ftoc.htm&remark=portal+%28Getting+Started%29|PL/SQL Reference].
    HTH!

  • Looking for help to improve Airport performance over LAN (WAN is fine)

    Ok, I've read through several threads on this forum that address problems people are having with slow performance with Airport. I've also checked out all of the Apple KBs that address Airport, recommended settings. Unfortunately my issue isn't addressed by anything I've read to date.
    The bottom line is that both download and upload performance between any of my devices and the internet is fine, no problems. I am paying for 30MBps download from Verizon FIOS, I routinely get 20, and I'm guessing that the delta is Verizon's problem, not my network's. However, streaming from my media server to another device on the wireless LAN is a different story entirely. I get somewhere between 1 and 2 MBps, tops, and this poses big problems for streaming music and movies.
    My network is comprised of 3 Airport Expresses. One of them is a MC414LL/A model. This one is connected to my Verizon FIOS Actiontec MI424WR router (which I have set to bridge-mode according to the instructions provided at http://www.dslreports.com/forum/r17679150-Howto-make-ActionTec-MI424WR-a-network -bridge) via CAT5 ethernet. This Airport Express is set to "create a network" network mode, "802.11 only (5GHz) - 802.11b/g/n" radio mode (although I have also tried "802.11 only (5GHz) - 802.11/n only (2.4 GHz)" radio mode, and this didn't solve the problem). Finally, I have chosen 2.4 and 5GHz channels that have little interference (2 and 161 respectively). My other two Airport Expresses are MB321LL/A models and are set to "Extend a wireless network" network mode, with the 5GHz network chosen as the network that they extend. (I have tried switching over to having them extend the 2.4GHz network, and performance gets worse, not better.)
    I am using a late 2009 Mac Mini as a media server. It is connected to the 5GHz network (though I've tried the 2.4GHz network), and it runs XBMC and JRiver media servers (not simultaneously, either one or the other.) I have a PS3 and a Sony Blu Ray player, each plugged into one of the MB321LL/A Airport Expresses via CAT5 ethernet, and I stream media to each of these devices via one or the other media server (both devices are DNLA-enabled). My Mac Mini has a 3TB external hard drive connected via FireWire 800, which is where all of my media resides. In addition to streaming media over the network, I have a TV plugged directly into the Mac Mini. When I play media to this TV, performance is outstanding, so I'm confident my poor performance to the PS3 and Sony BDP is a network issue, not an issue with the external drive.
    Although my building has several other wireless networks, only one of them is 5 GHz, and it isn't using channel 161. The 2.4 GHz band is crowded with several networks, although channel 2 is usually in the clear. I have tried switching let Airport choose a channel automatically, and I haven't noticed a difference. It has occurred to me that the problem could be with how I bridged the Verizon Actiontec router and not with any of the Airports, but I don't get any errors (e.g. double NAT errors, which some people who have bridged improperly get), and I am pleased with my download and upload speeds to the internet. The issue is only on my LAN. Finally, yes, all of my firmware is up to date, version 7.6.3 on all three Airport Expresses.
    Can anyone offer me suggestions for how I can get better performance streaming media from my server to the two playback devices? Since all 3 Airport Expresses support 5GHz, I'd have thought I'd be able to take advantage of 802.11n speeds when streaming between them. (MB321LL/A  supports "Draft N", but does this matter?) With the settings that I'm currently using, I can't stream faster than 2MBps (and that's on a good day), which is below what I ought to be able to get rom 802.11g. This is especially problematic when I try to stream hi res (96 MHz / 24 bit or higher)  music files, whether uncompressed or compressed. I hear awful pulsing sounds through my speakers. If I pause the track and let my streaming device buffer, I might get 10 or 15 seconds of clean playback, but then it starts the pulsing again as soon as the buffered music is finished playing. On occasion when I stream music from my iPhone via Airplay to one of the Airport Expresses, I get clean playback most of the time, but on occasion the music cuts out. (It's my understanding the Airplay requires ~800 Kbps, which seems consistent with my LAN speed usually being between 1 and 2 Mbps but sometimes dropping).
    I have iStubler and I've used the Apple network diagnostics -- these are the tools that led me to choose channels 2 and 161 for 2.4 and 5GHz respectively. I'm sure I could be using these tools to learn more about my network's performance, but I'm sure what to look for.
    Thanks for your suggestions.

    Ok, cool. I'm really glad that the issue has been isolated. Thanks a ton for your insight!
    Hopefully I can find a spot where the signal strength of the hub is noticably better but that isn't too inconvenient for an ethernet run. My Sony BDP, which is the device connected to the problem basestation, has wifi capability, so I could always ditch the ethernet cable if the best spot for the basestation doesn't permit a cable run. But I'm aware that ethernet usually offers faster transfer speeds than wifi. Moreover, I'm not sure that the Sony BDP supports 5GHz. It might be a 2.4GHz-only device, in which case I'll have new interference issues to contend with, since like I said in my original post, there are several other 2.4GHz networks in my building.
    Anyhow, now that I understand the problem, I can figure out a solution. Thanks again.

  • Setting up a new Time Capsule - WAN or Ethernet quandry

    Just got a new TC - I am hoping to have it host (or extend) my wireless network off a wired foundation that has a cable modem. I am struggling with which hard-wire port I can use to get it access to the internet. I try plugging the wire into the WAN port and the TC just disappears. I switch it to an Ethernet port and the Airport utility cries foul that I don't have anything in the WAN port! My Cable Modem is buried deep in the basement with a d-link WAN hub connected to it, sharing a wired network through the house. I was under the impression the TC would work (and talk to the internet) if you only hooked it to the rest of your wired network (using the Ethernet ports.) Is that not so? Does it need to be the go-between for your Cable Modem & Home wired network?

    Welcome to the discussions!
    Since you have a router ahead of the Time Capsule, please check to make sure that you have your TC set for Bridge Mode as follows:
    Hard Drive > Applications > Utilities > AirPort Utility
    Click Manual Setup
    Click the Internet icon
    At the bottom of the next page the setting for Connection Sharing should be set to "Off (Bridge Mode)".
    In this setting, it does not really matter whether you have the ethernet cable from the router plugged into the WAN or LAN port as they all behave the same when the TC is in Bridge Mode.
    You may need to restart your modem and router ahead of the TC and you should have internet.

  • Uccx lan/wan deployment requirement

    Hi All,
    I have a ccx case opened with Cisco Tac.
    The issue is that I have a CCX HA and my client needs to reinstall the ccx subscriber with the new IP address scheme.
    After the reinstllation, I need to logon to the ccx subsricber for initial the ccx database replicatoin.
    Unfortunately, I've got the error something saying that I've already had the second node on the HA cluster which I already deleted the node out from the uccx publisher administrator webapage.
    The Cisco TAC engineer said that it's because the deployment type and the subnet scheme does not meet the requirements.
    If the uccx publisher and the subscriber are in the DIFFERENT subnet, the deployment must be "WAN". But mine is "LAN".
    I'm trying to find the deployment documents that mention this requirement but I can't find it. So curious, since the first Tac didn't put this in to concerns.
    Does anyone know if this is really matter to the database replicatoin?
    Thanks in advance,

    Hi,
    The output of the cli:
    admin:show uccx dbreplication servers
    This operation may take a few minutes to complete. Please wait...
    SERVER                 ID STATE    STATUS     QUEUE  CONNECTION CHANGED
    g_hecnr_sl_uccx01_uccx    1 Active   Local           0
    g_hecnr_sl_uccx02_uccx    2 Active   Connected    1977 Jan  7 02:09:26
    it looks great.
    Here is the error from the log file:
    7: 1/7/2013 12:01:21 PM %CHC-LOG_SUBFAC-3-UNK:Database Connection Error | Unable to establish connection to database.  Check the log file for error 5051.
    8: 1/7/2013 12:01:32 PM %CHC-LOG_SUBFAC-3-UNK:CRA_DATABASE Connection String: Provider=Ifxoledbc.2;Password=*****;Persist Security Info=False;User ID=*****;Data Source=db_cra@hecnr_sl_uccx02_uccx;Extended Properties="CLIENT_LOCALE=en_US.utf8;DB_LOCALE=en_US.utf8;UNICODE=TRUE;RSASWS=TRUE"
    9: 1/7/2013 12:01:32 PM %CHC-LOG_SUBFAC-3-UNK:Failed to login user to the apps server since we failed to initialize database connections
    Any ideas?
    thanks in advance,

  • Cascade router behind NVG589 LAN - WAN. Can't talk between networks.

    I have a d-link DIR-655 cascaded behind my NVG589. I have it configured for two different networks/subnets. Nodes on each network can talk to each other and the internet. Nodes on one network cannot talk to nodes on the other network. NVG589:IP address: 172.16.0.1/255.255.0.0Cascaded router address: 172.16.0.2Network (behind cascaded router): 192.168.0.0/255.255.0.0 DIR-655:IP address: 192.168.0.1WAN IP address (static or DHCP): 172.16.0.2Default gateway: 172.16.0.1 Connect NVG589 LAN port to DIR-655 WAN port. As above. Nodes on the DIR-655 network can ping 192.168.0.1, each other, and access the internet.Nodes on the NVG589 network can ping 172.16.0.1, each other, and access the internet Nodes on the DIR-655 network cannot ping 172.16.0.1 or any other 172.16.x.x nodeNodes on the NVG589 network cannot ping 192.168.0.1, or 172.16.0.1, or any other 192.168.x.x node. The only explanation I can come up with is that configuring the cascaded router on the NVG589 does not create a static rouite for the network behind the cascaded router. in my configuration, it does not have a static route for 192.168.0.0/255.255.0.0 pointing to 172.16.0.2. And maybe visa versa in the other direction. Missing either or both might explain what I'm seeing. Can I do what I'm trying to do?

    Sigh... That part makes sense though .  I guess I'll buy another router then. Put the NVG589 in "bridge" mode and just use it as a modem to the new router. Cascade the DIR-655 behind my new router Thanks for the replies. 

  • Network Management system for our LAN/WAN

    Hello Everyone,
    We have a Cisco network covering around 350 staff, in 8 floors, and recommended Management system  to monitor the network , showing the bottleneck, performance, download speed for each client, it will be great if the tool is covering both LAN and WAN network.
    Is there any free tools from Cisco can do the job? if not pls advise
    Best Regards

    Sure - just remember free to buy is not the same as free to own. Open source tools usually require a larger investment in configuring things yourself and usually (but not always) come without any sort of option for paid support.
    Many people put together a system with Nagios (fault management), Cacti (performance management) and RANCID (configuration management). Each is free and community-supported. If you or your organization is comfortable setting up some Linux servers and customizing some files and templates you can have a quite workable system using those tools.
    If you want a lower cost of entry with paid support options, consider something like Spiceworks, What's Up Gold, or the entry level products from SolarWinds (Kiwi syslog manager, cattools, engineer's toolset etc.).

  • CAPWAP Wireless VLAN in Routed Campus LAN

    I am configuring CISCO Wireless LAN Controller in College campus. we have the following components
     1. CISCO 4510R as core switch and a centralized WLC is connected to Core Switch
     2. CISCO 3560 L3 switch at Distribution Layer Switch
     3. CISCO LWAP 1142
    I want to configure Wireless VLAN in a college campus. Wireless LAN.  The requirement is to configure Distribution switch as L3 so that VLAN will not reach till the Core Switch. That is the Link between Distribution and Core Switch will be Layer 3 routed link and not a Trunk Link.
    Since it is a routed back bone environment, VLAN is configured only in distribution layer switches. So, these configured VLAN will not reach core
    switch.
    With that said, is it technically possible to achieve the Wireless VLAN in this above proposed setup.?
    Do I have to configure Trunk between Distribution Switch (APs are connected) and Core Switch (WLC is connected), to pass the Wireless VLAN in the trunk link?
    Advance Thanks for reading and helping to get it clarified
    SAIRAM

    We are in the process of moving to a mostly routed Campus, and had similar questions and a few more. We will be using only EIGRP, with each enclave set-up as a stub. I was wondering if I can modify our wireless network to be strictly routed, and remove all the trunk/access configurations from the switch ports facing  theAPs, and hard code (static) all of them to IP routed ports. We only have one WLC active, with one back-up. The WLC is facing our core switches in a LAG set-up. The network was originally set-up with all the dynamic interfaces for each AP set-up in a GLBP fashion between our two cores. Each AP had a dynamic interface created in the WLC and added to one AP group. All of our APs are now connected via ethernet to the wired infrastructure, so none of our APs are in true MESH fashion anymore. We use Microsoft DHCP to issue out IPs to our APs.
    I was wondering if I can remove the dynamic interfaces from the WLC, and use EIGRP to sort of the routing of our wireless network. I would create L3 SVIs (multiple in some cases) on all the switches that APs are attached too, and modify each Microsoft DHCP scope to point to whatever AP model was used and to point to the WLC. Now, what I'm unsure on, how would this behave with no Native Vlan/User Vlans configured on trunk ports pointing toward the AP. I was thinking of using what was once used at the Native Vlan (subnet info), and using that same subnet to create a IP routed port facing the AP and modify the AP IP via the WLC to select static assign. I can place IP helper addresses under the routed port to face our DHCP server (not sure if this really matters, if I already place them under the user L3 SVIs). Before, I had a DHCP scope for the native and user subnet. Would the AP still be able to connect to the WLC correctly, if I delete the scope (used before for the native vlan), since it usually resolved the WLC IP via option 43 (it can use DNS instead). I would imagine so, since I will be placing these networks under EIGRP to advertise within our Campus, which has L3 reachability to the WLC. And under the user subnets, I would still configure the Microsoft DHCP scope to face the AP model and controller IP. There just woundn't be a scope for the subnet that use to be for the Native Vlan. For any new set-up, I would pre-provision the AP under a user subnet access port, and then hard code it within the controller a static IP, to deploy later at the new site. For routed networks, are dynamic interfaces really necessary on the WLC? As long as L3 is working as intended, and the user switch has reachability to the Microsoft DHCP server, then users should be able to pull IPs fine through, correct? I've tested already with a PTP bridge we have, and hardcoded the ports to IP routed ports, and advertised it via EIGRP, and haven't noticed any issues with the customers pulling new IPs. I wanted to gather more information before deploying this for across the board to our other types of wireless set-ups. I'm not using FlexConnect. I've moved most of our 1552e APs over to local mode recently, which have wired connections to the LAN.

  • Need help with Campus LAN building design

    Hey everyone,
    I'm currently studying in a program at College call Internet Communications Technology. I am working on a final project in my Physical layer class. Basically the final project is to design the telecom closets and network infastructure for a 3 level building.
    We never really covered the capabilities of certain cisco hardware so I'm looking for a little guidance in what to select.
    Basically we have between 300 - 400 people on each level. So we require 1148 cables. We need an additional 134 PoE connections for our phones and WAP's  I was going to VLAN each floor and then use VLANS on the floors themselves.
    On the main floor we will accept the fiber from the main section of the campus for the internet access and branch that out to the other telecom closets in the building using a single mode fiber cable.
    I was taking a look at some gear and this is where I am confused. I will require 1 fiber input from the campus and then I need 3 switches on each floor accepting fiber as there are 3 major areas on each floor. So each end of the floor has an auditorium with 170 people and then the middle.
    I was looking at using the Cisco Catalyst 2960-48PST-L - switch - 48 ports - managed - rack-mountable for our access layer switches in the telecom closets at the end... But I'm not really sure what to use for our core/distribution gear so I believe I would need 1 router on the main floor which can do all the interVLAN routing via fiber links between floors but then I would require a router on both floors 2 and 3 for the interVLAN routing on each floor. I would then need 3 main distribution switches on each floor. The switches I'm thinking could be smaller port based like a 12 or 24 port based switch as they would really just be there for accepting the fiber link from the main router on the first floor and branching that to the other telecom closets on the floor.
    Just looking for a little guidance here.
    Thanks everyone,
    Mike

    I'd recommend you have a look at the Cisco Smart Business Architecture designs: http://www.cisco.com/en/US/netsol/ns982/networking_solutions_program_home.html#lan
    Specifically see the LAN Deployment Guidefor advice on choosing the right type fo switch for the various layers.
    As a general guideline, I don't see anyone these days putting in routing away from the core in a campus (nor would I generally recommend it).

Maybe you are looking for

  • Serial number not working, what to do?

    I purchased the CS5 Extended Software on eBay and the serial number on my box is not working.  I am at a loss because I shelled out almost $400 for it and I still have no software.  I already tried some of the Adobe troubleshooting suggestions but no

  • One digit in customer number missing in Export to excel download

    Dear All,            We have a customized report for customer collection.The output of this report is as per desired. But when we download it to excel last digit in customer master is missing.That means say customer number is 1100051 while we export

  • Why cant I login to my Mac Pro?

    Hi, when I try to login to my Mac Pro from wakeup screensaver (it asks for the password), it no longer accepts my password. When I erase the username on that screen and try to type it in, it does not echo the characters on the screen either. It just

  • Purpose of motion tweens + movie clip symbols

    Hello. I've been going over several tutorials and whatnot and I'm confused on the point of movie clip symbols and motion tweens. To me using the other tweens and symbols are "easier". Can someone explain to me why they're so beneficial to have been a

  • MIRO ERROR _ REG

    MIGO completed for two line items on 23.01.2010.  Later it appears that VAT code was changed from V1 to V6 (both being non-deductible tax codes) on 30.01.2010 when I saw the po and went to environment and saw the item changes.  The item is not in sto