Vlan trunk problem
Hi,
Im configuring a vlan trunk between 2 switches but I'm having a problem somehow.
Switch 1 a Cisco 3750G n
name: alrswcc00
interface GigabitEthernet1/0/28
description Uplink Alrswcc20
switchport trunk encapsulation dot1q
switchport trunk allowed vlan 1-30
switchport mode trunk
end
Name: Gi1/0/28
Switchport: Enabled
Administrative Mode: trunk
Operational Mode: trunk
Administrative Trunking Encapsulation: dot1q
Operational Trunking Encapsulation: dot1q
Negotiation of Trunking: On
Access Mode VLAN: 1 (default)
Trunking Native Mode VLAN: 1 (default)
Administrative Native VLAN tagging: enabled
Voice VLAN: none
Administrative private-vlan host-association: none
Administrative private-vlan mapping: none
Administrative private-vlan trunk native VLAN: none
Administrative private-vlan trunk Native VLAN tagging: enabled
Administrative private-vlan trunk encapsulation: dot1q
Administrative private-vlan trunk normal VLANs: none
Administrative private-vlan trunk private VLANs: none
Operational private-vlan: none
Trunking VLANs Enabled: 1-30
Pruning VLANs Enabled: 2-1001
Capture Mode Disabled
Capture VLANs Allowed: ALL
Switch 2 a Cisco 2960S
name: alrswcc20
interface GigabitEthernet1/0/25
description Uplink Alrswcc00
switchport trunk allowed vlan 1-30
switchport mode trunk
end
Name: Gi1/0/24
Switchport: Enabled
Administrative Mode: trunk
Operational Mode: trunk
Administrative Trunking Encapsulation: dot1q
Operational Trunking Encapsulation: dot1q
Negotiation of Trunking: On
Access Mode VLAN: 1 (default)
Trunking Native Mode VLAN: 10 (Inactive)
Administrative Native VLAN tagging: enabled
Voice VLAN: none
Administrative private-vlan host-association: none
Administrative private-vlan mapping: none
Administrative private-vlan trunk native VLAN: none
Administrative private-vlan trunk Native VLAN tagging: enabled
Administrative private-vlan trunk encapsulation: dot1q
Administrative private-vlan trunk normal VLANs: none
Administrative private-vlan trunk associations: none
Administrative private-vlan trunk mappings: none
Operational private-vlan: none
Trunking VLANs Enabled: 10,20,30,40
Pruning VLANs Enabled: 2-1001
Capture Mode Disabled
Then lastly on switch 2 I created a port for an Ubiquiti access point with following settings.
interface GigabitEthernet1/0/24
switchport trunk native vlan 10
switchport trunk allowed vlan 10,20,30,40
switchport mode trunk
end
But my AP doesn't seem the get an IP. Where as if I plug it in on Switch 1 it does with the same settings.
So I am assuming there is something wrong with my trunk. What am I doing wrong?
Thank you,
Michael
Here are a couple of observations:
1. The switchport trunk encap dot1q command was not applied on the 2960 because 802.1q trunking is the default. The 2960 series switches do not support ISL encapsulation, as the OP observed. There is, therefore, no need to manually specify the trunking protocol. The show int g1/0/24 switchport command confirmed that trunking is working. I find the show int g1/0/24 trunk command to be more informative in this context. It tells you what VLANs are active and trunking between the connection.
2. You do need to define VLANS 2-30 on your second switch. You can do so manually or you can configure VLAN Trunking Protocol (VTP). VTP is your easiest bet. Example config:
Switch 1
sw1(config)# vtp mode server
sw1(config)# vtp version 2
sw1(config)# vtp domain MY_DOMAIN
sw1(config)# vtp password MySecret
Issue a show vtp status in priv exce mode to very your settings.
Switch 2
sw2# show vtp status
Do this command FIRST and make sure that the configuration revision number is smaller than the revision number of SW1.
VTP Operating Mode : Client
Maximum VLANs supported locally : 255
Number of existing VLANs : 25
Configuration Revision : 174
If config revision on SW2 is greater than config revision of SW1, then issue following command:
SW2(config)# vtp domain bogus
SW2(config)# vtp domain MY_Domain
SW2(config)# do show vtp status
Your config revision should go back to zero.
Now issue the same commands on SW2.
SW2(config)# vtp version 2 (pretty sure that is default, but I issue it anyway)
SW2(config)# vtp mode client (means you cannot define VLANs on this switch. Most admins prefer that only one switch be capable of creating VLANs).
SW2(config)# do sh vtp status
The config revision was important because injecting a switch into your network that has a higher VTP revision can overwrite your existing VLAN database. If that happens, chances are that most of your network traffic will cease to function as all of your access ports will be in a VLAN mismatch mode.
Similar Messages
-
ASA 5505 Trunking problem with cisco 3760
Here is my asa 5505 configuration and at bottom i am pasting cisco 3760 configuration, I am having trunking problem and seen other people having the same issue but no solution.
Problem: when i connect any device on Switch 3760 port 1 which is trunked i cannot communicate with niether vlan.
I have tried device with both static vlan configuration
192.168.1.99 (vlan 2)
172.168.1.99 (vlan 8)
if i change port 1 to access mode or define native vlan it work with one vlan.
interface 5 of Cisco ASA is connected with interface 25 (uplink) on Cisco Switch
interface Ethernet0/5
switchport trunk allowed vlan 1-10
switchport mode trunk
interface GigabitEthernet1/0/25
description **UPLINK**
switchport trunk encapsulation dot1q
switchport trunk allowed vlan 1-10
switchport mode trunk
On port 1 of cisco Switch i am creating trunk
interface GigabitEthernet1/0/1
description **LAN**
switchport trunk encapsulation dot1q
switchport trunk allowed vlan 1-10
switchport mode trunk
no logging event link-status
spanning-tree portfast
CISCO ASA Config i have configure the following vlans
interface Vlan2
nameif inside
security-level 100
ip address 192.168.1.1 255.255.255.0
interface Vlan8
description Server VLAN
nameif Internal_LAN
security-level 90
ip address 172.168.1.1 255.255.255.0
interface Ethernet0/0
switchport access vlan 2
on Cisco 3760 i have configure the following vlan.
v
vlan 2
name inside
vlan 8
name Internal_LAN
interface Null0
no ip unreachables
Message was edited by: macboyHello,
I can see many people have visited the post but there isn't any reply.
I think this is because of the following:
The configurations are long and most people dont want to read it. Try adding only relevant configuration to the issue.
The problem description is not clear. You mention trunking problem but what exactly is the problem? Can you ping from switch to ASA? Is any Vlan information being passed or they are all failing. Try to be as much specific as possible.
Which port of the switch connects to the ASA?
Using portfast on a trunk (interface GigabitEthernet1/0/1) is not recommended.
Regards,
Felipe.
Remember to rate useful posts. -
Router 2811 and C2960 Switch Trunking Problem
Hi all
I got an problem with a trunking problem between Router 2811 and C2960 switch
In router 2811 - I created f0/0.1 10.65.20.1 (VLAN 1) and f0/0.48 10.65.23.1 (VLAN 48)
In C2960 - Vlan 1 10.65.20.30 , VLAN 48 10.65.23.30
Finally I can only ping VLAN 1 IP but fail to ping VLAN 48 IP, can help me how to troubleshoot it?
Hugo
Router 2811 Configuration:
interface FastEthernet0/0.1
encapsulation dot1Q 1 native
ip address 10.65.20.1 255.255.255.0
interface FastEthernet0/0.48
encapsulation dot1Q 48
ip address 10.65.23.1 255.255.255.0
C2960 Configuration:
interface FastEthernet0/24
switchport mode trunk2811#sh vlans
Virtual LAN ID: 1 (IEEE 802.1Q Encapsulation)
vLAN Trunk Interface: FastEthernet0/0.1
This is configured as native Vlan for the following interface(s) :
FastEthernet0/0
Protocols Configured: Address: Received: Transmitted:
IP 10.65.20.1 388873 262275
Other 0 1723
390760 packets, 71854310 bytes input
263998 packets, 53723195 bytes output
Virtual LAN ID: 48 (IEEE 802.1Q Encapsulation)
vLAN Trunk Interface: FastEthernet0/0.48
Protocols Configured: Address: Received: Transmitted:
IP 10.65.23.1 0 0
Other 0 20
0 packets, 0 bytes input
20 packets, 1883 bytes output
2960_24#sh int trunk
Port Mode Encapsulation Status Native vlan
Fa0/24 on 802.1q trunking 1
Gi0/1 on 802.1q trunking 1
Port Vlans allowed on trunk
Fa0/24 1-4094
Gi0/1 1-4094
Port Vlans allowed and active in management domain
Fa0/24 1,48
Gi0/1 1,48
Port Vlans in spanning tree forwarding state and not pruned
Fa0/24 1,48
Gi0/1 1,48 -
I have not been able to configure a VLAN trunk at a CE-500. I configure the port using CNA as router and specify the native VLAN, but I do not know where to specify the allowed VLANs. The port is connected to a Cisco Router with sub-interfaced configured. When I click on "modify" the smartport, an small windows quicky opens and closes, only leaving an option for the native VLAN. What am I doing wrong? How do I specify a port as a trunk port?
Thanks a lot for the help.
Juan SI believe you are aware of creating the standard Cisco IOS procedure for creating VLAN trunks.
under the interface configuration mode, in which you need to create a trunk,
switchport mode trunk
switchport mode trunk encapsulation isl/dot1q
switchport mode trunk native vlan
switchport mode trunk allowed vlans
But if you are already using these commands correctly, still you have the problem, I want you to let me know the following informations.
1. What error message you receive at the console while implementing trunking?
2. What is the other end device with which you are trying to establish trunk?. -
Does the 8540 support VLAN Trunking
I would like to VLAN trunk four VLANs(8540 bridge-groups) from an 8540 switch router to a Cat 5000. I have not seen in Cisco's documentation anything that indicates that the 8540 supports VLAN trunking.
8540 supports both ISL and 802.1q VLAN trunking
http://www.cisco.com/univercd/cc/td/doc/product/atm/c8540/12_1/pereg_1/quick_cg/layer3.htm#39775 -
Encrypting vlan-trunk traffic between switches
Hi,
Can anyone guide me to some papers or other resources on how to encrypt traffic between 2 switches. The switchces will be connected with fiber and use dot-1q tagging. And I wan't to encrypt all of the trunked traffic.
I was thinking of L2TP, but I haven't found any good description on how to implement this. I have two 3750 switches I thought I might use.
Thanks for any input,
Regards,
Oyvind Mathiesen
mnemonic
NorwayHi,
Thanks for the response. I had a look at MACsec and it looks good. I would have liked to employ something P2P though, to also limit the ammount of MAC addresses broadcasted on the "wire". But let me first give you an understanding of the task:
We have two sites, connected via fibre and we want to create a VLAN trunk across and order to expand the broadcast domains to te other site.
The IDIOT carrier, has a limitation on the number of MAC addresses they allow on the fibre service, 100.
We also need to encrypt the datatraversing this connectivity.
MACsec wuold work 100% exept the source and dstination MAC addresses are still sent (at least according to https://docs.google.com/viewer?a=v&q=cache:LEf2qOmYZyYJ:www.ieee802.org/1/files/public/docs2011/bn-hutchison-macsec-sample-packets-0511.pdf+&hl=en&gl=za&pid=bl&srcid=ADGEESgmAHXpDOY0RBAE-Rv1HDpu_C_gkeSPN4cv6NGgyP0M1aXVu0UqzCfxo8t_P41ep6J37k4OLKnjfp1M9hoTDHxY22WGz2h7yB7YRLyPvRUbGS8TICzvEMlG92xqbhy6RWFugmnj&sig=AHIEtbTfu0LQIJejdYidE6yzq4lpPifxjQ
And that would cause me to eat into the 100 MAC limit.
Ridiculous I know, but we are looking for an out-of-the-norm plan...
Thanks -
Cisco VLAN Trunking Protocol Vulnerability
I have got a cisco 2821 model router with a c2800nm-advipservicesk9-mz.151-2.T4 IOS, and was reported with 'Cisco VLAN Trunking Protocol Vulnerability'.
Though the device is in server mode, I do not have any domain name or trunk port configured.
Is my device really vulnerable? If yes, whats next?Hi Alex,
for the trunk port on Catalyst on port GE 1/0/45, we need to enable the trunk and for on encapsulation dot1q because this catalyst model is ISL capable also and the SF300 working only with Dot1q Encapsultion
The configuration on catalyst should :
#config terminal
#interface Gi 1/0/45
# switchport encapsulation
#switchport trunk encapsulation dot1q
#switchport mode trunk
#switchport trunk allowed vlan 101-103
#spanning-tree portfast
For SF300 the port trunk it looks fine but for the port where the PC should receive an IP address
#interface fastethernet29
#switchport mode access
#switchport ccess vlan 103
Please let me know after this configuration
Thanks
Mehdi
Please rate or mark as answered to help other Cisco Customers -
Decided we'd give the Cisco 300 series switches a try and see
what we think about them compared to our Cisco Catalyst 2960 switches.
I'm already stumped on setting up VLAN trunking between 4 switches. Do I have to manually setup all the VLAN's on each switch? I set them up on the first switch and was expecting GVRP would propagate them to the others like VTP.
DennyDecided we'd give the Cisco 300 series switches a try and see
what we think about them compared to our Cisco Catalyst 2960 switches.
I'm already stumped on setting up VLAN trunking between 4 switches. Do I have to manually setup all the VLAN's on each switch? I set them up on the first switch and was expecting GVRP would propagate them to the others like VTP.
Denny -
How many VLANs supported via MACsec VLAN-trunk link?
Hi,
Any one know how many VLANs maximum allowed across a MACsec link between two C6500 with Sup2Ts or between two N7K respectively?
As far as I know, C3750X has limitation of 8 VLANs, according to
•Cisco TrustSec enforcement is supported only on up to eight VLANs on a VLAN-trunk link. If there are more than eight VLANs configured on a VLAN-trunk link and Cisco TrustSec enforcement is enabled on those VLANs, the switch ports on those VLAN-trunk links will be error-disabled.
http://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst3750x_3560x/software/release/15-0_2_se/configuration/guide/3750x_cg/trustsec.html
Thanks,
CedarHi,
Any one know how many VLANs maximum allowed across a MACsec link between two C6500 with Sup2Ts or between two N7K respectively?
As far as I know, C3750X has limitation of 8 VLANs, according to
•Cisco TrustSec enforcement is supported only on up to eight VLANs on a VLAN-trunk link. If there are more than eight VLANs configured on a VLAN-trunk link and Cisco TrustSec enforcement is enabled on those VLANs, the switch ports on those VLAN-trunk links will be error-disabled.
http://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst3750x_3560x/software/release/15-0_2_se/configuration/guide/3750x_cg/trustsec.html
Thanks,
Cedar -
Is it possible to run a VLAN trunk (DOT1Q) from a Central site to a remote over a MPLS connection?
You can do that either by using dot1q tunnelling or port based EoMPLS. For a description of these two features, please refer to the following document:
http://www.cisco.com/en/US/products/sw/iosswrel/ps5013/products_feature_guide09186a0080088187.html
Hope this helps, -
WRVS4400N VLAN trunking question
Hi all,
I just got a SRW224G4 today my main objective is to trunk 30 VLAN(s) to my WRVS4400N for interVLAN communication. So far I set G1 on my SRW as a trunk port and linked it to port 2 on my WRVS4400N (which is also set as a trunk).
So far no good when I go into LAN settings I do not see an option wheree I can set DHCP addresses or gateways for these VLAN(s). Is this even possible with the WRVS4400N I meen if Linksys is going to provide a small business solution atleast their equipment should support VLAN trunking with each other.
If anybody knows the solution to this please let me know.
CheersFrom what I know, although the WRVS4400N has support for port based VLAN setup, it does not give you the option to set different DHCP addresses for each of the 4 VLANS.
-
Hello,
does SG200 supoort VLAN Trunking?Hello, I think there is support:
I found this site too which shows how to configure it: http://lachlanmiskin.com/blog/2012/08/01/cisco-sg-200-08-trunking/
Cisco's datasheet says it supports tagging 802.1q.
http://www.cisco.com/en/US/prod/collateral/switches/ps5718/ps11229/data_sheet_c78-667827.html
Hope this helps.
Please rate useful posts and remember to mark any solved questions as answered. Thank you. -
VLAN trunking newbie SRW208MP to SRW2008MP
Hello All,
Just need a simple setup - 2 VLANs, a few ports each, on each unit, trunked together (ultimately on SFP module). Tried what seems to be right but (natch) not working. Just need simple guidelines to see where am going wrong. Thanks!OK, well, using that example, as well as another thread here (Cisco SLM224P
VLAN TRUNKING), I reset and redid all the VLAN related settings.
There are 2 subnets in play here -
10.51.0.0/255.255.252.0 - VLAN 1 - Used as the Management VLAN.
10.51.4.0/255.255.255.0 - VLAN 5 - A subnet for Wireless LAN POE connection and management.
And 2 switches -
198 is a SRW208MP, remote unit. will have single WAP and various devices.
199 is a SRW2008MP, at head end near subnet(s) source. Will have up to 4 WAPs and the
connections required to provide for both subnets.
For purposes of discussion, the planned fiber SFP interconnect is being played by a copper trunk.
Setups follow:
198 VLANs-
198 Port Setting-
198 Ports to VLAN 1-
198 Ports to VLAN 5-
198 VLAN to Ports-
Unit 2 - 199
199 VLANs-
199 Port Settings-
199 Ports to VLAN 1-
199 Ports to VLAN 5-
199 VLAN to Ports-
The configuration as posted does not provide the expected results.
I am convinced I am overlooking something simple. Usually is!
The net results are that the Management VLAN (1) is present and accounted for on both switches, but that could even be because they are acting as switches do.
The VLAN 5, however, does not function at either end. The 'Local' switch, 199, shows traffic on the WAP ports but no traffic of any consequence is traversing and the WAPs are nonresponsive.
Ditto Remote switch. Management VLAN yes, 5 VLAN no.
Any suggestions greatly appreciated. -
VLAN trunking from Cisco Catalyst 3750 to Cisco SF300-48P issue and related
Hello expert,
I'm having difficulties to configure VLAN trunking between Cisco Catalyst 3750 switch with Cisco SF300-48P switch and my workstation unable to get any DHCP IP from our DHCP server via Cisco SF300-48P switch. Below is the snippet of configuration on both switches:
[Cisco Catalyst 3750 Switch]
interface GigabitEthernet1/0/45
description NCC-CC-1stFlr
no switchport trunk encapsulation dot1q
no switchport trunk allowed vlan 101-103
spanning-tree portfast
[Cisco SF300-48P Switch]
interface fastethernet48
spanning-tree link-type point-to-point
switchport trunk allowed vlan add 101-103
macro description switch
!next command is internal.
macro auto smartport dynamic_type switch
interface fastethernet29
switchport mode general
switchport general allowed vlan add 103 tagged
switchport general pvid 103
Are these are correct? Kindly advice!
Thank you very much!
Regards,
AlexHi Alex,
for the trunk port on Catalyst on port GE 1/0/45, we need to enable the trunk and for on encapsulation dot1q because this catalyst model is ISL capable also and the SF300 working only with Dot1q Encapsultion
The configuration on catalyst should :
#config terminal
#interface Gi 1/0/45
# switchport encapsulation
#switchport trunk encapsulation dot1q
#switchport mode trunk
#switchport trunk allowed vlan 101-103
#spanning-tree portfast
For SF300 the port trunk it looks fine but for the port where the PC should receive an IP address
#interface fastethernet29
#switchport mode access
#switchport ccess vlan 103
Please let me know after this configuration
Thanks
Mehdi
Please rate or mark as answered to help other Cisco Customers -
Problem with VLAN Trunking within RHEL6.6 VM on Hyper-V 2012 R2?
Hello,
I'm wondering if there is a known issue with using a "trunk" mode interface within a RHEL6.6 VM? I found the following article:
https://technet.microsoft.com/en-us/library/dn531026.aspx
Where note 1 reads:
"For this specific RHEL/CentOS release, VLAN tagging may not work when used in conjunction with trunk mode".
I've been fighting with this for the better part of a day and can't figure out what I'm doing wrong. I have a RHEL 6.6 VM with two NICs. The first NIC is a standard access mode NIC - no problems there.
The second NIC has been set up as follows (via PowerShell):
$a=Get-VmNetworkAdapter -VMName "My VM"
Set-VMNetworkAdapterVlan -Trunk -VmNetworkAdapter $a[1] -AllowedVlanIdList 101-105 -NativeVlanId 1
Note that the physical switch and switchports are configured to send tagged packets for these VLANs as well.
I then set up a VLAN (eth1.102) based interface in the VM ... and never receive any traffic on it.
What I've observed is that:
A VM on the same physical host using the same virtual switch can communicate with the VM on the tagged VLAN
A pcap of the "eth1" interface (to which eth1.102 is bound) shows traffic for VLANs 101 through 105 arriving ... I just never see the traffic for VLAN 102 forwarded to the eth1.102 interface
An identical network configuration using Ubuntu 14.04.01 LTS works exactly as expected
It's this last point that has me wondering if the problem is with RHEL and not Hyper-V (or the physical/virtual switches involved).
I'm curious if anybody else has seen this behavior or, if RHEL 6.x is working for you, if you're using Intel or Broadcom NICs on the physical Hyper-V host?
Thanks,This is indeed a known issue with RHEL. There's a bug open with Red Hat on the issue, and our understanding is that they have a fix in progress that will be part of a RHEL 6.6 update. You might inquire with Red Hat regarding
their bugzilla #1135347.
Michael Kelley, Lead Program Manager, Open Source Technology Center
Maybe you are looking for
-
I have a new BB and the mail accounts i used to have in the old one doesnt work!!
Hello!!! 2 weeks ago someone stole my BB curve 8520. I reporte the robe to the mobile company and to the assurance. Since 4 days i have a new BB (curve 9300), with other company in other country. Im trying to vinculate my mail accounts (the ones i us
-
How do i move photos from imovie to iphoto
How do I move photos from imovie to iphoto?
-
How can I make my own design for a web page instead of using a template?
Need to ask the question again. I tried using the blank template, but could not get it to work. I could not insert images and copy where I wanted and in size I wanted.
-
Order levels in InventoryManager
Hi, wat are the different order levels in Inventory Manager in ATG Thanks in advance
-
Until recently, my available storage space was 86GB. While using the internet an hour ago, downloading apps (Seashore and Chocoflop, both lightweight), i noticed that the available storage space number was ticking down, slowly, by .00 GB at a time. I