Cisco Switches :: Voice VLAN Implementation On SGE2000P

Sep 17, 2011

I'm planning to separate voice and data traffic with two vlans.  I have a COR switch catalyst 3750, a UC560 for VOIP with SIP trunk and SGE2000P as access switches.  The thing is i had configured VLAN1 (data vlan) and VLAN8 (voice vlan), i've created the vlan 8 in the database on 3750 and let pass those vlans through a TRUNK port.  In the SGE2000P configuration i've created the VLAN8 and the the ports as trunk for letting pass the two vlans for the PC and the IP phone.  This works but some phones aren't registering, and for example i've unplugged a register phone and plug and doesn't registering anymore. 

View 0 Replies


ADVERTISEMENT

Cisco Switches :: Routing Vlan Traffic Out From SGE2000P

Nov 1, 2011

We have one SGE2000P switch that we are testing in Layer 3. We have a very simple configuration with some vlans that we want to route to our corporate network, but I want to test if there is actually traffic coming out from the up-link port first.
 
1- Created the vlans:
 VLAN1:     10.10.1.12 /16 (native)
VLAN10: 172.16.10.1 /24

[Code].....

View 1 Replies View Related

Cisco Switches :: How To Configure SGE2000P With 7900 Phones And Data VLAN

Feb 15, 2012

I am having problem setting up SGE2000P switches to work with my default data VLAN and additional voice VLAN. I am configuring it to pick IP address for phones from voice VLAN which is working fine but when I connect a PC on phone port it is also picking up an IP from Voice VLAN while default VLAN is data with different scope of IP.
 
I pack these switches and purchase ESW 500 series. I have ESW 500 at another client and they are working fine out of the box but this guy is giving me hard time.

View 1 Replies View Related

Cisco Switches :: SGE2000P Inter-VLAN Routing And Internet Gateway

Mar 25, 2013

Currently, we have a plain network and we are planning to 'upgrade' it a little. We want to implement VLANs to separate wireless clients, workstations + servers and infrastructure devices form each other.As of now, we have no VLANs, and no managed Switches. We only have an RV016 that handles two ISPs and a 3rd party connection service to the office branches ( I belive they're using Frame Relay, but as far as we know, we are not concerned since we cannot touch their devices)
 
The reason behind the title, pointing towards the famous SGE2000P, is that my workplace is located in Argentina... and we don't have as many choices as some of you guys have ! In fact, I was unsuccessful trying to get a Cisco partner to contact me. We would like to replace the RV016 with a cisco 1941 (and a HWIC switch card).
 
So, back to business..! Assuming we will be using the SGE2000P switches, I was thinking about setting VLANs using 802.1Q through seven of these switches, along with a 1941 Cisco router. I'm expecting the 1941 to handle load balancing between both ISPs and the 3rd party link. Now, as for Inter VLAN routing, I would like to have gigabit traffic between VLANs.

Is it possible to use one SGE as Layer 3 mode to hande inter VLAN traffic (gigabit speeds) while using the 1941 as a end point device to reach internet (using PAT) ?Would you suggest me to use the 1941 for Inter VLAN routing, despite the 10/100 limitation(*) and use all SGE's in L2 mode? We need two ISPs, a third link for the FR connection, and finally the LAN interface. As far as I know, I'm limited to the gigabit builtin interfaces for WAN purposes, am I right?

View 5 Replies View Related

Cisco Switches :: SF300-24P / Configure Vlan 10 For Data And Vlan 20 For Voice On The Same Port?

May 12, 2011

We are trying to config vlan 10 for data and vlan 20 for voice on the same port - port 1 of swtich SF300-24P to run both data and voice on different vlans.Do I have to add vlan 10 as an untagged vlan to port 1 and add vlan 20 as an tagged vlan to port 1?If I do not want to assign the native vlan 1 to port 1, how can I remove it ? The GUI page - assign VLAN to port does not allow to remove it.Aslo, what mode shall I set up on port 1? General, trunk or access ?

View 18 Replies View Related

Cisco Switching/Routing :: Sge2000p / Uc520 - All Data Traffic Passing OK But Voice Will Not Work

Aug 27, 2012

I have a sge2000p to install with a uc520. I have all data traffic passing ok but voice will not work. Phones to not get ip etc.

View 4 Replies View Related

Cisco Switches :: SG-300 Haven’t Set Up A VLAN For Voice From Scratch

Sep 13, 2011

We are about to install a new VoIP system (Allworx, which I did not select) and need to set up a new VLAN with QOS quickly for my SG 300 and SG 200 switches.  I have the default VLAN1  at 10.0.0.0/24 and will be setting up VLAN10 at 10.1.0.0/24 for voice. There are a few other VLANS on the switches as well.  I really don’t get the particulars of using a Voice VLAN vs. Smartport, but is one better than the other for this and what would be some good default settings to start with.  I have command line and VLAN experience; I just haven’t set up a VLAN for voice from scratch.

View 1 Replies View Related

Cisco Switches :: SG300 / 6941 Phone Not On Voice Vlan?

Jul 25, 2012

I am having a problem with 6941 phones on a SG300.When connected Smartport assignes the native and tagged voice vlan correctly, however the phone connects to the native vlan.  After running a few tests I have found it only happens when the voice vlan is also the default vlan, though this has only been tested with the default left as VL1.I can get to the phone on the native vlan, it picks up an address via dhcp, and the Operational VLAN ID is shown as 4095.Manually configuring the port as a trunk with the native and tagged voice vlans gives the same result.CDP properties for the ports show the voice vlan as correctly advertised.This happens on multiple phones/ports.The 7962 phones on the same switch work as expected.If I set the voice vlan to be something other than the default vlan 1, a vlan with dhcp available, the phone uses the configured, tagged vlan as expected and the Operational vlan shown on the phone is correct.The switch is running 1.2.7.76 I have a test setup with a number of 7900 and 6900 series phones running on a SF300 and have tested all phones as working if the voice vlan is not on the default.  I intend to test with the voice vlan as the default shortly to confirm it is not an issue with the specific switch and discover if it occurs on more than just the 6941.

View 1 Replies View Related

Cisco Switches :: SG300 - 6941 Phone Not On Voice Vlan

Dec 10, 2012

I am having a problem with 6941 phones on a SG300.
 
When connected Smartport assignes the native and tagged voice vlan correctly, however the phone connects to the native vlan.  After running a few tests I have found it only happens when the voice vlan is also the default vlan, though this has only been tested with the default left as VL1.
 
I can get to the phone on the native vlan, it picks up an address via dhcp, and the Operational VLAN ID is shown as 4095.Manually configuring the port as a trunk with the native and tagged voice vlans gives the same result.
 
CDP properties for the ports show the voice vlan as correctly advertised.This happens on multiple phones/ports.The 7962 phones on the same switch work as expected.
 
If I set the voice vlan to be something other than the default vlan 1, a vlan with dhcp available, the phone uses the configured, tagged vlan as expected and the Operational vlan shown on the phone is correct.
 
The switch is running 1.2.7.76 I have a test setup with a number of 7900 and 6900 series phones running on a SF300 and have tested all phones as working if the voice vlan is not on the default.  I intend to test with the voice vlan as the default shortly to confirm it is not an issue with the specific switch and discover if it occurs on more than just the 6941.

View 1 Replies View Related

Cisco Switches :: 200 Learn Voice VLAN And CoS / DSCP From Catalyst 2960?

Oct 31, 2012

How can I configure Cisco 200 (SG200-08P) to learn Voice VLAN and CoS/DSCP from upstreamCatalyst 2960?
 
The Cat 2960 is today used together with LLDP-MED to announce config to Aastra IP Telephones. In some cases I need to use a small switch inbetween and plan to use the Cisco SG200-08P for this. However, I would like to avoid manual config of the Cisco 200 switch.

View 3 Replies View Related

Cisco Switches :: SG300-10 Auto-Voice VLAN Not Working Properly

Nov 7, 2011

At our office we use seven Cisco 300 Series Small Business Switches. One main switch in the server room and one in each room. They work great! But I’m having difficulties getting the Auto Voice VLAN to work correctly. In fact, it seems to works straight away on a PoE model, but not on the non-PoE models.

Switch (main server room):
Cisco SG 300-28 (PID:SRW2024-K9)-VSD 
Switches (one in each room):
Cisco SG 300-10 (PID:SRW2008-K9)-VSDCisco SG 300-10 (PID:SRW2008-K9)-VSDCisco SG 300-10 (PID:SRW2008-K9)-VSDCisco SG 300-10 (PID:SRW2008-K9)-VSDCisco SG 300-10 (PID:SRW2008-K9)-VSDCisco SG 300-10P (PID:SRW2008P-K9)-VSD 

All these switches use firmware v1.1.1.8. The switches in each room are connected to the central switch by Link Aggregation. The main switch is configured in Layer 3 mode and all the others in Layer 2 mode. We have a lot of VLAN’s configured. For this problem allow me to describe only the two that are relevant.
 
VLAN 102 - Internal Network (Clients)VLAN 104 - Internal Network (Voice) The switches on each room are mainly used for clients, printers and IP phones. The clients and printers should operate in VLAN 102. The IP phones should operate in VLAN 104. For this to work I have the 10 port switches configured as following.
 
GE1 – Trunk – 102U;104TGE2 – Trunk – 102U;104TGE3 – Trunk – 102U;104TGE4 – Trunk – 102U;104TGE5 – Trunk – 102U;104TGE6 – Trunk – 102U;104TGE7 – Trunk – 102U;104TGE8 – Trunk – 102U;104TGE9 – Trunk – 1P (LAG 1, with 1U;102T;104T)GE10 – Trunk – 1P (LAG 1, with 1U;102T;104T) 
The network is fully routable. A DHCP Server is available. Each VLAN uses DHCP relaying. If we statically assign a VLAN to a port, that just works fine. Auto Voice VLAN is enabled with VLAN ID 104. All switches are configured the same. But this is what occurs…
 
When I connect an IP phone on the SG300-10P the IP phones are assigned to the Voice VLAN ID 104. If I would connect a desktop to that same port it is assigned to VLAN ID 102. Exactly as it should.But when I connect an IP phone on a SG300-10 the IP it is assigned to VLAN ID 102. But I also noticed that in some cases they are assigned to VLAN ID 1 and don’t get an IP Address. That depends in which order I change settings. The port its VLAN membership is then even changed to 1P. Although the port is recognized as an “IP Phone” by the smartport feature. I have noticed it does make difference if I modify the smartport macro and change the native_vlan paramater from "1" to "let's" say "102". That seems to affect it. Of course it may be just coincidence. What am I doing wrong? How should it work?How should you actually configure each port on a switch? (trunk?, Tagged/Untagged VLAN?)If you do not use Telephony OUI. Do you still need to configure the macros on the smartport defenitions?
 
I have tried about everything. I have also tried Telephony OUI, but it doesn't make any difference. I just can't get it to work properly on the non-PoE switch.

View 6 Replies View Related

Cisco :: Switchport Voice Vlan Command Not Putting Port In VLAN?

Feb 2, 2011

I have set up 2 DHCP pools and 2 VLANs (1 *the native* for data / 1 VLAN for voice). When I use the command "switchport voice vlan 20" the port disapear from the show vlan brief list. When I use the "switchport access vlan 20" it shows up in the show vlan brief in the correct VLAN and gives the phone an IP. I assume that using the access instead of the voice is wrong and the phones would not configure correctly. But when I use the access the phone goes to the next step and tells me the TFTP files are not found. Why does the port disapear from the VLAN list?

View 8 Replies View Related

Cisco :: VLAN Implementation To Live And Running Network?

Mar 27, 2012

Just wanted to get a few answers in regards to VLAN implementation (thinking about doing this for a large network)...VLAN's always sound good on paper, but how hard/easy are they to implement to a live and running network?

1.) Have successfully implemented VLAN's into a production environment (e.g. placed servers, production, printers, etc. on separate VLAN's)?

2.) How much of a pain is it to do this? If you are on a 192.168.1.x subnet, do you have to re-IP all of your printers, switches, etc. This sounds like a lot of work – especially since re-IP’ing domain controllers is a royal pain.

3.) Have you seen much of a performance increase when implementing VLAN’s (i.e. chatty protocols and broadcasts?)

View 6 Replies View Related

Cisco Switches :: SGE2000p QoS For VoIP?

Dec 27, 2012

I am trying to get QoS for my VoIP system setup on several SGE2000p switches and have got a question...How do I define the ACL for RTP? As far as I can tell it will not let me enter a UDP port range for the RTP traffic... And I cant imagine creating rules for each port would be very effective either. So, how can I define an ACL to cover the RTP traffic so I can classify it?

View 4 Replies View Related

Cisco Switches :: SGE2000P - Layer 3 Setup?

May 29, 2012

We have a potential new customer who is wanting to deploy a guest WLAN. I am happy doing this via a VLAN on the WAP4410N series AP’s. I would then create the relevant VLAN’s on the switch. Can each VLAN be assigned an IP address and allowing me to be able to add a static route on the router pointing the traffic for the Guest VLAN back to the switch? 

View 1 Replies View Related

Cisco Switches :: SGE2010P And SGE2000P LAG Configuration

Sep 19, 2011

I've got multiple SGE2000P & SGE2010P switches
 
Originally I was happy just set them all up in a stacked ring configuration. However I've become aware that my back bone fibre links are contantly pushed to their max.
 
So I've decided that I should change this configuration and unstack the switches and make them all stand-alone units. and I'll configure 2 cable LAG links between all my switches Theorically I should now get 2GIGs between each switch and to complete the ring in my network for redundancy I'll turn on Spanning tree.
 
However I've tested the speed and I just can not seem to get a LAG connection with 2 x 1gig cables to push more data than a single link 1gig link cable would.
 
My test enviroment(not using fibre optic cables just cat5e copper cabling):
4 x pc's(all gigabit network cards)
2 x sge2000p switches
PC1 ---(1G eth)---                                                                        /---(1G eth)--- PC2
[SGE2000P]===(LAG1 2x1G cables)===[SGE2000P]
PC3 ---(1G eth)---/                                                                        ---(1G eth)--- PC4
 
If I send files from PC1 & PC3 simultaneously to PC2 & PC4 They don't transfer faster than if I I just use a single 1GIG Link cable
 
looking at the LAG configuration it shows both cables are connected & the LAG looks like it's working. But it really doesn't seem to be running at the expected 2GIG?
 
The LAG fail over seems to work fine if I remove either of the 2 cables from the LAG the link continues to work. (sometimes it will drop a ping when removing or readding a LAG cable)

View 3 Replies View Related

Cisco Switches :: SGE2000P Stack Password Recovery?

Mar 22, 2013

Im trying to recover the password from my stacked switchs(doing procedure on master switch),im following a guide i have read in this forum("SRW248G4 V1.1 unable to reset password"), at console terminal have chosen "password Recovery" it prompts the "current password will be ignored" and then i hit "Escape" the switch start loading de configuration, at this point i attempt to login from telnet or http but the login fails.
Here is the password/username combo im using (admin/blank ; admin/admin). Is it possible to restore admin password or should i just hardware reset the switchs?

View 3 Replies View Related

Cisco Switches :: SGE2000P Stack Interface Utilization Percentage?

Aug 3, 2011

I'm using a stack of four SGE2000P switches for a PoE video camera system.  I've got the cameras in a VLAN and everything's working fine. 
 
I'm wondering, though, is there a way to find out what data rate the stack interfaces are working at (since it's going over cable infrastructure we put in ourselves), and also what percentage of that bandwidth is being used?  I don't see anyway to get to those interfaces from the main page, and I wasn't able to find a way to do any sort of percentage thing even on a regular interface.

View 2 Replies View Related

Cisco Switches :: Single Mode Fiber Link Between SGE2000P And Catalyst 2960?

Jun 4, 2013

I'm working with a customer who has an SGE2000P and a Catalyst 2960 to setup and configure a single mode fiber link.  The SGE2000P has an MFELX1 fiber GBIC and the 2960 has a GLC-LH-SMD GBIC.  When I have the customer plug in his fiber, there is a power light that comes on on the MFELX1 GBIC. Neither GBICs/switches show that a link or activity is occurring, but the presence of that light makes me think that they are connecting somehow. Are these two switches/GBICs compatible?

View 1 Replies View Related

Routers / Switches :: IPV6 Implementation In IPV4 Network

Jul 1, 2012

our company backbone is hp 5406, and desktop switches are hp 2510 currently we are working with ipv4.if we want to start use IPV6 for test environment, what’s things we need to enable in our backbone/regular switches.i mean for example if we want to set static IPV6 address for 2 servers and send ping between them, or even make new vlan with IVP6 subnet, and use it like regular vlan but with static ip's(until we got ipv6 dhcp).i have hp 5406 manual for IPV6 but i can't understand what i really need to do for start using IPV6.

View 5 Replies View Related

Cisco :: 3550 Catalyst Not Displaying Fa Ports In Voice VLAN?

Sep 13, 2011

Why aren't the fa ports that i assign to a voice vlan showing up when i issue show vlan?

View 2 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.2 Failed Authenticate With Same Voice And Data Vlan

Apr 14, 2011

I have a question its posible to authenticate an cisco phone and PC with the same vlan(voice and data)when i do this configuratión , the phone and pc dont work. The phone display registering and never finished.interface FastEthernet0/5 switchport mode access switchport voice vlan 1 authentication event fail action authorize vlan 11 authentication event no-response action authorize vlan 11 authentication host-mode multi-domain authentication port-control auto authentication periodic authentication violation protect mab dot1x pae authenticator dot1x timeout tx-period 10 dot1x max-reauth-req 3 spanning-tree portfastend.

View 1 Replies View Related

Cisco AAA/Identity/Nac :: WS-C4510R Critical Voice Vlan Support

Dec 15, 2011

Critical voice vlan feature, used to place a newly authenticating phone when radius server is dead into appropriate voice vlan, seems to be a new feature and I find the documentation to be incomplete.  Do the following switches support this feature in any IoS versions? WS-C4510R, 4506, 3560, 3550,2960s.

View 1 Replies View Related

Cisco Switching/Routing :: Voice Vlan In 3524 Switch With IOS 12.0(5)XU?

Dec 4, 2011

I'm using CISCO 3524 switch as access switch and trying to enable voice vlan in fast eth ports as below.
 
L3 vlans are created in core switches which is cisco 6509
vlan 1 - data vlan
vlan 2 - voice vlan
 in cisco 3524

[code]....
 
if i use the above configs, the phone which is connected to interface fa0/1 is not taking ip from dhcp server. even it didn't work with static configs.while troubelshooting, i have configured as below and it's started working..
 
int fa0/1
switchport acces vlan 2
speed 100
duplex full.
 
in this case i can't use this port for data connectivity where as it's required for data too.

View 2 Replies View Related

Cisco Switching/Routing :: IP Phone 6921 Voice Vlan?

Apr 9, 2012

I have CME on Router 2800 series, and switch 2960 PoE connected to this router.On 2960 switch, there is existing 7945 IP Phone that already work properly and get IP 14.x.x.x from voice vlan 2.
 
Problem is when I add cisco 6921 IP Phone connect to 2960 switch, it get data vlan 10.x.x.x, not voice Vlan 14.x.x.x I have check CDP and it use CDP v2
 
Config on 2960:
 
interface GigabitEthernet1/0/34  <--- this is connected to IP Phone 7945
switchport mode access
switchport voice vlan 2
spanning-tree portfast

[code]....
 
With same config and condition on port 2960, why the IP Phone 6921 can't get voice vlan 14.x.x.x, whereas IP Phone 7945 can get voice vlan 14.x.x.x

View 2 Replies View Related

Cisco Switching/Routing :: 3524xL - Switchport Voice VLan

Nov 10, 2012

I have encountered a different issue. When I configure " switchport voice vlan 2" under f0/2 connected to ip phone, it does not have any effect.
 
Below is my set up:
Sw  is cisco cat 3524 XL.
 
ip phone-------f0/2( vlan1)-----SW----f0/1---trunk------f0/0-CME-router+dhcp
                                                          |
                                                       f0/3( vlan2)
                                                       tftp server ( 201.201.201.3)
 
switch has two vlans:
 
vlan1 (data)   200.200.200.0/24
vlan 2 (voice)  201.201.201.0/24
 
Switch management int vlan 1 : 200.200.200.3
 
router
f0/0.1  200.200.200.1
f0/0.2  201.201.201.1
 
The trunk is working correctly. (code)

View 7 Replies View Related

Cisco Switching/Routing :: EX90 Voice And DATA VLAN On A Switch

Jun 4, 2013

If we configure a Voice and Data VLAn on a switch. And connect EX90 on voice VLAN and PCwith EX90 terminals. Than can we able to share a presentation or data with EX90 or not?

View 3 Replies View Related

Cisco Switching/Routing :: 2950 DTMF Not Working On Voice Vlan

Nov 9, 2011

i am facing a strange issue on cisco 2950 .IOS (tm) C2950 Software (C2950-I6K2L2Q4-M), Version 12.1(22)EA9, RELEASE SOFTWARE (fc1) suddenly my phone stopped working for DTMF tone, i mean when i  dial a conference bridge lets say 6565 and then it ask for conference  bridge code lets say 12345, it doesnt recognize the code and says code  is invalid, SIP Proxy is Asterisk in this case.Currently my cisco switch port is configured for dual data + voice vlan, where DTMF dont work, sample config below [code]

View 2 Replies View Related

Cisco Switching/Routing :: HP 1810 / SG 300-28P - Voice And Data All Reside On Same VLan

May 16, 2013

im working in a new enviroment and want to makes some design changes to the environment. I wanted to bounce my ideas some of you folks to see if my thinking is on the right path or maybe i could do things better.
 
Setup:
 
Currently the setup that i manage includes and Sonic Wall (also dishes out dhcp), HP 1810 "Core Switch" and 3 SG 300-28P cisco managed switches. (all cisco switches tie back into the HP) The router is managed by the isp. There is only one vlan with all traffic going across it.
 
Obviously the glaring issue here is that voice and data all reside on the same vlan. Correct me if i am thinking incorrectly but the first step would be to create a separate vlan for the phones with its own IP scheme. currently phones are issued addresses from the 150-200 range and everything else is left for pc's, printers etc. To my knowledge the HP switch does layer 3 but i do not know much about it. There are vpn tunnels to remote offices that are used for sharepoint, email and to access other services. Trying to wrap my mind around the environment as a whole so i may be missing something obvious i could do design wise to improve.

View 2 Replies View Related

Cisco Switching/Routing :: 3560 Port Security And Voice Vlan On Newer IOS

May 20, 2010

For many years we've had the following vlan and port security config on our 3560s: [code] This has worked great on 12.2(37)SE1, 12.2(40)SE and 12.2(46)SE. However since 12.2(50)SE, and I've tried all the versions since then, we have a problem with 7900 phones and ATA186s taking upwards of 20 minutes before they can get a valid IP number.The problem on the newer IOSes seems to be related to the inactivity aging.On the older IOS versions the mac address of the voice device appears on the voice vlan straight away.
 
On the newer IOS versions the mac address of the voice device appears on the DATA vlan and seems to be stuck there until the inactivity aging removes it. It then gets re-learned, sometimes on the voice vlan, and sometimes on the data vlan. If you're unlucky and it gets re-learned on the data vlan you've got to wait until the inactivity time ages the address out again. Repeat until the mac address eventually gets learned on the voice vlan. I don't want to be stuck on 12.2(46)SE forever.

View 11 Replies View Related

Cisco Routers :: SRP547W IP Phone Access To Line Number Via Wi-Fi Voice Vlan?

Mar 19, 2013

The SRP547W supports creating both Wifi Voice and Data vlans.Can I configure a Wifi IP Phone to connect to the SRP547W Voice Wifi Vlan and have the SRP associate it with Line 1 (in lieu of a standard phone connected to the Line 1 FXO port - without additional hardware)?

View 1 Replies View Related

Cisco Switching/Routing :: Catalyst 4505 - Write Extended ACL For Voice VLan

May 14, 2012

I am trying to write an extended ACL for the voice vlan.My scenario is the following:I have two PBXs with two Catalyst 4505 L3 switches.The C4505 are connected trough a trunk link.I have a VTP domain configured.

Voice VLANs are Vlan 100 and Vlan 101 with networks 10.2.0.0/16 and 10.4.0.0/16 Voip telephones are communicating between them self and everything is working fine.I want to secure both voice VLANs with an ACL to allow only couple of IPs to administer the phones.The PCs are connected trough a integrated switch via VOIP telephone.Here is the sample configuration of the dhcp pool for the PC VLAN:

ip dhcp pool PCs
   network 10.1.0.0 255.255.0.0
   default-router 10.1.1.1
   dns-server 10.10.10.1
   option 43 hex 010a.5369.656d.656e.7300.0000.0204.0000.0064.0000.0000.00ff

I had to implement the 43 hex option because the PCs did not get the ip from the DHCP because of the vendor specific information.The thing that worries me is will the DHCP forward the ACKs for the PCs if I implement this test ACL:

ip access-list extended VLAN100
permit ip 10.2.0.0 0.0.255.255 10.4.0.0 0.0.255.255
permit ip 10.4.0.0 0.0.255.255 10.2.0.0 0.0.255.255
permit ip 192.168.2.0 0.0.0.255 10.2.0.0 0.0.255.255
permit ip 192.168.2.0 0.0.0.255 10.4.0.0 0.0.255.255
permit udp host 0.0.0.0 eq bootpc host 255.255.255.255 eq bootps  (this I am not sure do I need)
permit udp host 255.255.255.255 eq bootps host 0.0.0.0 eq bootpc   (also this)
deny   ip any any
 
I only want to allow the network 192.168.2.0/24 and maybe some other hosts to access the web based http gui to adiminister the IP phones.All PCs are connected trough the VOIP terminals. I do not want to deny the traffic to PCs.

View 8 Replies View Related

Cisco Firewall :: 5515x Apply On Firewall / Switches To Make Implementation Successful

Apr 22, 2013

I will be implementing a new firewall (cisco asa 5515x) on my existing  3750x (server switches) and my 2960s (user switches). What should I need to apply on my firewall and swtiches to make the  implementation successfull.  I will put my 3750x as my DMZ and my 2960s  as my inside.  The 3750x have multiple subnet and also the 2960s.which  features and technologies i need to know on those 3 products.  my 3750x  and 2960s don't have any ACL defined and most common features are vlan,  switchport, trunking, spanning-tree, stacking, vtp.how  my asa knows that my 3750x/2960s have multiple vlans.  my current  connection right now on 3750x and 2960s is just through 6 ports i  assigned as one trunk, below is my config [code]

my  2960s vlans are almost the same with my 3750x except vlan 160, 170,  192.  but of course when i put this in asa, i have to segragate vlan for  3750x (192, 100, 110,160, 170) and 2960s (130, 150).  for my 2960s  connection to the asa and since this will have big bandwidth, i will use  3 ports on my asa (and trunk it) connecting to my 2960s and i will use 2  ports on my asa (and trunk it) connecting to my 3750x.  the one  internet ports and my one management ports on my asa will stay like  that.

View 2 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved