Cisco Switching/Routing :: 3750x And Private VLANs

Sep 5, 2012

Is this supported on a 3750X ?? A router has two VRFs and its lan interface is a trunk with 2 VLAN IDs, let say VLAN 10 and VLAN 20. The ip address subnet of these two vlans is the same (therefore , they are in different VRFs)

fa0/1
VLAN 10 = 10.15.4.9 (VRF A)
VLAN 20 = 10.15.4.10 (VRF B)
 
This router is connected on a 3750X switch. There is a firewall connected to this switch also, which is default gateway for several VLANs including VLAN 10 (10.15.4.1)

The goal is that VRF B ip can talk to 10.15.4.1 and VRF A can talk to 10.15.4.1 but VRF B can't talk to VRF A (10.15.4.9 <-> 10.15.4.10)
 
FW |--- TRUNK VLANs 1,2,3,4,10 ---------| SWITCH |----- TRUNK VLAN 10,20 -----| ROUTER (vlan 10 = VRF A, vlan 20 = VRF B)
 
I think this is not supported on the C3750, as my promiscuous port is located on a trunk.

View 1 Replies


ADVERTISEMENT

Cisco Switching/Routing :: Nexus 1000v Don't Use Private VLANs

Aug 28, 2012

We have a requirement for private VLANS for DMZ hosting within one of our datacentres. I just want to query how private VLANs would work in our environment.We have physical servers connected to fex ports (2 fex per rack for each 5k) of a 5548UP switch, virtual servers using the nexus 1000v (vmware hosts connected to fex ports) Out firewalls and load balancers are connected to an upstream pair of nexus 7ks using vPCs.My question is this, ordinarily the firewall would be in a promiscuous port but as these reside on a physically separate switch will the normal vPC trunk still be sufficient or would the "switchport mode private-vlan trunk promiscuous" be required on the vPC up to the northbound 7k.As these connections are already in production I do not want to affect the existing traffic that doesn’t use private VLANs.

View 3 Replies View Related

Cisco Switching/Routing :: Nexus 5548 - Private VLANs On FEX

Aug 13, 2012

regarding PVLANs and the Nexus, my understanding is that we cannot configure Private VLANs on a FEX trunk port with a NX-OS release older than 5.1(3)N2(1) for the Nexus5548... Is there any known workaround for this limitation (appart from performing a SW upgrade)?

View 2 Replies View Related

Cisco Switching/Routing :: Private Vlans Across 2960 / 2950 Switches?

Nov 12, 2012

I am aware that private-vlans are not supported on edge switches like 2960 series - so my question is would it be possibel to ceate private vlans on say just the core switch which would be a 3570 or 4506 that supports private vlans and then just trunk these to the edge like normal vlans?what I need to achive is to have edge port not able to communicate to each other even across switches - which cannot be done using 'protected' port so need the private vlan feature?

View 1 Replies View Related

Cisco Switching/Routing :: CBS30X0 - Private VLANs Interaction With Firewall

Nov 29, 2011

We currently have a HP blade platform which has two Cisco CBS30X0 switches built into it running Version 12.2(55)SE. These are connected to two Cisco C2960 aggregation switches running Version 12.2(44)SE6. According to this article I need to upgrade these to 12.2(25)FX: url...
 
1.)This will according to that article only allow me to create edge ports on them, is this a hardware limitation or am I just not finding what firmware I need to upgrade them to, in order to allow the creation of community VLANs? We have these aggregation switches conncted directly to multiple types of firewalls which take care of each of our clients networks including internet access etc. We are wasting many VLANs and IP addresses with our current setup so I am hoping to move over to using private VLANs. The setup of the private VLANs looks simple enough.
 
2.)When the private VLAN's try to communicate, all info will be sent directly to the layer 3 device I gather, which will not need to know anything about the private VLANs?

View 12 Replies View Related

Cisco Switching/Routing :: 2960 - Private Vlans Across Multiple Switches

Nov 11, 2012

I am aware that private-vlans are not supported on edge switches like 2960 series - so my question is would it be possibel to ceate private vlans on say just the core switch which would be a 3570 or 4506 that supports private vlans and then just trunk these to the edge like normal vlans?
 
what I need to achive is to have edge port not able to communicate to each other even across switches - which cannot be done using 'protected' port so need the private vlan feature

View 7 Replies View Related

Cisco Switching/Routing :: Does WS-C3750-48TS-S Supports Private Vlans And IPV6

Nov 3, 2012

Need to confirm if  WS-C3750-48TS-S supports Private vlans and IPV6?
 
Also need to know which stack cable like part number i can use for stacking them .

View 3 Replies View Related

Cisco Switching/Routing :: ASA And 3750x Switches - How To Get VLans Working

Jan 25, 2012

How to get vlans working properly between sub-interfaces on a ASA and a trunk port on a switch.There seems to be issue with the VLAN's being assigned to the correct VLAN and this information being properly sent to the ASA over the trunk.
 
We seem to be unable to ping most of the interfaces except for one on the switch. Sometimes if we are lucky we are able to ping a host on a different vlan that is on the switch. This seems sparadic at best.
 
Logs on the ASA show traffic does not seem to be assigned properly to the correct sub interface. We have access rules on the ASA disallowing traffic not part of the same vlan. For example you will see networkA blocked on networkB when it really should be directed through networkA's sub interface.
 
Any example commands for the ASA and Switch for at least the basic requirements to enable all the VLAN's to communicate properly with the ASA?

View 5 Replies View Related

Cisco Switching/Routing :: Route Internal VLANs On 3750X?

Apr 28, 2012

How can i route internal VLANs on a 3750X , my current network its small ( about 8 -10 subnets) so i dont wnat to add overhead using maybe dynamic protocol , My scenario is my stack of 3750X ( 2 switches)  will be my CORE SW, i will have 2 stack more (2960S - 4 switches ) and it will connect to the 3750X with a trunk port etherchannel each link connected to a different switch, ( i was planning to use a L3 routing in the 3750X but not sure how it will works )
 
My core SW 3750X it will be connect with a firewall for aVPN , by a Layer 3 interface (using a static or dynamic protocol)

View 2 Replies View Related

Cisco Switching/Routing :: 3750x - Denying VLAN Access To Other VLANs

Mar 18, 2013

I've got a 3750x stack set up as my core switch (only a small-ish environment) - I'm shortly going to be deploying an enterprise wireless network with Corporate and Guest SSID's. I'm going to be putting all traffic from the Guest SSID in VLAN 244, and don't want it to have access to any of the other VLANs (1 (Legacy Eqpt), 4, 8, 12, 16, 20, 24, 28, 32, 248 & 252).
 
IP ranges for all the main VLANs are:
 
1: 10.0.0.x/22
4: 10.0.4.x/22
8: 10.0.8.x/22
12: 10.0.12.x/22
16: 10.0.16.x/22 etc etc (you get the pattern)
 
I'll probably give Guest traffic (VLAN 248) the IP range 192.168.10.x/22 (not because I NEED that many addresses, but it's easier for everyone to remember/understand if I keep the subnet masks the same all round). However I also have a CCTV VLAN (252) which already has the range 192.168.0.x/24, which some people in other VLANs WILL need access to.
 
So my question is: What is the syntax for the ACL on my 3750x (IP base - 15.0.2) to prevent traffic from VLAN 244 gaining access to any of my other VLANs. I'm making a broad assumption here that a layer 3 switch is perfectly capable of supporting that function? I need ALL the syntax for setting up ACL's - I've never done it before
 
My gateway device by the way is 10.0.4.1, and I do have inter-VLAN routing set up on the core switch (obviously).

View 3 Replies View Related

Cisco Switching/Routing :: Routing Between Vlans On 3750x

Jan 24, 2013

I am setting up a vm environment for a customer in my lab off site. I have two stacked 3750-x switches, a san, and threes UCS c220 M3S servers for hosts. I am trying to separate the lan traffic, san iscsi traffic, and san management traffic using vlans. The problem is i'm unable to communicate cross vlan with my current config, which I have attached to this post. The only noteworthy things in my conifg is that the ip route 0.0.0.0 0.0.0.0 192.168.83.6 is referring to a switch stack they have on site, that I will connect this stack to using the first two trunk ports on each switch, that I do not have here in the lab. I don't want to cause any confusion in why I have things set a certain way.

View 1 Replies View Related

Cisco Routers :: RV110w - To Setup Two Vlans On Private IP

Jun 2, 2013

I'm looking to update our office network and replace our old wireless box.I've been looking at the RV110w after a google search and need to find out some things before suggesting anything.
 
Currently our network is running a public IP address for each piece of equipment which we'd like to keep, mainly for ease.  We have a wireless access point running in invisible mode for wireless client access to the entire network, and also a Netscreen firewall.
 
What I'd like to do is the following:
 1.  Keep public ip addresses for wired clients, complete with existing network/local server access/RDP.
2.  Set up two VLans on private ip addresses - one to have full access as per the wired clients and the other only for guest Internet access.
 
Is this something the RV110w is able to do?  If so how would I go about setting it up?

View 3 Replies View Related

Cisco Switches :: Setting Up Public / Private Vlans On Sg300-52?

Mar 25, 2013

How to setup 3 SG300-52 (in L2 mode) as per this diagram:Port 1 on all switches should be able to talk to each other and access the blob at the right.The ports 25 on the other hand should only be able to talk among themselves in their own private vlan. They are to carry sensitive traffic. So I created 3 vlans, vlan 78 for ports gi1, gi51 and vlan 10 for port25,49,50 and a dummy vlan: 666 with the intent of segratating vlan 10 from vlan 78. My attempts so far have failed. ports gi49-50 are configured as trunk ports and gi1,gi51 as access ports as the following cli output (excerpts of the startup config):
 
vlan database
vlan 10,78,666
exit
interface vlan 1
ip address 172.16.10.11 255.255.255.0

[code]....

Ports gi1 can talk to each other and access the blob but ports 25 refuse to talk to each other. But as soon as I remove the access links to the blob they can! Obviously, at that point port gi1 lose access.Is such a topology feasable or even advisable?

View 7 Replies View Related

Cisco Routers :: RVS4000 Private Networking Setting Up VLANs?

Jan 23, 2013

I live in a two family residential house and we share a common fibre connection to the internet. In the basement we have a modem/router(zyxel) which is in "bridge mode".  Therefore not acting as DHCP. Behind this zyxel we have a Cisco RVS4000 router. Ports 1 and 2 go to family A, and Ports 3 and 4 go to family B. Family A and B have separate routers which are both set to "access point mode". Family A has an ASUS RT-N66U router while family B has a dlink DIR-615. The asus has an "access point mode" while the dlink needs to be set up manually to achieve this. The dlink must also have a static IP adress. The asus can receive ip adress.
 
What I have unsuccessfully tried to achieve and am currently trying to separate the networks so that both families can access internett, but at the same time it must be impossible to access VLAN1(Family A) from VLAN2(Family B) vice versa. Meaning no communication between the two families through the local network.
 
I have tried different options but I am not sure how to deal with trunk, tagged, untagged etc. etc. etc. It seems every time I manage to create two different networks there is still accessability/communication between the two VLANs and everytime I manage to give out different IP adresses to different ports i.e. 192.168.10.xx and 192.168.2.xx it is still possible to communicate. What also usually happens is that the internetconnection is severed at the same time.

View 15 Replies View Related

Cisco Firewall :: Using VLANs With ASA5505 For Private And Public Internet Access

Oct 2, 2012

I am trying to provide internet access to public and private SSID's on Cisco AP541n using VLAN's connected directly to ASA5505.  VLAN1 is inside interface (private) and VLAN12 is wlan interface (public SSID). The AP541n is plugged into switch port 0/7 on an ASA 5505.Port 0/7 is configured as trunk mode.  I have internet access when connected to private SSID but no internet access when connected to public SSID. why I can't access internet on public SSID? 
 
logging class ip history emergencies
mtu inside 1500
mtu outside 1500

[Code].....

View 5 Replies View Related

Cisco WAN :: 887Va To Support Both Public And Private Addresses On Inside Vlans

Nov 27, 2012

On an 887VA running 15.x IOS, is there a way to support both public and private addresses on inside vlans? The outside interface is public static ip, so the requirement would be to not nat anything if coming from inside vlan10 but nat if coming from inside vlan20.I didn't think this was possible since the outside interface would have to use an outside nat command that would not be ignored for traffic coming from vlan10.

View 4 Replies View Related

Cisco Switching/Routing :: 3750 Private VLAN With Routing

Jan 1, 2012

I have a Cisco 3750 with private VLANS configured.. VLAN 2 is the "primary", VLAN 3 is "isolated" and VLAN 4 is "community".  This is all working correctly, however I now have the need to another VLAN called "production". I need the production VLAN to be able to reach all the private VLAN hosts (community and Isolated), and vice versa

View 2 Replies View Related

Cisco Switching/Routing :: N7K Private VLAN With F2

Jan 15, 2013

Why I got below error message when config Private VLAN?
 
Error: while enabling/disabling service: private-vlan, err: Private-vlan is not allowed in F2 VDC (0x40e4005d)

View 2 Replies View Related

Cisco Switching/Routing :: ME 4900 Private VLAN Config

Feb 9, 2012

We need to connect several DSLAMs on the 4900 switch, every DSLAM has 4 VLANs configured (VOIP service, MGMT, ADSL Private, ADSL Public), and sends the traffic for each service tagged with appropriate VLAN id according to the table:
 
VOIP: 608
MGMT: 594
ADSL PRIVATE: 2900
ADSL PUBLIC: 2930
 
On the DSLAM side it is very simple configuration, just a normal trunk with 4 VLANs transversing the link. On the 4900 I need to isolate the traffic for ADSL PRIVATE & PUBLIC service so DSLAMs connected to the same switch do not have L2 connectivity between them. For VOIP and MGMT they must communicate with each other. DSLAM acts also as a VOIP GW so it must communicate with other DSLAMs for VOIP service. Also VLAN 200 is configured on ME 4900 for switch management traffic.
 
This 4900 Switch connects to MPLS PE router, which offers L3 VPN service for VOIP & MGMT service, and L2 VPN for ADSL service (PPPoE traffic to BRAS). Fortunately we have ES+ linecard to support many ethernet features. I tried this config:
 
1) VOIP, DSLAM-MGMT, MPLS-MGMT configured as normal VLANs
2) ADSL PUBLIC & PRIVATE configured as isolated secondary VLANs, primary VLAN for ADSL PRIVATE is 2008, for PUBLIC 2308
3) Configure DSLAM facing ports on ME 4900 as private-vlan trunks
4) Configure ME 4900 uplink port to MPLS PE as a private-vlan promiscous trunk
5) Configure ethernet services on MPLS PE for each tag that comes from ME 4900 (ES+ cards are awesome, i love them:D )
6) Apply L3 VPN service for VOIP and DSLAM-MGMT, and L2 VPN for ADSL service.

But at least this last command should list on spanning tree forwarding state also the ADSL VLANs or not?
 
Here is the output of the show interface switchport.

View 1 Replies View Related

Cisco Switching/Routing :: 2960 / How To Configure Private Vlan

Mar 13, 2013

I have 2960 cisco switch. I want to configure private vlan. But it is not getting configured in cisco 2960. Is there any other way to configure that in switch.

View 1 Replies View Related

Cisco Switching/Routing :: Private VLAN's On Nexus 2148

Dec 29, 2011

I have the need for private vlans in isolated mode to backup some hosts on a secured network. We are using Cisco Nexus 5020 with the fex 2148 for copper-ports  - and I tried to implement this setup: [code]

The Cisco Nexus 2000 Fabric Extender does not support PVLANs over VLAN trunks used to connect to another switch. The PVLAN trunks are only used on inter-switch links but the FEX ports are only meant to connect to servers. Since it is not a valid configuration to have an isolated secondary VLAN as part of a Fabric Extender port configured as a VLAN trunk, all frames on isolated secondary VLANs are pruned from going out to a FEX.
 
the "only" limitation should be the trunk option - but as far as I can see from the output from my nexus this is not correct .We are running NXOS: [code]

View 1 Replies View Related

Cisco Switching/Routing :: 4900m - Private VLan And VTP Version 3?

Dec 10, 2012

know if Private Vlans are supported on the Cisco 4900m switch when set in VTP version 3 and VTP disabled?Most documents just specify VTY transparent mode without mentioning the version, trying not to assume since this is production.

View 1 Replies View Related

Cisco Switching/Routing :: Access Layer Switching With 2960 / 3560x / 3750x And 4506

Jan 17, 2013

My management has tasked me to give them a high level overview of the different switching we can choose for our new building.
 
This is what I know so far.4 Closets, each closet has 450 ports,One MDF room that is will contain one UCS Chassis and a Nimble iSCSI SAN.
 
I am working on the spreadsheet and it looks like this (Not totally filled):

2960s3560x3750x45064510Approx cost (Each, 48PORT, POE+, 10G uplink, Dual PS, IP BASE)
6K7K8K45K75KMax Capacity192432432192384Backplane speed206464520520ProLeast ExpensiveStackable to 9Stackable to 9ProDual PSDual PSDual PSDual PSDual PSProLayer 3 opt
Layer 3 optDual SupsDual SupsConExpensiveExpensiveConNo Dual PSConLayer 2 OnlyCannot stack more than 4 
For the MDF I would like to use 2 Nexus 5548's with FEX's, and the layer 3 daughter board.  For the IDF's I was thinking of two 4010's.

View 12 Replies View Related

Cisco Switching/Routing :: 3560x Or 3750x For Core Switching?

Mar 6, 2013

i cant find any difference in these two devices when i am trying to compare throughput.I need upgrade our new POP and there will be around 4900 MAC adresses in VLAN 150 and 130 MAC adresses in vlan 200.Uplink is 1 gig routed internet connection and there is 14 downlinks to separate villages.i found a few differences for eg stack interface on 3750x but i dont need it.  

View 2 Replies View Related

Cisco Switching/Routing :: 3750X Static Routing When Running LAN Base?

Dec 27, 2012

I have a stack of 2 x 3750X switches these are running 12.2(55)SE5. I needed to add some static IP routes and found that the ‘ip routing’ command is not supported. I came across a document that stated “On switches running the LAN base feature, static routing on VLANs is supported only with Cisco IOS Release 12.2(58)SE and later.” So I have upgraded to 12.2(58)SE2, but ‘ip routing’ is still not a valid command.
 
The release notes state:“On the Cisco Catalyst 3560-X and 3750-X Series, it adds support for 16 static IPv4 routes in the LAN Base image.”
 
I have read other posts that talk about running the ‘sdm prefer routing’ command which I have done, but I am still unable to add any routes or run the ‘ip routing’ command.

View 4 Replies View Related

Cisco Switching/Routing :: Moving Routing From Perimeter Router To 3750x?

Dec 9, 2012

I have an 1811 with several subnets connected to it.I recently installed a 3750x plant and want to bring my interior routing back to it.
 
All the routing is handled by the 1811 via secondary interfaces on vlan1?
 
I have 192 ports, and subnets show up on almost all of them.  None of the ports are assigned to any specific vlans.  Most ports have several subnets on them.
 
What is the best approach to getting the 3750x to handle the routing?

View 18 Replies View Related

Cisco Switching/Routing :: InterVLAN Routing On Switch 3750X?

May 22, 2013

my company pay a switch 3750 X. WS-C3750X-24T-E. It uses IP services basically but I failed to configure InterVLAN routing. why interVLAN routing doesn't work on my switch?

View 10 Replies View Related

Cisco Switching/Routing :: Nexus 1000v Private-Vlan Trunking

Apr 14, 2011

Having problem pinging from Host A on ESX1 to Host B on ESX2.  Each host are assigned the same port-profile.  If I put 2 host's on the same ESX machine using the same port-profile, they are able to ping each other.
 
n1kv-vsm# sh port-profile name xxx-prod-40port-profile xxx-prod-40  description:  type: vethernet  status: enabled  capability l3control: no  pinning control-vlan: -  pinning packet-vlan: -  system vlans: 1  port-group: xxxl-prod-40  max ports: 32  inherit:  config attributes:    switchport mode private-vlan host    switchport private-vlan host-association 40 400    no shutdown  evaluated config attributes:    switchport mode private-vlan host    switchport private-vlan host-association 40 400    no shutdown  assigned interfaces:    Vethernet3    Vethernet4
System-uplink profile is trunking all vlans.

View 2 Replies View Related

Cisco Switching/Routing :: 6500 - SSH Control Process / Private Key Not Found

Nov 30, 2012

we have configured SSh on our primary and secondry core switch , SSH is working on primary Switch but we are unabme to access secondry Core switch through SSH .
 
Error are as under :
 
ov 28 09:14:15.380: SSH1: starting SSH control process
ov 28 09:14:15.380: SSH1: sent protocol version id SSH-2.0-Cisco-1.25
ov 28 09:14:15.396: SSH1: protocol version id is - SSH-2.0-PuTTY_Release_0.62
ov 28 09:14:15.396: SSH2 1: send: len 280 (includes padlen 4)
ov 28 09:14:15.400: SSH2 1: SSH2_MSG_KEXINIT sent

[code]...

View 1 Replies View Related

Cisco Switching/Routing :: Assign 2 Ports To A Vlan On Slm2008 Private Network

Dec 17, 2012

Is it possible to assign 2 ports to a vlan on this switch and have the 2 machines connected to those ports be able to see each other without having to go off of the switch? If so, how would it need to be setup on the switch?

View 4 Replies View Related

Cisco Switching/Routing :: 3750V - Mixing Public And Private Networks On Same Switch

Oct 23, 2012

We have many remote offices that we want to add public wifi and a couple of other services that would be completely outside of our internal network.  Each office has a 3750 with plenty of open ports.  How can I safely create a vlan for public access on these switches which currently have our internal network on.  I have read that people are doing this to save on the cost of purchasing a dedicated switch.  Some people are using access lists and one person mentioned creating a private vlan for the public network.  I looked up private vlan and it seemed bit confusing.

View 3 Replies View Related

Cisco Switching/Routing :: Telnet Can't Login 2911 Router With Private Address

Jan 7, 2013

We have a cisco 2911 router configured with password for telnet login, but I always failed to login use telnet, does any one know any place need to be modify?

View 6 Replies View Related

Cisco Switching/Routing :: Private Vlan Configuration On 3560E 24 Port Switch

Dec 12, 2012

We have a 24 port and 48 port 3560 E switches with identical IOS the 48 port switch supports private vlan while 24 port switch doesnt
 
configure private vlans on 24 ports 3560e and is it best practise to configure private vlan on this platform(3560)?
  
IOS version : C3560E Software (C3560E-UNIVERSALK9-M), Version 12.2(55)SE3, RELEASE SOFTWARE (fc1)
flash:/c3560e-universalk9-mz.122-55.SE3/c3560e-universalk9-mz.122-55.SE3.bin

View 3 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved