Cisco Switching/Routing :: Blocking MAC From VLAN Access 2950

Dec 11, 2011

We have a group of computers on their own VLAN.  A router allows internet access while keeping them sandboxed.  We don't want them accidentally connect to our production network.  We blocked their wireless MACs in unauthorized WAPs.  I'd like to do the same thing for their ethernet MACs on our switches, (a mixture of 2950,2960 and 2960G currently testing on C2960-LANBASE-M, Version 12.2(25)SEE2).  I've been unable to locate the correct method on google, by searching these boards or in the command reference.
 
What is the best practice for blocking a group of MACs from accessing a particular VLAN on a network consisting of several Layer 2 Switches? 

View 4 Replies


ADVERTISEMENT

Cisco Switching/Routing :: 2950 To Assign DHCP With VLAN

Apr 27, 2012

Stumped again with my Catalyst 2950. Everything is working perfectly with wan/dhcp/router on fa 0/1 with all ports assigned to vlan1. All devices plugged in connect to the router correctly with ip's being assigned via dhcp.Instead of hooking up by console port I want to be able to SSH or telnet in to the switch using any port while still maintaining the above functionallity. Is it possible to assign a dhcp assigned ip address to vlan 2 and have vlan1 and 2 bridged? Or is there a better way of doing this ?

View 3 Replies View Related

Cisco Switching/Routing :: 2950 VLAN Database VTP Management

Jul 4, 2012

spam up the boards with the same basic CCNA level stuff, but I have a couple of questions about ios differences, limitations, and references. I have the following three switches. One appears to be considerably dated in regard to software version. My confusion/ignorance stems from managing VTP settings.
 
2924XL     12.0 5 WC8
2950          12.1 22 EA6
2950          12.1 22 EA6
 
When I set either 2950 switch as the VTP server, and the other as a client, the client inherits the server settings as expected. However the 2924 requires that I go into the vlan database from priv exec and manually set vtp client. That's pretty similar to setting any switch to client mode. The problem I am observing is that after setting the 2924 to client, it still doesn't inherit vtp version settings or pruning settings. I still have to manually configure those. Additionally, if I copy run start the 2924 after making these manual settings, and then reload the switch, all the settings are lost and it defaults back to server mode with all features disabled. From my searches, it looks like vlan information is stored in vlan.dat, but all the documentation I've found is on 12.1 ios which doesn't appear to use vlan database for vtp setup, meaning it might still be an issue, but not one I'm focused on at the moment.
 
Is the vlan database dumped at reload? I've read vlan.dat is stored in nvram and should be saved after a copy run start, but that is not the case for me.I have since set the 2924 as the server, manually configured the server from vlan database, executed copy run start, and reloaded the switch. Oddly, my manual settings saved from the reload, meaning I only lose settings when the switch is in client mode.Am I missing additional necessary client commands to save the config, or is this just a limitation of either the 2924XL or the 12.0 ios?On a related but completed out of scope topic, without a cisco service contract, how am I supposed to make heads or tails of all the different versions of ios, along with the letter-based features and what-not? I can't even find my 2924 in the list of platforms when searching for ios upgrades.

View 5 Replies View Related

Cisco Switching/Routing :: 2950 DTMF Not Working On Voice Vlan

Nov 9, 2011

i am facing a strange issue on cisco 2950 .IOS (tm) C2950 Software (C2950-I6K2L2Q4-M), Version 12.1(22)EA9, RELEASE SOFTWARE (fc1) suddenly my phone stopped working for DTMF tone, i mean when i  dial a conference bridge lets say 6565 and then it ask for conference  bridge code lets say 12345, it doesnt recognize the code and says code  is invalid, SIP Proxy is Asterisk in this case.Currently my cisco switch port is configured for dual data + voice vlan, where DTMF dont work, sample config below [code]

View 2 Replies View Related

Cisco Switching/Routing :: 2950 Loss Connectivity Management Vlan?

Apr 8, 2012

Randomly when I try to access to 2950 from management tools, switch is unreachable, I have to  access from other switch and reload 2950.
 
Problem only is from managemt tool to managament vlan 1 2950.
 
The strange thing is that management interface is encountering a very fast increase of throttles, broadcast and ignored packets:
 
2950#show interfaces vlan 1
Vlan1 is up, line protocol is up
  Hardware is CPU Interface, address is 0023.3488.fd65 (bia 0023.3488.fd65)
  Internet address is xxxxxxxxxx
  MTU 1500 bytes, BW 1000000 Kbit, DLY 10 usec,
     reliability 255/255, txload 1/255, rxload 1/255

[code]....
 
It could be  a hardware problem?, IOS has been upgraded.

View 11 Replies View Related

Cisco Switching/Routing :: Login To 2950 Switch And Modify VLAN Entry On It?

Nov 3, 2011

In my lab, there are some machines that are connected using Cisco 2950 switches. Those machines belong to a VLAN.Now I need to modify the VLAN settings of the machines and as such I also need to modify the VLAN settings on the ports on the Cisco switches.
 
In order to do this, first I need to login to those switches, but due to a lack of knowledge transfer, I don't have the password. Is the some generic password?Second I will need to  modify the VLAN settings on each individual port. How can I do this?

View 2 Replies View Related

Cisco Switching/Routing :: 3750 / 2950 - Which Series Switch Supports Vlan Up To 4000

Nov 4, 2012

we are using 3750 and 2950 switches  both of them do not support vlan up to 4000 .we need vlan about 3000 .Whic cisco series switch do support  vlan up to 4000.
  
2950
S-SW1.3(config-vlan)#exi

Proposed configuration has too many VLANs for this platform. Reduce the number of VLANs proposed.

S-SW1.3(config)#end 
 3750
SW1(config-vlan)#exi

proposed configuration exceeds the limit of 1005 VLANs that can be supported on this platform. Reduce the number of VLANs proposed to be within this limit.

View 1 Replies View Related

Cisco Switching/Routing :: 2950 - Private VLAN Across Trunk To Older Model Switches

Mar 7, 2012

I am looking into the possibility of using private vlan's for some dmz implementations however I do have what may be some very rudimentary questions. It seems straightforward how to configure the primary/secondary vlan configuration as well as associating them. However in my case I would be looking to configure the PVLAN on a 6500-vss platform acting as the router while all of the hosts which I would desire to have in the isolated vlan would be spread out across a number of older Cisco switches which only support "protected port" setup or Procurve switches all of which I do not have budget to replace with something newer. So in my scenario I would have a 6500 connected by trunk to multiple switches which only support a protected port setup such as a Procurve (top of rack) or a Cisco 2950. As the Procurve or 2950 would not support Private VLAN setup, do I then just configure the secondary vlan to be allowed across the trunk from the 6500, configure that vlan on the Procurve or 2950 (as vtp will not foward the info for the secondary vlan) and assign that vlan to the host port as well as setting it as a protected port and this will communicate just fine across the trunk to the router as well as stopping the protected port in top of rack switch 1 from being able to communicate to a protected port in top of rack 2,3,etc? If the above scenario is what needs to be done, do I just use a regular trunk or do I have to use a PVLAN trunk?

View 2 Replies View Related

Cisco Switching/Routing :: SG-300 52 Native VLAN Blocking Network Packets

Jun 15, 2013

SG-300 52 native VLAN blocking network packets

View 3 Replies View Related

Cisco Switching/Routing :: 2950 - Can't Access Switch Via Browser Or CNA

Jan 5, 2012

I upgraded a Catalyst 2950 switch and there wasn't enough room so I deleted the flash. The upgraded went well using tftp. It booted up fine. The  I0S version includes crypto. But, I can't access switch via web browser or CNA. Port scan shows port 80 0pen. What am I missing?
 
Here is the flash. 
Directory of flash:/
    2  -rwx         112  Mar 01 1993 01:00:48 +00:00  info    3  -rwx     3722814  Mar 01 1993 01:02:58 +00:00  c2950-i6k2l2q4-mz.121-22.EA14.bin    4  drwx        4416  Mar 01 1993 01:03:45 +00:00  html  331  -rwx         112  Mar 01 1993 01:04:19 +00:00  info.ver  332  -rwx   [code]....

View 5 Replies View Related

Cisco Switching/Routing :: 2950 / Vlans And Internet Access Sharing?

Apr 5, 2013

i am trying to set up a cisco 2950 with a vlan to seperate all of the pos machines on the network (4 of them) from all other machnes in the building (3 hard wired and wi-fi).  i was going to use vlan 1 as a trunk to allow internet access to go from fa0/1 to both vlans (vlan 10 and vlan 20).  i have read things about the acl having an explicit deny at the end, so i'm thinking that is my  problem.  i am testing it at my house before deploying it to the network.  i have 1 laptop setup with an ip of 192.168.0.50, and the other is .60.  my router is 192.168.0.1.  i have the ethernet from the router plugged into fa0/1, the 1st laptop on fa0/2 and the other at fa0/3. before i set the vlans up, i checked the communication by just plugging them in and trying to ping, they could both ping each other, the router and 8.8.8.8.  when i finished setting up the test vlans, they could not ping each other(what i wanted) and laptop 1 can ping the router, and 8.8.8.8.  laptop 2 cannot ping anything. 
the only thing i did was create vlan 10 and 20, set port fa0/2 to vlan 10 and no sh, fa03 to vlan 20 and no sh, fa0/1 to vlan 1 and no sh.  then i did switchport mode trunk on fa0/1, and switchport native vlan 1.  this seems to be how i was supposed to do it, but it's been a while since i have worked with switches.  i'm sure it's simple, but after searching the internet and poring over my cisco books for 5 hours, it is turning out not to be the case. here are some details:

greenhouse#sh int fa0/1 switchport
Name: Fa0/1
Switchport: Enabled
Administrative Mode: trunk
Operational Mode: trunk
Administrative Trunking Encapsulation: dot1q

[code]...

View 10 Replies View Related

Cisco Switching/Routing :: 2950 Disabling Windows Firewall / Allowing Access Through The Router

Dec 18, 2012

i bought a cisco 2950 series switch to play around with and im trying to set it up to SSH. I have google'd a bit on how to do this and i've sort of hit a wall... i have downloaded the cryptographic image from cisco's website, installed a TFTP server (think this is where my issue lies) but when i do the copy tftp flash global command i keep getting the error accessing "xxxx" message.I have tried allowing the server through windows firewall, disabling windows firewall, allowing access through the router..

View 6 Replies View Related

Cisco Switching/Routing :: 1002 ASR Sometimes Vlan User Will Not Be Able To Access

Apr 2, 2013

We are having Cisco router 1002 ASR and 2841 switch. Some times perticular VLAN user will not be able to access the network but from the same switch others VLAN users can able to access. We were getting ARP entries in router but we cannot ping the IP's. Even we clear the ARP entries. Once we restart the switch users can access the network. We have changed vlan ports, uplink too. but problem not solved. and we observed CPU utilization will be going 70-80% some times and at same time switch hangs.

View 3 Replies View Related

Cisco Switching/Routing :: 3750G / Allow A Computer Access Another VLAN?

Feb 20, 2013

We have 3 VLAN in our cisco 3750G switch. VLAN 1 10.1.0.0/24 for domain network, VLAN 2 10.2.0.0/24 for student and VLAN 3 10.3.0.0/24 for public. We have one printer 10.3.0.206  in the VLAN 3 and want to allow student server 10.2.0.253  in the VLAN 2 to access the printer. How can we configure access-list? Here is current configuration.

ip access-list extended publicaccess
permit icmp any any
permit ip any host 10.2.0.253
permit tcp any any established log
deny  ip 10.3.0.0 0.0.0.255 10.1.0.0 0.0.0.255
deny  ip 10.3.0.0 0.0.0.255 10.2.0.0 0.0.0.255

View 9 Replies View Related

Cisco Switching/Routing :: 192.168.10.10 / VLAN Access List Not Working?

Sep 5, 2012

Extended IP access list VLAN20
    10 permit tcp any any established
    11 permit icmp any any
    20 permit tcp any 192.168.20.0 0.0.0.255 eq 80
    30 permit tcp any 192.168.20.0 0.0.0.255 eq 443
    40 deny ip any any log

[code].....
 
Above is the network diagram and access list for VLAN 20 and VLAN 30, applied on incoming direction of each valn.But still able to access other port which is not on access list, tried changing the direction with no luck.Inter vlan routing is enabled on CoreSwitch default router is 192.168.10.10

View 5 Replies View Related

Cisco Switching/Routing :: 1841 Vlan 5 Cannot Access Internet

Oct 31, 2012

i have router 1841 have 2 interface.i make routing between vlan  by subinterface in router and in switch trunk but vlan 5 cannot access internet

View 3 Replies View Related

Cisco Switching/Routing :: SG-300 Vlan Unable To Access Internet

Apr 1, 2013

I am using a Cisco SG-300 28 port switch in layer 3 mode as my default gateway for all my devices. I have two vlans on the switch, vlan 1 and vlan 4. Both are pulling valid IP addresses in their scope from the DHCP server, and both have valid DNS settings. I set a static route to the Internet on the switch to our firewall (192.168.5.254). All devices connected to vlan 1 are able to access the Internet, however all devices connected to vlan 4 cannot get past the switch. A tracert from one of these devices shows it hits the switch as the gateway, but gets no further. [code]

View 4 Replies View Related

Cisco Switching/Routing :: 2960 No Internet Access From VLAN

Feb 6, 2012

I have a 2960-S running the lastest software for testing on my bench:

[code]
Switch Ports Model              SW Version            SW Image                
------ ----- -----              ----------            ----------              
*    1 24    WS-C2960-24-S      15.0(1)SE2            C2960-LANLITEK9-M  
[/code]

I have set up VLAN 2 on 192.168.2.0/24 with the switch as the DHCP server.  The switch is connected to an RV082 router which is at 192.168.1.65/27.  Once I figure out what I doing I'll eventually shift that to 192.168.1.0/24 or something similar.  So I have my switch acting as the DHCP server for VLAN 2 but I can't figure out how to get it to access the internet.
 
I found this example to set up the DHCP server:
[code]
###################################
this works to get vlan 2 to serve ips
conf t

[Code].....
 
The RV082 doesn't support trunks AFIK and I'm pretty much a newb at this stuff.  TIA.  I guess I should get a real router and I most likely will but I'd like to get this working if possible before taking the next plunge.

View 7 Replies View Related

Cisco Switching/Routing :: 5548 Prevent VLAN From Internet Access

May 9, 2012

At the core of my network I have two Nexus 5548's with the routing/L3 daughter installed. They have a default route that points to my ASA 5520 for Internet access. I have configured a VLAN that I do not want to have access to the Internet. What is the best way of preventing this access?  ACL on the Nexus or Firewall rules on the ASA?

View 1 Replies View Related

Cisco Switching/Routing :: Vlan Access List In 3750x Switch

Feb 6, 2013

I have a LIII Switch Cisco 3750x ,with diffrent Vlans , Some users are in Vlan 102 (10.10.2.0) and Some Users are in Vlan1 (10.10.1.0) , now i want to restrict  the Vlan102 users to access Vlan1 , i am pasting my configuration below , how to create a access list . 
 
interface Vlan1
ip address 10.10.1.36 255.255.255.0
ip helper-address 10.10.1.36

[Code].....

View 2 Replies View Related

Cisco Switching/Routing :: 876 - Ping Failure Between Default And Access VLan

May 26, 2013

I have a cisco 876 with, c870-adventerprisek9-mz.124-6.T9.bin. I have configured a VLAN with ID 230, an SVI with IP 192.168.230.1/24 and I have assigned switch port fa 2 to it…
 
interface Vlan230
ip address 192.168.230.1 255.255.255.0
VLAN ISL Id: 230

[Code]......

View 5 Replies View Related

Cisco Switching/Routing :: 3750X - Unable To Access VLAN IP Pool

Mar 19, 2013

I have one issue on Vlan in Cisco 3750X switches , I have 2 Offices  , I am sitting at corp OFfice and i have one 3750 ( 10.10.1.36)Switch at my location , in my remote office i have one more switch 3750 ( 10.10.33.1) and i am able to access the both vlan IPS with out any issue , now i have some network components in Vlan33 ( 10.10.33.1) at my remote office . i am able to ping 10.10.33.1 IP from my corp office , but i am not able to ping any network devices in 10.10.33.5 example : 10.10.33.5 is my Cyberoam IP at remote location and i am not able to ping , i have taken a trace route and not able to find the issue as i am not much femilar , ping 10.10.33.5 at remote location devicec
 
I am giving the Configuration for both locaitons below :
 
10.10.1.36 - Corp Office 3750 Switch:
sh run
L3-#sh running-config
Building configuration...

[Code].....

View 1 Replies View Related

Cisco Switching/Routing :: 3750x - Denying VLAN Access To Other VLANs

Mar 18, 2013

I've got a 3750x stack set up as my core switch (only a small-ish environment) - I'm shortly going to be deploying an enterprise wireless network with Corporate and Guest SSID's. I'm going to be putting all traffic from the Guest SSID in VLAN 244, and don't want it to have access to any of the other VLANs (1 (Legacy Eqpt), 4, 8, 12, 16, 20, 24, 28, 32, 248 & 252).
 
IP ranges for all the main VLANs are:
 
1: 10.0.0.x/22
4: 10.0.4.x/22
8: 10.0.8.x/22
12: 10.0.12.x/22
16: 10.0.16.x/22 etc etc (you get the pattern)
 
I'll probably give Guest traffic (VLAN 248) the IP range 192.168.10.x/22 (not because I NEED that many addresses, but it's easier for everyone to remember/understand if I keep the subnet masks the same all round). However I also have a CCTV VLAN (252) which already has the range 192.168.0.x/24, which some people in other VLANs WILL need access to.
 
So my question is: What is the syntax for the ACL on my 3750x (IP base - 15.0.2) to prevent traffic from VLAN 244 gaining access to any of my other VLANs. I'm making a broad assumption here that a layer 3 switch is perfectly capable of supporting that function? I need ALL the syntax for setting up ACL's - I've never done it before
 
My gateway device by the way is 10.0.4.1, and I do have inter-VLAN routing set up on the core switch (obviously).

View 3 Replies View Related

Cisco Switching/Routing :: 4948 - Configuration Of Access List For VLAN 2

May 19, 2013

In my core Switch,there are 2 v LAN(V LAN 1 & V LAN 2)my switch is Cisco 4948,so be default ip routing is enable in it. My all servers (DHCP,HTTP,HTTPS) are in v LAN 1 & internet is also in v LAN 1.

My requirement is that v LAN 1 user should not communicate with the v LAN 2 and vice versa. But the v LAN 2 users need an access of all servers and internet which is in v LAN 1. How to configure the access-list. I have try on Packet tracer which i have attached.
 
note:v LAN 2 user should get the IP from dhcp server which is in vlan1.

View 4 Replies View Related

Cisco Switching/Routing :: 2900 - Multiple Vlan Access On Standalone Switch

Feb 3, 2013

The field engineer has a stand alone 24 port 2900 series switch that he has different equipment connected to and are segmented using VLANs. So for example, he's got ports 1-4 assigned to VLAN 10, 5-12 assigned to VLAN 20, 13-19 assigned to VLAN 30 and 20-24 assigned to VLAN 40. He would like all the gear on VLAN 30 to have the ablity to talk to all of the other VLANS, but VLAN 40 should not be allowed to talk with any other VLAN. Trunking would do no good here since the switch isn't connected to anything and you can only assign one VLAN per port.
 
Is there a way to do this within the stand alone switch? The only possible way I could think of would be to ensure that each VLAN has an assigned IP number (subnet) and doing this through access lists.

View 2 Replies View Related

Cisco Switching/Routing :: Can't Assign Switch 3560G Port G0/1 To Access Vlan 10

Feb 21, 2012

cant assign cisco switch 3560G port g0/1to access vlan 10
 
main-switch(config-if)#switchport access vlan 10 Command rejected: Gi0/1 not a switching port.

View 5 Replies View Related

Cisco Switching/Routing :: WS-C3560G-24PS / Native Vlan Tagging And Vty Access To Autonomous APs?

Jan 14, 2013

I've been experimenting with the 'vlan dot1q tag native' command on a switch and it seems as though tagging the native vlan breaks vty access to my access point.With the 'vlan dot1q tag native' commnand applied, I lose management connectivity to the AP with 'no vlan dot1q tag native' applied, connectivity is restored. Why is this? Is it safe to say that one can access the AP via vty lines using ONLY untagged packets? 
 
SWITCH
Model: WS-C3560G-24PS
Code: c3560-advipservicesk9-mz.122-46.SE
--Abbreviated CONF
 vlan dot1q tag native

[code]....

View 14 Replies View Related

Cisco Switching/Routing :: 3560 Multiple Vlan Access To Port Connecting Phone System

Oct 25, 2012

I'm new to networking and was looking for some assistance. First off im using packet tracer to diagram my senario as I will be receiving my equipment next week to deploy.
 
Hardware to be used:
 
1. 2 catalyst 3560 switches
2. all connect to a sonic wall router
 
I have two companies that work in the same office space. I need to keep these companies seperate on their own vlan. They will however need to share the phone system.(Packet tracer file uploaded to give those who have the time to see what I put together.) [code]

View 13 Replies View Related

Protocols / Routing :: Cable Blocking Access To MSN?

Jan 16, 2013

We have three home systems connecting to the internet. Our cable/phone/internet provider upgraded their phone service to digital and installed a new modem/router combo (three months ago). Since then we've not been able to access MSN.com on our XP laptop and droid tablet but can access it on our windows 7 laptop. When the router settings are changed to "Bridged" and the router firewall is turned off, we can connect. We've changed the modem and the problem still continues. Our cable provider is stumped and so am I.

View 9 Replies View Related

Cisco Switching/Routing :: Way To Get More Messages Out Of 2950 Set To Syslog

Feb 11, 2012

Is there a way to get more messages out of a 2950 set to syslog? I've turned every logging option I can find to DEBUG, but all I get in my syslog are LinkUp/Down messages and "Configured from console by console". I'd love to see more information such as configuration changes, or even someone attempting to set up DTP on a switchport set to access mode.

View 2 Replies View Related

Cisco Switching/Routing :: 2950 CRC Errors On Switch

Jun 22, 2012

One of my wi-fi site having 2nos cisco 2950 switchs. in that network some D-link unmanageble swithes also there and access points also connected to cisco switchs and D-link switchs.after one or two days i am not able to connect the wi-fi, then i need to restart the access point then only wi-fi is working fine.I upgraded the latest ios also.I connected some access points to the cisco switch ports, those ports are showing crc error messages like below. [code]

View 18 Replies View Related

Cisco Switching/Routing :: 2950 / NIC Teaming On Two Switches?

Apr 25, 2013

I have a server windows 2008 that I would like to have a nic teaming configuration, the server has two nics, each nic is connected to a different switch. One is connected to cisco 2960 and the other is connected to cisco 2950. I have read here in forums about nic teaming but using the same switch. I have not found using different switch. Is this possible?

View 1 Replies View Related

Cisco Switching/Routing :: Set 2950 IOS To Be Loaded From TFTP

Jan 11, 2012

2950 switch has a IOS on flash , but i would like to set the swith like...

1. switch IOS to be loaded from TFTP server .if it fails

2. Loaded from local flash IOS1 , if it fails

3. IOS loaded from local flash IOS2.
 
does 2950 switch support this feature.

View 2 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved