Main Topics
Browse All TopicsI am migrating a Cisco 2950 switch to HP Pro Curve 2810 switch, On Cisco 2950 switch there are 2 VLAN's and 2 trunck ports setted up, i am going to paste the configuration for both the switches.
There are two VLAN's on the Cisco switch, one is Desktop and the other is for Auth.Server, and we have two Gigabit (Trunck Ports) for firwall from where all the network connections goes through, the firewall that is being used is Astaro Securtiy Gateway V7.
Now on the weekend i was trying to migrate the Cisco2950 switch over to HP Pro Curve 2810, but when i plugged the firewall / Auth. Servers cables on to the new switch, the dektops were not able to get an IP address from the DHCP server. (i.e Microsoft SBS server), I setted the new switch DHCP to Manual, Disable and automatic but none of them worked out.I am missing something but not able to figure out what....
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
Does your server or your switch normally handle DHCP?
If it is your server then you may want to check services.msc
Start > Run > services.msc and make sure DHCP server service is still running
If you are doing DHCP orginally through the Cisco unit and you now want to use the DHCP features of the HP Pro Curve then first thing would be to setup the HP Pro Curve by itself and connect a laptop or a PC (not server) to one of the ethernet ports and see if it can get an ip address without any other network devices being between the laptop/PC and the HP Pro Curve. If at that point you can get an ip address then you may want to start checking settings on your security gateway it may be blocking packets from the HP Pro Curve being a new device on the network.
Yes the SBS server handels our DHCP.
The DHCP is running because when i plugged my computer to the HP switch, it got an IP address between the range of 169.254.218.201 and subnet 255.255.0.0,Gateway 169.254.150.177 and DHCP server 255.255.255.255, where as for our desktops my ip is 10.50.10.53/24 with a default gateway of 10.50.10.254,
Now when i plugged the cable back to Cisco Switch it got the IP of 10.50.10.53. That means its getting the IP from the server.
When i connect a Laptop directly to HP switch it shows limited connectivity, and gets an IP address between the range of 169.
I am not sure on which ports the old switch was connected to,
On Cisco switch how can i find it out?
Do i have to define a new rule in Astaro firewall for the ports.
I tried doing one thing, i connected a laptop directly to switch, without connecting firewall or proxy, but still it shows that the network access is limited.
I have taken out the Trunk Port, because i thought that might be the problem, but when i took out the trunk port, it assigned those ports to the default vlan....which i dont want....
How can i find out that i am connecting more ports to the switch to more NIC's on the server?
All the workstations would be getting the DHCP from the SBS server, on that server we have one network card, and ip of that is 192.168.x.x, and the ip range for the desktops are 10.50.x.x, i didnt connected all of the computers i just connected mine.....and it showed limited connectivity.....
At what port is the DHCP-SBS server connected in the new setup??
and at what port is the Astaro Securtiy Gateway V7 ??
As there is only one network card (=NIC) on the DHCP-server there is no need for trunk (in HP-terms) here.
There is only one cable to the Astaro Securtiy Gateway V7 I asume, so no need for trunk (in HP-terms) here either; but some tagging of vlans will be needed.
HTH
The DHCP-SBS server is using the ports 546 and 547.
the port that Astaro firewall is using is 444.
We have two identical Linux boxes on which Astaro firewall is running, so that when one go's down we have the other one, now two ports which were in trunk mode were used for these two boxes.
which VLANs will need tagging........
'which VLANs will need tagging........'
Plain access-ports no tag.
In other links the 'tagging-mix' in both ends must match, meaning the vlans you want to carry must be either tagged or untagged on the port. In a common setup you would make all these vlan's tagged on all other vlan's but vlan1. (When connecting HP-HP you could also tag vlan1, but untag vlan1 in HP-Cisco links).
HTH
'which VLANs will need tagging........'
Plain access-ports no tag.
In other links(Cisco-term:trunk) the 'tagging-mix' in both ends must match, meaning the vlans you want to carry must be either tagged or untagged the same way on the ports in both ends of the link.
In a common setup you would make all these vlan's tagged on all other vlan's but vlan1. (When connecting HP-HP you could also tag vlan1, but untag vlan1 in HP-Cisco links).
HTH
there will be no connection between Cisco and HP switch, once the HP switch is up and running, i will take out the cisco switch.
Now if i understand correctly i should untage VLAN1 (Default Vlan)
tag VLAN2 and VLAN3.
but if i dont assign the firewall ports any trunk or VLAN, they goes into Default Vlan.
On the old cisco switch it didnt had any IP address, as well as it didnt had any DHCP address, no VLAN address was defined as well, if you can look at the top where i pasted the configuration for the switch, so should i do the same with HP switch....
Also if i dont assign the firewall ports to any trunk port or VLAN, they goes into Default Vlan, so is it going to make any difference........before the firewall ports were on trunk ports........
Where you used to connect to Cisco-term 'trunk' ports, you now should connect to HP-term 'tagged' ports
Only out-of-band configuration?
If you want to communicate with the HP-switch by means of serial-cable only, then you do not need an IP.
Otherwise asign IP's to the vlan's in witch you want to be able to communicate with the box.
Sorry about the last reply...i just wrote.....didnt see it before sending i will write it again....
Yes the two firewall cables from linux boxes were used to connect to Cisco trunk ports, which was providing us a gigabyte link.
So if i am not wrong i have to connect the two firewall ports and make them tagged ports (i.e. on HP switch) but would it be with default or withour default vlan ?
I will be connecting the HP switch through the serial port,so do i need to provide IP address, subnet mask and default gateway to the HP switch.
Thanks.
Thanks.
If i didnt get it wrong, i will tagg two ports and connect the firewall ports to them, but then they will be automatically be assigned to default-vlan, would that be fine.
And to reconfirm one more thing, i will be connecting to the switch through serial cable, so i dont have to assign any IP address to VLAN's or DHCP, or Gateway.
I have tagged the ports for VLAN2 and VLAN3, and untagged the Port for VLAN1 on which the firewall ports will be connected.I have taken out all the IP addresses.
Then i tried to connect a laptop directly to the HP switch (i.e. without the firewall or Authen.Server ports), but its still showing limited access.I tried doing releasing and renewing the IP, it showed the message that it not able to retrieve IP from DHCP server.
To find out if this is only a DHCP matter or a broader problem, please try to give the PC static settings of IP, netmask,dgw,DNS.. whatever would normaly be asigned by DHCP.
Then try if basic connectivity is as expected , ping dgw, ping dns-server , tracert www.google.com etc.
IS basic connectivity as expected, when asigning static IP settings?
What is the IP ?
what is the netmask?
dgw?
dns?/wins?
can you ping dgw?
ping dns-server ?
tracert www.google.com etc.
Perhaps some topology and roles of involved componets could clear up the problem.
Where is the DHCP-server?
at what vlan is it operating?
is the PC in the same vlan?
where is routing taking place in your network?
How is the connection from DHCP-server to the PC in question?
Does the DHCP-server have same network as your PC?
Is a switch in between with an IP helper adress configured?
Does trafic go th. some device with filtering capacities?
Sorry for lae reply, i was trying to test couple of things but it didnt worked out, anyways i will answer most of your questions, the ones i cant are because i have to unplug the firewall prots and attach it to HP switch, and i can only do that when there is no one in the office which is a rare chance, anyways i have taken the permission and i can do it over the weekend.
What is the IP ? 10.50.10.19
what is the netmask? 255.255.255.0
dgw? 192.168.0.1
can you ping dgw?I cant,because for that i have to take out the firewall and proxy ports, to get a response from dgw.
ping dns-server ?No
tracert www.google.com? I cant, because i cant ping the DHCP server.
Where is the DHCP-server? I will post the network diagram then it will be easy for you to understand.
at what vlan is it operating? Its not operating on any VLAN, all the windows server are connected through Netgear switch and are on the subnet of 192.168.x.x, and the desktops are on 10.50.x.x
is the PC in the same vlan?Workstations are on VLAN 2.
where is routing taking place in your network? I am not sure about the question so i will answer what i know, we have cisco 2600 router, but thats not managed by us, its managed by other comany,
How is the connection from DHCP-server to the PC in question?Not sure, thats where i am stuck.
Does the DHCP-server have same network as your PC? No, both are on different subnet.
Is a switch in between with an IP helper adress configured?There is a switch but its a normal 5 port Netgear switch.
Does trafic go th. some device with filtering capacities?Yes it goes through Astaro Firewall, and i have to add the machine in that firewall so that it can access the browser.
I am not sure if the old Cisco had been configured to use IP helper or not, not sure how to check it.
Also the PC i used for testing used to work with the old setup.
If i do IPconfig/all on my worksations (with the old setup with Cisco), i get this.
Windows IP Configuration
Host Name . . . . . . . . . . . . : Computer Name
Primary Dns Suffix . . . . . . . : Company Name.Local
Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
DNS Suffix Search List. . . . . . : Company Name.Local
Ethernet adapter Local Area Connection 4:
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : VMware Virtual Ethernet Adapter for
VMnet8
Physical Address. . . . . . . . . : 00-50-56-C0-00-08
Dhcp Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
IP Address. . . . . . . . . . . . : 192.168.x.x
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . :
DHCP Server . . . . . . . . . . . : 192.168.11.x
Primary WINS Server . . . . . . . : 192.168.11.x
Lease Obtained. . . . . . . . . . : Monday, 14 July 2008 16:20:20
Lease Expires . . . . . . . . . . : Monday, 14 July 2008 16:50:20
Ethernet adapter Local Area Connection 3:
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : VMware Virtual Ethernet Adapter for
VMnet1
Physical Address. . . . . . . . . : 00-50-56-C0-00-01
Dhcp Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
IP Address. . . . . . . . . . . . : 192.168.204.x
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . :
DHCP Server . . . . . . . . . . . : 192.168.204.x
Lease Obtained. . . . . . . . . . : Monday, 14 July 2008 16:20:20
Lease Expires . . . . . . . . . . : Monday, 14 July 2008 16:50:20
Ethernet adapter Local Area Connection:
Connection-specific DNS Suffix . : Company Name.Local
Description . . . . . . . . . . . : Intel(R) 82566DM-2 Gigabit Network C
onnection
Physical Address. . . . . . . . . : 00-1A-6B-5B-00-68
Dhcp Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
IP Address. . . . . . . . . . . . : 10.50.10.x
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 10.50.10.x
DHCP Server . . . . . . . . . . . : 192.168.0.x
DNS Servers . . . . . . . . . . . : 192.168.0.x
Primary WINS Server . . . . . . . : 192.168.0.x
Lease Obtained. . . . . . . . . . : Monday, 14 July 2008 15:19:15
Lease Expires . . . . . . . . . . : Tuesday, 22 July 2008 15:19:15
Ethernet adapter Local Area Connection 2:
Media State . . . . . . . . . . . : Media disconnected
Description . . . . . . . . . . . : TAP-Win32 Adapter V8
Physical Address. . . . . . . . . : 00-FF-4C-89-E8-10
And when I do IPConfig/all on the DHCP(i.e. Microsoft SBS) server, I get this;
Windows IP Configuration
Host Name . . . . . . . . . . . . : Windows SBS
Primary Dns Suffix . . . . . . . : Company Name.Local
Node Type . . . . . . . . . . . . : Unknown
IP Routing Enabled. . . . . . . . : Yes
WINS Proxy Enabled. . . . . . . . : Yes
DNS Suffix Search List. . . . . . : Company Name.Local
Ethernet adapter Server Local Area Connection:
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Broadcom NetXtreme Gigabit Ethernet
Physical Address. . . . . . . . . : 00-11-09-AF-45-B8
DHCP Enabled. . . . . . . . . . . : No
IP Address. . . . . . . . . . . . : 192.168.0.x
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 192.168.0.x
DNS Servers . . . . . . . . . . . : 192.168.0.x
Primary WINS Server . . . . . . . : 192.168.0.x
But when i connect it to HP switch i get allocated an IP address with the range of 169.x.x.x with limited access, i think its not able to get through to DHCP server.
Correct me if i am worng, i am not going to give any IP to the switch i am just going to assign it a default gateway of 192.168.0.254, and i am going to apply these settings.
Switch(config): ip default-gateway 192.168.0.254 (Default gateway address of the server)
VLAN2 (Desktops): 10.50.10.1 255.255.255.0 (port 9-45 untagged)
Vlan3(Auth.Server): 10.50.11.1 255.255.255.0 (Port 4-9 untagged)
The current scope options on the DHCP server are:
Servername [192.168.0.1]
Scope [10.50.10.0] Desktops
Ip's for distribution: 10.50.10.1 - 10.50.10.99
Scope options:
Router-->10.50.10.254
DNS Server-->192.168.0.1
WINS/NBNS Servers-->192.168.0.1
WINS/NBT Node Type-->0*8
Scope [192.168.0.0] Servers
IP's for distribution: 192.168.0.10 - 192.168.0.200
Router--> 192.168.0.254
DNS server -->192.168.0.1
WINS/NBNS Servers-->192.168.0.1
Cisco Switch
Port Name Status Vlan Duplex Speed Type
Fa0/1 notconnect 3 auto auto 10/100BaseTX
Fa0/2 connected 3 a-full a-100 10/100BaseTX
Fa0/3 connected 2 a-full a-100 10/100BaseTX
Fa0/4 notconnect 2 auto auto 10/100BaseTX
Fa0/5 connected 2 a-full a-100 10/100BaseTX
Fa0/6 connected 2 a-full a-100 10/100BaseTX
Fa0/7 connected 2 a-full a-100 10/100BaseTX
Fa0/8 connected 2 a-full a-100 10/100BaseTX
Fa0/9 notconnect 2 auto auto 10/100BaseTX
Fa0/10 notconnect 2 auto auto 10/100BaseTX
Fa0/11 notconnect 2 auto auto 10/100BaseTX
Fa0/12 connected 2 a-full a-100 10/100BaseTX
Fa0/13 notconnect 2 auto auto 10/100BaseTX
Fa0/14 connected 2 a-full a-10 10/100BaseTX
Fa0/15 connected 2 a-full a-100 10/100BaseTX
Fa0/16 connected 2 a-full a-100 10/100BaseTX
Fa0/17 connected 2 a-full a-100 10/100BaseTX
Fa0/18 connected 2 a-full a-100 10/100BaseTX
Fa0/19 connected 2 a-full a-100 10/100BaseTX
Fa0/20 notconnect 2 auto auto 10/100BaseTX
Fa0/21 notconnect 2 auto auto 10/100BaseTX
Port Name Status Vlan Duplex Speed Type
Fa0/22 connected 2 a-full a-100 10/100BaseTX
Fa0/23 notconnect 2 auto auto 10/100BaseTX
Fa0/24 notconnect 2 auto auto 10/100BaseTX
Gi0/1 connected trunk a-full a-1000 10/100/1000BaseTX
Gi0/2 connected trunk a-full a-1000 10/100/1000BaseTX
switch1#
i keep changing the configuration of HP switch because i am not sure how to replicate that, it looks quite easy but when i replicated it, it didnt work, the reason i found was because when i connected my machine with the HP switch it was not able to get IP from the DHCP server, it got an IP address of 169.254.218.201; GW: 169.254.150.177, not sure from where it got these IP's, because they dont exist on our network, and i am not sure whether i should provide IP to the HP switch and VLAN's or not, because on Cisco switch there were no IP's given either to switch or to VLAN's, not sure how they work without it.
switch1#show run
Building configuration...
Current configuration : 2653 bytes
!
version 12.1
no service pad
service timestamps debug uptime
service timestamps log uptime
no service password-encryption
!
hostname switch1
!
enable secret 5 $1$bLVE$casHwhBk2NCRxhSvbp
!
ip subnet-zero
!
no ip domain-lookup
!
spanning-tree mode pvst
no spanning-tree optimize bpdu transmission
spanning-tree extend system-id
!
!
interface FastEthernet0/1
switchport access vlan 3
switchport mode access
!
interface FastEthernet0/2
switchport access vlan 3
switchport mode access
!
interface FastEthernet0/3
switchport access vlan 2
switchport mode access
!
interface FastEthernet0/4
switchport access vlan 2
switchport mode access
!
interface FastEthernet0/5
switchport access vlan 2
switchport mode access
!
interface FastEthernet0/6
switchport access vlan 2
switchport mode access
interface FastEthernet0/7
switchport access vlan 2
switchport mode access
!
interface FastEthernet0/8
switchport access vlan 2
switchport mode access
!
interface FastEthernet0/9
switchport access vlan 2
switchport mode access
!
interface FastEthernet0/10
switchport access vlan 2
switchport mode access
!
interface FastEthernet0/11
switchport access vlan 2
switchport mode access
!
interface FastEthernet0/12
switchport access vlan 2
switchport mode access
interface FastEthernet0/13
switchport access vlan 2
switchport mode access
!
interface FastEthernet0/14
switchport access vlan 2
switchport mode access
!
interface FastEthernet0/15
switchport access vlan 2
switchport mode access
!
interface FastEthernet0/16
switchport access vlan 2
switchport mode access
!
interface FastEthernet0/17
switchport access vlan 2
switchport mode access
!
interface FastEthernet0/18
switchport access vlan 2
switchport mode access
interface FastEthernet0/19
switchport access vlan 2
switchport mode access
!
interface FastEthernet0/20
switchport access vlan 2
switchport mode access
!
interface FastEthernet0/21
switchport access vlan 2
switchport mode access
!
interface FastEthernet0/22
switchport access vlan 2
switchport mode access
!
interface FastEthernet0/23
switchport access vlan 2
switchport mode access
!
interface FastEthernet0/24
switchport access vlan 2
switchport mode access
interface GigabitEthernet0/1
switchport mode trunk
!
interface GigabitEthernet0/2
switchport mode trunk
!
interface Vlan1
no ip address
no ip route-cache
shutdown
!
interface Vlan2
no ip address
no ip route-cache
!
interface Vlan3
no ip address
no ip route-cache
shutdown
!
ip http server
!
line con 0
login
line vty 0
password
login
line vty 1 4
login
line vty 5 15
login
!
!
end
HP running config....
Switch# show run
Running configuration:
; J9022A Configuration Editor; Created on release #N.11.06
hostname "Switch"
snmp-server contact "Networks"
time timezone 10
mirror-port 10
interface 1
lacp Passive
exit
interface 4
lacp Passive
exit
interface 5
lacp Passive
exit
interface 6
lacp Passive
exit
interface 7
lacp Passive
exit
interface 8
lacp Passive
exit
trunk 2-3 Trk1 Trunk
ip timep manual 192.168.0.1 interval 1
snmp-server community "switch1" Unrestricted
vlan 1
name "DEFAULT_VLAN"
untagged Trk1
no ip address
no untagged 1,4-48
ip proxy-arp
exit
vlan 3
name "Auth Server"
no ip address
tagged 1,4-8
ip proxy-arp
exit
vlan 2
name "Desktops"
untagged 9-48
no ip address
tagged Trk1
ip proxy-arp
exit
vlan 4
name "FTP"
no ip address
exit
vlan 5
name "Wireless"
no ip address
exit
interface 9
monitor
exit
spanning-tree
spanning-tree Trk1 priority 4
password manager
Now it seems that no routing is taking place at the Cisco, you want to replace.
Then it should not be needed with routing and IP helper adress in new HP-switch.
As we now have a config of the old switch, perhaps it is possible to guess how you want the new setup:
config
interface 1-48
no lacp
exit
no trunk 2-3
vlan 1
name "DEFAULT_VLAN"
untagged 47,48
no ip address
no untagged 1-46
no ip proxy-arp
exit
vlan 3
name "Auth Server"
no ip address
untagged 1-2
tagged 47-48
no ip proxy-arp
exit
vlan 2
name "Desktops"
untagged 3-46
no ip address
tagged 47-48
no ip proxy-arp
exit
vlan 4
name "FTP"
no ip address
tagged 47-48
exit
vlan 5
name "Wireless"
tagged 47-48
no ip address
exit
no spanning-tree 47-48 edge-port
spanning-tree 47-48 priority 4
write mem
-here the Astaro Securtiy Gateway V7 can be connnected to port 47 or port 48 (used to be GigabitEthernet0/1 or GigabitEthernet0/2) - all vlans in the links.
-Auth Server on port 1 or port 2 (used to be FastEthernet0/1 or FastEthernet0/2)
-PC's on all other ports
HTH
IPConfig/all from my machine. Windows IP Configuration IpConfig/all from the DHCP Server.</P> 1) Now do i have to give an IP address/Default GW to the switch, if yes then what IP addresses should i define for these. 2)If i have to use the IP helper command how i will use it, means how will i define the IP addresses for this command, should i use these IP's for VLAN2; ip address: 10.50.10.1 255.255.255.0 ip helper-address: 10.50.10.1 and for VLAN3; Ip address: 10.50.11.1 255.255.255.0 ip helper-address: 10.50.11.1 3)I have already posted the scope for the DHCP server yesterday at 04:26PM, now do i have to define any new subnets under the DHCP scope. 4)Do i have to add these subnets under Astaro firewall.
I am not sure if i have to use IP helper or not, anyways i am going to paste ipconfig from my machine and from the DHCP (Microsoft SBS) server, kindly have a look at it, and then i will ask some questions.
Host Name . . . . . . . . . . . . : BNE01-053ws
Primary Dns Suffix . . . . . . . : Company.LOCAL
Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
DNS Suffix Search List. . . . . . : Company.LOCAL
Company.LOCAL
Ethernet adapter Local Area Connection 4:
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : VMware Virtual Ethernet Adapter for
VMnet8
Physical Address. . . . . . . . . : 00-50-56-C0-00-08
Dhcp Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
IP Address. . . . . . . . . . . . : 192.168.11.1
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . :
DHCP Server . . . . . . . . . . . : 192.168.11.254
Primary WINS Server . . . . . . . : 192.168.11.2
Lease Obtained. . . . . . . . . . : Thursday, 17 July 2008 10:24:28
Lease Expires . . . . . . . . . . : Thursday, 17 July 2008 10:54:28
Ethernet adapter Local Area Connection 3:
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : VMware Virtual Ethernet Adapter for
VMnet1
Physical Address. . . . . . . . . : 00-50-56-C0-00-01
Dhcp Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
IP Address. . . . . . . . . . . . : 192.168.204.1
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . :
DHCP Server . . . . . . . . . . . : 192.168.204.254
Lease Obtained. . . . . . . . . . : Thursday, 17 July 2008 10:24:28
Lease Expires . . . . . . . . . . : Thursday, 17 July 2008 10:54:28
Ethernet adapter Local Area Connection:
Connection-specific DNS Suffix . : Company.LOCAL
Description . . . . . . . . . . . : Intel(R) 82566DM-2 Gigabit Network C
onnection
Physical Address. . . . . . . . . : 00-1A-6B-5B-00-68
Dhcp Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
IP Address. . . . . . . . . . . . : 10.50.10.53
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 10.50.10.254
DHCP Server . . . . . . . . . . . : 192.168.0.1
DNS Servers . . . . . . . . . . . : 192.168.0.1
Primary WINS Server . . . . . . . : 192.168.0.1
Lease Obtained. . . . . . . . . . : Tuesday, 15 July 2008 16:37:34
Lease Expires . . . . . . . . . . : Wednesday, 23 July 2008 16:37:34
Ethernet adapter Local Area Connection 2:
Media State . . . . . . . . . . . : Media disconnected
Description . . . . . . . . . . . : TAP-Win32 Adapter V8
Physical Address. . . . . . . . . : 00-FF-4C-89-E8-10
Windows IP Configuration
Host Name . . . . . . . . . . . . : bne01-001sv
Primary Dns Suffix . . . . . . . : Company.LOCAL
Node Type . . . . . . . . . . . . : Unknown
IP Routing Enabled. . . . . . . . : Yes
WINS Proxy Enabled. . . . . . . . : Yes
DNS Suffix Search List. . . . . . : Company.LOCAL
Ethernet adapter Server Local Area Connection:
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Broadcom NetXtreme Gigabit Ethernet
Physical Address. . . . . . . . . : 00-11-09-AF-45-B8
DHCP Enabled. . . . . . . . . . . : No
IP Address. . . . . . . . . . . . : 192.168.0.1
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 192.168.0.254
DNS Servers . . . . . . . . . . . : 192.168.0.1
Primary WINS Server . . . . . . . : 192.168.0.1</SPAN>
hm, take a look here:
ftp://ftp.hp.com/pub/netwo
it is possible, that you will need dhcp server at each vlan :(
Its getting no where....
what if i wont migrate, means i keep both the switches, but i want to link the two switches, how can link both of them, the HP Pro switch provides gigbyte connection so can i link the Cisco switch and pass the VLAN information and connect my desktops to HP switch.
What configuration i need to do on the switches.......
Do i have to set up VLAN's on HP switch?
Also if you have looked at my cisco runinng configuration these two interfaces exist on the switch.
interface GigabitEthernet0/1
switchpo
!
interface GigabitEthernet0/2
switchpo
So if i am not wrong i have to go into config mode on cisco switch and run,
switchport allowed vlans 1-3.
Right.
and on the cisco switch port; 1-2 connects to Auth. Server (VLAN3), and from port 3-24 it connects to desktops (VLAN2), and there are two gigabyte ports which connects to the firewall.
So which port i have to use to connect the cisco switch to the HP switch?
i dont need both the ports to be 1 gig, so you reccom, i should use one of these ports and connect it to the HP switch?, also do i have set any IP addresses or default GW on the HP yes....if yes then which IP's should i give?
Jburgaard; are you refferring to your post that you posted on 7:17.2008 at 8:47, because i cant find the post that you are mentioning....
I am going tp connect to the switch through the serial port, but as you guys said i have to create VLANs on the HP switch, so if i only create VLAN1 as from_exp, suggested how its going to pass the information from both the VLANs on cisco to HP, do i need extra VLAN's setted up on the HP? i am bit confused on which port should i use to connect both the switches, because i will assign the ports on the HP switch for the VLAN,so which port on HP switch should i dedicate for Cisco connection,on which VLAN it should be, or should i leave it without assigning it any VLAN?
Also which port can i use on the Cisco switch to connect it to HP switch,both the firewalls ports are connected to two Unix firewall boxes, so should i use one of them, if i use one of them where i will connect the other firewall port.?or can i use any other port, if i can use any other port then from which VLAN port i can use,
1-2 connects to Auth. Server (VLAN3), and from port 3-24 it connects to desktops (VLAN2), and there are two gigabyte ports which connects to the firewall.
I am planning to test it out today, so please if you can guys help me out before that i would be highly grateful...
Thanks.
hi!
let me explain my vision of your network:
you are going to add additional 48 ports to your network, so I suppose, you can move one of the FW gig ports in cisco to HP gig port.
We need that gig cisco port to interconnect switches. on HP we can use port 48
so cisco port should look like:
conf t
int gi0/1
switchport
switchport mode trunk
switchport allowed vlans 1-3
end
procurve port 48 should be configured accordingly (not a hp expert, sorry ) - tagged with all 3 vlans allowed.
and sure thing procurve should have all 3 vlans created.
I would suggest using port 47 for firewall, so this port should also be tagged with all 3 vlans allowed.
I had a chat with the HP tech, he reccommends that if i take out the gigabyte (FW) port it will take out the network, so he is saying use any other port, but trunk (tag) it,
there are two VLAN's and both the vlans have different subnet's, VLAN2 has 10.50.10.254/24 and VLAN3 has 192.168.0.254/24, now if i use the switchport allowed vlans 1-3 command would it restrict the vlans?And can i use any other port, lets say port 6 which comes under VLAN2, and if i use port 6 on VLAN 2 do i have to do anything on VLAN3 because its a different subnet.
i just thought i will let you know, i will do whatever you say.
if anything goes wrong and i want to take out the "switchport mode trunk" from that port how i will do it, would it be like this
"no switchport mode trunk" (and it will stop broadcasting the information for vlan and it will come back to its original settings.)
hi
to change ports from trunk and back to access:
switchport mode trunk/switchport mode access
switchportr trun allowed vlans 1-3 - if you have more vlans, you have name them also, because when you don't issue this command all vlans are allowed on particular port, however I think that it is not a very good idea to allow all, instead of exactly what you need
you can save cisco's port 6 config and change it to trunk, and then you can paste back saved config to undo changes.
as for gig ports, I don't think that this is a good idea trunking 48 gigs via single 100M port. just imagine oversubscription ratio!
and it is not clear to me, why you can't place one of the FW ports (as I understand both gigs on cisco are used by FWs) to HP...
Thanks.
The tech from HP told me that my network will be disturbed if i take out one of the FW ports from there, he said that after looking at the diagram that i have posted over here as well.
The two firewall ports are already configured as trunk ports, if you look at my cisco config.
interface GigabitEthernet0/1
switchpo
!
interface GigabitEthernet0/2
switchpo
Now the only thing i need to add is this (correct me if i am wrong)
conf t
int gigabitethernet0/2
switchpo
end
and if anything goes wrong and i want to go back to old settings i have to do this;
switchport mode trunk/switchport mode access
right.
and on HP switch i have created two VLAN's, and assign it a default GW of 192.168.0.254/24 (for managebility) if the Default GW is not required let me know.
Also i am going to tag the port 48 on hp switch which comes under all VLAN.
Please let me know if whatever i have written is right.
if i take out one of the firewall ports, and connect it back again it sends out this message;
HA node is now Slave
--
HA Status : HA SLAVE (node id: 2)
System Uptime : 95 days 6 hours 24 minutes
System Load : 0.45
System Version : Astaro Security Gateway 7.104
Please refer to the manual for detailed instructions.
hm...
wrong
so gi0/1 and gi0/2 are interfaces of FW, which works in failover mode.
you don't need to add this
conf t
int gigabitethernet0/2
switchport allowed vlans 1-3
end
if the port is occupied by firewall
however, I would recommend you to make a try to unplug FW (do not make and changes to port), plug your HP port 48(configured as tagged for all needed vlans), and then plug FW to port 47 (also configured tagged for all needed vlans).
after that FWs should be able to sense each other again and you can try to unplug second FW port from cisco to chech if you can reach internet via FW plugged to HP
ok if i got you right you asked me to take out the firewall port from cisco switch, plug in the uplink cable from cisco to the HP port (i.e 48), and the firewall cable that i took out from cisco switch, plug it to hp port #47.
If that doesnt work then i should use the switchport allowed vlans 1-3, command, and if that doesnt work, what shoud i do.
and how i will take out this command that i have run on the cisco switch.
</P>
Business Accounts
Answer for Membership
by: usmansultanPosted on 2008-06-22 at 18:48:49ID: 21843017
Select allOpen in new window