Solved

Cisco 3400 Metro Switch Configuration help

Posted on 2010-11-24
3
1,168 Views
Last Modified: 2012-05-10
Wondering is someone can help me out here.  We just had a Cogent Layer 3 fiber service dropped into our office and they told us to get a Cisco 3400 Layer 3 Switch to work with the service.  We picked up the Cisco ME-3400-24TS-A switch.  I have upgraded the FW to the latest MetroIPAccess build.

We have two blocks of ip's from Cogent (ip's changed to mask the real ones), they provided the following

178.204.251.44/30
178.204.251.45 (Cogent Router)
178.204.251.46 (Our Router IP and attached to FasterEthernet 0/1 on Cisco)
255.255.255.252

They also provided a second block with the following ips
178.213.182.128/25
255.255.255.128

I have successfully configured FastEthernet 0/1 to work with the assigned router and ip address and I can ping all ip's outside our network and I can connect to the switch from the outside via the .46 ip.  I used a static route :
ip route 0.0.0.0 0.0.0.0 178.204.251.45

So questions now, how do I get the second block of ip's to work?  I am assuming I need to assign an ip on the switch to be my gateway ip for the 138.213.182.128 and route the ip traffic to the cogent router 178.204.251.45

How do I setup the rest of the ethernet ports so that I can just plug a firewall into any port and assign a static ip from the 138.213.182.128/25  I know I have to run a no shutdown command and no switch on the ports I want to use.

Please let me know if you need anymore info to help out!

Thanks so much
0
Comment
Question by:jennajdev
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 9

Expert Comment

by:DanJ
ID: 34212552
You got a second block of IPs as the first one is only for the switch and their PE router. The second block is for your organization.
On the switch you need to configure one port as routed port:
no switchport
ip address x.x.x.x
no shut

and assign a second IP from the range to the ASA. ASA will have the default route the address on the switch.
0
 

Author Comment

by:jennajdev
ID: 34217933
I got it working using a VLAN setting the ip of the vlan to 178.213.182.129 so that it would be the route/gateway of that subnet.  I then added the vlan all the ports except 0/1 as that one is used for the fiber connection.  I can now add servers/firewalls with public ip's from the 178.213.182.128/25 block.  

However I am having a big issue with this setup hopefully you can help, I can not access any devices on the vlan from each other.  So if I have two firewalls one 178.213.182.130 the other 178.213.182.254 I can not ping them or access them.  I can ping them both from the switch and from outside the network.  When I do a tracert from one of the firewalls to the other it never leaves the firewall, it bounces twice on the firewall and dies.... Not sure where to go on this one please help.
0
 
LVL 9

Accepted Solution

by:
DanJ earned 500 total points
ID: 34218121
this is the default mode for the uni-vlan and is called isolated. for communication between ports enable community mode fro the vlan

conf t
vlan vlan_number
uni-vlan community
0

Featured Post

What is SQL Server and how does it work?

The purpose of this paper is to provide you background on SQL Server. It’s your self-study guide for learning fundamentals. It includes both the history of SQL and its technical basics. Concepts and definitions will form the solid foundation of your future DBA expertise.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Adnexus.net keeps getting hit from OpenDNS 12 61
Bandwidth cap???? 8 61
Boot Camp 3 59
Cisco SPA525G2 - Stuck on Cisco Screen 3 19
For many of us, the  holiday season kindles the natural urge to give back to our friends, family members and communities. While it's easy for friends to notice the impact of such deeds, understanding the contributions of businesses and enterprises i…
For months I had no idea how to 'discover' the IP address of the other end of a link (without asking someone who knows), and it drove me batty. Think about it. You can't use Cisco Discovery Protocol (CDP) because it's not implemented on the ASAs.…
Viewers will learn how to connect to a wireless network using the network security key. They will also learn how to access the IP address and DNS server for connections that must be done manually. After setting up a router, find the network security…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …

749 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question