Solved

How to Bridge two VLANs on a Cisco 6509 and eliminate STP issues

Posted on 2012-03-25
7
1,046 Views
Last Modified: 2012-04-02
I have a pair of application firewalls that are logically inline to two VLANs on a pair of Cisco 6509 switches. The application FW's are doing transparent bridging between the two VLANs, and I need to remove them from the equation to upgrade them (and then post upgrade completion place them back inline). The application firewalls are in active passive mode and each one is connected to a different 6509 also in an active/passive configuration. The app firewalls have three ports involved. A management port that you connect to the appliance through and two bridge ports where each bridge port is configured to a different VLAN placing the appliance logically inline. I proposed the following config to make the two VLANs bridge themselves while minimizing STP bridge loop issues:

interface Vlan50
bridge-group 1
!
interface Vlan821
bridge-group 1
!
bridge 1 protocol vlan-bridge
bridge 1 priority 8192

The last line is what is supposed to minimize possible STP bridge loops according to Cisco online documentation I found. The onsite CCIE says he's not sure this will work, hence my question. I'm asking you all to vette out this problem and either verify my code will work or propose code that will.

Please help.
0
Comment
Question by:Sec-Man
  • 3
  • 2
  • 2
7 Comments
 
LVL 15

Expert Comment

by:Nayyar HH (CCIE RS)
ID: 37763421
I dont think you should have to bridge these vlans on the switch, the firewall should be bridging the traffic as it is in transparent mode.

What type of firewall is it?

Can you provide a logical diagram?
0
 
LVL 3

Assisted Solution

by:Sec-Man
Sec-Man earned 0 total points
ID: 37763441
Please re-read everything I explained as your questions are already answered by the givens I have already laid out, but in the interests of resolution I will re-answer your questions

The very first sentence explained that this is an application FW (The manufacturer is irrelevant since the question I'm asking is how do you bridge two VLANs on a Cisco 6509 together)... Further...the application FW is bridging the two VLANs, but since as I explained the issue is that I have to upgrade the application FW it cannot bridge while its being upgraded because that would cause an outage...

I dont need to attach a logical diagram since I already explained that the application firewall bridges two VLANs:

(VLAN 50) <-> Bridged App FW <-> (VLAN 821)
0
 
LVL 15

Expert Comment

by:Nayyar HH (CCIE RS)
ID: 37763451
I'm afraid I cannot help you - I'm sure other Experts will be answering your question


Thank you

CCIE/RS/#3476_
0
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

 
LVL 10

Expert Comment

by:mat1458
ID: 37764343
Your configuration looks pretty reasonable to me. Have you set any root bridges other than the default in your VLAN? For testing purposes I'd use two unused VLAN to see if everthing works the way you like. You don't have to use a looped topology with these, then you can test the forwarding only.
0
 
LVL 3

Author Comment

by:Sec-Man
ID: 37765461
Therein is one of my issues which is that I have no test environment. I was hoping either someone has already done this and had some "gotchas" or a "try this" to avoid...etc. Whats the commands again to determine whats the root bridge? I'm not at work to look into that yet, but I will when I get there. What are we trying to determine with what's the root bridge?
0
 
LVL 10

Accepted Solution

by:
mat1458 earned 250 total points
ID: 37766217
To find the root bridge you can issue a show spanning-tree vlan nnnn. If the root bridge is somewhere around 32000 you probably have all left to default. If it is lower then somebody has set a root bridge on purpose. By identifying the root port you can find out the next upstream switch.

I'd test on the 6500 by just adding two vlan that are not yet in use. then i'd confiugure vlan interfaces and implement the bridging. Finally i'd connect two PCs each in one of the new vlan, assign them an IP address of the same subnet. I'd make sure that no firewall prevents a ping test and with that it should be possible to test the forwarding part with the bridge statements.
0
 
LVL 3

Author Closing Comment

by:Sec-Man
ID: 37795058
We didnt go forward with bridging the two VLANs together so I have accepted your answer as partial, but I'm fairly certain my code would have worked.
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

There are two basic ways to configure a static route for Cisco IOS devices. I've written this article to highlight a case study comparing the configuration of a static route using the next-hop IP and the configuration of a static route using an outg…
Security is one of the biggest concerns when moving and migrating your data from your on-premise location to the Public Cloud.  Where is your data? Who can access it? Will it be safe from accidental deletion?  All of these questions and more are imp…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

910 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

22 Experts available now in Live!

Get 1:1 Help Now