?
Solved

HP Procurve msm765zl and 5406zl vlan configuration

Posted on 2012-04-04
2
Medium Priority
?
1,620 Views
Last Modified: 2012-04-10
we have x2 5406zl core switches linked with 10b links (trunked) and msm765zl wireless controller and need to change ip addressing from 10.10.1.0/16 to 10.10.1.0/24, 10.10.2.0/24 for example. we would like each subnet to be on its own vlans as at present everything is in one broadcast domain (including the wifi) to do this we need to
-create dhcp scopes for each subnet on the dhcp server
-add ip helper lines to each vlan config (pointing to dhcp server)
-enable ip routing on the core switches
-tag all core switch ports with vlans which will require access and tag the trunks to the outer switches with any vlans which will be used
- the main issue is how do i change the wifi controller to tunnel access point traffic directly to it rather than simply authenticating users and giving them direct access to the network on whichever switch the wifi point is connected.
- i would like to have for example 1 ssid which is employess (with access to say vlan10,20) and another ssid which is guest with only access to say vlan10). in capture1.png you can see the authentication option is selected but not the access control, effectively when that is selected the traffic is tunnelled to the controller. i need to know
A- how to setup the dhcp relay so that it will give the access points an ip address and the clients connected the correct ip based on vlan
B- how to handle the traffic when it reaches the controller, i believe this is the VSC egress settings??

please ask if i need to make anything clearer or if you need more info
Capture1.PNG
0
Comment
Question by:active8it
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
2 Comments
 
LVL 6

Accepted Solution

by:
RKinsp earned 1500 total points
ID: 37812066
Ok, start out by adding a VLAN in Controller-> Network -> Ports. For a VLAN to be valid for egress, it needs to have an IP address.

On your VSC, select "ACCESS CONTROL", this will force the traffic to go to the controller - note that this is not recommended for voice video. You might want to have some users on non-access controlled vcs.

You can then set your egress VLAN/network on the VSC setup page (see image).

According to the manual, you can also "A separate DHCP relay agent can be enabled on each VSC to provide custom addressing to users.", however i'm not sure where this setting is. I believe you have to have DHCP relay agent on global then set it on the VSC. Please note that the default VSC will always use the main DHCP relay agent.

Please note that for each VSC/VLAN, the IP address for that VLAN will be what the device sending to your DHCP server.

Does this cover your questions?

Good luck,
RK
egress-vlan.jpg
0
 
LVL 6

Expert Comment

by:RKinsp
ID: 37812693
Oh, and DHCP relay is global from Controller->Network -> address allocation
0

Featured Post

Four New Appliances. Same Industry-leading Speeds.

But don't take it from us.  The Firebox M370 is Miercom tested and Miercom approved, outperforming its competitors for stateless and stateful traffic throughput scenarios.  Learn more about the M370, M470, M570 and M670 and find the right solution for your organization today!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

When asking a question in a forum or creating documentation, screenshots are vital tools that can convey a lot more information and save you and your reader a lot of time
This article provides a convenient collection of links to Microsoft provided Security Patches for operating systems that have reached their End of Life support cycle. Included operating systems covered by this article are Windows XP,  Windows Server…
Viewers will learn how to connect to a wireless network using the network security key. They will also learn how to access the IP address and DNS server for connections that must be done manually. After setting up a router, find the network security…
With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…
Suggested Courses

752 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question