Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

HP Procurve Switching

Posted on 2013-01-31
5
Medium Priority
?
226 Views
Last Modified: 2013-01-31
Hi All.

Does anyone know the commands to isolate a single vlan from another on HP procurve switches?

I want to create two networks but don't want them to be able to touch one another.  However, I would like them to route out the same firewall.

Anyhelp is appreciated.

Thanks.
Lou
0
Comment
Question by:LouHabes
  • 3
  • 2
5 Comments
 
LVL 7

Accepted Solution

by:
avcontrol earned 1500 total points
ID: 38840162
Inter Swtiches links should be in Trunk.....
vlan 1
   name "Switch Managment"
   tagged "ports to switch A and D"
   exit
vlan 2
   name "IP cameras"
   tagged "ports to switch A and D"
your config, should looks like below:

Config t

vlan 1
   name "Switch Managment"
   ip address 192.168.1.100 255.255.255.0
   tagged 25-28
   exit
vlan 2
   name "IP cameras"
   untagged 1-12
   ip address 192.168.0.1 255.255.255.0
   tagged 25-28
   exit


This is just simplified example, you can insert your own values.
0
 

Author Comment

by:LouHabes
ID: 38840264
Right, I have a similar test config.  However I dont want them to be able to ping one another.  Thanks for your help.  


vlan 5
   name "test"
   untagged B1
   ip address 192.168.100.1 255.255.255.0
   tagged A1-A4
   exit
vlan 6
   name "Test2"
   untagged D24
   ip address 192.168.101.1 255.255.255.0
   tagged A1-A4
0
 
LVL 7

Expert Comment

by:avcontrol
ID: 38840294
They should not be able ping each if they are not routed by L3.......
Also if you using VLAN, then difrent subnet should have diffrent ports, in your confifgs, looks like you tagging same ports twice.......
Can you post diagram and router configs?
0
 

Author Comment

by:LouHabes
ID: 38841120
I really dont have much, I am trying to get off an old intel 550 routing switch that houses the VLANs and trunkports.  I did enable routing between them thanks for pointing out

  Currently through that switch the vlans are isolated but access the net through the same router.

I guess I would just assign two seperate trunk ports from the router to each vlan once I confirm they cannot ping one another?

Thanks Again AVCONTROL.
0
 
LVL 7

Assisted Solution

by:avcontrol
avcontrol earned 1500 total points
ID: 38841175
Yes, either trunk or taged with same VLAN id.
As long there is no routing for those two subnet in L3 device and both VLAN aggregated before coming int L3, they should not be able see each other.
In other word enabling routing for those two subnet you will make them see each other.
0

Featured Post

Ask an Anonymous Question!

Don't feel intimidated by what you don't know. Ask your question anonymously. It's easy! Learn more and upgrade.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

WARNING:   If you follow the instructions here, you will wipe out your VTP and VLAN configurations.  Make sure you have backed up your switch!!! I recently had some issues with a few low-end Cisco routers (RV325) and I opened a case with Cisco TA…
In this article, the configuration steps in Zabbix to monitor devices via SNMP will be discussed with some real examples on Cisco Router/Switch, Catalyst Switch, NAS Synology device.
This video shows how to quickly and easily deploy an email signature for all users in Office 365 and prevent it from being added to replies and forwards. (the resulting signature is applied on the server level in Exchange Online) The email signat…
We’ve all felt that sense of false security before—locking down external access to a database or component and feeling like we’ve done all we need to do to secure company data. But that feeling is fleeting. Attacks these days can happen in many w…

886 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question