Solved

HP Procurve Switching

Posted on 2013-01-31
5
212 Views
Last Modified: 2013-01-31
Hi All.

Does anyone know the commands to isolate a single vlan from another on HP procurve switches?

I want to create two networks but don't want them to be able to touch one another.  However, I would like them to route out the same firewall.

Anyhelp is appreciated.

Thanks.
Lou
0
Comment
Question by:LouHabes
  • 3
  • 2
5 Comments
 
LVL 7

Accepted Solution

by:
avcontrol earned 500 total points
ID: 38840162
Inter Swtiches links should be in Trunk.....
vlan 1
   name "Switch Managment"
   tagged "ports to switch A and D"
   exit
vlan 2
   name "IP cameras"
   tagged "ports to switch A and D"
your config, should looks like below:

Config t

vlan 1
   name "Switch Managment"
   ip address 192.168.1.100 255.255.255.0
   tagged 25-28
   exit
vlan 2
   name "IP cameras"
   untagged 1-12
   ip address 192.168.0.1 255.255.255.0
   tagged 25-28
   exit


This is just simplified example, you can insert your own values.
0
 

Author Comment

by:LouHabes
ID: 38840264
Right, I have a similar test config.  However I dont want them to be able to ping one another.  Thanks for your help.  


vlan 5
   name "test"
   untagged B1
   ip address 192.168.100.1 255.255.255.0
   tagged A1-A4
   exit
vlan 6
   name "Test2"
   untagged D24
   ip address 192.168.101.1 255.255.255.0
   tagged A1-A4
0
 
LVL 7

Expert Comment

by:avcontrol
ID: 38840294
They should not be able ping each if they are not routed by L3.......
Also if you using VLAN, then difrent subnet should have diffrent ports, in your confifgs, looks like you tagging same ports twice.......
Can you post diagram and router configs?
0
 

Author Comment

by:LouHabes
ID: 38841120
I really dont have much, I am trying to get off an old intel 550 routing switch that houses the VLANs and trunkports.  I did enable routing between them thanks for pointing out

  Currently through that switch the vlans are isolated but access the net through the same router.

I guess I would just assign two seperate trunk ports from the router to each vlan once I confirm they cannot ping one another?

Thanks Again AVCONTROL.
0
 
LVL 7

Assisted Solution

by:avcontrol
avcontrol earned 500 total points
ID: 38841175
Yes, either trunk or taged with same VLAN id.
As long there is no routing for those two subnet in L3 device and both VLAN aggregated before coming int L3, they should not be able see each other.
In other word enabling routing for those two subnet you will make them see each other.
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I see many questions here on Experts Exchange regarding switch port configurations and trunks. This article is meant for beginners in the subject to help to get basic knowledge about Virtual Local Area Network (VLAN (http://en.wikipedia.org/wiki/Vir…
This tutorial will go through the steps required to write a script that will back up the configuration settings of a HP-ProCurve switch. You will need to get the following things to follow this tutorial: Telnet Scripting Tool e.g. TST10.exe …
Email security requires an ever evolving service that stays up to date with counter-evolving threats. The Email Laundry perform Research and Development to ensure their email security service evolves faster than cyber criminals. We apply our Threat…

831 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question