L3 switch (VLAN routing, ACL and failover)

Posted on 2013-02-07
Last Modified: 2013-10-28

In LAN now we have 9 VLANs and traffic between VLANs is controlled by an router (actually is an Astaro UTM).
Because of performance problems we a thinking to move VLAN routing and access control (between VLANs) load on a switch.

So, I'm looking for some recommendations for switch model and configuration.

In short out needs are:
- switch must be capable of VLAN routing
- must have an option to control traffic between VLANs
- option for switch failover
- 24 1GB ports will be enough
- easy accessible support (brandname should be widely used - Cisco?)
- not to costly
- no stacking, PoE, uplink needs

If you need any additional data let me know.
Thanks for your help.
Question by:davorin
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
LVL 11

Accepted Solution

rharland2009 earned 332 total points
ID: 38864137
If you purchase Cisco, you will pay somewhat of a premium for a per-port cost and annual Smartnet maintenance. However, their support is indeed easily accessible and quite good.

A good Cisco model that would not be terribly pricey would be the SG500X-24. This is a stackable workgroup switch with full layer 3 capabilities, as well as gig ports (and some 10 gig as well). It's fixed, so 24+4 is as many ports as you'll get. It is stackable, but if you don't need it then you don't.

As far as failover.....not sure what you mean here. With a truly robust infrastructure, this would mean that you have redundancy in your switch links in the core and as far out to the access switch as possible. If this is what your users will be plugging directly into, then switch failover's not really part of the picture.
LVL 27

Author Comment

ID: 38864503
About failover:
We are hosting some services, that are not heavily used they but needs to be online all the time.
We have two internet links to two different ISP providers connected to two Cisco C3800 series routers (own C class network of public IP adresses, BGP), connected to two Astaro 200 UMT in HA. Servers are located on fully redundant equipment (hyper-v cluster on HP Blades and EVA4400 storage).
If I don't count servers, there are around 60 devices on LAN, but their connectivity is not essential and they will remain connected to a couple of managed L2 "workgroup" switches.
If one L3 switch dies, then the other must take all the job automatically.
I don't know if SG500X belongs to Linksys series of Cisco switches, but I have really bad experience with Linksys. One SGE2000 I'm using now like flowers stand ;)
LVL 11

Assisted Solution

rharland2009 earned 332 total points
ID: 38864602
I'd say, then, that you're looking for something a little more robust than a simple workgroup switch. Buy a couple of 3750-x or similar chassis and run HSRP.
Don't Miss ATEN at InfoComm 2017!

Visit booth #2167 to see the  new ATEN VM3200 32 x 32 Modular Matrix Switch. Other highlights include the VE8950 4K HDMI Over IP Extender, VS1912 12-Port DP Video Wall Media Player  and VK2100 ATEN Control System. Register now with Free Pass Code ATEN288!

LVL 18

Assisted Solution

Akinsd earned 168 total points
ID: 38865386
You also have options of GLBP on the switch which I always recommend. This gives you ability to use both uplinks while providing automatic failover in case one link goes down. The additional advantage is is load balances thereby easing process cycles. GLBP - Gateway Load Balance Protocol. It does everything HSRP does and more but only available in high end newer models.

Additional advice is to turn IP routing on the distribution switches and enable IP CEF.

Finally, take advantage of ether channels (bundle multiple ports together).

You will receive a Grammy for such implementation as described above

All the best
LVL 27

Author Comment

ID: 38881602
Thanks both of you for answers. I was waiting for some additional comments/ideas but I guess the question is to old to be seen by anybody else.

HSRP and GLBP are great ideas and also the type of ideas I was looking for.
Unfortunately GLBP is not supported on 3560X or 3750x.

My first choice before posting the question was 3560X, because I don't need stacking. From what I have seen it can suite our needs. Am I right?
Would you consider any other brand? HP? I have contacted some other brand representatives, but presales technical support was not so "impressive".
LVL 27

Author Closing Comment

ID: 39606411
Thank you for your help. Sorry for closing the question so late.

Featured Post

Announcing the Most Valuable Experts of 2016

MVEs are more concerned with the satisfaction of those they help than with the considerable points they can earn. They are the types of people you feel privileged to call colleagues. Join us in honoring this amazing group of Experts.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Data center, now-a-days, is referred as the home of all the advanced technologies. In-fact, most of the businesses are now establishing their entire organizational structure around the IT capabilities.
This article is a collection of issues that people face from time to time and possible solutions to those issues. I hope you enjoy reading it.
After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor ( If you're interested in additional methods for monitoring bandwidt…

752 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question