Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people, just like you, are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions

L3 switch (VLAN routing, ACL and failover)

Posted on 2013-02-07
Last Modified: 2013-10-28

In LAN now we have 9 VLANs and traffic between VLANs is controlled by an router (actually is an Astaro UTM).
Because of performance problems we a thinking to move VLAN routing and access control (between VLANs) load on a switch.

So, I'm looking for some recommendations for switch model and configuration.

In short out needs are:
- switch must be capable of VLAN routing
- must have an option to control traffic between VLANs
- option for switch failover
- 24 1GB ports will be enough
- easy accessible support (brandname should be widely used - Cisco?)
- not to costly
- no stacking, PoE, uplink needs

If you need any additional data let me know.
Thanks for your help.
Question by:davorin
  • 3
  • 2
LVL 11

Accepted Solution

rharland2009 earned 332 total points
ID: 38864137
If you purchase Cisco, you will pay somewhat of a premium for a per-port cost and annual Smartnet maintenance. However, their support is indeed easily accessible and quite good.

A good Cisco model that would not be terribly pricey would be the SG500X-24. This is a stackable workgroup switch with full layer 3 capabilities, as well as gig ports (and some 10 gig as well). It's fixed, so 24+4 is as many ports as you'll get. It is stackable, but if you don't need it then you don't.

As far as failover.....not sure what you mean here. With a truly robust infrastructure, this would mean that you have redundancy in your switch links in the core and as far out to the access switch as possible. If this is what your users will be plugging directly into, then switch failover's not really part of the picture.
LVL 27

Author Comment

ID: 38864503
About failover:
We are hosting some services, that are not heavily used they but needs to be online all the time.
We have two internet links to two different ISP providers connected to two Cisco C3800 series routers (own C class network of public IP adresses, BGP), connected to two Astaro 200 UMT in HA. Servers are located on fully redundant equipment (hyper-v cluster on HP Blades and EVA4400 storage).
If I don't count servers, there are around 60 devices on LAN, but their connectivity is not essential and they will remain connected to a couple of managed L2 "workgroup" switches.
If one L3 switch dies, then the other must take all the job automatically.
I don't know if SG500X belongs to Linksys series of Cisco switches, but I have really bad experience with Linksys. One SGE2000 I'm using now like flowers stand ;)
LVL 11

Assisted Solution

rharland2009 earned 332 total points
ID: 38864602
I'd say, then, that you're looking for something a little more robust than a simple workgroup switch. Buy a couple of 3750-x or similar chassis and run HSRP.
Connect further...control easier

With the ATEN CE624, you can now enjoy a high-quality visual experience powered by HDBaseT technology and the convenience of a single Cat6 cable to transmit uncompressed video with zero latency and multi-streaming for dual-view applications where remote access is required.

LVL 18

Assisted Solution

Akinsd earned 168 total points
ID: 38865386
You also have options of GLBP on the switch which I always recommend. This gives you ability to use both uplinks while providing automatic failover in case one link goes down. The additional advantage is is load balances thereby easing process cycles. GLBP - Gateway Load Balance Protocol. It does everything HSRP does and more but only available in high end newer models.

Additional advice is to turn IP routing on the distribution switches and enable IP CEF.

Finally, take advantage of ether channels (bundle multiple ports together).

You will receive a Grammy for such implementation as described above

All the best
LVL 27

Author Comment

ID: 38881602
Thanks both of you for answers. I was waiting for some additional comments/ideas but I guess the question is to old to be seen by anybody else.

HSRP and GLBP are great ideas and also the type of ideas I was looking for.
Unfortunately GLBP is not supported on 3560X or 3750x.

My first choice before posting the question was 3560X, because I don't need stacking. From what I have seen it can suite our needs. Am I right?
Would you consider any other brand? HP? I have contacted some other brand representatives, but presales technical support was not so "impressive".
LVL 27

Author Closing Comment

ID: 39606411
Thank you for your help. Sorry for closing the question so late.

Featured Post

VMware Disaster Recovery and Data Protection

In this expert guide, you’ll learn about the components of a Modern Data Center. You will use cases for the value-added capabilities of Veeam®, including combining backup and replication for VMware disaster recovery and using replication for data center migration.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Even if you have implemented a Mobile Device Management solution company wide, it is a good idea to make sure you are taking into account all of the major risks to your electronic protected health information (ePHI).
In this article, I am going to show you how to simulate a multi-site Lab environment on a single Hyper-V host. I use this method successfully in my own lab to simulate three fully routed global AD Sites on a Windows 10 Hyper-V host.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

840 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question