VLAN trunking between ASA and Cat2950

I have 2 sites. The is connected via IpSec VPN with ASA5505. There are roughly 10 servers and 50 work stations connected to the Cat2950s on each site. It is setup as daisy chain in a flat network.

My goal is to remove daisy chain and create vlans for separation.

I defined VLANs and trunked them one of the interface in ASA.
interface Ethernet0/2
description trunk-to-switch1-0/23
 switchport trunk allowed vlan 50,80,100,500,800
 switchport mode trunk

Open in new window

interface FastEthernet0/23
 description uplink-to-asa
 switchport mode trunk
 switchport nonegotiate
 mls qos trust cos
 auto qos voip trust 
 macro description cisco-desktop
 spanning-tree link-type point-to-point

Open in new window

Do I need to define the vlans on all 2950s? Should I use route-on-a stick?
LVL 21
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Don JohnstonInstructorCommented:
Do I need to define the vlans on all 2950s?
The VLANs need to be defined on any switches they will be transiting. The VLANs also need to be allowed on any trunks they will be crossing.

Should I use route-on-a stick?
Hard to say with out more information. If inter-VLANs communication is required, then it will need to be done on a router or the ASA.

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
Mohammed KhawajaManager - Infrastructure:  Information TechnologyCommented:
VLANs must be defined on the switches.  Since you will be using router on a stick, VLANs must be defined for each sub-interface.  This will ensure the PCs can reach the default gateway.
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today

From novice to tech pro — start learning today.