Solved

management vlan interface

Posted on 2013-11-28
6
477 Views
Last Modified: 2013-12-02
I'm looking at some instructions from Cisco's website and I'm confused about it. I thought that creating a vlan interface was only for management purposes? Can someone explain? So, does that mean that if I want to access the switch via IP then I need to create an interface with a vlan?

Also, in the example below the management vlan receives a subnet mask and the switch its self doesn't?

!-- Set the IP address and default gateway for VLAN1 for management purposes.

3512xl#configure terminal
Enter configuration commands, one per line. End with CNTL/Z.
3512xl(config)#int vlan 1
3512xl(config-if)#ip address 10.10.10.2 255.255.255.0
3512xl(config-if)#exit
3512xl(config)#ip default-gateway 10.10.10.1
3512xl(config)#end
0
Comment
Question by:tolinrome
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
6 Comments
 
LVL 18

Expert Comment

by:Akinsd
ID: 39684595
Yes but that's just one of the purposes of vlans.

Every port on a switch belongs to VLAN 1 by default. You can then add multiple vlans as needed if you have multiple subnets.

This works by assigning switchports to VLAN you want them to belong to. Eg VLAN 1 - Sales department. VLAN 2 - Marketting, VLAN 3 - Guest network. VLAN 4 - Management VLAN etc

In short, vlans are used for the following purposes
- Management
- Isolation or Security
- Administration
0
 
LVL 12

Accepted Solution

by:
Infamus earned 250 total points
ID: 39684706
The IP of VLAN interface also can be used as a default gateway of the devices that are belong to the same VLAN.
0
 
LVL 46

Assisted Solution

by:Craig Beck
Craig Beck earned 250 total points
ID: 39685240
A traditional layer-2 switch usually has one SVI only.  This is used as the management interface.  That SVI is a virtual interface which is linked to a VLAN, so if you want the switch management interface to be on VLAN 100 you would have this:

vlan 100
!
interface vlan 1
 no ip address
!
interface vlan 100
 ip address 10.0.0.1 255.255.255.0
!


You don't need to have a default gateway on the switch unless you want to be able to reach the IP address of the switch from a different subnet.

Layer-3 switches do things a little bit differently.  Because Layer-3 switches have routing capabilities you can have more than one SVI configured with an IP address.  This means that the switch management GUI or CLI could be accessible via multiple IP addresses if the switch is being used as a router.
0
Are You Using the Best Web Development Editor?

The worlds of web hosting and web development are constantly evolving. Every year we see design trends change, coding standards adapt and new frameworks/CMS created. With such a quick pace of change it’s easy to get lost trying to keep up.

See if your editor made the list.

 
LVL 7

Author Comment

by:tolinrome
ID: 39686922
ok, I understand what VLANS are. Its the IP on the vlan interface vs the default gateway IP of the switch. In the example I posted there is a IP for the default gateway of the switch and an IP for the VLAN interface.

So to clear things up. There can only be one vlan interface on a switch or network and that is used for management purposes of the network equipment on that subnet.

The switch has an IP address for the default gateway its self?

If I have 5 vlans on the switch then I would need 5 default gateways no?
0
 
LVL 46

Expert Comment

by:Craig Beck
ID: 39686930
The switch has a default gateway for the same reason a PC has one... to send traffic (from itself, not from connected hosts) to different subnets other than the one it's management interface is on.

If you have a normal switch (layer2 only) you would not have an IP address on each VLAN.  You would only have an IP address on one VLAN.  You might have a default gateway address, but you don't have to if you don't want hosts on other subnets to be able to talk to the switch.
0
 
LVL 18

Expert Comment

by:Akinsd
ID: 39687153
You can't have 5 default gateways on a switch perse but you can have multiple default routes if you have a layer 3 switch. Network devices use default gateways to automatically generate default routes. Network devices will only allow you to enter 1 default gateway.

Default gateway is a way to tell the device its main exit door when it tries to exit it's network.
0.0.0.0 0.0.0.0 10.10.10.1

You can assign multiple IP addresses for a switch but technically, a management vlan would be the vlan you would assign gateway for. Let me explain. If your management vlan 10.10.10.0 /24 and you have multiple addresses like 10.10.11.0 /24, 10.10.12.0 /24 etc you can assign the following IP addresses to the switch, 10.10.11.2 /24, 10.10.12.2 /24. The gateway you would assign in global mode therefore would be 10.10.10.1.

For a layer 2 switch, only 1 int vlan is active at a given time (1 SVI as craigbeck mentioned)and this should be your 10.10.10.0 /24 subnet.

For layer 3 switches, all int vlans can be active at the same time meaning you have the ability to communicate or telnet to the switch using any of the assigned address 10.10.10.2, 10.10.11.2 or 10.10.12.2 as long as you have a default gateway and a switchport assigned (generally but I won't go deeper into that to avoid confusion).

Going back to your original question. A management vlan is not written in stone. It is any vlan you choose to manage your devices with. You can change your management vlan on the fly as you wish.

Like I usually emphasise, breaking the terminology down in English terms usually creates clarity.
Management VLAN = Management Virtual Local Area Network = The Virtual Local Area Network that I choose to manage my devices with.

I hope this helps
0

Featured Post

Optimum High-Definition Video Viewing and Control

The ATEN VM0404HA 4x4 4K HDMI Matrix Switch supports 4K resolutions of UHD (3840 x 2160) and DCI (4096 x 2160) with refresh rates of 30 Hz (4:4:4) and 60 Hz (4:2:0). It is ideal for applications where the routing of 4K digital signals is required.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

WARNING:   If you follow the instructions here, you will wipe out your VTP and VLAN configurations.  Make sure you have backed up your switch!!! I recently had some issues with a few low-end Cisco routers (RV325) and I opened a case with Cisco TA…
Powerful tools can do wonders, but only in the right hands.  Nowhere is this more obvious than with the cloud.
In this video we outline the Physical Segments view of NetCrunch network monitor. By following this brief how-to video, you will be able to learn how NetCrunch visualizes your network, how granular is the information collected, as well as where to f…
Monitoring a network: why having a policy is the best policy? Michael Kulchisky, MCSE, MCSA, MCP, VTSP, VSP, CCSP outlines the enormous benefits of having a policy-based approach when monitoring medium and large networks. Software utilized in this v…
Suggested Courses
Course of the Month11 days, 17 hours left to enroll

623 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question