Solved

layer 2 and 3 switches

Posted on 2013-12-04
10
468 Views
Last Modified: 2013-12-10
Hello,
I would like to have a nice explanation on a couple of things regarding layer 2 & 3 switches. The last time I asked this question it kind of went in different directions, so to avoid that I'll try and be clearer. These things below are what I do not need explanations on (followed below that I will explain what I need to understand better). What I do not need explanations on:
- I understand what vlans are
- I understand the difference between layer 2 & 3 switches
- I know what vlan trunking\tagging is
- I know what a default gateway is
- I understand that Layer 3 switches does the IP routing and layer 2 doesn't (mac addresses).

What I need to understand clearly is:

When I look at a layer 2 switch (show run) I see that the default vlan1 has no ip address and is shut down, a new vlan was created vlan10 and this vlan was given an IP address and default gateway. But the switch its self was given an IP address as well.

For ex:
interface Vlan1
 no ip address
 shutdown
!
interface Vlan10
 ip address 10.10.50.2 255.255.255.0
 ip helper-address 10.10.50.101
 no ip route-cache
!
ip default-gateway 10.10.50.20

So I'm assuming the default gateway for the pc's that connect to this switch is 10.10.50.20 which is also the IP of the inside interface of the firewall.

So if that is correct then this is what I don't understand:
Why is there an IP for interface and DG address for vlan10?
Why do I read that there can only be 1 management vlan per switch? What do they specifically mean by management vlan? There has to be obviously an IP address to telnet into (10.10.40.2)? But if its used for management only why then are almost all the interfaces associated with that vlan10?

Shouldn't there be a vlan interface to access the switch and another vlan for all the computers to associate with?

So basically I need to understand better the concept of interface vlan and management vlan and ip default gateway.

Thanks!
0
Comment
Question by:tolinrome
  • 4
  • 3
  • 2
  • +1
10 Comments
 
LVL 2

Expert Comment

by:SpencerScannell
ID: 39696363
Well, the interface vlan 10 is what you would set the default gateway to the devices on vlan 10. So for the computers it would be 10.10.50.2. You typically make a different "Switched Virtual Interface" for every vlan and set that as the default gateway for the devices on that vlan. If the switch is only in layer 2 then the ip default gateway command is used. If it is in layer 3 there will either be a route for traffic or the ip route command will be used Hope this helps clarify things a little bit.
0
 
LVL 7

Author Comment

by:tolinrome
ID: 39696405
Is that the standard way of doing things? The devices that are part of vlan10 are using as their default gateway the address that is ip default-gateway 10.10.50.20 and all is working. I still need an explanation, also about the management vlan etc.
Thanks.
0
 
LVL 2

Expert Comment

by:SpencerScannell
ID: 39696465
That's because all traffic is being sent to .20.
The way I do it is a different subnet for each VLAN, and then a different subnet between the switch and router. As far as I know the management VLAN is for an out of band way to send management traffic on a different VLAN than normal user traffic.
0
Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 
LVL 7

Author Comment

by:tolinrome
ID: 39696750
Right but how does the switch know if I have more than one management vlan, I can create 50 vlans if I want
0
 
LVL 2

Assisted Solution

by:SpencerScannell
SpencerScannell earned 250 total points
ID: 39696815
Right, you can. The reason you can only have one management VLAN on a switch is because a purely layer 2 switch only can assign an IP to VLAN 1. In a multi-layer switch you can have as many as you want. However, people typically only use one, if at all.
0
 
LVL 50

Accepted Solution

by:
Don Johnston earned 250 total points
ID: 39698220
Right but how does the switch know if I have more than one management vlan, I can create 50 vlans if I want

Technically, (on Catalyst switches), there is no "management" VLAN.  All VLANs are the same. Which one you chose to use for management is just a decision that you make.  On layer-2 switches, only one SVI can be active at any one time. The only purpose of that SVI is for switch management.  Which, by extension, would make that VLAN the management VLAN.  But that VLAN could also be one of the regular data VLANs.

At the end of the day, the VLAN that you chose for management is an in-band management path. The only true out-of-band management port is the console port. Now on Nexus switches, there is an out-of-management port.
0
 
LVL 12

Expert Comment

by:Infamus
ID: 39699399
Now on Nexus switches, there is an out-of-management port.
Typo..    :-)
0
 
LVL 7

Author Comment

by:tolinrome
ID: 39701432
spenserscannell - On your first respone:

"Well, the interface vlan 10 is what you would set the default gateway to the devices on vlan 10. So for the computers it would be 10.10.50.2. You typically make a different "Switched Virtual Interface" for every vlan and set that as the default gateway for the devices on that vlan. (Is this layer 3?)

If the switch is only in layer 2 then the ip default gateway command is used. (Layer 2)

If it is in layer 3 there will either be a route for traffic or the ip route command will be used Hope this helps clarify things a little bit. " (Layer 3)

Correct?
--------------------------------------------------------------------------------------------------------------------------

Yes, its a layer 2 switch I'm talking about. I understand now what youre saying but, what confuses me is that are the clients looking to the switch as their default gateway or the firewall? The firewall inside IP is 10.10.50.20, which is the ip default-gateway of the layer 2 switch. So I'm assuming then that that is just the IP the switch uses (just like the pcs in vlan10 for their default gateway). Correct?

And if its a layer 3 switch and I have say 5 vlans, I will then have 5 vlan interfaces with all their own default gateways corresponding to the subet their on.

It seems that the example I wrote in the question is using the interface vlan 10 as their management interface (IP) and the vlan for the clients as well.
Correct?



donjohnston - thanks for the explanation on the management vlan, totally got that now.
0
 
LVL 7

Author Comment

by:tolinrome
ID: 39709993
anyone?
0
 
LVL 50

Expert Comment

by:Don Johnston
ID: 39710004
The default gateway for 10.10.50.0/24 network would be a routing device (or firewall) on that network. So in your case, it sounds like 10.10.50.20 is the correct gateway.

If you have a multi-layer switch, then there would be 5 SVI's (VLAN interfaces). Each SVI will have an IP address for that network. The hosts on those networks would use the SVI IP address on their network.
0

Featured Post

Don't miss ATEN at NAB Show April 24-27!

Visit ATEN at NAB Show to learn how our "Seamlessly Entertaining" solutions deliver fast, precise video streaming without delays for the broadcasting and media environment. ATEN will showcase its 16x16 Modular Matrix Switch (VM1600) and KVM Over IP Solution (KE6900 series).

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
VTP Setup 4 22
Cisco 2960 / 3560 Reset password - Using the Mode button on switch 2 33
PowerShell and cisco ios 3 46
Citrix App 7 34
How to set-up an On Demand, IPSec, Site to SIte, VPN from a Draytek Vigor Router to a Cyberoam UTM Appliance. A concise guide to the settings required on both devices
Join Greg Farro and Ethan Banks from Packet Pushers (http://packetpushers.net/podcast/podcasts/pq-show-93-smart-network-monitoring-paessler-sponsored/) and Greg Ross from Paessler (https://www.paessler.com/prtg) for a discussion about smart network …
Viewers will learn how to connect to a wireless network using the network security key. They will also learn how to access the IP address and DNS server for connections that must be done manually. After setting up a router, find the network security…
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…

726 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question