Solved

vlans

Posted on 2013-12-21
8
417 Views
Last Modified: 2013-12-21
I need some advice on setting up a network that requires 5 different vlans. I have two layer 2 switches and a layer 3 switch. (The layer 3 switch will then be connected to a firewall which then goes to the ISP router), but I only need help first on the switches and how to configure them.

This is my setup so far

vlan 10- IT - 10.25.10.0
vlan 20- Wareshouse - 10.25.20.0
vlan 30-Sales - 10.25.30.0
vlan 40-Exec - 10.25.40.0
vlan 50-Servers - 10.25.50.0

I need to make a default gateway for each network.
Do I make another vlan for management (like 10.25.60.0) and make interface vlan .61 and .62 for the 2 layer 2 switches to login and manage?
Where do I set the default gateways for all 5 subnets, on the layer 3 switch? On the layer 3 switch do I use the interface vlan id ip address for each subnet? The default gateway for the entire network will be the inside interface of the firewall.
Just need some guidance on this.
Thanks.
0
Comment
Question by:tolinrome
  • 4
  • 4
8 Comments
 
LVL 57

Accepted Solution

by:
giltjr earned 500 total points
ID: 39734189
To make things easier you will need at least one more VLAN that is for a small network between the L3 switch and the firewall.

The connection between the L2 and the L3 switch will need to be configured to support multiple tagged VLAN's (on Cisco devices this is known as a trunked  connection).

The L3 switch will need to have an IP address on each VLAN and this will be the default gateway for each of the VLAN's.

For only 3 devices I don't think you need a management VLAN.  I would assign address to the 3 devices in the "IT" VLAN.
0
 
LVL 7

Author Comment

by:tolinrome
ID: 39734198
ok so, since the L3 switch will have all the default gateways, how do I actually enter them in the switch?

I think I wouldn't use ip default-gateway command since that will be the actual devices default gateway (inside interface firewall). Which command do I use on the L3 switch for setting up the L3 gateways?


Trunks I can do, so I go that. I can create the other vlan between the L3 and firewall, so that's good, and the management vlan I'm good.
0
 
LVL 57

Expert Comment

by:giltjr
ID: 39734209
Well that depends on what type of L2 switch it is.  Not all L3 switches use the same commands.

Example on a Cisco switch it would be something like:

config t
vlan 10
state active
name IT
interface vlan 10
ip address 10.25.10.1 255.255.255.0
desc IT
vlan 20
state active
name Wareshouse
interface vlan 20
ip address 10.25.20.1 255.255.255.0
desc Wareshouse

and so on.
0
What is SQL Server and how does it work?

The purpose of this paper is to provide you background on SQL Server. It’s your self-study guide for learning fundamentals. It includes both the history of SQL and its technical basics. Concepts and definitions will form the solid foundation of your future DBA expertise.

 
LVL 7

Author Comment

by:tolinrome
ID: 39734211
Ok, got it.
One last thing, how do I route all the traffic from the L3 to the inside int of the firewall?
0
 
LVL 57

Expert Comment

by:giltjr
ID: 39734216
I am assuming that you have another VLAN/IP subnet between your L3 switch and the firewall.

You just make the IP address of the inside interface of the firewall the defualt gateway/route on the L3 switch.

What type of L2 and L3 devices do you have?
0
 
LVL 7

Author Comment

by:tolinrome
ID: 39734219
"You just make the IP address of the inside interface of the firewall the defualt gateway/route on the L3 switch."

How? #ip route command?

All cisco devices 2900's and 3560
0
 
LVL 57

Expert Comment

by:giltjr
ID: 39734226
Yes:

ip route 0.0.0.0 0.0.0.0 x.x.x.x

where x.x.x.x is the inside interface of the firewall.

Don't forget that you need to make the connection between the L2 switches and the L3 switches a trunk with all of your VLAN's allowed.
0
 
LVL 7

Author Comment

by:tolinrome
ID: 39734243
Thanks
0

Featured Post

Free Tool: SSL Checker

Scans your site and returns information about your SSL implementation and certificate. Helpful for debugging and validating your SSL configuration.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Telepresence on backup 3 34
Clarification about access via WAN 6 36
Cisco 2960 unable to add SFP modules to device 9 68
Connecting Servers to L2 OR L3 Switch 6 48
Short answer to this question: there is no effective WiFi manager in iOS devices as seen in Windows WiFi or Macbook OSx WiFi management, but this article will try and provide some amicable solutions to better suite your needs.
This article will inform Clients about common and important expectations from the freelancers (Experts) who are looking at your Gig.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Internet Business Fax to Email Made Easy - With  eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, f…

821 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question