Solved

Cisco 3550 Multi WAN and many vlans

Posted on 2013-12-24
5
621 Views
Last Modified: 2013-12-30
Hello and happy Holidays all.

I have a Cisco 3550 switch I am setting up but having some issues with.
 
We have two different WAN connections from different providers.
We are using many internal vLANs.

Both fa 0/2 and 0/3 are drops from isp’s, I addressed vlan 1 with the assigned subnet from isp 1 and vlan 2 with subnet addressing from isp2. I want fa 0/2 to be assigned to the isp2 / vlan2, and fa 0/3 to use isp1/vlan1. Then assign other vlan’s to each of these trunked.  I enabled ip routing and input 2 routes, one to each of the isp provided gateways.
What else needs to be assigned or configured for this? After setting up the trunks I am having intermittent pings and remote access to the IOS is slow and hangs randomly.

ip subnet-zero
ip routing
spanning-tree mode pvst
spanning-tree extend system-id
!
interface FastEthernet0/2
 switchport trunk encapsulation dot1q
 switchport trunk allowed vlan 2,6-31
 switchport mode trunk
 no ip address
!
interface FastEthernet0/3
 switchport trunk encapsulation dot1q
 switchport trunk allowed vlan 1,3
 switchport mode trunk
 no ip address
!

Open in new window




I am also trying to setup ip helper address.
I have a dhcp server on vlan 6 to assign addresses into other vlans, through ip helper address I assume. Would I assign the helper address onto each desired vlan interface or eth interfaces and if so Is that all that needs to be done for helper address?

Thanks for any help!
0
Comment
Question by:Daeta42
  • 2
  • 2
5 Comments
 
LVL 21

Assisted Solution

by:eeRoot
eeRoot earned 100 total points
ID: 39738826
The intermittent connection problem may be the result of bad cabling or a network loop, so double check the cabling.  If the cabling looks okay, then disconnect one ISP connection at a time and see if having one removed helps the connection.
    Also, this switch should have an IP address defined in each VLAN so it can build its IP routing table.  Without that, the switch will not be able to associate IP subnets with their VLAN's, or what traffic should be routed up to the ISP connections.
    And yes, each VLAN that will have DHCP clients will need the IP helper address.  The IP helper address is not needed on the physical interfaces.
    Lastly, your config appears to be missing the IP route statements that teach the switch which ports are the "uplink" ports to the internet.  With two ISP links, are you trying to set up a primary/secondary link?  Or do they server different purposes.
0
 
LVL 57

Assisted Solution

by:giltjr
giltjr earned 400 total points
ID: 39739502
I'm very confused about your configuration.  

-->  "Both fa 0/2 and 0/3 are drops from isp’s, I addressed vlan 1 with the assigned subnet from isp 1 and vlan 2 with subnet addressing from isp2."

That is clear VLAN1 is ISP1 and VLAN2 is ISP2.  Simple.

-->  "I want fa 0/2 to be assigned to the isp2 / vlan2, and fa 0/3 to use isp1/vlan1."

That is simple  Fa0/2 goes to ISP2 which is VLAN2 and Fa0/3 goes to ISP1 which is VLAN1.

So far simple and easy.


--> "Then assign other vlan’s to each of these trunked.  I enabled ip routing and input 2 routes, one to each of the isp provided gateways."

This is along with your config makes it confusing.

You have Fa0/2 in switchport trunk mode with VLAN 2 (ISP2) and VLANs 5-31.
You have Fa0/3 in switchport trunk mode with VLAN 1 (ISP1) and VLAN 3.

Is Fa0/2 directly connected to ISP2's routers?
Is Fa0/3 directly connected to ISP1's routers?

If so, I don't think your config will work.  Typically you don't have trunked connections to an ISP's router.  They don't know, nor do they typically care, about your VLAN's and they normally run their devices in switchport access mode.

If they are in access mode and you are in trunk mode you will have serious problems.
0
 

Author Comment

by:Daeta42
ID: 39742157
Thanks for the help so far.

If I take fa0/2 and fa0/3 off switchport mode trunk how can I assign the 'ISP' Vlans to these ports? Right now I can ping the vlan1 management address from outside the network but not the other isp link vlan 2.
0
 
LVL 57

Accepted Solution

by:
giltjr earned 400 total points
ID: 39742196
--> If I take fa0/2 and fa0/3 off switchport mode trunk how can I assign the 'ISP' Vlans to these ports?

You change them to mode access and set the they are on.   Again, this should ONLY be done if your ISP is expecting untagged frames.  If they are expecting tagged frames, you need to leave them as trunk.  If you are not sure, as them.  I will say that 99% of the time your ISP is expecting untagged frames.

If you issue the commands I have below and your ISP is expecting tagged frames, you will lose Internet connectivity.

From your 3550 can you ping the inside interface of either, or both, of your ISP's routers?

You might be able to ping the "vlan 1" interface because when you are in trunk mode there is something called a "native vlan".  This is the vlan ID that any untagged traffic is assumed to be on.  The default native vlan is vlan 1.  That is most likely why ISP#1 is working.


To switch your interfaces from trunk to access mode here are commands you would want to issue are:


interface FastEthernet0/2
no switchport trunk allowed vlan 2,6-31
 switchport mode access
 switchport access vlan 2
 no ip address
!
interface FastEthernet0/3
no switchport trunk allowed vlan 1,3
 switchport mode access
switchport access vlan 1
 no ip address
0
 

Author Comment

by:Daeta42
ID: 39746484
Thanks for the help, that did the trick.

I am also having a few vlan issues if you want to take a look...

http://www.experts-exchange.com/Hardware/Networking_Hardware/Q_28327628.html
0

Featured Post

Why You Should Analyze Threat Actor TTPs

After years of analyzing threat actor behavior, it’s become clear that at any given time there are specific tactics, techniques, and procedures (TTPs) that are particularly prevalent. By analyzing and understanding these TTPs, you can dramatically enhance your security program.

Join & Write a Comment

There are two basic ways to configure a static route for Cisco IOS devices. I've written this article to highlight a case study comparing the configuration of a static route using the next-hop IP and the configuration of a static route using an outg…
I recently attended Cisco Live! in Las Vegas, a conference that boasted over 28,000 techies in attendance, and a week of hands-on learning hosted by a solid partner with which Concerto goes to market.  Every year, Cisco displays cutting-edge technol…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

708 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now