Solved

HP Procurve 2 vlans (voice and data) with 1 dhcp server/nic - what port settings?

Posted on 2014-01-26
28
2,360 Views
Last Modified: 2014-05-27
Pretty standard config.  Voice vlan is 20, data is 10.  Most ports are untagged data, and tagged voice.  Phones boot up in data vlan and then have an option file that tells them to use vlan20 and reboot to get new ip address.  What are my port settings supposed to be on the DHCP server so it can communicate in both the voice and data vlan and provide IPs to the right devices etc?
Here is config.

interface 18
   name "dhcp_server"
exit
ip routing
vlan 1
   name "DEFAULT_VLAN"
   untagged A1-A2,B1
   ip address 172.16.11.2 255.255.255.0
   no untagged 1-48
   exit
vlan 10
   name "Data"
   untagged 1-2,6-8,10-43,45-47
   ip helper-address 172.16.1.52
   ip address 172.16.1.2 255.255.255.0
   exit
vlan 20
   name "VoIP"
   untagged 3-5,9
   qos priority 7
   ip helper-address 172.16.1.52
   ip address 172.16.2.2 255.255.255.0
   tagged 1-2,7-8,11-48
   voice
   exit
ip route 0.0.0.0 0.0.0.0 172.16.1.1
ip route 172.16.2.0 255.255.255.0 vlan 20
snmp-server community "public" Unrestricted
primary-vlan 10
no autorun

ProCurve 2910al-48G-PoE Switch(vlan-10)#
0
Comment
Question by:rhwimmers
  • 18
  • 9
28 Comments
 
LVL 25

Expert Comment

by:Zephyr ICT
ID: 39811202
Hi, I'm not sure what you mean with port settings for the DHCP server...

In any case, I see you already have the IP-helper in place, so you're on the right track, maybe this article can get you where you want to be (if I don't misunderstand your question that is): http://technet.microsoft.com/en-us/library/dd759168.aspx
0
 
LVL 1

Author Comment

by:rhwimmers
ID: 39812148
The dhcp server (windows box) has one data IP.  What port settings does it need to have, just untagged data (default) and tagged voice, just like the other ports?
0
 
LVL 17

Expert Comment

by:TimotiSt
ID: 39812210
As the DHCP server has an IP in the subnet of vlan10, you won't need a helper address for vlan10.
As 172.16.2.0/24 is connected, you won't need that static route either.
If the default gw of the DHCP server is 172.16.1.1, it'll need a static route to 172.16.2.0/24 through the switch (172.16.2.2).
Connect the DHCP server to an untagged vlan10 port.
That should be good to go with a dhcp-relay style setup.

If you want to dual-home the DHCP server to both vlans/subnets, that'll need a fairly different setup and a VLAN-aware OS/NIC in the server itself. If this is the case, what OS are you running? VLANs are a pain with Windows...

Tamas
0
 
LVL 1

Author Comment

by:rhwimmers
ID: 39812223
Data devices get DHCP IP just fine, but not voice.  If I static the phone to a voice IP/DG etc it works fine.
The switch lost its config but was working, so I shouldnt have to change anything on the server/phones etc - I recall the config noted the dhcp server port and am pretty sure that port had to be set differently than the others in terms of the tagging.
0
 
LVL 17

Expert Comment

by:TimotiSt
ID: 39812236
Can you post a 'route print' (Windows) or 'route -n' (Linux) from the server?
0
 
LVL 1

Author Comment

by:rhwimmers
ID: 39812241
default gateway is .2 for both voice and data (the switch) .1 is the firewall but we shouldn't be even touching that with this traffic.
0
 
LVL 1

Author Comment

by:rhwimmers
ID: 39812242
I Active Routes:
Network Destination        Netmask          Gateway       Interface  Metric
          0.0.0.0          0.0.0.0       172.16.1.2      172.16.1.52     15
        127.0.0.0        255.0.0.0         On-link         127.0.0.1    306
        127.0.0.1  255.255.255.255         On-link         127.0.0.1    306
  127.255.255.255  255.255.255.255         On-link         127.0.0.1    306
       172.16.1.0    255.255.255.0         On-link       172.16.1.52    266
      172.16.1.52  255.255.255.255         On-link       172.16.1.52    266
     172.16.1.255  255.255.255.255         On-link       172.16.1.52    266
    192.168.168.0    255.255.255.0         On-link     192.168.168.2    266
    192.168.168.2  255.255.255.255         On-link     192.168.168.2    266
  192.168.168.255  255.255.255.255         On-link     192.168.168.2    266
        224.0.0.0        240.0.0.0         On-link         127.0.0.1    306
        224.0.0.0        240.0.0.0         On-link     192.168.168.2    266
        224.0.0.0        240.0.0.0         On-link       172.16.1.52    266
  255.255.255.255  255.255.255.255         On-link         127.0.0.1    306
  255.255.255.255  255.255.255.255         On-link     192.168.168.2    266
  255.255.255.255  255.255.255.255         On-link       172.16.1.52    266
===========================================================================
Persistent Routes:
  Network Address          Netmask  Gateway Address  Metric
          0.0.0.0          0.0.0.0       172.16.1.2       5
          0.0.0.0          0.0.0.0       172.16.2.2  Default
===========================================================================
0
 
LVL 1

Author Comment

by:rhwimmers
ID: 39812247
I can ping to/from phones/pcs across vlans etc, no problems there.
0
 
LVL 17

Expert Comment

by:TimotiSt
ID: 39812376
Okay, in that case it should work okay. Can you put a port in vlan20 untagged and test with a PC what do you get? Possibly record the DHCP exchange with wireshark.
0
 
LVL 1

Author Comment

by:rhwimmers
ID: 39812437
I get a vlan 20 IP no problem with a PC.  Looks like a phone/pbx issue?
0
 
LVL 17

Expert Comment

by:TimotiSt
ID: 39812448
Can you double-check the option that directs the phones to reboot using vlan20?
Is that coming from DHCP, or they would use LLDP-MED?
0
 
LVL 1

Author Comment

by:rhwimmers
ID: 39812513
From dhcp I think.  On the phone menu it has bootserver cutom+opt66.  Custom is 160, which points to a internal url for the pbx.
The phone should boot up in data vlan and then somehow know to get to the voice but I dont see that happening or know how its supposed to work.  I can manually put vlan 20 in the phone but still dont get address via dhcp.
0
 
LVL 17

Expert Comment

by:TimotiSt
ID: 39812548
Do you have option 66 configured on the DHCP server?
0
 
LVL 1

Author Comment

by:rhwimmers
ID: 39812599
No, the phone guy said thats not used anymore, but the custom portion is (which is 160), so the phone says custom+66, the next screen says custom=160.  160 on the VOICE dhcp pool has an ipaddress:8088 for its config.  Phone guy says that is correct on the phone side.  and dhcp server hasn't changed, only thing that changed was the switch config as far as ive been told, at least.
0
VMware Disaster Recovery and Data Protection

In this expert guide, you’ll learn about the components of a Modern Data Center. You will use cases for the value-added capabilities of Veeam®, including combining backup and replication for VMware disaster recovery and using replication for data center migration.

 
LVL 1

Author Comment

by:rhwimmers
ID: 39812604
opt66 used to be used in older systems and would define a tftp server but now its just the option160 deal then it gets the config (xml file) from an internal webserver (located on the voice vlan)
0
 
LVL 17

Expert Comment

by:TimotiSt
ID: 39812609
If it's really only the switch that's changed, you could try to mark vlan20 as a voice vlan and enable LLDP-MED. It shouldn't mess up anything, and the phones might need it afterall.
0
 
LVL 1

Author Comment

by:rhwimmers
ID: 39812703
How to enable lldp-med?  Phone has it enabled, it also has cdp enabled by default.
If I take a port out of tagged vlan 20 it does get a data ip address, of course it doesnt work as a phone, but interesting
0
 
LVL 1

Author Comment

by:rhwimmers
ID: 39812774
I did a packet capture, heres a screen shot - crap load of dhcp disc, offer, request, and nack but not sure what to make of that.  I did this on a pc hooked to phone with phone not working.  PC ip is 1.120
Untitled.png
0
 
LVL 1

Author Comment

by:rhwimmers
ID: 39813138
Is it not possible to increase the points any more?
0
 
LVL 17

Expert Comment

by:TimotiSt
ID: 39813268
I'll get an example lldp-med config for you once I get home. :)
0
 
LVL 1

Author Comment

by:rhwimmers
ID: 39813345
Thanks.  It seems that as soon as the phone gets tagged in vlan 20 it will not get an ip address.  If it's put on the phone manually, it will not get an address.  If I take no tag 20 phone will get data ip.  Still feel like something on dhcp server doesnt like vlan 20 tags for some reason.
0
 
LVL 1

Author Comment

by:rhwimmers
ID: 39818542
Still can't get this working.  Would a packet capture help?
0
 
LVL 17

Expert Comment

by:TimotiSt
ID: 39819321
Sorry for the delay; see below for the LLDP-MED config.

lldp run
lldp config all medTlvEnable network_policy
lldp config all medTlvEnable capabilities

Open in new window


If it still doesn't work, can you post exact make/model and firmware version of the phones and a firmware version of the switch?
0
 
LVL 1

Author Comment

by:rhwimmers
ID: 39841006
Just made the config change, will update tomorrow
0
 
LVL 1

Author Comment

by:rhwimmers
ID: 39856463
Still no luck
HP 2910al-48G-PoE Switch (J9148A)
W.15.13.0005, ROM W.14.06

phones polycom soundpoint IP335
revision 4.2.2.0710

When booting and it says welcome (start, setup, about) and starts to count down if I click about it says server address resolving, click next then shows ip address resolving, next shows vlan20 (so its getting that from something).  I can circle through that menu but still just stays on waiting for network to initialize.
0
 
LVL 17

Expert Comment

by:TimotiSt
ID: 39859380
0
 
LVL 1

Accepted Solution

by:
rhwimmers earned 0 total points
ID: 40083761
The resolution was to have the port with the dhcp server to be set to "no" on the vlan option.  No clue why, but thats what worked
0
 
LVL 1

Author Closing Comment

by:rhwimmers
ID: 40092479
Solution self solved
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Data center, now-a-days, is referred as the home of all the advanced technologies. In-fact, most of the businesses are now establishing their entire organizational structure around the IT capabilities.
Join Greg Farro and Ethan Banks from Packet Pushers (http://packetpushers.net/podcast/podcasts/pq-show-93-smart-network-monitoring-paessler-sponsored/) and Greg Ross from Paessler (https://www.paessler.com/prtg) for a discussion about smart network …
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…

895 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

15 Experts available now in Live!

Get 1:1 Help Now