Solved

VLAN and Routing Design

Posted on 2014-01-27
11
404 Views
Last Modified: 2014-01-30
Have attached a proposed LAN diagram to illustrate what I am trying to do.  Want to totally separate the Staff and Public into 2 VLANs.  Then create another for all the video equipment.  The Staff and Public do have to share a standalone server which I could put on another VLAN.

VLAN10  = Staff
VLAN20  = Patron
VLAN30  = Video
VLAN40  = Shared Resources

All the switches are L3 capable, but not familiar with routing setup.  Have setup VLANs in L2 mode and with the Sonicwall performing the routing.   Got some feedback that it would be better to do the routing with the switches?  How would that change the configuration?

So far does this seem like a good proof of concept?  Any other thoughts.
LAN-Diagram.png
0
Comment
Question by:Webcc
  • 4
  • 4
  • 3
11 Comments
 
LVL 37

Expert Comment

by:Bing CISM / CISSP
ID: 39814017
your network topology should be changed to meet your requirement of routing between VLANs with a L3 switch.

simply use one of the L3 switch as the central router, then connect the other switches and Sonicwall to the central switch through the ports assigned to the VLANs on each connecting devices.

as for the L3 routing configuration on the central switch, please see below the discussion on Cisco site.

https://supportforums.cisco.com/thread/2080774
0
 

Author Comment

by:Webcc
ID: 39814196
Not clear on how to config the L3 switch.  First I assume that I have to assign IP addresses to the VLANs and then how do I configure the L3 switch to connect to the other switches and Sonicwall?  Do I configure trunk ports and tag the VLANs on those ports?

Started with this on one switch -
VLAN1      192.168.1.1 (mgmt VLAN)
VLAN30    10.10.30.1
VLAN50    10.10.50.1

Sonicwall -
Setup interface X5   192.168.1.2
Subinterface X5:30  10.10.30.2
Subinterface X5:50   10.10.50.2

Is this a correct start?  Do all the VLANs have to be setup on the Sonicwall?
0
 
LVL 26

Accepted Solution

by:
Soulja earned 500 total points
ID: 39815440
What you want to do is:

1. For your L3 switch connected to the Sonicwall. Enable routing and create a vlan interface for each vlan.

2. Trunk the vlans to the other switches that are layer 2.

3. Configure one vlan interface on the layer 2 switches for management. Configure the default gateway on the L2 switches to be the vlan 1 interface of your layer 3 switch.

4. The connection to the sonicwall from your L3 switch will be an access port on vlan 1.

5. Remove the subinterfaces on the Sonic as it won't be routing vlans anymore. It will only route internet /wan traffic.

6. Create a default route on the L3 switch to the sonicwall.

7. Create static routes on your sonicwall to your vlan 30 and 50 subnets. The next hop will be the vlan 1 interface of the L3 switch.
0
 
LVL 37

Expert Comment

by:Bing CISM / CISSP
ID: 39817380
> Do all the VLANs have to be setup on the Sonicwall?

VLAN is not necessarily seen on the SonicWALL device except you do have VPN based or related controls on that. commonly, if you multiple internal VLANs or subnets and they all share the same Internet connection, the internet-facing firewall or router just need to have one link (on a dedicated subnet) back to the central L3 switch.
0
 

Author Comment

by:Webcc
ID: 39819818
Have a few questions:

1.  Connected L3 switch to Sonicwall on interface X5.  
            SWITCH   = >       VLAN1 =   192.168.1.1
                                         VLAN30 = 10.10.30.1
                                          VLAN50 = 10.10.50.1
            SONICWALL =>   X5 = 192.168.1.2
2. Trunked Port 27 to L2 Switch
3. Configured VLAN1 on L2 Switch =>  192.168.1.3  Default gateway = 192.168.1.1
4. Connected L3 to Sonicwall  set as an Access port on L3 switch
Thought this had to be a trunk port with the VLANs added to the port as Tagged?

5. Done
6.  Created Default Route on L3 as 192.168.1.2
7. Conceptually I get the thought process but cannot figure out to set the routes?
      Asking for Source, Destination, Service, Gateway, Interface and Metric....
     Do I need to create new address objects to accomodate VLAN IP's and L3 Gateway?
0
How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

 
LVL 26

Expert Comment

by:Soulja
ID: 39819847
Yes. The connection fron l3 to sonic should be an access port.
You options sound like a fw rule.
Regardless the route  should be something like:
Source any
destination 10.10.30.0
service any
Gateway 192.168.1.1
I am not that familiar with Sonicwalls but the concept should be the same.
0
 

Author Comment

by:Webcc
ID: 39819938
Ok got it working.  Thought that VLAN1 should only be used for management?
The VLANs added to the trunk ports need to match between the L2 switches and L3 I assume and tagged?
Can I deliver DHCP from the Sonicwall to the VLANs this way?

Thanks
0
 
LVL 37

Expert Comment

by:Bing CISM / CISSP
ID: 39820046
> Can I deliver DHCP from the Sonicwall to the VLANs this way?

i don't think SonicWALL supports DHCP services across multiple subnets (VLANs) through a single physical port. :(
0
 
LVL 26

Expert Comment

by:Soulja
ID: 39820424
It would be ideal if you can run dhcp from the switch or a server.
0
 

Author Comment

by:Webcc
ID: 39820595
What about the last two questions:

1.  Thought that VLAN1 should only be used for management?

2. Do the ports on the L2 switches that connect to the L3 trunk ports also have to be set as trunk ports and are they all tagged?

Thank you!
0
 
LVL 26

Expert Comment

by:Soulja
ID: 39820877

1.  Thought that VLAN1 should only be used for management?


Not a big deal to use that vlan, but if it really bothers you, you could use a separate network between the switch and firewall such as

- creating a new vlan interface on the switch. Assign that access port to that vlan and chaning the firewall ip address to be in that vlan. It could be a small /30 network.
-Option 2: change the port connecting to the firewall into a routed port assign an different ip not part of your vlans and change the ip on the firewall to be part of that same subnet. It can be a /30 also.

2. Do the ports on the L2 switches that connect to the L3 trunk ports also have to be set as trunk ports and are they all tagged?


Yes you want those to be trunks also.
0

Featured Post

Threat Intelligence Starter Resources

Integrating threat intelligence can be challenging, and not all companies are ready. These resources can help you build awareness and prepare for defense.

Join & Write a Comment

Security is one of the biggest concerns when moving and migrating your data from your on-premise location to the Public Cloud.  Where is your data? Who can access it? Will it be safe from accidental deletion?  All of these questions and more are imp…
Is your computer hacked? learn how to detect and delete malware in your PC
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…

708 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

15 Experts available now in Live!

Get 1:1 Help Now