[Last Call] Learn how to a build a cloud-first strategyRegister Now

x
?
Solved

VLAN Setup - Windows Server 2003  DHCP - HP ProCurve Switches

Posted on 2014-08-13
8
Medium Priority
?
696 Views
Last Modified: 2015-01-03
Hi All,

VLAN is something totally new to me, so a few questions that I've run into. I'm looking to separate our wireless traffic from our LAN traffic.

I'm currently using a HP 5406ZL switch.

Domain Controller(running dhcp/dns) is connected to Port B23 & B24.
Wireless AP(AeroHive) is connected to port D16.

i created VLAN10 on switch and a new scope(10.10.10.1/23) on the server.
Domain controller is on VLAN1(192.168.0.1/21)
I created a new dhcp scope in the domain controller for 10.10.10.1/23.

I removed D16 from VLAN1 and added it to VLAN10. I changed D16 from untagged to tagged (i read that if you want the port to talk with more than 1 vlan, i had to tag it)

i enabled dhcp-relay and added ip helper-address to vlan 10. (192.168.0.3, which is the DHCP server address)

Is there something i'm missing? when i try to connect, i never get a ip from the DHCP server.


-------------------------------------------------------
; J8697A Configuration Editor; Created on release #K.15.10.0009
; Ver #03:03.1f.ef:f0
hostname "HP-5406zl"
module 1 type j8702a
module 2 type j8702a
module 3 type j8702a
module 4 type j8702a
module 5 type j8702a
ip default-gateway 192.168.0.1
snmp-server community "public" unrestricted
snmp-server contact "IT" location "Technology Closet"
vlan 1
   name "DEFAULT_VLAN"
   no untagged D16
   untagged A1-A24,B1-B24,C1-C24,D1-D15,D17-D24,E1-E24
   ip address dhcp-bootp
   exit
vlan 10
   name "VLAN10"
   tagged D16
   ip address 10.10.10.1 255.255.254.0
   ip helper-address 192.168.0.3
   exit
-------------------------------------------------------
0
Comment
Question by:AfternoonShift
8 Comments
 
LVL 2

Expert Comment

by:Axis52401
ID: 40259591
Here is a summary of the possible modes

Tagged – When a port is tagged, it allows communication among the different VLANs to which it is assigned.
Untagged – When a port is untagged, it can only be a member on one VLAN.
No untagged – The port is not a member of that VLAN.
Forbid – The port is “forbidden” to join that VLAN.

I think the only thing you are missing is tagging the server ports. Because the server ports are untagged it is only communicating over vlan 1, but since you need dhcp over vlan10 you'll need to tag the server ports too. This will allow the server to communicate over all vlans.
0
 

Author Comment

by:AfternoonShift
ID: 40259704
here's the current config now..  When i tagged port 23 and 24, both VLAN1 and VLAN10 cannot ping or connect to the dhcp server.  I also swapped my laptop port from D13(untagged on VLAN10) to D15(untagged on VLAN1) and still could not get an ip from the server.

 J8697A Configuration Editor; Created on release #K.15.10.0009
; Ver #03:03.1f.ef:f0
hostname "HP-5406zl"
module 1 type j8702a
module 2 type j8702a
module 3 type j8702a
module 4 type j8702a
module 5 type j8702a
ip default-gateway 192.168.0.1
snmp-server community "public" unrestricted
snmp-server contact "Erik" location "Technology Closet"
vlan 1
   name "DEFAULT_VLAN"
   no untagged D13
   untagged A1-A24,B1-B22,C1-C24,D1-D12,D14-D24,E1-E24
   tagged B23-B24
   ip address dhcp-bootp
   exit
vlan 10
   name "VLAN10"
   untagged D13
   ip address 10.10.10.1 255.255.254.0
   ip helper-address 192.168.0.3
   exit
0
 
LVL 17

Expert Comment

by:jburgaard
ID: 40264003
The config probably can be done more than one way.
The switch setup , the server setup and the client-setup however must mach.

On the server do you have 2 ports with an IP on each one for each vlan?
or do you have some sort of link-agregation /failover with a mix of vlans running in the link?

Is some sort of communication to take place between vlans in server or in switch or otherwise (routing)?

The configs above have conflicting assumptions.
0
Visualize your virtual and backup environments

Create well-organized and polished visualizations of your virtual and backup environments when planning VMware vSphere, Microsoft Hyper-V or Veeam deployments. It helps you to gain better visibility and valuable business insights.

 

Author Comment

by:AfternoonShift
ID: 40264172
The server is running 2 ips. 192.168.0.2(DNS) and 192.168.0.3(DHCP). I don't have any NICs setup for the VLAN10 ip address.  I was assuming i wouldn't need to do much to the server as i read someone say "it just works" once i have the ip-helper set up in the layer3 switch.  The NICs are just just for failover and aren't bridged or anything like that.

Here's the ipconfig from a connected PC on VLAN1
Physical Address. . . . . . . . . : 5C-F9-DD-72-54-FC
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
IPv4 Address. . . . . . . . . . . : 192.168.1.39(Preferred)
Subnet Mask . . . . . . . . . . . : 255.255.248.0
Lease Obtained. . . . . . . . . . : Tuesday, July 15, 2014 5:51:45 PM
Lease Expires . . . . . . . . . . : Tuesday, August 19, 2014 5:52:47 PM
Default Gateway . . . . . . . . . : 192.168.0.1
DHCP Server . . . . . . . . . . . : 192.168.0.3
DNS Servers . . . . . . . . . . . : 192.168.0.2
                                    192.168.0.4
NetBIOS over Tcpip. . . . . . . . : Enabled
dhcp.png
0
 
LVL 17

Assisted Solution

by:jburgaard
jburgaard earned 600 total points
ID: 40264255
L3-switch must hold IP of vlan=default gateway of clients
so if this switch is supposed to be the inter-vlan switching device it should have in vlan1 static :
ip address 192.168.0.1 255.255.248.0
vlan 10:
ip address 10.10.10.1 255.255.254.0
eventually some default gateway to rest of world like
IP ROUTE 0.0.0.0  0.0.0.0  192.168.0.254 or something

But to act as L3 configure:
IP ROUTING

For a start configure one of the ports to connect to the server:
UNtag B23 in vlan1 (for now leave B24: not connected or disabled)
(assuming  you have not done any vlan-config of server port)

HTH
0
 
LVL 17

Expert Comment

by:jburgaard
ID: 40279695
If testing the basic settings are in place:
ping , DHCP etc. working, then link aggregation can be set up.
In procure world the term TRUNK means more connections building a link.
(Some other vendors use the term trunk differently)

If you make a trunk of B23-B24 to a couple of ports in the server, it is not the single ports that should be tagged/untagged in some vlan(s) -but the trunk.

So a config could have:
trunk B23,B24 trk1 trunk
vlan 1
untag trk1
exit
0
 
LVL 10

Accepted Solution

by:
convergint earned 1400 total points
ID: 40351394
This should work:

; J8697A Configuration Editor; Created on release #K.15.10.0009
; Ver #03:03.1f.ef:f0
hostname "HP-5406zl"
module 1 type j8702a
module 2 type j8702a
module 3 type j8702a
module 4 type j8702a
module 5 type j8702a
ip default-gateway 192.168.0.1
snmp-server community "public" unrestricted
snmp-server contact "IT" location "Technology Closet"
dhcp-snooping
dhcp-snooping authorized-server 192.168.0.3
dhcp-snooping vlan 2 10
ip routing
interface D16
   name "Wireless_AP"
   exit
interface B23
   name "ServerNIC1_192.168.0.2"
   exit
interface B24
   name "ServerNIC2_192.168.0.3"
   dhcp-snooping trust
   exit
vlan 1
   name "MGMT VLAN"
   no untagged A1-A24,B1-B24,C1-C24,D1-D24,E1-E24
   no ip address
   exit
Vlan 2
   name "Corporate VLAN"
   untagged A1-A24,B1-B24,C1-C24,D1-D15,D17-D24,E1-E24
   ip address 192.168.0.10 255.255.248.0
   exit
vlan 10
   name "Wireless VLAN"
   untagged D16
   ip address 10.10.10.1 255.255.254.0
   ip helper-address 192.168.0.3
   exit

On your access point I'm assuming that you only have one VLAN required so therefore you need to make sure you are not tagging any ports on the wireless AP.  You'll only need to tag the port on both the switch and AP if you have something like both a guest and corporate VLAN.  It is also good practice not to use VLAN 1 for the corporate LAN so that is the reason why I made VLAN 2 with a static gateway IP of 192.168.0.10 (obviously change it to something else if you need).  I also like using the DHCP snooping to better protect your network and it also makes it so you can see what you DHCP server is from the config.
0
 

Author Comment

by:AfternoonShift
ID: 40529803
thanks convergint1! :) i wasn't aware of the dhcp-snooping....that came in handy! :)

IP routing was my main issues as well. I now use the switch to route all traffic between both VLANs.
0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I eventually solved a perplexing problem setting up telnet for a new switch.  I installed a new Cisco WS-03560X-24P switch connected to an existing Cisco 4506 running a WS-X4013-10GE Sup II-Plus. After configuring vlans and trunking,  I could no…
This article will show how Aten was able to supply easy management and control for Artear's video walls and wide range display configurations of their newsroom.
This Micro Tutorial will teach you how to add a cinematic look to any film or video out there. There are very few simple steps that you will follow to do so. This will be demonstrated using Adobe Premiere Pro CS6.
This video shows how to quickly and easily deploy an email signature for all users in Office 365 and prevent it from being added to replies and forwards. (the resulting signature is applied on the server level in Exchange Online) The email signat…

829 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question