Link to home
Start Free TrialLog in
Avatar of Jennifer
JenniferFlag for United States of America

asked on

New IP phone system, new subnet, add vlan

I am implementing a new phone system. First IP phone system. The company I am purchasing from suggested a new subnet and a vlan. I created the subnet. I do not currently have any vlans. I am trying to determine where to set it up. Here is my configuration...

Firewall, Cisco ASA
2 HP 48 port switches (data)
2 Luxul POE switches (phone)
I am not putting the phones through computer, they each have their own port/jack

I also need to determine how I want to figure the branch locations, here is that configuration

Site to Site VPN through Firewall
Cisco Router
HP switch (data)
POE switch (phone)
-one of the offices will use the same configuration as individual port/jack
-the other office will use the phone/computer pass through however they will not be setup immediately

Another note, I do not use DHCP.

How do I need to proceed?
ASKER CERTIFIED SOLUTION
Avatar of kevinhsieh
kevinhsieh
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of Jennifer

ASKER

Thanks for the info, a lot to take in. I will break it down on what I need now and maybe that will help us both.

Main office, Cisco ASA 5510 (router/firewall)
I have two HP switches, I previously had a VLAN on one
(this is my normal setup)
I have a new Toshiba IPEdge phone server coming
It will connect to the two Luxul POE switches (I will have to look into the Luxul switches, I don't know much about them at this point (our company sells them and my boss wanted me to put them in))

Now I need to connect the Luxul's to my network using the HP switches

The company putting in our phone system is the one suggesting the VLAN. I have created the subnet. I can create the VLAN I just wasn't sure where to create it.

The company putting in the phone system will be onsite and hooking it up as well I just need to be prepared. Then I can configure for the branches.
You will need to configure the L2 VLAN on every piece of equipment where data from that VLAN will be traveling. That means all of the local switches and the ASA. The ASA will route traffic from the voice VLAN to your other data VLAN as required.

The ASA will need some configuration to allow it to route between the two VLANs. See http://www.petenetlive.com/KB/Article/0000869.htm (I haven't read the whole thing, so be sure you understand any proposed changes before you put them in). You will certainly need to enable hair pinning on the same interface.
Separate question before I go further, would it make a difference if I used the IP pass through on the phones instead of its own IP and sub?
Well, there are two ways to use the passthrough. If you have the phones on the same VLAN and subnet as you do currently, that is very simple and all you need to do is uplink your switches and go.

If you want to have the phones on a separate VLAN and IP subnet as the PC, then using the passthrough is more complicated because the phone and the switch need to be configured to communicate with each other via LLDP, and the switch needs to know that phones go on a separate voice VLAN. It's completely doable, but I suggest that you get one part working at a time.
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Also, this is all internal, nothing external yet, about 45 machine users but about a quarter of that is light usage then 35 phones
I have to correct a previous statement. One of my HP's is being used as my gateway.
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
I was able to get my configuration with the help of an outside consultant. I will partial points for posting with help.