Solved

VLANs

Posted on 2015-01-17
25
125 Views
Last Modified: 2015-01-19
We have the following current setup.

1 flat network
Need 12 specific ports in VLAN 15 and only internet access on LAN
IP range 10.33.0.0/21
DHCP - Windows server 10.33.1.60
POOL - 10.33.6.1-10.33.6.254
DNS - 10.33.1.60
GW - 10.33.0.254
Cisco 4507 - 10.33.0.25

Have setup VLAN 15 and assign a port to it, when I do I lose network connectivity. Tried to build another DHCP pool on the 4507, but when I add the network 10.33.7.0 255.255.248.0, it puts the entire subnet 10.33.0.0, which is already on Windows server.

What I thought would happen is it would add just the 10.33.7.0 subnet and I could assign the ports to it and they can use this pool and existing gateway.

What am I not understanding or missing or other options?

Regards
0
Comment
Question by:Harold
  • 13
  • 12
25 Comments
 
LVL 18

Accepted Solution

by:
Akinsd earned 500 total points
Comment Utility
Your subnet mask is the problem
10.33.7.0 255.255.248.0

The range for that mask is
10.33.0.0 - 10.33.7.255
The actual notation is 10.33.0.0/21 even though you typed 10.33.7.0

Use 255.255.255.0 if you only need a subnet just for 10.33.7.0
Your range in that case will be
10.33.7.0 - 10.33.7.255
0
 
LVL 1

Author Comment

by:Harold
Comment Utility
Akinsd: sorry about the typo, but thanks for the help. Hadn't worked with subnetting in a while.
0
 
LVL 18

Expert Comment

by:Akinsd
Comment Utility
You're welcome
No one is perfect.
All the best
0
 
LVL 1

Author Comment

by:Harold
Comment Utility
Akinsd: that didn't work, because the Gateway is on /21 subnet, so can't find a GW and still not getting an IP from the Pool.
0
 
LVL 18

Expert Comment

by:Akinsd
Comment Utility
Post your config

If the gateway is /21 as you mentioned, then 10.33.7.0 is already part of that subnet.
Just extend your pool
POOL - 10.33.6.1-10.33.7.254
GW - 10.33.0.254
0
 
LVL 1

Author Comment

by:Harold
Comment Utility
Akinsd: here is some of it....

!
ip dhcp pool FDR
   network 10.33.7.0 255.255.255.0
   default-router 10.33.0.254
   dns-server 10.33.1.60
!

Can't add the IP 10.33.7.1 255.255.255.0 to the VLAN interface because it overlaps
(config-if)#ip address 10.33.7.1 255.255.255.0
10.33.7.0 overlaps with Vlan1
0
 
LVL 18

Expert Comment

by:Akinsd
Comment Utility
Exactly

To create a vlan 15 with a subnet of 10.33.7.0, you will need to change vlan 1 to a /22, but then that will shrink your range to 10.33.0.0 - 10.33.3.255 for vlan 1

Your alternative is to use 10.33.8.0 instead

The GW for 10.33.7.0 with your current configuration is
GW - 10.33.0.254

The /21 range is
10.33.0.0 - 10.33.7.255
This means, every IP within the range is already part of vlan 1
0
 
LVL 1

Author Comment

by:Harold
Comment Utility
To create a vlan 15 with a subnet of 10.33.7.0, you will need to change vlan 1 to a /22, but then that will shrink your range to 10.33.0.0 - 10.33.3.255  can't do this

Your alternative is to use 10.33.8.0 instead .......How can I use 10.33.8.0 and go out 10.33.0.254, still different subnets.
0
 
LVL 18

Expert Comment

by:Akinsd
Comment Utility
That's if you want to create a new vlan 15 like you stated.
10.33.8.0 can not go out from 10.33.0.254.

I need to understand your reason for creating vlan 15
Do you know why the 7 range is not part of the DHCP pool
0
 
LVL 1

Author Comment

by:Harold
Comment Utility
We've moved 8 people in a room and they are on our LAN. They are connected to our network, but are here temporarily. For security I was going to segment the ports they are on, to just have internet access.
 
The pool was created before I got here and is on a Windows server, which they don't authenticate to and if I add that pool and my other LAN users get an IP from that range, I'll have a mess.
0
 
LVL 18

Expert Comment

by:Akinsd
Comment Utility
Ok

Nothing in the IP range is usable then based on your explanation.
It makes sense to create another vlan but that can't include anything in the .7.0 range

On your 4507 create another interface (SVI)
interface vlan 15
IP address 10.33.8.254 255.255.255.0
ip helper-address 10.33.1.60

On your DHCP server
Create a new scope for vlan 15
POOL - 10.33.8.1-10.33.8.253
DNS - 10.33.1.60
GW - 10.33.8.254

Then create an access list that blocks traffic from .8 range to any ip in vlan 1
0
 
LVL 1

Author Comment

by:Harold
Comment Utility
If DNS is on /21, it will not be seen by this new subnet, as it would be /24 correct?

"Then create an access list that blocks traffic from .8 range to any ip in vlan 1"  This will be difficult to do, since the DNS server is on a different subnet. Unless I turn on DNS on the switch, which may cause more headaches.
0
Zoho SalesIQ

Hassle-free live chat software re-imagined for business growth. 2 users, always free.

 
LVL 18

Expert Comment

by:Akinsd
Comment Utility
You can permit traffic to the 10.33.1.60 in the ACL or use publicly available ones

POOL - 10.33.8.1-10.33.8.253
DNS - 8.8.8.8, 4.2.2.2
GW - 10.33.8.254
0
 
LVL 1

Author Comment

by:Harold
Comment Utility
Can I use an external DNS IP address as a help address?

Do I need to add a ip route 0.0.0.0 0.0.0.0 10.33.8.254 too or will this screw with my existing route?
0
 
LVL 18

Expert Comment

by:Akinsd
Comment Utility
No
The IP Helper address is to let the DHCP server know which vlan the DHCP request is coming from and assign IP appropriately
0
 
LVL 1

Author Comment

by:Harold
Comment Utility
Ok, I so do I use the IP I assigned to VLAN 15? Getting IPs now, just no route out. I'm guessing I need the IP route statement?
0
 
LVL 18

Expert Comment

by:Akinsd
Comment Utility
show ip route

show ip int brief

If the SVI for vlan 1 and vlan 15 are on the same 4507, a route is not needed as they are connected.
Run and post the 2 commands above 1st, and I'll let you know
0
 
LVL 1

Author Comment

by:Harold
Comment Utility
Gateway of last resort is 10.33.0.254 to network 0.0.0.0

     10.0.0.0/8 is variably subnetted, 2 subnets, 2 masks
C       10.33.8.0/24 is directly connected, Vlan15
C       10.33.0.0/21 is directly connected, Vlan1
S*   0.0.0.0/0 [1/0] via 10.33.0.254

7#sh ip int brief
Interface              IP-Address      OK? Method Status                Protocol
Vlan1                  10.33.0.25      YES NVRAM  up                    up      
Vlan15                 10.33.8.254     YES manual up                    up
0
 
LVL 18

Expert Comment

by:Akinsd
Comment Utility
What is the 4507 connected to?
That is where you'll need a route to be added
ip route 10.33.8.0 255.255.255.0 10.33.0.254
0
 
LVL 1

Author Comment

by:Harold
Comment Utility
didn't work....10.33.0.254 is on the /21 subnet

interface Vlan1
 ip address 10.33.0.25 255.255.248.0
!
interface Vlan15
 ip address 10.33.8.254 255.255.255.0
!
ip route 0.0.0.0 0.0.0.0 10.33.0.254
ip route 10.33.8.0 255.255.255.0 10.33.0.254
0
 
LVL 18

Expert Comment

by:Akinsd
Comment Utility
Not on the switch, but on the router the switch is connected to.

remove ip route 10.33.8.0 255.255.255.0 10.33.0.254 from the switch
What is the switch connected to?
That must be the device with address 10.33.0.254
On that device
insert the route statement ip route 10.33.8.0 255.255.255.0 10.33.0.25

I noticed also that the switch is not the gateway. The router the switch connects to seem to be the gateway for vlan 1
0
 
LVL 1

Author Comment

by:Harold
Comment Utility
Hmmm that's managed by the telco. I don't like working with these people. I'll get it done.
0
 
LVL 18

Expert Comment

by:Akinsd
Comment Utility
If you have access to the device, then that's the major thing needed for now.

Everything major is complete on the switch.
Remember to assign the switchports the guest PCs will be using to vlan 15
0
 
LVL 1

Author Comment

by:Harold
Comment Utility
that's just it we don't have access. We're off the contract in a couple months though.

I've added the port I'm testing with, so I'll wait on them to work the ticket I just opened and let you know tomorrow.

Thanks
0
 
LVL 18

Expert Comment

by:Akinsd
Comment Utility
Ok
All the best
0

Featured Post

Highfive + Dolby Voice = No More Audio Complaints!

Poor audio quality is one of the top reasons people don’t use video conferencing. Get the crispest, clearest audio powered by Dolby Voice in every meeting. Highfive and Dolby Voice deliver the best video conferencing and audio experience for every meeting and every room.

Join & Write a Comment

Introduction This article explores the design of a cache system that can improve the performance of a web site or web application.  The assumption is that the web site has many more “read” operations than “write” operations (this is commonly the ca…
If you are thinking of adopting cloud services, or just curious as to what ‘the cloud’ can offer then the leader according to Gartner for Infrastructure as a Service (IaaS) is Amazon Web Services (AWS).  When I started using AWS I was completely new…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

7 Experts available now in Live!

Get 1:1 Help Now