Solved

Multiple VLANs via multiple HP switches with routing and ACL? (access lists)

Posted on 2015-01-19
14
1,295 Views
Last Modified: 2015-01-21
Dear Mrs.and Mr.Experts.

I have problems with configuration of my (2x)HP switches 2920(layer3),  (1x)HP 1920PoE(for WLAN AP's)(basic layer3) and 1910(for Surveillance PoE - cameras,etc..)(basic layer3) and i do not know how to solve it.

Here is the scenario whose i partialy configure but i am not an expert so i need some help:

The first HP2920-48G-1 switch (hostname 2920-48G-1) is on the 1.st floor of building and probably this will be the "master" switch for routing,VLANS, etc..
The second switch HP2920 (hostname 2920-48G-2) on the ground floor of building (will) probably be the "L2" switch but this switch probably must also have "knowledge" of VLANs on the whole network via Trk1 (trunk) interface?
On both of these HP2920-48G switches i made "Trunk" (Trk1) channel via SFP 45 port and SFP46 port.
(please see the attached config files of both switches)

The third switch (HP1920-8G) is for WLAN Access Points and give power over ethernet and data connections to the WLAN controller HP-MSM720.
The fourth (HP1910-24G) switch gives power over ethernet and data connections to surveillance (cameras) but all of this debate i will post later, because firstly i want to have both of 2920HP's solved and configured properly.

The first main problems which i have is:
If i connect to the second switch (2920-48G-2) via ssh and ping some device on "PRODUCTION" network (VLAN 10) i do not receive any ping requests ("The destination address is unreachable.")
If i want to delete the untagged port 43 of VLAN 20 the switch says:"Ports 43 would be orphaned. No ports removed."

If someone can answer and help with this (for me) a little confused scenario i will be very, very happy and grateful.

Many thanks in advance.
Switch1-2.txt
0
Comment
Question by:MISIT
  • 8
  • 6
14 Comments
 
LVL 11

Expert Comment

by:rharland2009
Comment Utility
First, if you're on the second switch and ping the IP address of the first switch (in the default VLAN) do you receive a reply?
Re port 43 and VLAN 20 - you have to assign port 43 to be untagged in some other vlan. A port needs to be untagged in some VLAN at all times. If you do that, it will remove it from untagged in vlan 20.
0
 

Author Comment

by:MISIT
Comment Utility
Dear rharland2009.
Firstly,many thanks to your comment.

Yes if i connect to the second switch i can ping the first switch(192.168.10.1) from switch 2.
About (un)assign the untagged port on VLAN 20, thanks! It solved this little problem. :)
0
 
LVL 11

Accepted Solution

by:
rharland2009 earned 500 total points
Comment Utility
Okay, great.
On the second switch, you need an ip default-gateway statement pointing to the default VLAN IP address on your core switch. The second switch doesn't know how to get to networks other than the default.
It will look something like this:

ip default-gateway 192.168.10.1
0
 

Author Comment

by:MISIT
Comment Utility
Thank you rharland2009.
Now, it works!
Now if we can continue this debate i have on this "core" switch also second router (192.168.1.3) which provide VPN connections to remote offices. I already set up the static routes on "core" switch, but i don't want all the clients to have access to all of these vpn static subnets(routes) who are connected to this switch.
What can i do to limit some clients on VLAN10 to deny connections to VPN subnets?
Many thanks.
0
 
LVL 11

Expert Comment

by:rharland2009
Comment Utility
The easiest way would be to put an access-list on your VPN VLAN interface denying traffic from VLAN 10.

Here's a link to configuring ACLs on Procurve switches - very straightforward and works perfectly.

http://www.hp.com/rnd/support/manuals/pdf/release_06628_07110/Bk2_Ch3_ACL.pdf

In this case, you would configure an incoming ACL on your VPN VLAN interface denying traffic from the VLAN 10 subnet.
0
 

Author Comment

by:MISIT
Comment Utility
Ok. Thank you.
And if i want deny traffic from one VLAN to another VLAN what i must do? (Because now all configured VLAN's see each other). I hear from someone that this can be done also with routing?! Or i must also for this case configure an ACL's?
0
 
LVL 11

Expert Comment

by:rharland2009
Comment Utility
ACLs are the easiest way. Simply configure them on your core switch to your satisfaction and you're good to go.
I assure you - it's easy and works well.
0
What Should I Do With This Threat Intelligence?

Are you wondering if you actually need threat intelligence? The answer is yes. We explain the basics for creating useful threat intelligence.

 

Author Comment

by:MISIT
Comment Utility
Ok, i will let you know about my "findings" in relation with your suggestion.
Thanks!
0
 

Author Comment

by:MISIT
Comment Utility
Dear rharland2009.
I would like to ask you another question about my VLAN 30 (WIFI-GUESTS). The WLAN controller and AP's, would also must have a PRODUCTION network (in my case scenario this is VLAN 10) on the same AP's. So, for this i have a HP MSM720 controller who manage all AP's and HP1920-8G PoE switch which provide power and data connection to the AP's. (This debate continues previous about routing ACL's, etc..)
So now ..what would you suggest to configure the whole (with both of 2920-48G switches)network?
I would like to put the WIFI-GUESTS on VLAN 30 and isolate this whole VLAN 30 from any other network. The problem which i have is in which network put the AP's and controller to see each other. If i put it to VLAN 30 this is not probably the good idea for security reasons.
To conclude all of this i want to:
On WLAN network i would like to have two SSID (two VLAN network). One for production and one for wlan-guests network. The production wlan network is VLAN 10 network and must see the whole VLAN 10 network. AP's and controller must be on VLAN 1 (management network) WLAN-GUESTS must be on the same AP's and controller but on VLAN 30 network and isolated from any other network, but if i connecnt to controller i must "see" what is going on on the VLAN 30 (WLAN-GUESTS network).
The VLAN 1 (default-vlan) is the network in my mind which i want to use it for "management network" for manage the network device like server0s (iLO, iDRAC), Switches management,router's management, etc..
Many thanks!!!
0
 

Author Comment

by:MISIT
Comment Utility
Keep in mind that i wonder what i must set up on 1920-8G PoE and on a controller to work as it should. (VLAN's, DHCP,..)?
0
 
LVL 11

Expert Comment

by:rharland2009
Comment Utility
While I'm not intimately familiar with the HP wireless solutions, I can offer how I solve this problem using Aruba infrastructure. Our setup is quite familiar to yours. What we do is this.
The controller will connect to your core switch untagged on the default vlan and tagged in the VLANs it needs to communicate with on your LAN (in this case your PRODUCTION network). The APs can connect back to the controller on the default VLAN, and the AP configuration profile tells the APs about the VLANs for which they'll carry traffic - but the AP forwards all traffic to the controller in a tunnel on the default VLAN, which in turn puts the tag for the appropriate VLAN on the packet and forwards it.
For the guest network, we segregate it by keeping the guest VLAN *on the controller*, with only a default route for them to get to the internet. We also provide DHCP for the guest VLAN on the Aruba controller. Since the guest VLAN doesn't even exist on our LAN, it's completely segregated.
Again, I don't have specific experience with the GUI or CLI of the HP wireless controllers - and HP's method of doing this may be different - but you're on the right track.
Here's a link to a good config guide I found for the MSM that goes into some detail about config steps:

http://cdn.cnetcontent.com/0c/9c/0c9c9003-0f7c-4b04-bc71-eba0ba4d6bbc.pdf
0
 

Author Comment

by:MISIT
Comment Utility
Thanks you for this hint and link.
If are we a little more specific, i probably must set up a VLAN 30 on a 1920-8G switch and or only VLAN 10 on switch or both on 1920-8G PoE and controller?
And what i must set up for WLAN on 2920-48G "core" switches ?
0
 
LVL 11

Expert Comment

by:rharland2009
Comment Utility
You're in luck....I found a link for you that shows the steps for precisely what you want to accomplish!
You can disregard the steps about the ASA firewall. Concentrate on the core HP switch pieces and the controller configuration - substituting your private (LAN) and public (guest) information for the references in the walkthrough.
Long story short, your implementation will be a little different than how Aruba accomplishes this, but it will get you a good result.

http://www.petenetlive.com/KB/Article/0000833.htm
0
 

Author Comment

by:MISIT
Comment Utility
Thank you rharland2009.
0

Featured Post

How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

Join & Write a Comment

Before I go to far, let's explain HA (High Availability) and why you should consider it.  High availability is the mechanism used to provide redundancy to any service at the same site and appears as a single service to the users of that service.  As…
Every server (virtual or physical) needs a console: and the console can be provided through hardware directly connected, software for remote connections, local connections, through a KVM, etc. This document explains the different types of consol…
Access reports are powerful and flexible. Learn how to create a query and then a grouped report using the wizard. Modify the report design after the wizard is done to make it look better. There will be another video to explain how to put the final p…
This demo shows you how to set up the containerized NetScaler CPX with NetScaler Management and Analytics System in a non-routable Mesos/Marathon environment for use with Micro-Services applications.

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

9 Experts available now in Live!

Get 1:1 Help Now