Solved

VLAN Tag for chained network device.

Posted on 2016-09-19
11
79 Views
Last Modified: 2016-09-21
Hi Experts!!! I have another dilemma with vlan configuration. I have vlan 1 for data and vlan 20 for other. I have port has two devices daisy chained. 1st device need to be at vlan 1 and other device needs to be vlan 20. If I untagged for vlan 20 and tagged vlan 1, the device vlan 1 is not able to talk. How that work?  What is best way to handle this? Thanks in advance!!
0
Comment
Question by:MoonLive
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 5
11 Comments
 
LVL 30

Expert Comment

by:Predrag
ID: 41804963
If devices are PC and phone it is easy - tag traffic to phone and untag PC traffic.
Servers can talk "taggish" and can route, so basically, maybe, you can use server to route traffic for you (one of the tags here is Windows server). Or add switch if needed.
Otherwise, if one of devices (phone, server etc) can't do tricky part for other device I guess you will have to add switch somewhere (or hub - but hubs are half duplex, so it is not recommended solution).
0
 

Author Comment

by:MoonLive
ID: 41805155
Good to hear from you Predrag Jovic!.  

Well it is phone and PC! vlan 1 with voice, vlan 20 with security camera. I did untagg vlan 20 and tagged vlan 1, but i can't ping vlan 1 device when i do that.  PC needs to be connect to server for security camera connection.  how does device know which device is tagged or untagged?
0
 
LVL 30

Expert Comment

by:Predrag
ID: 41805346
Hi MoonLive, :)
how does device know which device is tagged or untagged?
That is the biggest issue.
Typically end devices do not know tags at all. Some devices (phones and switches etc) understand tags, but generally end devices do not understand frames with dot1q tag and simply drop frame if tag is present. So, typically, for end devices that don't understand frames with tags some other device (switch, phone) must remove tag from frame before frame is sent to that device (e.g PC, camera). Most of IP phones typically have built in 2 port switch for that purpose, but for some vendors you need to manually assign on phone what is voice VLAN (tagged). There are also implementations where both VLANs are untagged, actually Cisco have 4 ways  to implement VoIP and PC on one port.
Cisco's recommended port configuration on switch port is not including tagging at all:

 interface fastethernet 2/5
  switchport mode access
  switchport access vlan 10
  switchport voice vlan 20

You need to check how port is configured and also how phone vendor implementation.
I am sorry, but there are many ways that can this be implemented, so I can't give you solution.
0
Simple, centralized multimedia control

Watch and learn to see how ATEN provided an easy and effective way for three jointly-owned pubs to control the 60 televisions located across their three venues utilizing the ATEN Control System, Modular Matrix Switch and HDBaseT extenders.

 
LVL 46

Expert Comment

by:Craig Beck
ID: 41807887
Please be clear though... what is connecting to the port, and how?  Is it a phone connecting to the port and a device connecting to the phone?

Assuming it's a phone connected to the switch and a device connected to the phone, can the phone do CDP?  If so just do this on the port:

switchport mode access
switchport access vlan 20
switchport voice vlan 1

Open in new window

0
 

Author Comment

by:MoonLive
ID: 41808626
We are using HP Procurve Switch. The switch connected with ShoreTel phone and PC (security camera client).
I am now sure HP switch have command as Cisco does. if you or anyone knows please let me know.

PC vlan 20
voice vlan 1

i am planning to put voice vlan in the future once I can figure out this type of situation.
Thanks
0
 
LVL 30

Expert Comment

by:Predrag
ID: 41808920
Typically that kind of setup depends on phone needs. You can find configuration details on link below (including Cisco, Juniper and HP (HP Procurve – 2520G-24-POE Example - page 21)).
Data Network Best Practices for ShoreTel VoIP
0
 

Author Comment

by:MoonLive
ID: 41808989
On the document example show all dscp-map priority. if this command is entered in all switches, i don't need voice vlan to setup?  Did i understood correctly?  
Or do i need to setup voice vlan on all switch and tagged all ports that has phone and set those priority?  
I just want clear understanding of this. Thanks
0
 
LVL 30

Accepted Solution

by:
Predrag earned 500 total points
ID: 41809042
You need voice VLAN and PC VLAN setup.
On page 22 you have example how to configure HP ports.

HP is VLAN centric - you assign ports under VLAN.
vlan 10
name voice
 voice
 tagged 1-20, 27
vlan 20
 name office
 untagged 1-20, 27

Above config would be configuration of ports for both voice 1- 20 tagged and untagged PC traffic on port 1 - 20, port 27 would be example of uplink to L3 switch.
This should be useful if you are familiar with Cisco - HP Cisco commands reference guide
Also ports to phones and PCs should be configured as edge ports. I did not, so far, configured ShoreTel phones, so I will not be big help with this one.
I found this one, looks useful - HP ShoreTel configuration.
0
 

Author Comment

by:MoonLive
ID: 41809159
As always. you are helpful!!! do i still need qos dscp-map statement?
0
 
LVL 30

Assisted Solution

by:Predrag
Predrag earned 500 total points
ID: 41809177
You typically need QoS for voice, so yes.
However congestion is typically on WAN link and you need it at least at that point, but anyway - end-to-end QoS is highly recommended.
0
 

Author Closing Comment

by:MoonLive
ID: 41809186
Thanks for the all the respond and useful link.
0

Featured Post

Use Case: Protecting a Hybrid Cloud Infrastructure

Microsoft Azure is rapidly becoming the norm in dynamic IT environments. This document describes the challenges that organizations face when protecting data in a hybrid cloud IT environment and presents a use case to demonstrate how Acronis Backup protects all data.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

How to set-up an On Demand, IPSec, Site to SIte, VPN from a Draytek Vigor Router to a Cyberoam UTM Appliance. A concise guide to the settings required on both devices
For anyone that has accidentally used newSID with Server 2008 R2 (like I did) and hasn't been able to get the server running again because you were unlucky (as I was) and had no backups - I was able to get things working by doing a Registry Hive rec…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…
There's a multitude of different network monitoring solutions out there, and you're probably wondering what makes NetCrunch so special. It's completely agentless, but does let you create an agent, if you desire. It offers powerful scalability …

717 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question