troubleshooting Question

VOIP VLAN on Cascaded SG300-xx Switches

Avatar of hypercube
hypercubeFlag for United States of America asked on
CiscoNetworkingVoice Over IP
6 Comments1 Solution284 ViewsLast Modified:
I'm adding VOIP on an existing site that uses either Cisco SRW20xx or SG300-xx switches.  I'd like you to comment on my plan for doing this:

The VOIP will be coming in from the internet on it's own connection / firewall and will be using a separate local area subnet.
It will generally be distributed through all the switches unless there's no phone at all, just computers or network devices.

There is a central LAN switch that feeds into other switches in cascade.  I will refer to this as the TOP switch here.

My plan for the downstream switches is this:
Assign VOIP VLAN 100 to all the switch ports along with the Default VLAN 1.
Trunk all the switch ports.
Tag VOIP VLAN 100.

My plan for the TOP switch is this (there being only Default VLAN 1 and VOIP VLAN 100):
Trunk all the switch ports that feed downstream switches.
Trunk any switch ports that directly feed a VOIP phone.
Leave any other ports on Default VLAN 1 in Access Mode.
Assign VOIP VLAN 100 to a single switch port that goes to the firewall.  
Make this a General Mode port joined to VOIP VLAN 100.
Manually tag this port <<< is that right?
Internet Port Setting / TaggedThe VOIP firewall won't have any VLANs set up, just a generic LAN.

Since I've never done this before, I'm a bit unclear as to whether the VOIP firewall port needs to be tagged or not BUT the port sure needs to be part of the VOIP VLAN 100 ONLY with no interVLAN routing / connection.  I want the traffic on the two VLANs to be completely separate so it looks like this:

Main Firewall > TOP LAN Switch > Computers, etc.  using Default VLAN 1

VOIP Firewall> TOP LAN Switch<>Trunked Ports<> Phones using VOIP VLAN 100 and related computers using Default VLAN 1.


Does this look OK or are there suggestions / cautions?
ASKER CERTIFIED SOLUTION
Aaron Tomosky
Director, SD-WAN Solutions

Our community of experts have been thoroughly vetted for their expertise and industry experience.

Join our community to see this answer!
Unlock 1 Answer and 6 Comments.
Start Free Trial
Learn from the best

Network and collaborate with thousands of CTOs, CISOs, and IT Pros rooting for you and your success.

Andrew Hancock - VMware vExpert
See if this solution works for you by signing up for a 7 day free trial.
Unlock 1 Answer and 6 Comments.
Try for 7 days

”The time we save is the biggest benefit of E-E to our team. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange.

-Mike Kapnisakis, Warner Bros