ISP / IP Public routing with 6248P PowerConnect switch
My ISP says I need to pass a level 3; I have a couple of Dell 6248P
I get a single IP address in the range of 216.2.69.x/30 and a default gateway.
I have ALSO (usable) 5 of the intellectual property in the 216.2.234.X/29 range. I have 3 with separate public web servers IP, I need to host on the Internet (they are protected by a firewall/DMZ had through Microsoft TMG).
My ISP waiting to route my public IP 'par' 216.2.69.X gateway. Not only change the IP used 5, I have to send it.
Can I do this with a single Dell 6248P?
Tagging VLAN would not "work, I don't think that, as who knows if everything that we too are surfing, or whatever the customer is looking at our public IP, the web site would support tagging vlan.
I can do a 'physical segmentation"on 4 ports say then the installation program a route from
216.2.69.1-online 216.2.234.64, 65, 66?
and
216.2.234.64, 65, 66? -Online 216.2.69.1.
with 6248 routing?
If the Dell PowerConnect 6248 this is not possible, can anyone recommend a router that can?
Thank you
== John ==
I make a few assumptions here, so if I'm wrong, please correct me. Here's how you must configure the 6248 and this is just one example. The ports you are using may be completely different. Just make necessary substitutions and you should be fine:
Create a VLAN 10 and VLAN 20
Enable
config
database of VLAN
VLAN 10.20
output
Assign an IP address in VLAN 10
interface vlan 10
216.2.69.1/30 IP address
output
Assign an IP address in VLAN 20
interface vlan 20
216.2.234.65/29 IP address
output
enable routing in the world
IP routing
Go to an interface to which you connect to the ISP and set access mode for VLAN 10
interface ethernet 1/g1
switchport mode access
switchport access vlan 10
Disable spanning tree
output
Go to the interface or interfaces that you will use for your servers. If you connect the servers directly to the 6248 you do the following:
range of interface ethernet 1/g2-1/g4
switchport mode access
switchport access vlan 20
disable the spanning tree (but only if you're connected directly to the server)
output
Configure a default route to get the ISP since public addresses internal
IP route 0.0.0.0 0.0.0.0 216.2.69.2
If your ISP est.69.1 and you etes.69.2, your last noted the route should point vers.69.1 instead de.2.
I hope this makes sense.
Tags: Dell Switches
Similar Questions
-
Help routing with double connections 1 ISP, 2 routers, Firewall-2 lights
My company is moving to a new building and ordered redundant Internet connections by the same ISP. I did have a chance to talk to the ISP seller, but from what I've heard say that they expect us to participate in the BGP as will force us to balance load and high availability for inbound web traffic. My limited experience with BGP has been in a lab environment. The company has already bought two routers and two ASAs. We have a block of public IP addresses.
My goals are to
1 allow internal out of the Internet users
2. allow to outside users to browse our public web site.
3. configure the routers and the ASAs so that if any one device Internet connections or lack fails, the business will continue as usual.Here are some of my questions to help me make sure that I'm heading down the correct path:
-The IP addresses on the links point to point between our routers and the ISP will come from our IP address block, or if they are separated/30 links provided by the ISP? (Even once, I have not had the chance to talk to the seller)
' '-Will be the link iBGP "has" requires the use of public or private IP addresses IPs can be used? In addition to configuring iBGP on these routers, is thus a first protocol redundancy Hop configured here?
-Should there be links routed between R1 and R2 and FW2, FW1? Too complicating the design without real value?
-Would be OSPF or EIGRP usually configured for links B, C D & to allow redundancy you want between the firewalls and routers?
-What is the best practice for the determination of the flow of outbound traffic layer 3 switch (6509 s configured as a VSS) to the two ASAs?
Any help is greatly appreciated.
Mike
Hello
first of all that you need in your design for me of course that traffic inbound and outbound flows must be aligned end-to-end
answers to your questions are by below:
-The IP addresses on the links point to point between our routers and the ISP will come from our IP address block, or if they are separated/30 links provided by the ISP? (Even once, I have not had the chance to talk to the seller)
Any dose not need and ask the ISP to provide their own IPs for p2p links (to avoid wasting your public IP addresses)
' '-Will be the link iBGP "has" requires the use of public or private IP addresses IPs can be used? In addition to configuring iBGP on these routers, is thus a first protocol redundancy Hop configured here?
You cannot use private IP addresses
-Should there be links routed between R1 and R2 and FW2, FW1? Too complicating the design without real value?
Here, it's better to use a shared VLAN L2 (switch) for these interfaces get FHRP of routers and the FWs failover works as expected
-Would be OSPF or EIGRP usually configured for links B, C D & to allow redundancy you want between the firewalls and routers?
If you use between HSRP/VRRP routers and using failover between the FWs, then using a shared vlan L2 as suggested above will be necessary without IGP, such as EIGRP also the link between the firewall used for FW failover is not like the one used between routers 'dose not need routing.
-What is the best practice for the determination of the flow of outbound traffic layer 3 switch (6509 s configured as a VSS) to the two ASAs?
If you put the ASA FWs in failover mode, then the IP address of th eprimary/active ASA FW will be used for your static routes in the L3 switches to point to and this IP address will be used by the secondary FW in a failover situation "transparent and automatic.
hope this helps
If useful rates
-
Access to the COR to two XP systems behind a router with a single public IP address
Hello
is it possible to access the RDC to two XP systems, with two different port for the DRC, behind a router with a single public IP address?
Please note this ia a small home network without any parameters of the field. I use IP to access DRC.
You comments are appreciated.
Thank you
Use different ports for the DRC on both XP and configure the router to redirect to the appropriate port on the appropriate computer.
See the article in the Microsoft Knowledge Base How to change the listening port for remote desktop .
-
PowerConnect switch and Cisco routers
I have 4 Cisco routers connected to our Dell Powerconnect 7024. This is a laboratory environment where I'm having every act of router (2 per site) as a WAN gateway for these 2 sites.
Site 1 Site 2
2 3 router
PC - Dumb_switch PowerConnect Dumb_switch client - PC Client
Router 1 router 4
There are a few other Vlans on the switch with connected devices. With the current configuration, these two sites can communicate with any other "site" connected to the switch on each route, with the exception of the other.
Directly connected to the router interfaces are in trunk mode, as it's the only way I could get the dell to connect with the Cisco. Ive read in other threads that the general mode is usually suggested on the powerconnect switch, but had no luck with this configuration.
Router 1---> item in gi1/0/15 (vlan 10)
Router 2---> item in gi1/0/14 (vlan 11)
Router 3---> item in gi1/0/22 (vlan 16)
Router 4---> article gi1/0/23 (vlan 14)
Example: a ping from Site 1 can reach int 22 of the switch without problem, but I can't ping jump according to R3. As all the other devices on this switch can talk to these sites, I'm not clear if the problem is my config switch dell or routers. Any input would be greatly appreciated. Thank you!
! Current configuration:
! Description of the system "PowerConnect 7024, 5.1.2.3, VxWorks 6.6"
! 5.1.2.3 system software version
! 'Normal' system operation mode
!
Configure
GVRP enable
VLAN 2-7, 9-14, 16
output
VLAN 2
name 'BOSTON '.
output
VLAN 3
name "MIAMI".
output
VLAN 4
name of 'THE
output
VLAN 5
name "SEATTLE".
output
VLAN 6
name "DALLAS".
output
VLAN 7
name "London".
output
VLAN 9
name "Frankfurt".
output
VLAN 10
name "Rome".
output
VLAN 11
name "Sczecin.
output
VLAN 12
name "Budapest".
output
VLAN 13
name "Moscow".
output
VLAN 14
name "Quebec".
output
-Other - or ITU (q)
VLAN 16
name "Winnipeg".
output
hostname "Devlin".
location 1/0 2. PowerConnect 7024
clock timezone-5 minutes 0
battery
1 2 Member! PCT7024
output
out-of-band interface
Shutdown
output
no ip domain-lookup
"local" IP domain name
IP routing
IP route 0.0.0.0 0.0.0.0 172.16.37.3
IP route 172.16.37.160 255.255.255.240 172.16.37.162
IP route 172.16.37.112 255.255.255.240 172.16.37.162
IP route 172.16.37.112 255.255.255.240 172.16.37.147
IP route 172.16.37.144 255.255.255.240 172.16.37.147
IP route 172.16.37.240 255.255.255.240 172.16.37.244
IP route 172.16.37.224 255.255.255.240 172.16.37.244
IP route 172.16.37.224 255.255.255.240 172.16.37.217
-Other - or ITU (q)
IP route 172.16.37.208 255.255.255.240 172.16.37.217
ARP 172.16.37.162 0022.9057.7F51
interface vlan 1
IP 172.16.37.4 255.255.255.240
bandwidth 10000
IP ospf cost 10
output
interface vlan 2
IP 172.16.37.17 255.255.255.240
output
interface vlan 3
IP 172.16.37.33 255.255.255.240
output
interface vlan 4
IP 172.16.37.49 255.255.255.240
output
interface vlan 5
IP 172.16.37.65 255.255.255.240
output
interface vlan 6
IP 172.16.37.81 255.255.255.240
output
interface vlan 7
-Other - or ITU (q)
IP 172.16.37.97 255.255.255.240
output
interface vlan 9
IP 172.16.37.129 255.255.255.240
bandwidth 10000
output
interface vlan 10
IP 172.16.37.145 255.255.255.240
bandwidth 1000
IRDP IP
output
interface vlan 11
IP 172.16.37.161 255.255.255.240
bandwidth 1000
IRDP IP
output
interface vlan 12
IP 172.16.37.177 255.255.255.240
bandwidth 100000
output
interface vlan 13
IP 172.16.37.193 255.255.255.240
bandwidth 1000
output
interface vlan 14
IP 172.16.37.209 255.255.255.240
bandwidth 1000
output
interface vlan 16
IP 172.16.37.241 255.255.255.240
bandwidth 1000
IP ospf cost 100
output
No flowcontrol
!
interface item in gi1/0/3
spanning tree portfast
output
!
interface item in gi1/0/4
spanning tree portfast
output
!
interface item in gi1/0/5
spanning tree portfast
switchport access vlan 2
output
!
interface item in gi1/0/6
spanning tree portfast
switchport access vlan 3
output
!
interface item in gi1/0/7
spanning tree portfast
switchport access vlan 4
output
!
interface item in gi1/0/8
spanning tree portfast
switchport access vlan 5
output
!
interface item in gi1/0/9
switchport access vlan 6
output
!
interface item in gi1/0/10
switchport access vlan 7
output
!
interface item in gi1/0/11
spanning tree portfast
switchport mode trunk
output
!
interface item in gi1/0/12
spanning tree portfast
switchport mode trunk
output
!
interface item in gi1/0/13
switchport access vlan 9
output
!
interface item in gi1/0/14
Speed 100
full duplex
switchport mode trunk
switchport general allowed vlan add 10 tag
switchport access vlan 10
output
!
interface item in gi1/0/15
Speed 100
full duplex
switchport mode trunk
switchport general allowed vlan add 11 tag
switchport access vlan 11
output
!
interface item in gi1/0/16
switchport access vlan 12
output
!
interface item in gi1/0/17
switchport access vlan 12
output
!
interface item in gi1/0/18
switchport access vlan 13
output
!
interface item in gi1/0/19
switchport access vlan 13
output
!
interface item in gi1/0/22
Speed 100
full duplex
switchport mode trunk
switchport general allowed vlan add 16 tag
switchport access vlan 16
output
!
interface item in gi1/0/23
Speed 100
full duplex
switchport mode trunk
VLAN allowed switchport General add 14
switchport access vlan 14
output
!
interface item in gi1/0/24You could probably create a static route in Router 1 router 4 with a priority which is better than the other options, so we're going unless the link is down.
-
Configure L3 routing with different suppliers
Hello people, I am not used to work with layer 3 switches, so I need your help: I have two different sites. Each site has one switch L3 and networks like the example below: Switch A (power connect 6224):Network 192.168.0.0 /24 Switch B (Cisco 3560)Network 172.19.16.0 /24network 10.10.10.0 /24 I need to configure both sites to comunicate witch each other. I have the following idea: - Connect a Cable between two switches- Create a vlan on each switch and configure the ips like below:Switch A: interface ethernet 1/g1 - 10.0.0.2Switch B: interface gigabit 1 - 10.0.0.3- Configure static route on each switch like:Switch A: ip route 172.19.16.0 255.255.255.0 10.0.0.3 ip route 10.10.10.0 255.255.255.0 10.0.0.3Switch B: ip route 192.168.0.0 255.255.255.0 10.0.0.2 Is this possible? Is this configuratios right? If so, do I need to improve something else? A appreciate any help.
The decisive factor here is going to be if the PowerConnect and Cisco have different Broadcast domains from each other. If they have a separate broadcast domain, then the method you mentioned should work fine. If they share broadcast domains, then you want the physical connection to the two switches in general or Trunk mode, allowing the VLANS on the connection.
-
How can I secure my laptop when I surf the internet via a public router at work?
How can I secure my laptop when I surf the internet via a public router at work? I mean if I use a router to work and others use too and I use a private laptop! I heard that someone hase the knoladge he can enter my laptop the couscous that he uses the same router I do. you have a special program for that, or is there a place in my computer that I need to enable to avoid the unwanted entries?
If your Windows is updated and your Windows Firewall is enabled and that you have updated anti-virus, that would be fine. In Windows 7, you must check Action Center in Control Panel to see your security status, if something is wrong that it will show a message in Windows XP and Windows Vista, he calls the center of security.
They may only enter your laptop or hack, if your firewall is disabled or there is a vulnerability in your system or a Malware would cause of vulnerability, and in all cases to ensure that your Windows updates and anti-virus is running, you are protected.
Another thing is that if your router requires the password, then choose strong password and change it regularly, if it is public without password or authentication, then you need to careful when visiting Web sites because they could be monitor and publicly display information. Some websites have encryption that in Internet Explorer, it shows as a lock icon pad indicating that your transaction is encrypted and you're safe.
It depends also wireless encryption in your company that will be in service by admin or SOUND Department if it's WPA2 which is good but for WEP or WPA, you should be very careful. I suggest to discuss this issue with your COMPUTER service too.
-
Wired router with POE and Gigabit ethernet to run two AC1750 access points?
Hello, I'm looking for a recommendation for a wired router with POE and Gigabit ethernet to connect to both access to ceiling LinkSys AC1750 points internet routing on the WAN to a Virgin Media UK cable connection plug - can someone advise a good solution?
I'm a Home Office / Small Office so user there are several Wired's devices and a mixture of wireless clients. I need at least 8 ethernet outlets. Reliablity and speed performance are important, but not important enough to go overboard on the cost!
Many thanks to you all.
I recommend a router Linksys (SMB) LRT214\224 and a switch POE LGS Linksys (SMB). This combination will be very fast and stable.
-
RV082 - routing with quickvpn issues
Hi all
I ve a special configuration to my network, we have about 20 sites managed by an external supplier. Last week, we bought a Linksys RV082, in order to enable remote access in our network.
It is possible to configure the router with an ip address public luckily. We are currentliy use tar on the firewall to allow access to the router. / * Style definitions * / table. MsoNormalTable {mso-style-name : « Normale Tabelle » ; mso-tstyle-rowband-taille : 0 ; mso-tstyle-colband-taille : 0 ; mso-style-noshow:yes ; mso-style-priorité : 99 ; mso-style-qformat:yes ; mso-style-parent : » « ;" mso-rembourrage-alt : 0 cm 5.4pt cm 0 5.4pt ; mso-para-margin : 0 cm ; mso-para-marge-bottom : .0001pt ; mso-pagination : widow-orphelin ; police-taille : 11.0pt ; famille de police : « Calibri », « sans-serif » ; mso-ascii-font-family : Calibri ; mso-ascii-theme-font : minor-latin ; mso-fareast-font-family : « Times New Roman » ; mso-fareast-theme-font : minor-fareast ; mso-hansi-font-family : Calibri ; mso-hansi-theme-font : minor-latin ; mso-bidi-font-family : « Times New Roman » ; mso-bidi-theme-font : minor-bidi ;}
IP nat inside source 192.168.5.180 static and external IP address
When I opened the public ip address in my browser I can access the web interface of the router. So far so good.
The WAN Interface is configured as follows
Static IP 192.168.5.182
Subnet 255.255.255.0
Gateway 192.168.5.254
DNS 192.168.1.1
The unit is configured as a router (with the two RIP) and a 192.168.252.1 IP address. (This network is unique in our company)
The firewall is disabled
HardwareVersion 2
When one add a pptp user and enable the pptp, I m able to access each subnet in our company server
When I add a user QuickVPN and successfully establish a connection, I m unable to access any subnet/Ip in our company. Only the WAN IP 192.168.5.182 is ping-able. I can't ping any device, neither the 192.168.252.1 nor the 192.168.5.10
This is the routing table when you're connected via pptp
List of Routing Table entries Destination IP address Subnet Mask Default gateway Hop Count Interface 192.168.252.1 255.255.255.255 * 50 ppp200 192.168.252.200 255.255.255.255 * 0 ppp200 192.168.5.0 255.255.255.0 192.168.5.182 0 ixp1 192.168.5.0 255.255.255.0 * 40 ixp1 192.168.5.0 255.255.255.0 * 45 ipsec0 192.168.252.0 255.255.255.0 192.168.252.1 0 ixp0 192.168.252.0 255.255.255.0 * 50 ixp0 by default 0.0.0.0 192.168.5.254 40 ixp1 My questions,
How to configure the device to access the network via quickvpn as pptp?
My goal is accessible?
I ve no more ideas, the I ve found anything in the internet, or on google, nor in this forum that match my troubles.
Please give me your comments, regards dario
PS: Sorry for my bad English...
It will be difficult, especially because QVPN does not allow you to configure it to several networks. The reason why PPTP and QVPN work doesn't have is the Protocol in use. QVPN use IPSec in which you specify the authorized networks, where in PPTP you log only the user to connect to the device or the server. There are ways to deceive our router so that we can make what you need, but it is not easy and you are limited to the number of users who can use the connection. I wrote a couple of 'how to' using IPsecuritas for Mac and also shrew VPN. You will not be able to get several subnets with the QVPN customer.
-
EIGRP running between the router and ASA by switch
Hello
Is that possible I can running an EIGRP between router and ASA by switch?
Router and ASA connected to the switch with static route.
Hi Tommy Chin.
It is possible, we must advertise to the route between the router and ASA.
Please provide your connectivity diagram to better explain.
For example...
interface GigabitEthernet0/0
Description links to WAN router
nameif OUTSIDE
security-level 50
IP 10.1.1.1 255.255.255.192 ensures 10.1.1.2
Summary-address eigrp 100 10.1.0.0 255.255.0.0 1
!
Confiuration Protocol EIGRP
standard access list eigrpACL_FR allow a
!
Router eigrp 100
eigrpACL_FR distribute-list in the interface outside
neighbor 10.1.1.3 OUTSIDE interface
neighbor 10.1.1.2 OUTSIDE interface
Network 10.1.1.0 255.255.255.192
redistribute connected
redistribute static
!
Kind regards
Srinivas.
Note: if it solves your problem it mark it as resolved.
-
I have a Cisco ACS 4.2 on Windows 2003. Authentication works very well for various cisco as the routers, VPN etc Hub devices
Today, I added a 48-Port L2 switch as a client of the AAA authentication works well. However, I see several connection attempts that have failed this L2 switch with the user 'C '.
Message Type: Authentic failed
Caller ID: async
Authentic-failure-Code: external DB invalid or wrong password user
NAS-Port: tty0
What is causing this connection failed?
If the port console switch generating errors of parasitic connection is connected to a device offering remote access to the console port, then it is likely that an output of this unit is causing the false connection attempt.
If this device is an IOS router with a bunch of asynchronous ports add "no exec" to the line connected to the switch console port.
-
I had this problem since the first part of January 2011. I use a dial-up connection, I have windows vista home Premium 32 bit. I can click on the internet icon on my desktop what the little box that has a checkbox to automatically connect to the internet, the diallog which is supposed to have the name of the internet connection is empty, it tries even to compose, but he does not open the port to dial an outside line. All the time I have a tick on my tab internet connections dial options each time that a network connection is not present or always dial my connection default slot choose settings if you need to configure a proxy server for a connection, it will not work on one, I can manually connect using of these (one at a time) but every time I click on the internet icon does not recognize a connection already exists, I get this message telling me that I need to connect to the cause of the internet, I work in offline mode. Whenever I get that message I click on connect to go online then it trying to connect automatically by calling and then I get this message, it cannot establish a dial-up access and still it does not open the port to dial an outside line.
I can connect manually using the same connection and put the check box on the never dial a connection under select parameters if you need to configure a proxy server for a connection on the connections to internet options tab and I don't have a problem connecting to the internet. I did a reset and set up a new connection and that didn't work either.
The Connection Wizard recalled the correct information, it was not correct that then I would not use this same computer online now. The reason is that I am currently using the same computer that has the problem of not being able to connect to internet automatically online. This same computer that has the problem of not being able to connect to the internet automatically, it will connect manually using exactly the same ISP configuration by routing the connection in order to never establish a connection on the internet connections tab options, while I'm on dial upward, it is assumed to be always dial my default connection under choose settings If you need to configure a proxy server.
I have windows Vista Home premium 32-bit with service pack 2
-
My Ipad air2 does not start. Tried hold it together switch with on/off switch. Apple logo appears for about 15 seconds and then turns off again.
Is there another way to start the IPAD?
Try the steps here:
-
Hi my TV a WPS button my router N300 model [WNR2200] has no WPS button. What router do I need to connect to broadband?
Any router with a WPS option. Or use your router and enter the appropriate security settings.
-
Using Windows XP with an access switched. How can I prevent the network Dialer to invite the user connect even if I checked: never establish a connection to the Control Panel, then apply, then OK? She comes right back in a few minutes for: always connect by default. Help! Control panel Connections tab doesn't really seem to apply my change to never establish a connection right back to always make the default connection. What else is there to do?
Hi Richard,
You did it all change hardware or software on your computer before this problem?
You can follow this link & check if the problem persists:
Network connections and remote access troubleshooting
Hope the helps of information.
-
VIsta - Local access only
HI -.
I recently moved. I use the same router from my old apartment and I had no problem connection in the past. Since I moved I have a new Time Warner modem (Cisco) and the modem works fine.The router also works very well I'm able to connect with my iPhone and IPad without any problem.
But when I try to connect with my wireless laptop, it will only connect to Local access. If I connect the laptop to the router with the ethernet cable, it works very well.
It's a Dell Studio 15 with Vista.
The computer is able to connect to wifi to other places without any problem, but for some reason that I can't connect home. I tried to reset the modem and the router several times, but that did not help. I tried the option repair & diagnose several times but it doesn't work.
I tried to look for other solutions online and tried to disable IPv6, and while it helped some and I was able to connect wireless, the computer ran so slowly that it didn't seem like a good solution.
This has been very frustrating. Thanks in advance for any help or suggestion.
StaciHello Staciusa,
Have you tried to change the wireless channel that your router is running at? There may be interference that could prevent the internet connection:
Take a look at step 6 in this article that give more details about it:
http://www.Microsoft.com/athome/Setup/wirelesstips.aspx
If you need assistance to change the settings of the specific router, you will need to contact your router manufacturer or your internet service provider.
Maybe you are looking for
-
Dear team, I want to know ask. I always use the 5s iPhone gold from 2014. It is perfectly good work again. It is only fair that I get bored now and I want a bigger screen. My question is can exchange my phone today again gold G N 7 and 32. coz I don'
-
Cannot change Hardware acceleration settings
HelloI have a Toshiba laptop with windows vista and cannot read my desperate Housewives Games distributed by PBA games. When I try to install it it says that my hardware acceleration has failed. He told me to install direct X 9 .0c which I did and it
-
Direct access USB of Labview?
A USB port may not be comparred to a serial port or RS-232 connection, but is it possible with LabVIEW or similar, to have the two pins on the port data generate a camera digital power signal or even a PWM signal. The USB communication protocol is ri
-
Files duplicated in the libraries?
I have files duplicated music in my library - there is one under libraries and the other under Documents. Within these folders are folders, called 'My Music' or just 'music '. They look the same as they have the same content, but when I try to merge
-
I can't update iTunes on windows 7
I'm trying to update iTunes on windows 7. Downloaded to office iTunes64Setup and I tried to run as an administrator. Also tried uninstall all the programs Apple and re - install. FILE SECURITY GET ERROR: C:\PROGRAM DATA\ 34BE82C4-E596-4e99-A191-52C61