L3 PC 6248 ISP routing switch

And I was wondering if someone could help me please?
We have recently sign up for FPL FiberNet Direct Internet Access (DIA), and they give us a point to point IP 30 for connection between our fiber-copper Transceiver and the NOC and also gave us a block of 28 public IPs we road to the 30 default of IPs to our local network gateway and servers.
We have a few 6248 PC laying around and were told to use one of them to get the job of the internet!
I did research on how to make this work between manual the device reference guide and other threads on the support forum, I came up with the following configuration and I was wondering anyone could look at it and let me know if it wise and might work or if I'm missing something, or maybe do it in a completely different way :

Create a VLAN 100 to 28 address block

Console #configurer
console (config) #vlan database
Console (config - vlan) #vlan 100
Console (config - vlan) #exit

Configure the VLAN routing for the VLAN and assign an IP address

Console #configurer
Console (config) #interface vlan 100
Console (config-if-vlan100) #routing

Console (config-if-vlan100) #ip address 68.168.25.33 255.255.255.240

Console (config-if-vlan100) #exit

Console (config) #ip Routing

Associate a subnet IP with a VLAN

It shows how to configure the switch so that all hosts with IP addresses in the network of 68.168.25.32/28 are members of the VLAN 100.

Console #configurer
console (config) #vlan database

subnet of console (config - vlan) #vlan association 68.168.25.32 255.255.255.240 100

Create VLAN 200 out of the 30 internet

Console #configurer
console (config) #vlan database
Console (config - vlan) #vlan 200
Console (config - vlan) #exit

Configure the VLAN routing for the VLAN and assign an IP address

Console #configurer
Console (config) #interface vlan 200

Console (config-if-vlan200) #ip address 198.150.3.110 255.255.255.252

Console (Config-if-vlan200) # name internet vlan
Console (config-if-vlan200) #routing

Console (config-if-vlan200) #exit

Assign a Port to VLAN200

Console (config) #interface ethernet 1/g1

access mode console (config-if-1/g1) #switchport

Console (config-if-1/g1) #switchport access vlan 200

Console (config-if-1/g1) #exit

road to console (config) #ip 0.0.0.0 0.0.0.0 198.150.3.109

OK, we finally got I work, my mistake was that I had together 1/g1 port for access mode and it was supposed to be in general Mode so I issued the following command so my VLAN would receive traffic labeled the ISP VLAN 200 they gave me with:

interface ethernet 1/g1

switchport mode general

switchport General pvid 200

switchport general allowed vlan add 200 tag

I also was on the phone with them to make sure that I got everything we need on the VIRTUAL LAN, they gave me and to make sure we could ping back, they end up doing some changes at their end for all operate as it should, it's the running configuration see the final :

! Current configuration:

! Description of the system "PowerConnect 6248, 3.3.7.2, VxWorks 6.5.

! 3.3.7.2 system software version

! Passage mode is configured as disabled

!

Configure

database of VLAN

VLAN 100 200

VLAN 100 1 routing

VLAN 200 2 routing

output

battery

1 2 Member

output

IP 192.168.1.1 255.255.255.0

by default-gateway IP 192.168.1.254

no console logging

IP routing

IP route 0.0.0.0 0.0.0.0 198.150.3.109

interface vlan 100

Routing

IP 68.168.25.33 255.255.255.240

output

interface vlan 200

name ' internet - vlan ".

Routing

IP 198.150.3.110 255.255.255.252

output

user name 'admin' password password

!

interface ethernet 1/g1

switchport mode general

switchport General pvid 200

switchport general allowed vlan add 200 tag

output

!

interface ethernet 1/g2

GVRP enable

switchport access vlan 100

output

!

interface ethernet 1/g3

GVRP enable

switchport access vlan 100

output

!

interface ethernet 1/g4

GVRP enable

switchport access vlan 100

output

!

interface ethernet 1/g5

GVRP enable

switchport access vlan 100

output

!

interface ethernet 1/g6

GVRP enable

switchport access vlan 100

output

!

interface ethernet 1/g7

GVRP enable

switchport access vlan 100

output

!

interface ethernet 1/g8

GVRP enable

switchport access vlan 100

output

!

interface ethernet 1/g9

GVRP enable

switchport access vlan 100

output

!

interface ethernet 1/g10

GVRP enable

switchport access vlan 100

output

!

interface ethernet 1/g11

GVRP enable

switchport access vlan 100

output

!

interface ethernet 1/g12

GVRP enable

switchport access vlan 100

output

!

interface ethernet 1/g13

GVRP enable

switchport access vlan 100

output

!

interface ethernet 1/g14

GVRP enable

switchport access vlan 100

output

!

interface ethernet 1/g15

GVRP enable

switchport access vlan 100

output

!

interface ethernet 1/g16

GVRP enable

switchport access vlan 100

output

!

interface ethernet 1/g17

GVRP enable

switchport access vlan 100

output

!

interface ethernet 1/g18

GVRP enable

switchport access vlan 100

output

!

interface ethernet 1/g19

GVRP enable

switchport access vlan 100

output

!

interface ethernet 1/g20

GVRP enable

switchport access vlan 100

output

!

interface ethernet 1/g21

GVRP enable

switchport access vlan 100

output

!

interface ethernet 1/g22

GVRP enable

switchport access vlan 100

output

!

interface ethernet 1/g23

GVRP enable

switchport access vlan 100

output

!

interface ethernet 1/g24

GVRP enable

switchport access vlan 100

Tags: Dell Tech

Similar Questions

  • Should I fill the ISP router or TimeCapsule airport?

    Hello

    I hope that you will be able to provide me with some clarification on this subject: I recently bought a TimeCapsule airport that I intend to use for the implementation of a personal home network + network comments + backups etc. used in the family.

    Navigation through the Q & A on this (and other) support forum, I came to the conclusion that I can't use the airport as a router and at the same time use the router in the router/modem provided by my ISP. What I would like your help with is to understand what are the advantages and disadvantages of fill the ISP modem/router and airport, respectively.

    I understand now there might be an advantage to use the airport as the router because it's a powerful piece of equipment, but it might be a bad idea wise security visible directly from the Internet?

    Thank you for your support!

    If the ISP router is your main router, then the time Capsule would establish to a network bridge by selecting the join an existing network in the Airport utility. If the ISP router is a distinct feature of the cable modem, then remove it and use only the time Capsule as the router.

  • Communication from router to router via an ISP router

    Nice day

    I have a Setup at home, with that I would like to help.

    I have two routers in my house. One in the living room and the bedroom. The routers are connected to the router of my ISP.

    I would like to communicate between my two routers for the purpose of sharing SMB between my NAS and the NUC Intel running kodi. I am not able to routers link the two and am stuck with the ISP router. If I filled two routers I can share, but I prefer to do (if possible) not in bridge mode. Is it possible to get both routers to talk with each other? I'm a little lost here

    I put the 1900ACS in the lounge to have:

    IP: 192.168.1.1

    LAN DHCP: 192.168.1.2 to 192.168.1.50

    And the EA6400 in the bedroom:

    IP: 192.168.1.51

    LAN DHCP: 192.168.1.52 to 192.168.1.100

    Drawing enclosed with the installation program:

    http://i.imgur.com/WoJ8nW7.PNG

    Hi, @ckZA. Because the router is a NAT firewall, the installation type you want is not possible. The router will block incoming pings outside its own network.

    You rather connect the EA6400 to the WRT1900ACS and the EA6400 value clipping that both computers are connected to the same DHCP. They should be able to discover each other with this configuration.

    I hope this helps.

  • bandwidth of router-switch concern

    I have a router with integrated 10/100 switch linksys wireless.  I need increase the bandwidth on the wired side and plans to put a switch 10/100/1000 between the router and the cable devices.  Given that the routing table is stored on the router, will be the speed of the slower speed of the router switch?  I don't want to get a switch of concert and brought 100 between the wired devices.

    Thank you!

    The router will not slow down the switch.

    The routing is no concern on a switch. Routing is only between networks, for example between your network and the internet.

    An ethernet switch extends the ethernet network. On the inside of your LAN packets are not routed IP but address by devices ethernet mac addresses.

    Between two devices connected to your local network, you will see the speed that is available on the way between these two devices. If the path is entirely 1000 Mbit/s, then it will be the speed that you see. So, if you get an ethernet Gigabit switch disconnect all devices from the router and connect them all to the Gigabit switch passed to the router, then you have gigabit between all your LAN devices except for traffic to and from the router, which is essentially the internet traffic.

  • How to distinguish the physical interface and logic (subinterface) interface to the Cisco router/Switch?

    Hi Expert,

    How to distinguish the physical interface and logic (subinterface) interface to the Cisco router/Switch? Can you please clarify a formal way for this so have?

    A physical interface is numbered with the same name of the interface when printing on the physical port. For example "GigabitEthernet 0/1" corresponds to port 1 of the 0 module (or the base unit).

    A logical interface can be a subinterface on a routed port and will have a point ("". "") preceding the number sous-interface (ex. GigabitEthernet 0/1.1). It can also be a loop or a virtual interface (on a router this could also include interfaces like the tunnel and virtual tunnel or VTI types). A switch may also have a VLAN logical interfaces (e.g. interface vlan 1) which are used as layer 3 virtual interfaces of type.

  • How to use Layer 2 Ports on the Cisco 1841 router switch

    Hello

    I use the Cisco 1841 router with a single port layer 3 Fe0 and 8 Ports switched.

    I gave the IP on the Fe0 port which is connected to another router.

    Now I don't know how to use Layer 2 of the router switch ports.

    I tried to make one of the port as a Port of access by switchport mode access and connected my laptop and the same subnet given IP, but I can't ping my Fe0 IP port and vice versa, as I am also unable to ping my laptop router.

    Can someone explain to me how to use these ports on layer 2?

    Hi Muhammadatifmasood, take a look at the link below, I'm sure that you will find it useful.

    https://supportforums.Cisco.com/discussion/10919631/how-enable-routing-b...

    BenSamayoa

  • L2l VPN between ASA with the IP address public and CISCO2911 behind the ISP router with port forwarding

    Hi all

    My apologies if this is a trivial question, but I spent considerable time trying to search and had no luck.

    I encountered a problem trying to set up a temporary L2L VPN from a Subscriber with CISCO2911 sitting behind the router of the ISP of an ASA. ISP has informed that I can't ignore their device and complete the circuit Internet on the Cisco for a reason, so I'm stuck with it. The Setup is:

    company 10.1.17.1 - y.y.y.y - router Internet - z.z.z.z - ISP - LAN - 10.x.x.2 - XXX1 - ASA - 10.1.17.2 - CISCO2911 - 10.1.15.1 LAN

    where 10.x.x.x is a corporate LAN Beach private network, y.y.y.y is a public ip address assigned to the external interface of the ASA and the z.z.z.z is the public IP address of the ISP router.

    I have forwarded ports 500, 4500 and ESP on the ISP router for 10.1.17.2. The 2911 config attached below, what I can't understand is what peer IP address to configure on the SAA, because if I use z.z.z.z it will be a cause of incompatibility of identity 2911 identifies himself as 10.1.17.2...

    ! ^ ^ ^ ISAKMP (Phase 1) ^ ^ ^!
    crypto ISAKMP policy 5
    BA 3des
    md5 hash
    preshared authentication
    Group 2
    lifetime 28800
    isakmp encryption key * address no.-xauth y.y.y.y

    ! ^ ^ ^ IPSEC (Phase 2) ^ ^ ^!
    crymap extended IP access list
    IP 10.1.15.0 allow 0.0.0.255 10.0.0.0 0.255.255.255
    Crypto ipsec transform-set ESP-3DES-SHA 3rd-esp esp-sha-hmac
    card crypto 1 TUNNEL VPN ipsec-isakmp
    defined peer y.y.y.y
    game of transformation-ESP-3DES-SHA
    match the address crymap

    Gi0/2 interface
    card crypto VPN TUNNEL

    Hello

    debug output, it seems he's going on IPSEC States at the tunnel of final bud QM_IDLE's.

    What I noticed in your configuration of ASA box, it's that you're usig PFS but not on 2911 router.

    So I suggest:

    no card crypto OUTSIDE_map 4 don't set pfs <-- this="" will="" disable="" pfs="" on="" asa="">

    Then try tunnel initiate.

    Kind regards

    Jan

  • Problems of router, switch, and WAP.

    I have a router Wrt400n, a WAP610n and a couple of switches EZXS55W.  I've implemented the rounter connected routers to him cheating.  I have about 6 PC tips and video games wired to the switches.  When I connect wap to one of the switches, some time later my entire network loses the connection with the internet and the only way to fix it is to disconnect the wap and reboot the router.  I have the configuration of the route with dhcp and have given an ip address for the WAP as 1.99 to get him out of the side of the dhcp range.  I only did the 1.99 recently becuaes nothing else has worked.  with on wap everything works fine.  Help, please.  I use wap to extend the wifi at home.

    Fixed.  I had to book the IP of the GPA in the rounter and and set the WAP at this static IP address.  This isn't a requirment in the manual, but it doesn't work any other way.

  • The managed behind router switch remote access?

    What is the best way to access remotely to a switch behind a router?  I will use a switch SF300, and there is no server.

    For points of access (PA) behind a router, I give each a diffferent LAN address and port number.  In router I have forward TCP traffic with the single port/LAN IP.  Then using the port numbers with the address of the static router, the browser can remote access to the router or the attached AP.  But where do I put the managed switch LAN port number?  Assume default is port 80 and I would change to 8001 to switch #1; 8002 to switch #2; etc.  Could not find this info in the manual of configurtion.

    Hello

    At this point, I would recommend a call to the Cisco Small Business Centre at 1-866-606-1866 support so that action can be taken and your configuration can be reviewed.

    I have reproduced the concern here and I am able to remotely manage my switch SF300 with an RV082 as the router.

    My rule in the RV082 are as follows:

    Creating a custom topic UPnP service.  Create SF300 application name (it is a basic text field and can be any name), 8001 an external port and internal port 80.  I send to the address IP internal SF300 switch and click the check box.  From there on, I select Add to the list.  Once it appears in my list, I then click Save settings at the bottom of the page.

    Thank you!

    Dave

  • interface of the router switching modes

    I would like to know the best type of mode switching for router interfaces. I have connections VPN site to site on the Wan. Can I use the command interface "no ip route-cache"? What other options are there? No matter if you run VPN vs frame relay? Is there an article someone can show me?

    Thank you

    RJ

    1. turn on all interfaces, the router will handle the buffering if it cannot transmit data fast enough, it'll be even less load on the CPU of the router.

    2. Yes, definitely do.

  • Problems with the windows/debian home network after router switch

    Hi all:

    I'm new on all the forums, but desperately need help. Even though I am not new on windows and have been building my own computers for years, I am pretty new to networking and also for Linux.

    I have a home network with 3 computers with windows 7 installed and my server with Debian Squeeze. Somehow I've muddled through the installation of debian and even on my network using samba (after days of research). Everything has been great to work with all 3 computers and my server talking to each other.

    I got internet connection across the home network, and all the computers + Server appeared and was accessible on the LAN. It was with a little D - link DIR-601, last week I lost all the internet connect to Comcast, which turned out be their problem but Comcast informed me that my router was not the best and he was originally put my speed problems.

    So I bought a new router Linksys WRT54GL and installed yesterday and it's where I need help... I have internet connection and you can surf the web on all computers 3 windows and the debian server, all computers 3 windows appear and are accessible on the LAN, but not the debian server.

    As soon as I reinstall the D-link router, everything is back to normal. I tried with my limited knowledge of Linux to change network configuration files in my debian server but so far no change. I'm not sure this is a linux problem or a problem with linksys... If anyone has any ideas on how to solve this problem, I could use you help... Thank you ALL!.

    Thanks for your suggestions, but it turns out that the problem was a Linux problem, after changing routers, I had to make some changes in debian Linux as share. I'm on duty again.

  • 2 ISP, Router 1, 2 servers.

    Forgive any ignorance in the matter. I have an ASA 5515 - x on my place of work, and we've just added a second service provider to one of the interfaces. We have two servers within our network and we want each server to use one of the internet connections that the ASA is connected. Is there a way I can put a server to send all of its contents on a pipe and the other server through another, without each interfere with each other. Any help would be appreciated. Thanks in advance.

    Hello

    I didn't try the below before but I guess you can.

    Try the config below:

    Example 1

    gi0/1 interface

    nameif ISP_1

    security-level 0

    address IP 1.1.1.1 255.255.255.252 (replace with your real ip address)

    gi0/2 interface

    nameif ISP_2

    security-level 0

    2.2.2.1 IP address 255.255.255.252 (replace with your real ip address)

    gi0/3 interface

    nameif inside

    security-level 100

    IP 192.168.1.1 255.255.255.0

    network of the server_1 object

    host 192.168.1.10

    dynamic interface of NAT (inside ISP_1)

    network of the LAN_TO_INTERNET object

    subnet 192.168.1.0 255.255.255.0-online Note this server 2 will decrease as well as your home address

    dynamic interface of NAT (inside ISP_2)

    Example 2 (Server resides on DMZ) Public static PAT will be used

    gi0/1 interface

    nameif ISP_1

    security-level 0

    address IP 1.1.1.1 255.255.255.252 (replace with your real ip address)

    gi0/2 interface

    nameif ISP_2

    security-level 0

    2.2.2.1 IP address 255.255.255.252 (replace with your real ip address)

    gi0/3 interface

    nameif inside

    security-level 100

    IP 192.168.1.1 255.255.255.0

    gi0/4 interface

    nameif DMZ

    security-level 100

    address 192.168.20.1 255.255.255.0

    network of the server_1 object

    host 192.168.20.10

    NAT (inside ISP_1) interface static tcp 80 80 service (this will allow what anyone from and to port 80)

    network of the server_1 object

    Home 192.168.20.20

    NAT (inside ISP_2) interface static service tcp 80 80

    see http://www.tunnelsup.com/nat-for-cisco-asas-version-8-3 for more examples.

    HTH.

    Kind regards

    Terence

  • Renewal of CCNA routing &amp; switching Certification

    My CCNA R & S is about to expire

    Can I renew it by giving just ICND2 exam?

    Hello

    You can not re - certify with any of these 2, because those who form the CCNA, therefore, basically, the only way to renew their certification must present cert CCNA, other level a CCIE or CCNA CCNA security, Specialist certifications.

    Please note and mark it as correct this message if this helped you! Keep me posted,

    I thank you,

    David Castro,

  • Reference Dell 6248 as default gateway - next hop router

    Hi all

    I guess it's a matter of very basic network design. Good practice / can I use Dell 6248 layer 3 switch as the gateway / next hop router, even if the correct entry door is directly connected to the same subnet / vlan?

    The problem is that we are making changes to our network, and have several routers on the edge of our network configured static routes so they can achieve our other subnets, local and remote. These static routes will need to be changed when we move from one circuit to another, but some border routers are managed provider, and it is inconvenient to reschedule. Also, sellers will have to do more than once, the road changes if we want to clean our ip addressing scheme after the move. Once the changes are made, the topology of the network likely will not change for a long time, so I would stick with static routing. Given that we can grasp and control the static routes in our Dell 6248, can we just say sellers use our Dell switch as the next hop router when they change their static routes?

    I know that ip redirects could try to "correct" this inefficient configuration, and that could cause problems, at least during the transition phase. On a small network with 10 servers, 100 computers and 80 phones, is it without further consequence of routing for the Dell 6248 layer 3 switch, or is this something configuration you should avoid (for other reasons)? Thanks for your understanding!

    Without seeing a topology, you may be a little difficult to give recommendations. Is the 6248 your switch? It connects to your firewall? All edge switches are like L3 switches that are basically their own broadcast domain? If so, then what you are wanting to do would work. All edge switches have a static route of coverage which directed traffic to the 6248. You then place a static route pointing to the firewall on the 6248.

    If all switches are in L2 and the 6248 mode is the only L3 switch on the network. Then the switches will not need static routes.

  • How can I set Up Airport Express with an existing router/modem from the ISP

    I have a wireless modem/router ISP and I want to get the ability to use Air Print using a non-Airprint but the USB printer. I suggest you to connect the printer to the Airport Express A1392 Epson) via a USB port to enable the AirPrint features.  However, I guess the Airport Express must be an ethernet to the modem/router ISP connection and then use the Epxress airport more convenient than my wireless router.

    Issues related to the:

    1. do I need to turn off the function the ISP router's wireless when I plugged as stated above? So I wait.

    2. as the Airport Express only has one ethernet port I assume that I can connect my other ethernet connections using a hub 4 ports connected to the Airport Express Terminal.  It will be always possible to use other ports ethernet on the modem/router ISP as well?

    Doug

    I have a wireless modem/router ISP and I want to get the ability to use Air Print using a non-Airprint but the USB printer.

    You may have received incorrect information, because a non-AirPrint on the USB port on an AirPort Express Terminal... or any other router from Apple also printer... do not make the AirPrint-compatible printer.

    You want to continue nevertheless to check that this is true?

    The AirPort Express can connect to the network wireless router using a wireless connection... or... it can connect to one of the router's Ethernet ports using a wired Ethernet connection.

    Wired connections are always preferable wireless if possible for your Express.  Turn off the wireless router is not necessary if you want to connect to the Express using an Ethernet connection.

Maybe you are looking for

  • Satellite C855-1j4j does not turn on - the Bios Update interrupted

    Hello I did the update on my laptop Satellite C855-14 days, and all of a sudden the power went out,now the pc running either party but not nothing DON'T get PAST... What should do? + The message was edited: message has already been translated.

  • Automatic rotation

    My auto screen just stopped turning. I checked the setting and it's turned on... What can I do? A reboot didn't help... I don't know what else I can try.

  • installer of hp deskjet 1050 for mac 10.10.2

    I have a mac book pro with me. OS X yosemite 10.10.2 version I want to connect to my printer. Please give me the Installer HP DESKJET 1050 for mac 10.10.2

  • TMS and improved security server TCS

    Hey there everyone! On the Tandberg Web site, there is a page that contains updates for the OS that have been tested for use with the administration server and content server security.  However, the last update was 9/2010.  Is there a comparable down

  • Failed to export - file not found

    HelloI am new user with Lightroom and were from manage my photos, make changes, collection management.I'm reaching the point to export my images to share and start the problem here.I use LR 6.3.My catalog is on my MacMy photos are located on a NAS of