PowerConnect 5448 several VLANS between upstream and downstream server firewall
I am struggling with what I thought, would be a simple task: route several subnets, each on one VLAN different, a firewall to a server. In fact, I can't even pass the VLAN by default one still looking correct in the address tables and STP.
Port 1 = firewall, VLAN 1 unidentified, 2 VLAN Tag, 1 PVID, tried the two trunk and general patterns
17 = server NIC, VLAN 1 unidentified port, VLAN Tag, PVID 1 and 2 2, tried, tried both safe and general patterns
VLAN 1 (firewall untagged) 10.84.195.0/24, 10.84.195.2 Interface IP and default gateway 10.84.195.1
VLAN 2 (tag of firewall) 10.101.0.0/16, IP Interface 10.101.0.2 for 2 VLAN, firewall est.1
The first thing I got was that something has not been properly marked by (Hyper-V, using SC VMM 2012 SP1) server or the firewall (Watchguard XTM 520). Simple test: VPN Firewall, ping the switch to 10.101.0.2 with the tag, and works, remove the label and it doesn't. Dynamic address table shows the two-way firewall. Line 18 below appears right after the ping as planned on VLAN 2 with the same MAC address in VLAN 1. In addition, I ping the switch 10.101.0.2 from the server and it works fine. The table shows that VLAN 2 from the host (and 1 other VM), so it seems to me that everything is properly labeled.
|
15 | VLAN 1 | 00907f8f571b | G1 | ||
16 | VLAN 2 | 00155d1f1b07 | G17 | |||
17 | VLAN 2 | 001dd8b71c01 | G17 | |||
18 | VLAN 2 | 00907f8f571b | G1 | |||
What I can't do, is ping through the switch to VLAN 2. I can't ping my VPN server (10.101.20.1), and I can not ping to the gateway (10.101.0.1) from the server. Note, it is not because of rules to firewall on each end.
What Miss me? I don't think I need a routing of layer 3 here, I don't have to go through VLAN, just have them several VLANS passes from one port to the other.
Other things to note in case it is useful:
-I have no connectivity not tag with everything else through the 10.84.195.xxx/24 switch.
-If I delete the Tags VLAN port 2 1 trunk, I suddenly can ping the bridge VLAN 2 (10.101.0.1) from the server, although I suspect that it is because the same port is the default gateway for the switch.
-For brevity, only 2 lines of the STP are listed below, but all ports are therefore based on the question of whether they are connected or not.
G1 activated 128.1 Frw Desg P2P (STP) No. 4
G2 activated 128.2 Dsbl Dsbl No. 100.
-Latest firmware installed.
-In addition, for people concerned about their security, I want to remove use VLAN by default in the future.
Would it be possible for run you to stick your show output here in the forum. In this way, we can take closer look at what you have configured.
If you connect a desktop/laptop computer (with and intellectual property in the 10.101.0.0/16 range) in a port with the mode of access switchport VLAN 2 are you able to ping IP Interface 10.101.0.2 for 2 VLANS? You could try to disconnect the firewall and the configurations for the port and work on getting through the switch with 2 terminals on a single VLAN. Then, once this is confirmed as work connect the firewall back up with a trunk/general mode adding the VLAN necessary.
You connect to the firewall on a layer 3 interface? You need Layer 3 routing to reach the firewall correctly.
Tags: Dell Switches
Similar Questions
-
How can I check upstream and downstream in AS3?
Hello
I want to know how can I check the upstream and downstream, in AS3, when I press a button in my SWF file.
I need to know the bandwidth of my connection at any time by clicking on a button of my SWF file loaded into one of the most browsers (IE, Firefox, Safari, Chrome, Opera,...). The result of this action must be shown in two textfields, upstream in the first and downstream in the second., without any other intervention from the user.
Best regards
Manel
you will need to encode that by downloading and download a file.
-
PowerConnect 2848 - several VLANS on the 1 port does not
Hello everyone.
I have a Dell PowerConnect 2848. My router is a Netgear SRX5308. In the router, I've created several VLANs (VLAN ID 10 and 20) and would that pass to the ESXi server. If I connect the ESXi server directly to the router, everything works as expected. My VMs are picking up correct VLAN based on the parameters of ESXi.
I need the 2848 between the two, because I need to add more devices and other servers with a VLAN specific.
Currently I use port 25 for switch 2848.
I put the switch to managed mode.
I created switch-> VLAN-> belonging to a VLAN, VLAN ID 10 and 20.
I select 10 VLANS and put the T on port 25.
I select the VLAN 20 and put the T on port 25. (I also tried to put a U on them, just to try, but did not work)
But my virtual computer are not able to reach the DHCP on the router.
Spanning Tree is enabled.
I'm obviously missing something...
I have already passed last week banging my head on this, but have not been able to pass traffic along.
Help, please!
So you're on the right track. If port 25 is facing the router? What port must face the ESXi Server? That port should also have VLAN 10 and 20 should be labelled.
-
Design of switching between Nexus7K and active / standby firewall
In the attached diagram, Nexus7K is used in two ways: on the left side, pair NX7K connects to the firewall as layer 2 trunks. vPC VLAN are shared through resources. The firewall is a pair in Active mode / standby. On the right side, another pair of NX7K connects to the firewall as layer 3 rotued links. HSRP or VRRP is running between the pair of NX7K for firewall VLAN SVI.
Because even NX7K have mesh connections to the active firewall units / standby, I want to make sure in failover scenarios (failover firewalls or failures of NX7K), the link that remains between the pair of NX7K and the firewall can actually send traffic (not perforated black).
Failure scenarios I can think of include: Firewall active failover on the eve, failure of the main device NX7K, double NX7K active and failure of peers-link NX7K vPC. I would like to get some advice on what I should consider and implement in these scenarios to achieve high availability.
Many thanks for any advice.
Hello
your topology, I see that the main problem is that the physical connectivity from the firewall to the pair of devices nexus in topologies to fails to a redundant link to the N7K
first since you're using vPC with one counterpart vPC linking the pair of N7K then you must follow the recommendations of Cisco firewalls of L2 and L3 link connection
L2 if you pass vPC vlan on the trunk in your topology and firewall then there is a possibility of blocking traffic or drop cases underwritten by vPC loop prevention mechanism in the case for example a vPC counterpart link gose down
the fix to the East either:
use no-vPC VLAN and link to switch separate inter for VLANs (i thin that you already have this link)
or multi home L2 connects each firewall for the two switch N7K and assuming that HSRP is configured in the N7K and static routing is used between the firewall and the N7K
for links to L3 Firewalls:
You must stream as well (if possible and recommend) and use a static routing between N7K and firewalls and firewalls must point to the VIP of HSRP N7K
multiple L3 and L3 dyanaminc routing peering on the link of the vPC-peer is not supported design
Look at the discussion that might help as well
https://supportforums.Cisco.com/message/3792466#3792466
hope this helps
If useful rates
-
Sort of the differences between Oracle and SQL Server
Hi all
This question is linked by both Oracle and SQL Server
I have a requirement where I want to compare 2 tables line by line. A table is in Oracle and other table in SQL Server
And suppose that both tables do not have a primary key. Now when I sort records by using the order by clause for a column, then-
Rows with null values in that column of Oracle are placed in the background.
When that rows with null values in the same column in SQL Server are placed right at the top.
How can I make one of them to behave like any other.
My only goal is to have same order of lines in Oracle and SQL Server tables so that I can compare line by line.YADQ: Yet another Doc Question
Can you please avoid them?
Take your SQL reference manual, search for the ORDER BY clause and notice that it has
NULL FIRST or LAST values NULL values.------------
Sybrand Bakker
Senior Oracle DBA -
Several VLANS between 2 SG300-10
Hi all
I have 2 switches SG300-10, and I need two VLANs, one for the internal network and the other for WiFi AP.
I need ports 1-> 4 on both switches in order to be part of VLAN 1 and 5-2 8 > VLAN. and a 10 to the 2nd switch uplink port.
How to configure the VLAN and the interface mode VLAN?
1-> 4 vlan 10 port, port 5-> 8 vlan 20 and vlan port 10 10, 20 and 1? (assuming I have have VLAN 10 and 20 and 1 by default)
Ports 1-> 8 General mode and trunk of 10 port mode?
Thank you!
Hi Adrien, the first question is, what is your router?
To answer your question. Single host connection ports can be configured as any mode of port, but coelio is preferential. Links of connection between switches can be trunk or general with vlan 1 UNTAG, vlan 10 tag, tag vlan 20.
Cli command would look like this
config t
database of VLAN
VLAN 10.20
item in gi1-4 serial interface
switchport mode access
switchport access vlan 10
IG5-8 serial interface
switchport mode access
switchport access vlan 20
gi10 interface
switchport mode trunk
switchport trunk allowed vlan add all
-Tom
Please evaluate the useful messages -
Reference Dell powerconnect 5524 cannot ping between coelio and trunk port
Hello...
We set up a new switch of 5524 I untagged on vlan 20 and access ports where vlan 20 I allowed. I created a computer on the access port on the same trunk port ip net... cant ping beween them. I'm no expert of switch, so I wonder what I missed. I did the same thing on a dell old 3524 and it works directly...
Here's the port config I tried to do a ping beween is 6 and 10 ports
(Another thing, how how to remove):
switchport mode trunk
switchport access vlan none)Any help would be greatly appreciated!
interface vlan 1
IP 88.131.90.252 255.255.255.240
!
interface vlan 5
the name 'SCE CJA'
!
interface vlan 6
the name "out of Tele2.
!
interface vlan 7
name "Outside Telenor"
!
interface vlan 8
name "TDC Multivrf"
!
interface vlan 20
TDC-CISCO-LAN name
!
[0mMore:, quit: q or CTRL + Z, one line: interface vlan 21]
the name "FW inside."
!
interface vlan 99
name «FW sync»
!
gigabitethernet1/0/1 interface
Description CPE1
switchport access vlan 5
!
interface gigabitethernet1/0/2
Description CPE2
switchport access vlan 5
!
interface gigabitethernet1/0/3
Df description
spanning tree portfast
switchport mode trunk
switchport access vlan no
!
interface gigabitethernet1/0/4
Description Oupps-cb2
[0mMore:, quit: q or CTRL + Z, a single line: spanning tree portfast]
switchport mode trunk
switchport access vlan no
!
interface gigabitethernet1/0/5
Upp-ccm1 description
spanning tree portfast
switchport access vlan 20
!
interface gigabitethernet1/0/6
Oupps-ccm2 description
spanning tree portfast
switchport access vlan 20
!
interface gigabitethernet1/0/7
Tdc-multivrf1 description
switchport access vlan 8
!
interface gigabitethernet1/0/8
TDC-multivrf2 description
switchport access vlan 8
!
[0mMore:, quit: q or CTRL + Z, one line: interface gigabitethernet1/0/9]
Description Oupps-cb-tq03
spanning tree portfast
switchport mode trunk
!
interface gigabitethernet1/0/10
Description Oupps-cb-tq04
spanning tree portfast
switchport mode trunk
!
interface gigabitethernet1/0/11
Tele2-outside description
switchport access vlan 6
!
interface gigabitethernet1/0/12
Tele2-outside description
switchport access vlan 6
!
interface gigabitethernet1/0/13
Telenor-outside description
switchport access vlan 7
!
[0mMore:, quit: q or CTRL + Z, one line: interface gigabitethernet1/0/14]
Telenor-outside description
switchport access vlan 7
!
interface gigabitethernet1/0/15
Description Word-Oupps-fw-tq01-inside
switchport mode trunk
!
interface gigabitethernet1/0/16
Description Word-Oupps-fw-tq02-inside
switchport mode trunk
!
interface gigabitethernet1/0/17
FW-sync description
switchport access vlan 99
!
interface gigabitethernet1/0/18
FW-sync description
switchport access vlan 99
!
interface gigabitethernet1/0/19
Description Word-Oupps-fw-tq01-outside
[0mMore:, quit: q or CTRL + Z, a single line: switchport mode trunk]
!
interface gigabitethernet1/0/20
Description Word-Oupps-fw-tq02-outside
switchport mode trunk
!
interface gigabitethernet1/0/22
FW-Sync description
switchport access vlan 99
!
interface gigabitethernet1/0/23
Description Word-Oupps-FW-tq01-outside
192.168.11.1 IP address 255.255.255.0
switchport mode trunk
!
interface gigabitethernet1/0/24
Description Word-AIN-LAN-SW
switchport access vlan 20
!
IP route 0.0.0.0 0.0.0.0 88.131.90.241[0mMore:
, quit: q or CTRL + Z, a single line:] Information of VLAN
The name of the VLAN Tag Ports Ports unmarked Type permission
---- ------------ ------------------ ------------------ --------- -------------
1 1 article gi1/0/3-4, default required
Article gi1/0/9-10
item in gi1/0/15-16,
item in gi1/0/19-21,
item in gi1/0/23,
item in gi1/0/25-48,
TE1/0/1-2.
GI2/0/1-48.
TE2/0/1-2.
IG3/0/1-48.
TE3/0/1-2.
IG4/0/1-48.
TE4/0/1-2.
IG5/0/1-48.
TE5/0/1-2.
GI6/0/1-48.
TE6/0/1-2.
gi7/0/1-48.
TE7/0/1-2.
gi8/0/1-48.
TE8/0/1-2, m 1-32
5 CPE TDC article gi1/0/3-4, item in gi1/0/1-2 permanent required
[0mMore:, quit: q or CTRL + Z, one line: article gi1/0/9-10]
item in gi1/0/15-16,
item in gi1/0/19-20,
item in gi1/0/23
6 outside section gi1/0/3-4, item in gi1/0/11-12 permanent required
Tele2 item in gi1/0/9-10,
item in gi1/0/15-16,
item in gi1/0/19-20,
item in gi1/0/23
7 outside article gi1/0/3-4, item in gi1/0/13-14 required permanent
Telenor item in gi1/0/9-10,
item in gi1/0/15-16,
item in gi1/0/19-20,
item in gi1/0/23
8 TDC Multivrf item in gi1/0/3-4, item in gi1/0/7-8 permanent required
Article gi1/0/9-10
item in gi1/0/15-16,
item in gi1/0/19-20,
item in gi1/0/23
TDC-CISCO-LA 20, article gi1/0/3-4, item in gi1/0/5-6, item in gi1/0/24 required permanent
N item in gi1/0/9-10,
item in gi1/0/15-16,
[0mMore:, quit: q or CTRL + Z, one line: item in gi1/0/19-20,]
item in gi1/0/23In safe mode the PVID is 1 VLAN by default. You can do this by entering the command #switchport trunk vlan native {number of vlan}. If Cisco is configured to accept and send the marked packets and has an IP address in the subnet of VLAN 20, it should be able to communicate with other devices in VLAN 20.
-
tape drive sharing between ndmphost and admin server usnig osb.
Hello.
It is available to share the tape drive between san usnig adminserver and ndmphost the switch?
We have 6 lto5 disks and will be attached to the machine oracle ss7420 NDMP.
The customer site has no backup of the customer unless the nas data.
Reason why I'm asking as OSB catalogdb to tape drive backup.
Is it safe to admin osb catalogdb backup as client or tape drive sharing is available?
Another issue is that when we set up unit NDMP, NDMP host can control robot or robot control should assign to the server administrator or the two availble?
Thank you.Yes it's available by design. You have to configure the NAS with the role of mediaserver and add a 2nd point of attachment to the device. You can then create calendars that limit to those fixing points. Allows you to share all the drives between all media servers.
For the robot, I let the server admin to do that, just tape devices were mapped to the time. Controlling Robotics is a light enough task.
Here is an example of one of my setups where the drive is shared between several media servers, Oracle Linux 4, Linux 5 Oracle and NetApp
L700-1-lect1:
Device type: Ribbon
Model: ULTRIUM-TD2
Serial number: 7MHHY00202
In service: Yes
Library: L700-1
DTE: 2
Automount: Yes
Error rate: 8
Frequency of application: [unknown]
Debug mode: no
Blocking factor: 512
Blocking max factor: 512
The current band: 999
Use the list: all the
In-car use: 7 months, 3 weeks
Cleaning required: no
UUID: 558a34da-045e-102c-8443-002264f35328
Annex 1:
Host: dadbdn01
Raw device: / dev/tape/by-id/scsi-1IBM_ULTRIUM-TD2_7MHHY00202
Appendix 2:
Host: dadbdh01
Raw device: / dev/tape/by-id/scsi-1IBM___ULTRIUM-TD2___7MHHY00202__
Annex 3:
Host: dadbeh01
Raw device: / dev/tape/by-id/scsi-1IBM___ULTRIUM-TD2___7MHHY00202__
Appendix 4:
Host: ap1030nap
Raw device: nrst1a
Annex 5:
Host: dadbak01
Raw device: / dev/tape/by-id/scsi-1IBM___ULTRIUM-TD2___7MHHY00202__Thank you
Rich
-
Link between ITC and CallManager Server
Hi list;
The link between the CallManager and the CTI server is done via JTAPI or one Trunk IP (as gatekeeeper of access using H.323 or SIP controller and so on)?
Concerning
Bilal
Bilal,.
If you plan to deploy the IPCC with Avaya or Nortel, he has no problem using CT Connect as a CTI server. In this case you don? business ICT or CTIOS need t. I have a deployment with ten Avaya Definity and ICM is used for intelligent routing between the ten Avayas and Envox CT Connect is the CTI server for the agents.
You can not use CT Connect with the IPCC and CallManager, for later call center, because CT Connect do? do not provide Contact Center functions: login, logout, ready, etc. With the IPCC and CallManager, you can use CTIOS.
For Avaya, Nortel and other OBXs, Envox CT COnnect provides functionality to connect, disconnect and change the status of the agent. For CallManager only provides functions of phone or the duties of the agent.
Juan Luis
-
Repeated loss of connection between Outlook and Exchange server
Hello
I am running Windows 7 beta ultimate evaluation copy Build 7100.
On that, I installed Office 2007, part of which is Outlook (12.0.6514.5000) SP2 MSO (12.0.64251000).
I do the usual Windows updates and recently, I noticed that my Outlook has been updated as when I turn it off, I have a new Outlook "grey" with a red 'x' icon in this document, which disappears when the software is finally off.
The problem is that now Outlook repeatedly loses the connection with the Exchange Server in my (work) and I have to close Outlook in order to reconnect and reactivate.
It only happens when I'm at home - not at work (where I am actually on the internal network).
It's very frustrating.
Can you please help?
Check with this community: http://www.microsoft.com/office/community/en-us/flyoutoverview.mspx
-
mechanism between DB and application server
Hello
Currently I have installed R12.1.3 ebs and DB under 11.1.0.7 upgrade to 11.2.0.2.
When upgrading the database server, I have a question how application server detects the database server.
The question may seem a little silly, but that's how it is. :)
For example, when DB is upgraded, upgrade, configuration and post activities are explained on side DB in the documents.
But then, how the database server to find application after the installation of new DB?
It works based on the updated file listener only...?
Or is there a configuration that must be done application server side as well after the DB is upgraded?
Can someone help with my questions...?
Thank youHello
> It works based on the updated file listener only...?
Definitely, it will use the earpiece to connect with the db.During the upgrade, you create appsutl.zip and copy this to the level of the database and run the automatic configuration service. It's that time where the link is established.
Thank you
-
LDAP over SSL doesn't work is not between ASA and AD server
Hi all.
We have configured clientless SSL WebVPN portal on an ASA5525 using LDAP authentication with an ad server. All is well until what we enable LDAP over SSL to allow users to change an expired password. They get just connection error every time, even if their password is correct.
The systems team have installed the necessary certificate on the AD server.
The newspaper of the ASDM I get
Joffrey.pcmtu.Keele.AC.UK marking AAA in aaa-Server CTU_LDAP04 group LDAP server down
Marking AAA 172.16.0.10 LDAP server group aaa-server active CTU_LDAP04On the ASA, I get the debugging ldap following 255
[50] starting a session
[50] new application Session, framework 0x00007fffddc99a60, reqType = authentication
[50] the fiber began
[50] create LDAP context with uri = ldaps://172.16.0.10:636
[50] to connect to the LDAP server: ldaps://172.16.0.10:636, status = failure
[50] cannot read the rootDSE. Cannot contact the LDAP server.
[50] output fiber Tx = 0 bytes Rx = 0 bytes, status =-2
[50] end of sessionOn the ad server, the systems team report TLS Fatal Alert Code 48 which is...
Received a valid certificate chain or partial string, but the certificate has been refused because the authority , could not be located or couldn't be matched with a known, trusted CA. This message is always fatal.
Can someone shed some light on where we need to look at.
Thank you. Richard.
Richard,
This could be due to:
https://Tools.Cisco.com/bugsearch/bug/CSCus71190/?reffering_site=dumpcr
M.
-
to connect to the internet have no upstream and downstream. How to change the protocols so my modem can send and receive.
original title: unable to connect to the internetHello
1 how long have you been faced with this problem?
2. don't you make changes on the computer before this problem?
3. what type of internet connection (wired or wireless) do you use?Answer these questions and provide us with more specific information on the issue. This could help us help you better.
Refer the article that could help you solve this problem.
How to troubleshoot possible causes of Internet connection problems in Windows XP
http://support.Microsoft.com/kb/314095 -
Unlike char in ORACLE and SQL SERVER
Hello gurus,
I tried to querying data from Oracle to sql server through linked server, but get me an error! set length corresponds to the error! I know there are CHAR data type in sql server and thus as in oracle.
But when I use the CAST FUNCTION with CHAR it works fine
----- error code select * from openquery( linkoracle11 select col1, col2, col3 from test_table ) -- say col3 char(1) -- data type
I was wondering, what is the difference between oracle and sql server for the CHAR data type?-- working code select * from openquery ( linkoracle 11 select col1, col2, cast (col3 as char(1)) as col_3 from test_table )
The gurus of the idea?
Thank youWhat is the error you get?
What is the characters in database and NLS_LENGTH_SEMANTICS game on your Oracle system?
SELECT * FROM v$nls_parameters WHERE name LIKE '%CHARACTERSET'; SQL> SHOW PARAMETER nls_length_semantics;
What is the character set of data in SQL Server?
If your local database is a variable length character set (like UTF8) and NLS_LENGTH_SEMANTICS is set to (default) BYTES, a char (1) allocate 1 byte of storage which may not be sufficient for a single character. The receiving application may need to allocate a buffer with 3 times more many bytes as there are characters in order to ensure that it will be able to process the result. I don't know why add an implicit CAST that would change, but since we are several levels removed from the code to figure out how large a buffer to allocate, it is not very surprising.
Justin
-
And connector server AD, Exchange, AS400
Hello world
I want to put in place the connectors for the AD, Exchange, target AS400 systems.
I tried to implement these system three target.
I have a few questions about the connectors?
1. is server connector is required for AD, Exchange, AS400? If it's the need for tagert systems is necessary?
Can you explain the connection between connector and connector server?
2. can you connector server installed on the machine target AS400 AS400?
Thank you.
Best regards.I would say, install two connector server an AD and exchange and other for AS400. You can install on the target systems, but not mandatory. You can have the autonomous system for server connector as well. One thing to consider is, it should be in the same field of the target system.
Maybe you are looking for
-
After clicking on the link, Firefox opens 2 tabs double address of this link.
After clicking on the link, Firefox opens 2 tabs double address of this link.Here is the site: http://www.hifishark.com/search?q=sony On the right side of the page, when I click on SHOW, 2 tablets of addresses duplicated this link open.I've been on t
-
Acquisition of a sequence of images based on an external trigger.
Hello I have a photonfocus MV-D1024E-160-CL-CMOS camera. I'm generating a square signal of a NOR-DAQ. I want the camera to image acquisition on each falling edge or rising edge of the signal. I've seen examples related to IMAQdx drivers to get a sequ
-
"Not enough memory to run the Titanic"
Basically I'm playing an old game of Windows 95, Titanic and I changed the compatibility, but now it says that I don't have enough memory to run it. I deleted some programs, done the cleaning disc too. I have not any open programs. It is said to the
-
I get error message "Unable to establish internet connection" when I try and run updates.
I have no problem connecting with other programs.
-
Problem of compatibility printer PhotoSmart C7280 with Mac OS 10.7 (lion)
my printer hp photosmart c7280 all-in-one will work with the new mac os 10.7 (Lion)?