PowerConnect 5448 several VLANS between upstream and downstream server firewall

I am struggling with what I thought, would be a simple task: route several subnets, each on one VLAN different, a firewall to a server.  In fact, I can't even pass the VLAN by default one still looking correct in the address tables and STP.

Port 1 = firewall, VLAN 1 unidentified, 2 VLAN Tag, 1 PVID, tried the two trunk and general patterns

17 = server NIC, VLAN 1 unidentified port, VLAN Tag, PVID 1 and 2 2, tried, tried both safe and general patterns

VLAN 1 (firewall untagged) 10.84.195.0/24, 10.84.195.2 Interface IP and default gateway 10.84.195.1

VLAN 2 (tag of firewall) 10.101.0.0/16, IP Interface 10.101.0.2 for 2 VLAN, firewall est.1

The first thing I got was that something has not been properly marked by (Hyper-V, using SC VMM 2012 SP1) server or the firewall (Watchguard XTM 520).  Simple test: VPN Firewall, ping the switch to 10.101.0.2 with the tag, and works, remove the label and it doesn't.  Dynamic address table shows the two-way firewall.  Line 18 below appears right after the ping as planned on VLAN 2 with the same MAC address in VLAN 1.  In addition, I ping the switch 10.101.0.2 from the server and it works fine.  The table shows that VLAN 2 from the host (and 1 other VM), so it seems to me that everything is properly labeled.


 
15 VLAN 1 00907f8f571b G1    
  16 VLAN 2 00155d1f1b07 G17    
  17 VLAN 2 001dd8b71c01 G17    
  18 VLAN 2 00907f8f571b G1    
 

What I can't do, is ping through the switch to VLAN 2.  I can't ping my VPN server (10.101.20.1), and I can not ping to the gateway (10.101.0.1) from the server.  Note, it is not because of rules to firewall on each end.

What Miss me?  I don't think I need a routing of layer 3 here, I don't have to go through VLAN, just have them several VLANS passes from one port to the other.

Other things to note in case it is useful:

-I have no connectivity not tag with everything else through the 10.84.195.xxx/24 switch.

-If I delete the Tags VLAN port 2 1 trunk, I suddenly can ping the bridge VLAN 2 (10.101.0.1) from the server, although I suspect that it is because the same port is the default gateway for the switch.

-For brevity, only 2 lines of the STP are listed below, but all ports are therefore based on the question of whether they are connected or not.

G1 activated 128.1 Frw Desg P2P (STP) No. 4
G2 activated 128.2 Dsbl Dsbl No. 100.

-Latest firmware installed.

-In addition, for people concerned about their security, I want to remove use VLAN by default in the future.

Would it be possible for run you to stick your show output here in the forum.  In this way, we can take closer look at what you have configured.

If you connect a desktop/laptop computer (with and intellectual property in the 10.101.0.0/16 range) in a port with the mode of access switchport VLAN 2 are you able to ping IP Interface 10.101.0.2 for 2 VLANS?  You could try to disconnect the firewall and the configurations for the port and work on getting through the switch with 2 terminals on a single VLAN.  Then, once this is confirmed as work connect the firewall back up with a trunk/general mode adding the VLAN necessary.

You connect to the firewall on a layer 3 interface?  You need Layer 3 routing to reach the firewall correctly.

Tags: Dell Switches

Similar Questions

  • How can I check upstream and downstream in AS3?

    Hello

    I want to know how can I check the upstream and downstream, in AS3, when I press a button in my SWF file.

    I need to know the bandwidth of my connection at any time by clicking on a button of my SWF file loaded into one of the most browsers (IE, Firefox, Safari, Chrome, Opera,...). The result of this action must be shown in two textfields, upstream in the first and downstream in the second., without any other intervention from the user.

    Best regards

    Manel

    you will need to encode that by downloading and download a file.

  • PowerConnect 2848 - several VLANS on the 1 port does not

    Hello everyone.

    I have a Dell PowerConnect 2848.  My router is a Netgear SRX5308. In the router, I've created several VLANs (VLAN ID 10 and 20) and would that pass to the ESXi server. If I connect the ESXi server directly to the router, everything works as expected. My VMs are picking up correct VLAN based on the parameters of ESXi.

    I need the 2848 between the two, because I need to add more devices and other servers with a VLAN specific.

    Currently I use port 25 for switch 2848.

    I put the switch to managed mode.

    I created switch-> VLAN-> belonging to a VLAN, VLAN ID 10 and 20.

    I select 10 VLANS and put the T on port 25.

    I select the VLAN 20 and put the T on port 25.  (I also tried to put a U on them, just to try, but did not work)

    But my virtual computer are not able to reach the DHCP on the router.

    Spanning Tree is enabled.

    I'm obviously missing something...

    I have already passed last week banging my head on this, but have not been able to pass traffic along.

    Help, please!

    So you're on the right track. If port 25 is facing the router? What port must face the ESXi Server? That port should also have VLAN 10 and 20 should be labelled.

  • Design of switching between Nexus7K and active / standby firewall

    In the attached diagram, Nexus7K is used in two ways: on the left side, pair NX7K connects to the firewall as layer 2 trunks. vPC VLAN are shared through resources. The firewall is a pair in Active mode / standby. On the right side, another pair of NX7K connects to the firewall as layer 3 rotued links. HSRP or VRRP is running between the pair of NX7K for firewall VLAN SVI.

    Because even NX7K have mesh connections to the active firewall units / standby, I want to make sure in failover scenarios (failover firewalls or failures of NX7K), the link that remains between the pair of NX7K and the firewall can actually send traffic (not perforated black).

    Failure scenarios I can think of include: Firewall active failover on the eve, failure of the main device NX7K, double NX7K active and failure of peers-link NX7K vPC. I would like to get some advice on what I should consider and implement in these scenarios to achieve high availability.

    Many thanks for any advice.

    Hello

    your topology, I see that the main problem is that the physical connectivity from the firewall to the pair of devices nexus in topologies to fails to a redundant link to the N7K

    first since you're using vPC with one counterpart vPC linking the pair of N7K then you must follow the recommendations of Cisco firewalls of L2 and L3 link connection

    L2 if you pass vPC vlan on the trunk in your topology and firewall then there is a possibility of blocking traffic or drop cases underwritten by vPC loop prevention mechanism in the case for example a vPC counterpart link gose down

    the fix to the East either:

    use no-vPC VLAN and link to switch separate inter for VLANs (i thin that you already have this link)

    or multi home L2 connects each firewall for the two switch N7K and assuming that HSRP is configured in the N7K and static routing is used between the firewall and the N7K

    for links to L3 Firewalls:

    You must stream as well (if possible and recommend) and use a static routing between N7K and firewalls and firewalls must point to the VIP of HSRP N7K

    multiple L3 and L3 dyanaminc routing peering on the link of the vPC-peer is not supported design

    Look at the discussion that might help as well

    https://supportforums.Cisco.com/message/3792466#3792466

    hope this helps

    If useful rates

  • Sort of the differences between Oracle and SQL Server

    Hi all

    This question is linked by both Oracle and SQL Server

    I have a requirement where I want to compare 2 tables line by line. A table is in Oracle and other table in SQL Server

    And suppose that both tables do not have a primary key. Now when I sort records by using the order by clause for a column, then-

    Rows with null values in that column of Oracle are placed in the background.
    When that rows with null values in the same column in SQL Server are placed right at the top.

    How can I make one of them to behave like any other.

    My only goal is to have same order of lines in Oracle and SQL Server tables so that I can compare line by line.

    YADQ: Yet another Doc Question

    Can you please avoid them?

    Take your SQL reference manual, search for the ORDER BY clause and notice that it has
    NULL FIRST or LAST values NULL values.

    ------------
    Sybrand Bakker
    Senior Oracle DBA

  • Several VLANS between 2 SG300-10

    Hi all

    I have 2 switches SG300-10, and I need two VLANs, one for the internal network and the other for WiFi AP.

    I need ports 1-> 4 on both switches in order to be part of VLAN 1 and 5-2 8 > VLAN. and a 10 to the 2nd switch uplink port.

    How to configure the VLAN and the interface mode VLAN?

    1-> 4 vlan 10 port, port 5-> 8 vlan 20 and vlan port 10 10, 20 and 1? (assuming I have have VLAN 10 and 20 and 1 by default)

    Ports 1-> 8 General mode and trunk of 10 port mode?

    Thank you!

    Hi Adrien, the first question is, what is your router?

    To answer your question. Single host connection ports can be configured as any mode of port, but coelio is preferential. Links of connection between switches can be trunk or general with vlan 1 UNTAG, vlan 10 tag, tag vlan 20.

    Cli command would look like this

    config t

    database of VLAN

    VLAN 10.20

    item in gi1-4 serial interface

    switchport mode access

    switchport access vlan 10

    IG5-8 serial interface

    switchport mode access

    switchport access vlan 20

    gi10 interface

    switchport mode trunk

    switchport trunk allowed vlan add all

    -Tom
    Please evaluate the useful messages

  • Reference Dell powerconnect 5524 cannot ping between coelio and trunk port

    Hello...

    We set up a new switch of 5524 I untagged on vlan 20 and access ports where vlan 20 I allowed. I created a computer on the access port on the same trunk port ip net... cant ping beween them. I'm no expert of switch, so I wonder what I missed. I did the same thing on a dell old 3524 and it works directly...

    Here's the port config I tried to do a ping beween is 6 and 10 ports

    (Another thing, how how to remove):

    switchport mode trunk
    switchport access vlan none)

    Any help would be greatly appreciated!

    interface vlan 1
    IP 88.131.90.252 255.255.255.240
    !
    interface vlan 5
    the name 'SCE CJA'
    !
    interface vlan 6
    the name "out of Tele2.
    !
    interface vlan 7
    name "Outside Telenor"
    !
    interface vlan 8
    name "TDC Multivrf"
    !
    interface vlan 20
    TDC-CISCO-LAN name
    !
    [0mMore: , quit: q or CTRL + Z, one line: interface vlan 21]
    the name "FW inside."
    !
    interface vlan 99
    name «FW sync»
    !
    gigabitethernet1/0/1 interface
    Description CPE1
    switchport access vlan 5
    !
    interface gigabitethernet1/0/2
    Description CPE2
    switchport access vlan 5
    !
    interface gigabitethernet1/0/3
    Df description
    spanning tree portfast
    switchport mode trunk
    switchport access vlan no
    !
    interface gigabitethernet1/0/4
    Description Oupps-cb2
    [0mMore: , quit: q or CTRL + Z, a single line: spanning tree portfast]
    switchport mode trunk
    switchport access vlan no
    !
    interface gigabitethernet1/0/5
    Upp-ccm1 description
    spanning tree portfast
    switchport access vlan 20
    !
    interface gigabitethernet1/0/6
    Oupps-ccm2 description
    spanning tree portfast
    switchport access vlan 20
    !
    interface gigabitethernet1/0/7
    Tdc-multivrf1 description
    switchport access vlan 8
    !
    interface gigabitethernet1/0/8
    TDC-multivrf2 description
    switchport access vlan 8
    !
    [0mMore: , quit: q or CTRL + Z, one line: interface gigabitethernet1/0/9]
    Description Oupps-cb-tq03
    spanning tree portfast
    switchport mode trunk
    !
    interface gigabitethernet1/0/10
    Description Oupps-cb-tq04
    spanning tree portfast
    switchport mode trunk
    !
    interface gigabitethernet1/0/11
    Tele2-outside description
    switchport access vlan 6
    !
    interface gigabitethernet1/0/12
    Tele2-outside description
    switchport access vlan 6
    !
    interface gigabitethernet1/0/13
    Telenor-outside description
    switchport access vlan 7
    !
    [0mMore: , quit: q or CTRL + Z, one line: interface gigabitethernet1/0/14]
    Telenor-outside description
    switchport access vlan 7
    !
    interface gigabitethernet1/0/15
    Description Word-Oupps-fw-tq01-inside
    switchport mode trunk
    !
    interface gigabitethernet1/0/16
    Description Word-Oupps-fw-tq02-inside
    switchport mode trunk
    !
    interface gigabitethernet1/0/17
    FW-sync description
    switchport access vlan 99
    !
    interface gigabitethernet1/0/18
    FW-sync description
    switchport access vlan 99
    !
    interface gigabitethernet1/0/19
    Description Word-Oupps-fw-tq01-outside
    [0mMore: , quit: q or CTRL + Z, a single line: switchport mode trunk]
    !
    interface gigabitethernet1/0/20
    Description Word-Oupps-fw-tq02-outside
    switchport mode trunk
    !
    interface gigabitethernet1/0/22
    FW-Sync description
    switchport access vlan 99
    !
    interface gigabitethernet1/0/23
    Description Word-Oupps-FW-tq01-outside
    192.168.11.1 IP address 255.255.255.0
    switchport mode trunk
    !
    interface gigabitethernet1/0/24
    Description Word-AIN-LAN-SW
    switchport access vlan 20
    !
    IP route 0.0.0.0 0.0.0.0 88.131.90.241

    [0mMore: , quit: q or CTRL + Z, a single line:]

    Information of VLAN

    The name of the VLAN Tag Ports Ports unmarked Type permission
    ---- ------------ ------------------ ------------------ --------- -------------
    1 1 article gi1/0/3-4, default required
    Article gi1/0/9-10
    item in gi1/0/15-16,
    item in gi1/0/19-21,
    item in gi1/0/23,
    item in gi1/0/25-48,
    TE1/0/1-2.
    GI2/0/1-48.
    TE2/0/1-2.
    IG3/0/1-48.
    TE3/0/1-2.
    IG4/0/1-48.
    TE4/0/1-2.
    IG5/0/1-48.
    TE5/0/1-2.
    GI6/0/1-48.
    TE6/0/1-2.
    gi7/0/1-48.
    TE7/0/1-2.
    gi8/0/1-48.
    TE8/0/1-2, m 1-32
    5 CPE TDC article gi1/0/3-4, item in gi1/0/1-2 permanent required
    [0mMore: , quit: q or CTRL + Z, one line: article gi1/0/9-10]
    item in gi1/0/15-16,
    item in gi1/0/19-20,
    item in gi1/0/23
    6 outside section gi1/0/3-4, item in gi1/0/11-12 permanent required
    Tele2 item in gi1/0/9-10,
    item in gi1/0/15-16,
    item in gi1/0/19-20,
    item in gi1/0/23
    7 outside article gi1/0/3-4, item in gi1/0/13-14 required permanent
    Telenor item in gi1/0/9-10,
    item in gi1/0/15-16,
    item in gi1/0/19-20,
    item in gi1/0/23
    8 TDC Multivrf item in gi1/0/3-4, item in gi1/0/7-8 permanent required
    Article gi1/0/9-10
    item in gi1/0/15-16,
    item in gi1/0/19-20,
    item in gi1/0/23
    TDC-CISCO-LA 20, article gi1/0/3-4, item in gi1/0/5-6, item in gi1/0/24 required permanent
    N item in gi1/0/9-10,
    item in gi1/0/15-16,
    [0mMore: , quit: q or CTRL + Z, one line: item in gi1/0/19-20,]
    item in gi1/0/23

    In safe mode the PVID is 1 VLAN by default. You can do this by entering the command #switchport trunk vlan native {number of vlan}. If Cisco is configured to accept and send the marked packets and has an IP address in the subnet of VLAN 20, it should be able to communicate with other devices in VLAN 20.

  • tape drive sharing between ndmphost and admin server usnig osb.

    Hello.
    It is available to share the tape drive between san usnig adminserver and ndmphost the switch?
    We have 6 lto5 disks and will be attached to the machine oracle ss7420 NDMP.
    The customer site has no backup of the customer unless the nas data.

    Reason why I'm asking as OSB catalogdb to tape drive backup.
    Is it safe to admin osb catalogdb backup as client or tape drive sharing is available?

    Another issue is that when we set up unit NDMP, NDMP host can control robot or robot control should assign to the server administrator or the two availble?

    Thank you.

    Yes it's available by design. You have to configure the NAS with the role of mediaserver and add a 2nd point of attachment to the device. You can then create calendars that limit to those fixing points. Allows you to share all the drives between all media servers.

    For the robot, I let the server admin to do that, just tape devices were mapped to the time. Controlling Robotics is a light enough task.

    Here is an example of one of my setups where the drive is shared between several media servers, Oracle Linux 4, Linux 5 Oracle and NetApp

    L700-1-lect1:
    Device type: Ribbon
    Model: ULTRIUM-TD2
    Serial number: 7MHHY00202
    In service: Yes
    Library: L700-1
    DTE: 2
    Automount: Yes
    Error rate: 8
    Frequency of application: [unknown]
    Debug mode: no
    Blocking factor: 512
    Blocking max factor: 512
    The current band: 999
    Use the list: all the
    In-car use: 7 months, 3 weeks
    Cleaning required: no
    UUID: 558a34da-045e-102c-8443-002264f35328
    Annex 1:
    Host: dadbdn01
    Raw device: / dev/tape/by-id/scsi-1IBM_ULTRIUM-TD2_7MHHY00202
    Appendix 2:
    Host: dadbdh01
    Raw device: / dev/tape/by-id/scsi-1IBM___ULTRIUM-TD2___7MHHY00202__
    Annex 3:
    Host: dadbeh01
    Raw device: / dev/tape/by-id/scsi-1IBM___ULTRIUM-TD2___7MHHY00202__
    Appendix 4:
    Host: ap1030nap
    Raw device: nrst1a
    Annex 5:
    Host: dadbak01
    Raw device: / dev/tape/by-id/scsi-1IBM___ULTRIUM-TD2___7MHHY00202__

    Thank you

    Rich

  • Link between ITC and CallManager Server

    Hi list;

    The link between the CallManager and the CTI server is done via JTAPI or one Trunk IP (as gatekeeeper of access using H.323 or SIP controller and so on)?

    Concerning

    Bilal

    Bilal,.

    If you plan to deploy the IPCC with Avaya or Nortel, he has no problem using CT Connect as a CTI server. In this case you don? business ICT or CTIOS need t. I have a deployment with ten Avaya Definity and ICM is used for intelligent routing between the ten Avayas and Envox CT Connect is the CTI server for the agents.

    You can not use CT Connect with the IPCC and CallManager, for later call center, because CT Connect do? do not provide Contact Center functions: login, logout, ready, etc. With the IPCC and CallManager, you can use CTIOS.

    For Avaya, Nortel and other OBXs, Envox CT COnnect provides functionality to connect, disconnect and change the status of the agent. For CallManager only provides functions of phone or the duties of the agent.

    Juan Luis

  • Repeated loss of connection between Outlook and Exchange server

    Hello

    I am running Windows 7 beta ultimate evaluation copy Build 7100.

    On that, I installed Office 2007, part of which is Outlook (12.0.6514.5000) SP2 MSO (12.0.64251000).

    I do the usual Windows updates and recently, I noticed that my Outlook has been updated as when I turn it off, I have a new Outlook "grey" with a red 'x' icon in this document, which disappears when the software is finally off.

    The problem is that now Outlook repeatedly loses the connection with the Exchange Server in my (work) and I have to close Outlook in order to reconnect and reactivate.

    It only happens when I'm at home - not at work (where I am actually on the internal network).

    It's very frustrating.

    Can you please help?

    Check with this community: http://www.microsoft.com/office/community/en-us/flyoutoverview.mspx

  • mechanism between DB and application server

    Hello

    Currently I have installed R12.1.3 ebs and DB under 11.1.0.7 upgrade to 11.2.0.2.
    When upgrading the database server, I have a question how application server detects the database server.
    The question may seem a little silly, but that's how it is. :)
    For example, when DB is upgraded, upgrade, configuration and post activities are explained on side DB in the documents.
    But then, how the database server to find application after the installation of new DB?
    It works based on the updated file listener only...?
    Or is there a configuration that must be done application server side as well after the DB is upgraded?

    Can someone help with my questions...?

    Thank you

    Hello
    > It works based on the updated file listener only...?
    Definitely, it will use the earpiece to connect with the db.

    During the upgrade, you create appsutl.zip and copy this to the level of the database and run the automatic configuration service. It's that time where the link is established.

    Thank you

  • LDAP over SSL doesn't work is not between ASA and AD server

    Hi all.

    We have configured clientless SSL WebVPN portal on an ASA5525 using LDAP authentication with an ad server. All is well until what we enable LDAP over SSL to allow users to change an expired password. They get just connection error every time, even if their password is correct.

    The systems team have installed the necessary certificate on the AD server.

    The newspaper of the ASDM I get

    Joffrey.pcmtu.Keele.AC.UK marking AAA in aaa-Server CTU_LDAP04 group LDAP server down
    Marking AAA 172.16.0.10 LDAP server group aaa-server active CTU_LDAP04

    On the ASA, I get the debugging ldap following 255

    [50] starting a session
    [50] new application Session, framework 0x00007fffddc99a60, reqType = authentication
    [50] the fiber began
    [50] create LDAP context with uri = ldaps://172.16.0.10:636
    [50] to connect to the LDAP server: ldaps://172.16.0.10:636, status = failure
    [50] cannot read the rootDSE. Cannot contact the LDAP server.
    [50] output fiber Tx = 0 bytes Rx = 0 bytes, status =-2
    [50] end of session

    On the ad server, the systems team report TLS Fatal Alert Code 48 which is...

    Received a valid certificate chain or partial string, but the certificate has been refused because the authority , could not be located or couldn't be matched with a known, trusted CA. This message is always fatal.

    Can someone shed some light on where we need to look at.

    Thank you. Richard.

    Richard,

    This could be due to:

    https://Tools.Cisco.com/bugsearch/bug/CSCus71190/?reffering_site=dumpcr

    M.

  • I have not located upstream or downstream activity and no internet connection. How can I configure my modem the internet works that way?

    to connect to the internet have no upstream and downstream. How to change the protocols so my modem can send and receive.

    original title: unable to connect to the internet

    Hello

    1 how long have you been faced with this problem?
    2. don't you make changes on the computer before this problem?
    3. what type of internet connection (wired or wireless) do you use?

    Answer these questions and provide us with more specific information on the issue. This could help us help you better.

    Refer the article that could help you solve this problem.
    How to troubleshoot possible causes of Internet connection problems in Windows XP
    http://support.Microsoft.com/kb/314095

  • Unlike char in ORACLE and SQL SERVER

    Hello gurus,

    I tried to querying data from Oracle to sql server through linked server, but get me an error! set length corresponds to the error! I know there are CHAR data type in sql server and thus as in oracle.

    But when I use the CAST FUNCTION with CHAR it works fine
    -- error code 
    
      select * from openquery( linkoracle11 
               select  col1, col2, col3 from test_table )
    
    
    -- say col3 char(1)   -- data type
    ---

    -- working code 
    
      select * from openquery ( linkoracle 11 
               select  col1, col2, cast (col3 as char(1)) as col_3 from test_table )
    I was wondering, what is the difference between oracle and sql server for the CHAR data type?

    The gurus of the idea?

    Thank you

    What is the error you get?

    What is the characters in database and NLS_LENGTH_SEMANTICS game on your Oracle system?

    SELECT *
      FROM v$nls_parameters
     WHERE name LIKE '%CHARACTERSET';
    
    SQL> SHOW PARAMETER nls_length_semantics;
    

    What is the character set of data in SQL Server?

    If your local database is a variable length character set (like UTF8) and NLS_LENGTH_SEMANTICS is set to (default) BYTES, a char (1) allocate 1 byte of storage which may not be sufficient for a single character. The receiving application may need to allocate a buffer with 3 times more many bytes as there are characters in order to ensure that it will be able to process the result. I don't know why add an implicit CAST that would change, but since we are several levels removed from the code to figure out how large a buffer to allocate, it is not very surprising.

    Justin

  • And connector server AD, Exchange, AS400

    Hello world

    I want to put in place the connectors for the AD, Exchange, target AS400 systems.
    I tried to implement these system three target.

    I have a few questions about the connectors?
    1. is server connector is required for AD, Exchange, AS400? If it's the need for tagert systems is necessary?
    Can you explain the connection between connector and connector server?
    2. can you connector server installed on the machine target AS400 AS400?

    Thank you.
    Best regards.

    I would say, install two connector server an AD and exchange and other for AS400. You can install on the target systems, but not mandatory. You can have the autonomous system for server connector as well. One thing to consider is, it should be in the same field of the target system.

Maybe you are looking for