VLAN SG300-10 Questions

My apologies if this has been asked before, but I have a few questions on setup of my new switch and network. I've never worked with before switches, so it's quite a learning experience. The image above shows the current provision of my network. Here's how I tried to implement, so far.

VLAN 1 [1-4 Ports, unidentified, trunk] (172.16.1.1/24)

Workstation A (wired)

172.16.1.2/24

Server B (wired)

172.16.1.3/24

VLAN 2 [Ports 5-8, unidentified, trunk] (172.16.2.1/24)

Server C (wired)

172.16.2.2/24

Server (wired)

172.16.2.3/24

Server E (wired)

172.16.2.4/24

Server F (wired)

172.16.2.5/24

VLAN 3 [9-10, unidentified, trunk Ports] (192.168.1.1/24)

G laptop (wireless)

DHCP through a router

H laptop (wireless)

DHCP through a router

Laptop I have (wireless)

DHCP through a router

Wireless router

192.168.1.254/24

Now, my goal is to have all 3 VLAN power talking to each other but also have VLAN 1 access to the internet through the wireless router. In the future, I also Server B to be able to expose services (http and ssh) outwards. VLAN 2 should not have access to the internet at all. I know that I can add static to the wireless router, if necessary routes. All three laptops, can access the internet via the wireless router, with no problems.

So my questions are:

(1) is there something inherently wrong with the design of this network? If so, what could be changed?

(2) 3 VLAN isn't really necessary?

(3) what I need to do, to get the 3 VLANS communicate with each other?

(4) what should be the doors, to get internet access 1 VLAN?

(5) what would need to do, to expose services from Server B to the outside?

(6) what static routes can I add?

Thanks in advance!

Jer

Hello Jeremy,.

I think that the problem is probably in the router does not route traffic to the switch. That no interface you specified in your career? Once the routing works, DNS should also work.

Kind regards

-David Aguilar

Cisco Small Business Support Center

Tags: Cisco Support

Similar Questions

  • VLAN SG300 - 28 p L3 Question

    Hello

    I'm fighting for the last 20 days to learn how to change IP address on my switch. When the switch came 1st time, he grabbed a my server DHCP address. I changed the config instead of default L2 L3 configuration. After that point he does give me not an option to change the static IP address. I changed to static IP, but it allows me to change the mask only.

    My need is to change the IP Address of the interface vlan1 to be du.1 default gateway. So far, I am unable to do so. Attached screenshot shows that the IP address field is not modifyable.

    Any ideas?

    You have activated services (security-> TCP/UDP services)? and copied running at startup? ('Save')

    Svein

  • SG300 Setup question

    Hi and thanks for reading.

    I have 3 sg300 switch/routers, I'm trying to set up and I have a few questions. This is how I have it set up so far.

    SG300 #1 mode layer 3 (router) with spf ge27 connected to our switch through fibers. have set up 2 VLANS (vlan1 10.10.0.1 device ip value) contains all the unidentified ports. (vlan200 ip 172.30.0.30 the value contains the ge27 port). our main hp curve pro is 172.30.0.1.

    second sg300 #2 (layer switch mode 2) a fiber connecting port 10 to 28 of the first sg300 port. This one has 1 vlan with ip defined on 10.10.0.3

    third sg300 #3 (layer switch mode 2) a fibre port connected to the port the second sg300 also with 1 9 vlan, ip device set to 10.10.0.4.

    After you add the declarations of good road to the first device I can ping to all remote subnets and receive answers from one of the devices. everything seems to be working but having a weird problem. I can't device managed on the basis of 2 or 3 (interface) web from anywhere that directly connected to one of the 3 devices. I can handle the device one from anywhere.

    Not sure if it's the correct configuration or what Miss me to be honest.

    Thank you

    On the 2 switch, the switch must have a default gateway specified in order to manage from a different subnet.

    -Tom
    Please evaluate the useful messages

  • Setup VLAN SG300-52 beginner

    Hello world

    I appreciate, it's a very beginner question and there may be a few facepalms is going to happen, but I could do with help.
    We just bought a SG300-51 switch to enable our businesses to grow. I'm trying to set up 2 VLANS (1 containing a router, the second comes from my pc at the moment so I have test).

    • VLAN 1 (the default) works obviously fine with access to the internet.
    • VLAN 2 (which is the vlan id 10) doesn't have access to the internet.

    For note, our router is run so I have no control over that.

    So for now 1-2 Ports are on the vlan 1 under Access. Port 3 is in vlan 2 access. I changed the 3 to the trunk port, but nothing helped. All traffic is marked as not signposted on all ports.

    IP addresses assigned on the vlan 1 are allocated from the router from 192.168.1.1 to x.x.1.254 (the router is 254). The switch for the vlan 1 is at 192.168.1.1.
    Assigned IP address in vlan 2 (by aboard dhcp on the switch) are 10.0.10.1 - 10.0.10.254 (the 10.0.10.1 switch setting).

    I have an IPv4 static route from: 0.0.0.0 to 192.168.1.254.

    Now, I don't know I'm missing something fundamental and I read through the article furiously to try to discover what is happening, if someone could help and point me in the right direction, I would be very grateful.

    Thanks in advance.

    I could be wrong, but I think it should already be in mode L3 because it appears that he has been able to assign addresses IP interface VLAN 1 and 10.

    If your PC is plugged IG3 access vlan 10 then you should use 10.0.10.1 as your default gateway and you need a way back to 10.0.10.0/24 via 192.168.1.1 in your router/firewall

  • Setup VLAN SG300-20

    Hello! Everyone.

    I have 2 small business sg300 switches connected through a catalyst 2960S, I created 2 VLANS and VLAN 3 on two SG300 connect my servers, but those who do not work properly. I connect a pc to a port in each VLAN on the two switches, then I test ping interfaces connected to this VLAN, but sometimes I only connections of a switch, and nothing when I try the second switch. Or I can reach almost all interfaces connected to the switch and one of them does not.  When I disconnect and connect to an interface connected to these switches and try to test again the results change other behaviours.

    I Don t need to route via VLAN I want only the link between each VLAN. So I Don t know if it s necessary to assign an IP address for VLANs

    I made the other configuration using the web interface:

    • I created 2 VLANS and VLAN 3 on each switch SG300 manually and ports assigned to VLANs
    • I configured an each SG300 as TRUNK switch port to connect to the catalyst 2960S. And other ports such as access mode.
    • In the Cat2960S, I configured the ports connected to each SG300 as TRUNK and the traffic of VLAN enabled if these ports.

    The thing is, I don't know what is the problem in my setup. I thought on the GVRP Protocol implementation but Cat2960S support only VTP.

    Does anyone know the right steps to implement this configuration or what is the process to implement the GVRP protocol using these 3 switches?

    I have attached my diagram to know what I m doing.

    Best regards.

    Hello

    In the two SG300 switch:

    Configure the port Fe0/19 in the trunk and VLAN enable this port 1U, 2T, 3T (can be configured on GUI)

    Cat2960 switch:

    Configure the port Fe0/11.0/12 in the trunk and leave all the VLANS. (Vlan 1 must be native.)

    concerning

    Deborah

  • Interface VLAN SG300-28 Firmware 1.3.7.18

    Hello

    I just my SG300 to update the last firrmware 1.3.7.1.8 and I met this problem:

    -By default, the interface VLAN has been activated, but the display is always disabled

    -I can not change and I can not ping to the VLAN IP interface as well (I gave an IP 192.168.10.1)

    Is this a bug? Does anyone know how to fix this? Please help me!

    Appreciate your help

    Minh

    minh06,

    You upgrade the startup code for Sx300_FW_Boot_1.3.5.58 ?

    -Marty

  • Routing inter - vlan Sg300-28

    Hello

    Thank you and thank you in advance if you can help with this simple configuration

    SG300, how can mode layer 3, you make 2 VLAN see each other?

    In my lab at home:

    Default Vlan1 (GE1: access mode) 192,168,2.254

    Static VLAN10 (GE24: access mode) 192.168.10.1

    Town of Port GE25: Trunk Mode directly connected to interface my router 192.168.2.1)

    Vlan1 can communicate with the outside world and the internet, for example, to a different subnet: 192.168.1.0

    VLAN10 is not visible from the outside and from VLAN1

    How can I allow traffic from VLAN10 through the commune GE25 Port to the outside world?

    The router config says: VLAN10 is diretly connected to 192.168.2.1, but I can't ping. I wonder why?

    Concerning

    Minh

    --------------------------------------------------

    VLAN #show SG300

    Created by: D-default, S-Static, G-GVRP, R-radius assigned VLAN

    Ports created by virtual local network name

    ---- ----------------- --------------------------- ----------------

    1 1 article gi1-23, gi25-28, D m 1-8

    10 gi24 S VLAN10

    Ip #show SG300 road

    Maximum parallel paths: 1 (1 after reset)

    IP routing: enabled

    Codes: > - best, C - connected, S - static

    S 0.0.0.0/0 [1/1] via 192.168.2.1, 36:24:22, vlan 1

    C 192.168.2.0/24 is directly connected, vlan 1

    S 192.168.10.0/24 [1/1] via 192.168.2.1, 27:23:12, vlan 1

    He had to set the default gateway on the switch to 192.168.2.1

    -Tom
    Please mark replied messages useful

  • How to track down the STP with SG300-52 questions and SG300-28 - the command debug debug mode password?

    Hello *.

    actually, I'm trying to track down and identify serious problems of STP loop to my switch tree SG300-xy.

    For further investigation, I would use the CLI debug mode but unfortunately the

    debugging

    debug mode command is password protected. I always "DEBUG password: *" :-((

    Could someone please help with the password of the SG300-xy switches with 1.3.0.62 firmware debugging it please?

    Thank you very much in advance for your help and your response!

    Best regards
    Matthias

    Hi Matthias, debugging is to engineer end only, it has no practical use.

    Also, if you are unable to go to the debug console, it is unsupported.

    I don't know how you can have a loop spanning trees like the tree covering weight stops redundant links. So I think that you are either using BPMH and incorrectly labeled regions or added a vlan incorrect or these switches connect in a device that is not active PLEASE and causing the transfer of issues like that.

    Quite honestly if you have a loop of network which is so bad, the best thing to do is to unplug the 1 wire at a time until you see what link has caused.

    -Tom
    Please mark replied messages useful

  • SG300-28 questions - InterVLAN routing

    Hi all

    I am trying to switch SG300-28 place and do work for several days, with a very simple configuration, but this device is just to stuborn giving me headaches. I hope that you will tell me a solution to my problem.

    So I configured the VLAN on the switch, assigned to all ports, given IP addresses for VLANs, etc.. But I digress not test phase where I try to rattle of two stations of different VLANS.

    I have pictures of the attached current configuration. Stations are on ports 4 (VLAN4) and port 15 (VLAN3). First good 192.168.30.x a station address with the default gateway 192.168.30.1. Second station address of the 192.168.5.x and gateway 192.168.5.1. The two stations can ping the two gateways, but not eachother. Traffic within a VIRTUAL local network works fine, so routing is the most obvious problem.

    There is no active ACLs.

    Please see attached photos and give me something to try, because I spent three days to experiment without luck!

    One of the biggest mistakes I see relies on 'ping' to see if things work. Do not forget that the 'ping' sends a request to echo, that does not force the customer to send and echo response. Ensure that stations are configured to respond to pings or try to access a share, or a service configured on clients. Another thing to consider, that the client ports access ports and not General, this can be a problem, but it should be allowed, as is.

    On a side note, the current configuration you cannot access anything out in the cloud. If you need to access cloud do not forget to add a default route on the switch.

    I hope this helps!

  • LACP hash between N3048 and CISCO SG300/SG200 + question Twinax attach direct cable

    Hello

    In my network I have deployed two new N3048 with 2 transceivers SPF + and SPF module back + as core switches are connected to other 3 switches from edge of N2048 using optical fiber and I reused my previous CISCO SG300 and SG200 goes to serve the other two boxes of my campus via the spine in copper.

    I have 4 copper cable which starts from the hub of the SG300 network and 2 the SG200 brass. I set up to have a redundant connection using 2 + 2 with SG300 and 1 + 1 with SG200 RSTP.

    So for the SG300 I re LAG + LACP to have two channels of the N3048s port, but now that a single cable is connected because I don't know what kind of LACP hash mode should I put on N3048 to have a compatible hash between Dell and Cisco switches.

    My N3048 have mode 7 (Advanced hash) as default but I guess that cisco models do not understand... so, what mode is the best for LACP work perfectly with small business cisco switches?

    I also received my twinax cables to connect my two N3048 via SPF + back modules... conhot can I plug the cables into the slots SPF + (already mounted) without turning off my basic switches?

    Thank you!

    See you soon

    Cables can be connected/disconnected, but I don't know if the real module SFP + for the rear of the N3000 is hot plug.

  • SG200 to VLAN SG300

    Hi all

    I have a client with of several SG300 for VLAN1 for data and voice VLAN10. PCs are piggy is interrupting the phones and showing in the fine SG300:

    A Department has recently employed more people, so we have a SG200 switch to connect the computers and phones. I don't seem to be able to get all the connectivity between the new switch and the SG300 it should connect. I have installation VLAN1 and 10 according to the images below:

    (Most likely) I'm missing something obvious here?

    Thanks in advance.

    If all ports are 1u, 10 t between the two switches, there is a different problem.

    I guess it's possible that the new switch SX200 can act only wobbly. Pass you any firmware prior to installation?

    I probably load the latest software and the switch to make sure it isn't being weird with you.

    -Tom
    Please mark replied messages useful

  • Help VLAN SG300

    I have install successfully one VLAN but...

    Since 192.168.1.x I can ping everything on 192.168.50.x

    Inside the ports VLAN 50 5 & 6 both the portable and the nas server can talk to 192.168.50.1.

    Since 192.168.1.x, I can access all the 192.168.50.1 resources.

    Inside of VLAN 50 I can ping 192.168.50.1 but can't access anything that anybody else in the VLAN or off.

    From the 192.168.50.100 laptop, I cannot ping 192.168.50.50 (NAS), but I can ping the 192.168.50.1 gateway. I can't ping any internet addresses.

    New kind of learning VLAN here. Any ideas why this happens?

    Hello and thanks for the reply.

    I'm sorry, I didn't know what was the purpose of the configuration.

    If what you're trying to do is to configure your network if the switch then makes the routing steps:

    1 - Position the layer 3 switch

    2. create the VLAN

    3 assign Ip addresses to all the VLANS.

    4 - for all VLANS can get out to the internet, you must create a default route on the switch. It should look like this: 0.0.0.0 0.0.0.0 IP_address_of_router

    5. on the router, you need to create static routes for all the VLANS the router does not know. When you create the static routes, be sure to send this traffic to the IP address of the switch on the same VLAN as the router.

    6 - buy last, perhaps the most important of them step is to ensure that all PC use the IP address of the switch as the gateway by default for the VLAN to which they belong.

    Try this and let us know if it worked. Also, feel free to ask ay if something was not clear enough.

  • Configuration of Vlan SG300-20 for the desktop and server ESXi

    Hello

    I'm fairly new to network so please, be gentle.  I'm setting up a number of VLANs for my lab at home.

    I recently moved jobs and took an Oracle Apps of the Middleware & role has therefore need to start picking up the Apache, e-Business Suite, etc. of the load balancers so need to segragate my network to allow different configurations, I want to install in my lab ESXi.

    My setup is detailed below:-

    I have a router of dryatek 2860n which is my entry for the installation of the internet on IP 192.168.1.1

    My Cisco switch has been set to 192.168.1.2 and the installer to use the 3 layer.

    I have a number of PCs connected to my switch I want to use to administer my ESXi server and have access to the different VLANS.

    VIRTUAL LANs, I need are the following

    VLAN 1 192.168.1.x/24 By default / Internet Uplink
    VLAN 12 10.0.12.x/24 Workstations
    VLAN 13 10.0.13.x/24 Server management interface
    VLAN 14 10.0.14.x/24 Public Interface Server
    VLAN 15 10.0.15.x/24 Private server interface
    VLAN 20 10.0.20.x/24 Storage

    My esxi server has two network interfaces that will have traffic MGMT, Public and private configured as virtual interfaces in ESXi and one that runs my traffic of storage/nfs mounts on a QNAP NAS, I want to make it work on my network

    Here is how I have the ports

    A Port VLAN membership
    G1 VLAN1
    G13 - 20 VLAN 12

    Need to access the VLAN 1, 13, 14, 15, 20

    G9

    VLAN 13, 14, 15

    G10 VLAN 20
    G7 - 8 VLAN 20 LAG configured to QNAP NAS

    G13-20 are my workstations that need to be on VLAN 12, but must also be able to connect to 13, 14, 15, 20, SSH, RDP, NFS

    G9 is the Interface of MGMT of ESXi who need to have traffic on VLAN 13, 14, 15

    G10 is ESXi storage Interface that needs to access the VLAN 20 only

    G7/g8 are connect to QNAP that ideally I want to configure as a LAG.   When I get more interfaces in my ESXi Server I'll finally the team to match.

    I set up an ip interface in my CISCO switch to 10.0.12.1 as gateway to my workstations and created a static route in my router to allow traffic to the switch.  This does not quite yet.

    I also installed a default route to 0.0.0.0

    I followed a number of guides, but struggling to get my head around concepts and how to achieve the above configuration.

    Ideally, I want to configure this through the CLI as Ive had no end of problems with the web interface of the Cisco switch.

    I believe need g9 of trunk, and other ACCESS is it exact.

    How the workstatations to access the other VLAN?

    Any help would be appreciated

    Thank you

    Paul

    Hi Paul, to break it down a little.

    Host A connects to port 13.

    config t

    int gi0/13

    switchport mode access

    switchport access vlan 12

    ESXI connects to port 9

    config t

    int gi0/9

    switchport mode trunk

    switchport trunk allowed vlan add 13-15 (keep in mind this vlan 1 is unmarked here and is the IP of your server interface)

    This translates

    ESXI = 192.168.1.x 24 gateway 192.168.1.2

    interface vlan 1

    IP 192.168.1.2 255.255.255.0

    no ip address dhcp

    Host A = 10.0.12.x 24 10.0.12.1

    interface vlan 12

    name of the workstations

    10.0.12.1 IP address 255.255.255.0

    With this basic host configuration at shall communicate to ESXI (no other config on the switch)

    If please try to get the connectivity of base first, then can work on the roads and DHCP.

    -Tom
    Please mark replied messages useful

  • Creation of trunk of Cisco 6513 to Cisco SG300 - 10 p for Shoretel phones

    I plugged a new Cisco SG300 - 10 p in an access on our Cisco 6513 port, which is in vtp mode.  I think I will need to create a trunk port of the Cisco SG300 - 10 p 6513, to carry out my office data vlan 1 and my new vlan 112 shoretel VOIP.  I believe that some how all ports are in mode trunk on the default sg300.  I have attached a picture of what it looks like on the management area of vlan sg300.  For some reason any I can plug 3 phones in the sg300 currently just plugged in the 6513 access port and one of the 3 phones come with the vlan voip good 112 and goes into the service very good.  The other 2 phones come but show no service, until I closed the port on sg300 for these other 2 phones and then put the ports back up, then the phones go up.  All of this without going through the port on the Cisco 6513 as a trunk port, it is only now as an access port vlan 1 data and vlan 112 voip vlan.

    My question is, should I put the cisco 6513 in trunk mode and the sg300 will attempt to become the server in vtp and ruin my entire network.  This is what scares me, because I've heard the horror stories of what happens.  My other question is if I have to put the port in trunk mode on him going the sg300 6513, it causes all future phones at the same time without problems?  What would be the cause of 1 of the 3 phones to come as they do and 2 others to come after stop int and put it up?

    Thanks Dave

    Double post.

    Go HERE.

  • Cisco SG300 / ASA 5505 intervlan routing problem

    Dear all

    I have a problem with the configuration correctly sg300 layer 3 behind the ASA 5505 switch (incl. license more security)

    The configuration is the following:

    CISCO SG300 is configured as a layer 3 switch

    VLAN native 1: 192.168.1.254, default route ip address (inside interface ASA 192.168.1.1)

    VLAN defined additional switch

    VLAN 100 with 192.168.100.0/24, default gateway 192.168.100.254

    VLAN 110 with 192.168.110.0/24, default gateway 192.168.110.254

    VLAN 120 with 172.16.0.0/16, default gateway 172.16.10.254

    Of the VLANS (100,110,120) different, I am able to connect to all devices on the other VIRTUAL local networks (with the exception of Native VLAN 1; is not the ping requests)

    From the switch cli I can ping my firewall (192.168.1.1) and all the other gateways of VLANs and vlan (VLAN1, 100, 110, 120) devices

    Asa cli I can only ping my switch (192.168.1.254) port, but no other devices in other VLAN

    My question is this. What should I change or installation in the switch configuration or asa so that other VLANs to access the Internet through the ASA. I will not use the ASA as intervlan routing device, because the switch does this for me

    I tried to change the asa int e0/1 in trunkport (uplink port switch also), to enable all the VLANS, but as soon as I do that, I can not ping 192.168.1.254 ASA cli more.

    Any help is greatly appreciated

    Concerning

    Edwin

    Hi Edwin, because the switch is layer 3, the only necessary behavior is to ensure that default gateways to the computer are set on the SVI interface connection to the switch to make sure that the switch is transfer traffic wished to the ASA.

    The configuration between the ASA and the switch must stay true by dot1q, such as the vlan all other, unidentified native VLAN tagged.

    Also, if I'm not wrong, on the SAA you must set the security level of the port to 100.

    -Tom
    Please evaluate the useful messages

Maybe you are looking for