VLAN SG300-10 Questions
My apologies if this has been asked before, but I have a few questions on setup of my new switch and network. I've never worked with before switches, so it's quite a learning experience. The image above shows the current provision of my network. Here's how I tried to implement, so far.
VLAN 1 [1-4 Ports, unidentified, trunk] (172.16.1.1/24)
Workstation A (wired)
172.16.1.2/24
Server B (wired)
172.16.1.3/24
VLAN 2 [Ports 5-8, unidentified, trunk] (172.16.2.1/24)
Server C (wired)
172.16.2.2/24
Server (wired)
172.16.2.3/24
Server E (wired)
172.16.2.4/24
Server F (wired)
172.16.2.5/24
VLAN 3 [9-10, unidentified, trunk Ports] (192.168.1.1/24)
G laptop (wireless)
DHCP through a router
H laptop (wireless)
DHCP through a router
Laptop I have (wireless)
DHCP through a router
Wireless router
192.168.1.254/24
Now, my goal is to have all 3 VLAN power talking to each other but also have VLAN 1 access to the internet through the wireless router. In the future, I also Server B to be able to expose services (http and ssh) outwards. VLAN 2 should not have access to the internet at all. I know that I can add static to the wireless router, if necessary routes. All three laptops, can access the internet via the wireless router, with no problems.
So my questions are:
(1) is there something inherently wrong with the design of this network? If so, what could be changed?
(2) 3 VLAN isn't really necessary?
(3) what I need to do, to get the 3 VLANS communicate with each other?
(4) what should be the doors, to get internet access 1 VLAN?
(5) what would need to do, to expose services from Server B to the outside?
(6) what static routes can I add?
Thanks in advance!
Jer
Hello Jeremy,.
I think that the problem is probably in the router does not route traffic to the switch. That no interface you specified in your career? Once the routing works, DNS should also work.
Kind regards
-David Aguilar
Cisco Small Business Support Center
Tags: Cisco Support
Similar Questions
-
Hello
I'm fighting for the last 20 days to learn how to change IP address on my switch. When the switch came 1st time, he grabbed a my server DHCP address. I changed the config instead of default L2 L3 configuration. After that point he does give me not an option to change the static IP address. I changed to static IP, but it allows me to change the mask only.
My need is to change the IP Address of the interface vlan1 to be du.1 default gateway. So far, I am unable to do so. Attached screenshot shows that the IP address field is not modifyable.
Any ideas?
You have activated services (security-> TCP/UDP services)? and copied running at startup? ('Save')
Svein
-
Hi and thanks for reading.
I have 3 sg300 switch/routers, I'm trying to set up and I have a few questions. This is how I have it set up so far.
SG300 #1 mode layer 3 (router) with spf ge27 connected to our switch through fibers. have set up 2 VLANS (vlan1 10.10.0.1 device ip value) contains all the unidentified ports. (vlan200 ip 172.30.0.30 the value contains the ge27 port). our main hp curve pro is 172.30.0.1.
second sg300 #2 (layer switch mode 2) a fiber connecting port 10 to 28 of the first sg300 port. This one has 1 vlan with ip defined on 10.10.0.3
third sg300 #3 (layer switch mode 2) a fibre port connected to the port the second sg300 also with 1 9 vlan, ip device set to 10.10.0.4.
After you add the declarations of good road to the first device I can ping to all remote subnets and receive answers from one of the devices. everything seems to be working but having a weird problem. I can't device managed on the basis of 2 or 3 (interface) web from anywhere that directly connected to one of the 3 devices. I can handle the device one from anywhere.
Not sure if it's the correct configuration or what Miss me to be honest.
Thank you
On the 2 switch, the switch must have a default gateway specified in order to manage from a different subnet.
-Tom
Please evaluate the useful messages -
Hello world
I appreciate, it's a very beginner question and there may be a few facepalms is going to happen, but I could do with help.
We just bought a SG300-51 switch to enable our businesses to grow. I'm trying to set up 2 VLANS (1 containing a router, the second comes from my pc at the moment so I have test).- VLAN 1 (the default) works obviously fine with access to the internet.
- VLAN 2 (which is the vlan id 10) doesn't have access to the internet.
For note, our router is run so I have no control over that.
So for now 1-2 Ports are on the vlan 1 under Access. Port 3 is in vlan 2 access. I changed the 3 to the trunk port, but nothing helped. All traffic is marked as not signposted on all ports.
IP addresses assigned on the vlan 1 are allocated from the router from 192.168.1.1 to x.x.1.254 (the router is 254). The switch for the vlan 1 is at 192.168.1.1.
Assigned IP address in vlan 2 (by aboard dhcp on the switch) are 10.0.10.1 - 10.0.10.254 (the 10.0.10.1 switch setting).I have an IPv4 static route from: 0.0.0.0 to 192.168.1.254.
Now, I don't know I'm missing something fundamental and I read through the article furiously to try to discover what is happening, if someone could help and point me in the right direction, I would be very grateful.
Thanks in advance.
I could be wrong, but I think it should already be in mode L3 because it appears that he has been able to assign addresses IP interface VLAN 1 and 10.
If your PC is plugged IG3 access vlan 10 then you should use 10.0.10.1 as your default gateway and you need a way back to 10.0.10.0/24 via 192.168.1.1 in your router/firewall
-
Hello! Everyone.
I have 2 small business sg300 switches connected through a catalyst 2960S, I created 2 VLANS and VLAN 3 on two SG300 connect my servers, but those who do not work properly. I connect a pc to a port in each VLAN on the two switches, then I test ping interfaces connected to this VLAN, but sometimes I only connections of a switch, and nothing when I try the second switch. Or I can reach almost all interfaces connected to the switch and one of them does not. When I disconnect and connect to an interface connected to these switches and try to test again the results change other behaviours.
I Don t need to route via VLAN I want only the link between each VLAN. So I Don t know if it s necessary to assign an IP address for VLANs
I made the other configuration using the web interface:
- I created 2 VLANS and VLAN 3 on each switch SG300 manually and ports assigned to VLANs
- I configured an each SG300 as TRUNK switch port to connect to the catalyst 2960S. And other ports such as access mode.
- In the Cat2960S, I configured the ports connected to each SG300 as TRUNK and the traffic of VLAN enabled if these ports.
The thing is, I don't know what is the problem in my setup. I thought on the GVRP Protocol implementation but Cat2960S support only VTP.
Does anyone know the right steps to implement this configuration or what is the process to implement the GVRP protocol using these 3 switches?
I have attached my diagram to know what I m doing.
Best regards.
Hello
In the two SG300 switch:
Configure the port Fe0/19 in the trunk and VLAN enable this port 1U, 2T, 3T (can be configured on GUI)
Cat2960 switch:
Configure the port Fe0/11.0/12 in the trunk and leave all the VLANS. (Vlan 1 must be native.)
concerning
Deborah
-
Interface VLAN SG300-28 Firmware 1.3.7.18
Hello
I just my SG300 to update the last firrmware 1.3.7.1.8 and I met this problem:
-By default, the interface VLAN has been activated, but the display is always disabled
-I can not change and I can not ping to the VLAN IP interface as well (I gave an IP 192.168.10.1)
Is this a bug? Does anyone know how to fix this? Please help me!
Appreciate your help
Minh
minh06,
You upgrade the startup code for Sx300_FW_Boot_1.3.5.58 ?
-Marty
-
Hello
Thank you and thank you in advance if you can help with this simple configuration
SG300, how can mode layer 3, you make 2 VLAN see each other?
In my lab at home:
Default Vlan1 (GE1: access mode) 192,168,2.254
Static VLAN10 (GE24: access mode) 192.168.10.1
Town of Port GE25: Trunk Mode directly connected to interface my router 192.168.2.1)
Vlan1 can communicate with the outside world and the internet, for example, to a different subnet: 192.168.1.0
VLAN10 is not visible from the outside and from VLAN1
How can I allow traffic from VLAN10 through the commune GE25 Port to the outside world?
The router config says: VLAN10 is diretly connected to 192.168.2.1, but I can't ping. I wonder why?
Concerning
Minh
--------------------------------------------------
VLAN #show SG300
Created by: D-default, S-Static, G-GVRP, R-radius assigned VLAN
Ports created by virtual local network name
---- ----------------- --------------------------- ----------------
1 1 article gi1-23, gi25-28, D m 1-8
10 gi24 S VLAN10
Ip #show SG300 road
Maximum parallel paths: 1 (1 after reset)
IP routing: enabled
Codes: > - best, C - connected, S - static
S 0.0.0.0/0 [1/1] via 192.168.2.1, 36:24:22, vlan 1
C 192.168.2.0/24 is directly connected, vlan 1
S 192.168.10.0/24 [1/1] via 192.168.2.1, 27:23:12, vlan 1
He had to set the default gateway on the switch to 192.168.2.1
-Tom
Please mark replied messages useful -
Hello *.
actually, I'm trying to track down and identify serious problems of STP loop to my switch tree SG300-xy.
For further investigation, I would use the CLI debug mode but unfortunately the
debugging
debug mode command is password protected. I always "DEBUG password: *" :-((
Could someone please help with the password of the SG300-xy switches with 1.3.0.62 firmware debugging it please?
Thank you very much in advance for your help and your response!
Best regards
MatthiasHi Matthias, debugging is to engineer end only, it has no practical use.
Also, if you are unable to go to the debug console, it is unsupported.
I don't know how you can have a loop spanning trees like the tree covering weight stops redundant links. So I think that you are either using BPMH and incorrectly labeled regions or added a vlan incorrect or these switches connect in a device that is not active PLEASE and causing the transfer of issues like that.
Quite honestly if you have a loop of network which is so bad, the best thing to do is to unplug the 1 wire at a time until you see what link has caused.
-Tom
Please mark replied messages useful -
SG300-28 questions - InterVLAN routing
Hi all
I am trying to switch SG300-28 place and do work for several days, with a very simple configuration, but this device is just to stuborn giving me headaches. I hope that you will tell me a solution to my problem.
So I configured the VLAN on the switch, assigned to all ports, given IP addresses for VLANs, etc.. But I digress not test phase where I try to rattle of two stations of different VLANS.
I have pictures of the attached current configuration. Stations are on ports 4 (VLAN4) and port 15 (VLAN3). First good 192.168.30.x a station address with the default gateway 192.168.30.1. Second station address of the 192.168.5.x and gateway 192.168.5.1. The two stations can ping the two gateways, but not eachother. Traffic within a VIRTUAL local network works fine, so routing is the most obvious problem.
There is no active ACLs.
Please see attached photos and give me something to try, because I spent three days to experiment without luck!
One of the biggest mistakes I see relies on 'ping' to see if things work. Do not forget that the 'ping' sends a request to echo, that does not force the customer to send and echo response. Ensure that stations are configured to respond to pings or try to access a share, or a service configured on clients. Another thing to consider, that the client ports access ports and not General, this can be a problem, but it should be allowed, as is.
On a side note, the current configuration you cannot access anything out in the cloud. If you need to access cloud do not forget to add a default route on the switch.
I hope this helps!
-
LACP hash between N3048 and CISCO SG300/SG200 + question Twinax attach direct cable
Hello
In my network I have deployed two new N3048 with 2 transceivers SPF + and SPF module back + as core switches are connected to other 3 switches from edge of N2048 using optical fiber and I reused my previous CISCO SG300 and SG200 goes to serve the other two boxes of my campus via the spine in copper.
I have 4 copper cable which starts from the hub of the SG300 network and 2 the SG200 brass. I set up to have a redundant connection using 2 + 2 with SG300 and 1 + 1 with SG200 RSTP.
So for the SG300 I re LAG + LACP to have two channels of the N3048s port, but now that a single cable is connected because I don't know what kind of LACP hash mode should I put on N3048 to have a compatible hash between Dell and Cisco switches.
My N3048 have mode 7 (Advanced hash) as default but I guess that cisco models do not understand... so, what mode is the best for LACP work perfectly with small business cisco switches?
I also received my twinax cables to connect my two N3048 via SPF + back modules... conhot can I plug the cables into the slots SPF + (already mounted) without turning off my basic switches?
Thank you!
See you soon
Cables can be connected/disconnected, but I don't know if the real module SFP + for the rear of the N3000 is hot plug.
-
Hi all
I have a client with of several SG300 for VLAN1 for data and voice VLAN10. PCs are piggy is interrupting the phones and showing in the fine SG300:
A Department has recently employed more people, so we have a SG200 switch to connect the computers and phones. I don't seem to be able to get all the connectivity between the new switch and the SG300 it should connect. I have installation VLAN1 and 10 according to the images below:
(Most likely) I'm missing something obvious here?
Thanks in advance.
If all ports are 1u, 10 t between the two switches, there is a different problem.
I guess it's possible that the new switch SX200 can act only wobbly. Pass you any firmware prior to installation?
I probably load the latest software and the switch to make sure it isn't being weird with you.
-Tom
Please mark replied messages useful -
I have install successfully one VLAN but...
Since 192.168.1.x I can ping everything on 192.168.50.x
Inside the ports VLAN 50 5 & 6 both the portable and the nas server can talk to 192.168.50.1.
Since 192.168.1.x, I can access all the 192.168.50.1 resources.
Inside of VLAN 50 I can ping 192.168.50.1 but can't access anything that anybody else in the VLAN or off.
From the 192.168.50.100 laptop, I cannot ping 192.168.50.50 (NAS), but I can ping the 192.168.50.1 gateway. I can't ping any internet addresses.
New kind of learning VLAN here. Any ideas why this happens?
Hello and thanks for the reply.
I'm sorry, I didn't know what was the purpose of the configuration.
If what you're trying to do is to configure your network if the switch then makes the routing steps:
1 - Position the layer 3 switch
2. create the VLAN
3 assign Ip addresses to all the VLANS.
4 - for all VLANS can get out to the internet, you must create a default route on the switch. It should look like this: 0.0.0.0 0.0.0.0 IP_address_of_router
5. on the router, you need to create static routes for all the VLANS the router does not know. When you create the static routes, be sure to send this traffic to the IP address of the switch on the same VLAN as the router.
6 - buy last, perhaps the most important of them step is to ensure that all PC use the IP address of the switch as the gateway by default for the VLAN to which they belong.
Try this and let us know if it worked. Also, feel free to ask ay if something was not clear enough.
-
Configuration of Vlan SG300-20 for the desktop and server ESXi
Hello
I'm fairly new to network so please, be gentle. I'm setting up a number of VLANs for my lab at home.
I recently moved jobs and took an Oracle Apps of the Middleware & role has therefore need to start picking up the Apache, e-Business Suite, etc. of the load balancers so need to segragate my network to allow different configurations, I want to install in my lab ESXi.
My setup is detailed below:-
I have a router of dryatek 2860n which is my entry for the installation of the internet on IP 192.168.1.1
My Cisco switch has been set to 192.168.1.2 and the installer to use the 3 layer.
I have a number of PCs connected to my switch I want to use to administer my ESXi server and have access to the different VLANS.
VIRTUAL LANs, I need are the following
VLAN 1 192.168.1.x/24 By default / Internet Uplink VLAN 12 10.0.12.x/24 Workstations VLAN 13 10.0.13.x/24 Server management interface VLAN 14 10.0.14.x/24 Public Interface Server VLAN 15 10.0.15.x/24 Private server interface VLAN 20 10.0.20.x/24 Storage My esxi server has two network interfaces that will have traffic MGMT, Public and private configured as virtual interfaces in ESXi and one that runs my traffic of storage/nfs mounts on a QNAP NAS, I want to make it work on my network
Here is how I have the ports
A Port VLAN membership G1 VLAN1 G13 - 20 VLAN 12 Need to access the VLAN 1, 13, 14, 15, 20
G9 VLAN 13, 14, 15
G10 VLAN 20 G7 - 8 VLAN 20 LAG configured to QNAP NAS G13-20 are my workstations that need to be on VLAN 12, but must also be able to connect to 13, 14, 15, 20, SSH, RDP, NFS
G9 is the Interface of MGMT of ESXi who need to have traffic on VLAN 13, 14, 15
G10 is ESXi storage Interface that needs to access the VLAN 20 only
G7/g8 are connect to QNAP that ideally I want to configure as a LAG. When I get more interfaces in my ESXi Server I'll finally the team to match.
I set up an ip interface in my CISCO switch to 10.0.12.1 as gateway to my workstations and created a static route in my router to allow traffic to the switch. This does not quite yet.
I also installed a default route to 0.0.0.0
I followed a number of guides, but struggling to get my head around concepts and how to achieve the above configuration.
Ideally, I want to configure this through the CLI as Ive had no end of problems with the web interface of the Cisco switch.
I believe need g9 of trunk, and other ACCESS is it exact.
How the workstatations to access the other VLAN?
Any help would be appreciated
Thank you
Paul
Hi Paul, to break it down a little.
Host A connects to port 13.
config t
int gi0/13
switchport mode access
switchport access vlan 12
ESXI connects to port 9
config t
int gi0/9
switchport mode trunk
switchport trunk allowed vlan add 13-15 (keep in mind this vlan 1 is unmarked here and is the IP of your server interface)
This translates
ESXI = 192.168.1.x 24 gateway 192.168.1.2
interface vlan 1
IP 192.168.1.2 255.255.255.0
no ip address dhcp
Host A = 10.0.12.x 24 10.0.12.1
interface vlan 12
name of the workstations
10.0.12.1 IP address 255.255.255.0
With this basic host configuration at shall communicate to ESXI (no other config on the switch)
If please try to get the connectivity of base first, then can work on the roads and DHCP.
-Tom
Please mark replied messages useful -
Creation of trunk of Cisco 6513 to Cisco SG300 - 10 p for Shoretel phones
I plugged a new Cisco SG300 - 10 p in an access on our Cisco 6513 port, which is in vtp mode. I think I will need to create a trunk port of the Cisco SG300 - 10 p 6513, to carry out my office data vlan 1 and my new vlan 112 shoretel VOIP. I believe that some how all ports are in mode trunk on the default sg300. I have attached a picture of what it looks like on the management area of vlan sg300. For some reason any I can plug 3 phones in the sg300 currently just plugged in the 6513 access port and one of the 3 phones come with the vlan voip good 112 and goes into the service very good. The other 2 phones come but show no service, until I closed the port on sg300 for these other 2 phones and then put the ports back up, then the phones go up. All of this without going through the port on the Cisco 6513 as a trunk port, it is only now as an access port vlan 1 data and vlan 112 voip vlan.
My question is, should I put the cisco 6513 in trunk mode and the sg300 will attempt to become the server in vtp and ruin my entire network. This is what scares me, because I've heard the horror stories of what happens. My other question is if I have to put the port in trunk mode on him going the sg300 6513, it causes all future phones at the same time without problems? What would be the cause of 1 of the 3 phones to come as they do and 2 others to come after stop int and put it up?
Thanks Dave
Double post.
Go HERE.
-
Cisco SG300 / ASA 5505 intervlan routing problem
Dear all
I have a problem with the configuration correctly sg300 layer 3 behind the ASA 5505 switch (incl. license more security)
The configuration is the following:
CISCO SG300 is configured as a layer 3 switch
VLAN native 1: 192.168.1.254, default route ip address (inside interface ASA 192.168.1.1)
VLAN defined additional switch
VLAN 100 with 192.168.100.0/24, default gateway 192.168.100.254
VLAN 110 with 192.168.110.0/24, default gateway 192.168.110.254
VLAN 120 with 172.16.0.0/16, default gateway 172.16.10.254
Of the VLANS (100,110,120) different, I am able to connect to all devices on the other VIRTUAL local networks (with the exception of Native VLAN 1; is not the ping requests)
From the switch cli I can ping my firewall (192.168.1.1) and all the other gateways of VLANs and vlan (VLAN1, 100, 110, 120) devices
Asa cli I can only ping my switch (192.168.1.254) port, but no other devices in other VLAN
My question is this. What should I change or installation in the switch configuration or asa so that other VLANs to access the Internet through the ASA. I will not use the ASA as intervlan routing device, because the switch does this for me
I tried to change the asa int e0/1 in trunkport (uplink port switch also), to enable all the VLANS, but as soon as I do that, I can not ping 192.168.1.254 ASA cli more.
Any help is greatly appreciated
Concerning
Edwin
Hi Edwin, because the switch is layer 3, the only necessary behavior is to ensure that default gateways to the computer are set on the SVI interface connection to the switch to make sure that the switch is transfer traffic wished to the ASA.
The configuration between the ASA and the switch must stay true by dot1q, such as the vlan all other, unidentified native VLAN tagged.
Also, if I'm not wrong, on the SAA you must set the security level of the port to 100.
-Tom
Please evaluate the useful messages
Maybe you are looking for
-
The accident of the L50 - A satellite BIOS update
I have a portable Satellite L50-A-10W with win7 64-bit.A few days ago the Tempro software began to show the message, a new BIOS update is available, that I downloaded. After clicking on the file .exe, Setup window popped up. All right, the computer r
-
Satellite U300-15 q - cannot read some CD.
I recently had some problems with the CD / DVD drive. DVD playback with Windows player without any problem. Some CD cannot be read by the reader, it just don't see them, others he will play with windows media player, the CD are original bought in a l
-
Help! The ap store totally disappear from my phone. When I say Siri to open the ap store, it says unable to do.
-
You can run a program entirely in virtual memory?
Can I run a program entirely in virtual memory?
-
XPS 8700 (non-SE) is provided with a Bay 2.5 "for ssd?
Spec says there are 4 bays for hard drives with 3 Bay 3.5 ", but it does not specify the 4th Bay. Not sure if it's a 2.5 ". THX.