Connect to the serial port (9600 baud, 8 bit, no flow control, 1 stop bit) Then just copy/paste this group of CLI commands into the switch. This will give you the basic setup for a layer-2 switch.
============================== enable config flowcontrol y interface range ethernet 1/g1-1/g24 mtu 9216 spanning-tree portfast exit int ran eth 1/xg1-1/xg4 mtu 9216 exit exit copy r s y ============================ In the switch "Command Line Interface" or CLI, you must enable the privileged mode to do anything useful. Typing a ? will give you help anywhere, and also the tab and space bar will complete a command if you have typed enough characters for a unique command word.
Configuration commands that you type take effect immediately, they become part of the "running-config". If you want the commands to come back after a reload or power loss, you must copy the "running-config to the "startup-config".
You can use the top level commands "show run" or "show start" to view the contents of the running-config or the startup-config.
Connect to the serial port (9600 baud, 8 bit, no flow control, 1 stop bit) Then just copy/paste this group of CLI commands into the switch. This will give you the basic setup for a layer-2 switch.
============================== enable config flowcontrol (?) y interface range ethernet 1/g1-1/g24 mtu 9216 spanning-tree portfast exit int ran eth 1/xg1-1/xg4 (what is this doing?) mtu 9216 (?) exit exit copy r s y ============================ In the switch "Command Line Interface" or CLI, you must enable the privileged mode to do anything useful. Typing a ? will give you help anywhere, and also the tab and space bar will complete a command if you have typed enough characters for a unique command word.
Configuration commands that you type take effect immediately, they become part of the "running-config". If you want the commands to come back after a reload or power loss, you must copy the "running-config to the "startup-config".
You can use the top level commands "show run" or "show start" to view the contents of the running-config or the startup-config.
Hi Thomas,
Thank you very much for your reply, at least i can save configurations now!
What exactly did the above commands do?
I will get cracking on trying to get vlans sorted now...
After adding you starter configuration i found a similar one to what i was looking for and added this:
Normal 0 false false false EN-IE X-NONE X-NONE MicrosoftInternetExplorer4 configure vlan database vlan 10,20 vlan association subnet 192.168.0.0 255.255.255.0 1 vlan association subnet 10.10.11.0 255.255.255.0 10 vlan association subnet 10.10.12.0 255.255.255.0 20
exit
switch 1 priority 1
interface vlan 10 routing ip address 10.10.11.1 255.255.255.0 ip rip send version rip1 ip irdp exit interface vlan 20 routing ip address 10.10.12.1 255.255.255.0 ip rip send version rip1 ip irdp
exit
interface ethernet 1/g23 switchport mode general switchport general pvid 10 no switchport general acceptable-frame-type tagged-only switchport general allowed vlan add 10,20 exit ! interface ethernet 1/g24 switchport mode general switchport general pvid 10 no switchport general acceptable-frame-type tagged-only switchport general allowed vlan add 10,20 exit
Just not sure how to route between the two subnets and to the gateway?
You are going in the right direction. Something that I failed to mention in the first post, you can completely wipe the configuration and go back to the factory defaults anytime by using the global command "clear config".
I have never seen the config command "vlan association" used and I'm not sure what it does. Also I strongly recomend not using RIP as a dynamic routing protocol, and especially not RIP version 1.
On the ports, "switchport mode access" is usually the best choice, then "switchport access vlan 10" to assign a port to a local vlan. "General" mode allows much more flexiblity, but is much easier to get yourself into trouble. If you are interconnecting two switches, and want to interconnect the vlans as well, use "switchport mode trunk". In trunk mode, the ethernet frames are "vlan tagged", so both ends of the connection must be configured the same (same mode mode, same vlans allowed, and same PVID).
I will give you more detailed instructions just as soon as I get the time.
So machine on each vlan can talk to each other and route out to the internet. I am guessing these changes are made under Routing > Router > Configured Routes
I’m just not sure in what format I need to add the routes…
Vlan 10: 10.10.11.0
Vlan 20: 10.10.12.0
Firewall 10.10.10.254 (route to internet)
Subnets for all 255.255.255.0
Do I need to assign an ip (gateway address) for each vlan / port? I was thinking do I assign vlan 10 a gateway address of 10.10.11.1 had apply that to a port?
Thanks for your help Thomas I feel like I am finally getting somewhere.
I’ve managed to work out why only one subnet can talk to the firewall.
The firewall has no default gateway on the internal NIC because you can only have one default gateway on a server and that’s on the external NIC with the public IP address on it. (ISA 2004)
So how can I get the clients on each subnet to talk to the firewall?
I tried to structure this reply as a general tutorial on how to setup one of these switches, so this builds on the first post that I made on a basic Layer-2 config. Your config has a few things that might be a problem - I would suggest just clearing the config and starting over.
Now that you have a basic Layer-2 config, let's add a couple Vlans...
============================
enable config vlan data vlan 10 vlan 20 exit
============================
For this example, we will leave ports 1 and 2 in the default Vlan 1. We will add ports 3 through 12 to Vlan 10 and ports 13 through 24 to Vlan 20.
============================
enable config int ran eth 1/g3-1/g12 switchport mode access switchport access vlan 10 exit interface range ethernet 1/g13-1/g24 switchport mode access switchport access vlan 20 exit exit copy r s
=============================
So now we have divided a 24 port switch into three virtual switches. Devices in each Vlan are completely isolated from any devices in the other Vlans. Nothing crosses over - no broadcasts, no pings, - nothing. In some cases this is a good thing.
If you really would like devices in one vlan to communicate with devices in other vlans, you need to enable IP (Layer-3) routing in the switch. The Layer-3 refers to the ISO 7-Layer network model.
First, we enable Layer-3 routing, then we need to configure routing interfaces in each of the Vlans. BTW - Vlan 1 does not allow routing on this switch. It typically used an a local "Management" Vlan. Here is a configuration example:
==============================
enable config ip routing interface vlan 10 ip address 192.168.10.254 255.255.255.0 exit interface vlan 20 ip address 192.168.20.254 255.255.255.0 exit exit copy r s
===============================
Any devices in Vlan 10 (ports 3-12) need to have an IP address of 192.168.10.xxx with a mask of 255.255.255.0, and a default gateway of 192.168.10.254.
And, any devices in Vlan 20 (ports 13-24) need to have an IP address of 192.168.20.xxx with a mask of 255.255.255.0, and a default gateway of 192.168.20.254.
"xxx" is some number between 1 and 253 (the switch has 254, 0 is the net address, 255 is the broadcast address). The "default gateway" is just the IP address of the router in your local IP subnet. At this point, anything in Vlan 10 should be able to "ping" anything in Vlan 20, and vise versa.
Suppose you want to connect to the Internet with a cable modem, router or whatever. You could give the cable modem an address of 192.168.10.1, mask 255.255.255.0 and plug him into one of the Vlan 10 ports. Then you neet to make these configuration changes to your PowerConnect switch:
===============================
enable config ip route 0.0.0.0 0.0.0.0 192.168.10.1 exit copy r s
===============================
This command creates a "default route" that points back to the cable modem. Configuring the cable modem is beyond the scope of this document, but you will need to add a route to the cable modem for each subnet that is not directly connected.
In this example, subnet 192.168.10.0 is directly connected. An additional static route will be needed for 192.168.20.0 (Vlan 20). In the cable modem that might look like this:
ip route 192.168.20.0 mask 255.255.255.0 gw 192.168.10.254
No garentees on that, you better look it up in the manual.
thomas_williams
5 Posts
1582
0
Posted November 12th, 2009 15:00
Connect to the serial port (9600 baud, 8 bit, no flow control, 1 stop bit)
Then just copy/paste this group of CLI commands into the switch. This will give you the basic setup for a layer-2 switch.
==============================
enable
config
flowcontrol
y
interface range ethernet 1/g1-1/g24
mtu 9216
spanning-tree portfast
exit
int ran eth 1/xg1-1/xg4
mtu 9216
exit
exit
copy r s
y
============================
In the switch "Command Line Interface" or CLI, you must enable the privileged mode to do anything useful. Typing a ? will give you help anywhere, and also the tab and space bar will complete a command if you have typed enough characters for a unique command word.
Configuration commands that you type take effect immediately, they become part of the "running-config". If you want the commands to come back after a reload or power loss, you must copy the "running-config to the "startup-config".
You can use the top level commands "show run" or "show start" to view the contents of the running-config or the startup-config.