I have a Powerconnect 6224 & need some help with routing configuration.
Basically 1 port on the switch (port 17) comes from our Data Center provider that has say 15 public ip addresses.
What I need is for those ip addresses to be divided to 3 nics. In other words Port 18 needs to have 1-5 public ip addresses, port 19 needs to have 6-10 public ip addresses & port 20 needs to have 11-15 public ip addresses.
Obviously I would put those IP addresses on the relevant nics but need to sort out the routing inside the switch.
The data centre can only provide me with 1 link (port).
Is it possible to have 1 vlan then 3 other vlans inside the origonal vlan?
Does Windows Hyper V Virtual network vlans link to vlans on the switch so they operate on the 1 network?
Im new to layer 3 switches & would appreciate any assistane on setting this up.
to mask is a way of saying to AND the 2 numbers. Or in other words, the 1's in the mask tell you which bits to pay attention to and the 0's tell you which bits to ignore.
42h AND F0h = 40h = 64 decimal.
So, what you are seeing is correct. You need to use a mask of 255.255.255.255 to set a vlan association for a specific IP address.
For the 6224 config look at the config below. This assumes that the data center provider is sending you tagged traffic and that the servers are configured to accept tagged traffic. The 6224 is not routing in this config, it is just doing tagged switching.
I do not really understand the rest of your post, but if you need to to double tagged vlans, the switch is capable.
Post more information about your network if you have more questions.
In other words I have a VLAN that seperates the inbound public ip addresses from the rest of the switch. Then it seems I need to create a seperate VLAN for the outbound 3 ports then put the ip addresses on to the VLAN.
I still do not understand your question, but here is an example of Q-in-Q or double vlan tagging that you may be able to apply to your netowrk. In this example, tagged traffic ingressing the switch on port 1/g1 is switched as if it is in vlan 800. If this traffic egresses port 1/g24, it will be double tagged with vlan 800 in outer tag and the original vlans in the inner tags. The same description is true for port 1/g2 and vlan 900.
if this does not answer your question, then please provide an example of how traffic is ingressing your switch and what you would like to do with it. Be very explicit please.
configure vlan database vlan 800,900 exit stack member 1 2 exit ip address 192.168.2.1 255.255.255.0 no spanning-tree ! interface ethernet 1/g1 switchport mode general switchport general pvid 800 no switchport general acceptable-frame-type tagged-only switchport general allowed vlan add 800 exit !
interface ethernet 1/g2 switchport mode general switchport general pvid 900 no switchport general acceptable-frame-type tagged-only switchport general allowed vlan add 900 exit ! interface ethernet 1/g24 switchport mode general no switchport general acceptable-frame-type tagged-only switchport general allowed vlan add 800,900 tagged mode dvlan-tunnel exit exit
just to recap, 4 ports in a vlan, this needs to be seperate to other networks on the switch.
Port 17 comes from datacentre thats has 15 inbound public ip addresses.port 18 needs to have 5 of these ip's, port 19 needs to have next 5 & port to needs to have final 5.
All ips are on the same subnet.
I tried just putting the seperate ips in the nics that go to the three ports but that didnt work
The example below will take ingress traffic on port 1/g17 and classify it to a vlan according to its destination IP address. The first five IPs are associated to the vlan that port g18 is a member of, the second five are ossociated to the vlan that port g19 is a member of, etc.. Traffic egressing 1/g17 is untagged.
configure vlan database vlan 101-103 vlan association subnet 192.168.1.11 255.255.255.255 101 vlan association subnet 192.168.1.12 255.255.255.255 101 vlan association subnet 192.168.1.13 255.255.255.255 101 vlan association subnet 192.168.1.14 255.255.255.255 101 vlan association subnet 192.168.1.15 255.255.255.255 101 vlan association subnet 192.168.1.21 255.255.255.255 102 vlan association subnet 192.168.1.22 255.255.255.255 102 vlan association subnet 192.168.1.23 255.255.255.255 102 vlan association subnet 192.168.1.24 255.255.255.255 102 vlan association subnet 192.168.1.25 255.255.255.255 102 vlan association subnet 192.168.1.31 255.255.255.255 103 vlan association subnet 192.168.1.32 255.255.255.255 103 vlan association subnet 192.168.1.33 255.255.255.255 103
vlan association subnet 192.168.1.34 255.255.255.255 103 vlan association subnet 192.168.1.35 255.255.255.255 103 exit stack member 1 1 exit ip address 192.168.2.62 255.255.255.0 ! interface ethernet 1/g17 switchport mode general switchport general allowed vlan add 101-103 exit ! interface ethernet 1/g18 switchport access vlan 101 exit ! interface ethernet 1/g19 switchport access vlan 102 exit !
I am not sure what you are asking. However, this may answer the question. I was thinking about my suggestion and I neglected to account for ARP packets. So here is a new config that should work better.:
configure vlan database vlan 100-103 vlan association subnet 192.168.1.11 255.255.255.255 101 vlan association subnet 192.168.1.12 255.255.255.255 101 vlan association subnet 192.168.1.13 255.255.255.255 101 vlan association subnet 192.168.1.14 255.255.255.255 101 vlan association subnet 192.168.1.15 255.255.255.255 101 vlan association subnet 192.168.1.21 255.255.255.255 102 vlan association subnet 192.168.1.22 255.255.255.255 102 vlan association subnet 192.168.1.23 255.255.255.255 102 vlan association subnet 192.168.1.24 255.255.255.255 102 vlan association subnet 192.168.1.25 255.255.255.255 102 vlan association subnet 192.168.1.31 255.255.255.255 103 vlan association subnet 192.168.1.32 255.255.255.255 103 vlan association subnet 192.168.1.33 255.255.255.255 103 vlan association subnet 192.168.1.34 255.255.255.255 103 vlan association subnet 192.168.1.35 255.255.255.255 103 exit stack member 1 2 exit ip address 192.168.2.62 255.255.255.0 ! interface ethernet 1/g17 switchport mode general switchport general allowed vlan add 100-103 untagged switchport general pvid 100 exit ! interface ethernet 1/g18 switchport mode general switchport general allowed vlan add 100,101 untagged switchport general pvid 100 exit ! interface ethernet 1/g19 switchport mode general switchport general allowed vlan add 100,102 untagged switchport general pvid 100 exit ! interface ethernet 1/g20 switchport mode general switchport general allowed vlan add 100,103 untagged switchport general pvid 100 exit exit
The behaviour of this config is:
port g17: ingress broadcast/multicast/unknown unicast packets egress ports g18 AND g19 AND g20. ingress known unicast packets are associated with the listed vlan and egress port g18 OR g19 OR g20.
port g18: ingress broadcast/multicast/unknown unicast packets egress ports g17 AND g19 AND g20. ingress known unicast packets are switched in vlan 100 and can egress port g17 OR g19 OR g20.
bh1633
909 Posts
1982
1
Posted June 1st, 2010 08:00
66 in decimal = 42 in hexadecimal (42h)
240 in decimal = F0 in hexidecimal (F0h)
to mask is a way of saying to AND the 2 numbers. Or in other words, the 1's in the mask tell you which bits to pay attention to and the 0's tell you which bits to ignore.
42h AND F0h = 40h = 64 decimal.
So, what you are seeing is correct. You need to use a mask of 255.255.255.255 to set a vlan association for a specific IP address.