I'm thinking about getting a Dell PowerConnect 5324 switch.
I have a question that I'm a little unclear about (I'm new to VLANS):
If I plug a bunch of servers and workstations into the switch and create 3 VLAN's (DEV, MANAGEMENT, SERVERS), will the unit automatically do the routing between the VLAN's? Or, do I have to have an external router that will use up 1 port for each vlan in order to do the routing between the vlans? (this seems like a waste).
I'm just not sure if its implicit that the switch will do the inter-vlan routing??
If it doesnt automatically do this, would I then have to get something like a PowerConnect 6024 that has L3 routing in addition to L2 switching?
The 5324 is a layer 2 switch which means it does not do VLAN routing. At layer 2 the switch will NEVER forward a packet from one VLAN to another. You will need a router to do cross VLAN routing. However you don't need three ports for each VLAN. You can trunk all the VLANs to the same port (or use a LAG to improve bandwidth) to the 6024 then use VLAN routing to route between these VLANs. This concept is called a "one-arm router" (google this term for more explanation).
So yes you would need a layer 3 switch to do routing, and if you don't have one already then the 6024 will serve your purpose.
Note that if you are trunking the VLANs to one port or LAG (a link aggregation group or a collection of ports) then be aware that you may be oversubscribing the trunk. Meaning that if you have 11 100Mbps ports carrying traffic for these VLANs and you trunk them to the router using a Gigabit port then you could be oversubscribing the gigabit port but if you have 10 100Mbps ports trunked to the Gig port then you would be OK. Note that you could trunk these ports to a pair of Gig ports configured in a LAG to improve BW and reduce the chance for oversubscribing (note that the way LAG works you may not get 100% utilization so be aware - meaning that if you have 2 Gigabit ports in a LAG and you trunk 20 100Mbps ports to this LAG you would expect to not be oversubscribed but that may not be the case depending on a number of factors - if you need more detail on this please see this paper - http://www.dell.com/downloads/global/power/ps2q05-20040286-Holmes-OE.pdf).
1) If I go with the L2 swtich I will need an external router. If I trunk the VLANS to one port and connect the router to this port, does the router have to be VLAN aware? Is it possible at all to use a router that is not VLAN aware? I'm thinking maybe I could assign multiple IP addresses to the network card on the router that is connected to the vlan trunk switch port. Each IP address would be on one of the respective VLAN's. (this would be a temporary solution until we purchase an actual router that supports VLAN's). I'm just not sure if there is anything special about the packets that would confuse the router which is not vlan aware?
[Cuong] That won't work. You will need a VLAN aware router. When you trunk the traffic from all these VLANs to the same port the traffic will be sent to the router with VLAN tags (the Ethernet packet header will be expanded to include VLAN information). If the other router is not VLAN aware it will likely drop the packets. Also VLAN routing requires that a router actually changes the VLAN tag when it route a packet from one VLAN to another otherwise the receiving L2 switch will not properly forward the packet. Anyway, you need a VLAN aware router to do cross-VLAN routing.
2) You mentioned oversubscribing. If I do end up oversubscribing what is the worst that would happen? Would the bandwidth get evendly distributed across all users or would connections start to drop?
[Cuong] Actually even if you do oversubscribe, probably nothing bad will really happen. You would have to have every users on every port actually pushing full bandwidth continuously before you will see a problem. Even if you do end up exceeding the BW on the uplink (trunk) port, what will happen is that the excessive BW will be dropped, and the end stations will have to resend their packets. So you may notice performance degradation if every port somehow start sending continuous stream up the the maximum BW of the port and all these traffic somehow must be trunked through the same uplink. Not likely to happen unless you were doing continuous multicast video stream or something like that. Just think about the kind of traffic pattern that may be on your network and you can judge for yourself if you think you might have to be too concern about an oversubscription problem.
3) If I were to instead purchase an L3 switch, where exactly does the default gateway get configured for each vlan? Since there are 3 subents (1 for each vlan) I would have to have 3 DG's configured. But if all the physical ports on the switch are used up then were exactly is the IP of the DG located? Would it be some sort of an internal interface that gets configured on the switch for each vlan that is created?
[Cuong] You don't really need a default gateway for each VLAN. You probably need to read a bit first on VLAN routing to understand how it works (see this discussion thread: http://forums.us.dell.com/supportforums/board/message?board.id=pc_managed&message.id=6193). In this case the router would see these subnet as "direct connected" subnets and will properly route between those subnets.
4) Do clients on the network have to be speifically vlan aware (ie do I have to get new software/network cards for the existing servers/workstations?). What happens if I plug a dumb switch into one of the ports on the switch that is configured for a specific vlan. Is that OK? Does that switch have to be vlan aware too?
[Cuong] When you send traffic from a VLAN aware device to a VLAN unaware device you need to configure the VLAN aware switch to "untag" the traffic it sends out. You can do this when you know that all the traffic sent on the same port is from only one VLAN or if you don't think the remote side need to know that the traffic comes from different VLANs. If the remote side needs to distinguish between traffics from different VLAN then you cannot strip the VLAN information before you send it. Typically access ports (ports connecting a switch to a workstation or client system) is configured to send traffic without VLAN tags and to accept traffic without VLAN tags. The access port is configured to accept untag traffic and automatically assign these packets to a "default" VLAN (aka PVID = permanent VLAN ID). The access port is also configured to strip VLAN tags before the packet is sent out to the connected system. So you may have VLAN unaware systems and devices connected to a VLAN aware switch. Mostly this is fine for hosts but for switches you have to be careful. If you have a VLAN unaware switch in the network that switch must be servicing packets ONLY on one VLAN because it will receive packets without VLAN info so it cannot properly isolate the VLAN. So you can have edge switches that service a single VLAN connected to a switch which services multiple VLANs.
5) When thinking of VLAN's, is it the same to think of having a physical switch for each vlan? Is that all thats really going on? As per question 1), I know that if I instead had a physical switch for each VLAN, and I uplinked them all to another aggregation switch into which I plugged a router with more than 1IP address (1 for each subnet/vlan) then everything would work fine. Is this a valid way of thinking of vlans or does the vlan tagging, etc interefere with this?
[Cuong] Not exactly. Please read answer to question 1. You cannot emulate VLAN routing using this method when you are using a one-arm router method - in that case all the VLANs come through the uplink port and so you need a way to distinguish between the different traffic streams. I guess if you were to use a different port for each VLAN then you can use the port to distinguish between multiple VLANs then perhaps you can do what you suggest above but that would be a waste of resources. A 6024 router is really not that expensive :-) and will save you alot of time and setup.
Sorry for all the questions. Just trying to get everything straight before making the purchase.
1) If I go with the L2 swtich I will need an external router. If I trunk the VLANS to one port and connect the router to this port, does the router have to be VLAN aware? Is it possible at all to use a router that is not VLAN aware? I'm thinking maybe I could assign multiple IP addresses to the network card on the router that is connected to the vlan trunk switch port. Each IP address would be on one of the respective VLAN's. (this would be a temporary solution until we purchase an actual router that supports VLAN's). I'm just not sure if there is anything special about the packets that would confuse the router which is not vlan aware?
2) You mentioned oversubscribing. If I do end up oversubscribing what is the worst that would happen? Would the bandwidth get evendly distributed across all users or would connections start to drop?
3) If I were to instead purchase an L3 switch, where exactly does the default gateway get configured for each vlan? Since there are 3 subents (1 for each vlan) I would have to have 3 DG's configured. But if all the physical ports on the switch are used up then were exactly is the IP of the DG located? Would it be some sort of an internal interface that gets configured on the switch for each vlan that is created?
4) Do clients on the network have to be speifically vlan aware (ie do I have to get new software/network cards for the existing servers/workstations?). What happens if I plug a dumb switch into one of the ports on the switch that is configured for a specific vlan. Is that OK? Does that switch have to be vlan aware too?
5) When thinking of VLAN's, is it the same to think of having a physical switch for each vlan? Is that all thats really going on? As per question 1), I know that if I instead had a physical switch for each VLAN, and I uplinked them all to another aggregation switch into which I plugged a router with more than 1IP address (1 for each subnet/vlan) then everything would work fine. Is this a valid way of thinking of vlans or does the vlan tagging, etc interefere with this?
Sorry for all the questions. Just trying to get everything straight before making the purchase.
Thanks again for your excellent repsonse. Please see my answers interleaved below:
soniic wrote:
1) If I go with the L2 swtich I will need an external router. If I trunk the VLANS to one port and connect the router to this port, does the router have to be VLAN aware? Is it possible at all to use a router that is not VLAN aware? I'm thinking maybe I could assign multiple IP addresses to the network card on the router that is connected to the vlan trunk switch port. Each IP address would be on one of the respective VLAN's. (this would be a temporary solution until we purchase an actual router that supports VLAN's). I'm just not sure if there is anything special about the packets that would confuse the router which is not vlan aware?
[Cuong] That won't work. You will need a VLAN aware router. When you trunk the traffic from all these VLANs to the same port the traffic will be sent to the router with VLAN tags (the Ethernet packet header will be expanded to include VLAN information). If the other router is not VLAN aware it will likely drop the packets. Also VLAN routing requires that a router actually changes the VLAN tag when it route a packet from one VLAN to another otherwise the receiving L2 switch will not properly forward the packet. Anyway, you need a VLAN aware router to do cross-VLAN routing.
[Soniic] Makes sense, thank you. However, consider the same scenario if I now instead was running everything on the 6024 L3 switch. The L3 switch would do all the inter vlan routing, etc so I would have nothing to worry about. Now consider how the users would get internet access. Lets say I have a simple DSL router that is NOT vlan aware. Is there any way to get it to provide internet access to all the VLANS? From my reading and understanding so far, I believe this is how it would work: Create a new "dmz vlan"; assign it to a port on the 6024 and connect the DSL router to it; set the PVID on the port to that of the "dmz vlan"; set the port to untag outbound traffic so there will be no vlan tag on outbound traffic; set the routing table on the l3 swtich to send all unknown traffic to the IP of the DSL router on the "dmz vlan"; set the routing table on the DSL router to send vlan subnets to the IP address of the L3 switch on the "dmz vlan". Does this make sense for a dsl router that does not support vlan's?
2) You mentioned oversubscribing. If I do end up oversubscribing what is the worst that would happen? Would the bandwidth get evendly distributed across all users or would connections start to drop?
[Cuong] Actually even if you do oversubscribe, probably nothing bad will really happen. You would have to have every users on every port actually pushing full bandwidth continuously before you will see a problem. Even if you do end up exceeding the BW on the uplink (trunk) port, what will happen is that the excessive BW will be dropped, and the end stations will have to resend their packets. So you may notice performance degradation if every port somehow start sending continuous stream up the the maximum BW of the port and all these traffic somehow must be trunked through the same uplink. Not likely to happen unless you were doing continuous multicast video stream or something like that. Just think about the kind of traffic pattern that may be on your network and you can judge for yourself if you think you might have to be too concern about an oversubscription problem.
[Soniic] Understood,thanks!
3) If I were to instead purchase an L3 switch, where exactly does the default gateway get configured for each vlan? Since there are 3 subents (1 for each vlan) I would have to have 3 DG's configured. But if all the physical ports on the switch are used up then were exactly is the IP of the DG located? Would it be some sort of an internal interface that gets configured on the switch for each vlan that is created?
[Cuong] You don't really need a default gateway for each VLAN. You probably need to read a bit first on VLAN routing to understand how it works (see this discussion thread: http://forums.us.dell.com/supportforums/board/message?board.id=pc_managed&message.id=6193). In this case the router would see these subnet as "direct connected" subnets and will properly route between those subnets.
[Soniic] Sorry I dont think I was clear with my question. I was actually referring to the clients on the vlan subnets rather than the actual L3 switch itself. For example, a client computer on any vlan subnet would have to have a DG configured in order for it to communicate with computers outside of its subnet/vlan. This DG would have to be an IP address on its own subnet. My question was: What/where exactly is the interface for this DG that the clients are pointing to? I'm assuming it would be some sort of internal/dynamic interface created on the L3 switch each time a vlan is created? What happens in trunked situations when a vlan spans multiple physical switches? Where is the actual IP address of the DG for the clients on the vlan?
5) When thinking of VLAN's, is it the same to think of having a physical switch for each vlan? Is that all thats really going on? As per question 1), I know that if I instead had a physical switch for each VLAN, and I uplinked them all to another aggregation switch into which I plugged a router with more than 1IP address (1 for each subnet/vlan) then everything would work fine. Is this a valid way of thinking of vlans or does the vlan tagging, etc interefere with this?
[Cuong] Not exactly. Please read answer to question 1. You cannot emulate VLAN routing using this method when you are using a one-arm router method - in that case all the VLANs come through the uplink port and so you need a way to distinguish between the different traffic streams. I guess if you were to use a different port for each VLAN then you can use the port to distinguish between multiple VLANs then perhaps you can do what you suggest above but that would be a waste of resources. A 6024 router is really not that expensive :-) and will save you alot of time and setup.
[Soniic] Wouldnt I be able to distinguish betwen the different traffic streams based on the IP addresses? If one port on the L2 switch is configured as a member of all the vlans, and its outbound data is set to be untagged, then wouldnt the router thats connected to that port see all the traffic as packets from 3 different subnets over 1 physical cable? If the the routers interface to that port was then configured with 3 different IP addresses (1 for each of the subnets that the vlans are on) wouldnt things work? (at this point I would think that its no different than assigning more than 1 IP address to a NIC in windows and communicating on multiple different subnets on the same physical NIC/cable). I'm just not sure what I'm missing here?
1) If I go with the L2 swtich I will need an external router. If I trunk the VLANS to one port and connect the router to this port, does the router have to be VLAN aware? Is it possible at all to use a router that is not VLAN aware? I'm thinking maybe I could assign multiple IP addresses to the network card on the router that is connected to the vlan trunk switch port. Each IP address would be on one of the respective VLAN's. (this would be a temporary solution until we purchase an actual router that supports VLAN's). I'm just not sure if there is anything special about the packets that would confuse the router which is not vlan aware?
[Cuong] That won't work. You will need a VLAN aware router. When you trunk the traffic from all these VLANs to the same port the traffic will be sent to the router with VLAN tags (the Ethernet packet header will be expanded to include VLAN information). If the other router is not VLAN aware it will likely drop the packets. Also VLAN routing requires that a router actually changes the VLAN tag when it route a packet from one VLAN to another otherwise the receiving L2 switch will not properly forward the packet. Anyway, you need a VLAN aware router to do cross-VLAN routing.
[Soniic] Makes sense, thank you. However, consider the same scenario if I now instead was running everything on the 6024 L3 switch. The L3 switch would do all the inter vlan routing, etc so I would have nothing to worry about. Now consider how the users would get internet access. Lets say I have a simple DSL router that is NOT vlan aware. Is there any way to get it to provide internet access to all the VLANS? From my reading and understanding so far, I believe this is how it would work: Create a new "dmz vlan"; assign it to a port on the 6024 and connect the DSL router to it; set the PVID on the port to that of the "dmz vlan"; set the port to untag outbound traffic so there will be no vlan tag on outbound traffic; set the routing table on the l3 swtich to send all unknown traffic to the IP of the DSL router on the "dmz vlan"; set the routing table on the DSL router to send vlan subnets to the IP address of the L3 switch on the "dmz vlan". Does this make sense for a dsl router that does not support vlan's?
[Cuong2] Yes I think that would probably work. If you use the L3 switch for everything and do not intend to forward packets back into an L2 switch that service more then one VLANs then what you describe above will probably work (see more discussion on last question below).
3) If I were to instead purchase an L3 switch, where exactly does the default gateway get configured for each vlan? Since there are 3 subents (1 for each vlan) I would have to have 3 DG's configured. But if all the physical ports on the switch are used up then were exactly is the IP of the DG located? Would it be some sort of an internal interface that gets configured on the switch for each vlan that is created?
[Cuong] You don't really need a default gateway for each VLAN. You probably need to read a bit first on VLAN routing to understand how it works (see this discussion thread: http://forums.us.dell.com/supportforums/board/message?board.id=pc_managed&message.id=6193). In this case the router would see these subnet as "direct connected" subnets and will properly route between those subnets.
[Soniic] Sorry I dont think I was clear with my question. I was actually referring to the clients on the vlan subnets rather than the actual L3 switch itself. For example, a client computer on any vlan subnet would have to have a DG configured in order for it to communicate with computers outside of its subnet/vlan. This DG would have to be an IP address on its own subnet. My question was: What/where exactly is the interface for this DG that the clients are pointing to? I'm assuming it would be some sort of internal/dynamic interface created on the L3 switch each time a vlan is created? What happens in trunked situations when a vlan spans multiple physical switches? Where is the actual IP address of the DG for the clients on the vlan?
[Cuong2] Ah...I see. If you read the thread on VLAN routing you see that you have to define an IP address on the 6024 for each VLAN which defines the "network" on that VLAN. All these VLANs on the 6024 happens to be trunked through the same physical port but they are independent VLANs. So for each workstation you need to correctly specify one of those IP address on the 6024 on the same network to which the host belongs as the default gateway for that host.
5) When thinking of VLAN's, is it the same to think of having a physical switch for each vlan? Is that all thats really going on? As per question 1), I know that if I instead had a physical switch for each VLAN, and I uplinked them all to another aggregation switch into which I plugged a router with more than 1IP address (1 for each subnet/vlan) then everything would work fine. Is this a valid way of thinking of vlans or does the vlan tagging, etc interefere with this?
[Cuong] Not exactly. Please read answer to question 1. You cannot emulate VLAN routing using this method when you are using a one-arm router method - in that case all the VLANs come through the uplink port and so you need a way to distinguish between the different traffic streams. I guess if you were to use a different port for each VLAN then you can use the port to distinguish between multiple VLANs then perhaps you can do what you suggest above but that would be a waste of resources. A 6024 router is really not that expensive :-) and will save you alot of time and setup.
[Soniic] Wouldnt I be able to distinguish betwen the different traffic streams based on the IP addresses? If one port on the L2 switch is configured as a member of all the vlans, and its outbound data is set to be untagged, then wouldnt the router thats connected to that port see all the traffic as packets from 3 different subnets over 1 physical cable? If the the routers interface to that port was then configured with 3 different IP addresses (1 for each of the subnets that the vlans are on) wouldnt things work? (at this point I would think that its no different than assigning more than 1 IP address to a NIC in windows and communicating on multiple different subnets on the same physical NIC/cable). I'm just not sure what I'm missing here?
[Cuong2] Ok let's define the network setup first because it's not clear until we are both looking at the same picture. Your original questions refer to having a 5324 L2 switch which trunk different VLANs to an L3 switch which is used to route between those VLANs. If that's the scenario and you were using the L3 as a one-arm router then consider what would be happening. First on the 5324 switch you have packets on different VLANs all of them are sent to the L3 switch on the same physical interface. The L3 switch responsibility is to route between those VLANs. To do that the L3 switch is actually taking a packet on VLAN 10 (for example) and forwarding it to VLAN 20 (for example) and then returning that packet to the 5324 which must service both VLAN 10 and 20. So how does the L3 switch do that? It does it by modifying the VLAN tag on the packet from 10 to 20 when it forward the packet to VLAN 20. It MUST do this because if it doesn't and the packet is returned to the 5324, the 5324 switch would not know what to do with the packet (remember the packets for all the VLANs come through the same physical port). A layer 2 switch does not typically understand IP addresses. A layer 2 switch forward packets based on MAC and VLAN only. The 5324 does not support IP subnet based VLAN (see discussion below).
There are however some advance L2 features (usually you have to pay a premium for the advance features though :-)) which support the concept of IP subnet based VLAN where the switch can be configured to examine each incoming packet and filter on source/destination IP and protocol (UDP/TCP and even ports) to determine which VLAN the packet stream belong to. Using this L2 feature, perhaps you can forward all the traffic to the L3 for routing then filter out the returning traffic based on the IP (L3 & L4 information) to reconstruct the VLAN tags. This is probably non-trivial and more work to maintain.
Another method which you hinted to earlier is to use different physical ports for each VLAN instead of a trunk port. An L2 switch (5324) may also automatically tag all traffic on a given port to a given VLAN so if you were to use a different port for each VLAN and forward all these ports to the L3 router untagged, then you can use the L3 routing feature to route between the ports and have the L2 switch retag (using PVID) the returning packets. This method as we discussed earlier would work if you have only non-VLAN aware routers although as we also mentioned, this will waste alot of resources.
I'm probably going into much more detail then really necessary but I didn't want to leave out an option or to mislead you through omission :-). There are always ways to setup what you need and since there are so many options I can get kind of verbose but I think the discussion would be more complete that way :-).
Thank you very much for your excellent answers, things are really starting to make sense. I have decided to purchase the 6024 L3 switch in addition to a 2724 L2 switch for additional ports.
I have two final questions for you (honest!). Considering that I purchase the above switches:
1) There is one scenario that I forgot to mention. I have a VPN server on my network (microsoft VPN server using PPTP). It is configured for normal vpn access (for remote users) and also as a site-to-site VPN router (to connect our corporate network to our offsite internet datacentre where we have servers colocated).
For all intents and purposes, this VPN server looks like a normal router that is NOT vlan aware. It routes between the corporate network, the datacentre network, and dialup VPN users. Note: The datacentre does NOT use vlans.
For clarity, here are the network subnets that I'm planning:
VLAN 10 (Internet DMZ - 192.168.1.X)
VLAN 20 (Servers - 10.1.20.X)
VLAN 30 (Management - 10.1.30.X)
VLAN 40 (Developers - 10.1.40.X)
Remote VPN users - NOT vlan aware - 10.1.250.X
Datacentre Network - NOT vlan aware - 10.2.X.X
The VPN server will exist on VLAN 20 (servers). The L3 switch will have static routes configured in it so that anybody trying to get to 10.1.250.X (remote vpn users) or 10.2.X.X (remote datacentre) will be sent to the VPN server sitting on vlan 20.
My question is: Will I be able to properly route from my network to the VPN users and remote datacentre? Since all the remote 'networks' connected to the VPN server are not vlan aware, everything should be ok, right? I would set the PVID on the 6024 for the VPN server port to vlan20; the outbound traffic would be untagged; and the routing tables on the L3 switch and the vpn server would be setup with the correct static routes.
My only concern is what happens when a vpn user (say, 10.1.250.7) tries to ping a computer on say the management network (10.1.30.99). It would arrive at the VPN server, the VPN server would forward it to the L3 swtich due to the static entry in the routing table. Now, when the L3 switch receives it, it will set the VLAN to 20 since the PVID on the vpn server port is for vlan20. This is the point where I get confused. Is the PVID being set for the remote IP address from the VPN user (10.1.250.7 -- which obiviously doesnt belong on the vlan 20); or is the PVID being set for the VPN router which is what forwarded the packet (which would be correct, because it is on VLAN 20). I'm just not sure if the PVID is for the original "source" IP address (remote VPN user) or the last hop router (the vpn server) that is forwarding the packet to the port. OR - do I just consider anything that's directly/indirectly connected to that port as part of vlan20 (so, the vpn users, remote datacentre, and servers are all 'part' of vlan 20)?
Anyways - I really hope this question makes sense. I know I can get very verbose! Will this situation work? (I just dont want to end up purchasing the 6024, set it up with VLANS, then realize things wont work properly).
2) Last question, this is a short one. I was looking at the online documentation for the 2724 and although it supports VLANS and LAG, I did not see where/how to setup trunking? My plan is to setup LAG over 2 gigabit links between the 6024 and the 2724. Users of different vlans will be spread out across both switches (due to their physical locations). How do I ensure that the propper vlan info is passed over the LAG between the two switches? Also: Is LAG considered to be a 'loop' in the network at wich poitn I would have to setup STP/RSTP? Or is it treated as 1 port so I wouldnt have to run STP/RSTP?
Thanks so much! I really appreciate all your knowledgeable input!
I wrote this really detail reply and then the stupid tool messed up and my reply was lost :-(. So sorry about this brief version.
On issue 1:
Assuming the VPN server is going to route between 10.1.250.x and the rest of your network such as 10.1.30.x through the 6024. So let's say the VPN server has an address 10.1.20.10 and is connected to port 3 on 6024. Then assume that the VPN server is the next hop router for the 10.1.250.x network. Then assume that 10.1.30.x subnet is serviced by the 2724 and is trunked to the 6024 on port 10.
You would setup port 3 as an access port (because VPN server is not VLAN aware) member of VLAN 20 (because you want servers to be VLAN 20). Then setup port 10 as a trunk port member of VLAN 30.
On the 6024 setup a static route for the 10.1.250.x so that the next hop router is set to 10.1.20.10 (the VPN server). On the VPN server remember to setup a static route for the return path to 10.1.30.x with the correct next hop router IP address of the 6024 on the subnet 10.1.20.x.
So if a ping comes from 10.1.250.x to 10.1.30.x it first gets to the VPN server, which route it to the 6024 based on its static route. The packet enters port 3 on the 6024 and since it is an access port it automatically tag as VLAN 20. The 6024 then look up its routing table for the destination address of the packet (10.1.30.x) and sees that it is a direct connected subnet on port 10. Since port 10 is a member of VLAN 30, the 6024 change the VLAN tag from 20 to 30 and forward to port 10. Since port 10 is a trunk port the packet is sent through port 10 tagged and is returned to the 2724. The 2724 forward the packet to the correct host (see previous discussion for the rest of this path).
Ping response comes back from 10.1.30.x to 10.1.250.x. Packet is trunk from 2724 back to port 10 on 6024 and is sent with correct VLAN tag of 30. The 6024 looks up 10.1.250.x in its routing table and sees a static route indicating that the packet should be routed to port 3. Since port 3 is a member of VLAN 20, the packet VLAN tag is changed to 20 and forwarded to port 3. Since port 3 is an access port the packet is stripped of the VLAN tag before it is sent to the VPN server. The VPN server route the packet to the remote system.
On issue 2:
See this link for 2724 documentation -
<ADMIN NOTE: Broken link has been removed from this post by Dell> (look for section on "Configuring LAG Membership".
When you LAG two ports it is considered to be a single interface so you can configure a LAG as you would a physical interface including configuration of VLAN membership. Whatever you can do on a port you can also do on a LAG. Since a LAG is considered a single interface if it is used to connect two switches it does not form a bridging loop (a LAG an a port or two LAGs would form a loop but not a single LAG between two switches).
DELL-Cuong N.
1017 Posts
472
0
Posted April 5th, 2006 15:00
The 5324 is a layer 2 switch which means it does not do VLAN routing. At layer 2 the switch will NEVER forward a packet from one VLAN to another. You will need a router to do cross VLAN routing. However you don't need three ports for each VLAN. You can trunk all the VLANs to the same port (or use a LAG to improve bandwidth) to the 6024 then use VLAN routing to route between these VLANs. This concept is called a "one-arm router" (google this term for more explanation).
So yes you would need a layer 3 switch to do routing, and if you don't have one already then the 6024 will serve your purpose.
Note that if you are trunking the VLANs to one port or LAG (a link aggregation group or a collection of ports) then be aware that you may be oversubscribing the trunk. Meaning that if you have 11 100Mbps ports carrying traffic for these VLANs and you trunk them to the router using a Gigabit port then you could be oversubscribing the gigabit port but if you have 10 100Mbps ports trunked to the Gig port then you would be OK. Note that you could trunk these ports to a pair of Gig ports configured in a LAG to improve BW and reduce the chance for oversubscribing (note that the way LAG works you may not get 100% utilization so be aware - meaning that if you have 2 Gigabit ports in a LAG and you trunk 20 100Mbps ports to this LAG you would expect to not be oversubscribed but that may not be the case depending on a number of factors - if you need more detail on this please see this paper - http://www.dell.com/downloads/global/power/ps2q05-20040286-Holmes-OE.pdf).
Cuong.