<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0"
 xmlns:blogChannel="http://backend.userland.com/blogChannelModule"
>

<channel>
<title>Topic &#x27;[HELP] Using VLANS on a 2900 Series switch.&#x27; in forum &#x27;Cisco&#x27; - dslreports.com</title>
<link>http://www.dslreports.com/forum/HELP-Using-VLANS-on-a-2900-Series-switch-10256435</link>
<description></description>
<language>en</language>
<pubDate>Fri, 25 Mar 2022 10:44:02 EDT</pubDate>
<lastBuildDate>Fri, 25 Mar 2022 10:44:02 EDT</lastBuildDate>

<item>
<title>Re: [HELP] Using VLANS on a 2900 Series switch.</title>
<link>http://www.dslreports.com/forum/Re-HELP-Using-VLANS-on-a-2900-Series-switch-10285211</link>
<description><![CDATA[astamand posted : [QUOTE=dpocoroba <A HREF="/useremail/u/241337"><i class='fa fa-user'></i></A>]Glad to see you got it working. AS for the AP and assigning static vlans. Im honestly not sure on a AP. I know my switches here can most certainly assign a mac addy to a vlan using a static entry. :)<br><br>Basically its straight forward<br><div class="code"><PRE><span class="codetext">sw1(config)#mac address-table static 1111.2222.3333 vlan 51<br></SPAN></PRE></DIV><br>Yeah that looks right.  I printed out several chapters on the VLAN config for the AP350.  I'm going to start tonight. I'll let you know how it goes.<br><br>Thanks again,<br><br>-=Alex<br>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-HELP-Using-VLANS-on-a-2900-Series-switch-10285211</guid>
<pubDate>Wed, 19 May 2004 21:09:58 EDT</pubDate>
</item>
<item>
<title>Re: [HELP] Using VLANS on a 2900 Series switch.</title>
<link>http://www.dslreports.com/forum/Re-HELP-Using-VLANS-on-a-2900-Series-switch-10285200</link>
<description><![CDATA[astamand posted :  <BLOCKQUOTE><SMALL>said by <a href="/profile/723611" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=723611');">Dan_D</a>:</SMALL><HR>The only other thing we did not discuss was the access-lists. Make sure if you have an access-list on the sub-interfaces inbound the first line permits hosts with an address of 0.0.0.0(access-list 1xx permit ip host 0.0.0.0 any). This will allow dhcp requests from clients.<HR></BLOCKQUOTE><br><br>OK, now that I'm paying more attention, I realized you said &#147;IF&#148; I have an ACL.  I don't.<br><br>Maybe you had a different mask on your nets that allowed you to get through to the DHCP server?  We had to use the helper IP on our layer three switches as well.  I'm going to do more research on it.<br><br>At least it's working.  Thanks!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-HELP-Using-VLANS-on-a-2900-Series-switch-10285200</guid>
<pubDate>Wed, 19 May 2004 21:08:42 EDT</pubDate>
</item>
<item>
<title>Re: [HELP] Using VLANS on a 2900 Series switch.</title>
<link>http://www.dslreports.com/forum/Re-HELP-Using-VLANS-on-a-2900-Series-switch-10284711</link>
<description><![CDATA[dpocoroba posted : Glad to see you got it working. AS for the AP and assigning static vlans. Im honestly not sure on a AP. I know my switches here can most certainly assign a mac addy to a vlan using a static entry. :)<br><br>Basically its straight forward<br><div class="code"><PRE><span class="codetext">sw1(config)#mac address-table static 1111.2222.3333 vlan 51<br> <br></SPAN></PRE></DIV><br>DP<br><br><SMALL>--<br>"Knowledge is contagious, infect"</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-HELP-Using-VLANS-on-a-2900-Series-switch-10284711</guid>
<pubDate>Wed, 19 May 2004 20:14:56 EDT</pubDate>
</item>
<item>
<title>Re: [HELP] Using VLANS on a 2900 Series switch.</title>
<link>http://www.dslreports.com/forum/Re-HELP-Using-VLANS-on-a-2900-Series-switch-10280828</link>
<description><![CDATA[astamand posted :  <BLOCKQUOTE><SMALL>said by <a href="/profile/723611" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=723611');">Dan_D</a>:</SMALL><HR>I am glad all is working.......I am however surprised that the IP helper had to be added to make it function. Like i stated earlier i have a similar setup at about 700 sites with no issues. The only other thing we did not discuss was the access-lists. Make sure if you have an access-list on the sub-interfaces inbound the first line permits hosts with an address of 0.0.0.0(access-list 1xx permit ip host 0.0.0.0 any). This will allow dhcp requests from clients.<HR></BLOCKQUOTE><br><br>It could possibly be the need for an ACL.  Does that mean Cisco is blocking that by default?  I would imagine it would be wide open since I have nothing specified between virtual interfaces.<br><br>I also noticed my VPN connection to work no longer works.  It appears I can not pick up an IP address there as well.  I was going to add a helper IP for the VPN switch and possible our internal DHCP server as well to work around it.<br><br>If I need to add an ACL inbound to the virtual interfaces, then I assume I need to add it inbound to all of them, correct?  Can I just add it inbound to the parent interface (FE0/0)?  <br><br>It's not a problem because half of the reason for having the Vlans was to be able to isolate traffic; the other half was purely educational.<br><br> <BLOCKQUOTE><SMALL>said by <a href="/profile/723611" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=723611');">Dan_D</a>:</SMALL><HR>As far as the Aironet 350, I am not sure if you can assign clients based on the mac, without additional hardware, software, etc. Maybe peaches or rizacerx can shed some light on the topic.<HR></BLOCKQUOTE><br><br>Yeah your right, I was out of my mind when I was going over the wireless Vlans.  What I do plan on doing is configuring the Vlans on the access point just like the switch.  I'll continue the trunk up to the access point and have a separate SSID for each Vlan.  Then I can keep my work laptop and the wife&#146;s laptop on separate Vlans.<br><br>Doing this allows me to eliminate the Wireless Vlan from my original config!<br><br>Thanks again.<br><br>-=Alex]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-HELP-Using-VLANS-on-a-2900-Series-switch-10280828</guid>
<pubDate>Wed, 19 May 2004 12:48:29 EDT</pubDate>
</item>
<item>
<title>Re: [HELP] Using VLANS on a 2900 Series switch.</title>
<link>http://www.dslreports.com/forum/Re-HELP-Using-VLANS-on-a-2900-Series-switch-10280115</link>
<description><![CDATA[Dan_D posted :  <BLOCKQUOTE><SMALL>said by <a href="/profile/886132" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=886132');">astamand</a>:</SMALL><HR><BR><br><B>WOOOOOOOOOOOOO HOOOOOOOOOOOOO!!!!</B><br><br>Thanks guy's it works!!!<br><br>One interesting thing I should point out however is that I needed to put the ip helper-address back in order for DHCP to work.  It would work with a static address but could not find the DHCP server.  This is something I learned from our Layer III switch at work.<br><br>Now, I want to pass this trunk up to my ap350 running IOS and set it to assign clients to a particular VLAN based on their MAC address.  I've been told this is possible.<br><br>If I can accomplish that, I will remove the WIRELESS VLAN since I would now be able to keep home laptops and work laptops on their respective VLANS.  There will be no reason to have a third VLAN.<br><br>Any thoughts?  (I can post a new help wanted thread if necessary).<br><br>Thanks!!!<br> <HR></BLOCKQUOTE><br><br>I am glad all is working.......I am however surprised that the IP helper had to be added to make it function. Like i stated earlier i have a similar setup at about 700 sites with no issues. The only other thing we did not discuss was the access-lists. Make sure if you have an access-list on the sub-interfaces inbound the first line permits hosts with an address of 0.0.0.0(access-list 1xx permit ip host 0.0.0.0 any). This will allow dhcp requests from clients.<br><br>As far as the aironet 350, I am not sure if you can assign clients based on the mac, without additional hardware, software, etc. Maybe peaches or rizacerx can shed some light on the topic.<br><br>We keep all wireless clients segregated for security and manageability reasons. We allow essential services only from the WLAN such as http, pop, smtp, etc. We disallow all netbios, icmp, etc mostly as a result of lessons learned from virus' past. It ultimately gives us an on/off switch for all wireless to avoid or react to problems.<br><br>Food for thought!!<br><br>Dan<br><SMALL>--<br>^^There's no place like 127.0.0.1 ^^</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-HELP-Using-VLANS-on-a-2900-Series-switch-10280115</guid>
<pubDate>Wed, 19 May 2004 11:03:09 EDT</pubDate>
</item>
<item>
<title>Re: [HELP] Using VLANS on a 2900 Series switch.</title>
<link>http://www.dslreports.com/forum/Re-HELP-Using-VLANS-on-a-2900-Series-switch-10277281</link>
<description><![CDATA[astamand posted : <BR><br><B>WOOOOOOOOOOOOO HOOOOOOOOOOOOO!!!!</B><br><br>Thanks guy's it works!!!<br><br>One interesting thing I should point out however is that I needed to put the ip helper-address back in order for DHCP to work.  It would work with a static address but could not find the DHCP server.  This is something I learned from our Layer III switch at work.<br><br>Now, I want to pass this trunk up to my ap350 running IOS and set it to assign clients to a particular VLAN based on their MAC address.  I've been told this is possible.<br><br>If I can accomplish that, I will remove the WIRELESS VLAN since I would now be able to keep home laptops and work laptops on their respective VLANS.  There will be no reason to have a third VLAN.<br><br>Any thoughts?  (I can post a new help wanted thread if necessary).<br><br>Thanks!!!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-HELP-Using-VLANS-on-a-2900-Series-switch-10277281</guid>
<pubDate>Tue, 18 May 2004 23:24:58 EDT</pubDate>
</item>
<item>
<title>Re: [HELP] Using VLANS on a 2900 Series switch.</title>
<link>http://www.dslreports.com/forum/Re-HELP-Using-VLANS-on-a-2900-Series-switch-10273516</link>
<description><![CDATA[ChitownSVT5 posted : ^^^^ He's the man ;)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-HELP-Using-VLANS-on-a-2900-Series-switch-10273516</guid>
<pubDate>Tue, 18 May 2004 16:35:17 EDT</pubDate>
</item>
<item>
<title>Re: [HELP] Using VLANS on a 2900 Series switch.</title>
<link>http://www.dslreports.com/forum/Re-HELP-Using-VLANS-on-a-2900-Series-switch-10273034</link>
<description><![CDATA[Dan_D posted :  <BLOCKQUOTE><SMALL>said by <a href="/profile/886132" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=886132');">astamand</a>:</SMALL><HR> <br>Would it be safe to say that if I left them there I would then be able to manage the switch from a client attached to a port in any VLAN as long as it had an IP address on that VLANS network already?  Not that I can imagine a scenario that would warrant it...<br><br> <HR></BLOCKQUOTE><br><br>I believe peaches stated earlier that the SVI can only affix to one Vlan. That being said elimination of the additional addressing seems appropriate.<br><br>If you need to telnet to to the switch from a client on say Vlan 20 you can always telnet to the router's vlan 20 subinterface(192.168.20.1) and then telnet to the switch from there. <br><SMALL>--<br>^^There's no place like 127.0.0.1 ^^</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-HELP-Using-VLANS-on-a-2900-Series-switch-10273034</guid>
<pubDate>Tue, 18 May 2004 15:44:19 EDT</pubDate>
</item>
<item>
<title>Re: [HELP] Using VLANS on a 2900 Series switch.</title>
<link>http://www.dslreports.com/forum/Re-HELP-Using-VLANS-on-a-2900-Series-switch-10272617</link>
<description><![CDATA[astamand posted :  <BLOCKQUOTE><SMALL>said by <a href="/profile/723611" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=723611');">Dan_D</a>:</SMALL><HR>The 802.1Q standard allows for a single Vlan to be bridged and all others tagged. Cisco operates in this manner, and as such make sure you set a subinterface of 0/0.1(corresponds to Vlan 1) and that it is specified as the native(This insures if the trunk drops you will be able to access the IP for management purposes). The native vlan will be bridged and all others on the trunk will have tags added. <br><br>interface FastEthernet0/0.1<br>description FE interface for VLAN 1 (default)<br><B>encapsulation dot1Q 1 native</B><br>ip address 172.25.1.1 255.255.255.0<HR></BLOCKQUOTE><br><br>I'm with ya...<br><br> <BLOCKQUOTE><SMALL>said by <a href="/profile/723611" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=723611');">Dan_D</a>:</SMALL><HR>You can effectively eliminate the IP addresses on all Vlans in the switch config with the exception of Vlan1. The objective is to provide an ip address for management purposes.<HR></BLOCKQUOTE><br><br>Would it be safe to say that if I left them there I would then be able to manage the switch from a client attached to a port in any VLAN as long as it had an IP address on that VLANS network already?  Not that I can imagine a scenario that would warrant it...<br><br> <BLOCKQUOTE><SMALL>said by <a href="/profile/723611" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=723611');">Dan_D</a>:</SMALL><HR>:)!!!!!Getting Closer!!!!!:)<HR></BLOCKQUOTE><br><br>I can taste it!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-HELP-Using-VLANS-on-a-2900-Series-switch-10272617</guid>
<pubDate>Tue, 18 May 2004 14:55:01 EDT</pubDate>
</item>
<item>
<title>Re: [HELP] Using VLANS on a 2900 Series switch.</title>
<link>http://www.dslreports.com/forum/Re-HELP-Using-VLANS-on-a-2900-Series-switch-10272438</link>
<description><![CDATA[Dan_D posted : rizacerx stated:<br>"For the router interface, im not 100% sure but I would only worry about setting the speed and duplex on the main interface."<br><br>This is factual and sound advice:D<br><br>The 802.1Q standard allows for a single Vlan to be bridged and all others tagged. Cisco operates in this manner, and as such make sure you set a subinterface of 0/0.1(corresponds to Vlan 1) and that it is specified as the native(This insures if the trunk drops you will be able to access the IP for management purposes). The native vlan will be bridged and all others on the trunk will have tags added. <br><br>interface FastEthernet0/0.1<br>description FE interface for VLAN 1 (default)<br><B>encapsulation dot1Q 1 native</B><br>ip address 172.25.1.1 255.255.255.0<br><br>You can effectively eliminate the IP addresses on all Vlans in the switch config with the exception of Vlan1. The objective is to provide an ip address for management purposes.<br><br>:)!!!!!Getting Closer!!!!!:)<br><SMALL>--<br>^^There's no place like 127.0.0.1 ^^</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-HELP-Using-VLANS-on-a-2900-Series-switch-10272438</guid>
<pubDate>Tue, 18 May 2004 14:29:15 EDT</pubDate>
</item>
<item>
<title>Re: [HELP] Using VLANS on a 2900 Series switch.</title>
<link>http://www.dslreports.com/forum/Re-HELP-Using-VLANS-on-a-2900-Series-switch-10272105</link>
<description><![CDATA[astamand posted :  <BLOCKQUOTE><SMALL>said by <a href="/profile/241337" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=241337');">dpocoroba</a>:</SMALL><HR>Basicly the two commands you have in bold are defaults. As we pointed out before the native vlan is 1. As for the allowed vlan's, all vlans are allowed by default on a trunk port. The only commands you will need to form a trunk is to set the encapsulation then set it to trunk. <br><div class="code"><PRE><span class="codetext">switchport mode trunk<br>switchport trunk encapsulation dot1q<br></SPAN></PRE></DIV>Should be just fine<HR></BLOCKQUOTE><br><br>That makes sense.  Thanks for clarifying it.<br><br> <BLOCKQUOTE><SMALL>said by <a href="/profile/241337" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=241337');">dpocoroba</a>:</SMALL><HR>For the router interface, im not 100% sure but I would only worry about setting the speed and duplex on the main interface. However if your using nat you will need to use "ip nat inside" on the subinterface.HTH<HR></BLOCKQUOTE><br><br>Excellent, I will keep those other specific entries on the virtual interfaces.<br><br>Thanks, again.<br>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-HELP-Using-VLANS-on-a-2900-Series-switch-10272105</guid>
<pubDate>Tue, 18 May 2004 13:44:13 EDT</pubDate>
</item>
<item>
<title>Re: [HELP] Using VLANS on a 2900 Series switch.</title>
<link>http://www.dslreports.com/forum/Re-HELP-Using-VLANS-on-a-2900-Series-switch-10271998</link>
<description><![CDATA[dpocoroba posted : Basicly the two commands you have in bold are defaults. As we pointed out before the native vlan is 1. As for the allowed vlan's, all vlans are allowed by default on a trunk port. The only commands you will need to form a trunk is to set the encapsulation then set it to trunk. <br><div class="code"><PRE><span class="codetext">switchport mode trunk<br>switchport trunk encapsulation dot1q<br></SPAN></PRE></DIV>Should be just fine<br><br>For the router interface, im not 100% sure but I would only worry about setting the speed and duplex on the main interface. However if your using nat you will need to use "ip nat inside" on the subinterface.HTH<br><br>DP<br><br><SMALL>--<br>"Knowledge is contagious, infect"</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-HELP-Using-VLANS-on-a-2900-Series-switch-10271998</guid>
<pubDate>Tue, 18 May 2004 13:31:47 EDT</pubDate>
</item>
<item>
<title>Re: [HELP] Using VLANS on a 2900 Series switch.</title>
<link>http://www.dslreports.com/forum/Re-HELP-Using-VLANS-on-a-2900-Series-switch-10271922</link>
<description><![CDATA[astamand posted : The support just keeps rolling in.  You guys are a great asset to the community!<br><br>I am writing my outline for the new config now which I will be testing tonight.  I see a couple of things different between these last two examples of the proposed switch and router configurations.<br><br>On the switch config, there are two different examples of some vlan config lines:<br><br>Dan_D, you gave us this example:<br><br>interface FastEthernet0/1<br>description Uplink<br>switchport trunk encapsulation dot1q<br>switchport mode trunk<br><B>switchport trunk native vlan 1</B><br><br>and ChitownSVT, you gave this example:<br><br>interface FastEthernet0/1<br>description Uplink<br>switchport mode trunk<br>switchport trunk encapsulation dot1q<br><B>switchport trunk allowed vlan all</B><br><br>I am questioning the line in bold.  Should I have both, or one or the other?<br><BR><br>On the router config, I have the following configuration lines as part of my FastEthernet0/0:<br><br><div class="code"><PRE><span class="codetext">no ip redirects<br>no ip unreachables<br>no ip proxy-arp<br>ip nat inside<br>ip tcp adjust-mss 1452<br>duplex full<br>speed 100<br></SPAN></PRE></DIV><br>Do I need to have these lines on ALL of the virtual FastEthernet0/0.x interfaces or just the PRIMARY FastEthernet0/0 as it is now?<br><br>Thanks again,<br><br>-=Alex<br>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-HELP-Using-VLANS-on-a-2900-Series-switch-10271922</guid>
<pubDate>Tue, 18 May 2004 13:23:10 EDT</pubDate>
</item>
<item>
<title>Re: [HELP] Using VLANS on a 2900 Series switch.</title>
<link>http://www.dslreports.com/forum/Re-HELP-Using-VLANS-on-a-2900-Series-switch-10271427</link>
<description><![CDATA[ChitownSVT5 posted : yes it should still work, i experimented with that on my 2610 router and 2900xl switch, it worked fine except for some reason i could not get any information to go through vlan 1 but all others worked fine.  All you need to do is make one of the interfaces on the switch a trunk going to the router carrying all vlans.  Then set up subinterfaces on the router and and give them separate network IPs such as<br>VLAN 10 = 192.168.10.0<br>VLAN 20 = 192.168.20.0<br><br>Another thing, get rid of the "switchport trunk native vlan" cmd from all ur interfaces on the switch<br><br>SWITCH CONFIG<br>Interface fast-ethernet 0/1<br>switchport mode trunk<br>switchport trunk encapsulation dot1q<br>switchport trunk allowed vlan all<br><br>Interface fastethernet 0/?<br>switchport mode access<br>switchport access vlan ?<br><br>ROUTER CONFIG<br><br>interface ethernet 0/0<br>no ip address<br>no shutdown<br><br>interfacece ethernet 0/0.10<br>encapsulation dot1q 10<br>ip address 192.168.10.1 255.255.255.0<br>ip nat inside<br><br>interfacece ethernet 0/0.20<br>encapsulation dot1q 20<br>ip address 192.168.20.1 255.255.255.0<br>ip nat inside<br><br>im pretty sure this is all u need<br>you might also need to set VTP mode to transparent]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-HELP-Using-VLANS-on-a-2900-Series-switch-10271427</guid>
<pubDate>Tue, 18 May 2004 12:14:53 EDT</pubDate>
</item>
<item>
<title>Re: [HELP] Using VLANS on a 2900 Series switch.</title>
<link>http://www.dslreports.com/forum/Re-HELP-Using-VLANS-on-a-2900-Series-switch-10271169</link>
<description><![CDATA[astamand posted : So will my plan still work?  Is it just that they will stay listed as "shutdown"?<br><br>I too am coming from a different environment.  I am used to Layer three switches.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-HELP-Using-VLANS-on-a-2900-Series-switch-10271169</guid>
<pubDate>Tue, 18 May 2004 11:38:52 EDT</pubDate>
</item>
<item>
<title>Re: [HELP] Using VLANS on a 2900 Series switch.</title>
<link>http://www.dslreports.com/forum/Re-HELP-Using-VLANS-on-a-2900-Series-switch-10271088</link>
<description><![CDATA[Dan_D posted : Did not even consider that.........I have a similar implementation at about 700 remote sites but my routers connect to 6500's. I guess you do get somewhat used to a specific environment.<br><SMALL>--<br>^^There's no place like 127.0.0.1 ^^</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-HELP-Using-VLANS-on-a-2900-Series-switch-10271088</guid>
<pubDate>Tue, 18 May 2004 11:29:03 EDT</pubDate>
</item>
<item>
<title>Re: [HELP] Using VLANS on a 2900 Series switch.</title>
<link>http://www.dslreports.com/forum/Re-HELP-Using-VLANS-on-a-2900-Series-switch-10271009</link>
<description><![CDATA[dpocoroba posted : Ahh peaches28 <A HREF="/useremail/u/934874"><i class='fa fa-user'></i></A> great point. It totally skipped my mind about having only <B>one</B> mangement vlan. :) I guess you get used to EMI 3550's<br><SMALL>--<br>"Knowledge is contagious, infect"</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-HELP-Using-VLANS-on-a-2900-Series-switch-10271009</guid>
<pubDate>Tue, 18 May 2004 11:18:45 EDT</pubDate>
</item>
<item>
<title>Re: [HELP] Using VLANS on a 2900 Series switch.</title>
<link>http://www.dslreports.com/forum/Re-HELP-Using-VLANS-on-a-2900-Series-switch-10270988</link>
<description><![CDATA[peaches28 posted : In case you guys were wondering why the Vlan interfaces on the switch stayed shutdown, think about it.  It is a switch, it can have only one layer 3 interface up at a time. The Vlan interface on a switch is called the SVI, Switch VLAN interface.(At least I think so, acronym soup you know.)  That interface can affix to any ONE VLAN.  If it could have more than one interface well we call those Layer3 swtiches AKA routers.  ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-HELP-Using-VLANS-on-a-2900-Series-switch-10270988</guid>
<pubDate>Tue, 18 May 2004 11:14:50 EDT</pubDate>
</item>
<item>
<title>Re: [HELP] Using VLANS on a 2900 Series switch.</title>
<link>http://www.dslreports.com/forum/Re-HELP-Using-VLANS-on-a-2900-Series-switch-10270781</link>
<description><![CDATA[astamand posted : OIC now!  It's because I am now going to have to add the sub interfaces and they too will needs addresses.  I did not understand since I had not done it yet.  I will do as you recommend, it sounds like good practice.<br><br>Thanks!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-HELP-Using-VLANS-on-a-2900-Series-switch-10270781</guid>
<pubDate>Tue, 18 May 2004 10:45:22 EDT</pubDate>
</item>
<item>
<title>Re: [HELP] Using VLANS on a 2900 Series switch.</title>
<link>http://www.dslreports.com/forum/Re-HELP-Using-VLANS-on-a-2900-Series-switch-10270739</link>
<description><![CDATA[dpocoroba posted : It doesnt matter what physical interface you will use. f0/0 or f1/0/0 etc. The latest router config you posted will work for setting up the subinterfaces. What I mean about the IP addressing is what Dan_D <A HREF="/useremail/u/723611"><i class='fa fa-user'></i></A> pointed out, if you make the ip addy of vlan 2 say 172.25.20.1 and the subinteface on the router 172.25.20.1 its an adressing conflict. For personal choice in picking ip address for this case is to set all of the router interfaces to x.x.x.1 and the ip of the vlans to x.x.x.254 HTH<br><br>DP<br><SMALL>--<br>"Knowledge is contagious, infect"</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-HELP-Using-VLANS-on-a-2900-Series-switch-10270739</guid>
<pubDate>Tue, 18 May 2004 10:40:11 EDT</pubDate>
</item>
<item>
<title>Re: [HELP] Using VLANS on a 2900 Series switch.</title>
<link>http://www.dslreports.com/forum/Re-HELP-Using-VLANS-on-a-2900-Series-switch-10270558</link>
<description><![CDATA[Dan_D posted : First off rizacerx is correct i overlooked the addressing conflict, I apologize. The easiest option as pointed out is to change the addresses assigned to the Vlans on the switch......Make them .2 in their respective subnets<br><br>The Vlan native not being shown is normal......The intention was to insure that there was a known base to work from........As rizacerx pointed out since Vlan 1 is the default native it will not show.<br><br>As far as the interfaces being shutdown, once again i concur with rizacerx, do a no shut on all interfaces, incl. Vlan and attach devices.<br><br>Finally, when using sub-interfaces, the respective main interface is only used to set speed, duplex, etc. All addresses, access-list application, etc is done via the sub. You can change the configs for the sub-interfaces to fa0/0.1, fa0/0.10, fa0/0.20, etc to suit your needs and/or wants.<br><br>I hope this helps<br><SMALL>--<br>^^There's no place like 127.0.0.1 ^^</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-HELP-Using-VLANS-on-a-2900-Series-switch-10270558</guid>
<pubDate>Tue, 18 May 2004 10:13:57 EDT</pubDate>
</item>
<item>
<title>Re: [HELP] Using VLANS on a 2900 Series switch.</title>
<link>http://www.dslreports.com/forum/Re-HELP-Using-VLANS-on-a-2900-Series-switch-10270437</link>
<description><![CDATA[astamand posted :  <BLOCKQUOTE><SMALL>said by <a href="/profile/241337" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=241337');">dpocoroba</a>:</SMALL><HR>Ok, the reason you dont see "native vlan 1" in the config is becuase that vlan1 is the native for all cisco switches.<HR></BLOCKQUOTE><br><br>Makes sense.<br><br> <BLOCKQUOTE><SMALL>said by <a href="/profile/241337" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=241337');">dpocoroba</a>:</SMALL><HR>When you talk about removing "shutdown"? is that from the port or interface vlan?. Big difference between the two. You may have to have something connected to that vlan( not 100% on this I have seen that kind of problem before). Like one of your pc's maybe.<HR></BLOCKQUOTE><br><br>I tried it on the VLAN interfaces.  But what you said makes sense that it would be shutdown if nothing was attached.  I'll prove that tonight.<br><br> <BLOCKQUOTE><SMALL>said by <a href="/profile/241337" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=241337');">dpocoroba</a>:</SMALL><HR>Glancing over the config you have posted and the config for the router. You gave the sub interface of the router ethernet the same IP's as the layer 3 address of the vlans, nothing but headaches I would just change the IP addy of the vlans.<HR></BLOCKQUOTE><br><br>Do you mean somthing other than 172.25.x.x?<br><br> <BLOCKQUOTE><SMALL>said by <a href="/profile/241337" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=241337');">dpocoroba</a>:</SMALL><HR>As for your question about haveing a IP on the main interface. That most certinaly should <B>not</B> be there.<HR></BLOCKQUOTE><br><br>Since I have a physical FastEthernet0/1 shouldn't I build all of my virtual interfaces off of 0/0 like this (instead of 0/1?):<br><br><div class="code"><PRE><span class="codetext"> <br>(ROUTER)<br> <br>interface FastEthernet0/0<br>no ip address<br>load-interval 30<br>speed 100<br>full-duplex<br>!<br>interface FastEthernet0/0.1<br>description FE interface for VLAN 1 (default)<br>encapsulation dot1Q 1 native<br>ip address 172.25.1.1 255.255.255.0<br>!<br>interface FastEthernet0/0.10<br>description FE interface for VLAN 2 (Office Vlan)<br>encapsulation dot1Q 10<br>ip address 172.25.10.1 255.255.255.0<br>!<br>interface FastEthernet0/0.20<br>description FE interface for VLAN 2 (Home Vlan)<br>encapsulation dot1Q 20<br>ip address 172.25.20.1 255.255.255.0<br>!<br>interface FastEthernet0/0.30<br>description FE interface for VLAN 2 (Wireless Vlan)<br>encapsulation dot1Q 30<br>ip address 172.25.30.1 255.255.255.0<br></SPAN></PRE></DIV><br> <BLOCKQUOTE><SMALL>said by <a href="/profile/241337" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=241337');">dpocoroba</a>:</SMALL><HR>Think of ethernet subinterfaces like frame-relay and ATM.<HR></BLOCKQUOTE><br><br>Got it. (that's also why I questioned it above).<br><br> <BLOCKQUOTE><SMALL>said by <a href="/profile/241337" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=241337');">dpocoroba</a>:</SMALL><HR>I did a quick test of a config like this in my lab here and every vlan pulled from the correct ip pool. I dont have a 2900 to test this on though.<HR></BLOCKQUOTE><br><br>Great, then I am confident I'll have it working soon!  <br><br>Thanks for taking the time to help me.<br><br>-=Alex<br>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-HELP-Using-VLANS-on-a-2900-Series-switch-10270437</guid>
<pubDate>Tue, 18 May 2004 09:56:30 EDT</pubDate>
</item>
<item>
<title>Re: [HELP] Using VLANS on a 2900 Series switch.</title>
<link>http://www.dslreports.com/forum/Re-HELP-Using-VLANS-on-a-2900-Series-switch-10268337</link>
<description><![CDATA[dpocoroba posted : Ok, the reason you dont see "native vlan 1" in the config is becuase that vlan1 is the native for all cisco switches. When you talk about removing "shutdown"? is that from the port or interface vlan?. Big difference between the two. You may have to have something connected to that vlan( not 100% on this I have seen that kind of problem before). Like one of your pc's maybe. Glancing over the config you have posted and the config for the router. You gave the sub interface of the router ethernet the same IP's as the layer 3 address of the vlans, nothing but headaches I would just change the IP addy of the vlans. As for your question about haveing a IP on the main interface. That most certinaly should <B>not</B> be there. Think of ethernet subinterfaces like frame-relay and ATM. I did a quick test of a config like this in my lab here and every vlan pulled from the correct ip pool. I dont have a 2900 to test this on though. HTH<br><br>DP<br><SMALL>--<br>"Knowledge is contagious, infect"</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-HELP-Using-VLANS-on-a-2900-Series-switch-10268337</guid>
<pubDate>Mon, 17 May 2004 23:40:52 EDT</pubDate>
</item>
<item>
<title>Re: [HELP] Using VLANS on a 2900 Series switch.</title>
<link>http://www.dslreports.com/forum/Re-HELP-Using-VLANS-on-a-2900-Series-switch-10267942</link>
<description><![CDATA[astamand posted : OK (Dan) here's what's going on with the switch config.<br><br>I have added two out of the three lines you suggested to the switch config.  The third line, "switchport trunk native vlan 1", gets accepted, but after saving the config, it's not there.<br><br>Similarly, I removed the statement "switchport trunk native vlan XX" on all of the other interfaces, but I am not able to remove the "shutdown" even if I enter "no shut" to each interface.  They just want to stay shutdown.<br><br>On the router side I have a question now that I have looked at it more closely.<br><br>My current router interface connecting to the switch is FastEthernet0/0, you show it as being given no IP address.  Also, I have a FastEthernet0/1 which is currently not being used.  I was planning on making that a DMZ someday.<br><br>Does this change you recommendation on the settings at all?<br><br>I have attached a copy of the router config with this post.<br><br>I think were almost there!<br><br>Thanks, I appreciate your help.<br><br>-=Alex<!-- 10267942  HASH(0xacff1a0)   --><div class="borderless"><TABLE WIDTH=96% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=MIDDLE WIDTH=33%><A HREF="/r0/download/595733~a06fda0b8b29fa38696e06ea80388e24/config.zip"><i class="fa fa-download"></i> <big>config.zip</big></A><br><small>2,906 bytes</small></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-HELP-Using-VLANS-on-a-2900-Series-switch-10267942</guid>
<pubDate>Mon, 17 May 2004 22:49:07 EDT</pubDate>
</item>
<item>
<title>Re: [HELP] Using VLANS on a 2900 Series switch.</title>
<link>http://www.dslreports.com/forum/Re-HELP-Using-VLANS-on-a-2900-Series-switch-10264112</link>
<description><![CDATA[astamand posted : Thanks Dan_D, HawkRdr, and Army Dude!<br><br>you have been a lot of help.  I'll try these changes tonight and let you know how it worked.<br><br>Thanks again.<br><br>-=Alex]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-HELP-Using-VLANS-on-a-2900-Series-switch-10264112</guid>
<pubDate>Mon, 17 May 2004 15:15:08 EDT</pubDate>
</item>
<item>
<title>Re: [HELP] Using VLANS on a 2900 Series switch.</title>
<link>http://www.dslreports.com/forum/Re-HELP-Using-VLANS-on-a-2900-Series-switch-10262621</link>
<description><![CDATA[Dan_D posted : Try This!!<br><br>!!!!!!!!!!!ROUTER CONFIGURATION!!!!!!!!!!!!!!<br><br>interface FastEthernet0/0<br> no ip address<br> load-interval 30<br> speed 100<br> full-duplex<br>!<br>interface FastEthernet0/1.1<br> description FE interface for VLAN 1 (default)<br> encapsulation dot1Q 1 native<br> ip address 172.25.1.1 255.255.255.0<br>!<br>interface FastEthernet0/1.10<br> description FE interface for VLAN 2 (Office Vlan)<br> encapsulation dot1Q 10<br> ip address 172.25.10.1 255.255.255.0<br>!<br>interface FastEthernet0/1.20<br> description FE interface for VLAN 2 (Home Vlan)<br> encapsulation dot1Q 20<br> ip address 172.25.20.1 255.255.255.0<br>!<br>interface FastEthernet0/1.30<br> description FE interface for VLAN 2 (Wireless Vlan)<br> encapsulation dot1Q 30<br> ip address 172.25.30.1 255.255.255.0<br>!<br><br>ip dhcp pool Office<br>   network 172.25.10.0 255.255.255.0<br>   dns-server 151.203.0.84 151.203.0.85<br>   default-router 172.25.10.1  <br>!<br>ip dhcp pool Home<br>   network 172.25.20.0 255.255.255.0<br>    dns-server 151.203.0.84 151.203.0.85<br>   default-router 172.25.20.1 <br>!<br>ip dhcp pool Wireless<br>   network 172.25.30.0 255.255.255.0<br>    dns-server 151.203.0.84 151.203.0.85<br>   default-router 172.25.30.1 <br><br>!!!!!!!!!!!!!!!SWITCH CONFIGURATION!!!!!!!!!!!!!!!!!!!<br><br>interface FastEthernet0/1<br> description Uplink<br> switchport trunk encapsulation dot1q<br> switchport mode trunk<br> switchport trunk native vlan 1<br><br>Remove ip helper-address 172.25.1.1 from all Vlan configuration<br><br>Remove the statement "switchport trunk native vlan XX" on all other interfaces<br><br>No Shut on all vlan interfaces<br><br>That should do it<br><br>Best of Luck<br><SMALL>--<br>^^There's no place like 127.0.0.1 ^^</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-HELP-Using-VLANS-on-a-2900-Series-switch-10262621</guid>
<pubDate>Mon, 17 May 2004 11:58:45 EDT</pubDate>
</item>
<item>
<title>Re: [HELP] Using VLANS on a 2900 Series switch.</title>
<link>http://www.dslreports.com/forum/Re-HELP-Using-VLANS-on-a-2900-Series-switch-10262514</link>
<description><![CDATA[HawkRdr posted : Your VLANs need to be defined on the router as well, * i think*<br>been awhile since I have had to do it so...]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-HELP-Using-VLANS-on-a-2900-Series-switch-10262514</guid>
<pubDate>Mon, 17 May 2004 11:44:07 EDT</pubDate>
</item>
<item>
<title>Re: [HELP] Using VLANS on a 2900 Series switch.</title>
<link>http://www.dslreports.com/forum/Re-HELP-Using-VLANS-on-a-2900-Series-switch-10261687</link>
<description><![CDATA[astamand posted : Thanks for taking the time to research it Army Dude.<br><br>I think I understand what you are saying.  In the case of my foundry switch, it was layer three, so it could do some basic routing.  As I understand it, this switch is only layer two, so just having a default gateway set on it is not enough.<br><br>I understand I'll have to trunk the uplink port so that all the VLAN traffic can pass to the router.  That makes sense.  I'll disable trunking on the other ports as well.<br><br>So now the question is, do I need to create the VLANS on the router or is simply just having the DHCP scopes enough?<br><br>I just need a pointer to some examples or instructions on configuring the router to talk to a layer 2 switch with VLANS.<br><br>Thanks again.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-HELP-Using-VLANS-on-a-2900-Series-switch-10261687</guid>
<pubDate>Mon, 17 May 2004 09:35:02 EDT</pubDate>
</item>
<item>
<title>Re: [HELP] Using VLANS on a 2900 Series switch.</title>
<link>http://www.dslreports.com/forum/Re-HELP-Using-VLANS-on-a-2900-Series-switch-10261172</link>
<description><![CDATA[army dude posted : After a little research, it looks like your problem is with trunking. All of your interfaces, except for E0/1 are set as trunk ports. I think the opposite is what needs to be done...set E0/1 as a trunk port to the router. A trunk port will carry traffic from ALL vlans. Since you are using just one port (one connection) to the router, you will need to set up sub-interfaces on E0/1 and also on the router interface that connects to E0/1. You will need to set up a sub-interface for each vlan.<br>This will enable routing to take place between your different vlans.<br>I am pretty sure this is why you can't get the interfaces to come up. Maybe someone who knows vlans and trunking on cisco switches real well can offer some more advice here.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-HELP-Using-VLANS-on-a-2900-Series-switch-10261172</guid>
<pubDate>Mon, 17 May 2004 07:13:29 EDT</pubDate>
</item>
<item>
<title>Re: [HELP] Using VLANS on a 2900 Series switch.</title>
<link>http://www.dslreports.com/forum/Re-HELP-Using-VLANS-on-a-2900-Series-switch-10256809</link>
<description><![CDATA[astamand posted : Thanks, I forgot to mention they were listed as "shutdown" which you obviously saw by the show run above.<br><br>When I try that the command completes OK, but VLANS stay as "shutdown".<br><br>I'm sure that's what's wrong but I can't get them to budge.<br><br>Thanks,<br><br>Alex]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-HELP-Using-VLANS-on-a-2900-Series-switch-10256809</guid>
<pubDate>Sun, 16 May 2004 16:28:59 EDT</pubDate>
</item>
<item>
<title>Re: [HELP] Using VLANS on a 2900 Series switch.</title>
<link>http://www.dslreports.com/forum/Re-HELP-Using-VLANS-on-a-2900-Series-switch-10256716</link>
<description><![CDATA[army dude posted : Try this: <br><br>c2912# <B>config t</B><br>c2912(config)# <B>int VLAN10</B><br>c2912(config-if)# <B> no shut</B><br><br>repeat for the other 2 vlan interfaces....]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-HELP-Using-VLANS-on-a-2900-Series-switch-10256716</guid>
<pubDate>Sun, 16 May 2004 16:14:11 EDT</pubDate>
</item>
<item>
<title>[HELP] Using VLANS on a 2900 Series switch.</title>
<link>http://www.dslreports.com/forum/HELP-Using-VLANS-on-a-2900-Series-switch-10256435</link>
<description><![CDATA[astamand posted : I was wondering is if someone would mind looking at my switch config for my 2912.<br><br>I am trying to create three VLANS on the switch.  One VLAN for the HOME Network, one for the OFFICE network, and one for the WIRELESS network.<br><br>I believe I have the VLANS created correctly, but when I connect a client into one of the ports it can not get an IP address from the DHCP server (which is a Cisco router configured with DHCP scopes for all three VLANS as well as the default VLAN).<br><br>The IP address of the IP Helper is the address of the Cisco router giving out DHCP.  I have configured an IP Helper address for each VLAN since that was required when I run the same scenario on a Foundry switch.  On that switch, this configuration works (so the router is configured for DHCP correctly).<br><br>The switch is running IOS Version 12.0(5)WC9a (c2900xl-c3h2s-mz.120-5.WC9a.bin)<br><br>Any idea what I am missing?<br><br>Thanks in advance for your help.<br><BR><br><BLOCKQUOTE><br><div class="code"><PRE><span class="codetext">c2912#sh run<br>Building configuration...<br> <br>Current configuration:<br>!<br>! Last configuration change at 03:36:24 UTC Sun May 16 2004<br>! NVRAM config last updated at 03:36:25 UTC Sun May 16 2004<br>!<br>version 12.0<br>no service pad<br>service timestamps debug uptime<br>service timestamps log uptime<br>service password-encryption<br>!<br>hostname c2912<br>!<br>enable secret 5 &lt;SECRET&gt;<br>!<br>username astamand password 7 &lt;PASSWORD&gt;<br>!<br>!<br>!<br>!<br>!<br>ip subnet-zero<br>ip domain-name verizon.net<br>ip name-server 151.203.0.84<br>ip name-server 151.203.0.85<br>ip name-server 151.202.0.84<br>!<br>!<br>!<br>interface FastEthernet0/1<br> description Uplink<br>!<br>interface FastEthernet0/2<br> switchport access vlan 10<br> switchport trunk native vlan 10<br>!<br>interface FastEthernet0/3<br> switchport access vlan 10<br> switchport trunk native vlan 10<br>!<br>interface FastEthernet0/4<br> switchport access vlan 10<br> switchport trunk native vlan 10<br>!<br>interface FastEthernet0/5<br> switchport access vlan 20<br> switchport trunk native vlan 20<br>!<br>interface FastEthernet0/6<br> switchport access vlan 20<br> switchport trunk native vlan 20<br>!<br>interface FastEthernet0/7<br> switchport access vlan 20<br> switchport trunk native vlan 20<br>!<br>interface FastEthernet0/8<br> switchport access vlan 20<br> switchport trunk native vlan 20<br>!<br>interface FastEthernet0/9<br> switchport access vlan 30<br> switchport trunk native vlan 30<br>!<br>interface FastEthernet0/10<br> switchport access vlan 30<br> switchport trunk native vlan 30<br>!<br>interface FastEthernet0/11<br> switchport access vlan 30<br> switchport trunk native vlan 30<br>!<br>interface FastEthernet0/12<br> switchport access vlan 30<br> switchport trunk native vlan 30<br>!<br>interface VLAN1<br> description DEFAULT<br> ip address 172.25.1.5 255.255.255.0<br> no ip directed-broadcast<br> no ip route-cache<br>!<br>interface VLAN10<br> description OFFICE<br> ip address 172.25.10.1 255.255.255.0<br> ip helper-address 172.25.1.1<br> no ip directed-broadcast<br> no ip route-cache<br> shutdown<br>!<br>interface VLAN20<br> description HOME<br> ip address 172.25.20.1 255.255.255.0<br> ip helper-address 172.25.1.1<br> no ip directed-broadcast<br> no ip route-cache<br> shutdown<br>!<br>interface VLAN30<br> description WIRELESS<br> ip address 172.25.30.1 255.255.255.0<br> ip helper-address 172.25.1.1<br> no ip directed-broadcast<br> no ip route-cache<br> shutdown<br>!<br>ip default-gateway 172.25.1.1<br>!<br>line con 0<br> logging synchronous<br> transport input none<br> stopbits 1<br>line vty 0 4<br> logging synchronous<br> login local<br> transport input telnet<br>!<br>ntp clock-period 22518299<br>ntp server 172.25.1.1<br>end<br> <br>c2912#<br></SPAN></PRE></DIV></BLOCKQUOTE><br><BR><br>Here is the output of a Show VLAN Brief:<br><BR><br><BLOCKQUOTE><br><div class="code"><PRE><span class="codetext">c2912#show vlan brief<br>VLAN Name                             Status    Ports<br>---- -------------------------------- --------- -------------------------------<br>1    default                          active    Fa0/1<br>10   OFFICE                           active    Fa0/2, Fa0/3, Fa0/4<br>20   HOME                             active    Fa0/5, Fa0/6, Fa0/7, Fa0/8<br>30   WIRELESS                         active    Fa0/9, Fa0/10, Fa0/11, Fa0/12<br>1002 fddi-default                     active<br>1003 token-ring-default               active<br>1004 fddinet-default                  active<br>1005 trnet-default                    active<br>c2912#<br></SPAN></PRE></DIV></BLOCKQUOTE><br>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/HELP-Using-VLANS-on-a-2900-Series-switch-10256435</guid>
<pubDate>Sun, 16 May 2004 15:29:47 EDT</pubDate>
</item>
</channel>
</rss>
