10-12-2020 09:38 AM
I'm guessing this has been asked a 100 times but here my scenario....
I have a number of layer 3 vlan's on a switch, as the switch is controlled by Cisco ISE a connected device could exist in 3 different vlan's dependant on its status (powered up, logged on or needs remediation).....
From time to time a certain vlan may not have a device connect (i.e. no PC's need remediating), therefore that vlan will go down....
This isn't the issue.... The issue to our Cyber security team and our Tenable scanning server. This is configured to scan all know networks... If the remediation vlan is down because no PC's need remediating then all scanning traffic follows the default route to our FTD which is the main gateway.....
Any ideas how I can keep the vlan up????
Thanks
10-12-2020 09:45 AM
Allow in trunk I think do job.
10-12-2020 10:57 AM - edited 10-12-2020 11:05 AM
are we talking about SVI, like interface vlan x ? there is command that you can put under at least 1 access vlan x port Or trunk port to prevent SVI to go down. I think is switchport autostate (use ? to find particular command for your ios )
also, keep vlan on trunks (at least 1 trunk) and in database, as suggested by MHM
Regards, ML
**Please Rate All Helpful Responses **
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide