05-15-2013 09:05 AM - edited 03-04-2019 07:54 PM
hi
If I have a dmz switch, which then plugs into my distrubution switch, this then goes to my core switch which has a wan link connected. The other end of the wan link connects to a core, then a dmz switch.
if I have vlans 1,2,3,4,5,6 on my DMZ switches
Am I correct in saying that on the distribution switch i will create the tunnel interface and simply add say vlan 2000 as the access vlan, then tag this vlan to my cores, will all the dmz vlans get tunneled across this one vlan ?
or on the distrubution switch do i need to add the dmz vlans on the trunk port to the dmz switch ? and only tag the vlan 2000 to my core and across the wan ports ?
cheers
Carl
05-15-2013 03:14 PM
You can tunnel Vlans 1-6 on your DMZ switch across the Distro and Core without them knowing about any of them. You will have to use option dot1q-tunnel on switchport mode command.
HTH.
05-17-2013 08:52 AM
Hi there
where would I configure the tunnel interface? On the dust switch port where it plugs into the DMZ switch?
Also, would what vlan would need to be I the dist switch port? Would it be all of them or just an access vlan for the tunnel?
05-19-2013 08:51 PM
Tunnel interface is going to be on the distro switch port as you have mentioned.
Only access vlan need to be known on distro.
Thanks.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide