cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
277
Views
0
Helpful
3
Replies

q in q tunneling question

carl_townshend
Spotlight
Spotlight

hi

If I have a dmz switch, which then plugs into my distrubution switch, this then goes to my core switch which has a wan link connected. The other end of the wan link connects to a core, then a dmz switch.

if I have vlans 1,2,3,4,5,6 on my DMZ switches

Am I correct in saying that on the distribution switch i will create the tunnel interface and simply add say vlan 2000 as the access vlan, then tag this vlan to my cores, will all the dmz vlans get tunneled across this one vlan ?

or on the distrubution switch do i need to add the dmz vlans on the trunk port to the dmz switch ? and only tag the vlan 2000 to my core and across the wan ports ?

cheers

Carl

3 Replies 3

rais
Level 7
Level 7

You can tunnel Vlans 1-6 on your DMZ switch across the Distro and Core without them knowing about any of them. You will have to use option dot1q-tunnel on switchport mode command.

HTH.

Hi there

where would I configure the tunnel interface? On the dust switch port where it plugs into the DMZ switch?

Also, would what vlan would need to be I the dist switch port? Would it be all of them or just an access vlan for the tunnel?

Tunnel interface is going to be on the distro switch port as you have mentioned.

Only access vlan need to be known on distro.

Thanks.

Review Cisco Networking products for a $25 gift card