cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1672
Views
0
Helpful
2
Replies

2 x Cisco SG300 switches, best practices

icehckyplyr22
Level 1
Level 1

I have some questions about the best way to setup 2 x SG300 switch in a pair (this model doesn't allow stacking). Both are the 28 port model. Here is my config:

 

VLAN 1  (default VLAN) I would love to delete it but can't seem to because it is attached in all of the auto features

VLAN 10  (LAN VLAN)  Interface IP on SW-01  10.0.0.254

VLAN 50  (IP_Phone VLAN) Interface IP on SW-01 10.0.50.254

Ports 1-24 are 10U & 50T (trunk ports)

Ports 25/26 are 50T (access ports)

Port 27 (Uplink to my firewall)  10U (access port)

Port 28 (Uplink to SW-02)

I have a route on SW-01:  for 0.0.0.0 to 10.0.0.1 (my firewall IP)

Now my questions come into play with SW-02

Do I need to set interface IP's on these VLANs? My assumption is not since I will be using the .254 as my gateway to be given via DHCP

How should I configure the Tagging for on Port 28 on both switches? (This will be my uplink between the two switches)

Do I need any routes on SW-02? I am assuming not since .254 will be my gateway

 

1 Accepted Solution

Accepted Solutions

Mike Williams
Level 5
Level 5
You can forbid VLAN 1 from all ports, but you cannot delete it on the small biz switches. You should set port 28 as a trunk port and allow both VLANs 10 and 50 as tagged VLANs on that port. For switch 2, you only need an IP on one of the active VLANs for management as well as a static default route to .254 if you want to access it from anywhere besides the management/data VLAN. Regards, Mike

View solution in original post

2 Replies 2

Mike Williams
Level 5
Level 5
You can forbid VLAN 1 from all ports, but you cannot delete it on the small biz switches. You should set port 28 as a trunk port and allow both VLANs 10 and 50 as tagged VLANs on that port. For switch 2, you only need an IP on one of the active VLANs for management as well as a static default route to .254 if you want to access it from anywhere besides the management/data VLAN. Regards, Mike

icehckyplyr22
Level 1
Level 1

It wants at least 1 Untagged VLAN on Port 28, so I did 10U & 50T.

 

Thanks for the other info as well!!