11-27-2018 08:15 AM - edited 03-08-2019 04:41 PM
This may seems pretty simple.............it is, but I'm having a heck of a time getting it to work.
I have a 3560 switch that has been factory defaulted. It is connecting a small network of workstations and servers (including DHCP server). All 48 ports are in VLAN 1 and I have Gb1 setup as trunk to connect to firewall to Internet. Everything works.
Here is my issue....I would like to change all of the ports from VLAN 1 to another VLAN number (the number doesn't matter). I use CNA to administer to the switch. When I go into CNA and change the VLAN on all of the ports, (ie from 1 to 99) and APPLY, all connectivity is lost. I thought perhaps it might take a few minutes to process, so I waited 10 minutes and still no joy.
I changed the VLAN back to 1 and within a couple of minutes, everything worked again.
Any help would be appreciated.
Solved! Go to Solution.
11-27-2018 10:41 AM
Hi
Since you change the vlan assignement on the switch, do you have vlan 99 or the new vlan created on the firewall? Vlan 1 working as native vlan in a switch may be passing to the firewall untagged. When you configure the new vlan, Firewall will be receiving vlan 1 untagged and a new vlan with a tag that may not recognize.
You can try to only apply the changes not to all but to a portion of the ports and see the effects.
If this works, may be the issue could be pressent on the FW.
BR
Gaston
11-27-2018 08:24 AM
perhaps your effecting the trunk port config when you make the change?
ensure all vlans are allowed across the trunk link, including 99.
you could console to switch & do it:
conf t
vlan 99
name test-vlan
exit
interface range g1/0/1 - 10
switchport mode access
switchport access vlan 99
regards, mk
11-27-2018 09:43 AM
Thanks for the quick response.
The Gi0/1 port is set as 802.1Q Trunk and VLANs set to ALL.
I use CNA and highlight ports 1 - 48 and click Modify and change the Static-Access VLAN number to 99. Then OK and Apply.
Still no joy.
Does that set the switchport mode access & switchport access or does that need to be done through CLI?
11-27-2018 10:41 AM
Hi
Since you change the vlan assignement on the switch, do you have vlan 99 or the new vlan created on the firewall? Vlan 1 working as native vlan in a switch may be passing to the firewall untagged. When you configure the new vlan, Firewall will be receiving vlan 1 untagged and a new vlan with a tag that may not recognize.
You can try to only apply the changes not to all but to a portion of the ports and see the effects.
If this works, may be the issue could be pressent on the FW.
BR
Gaston
11-30-2018 07:20 AM
Thanks! That was the piece I was missing. Everything is running great now.
11-30-2018 08:29 AM
I am glad to hear that
thanks
BR
Gaston
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide