cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1284
Views
35
Helpful
11
Replies

Cisco basic vlan configuration

Hi Guys,

I need help configuring a cisco switch. Please refer to the below screenshot for reference. 

SW.png

 

So what I want is that my two windows7 machines should be in different VLANs (10 and 20). Further, I created a DHCP server in the firewall and I want these two win7 machines to take DHCP IP from the firewall.

So I configured the below configuration in the switch - 

#vlan 10
#interface e0/2
#switchport access VLAN 10
#switchport mode access

#vlan 20
#interface e0/3
#switchport access VLAN 20
#switchport mode access

---------------FIREWALL CONFIGURATION-----------

I configured Eth2 of my firewall as VLAN

I created 3 VLANs i.e., vlan1, vlan10, and vlan20 and I created DHCP pools in all three VLANs in the firewall.

So I configured vlan1 as untagged for Eth2, vlan10 as tagged for Eth2, vlan20 as tagged for Eth2

After all this config, I am not getting any IP in the switch or computer. Do I have to configure something else? Please guide.

1 Accepted Solution

Accepted Solutions

SW(cisco)-FW(other Vendor)
between the SW and FW use trunk 
in FW must tag all VLAN 
in FW dont use native VLAN 

View solution in original post

11 Replies 11

 SW is L3 or L2 SW? i.e. ip routing is config in SW or not ?

SW(cisco)-FW(other Vendor)
between the SW and FW use trunk 
in FW must tag all VLAN 
in FW dont use native VLAN 

@MHM Cisco World Just out of curiosity (and I admit that my knowledge of Watchguard is limited), if you tag all Vlans on the Watchguard, and since the Cisco trunk needs a native, untagged Vlan, will there not be a mismatch (actually, will the trunk work at all) ? Which model did you test this on (e.g. T20/T40/T80) and which Fireware version ?

Hello,

the link between the switch and the firewall needs to be a trunk:

Switch

interface Ethernet0/1

switchport mode trunk

What brand/type/model is the firewall ?

Hi Georg,

It's a WatchGuard firewall. What about VLAN 10 and 20, should I select untagged or tagged traffic for them?

And after configuring a trunk port E0/1, will my switch start getting DHCP from FW?

Hello,

you need to tag Vlan 10 and Vlan 20, leave Vlan 1 as the default (untagged) native Vlan. In theory, that should get all clients DHCP addresses.

@Georg Pauwen @MHM Cisco World 

Hi Guys, Thanks for replying. So I made some changes, I changed e0/1 which is connected to the switch as a Trunk port, and remove VLAN-1 from the firewall and now my PC is getting DHCP from FW.

Now my Firewall has two VLANs 10 and 20 and both of them have tagged traffic.

One more thing I can't figure out is can my VLANs in the switch get the IP from the firewall DHCP. I mean how do I access my switch remotely? Do I have to manually assign some IP to VLAN? Can't it get from the FW DHCP?

as I know 
you can do that 
vlan x
ip address dhcp 
this make SW ask FW for IP

one more note:- We assign IP to VLAN in L2SW for management SW, make VLAN have dynamic IP may be it be more difficult to manage the SW remotely. 

Hi,

Just the last two queries I have before closing this post, if you can clarify that

1) If I want to access the switch from the firewall side, how to assign the IP address to E0/1 since it is a trunk port?

2) "if you tag all Vlans on the Watchguard, and since the Cisco trunk needs a native, untagged Vlan, will there not be a mismatch (actually, will the trunk work at all)". Can you please explain what Georg was saying? I have very limited networking knowledge. 

bvnnbvbnvbnbvvn.png

the native VLAN in trunk is only use in L2SW not use in any L3 device, L3 device use sub-interface, it dont care about which native VLAN L2SW use 
but 
the most important is tag 
L3 device dont care about native VLAN but if it send untag frame, the L2SW will assume that this frame is for native VLAN.
so that why I mention dont use native VLAN ID in FW 
(not use native VLAN ID in FW is different than allow native VLAN in truck)

that it.

for access SW and you have L2 port trunk, 
simply config SVI for VLAN 10 and assing manually IP to it  and you can access SW. 

Review Cisco Networking for a $25 gift card