- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-03-2023 05:38 PM
I have 2 Cisco CBS350 switches. They are connected by fiber. I am trying to setup a VLAN (20) on port 1 of each switch to isolate the 2 machines so they can only see each other. I have create VLAN 20 on each switch. I have setup each fiber port as Trunked with with access to both VLANS ( 1U, 20T ). I then setup port 1 on each switch as access to VLAN 20 ( 20U ). These 2 machines will not see each other.
Solved! Go to Solution.
- Labels:
-
LAN Switching
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-05-2023 12:47 PM
Remove this one more and test please
interface TenGigabitEthernet1/0/1
no macro auto
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-03-2023 06:09 PM
Hi
When you say not see each other do you mean ping or are you trying another way?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-03-2023 06:23 PM - edited 07-03-2023 06:23 PM
Yes ping. On VLAN 1 they ping just fine.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-03-2023 07:28 PM
Do you have access via CLI ? Would be Nice see the show running!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-05-2023 07:45 AM
Do you want to see the entire show running?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-05-2023 07:49 AM
that would be great.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-05-2023 07:53 AM
config-file-header
IT-CBS350-24T
v3.3.0.16 / RCBS3.3_950_377_202
CLI v1.0
file SSD indicator encrypted
@
ssd-control-start
ssd config
ssd file passphrase control unrestricted
no ssd file integrity control
ssd-control-end cb0a3fdb1f3a1af4e4430033719968c0
!
!
unit-type-control-start
unit-type unit 1 network gi uplink te
unit-type unit 2 network gi uplink te
unit-type unit 3 network gi uplink te
unit-type unit 4 network gi uplink te
unit-type-control-end
!
vlan database
vlan 20
exit
voice vlan state auto-triggered
voice vlan oui-table add 0001e3 Siemens_AG_phone
voice vlan oui-table add 00036b Cisco_phone
voice vlan oui-table add 00096e Avaya
voice vlan oui-table add 000fe2 H3C_Aolynk
voice vlan oui-table add 0060b9 Philips_and_NEC_AG_phone
voice vlan oui-table add 00d01e Pingtel_phone
voice vlan oui-table add 00e075 Polycom/Veritel_phone
voice vlan oui-table add 00e0bb 3Com_phone
dot1x system-auth-control
dot1x mac-auth eap username groupsize 2 separator : lowercase
bonjour interface range vlan 1
hostname IT-CBS350-24T
encrypted radius-server host 10.5.19.44 key +kcLT6/E8WI+PuwsVO
aaa accounting dot1x start-stop group radius
passwords aging 180
username
ip telnet server
!
interface vlan 1
ip address 10.5.19.70 255.255.255.0
no ip address dhcp
!
interface GigabitEthernet1/0/1
dot1x authentication 802.1x mac
dot1x port-control auto
spanning-tree link-type point-to-point
macro description switch
!next command is internal.
macro auto smartport dynamic_type switch
!
interface GigabitEthernet1/0/2
dot1x authentication 802.1x mac
dot1x port-control auto
!
interface GigabitEthernet1/0/3
dot1x authentication 802.1x mac
dot1x port-control auto
spanning-tree link-type point-to-point
macro description switch
!next command is internal.
macro auto smartport dynamic_type switch
!
interface GigabitEthernet1/0/4
dot1x authentication 802.1x mac
dot1x port-control auto
!
interface GigabitEthernet1/0/5
dot1x authentication 802.1x mac
dot1x port-control auto
!
interface GigabitEthernet1/0/6
dot1x authentication 802.1x mac
dot1x port-control auto
!
interface GigabitEthernet1/0/7
dot1x authentication 802.1x mac
dot1x port-control auto
!
interface GigabitEthernet1/0/8
dot1x authentication 802.1x mac
dot1x port-control auto
!
interface GigabitEthernet1/0/9
dot1x authentication 802.1x mac
switchport access vlan 20
switchport trunk native vlan 20
switchport trunk allowed vlan 20
!
interface GigabitEthernet1/0/10
dot1x authentication 802.1x mac
spanning-tree link-type point-to-point
switchport access vlan 20
switchport general pvid 20
switchport trunk native vlan 20
macro description switch
!next command is internal.
macro auto smartport dynamic_type switch
!
interface GigabitEthernet1/0/11
dot1x authentication 802.1x mac
dot1x port-control auto
!
interface GigabitEthernet1/0/12
dot1x authentication 802.1x mac
dot1x port-control auto
!
interface GigabitEthernet1/0/13
dot1x authentication 802.1x mac
dot1x port-control auto
!
interface GigabitEthernet1/0/14
dot1x authentication 802.1x mac
dot1x port-control auto
!
interface GigabitEthernet1/0/15
dot1x authentication 802.1x mac
dot1x port-control auto
!
interface GigabitEthernet1/0/16
dot1x authentication 802.1x mac
dot1x port-control auto
!
interface GigabitEthernet1/0/17
dot1x authentication 802.1x mac
dot1x port-control auto
!
interface GigabitEthernet1/0/18
dot1x authentication 802.1x mac
dot1x port-control auto
!
interface GigabitEthernet1/0/19
dot1x authentication 802.1x mac
dot1x port-control auto
!
interface GigabitEthernet1/0/20
dot1x authentication 802.1x mac
dot1x port-control auto
!
interface GigabitEthernet1/0/21
dot1x authentication 802.1x mac
dot1x port-control auto
!
interface GigabitEthernet1/0/22
dot1x authentication 802.1x mac
dot1x port-control auto
!
interface GigabitEthernet1/0/23
dot1x authentication 802.1x mac
!
interface TenGigabitEthernet1/0/1
spanning-tree link-type point-to-point
switchport mode trunk
switchport trunk allowed vlan 1,20
macro description switch
!next command is internal.
macro auto smartport dynamic_type switch
!
exit
macro auto controlled
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-05-2023 08:27 AM - edited 07-05-2023 08:28 AM
config-file-header
IT-CBS350-24T
v3.3.0.16 / RCBS3.3_950_377_202
CLI v1.0
file SSD indicator encrypted
@
ssd-control-start
ssd config
ssd file passphrase control unrestricted
no ssd file integrity control
ssd-control-end cb0a3fdb1f3a1af4e4430033719968c0
!
!
unit-type-control-start
unit-type unit 1 network gi uplink te
unit-type unit 2 network gi uplink te
unit-type unit 3 network gi uplink te
unit-type unit 4 network gi uplink te
unit-type-control-end
!
vlan database
vlan 20
exit
voice vlan state auto-triggered
voice vlan oui-table add 0001e3 Siemens_AG_phone
voice vlan oui-table add 00036b Cisco_phone
voice vlan oui-table add 00096e Avaya
voice vlan oui-table add 000fe2 H3C_Aolynk
voice vlan oui-table add 0060b9 Philips_and_NEC_AG_phone
voice vlan oui-table add 00d01e Pingtel_phone
voice vlan oui-table add 00e075 Polycom/Veritel_phone
voice vlan oui-table add 00e0bb 3Com_phone
dot1x system-auth-control
dot1x mac-auth eap username groupsize 2 separator : lowercase
bonjour interface range vlan 1
hostname IT-CBS350-24T
encrypted radius-server host xxxkey xx
aaa accounting dot1x start-stop group radius
passwords aging 180
username
ip telnet server
!
interface vlan 1
ip address 10.5.19.70 255.255.255.0
no ip address dhcp
!
interface GigabitEthernet1/0/1
dot1x authentication 802.1x mac
dot1x port-control auto
spanning-tree link-type point-to-point
macro description switch
!next command is internal.
macro auto smartport dynamic_type switch
!
interface GigabitEthernet1/0/2
dot1x authentication 802.1x mac
dot1x port-control auto
!
interface GigabitEthernet1/0/3
dot1x authentication 802.1x mac
dot1x port-control auto
spanning-tree link-type point-to-point
macro description switch
!next command is internal.
macro auto smartport dynamic_type switch
!
interface GigabitEthernet1/0/4
dot1x authentication 802.1x mac
dot1x port-control auto
!
interface GigabitEthernet1/0/5
dot1x authentication 802.1x mac
dot1x port-control auto
!
interface GigabitEthernet1/0/6
dot1x authentication 802.1x mac
dot1x port-control auto
!
interface GigabitEthernet1/0/7
dot1x authentication 802.1x mac
dot1x port-control auto
!
interface GigabitEthernet1/0/8
dot1x authentication 802.1x mac
dot1x port-control auto
!
interface GigabitEthernet1/0/9
dot1x authentication 802.1x mac
switchport access vlan 20
switchport trunk native vlan 20
switchport trunk allowed vlan 20
!
interface GigabitEthernet1/0/10
dot1x authentication 802.1x mac
spanning-tree link-type point-to-point
switchport access vlan 20
switchport general pvid 20
switchport trunk native vlan 20
macro description switch
!next command is internal.
macro auto smartport dynamic_type switch
!
interface GigabitEthernet1/0/11
dot1x authentication 802.1x mac
dot1x port-control auto
!
interface GigabitEthernet1/0/12
dot1x authentication 802.1x mac
dot1x port-control auto
!
interface GigabitEthernet1/0/13
dot1x authentication 802.1x mac
dot1x port-control auto
!
interface GigabitEthernet1/0/14
dot1x authentication 802.1x mac
dot1x port-control auto
!
interface GigabitEthernet1/0/15
dot1x authentication 802.1x mac
dot1x port-control auto
!
interface GigabitEthernet1/0/16
dot1x authentication 802.1x mac
dot1x port-control auto
!
interface GigabitEthernet1/0/17
dot1x authentication 802.1x mac
dot1x port-control auto
!
interface GigabitEthernet1/0/18
dot1x authentication 802.1x mac
dot1x port-control auto
!
interface GigabitEthernet1/0/19
dot1x authentication 802.1x mac
dot1x port-control auto
!
interface GigabitEthernet1/0/20
dot1x authentication 802.1x mac
dot1x port-control auto
!
interface GigabitEthernet1/0/21
dot1x authentication 802.1x mac
dot1x port-control auto
!
interface GigabitEthernet1/0/22
dot1x authentication 802.1x mac
dot1x port-control auto
!
interface GigabitEthernet1/0/23
dot1x authentication 802.1x mac
!
interface TenGigabitEthernet1/0/1
spanning-tree link-type point-to-point
switchport mode trunk
switchport trunk allowed vlan 1,20
macro description switch
!next command is internal.
macro auto smartport dynamic_type switch
!
exit
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-05-2023 08:44 AM
I have added it twice but it keeps getting removed from here for some reason.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-05-2023 08:52 AM
You can save the config in a txt file and attach file here.
But I could see your config. This diagram below is what you are trying to accomplish right?
What I would recommend is first clean up the interfaces involved.
conf t
default interface <interface>
Then, config the interface with the minimum necessary
Interfaces between switches:
conf t
int gx/x
switch port mode trunk
Interface between switches and PCs.
conf t
int gx/x
switchport mode acess
switch access vlan 20
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-05-2023 09:07 AM
Let's see if this works. Here is what I think you want to see:
Switch 1
VLAN Setup:
!
interface vlan 1
ip address 10.5.19.70 255.255.255.0
no ip address dhcp
!
interface vlan 30
name Test
!
Trunk Port:
!
interface TenGigabitEthernet1/0/1
spanning-tree link-type point-to-point
switchport mode trunk
switchport trunk allowed vlan 1,30
macro description switch
!next command is internal.
macro auto smartport dynamic_type switch
!
Access Port:
!
interface GigabitEthernet1/0/10
dot1x authentication 802.1x mac
spanning-tree link-type point-to-point
switchport access vlan 30
switchport general pvid 30
switchport trunk native vlan 30
macro description switch
!next command is internal.
macro auto smartport dynamic_type switch
!
Switch 2
!
interface vlan 1
ip address 192.168.168.1 255.255.255.0
no ip address dhcp
!
interface vlan 30
name Test
!
Trunk Port:
!
interface TenGigabitEthernet1/0/22
switchport mode trunk
switchport trunk allowed vlan 1,30
!
Access Port
!
interface TenGigabitEthernet1/0/24
speed 1000
switchport access vlan 30
switchport general pvid 30
switchport trunk native vlan 30
!
!
interface TenGigabitEthernet1/0/1
spanning-tree link-type point-to-point
switchport mode trunk
switchport trunk allowed vlan 1,20
macro description switch
!next command is internal.
macro auto smartport dynamic_type switch
!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-05-2023 09:20 AM
Thanks.
First you need to device by vlan 20 or 30. Initially you mentioned 20.
If you want to make the switch as layer3, which means the switch will have IP address on the vlan and differents vlans to communicate, you need to run the command:
conf t
ip routing
Then, on the vlan you need to do:
int vlan 20
ip add x.x.x. x x.x (choose the ip address and mask)
Do it on both switches. Keep in mind that vlan 1 will not participate on this.
I will give here and example
Switch 1
conf t
int vlan 20
ip add 192.168.20.1 255.255.2550
switch 2
int vlan 20
ip add 192.168.20.2 255.255.255.0
Use the IP add 192.168.20.3 and 192.168.20.4 on the PCs.
For the interface config, use the following example
conf t
default interface <interface>
Then, config the interface with the minimum necessary
Interfaces between switches:
conf t
int gx/x
switch port mode trunk
Interface between switches and PCs.
conf t
int gx/x
switchport mode acess
switch access vlan 20
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-05-2023 09:25 AM - edited 07-05-2023 09:26 AM
I changed it to 30 testing. End result I just want 1 port on each switch to be able to communicate with each other on VLAN 30. Does this require Layer 3 if I do not need any other subnets to route to this? It doesn't seem to be as hard and it is being for me!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-05-2023 09:35 AM
It does not required layer3 on the switch
You need to create vlan 30 on both switch
Add vlan 30 on trunk between switches
You need to put both PC interface on vlan 30
Add IP on PCs.
Thats it.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-05-2023 09:50 AM
I feel like that is exactly what I am doing. Your diagram looks like what I want. I will try what you suggested and keep you posted. Thanks for the help so far!
