cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2409
Views
0
Helpful
32
Replies

Vlan Problem

cbaze
Level 1
Level 1

I have 2 Cisco CBS350 switches. They are connected by fiber. I am trying to setup a VLAN (20) on port 1 of each switch to isolate the 2 machines so they can only see each other. I have create VLAN 20 on each switch. I have setup each fiber port as Trunked with with access to both VLANS ( 1U, 20T ). I then setup port 1 on each switch as access to VLAN 20 ( 20U ). These 2 machines will not see each other. 

1 Accepted Solution

Accepted Solutions

Remove this one more and test please

interface TenGigabitEthernet1/0/1

no macro auto

View solution in original post

32 Replies 32

Hi

 When you say not see each other do you mean ping or are you trying another way?

Yes ping. On VLAN 1 they ping just fine. 

Do you have access via CLI ? Would be Nice see the show running!

Do you want to see the entire show running?

 

that would be great.

config-file-header
IT-CBS350-24T
v3.3.0.16 / RCBS3.3_950_377_202
CLI v1.0
file SSD indicator encrypted
@
ssd-control-start
ssd config
ssd file passphrase control unrestricted
no ssd file integrity control
ssd-control-end cb0a3fdb1f3a1af4e4430033719968c0
!
!
unit-type-control-start
unit-type unit 1 network gi uplink te
unit-type unit 2 network gi uplink te
unit-type unit 3 network gi uplink te
unit-type unit 4 network gi uplink te
unit-type-control-end
!
vlan database
vlan 20
exit
voice vlan state auto-triggered
voice vlan oui-table add 0001e3 Siemens_AG_phone
voice vlan oui-table add 00036b Cisco_phone
voice vlan oui-table add 00096e Avaya
voice vlan oui-table add 000fe2 H3C_Aolynk
voice vlan oui-table add 0060b9 Philips_and_NEC_AG_phone
voice vlan oui-table add 00d01e Pingtel_phone
voice vlan oui-table add 00e075 Polycom/Veritel_phone
voice vlan oui-table add 00e0bb 3Com_phone
dot1x system-auth-control
dot1x mac-auth eap username groupsize 2 separator : lowercase
bonjour interface range vlan 1
hostname IT-CBS350-24T
encrypted radius-server host 10.5.19.44 key +kcLT6/E8WI+PuwsVO
aaa accounting dot1x start-stop group radius
passwords aging 180
username
ip telnet server
!
interface vlan 1
ip address 10.5.19.70 255.255.255.0
no ip address dhcp
!
interface GigabitEthernet1/0/1
dot1x authentication 802.1x mac
dot1x port-control auto
spanning-tree link-type point-to-point
macro description switch
!next command is internal.
macro auto smartport dynamic_type switch
!
interface GigabitEthernet1/0/2
dot1x authentication 802.1x mac
dot1x port-control auto
!
interface GigabitEthernet1/0/3
dot1x authentication 802.1x mac
dot1x port-control auto
spanning-tree link-type point-to-point
macro description switch
!next command is internal.
macro auto smartport dynamic_type switch
!
interface GigabitEthernet1/0/4
dot1x authentication 802.1x mac
dot1x port-control auto
!
interface GigabitEthernet1/0/5
dot1x authentication 802.1x mac
dot1x port-control auto
!
interface GigabitEthernet1/0/6
dot1x authentication 802.1x mac
dot1x port-control auto
!
interface GigabitEthernet1/0/7
dot1x authentication 802.1x mac
dot1x port-control auto
!
interface GigabitEthernet1/0/8
dot1x authentication 802.1x mac
dot1x port-control auto
!
interface GigabitEthernet1/0/9
dot1x authentication 802.1x mac
switchport access vlan 20
switchport trunk native vlan 20
switchport trunk allowed vlan 20
!
interface GigabitEthernet1/0/10
dot1x authentication 802.1x mac
spanning-tree link-type point-to-point
switchport access vlan 20
switchport general pvid 20
switchport trunk native vlan 20
macro description switch
!next command is internal.
macro auto smartport dynamic_type switch
!
interface GigabitEthernet1/0/11
dot1x authentication 802.1x mac
dot1x port-control auto
!
interface GigabitEthernet1/0/12
dot1x authentication 802.1x mac
dot1x port-control auto
!
interface GigabitEthernet1/0/13
dot1x authentication 802.1x mac
dot1x port-control auto
!
interface GigabitEthernet1/0/14
dot1x authentication 802.1x mac
dot1x port-control auto
!
interface GigabitEthernet1/0/15
dot1x authentication 802.1x mac
dot1x port-control auto
!
interface GigabitEthernet1/0/16
dot1x authentication 802.1x mac
dot1x port-control auto
!
interface GigabitEthernet1/0/17
dot1x authentication 802.1x mac
dot1x port-control auto
!
interface GigabitEthernet1/0/18
dot1x authentication 802.1x mac
dot1x port-control auto
!
interface GigabitEthernet1/0/19
dot1x authentication 802.1x mac
dot1x port-control auto
!
interface GigabitEthernet1/0/20
dot1x authentication 802.1x mac
dot1x port-control auto
!
interface GigabitEthernet1/0/21
dot1x authentication 802.1x mac
dot1x port-control auto
!
interface GigabitEthernet1/0/22
dot1x authentication 802.1x mac
dot1x port-control auto
!
interface GigabitEthernet1/0/23
dot1x authentication 802.1x mac
!
interface TenGigabitEthernet1/0/1
spanning-tree link-type point-to-point
switchport mode trunk
switchport trunk allowed vlan 1,20
macro description switch
!next command is internal.
macro auto smartport dynamic_type switch
!
exit
macro auto controlled

config-file-header
IT-CBS350-24T
v3.3.0.16 / RCBS3.3_950_377_202
CLI v1.0
file SSD indicator encrypted
@
ssd-control-start
ssd config
ssd file passphrase control unrestricted
no ssd file integrity control
ssd-control-end cb0a3fdb1f3a1af4e4430033719968c0
!
!
unit-type-control-start
unit-type unit 1 network gi uplink te
unit-type unit 2 network gi uplink te
unit-type unit 3 network gi uplink te
unit-type unit 4 network gi uplink te
unit-type-control-end
!
vlan database
vlan 20
exit
voice vlan state auto-triggered
voice vlan oui-table add 0001e3 Siemens_AG_phone
voice vlan oui-table add 00036b Cisco_phone
voice vlan oui-table add 00096e Avaya
voice vlan oui-table add 000fe2 H3C_Aolynk
voice vlan oui-table add 0060b9 Philips_and_NEC_AG_phone
voice vlan oui-table add 00d01e Pingtel_phone
voice vlan oui-table add 00e075 Polycom/Veritel_phone
voice vlan oui-table add 00e0bb 3Com_phone
dot1x system-auth-control
dot1x mac-auth eap username groupsize 2 separator : lowercase
bonjour interface range vlan 1
hostname IT-CBS350-24T
encrypted radius-server host xxxkey xx
aaa accounting dot1x start-stop group radius
passwords aging 180
username
ip telnet server
!
interface vlan 1
ip address 10.5.19.70 255.255.255.0
no ip address dhcp
!
interface GigabitEthernet1/0/1
dot1x authentication 802.1x mac
dot1x port-control auto
spanning-tree link-type point-to-point
macro description switch
!next command is internal.
macro auto smartport dynamic_type switch
!
interface GigabitEthernet1/0/2
dot1x authentication 802.1x mac
dot1x port-control auto
!
interface GigabitEthernet1/0/3
dot1x authentication 802.1x mac
dot1x port-control auto
spanning-tree link-type point-to-point
macro description switch
!next command is internal.
macro auto smartport dynamic_type switch
!
interface GigabitEthernet1/0/4
dot1x authentication 802.1x mac
dot1x port-control auto
!
interface GigabitEthernet1/0/5
dot1x authentication 802.1x mac
dot1x port-control auto
!
interface GigabitEthernet1/0/6
dot1x authentication 802.1x mac
dot1x port-control auto
!
interface GigabitEthernet1/0/7
dot1x authentication 802.1x mac
dot1x port-control auto
!
interface GigabitEthernet1/0/8
dot1x authentication 802.1x mac
dot1x port-control auto
!
interface GigabitEthernet1/0/9
dot1x authentication 802.1x mac
switchport access vlan 20
switchport trunk native vlan 20
switchport trunk allowed vlan 20
!
interface GigabitEthernet1/0/10
dot1x authentication 802.1x mac
spanning-tree link-type point-to-point
switchport access vlan 20
switchport general pvid 20
switchport trunk native vlan 20
macro description switch
!next command is internal.
macro auto smartport dynamic_type switch
!
interface GigabitEthernet1/0/11
dot1x authentication 802.1x mac
dot1x port-control auto
!
interface GigabitEthernet1/0/12
dot1x authentication 802.1x mac
dot1x port-control auto
!
interface GigabitEthernet1/0/13
dot1x authentication 802.1x mac
dot1x port-control auto
!
interface GigabitEthernet1/0/14
dot1x authentication 802.1x mac
dot1x port-control auto
!
interface GigabitEthernet1/0/15
dot1x authentication 802.1x mac
dot1x port-control auto
!
interface GigabitEthernet1/0/16
dot1x authentication 802.1x mac
dot1x port-control auto
!
interface GigabitEthernet1/0/17
dot1x authentication 802.1x mac
dot1x port-control auto
!
interface GigabitEthernet1/0/18
dot1x authentication 802.1x mac
dot1x port-control auto
!
interface GigabitEthernet1/0/19
dot1x authentication 802.1x mac
dot1x port-control auto
!
interface GigabitEthernet1/0/20
dot1x authentication 802.1x mac
dot1x port-control auto
!
interface GigabitEthernet1/0/21
dot1x authentication 802.1x mac
dot1x port-control auto
!
interface GigabitEthernet1/0/22
dot1x authentication 802.1x mac
dot1x port-control auto
!
interface GigabitEthernet1/0/23
dot1x authentication 802.1x mac
!
interface TenGigabitEthernet1/0/1
spanning-tree link-type point-to-point
switchport mode trunk
switchport trunk allowed vlan 1,20
macro description switch
!next command is internal.
macro auto smartport dynamic_type switch
!
exit

I have added it twice but it keeps getting removed from here for some reason.

You can save the config in a txt file and attach file here.

But I could see your config. This diagram below is what you are trying to accomplish right?

What I would recommend is first clean up the interfaces involved.

conf t

default interface <interface>

Then, config the interface with the minimum necessary

Interfaces between switches:

conf t

int gx/x

switch port mode trunk

Interface between switches and PCs.

conf t

int gx/x

switchport mode acess

switch access vlan 20

 

 

 

FlavioMiranda_0-1688572204238.png

 

Let's see if this works. Here is what I think you want to see:

Switch 1

VLAN Setup:
!
interface vlan 1
ip address 10.5.19.70 255.255.255.0
no ip address dhcp
!
interface vlan 30
name Test
!


Trunk Port:
!
interface TenGigabitEthernet1/0/1
spanning-tree link-type point-to-point
switchport mode trunk
switchport trunk allowed vlan 1,30
macro description switch
!next command is internal.
macro auto smartport dynamic_type switch
!

Access Port:
!
interface GigabitEthernet1/0/10
dot1x authentication 802.1x mac
spanning-tree link-type point-to-point
switchport access vlan 30
switchport general pvid 30
switchport trunk native vlan 30
macro description switch
!next command is internal.
macro auto smartport dynamic_type switch
!


Switch 2

!
interface vlan 1
ip address 192.168.168.1 255.255.255.0
no ip address dhcp
!
interface vlan 30
name Test
!

Trunk Port:
!
interface TenGigabitEthernet1/0/22
switchport mode trunk
switchport trunk allowed vlan 1,30
!

Access Port
!
interface TenGigabitEthernet1/0/24
speed 1000
switchport access vlan 30
switchport general pvid 30
switchport trunk native vlan 30
!



!
interface TenGigabitEthernet1/0/1
spanning-tree link-type point-to-point
switchport mode trunk
switchport trunk allowed vlan 1,20
macro description switch
!next command is internal.
macro auto smartport dynamic_type switch
!

 

Thanks.

 First you need to device by vlan 20 or 30.  Initially you mentioned 20.

If you want to make the switch as layer3, which means the switch will have IP address on the vlan and differents vlans to communicate, you need to run the command:

conf t

ip routing

Then, on the vlan you need to do:

int vlan 20

 ip add x.x.x. x x.x (choose the ip address and mask)

Do it on both switches. Keep in mind that vlan 1 will not participate on this.

I will give here and example

Switch 1

conf t

int vlan 20

ip add 192.168.20.1 255.255.2550

switch 2

int vlan 20

ip add 192.168.20.2 255.255.255.0

Use the IP add 192.168.20.3 and 192.168.20.4 on the PCs.

For the interface config, use the following example

conf t

default interface <interface>

Then, config the interface with the minimum necessary

Interfaces between switches:

conf t

int gx/x

switch port mode trunk

Interface between switches and PCs.

conf t

int gx/x

switchport mode acess

switch access vlan 20

 

 

I changed it to 30 testing. End result I just want 1 port on each switch to be able to communicate with each other on VLAN 30. Does this require Layer 3 if I do not need any other subnets to route to this? It doesn't seem to be as hard and it is being for me!

It does not required layer3 on the switch

You need to create vlan 30 on both switch

Add vlan 30 on trunk between switches

You need to put both PC interface on vlan 30

Add IP on PCs.

Thats it.

I feel like that is exactly what I am doing. Your diagram looks like what I want. I will try what you suggested and keep you posted. Thanks for the help so far!

Review Cisco Networking for a $25 gift card