02-08-2008 12:32 PM - edited 03-05-2019 09:02 PM
Hi,
I am very new to Cisco hardware and VLANs in general. We have a very simple network setup (ASA5510 set up as a router/firewall and many switched of which I am only trying to deal with a Cisco Catalyst 2960).
WHat I was hoping to do without any additional wiring is to add a VLAN for an AP that would be used for guest access to the internet, but not the internal network.
So on the ASA i created a subinterface off of the main inside interface and on the 2960 I created a new VLAN. Then i tried to configure the port on the 2960 to which the ASA is connected as a trunk port, but at that moment everybody loses the connection to the outside.
Basically, where can i find any documentation on how to properly set this up with the hardware I have.
I am sure i am missing many things, but I do need some guidance.
Thank you
02-11-2008 12:43 PM
tboard#show interface trunk
Port Mode Encapsulation Status Native vlan
Gi0/12 on 802.1q trunking 200
Port Vlans allowed on trunk
Gi0/12 200
Port Vlans allowed and active in management domain
Gi0/12 200
Port Vlans in spanning tree forwarding state and not pruned
Gi0/12 200
tboard#
02-11-2008 12:45 PM
ASA
!
interface Ethernet0/2
description Trunk Only!!!! DO NOT CONFIGURE
speed 100
duplex full
nameif dmz
security-level 10
no ip address
!
interface Ethernet0/2.200
description WiFi DMZ
vlan 200
nameif WIFI
security-level 10
ip address 192.168.2.1 255.255.255.0
!
02-11-2008 12:49 PM
switch
I use port 13 to connect my laptop with a hardcoded IP of 192.168.2.100
tboard#sh running-config interface gig 0/12
Building configuration...
Current configuration : 197 bytes
!
interface GigabitEthernet0/12
description ASA_DMZ
switchport trunk native vlan 200
switchport trunk allowed vlan 200
switchport trunk pruning vlan none
switchport mode trunk
speed 100
end
tboard#sh running-config interface gig 0/13
Building configuration...
Current configuration : 124 bytes
!
interface GigabitEthernet0/13
switchport access vlan 200
switchport trunk allowed vlan 200
switchport mode access
end
02-11-2008 01:47 PM
based on what i posted do you see anything obvious I am missing?
02-12-2008 12:03 PM
That looks OK, can you post the interface config on the FW?
02-12-2008 12:11 PM
please look at the post titled ASA...
But i don't believe that is the problem, at least not yet.
I tried to ping my laptop when i had it plugged in the switch at port 0/13 and got timed out. I pinged it from the switch itself, so i have to have something messed up with the port config on the switch
02-12-2008 12:19 PM
Oops sorry. The IP on the laptop was in the 192.168.2.0/24 network right? Can you give the switch an IP or are you managing it in-band (ie Telnet/SSH)?
02-12-2008 12:23 PM
hehe, now you are pointing out something obvious that I missed.
the switch does have an ip 192.168.1.8.
question is how does that affect this whole scenario, if at all?
02-12-2008 12:25 PM
None really. I'm assuming your using a layer 2 switch and hence can have only 1 IP address. The 192.168.1.8 is part of your management domain. If you have a L3 switch you can have multiple IP addresses on the switch and you could configure vlan 200 with an IP and we could test directly from the switch instead of the laptop. The laptop was int 192.168.2.0/24 right?
02-12-2008 12:28 PM
yes it is a L2 switch 2960 model.
the laptop and the VLan were configured for .2.0/24
02-12-2008 12:40 PM
Hmmm. What version of OS is on the ASA? Can you post a show interface for the ASA?
02-12-2008 12:44 PM
Add this to your ASAs interface.
switchport mode trunk
switchport trunk allowed vlan 200
02-12-2008 12:47 PM
0/2 or 0/2.200
02-12-2008 12:51 PM
0/2
02-12-2008 12:58 PM
can't. the switchport command doesn't appear to exist. i tried it on config-if and just config
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide