cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
748
Views
0
Helpful
17
Replies

Mulitple vlan support in one single port

Anand Narayana
Level 6
Level 6

Is it possible to have multiple vlans in single port? Current configuration what i have is "switchport access vlan2" which means if a vlan3 users wanted to connect on this same port, I will have change the configuration as "switchport access vlan3" every time & vice versa. This is required for me to have this achieve in the conference room network ports in my office where multiple users from various vlan's often connects & every time I will have to change the port settings manually

17 Replies 17

burleyman
Level 8
Level 8

Yes and no....you can have two vlans on one port but only one for Data and the other for VoIP, but you can't have two differnt VLAN's for data or even two different VLAN's for VoIP.

Do all your people have static IP addresses? Also are they in different VLAN for security reasons?

Mike

Multiple vlans YES, because for security reason as vlan 2 uses should access all vlans & vlan 3 should access only internet.

All users will get IP address from DHCP server using ip helper-address.

Some of the latest port security stuff supports access port VLAN assignment based on user authenication (non-authenicated users get a guest VLAN).

Leo Laohoo
Hall of Fame
Hall of Fame

How about configuring the ports as Dot1Q Trunk and specifying what VLANs are allowed?

Leo,

That was really a good thought. Lemme try this morning & will come back with the test result :-)

Unfortunately it never worked & ended up with unsuccessful result :-(

Pronoy Dasgupta
Cisco Employee
Cisco Employee

what switch are you using?

Pronoy

I use WS-C2960-48TT-L & the IOS is

c2960-lanbase-mz.122-35.SE5.bin

Leo Laohoo
Hall of Fame
Hall of Fame

Ok, now you getting my curiosity. Any switch can do Dot1Q. Can you elaborate why it's not working?

"switcport trunk encapsulation dot1q" & is found in my 3650 but in 2960 "switchport mode trunk" is alone found. Could that be a limitation in 2960 switch?

Ahhhh ... The 2950 and 2960 switch will only support Dot1Q encapsulation. This is why the command "switchport trunk encapsulation dot1q" doesn't exist on these two models.

If you enter the command "sh interface switch" you'll see the default is Dot1Q.

Leo,

I found a better way to acheive this by implementing VMPS. But I really appreciate for your continuious suggestion :-)/

However, VMPS demands a CatOS device somewhere and is an old feature which Cisco is not supporting going forward (as CatOS is deprecated).

See also this article:

http://www.networkworld.com/community/node/42923?source=NWWNLE_nlt_daily_am_2009-06-24

The way forward will be to look into NAC.

HTH

bflseanny
Level 1
Level 1

Just out of curiosity: do your users bring laptops to the conference room and have to connect into your switch?

Are the clients assigned to a VLAN in the operating system?

Please describe your scenario more for the sake of wisdom. I'd like to know what to think about if I have to approach such a situation in the future.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card