We have L3 switch with VLAN 10,20, and 30. There are no interfcaes for VLAN 20 and 30 on this L3 switch. But interfces are created with IP addresses. Other L2 switches are connected by trunk to this L3 switch. On L3 switch there are interfaces only with VLAN 10. One interface connectd in VLAN 10 is firewall. Hosts in VLAN 20 and 30 have their default gateway as L3 switch VLAN interface. Devices from VLAN 20 and VLAN 30 can communicate with eachn other - inter VLAN routing is working. Now we need to forward traffic to firewall from L3 switch which belongs to internet and not VLAN 20 and 30.
So the interface connected to firewall which is memeber of VLAN 10 group need to be in trunk ?
In my opinion when L3 switch is forwarding the frame to firewall it will remove the VLAN-tag-id from frame and will forward that frame to firewall as if the firewall is next hop router. ( It will send a untagged frame to firewall then firewall will NAT-PAT and will send it to internet, also firewall will have reverse route for VLAN 20 and VLAN 30 subnet ).
- You have an IP address assigned to the Firewall. The firewall has been connected to the interface on the L3 switch with the access port of vlan 10.
- Create a default route pointing to the IP address of the Firewall.
Edit: What you thought is right. Untagged frames will be sent to the firewall. You just have to make sure that there is a route to forward packets out to the firewall. However, If I were you, I will design a new network to connect to the firewall. I properly use a routed port to do so. No need to send any broadcast traffic from vlan 10 to it. If the interface on the firewall is the routed port, I don't see any reason to send BPDUs to it. That's why I'd better create a new network to connect them together and use a routed port on L3 Switch.
This is actually a pretty cool feature, i didn't even know it existed until I was looking for a solution to advertise a subnet (prefix in BGP talk), only if a certain condition existed. This is exactly what conditional advertisements does
j ai une question j ai achete un routeur cisco 887VA-k9 , je le configuré avec la configuration ci- dessous
si je le lier avec mon pc portable sur l un de ses ports directement ça marche toute est bien ( la connexion internet + m...
Attached policy provides CLI access to the Cisco 4G router over text messaging. Two files are in the attached .tar file:
2. PDF with instructions on how to load and use the .tcl file.