DMcCoy Posted August 11, 2015 Posted August 11, 2015 Do note that if there are no ACTIVE ports in a vlan (either a client or switch/switch port with the VLAN tagged *and* plugged in), then it will not be activated and you won't be able to ping its gateway IP etc.
FN-GM Posted August 11, 2015 Posted August 11, 2015 Guess what, Windows f****** Firewall! For anyone looking at this I would say everything up to post #41 (& #48) is all good advice. My issue was that when I originally created the VLANs the switch did not create entries in the routing table for them. I resolved this by simply deleting and recreating the VLANs, they then showed in the routing table as expected. Everything from post #42 onwards was because Windows firewall had been turned back on. Many thanks to @FN-GM, @themightymrp, @IrritableTech & @simpsonj for their help on this. Woo hoo! I bet that is relief for you!
foofighterjim Posted August 11, 2015 Author Posted August 11, 2015 Woo hoo! I bet that is relief for you! Just a bit. I have cracked on now; I have all my DHCP scopes, switches configured, Aerohive tagging VLAN traffic and Smoothwall filtering as expected. Just playing now trying to break it as a user, so far no luck
FN-GM Posted August 11, 2015 Posted August 11, 2015 Just a bit. I have cracked on now; I have all my DHCP scopes, switches configured, Aerohive tagging VLAN traffic and Smoothwall filtering as expected. Just playing now trying to break it as a user, so far no luck If you get time shift everything off VLAN 1
foofighterjim Posted August 11, 2015 Author Posted August 11, 2015 If you get time shift everything off VLAN 1 I might have a look during the October half term, there is no way I'm messing with the wired traffic this close to exam results!
simpsonj Posted August 11, 2015 Posted August 11, 2015 Glad you got it sorted Windows Firewall only clicked for me when i tried to ping the client from the switch and it wasn't working, and then my techie asked whether I'd turned the firewall off or not... When you get down to it, the tricky parts are making sure that everything is documented, and inputting the IP helper command on the HP switches (Why that isn't part of the web console I don't know...). Once they are in place, vLanning isn't as daunting as it first appears. Mind you, I've still got a host of switches to setup with the new vLan, so I'll not count my chickens just yet! Also, I had to contact Virgin to get them to make the virtual switch (or IP route) for the new vLan, which had to be outside the existing subnet (they had set it to 10.104.0.0/16), just in case this of any use to someone with a virgin setup and Palo Alto managed router/firewall. Their support was actually quite helpful, but it does help if you know what you're talking about (which I can only half claim!). I think I'll be blogging about this later, if only to ensure it's all in my head when I inevitable come back to expand my vLans later.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now