Jump to content

Recommended Posts

Posted
Do note that if there are no ACTIVE ports in a vlan (either a client or switch/switch port with the VLAN tagged *and* plugged in), then it will not be activated and you won't be able to ping its gateway IP etc.
Posted
Guess what, Windows f****** Firewall! For anyone looking at this I would say everything up to post #41 (& #48) is all good advice. My issue was that when I originally created the VLANs the switch did not create entries in the routing table for them. I resolved this by simply deleting and recreating the VLANs, they then showed in the routing table as expected. Everything from post #42 onwards was because Windows firewall had been turned back on. Many thanks to @FN-GM, @themightymrp, @IrritableTech & @simpsonj for their help on this.

 

Woo hoo! I bet that is relief for you! :)

Posted
Woo hoo! I bet that is relief for you! :)

 

Just a bit. I have cracked on now; I have all my DHCP scopes, switches configured, Aerohive tagging VLAN traffic and Smoothwall filtering as expected. Just playing now trying to break it as a user, so far no luck :D

Posted
Just a bit. I have cracked on now; I have all my DHCP scopes, switches configured, Aerohive tagging VLAN traffic and Smoothwall filtering as expected. Just playing now trying to break it as a user, so far no luck :D

 

If you get time shift everything off VLAN 1 :)

Posted

Glad you got it sorted :) Windows Firewall only clicked for me when i tried to ping the client from the switch and it wasn't working, and then my techie asked whether I'd turned the firewall off or not...

 

When you get down to it, the tricky parts are making sure that everything is documented, and inputting the IP helper command on the HP switches (Why that isn't part of the web console I don't know...). Once they are in place, vLanning isn't as daunting as it first appears. Mind you, I've still got a host of switches to setup with the new vLan, so I'll not count my chickens just yet!

 

Also, I had to contact Virgin to get them to make the virtual switch (or IP route) for the new vLan, which had to be outside the existing subnet (they had set it to 10.104.0.0/16), just in case this of any use to someone with a virgin setup and Palo Alto managed router/firewall. Their support was actually quite helpful, but it does help if you know what you're talking about (which I can only half claim!).

 

I think I'll be blogging about this later, if only to ensure it's all in my head when I inevitable come back to expand my vLans later.

  • 4 months later...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...