Jump to content

Recommended Posts

Posted (edited)

Hi All

 

we are in the process of creating VLAN's and lgfl have told us that they will need to create a stub network on the firewall.

They have now deployed a 10.24.*.0/30 stub network routing 10.24.*.0/22 to 10.24.*.2 . Please can someone explain what i will need to do at my end?

 

I currently have my Management vlan on /28 network which has the core switch 10.24.*.2 . they have now said

 

LGFL COMMENT - "They now can see a capture on the firewall 10.24.*.1 which according to them indicates devices outside the 10.24.*.0/30 stub network are on the same vlan/broadcast domain. This should not be the case and indicates that the IP interface of the switch is not using a /30 mask on a different VLan to the internal ranges."

 

Does anyone know what this means? and how to fix? Do i have to put the core on /30. I have two other stacks on /27

 

We have no internet for 2 days .. Please help :-(

 

Many Thanks

Edited by silvestre
Posted

@PaddyNewman should be able to help.

 

If I talk through one of our schools setup it may help.

 

Have two separate /21 LGFL 10.* Ranges available to us.

 

E.g. lgfl router is on 10.10.10.1

We then set a vlan on our core L3 switch on 10.10.10.2 with a really small subnet like /29

 

We tell LGfL that they should pass everything to 10.10.10.2.

 

We then segment the rest of the /21 ranges into smaller vlans. Staff WiFi, wired computers, KS3 WiFi, etc. Those vlans are setup in the core switch with appropriate ports tagged to route to other edge switches and end user ports

 

What is your core switch?

Don't know how much more info I need to give you. Happy to look at your core switch config.

Posted

@gh5000 Our lgfl router is is 10.24.*.1 and Core is 10.24.*.2/28 in which we have the other edge switches as well. LGFL have created a /30 stub network to route everything to 10.24.*.2

 

Have i made a mistake in putting all switches in /28 , should i just have core in /30?

 

Do you have your edge switches in the /30 range or just the core? and another vlan for the edge switches?

 

Thank you

Posted
@gh5000 Our lgfl router is is 10.24.*.1 and Core is 10.24.*.2/28 in which we have the other edge switches as well. LGFL have created a /30 stub network to route everything to 10.24.*.2

 

Have i made a mistake in putting all switches in /28 , should i just have core in /30?

 

Do you have your edge switches in the /30 range or just the core? and another vlan for the edge switches?

 

Thank you

I think the two subnets would need to match but I'm not a networking expert by any means. I know the how but not the why fully! But that would be my first guess.

 

But yes I've just got the core in the stub network.

 

Without knowing your school a /28 is quite small for all your current and future edge switches.

 

I have edge switches (and wifi, and printers and VoIP) on subnets that are outside of LGfLs provided ranges. These devices don't get internet access and it saves internet accessible IPs for other use.

 

How far can you ping from a computer. Can it get to the vlan gateway? To the core switch on 10.24.*.2? To the VM box on 10.24.*.1? If yes to all your internal config is probably ok and it's just the stub subnets not being the same.

Posted

My suggestion would be draw it out.

 

You could do something like this?

 

i.e.

vlan 10 - between core and LGFL

LGFL - 10.24.1.1

Core - 10.24.1.2

 

Then have a new for you edge switches

vlan 100 - between core and the switches

Core - 10.24.2.2

edge - 10.24.2.3

vlan.PNGvlan.PNG

Posted
@gh5000 and @RobD many thanks for your help. I have the most of the work done and internet seems to be working fine. But i get loads of errors like VALID Duplicated in some of the vlans. Have you guys come across this?
Posted
Thanks guys i have finally sorted this out. Now just issues with cambium remain. I will open another thread for the cambium

 

For the benefit of anyone who has similar issues in the future could you explain how you sorted it?

Posted

So we had an issue with the same VLAN IP on all switches. I removed everything from the core and the minute i plugged in the first stack i would get loads of duplicate IP's. if the VLAN IP on the edge switch is the same as the core it will give you a duplicate IP. We then changed the VLAN IP to a new IP in the subnet.

 

VLAN was designed like below

 

 

vlan 10 - between core and LGFL

LGFL - 10.24.1.1 - Core - 10.24.1.2 /30 subnet

 

Management /29 Subnet for eg. core -10.24.1.9 Stack 1 10.24.1.11 Stack 2 10.27.1.13

 

Previously it was Management /29 Subnet for eg. core -10.24.1.9 Stack 1 10.24.1.9 Stack 2 10.27.1.9 - So we were getting a duplicate IP across all VLANS as we had the same design across all.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...