silvestre Posted October 8, 2020 Posted October 8, 2020 (edited) Hi All we are in the process of creating VLAN's and lgfl have told us that they will need to create a stub network on the firewall. They have now deployed a 10.24.*.0/30 stub network routing 10.24.*.0/22 to 10.24.*.2 . Please can someone explain what i will need to do at my end? I currently have my Management vlan on /28 network which has the core switch 10.24.*.2 . they have now said LGFL COMMENT - "They now can see a capture on the firewall 10.24.*.1 which according to them indicates devices outside the 10.24.*.0/30 stub network are on the same vlan/broadcast domain. This should not be the case and indicates that the IP interface of the switch is not using a /30 mask on a different VLan to the internal ranges." Does anyone know what this means? and how to fix? Do i have to put the core on /30. I have two other stacks on /27 We have no internet for 2 days .. Please help :-( Many Thanks Edited October 8, 2020 by silvestre
gh5000 Posted October 8, 2020 Posted October 8, 2020 @PaddyNewman should be able to help. If I talk through one of our schools setup it may help. Have two separate /21 LGFL 10.* Ranges available to us. E.g. lgfl router is on 10.10.10.1 We then set a vlan on our core L3 switch on 10.10.10.2 with a really small subnet like /29 We tell LGfL that they should pass everything to 10.10.10.2. We then segment the rest of the /21 ranges into smaller vlans. Staff WiFi, wired computers, KS3 WiFi, etc. Those vlans are setup in the core switch with appropriate ports tagged to route to other edge switches and end user ports What is your core switch? Don't know how much more info I need to give you. Happy to look at your core switch config.
silvestre Posted October 8, 2020 Author Posted October 8, 2020 @gh5000 Our lgfl router is is 10.24.*.1 and Core is 10.24.*.2/28 in which we have the other edge switches as well. LGFL have created a /30 stub network to route everything to 10.24.*.2 Have i made a mistake in putting all switches in /28 , should i just have core in /30? Do you have your edge switches in the /30 range or just the core? and another vlan for the edge switches? Thank you
gh5000 Posted October 9, 2020 Posted October 9, 2020 @gh5000 Our lgfl router is is 10.24.*.1 and Core is 10.24.*.2/28 in which we have the other edge switches as well. LGFL have created a /30 stub network to route everything to 10.24.*.2 Have i made a mistake in putting all switches in /28 , should i just have core in /30? Do you have your edge switches in the /30 range or just the core? and another vlan for the edge switches? Thank youI think the two subnets would need to match but I'm not a networking expert by any means. I know the how but not the why fully! But that would be my first guess. But yes I've just got the core in the stub network. Without knowing your school a /28 is quite small for all your current and future edge switches. I have edge switches (and wifi, and printers and VoIP) on subnets that are outside of LGfLs provided ranges. These devices don't get internet access and it saves internet accessible IPs for other use. How far can you ping from a computer. Can it get to the vlan gateway? To the core switch on 10.24.*.2? To the VM box on 10.24.*.1? If yes to all your internal config is probably ok and it's just the stub subnets not being the same.
RobD Posted October 9, 2020 Posted October 9, 2020 My suggestion would be draw it out. You could do something like this? i.e. vlan 10 - between core and LGFL LGFL - 10.24.1.1 Core - 10.24.1.2 Then have a new for you edge switches vlan 100 - between core and the switches Core - 10.24.2.2 edge - 10.24.2.3
silvestre Posted October 9, 2020 Author Posted October 9, 2020 @gh5000 and @RobD many thanks for your help. I have the most of the work done and internet seems to be working fine. But i get loads of errors like VALID Duplicated in some of the vlans. Have you guys come across this?
Primus Posted October 10, 2020 Posted October 10, 2020 You've got duplicated IP addresses - are there any devices on statics that could be conflicting? How many DHCP servers are you using.
silvestre Posted October 11, 2020 Author Posted October 11, 2020 I have just one DHCP server running.
silvestre Posted October 11, 2020 Author Posted October 11, 2020 Is anyone willing to help me if i send the configs?
silvestre Posted October 13, 2020 Author Posted October 13, 2020 Thanks guys i have finally sorted this out. Now just issues with cambium remain. I will open another thread for the cambium
Primus Posted October 13, 2020 Posted October 13, 2020 Thanks guys i have finally sorted this out. Now just issues with cambium remain. I will open another thread for the cambium For the benefit of anyone who has similar issues in the future could you explain how you sorted it?
silvestre Posted October 14, 2020 Author Posted October 14, 2020 So we had an issue with the same VLAN IP on all switches. I removed everything from the core and the minute i plugged in the first stack i would get loads of duplicate IP's. if the VLAN IP on the edge switch is the same as the core it will give you a duplicate IP. We then changed the VLAN IP to a new IP in the subnet. VLAN was designed like below vlan 10 - between core and LGFL LGFL - 10.24.1.1 - Core - 10.24.1.2 /30 subnet Management /29 Subnet for eg. core -10.24.1.9 Stack 1 10.24.1.11 Stack 2 10.27.1.13 Previously it was Management /29 Subnet for eg. core -10.24.1.9 Stack 1 10.24.1.9 Stack 2 10.27.1.9 - So we were getting a duplicate IP across all VLANS as we had the same design across all.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now