|
|
Question : Problem: I need to know how to configure a 3560-g switch with 2 VLANs and ACLs.
|
|
I currently have a star network. I have two layer 2 switches in production currently, 1 is a Cisco 2960 and the other is a 3Com. They receive their IPs via DHCP from our PIX. I want to know if I can add the Cisco 3560 in the daisy chain via port 1, configure ports 39-48 on VLAN 2, and still use ports 1-38 on the default VLAN (which currently is unmanaged.) I want to allow the entire VLAN 2 (192.168.1.0/24) to access all of VLAN 1 (192.168.0.0/24) however, I only want to allow a few IPs on VLAN 1 to access VLAN 2.
Currently I have ports 39-48 on VLAN2. I have assigned VLAN2 the IP of 192.168.1.1. I have not done any configuring of ACLs or of VLAN 1. The current gateway of VLAN 1 is our PIX, which is 192.168.0.2 (I know it should be .1, but it was configured before my time.) I have not tried to hook this up yet, but my expected result is the first 38 ports should act as if they were daisy chained and will continue to hand out IP addresses on the 0.0/24 network. I am only putting devices with static IPs on the VLAN2 so that I don't have to configure DHCP.
Can someone please either derail me if I am nuts, or give some help to continue the configuration of my ACLs. Thanks.
|
Answer : Problem: I need to know how to configure a 3560-g switch with 2 VLANs and ACLs.
|
|
The VLAN 1 devices on the 3560 will work fine. The VLAN 2 devices, however, won't... Unless you create a route on the PIX so it knows that the 192.168.1.0/24 network is accessible by going to the VLAN 1 interface of the 3560.
As for the ACL, you would use a standard ACL applied either inbound on the VLAN 1 interface of the 3560 or outbound on the VLAN 2 interface.
|
|
|
|