VLANS trunking

Jun 14, 2006 10 Replies

Hi

I have following netowork:

VLAN1 VLAN1 VLAN2 VLAN2 VLAN1 VLAN1 host1--------------switch1-------------switch2-------------host2

Everything ports are in trunking mode. If I send packet from host1 to host2 I want to stop packet on switch1. Is this scheme OK? Or how to reorganize configuration (where to place trunk or access mode) If it isn't correct .

Hi

I have following netowork:

VLAN1 VLAN1 VLAN2 VLAN2 VLAN1 VLAN1 host1--------------switch1-------------switch2-------------host2

Everything ports are in trunking mode. If I send packet from host1 to host2 I want to stop packet on switch1. Is this scheme OK? Or how to reorganize configuration (where to place trunk or access mode) If it isn't correct .

Hi

I have following netowork:

VLAN1 VLAN1 VLAN2 VLAN2 VLAN1 VLAN1 host1--------------switch1-------------switch2-------------host2

Everything ports are in trunking mode. If I send packet from host1 to host2 I want to stop packet on switch1. Is this scheme OK? Or how to reorganize configuration (where to place trunk or access mode) If it isn't correct .

Hi



I have following netowork:


VLAN1 VLAN1 VLAN2 VLAN2 VLAN1 VLAN1 host1--------------switch1-------------switch2-------------host2



Everything ports are in trunking mode. If I send packet from host1 to host2 I want to stop packet on switch1. Is this scheme OK? Or how to reorganize configuration (where to place trunk or access mode) If it isn't correct .


Unless you trunk VLAN 1 between switch1 and switch2 hosts 1 and 2 can't communicate.

BernieM

Only a port of sw1 and corrispective connection on sw2 need to be in trunking mode, other ports on sw1 and sw2 can be inserted on VLAN1 or VLAN2. SW1 and SW2 are joined by trunk in the same logical switch that contain the two differents VLANs

If you want stoping packets transmit from host1 to host2 you need insert by two hosts a router with a specific ACL for the two IP address by host1 and host2 to deny traffic....or simple move an host in other VLAN2!!! ;)))

Vlan 1 is generally untagged so it should go through, depending on the switches' OS/mfr

It means that connection switch1 and switch2 shouldn't have trunk mode?

How will work above scheme If I turn on every port in access mode ?

U¿ytkownik "jw" napisa³ w wiadomo¶ci news:3x0kg.467$ snipped-for-privacy@ursa-nb00s0.nbnet.nb.ca...

For example on Cisco Catalyst 2950 how to this work for VLAN1?

Oh, ok thanks, wasn't aware of that. So for the requirement to "stop packets on switch 1" there's going to have to be some form of layer-3 security ie. acl etc.

BernieM

From what jw was saying I was incorrect so traffic should pass from host1 to host2 with a trunk between switch1 and switch2 regardless of whether vlan 1 is specifically trunked. To 'stop packets on switch1' you're going to need some form of IP or mac-based acl.

BernieM

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required