Hi there, I have this infrastructure:
5 catalyst 2950G with 24 F.Eth. ports and 2 Gigabit ports 1 catalyst 3508G-XL 8 Gbit ports 1 router 1721 with ADSL module 1 pix 506e around 240 windows PC with a static IP like 10.155.254.0/24 there's also a old 3620 router that I can use if necessaryThe five 2950 are connected to the 3508 with optic fibre calbes. The 1721 router is connected to one of the f.e. ports on one of the 2950 and "gets out" to the internet with an ADSL module (has also an internet static ip). Considered that I'm already quite confused, I did not used the pix yet ;-)
My aim is this: - to create 6 vlans to limit broadcast domains: each VLAN should include all the ports of one of the 5 switches. Except for the switch to which the router is connected, that has to be divided in 2 vlans. - to let all the PCs accessing the internet throught the router - to let all the PCs reaching any other PC on the lan (I know that this decision is quite stupid :-) )
In short, all this mess is to start segmenting a too much grown lan by using layer 3.
I should respect these bindings: - NOT to change any of the IP addresses of the connected PCs - to limit as much as possible the load on the router that is already quite busy letting all those PCs surfing on the web ;-)
I managed to accomplish only a part of the work:
1) to configure every Gbit port as a 802.1q trunk link 2) to configure the port to which is attached the router as a 802.1q trunk link 3) to assign all the ports on the first 2950 to VLAN 1 (static access) 4) to assign all the ports on the second 2950 to VLAN 2 (static access) 5) to assign all the ports on the third 2950 to VLAN 3 (static access) 6) to assign all the ports on the fourth 2950 to VLAN 4 (static access) 7) to assign the first 12 ports on the fifth 2950 to VLAN 5 (static access) 8) to assign the remaining 11 ports on the fifth 2950 to VLAN 5 (static access) [the last port is the trunk link to the router]I have some questions: - only PCs conncted to the same switch of the router can access the internet. why? Aren't trunk link accessible by every VLAN? - how do I connect all the VLANs each other, considered that the 3508 can't (I think) do interVLAN routing and that the router isn't (I think) powerful enought to do all the routing? - if I assign to two VLANs, two IPs like 10.155.254.0/24 the catalyst puts one vlan in shutdown mode: where can I read why this is happening? - is there another way to limit broadcast domains without doing all this mess? ;-) - where do I find something to study about "routing-on-a-stick"? It seems to me that this can be useful for my case. - how much the situation grows difficult if I replace the router with the pix and I put the router "behind" the pix (the pix serves only as a basic firewall protection for the web)?
I know that these are a lot of questions and that many of them are quite dumb but please help me anyway. Thanks a lot!
blu_aqua