VLAN trunking на Cisco ASA

* VLAN Trunking (ASA 5510, ASAOS 7.2.1)

Hey! If you are trying to trunk VLAN 1, you are going to run into trouble (using the below config, I think you may have to configure Ethernet0/3 (NOT a sub-interface) to have an ip address. You will not be able to type in ‘vlan 1’, as it is assumed). You have been warned.

same-security-traffic permit inter-interface
same-security-traffic permit intra-interface

interface Ethernet0/3
no nameif
no security-level
no ip address
!
interface Ethernet0/3.1
description Development Network
vlan 50
nameif dev
security-level 40
ip address 192.168.50.1 255.255.255.0 standby 192.168.50.2
!
interface Ethernet0/3.2
description Test Network
vlan 88
nameif test
security-level 60
ip address 192.168.88.1 255.255.255.0 standby 192.168.88.2

QTECH QSW2900

Аналогичный коммутатору Zyxel ES2024 конфигурационный файл для QTECH QSW2900 (все данные, идентифицирующие нашу сеть были удалены):

QTECH-QSW2900#sh run
!LanSwitch BuildRun(QTECH Platform)
enable
configure terminal
![VLAN]
interface range ethernet 1/1 to ethernet 2/1
switchport mode trunk
exit
vlan 1
description VLAN1
interface ip 10.2.6.253 255.255.255.0 10.2.6.1
exit
vlan 2
description MULTICAST
switchport ethernet 1/1 to ethernet 2/1
exit
vlan 10
description MANAGED_VLAN10
switchport ethernet 1/1 to ethernet 2/1
interface ip 192.168.3.181 255.255.252.0 192.168.2.1
exit
![DEVICE]
interface ethernet 0/1
exit
interface ethernet 0/2
exit
interface ethernet 0/3
exit
interface ethernet 0/4
exit
interface ethernet 0/5
exit
interface ethernet 0/6
exit
interface ethernet 0/7
exit
interface ethernet 0/8
exit
interface ethernet 0/9
exit
interface ethernet 0/10
exit
interface ethernet 0/11
exit
interface ethernet 0/12
exit
interface ethernet 0/13
exit
interface ethernet 0/14
exit
interface ethernet 0/15
exit
interface ethernet 0/16
exit
interface ethernet 0/17
exit
interface ethernet 0/18
exit
interface ethernet 0/19
exit
interface ethernet 0/20
exit
interface ethernet 0/21
exit
interface ethernet 0/22
exit
interface ethernet 0/23
exit
interface ethernet 0/24
exit
interface ethernet 1/1
exit
interface ethernet 2/1
exit
![OAM]
ipaddress 10.2.6.253 255.255.255.0 10.2.6.1
hostname QTECH-QSW2900
![IGMP_SNOOPING]
igmp-snooping
![SNMP]
snmp-server contact noc@provider
snmp-server location Koe-gde-2
QTECH-QSW2900#

Информация о VLAN’ах:

QTECH-QSW2900#sh vlan
show VLAN information
VLAN name              : VLAN1
VLAN ID                : 1
VLAN status            : static
VLAN member            : e0/1-e2/1.
Static tagged ports    : e1/1-e2/1.
Static untagged Ports  : e0/1-e0/24.
Dynamic tagged ports   : 

show VLAN information
VLAN name              : MULTICAST
VLAN ID                : 2
VLAN status            : static
VLAN member            : e1/1-e2/1.
Static tagged ports    : e1/1-e2/1.
Static untagged Ports  :
Dynamic tagged ports   : 

show VLAN information
VLAN name              : MANAGED_VLAN10
VLAN ID                : 10
VLAN status            : static
VLAN member            : e1/1-e2/1.
Static tagged ports    : e1/1-e2/1.
Static untagged Ports  :

Конфигурация должна работать, если по аплинку приходит транк (а в нашем случае он не приходит, это жаль) )) Из-за этого Инет у людей работал на портах 1-24,  при этом он проходил по native VLAN 1, а вот 25-26 порты, которые в транке, не пинговались извне. До конца еще не разобрался — то ли надо просто отключить trunk, то ли руками прописать default native VLAN 1.

Вот аналогичный конфиг который отлично работает на другом доме:

QTECH#sh run
!LanSwitch BuildRun(QTECH Platform)
enable
configure terminal
![DEVICE]
interface ethernet 0/1
exit
interface ethernet 0/2
exit
interface ethernet 0/3
exit
interface ethernet 0/4
exit
interface ethernet 0/5
exit
interface ethernet 0/6
exit
interface ethernet 0/7
exit
interface ethernet 0/8
exit
interface ethernet 0/9
exit
interface ethernet 0/10
exit
interface ethernet 0/11
exit
interface ethernet 0/12
exit
interface ethernet 0/13
exit
interface ethernet 0/14
exit
interface ethernet 0/15
exit
interface ethernet 0/16
exit
interface ethernet 0/17
exit
interface ethernet 0/18
exit
interface ethernet 0/19
exit
interface ethernet 0/20
exit
interface ethernet 0/21
exit
interface ethernet 0/22
exit
interface ethernet 0/23
exit
interface ethernet 0/24
exit
interface ethernet 1/1
description UPLINK
exit
interface ethernet 2/1
exit
![OAM]
ipaddress 10.2.5.252 255.255.255.0 10.2.5.1
hostname Koe-gde-3
QTECH#sh vlan
show VLAN information
VLAN ID                : 1
VLAN status            : static
VLAN member            : e0/1-e2/1.
Static tagged ports    :
Static untagged Ports  : e0/1-e2/1.
Dynamic tagged ports   :

Total entries: 1 vlan.

Т.е. не настроено НИЧЕГО!

Алгоритм быстрой настройки свитча:

1. Подключаемся по COM-порту и вводим логин/пароль.
2. enable
3. clear startup-config
4. reboot
5. Вводим default логин/пароль: admin/123456
6. enable
7. conf t
8. username admin privilege 15 password 7 P@$$W0RD
9. hostname KOE-GDE
10. ipaddress 10.2.6.253
11. exit
12. reboot

Вот и всё. Быстрая настройка коммутатора по вышеописанному конфигу готова.